Prosím o kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: memphisto, Mods_senior, Security team

Uživatelský avatar
Pajus
Level 2.5
Level 2.5
Příspěvky: 315
Registrován: březen 12
Pohlaví: Muž

Re: Prosím o kontrolu

Příspěvekod Pajus » 01 lis 2019 16:04

pokračování

2019-10-29 18:03 - 2019-10-29 18:03 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmd.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000230200 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamMap.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagSvc.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CmUtil.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000204816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spacedump.sys
2019-10-29 18:03 - 2019-10-29 18:03 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000202552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-10-29 18:03 - 2019-10-29 18:03 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000199680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\accessibilitycpl.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000189440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\AarSvc.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmvdsitf.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000164776 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000164368 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMapi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmvdsitf.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000136536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\omadmapi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Utilman.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2019-10-29 18:03 - 2019-10-29 18:03 - 000113160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2019-10-29 18:03 - 2019-10-29 18:03 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000105488 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2019-10-29 18:03 - 2019-10-29 18:03 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Utilman.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000089328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000088568 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcXtrnal.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AtBroker.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-10-29 18:03 - 2019-10-29 18:03 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2019-10-29 18:03 - 2019-10-29 18:03 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncController.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000073024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000071696 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32appinventorycsp.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Common.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2019-10-29 18:03 - 2019-10-29 18:03 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AtBroker.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000065272 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcadm.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppCore.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAppMonitor.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CabUtil.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nsiproxy.sys
2019-10-29 18:03 - 2019-10-29 18:03 - 000047208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.EventLogMessages.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Office2010CustomActions.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevAgentPolicyGenerator.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2019-10-29 18:03 - 2019-10-29 18:03 - 000036368 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2010CustomActions.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winnsi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\posetup.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000030720 _____ C:\WINDOWS\system32\uwfservicingapi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsisvc.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000028344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winnsi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscisvif.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidtel.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000024792 _____ (Microsoft Corporation) C:\WINDOWS\system32\nsi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Management.WmiAccess.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000022016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Management.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000021520 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000020992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppData.WinRT.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000020352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nsi.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncCommon.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.Common.WinRT.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\applockerfltr.sys
2019-10-29 18:03 - 2019-10-29 18:03 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.LocalSyncProvider.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsilog.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcXtrnal.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernSync.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevTemplateBaselineGenerator.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaevts.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\UevTemplateConfigItemGenerator.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000011264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SmbSyncProvider.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spwmp.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscadminui.exe
2019-10-29 18:03 - 2019-10-29 18:03 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.MonitorSyncProvider.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.SyncConditions.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdxm.ocx
2019-10-29 18:03 - 2019-10-29 18:03 - 000005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxmasf.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2019-10-29 18:03 - 2019-10-29 18:03 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-10-29 18:03 - 2019-10-29 18:03 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2019-10-29 17:58 - 2019-10-15 07:43 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2019-10-29 17:58 - 2019-10-15 07:06 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2019-10-26 20:55 - 2019-10-26 20:55 - 000552848 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetSec.sys
2019-10-26 20:55 - 2019-10-26 20:55 - 000002088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premium Security.lnk
2019-10-26 20:55 - 2019-09-19 19:35 - 000355720 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2019-10-26 19:49 - 2019-10-30 18:59 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-10-26 19:49 - 2019-10-26 19:49 - 000000000 ____D C:\Users\pajus\AppData\Local\mbamtray
2019-10-26 19:49 - 2019-10-26 19:49 - 000000000 ____D C:\Users\pajus\AppData\Local\mbam
2019-10-26 19:49 - 2019-10-26 19:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-10-26 19:49 - 2019-10-26 19:49 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-10-26 19:49 - 2019-10-26 19:49 - 000000000 ____D C:\Program Files\Malwarebytes
2019-10-26 19:49 - 2019-06-26 12:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-10-26 18:54 - 2019-10-26 18:54 - 000000702 _____ C:\Users\pajus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ESET Online Scanner.lnk
2019-10-26 18:54 - 2019-10-26 18:54 - 000000000 ____D C:\Users\pajus\AppData\Local\ESET
2019-10-24 15:56 - 2019-10-24 15:56 - 000000000 ____D C:\ProgramData\Unknown Worlds
2019-10-24 15:54 - 2019-10-24 15:54 - 000000000 ____D C:\Users\pajus\AppData\LocalLow\Unknown Worlds
2019-10-24 15:46 - 2019-10-24 15:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Subnautica
2019-10-16 08:10 - 2019-10-15 14:49 - 000031672 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamemodcontrol.exe
2019-10-11 11:12 - 2019-10-11 11:12 - 019811840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 005915648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 005041664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 002861568 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2019-10-11 11:12 - 2019-10-11 11:12 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2019-10-11 11:12 - 2019-10-11 11:12 - 002494440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 002422592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2019-10-11 11:12 - 2019-10-11 11:12 - 002314648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 002236144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 002138472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2019-10-11 11:12 - 2019-10-11 11:12 - 002095104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001952360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001847808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001730560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001687040 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001563648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001562424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001283072 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001273392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001217904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-10-11 11:12 - 2019-10-11 11:12 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001152016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000904208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000856576 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2019-10-11 11:12 - 2019-10-11 11:12 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000829536 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2019-10-11 11:12 - 2019-10-11 11:12 - 000818688 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000679880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000598024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000537600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000452408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-10-11 11:12 - 2019-10-11 11:12 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000404392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000380216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-10-11 11:12 - 2019-10-11 11:12 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-10-11 11:12 - 2019-10-11 11:12 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-10-11 11:12 - 2019-10-11 11:12 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000150328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2019-10-11 11:12 - 2019-10-11 11:12 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000033048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NtlmShared.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2019-10-11 11:12 - 2019-10-11 11:12 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll
2019-10-11 11:12 - 2019-10-11 11:12 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 004562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 002456064 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 002448712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 002114048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 002000168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 001830200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 001084432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000890472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000880088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000758584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mousocoreworker.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000516408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 000515896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 000466416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000462136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-10-11 11:11 - 2019-10-11 11:11 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-10-11 11:11 - 2019-10-11 11:11 - 000412152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000225080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2019-10-11 11:11 - 2019-10-11 11:11 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000220472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 000165832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-10-11 11:11 - 2019-10-11 11:11 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2019-10-11 11:11 - 2019-10-11 11:11 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000039304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NtlmShared.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000037176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2019-10-11 11:11 - 2019-10-11 11:11 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2019-10-11 11:11 - 2019-10-11 11:11 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2019-10-10 16:33 - 2019-10-29 07:49 - 000000000 ____D C:\Users\pajus\OneDrive\Dokumenty\TrailMakers
2019-10-10 16:33 - 2019-10-10 16:33 - 000000000 ____D C:\Users\pajus\AppData\LocalLow\Flashbulb
2019-10-10 16:32 - 2019-10-10 16:32 - 000000691 _____ C:\ProgramData\Plocha\Trailmakers.lnk
2019-10-10 16:32 - 2019-10-10 16:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trailmakers
2019-10-10 15:04 - 2019-10-10 15:04 - 000000000 ____D C:\Users\pajus\OneDrive\Dokumenty\4A Games
2019-10-07 18:22 - 2019-10-07 18:22 - 000000000 ____D C:\Program Files\Samsung
2019-10-06 17:29 - 2019-10-06 17:29 - 000000000 ____D C:\Program Files\Common Files\Common Desktop Agent
2019-10-06 12:11 - 2019-10-06 17:29 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Printers
2019-10-06 12:11 - 2019-10-06 17:29 - 000000000 ____D C:\Users\pajus\AppData\Roaming\Samsung
2019-10-06 12:11 - 2019-10-06 17:29 - 000000000 ____D C:\Program Files (x86)\Samsung
2019-10-06 12:11 - 2019-06-20 21:48 - 000174536 _____ C:\WINDOWS\system32\us015ci.exe
2019-10-06 12:11 - 2019-06-20 21:48 - 000098160 _____ (SS) C:\WINDOWS\system32\us015ci.dll
2019-10-06 12:11 - 2019-06-20 21:48 - 000031096 _____ () C:\WINDOWS\system32\us015lm.dll
2019-10-06 12:11 - 2016-07-26 07:20 - 002847744 ____N C:\WINDOWS\system32\DlgSearchEngine.dll
2019-10-06 12:11 - 2016-07-26 07:20 - 002094592 ____N C:\WINDOWS\SysWOW64\DlgSearchEngine.dll
2019-10-06 12:11 - 2016-07-26 07:20 - 000169472 ____N C:\WINDOWS\system32\StatusMessage.dll
2019-10-06 12:11 - 2016-07-26 07:20 - 000124928 ____N C:\WINDOWS\SysWOW64\StatusMessage.dll
2019-10-06 12:11 - 2015-02-07 04:58 - 000143664 ____N C:\WINDOWS\SysWOW64\SecUPDUtilSvc.exe
2019-10-06 12:11 - 2015-02-07 04:58 - 000143664 ____N C:\WINDOWS\system32\SecUPDUtilSvc.exe
2019-10-06 12:07 - 2019-10-06 17:29 - 000000000 ____D C:\ProgramData\Samsung
2019-10-05 14:37 - 2019-10-05 14:37 - 005865272 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizimg.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 003553280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 003184128 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 002821120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 002590208 _____ C:\WINDOWS\system32\dwmscene.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 002552120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 002160640 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 002132280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 002069504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001957008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001845408 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001788728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001664376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001616784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001616608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdrecordcpu.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001607680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001543168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 001510752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001505320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001383856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-10-05 14:37 - 2019-10-05 14:37 - 001334064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdrecordcpu.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001297936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001263616 _____ (Microsoft Corporation) C:\WINDOWS\system32\opengl32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001261800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001244944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001182240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 001178816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001150240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputHost.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001091584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001054872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001047968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001029432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 001023128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\assignedaccessmanagersvc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000944664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000939008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000931840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000904704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\opengl32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000833312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000792296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputHost.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000759488 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000732176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000659456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessManager.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000656960 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000649016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000639400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000612864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000576512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\csc.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000551952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiagn.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourceMapper.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000541480 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000539648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000502784 _____ C:\WINDOWS\system32\AssignedAccessCsp.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000501232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-10-05 14:37 - 2019-10-05 14:37 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000487576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiagn.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000450360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000449888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000442704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-10-05 14:37 - 2019-10-05 14:37 - 000417280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000398728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000387832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000383984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000379840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiag.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000342896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdwriter.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000334936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiag.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000293344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgmgr32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\SshdBroker.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\directxdatabaseupdater.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000285256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000283688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdwriter.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000278080 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ManageCI.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glu32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgmgr32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000231440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVShNotify.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000223032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgiadaptercache.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000202768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVStreamingUX.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000181776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVDllSurrogate.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlib.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000176152 _____ (Microsoft Corporation) C:\WINDOWS\system32\imm32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000173072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVNice.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glu32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000159112 _____ (Microsoft Corporation) C:\WINDOWS\system32\devobj.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000145208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CscMig.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000143808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imm32.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000140496 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prntvpt.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000137864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devobj.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwclientres.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ForceSync.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000125232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000119840 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000116904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\SshdPinAuthLsa.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000110080 _____ C:\WINDOWS\system32\ResBParser.dll

ještě budem pokračovat


MSI B450 TOMAHAWK , AMD RYZEN 5 2600 , Crucial 16GB KIT DDR4 3200MHz CL16 Ballistix Sport AT , MSI GeForce GTX 1060 ARMOR 6G OCV1 , hdd Crucial MX500 500GB SSD + WD Blue WD10EZEX 3.5" 1TB , Windows 10 pro. + Linux Mint Cinammon 18.1- 64bit. , Zdroj Seasonic 500W

Reklama
Uživatelský avatar
Pajus
Level 2.5
Level 2.5
Příspěvky: 315
Registrován: březen 12
Pohlaví: Muž

Re: Prosím o kontrolu

Příspěvekod Pajus » 01 lis 2019 16:07

2019-10-05 14:37 - 2019-10-05 14:37 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000100664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000092624 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostw.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvvmtransport.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000079376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uaspstor.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000066832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvvmtransport.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidspi.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\devrtl.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devrtl.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnppolicy.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000053248 _____ C:\WINDOWS\system32\Drivers\UsbPmApi.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000052752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmstorfl.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000047616 _____ C:\WINDOWS\system32\UsbPmApi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000043536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storvsc.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000037904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncAppvPublishingServer.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2019-10-05 14:37 - 2019-10-05 14:37 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32_DeviceGuard.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000021816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScriptRunner.exe
2019-10-05 14:37 - 2019-10-05 14:37 - 000020944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000016696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizres.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\appvetwstreamingux.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSErrRedir.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000011576 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlibres.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2019-10-05 14:37 - 2019-10-05 14:37 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-11-01 15:47 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-11-01 15:21 - 2019-03-09 14:53 - 000000000 ____D C:\Users\pajus\AppData\LocalLow\Mozilla
2019-11-01 12:13 - 2019-07-05 08:39 - 000003142 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner
2019-11-01 12:13 - 2019-03-09 13:10 - 000000000 ____D C:\ProgramData\NVIDIA
2019-11-01 11:33 - 2019-07-05 08:34 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-11-01 09:45 - 2019-07-05 08:42 - 001693636 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-11-01 09:45 - 2019-03-19 12:57 - 000716780 _____ C:\WINDOWS\system32\perfh005.dat
2019-11-01 09:45 - 2019-03-19 12:57 - 000144860 _____ C:\WINDOWS\system32\perfc005.dat
2019-11-01 09:45 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2019-11-01 09:39 - 2019-03-09 14:52 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2019-11-01 09:39 - 2019-03-09 14:52 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-11-01 09:38 - 2019-07-05 08:39 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-10-31 19:48 - 2019-03-19 05:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-10-31 19:48 - 2019-03-09 18:47 - 000000000 ____D C:\Program Files (x86)\Steam
2019-10-31 19:08 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Windows Defender
2019-10-31 19:08 - 2019-03-09 20:10 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-10-31 19:01 - 2019-03-09 14:39 - 000000000 ____D C:\Users\pajus\AppData\Local\CrashDumps
2019-10-31 15:33 - 2019-03-09 14:17 - 000000000 ____D C:\Users\pajus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2019-10-31 15:25 - 2019-09-16 17:50 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2019-10-31 15:25 - 2019-07-05 08:39 - 000003402 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2019-10-31 15:25 - 2019-07-05 08:39 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2019-10-31 15:25 - 2019-07-05 08:39 - 000003178 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2019-10-31 15:25 - 2019-07-05 08:39 - 000002954 _____ C:\WINDOWS\system32\Tasks\klcp_update
2019-10-31 15:25 - 2019-07-05 08:39 - 000002402 _____ C:\WINDOWS\system32\Tasks\MSI_Toast_Server
2019-10-31 15:25 - 2019-07-05 08:39 - 000002280 _____ C:\WINDOWS\system32\Tasks\MSIGH_Host
2019-10-31 15:25 - 2019-07-05 08:39 - 000002236 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2019-10-31 15:25 - 2019-07-05 08:39 - 000002148 _____ C:\WINDOWS\system32\Tasks\MSISW_Host
2019-10-31 15:25 - 2019-07-05 08:39 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2019-10-31 13:19 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-10-31 13:10 - 2019-03-10 13:37 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2019-10-31 12:56 - 2019-07-05 08:39 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2019-10-31 07:09 - 2019-03-09 13:38 - 000741432 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2019-10-30 09:44 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-10-29 18:16 - 2019-03-09 13:17 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-10-29 18:16 - 2019-03-09 13:17 - 000000000 ___RD C:\Users\pajus\3D Objects
2019-10-29 18:14 - 2019-07-05 08:34 - 000267720 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\appraiser
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellComponents
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\DiagTrack
2019-10-29 18:13 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-10-29 18:05 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-10-29 17:45 - 2019-03-09 18:58 - 000000000 ____D C:\Users\pajus\AppData\Local\Ubisoft Game Launcher
2019-10-28 12:29 - 2019-04-20 17:31 - 000000000 ____D C:\Users\pajus\AppData\Roaming\.minecraft
2019-10-27 09:11 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-10-26 20:55 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-10-26 20:15 - 2019-03-29 17:37 - 000000000 ____D C:\Program Files (x86)\GOG Galaxy
2019-10-26 19:56 - 2019-03-09 13:19 - 000000000 ____D C:\Users\pajus\AppData\Local\D3DSCache
2019-10-26 14:00 - 2019-03-10 14:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2019-10-25 14:53 - 2019-09-16 17:50 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-10-24 15:38 - 2019-03-10 14:18 - 000000000 ____D C:\Users\pajus\AppData\Roaming\uTorrent
2019-10-24 15:34 - 2019-03-09 13:49 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-10-21 18:31 - 2019-03-09 14:41 - 000000000 ____D C:\Users\pajus\OneDrive\Dokumenty\American Truck Simulator
2019-10-19 07:56 - 2019-03-09 17:50 - 000000000 ____D C:\Users\pajus\AppData\Roaming\vlc
2019-10-17 15:18 - 2019-09-29 16:36 - 000775224 ____N C:\WINDOWS\system32\Drivers\smrtkrnl.sys
2019-10-15 14:49 - 2019-07-05 08:50 - 001245624 _____ (Microsoft Corporation) C:\WINDOWS\system32\xgameruntime.dll
2019-10-15 14:49 - 2019-07-05 08:50 - 000197552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameconfighelper.dll
2019-10-15 14:49 - 2019-07-05 08:50 - 000086456 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingservicesproxy.dll
2019-10-11 11:41 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-10-11 11:41 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-10-11 11:41 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2019-10-11 11:41 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-10-11 11:41 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-10-11 11:16 - 2019-03-09 13:39 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-10-11 11:13 - 2019-03-09 13:39 - 127230528 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-10-05 14:41 - 2019-03-19 12:59 - 000000000 ___SD C:\WINDOWS\system32\AppV
2019-10-05 14:41 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2019-10-05 14:41 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-10-05 14:26 - 2019-03-09 13:17 - 000000000 ____D C:\Users\pajus\AppData\Local\Packages
2019-10-05 14:22 - 2019-03-09 13:18 - 000000000 ___RD C:\Users\pajus\OneDrive
2019-10-03 12:41 - 2019-03-09 13:48 - 000000000 ____D C:\Program Files (x86)\Google

==================== Files in the root of some directories ========

2019-03-09 18:23 - 2019-08-22 17:31 - 001065984 _____ () C:\Users\pajus\AppData\Local\file__0.localstorage
2019-03-09 17:38 - 2019-07-21 14:26 - 000007602 _____ () C:\Users\pajus\AppData\Local\Resmon.ResmonCfg

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================
MSI B450 TOMAHAWK , AMD RYZEN 5 2600 , Crucial 16GB KIT DDR4 3200MHz CL16 Ballistix Sport AT , MSI GeForce GTX 1060 ARMOR 6G OCV1 , hdd Crucial MX500 500GB SSD + WD Blue WD10EZEX 3.5" 1TB , Windows 10 pro. + Linux Mint Cinammon 18.1- 64bit. , Zdroj Seasonic 500W

Uživatelský avatar
Pajus
Level 2.5
Level 2.5
Příspěvky: 315
Registrován: březen 12
Pohlaví: Muž

Re: Prosím o kontrolu

Příspěvekod Pajus » 01 lis 2019 16:08

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-11-2019
Ran by pajus (01-11-2019 15:53:20)
Running from C:\Users\pajus\OneDrive\Plocha
Windows 10 Pro Version 1903 18362.449 (X64) (2019-07-05 07:39:33)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2527519168-583348821-1951529318-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2527519168-583348821-1951529318-503 - Limited - Disabled)
Guest (S-1-5-21-2527519168-583348821-1951529318-501 - Limited - Disabled)
pajus (S-1-5-21-2527519168-583348821-1951529318-1001 - Administrator - Enabled) => C:\Users\pajus
WDAGUtilityAccount (S-1-5-21-2527519168-583348821-1951529318-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: Avast Antivirus (Disabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.021.20049 - Adobe Systems Incorporated)
AIDA64 Extreme v5.99 (HKLM-x32\...\AIDA64 Extreme_is1) (Version: 5.99 - FinalWire Ltd.)
AMD Product Verification Tool version 1.0.2.8 (HKLM\...\{4242685A-EF3E-45FF-B4AE-758E49020936}_is1) (Version: 1.0.2.8 - AMD)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 19.10.16 - Advanced Micro Devices, Inc.)
Avast Premium Security (HKLM-x32\...\Avast Antivirus) (Version: 19.8.2393 - AVAST Software)
Balanced (HKLM-x32\...\{0EA45DD4-A825-420C-AFED-C659EFE3B84F}) (Version: 4.00.0000 - Advanced Micro Devices, Inc.) Hidden
Balíček ovladačů pro úsporný režim (HKLM-x32\...\Samsung Eco Driver Pack) (Version: 2.01.10.00 (28.05.2015) - Samsung Electronics Co., Ltd.)
CCleaner (HKLM\...\CCleaner) (Version: 5.56 - Piriform)
Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden
CPUID CPU-Z MSI 1.86 (HKLM\...\CPUID CPU-Z MSI_is1) (Version: 1.86 - CPUID, Inc.)
CPUID HWMonitor 1.40 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.40 - CPUID, Inc.)
Crossout Launcher 1.0.3.89 (HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\CrossOutLauncher_is1) (Version: - )
Crucial Storage Executive (HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\Crucial Storage Executive 3.60.082018.04) (Version: 3.65.012019.06 - Crucial)
CrystalDiskMark 6.0.2 (HKLM\...\CrystalDiskMark6_is1) (Version: 6.0.2 - Crystal Dew World)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.10.0.0797 - Disc Soft Ltd)
Dragon Age Inquisition v.1.11.u10 (HKLM-x32\...\Dragon Age Inquisition_is1) (Version: - )
Epic Games Launcher (HKLM-x32\...\{A398FCC0-8E8B-409E-90E9-ACF4671633F2}) (Version: 1.1.183.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Factorio version 0.17.9 (HKLM\...\Factorio_is1) (Version: - )
Farming Simulator 19 v.1.3.0.1 (HKLM-x32\...\Farming Simulator 19_is1) (Version: - )
Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 78.0.3904.70 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.301 - Google LLC) Hidden
House Flipper Halloween (HKLM-x32\...\House Flipper Halloween_is1) (Version: - )
Java 8 Update 211 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180211F0}) (Version: 8.0.2110.12 - Oracle Corporation)
Java 8 Update 211 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180211F0}) (Version: 8.0.2110.12 - Oracle Corporation)
K-Lite Mega Codec Pack 14.7.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.7.5 - KLCP)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Little Nightmares - Fox mask (HKLM-x32\...\1828170949_is1) (Version: 1.0.43.1 - GOG.com)
Little Nightmares - Hideaway (HKLM-x32\...\1675156362_is1) (Version: 1.0.43.1 - GOG.com)
Little Nightmares - Scarecrow sack (HKLM-x32\...\1268928435_is1) (Version: 1.0.43.1 - GOG.com)
Little Nightmares - Tengu mask (HKLM-x32\...\1611302854_is1) (Version: 1.0.43.1 - GOG.com)
Little Nightmares - The Depths (HKLM-x32\...\1863057712_is1) (Version: 1.0.43.1 - GOG.com)
Little Nightmares - The Residence (HKLM-x32\...\1185734803_is1) (Version: 1.0.43.1 - GOG.com)
Little Nightmares - Upside-down teapot (HKLM-x32\...\1352220891_is1) (Version: 1.0.43.1 - GOG.com)
Little Nightmares (HKLM-x32\...\1433377508_is1) (Version: 1.0.43.1 - GOG.com)
Malwarebytes verze 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{a2199617-3609-410f-a8e8-e8806c73545b}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{d98165f5-8b37-4100-8852-a0664374ff8a}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{2fa65abe-2cfc-4cf3-89b1-99122a47fdd6}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.16.27027 (HKLM-x32\...\{fd9b6070-d13e-45dc-819b-41806bf45b6b}) (Version: 14.16.27027.1 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.16.27027 (HKLM-x32\...\{39e28474-b67b-4209-af1b-e9ad0a83d8ca}) (Version: 14.16.27027.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Mozilla Firefox 70.0.1 (x64 cs) (HKLM\...\Mozilla Firefox 70.0.1 (x64 cs)) (Version: 70.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 65.0.2 - Mozilla)
MSI Afterburner 4.6.1 (HKLM-x32\...\Afterburner) (Version: 4.6.1 - MSI Co., LTD)
MSI APP Manager (HKLM-x32\...\{00F47104-12BA-4E58-A7E6-F456C1BA338E}}_is1) (Version: 1.0.0.32 - MSI)
MSI Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 3.0.0.97 - MSI)
MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.2.0.90 - MSI)
MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.2.0.58 - MSI)
MSI Smart Tool (HKLM-x32\...\{DDCCA038-DAB1-4D09-B85C-848020AA75D6}}_is1) (Version: 1.0.0.42 - MSI)
MSI X Boost (HKLM-x32\...\{515143BB-7A11-4D85-B941-D520AAAA099C}_is1) (Version: 1.0.0.46 - MSI)
NVIDIA Ovladač HD audia 1.3.38.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.21 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 436.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 436.30 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
OCCT 4.5.1 (HKLM-x32\...\OCCT) (Version: 4.5.1 - Ocbase.com)
OEM Application Profile (HKLM-x32\...\{7F5DCD33-1039-C3B2-9538-B645B65BBA63}) (Version: 1.00.0000 - Název společnosti:)
Ovládací panel NVIDIA 436.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 436.30 - NVIDIA Corporation) Hidden
Pomocník s aktualizací Windows 10 (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22807 - Microsoft Corporation)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.35.510.2019 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8627 - Realtek Semiconductor Corp.)
RivaTuner Statistics Server 7.2.2 (HKLM-x32\...\RTSS) (Version: 7.2.2 - Unwinder)
Roblox Player for pajus (HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\roblox-player) (Version: - Roblox Corporation)
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 2.00.01.24 - HP Printing Korea Co., Ltd.)
Samsung Easy Wireless Setup (HKLM-x32\...\Easy Wireless Setup) (Version: 3.70.18.0 - Samsung Electronics Co., Ltd.)
Samsung Printer Center (HKLM-x32\...\Samsung Printer Center) (Version: 1.0.0.29 - Samsung Electronics Co., Ltd.)
Samsung Scan Process Machine (HKLM-x32\...\Samsung Scan Process Machine) (Version: 1.03.05.28 - Samsung Electronics Co., Ltd.) Hidden
Shadow of the Tomb Raider Cpy Čeština (HKLM-x32\...\{F233C280-925A-422A-91DD-F99B398A76E6}) (Version: 1.0.0 - cpy)
Sophos Virus Removal Tool (HKLM-x32\...\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.7.0 - Sophos Limited)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Subnautica (HKLM-x32\...\Subnautica_is1) (Version: - )
Thief Simulator (HKLM-x32\...\Thief Simulator_is1) (Version: 1.027 - )
Trailmakers (HKLM-x32\...\Trailmakers_is1) (Version: 1.0.2.0 - Flashbulb)
Unigine Valley Benchmark version 1.0 (HKLM-x32\...\Unigine Valley Benchmark_is1) (Version: 1.0 - Unigine Corp.)
Uninstall Samsung Printer Software (HKLM-x32\...\TotalUninstaller) (Version: 4.0.0.93 - Samsung Electronics CO., LTD.)
Uplay (HKLM-x32\...\Uplay) (Version: 85.0 - Ubisoft)
VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN)
Wargaming.net Game Center (HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\Wargaming.net Game Center) (Version: 19.6.0.7019 - Wargaming.net)
Windows 7 USB/DVD Download Tool (HKLM-x32\...\{CCF298AF-9CE1-4B26-B251-486E98A34789}) (Version: 1.0.30 - Microsoft Corporation)
WinRAR 5.70 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.70.0 - win.rar GmbH)
World of Tanks EU (HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\WOT.EU.PRODUCTION) (Version: - Wargaming.net)
Zemana AntiMalware verze 3.1.395 (HKLM-x32\...\{4E1F3677-C72E-4F7D-B66E-85467B1A289E}_is1) (Version: 3.1.395 - Zemana)

Packages:
=========
DirectX -> C:\Program Files\WindowsApps\Microsoft.DirectXRuntime_9.29.952.0_x64__8wekyb3d8bbwe [2019-07-05] (Microsoft Corporation)
DirectX -> C:\Program Files\WindowsApps\Microsoft.DirectXRuntime_9.29.952.0_x86__8wekyb3d8bbwe [2019-07-05] (Microsoft Corporation)
Dolby Access -> C:\Program Files\WindowsApps\DolbyLaboratories.DolbyAccess_3.0.3587.0_x64__rz1tebttyb220 [2019-10-08] (Dolby Laboratories)
EdgeDevtoolsPlugin -> C:\WINDOWS\SystemApps\Microsoft.EdgeDevtoolsPlugin_cw5n1h2txyewy [2019-10-29] (Microsoft Corporation)
Forza Horizon 4 -> C:\Program Files\WindowsApps\Microsoft.SunriseBaseGame_1.361.362.2_x64__8wekyb3d8bbwe [2019-10-30] (Microsoft Studios)
Gears 5 -> C:\Program Files\WindowsApps\Microsoft.HalifaxBaseGame_1.1.95.0_x64__8wekyb3d8bbwe [2019-10-19] (Microsoft Studios)
Geometry SubZero World -> C:\Program Files\WindowsApps\18135VOODOOGamesFree.GeometrySubZeroDasher_8.9.0.0_x64__sp8w4c1epg18p [2019-09-20] (VOODOO Games Free) [MS Ad]
Herní služby -> C:\Program Files\WindowsApps\Microsoft.GamingServices_1.34.7001.0_x64__8wekyb3d8bbwe [2019-10-15] (Microsoft Corporation)
Horizon Go CZ -> C:\Program Files\WindowsApps\LibertyGlobal.HorizonGoCZ_2.12.0.0_x64__gmwgfebrpy77e [2019-08-31] (Liberty Global)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-03-09] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-03-09] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.10022.0_x64__8wekyb3d8bbwe [2019-10-08] (Microsoft Studios) [MS Ad]
Phototastic Collage -> C:\Program Files\WindowsApps\ThumbmunkeysLtd.PhototasticCollage_2.2.16.0_x64__nfy108tqq3p12 [2019-09-27] (Thumbmunkeys Ltd) [MS Ad]
Pošta a Kalendář -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe [2019-09-27] (Microsoft Corporation) [MS Ad]
ROBLOX -> C:\Program Files\WindowsApps\ROBLOXCORPORATION.ROBLOX_2.407.25915.0_x86__55nm5eh3cm0pr [2019-10-30] (ROBLOX Corporation)
Super Lucky's Tale -> C:\Program Files\WindowsApps\Microsoft.AcornUWP_1.5.2019.2_x64__8wekyb3d8bbwe [2019-09-06] (Microsoft Studios)
Tanks VS Robots -> C:\Program Files\WindowsApps\23866ExtremeDevelopers.TanksVSRobots_2.68.1.0_x64__zxxvj7ezs5pcc [2019-06-19] (Extreme Developers)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2019-08-27] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-03-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2019-03-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-09-05] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana\AntiMalware\AM_ShellExt64.dll [2019-08-27] (Zemana D.O.O. Sarajevo -> Advanced Malware Protection. Copyright 2019.)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-09-19] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\system32\x264vfw64.dll [3799552 2017-07-30] (x264vfw project) [File not signed]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\system32\lagarith.dll [148992 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\system32\xvidvfw.dll [311296 2018-01-28] () [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\system32\ac3acm.acm [180736 2012-07-21] (fccHandler) [File not signed]
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\system32\frapsv64.dll [71680 2012-08-30] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3850240 2017-07-30] (x264vfw project) [File not signed]
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\SysWOW64\xvidvfw.dll [284672 2018-01-28] () [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [File not signed]
HKLM\...\Drivers32: [VIDC.FFDS] => C:\Windows\SysWOW64\ff_vfw.dll [112128 2015-10-24] () [File not signed]
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [65536 2012-08-30] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2019-04-21 09:33 - 2019-04-21 09:33 - 000232448 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTCore.dll
2019-04-21 09:32 - 2019-04-21 09:32 - 000057344 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTFC.dll
2019-04-21 09:33 - 2019-04-21 09:33 - 000649216 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
2019-04-21 09:32 - 2019-04-21 09:32 - 000074240 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
2019-04-21 09:33 - 2019-04-21 09:33 - 000367104 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTUI.dll
2019-06-04 17:31 - 2005-07-18 12:43 - 000160256 _____ () [File not signed] C:\Program Files (x86)\MSI\APP Manager\unrar.dll
2019-03-11 17:44 - 2005-07-18 12:43 - 000160256 _____ () [File not signed] C:\Program Files (x86)\MSI\Live Update\unrar.dll
2019-03-10 14:53 - 2016-04-20 14:12 - 000772608 _____ () [File not signed] C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\Lib\USB_DLL.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\pajus\OneDrive:${3D0CE612-FDEE-43f7-8ACA-957BEC0CCBA0}.SyncRootIdentity [130]

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2018-09-15 08:31 - 2019-11-01 15:46 - 000000813 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\Crucial\Crucial Storage Executive;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-2527519168-583348821-1951529318-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is disabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\Run: => "RTHDVCPL"
HKLM\...\StartupApproved\Run: => "CDAServer"
HKLM\...\StartupApproved\Run32: => "Command Center"
HKLM\...\StartupApproved\Run32: => "APP Manager"
HKLM\...\StartupApproved\Run32: => "Live Update"
HKLM\...\StartupApproved\Run32: => "X_Boost"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\StartupApproved\Run: => "GalaxyClient"
HKU\S-1-5-21-2527519168-583348821-1951529318-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe No File
FirewallRules: [UDP Query User{5A53385B-5FDB-4FA6-ADEE-15E6B71657A6}C:\games\rage 2\rage2.exe] => (Block) C:\games\rage 2\rage2.exe No File
FirewallRules: [TCP Query User{A292105F-5E93-491A-8AD6-64D8B005645E}C:\games\rage 2\rage2.exe] => (Block) C:\games\rage 2\rage2.exe No File
FirewallRules: [UDP Query User{432F5040-ED34-4C60-9330-70AB1D8FAA7D}D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe] => (Block) D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe No File
FirewallRules: [TCP Query User{5A7590D5-F62C-4346-8BDC-6571D50AAC85}D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe] => (Block) D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe No File
FirewallRules: [{A4FB676E-6B25-4722-A03C-24F1CAE4FD26}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{7F713F96-0270-449C-B551-C35F1A7BEBCB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{6EE585B3-9644-46D0-AC5F-EBDDE6E81A8E}] => (Allow) D:\steam\steamapps\common\Crossout\launcher.exe (Gaijin Network LTD -> Gaijin Entertainment)
FirewallRules: [{FC20D084-3435-407A-AD72-D071A0F8F81C}] => (Allow) D:\steam\steamapps\common\Crossout\launcher.exe (Gaijin Network LTD -> Gaijin Entertainment)
FirewallRules: [UDP Query User{400BFF31-0876-4405-B084-A90BCEFC11DA}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe
FirewallRules: [TCP Query User{4E352CC9-1729-40BF-9543-873771C7BE6E}C:\program files\java\jre1.8.0_211\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_211\bin\javaw.exe
FirewallRules: [{68126390-C258-4FB0-98D3-6F406A14D270}] => (Allow) D:\steam\steamapps\common\wallpaper_engine\launcher.exe (Kristjan Skutta -> )
FirewallRules: [{B6C182DE-0A3E-4DB8-8D81-571B654E0666}] => (Allow) D:\steam\steamapps\common\wallpaper_engine\launcher.exe (Kristjan Skutta -> )
FirewallRules: [{05A04400-0785-45A0-AD4C-081463FD94BE}] => (Allow) D:\steam\steamapps\common\RoboBall\RoboBall.exe () [File not signed]
FirewallRules: [{7490B820-CEE6-4FC4-BE37-35A2FA910C45}] => (Allow) D:\steam\steamapps\common\RoboBall\RoboBall.exe () [File not signed]
FirewallRules: [UDP Query User{AE7D6B3A-B90B-417D-AE38-DCCCCFFD1E69}C:\program files\crucial\crucial storage executive\java\bin\javaw.exe] => (Allow) C:\program files\crucial\crucial storage executive\java\bin\javaw.exe
FirewallRules: [TCP Query User{95E6F428-51B1-43E4-AE54-A9C8CFF95491}C:\program files\crucial\crucial storage executive\java\bin\javaw.exe] => (Allow) C:\program files\crucial\crucial storage executive\java\bin\javaw.exe
FirewallRules: [{DC50E766-A3FE-42E2-9D6E-FC4EECE37838}] => (Block) D:\Hry\Forza Horizon 3\AppFiles\forza_x64_release_final.exe No File
FirewallRules: [{42D87C95-8EA7-48EC-8BD0-734EC3816E13}] => (Block) D:\Hry\Forza Horizon 3\AppFiles\forza_x64_release_final.exe No File
FirewallRules: [UDP Query User{EC65F932-E3B2-466D-95F1-F1B6C5B493FD}C:\users\pajus\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\pajus\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [TCP Query User{016EA204-970F-4FA0-9F2E-F29D21464AF2}C:\users\pajus\appdata\roaming\utorrent\utorrent.exe] => (Allow) C:\users\pajus\appdata\roaming\utorrent\utorrent.exe (uTorrent.CZ -> BitTorrent, Inc.) [File not signed]
FirewallRules: [UDP Query User{4F60AD1B-A8CF-4AFA-A827-E9AB0E225973}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{9AF27F65-3F90-4A3B-80E6-179D901B4936}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [UDP Query User{B07214D9-3C4D-4945-962E-CE04F5F43854}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [TCP Query User{A48A4E1E-7C1E-4739-8C4C-B1266C3AEEF8}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe (Epic Games Inc. -> Epic Games, Inc.)
FirewallRules: [{1B15562E-3648-46AB-A6EE-2A23FD34D23C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{252376D0-4E95-47D9-B943-D51274D5D60A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{87BA24D8-46A6-4D26-948B-3D4A66DC5D36}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{3E39D2BF-7CBE-4001-9BF2-9434CE5936E3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{7EBCE7D8-F289-4AD0-98F4-21980D4D4BC6}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{99874CB1-C70A-46BA-9E44-CD3A72EDC276}] => (Allow) LPort=26789
FirewallRules: [TCP Query User{531704CE-B928-4BB3-9480-479AEFA7387B}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [UDP Query User{5B2AB229-439F-4A49-AFB7-BB675F6D87B8}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe (VideoLAN -> VideoLAN)
FirewallRules: [{7FC2184E-908D-4ACF-B9CF-8E446E8C6A02}] => (Allow) C:\ProgramData\Wargaming.net\GameCenter\wgc.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [TCP Query User{22E3673A-76BE-4876-9576-E1E026690E18}D:\wot\world_of_tanks_eu\worldoftanks.exe] => (Allow) D:\wot\world_of_tanks_eu\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [UDP Query User{2660FD13-40A9-4182-A406-717C3C419FDC}D:\wot\world_of_tanks_eu\worldoftanks.exe] => (Allow) D:\wot\world_of_tanks_eu\worldoftanks.exe (Wargaming.net Limited -> Wargaming.net)
FirewallRules: [{824F68A7-8A79-4723-B0FF-7EF58B07DDC2}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Printer Center\SamsungPrinterCenter.exe (HP Inc. -> Samsung Electronics Co., Ltd.)
FirewallRules: [{D1BF68F7-E1D4-4695-ABBC-32A69CCADB82}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{3AC887D0-2FC6-468E-ACCC-CAD3EE7404A2}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [{64534C3A-D7C7-4F29-BE2F-1BF91306A71C}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EasyPrinterManagerV2.exe (HP Inc. -> )
FirewallRules: [{538348B5-0964-4613-AE37-0546EEAA59AA}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe (HP Inc. -> HP Printing Korea Co., Ltd.)
FirewallRules: [{6FA90051-F8B8-4752-AA71-C2378632A9DD}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2AlertList.exe (HP Inc. -> HP Printing Korea Co., Ltd.)
FirewallRules: [{0277319D-5E0D-4B70-BEDD-5BC5307BED61}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\EPM2Migrator.exe (HP Inc. -> )
FirewallRules: [{B96EF72D-0720-4835-AC68-B379B3352A08}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe (Samsung Electronics CO., LTD. -> )
FirewallRules: [TCP Query User{631478E8-D542-459C-9116-15E7C6BF36E4}D:\hry\trailmakers\trailmakers.exe] => (Block) D:\hry\trailmakers\trailmakers.exe () [File not signed]
FirewallRules: [UDP Query User{50D7D21E-A864-4BE8-897A-23C55ECDF79B}D:\hry\trailmakers\trailmakers.exe] => (Block) D:\hry\trailmakers\trailmakers.exe () [File not signed]
FirewallRules: [{E57E788D-6C23-44A9-ABDA-69F60670B7A5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [TCP Query User{B73B6566-7A8F-45DC-8A01-41CCD0BDBE12}D:\hry\subnautica\subnautica.exe] => (Block) D:\hry\subnautica\subnautica.exe () [File not signed]
FirewallRules: [UDP Query User{4B361F65-C255-4B39-88F8-5133FDEFA952}D:\hry\subnautica\subnautica.exe] => (Block) D:\hry\subnautica\subnautica.exe () [File not signed]
FirewallRules: [{1C9339CC-6ED2-42F1-8107-86C8D37A411F}] => (Allow) D:\steam\steamapps\common\wallpaper_engine\bin\diagnostics32.exe (Kristjan Skutta -> )
FirewallRules: [{001F3463-2A5D-446D-91B5-77D1A5CECB2F}] => (Allow) D:\steam\steamapps\common\wallpaper_engine\bin\diagnostics32.exe (Kristjan Skutta -> )

==================== Restore Points =========================

15-10-2019 12:54:08 Windows Update
25-10-2019 17:56:45 Naplánovaný kontrolní bod
29-10-2019 17:58:29 Windows Update
31-10-2019 07:09:35 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (11/01/2019 03:43:45 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10344,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (11/01/2019 03:35:15 PM) (Source: Microsoft-Windows-Perflib) (EventID: 1020) (User: NT AUTHORITY)
Description: Velikost požadované vyrovnávací paměti je větší než velikost vyrovnávací paměti předané do funkce Collect knihovny DLL rozšiřitelných čítačů C:\Windows\System32\perfts.dll pro službu LSM. Velikost dané vyrovnávací paměti: 26000; požadovaná velikost: 27520.

Error: (11/01/2019 03:26:55 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (7096,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (11/01/2019 03:18:32 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2132,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (11/01/2019 03:12:18 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1460,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (11/01/2019 02:14:38 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (9916,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (11/01/2019 02:08:07 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5700,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (11/01/2019 02:02:55 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (10236,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).


System errors:
=============
Error: (11/01/2019 09:38:24 AM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 3221225684Při zpracování obnovovacích dat došlo k závažné chybě.

Error: (11/01/2019 09:38:31 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (19:48:58, ‎31.‎10.‎2019) bylo neočekávané.

Error: (10/31/2019 07:29:46 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Acrobat Update Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/31/2019 07:17:30 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (10/31/2019 07:17:30 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (10/31/2019 07:17:30 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (10/31/2019 07:17:30 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.

Error: (10/31/2019 07:17:29 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Služba PEVSystemStart je označena jako interaktivní služba. Avšak systém je nakonfigurován tak, že neumožňuje použití interaktivní služby. Tato služba nebude fungovat správně.


Windows Defender:
===================================
Date: 2019-09-06 10:11:35.526
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.289.769.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

Date: 2019-09-06 10:11:35.526
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.289.769.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

Date: 2019-09-06 10:11:35.526
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.289.769.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

Date: 2019-09-06 10:11:35.520
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.289.769.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

Date: 2019-09-06 10:11:35.520
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.289.769.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.15700.9
Kód chyby: 0x80072ee7
Popis chyby: Nelze rozpoznat název nebo adresu serveru.

CodeIntegrity:
===================================

Date: 2019-11-01 15:49:36.770
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-11-01 15:49:34.754
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-11-01 15:49:32.754
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-11-01 15:49:30.738
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-11-01 15:49:28.738
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-11-01 15:49:26.740
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-11-01 15:49:23.300
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2019-11-01 15:49:23.294
Description:
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

==================== Memory info ===========================

BIOS: American Megatrends Inc. 1.70 03/06/2019
Motherboard: Micro-Star International Co., Ltd B450 TOMAHAWK (MS-7C02)
Processor: AMD Ryzen 5 2600 Six-Core Processor
Percentage of memory in use: 22%
Total physical RAM: 16334.88 MB
Available physical RAM: 12639.48 MB
Total Virtual: 17358.88 MB
Available Virtual: 12183.6 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.16 GB) (Free:401.86 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:354.8 GB) NTFS

\\?\Volume{f9a3dbda-9890-4465-9dce-ef8cdb260f84}\ (Obnovení) (Fixed) (Total:0.49 GB) (Free:0.07 GB) NTFS
\\?\Volume{81f8d56d-7727-fff1-6b48-79d5293ad327}\ () (Fixed) (Total:72.49 GB) (Free:0 GB) NTFS
\\?\Volume{f099763c-f286-404d-96f7-6ae7ea70be35}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: C05FB28B)

Partition: GPT.

==========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 000AA249)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=42)
Attempted reading MBR returned 0 bytes.
Could not read MBR for disk 2.

==================== End of Addition.txt =======================


Tak a je to vše. Rozdělit jsem to musel.
MSI B450 TOMAHAWK , AMD RYZEN 5 2600 , Crucial 16GB KIT DDR4 3200MHz CL16 Ballistix Sport AT , MSI GeForce GTX 1060 ARMOR 6G OCV1 , hdd Crucial MX500 500GB SSD + WD Blue WD10EZEX 3.5" 1TB , Windows 10 pro. + Linux Mint Cinammon 18.1- 64bit. , Zdroj Seasonic 500W

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40039
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: Prosím o kontrolu

Příspěvekod jaro3 » 01 lis 2019 18:35

Prosím, postupuj následujícím způsobem:
Otevřít poznámkový blok (Start => Všechny programy => Příslušenství => Poznámkový blok).
Prosím, zkopíruj do něj celý obsah níže.

Kód: Vybrat vše

Start
CreateRestorePoint:
CloseProcesses:
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {8DDA32D9-DAF1-401D-A66B-BDCA9CFF9479} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-03-09] (Google Inc -> Google Inc.)
Task: {A3436C32-FBCC-4F32-9235-BA157330576B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-03-09] (Google Inc -> Google Inc.)
SearchScopes: HKU\S-1-5-21-2527519168-583348821-1951529318-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
S3 cpuz148; \??\C:\WINDOWS\temp\cpuz148\cpuz148_x64.sys [X]
 C:\Users\pajus\AppData\Local\ESET
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe No File
FirewallRules: [UDP Query User{5A53385B-5FDB-4FA6-ADEE-15E6B71657A6}C:\games\rage 2\rage2.exe] => (Block) C:\games\rage 2\rage2.exe No File
FirewallRules: [TCP Query User{A292105F-5E93-491A-8AD6-64D8B005645E}C:\games\rage 2\rage2.exe] => (Block) C:\games\rage 2\rage2.exe No File
FirewallRules: [UDP Query User{432F5040-ED34-4C60-9330-70AB1D8FAA7D}D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe] => (Block) D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe No File
FirewallRules: [TCP Query User{5A7590D5-F62C-4346-8BDC-6571D50AAC85}D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe] => (Block) D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe No File
FirewallRules: [{DC50E766-A3FE-42E2-9D6E-FC4EECE37838}] => (Block) D:\Hry\Forza Horizon 3\AppFiles\forza_x64_release_final.exe No File
FirewallRules: [{42D87C95-8EA7-48EC-8BD0-734EC3816E13}] => (Block) D:\Hry\Forza Horizon 3\AppFiles\forza_x64_release_final.exe No File

EmptyTemp:
End

(Můžeš použít funkci „vybrat vše“, klepni pravým tlačítkem myši na levé horní políčko v otevřeném poznámkovém bloku a zvol „ Vložit“).

Ulož jej na na plochu jako fixlist.txt


Spusťt FRST a stiskni tlačítko „Fix“ (Opravit) jen jednou a čekej.
Nástroj vypracuje log na ploše (Fixlog.txt), prosím zkopíruj sem celý jeho obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pajus
Level 2.5
Level 2.5
Příspěvky: 315
Registrován: březen 12
Pohlaví: Muž

Re: Prosím o kontrolu

Příspěvekod Pajus » 01 lis 2019 19:17

Fix result of Farbar Recovery Scan Tool (x64) Version: 01-11-2019
Ran by pajus (01-11-2019 19:14:25) Run:1
Running from C:\Users\pajus\OneDrive\Plocha
Loaded Profiles: pajus (Available Profiles: pajus)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {8DDA32D9-DAF1-401D-A66B-BDCA9CFF9479} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-03-09] (Google Inc -> Google Inc.)
Task: {A3436C32-FBCC-4F32-9235-BA157330576B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2019-03-09] (Google Inc -> Google Inc.)
SearchScopes: HKU\S-1-5-21-2527519168-583348821-1951529318-1001 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
S3 cpuz148; \??\C:\WINDOWS\temp\cpuz148\cpuz148_x64.sys [X]
C:\Users\pajus\AppData\Local\ESET
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\pajus\AppData\Local\Microsoft\OneDrive\19.152.0801.0009\amd64\FileSyncShell64.dll => No File
ContextMenuHandlers1: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => -> No File
ContextMenuHandlers4: [ FileSyncEx] -> {CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe No File
FirewallRules: [UDP Query User{5A53385B-5FDB-4FA6-ADEE-15E6B71657A6}C:\games\rage 2\rage2.exe] => (Block) C:\games\rage 2\rage2.exe No File
FirewallRules: [TCP Query User{A292105F-5E93-491A-8AD6-64D8B005645E}C:\games\rage 2\rage2.exe] => (Block) C:\games\rage 2\rage2.exe No File
FirewallRules: [UDP Query User{432F5040-ED34-4C60-9330-70AB1D8FAA7D}D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe] => (Block) D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe No File
FirewallRules: [TCP Query User{5A7590D5-F62C-4346-8BDC-6571D50AAC85}D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe] => (Block) D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe No File
FirewallRules: [{DC50E766-A3FE-42E2-9D6E-FC4EECE37838}] => (Block) D:\Hry\Forza Horizon 3\AppFiles\forza_x64_release_final.exe No File
FirewallRules: [{42D87C95-8EA7-48EC-8BD0-734EC3816E13}] => (Block) D:\Hry\Forza Horizon 3\AppFiles\forza_x64_release_final.exe No File

EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8DDA32D9-DAF1-401D-A66B-BDCA9CFF9479}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8DDA32D9-DAF1-401D-A66B-BDCA9CFF9479}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A3436C32-FBCC-4F32-9235-BA157330576B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A3436C32-FBCC-4F32-9235-BA157330576B}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
HKU\S-1-5-21-2527519168-583348821-1951529318-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck => removed successfully
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki => removed successfully
HKLM\System\CurrentControlSet\Services\cpuz148 => removed successfully
cpuz148 => service removed successfully
C:\Users\pajus\AppData\Local\ESET => moved successfully
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found
HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => removed successfully
HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => removed successfully
HKU\S-1-5-21-2527519168-583348821-1951529318-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\{4A7C4306-57E0-4C0C-83A9-78C1528F618C} => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\ FileSyncEx => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\OpenSSH-Server-In-TCP" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5A53385B-5FDB-4FA6-ADEE-15E6B71657A6}C:\games\rage 2\rage2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{A292105F-5E93-491A-8AD6-64D8B005645E}C:\games\rage 2\rage2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{432F5040-ED34-4C60-9330-70AB1D8FAA7D}D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{5A7590D5-F62C-4346-8BDC-6571D50AAC85}D:\hry\satisfactory\factorygame\binaries\win64\factorygame-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DC50E766-A3FE-42E2-9D6E-FC4EECE37838}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{42D87C95-8EA7-48EC-8BD0-734EC3816E13}" => removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 56747590 B
Java, Flash, Steam htmlcache => 386089593 B
Windows/system/drivers => 6044832 B
Edge => 0 B
Chrome => 2100463040 B
Firefox => 414011693 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 50438 B
NetworkService => 52818 B
pajus => 376119383 B

RecycleBin => 2685 B
EmptyTemp: => 3.1 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 19:15:28 ====
MSI B450 TOMAHAWK , AMD RYZEN 5 2600 , Crucial 16GB KIT DDR4 3200MHz CL16 Ballistix Sport AT , MSI GeForce GTX 1060 ARMOR 6G OCV1 , hdd Crucial MX500 500GB SSD + WD Blue WD10EZEX 3.5" 1TB , Windows 10 pro. + Linux Mint Cinammon 18.1- 64bit. , Zdroj Seasonic 500W

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40039
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: Prosím o kontrolu

Příspěvekod jaro3 » 01 lis 2019 21:13

Stáhni si zde DelFix
Další odkazy:
https://toolslib.net/downloads/viewdownload/2-delfix/
http://ccm.net/download/download-24087-delfix
https://www.bleepingcomputer.com/download/delfix/

ulož si soubor na plochu.
Poklepáním na ikonu spusť nástroj Delfix.exe
( Ve Windows Vista, Windows 7, 8 a10 musíš spustit soubor pravým tlačítkem myši -> Spustit jako správce .
V hlavním menu, zkontroluj tyto možnosti - Odstranění dezinfekce nástrojů (Remove desinfection tools) – Vyčistit body obnovy (Purge System Restore)
Poté klikněte na tlačítko Spustit (Run) a nech nástroj dělat svoji práci

Poté se zpráva se otevře (DelFix.txt). Vlož celý obsah zprávy sem.Jinak je zpráva zde:
v C: \ DelFix.txt

Asi čisto..

Pokud nejsou problémy , je to vše a můžeš dát vyřešeno , zelenou fajfku.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
Pajus
Level 2.5
Level 2.5
Příspěvky: 315
Registrován: březen 12
Pohlaví: Muž

Re: Prosím o kontrolu  Vyřešeno

Příspěvekod Pajus » 02 lis 2019 08:00

# DelFix v1.013 - Logfile created 02/11/2019 at 07:58:00
# Updated 17/04/2016 by Xplode
# Username : pajus - DESKTOP-1FVNKG7
# Operating System : Windows 10 Enterprise (64 bits)

~ Removing disinfection tools ...

Deleted : C:\FRST
Deleted : C:\zoek_backup
Deleted : C:\AdwCleaner
Deleted : C:\zoek-results.log
Deleted : C:\Users\pajus\OneDrive\Plocha\Addition.txt
Deleted : C:\Users\pajus\OneDrive\Plocha\Fixlog.txt
Deleted : C:\Users\pajus\OneDrive\Plocha\FRST.txt
Deleted : C:\Users\pajus\OneDrive\Plocha\FRST64.exe
Deleted : C:\Users\pajus\OneDrive\Plocha\HijackThis.exe
Deleted : HKLM\SOFTWARE\OldTimer Tools
Deleted : HKLM\SOFTWARE\TrendMicro\Hijackthis

~ Cleaning system restore ...

Deleted : RP #17 [Windows Update | 10/15/2019 11:54:08]
Deleted : RP #18 [Naplánovaný kontrolní bod | 10/25/2019 16:56:45]
Deleted : RP #19 [Windows Update | 10/29/2019 16:58:29]
Deleted : RP #20 [JRT Pre-Junkware Removal | 10/31/2019 06:09:35]

New restore point created !

########## - EOF - ##########

¨




Tak pokud to je vše, moc ti děkuji za pomoc a čas co jsi mi věnoval.
MSI B450 TOMAHAWK , AMD RYZEN 5 2600 , Crucial 16GB KIT DDR4 3200MHz CL16 Ballistix Sport AT , MSI GeForce GTX 1060 ARMOR 6G OCV1 , hdd Crucial MX500 500GB SSD + WD Blue WD10EZEX 3.5" 1TB , Windows 10 pro. + Linux Mint Cinammon 18.1- 64bit. , Zdroj Seasonic 500W


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: CommonCrawl [Bot] a 9 hostů