prosím o kontrola logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: memphisto, Mods_senior, Security team

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40708
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod jaro3 » 11 kvě 2020 18:32

Stáhni si RogueKiller by Adlice Software
32bit.:
http://www.adlice.com/download/roguekil ... HlwZT14ODY
64bit.:
http://www.adlice.com/download/roguekil ... HlwZT14NjQ
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- Pro OS Vista a win7,8,10 spusť program RogueKiller.exe jako správce , u XP poklepáním.
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Open Report “ , v okně pak na „Open TXT“ a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků

další odkazy:
http://www.adlice.com/download/roguekiller/
http://www.bleepingcomputer.com/download/roguekiller/


Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Reklama
Uživatelský avatar
PARKR
Level 3
Level 3
Příspěvky: 407
Registrován: červenec 12
Bydliště: Severní Morava
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod PARKR » 11 kvě 2020 19:36

RogueKiller V10.5.5.0 (x64) [Mar 16 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno : Normální režim
Uživatel : Bronislav.P [Práva správce]
Started from : C:\Program Files\RogueKiller\RogueKiller.exe
Mód : Prohledat -- Datum : 05/11/2020 19:34:10

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 21 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google Update : "C:\Users\Bronislav.P\AppData\Local\Google\Update\1.3.35.452\GoogleUpdateCore.exe" -> Nalezeno
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Windows\CurrentVersion\Run | Opera Browser Assistant : C:\Users\Bronislav.P\AppData\Local\Programs\Opera\assistant\browser_assistant.exe -> Nalezeno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google Update : "C:\Users\Bronislav.P\AppData\Local\Google\Update\1.3.35.452\GoogleUpdateCore.exe" -> Nalezeno
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Windows\CurrentVersion\Run | Opera Browser Assistant : C:\Users\Bronislav.P\AppData\Local\Programs\Opera\assistant\browser_assistant.exe -> Nalezeno
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CredentialEnrollmentManagerUserSvc (%SystemRoot%\system32\CredentialEnrollmentManager.exe) -> Nalezeno
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WdNisSvc ("%ProgramData%\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe") -> Nalezeno
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinDefend ("C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe") -> Nalezeno
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WdNisSvc ("%ProgramData%\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe") -> Nalezeno
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinDefend ("C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe") -> Nalezeno
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.bing.com/?pc=HRTE -> Nalezeno
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.bing.com/?pc=HRTE -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : 172.16.32.3 172.16.32.6 192.168.1.1 [(Private Address) (XX)][(Private Address) (XX)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 172.16.32.3 172.16.32.6 192.168.1.1 [(Private Address) (XX)][(Private Address) (XX)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{18fa9ebe-32d5-40db-a15a-c8a684f8fe96} | DhcpNameServer : 172.16.32.3 172.16.32.6 192.168.1.1 [(Private Address) (XX)][(Private Address) (XX)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{978ffe35-2a1b-4d93-8444-88e361a0717e} | DhcpNameServer : 10.0.0.138 [(Private Address) (XX)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{18fa9ebe-32d5-40db-a15a-c8a684f8fe96} | DhcpNameServer : 172.16.32.3 172.16.32.6 192.168.1.1 [(Private Address) (XX)][(Private Address) (XX)] -> Nalezeno
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{978ffe35-2a1b-4d93-8444-88e361a0717e} | DhcpNameServer : 10.0.0.138 [(Private Address) (XX)] -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 -> Nalezeno
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 1 -> Nalezeno

¤¤¤ Úlohy : 4 ¤¤¤
[Suspicious.Path] \\OneDrive Standalone Update Task-S-1-5-21-377485661-1175933967-1024712423-1001 -- %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe -> Nalezeno
[Suspicious.Path] \\Opera scheduled assistant Autoupdate 1589103392 -- C:\Users\Bronislav.P\AppData\Local\Programs\Opera\launcher.exe (--scheduledautoupdate --component-name=assistant --component-path="C:\Users\Bronislav.P\AppData\Local\Programs\Opera\assistant" $(Arg0)) -> Nalezeno
[Suspicious.Path] \\Opera scheduled Autoupdate 1589103384 -- C:\Users\Bronislav.P\AppData\Local\Programs\Opera\launcher.exe (--scheduledautoupdate $(Arg0)) -> Nalezeno
[Suspicious.Path] \Microsoft\Windows\PushToInstall\Registration -- %windir%\system32\sc.exe (start pushtoinstall registration) -> Nalezeno

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 keystone.mwbsys.com
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 telemetry.malwarebytes.com

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 0 ¤¤¤

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABD100 +++++
--- User ---
[MBR] e0bbac2451de4085492bd42241c85042
[BSP] 50377dc8d3b1e395a8e578f252caf47a : Empty MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 360 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 739328 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 1001472 | Size: 934163 MB
3 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1914169344 | Size: 1738 MB
4 - [SYSTEM] Basic data partition | Offset (sectors): 1917728768 | Size: 15425 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 1949319168 | Size: 2048 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: ADATA USB Flash Drive USB Device +++++
--- User ---
[MBR] c78645fb861e370c9f9e715d5b88866e
[BSP] ea137df246739ae8058ad4c237748d8b : Unknown MBR Code
Partition table:
User = LL1 ... OK
Error reading LL2 MBR! ([32] Po?adavek není podporován. )


============================================
RKreport_SCN_05102020_125514.log
OS WIN 8 pro / MB MSI B150 PC MATE / CPU Intel Core i5-7400 /RAM Kingston 8GB DDR4 / GPU MSI RADEON RX 480 GAMING X 4G /
HDD Seagate BarraCuda 7200 SATA lll 1TB / SSD Kingston Now UV400 SATA III - 120GB / PSU CORSAIR CX Series 550W
-------------------------------------------------

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40708
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod jaro3 » 11 kvě 2020 19:57

Zavři všechny programy a prohlížeče. Deaktivuj antivir a firewall.
Prosím, odpoj všechny USB (kromě myši s klávesnice) nebo externí disky z počítače před spuštěním tohoto programu.
Spusť znovu RogueKiller ( Pro Windows Vista nebo Windows 7, klepni pravým a vyber "Spustit jako správce", ve Windows XP poklepej ke spuštění).
- klikni na „Start Scan“. V novém okně nic neměň a klikni dole na „Start Scan“,
po jeho skončení - vše zatrhni (dej zatržítka vlevo od nálezů , do bílých políček)
- pak klikni na "Remove Selected"
- Počkej, dokud Status box nezobrazí " Removal finished, please review result "
- Klikni na "Open report " a pak na " Open TXT“ a zkopíruj ten log a vlož obsah té zprávy prosím sem. Log je možno nalézt v C:\ProgramData\RogueKiller\Logs - Zavři RogueKiller.

Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
http://www.majorgeeks.com/files/details ... _tool.html
http://www.majorgeeks.com/mg/get/sophos ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html

Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Pokud byly nalezeny viry , tak po skenu klikni na „Details…“ a potom na „View log file“. Zkopíruj celý log a vlož ho sem. Potom zavři „threat detail“ a klikni na „Start cleanup“.
Jinak se log nachází zde:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs

Vypni antivir i firewall.
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.

Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Můžeš si zatrhnout i vytvoření bodu obnovy:
Klikni na ozubené kolečko , poté na „Skenování“ a zatrhni „vytvářet body obnovy“.
Vrať se zpět ( klikni na domeček).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Další“. Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, objeví se tisková zpráva , zkopíruj sem celý obsah té zprávy.
Jinak můžeš zprávy vidět , když klikneš vpravo nahoře na „ zprávy“.


Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
PARKR
Level 3
Level 3
Příspěvky: 407
Registrován: červenec 12
Bydliště: Severní Morava
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod PARKR » 11 kvě 2020 20:18

RogueKiller V10.5.5.0 (x64) [Mar 16 2015] by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : http://forum.adlice.com
Webová stránka : http://www.adlice.com/softwares/roguekiller/
Blog : http://www.adlice.com

Operační systém : Windows 8 (6.2.9200 ) 64 bits version
Spuštěno : Normální režim
Uživatel : Bronislav.P [Práva správce]
Started from : C:\Program Files\RogueKiller\RogueKiller.exe
Mód : Smazat -- Datum : 05/11/2020 20:13:10

¤¤¤ Procesy : 0 ¤¤¤

¤¤¤ Registry : 21 ¤¤¤
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google Update : "C:\Users\Bronislav.P\AppData\Local\Google\Update\1.3.35.452\GoogleUpdateCore.exe" [7] -> ERROR [0]
[Suspicious.Path] (X64) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Windows\CurrentVersion\Run | Opera Browser Assistant : C:\Users\Bronislav.P\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [7] -> ERROR [0]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Windows\CurrentVersion\Run | Google Update : "C:\Users\Bronislav.P\AppData\Local\Google\Update\1.3.35.452\GoogleUpdateCore.exe" -> ERROR [2]
[Suspicious.Path] (X86) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Windows\CurrentVersion\Run | Opera Browser Assistant : C:\Users\Bronislav.P\AppData\Local\Programs\Opera\assistant\browser_assistant.exe -> ERROR [2]
[Hidden.From.SCM] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\CredentialEnrollmentManagerUserSvc -> ERROR [2]
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WdNisSvc -> ERROR [2]
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\WinDefend -> ERROR [2]
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WdNisSvc -> ERROR [2]
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\WinDefend -> ERROR [2]
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-377485661-1175933967-1024712423-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Nahrazeno (http://go.microsoft.com/fwlink/p/?LinkId=255141)
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters | DhcpNameServer : [(Private Address) (XX)][(Private Address) (XX)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : [(Private Address) (XX)][(Private Address) (XX)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{18fa9ebe-32d5-40db-a15a-c8a684f8fe96} | DhcpNameServer : [(Private Address) (XX)][(Private Address) (XX)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{978ffe35-2a1b-4d93-8444-88e361a0717e} | DhcpNameServer : [(Private Address) (XX)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{18fa9ebe-32d5-40db-a15a-c8a684f8fe96} | DhcpNameServer : [(Private Address) (XX)][(Private Address) (XX)] -> Nahrazeno ()
[PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{978ffe35-2a1b-4d93-8444-88e361a0717e} | DhcpNameServer : [(Private Address) (XX)] -> Nahrazeno ()
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0 -> Nahrazeno (0)
[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0 -> Nahrazeno (0)
[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0 -> Nahrazeno (0)

¤¤¤ Úlohy : 4 ¤¤¤
[Suspicious.Path] \\OneDrive Standalone Update Task-S-1-5-21-377485661-1175933967-1024712423-1001 -- %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe -> ERROR [0]
[Suspicious.Path] \\Opera scheduled assistant Autoupdate 1589103392 -- C:\Users\Bronislav.P\AppData\Local\Programs\Opera\launcher.exe (--scheduledautoupdate --component-name=assistant --component-path="C:\Users\Bronislav.P\AppData\Local\Programs\Opera\assistant" $(Arg0)) -> ERROR [0]
[Suspicious.Path] \\Opera scheduled Autoupdate 1589103384 -- C:\Users\Bronislav.P\AppData\Local\Programs\Opera\launcher.exe (--scheduledautoupdate $(Arg0)) -> ERROR [0]
[Suspicious.Path] \Microsoft\Windows\PushToInstall\Registration -- %windir%\system32\sc.exe (start pushtoinstall registration) -> ERROR [0]

¤¤¤ Soubory : 0 ¤¤¤

¤¤¤ Soubor HOSTS : 2 ¤¤¤
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 keystone.mwbsys.com -> Smazáno
[C:\Windows\System32\drivers\etc\hosts] 0.0.0.0 telemetry.malwarebytes.com -> Smazáno

¤¤¤ Antirootkit : 0 (Driver: Nahrán) ¤¤¤

¤¤¤ Webové prohlížeče : 10 ¤¤¤
[FIREFX:Addon] p4qz6hor.default : Activity Stream [activity-stream@mozilla.org] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : Application Update Service Helper [aushelper@mozilla.org] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : Pocket [firefox@getpocket.com] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : Follow-on Search Telemetry [followonsearch@mozilla.com] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : Form Autofill [formautofill@mozilla.org] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : Photon onboarding [onboarding@mozilla.org] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : Firefox Screenshots [screenshots@mozilla.org] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : Shield Recipe Client [shield-recipe-client@mozilla.org] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : Web Compat [webcompat@mozilla.org] -> Smazáno
[FIREFX:Addon] p4qz6hor.default : TLS 1.3 gradual roll-out [tls13-rollout-bug1442042@mozilla.org] -> Smazáno

¤¤¤ Kontrola MBR : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA MQ01ABD100 +++++
--- User ---
[MBR] e0bbac2451de4085492bd42241c85042
[BSP] 50377dc8d3b1e395a8e578f252caf47a : Empty MBR Code
Partition table:
0 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2048 | Size: 360 MB
1 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 739328 | Size: 128 MB
2 - Basic data partition | Offset (sectors): 1001472 | Size: 934163 MB
3 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 1914169344 | Size: 1738 MB
4 - [SYSTEM] Basic data partition | Offset (sectors): 1917728768 | Size: 15425 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 1949319168 | Size: 2048 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: ADATA USB Flash Drive USB Device +++++
--- User ---
[MBR] c78645fb861e370c9f9e715d5b88866e
[BSP] ea137df246739ae8058ad4c237748d8b : Unknown MBR Code
Partition table:
User = LL1 ... OK
Error reading LL2 MBR! ([32] Po?adavek není podporován. )


============================================
RKreport_SCN_05102020_125514.log - RKreport_SCN_05112020_193410.log - RKreport_DEL_05112020_201238.log - RKreport_DEL_05112020_201246.log
RKreport_DEL_05112020_201248.log - RKreport_DEL_05112020_201249.log - RKreport_DEL_05112020_201256.log - RKreport_DEL_05112020_201302.log
OS WIN 8 pro / MB MSI B150 PC MATE / CPU Intel Core i5-7400 /RAM Kingston 8GB DDR4 / GPU MSI RADEON RX 480 GAMING X 4G /
HDD Seagate BarraCuda 7200 SATA lll 1TB / SSD Kingston Now UV400 SATA III - 120GB / PSU CORSAIR CX Series 550W
-------------------------------------------------

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40708
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod jaro3 » 11 kvě 2020 22:10

Ještě to další.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
PARKR
Level 3
Level 3
Příspěvky: 407
Registrován: červenec 12
Bydliště: Severní Morava
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod PARKR » 11 kvě 2020 22:22

Sophos Virus Removal Tool je je čistý . Další pošlu zítra . Pro zatím děkuji :thumbup:
OS WIN 8 pro / MB MSI B150 PC MATE / CPU Intel Core i5-7400 /RAM Kingston 8GB DDR4 / GPU MSI RADEON RX 480 GAMING X 4G /
HDD Seagate BarraCuda 7200 SATA lll 1TB / SSD Kingston Now UV400 SATA III - 120GB / PSU CORSAIR CX Series 550W
-------------------------------------------------

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 40708
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod jaro3 » 11 kvě 2020 23:05

OK.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Uživatelský avatar
PARKR
Level 3
Level 3
Příspěvky: 407
Registrován: červenec 12
Bydliště: Severní Morava
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod PARKR » 12 kvě 2020 06:22

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by Bronislav.P on 12.05.2020 at 5:28:25,99.
Microsoft Windows 10 Home 10.0.18362 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Bronislav.P\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

12.05.2020 5:33:31 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~3\Comms deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\PROGRA~3\ssh deleted successfully
C:\Users\Default\AppData\Roaming\Hewlett-Packard deleted successfully
C:\Users\Bronislav.P\AppData\Local\Adobe deleted successfully
C:\Users\Bronislav.P\AppData\Local\DBG deleted successfully
C:\Users\Bronislav.P\AppData\Local\NetworkTiles deleted successfully
C:\Users\Bronislav.P\AppData\Local\PlaceholderTileLogoFolder deleted successfully
C:\Users\Bronislav.P\AppData\Local\VirtualStore deleted successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\DBG deleted successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\DBG deleted successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\NetworkTiles deleted successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Packages deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Bronislav.P\AppData\Roaming\Mozilla\Firefox\Profiles\p4qz6hor.default\prefs.js:

Added to C:\Users\Bronislav.P\AppData\Roaming\Mozilla\Firefox\Profiles\p4qz6hor.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~3\{C6FA530F-BB98-4D9F-BA00-45FD0698077C} deleted
C:\PROGRA~3\Package Cache deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM22A2A.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM297A8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2D180.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM2E611.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1ce9d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1cf0c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1cf2e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1cf8d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1cfaf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1cfc0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1cfe1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d003.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d014.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d026.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d038.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d059.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d05b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d06c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d06e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d080.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d092.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d0b3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1364-2b50-51a1d0d4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc90d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc9135.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc9156.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc91b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc91c7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc91d9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc91eb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc91fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc921d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc923f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc9241.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc9252.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc92b2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc92c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc92f5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc9306.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc9366.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc93f5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1574-2554-15fc9425.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798ae2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798af4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b05.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b07.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b19.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b2b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b4c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b4e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b50.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b61.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b63.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b75.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b77.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b79.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798b9a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798bac.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798bbe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798bdf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15b8-16ac-85798c00.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc4a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc4e6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc4f8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc509.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc52b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc56b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc57d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc5ae.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc5de.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc5f0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc602.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc633.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc654.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc685.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc6a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc6b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc6c9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc6db.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-164c-1184-10dfc6fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f0695.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f06b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f06c7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f06d9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f06eb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f06ed.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f06fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f0700.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f0712.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f0724.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f0735.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f0737.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f0749.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f074b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f075c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f076e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f0780.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f07a1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bac-1e88-97f07b3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bd5d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bdad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bdce.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bde0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6be01.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6be13.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6be24.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6be36.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6be57.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6be79.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6be7b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6beab.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bebd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bede.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bf00.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bf21.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bf61.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bf83.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cb8-34e8-53e6bfc3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-43260e2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326103.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326105.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326117.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326129.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-432615a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-432616b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-432619c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-43261bd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-43261df.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326200.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326211.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326252.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326254.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326275.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-4326296.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-43262a8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-43262ba.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1cd0-2e94-43262cb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-ada40.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adaa0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adab1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adac3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adae4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adaf6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adb46.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adb48.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adb69.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adb7b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adb8c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adb8e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adbbf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adbd1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adbf2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adbf4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adc06.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adc46.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d8c-1090-adc96.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2fd2bc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2fe116.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2fe3b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2fe4c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2fe746.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2fe7e4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2feb61.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2fedd4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2ff539.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2ff71f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2ffb19.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2ffbc7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2fff53.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-2ffff1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-300439.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3004d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-300a38.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-300ad6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-300d88.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-300ec2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-30107a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-301195.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3014d3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-301543.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3018fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3019fa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-301c9c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-301e43.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3020b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-302126.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-30256e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-302706.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3028dd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-30297b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-302e5f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-303026.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3034db.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-303c8e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-304b84.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3054cd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-305721.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3057ee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-30585d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-30591b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-30599a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-305b03.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-305c2e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-305d59.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-305de7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-30601c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-306185.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3062fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-306581.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-30669c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3067d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-3069ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-201c-18bc-306d49.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b678d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b67ec.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b680e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b682f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6850.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6871.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6883.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6912.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6962.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b69f0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6a12.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6a42.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6ab2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6b60.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6bee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6c1f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6c21.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6c62.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-20a0-34fc-542b6cf0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d8d1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d930.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d961.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d963.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d985.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d9a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d9b7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d9c9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54d9ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54da0c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54da1d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54da3e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54da60.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54da62.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54da73.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54da95.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54daa6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54dab8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2180-1a74-54dad9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075747.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075797.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-70757b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-70757d9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-70757fb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-70757fd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-707580e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075830.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075851.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-70758d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075910.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075960.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075972.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075984.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-70759c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-70759f5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075a07.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075a38.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-222c-2c98-7075a49.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bedba4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf01eb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf0604.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf078d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf09f0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf1dd8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf2358.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf29b3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf2d9d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf339a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf3458.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf365d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf3ad4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf4045.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf4651.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf4ab8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf50a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf61bf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2304-10b8-80bf744f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a34de.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a379f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a3966.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a3afe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a3c1a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a3d16.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a3eae.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a3fe8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a4152.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a425d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a433a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a4417.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a44d4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a4582.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a45f2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a4661.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a46e0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a4720.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2338-1f54-1e8a4907.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d72376d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d72378e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d7237a0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d7237c1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d7237d3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d7237e4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d7237f6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d7237f8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d72380a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d72380c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d72381d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d72381f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d723821.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d723833.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d723835.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d723856.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d723868.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d723889.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2690-ec4-2d72389b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624bb5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624bd6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624be8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624bea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624bec.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624bfe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c00.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c02.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c13.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c15.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c17.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c29.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c2b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c2d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c3f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c41.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c43.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c64.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2b94-29ec-2624c75.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3cc8c8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3cc928.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3cc939.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3cc95b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3cc96c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3cca97.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccae7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccaf9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccb0a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccb4b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccb8b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccbfb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccc1c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccc1e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccc3f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccc51.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3ccc63.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3cccb3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2c1c-1c14-3cccc4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-86594d6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-8659565.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-8659576.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-8659578.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-865959a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-86595cb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-86595ec.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-865962c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-8659767.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-8659778.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-865978a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-86597f9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-865981b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-865982c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-865984e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-865985f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-86599d8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-86599ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2d70-12a8-8659ae6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e540488.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e540aa4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e540e11.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e541324.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e541875.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e541cfc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e54227c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e5426f2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e542c44.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e543260.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e543a52.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e543ee7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e5441c8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e5444f6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e544806.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e544b24.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e544e53.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e5451ef.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-3244-3248-3e54558b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d36d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d38f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d391.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3a4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3ba.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3bc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3ce.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3d2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3e3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3e5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3e7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d3f9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d40a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d41c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-35a4-c5c-5912d42e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011977.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011999.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-40119aa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-40119bc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-40119cd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-40119ef.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011a00.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011a02.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011a24.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011a35.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011a47.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011a58.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011a7a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011a8b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011adb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011afd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011b0e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011b30.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-4b0-f64-4011b41.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e075.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e0a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e0a8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e0c9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e0db.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e0fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e0fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e100.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e160.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e171.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e193.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e1a4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e1d5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e225.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e295.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e2a6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e2c8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e318.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-574-78-42a1e368.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0eecc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0efc8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0efd9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0efeb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f00c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f03d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f04f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f060.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f072.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f084.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f086.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f0a7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f0b9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f0ca.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f0dc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f0ed.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f0ff.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f120.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-8b0-24e8-3cf0f170.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c148.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c179.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c18a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c19c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c1ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c1af.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c1d1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c1d3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c1e4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c1f6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c208.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c219.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c22b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c23c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c25e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c26f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c281.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c2a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-92c-4c4-20a7c2c3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-1062ff.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-10634f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106371.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106392.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106394.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-1063b5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-1063c7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-1063e8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-1063fa.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-1063fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-10640d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-10641f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106440.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106452.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106454.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106465.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106467.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-106489.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-dcc-2e94-10648b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c2f70.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c2f91.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c2fa3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c3022.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c3033.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c3035.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c3047.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c3059.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c305b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c305d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c306e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c3080.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c3092.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c30a3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c30c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c30c6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c30d8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c30ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-fd8-32e4-1b2c30fb.tmp deleted
C:\windows\SysNative\Tasks\AvastUpdateTaskMachineCore deleted
C:\windows\SysNative\Tasks\AvastUpdateTaskMachineUA deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.PFfl2.dat" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pam.db" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pamcore.db" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pampub.db" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\pam.db" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.PFfl2.dat" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pam.db" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pamcore.db" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pampub.db" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\pam.db" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM" not deleted
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P" not deleted
OS WIN 8 pro / MB MSI B150 PC MATE / CPU Intel Core i5-7400 /RAM Kingston 8GB DDR4 / GPU MSI RADEON RX 480 GAMING X 4G /
HDD Seagate BarraCuda 7200 SATA lll 1TB / SSD Kingston Now UV400 SATA III - 120GB / PSU CORSAIR CX Series 550W
-------------------------------------------------

Uživatelský avatar
PARKR
Level 3
Level 3
Příspěvky: 407
Registrován: červenec 12
Bydliště: Severní Morava
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod PARKR » 12 kvě 2020 06:24

==== Orphaned Tasks deleted from Registry ======================

AvastUpdateTaskMachineCore deleted
AvastUpdateTaskMachineUA deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Bronislav.P\AppData\Roaming\Mozilla\Firefox\Profiles\p4qz6hor.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

==== Firefox Plugins ======================

Profilepath: C:\Users\Bronislav.P\AppData\Roaming\Mozilla\Firefox\Profiles\p4qz6hor.default
- C:\Users\Bronislav.P\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll - [?]


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
ncffjdbbodifgldkcbhmiiljfcnbgjab - c:\Program Files (x86)\Hewlett-Packard\HP ProtectTools Security Manager\Bin\BrowserExt\dpchrome.crx[28.09.2015 21:47]

Chrome Media Router - Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm
Chrome Media Router - Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"
"Default_Page_URL"="http://www.bing.com?pc=HRTE"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/p/?LinkId=255141"

==== All HKLM and HKCU SearchScopes ======================

HKLM\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=PRHPR1&src=IE11TR&pc=HRTS
HKLM\Wow6432Node\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKLM\Wow6432Node\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=PRHPR1&src=IE11TR&pc=HRTS
HKCU\SearchScopes "DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
HKCU\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66} - http://www.google.com/search?q={searchTerms}
HKCU\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} - http://www.bing.com/search?q={searchTerms}&form=PRHPR1&src=IE11TR&pc=HRTS

==== Reset Google Chrome ======================

C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences.bad was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\System Profile\Preferences was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\System Profile\Secure Preferences was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Preferences.bad was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences.bad was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\System Profile\Preferences was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\System Profile\Secure Preferences was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Preferences.backup was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Secure Preferences was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Secure Preferences.backup was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Preferences was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Preferences.backup was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Secure Preferences was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Secure Preferences.backup was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\System Profile\Web Data was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\System Profile\Web Data was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Web Data-journal was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Web Data was reset successfully
C:\Users\Bronislav.P\Appdata\Roaming\Opera Software\Opera Stable\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\Software\wow6432node\Policies\Google deleted successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Bronislav.P\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Bronislav.P\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\Bronislav.P\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\Users\Bronislav.P\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

No FireFox Cache found

==== Empty Edge Cache ======================

Edge Cache is not empty, a reboot is needed

==== Empty Chrome Cache ======================

C:\Users\Bronislav.P\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Bronislav.P\AppData\Local\Opera Software\Opera Stable\Cache emptied successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\System Profile\Cache emptied successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully
C:\Users\Bronislav.P\AppData\Local\Google\Chrome\User Data\System Profile\Cache emptied successfully

==== Empty All Flash Cache ======================

No Flash Cache Found

==== Empty All Java Cache ======================

No Java Cache Found

==== C:\zoek_backup content ======================

C:\zoek_backup (files=93 folders=599 517638384 bytes)

==== Empty Temp Folders ======================

C:\Users\Bronislav.P\AppData\Local\Temp will be emptied at reboot
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\TEMP\AppData\Local\Temp emptied successfully
C:\Users\Bronislav.P\AppData\Local\Temp will be emptied at reboot
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\Bronislav.P\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.PFfl2.dat" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pam.db" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pamcore.db" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pampub.db" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\pam.db" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.PFfl2.dat" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pam.db" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pamcore.db" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\kv_pampub.db" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software\APM\Bronislav.P\pam.db" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software" not found
"C:\Users\Bronislav.P\AppData\Local\AVAST Software" not found
"C:\Users\Bronislav.P\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge" not found
"C:\Users\Bronislav.P\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\AC\MicrosoftEdge" not found

==== EOF on 12.05.2020 at 6:18:13,29 ======================
OS WIN 8 pro / MB MSI B150 PC MATE / CPU Intel Core i5-7400 /RAM Kingston 8GB DDR4 / GPU MSI RADEON RX 480 GAMING X 4G /
HDD Seagate BarraCuda 7200 SATA lll 1TB / SSD Kingston Now UV400 SATA III - 120GB / PSU CORSAIR CX Series 550W
-------------------------------------------------

Uživatelský avatar
PARKR
Level 3
Level 3
Příspěvky: 407
Registrován: červenec 12
Bydliště: Severní Morava
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod PARKR » 12 kvě 2020 06:25

zemana AntiMalware dodám odpoledne zatím děkuji
OS WIN 8 pro / MB MSI B150 PC MATE / CPU Intel Core i5-7400 /RAM Kingston 8GB DDR4 / GPU MSI RADEON RX 480 GAMING X 4G /
HDD Seagate BarraCuda 7200 SATA lll 1TB / SSD Kingston Now UV400 SATA III - 120GB / PSU CORSAIR CX Series 550W
-------------------------------------------------

Uživatelský avatar
PARKR
Level 3
Level 3
Příspěvky: 407
Registrován: červenec 12
Bydliště: Severní Morava
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod PARKR » 12 kvě 2020 17:18

Zemana AntiMalware
Stav kontroly    :  Dokončena
Datum kontroly    :  12.05.2020 17:04:45
Typ kontroly    :  Inteligentní kontrola
Čas trvání    :  00:01:25
Zkontrolované objekty    :  1921
Zjištěné objekty    :  0
Vyloučené objekty    :  0
Automatické odesílání    :  Ne
Operační systém    :  Windows 10 x64
Procesor    :  4X Intel(R) Core(TM) i3-6100U CPU @ 2.30GHz
Režim systému BIOS    :  UEFI
Informace o doméně    :  WORKGROUP,False,NetSetupWorkgroupName
CUID    :  126AC17E53488C3EF8EFCA
OS WIN 8 pro / MB MSI B150 PC MATE / CPU Intel Core i5-7400 /RAM Kingston 8GB DDR4 / GPU MSI RADEON RX 480 GAMING X 4G /
HDD Seagate BarraCuda 7200 SATA lll 1TB / SSD Kingston Now UV400 SATA III - 120GB / PSU CORSAIR CX Series 550W
-------------------------------------------------

Uživatelský avatar
PARKR
Level 3
Level 3
Příspěvky: 407
Registrován: červenec 12
Bydliště: Severní Morava
Pohlaví: Muž

Re: prosím o kontrola logu

Příspěvekod PARKR » 12 kvě 2020 17:21

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:21:30, on 12.05.2020
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.18362.0001)
CHROME: 81.0.4044.138

Boot mode: Normal

Running processes:
C:\Users\Bronislav.P\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O1 - Hosts: ::1 localhost
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (file missing)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software - C:\Program Files\AVAST Software\Avast\aswidsagent.exe
O23 - Service: Služba %1!s! Update (avast) (avast) - AVAST Software - C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall Service (avast! Firewall) - AVAST Software - C:\Program Files\AVAST Software\Avast\afwServ.exe
O23 - Service: Služba %1!s! Update (avastm) (avastm) - AVAST Software - C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe
O23 - Service: AvastWscReporter - AVAST Software - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_862bac15d0efb48d\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_862bac15d0efb48d\IntelCpHDCPSvc.exe
O23 - Service: CxMonSvc - Conexant Systems, Inc - C:\WINDOWS\CxSvc\CxMonSvc.exe
O23 - Service: CxUtilSvc - Conexant Systems, Inc. - C:\WINDOWS\CxSvc\CxUtilSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Služba DigitalPersona Authentication Service (DpHost) - DigitalPersona, Inc. - c:\Program Files\Hewlett-Packard\HP ProtectTools Security Manager\Bin\DpHostW.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @oem23.inf,%fpCSEvtService_SvcDesc%;fpCSEvtSvc (fpCsEvtSvc) - Unknown owner - C:\WINDOWS\system32\fpCSEvtSvc.exe (file missing)
O23 - Service: @oem15.inf,%HP.HotKeyServiceUWP%;HP Hotkey UWP Service (HotKeyServiceUWP) - HP Inc. - C:\WINDOWS\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5\HotKeyServiceUWP.exe
O23 - Service: HP CASL Framework Service (hpqcaslwmiex) - HP - C:\Program Files (x86)\HP\Shared\hpqwmiex.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - HP - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HP Support Solutions Framework Service (HPSupportSolutionsFrameworkService) - HP Inc. - c:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @oem31.inf,%SERVICE_NAME%;Intel Bluetooth Service (ibtsiva) - Unknown owner - C:\WINDOWS\System32\ibtsiva (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_862bac15d0efb48d\igfxCUIService.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\SocketHeciServer.exe
O23 - Service: Intel(R) Security Assist - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
O23 - Service: Intel(R) TPM Provisioning Service - Intel(R) Corporation - C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\TPMProvisioningService.exe
O23 - Service: Intel(R) WiDi Software Asset Manager (Intel(R) WiDi SAM) - Intel Corporation - C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe
O23 - Service: Intel(R) Audio Service (IntelAudioService) - Unknown owner - C:\WINDOWS\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe (file missing)
O23 - Service: Intel(R) Security Assist Helper (isaHelperSvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @oem15.inf,%HP.LanWlanWwanSwitchingServiceUWP%;HP LAN/WLAN/WWAN Switching UWP Service (LanWlanWwanSwitchingServiceUWP) - HP Inc. - C:\WINDOWS\System32\DriverStore\FileRepository\hpqkbsoftwarecompnent.inf_amd64_8598cf7f18c538c5\LanWlanWwanSwitchingServiceUWP.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @oem23.inf,%WBFService_SvcDesc%;Synaptics FP WBF Policy Service (valWBFPolicyService) - Unknown owner - C:\WINDOWS\system32\valWBFPolicyService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 11688 bytes
OS WIN 8 pro / MB MSI B150 PC MATE / CPU Intel Core i5-7400 /RAM Kingston 8GB DDR4 / GPU MSI RADEON RX 480 GAMING X 4G /
HDD Seagate BarraCuda 7200 SATA lll 1TB / SSD Kingston Now UV400 SATA III - 120GB / PSU CORSAIR CX Series 550W
-------------------------------------------------


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: CommonCrawl [Bot] a 3 hosti