prosím o kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: memphisto, Mods_senior, Security team

cosopt
nováček
Příspěvky: 12
Registrován: leden 20
Pohlaví: Nespecifikováno

prosím o kontrolu

Příspěvekod cosopt » 28 led 2020 09:55

ak si niekto nájde čas poprosil by som o kontrolu,chcem mať istotu že je všetko ok.ďakujem

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:41:43, on 28. 1. 2020
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.18362.0001)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Users\alex\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=CMNTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Service for Navitel Navigator Update Center] C:\Program Files (x86)\CNT\Navitel Navigator update center\NavitelUpdaterService.exe
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} - https://mapa.katasterportal.sk/kapor2/lib/mgaxctrl.cab
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AVG Antivirus - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\AVGSvc.exe
O23 - Service: avgbIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\aswidsagent.exe
O23 - Service: AvgWscReporter - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\wsc_proxy.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_4d09b01b - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\elevation_service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13540 bytes



Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40449
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: prosím o kontrolu

Příspěvekod jaro3 » 28 led 2020 18:50

Stáhni si ATF Cleaner
https://www.majorgeeks.com/mg/getmirror ... ner,2.html
Poklepej na ATF Cleaner.exe, klikni na select all, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode
http://www.bleepingcomputer.com/download/adwcleaner/
http://www.adlice.com/downloadprogress/
pro majitele win7 stáhni zde:
https://filehippo.com/download_adwcleaner/ ( nedávej aktualizaci!)

Ulož si ho na svojí plochu . Klikni na „Souhlasím“ k povrzení podmínek.
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Skenování“
Po skenu se objeví log , který se otevře. ( jinak je uložen systémovem disku jako C:\AdwCleaner [C?].txt ), jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware na plochu , nainstaluj a spusť ho
-Pokud není program aktuální , klikni na možnost „Aktualizovat nyní“ či „Opravit nyní“.
- bude nalezena aktualizace a nainstaluje se.
- poté klikni na Spustit skenování
- po proběhnutí skenu se ti objeví hláška vpravo dole, tak klikni na Zobrazit zprávu a vyber Export a vyber Kopírovat do schránky a vlož sem celý log. Nebo klikni na „Textový soubor ( .txt)“ a log si ulož.
-jinak se log nachází v programu po kliknutí na „Zprávy“ , nebo je uložen zde: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs

- po té klikni na tlačítko Dokončit, a program zavři křížkem vpravo nahoře.
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

cosopt
nováček
Příspěvky: 12
Registrován: leden 20
Pohlaví: Nespecifikováno

Re: prosím o kontrolu

Příspěvekod cosopt » 29 led 2020 09:44

dúfam že som všetko urobil správne

# -------------------------------
# Malwarebytes AdwCleaner 8.0.1.0
# -------------------------------
# Build: 12-17-2019
# Database: 2020-01-24.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 01-29-2020
# Duration: 00:01:02
# OS: Windows 10 Home
# Scanned: 34795
# Detected: 30


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.Legacy C:\Program Files (x86)\ShowMyPCService

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

No malicious registry entries found.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Preinstalled Software ] *****

Preinstalled.HPHealthCheck Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6F340107-F9AA-47C6-B54C-C3A19F11553F}
Preinstalled.HPLaunchBox Folder C:\Program Files\HEWLETT-PACKARD\HP LAUNCHBOX
Preinstalled.HPLaunchBox Registry HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\SetDefault
Preinstalled.HPLaunchBox Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5A847522-375C-4D05-BD3D-88C450CC047F}
Preinstalled.HPMediaSmart Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B30AC4F3-1736-4A47-8687-109194FA2BC4}
Preinstalled.HPMediaSmart Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MirageAgent
Preinstalled.HPMediaSmart Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}
Preinstalled.HPMediaSmart Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{01FB4998-33C4-4431-85ED-079E3EEFE75D}
Preinstalled.HPMediaSmart Task C:\Windows\System32\Tasks\MIRAGEAGENT
Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP CUSTOMER FEEDBACK
Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT SOLUTIONS
Preinstalled.HPSupportAssistant Folder C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Folder C:\Users\alex\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Folder C:\Users\alex\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Folder C:\Windows\System32\config\systemprofile\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Classes\CLSID\{335F9A62-FE4B-40CD-B4ED-BB4DE21DC95D}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{335F9A62-FE4B-40CD-B4ED-BB4DE21DC95D}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{C0ABBA07-B636-47B8-B9E1-BB96D7CD4831}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}
Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}
Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-hp-mahjonggdarkdimensions
Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-hp-genres



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########




Malwarebytes
www.malwarebytes.com

-Podrobnosti denníka-
Dátum skenovania: 29. 1. 2020
Čas skenovania: 9:27
Súbor denníka: 32776cf4-4271-11ea-b2fa-a0b3cccd21de.json

-Údaje o softvéri-
Verzia: 4.0.4.49
Verzia súčastí: 1.0.810
Aktualizovať verziu balíka: 1.0.18364
Licencia: Zadarmo

-Systémové informácie-
OS: Windows 10 (Build 18362.592)
Procesor: x64
Systém súborov: NTFS
Používateľ: ALEX-HP\alex

-Zhrnutie skenovania-
Typ skenovania: Vyhľadávanie hrozieb
Skenovanie bolo spustené: Manuálne
Výsledok: Dokončené
Preskenované objekty: 343524
Zistené hrozby: 7
Hrozby umiestnené do karantény: 0
Uplynulý čas: 9 min, 14 s

-Možnosti skenovania-
Pamäť: Povolené
Spúšťanie: Povolené
Systém súborov: Povolené
Archívy: Povolené
Rootkity: Zakázané
Heuristika: Povolené
PUP: Zistiť
PUM: Zistiť

-Podrobnosti skenovania-
Proces: 0
(Nezistili sa nijaké škodlivé položky)

Modul: 0
(Nezistili sa nijaké škodlivé položky)

Kľúč databázy Registry: 3
PUP.Optional.ASK, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2FA28606-DE77-4029-AF96-B231E3B8F827}, Bez zásahu používateľa, 1, 184156, , , ,
PUP.Optional.ASK, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2FA28606-DE77-4029-AF96-B231E3B8F827}, Bez zásahu používateľa, 1, 184156, , , ,
PUP.Optional.ASK, HKU\S-1-5-21-1868968748-2318614808-2451380565-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}, Bez zásahu používateľa, 1, 184156, 1.0.18364, , ame,

Hodnota databázy Registry: 3
PUP.Optional.ASK, HKU\S-1-5-21-1868968748-2318614808-2451380565-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}|URL, Bez zásahu používateľa, 1, 184156, 1.0.18364, , ame,
PUP.Optional.ASK, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}|URL, Bez zásahu používateľa, 1, 184157, 1.0.18364, , ame,
PUP.Optional.ASK, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}|URL, Bez zásahu používateľa, 1, 184157, 1.0.18364, , ame,

Údaje databázy Registry: 0
(Nezistili sa nijaké škodlivé položky)

Prúd údajov: 0
(Nezistili sa nijaké škodlivé položky)

Priečinok: 0
(Nezistili sa nijaké škodlivé položky)

Súbor: 1
PUP.Optional.BundleInstaller, C:\USERS\ALEX\DOWNLOADS\ZODIAC.EXE, Bez zásahu používateľa, 498, 309975, 1.0.18364, , ame,

Fyzický sektor: 0
(Nezistili sa nijaké škodlivé položky)

WMI: 0
(Nezistili sa nijaké škodlivé položky)


(end)

Uživatelský avatar
Orcus
člen Security týmu
Elite Level 10.5
Elite Level 10.5
Příspěvky: 10643
Registrován: duben 10
Bydliště: Okolo rostou 3 růže =o)
Pohlaví: Muž

Re: prosím o kontrolu

Příspěvekod Orcus » 29 led 2020 10:17

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Skenování“ , po prohledání klikni na „ Čištění

Program provede opravu, po automatickém restartu klikni na „Log soubor“ a pak poklepej na odpovídají log, (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
https://downloads.malwarebytes.com/file/JRT-EOL
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dloho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.



. spusť znovu Malwarebytes' Anti-Malware a dej Skenovat nyní
- po proběhnutí programu se ti objeví hláška tak klikni na „Vše do karantény(smazat vybrané)“ a na „Exportovat záznam“ a vyber „textový soubor“ , soubor nějak pojmenuj a někam ho ulož. Zkopíruj se celý obsah toho logu.

Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
http://www.majorgeeks.com/files/details ... _tool.html
http://www.majorgeeks.com/mg/get/sophos ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html

Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Pokud byly nalezeny viry , tak po skenu klikni na „Details…“ a potom na „View log file“. Zkopíruj celý log a vlož ho sem. Potom zavři „threat detail“ a klikni na „Start cleanup“.
Jinak se log nachází zde:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.adlice.com/download/roguekil ... HlwZT14ODY
64bit.:
http://www.adlice.com/download/roguekil ... HlwZT14NjQ
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků

další odkazy:
http://www.adlice.com/download/roguekiller/
http://www.bleepingcomputer.com/download/roguekiller/
Láska hřeje, ale uhlí je uhlí. :fire:



Log z HJT vkládejte do HJT sekce. Je-li moc dlouhý, rozděl jej do více zpráv.

Pár rad k bezpečnosti PC.

Po dobu mé nepřítomnosti mě zastupuje memphisto, jaro3 a Diallix

Pokud budete spokojeni , můžete podpořit naše fórum.

cosopt
nováček
Příspěvky: 12
Registrován: leden 20
Pohlaví: Nespecifikováno

Re: prosím o kontrolu

Příspěvekod cosopt » 29 led 2020 10:54

# -------------------------------
# Malwarebytes AdwCleaner 8.0.1.0
# -------------------------------
# Build: 12-17-2019
# Database: 2020-01-24.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 01-29-2020
# Duration: 00:00:36
# OS: Windows 10 Home
# Cleaned: 29
# Failed: 1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Program Files (x86)\ShowMyPCService

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Preinstalled Software ] *****

Deleted Preinstalled.HPHealthCheck Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6F340107-F9AA-47C6-B54C-C3A19F11553F}
Deleted Preinstalled.HPLaunchBox Folder C:\Program Files\HEWLETT-PACKARD\HP LAUNCHBOX
Deleted Preinstalled.HPLaunchBox Registry HKLM\Software\Microsoft\Shared Tools\MSConfig\startupreg\SetDefault
Deleted Preinstalled.HPLaunchBox Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{5A847522-375C-4D05-BD3D-88C450CC047F}
Deleted Preinstalled.HPMediaSmart Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B30AC4F3-1736-4A47-8687-109194FA2BC4}
Deleted Preinstalled.HPMediaSmart Registry HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MirageAgent
Deleted Preinstalled.HPMediaSmart Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}
Deleted Preinstalled.HPMediaSmart Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{01FB4998-33C4-4431-85ED-079E3EEFE75D}
Deleted Preinstalled.HPMediaSmart Task C:\Windows\System32\Tasks\MIRAGEAGENT
Deleted Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP CUSTOMER FEEDBACK
Deleted Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Folder C:\ProgramData\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Folder C:\Users\alex\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Folder C:\Users\alex\AppData\Roaming\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Folder C:\Windows\System32\config\systemprofile\AppData\Local\HEWLETT-PACKARD\HP SUPPORT FRAMEWORK
Deleted Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Classes\CLSID\{335F9A62-FE4B-40CD-B4ED-BB4DE21DC95D}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{335F9A62-FE4B-40CD-B4ED-BB4DE21DC95D}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{C0ABBA07-B636-47B8-B9E1-BB96D7CD4831}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Classes\CLSID\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}
Deleted Preinstalled.HPSupportAssistant Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}
Deleted Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGDF-hp-mahjonggdarkdimensions
Deleted Preinstalled.WildTangentGamesBundle Registry HKLM\Software\Wow6432Node\\Microsoft\Windows\CurrentVersion\Uninstall\WildTangentGameProvider-hp-genres
Not Deleted Preinstalled.HPSupportAssistant Folder C:\Program Files (x86)\HEWLETT-PACKARD\HP SUPPORT SOLUTIONS


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [5170 octets] - [29/01/2020 09:22:10]
AdwCleaner[S01].txt - [5231 octets] - [29/01/2020 10:43:32]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by alex (Administrator) on st 29. 01. 2020 at 10:59:43,48
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


File System: 12

Successfully deleted: C:\ProgramData\drivergenius (Folder)
Successfully deleted: C:\ProgramData\Start Menu\Programs\driver genius (Folder)
Successfully deleted: C:\Users\alex\AppData\Local\{2625EDA6-72A4-409F-A69B-7B53DDD86413} (Empty Folder)
Successfully deleted: C:\Users\alex\AppData\Local\{5B442C6E-4B23-4CA0-9A4B-96C9F0A17B88} (Empty Folder)
Successfully deleted: C:\Users\alex\AppData\Local\{6DEE05FA-BF6A-4538-9477-A1A332540F2A} (Empty Folder)
Successfully deleted: C:\Users\alex\AppData\Local\{CEC44973-5841-426F-A7F1-22B79763AE70} (Empty Folder)
Successfully deleted: C:\Users\alex\AppData\Local\{EBABAA3A-56CE-4E0E-8014-2303E9385908} (Empty Folder)
Successfully deleted: C:\Users\alex\AppData\Local\{F2D80594-8225-4AF9-8AFC-B133DC4EDA74} (Empty Folder)
Successfully deleted: C:\Users\alex\AppData\Roaming\driver-soft (Folder)
Successfully deleted: C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\xfna1feo.default\extensions\staged (Folder)
Successfully deleted: C:\Users\alex\Desktop\driver genius.lnk (Shortcut)
Successfully deleted: C:\Program Files (x86)\driver-soft (Folder)



Registry: 2

Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 29. 01. 2020 at 11:05:18,73
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~





Malwarebytes
http://www.malwarebytes.com

-Podrobnosti denníka-
Dátum skenovania: 29. 1. 2020
Čas skenovania: 11:09
Súbor denníka: 689bd406-427f-11ea-a205-a0b3cccd21de.json

-Údaje o softvéri-
Verzia: 4.0.4.49
Verzia súčastí: 1.0.810
Aktualizovať verziu balíka: 1.0.18366
Licencia: Zadarmo

-Systémové informácie-
OS: Windows 10 (Build 18362.592)
Procesor: x64
Systém súborov: NTFS
Používateľ: ALEX-HP\alex

-Zhrnutie skenovania-
Typ skenovania: Vyhľadávanie hrozieb
Skenovanie bolo spustené: Manuálne
Výsledok: Dokončené
Preskenované objekty: 342302
Zistené hrozby: 3
Hrozby umiestnené do karantény: 3
Uplynulý čas: 8 min, 8 s

-Možnosti skenovania-
Pamäť: Povolené
Spúšťanie: Povolené
Systém súborov: Povolené
Archívy: Povolené
Rootkity: Zakázané
Heuristika: Povolené
PUP: Zistiť
PUM: Zistiť

-Podrobnosti skenovania-
Proces: 0
(Nezistili sa nijaké škodlivé položky)

Modul: 0
(Nezistili sa nijaké škodlivé položky)

Kľúč databázy Registry: 1
PUP.Optional.ASK, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}, Umiestené do karantény, 1, 184157, 1.0.18366, , ame,

Hodnota databázy Registry: 1
PUP.Optional.ASK, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2fa28606-de77-4029-af96-b231e3b8f827}|URL, Umiestené do karantény, 1, 184157, 1.0.18366, , ame,

Údaje databázy Registry: 0
(Nezistili sa nijaké škodlivé položky)

Prúd údajov: 0
(Nezistili sa nijaké škodlivé položky)

Priečinok: 0
(Nezistili sa nijaké škodlivé položky)

Súbor: 1
PUP.Optional.BundleInstaller, C:\USERS\ALEX\DOWNLOADS\ZODIAC.EXE, Umiestené do karantény, 498, 309975, 1.0.18366, , ame,

Fyzický sektor: 0
(Nezistili sa nijaké škodlivé položky)

WMI: 0
(Nezistili sa nijaké škodlivé položky)

(end)


ďalšie logy dám zajtra.Sophosu to dlho trvá a ja musím ísť do práce.

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40449
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: prosím o kontrolu

Příspěvekod jaro3 » 29 led 2020 18:56

OK.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

cosopt
nováček
Příspěvky: 12
Registrován: leden 20
Pohlaví: Nespecifikováno

Re: prosím o kontrolu

Příspěvekod cosopt » 30 led 2020 09:09

Sophos nič nenašiel.

RogueKiller Anti-Malware V14.1.1.0 (x64) [Jan 28 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.18362) 64 bits
Started in : Normal mode
User : alex [Administrator]
Started from : C:\Users\alex\Desktop\RogueKiller_portable64.exe
Signatures : 20200129_130308, Driver : Loaded
Mode : Standard Scan, Scan -- Date : 2020/01/30 08:14:30 (Duration : 00:50:43)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Process Modules ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.HackTool (Potentially Malicious)] WinDivert1.1 (0) -- (Nemea Mjukvaruutveckling AB) \??\C:\Program Files\KMSpico\WinDivert.sys -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Tasks ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.HackTool (Potentially Malicious)] \AutoPico Daily Restart -- "C:\Program Files\KMSpico\AutoPico.exe" [/silent] -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
>>>>>> XX - Uninstall
[PUP.HackTool (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\KMSpico_is1 -- N/A -> Found
>>>>>> O23 - Services
[PUP.HackTool (Potentially Malicious)] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinDivert1.1 -- (Nemea Mjukvaruutveckling AB) "C:\Program Files\KMSpico\WinDivert.sys" -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ WMI ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Hosts File ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Files ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.HackTool (Potentially Malicious)] (folder) KMSpico -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico -> Found
[PUP.HackTool (Potentially Malicious)] (folder) KMSpico -- C:\Program Files\KMSpico -> Found

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Web browsers ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40449
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: prosím o kontrolu

Příspěvekod jaro3 » 30 led 2020 17:54

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.

Vypni antivir i firewall.
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.

Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Můžeš si zatrhnout i vytvoření bodu obnovy:
Klikni na ozubené kolečko , poté na „Skenování“ a zatrhni „vytvářet body obnovy“.
Vrať se zpět ( klikni na domeček).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Další“. Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, objeví se tisková zpráva , zkopíruj sem celý obsah té zprávy.
Jinak můžeš zprávy vidět , když klikneš vpravo nahoře na „ zprávy“.


Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

cosopt
nováček
Příspěvky: 12
Registrován: leden 20
Pohlaví: Nespecifikováno

Re: prosím o kontrolu

Příspěvekod cosopt » 31 led 2020 09:42

RogueKiller Anti-Malware V14.1.1.0 (x64) [Jan 28 2020] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.18362) 64 bits
Started in : Normal mode
User : alex [Administrator]
Started from : C:\Users\alex\Desktop\RogueKiller_portable64.exe
Signatures : 20200130_104439, Driver : Loaded
Mode : Standard Scan, Delete -- Date : 2020/01/31 06:53:29 (Duration : 00:50:26)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUP.HackTool (Potentially Malicious)] WinDivert1.1 [Nemea Mjukvaruutveckling AB] -- %ProgramFiles%\KMSpico\WinDivert.sys -> Stopped
[PUP.HackTool (Potentially Malicious)] \AutoPico Daily Restart -- "C:\Program Files\KMSpico\AutoPico.exe" (/silent) -> Deleted
[PUP.HackTool (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\KMSpico_is1 -- -> Deleted
[PUP.HackTool (Potentially Malicious)] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinDivert1.1 -- [%ProgramFiles%\KMSpico\WinDivert.sys] -> Deleted
[PUP.HackTool (Potentially Malicious)] KMSpico -- %programdata%\Microsoft\Windows\Start Menu\Programs\KMSpico -> Deleted
=> Log KMSpico.lnk -- C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\KMSpico\LOGKMS~1.LNK [1]
=> Uninstall KMSpico.lnk -- C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\KMSpico\UNINST~1.LNK [1]
[PUP.HackTool (Potentially Malicious)] KMSpico -- %ProgramFiles%\KMSpico -> Deleted
=> installAll.cmd -- C:\PROGRA~1\KMSpico\cert\INSTAL~1.CMD [1]
=> AccessVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACCESS~1.REG [1]
=> AccessVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACCESS~2.REG [1]
=> AccessVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACCESS~3.REG [1]
=> Access_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACCESS~1.XRM [1]
=> Access_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACCESS~2.XRM [1]
=> Access_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACCESS~3.XRM [1]
=> Access_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACCESS~4.XRM [1]
=> Access_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACFE37~1.XRM [1]
=> Access_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\AC79B1~1.XRM [1]
=> Access_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACC7AC~1.XRM [1]
=> Access_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACAEA9~1.XRM [1]
=> Access_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access\ACB507~1.XRM [1]
=> Access -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Access [1]
=> ExcelVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EXCELV~1.REG [1]
=> ExcelVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EXCELV~2.REG [1]
=> ExcelVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EXCELV~3.REG [1]
=> Excel_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EXCEL_~1.XRM [1]
=> Excel_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EXCEL_~2.XRM [1]
=> Excel_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EXCEL_~3.XRM [1]
=> Excel_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EXCEL_~4.XRM [1]
=> Excel_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EX2451~1.XRM [1]
=> Excel_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EX1308~1.XRM [1]
=> Excel_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EX6AA9~1.XRM [1]
=> Excel_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EX6C27~1.XRM [1]
=> Excel_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel\EXFAB0~1.XRM [1]
=> Excel -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Excel [1]
=> GrooveVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GROOVE~1.REG [1]
=> GrooveVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GROOVE~2.REG [1]
=> GrooveVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GROOVE~3.REG [1]
=> Groove_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GROOVE~1.XRM [1]
=> Groove_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GROOVE~2.XRM [1]
=> Groove_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GROOVE~3.XRM [1]
=> Groove_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GROOVE~4.XRM [1]
=> Groove_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GR6021~1.XRM [1]
=> Groove_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GR343F~1.XRM [1]
=> Groove_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GR822A~1.XRM [1]
=> Groove_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GREA7B~1.XRM [1]
=> Groove_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove\GR7DBF~1.XRM [1]
=> Groove -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Groove [1]
=> InfoPathVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\INFOPA~1.REG [1]
=> InfoPathVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\INFOPA~2.REG [1]
=> InfoPathVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\INFOPA~3.REG [1]
=> InfoPath_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\INFOPA~1.XRM [1]
=> InfoPath_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\INFOPA~2.XRM [1]
=> InfoPath_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\INFOPA~3.XRM [1]
=> InfoPath_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\INFOPA~4.XRM [1]
=> InfoPath_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\IN1165~1.XRM [1]
=> InfoPath_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\INB8A9~1.XRM [1]
=> InfoPath_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\IN546B~1.XRM [1]
=> InfoPath_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\IN5111~1.XRM [1]
=> InfoPath_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath\IN9DFD~1.XRM [1]
=> InfoPath -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\InfoPath [1]
=> OneNoteVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ONENOT~1.REG [1]
=> OneNoteVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ONENOT~2.REG [1]
=> OneNoteVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ONENOT~3.REG [1]
=> OneNote_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ONENOT~1.XRM [1]
=> OneNote_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ONENOT~2.XRM [1]
=> OneNote_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ONENOT~3.XRM [1]
=> OneNote_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ONENOT~4.XRM [1]
=> OneNote_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ON1933~1.XRM [1]
=> OneNote_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ON4519~1.XRM [1]
=> OneNote_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ONEC98~1.XRM [1]
=> OneNote_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ON411A~1.XRM [1]
=> OneNote_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote\ON0848~1.XRM [1]
=> OneNote -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\OneNote [1]
=> OutlookVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OUTLOO~1.REG [1]
=> OutlookVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OUTLOO~2.REG [1]
=> OutlookVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OUTLOO~3.REG [1]
=> Outlook_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OUTLOO~1.XRM [1]
=> Outlook_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OUTLOO~2.XRM [1]
=> Outlook_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OUTLOO~3.XRM [1]
=> Outlook_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OUTLOO~4.XRM [1]
=> Outlook_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OU2A27~1.XRM [1]
=> Outlook_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OU1196~1.XRM [1]
=> Outlook_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OUC2AB~1.XRM [1]
=> Outlook_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OU3D3C~1.XRM [1]
=> Outlook_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook\OU1BD5~1.XRM [1]
=> Outlook -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Outlook [1]
=> PowerPointVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POWERP~1.REG [1]
=> PowerPointVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POWERP~2.REG [1]
=> PowerPointVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POWERP~3.REG [1]
=> PowerPoint_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POWERP~1.XRM [1]
=> PowerPoint_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POWERP~2.XRM [1]
=> PowerPoint_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POWERP~3.XRM [1]
=> PowerPoint_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POWERP~4.XRM [1]
=> PowerPoint_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POC4CE~1.XRM [1]
=> PowerPoint_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\POCF5A~1.XRM [1]
=> PowerPoint_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\PO4DAA~1.XRM [1]
=> PowerPoint_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\PO7B37~1.XRM [1]
=> PowerPoint_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1\PO49CC~1.XRM [1]
=> PowerPoint -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\POWERP~1 [1]
=> ProjectProVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PROJEC~1.REG [1]
=> ProjectProVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PROJEC~2.REG [1]
=> ProjectProVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PROJEC~3.REG [1]
=> ProjectPro_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PROJEC~1.XRM [1]
=> ProjectPro_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PROJEC~2.XRM [1]
=> ProjectPro_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PROJEC~3.XRM [1]
=> ProjectPro_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PROJEC~4.XRM [1]
=> ProjectPro_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PRA5D8~1.XRM [1]
=> ProjectPro_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PRCA3E~1.XRM [1]
=> ProjectPro_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PRB273~1.XRM [1]
=> ProjectPro_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PRD06C~1.XRM [1]
=> ProjectPro_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1\PR972B~1.XRM [1]
=> ProjectPro -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~1 [1]
=> ProjectStdVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PROJEC~1.REG [1]
=> ProjectStdVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PROJEC~2.REG [1]
=> ProjectStdVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PROJEC~3.REG [1]
=> ProjectStd_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PROJEC~1.XRM [1]
=> ProjectStd_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PROJEC~2.XRM [1]
=> ProjectStd_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PROJEC~3.XRM [1]
=> ProjectStd_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PROJEC~4.XRM [1]
=> ProjectStd_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PRAB27~1.XRM [1]
=> ProjectStd_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PR676A~1.XRM [1]
=> ProjectStd_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PR197F~1.XRM [1]
=> ProjectStd_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PR7669~1.XRM [1]
=> ProjectStd_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PR2E61~1.XRM [1]
=> ProjectStd_MAK2.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PR96DE~1.XRM [1]
=> ProjectStd_MAK2.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PRE6D2~1.XRM [1]
=> ProjectStd_MAK2.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PR95D6~1.XRM [1]
=> ProjectStd_MAK2.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2\PR5451~1.XRM [1]
=> ProjectStd -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PROJEC~2 [1]
=> ProPlusAcad_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PROPLU~1.XRM [1]
=> ProPlusAcad_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PROPLU~2.XRM [1]
=> ProPlusAcad_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PROPLU~3.XRM [1]
=> ProPlusAcad_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PROPLU~4.XRM [1]
=> ProPlusVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PROPLU~1.REG [1]
=> ProPlusVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PROPLU~2.REG [1]
=> ProPlusVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PROPLU~3.REG [1]
=> ProPlus_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PR2040~1.XRM [1]
=> ProPlus_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PR5CF9~1.XRM [1]
=> ProPlus_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PR036D~1.XRM [1]
=> ProPlus_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PRB100~1.XRM [1]
=> ProPlus_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PRC183~1.XRM [1]
=> ProPlus_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PRE40D~1.XRM [1]
=> ProPlus_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PR2808~1.XRM [1]
=> ProPlus_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PRFDC4~1.XRM [1]
=> ProPlus_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus\PR5693~1.XRM [1]
=> ProPlus -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\ProPlus [1]
=> PublisherVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUBLIS~1.REG [1]
=> PublisherVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUBLIS~2.REG [1]
=> PublisherVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUBLIS~3.REG [1]
=> Publisher_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUBLIS~1.XRM [1]
=> Publisher_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUBLIS~2.XRM [1]
=> Publisher_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUBLIS~3.XRM [1]
=> Publisher_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUBLIS~4.XRM [1]
=> Publisher_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUF56D~1.XRM [1]
=> Publisher_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PU6D45~1.XRM [1]
=> Publisher_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PU106C~1.XRM [1]
=> Publisher_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUE475~1.XRM [1]
=> Publisher_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1\PUBB5B~1.XRM [1]
=> Publisher -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\PUBLIS~1 [1]
=> SmallBusBasicsVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SMALLB~1.REG [1]
=> SmallBusBasicsVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SMALLB~2.REG [1]
=> SmallBusBasicsVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SMALLB~3.REG [1]
=> SmallBusBasics_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SMALLB~1.XRM [1]
=> SmallBusBasics_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SMALLB~2.XRM [1]
=> SmallBusBasics_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SMALLB~3.XRM [1]
=> SmallBusBasics_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SMALLB~4.XRM [1]
=> SmallBusBasics_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SMD564~1.XRM [1]
=> SmallBusBasics_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SM861A~1.XRM [1]
=> SmallBusBasics_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SM382F~1.XRM [1]
=> SmallBusBasics_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SM8FB7~1.XRM [1]
=> SmallBusBasics_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1\SM5C92~1.XRM [1]
=> SmallBusBasics -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\SMALLB~1 [1]
=> StandardAcad_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STANDA~1.XRM [1]
=> StandardAcad_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STANDA~2.XRM [1]
=> StandardAcad_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STANDA~3.XRM [1]
=> StandardAcad_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STANDA~4.XRM [1]
=> StandardVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STANDA~1.REG [1]
=> StandardVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STANDA~2.REG [1]
=> StandardVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STANDA~3.REG [1]
=> Standard_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\ST87DC~1.XRM [1]
=> Standard_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STDDAA~1.XRM [1]
=> Standard_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\ST1611~1.XRM [1]
=> Standard_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STFA12~1.XRM [1]
=> Standard_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STECED~1.XRM [1]
=> Standard_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\STDA03~1.XRM [1]
=> Standard_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\ST8C18~1.XRM [1]
=> Standard_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\ST29AC~1.XRM [1]
=> Standard_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard\ST651F~1.XRM [1]
=> Standard -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Standard [1]
=> VisioPrem_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOP~1.XRM [1]
=> VisioPrem_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOP~2.XRM [1]
=> VisioPrem_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOP~3.XRM [1]
=> VisioPrem_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOP~4.XRM [1]
=> VisioPrem_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI096A~1.XRM [1]
=> VisioPrem_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI03A0~1.XRM [1]
=> VisioPrem_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI0A64~1.XRM [1]
=> VisioPrem_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI8865~1.XRM [1]
=> VisioPrem_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VIF6F4~1.XRM [1]
=> VisioPro_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI36AB~1.XRM [1]
=> VisioPro_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI26F5~1.XRM [1]
=> VisioPro_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI5845~1.XRM [1]
=> VisioPro_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI9B63~1.XRM [1]
=> VisioPro_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI0942~1.XRM [1]
=> VisioPro_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI7954~1.XRM [1]
=> VisioPro_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI2B69~1.XRM [1]
=> VisioPro_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VIE31D~1.XRM [1]
=> VisioPro_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VIF5BD~1.XRM [1]
=> VisioStd_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOS~1.XRM [1]
=> VisioStd_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOS~2.XRM [1]
=> VisioStd_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOS~3.XRM [1]
=> VisioStd_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOS~4.XRM [1]
=> VisioStd_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI9B28~1.XRM [1]
=> VisioStd_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VIF97F~1.XRM [1]
=> VisioStd_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI3832~1.XRM [1]
=> VisioStd_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VI63B8~1.XRM [1]
=> VisioStd_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VIF3A8~1.XRM [1]
=> VisioVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOV~1.REG [1]
=> VisioVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOV~2.REG [1]
=> VisioVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio\VISIOV~3.REG [1]
=> Visio -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Visio [1]
=> WordVLReg32.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORDVL~1.REG [1]
=> WordVLReg64.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORDVL~2.REG [1]
=> WordVLRegWOW.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORDVL~3.REG [1]
=> Word_KMS_Client.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORD_K~1.XRM [1]
=> Word_KMS_Client.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORD_K~2.XRM [1]
=> Word_KMS_Client.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORD_K~3.XRM [1]
=> Word_KMS_Client.RAC_Priv.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORD_K~4.XRM [1]
=> Word_KMS_Client.RAC_Pub.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WO0FDB~1.XRM [1]
=> Word_MAK.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORD_M~1.XRM [1]
=> Word_MAK.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORD_M~2.XRM [1]
=> Word_MAK.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORD_M~3.XRM [1]
=> Word_MAK.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word\WORD_M~4.XRM [1]
=> Word -- C:\PROGRA~1\KMSpico\cert\KMSCER~1\Word [1]
=> kmscert2010 -- C:\PROGRA~1\KMSpico\cert\KMSCER~1 [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LI6333~1.XRM [1]
=> LicenseSetData._4374022D_56B8_48C1_9BB7_D8F2FC726343.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LIC198~1.XRM [1]
=> LicenseSetData._4374022D_56B8_48C1_9BB7_D8F2FC726343.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LI4B7C~1.XRM [1]
=> LicenseSetData._4374022D_56B8_48C1_9BB7_D8F2FC726343.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LIB9B1~1.XRM [1]
=> LicenseSetData._4374022D_56B8_48C1_9BB7_D8F2FC726343.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LIEBCE~1.XRM [1]
=> LicenseSetData._6EE7622C_18D8_4005_9FB7_92DB644A279B.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LI8ADC~1.XRM [1]
=> LicenseSetData._6EE7622C_18D8_4005_9FB7_92DB644A279B.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LI82EB~1.XRM [1]
=> LicenseSetData._6EE7622C_18D8_4005_9FB7_92DB644A279B.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access\LI5F8F~1.XRM [1]
=> Access -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Access [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LI6333~1.XRM [1]
=> LicenseSetData._AC1AE7FD_B949_4E04_A330_849BC40638CF.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LIEFFB~1.XRM [1]
=> LicenseSetData._AC1AE7FD_B949_4E04_A330_849BC40638CF.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LI42B5~1.XRM [1]
=> LicenseSetData._AC1AE7FD_B949_4E04_A330_849BC40638CF.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LIFED4~1.XRM [1]
=> LicenseSetData._AC1AE7FD_B949_4E04_A330_849BC40638CF.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LI43B0~1.XRM [1]
=> LicenseSetData._F7461D52_7C2B_43B2_8744_EA958E0BD09A.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LI3B09~1.XRM [1]
=> LicenseSetData._F7461D52_7C2B_43B2_8744_EA958E0BD09A.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LIE91A~2.XRM [1]
=> LicenseSetData._F7461D52_7C2B_43B2_8744_EA958E0BD09A.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel\LIA66F~1.XRM [1]
=> Excel -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Excel [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LI6333~1.XRM [1]
=> LicenseSetData._9E016989_4007_42A6_8051_64EB97110CF2.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LI366F~1.XRM [1]
=> LicenseSetData._9E016989_4007_42A6_8051_64EB97110CF2.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LID6A5~1.XRM [1]
=> LicenseSetData._9E016989_4007_42A6_8051_64EB97110CF2.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LI3F51~1.XRM [1]
=> LicenseSetData._9E016989_4007_42A6_8051_64EB97110CF2.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LI8682~1.XRM [1]
=> LicenseSetData._A30B8040_D68A_423F_B0B5_9CE292EA5A8F.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LI4109~1.XRM [1]
=> LicenseSetData._A30B8040_D68A_423F_B0B5_9CE292EA5A8F.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LI8E36~1.XRM [1]
=> LicenseSetData._A30B8040_D68A_423F_B0B5_9CE292EA5A8F.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath\LIC4B5~1.XRM [1]
=> InfoPath -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\InfoPath [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LI6333~1.XRM [1]
=> LicenseSetData._1B9F11E3_C85C_4E1B_BB29_879AD2C909E3.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LI066F~1.XRM [1]
=> LicenseSetData._1B9F11E3_C85C_4E1B_BB29_879AD2C909E3.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LI9662~1.XRM [1]
=> LicenseSetData._1B9F11E3_C85C_4E1B_BB29_879AD2C909E3.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LI4E52~1.XRM [1]
=> LicenseSetData._E1264E10_AFAF_4439_A98B_256DF8BB156F.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LI8735~1.XRM [1]
=> LicenseSetData._E1264E10_AFAF_4439_A98B_256DF8BB156F.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LI3ADF~1.XRM [1]
=> LicenseSetData._E1264E10_AFAF_4439_A98B_256DF8BB156F.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LI6D25~1.XRM [1]
=> LicenseSetData._E1264E10_AFAF_4439_A98B_256DF8BB156F.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync\LI1636~1.XRM [1]
=> Lync -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Lync [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LI6333~1.XRM [1]
=> LicenseSetData._B067E965_7521_455B_B9F7_C740204578A2.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LI1158~1.XRM [1]
=> LicenseSetData._B067E965_7521_455B_B9F7_C740204578A2.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LI3020~1.XRM [1]
=> LicenseSetData._B067E965_7521_455B_B9F7_C740204578A2.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LI180C~1.XRM [1]
=> LicenseSetData._B067E965_7521_455B_B9F7_C740204578A2.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LIC45D~1.XRM [1]
=> LicenseSetData._EFE1F3E6_AEA2_4144_A208_32AA872B6545.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LI8197~1.XRM [1]
=> LicenseSetData._EFE1F3E6_AEA2_4144_A208_32AA872B6545.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LI2AAA~1.XRM [1]
=> LicenseSetData._EFE1F3E6_AEA2_4144_A208_32AA872B6545.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote\LIBC26~1.XRM [1]
=> OneNote -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\OneNote [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LI6333~1.XRM [1]
=> LicenseSetData._771C3AFA_50C5_443F_B151_FF2546D863A0.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LI22BA~1.XRM [1]
=> LicenseSetData._771C3AFA_50C5_443F_B151_FF2546D863A0.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LIE562~1.XRM [1]
=> LicenseSetData._771C3AFA_50C5_443F_B151_FF2546D863A0.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LI9664~1.XRM [1]
=> LicenseSetData._8D577C50_AE5E_47FD_A240_24986F73D503.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LI65BE~1.XRM [1]
=> LicenseSetData._8D577C50_AE5E_47FD_A240_24986F73D503.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LICCF2~1.XRM [1]
=> LicenseSetData._8D577C50_AE5E_47FD_A240_24986F73D503.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LIE6AA~1.XRM [1]
=> LicenseSetData._8D577C50_AE5E_47FD_A240_24986F73D503.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook\LIFB37~1.XRM [1]
=> Outlook -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Outlook [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LI6333~1.XRM [1]
=> LicenseSetData._8C762649_97D1_4953_AD27_B7E2C25B972E.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LI35A8~1.XRM [1]
=> LicenseSetData._8C762649_97D1_4953_AD27_B7E2C25B972E.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LIB144~1.XRM [1]
=> LicenseSetData._8C762649_97D1_4953_AD27_B7E2C25B972E.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LIB47B~1.XRM [1]
=> LicenseSetData._E40DCB44_1D5C_4085_8E8F_943F33C4F004.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LI30F0~1.XRM [1]
=> LicenseSetData._E40DCB44_1D5C_4085_8E8F_943F33C4F004.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LIDC14~1.XRM [1]
=> LicenseSetData._E40DCB44_1D5C_4085_8E8F_943F33C4F004.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LI78B0~1.XRM [1]
=> LicenseSetData._E40DCB44_1D5C_4085_8E8F_943F33C4F004.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1\LIA5B5~1.XRM [1]
=> PowerPoint -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\POWERP~1 [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LI6333~1.XRM [1]
=> LicenseSetData._4A5D124A_E620_44BA_B6FF_658961B33B9A.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LIE203~1.XRM [1]
=> LicenseSetData._4A5D124A_E620_44BA_B6FF_658961B33B9A.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LIA127~1.XRM [1]
=> LicenseSetData._4A5D124A_E620_44BA_B6FF_658961B33B9A.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LIFAF9~1.XRM [1]
=> LicenseSetData._ED34DC89_1C27_4ECD_8B2F_63D0F4CEDC32.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LI9089~1.XRM [1]
=> LicenseSetData._ED34DC89_1C27_4ECD_8B2F_63D0F4CEDC32.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LI219B~1.XRM [1]
=> LicenseSetData._ED34DC89_1C27_4ECD_8B2F_63D0F4CEDC32.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LI0248~1.XRM [1]
=> LicenseSetData._ED34DC89_1C27_4ECD_8B2F_63D0F4CEDC32.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1\LI43D9~1.XRM [1]
=> ProjectPro -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~1 [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LI6333~1.XRM [1]
=> LicenseSetData._2B9E4A37_6230_4B42_BEE2_E25CE86C8C7A.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LIC1F4~1.XRM [1]
=> LicenseSetData._2B9E4A37_6230_4B42_BEE2_E25CE86C8C7A.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LIFF10~1.XRM [1]
=> LicenseSetData._2B9E4A37_6230_4B42_BEE2_E25CE86C8C7A.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LI53F2~1.XRM [1]
=> LicenseSetData._2B9E4A37_6230_4B42_BEE2_E25CE86C8C7A.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LI1287~1.XRM [1]
=> LicenseSetData._427A28D1_D17C_4ABF_B717_32C780BA6F07.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LI60CA~1.XRM [1]
=> LicenseSetData._427A28D1_D17C_4ABF_B717_32C780BA6F07.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LI08F9~1.XRM [1]
=> LicenseSetData._427A28D1_D17C_4ABF_B717_32C780BA6F07.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2\LI635B~1.XRM [1]
=> ProjectStd -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PROJEC~2 [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LI6333~1.XRM [1]
=> LicenseSetData._2B88C4F2_EA8F_43CD_805E_4D41346E18A7.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LI5833~1.XRM [1]
=> LicenseSetData._2B88C4F2_EA8F_43CD_805E_4D41346E18A7.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LI0A48~1.XRM [1]
=> LicenseSetData._2B88C4F2_EA8F_43CD_805E_4D41346E18A7.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LI86DE~1.XRM [1]
=> LicenseSetData._2B88C4F2_EA8F_43CD_805E_4D41346E18A7.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LIECD9~1.XRM [1]
=> LicenseSetData._B322DA9C_A2E2_4058_9E4E_F59A6970BD69.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LI7A30~1.XRM [1]
=> LicenseSetData._B322DA9C_A2E2_4058_9E4E_F59A6970BD69.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LIF3FF~1.XRM [1]
=> LicenseSetData._B322DA9C_A2E2_4058_9E4E_F59A6970BD69.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\LI8B16~1.XRM [1]
=> proplus.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus\proplus.reg [1]
=> ProPlus -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\ProPlus [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LI6333~1.XRM [1]
=> LicenseSetData._00C79FF1_6850_443D_BF61_71CDE0DE305F.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LI2B91~1.XRM [1]
=> LicenseSetData._00C79FF1_6850_443D_BF61_71CDE0DE305F.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LIAF39~1.XRM [1]
=> LicenseSetData._00C79FF1_6850_443D_BF61_71CDE0DE305F.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LIEADB~1.XRM [1]
=> LicenseSetData._38EA49F6_AD1D_43F1_9888_99A35D7C9409.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LI8CE5~1.XRM [1]
=> LicenseSetData._38EA49F6_AD1D_43F1_9888_99A35D7C9409.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LI352F~1.XRM [1]
=> LicenseSetData._38EA49F6_AD1D_43F1_9888_99A35D7C9409.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LI1818~1.XRM [1]
=> LicenseSetData._38EA49F6_AD1D_43F1_9888_99A35D7C9409.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1\LI4A52~1.XRM [1]
=> Publisher -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\PUBLIS~1 [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LI6333~1.XRM [1]
=> LicenseSetData._A24CCA51_3D54_4C41_8A76_4031F5338CB2.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LI8629~1.XRM [1]
=> LicenseSetData._A24CCA51_3D54_4C41_8A76_4031F5338CB2.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LI3BEB~1.XRM [1]
=> LicenseSetData._A24CCA51_3D54_4C41_8A76_4031F5338CB2.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LI19DA~1.XRM [1]
=> LicenseSetData._A24CCA51_3D54_4C41_8A76_4031F5338CB2.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LIDBC0~1.XRM [1]
=> LicenseSetData._B13AFB38_CD79_4AE5_9F7F_EED058D750CA.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LID889~1.XRM [1]
=> LicenseSetData._B13AFB38_CD79_4AE5_9F7F_EED058D750CA.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LI7099~1.XRM [1]
=> LicenseSetData._B13AFB38_CD79_4AE5_9F7F_EED058D750CA.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard\LIDB7C~1.XRM [1]
=> Standard -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Standard [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LI6333~1.XRM [1]
=> LicenseSetData._3E4294DD_A765_49BC_8DBD_CF8B62A4BD3D.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LIC999~1.XRM [1]
=> LicenseSetData._3E4294DD_A765_49BC_8DBD_CF8B62A4BD3D.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LI87DE~1.XRM [1]
=> LicenseSetData._3E4294DD_A765_49BC_8DBD_CF8B62A4BD3D.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LI2802~1.XRM [1]
=> LicenseSetData._3E4294DD_A765_49BC_8DBD_CF8B62A4BD3D.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LID422~1.XRM [1]
=> LicenseSetData._E13AC10E_75D0_4AFF_A0CD_764982CF541C.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LI13A0~1.XRM [1]
=> LicenseSetData._E13AC10E_75D0_4AFF_A0CD_764982CF541C.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LI882C~1.XRM [1]
=> LicenseSetData._E13AC10E_75D0_4AFF_A0CD_764982CF541C.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\LID945~1.XRM [1]
=> visio.reg -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro\visio.reg [1]
=> VisioPro -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioPro [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LI6333~1.XRM [1]
=> LicenseSetData._44A1F6FF_0876_4EDB_9169_DBB43101EE89.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LI0EA2~1.XRM [1]
=> LicenseSetData._44A1F6FF_0876_4EDB_9169_DBB43101EE89.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LIB362~1.XRM [1]
=> LicenseSetData._44A1F6FF_0876_4EDB_9169_DBB43101EE89.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LI462A~1.XRM [1]
=> LicenseSetData._44A1F6FF_0876_4EDB_9169_DBB43101EE89.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LI29C9~1.XRM [1]
=> LicenseSetData._AC4EFAF0_F81F_4F61_BDF7_EA32B02AB117.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LIEA2E~1.XRM [1]
=> LicenseSetData._AC4EFAF0_F81F_4F61_BDF7_EA32B02AB117.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LICB18~1.XRM [1]
=> LicenseSetData._AC4EFAF0_F81F_4F61_BDF7_EA32B02AB117.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd\LI947F~1.XRM [1]
=> VisioStd -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\VisioStd [1]
=> Licenses.sl.ISSUANCE.CLIENT_BRIDGE_OFFICE.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LICENS~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LICENS~2.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_ROOT_BRIDGE_TEST.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LICENS~3.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_STIL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LICENS~4.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LIEC81~1.XRM [1]
=> Licenses.sl.ISSUANCE.CLIENT_UL_OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LIE91A~1.XRM [1]
=> Licenses.sl.PKEYCONFIG.SIGNED.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LI6333~1.XRM [1]
=> LicenseSetData._9CEDEF15_BE37_4FF0_A08A_13A045540641.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LID09D~1.XRM [1]
=> LicenseSetData._9CEDEF15_BE37_4FF0_A08A_13A045540641.PHN.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LI82A2~1.XRM [1]
=> LicenseSetData._9CEDEF15_BE37_4FF0_A08A_13A045540641.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LI273B~1.XRM [1]
=> LicenseSetData._9CEDEF15_BE37_4FF0_A08A_13A045540641.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LID36F~1.XRM [1]
=> LicenseSetData._D9F5B1C6_5386_495A_88F9_9AD6B41AC9B3.OOB.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LI7E94~1.XRM [1]
=> LicenseSetData._D9F5B1C6_5386_495A_88F9_9AD6B41AC9B3.PL.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LIBCEB~1.XRM [1]
=> LicenseSetData._D9F5B1C6_5386_495A_88F9_9AD6B41AC9B3.PPDLIC.xrm-ms -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word\LI19BD~1.XRM [1]
=> Word -- C:\PROGRA~1\KMSpico\cert\KMSCER~2\Word [1]
=> kmscert2013 -- C:\PROGRA~1\KMSpico\cert\KMSCER~2 [1]
=> Business -- C:\PROGRA~1\KMSpico\cert\KMSCER~3\Business [1]
=> Enterprise -- C:\PROGRA~1\KMSpico\cert\KMSCER~3\ENTERP~1 [1]
=> kmscertw6 -- C:\PROGRA~1\KMSpico\cert\KMSCER~3 [1]
=> Enterprise -- C:\PROGRA~1\KMSpico\cert\KMSCER~4\ENTERP~1 [1]
=> Professional -- C:\PROGRA~1\KMSpico\cert\KMSCER~4\PROFES~1 [1]
=> kmscertw7 -- C:\PROGRA~1\KMSpico\cert\KMSCER~4 [1]
=> plugin-manifests-signed -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\PLUGIN~1 [1]
=> APPXLOB-Client -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\addons\APPXLO~1 [1]
=> OCUR -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\addons\OCUR [1]
=> addons -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\addons [1]
=> issuance -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\issuance [1]
=> legacy -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\legacy [1]
=> pkeyconfig -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\PKEYCO~1 [1]
=> ppdlic -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\ppdlic [1]
=> rules -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\rules [1]
=> csvlk-pack -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\skus\CSVLK-~1 [1]
=> Enterprise -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\skus\ENTERP~1 [1]
=> skus -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens\skus [1]
=> tokens -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1\tokens [1]
=> Enterprise -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\ENTERP~1 [1]
=> Professional -- C:\PROGRA~1\KMSpico\cert\KM41A8~1\PROFES~1 [1]
=> kmscertw8 -- C:\PROGRA~1\KMSpico\cert\KM41A8~1 [1]
=> Professional -- C:\PROGRA~1\KMSpico\cert\KM1BAD~1\PROFES~1 [1]
=> kmscertw81 -- C:\PROGRA~1\KMSpico\cert\KM1BAD~1 [1]
=> cert -- C:\PROGRA~1\KMSpico\cert [1]
=> DevComponents.DotNetBar2.dll -- C:\PROGRA~1\KMSpico\DEVCOM~1.DLL [1]
=> OpenVPN.cer -- C:\PROGRA~1\KMSpico\driver\OpenVPN.cer [1]
=> tap-windows-9.9.2_3.exe -- C:\PROGRA~1\KMSpico\driver\TAP-WI~1.EXE [1]
=> UnInstallDriver.cmd -- C:\PROGRA~1\KMSpico\driver\UNINST~1.CMD [1]
=> driver -- C:\PROGRA~1\KMSpico\driver [1]
=> Error.png -- C:\PROGRA~1\KMSpico\icons\Error.png [1]
=> Information.png -- C:\PROGRA~1\KMSpico\icons\INFORM~1.PNG [1]
=> Question.png -- C:\PROGRA~1\KMSpico\icons\Question.png [1]
=> Warning.png -- C:\PROGRA~1\KMSpico\icons\Warning.png [1]
=> icons -- C:\PROGRA~1\KMSpico\icons [1]
=> AutoPico.log -- C:\PROGRA~1\KMSpico\logs\AutoPico.log [1]
=> KMSELDI.log -- C:\PROGRA~1\KMSpico\logs\KMSELDI.log [1]
=> Service_KMS.log -- C:\PROGRA~1\KMSpico\logs\SERVIC~1.LOG [1]
=> logs -- C:\PROGRA~1\KMSpico\logs [1]
=> EnableSmartScreen.cmd -- C:\PROGRA~1\KMSpico\scripts\ENABLE~1.CMD [1]
=> EnableSmartScreen.reg -- C:\PROGRA~1\KMSpico\scripts\ENABLE~1.REG [1]
=> Install_Service.cmd -- C:\PROGRA~1\KMSpico\scripts\INSTAL~1.CMD [1]
=> Install_Task.cmd -- C:\PROGRA~1\KMSpico\scripts\INSTAL~2.CMD [1]
=> Log.cmd -- C:\PROGRA~1\KMSpico\scripts\Log.cmd [1]
=> Silent.cmd -- C:\PROGRA~1\KMSpico\scripts\Silent.cmd [1]
=> UnInstall_Service.cmd -- C:\PROGRA~1\KMSpico\scripts\UNINST~1.CMD [1]
=> scripts -- C:\PROGRA~1\KMSpico\scripts [1]
=> affirmative.mp3 -- C:\PROGRA~1\KMSpico\sounds\AFFIRM~1.MP3 [1]
=> begin.mp3 -- C:\PROGRA~1\KMSpico\sounds\begin.mp3 [1]
=> complete.mp3 -- C:\PROGRA~1\KMSpico\sounds\complete.mp3 [1]
=> diagnostic.mp3 -- C:\PROGRA~1\KMSpico\sounds\DIAGNO~1.MP3 [1]
=> enterauthorizationcode.mp3 -- C:\PROGRA~1\KMSpico\sounds\ENTERA~1.MP3 [1]
=> incomingtransmission.mp3 -- C:\PROGRA~1\KMSpico\sounds\INCOMI~1.MP3 [1]
=> inputfailed.mp3 -- C:\PROGRA~1\KMSpico\sounds\INPUTF~1.MP3 [1]
=> inputok.mp3 -- C:\PROGRA~1\KMSpico\sounds\inputok.mp3 [1]
=> processing.mp3 -- C:\PROGRA~1\KMSpico\sounds\PROCES~1.MP3 [1]
=> transfer.mp3 -- C:\PROGRA~1\KMSpico\sounds\transfer.mp3 [1]
=> verified.mp3 -- C:\PROGRA~1\KMSpico\sounds\verified.mp3 [1]
=> warning.mp3 -- C:\PROGRA~1\KMSpico\sounds\warning.mp3 [1]
=> sounds -- C:\PROGRA~1\KMSpico\sounds [1]
=> unins000.dat -- C:\PROGRA~1\KMSpico\unins000.dat [1]
=> unins000.exe -- C:\PROGRA~1\KMSpico\unins000.exe [1]
=> UninsHs.exe -- C:\PROGRA~1\KMSpico\UninsHs.exe [1]
=> WinDivert.dll -- C:\PROGRA~1\KMSpico\WINDIV~1.DLL [1]
=> WinDivert.sys -- C:\PROGRA~1\KMSpico\WINDIV~1.SYS [1]
=> x64 -- C:\PROGRA~1\KMSpico\x64 [1]
=> x86 -- C:\PROGRA~1\KMSpico\x86 [1]

cosopt
nováček
Příspěvky: 12
Registrován: leden 20
Pohlaví: Nespecifikováno

Re: prosím o kontrolu

Příspěvekod cosopt » 31 led 2020 09:43

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by alex on pi 31. 01. 2020 at 7:06:39,24.
Microsoft Windows 10 Home 10.0.18362 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\alex\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

31. 1. 2020 7:14:07 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Alcohol Soft deleted successfully
C:\PROGRA~3\Comms deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\PROGRA~3\WinZip deleted successfully
C:\Users\alex\AppData\Roaming\iLauncher deleted successfully
C:\Users\alex\AppData\Roaming\MPC-HC deleted successfully
C:\Users\alex\AppData\Roaming\TightVNC deleted successfully
C:\Users\alex\AppData\Local\DBG deleted successfully
C:\Users\alex\AppData\Local\EmieBrowserModeList deleted successfully
C:\Users\alex\AppData\Local\EmieSiteList deleted successfully
C:\Users\alex\AppData\Local\EmieUserList deleted successfully
C:\Users\alex\AppData\Local\NetworkTiles deleted successfully
C:\Users\alex\AppData\Local\PackageStaging deleted successfully
C:\Users\alex\AppData\Local\PDFC deleted successfully
C:\Users\alex\AppData\Local\PlaceholderTileLogoFolder deleted successfully
C:\Users\alex\AppData\Local\Skype deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\DBG deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Maps deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1868968748-2318614808-2451380565-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_USERS\S-1-5-21-1868968748-2318614808-2451380565-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_USERS\S-1-5-21-1868968748-2318614808-2451380565-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_USERS\S-1-5-21-1868968748-2318614808-2451380565-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-1868968748-2318614808-2451380565-1000\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_USERS\S-1-5-21-1868968748-2318614808-2451380565-1000\Software\Classes\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{9030D464-4C02-4ABF-8ECC-5164760863C6} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{B4F3A835-0E21-4959-BA22-42B3008E02FF} deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{4169044D-6BA4-4661-B7D6-E29274F1F458} deleted successfully

==== Deleting CLSID Registry Values ======================

HKEY_USERS\S-1-5-21-1868968748-2318614808-2451380565-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully

==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\xfna1feo.default\prefs.js:
user_pref("browser.startup.homepage", "http://www.google.sk/");
user_pref("browser.newtab.url", "www.google.sk");
user_pref("browser.search.useDBForOrder", true);

Added to C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\xfna1feo.default\prefs.js:

ProfilePath: C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\xfna1feo.default

user.js not found
---- FireFox user.js and prefs.js backups ----

prefs_202031.01._0745_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Alcohol Soft not found
C:\Users\alex\AppData\Roaming\iLinker deleted
C:\PROGRA~3\fontcacheev1.dat deleted
C:\PROGRA~3\{18165758-115C-4DC0-9EC2-FF89F725767F} deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\alex\AppData\Local\AVAST Software deleted
C:\Users\alex\AppData\Local\cache deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM21153.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM21B2A.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM21B82.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM22B40.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM22C7E.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM23D4B.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM29496.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2A081.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2A39B.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2C30B.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2CB5E.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2EFAC.tmp deleted
C:\windows\SysNative\GroupPolicy\Machine deleted
C:\windows\SysNative\GroupPolicy\User deleted
C:\windows\SysNative\GroupPolicy\GPT.INI deleted
C:\WINDOWS\Syswow64\GroupPolicy\gpt.ini deleted
C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\xfna1feo.default\extensions\firefox@mega.co.nz.xpi deleted

==== Orphaned Tasks deleted from Registry ======================

OfficeSoftwareProtectionPlatform\SvcRestartTask deleted

==== Firefox Extensions ======================

ProfilePath: C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\xfna1feo.default
- AdBlock - %ProfilePath%\extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi
- __MSG_avastAppShortName__ - %ProfilePath%\extensions\sp@avast.com.xpi
- short_ Refundo - %ProfilePath%\extensions\toolbar@refundo.cz.xpi
- Avast Online Security - %ProfilePath%\extensions\wrc@avast.com.xpi
- short_ __MSG_name__ - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
- theme: images: theme_frame: HautDUSTERDACIA.png colors: frame: e81515 tab_background_text: 030303 version: 2.0 DUSTER manifest_version: 2 description: Tribute to users of dacia duster - %ProfilePath%\extensions\{e61084a4-ce0a-4011-b997-880b689942bf}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\alex\AppData\Roaming\Mozilla\Firefox\Profiles\xfna1feo.default
306511A40B9906A0AB6CBB42F9C86987 - C:\Program Files\Microsoft Office\Office15\NPSPWRAP.DLL - Microsoft Office 2013
124FA95972259D35F25B6133DD4DC425 - c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll - Silverlight Plug-In
29D9DD280A871C15C8517D30969A65D5 - c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrlui.dll - Microsoft® Silverlight
3CD19649B2C3023D65E67C056457A2BC - C:\Users\alex\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll - Facebook Video Calling Plugin


==== Chromium Look ======================

Google Chrome Version: 79.0.3945.130

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
efaidnbmnnnibpcajpcglclefindmkaj - No path found[]
eofcbnmajmjmplflapaojjnihcjkigck - No path found[]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[]
lifbcibllhkdhoafpjfnlhfpfgnpldfl - No path found[]

Tampermonkey - alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo
Avast Online Security - alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki
Chrome Media Router - alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Chromium Fix ======================

C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.google.sk/"
"Default_Page_URL"="http://www.bing.com?pc=CMNTDF"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.google.sk/"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
HKLM\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} - http://sk.wikipedia.org/wiki/Special:Search?search={searchTerms}
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox
HKLM\Wow6432Node\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} - http://sk.wikipedia.org/wiki/Special:Search?search={searchTerms}
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02
HKCU\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3} - http://sk.wikipedia.org/wiki/Special:Search?search={searchTerms}

==== Reset Google Chrome ======================

C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\alex\Appdata\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\alex\Appdata\Roaming\Opera Software\Opera Stable\Web Data was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Driver Genius_is1 deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\alex\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\alex\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\alex\AppData\Local\Mozilla\Firefox\Profiles\xfna1feo.default\cache2 emptied successfully

==== Empty Edge Cache ======================

Edge Cache Emptied Successfully

==== Empty Chrome Cache ======================

C:\Users\alex\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\alex\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=388 folders=89 85188709 bytes)

==== Empty Temp Folders ======================

C:\Users\alex\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\DefaultAppPool\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\alex\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on pi 31. 01. 2020 at 8:05:41,37 ======================

cosopt
nováček
Příspěvky: 12
Registrován: leden 20
Pohlaví: Nespecifikováno

Re: prosím o kontrolu

Příspěvekod cosopt » 31 led 2020 09:46

Informácie o kontroly
Názov produktu    :  Zemana AntiMalware
Stav kontroly    :  Dokončená
Dátum kontroly    :  31. 1. 2020 8:53:47
Typ kontroly    :  Inteligentná kontrola
Čas trvania    :  00:02:11
Skontrolované objekty    :  1991
Zistené objekty    :  8
Vylúčené objekty    :  0
Automatické odosielanie    :  Áno
Operačný systém    :  Windows 10 x64
Procesor    :  2X Intel(R) Pentium(R) CPU B970 @ 2.30GHz
Režim systému BIOS    :  Legacy
Informácie o doméne    :  WORKGROUP,False,NetSetupWorkgroupName
CUID    :  1267B2C0406A433EEF48C3

Odhalenia
MD5    :  
Stav    :  Skontrolované
Objekt    :  c:\users\alex\appdata\roaming\mozilla\firefox\profiles\xfna1feo.default\extensions\toolbar@refundo.cz.xpi
Vydavatel    :  
Veľkosť    :  0
Odhalenie    :  HijackExt:FirefoxPlugin/toolbar@refundo.cz
Akcia    :  Vymazať
-----------------------------------------------------------------------
MD5    :  
Stav    :  Skontrolované
Objekt    :  c:\users\alex\appdata\roaming\mozilla\firefox\profiles\xfna1feo.default\extensions\{e61084a4-ce0a-4011-b997-880b689942bf}.xpi
Vydavatel    :  
Veľkosť    :  0
Odhalenie    :  HijackExt:FirefoxPlugin/{e61084a4-ce0a-4011-b997-880b689942bf}
Akcia    :  Vymazať
-----------------------------------------------------------------------
MD5    :  
Stav    :  Skontrolované
Objekt    :  azet - http://azet.sk
Vydavatel    :  
Veľkosť    :  0
Odhalenie    :  Hijack:Browser/FirefoxSearch
Akcia    :  Vymazať
-----------------------------------------------------------------------
MD5    :  
Stav    :  Skontrolované
Objekt    :  atlas - http://atlas.sk
Vydavatel    :  
Veľkosť    :  0
Odhalenie    :  Hijack:Browser/FirefoxSearch
Akcia    :  Vymazať
-----------------------------------------------------------------------
MD5    :  
Stav    :  Skontrolované
Objekt    :  zoznam - http://zoznam.sk
Vydavatel    :  
Veľkosť    :  0
Odhalenie    :  Hijack:Browser/FirefoxSearch
Akcia    :  Vymazať
-----------------------------------------------------------------------
MD5    :  3FF5D044E56F2DC564F679E1557D25BE

Stav    :  Skontrolované
Objekt    :  c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
Vydavatel    :  Adobe Inc.
Veľkosť    :  88136
Odhalenie    :  Suspicious:SRC!P
Akcia    :  Karanténa
-----------------------------------------------------------------------
MD5    :  FDB89B03E2BABF8E0907DA1F80AC4D5E

Stav    :  Skontrolované
Objekt    :  c:\program files (x86)\common files\adobe\acrobat\activex\acropdf64.dll
Vydavatel    :  Adobe Inc.
Veľkosť    :  549424
Odhalenie    :  Suspicious:SRC!R
Akcia    :  Karanténa
-----------------------------------------------------------------------
MD5    :  764E5BFE4F72A580068478E6AEEB498A

Stav    :  Skontrolované
Objekt    :  c:\program files (x86)\adobe\acrobat reader dc\reader\air\nppdf32.dll
Vydavatel    :  Adobe Inc.
Veľkosť    :  267824
Odhalenie    :  Suspicious:SRC!R
Akcia    :  Karanténa
-----------------------------------------------------------------------

v Zemana nikde nebola ponuka vytvorit bod obnovenia,tak som ho vytvoril sám.
_________________________________________________________________________________________________________




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:04:55, on 31. 1. 2020
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.18362.0001)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Users\alex\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
O4 - HKLM\..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\alex\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Service for Navitel Navigator Update Center] C:\Program Files (x86)\CNT\Navitel Navigator update center\NavitelUpdaterService.exe
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] C:\Program Files\Zoner\Photo Studio 15\Program32\ZPSTRAY.EXE
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Volanie kliknutím - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} - https://mapa.katasterportal.sk/kapor2/lib/mgaxctrl.cab
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AVG Antivirus - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\AVGSvc.exe
O23 - Service: avgbIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\aswidsagent.exe
O23 - Service: AvgWscReporter - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\Antivirus\wsc_proxy.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_4e0b3 - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\79.0.3945.130\elevation_service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13438 bytes

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40449
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: prosím o kontrolu

Příspěvekod jaro3 » 31 led 2020 18:11

Zavři ostatní aplikace a prohlížeče, odpoj se od netu a fixni v HJT:
Návod

Kód: Vybrat vše

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: ::1 localhost
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)


Vypni antivir i firewall.
Prosím stáhni příslušnou verzi programu pro Tvůj systém 32-bit/64-bit FarbarRecovery Scan Tool (FrSt)
32bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/81/
64bit.:
http://www.bleepingcomputer.com/downloa ... ool/dl/82/
další odkaz:
http://www.bleepingcomputer.com/downloa ... scan-tool/
a ulož jej na plochu. ,pak spusť FrSt.
Potvrď způsob užití.
Neměň žádné z výchozích nastavení a klikni na položku „Scan“ („Skenovat“) .Když je skenování dokončeno, ukážou se dva logy = FRST.txt a Addition.txt a uloží se na ploše.Prosím zkopíruj sem celý jejich obsah.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: CommonCrawl [Bot] a 20 hostů