Prosím o kontrolu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

xfoxy
nováček
Příspěvky: 12
Registrován: březen 22
Pohlaví: Muž
Stav:
Offline

Prosím o kontrolu

Příspěvekod xfoxy » 07 bře 2022 17:47

Dobrý den
mohl bych vás poprosit o kontrolu jestli nemám v pc vir?

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:41:57, on 7.3.2022
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.1202)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\steam.exe
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Users\Rudolf\Desktop\knfgzx2k.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\99.0.1150.30\BHO\ie_to_edge_bho.dll
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Alcohol Virtual Drive Auto-mount Service (AxAutoMntSrv) - Alcohol Soft Development Team - C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_eacd2df - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: EasyAntiCheat - Epic Games, Inc - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA FrameView SDK service (FvSvc) - NVIDIA - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\98.0.4758.102\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google LLC - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_3b12ac0f95b18b9d\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\steamservice.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 8204 bytes

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 07 bře 2022 18:26

Stáhni si ATF Cleaner
https://www.majorgeeks.com/mg/getmirror ... ner,2.html
Poklepej na ATF Cleaner.exe, klikni na select all, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
http://www.adlice.com/downloadprogress/
pro majitele win7 stáhni zde:
https://filehippo.com/download_adwcleaner/ ( nedávej aktualizaci!)

Ulož si ho na svojí plochu . Klikni na „Souhlasím“ k povrzení podmínek.
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Skenování“
Po skenu se objeví log , který se otevře. ( jinak je uložen systémovem disku jako) C:\AdwCleaner\Logs, jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
https://www.malwarebytes.com/mwb-download/thankyou/

na plochu , nainstaluj a spusť ho
-Pokud není program aktuální , klikni na možnost „Aktualizovat nyní“ či „Opravit nyní“.
- bude nalezena aktualizace a nainstaluje se.
- poté klikni na Spustit skenování
- po proběhnutí skenu se ti objeví hláška vpravo dole, tak klikni na Zobrazit zprávu a vyber Export a vyber Kopírovat do schránky a vlož sem celý log. Nebo klikni na „Textový soubor ( .txt)“ a log si ulož.
-jinak se log nachází v programu po kliknutí na „Zprávy“ , nebo je uložen zde: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs

- po té klikni na tlačítko Dokončit, a program zavři křížkem vpravo nahoře.
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

xfoxy
nováček
Příspěvky: 12
Registrován: březen 22
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod xfoxy » 07 bře 2022 20:33

# -------------------------------
# Malwarebytes AdwCleaner 8.3.1.0
# -------------------------------
# Build: 11-18-2021
# Database: 2022-02-03.4 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 03-07-2022
# Duration: 00:00:14
# OS: Windows 10 Home
# Scanned: 32045
# Detected: 8


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

PUP.Optional.Reimage C:\Windows\Reimage.ini

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Legacy HKCU\Software\Video Player
PUP.Optional.Legacy HKLM\Software\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
PUP.Optional.Legacy HKLM\Software\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
PUP.Optional.Legacy HKLM\Software\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
PUP.Optional.Legacy HKLM\Software\Wow6432Node\\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########

xfoxy
nováček
Příspěvky: 12
Registrován: březen 22
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod xfoxy » 07 bře 2022 20:44

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 07.03.22
Čas skenování: 20:37
Logovací soubor: 01d4d2b8-9e4e-11ec-8cf2-14dae9728e7c.json

-Informace o softwaru-
Verze: 4.5.5.175
Verze komponentů: 1.0.1621
Aktualizovat verzi balíku komponent: 1.0.52025
Licence: Bezplatná

-Systémová informace-
OS: Windows 10 (Build 19044.1526)
CPU: x64
Systém souborů: NTFS
Uživatel: Rudolf-PC\Rudolf

-Shrnutí skenování-
Typ skenování: Skenování hrozeb (Threat Scan)
Spuštění skenování: Ruční
Výsledek: Dokončeno
Skenované objekty: 283525
Zjištěné hrozby: 0
Hrozby umístěné do karantény: 0
Uplynulý čas: 4 min, 56 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Zakázáno
Heuristika: Povoleno
Potenciálně nežádoucí program: Detekovat
Potenciálně nežádoucí modifikace: Detekovat

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 0
(Nebyly zjištěny žádné škodlivé položky)

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)

WMI: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

xfoxy
nováček
Příspěvky: 12
Registrován: březen 22
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod xfoxy » 07 bře 2022 20:46

položky z AdwCleaner do karantény?

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 07 bře 2022 21:36

Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Skenování“ , po prohledání klikni na „ do karantény

Program provede opravu, po automatickém restartu klikni na Zobrazit logovací soubor“ a pak poklepej na odpovídají log, (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
https://downloads.malwarebytes.com/file/JRT-EOL
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dlouho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.

Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
https://www.majorgeeks.com/mg/getmirror ... ool,1.html
https://www.majorgeeks.com/mg/get/sopho ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html

Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Pokud byly nalezeny viry , tak po skenu klikni na „Details…“ a potom na „View log file“. Zkopíruj celý log a vlož ho sem. Potom zavři „threat detail“ a klikni na „Start cleanup“.
Jinak se log nachází zde:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs

Stáhni si RogueKiller by Adlice Software
http://www.adlice.com/download/roguekiller/
http://www.bleepingcomputer.com/download/roguekiller/
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- - klikni na „Scan“. V novém okně nic neměň a klikni dole na „Start“ ve sloupci „Quick Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Results “ , v dalším okně pak levým t. na „Export“ a vyber : „Text File“ , log nazvi třeb RK a ulož do dokumentů nebo na plochu. Otevři soubor a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

xfoxy
nováček
Příspěvky: 12
Registrován: březen 22
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod xfoxy » 07 bře 2022 21:45

# -------------------------------
# Malwarebytes AdwCleaner 8.3.1.0
# -------------------------------
# Build: 11-18-2021
# Database: 2022-02-03.4 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-07-2022
# Duration: 00:00:02
# OS: Windows 10 Home
# Cleaned: 8
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

Deleted C:\Windows\Reimage.ini

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\Video Player
Deleted HKLM\Software\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted HKLM\Software\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted HKLM\Software\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted HKLM\Software\Wow6432Node\\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted HKLM\Software\Wow6432Node\\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted HKLM\Software\Wow6432Node\\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2116 octets] - [07/03/2022 20:31:58]
AdwCleaner[S01].txt - [2177 octets] - [07/03/2022 21:42:49]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

xfoxy
nováček
Příspěvky: 12
Registrován: březen 22
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod xfoxy » 07 bře 2022 21:52

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Home x64
Ran by Rudolf (Administrator) on po 07.03.2022 at 21:46:35,37
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 2

Successfully deleted: C:\ProgramData\mntemp (File)
Successfully deleted: C:\Users\Rudolf\AppData\Roaming\Mozilla\Firefox\Profiles\t86bxhvl.default\extensions\staged (Folder)



Registry: 2

Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on po 07.03.2022 at 21:49:14,32
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 08 bře 2022 00:03

ještě to další. Zítra odpoledne pokračujeme.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

xfoxy
nováček
Příspěvky: 12
Registrován: březen 22
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod xfoxy » 08 bře 2022 05:00

Sophos nic nenašel
tady je log z RogueKiller:

Program : RogueKiller Anti-Malware
Version : 15.4.0.0
x64 : Yes
Program Date : Mar 7 2022
Location : C:\Program Files\RogueKiller\RogueKiller64.exe
Premium : No
Company : Adlice Software
Website : https://www.adlice.com/
Contact : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19044) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : Rudolf
User is Admin : Yes
Date : 2022/03/08 03:52:30
Type : Scan
Aborted : No
Scan Mode : Quick
Duration : 18
Found items : 0
Total scanned : 899
Signatures Version : 20220307_144134
Truesight Driver : Yes
Updates Count : 0
Arguments : -minimize

************************* Warnings *************************

************************* Processes *************************

************************* Modules *************************

************************* Services *************************

************************* Scheduled Tasks *************************

************************* Registry *************************

************************* WMI *************************

************************* Hosts File *************************
is_too_big : No
hosts_file_path : N/A


************************* Filesystem *************************

************************* Web Browsers *************************

************************* Antirootkit *************************

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43060
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod jaro3 » 08 bře 2022 16:49

Vypni antivir i firewall, RogueKiller, Malwarebytes Antimalware, windowsDefender
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe
https://uloz.to/file/nFH1LwSrGioP/zoek1-rar

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.

Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat nyní“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Vykonat“ ( vymazat). Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, klikni vlevo na „zprávy“ a pak na „otevři zprávu“ a zkopíruj sem celý obsah té zprávy.

Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

xfoxy
nováček
Příspěvky: 12
Registrován: březen 22
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu

Příspěvekod xfoxy » 08 bře 2022 17:28

Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by Rudolf on Łt 08.03.2022 at 16:52:51,66.
Microsoft Windows 10 Home 10.0.19044 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\Rudolf\Desktop\zoek (1).exe [Scan all users] [Script inserted]

==== System Restore Info ======================

8.3.2022 16:56:26 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Origin Games deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\PROGRA~3\ssh deleted successfully
C:\Users\Rudolf\AppData\Roaming\MPC-HC deleted successfully
C:\Users\Rudolf\AppData\Roaming\Publish Providers deleted successfully
C:\Users\Rudolf\AppData\Local\DBG deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Rudolf\AppData\Roaming\Mozilla\Firefox\Profiles\t86bxhvl.default\prefs.js:
user_pref("browser.search.suggest.enabled", false);

Added to C:\Users\Rudolf\AppData\Roaming\Mozilla\Firefox\Profiles\t86bxhvl.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Origin Games not found
C:\Users\Rudolf\AppData\Roaming\calibre deleted
C:\Users\Rudolf\.android deleted
C:\PROGRA~3\krosqm.txt deleted
C:\PROGRA~3\Wondershare MediaServer deleted
C:\PROGRA~3\Wondershare Video Converter Ultimate deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\Rudolf\AppData\Local\D21156.tmp deleted
C:\Users\Rudolf\AppData\Local\D2117F.tmp deleted
C:\Users\Rudolf\AppData\Local\D21451.tmp deleted
C:\Users\Rudolf\AppData\Local\D21563.tmp deleted
C:\Users\Rudolf\AppData\Local\D21573.tmp deleted
C:\Users\Rudolf\AppData\Local\D21726.tmp deleted
C:\Users\Rudolf\AppData\Local\D2189E.tmp deleted
C:\Users\Rudolf\AppData\Local\D2189F.tmp deleted
C:\Users\Rudolf\AppData\Local\D218AD.tmp deleted
C:\Users\Rudolf\AppData\Local\D21A63.tmp deleted
C:\Users\Rudolf\AppData\Local\D21CA9.tmp deleted
C:\Users\Rudolf\AppData\Local\D21CF.tmp deleted
C:\Users\Rudolf\AppData\Local\D21D5F.tmp deleted
C:\Users\Rudolf\AppData\Local\D21E16.tmp deleted
C:\Users\Rudolf\AppData\Local\D21E20.tmp deleted
C:\Users\Rudolf\AppData\Local\D2217F.tmp deleted
C:\Users\Rudolf\AppData\Local\D22230.tmp deleted
C:\Users\Rudolf\AppData\Local\D223AA.tmp deleted
C:\Users\Rudolf\AppData\Local\D2297.tmp deleted
C:\Users\Rudolf\AppData\Local\D229CB.tmp deleted
C:\Users\Rudolf\AppData\Local\D22FD6.tmp deleted
C:\Users\Rudolf\AppData\Local\D23024.tmp deleted
C:\Users\Rudolf\AppData\Local\D23143.tmp deleted
C:\Users\Rudolf\AppData\Local\D2314C.tmp deleted
C:\Users\Rudolf\AppData\Local\D23967.tmp deleted
C:\Users\Rudolf\AppData\Local\D23ADD.tmp deleted
C:\Users\Rudolf\AppData\Local\D23DC4.tmp deleted
C:\Users\Rudolf\AppData\Local\D23FD7.tmp deleted
C:\Users\Rudolf\AppData\Local\D24153.tmp deleted
C:\Users\Rudolf\AppData\Local\D2416E.tmp deleted
C:\Users\Rudolf\AppData\Local\D24462.tmp deleted
C:\Users\Rudolf\AppData\Local\D248B4.tmp deleted
C:\Users\Rudolf\AppData\Local\D24A48.tmp deleted
C:\Users\Rudolf\AppData\Local\D24A6C.tmp deleted
C:\Users\Rudolf\AppData\Local\D24C99.tmp deleted
C:\Users\Rudolf\AppData\Local\D24CEF.tmp deleted
C:\Users\Rudolf\AppData\Local\D24EFB.tmp deleted
C:\Users\Rudolf\AppData\Local\D24F84.tmp deleted
C:\Users\Rudolf\AppData\Local\D2516F.tmp deleted
C:\Users\Rudolf\AppData\Local\D254D3.tmp deleted
C:\Users\Rudolf\AppData\Local\D2561B.tmp deleted
C:\Users\Rudolf\AppData\Local\D25767.tmp deleted
C:\Users\Rudolf\AppData\Local\D257A9.tmp deleted
C:\Users\Rudolf\AppData\Local\D25902.tmp deleted
C:\Users\Rudolf\AppData\Local\D259AB.tmp deleted
C:\Users\Rudolf\AppData\Local\D259F2.tmp deleted
C:\Users\Rudolf\AppData\Local\D25E37.tmp deleted
C:\Users\Rudolf\AppData\Local\D2605C.tmp deleted
C:\Users\Rudolf\AppData\Local\D2620C.tmp deleted
C:\Users\Rudolf\AppData\Local\D263CB.tmp deleted
C:\Users\Rudolf\AppData\Local\D264FA.tmp deleted
C:\Users\Rudolf\AppData\Local\D2668F.tmp deleted
C:\Users\Rudolf\AppData\Local\D2670B.tmp deleted
C:\Users\Rudolf\AppData\Local\D268D6.tmp deleted
C:\Users\Rudolf\AppData\Local\D26C69.tmp deleted
C:\Users\Rudolf\AppData\Local\D284BC.tmp deleted
C:\Users\Rudolf\AppData\Local\D286B9.tmp deleted
C:\Users\Rudolf\AppData\Local\D2873A.tmp deleted
C:\Users\Rudolf\AppData\Local\D288E6.tmp deleted
C:\Users\Rudolf\AppData\Local\D2892C.tmp deleted
C:\Users\Rudolf\AppData\Local\D28B30.tmp deleted
C:\Users\Rudolf\AppData\Local\D28B6D.tmp deleted
C:\Users\Rudolf\AppData\Local\D28D3E.tmp deleted
C:\Users\Rudolf\AppData\Local\D28D6.tmp deleted
C:\Users\Rudolf\AppData\Local\D28E7E.tmp deleted
C:\Users\Rudolf\AppData\Local\D291CD.tmp deleted
C:\Users\Rudolf\AppData\Local\D291D6.tmp deleted
C:\Users\Rudolf\AppData\Local\D292A0.tmp deleted
C:\Users\Rudolf\AppData\Local\D294E5.tmp deleted
C:\Users\Rudolf\AppData\Local\D29781.tmp deleted
C:\Users\Rudolf\AppData\Local\D2988A.tmp deleted
C:\Users\Rudolf\AppData\Local\D29AB9.tmp deleted
C:\Users\Rudolf\AppData\Local\D29BDF.tmp deleted
C:\Users\Rudolf\AppData\Local\D29C37.tmp deleted
C:\Users\Rudolf\AppData\Local\D29D1C.tmp deleted
C:\Users\Rudolf\AppData\Local\D2A054.tmp deleted
C:\Users\Rudolf\AppData\Local\D2A247.tmp deleted
C:\Users\Rudolf\AppData\Local\D2A460.tmp deleted
C:\Users\Rudolf\AppData\Local\D2A4C.tmp deleted
C:\Users\Rudolf\AppData\Local\D2A63A.tmp deleted
C:\Users\Rudolf\AppData\Local\D2A6AA.tmp deleted
C:\Users\Rudolf\AppData\Local\D2A830.tmp deleted
C:\Users\Rudolf\AppData\Local\D2ADAD.tmp deleted
C:\Users\Rudolf\AppData\Local\D2AE10.tmp deleted
C:\Users\Rudolf\AppData\Local\D2AEFF.tmp deleted
C:\Users\Rudolf\AppData\Local\D2AFF0.tmp deleted
C:\Users\Rudolf\AppData\Local\D2B21F.tmp deleted
C:\Users\Rudolf\AppData\Local\D2B7AD.tmp deleted
C:\Users\Rudolf\AppData\Local\D2BBA7.tmp deleted
C:\Users\Rudolf\AppData\Local\D2BD32.tmp deleted
C:\Users\Rudolf\AppData\Local\D2BDD3.tmp deleted
C:\Users\Rudolf\AppData\Local\D2BEAC.tmp deleted
C:\Users\Rudolf\AppData\Local\D2C25C.tmp deleted
C:\Users\Rudolf\AppData\Local\D2C2E1.tmp deleted
C:\Users\Rudolf\AppData\Local\D2C3C5.tmp deleted
C:\Users\Rudolf\AppData\Local\D2C467.tmp deleted
C:\Users\Rudolf\AppData\Local\D2C924.tmp deleted
C:\Users\Rudolf\AppData\Local\D2CB39.tmp deleted
C:\Users\Rudolf\AppData\Local\D2CBF5.tmp deleted
C:\Users\Rudolf\AppData\Local\D2CD81.tmp deleted
C:\Users\Rudolf\AppData\Local\D2CEBB.tmp deleted
C:\Users\Rudolf\AppData\Local\D2CF91.tmp deleted
C:\Users\Rudolf\AppData\Local\D2D019.tmp deleted
C:\Users\Rudolf\AppData\Local\D2D1A2.tmp deleted
C:\Users\Rudolf\AppData\Local\D2D605.tmp deleted
C:\Users\Rudolf\AppData\Local\D2D645.tmp deleted
C:\Users\Rudolf\AppData\Local\D2D79A.tmp deleted
C:\Users\Rudolf\AppData\Local\D2D893.tmp deleted
C:\Users\Rudolf\AppData\Local\D2DE4D.tmp deleted
C:\Users\Rudolf\AppData\Local\D2E031.tmp deleted
C:\Users\Rudolf\AppData\Local\D2E07E.tmp deleted
C:\Users\Rudolf\AppData\Local\D2E08E.tmp deleted
C:\Users\Rudolf\AppData\Local\D2E490.tmp deleted
C:\Users\Rudolf\AppData\Local\D2E76.tmp deleted
C:\Users\Rudolf\AppData\Local\D2E954.tmp deleted
C:\Users\Rudolf\AppData\Local\D2EA1B.tmp deleted
C:\Users\Rudolf\AppData\Local\D2EA7D.tmp deleted
C:\Users\Rudolf\AppData\Local\D2EB67.tmp deleted
C:\Users\Rudolf\AppData\Local\D2EC68.tmp deleted
C:\Users\Rudolf\AppData\Local\D2EE.tmp deleted
C:\Users\Rudolf\AppData\Local\D2EE0E.tmp deleted
C:\Users\Rudolf\AppData\Local\D2EECC.tmp deleted
C:\Users\Rudolf\AppData\Local\D2F446.tmp deleted
C:\Users\Rudolf\AppData\Local\D2F5A4.tmp deleted
C:\Users\Rudolf\AppData\Local\D2F5D3.tmp deleted
C:\Users\Rudolf\AppData\Local\D2F6EB.tmp deleted
C:\Users\Rudolf\AppData\Local\D2F6F3.tmp deleted
C:\Users\Rudolf\AppData\Local\D2F842.tmp deleted
C:\Users\Rudolf\AppData\Local\D2F93E.tmp deleted
C:\Users\Rudolf\AppData\Local\D2FA26.tmp deleted
C:\Users\Rudolf\AppData\Local\D2FA5E.tmp deleted
C:\Users\Rudolf\AppData\Local\D2FCEA.tmp deleted
C:\Users\Rudolf\AppData\Local\D2FE3B.tmp deleted
C:\Users\Rudolf\AppData\Local\Wondershare deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\CM24AF0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-4116b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-411d11.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-411d70.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-412060.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-4120a1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-4120b3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-412122.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-412143.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-412174.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-4121c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-4121d6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-4121e7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-4121e9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-4121fb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-41220d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-41221e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-412230.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-412232.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1158-19c4-412253.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa164.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa176.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa178.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa17a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa18b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa18d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa18f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1a1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1a3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1a5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1b7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1b9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1ca.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1de.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1e0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1e2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1f3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-12b0-1bbc-7fa1f5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b6692.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66a3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66a5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66b7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66b9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66bb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66cd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66de.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66e0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66e2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66f4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b66f6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b6707.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b6709.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b670b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b671d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b671f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b6721.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1328-ff8-b6733.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c06e9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0787.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0844.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0875.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0896.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c08d7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0b4a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0bb9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0c48.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0cd7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0d46.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0d77.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0d88.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0dc9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0dea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0e1b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0e3c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0e7d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-142c-1bfc-c0f69.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108ed38.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108eea1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108eee2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f01c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f06c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f168.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f1b8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f247.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f2e5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f345.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f48f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f56c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f5fb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f60c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f63d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f739.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f74b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f77c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1430-818-108f7bc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1da98f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1da9b0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1da9c1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1daa02.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1daa14.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1daa35.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1daa56.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1daaa6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1daad7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dab18.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dab48.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dab79.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dab9b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dabdb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dac0c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dac1e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dac3f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dae44.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15cc-860-1dae66.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdcd2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd13.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd25.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd27.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd38.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd3a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd4c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd4e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd50.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd61.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd73.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd75.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd87.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd89.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd8b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd9c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfdd9e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfddb0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-15f8-5c8-1bfddb2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7753.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7774.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d77b5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d77d6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d77e8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7922.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7953.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7965.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7986.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d79a7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d79b9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d79da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d79fb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7a1d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7a2e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7a50.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7a71.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7a82.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1718-1348-1d7a94.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29eb62.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29ebb2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29ebd3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29ec04.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29ec25.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29ec56.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29ec87.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29eecb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1724-568-29f0a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a24ea.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a24fc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a24fe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2500.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2511.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2513.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2525.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2527.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2529.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a253a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a253c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a253e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2550.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2552.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2564.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2575.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2577.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a2579.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-176c-100c-a258b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6c44.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6c65.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6c76.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6c78.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6c8a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6c9c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6cad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6cbf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6cd1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6ce2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6cf4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6d05.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6d17.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6d19.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6d2b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6d2d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6d3e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6d40.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1784-1ff0-a6d52.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a602e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a604f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6061.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6072.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6084.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6096.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a60a7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a60b9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a60bb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a60cc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a60ee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a60ff.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6111.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6123.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6125.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6136.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6157.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a6169.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-18ec-1810-a617b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1cd8c1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1cd902.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1cd952.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1cd973.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1cdc83.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1cdfd0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce05f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce09f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce0c1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce101.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce122.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce124.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce136.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce138.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce159.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce19a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce1ab.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce1ad.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-19dc-1cd8-1ce1cf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2af4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2b63.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2b75.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2b77.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2b88.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2b9a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2bbb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2bdc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2bee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2c00.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2c11.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2c32.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2c54.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2c75.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2c87.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2c98.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2cb9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2d19.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1a98-1b94-1e2da8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b9769.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b979a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b97ab.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b97ec.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b980d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b981f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b984f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b9861.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b9873.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b9884.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b9896.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b98a8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b98d8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b98da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b98dc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b98ee.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b98f0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b9902.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ad4-25bc-61b9913.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7ceb9b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cebcc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cebfc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cec1e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cec3f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cec7f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cecb0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cecf1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7ced12.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7ced33.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7ced64.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7ced85.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cedb6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cedd8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cee08.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cef91.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cefd2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cf012.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1b14-1ec8-7cf043.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780380.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780392.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-78048e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-7804de.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-78051e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780530.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780551.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780553.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780565.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780567.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780644.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780646.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780657.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-780669.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-78067b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-78068c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-78069e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-7806a0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1bd0-11ec-7806a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937ac3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937ad5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937b05.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937b17.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937b29.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937b5a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937b6b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937ca6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937cc7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937cd9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937cdb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937cfc.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937d0d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937d0f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937d31.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937d90.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937da2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937db4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1c20-2a7c-1937db6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26db16f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26db2f7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26db441.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26db4a1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26db7c0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26db8fb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26db92b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dbb60.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dbb91.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dbc00.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dbcdd.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dbe85.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dbfcf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dc04e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dc84f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dd3da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dd459.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dd47a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d18-730-26dd528.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7cfb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7d1c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7d2e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7d5f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7d90.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7dc1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7e11.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7e42.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7e63.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7e84.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7ea5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7ec7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7ed8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7f38.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7f4a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7f4c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7f5d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7f6f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1d6c-1fec-3f7faf.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-253fe1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-253ff3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-253ff5.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-254006.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-254018.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-25401a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-25401c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-25402d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-254149.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-25415a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-25419b.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-2541ac.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-2541ae.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-2541c0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-2541c2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-2541c4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-2541d6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-2541e7.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1ee8-11c0-2541e9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad55e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad57f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad591.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5a2.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5b4.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5b6.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5c8.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5ca.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5db.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5ed.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5ef.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad5f1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad602.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad604.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad6e1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad77f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad80e.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad820.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f18-1f34-ad88f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23fd01.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23fd51.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23fd72.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23ff1a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23ff5a.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23ff7c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23ff9d.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23ffbe.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23ffd0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23ffe1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-23fff3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-240005.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-240026.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-240047.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-240078.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-2400b9.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-2400da.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-2400fb.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-1f4c-1398-24011c.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2054-1534-c4789f.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2054-1534-c478d0.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2054-1534-c478e1.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2054-1534-c478f3.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2054-1534-c47905.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2054-1534-c47916.tmp deleted
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\tw-2054-1534-c47938.tmp deleted


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 11 hostů