Prosím o kontrolu logu Vyřešeno

Místo pro vaše HiJackThis logy a logy z dalších programů…

Moderátoři: Mods_senior, Security team

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Prosím o kontrolu logu

Příspěvekod Bretal » 04 říj 2022 08:49

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:48:42, on 04.10.2022
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.1566)


Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Users\bretislav.lebloch\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\105.0.1343.53\BHO\ie_to_edge_bho.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~2\Office16\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\bretislav.lebloch\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CiscoSpark] C:\Users\bretislav.lebloch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Webex\Webex.lnk /minimized /autostartedWithWindows=true
O4 - HKCU\..\Run: [com.squirrel.Teams.Teams] C:\Users\bretislav.lebloch\AppData\Local\Microsoft\Teams\Update.exe --processStart "Teams.exe" --process-start-args "--system-initiated"
O4 - HKCU\..\Run: [MicrosoftEdgeAutoLaunch_F4D67F32E862673C7C6D7218AEF13601] "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --no-startup-window --win-session-start /prefetch:5
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\PROGRA~2\MICROS~2\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Poslat do On&eNotu - res://C:\PROGRA~2\MICROS~2\Office16\ONBttnIE.dll/105
O9 - Extra button: Poslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Poslat do On&eNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = zshorninemci.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = zshorninemci.local
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: 602Updater (602XML Updater) - Software602 a.s. - C:\Program Files (x86)\Common Files\soft602\602updsvc\602updsvc.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Inc. - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - AMD - C:\Windows\System32\DriverStore\FileRepository\u0373234.inf_amd64_2f2bf0ce197fd0ec\B371260\atiesrxx.exe
O23 - Service: AtherosSvc - Unknown owner - C:\Windows\System32\drivers\AdminService.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_1dc9fc8d5e442f6a\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_1dc9fc8d5e442f6a\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_18cf2b6c - Unknown owner - C:\Windows\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET HTTP Server (EHttpSrv) - ESET - C:\Program Files\ESET\ESET Security\ehttpsrv.exe
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Security\ekrn.exe
O23 - Service: ESET Firewall Helper (ekrnEpfw) - ESET - C:\Program Files\ESET\ESET Security\ekrn.exe
O23 - Service: ESET Management Agent (EraAgentSvc) - ESET - C:\Program Files\ESET\RemoteAdministrator\Agent\ERAAgent.exe
O23 - Service: @oem12.inf,%ServiceDisplayName%;ESIF Upper Framework Service (esifsvc) - Unknown owner - C:\Windows\System32\Intel\DPTF\esif_uf.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Intel(R) Graphics Command Center Service (igccservice) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_003a6d3c4c50c291\OneApp.IGCC.WinService.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_12ed482042e0dee5\igfxCUIService.exe
O23 - Service: @oem67.inf,%SocketHECIServiceName%;Intel(R) Capability Licensing Service TCP IP Interface (Intel(R) Capability Licensing Service TCP IP Interface) - Intel(R) Corporation - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\SocketHeciServer.exe
O23 - Service: @oem67.inf,%TPMProvisioningServiceName%;Intel(R) TPM Provisioning Service (Intel(R) TPM Provisioning Service) - Intel(R) Corporation - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\TPMProvisioningService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\Windows\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: SACSrv - Gemalto - C:\Program Files\SafeNet\Authentication\SAC\x64\SACSRV.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\Windows\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer - TeamViewer Germany GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Intel(R) Management Engine WMI Provider Registration (WMIRegistrationService) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_cad1db73e8c782a6\WMIRegistrationService.exe
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12194 bytes
Heslo:"Lepší živý posera, než mrtvý hrdina."

Reklama
Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 04 říj 2022 15:14

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = zshorninemci.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = zshorninemci.local

tohle Ti něco říká?

Stáhni si ATF Cleaner
https://www.majorgeeks.com/mg/getmirror ... ner,2.html
Poklepej na ATF Cleaner.exe, klikni na select all, poté:
-Když používáš Firefox (Mozzila), klikni na Firefox nahoře a vyber: Select All, poté klikni na Empty Selected.
-Když používáš Operu, klikni nahoře na Operu a vyber: Select All, poté klikni na Empty Selected. Poté klikni na Main (hlavní stránku ) a klikni na Empty Selected.
Po vyčištění klikni na Exit k zavření programu.
ATF-Cleaner je jednoduchý nástroj na odstranění historie z webového prohlížeče. Program dokáže odstranit cache, cookies, historii a další stopy po surfování na Internetu. Mezi podporované prohlížeče patří Internet Explorer, Firefox a Opera. Aplikace navíc umí odstranit dočasné soubory Windows, vysypat koš atd.
- Pokud používáš jen Google Chrome ,Edge , tak ATF nemusíš použít.


Stáhni si TFC
http://www.geekstogo.com/forum/files/fi ... -oldtimer/
Otevři soubor a zavři všechny ostatní okna, Klikni na Start k zahájení procesu. Program by neměl trvat dlouho.
Poté by se měl PC restartovat, pokud ne , proveď sám.

Stáhni AdwCleaner (by Xplode)
http://www.bleepingcomputer.com/download/adwcleaner/
http://www.adlice.com/downloadprogress/
pro majitele win7 stáhni zde:
https://filehippo.com/download_adwcleaner/ ( nedávej aktualizaci!)

Ulož si ho na svojí plochu . Klikni na „Souhlasím“ k povrzení podmínek.
Ukonči všechny programy , okna a prohlížeče
Spusť program poklepáním a klikni na „Skenování“
Po skenu se objeví log , který se otevře. ( jinak je uložen systémovem disku jako) C:\AdwCleaner\Logs, jeho obsah sem celý vlož.

Stáhni si Malwarebytes' Anti-Malware
https://www.malwarebytes.com/mwb-download/thankyou/

na plochu , nainstaluj a spusť ho
-Pokud není program aktuální , klikni na možnost „Aktualizovat nyní“ či „Opravit nyní“.
- bude nalezena aktualizace a nainstaluje se.
- poté klikni na Spustit skenování
- po proběhnutí skenu se ti objeví hláška vpravo dole, tak klikni na Zobrazit zprávu a vyber Export a vyber Kopírovat do schránky a vlož sem celý log. Nebo klikni na „Textový soubor ( .txt)“ a log si ulož.
-jinak se log nachází v programu po kliknutí na „Zprávy“ , nebo je uložen zde: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs

- po té klikni na tlačítko Dokončit, a program zavři křížkem vpravo nahoře.
(zatím nic nemaž!).
Pokud budou problémy , spusť v nouz. režimu.
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu

Příspěvekod Bretal » 05 říj 2022 09:40

Log z Malwarebytes:

# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build: 08-30-2022
# Database: 2022-08-22.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Scan
# -------------------------------
# Start: 10-05-2022
# Duration: 00:00:09
# OS: Windows 10 (Build 19044.2006)
# Scanned: 32095
# Detected: 2


***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
PUP.Optional.Legacy HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries found.

***** [ Chromium URLs ] *****

No malicious Chromium URLs found.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries found.

***** [ Firefox URLs ] *****

No malicious Firefox URLs found.

***** [ Hosts File Entries ] *****

No malicious hosts file entries found.

***** [ Preinstalled Software ] *****

No Preinstalled Software found.



########## EOF - C:\AdwCleaner\Logs\AdwCleaner[S00].txt ##########
Heslo:"Lepší živý posera, než mrtvý hrdina."

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu

Příspěvekod Bretal » 05 říj 2022 09:50

Ještě k tomu Malwarebytes hlásil něco do karantény. Co s tím?

Díky.
Heslo:"Lepší živý posera, než mrtvý hrdina."

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 05 říj 2022 15:01

Máte vložit log , jinak nevím o co se jedná. Dejte tedy do karantény a vložte sem potom log.

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = zshorninemci.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = zshorninemci.local

tohle Ti něco říká?


+
Spusť znovu AdwCleaner (u Windows Vista či Windows7, klikni na AdwCleaner pravým a vyber „Spustit jako správce
klikni na „Skenování“ , po prohledání klikni na „ do karantény

Program provede opravu, po automatickém restartu klikni na Zobrazit logovací soubor“ a pak poklepej na odpovídají log, (C:\AdwCleaner [C?].txt) , jeho obsah sem celý vlož.

Stáhni si Junkware Removal Tool by Thisisu
http://www.bleepingcomputer.com/downloa ... oval-tool/
https://downloads.malwarebytes.com/file/JRT-EOL
na svojí plochu.

Deaktivuj si svůj antivirový program. Pravým tl. myši klikni na JRT.exe a vyber „spustit jako správce“. Pro pokračování budeš vyzván ke stisknutí jakékoliv klávesy. Na nějakou klikni.
Začne skenování programu. Skenování může trvat dlouho , podle množství nákaz. Po ukončení skenu se objeví log (JRT.txt) , který se uloží na ploše.
Zkopíruj sem prosím celý jeho obsah.


Sophos Virus Removal Tool je praktický softwarový nástroj, který by mohl odstranit infekce, které antivirový program nedetekuje .
Stáhněte si ho zde z některého odkazu:
https://www.majorgeeks.com/mg/getmirror ... ool,1.html
https://www.majorgeeks.com/mg/get/sopho ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,1.html
http://www.majorgeeks.com/mg/getmirror/ ... ool,2.html

Viry mohou zpomalit počítač, nebo se snaží ukrást vaše data, a ani nevíte , že je máte. Co potřebujete, je rychlý a snadný způsob, jak je najít a zbavit se jich, pokud již máte antivirový program v počítači nainstalován , můžete nainstalovat i nástroj Sophos Virus Removal , který identifikuje a vyčistí zbylé infekce, které mohl Váš antivirový program přehlédnout.
K použití Sophos Virus Removal Tool na něj poklepejte a stiskněte tlačítko „Start scanning“ . Pak bude Sophos Virus Removal Tool vyhledávat a odstraňovat viry, které najde. Může být vyžadován restart.
Pokud byly nalezeny viry , tak po skenu klikni na „Details…“ a potom na „View log file“. Zkopíruj celý log a vlož ho sem. Potom zavři „threat detail“ a klikni na „Start cleanup“.
Jinak se log nachází zde:
C:\ProgramData\Sophos\Sophos Virus Removal Tool\Logs

Stáhni si RogueKiller by Adlice Software
http://www.adlice.com/download/roguekiller/
http://www.bleepingcomputer.com/download/roguekiller/
na svojí plochu.
- Zavři všechny ostatní programy a prohlížeče.
- - klikni na „Scan“. V novém okně nic neměň a klikni dole na „Start“ ve sloupci „Quick Scan“
- Program skenuje procesy PC. Po proskenování klikni na „Results “ , v dalším okně pak levým t. na „Export“ a vyber : „Text File“ , log nazvi třeb RK a ulož do dokumentů nebo na plochu. Otevři soubor a celý obsah logu sem zkopíruj.
Pokud je program blokován , zkus ho spustit několikrát. Pokud dále program nepůjde spustit a pracovat, přejmenuj ho na winlogon.exe.
-pokud bude mít log více než 60.000 znaků , rozděl ho a vlož do více příspěvků
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu

Příspěvekod Bretal » 05 říj 2022 15:15

Log Z MAlwarebytes:
# -------------------------------
# Malwarebytes AdwCleaner 8.4.0.0
# -------------------------------
# Build: 08-30-2022
# Database: 2022-08-22.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 10-05-2022
# Duration: 00:00:01
# OS: Windows 10 (Build 19044.2006)
# Cleaned: 2
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\dotomi.com
Deleted HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\dotomi.com

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1833 octets] - [05/10/2022 08:35:54]
AdwCleaner[S01].txt - [1894 octets] - [05/10/2022 09:41:40]
AdwCleaner[S02].txt - [1955 octets] - [05/10/2022 09:46:52]
AdwCleaner[S03].txt - [2016 octets] - [05/10/2022 15:11:07]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C03].txt ##########


Tam ty dva řádky, jak jsi posílal odkaz, tak mi to říká akorát to, že pracuju na takové WiFi ZS Horninemci a asi se tak možná jmenuje i náš pracovní server, ale jsem úplné poleno, tak se omlouvám, že je to se mnou trochu složitější. Děkuji za rady trpělivost.
Heslo:"Lepší živý posera, než mrtvý hrdina."

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu

Příspěvekod Bretal » 05 říj 2022 15:22

Log z JRT
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 10 Enterprise x64
Ran by bretislav.lebloch (Administrator) on 05.10.2022 at 15:19:23,29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 2

Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C} (Registry Key)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 05.10.2022 at 15:20:24,05
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Heslo:"Lepší živý posera, než mrtvý hrdina."

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu

Příspěvekod Bretal » 05 říj 2022 16:32

Sophos nic nenašel.
Heslo:"Lepší živý posera, než mrtvý hrdina."

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu

Příspěvekod Bretal » 05 říj 2022 16:37

Log z RougKilleru:
Program : RogueKiller Anti-Malware
Version : 15.6.1.0
x64 : Yes
Program Date : Sep 13 2022
Location : C:\Program Files\RogueKiller\RogueKiller64.exe
Premium : No
Company : Adlice Software
Website : https://www.adlice.com/
Contact : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 10 (10.0.19044) 64-bit
64-bit OS : Yes
Startup : 0
WindowsPE : No
User : bretislav.lebloch
User is Admin : Yes
Date : 2022/10/05 14:36:29
Type : Scan
Aborted : No
Scan Mode : Quick
Duration : 13
Found items : 0
Total scanned : 955
Signatures Version : 20221003_071758
Truesight Driver : Yes
Updates Count : 0
Arguments : -minimize

************************* Warnings *************************

************************* Processes *************************

************************* Modules *************************

************************* Services *************************

************************* Scheduled Tasks *************************

************************* Registry *************************

************************* WMI *************************

************************* Hosts File *************************
is_too_big : No
hosts_file_path : N/A


************************* Filesystem *************************

************************* Web Browsers *************************

************************* Antirootkit *************************
Heslo:"Lepší živý posera, než mrtvý hrdina."

Uživatelský avatar
jaro3
člen Security týmu
Guru Level 15
Guru Level 15
Příspěvky: 43054
Registrován: červen 07
Bydliště: Jižní Čechy
Pohlaví: Muž
Stav:
Offline

Re: Prosím o kontrolu logu

Příspěvekod jaro3 » 05 říj 2022 18:09

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = zshorninemci.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = zshorninemci.local

tohle Ti něco říká?


Vypni antivir i firewall, RogueKiller, Malwarebytes Antimalware, windowsDefender
Stáhni Zoek.exe
http://download.bleepingcomputer.com/smeenk/zoek.exe
https://uloz.to/file/nFH1LwSrGioP/zoek1-rar

Zavři všechny ostatní programy , okna i prohlížeče.
Spusť Zoek.exe ( u win vista , win7, 8 klikni na něj pravým a vyber : „Spustit jako správce“
-pozor , náběh programu může trvat déle.
Do okna programu vlož skript níže:

Kód: Vybrat vše

autoclean;
resethosts;
emptyclsid;
IEdefaults;
FFdefaults;
CHRdefaults;
emptyIEcache;
emptyFFcache;
emptyCHRcache;
emptyalltemp;
emptyflash;
emptyjava;
emptyrecycle.bin;

klikni na Run Script
Program provede sken , opravu, sken i oprava může trvat i více minut ,je třeba posečkat do konce. Do okna neklikej!
Program nabídne restart , potvrď .
Po restartu se může nějaký čas ukázat pouze černá plocha , to je normální. Je třeba počkat až se vytvoří log. Ten si můžeš uložit třeba do dokumentů , jinak se sám ukládá do:
C:\zoek-results.log Zkopíruj sem celý obsah toho logu.
Pokud budou problémy , spusť zoek v nouz. režimu.


Stáhni si Zemana AntiMalware Free z tohoto odkazu:
https://www.zemana.com/Download/AntiMal ... .Setup.exe

(posuvník dolu na download)
a ulož si ho na plochu.
Poklepej na tento soubor na ploše a postupuj podle pokynů k instalaci programu.
Přijmi licenci k používání programu EULA , pokud se nabídne.
Pokud je k dispozici aktualizace programu , klepni na tlačítko „Update now“ ( aktualizovat nyní).
Zavři všechny otevřené soubory, složky a prohlížeče
Neměň žádné nastavení. Klikni na „Skenovat nyní“.
Po skenu lze vidět , zda jsou nějaké nákazy. Klikni na „Vykonat“ ( vymazat). Nákazy budou přemístěny do karantény.
Když je skenování dokončeno, klikni vlevo na „zprávy“ a pak na „otevři zprávu“ a zkopíruj sem celý obsah té zprávy.

Vlož nový log z HJT + informuj o problémech
Při práci s programy HJT, ComboFix,MbAM, SDFix aj. zavřete všechny ostatní aplikace a prohlížeče!
Neposílejte logy do soukromých zpráv.Po dobu mé nepřítomnosti mě zastupuje memphisto , Žbeky a Orcus.
Pokud budete spokojeni , můžete podpořit naše forum:Podpora fóra

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu

Příspěvekod Bretal » 05 říj 2022 18:20

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = zshorninemci.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = zshorninemci.local
Vůbec nevím co to znamená, vím jen, že na ZS Horni Němčí pracuju a jmenuje se tak naše wifi síť, možná i server, na který se automaticky napojuju, když se v práci přihlásím. Jinak vůbec nevím, co by to mohlo být. Omlouvám se, že asi nedávám pořádnou odpoveď, ale jsem totál amatér.
Heslo:"Lepší živý posera, než mrtvý hrdina."

Bretal
Level 2.5
Level 2.5
Příspěvky: 290
Registrován: leden 08
Bydliště: UH
Pohlaví: Nespecifikováno
Stav:
Offline
Kontakt:

Re: Prosím o kontrolu logu

Příspěvekod Bretal » 05 říj 2022 18:57

ZOEK:
Zoek.exe v5.0.0.2 Updated 03-May-2018(Online Version)
Tool run by bretislav.lebloch on 05.10.2022 at 18:24:11,56.
Microsoft Windows 10 Pro 10.0.19044 x64
Running in: Normal Mode Internet Access Detected
Launched: C:\Users\bretislav.lebloch\Desktop\zoek1\zoek (1).exe [Scan all users] [Script inserted]

==== System Restore Info ======================

05.10.2022 18:25:17 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\Illusion deleted successfully
C:\PROGRA~3\SoftwareDistribution deleted successfully
C:\PROGRA~3\ssh deleted successfully
C:\Users\bretislav.lebloch\AppData\Roaming\602XML deleted successfully
C:\Users\admin\AppData\Local\PlaceholderTileLogoFolder deleted successfully
C:\Users\admin\AppData\Local\VirtualStore deleted successfully
C:\Users\bretislav.lebloch\AppData\Local\PeerDistRepub deleted successfully
C:\Users\servis1\AppData\Local\VirtualStore deleted successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistPub deleted successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\PeerDistRepub deleted successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Packages deleted successfully

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\BRETIS~1.LEB\AppData\Roaming\Mozilla\Firefox\Profiles\qinpcg0u.default-release\prefs.js:

Added to C:\Users\BRETIS~1.LEB\AppData\Roaming\Mozilla\Firefox\Profiles\qinpcg0u.default-release\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

C:\PROGRA~2\Illusion not found
C:\Users\bretislav.lebloch\AppData\Roaming\Twine deleted
C:\PROGRA~3\Package Cache deleted
C:\Users\bretislav.lebloch\AppData\Local\PlariumPlay.log deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\CM241D6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\CM2E9C1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7ae2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7ae4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7af6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7af8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7afa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7afc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b0d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b0f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b11.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b13.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b25.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b27.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b29.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b2b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b3d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b3f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b41.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b43.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-11f0-116c-1c7b54.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9e4d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9e7e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9e80.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9e82.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9e93.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9eb5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9ee6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f16.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f18.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f1a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f3c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f4d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f5f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f61.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f73.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f75.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f77.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9f88.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1320-e8c-51e9fa9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a679.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a67b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a67d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a67f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a690.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a692.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a694.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6a6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6a8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6aa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6ac.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6be.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6c0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6c2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6d3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6d5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6d7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6e9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1428-568-43a6eb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d76c4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d76d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d76d8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d76da.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d76ec.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d76ee.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d76f0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7701.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7703.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7705.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7717.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7719.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d771b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d772d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d772f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7731.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7742.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7744.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-15f0-1390-d7746.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ab0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ab2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ac4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ac6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ac8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262aca.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262acc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ade.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ae0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ae2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ae4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262ae6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262af7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262af9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262afb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-177c-24b0-262afd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e908.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e91a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e91c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e91e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e92f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e931.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e933.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e935.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e947.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e949.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e94b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e94d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e96e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e970.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e972.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e974.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e986.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e988.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-17a0-2570-27e98a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219aa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219ac.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219be.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219c0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219c2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219c4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219d8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219da.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219dc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219ed.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219ef.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-2219f1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-221a03.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-221a05.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-221a07.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-221a09.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-221a0b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-18e0-1060-221a1c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b27c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b27e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b290.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b292.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b2b3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b2d4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b2f5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b307.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b319.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b32a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b34b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b36d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b38e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b3a0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b3a2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b3b3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b3c5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b3d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1908-728-26b3d8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fbfba.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fbfbc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fbfbe.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fbfc0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc11a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc3fa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc498.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc4f8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc50a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc52b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc53d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc58d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc63b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc67b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc68d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc69e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc6fe.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc72f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1918-bdc-42fc750.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268e98.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268eaa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268ebc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268ecd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268ecf.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268ef1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268ef3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268f14.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268f25.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268f37.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268f39.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268f5a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268f7c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268f8d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268fae.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268fd0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268fe1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-268ff3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a1c-32fc-269005.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5b1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5b3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5c5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5c7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5d8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5da.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5dc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5ee.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d5f0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d601.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d603.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d605.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d617.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d619.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d62b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d62d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d62f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d640.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1a60-16b0-37d642.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a129a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12ac.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12ae.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12b0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12b2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12c4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12c6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12c8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12d9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12db.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12dd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12ef.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12f1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12f3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a12f5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a1307.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a1309.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a130b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1b70-30b8-a130d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-3854371.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-3854382.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-3854384.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-3854396.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-3854398.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543a9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543ab.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543ad.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543bf.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543c1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543d3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543d5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543e6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-38543e8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-385440a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-385440c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-385441d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-385442f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1bc0-275c-3854440.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fb6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fb8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fca.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fcc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fce.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fe0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fe2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fe4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9fe6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9ff7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9ff9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9ffb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4c9ffd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4ca00f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4ca011.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4ca013.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4ca015.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4ca027.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1c48-20a0-4ca029.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f76b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f77c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f78e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f79f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f7b1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f7b3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f7d4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f7d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f7f8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f7fa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f81b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f81d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f82e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f850.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f861.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f892.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f8a4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f8c5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1ddc-19f0-282f8c7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d4d4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d4d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d4d8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d4ea.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d4fb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d4fd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d4ff.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d501.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d513.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d515.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d526.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d528.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d52a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d53c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d53e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d540.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d552.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d554.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1dfc-25e0-10d556.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7a98.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7bc3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7c90.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7ce0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7ce2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7ce4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7cf6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7cf8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7cfa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d0b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d0d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d0f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d11.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d23.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d25.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d27.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d29.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d3b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1e4c-2514-e7d3d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de96f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de980.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de982.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de984.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de996.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de998.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de99a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9ac.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9ae.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9bf.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9c1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9c3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9d5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9d7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9e9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9eb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5de9ed.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5dea1d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-1f08-1f64-5dea1f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9b6e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9b9f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9ba1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9bb2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9bb4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9bc6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9bd8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9bda.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9beb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9bfd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9bff.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9c01.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9c12.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9c14.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9c26.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9c38.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9c3a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9c4b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-21c8-1ffc-2f9c4d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551afa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b0c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b0e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b10.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b12.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b23.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b25.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b37.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b39.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b3b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b3d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b4f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b51.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b53.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b64.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b66.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b68.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b7a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-24ec-d44-551b7c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5883.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5894.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa58c5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa58f6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5917.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5919.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa592b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa592d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa594e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa596f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa59a0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa59b2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa59c4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa59f4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5a06.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5a18.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5a39.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5a3b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26b0-aec-aa5a5c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-36894b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-36894d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-36896e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-368970.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-368972.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-368974.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-368986.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-368988.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-36899a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-36899c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-36899e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-3689af.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-3689b1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-3689b3.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-3689c5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-3689c7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-3689c9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-3689db.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c0-307c-3689dd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbdd6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbde8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbdea.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbdfb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbdfd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbdff.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe01.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe13.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe15.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe27.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe29.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe2b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe3c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe3e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe40.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe52.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe54.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe56.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-26c8-1cc8-fbe67.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d6d6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d6e7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d6e9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d6eb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d6ed.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d6ff.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d701.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d703.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d714.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d716.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d718.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d71a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d72c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d72e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d730.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d742.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d744.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d746.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-27f4-268c-17d757.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-3624b5.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-3624b7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-3624c9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-3624cb.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-3624dc.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-3624ee.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-3624f0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362502.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362513.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362515.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362537.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362539.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-36254a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-36254c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-36255e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362560.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362571.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362583.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2858-2b28-362585.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c28.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c2a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c3c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c3e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c40.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c42.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c53.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c55.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c67.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c69.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c6b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c7d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c7f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c81.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c92.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c94.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19c96.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19ca8.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2940-1218-1d19caa.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-95277.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-95279.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-9528b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-9528d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-9528f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952a0.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952a2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952b4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952b6.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952c7.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952c9.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952db.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952dd.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952ef.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-952f1.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-95302.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-95304.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-95345.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2b84-2f18-95356.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-965ff.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96601.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96613.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96615.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96626.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96628.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-9662a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-9663c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-9663e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96640.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96651.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96653.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96655.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96657.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96669.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-9666b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-9666d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-9667f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2cb0-20ec-96681.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128013.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128025.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128036.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128038.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-12803a.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-12804c.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-12804e.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128050.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128052.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128063.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128065.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128067.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128079.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-12807b.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-12807d.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-12808f.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-128091.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-1280a2.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ddc-2060-1280a4.tmp deleted
C:\Windows\SysNative\config\systemprofile\AppData\Local\tw-2ec-1304-1ceab69.tmp deleted
Heslo:"Lepší živý posera, než mrtvý hrdina."


Zpět na “HiJackThis”

Kdo je online

Uživatelé prohlížející si toto fórum: Žádní registrovaní uživatelé a 12 hostů