Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

V normálním módu nelze spustit žádný program

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

V normálním módu nelze spustit žádný program

#1 Příspěvek od detox »

Instalace programu údajně na záchranu fotek z androidu.. instalaci jsem spustil, ale ihned mi bylo jasné že to není real. Ukončil jsem hned, ale již zde byl SafeSearchFinder ktery sem odstranil a odinstaloval, MWB scan něco našel a odstranil, pak vyžádal restart - po restartu již nelze nic spustit.

Momentálně v nouzovém módu.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-06-2016
Ran by Host (administrator) on PC (19-06-2016 17:15:50)
Running from C:\Users\Host\Downloads
Loaded Profiles: Host (Available Profiles: Host)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3037296 2011-05-06] (VIA)
HKU\S-1-5-21-2504773853-1791968555-2413179023-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2504773853-1791968555-2413179023-1000\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3582240 2016-06-02] (Nota Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
Startup: C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-06-19]
ShortcutTarget: Dropbox.lnk -> C:\Users\Host\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{B8F47EBA-74B8-4DC5-81F9-423112F16554}: [NameServer] 8.8.8.8,8.8.4.4,4.2.2.1,4.2.2.2,208.67.222.222,208.67.220.220,8.26.56.26,8.20.247.20,156.154.70.1,156.154.71.1
Tcpip\..\Interfaces\{D3AE1677-8D67-4074-8806-8E40612429C5}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2504773853-1791968555-2413179023-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

FireFox:
========
FF ProfilePath: C:\Users\Host\AppData\Roaming\Mozilla\Firefox\Profiles\bc89wx67.default
FF Homepage: hxxps://www.malwarebytes.org/restorebrowser/
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Peete\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-12] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Host\AppData\Roaming\Mozilla\Firefox\Profiles\bc89wx67.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28]
FF HKU\S-1-5-21-2504773853-1791968555-2413179023-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [not signed]

Chrome:
=======
CHR HomePage: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0Qo54vWR8nn8udyB3gSocMZdWbXllAnmIqhg_sb8PUkLJdOk-0Q0Nv7TxU-e_2uSNZ5VsYLTCRKnlBEL9iqhSVXxFVwR7UlJxz2S1XibtmZx-BzevUKw9eNAJI6VC5cZTuIiwHET92vFzXC0SzPfVLvypZg,,
CHR DefaultSearchURL: Default -> hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0Qo54vWR8nn8udyB3gSocMZdWbXllAnmIqhg_sb8PUkLJdOk-0Q0Nv7TxU-e_2uSNa7UoY0WIaZ9e8M2tjyKAqYyQ5doZy9lF7YUEF54Li4wh7gkG0jnl3pEmrgK8Os2mO0p4tyL_wVmIFraE3dvT_xS1Sg,,&q={searchTerms}
CHR DefaultSearchKeyword: Default -> feed.sonic-search.com
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command={searchTerms}
CHR Profile: C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-18]
CHR Extension: (BetterTTV) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2016-06-03]
CHR Extension: (Dokumenty Google) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-18]
CHR Extension: (Disk Google) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-18]
CHR Extension: (YouTube) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-18]
CHR Extension: (Tabulky Google) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-18]
CHR Extension: (Dokumenty Google offline) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-18]
CHR Extension: (AdBlock) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-06-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-24]
CHR Extension: (Gmail) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-18]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Plán2\schedul2.exe [1055200 2010-06-03] ()
S2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [90112 2009-08-19] (ASUSTeK Computer Inc.) [File not signed]
S3 DAUpdaterSvc; C:\Peete\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-12-15] (BioWare)
S2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] ()
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-12] (NVIDIA Corporation)
S2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-21] (Microsoft Corporation)
S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [724992 2006-10-09] (Nero AG) [File not signed]
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
S2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] ()
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-12] (NVIDIA Corporation)
S4 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-12] (NVIDIA Corporation)
S2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1072296 2016-06-18] (Enigma Software Group USA, LLC.)
S2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-03-29] (VIA Technologies, Inc.)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.2.1.5\WsAppService.exe [412672 2016-06-02] (Wondershare) [File not signed]
S3 WsDrvInst; C:\Program Files (x86)\Wondershare\Dr.Fone for Android\DriverInstall.exe [115856 2016-06-07] (Wondershare)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-13] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2016-06-18] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2016-06-18] ()
S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-12] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R0 tdrpman258; C:\Windows\System32\DRIVERS\tdrpm258.sys [1477728 2013-07-01] (Acronis)
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [119712 2016-04-28] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [192352 2016-04-28] (Oracle Corporation)
S3 gkernel; \??\C:\Users\Host\AppData\Local\Temp\gkernel.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-19 17:15 - 2016-06-19 17:19 - 00016884 _____ C:\Users\Host\Downloads\FRST.txt
2016-06-19 17:15 - 2016-06-19 17:15 - 02387456 _____ (Farbar) C:\Users\Host\Downloads\FRST64.exe
2016-06-19 17:08 - 2016-06-19 17:09 - 00102684 _____ C:\Windows\ntbtlog.txt
2016-06-19 05:10 - 2016-06-19 16:21 - 00000080 _____ C:\Users\Host\Desktop\VirtualBox - zástupce.lnk
2016-06-18 17:49 - 2016-06-19 16:22 - 00001371 _____ C:\Users\Public\Desktop\EaseUS MobiSaver for Android.lnk
2016-06-18 17:49 - 2016-06-18 17:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS MobiSaver for Android
2016-06-18 17:49 - 2016-06-18 17:49 - 00000000 ____D C:\Program Files (x86)\EaseUS
2016-06-18 17:48 - 2016-06-18 17:48 - 22142184 _____ (CHENGDU YIWO Tech Development Co., Ltd. ) C:\Users\Host\Downloads\emsa_free.exe
2016-06-18 17:48 - 2016-06-18 17:48 - 00000000 ____D C:\ProgramData\wsr
2016-06-18 17:34 - 2016-06-19 16:20 - 00001131 _____ C:\Users\Host\Desktop\SpyHunter.lnk
2016-06-18 17:34 - 2016-06-18 17:34 - 00003310 _____ C:\Windows\System32\Tasks\SpyHunter4Startup
2016-06-18 17:34 - 2016-06-18 17:34 - 00000000 ____D C:\Users\Host\AppData\Roaming\Enigma Software Group
2016-06-18 17:34 - 2016-06-18 17:34 - 00000000 ____D C:\sh4ldr
2016-06-18 17:34 - 2016-06-18 17:34 - 00000000 _____ C:\autoexec.bat
2016-06-18 17:33 - 2016-06-18 17:33 - 03482800 _____ (Enigma Software Group USA, LLC.) C:\Users\Host\Downloads\SpyHunter-Installer.exe
2016-06-18 17:33 - 2016-06-18 17:33 - 00022704 _____ C:\Windows\system32\Drivers\EsgScanner.sys
2016-06-18 17:33 - 2016-06-18 17:33 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-06-18 17:22 - 2016-06-18 17:46 - 00000000 ___HD C:\DrFoneForAndroid
2016-06-18 17:16 - 2016-06-18 17:16 - 06867968 _____ C:\Users\Host\AppData\Roaming\agent.dat
2016-06-18 17:16 - 2016-06-18 17:16 - 00018432 _____ C:\Users\Host\AppData\Roaming\Main.dat
2016-06-18 17:16 - 2016-06-18 17:15 - 01106432 _____ C:\Users\Host\AppData\Roaming\Vaiain.exe
2016-06-18 17:16 - 2016-06-18 17:15 - 01106432 _____ C:\Users\Host\AppData\Roaming\Doublefan.exe
2016-06-18 17:15 - 2016-06-18 17:15 - 00128512 _____ C:\Users\Host\AppData\Roaming\Installer.dat
2016-06-18 16:57 - 2016-06-18 16:57 - 00000000 ____D C:\Users\Host\AppData\Roaming\HMYGSetting
2016-06-18 16:57 - 2016-06-18 16:57 - 00000000 ____D C:\Users\Host\.android
2016-06-18 16:55 - 2016-06-19 16:22 - 00002191 _____ C:\Users\Public\Desktop\Wondershare Dr.Fone for Android.lnk
2016-06-18 16:55 - 2016-06-18 16:57 - 00000000 ____D C:\ProgramData\Wondershare
2016-06-18 16:55 - 2016-06-18 16:55 - 00000000 ___HD C:\Program Files (x86)\DrFoneAndroid_Temp
2016-06-18 16:55 - 2016-06-18 16:55 - 00000000 ____D C:\Users\Public\Documents\Wondershare
2016-06-18 16:55 - 2016-06-18 16:55 - 00000000 ____D C:\Users\Host\AppData\Roaming\Wondershare
2016-06-18 16:55 - 2016-06-18 16:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2016-06-18 16:55 - 2016-06-18 16:55 - 00000000 ____D C:\Program Files (x86)\Wondershare
2016-06-18 16:55 - 2016-05-27 09:41 - 00000232 _____ C:\Windows\SysWOW64\dllhost.exe.config
2016-06-18 16:54 - 2016-06-18 16:54 - 01192592 _____ C:\Users\Host\Downloads\drfone-for-android_setup_full1464.exe
2016-06-18 16:43 - 2016-06-18 16:43 - 00000000 ____D C:\Users\Host\AppData\Roaming\R-TT
2016-06-18 16:42 - 2016-06-18 16:43 - 00000000 ____D C:\Users\Host\Documents\R-TT
2016-06-18 16:42 - 2016-06-18 16:42 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\R-Studio
2016-06-18 16:42 - 2016-06-18 16:42 - 00000000 ____D C:\Program Files (x86)\R-Studio
2016-06-18 16:41 - 2016-06-18 16:41 - 42706536 _____ (R-Tools Technology Inc.) C:\Users\Host\Downloads\RStudio8.exe
2016-06-18 16:37 - 2016-06-18 16:37 - 00164192 _____ C:\Users\Host\Downloads\restoration.zip
2016-06-15 22:05 - 2016-06-15 22:05 - 00236086 _____ C:\Users\Host\Downloads\testy.rar
2016-06-14 22:50 - 2016-06-14 22:50 - 06608965 _____ C:\Users\Host\Downloads\crazymembpack 4.3 + individual maps + screenshots (1).rar
2016-06-14 22:26 - 2016-06-14 22:26 - 06608965 _____ C:\Users\Host\Downloads\crazymembpack 4.3 + individual maps + screenshots.rar
2016-06-14 22:17 - 2016-05-18 18:10 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-06-14 22:17 - 2016-05-18 18:09 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-06-14 22:17 - 2016-05-12 19:15 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-06-14 22:17 - 2016-05-12 17:18 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-06-14 22:17 - 2016-05-11 19:02 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2016-06-14 22:17 - 2016-05-11 19:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2016-06-14 22:17 - 2016-05-11 19:02 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2016-06-14 22:17 - 2016-05-11 17:19 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2016-06-14 22:17 - 2016-05-11 17:19 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2016-06-14 22:17 - 2016-05-11 17:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2016-06-14 22:17 - 2016-05-11 17:11 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2016-06-14 22:17 - 2016-05-11 17:01 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2016-06-14 22:17 - 2016-05-11 16:58 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2016-06-14 22:16 - 2016-06-06 18:58 - 00041704 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-06-14 22:16 - 2016-06-06 18:50 - 01204224 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-06-14 22:16 - 2016-06-03 15:05 - 01413120 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-06-14 22:16 - 2016-05-27 15:06 - 00569856 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-06-14 22:16 - 2016-05-27 15:06 - 00544256 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-06-14 22:16 - 2016-05-27 15:06 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-06-14 22:16 - 2016-05-27 15:06 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2016-06-14 22:16 - 2016-05-22 15:06 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-06-14 22:16 - 2016-05-14 00:15 - 00382184 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-06-14 22:16 - 2016-05-14 00:09 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-06-14 22:16 - 2016-05-14 00:09 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-06-14 22:16 - 2016-05-14 00:09 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-06-14 22:16 - 2016-05-14 00:09 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-06-14 22:16 - 2016-05-13 23:54 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-06-14 22:16 - 2016-05-13 23:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-06-14 22:16 - 2016-05-13 23:49 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-06-14 22:16 - 2016-05-13 23:49 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-06-14 22:16 - 2016-05-13 23:27 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-06-14 22:16 - 2016-05-12 19:20 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-06-14 22:16 - 2016-05-12 19:20 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-06-14 22:16 - 2016-05-12 19:15 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-06-14 22:16 - 2016-05-12 19:15 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-06-14 22:16 - 2016-05-12 19:15 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-06-14 22:16 - 2016-05-12 19:15 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-06-14 22:16 - 2016-05-12 17:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-06-14 22:16 - 2016-05-12 16:58 - 00464896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-06-14 22:16 - 2016-05-12 16:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-06-14 22:16 - 2016-05-12 16:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-06-14 22:16 - 2016-05-12 16:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-06-14 22:16 - 2016-05-12 15:05 - 00459640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-06-14 22:16 - 2016-05-12 15:05 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2016-06-14 22:16 - 2016-05-12 15:04 - 00249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2016-06-14 22:16 - 2016-05-11 19:02 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2016-06-14 22:16 - 2016-05-11 17:19 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2016-06-14 22:15 - 2016-05-12 19:15 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00794624 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00793088 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00502272 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2016-06-14 22:15 - 2016-05-12 19:14 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00591872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
2016-06-14 22:15 - 2016-05-12 17:06 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.exe
2016-06-14 22:15 - 2016-05-12 17:03 - 03217408 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-06-14 22:15 - 2016-05-12 16:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.dll
2016-06-14 22:15 - 2016-05-12 16:57 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.exe
2016-06-14 22:15 - 2016-03-09 21:00 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2016-06-14 22:15 - 2016-03-09 20:40 - 00316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2016-06-14 22:14 - 2016-04-14 18:46 - 00114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2016-06-14 22:14 - 2016-04-14 18:42 - 03243520 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-06-14 22:14 - 2016-04-14 18:42 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-06-14 22:14 - 2016-04-14 18:42 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2016-06-14 22:14 - 2016-04-14 18:42 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2016-06-14 22:14 - 2016-04-14 18:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2016-06-14 22:14 - 2016-04-14 17:33 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2016-06-14 22:14 - 2016-04-14 17:33 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-06-14 22:14 - 2016-04-14 17:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2016-06-14 22:14 - 2016-04-14 17:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2016-06-14 22:14 - 2016-04-14 17:19 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2016-06-14 22:14 - 2016-04-14 17:11 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2016-06-14 22:14 - 2016-04-09 08:58 - 14186496 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-06-14 22:14 - 2016-04-09 08:57 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-06-14 22:14 - 2016-04-09 08:54 - 12881408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-06-14 22:14 - 2016-04-09 08:54 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-06-14 22:14 - 2016-04-09 07:53 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-06-14 22:14 - 2016-04-09 07:44 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-06-14 22:13 - 2016-05-24 01:37 - 00394960 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-06-14 22:13 - 2016-05-24 00:54 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-06-14 22:13 - 2016-05-21 19:28 - 25802752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-06-14 22:13 - 2016-05-21 18:57 - 20341248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-06-14 22:13 - 2016-05-21 00:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-06-14 22:13 - 2016-05-21 00:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-06-14 22:13 - 2016-05-21 00:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-06-14 22:13 - 2016-05-21 00:10 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-06-14 22:13 - 2016-05-21 00:09 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-06-14 22:13 - 2016-05-21 00:09 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-06-14 22:13 - 2016-05-21 00:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-06-14 22:13 - 2016-05-21 00:08 - 02895360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-06-14 22:13 - 2016-05-21 00:08 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-06-14 22:13 - 2016-05-21 00:02 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-06-14 22:13 - 2016-05-21 00:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-06-14 22:13 - 2016-05-20 23:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-06-14 22:13 - 2016-05-20 23:57 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-06-14 22:13 - 2016-05-20 23:57 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-06-14 22:13 - 2016-05-20 23:57 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-06-14 22:13 - 2016-05-20 23:56 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-06-14 22:13 - 2016-05-20 23:56 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-06-14 22:13 - 2016-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-06-14 22:13 - 2016-05-20 23:54 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-06-14 22:13 - 2016-05-20 23:54 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-06-14 22:13 - 2016-05-20 23:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-06-14 22:13 - 2016-05-20 23:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-06-14 22:13 - 2016-05-20 23:50 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-06-14 22:13 - 2016-05-20 23:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-06-14 22:13 - 2016-05-20 23:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-06-14 22:13 - 2016-05-20 23:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-06-14 22:13 - 2016-05-20 23:45 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-06-14 22:13 - 2016-05-20 23:44 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-06-14 22:13 - 2016-05-20 23:44 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-06-14 22:13 - 2016-05-20 23:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-06-14 22:13 - 2016-05-20 23:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-06-14 22:13 - 2016-05-20 23:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-06-14 22:13 - 2016-05-20 23:33 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-06-14 22:13 - 2016-05-20 23:32 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-06-14 22:13 - 2016-05-20 23:29 - 13815808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-06-14 22:13 - 2016-05-20 23:28 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-06-14 22:13 - 2016-05-20 23:27 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-06-14 22:13 - 2016-05-20 23:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-06-14 22:13 - 2016-05-20 23:26 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-06-14 22:13 - 2016-05-20 23:25 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-06-14 22:13 - 2016-05-20 23:23 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-06-14 22:13 - 2016-05-20 23:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-06-14 22:13 - 2016-05-20 23:22 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-06-14 22:13 - 2016-05-20 23:21 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-06-14 22:13 - 2016-05-20 23:19 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-06-14 22:13 - 2016-05-20 23:14 - 04610048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-06-14 22:13 - 2016-05-20 23:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-06-14 22:13 - 2016-05-20 23:11 - 15420928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-06-14 22:13 - 2016-05-20 23:11 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-06-14 22:13 - 2016-05-20 23:09 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-06-14 22:13 - 2016-05-20 23:09 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-06-14 22:13 - 2016-05-20 23:08 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-06-14 22:13 - 2016-05-20 23:08 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-06-14 22:13 - 2016-05-20 23:07 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-06-14 22:13 - 2016-05-20 23:07 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-06-14 22:13 - 2016-05-20 23:06 - 02131968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-06-14 22:13 - 2016-05-20 22:46 - 02597888 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-06-14 22:13 - 2016-05-20 22:42 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-06-14 22:13 - 2016-05-20 22:38 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-06-14 22:13 - 2016-05-20 22:38 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-06-14 22:13 - 2016-05-20 22:34 - 01544192 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-06-14 22:13 - 2016-05-20 22:23 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-06-13 02:25 - 2016-06-14 22:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-06-12 18:54 - 2016-06-12 18:54 - 00000000 ____D C:\Users\Host\AppData\Roaming\Gyazo
2016-06-11 22:48 - 2016-06-19 16:22 - 00000986 _____ C:\Users\Public\Desktop\Gyazo.lnk
2016-06-11 22:48 - 2016-06-19 16:22 - 00000986 _____ C:\Users\Public\Desktop\Gyazo GIF.lnk
2016-06-11 22:48 - 2016-06-18 17:29 - 00003268 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine
2016-06-11 22:48 - 2016-06-18 17:28 - 00003394 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachineDaily
2016-06-11 22:48 - 2016-06-12 14:34 - 00000000 ____D C:\Program Files (x86)\Gyazo
2016-06-11 22:48 - 2016-06-11 22:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo
2016-06-11 22:43 - 2016-06-11 22:43 - 15669424 _____ (Nota Inc. ) C:\Users\Host\Downloads\Gyazo-3.2.2.exe
2016-06-11 19:15 - 2016-06-11 19:15 - 00002066 _____ C:\Users\Host\AppData\Local\recently-used.xbel
2016-06-11 19:09 - 2016-06-11 19:15 - 00001283 _____ C:\Users\Host\Desktop\meleeprot.xcf
2016-06-11 18:45 - 2016-06-11 18:45 - 00000532 _____ C:\Users\Host\Desktop\dld.htm
2016-06-11 18:40 - 2012-06-01 07:39 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wamregps.dll
2016-06-11 18:40 - 2012-06-01 07:36 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\iisRtl.dll
2016-06-11 18:40 - 2012-06-01 07:36 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\iisrstap.dll
2016-06-11 18:40 - 2012-06-01 07:35 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ahadmin.dll
2016-06-11 18:40 - 2012-06-01 07:34 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\admwprox.dll
2016-06-11 18:40 - 2012-06-01 07:33 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\iisreset.exe
2016-06-11 18:40 - 2012-06-01 06:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wamregps.dll
2016-06-11 18:40 - 2012-06-01 06:37 - 00154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisRtl.dll
2016-06-11 18:40 - 2012-06-01 06:37 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisrstap.dll
2016-06-11 18:40 - 2012-06-01 06:35 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admwprox.dll
2016-06-11 18:40 - 2012-06-01 06:35 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ahadmin.dll
2016-06-11 18:40 - 2012-06-01 06:34 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisreset.exe
2016-06-11 17:46 - 2016-06-11 17:49 - 07069441 _____ C:\Users\Host\Desktop\Julkkis.mp4
2016-06-10 02:12 - 2016-06-10 02:32 - 00040035 _____ C:\Users\Host\Desktop\ok.wlmp
2016-06-10 01:26 - 2016-06-10 01:26 - 00000000 ____D C:\inetpub
2016-06-10 00:40 - 2016-06-10 00:40 - 00000000 ____D C:\Program Files\Hyper-V
2016-06-09 23:35 - 2016-06-18 15:58 - 00000000 ____D C:\Users\Host\Desktop\100ANDRO
2016-06-09 22:50 - 2009-07-14 03:41 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\wts.dll
2016-06-09 22:49 - 2009-07-14 03:33 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\umcRes.dll
2016-06-09 22:48 - 2010-11-20 14:44 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\tsadmin.dll
2016-06-09 22:48 - 2010-11-20 14:27 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\mstsmhst.dll
2016-06-09 22:48 - 2010-11-20 14:24 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\dnscmd.exe
2016-06-09 22:48 - 2010-11-20 14:15 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\RemoteFileBrowse.dll
2016-06-09 22:48 - 2009-07-14 03:40 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\certpick.dll
2016-06-09 22:48 - 2009-06-10 22:33 - 00063978 _____ C:\Windows\system32\tsadmin.msc
2016-06-09 22:47 - 2010-11-20 14:27 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\mstsmmc.dll
2016-06-09 22:47 - 2010-11-20 14:27 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\tsuserex.dll
2016-06-09 22:47 - 2010-11-05 02:55 - 00146694 _____ C:\Windows\system32\dhcpmgmt.msc
2016-06-09 22:47 - 2010-11-05 02:55 - 00042131 _____ C:\Windows\system32\tsmmc.msc
2016-06-09 22:47 - 2009-07-14 03:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\TlsBrand.dll
2016-06-09 22:46 - 2010-11-20 14:26 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\dnsmgr.dll
2016-06-09 22:46 - 2010-11-05 02:55 - 00145867 _____ C:\Windows\system32\dnsmgmt.msc
2016-06-09 22:46 - 2009-07-14 03:41 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\rsatclient.dll
2016-06-09 22:46 - 2009-07-14 03:40 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dhcpmon.dll
2016-06-09 22:46 - 2009-07-14 03:15 - 00238592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpmon.dll
2016-06-09 22:45 - 2010-11-20 14:26 - 03582464 _____ (Microsoft Corporation) C:\Windows\system32\dhcpsnap.dll
2016-06-09 22:25 - 2016-06-09 22:28 - 251170997 _____ C:\Users\Host\Downloads\Windows6.1-KB958830-x64-RefreshPkg.msu
2016-06-08 01:55 - 2016-06-08 01:55 - 37452844 _____ C:\Users\Host\Desktop\yellowcoldplay.wav
2016-06-08 01:42 - 2016-06-08 01:42 - 39083564 _____ C:\Users\Host\Desktop\takemetochurch.wav
2016-06-06 23:40 - 2016-06-06 23:40 - 00108174 _____ C:\Users\Host\Downloads\CrazyMembPack 1.2.rms
2016-06-06 17:23 - 2016-06-06 17:24 - 00013886 _____ C:\Users\Host\Downloads\cenik (2).xlsx
2016-06-06 17:18 - 2016-06-06 17:18 - 00013886 _____ C:\Users\Host\Downloads\cenik (1).xlsx
2016-06-04 02:55 - 2016-06-04 02:55 - 00013886 _____ C:\Users\Host\Downloads\cenik.xlsx
2016-06-03 20:01 - 2016-06-03 20:01 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-05-31 20:10 - 2016-05-31 20:10 - 13163744 _____ (Microsoft Corporation) C:\Users\Host\Downloads\Silverlight_x64.exe
2016-05-30 23:16 - 2016-05-30 23:16 - 00141294 _____ C:\Users\Host\Downloads\P16416.A01 (1).pdf
2016-05-30 23:13 - 2016-05-30 23:13 - 00141294 _____ C:\Users\Host\Downloads\P16416.A01.pdf
2016-05-27 18:06 - 2016-05-28 22:20 - 00000000 ____D C:\Users\Host\AppData\LocalLow\BitTorrent
2016-05-27 08:07 - 2016-05-27 08:07 - 00001551 _____ C:\Users\Host\Desktop\VirtualBox – zástupce.lnk
2016-05-26 22:14 - 2016-05-26 22:19 - 1520762880 ____R C:\Users\Host\Downloads\kubuntu-16.04-desktop-amd64.iso
2016-05-26 22:13 - 2016-05-26 22:13 - 00058248 _____ C:\Users\Host\Downloads\kubuntu-16.04-desktop-amd64.iso.torrent
2016-05-26 22:06 - 2016-05-26 22:07 - 05111240 _____ (Piriform Ltd) C:\Users\Host\Downloads\spsetup129 (1).exe
2016-05-26 22:05 - 2016-06-19 16:22 - 00000840 _____ C:\Users\Public\Desktop\Speccy.lnk
2016-05-26 22:04 - 2016-05-26 22:05 - 00000000 ____D C:\Program Files\Speccy
2016-05-26 22:04 - 2016-05-26 22:04 - 05111240 _____ (Piriform Ltd) C:\Users\Host\Downloads\spsetup129.exe
2016-05-26 21:40 - 2016-05-26 21:42 - 258998272 _____ C:\Users\Host\Downloads\debian-8.4.0-amd64-netinst.iso
2016-05-26 21:19 - 2016-05-27 08:11 - 00000000 ____D C:\Users\Host\VirtualBox VMs
2016-05-26 21:18 - 2016-05-27 08:12 - 00000000 ____D C:\Users\Host\.VirtualBox
2016-05-26 21:17 - 2016-05-26 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2016-05-26 21:17 - 2016-05-26 21:17 - 00000000 ____D C:\Program Files\Oracle
2016-05-26 21:17 - 2016-04-28 15:05 - 00916520 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2016-05-26 21:17 - 2016-04-28 15:05 - 00143568 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2016-05-24 22:22 - 2016-06-08 01:55 - 00000000 ____D C:\Users\Host\AppData\Roaming\Audacity
2016-05-24 22:21 - 2016-06-19 16:22 - 00001011 _____ C:\Users\Public\Desktop\Audacity.lnk
2016-05-24 22:21 - 2016-06-19 05:11 - 00001023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2016-05-24 22:21 - 2016-05-24 22:21 - 00000000 ____D C:\Program Files (x86)\Audacity
2016-05-24 22:16 - 2016-05-24 22:16 - 24210616 _____ (Audacity Team ) C:\Users\Host\Downloads\audacity-win-2.1.0.exe
2016-05-24 22:05 - 2016-06-19 16:24 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-05-24 22:04 - 2016-06-19 16:22 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-05-24 22:04 - 2016-05-24 22:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-05-24 22:04 - 2016-05-24 22:04 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-05-24 22:04 - 2016-05-24 22:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-05-24 22:04 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-05-24 22:04 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-05-24 22:04 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-05-24 21:58 - 2016-05-24 21:59 - 22851472 _____ (Malwarebytes ) C:\Users\Host\Downloads\mbam-setup-2.2.1.1043.exe
2016-05-24 21:57 - 2016-05-24 22:01 - 1485881344 _____ C:\Users\Host\Downloads\ubuntu-16.04-desktop-amd64.iso
2016-05-24 21:57 - 2016-05-24 21:58 - 113110496 _____ (Oracle Corporation) C:\Users\Host\Downloads\VirtualBox-5.0.20-106931-Win.exe
2016-05-24 20:35 - 2016-05-24 20:35 - 00000000 ____D C:\_OTL
2016-05-22 22:51 - 2016-05-22 22:53 - 00068199 _____ C:\Users\Host\Downloads\OTL (1).zip
2016-05-22 22:48 - 2016-05-22 22:49 - 00068199 _____ C:\Users\Host\Downloads\OTL.zip
2016-05-22 22:35 - 2016-05-22 22:46 - 00097192 _____ C:\Users\Host\Downloads\Extras.Txt
2016-05-22 22:33 - 2016-05-22 22:33 - 00564854 _____ C:\Users\Host\Downloads\OTL.Txt
2016-05-22 20:54 - 2016-05-22 20:54 - 00880432 _____ C:\Users\Host\Downloads\OSBuddy (1).exe
2016-05-22 19:31 - 2016-05-22 19:31 - 00000512 _____ C:\PhysicalMBR.bin
2016-05-22 19:26 - 2016-05-22 19:26 - 00602112 _____ (OldTimer Tools) C:\Users\Host\Downloads\OTL.exe
2016-05-22 14:43 - 2016-05-22 14:43 - 00307495 _____ C:\Users\Host\Downloads\CV_2015_AJ.pdf
2016-05-22 13:01 - 2016-05-22 13:01 - 00786432 _____ C:\Windows\mod_frst.exe
2016-05-22 12:55 - 2016-06-19 17:15 - 00000000 ____D C:\FRST

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-19 16:30 - 2009-07-14 06:45 - 00027168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-06-19 16:30 - 2009-07-14 06:45 - 00027168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-06-19 16:22 - 2016-01-25 21:39 - 00001049 _____ C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameRanger.lnk
2016-06-19 16:22 - 2015-12-19 18:31 - 00002102 _____ C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2016-06-19 16:22 - 2015-12-19 14:35 - 00001995 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk
2016-06-19 16:22 - 2015-12-19 14:34 - 00002212 _____ C:\Users\Public\Desktop\HP Deskjet 4510 series.lnk
2016-06-19 16:22 - 2015-11-08 01:13 - 00002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-06-19 16:22 - 2015-10-08 22:19 - 00002193 _____ C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2016-06-19 16:22 - 2015-09-11 19:23 - 00002731 _____ C:\Users\Public\Desktop\Skype.lnk
2016-06-19 16:22 - 2015-05-23 16:25 - 00000866 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-06-19 16:22 - 2015-03-26 18:46 - 00002008 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2016-06-19 16:22 - 2014-08-16 12:17 - 00000640 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-06-19 16:22 - 2013-12-13 22:30 - 00001954 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2016-06-19 16:22 - 2013-07-05 13:06 - 00000812 _____ C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
2016-06-19 16:22 - 2013-07-01 08:41 - 00002225 _____ C:\Users\Public\Desktop\Acronis Záloha jedním kliknutím.lnk
2016-06-19 16:22 - 2013-07-01 08:41 - 00001139 _____ C:\Users\Public\Desktop\Acronis True Image Home 2010.lnk
2016-06-19 16:22 - 2013-06-28 15:11 - 00001206 _____ C:\Users\Public\Desktop\HD VDeck.lnk
2016-06-19 16:22 - 2013-06-27 15:47 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-06-19 16:22 - 2013-06-27 15:39 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-06-19 16:22 - 2013-06-26 12:33 - 00002754 _____ C:\Users\Public\Desktop\Nero StartSmart.lnk
2016-06-19 16:22 - 2013-06-26 10:45 - 00001126 _____ C:\Users\Public\Desktop\BS.Player FREE.lnk
2016-06-19 16:22 - 2013-06-26 10:08 - 00001397 _____ C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2016-06-19 16:21 - 2014-09-22 12:03 - 00002049 _____ C:\Users\Host\Desktop\Tribes of the East.lnk
2016-06-19 16:21 - 2014-03-16 23:21 - 00001997 _____ C:\Users\Host\Desktop\Vypínač na dobrou noc.lnk
2016-06-19 16:21 - 2013-08-01 19:43 - 00000955 _____ C:\Users\Host\Desktop\WESNOTH SAVES.lnk
2016-06-19 16:20 - 2016-03-12 15:52 - 00001042 _____ C:\Users\Host\Desktop\Folder Size.lnk
2016-06-19 16:20 - 2014-06-10 15:28 - 00001126 _____ C:\Users\Host\Desktop\EVEREST Ultimate Edition.lnk
2016-06-19 16:20 - 2013-12-13 22:26 - 00001268 _____ C:\Users\Host\Desktop\Revo Uninstaller.lnk
2016-06-19 16:20 - 2013-09-14 08:44 - 00000895 _____ C:\Users\Host\Desktop\Downloads.lnk
2016-06-19 16:20 - 2013-09-04 22:11 - 00001052 _____ C:\Users\Host\Desktop\Quick Screenshot Maker.lnk
2016-06-19 16:20 - 2013-08-13 19:22 - 00001008 _____ C:\Users\Host\Desktop\Dropbox.lnk
2016-06-19 16:20 - 2013-07-05 13:06 - 00000832 _____ C:\Users\Host\Desktop\BitTorrent.lnk
2016-06-19 16:20 - 2013-06-28 08:46 - 00001007 _____ C:\Users\Host\Desktop\Hard Disk Sentinel.lnk
2016-06-19 16:20 - 2013-06-27 15:37 - 00001367 _____ C:\Users\Host\Desktop\Internet Explorer.lnk
2016-06-19 16:19 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\inetsrv
2016-06-19 16:17 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-06-19 16:16 - 2013-06-27 08:47 - 00000000 ____D C:\Windows\lt-LT
2016-06-19 05:11 - 2015-11-08 01:13 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-06-19 05:11 - 2015-10-08 22:32 - 00001374 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2016-06-19 05:11 - 2015-10-08 22:32 - 00001305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Movie Maker.lnk
2016-06-19 05:11 - 2015-10-08 22:31 - 00002486 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2016-06-19 05:11 - 2015-10-08 22:31 - 00001458 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2016-06-19 05:11 - 2015-10-07 23:42 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2016-06-19 05:11 - 2015-05-23 16:18 - 00000000 ____D C:\Users\Host\Desktop\Games
2016-06-19 05:11 - 2013-08-25 21:18 - 00001590 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOL Recorder.lnk
2016-06-19 05:11 - 2013-08-22 21:30 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-06-19 05:11 - 2013-06-28 15:11 - 00001218 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD VDeck.lnk
2016-06-19 05:11 - 2013-06-27 15:47 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-19 05:11 - 2013-06-27 15:39 - 00001163 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-06-19 05:11 - 2013-06-27 10:04 - 00000406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Messenger Center.lnk
2016-06-19 05:11 - 2013-06-27 10:04 - 00000406 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Player Center.lnk
2016-06-19 05:11 - 2013-06-26 10:45 - 00001132 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BS.Player FREE.lnk
2016-06-19 05:11 - 2013-06-26 10:44 - 00002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2016-06-19 05:11 - 2013-06-26 10:04 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2016-06-19 05:11 - 2013-06-26 10:04 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2016-06-19 05:11 - 2009-07-14 07:01 - 00001282 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk
2016-06-19 05:11 - 2009-07-14 06:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-06-19 05:11 - 2009-07-14 06:57 - 00001330 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sidebar.lnk
2016-06-19 05:11 - 2009-07-14 06:57 - 00001246 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk
2016-06-19 05:11 - 2009-07-14 06:54 - 00001210 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk
2016-06-19 05:11 - 2009-07-14 06:49 - 00001266 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk
2016-06-18 18:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-06-18 17:34 - 2013-06-26 10:08 - 00000000 ____D C:\Users\Host
2016-06-18 17:03 - 2015-02-26 18:38 - 00000043 _____ C:\Users\Host\jagex_cl_oldschool_LIVE.dat
2016-06-18 16:58 - 2016-05-01 14:25 - 00000000 ____D C:\Users\Host\Desktop\algebra
2016-06-18 16:50 - 2013-06-26 13:04 - 00000000 ____D C:\Users\Host\Desktop\Fcb
2016-06-16 00:31 - 2013-06-26 10:46 - 00000000 ____D C:\Users\Host\AppData\Roaming\Skype
2016-06-15 22:40 - 2010-11-21 05:27 - 00484008 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-06-15 18:42 - 2009-07-14 06:45 - 00489176 _____ C:\Windows\system32\FNTCACHE.DAT
2016-06-15 18:36 - 2014-12-17 16:04 - 00000000 ____D C:\Windows\system32\appraiser
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\lv-LV
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\lt-LT
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\et-EE
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lv-LV
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lt-LT
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\et-EE
2016-06-15 18:35 - 2013-06-27 08:48 - 00000000 ____D C:\Windows\et-EE
2016-06-15 18:35 - 2013-06-27 08:38 - 00000000 ____D C:\Windows\lv-LV
2016-06-15 00:45 - 2013-08-15 03:03 - 00000000 ____D C:\Windows\system32\MRT
2016-06-15 00:38 - 2013-06-26 10:39 - 142482544 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-06-14 22:33 - 2016-03-14 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voobly
2016-06-14 22:02 - 2013-06-27 15:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-06-12 14:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\inetsrv
2016-06-11 19:15 - 2015-10-07 23:44 - 00000000 ____D C:\Users\Host\.gimp-2.8
2016-06-11 19:12 - 2015-10-07 23:46 - 00000000 ____D C:\Users\Host\AppData\Local\gtk-2.0
2016-06-10 01:45 - 2015-10-08 22:13 - 00000000 ____D C:\Users\Host\AppData\Local\Windows Live
2016-06-10 01:27 - 2013-06-27 09:53 - 00744326 _____ C:\Windows\system32\perfh013.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00741090 _____ C:\Windows\system32\perfh015.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00729598 _____ C:\Windows\system32\prfh0816.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00724534 _____ C:\Windows\system32\perfh019.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00714344 _____ C:\Windows\system32\prfh0416.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00663708 _____ C:\Windows\system32\perfh01D.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00656784 _____ C:\Windows\system32\perfh01F.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00608290 _____ C:\Windows\system32\perfh008.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00509868 _____ C:\Windows\system32\perfh006.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00494606 _____ C:\Windows\system32\perfh014.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00481932 _____ C:\Windows\system32\perfh00B.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00425894 _____ C:\Windows\system32\perfh012.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00415534 _____ C:\Windows\system32\perfh011.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00398048 _____ C:\Windows\system32\prfh0404.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00380876 _____ C:\Windows\system32\prfh0804.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00159574 _____ C:\Windows\system32\perfc015.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00156352 _____ C:\Windows\system32\perfc013.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00156248 _____ C:\Windows\system32\prfc0816.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00154216 _____ C:\Windows\system32\perfc019.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00150878 _____ C:\Windows\system32\prfc0416.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00145506 _____ C:\Windows\system32\perfc01D.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00143286 _____ C:\Windows\system32\perfc01F.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00124684 _____ C:\Windows\system32\perfc011.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00122968 _____ C:\Windows\system32\perfc012.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00122176 _____ C:\Windows\system32\prfc0804.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00117674 _____ C:\Windows\system32\prfc0404.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00114676 _____ C:\Windows\system32\perfc008.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00105064 _____ C:\Windows\system32\perfc00B.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00101764 _____ C:\Windows\system32\perfc006.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00097988 _____ C:\Windows\system32\perfc014.dat
2016-06-10 01:27 - 2013-06-26 14:23 - 00684992 _____ C:\Windows\system32\perfh00E.dat
2016-06-10 01:27 - 2013-06-26 14:23 - 00174978 _____ C:\Windows\system32\perfc00E.dat
2016-06-10 01:27 - 2013-06-26 14:10 - 00745996 _____ C:\Windows\system32\perfh00A.dat
2016-06-10 01:27 - 2013-06-26 14:10 - 00161930 _____ C:\Windows\system32\perfc00A.dat
2016-06-10 01:27 - 2013-06-26 14:02 - 00391514 _____ C:\Windows\system32\perfh00D.dat
2016-06-10 01:27 - 2013-06-26 14:02 - 00087342 _____ C:\Windows\system32\perfc00D.dat
2016-06-10 01:27 - 2013-06-26 13:46 - 00740304 _____ C:\Windows\system32\perfh010.dat
2016-06-10 01:27 - 2013-06-26 13:46 - 00150090 _____ C:\Windows\system32\perfc010.dat
2016-06-10 01:27 - 2013-06-26 13:40 - 00746190 _____ C:\Windows\system32\perfh00C.dat
2016-06-10 01:27 - 2013-06-26 13:40 - 00480192 _____ C:\Windows\system32\perfh001.dat
2016-06-10 01:27 - 2013-06-26 13:40 - 00152696 _____ C:\Windows\system32\perfc00C.dat
2016-06-10 01:27 - 2013-06-26 13:40 - 00097356 _____ C:\Windows\system32\perfc001.dat
2016-06-10 01:27 - 2013-06-26 13:28 - 00697596 _____ C:\Windows\system32\perfh007.dat
2016-06-10 01:27 - 2013-06-26 13:28 - 00152158 _____ C:\Windows\system32\perfc007.dat
2016-06-10 01:27 - 2011-04-12 10:34 - 00677906 _____ C:\Windows\system32\perfh005.dat
2016-06-10 01:27 - 2011-04-12 10:34 - 00145658 _____ C:\Windows\system32\perfc005.dat
2016-06-10 01:26 - 2013-06-27 08:56 - 00000000 ____D C:\Windows\system32\ja
2016-06-10 01:26 - 2013-06-27 08:54 - 00000000 ____D C:\Windows\system32\zh-CHT
2016-06-10 01:26 - 2013-06-27 08:52 - 00000000 ____D C:\Windows\system32\pt
2016-06-10 01:26 - 2013-06-27 08:51 - 00000000 ____D C:\Windows\system32\pl
2016-06-10 01:26 - 2013-06-27 08:50 - 00000000 ____D C:\Windows\system32\tr
2016-06-10 01:26 - 2013-06-27 08:49 - 00000000 ____D C:\Windows\system32\zh-CHS
2016-06-10 01:26 - 2013-06-27 08:47 - 00000000 ____D C:\Windows\system32\ru
2016-06-10 01:26 - 2013-06-27 08:44 - 00000000 ____D C:\Windows\system32\sv
2016-06-10 01:26 - 2013-06-27 08:42 - 00000000 ____D C:\Windows\system32\ko
2016-06-10 01:26 - 2013-06-27 08:39 - 00000000 ____D C:\Windows\system32\nl
2016-06-10 01:26 - 2013-06-26 14:22 - 00000000 ____D C:\Windows\system32\hu
2016-06-10 01:26 - 2013-06-26 14:09 - 00000000 ____D C:\Windows\system32\es
2016-06-10 01:26 - 2013-06-26 13:45 - 00000000 ____D C:\Windows\system32\it
2016-06-10 01:26 - 2013-06-26 13:39 - 00000000 ____D C:\Windows\system32\fr
2016-06-10 01:26 - 2013-06-26 13:26 - 00000000 ____D C:\Windows\system32\de
2016-06-10 01:26 - 2011-04-12 10:34 - 00000000 ____D C:\Windows\system32\cs
2016-06-06 16:50 - 2009-07-14 07:13 - 17544796 _____ C:\Windows\system32\PerfStringBackup.INI
2016-06-05 14:34 - 2014-09-10 09:45 - 00000000 ____D C:\Users\Host\AppData\Local\CrashDumps
2016-06-04 22:44 - 2015-09-11 19:23 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-06-04 22:43 - 2013-06-26 10:46 - 00000000 ____D C:\ProgramData\Skype
2016-06-03 20:01 - 2013-08-13 19:19 - 00000000 ____D C:\Users\Host\AppData\Roaming\Dropbox
2016-06-02 23:25 - 2015-09-28 21:17 - 00000000 ____D C:\Users\Host\AppData\Local\Battle.net
2016-06-02 21:29 - 2015-09-28 21:16 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-06-02 19:53 - 2014-05-12 18:42 - 00000000 ____D C:\Users\Host\Desktop\Movie
2016-06-02 19:53 - 2013-07-05 13:07 - 00000000 ____D C:\Users\Host\Desktop\BitTorrent
2016-06-01 18:13 - 2016-05-17 21:57 - 00000000 ____D C:\Users\Host\Desktop\Morpho
2016-06-01 17:41 - 2013-07-01 23:07 - 00000000 ____D C:\Peete
2016-05-31 21:28 - 2016-04-18 20:37 - 00000000 ____D C:\Users\Host\AppData\Roaming\HearthstoneDeckTracker
2016-05-29 14:59 - 2014-01-08 02:35 - 00000000 ____D C:\ProgramData\NVIDIA
2016-05-28 22:22 - 2015-02-22 04:46 - 00000000 ____D C:\Users\Host\AppData\Roaming\BitTorrent
2016-05-27 18:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PLA
2016-05-27 08:33 - 2016-04-18 00:12 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-05-27 08:33 - 2016-04-18 00:12 - 00000000 ___SD C:\Windows\system32\GWX
2016-05-27 01:32 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2016-05-26 22:50 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-05-26 21:10 - 2013-12-13 22:24 - 00000000 ____D C:\Users\Host\AppData\Roaming\DAEMON Tools Lite
2016-05-25 18:24 - 2013-06-28 08:52 - 00000000 ____D C:\Windows\System32\Tasks\HardDiskSentinel

==================== Files in the root of some directories =======

2016-06-18 17:16 - 2016-06-18 17:16 - 6867968 _____ () C:\Users\Host\AppData\Roaming\agent.dat
2016-06-18 17:16 - 2016-06-18 17:15 - 1106432 _____ () C:\Users\Host\AppData\Roaming\Doublefan.exe
2016-06-18 17:15 - 2016-06-18 17:15 - 0128512 _____ () C:\Users\Host\AppData\Roaming\Installer.dat
2016-06-18 17:16 - 2016-06-18 17:16 - 0018432 _____ () C:\Users\Host\AppData\Roaming\Main.dat
2013-08-20 23:30 - 2016-02-28 22:14 - 0045270 _____ () C:\Users\Host\AppData\Roaming\room_v3.dat
2016-06-18 17:16 - 2016-06-18 17:15 - 1106432 _____ () C:\Users\Host\AppData\Roaming\Vaiain.exe
2016-06-11 19:15 - 2016-06-11 19:15 - 0002066 _____ () C:\Users\Host\AppData\Local\recently-used.xbel
2015-12-19 16:17 - 2015-12-19 16:17 - 0007641 _____ () C:\Users\Host\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Host\AppData\Local\Temp\SkypeSetup.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-06-09 21:41

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118289
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: V normálním módu nelze spustit žádný program

#2 Příspěvek od Rudy »

Zdravím!
Nejprve zkuste obnovu systému k datu, kdy korektně fungoval.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

Re: V normálním módu nelze spustit žádný program

#3 Příspěvek od detox »

Díky, to mě nenapadlo... :shock: Úspěšně jsem obnovil na včerejšek..

Je možné že po obnově zůstane nějaká možnost remote control nebo něco podobného ?

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118289
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: V normálním módu nelze spustit žádný program

#4 Příspěvek od Rudy »

To prověříme. Dejte teď log FRST.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

Re: V normálním módu nelze spustit žádný program

#5 Příspěvek od detox »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-06-2016 01
Ran by Host (administrator) on PC (19-06-2016 20:57:27)
Running from C:\Users\Host\Downloads
Loaded Profiles: Host (Available Profiles: Host)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
() C:\Program Files (x86)\Common Files\Acronis\Plán2\schedul2.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Dropbox, Inc.) C:\Users\Host\AppData\Roaming\Dropbox\bin\Dropbox.exe
(VIA) C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\POWERPNT.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
() C:\Users\Host\Downloads\OSBuddy.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation)
HKLM-x32\...\Run: [HDAudDeck] => C:\Program Files (x86)\VIA\VIAudioi\VDeck\VDeck.exe [3037296 2011-05-06] (VIA)
HKU\S-1-5-21-2504773853-1791968555-2413179023-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-2504773853-1791968555-2413179023-1000\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3582240 2016-06-02] (Nota Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt64.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Host\AppData\Roaming\Dropbox\bin\DropboxExt.34.dll [2016-05-31] (Dropbox, Inc.)
Startup: C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-06-03]
ShortcutTarget: Dropbox.lnk -> C:\Users\Host\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{D3AE1677-8D67-4074-8806-8E40612429C5}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-2504773853-1791968555-2413179023-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://seznam.cz/
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2504773853-1791968555-2413179023-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

FireFox:
========
FF ProfilePath: C:\Users\Host\AppData\Roaming\Mozilla\Firefox\Profiles\bc89wx67.default
FF Homepage: hxxp://www.seznam.cz/
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Peete\VLC\npvlc.dll [2014-07-30] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_242.dll [2016-05-12] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-03-22] (NVIDIA Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-05-11] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-05-03] (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Host\AppData\Roaming\Mozilla\Firefox\Profiles\bc89wx67.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28]
FF HKU\S-1-5-21-2504773853-1791968555-2413179023-1000\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: McAfee Security Scan Plus - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04] [not signed]

Chrome:
=======
CHR HomePage: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoHoTG1nEZQLY5Ws0Qo54vWR8nn8udyB3gSocMZdWbXllAnmIqhg_sb8PUkLJdOk-0Q0Nv7TxU-e_2uSNZ5VsYLTCRKnlBEL9iqhSVXxFVwR7UlJxz2S1XibtmZx-BzevUKw9eNAJI6VC5cZTuIiwHET92vFzXC0SzPfVLvypZg,,
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-18]
CHR Extension: (BetterTTV) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2016-06-03]
CHR Extension: (Dokumenty Google) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-18]
CHR Extension: (Disk Google) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-18]
CHR Extension: (YouTube) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-18]
CHR Extension: (Tabulky Google) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-18]
CHR Extension: (Dokumenty Google offline) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-18]
CHR Extension: (AdBlock) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-06-02]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-05-24]
CHR Extension: (Gmail) - C:\Users\Host\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-18]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - hxxp://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Plán2\schedul2.exe [1055200 2010-06-03] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [90112 2009-08-19] (ASUSTeK Computer Inc.) [File not signed]
S3 DAUpdaterSvc; C:\Peete\Dragon Age\bin_ship\DAUpdaterSvc.Service.exe [25832 2009-12-15] (BioWare)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [496232 2010-01-21] ()
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-12] (NVIDIA Corporation)
R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [15872 2010-11-21] (Microsoft Corporation)
S4 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.309\McCHSvc.exe [293128 2016-03-11] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation)
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [724992 2006-10-09] (Nero AG) [File not signed]
R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [209000 2010-01-21] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-12] (NVIDIA Corporation)
S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-12] (NVIDIA Corporation)
S4 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-12] (NVIDIA Corporation)
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [27760 2011-03-29] (VIA Technologies, Inc.)
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-13] (Disc Soft Ltd)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-12] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
R0 tdrpman258; C:\Windows\System32\DRIVERS\tdrpm258.sys [1477728 2013-07-01] (Acronis)
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [119712 2016-04-28] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [192352 2016-04-28] (Oracle Corporation)
S3 gkernel; \??\C:\Users\Host\AppData\Local\Temp\gkernel.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-19 20:54 - 2016-06-19 20:54 - 02387456 _____ (Farbar) C:\Users\Host\Downloads\FRST64.exe
2016-06-19 20:19 - 2016-06-19 20:19 - 00000000 ____D C:\Users\Host\Downloads\SysinternalsSuite
2016-06-19 18:31 - 2016-06-19 18:32 - 16127164 _____ C:\Users\Host\Downloads\SysinternalsSuite.zip
2016-06-19 17:42 - 2016-06-19 17:42 - 00000000 ____D C:\Program Files (x86)\MSECache
2016-06-19 17:20 - 2016-06-19 17:23 - 00050347 _____ C:\Users\Host\Downloads\Addition.txt
2016-06-19 17:15 - 2016-06-19 20:57 - 00017898 _____ C:\Users\Host\Downloads\FRST.txt
2016-06-18 17:49 - 2016-06-18 17:49 - 00000000 ____D C:\Program Files (x86)\EaseUS
2016-06-18 17:48 - 2016-06-18 17:48 - 00000000 ____D C:\ProgramData\wsr
2016-06-18 17:34 - 2016-06-18 17:34 - 00000000 ____D C:\sh4ldr
2016-06-18 17:34 - 2016-06-18 17:34 - 00000000 _____ C:\autoexec.bat
2016-06-18 17:33 - 2016-06-18 17:33 - 00000000 ____D C:\Program Files\Enigma Software Group
2016-06-18 17:22 - 2016-06-18 17:46 - 00000000 ___HD C:\DrFoneForAndroid
2016-06-18 17:16 - 2016-06-18 17:16 - 06867968 _____ C:\Users\Host\AppData\Roaming\agent.dat
2016-06-18 17:16 - 2016-06-18 17:16 - 00018432 _____ C:\Users\Host\AppData\Roaming\Main.dat
2016-06-18 17:15 - 2016-06-18 17:15 - 00128512 _____ C:\Users\Host\AppData\Roaming\Installer.dat
2016-06-18 16:57 - 2016-06-18 16:57 - 00000000 ____D C:\Users\Host\AppData\Roaming\HMYGSetting
2016-06-18 16:57 - 2016-06-18 16:57 - 00000000 ____D C:\Users\Host\.android
2016-06-18 16:55 - 2016-06-19 18:17 - 00000000 ____D C:\Users\Public\Documents\Wondershare
2016-06-18 16:55 - 2016-06-18 16:57 - 00000000 ____D C:\ProgramData\Wondershare
2016-06-18 16:55 - 2016-06-18 16:55 - 00000000 ____D C:\Users\Host\AppData\Roaming\Wondershare
2016-06-18 16:55 - 2016-06-18 16:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2016-06-18 16:55 - 2016-06-18 16:55 - 00000000 ____D C:\Program Files (x86)\Wondershare
2016-06-18 16:42 - 2016-06-19 18:17 - 00000000 ____D C:\Program Files (x86)\R-Studio
2016-06-18 16:42 - 2016-06-18 16:43 - 00000000 ____D C:\Users\Host\Documents\R-TT
2016-06-18 16:37 - 2016-06-18 16:37 - 00164192 _____ C:\Users\Host\Downloads\restoration.zip
2016-06-15 22:05 - 2016-06-15 22:05 - 00236086 _____ C:\Users\Host\Downloads\testy.rar
2016-06-14 22:50 - 2016-06-14 22:50 - 06608965 _____ C:\Users\Host\Downloads\crazymembpack 4.3 + individual maps + screenshots (1).rar
2016-06-14 22:26 - 2016-06-14 22:26 - 06608965 _____ C:\Users\Host\Downloads\crazymembpack 4.3 + individual maps + screenshots.rar
2016-06-14 22:17 - 2016-05-18 18:10 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2016-06-14 22:17 - 2016-05-18 18:09 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2016-06-14 22:17 - 2016-05-12 19:15 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-06-14 22:17 - 2016-05-12 17:18 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-06-14 22:17 - 2016-05-11 19:02 - 00444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2016-06-14 22:17 - 2016-05-11 19:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2016-06-14 22:17 - 2016-05-11 19:02 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2016-06-14 22:17 - 2016-05-11 17:19 - 00351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2016-06-14 22:17 - 2016-05-11 17:19 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2016-06-14 22:17 - 2016-05-11 17:19 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2016-06-14 22:17 - 2016-05-11 17:11 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2016-06-14 22:17 - 2016-05-11 17:01 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2016-06-14 22:17 - 2016-05-11 16:58 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2016-06-14 22:16 - 2016-06-06 18:58 - 00041704 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-06-14 22:16 - 2016-06-06 18:50 - 01204224 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-06-14 22:16 - 2016-06-03 15:05 - 01413120 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-06-14 22:16 - 2016-05-27 15:06 - 00569856 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-06-14 22:16 - 2016-05-27 15:06 - 00544256 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-06-14 22:16 - 2016-05-27 15:06 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-06-14 22:16 - 2016-05-27 15:06 - 00265216 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2016-06-14 22:16 - 2016-05-22 15:06 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-06-14 22:16 - 2016-05-14 00:15 - 00382184 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-06-14 22:16 - 2016-05-14 00:09 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-06-14 22:16 - 2016-05-14 00:09 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-06-14 22:16 - 2016-05-14 00:09 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-06-14 22:16 - 2016-05-14 00:09 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-06-14 22:16 - 2016-05-13 23:54 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-06-14 22:16 - 2016-05-13 23:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-06-14 22:16 - 2016-05-13 23:49 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-06-14 22:16 - 2016-05-13 23:49 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-06-14 22:16 - 2016-05-13 23:27 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-06-14 22:16 - 2016-05-12 19:20 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-06-14 22:16 - 2016-05-12 19:20 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-06-14 22:16 - 2016-05-12 19:15 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-06-14 22:16 - 2016-05-12 19:15 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-06-14 22:16 - 2016-05-12 19:15 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-06-14 22:16 - 2016-05-12 19:15 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-06-14 22:16 - 2016-05-12 19:14 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-06-14 22:16 - 2016-05-12 17:18 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-06-14 22:16 - 2016-05-12 17:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-06-14 22:16 - 2016-05-12 16:58 - 00464896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-06-14 22:16 - 2016-05-12 16:58 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-06-14 22:16 - 2016-05-12 16:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-06-14 22:16 - 2016-05-12 16:56 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-06-14 22:16 - 2016-05-12 16:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-06-14 22:16 - 2016-05-12 15:05 - 00459640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-06-14 22:16 - 2016-05-12 15:05 - 00297984 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2016-06-14 22:16 - 2016-05-12 15:04 - 00249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2016-06-14 22:16 - 2016-05-11 19:02 - 00483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2016-06-14 22:16 - 2016-05-11 17:19 - 00363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2016-06-14 22:15 - 2016-05-12 19:15 - 00105472 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00794624 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00793088 _____ (Microsoft Corporation) C:\Windows\system32\gpprefcl.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00502272 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2016-06-14 22:15 - 2016-05-12 19:14 - 00373760 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll
2016-06-14 22:15 - 2016-05-12 19:14 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00591872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpprefcl.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll
2016-06-14 22:15 - 2016-05-12 17:18 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
2016-06-14 22:15 - 2016-05-12 17:06 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\gpscript.exe
2016-06-14 22:15 - 2016-05-12 17:03 - 03217408 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-06-14 22:15 - 2016-05-12 16:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.dll
2016-06-14 22:15 - 2016-05-12 16:57 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpscript.exe
2016-06-14 22:15 - 2016-03-09 21:00 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2016-06-14 22:15 - 2016-03-09 20:40 - 00316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2016-06-14 22:14 - 2016-04-14 18:46 - 00114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2016-06-14 22:14 - 2016-04-14 18:42 - 03243520 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2016-06-14 22:14 - 2016-04-14 18:42 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-06-14 22:14 - 2016-04-14 18:42 - 00504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2016-06-14 22:14 - 2016-04-14 18:42 - 00070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2016-06-14 22:14 - 2016-04-14 18:42 - 00025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2016-06-14 22:14 - 2016-04-14 17:33 - 02365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2016-06-14 22:14 - 2016-04-14 17:33 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-06-14 22:14 - 2016-04-14 17:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2016-06-14 22:14 - 2016-04-14 17:33 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2016-06-14 22:14 - 2016-04-14 17:19 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2016-06-14 22:14 - 2016-04-14 17:11 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2016-06-14 22:14 - 2016-04-09 08:58 - 14186496 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-06-14 22:14 - 2016-04-09 08:57 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-06-14 22:14 - 2016-04-09 08:54 - 12881408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-06-14 22:14 - 2016-04-09 08:54 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-06-14 22:14 - 2016-04-09 07:53 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-06-14 22:14 - 2016-04-09 07:44 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-06-14 22:13 - 2016-05-24 01:37 - 00394960 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-06-14 22:13 - 2016-05-24 00:54 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-06-14 22:13 - 2016-05-21 19:28 - 25802752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-06-14 22:13 - 2016-05-21 18:57 - 20341248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-06-14 22:13 - 2016-05-21 00:27 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-06-14 22:13 - 2016-05-21 00:27 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-06-14 22:13 - 2016-05-21 00:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-06-14 22:13 - 2016-05-21 00:10 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-06-14 22:13 - 2016-05-21 00:09 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-06-14 22:13 - 2016-05-21 00:09 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-06-14 22:13 - 2016-05-21 00:09 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-06-14 22:13 - 2016-05-21 00:08 - 02895360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-06-14 22:13 - 2016-05-21 00:08 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-06-14 22:13 - 2016-05-21 00:02 - 06051328 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-06-14 22:13 - 2016-05-21 00:00 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-06-14 22:13 - 2016-05-20 23:59 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-06-14 22:13 - 2016-05-20 23:57 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-06-14 22:13 - 2016-05-20 23:57 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-06-14 22:13 - 2016-05-20 23:57 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-06-14 22:13 - 2016-05-20 23:56 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-06-14 22:13 - 2016-05-20 23:56 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-06-14 22:13 - 2016-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-06-14 22:13 - 2016-05-20 23:54 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-06-14 22:13 - 2016-05-20 23:54 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-06-14 22:13 - 2016-05-20 23:54 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-06-14 22:13 - 2016-05-20 23:54 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-06-14 22:13 - 2016-05-20 23:50 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-06-14 22:13 - 2016-05-20 23:49 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-06-14 22:13 - 2016-05-20 23:48 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-06-14 22:13 - 2016-05-20 23:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-06-14 22:13 - 2016-05-20 23:45 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-06-14 22:13 - 2016-05-20 23:44 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-06-14 22:13 - 2016-05-20 23:44 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-06-14 22:13 - 2016-05-20 23:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-06-14 22:13 - 2016-05-20 23:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-06-14 22:13 - 2016-05-20 23:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-06-14 22:13 - 2016-05-20 23:33 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-06-14 22:13 - 2016-05-20 23:32 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-06-14 22:13 - 2016-05-20 23:29 - 13815808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-06-14 22:13 - 2016-05-20 23:28 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-06-14 22:13 - 2016-05-20 23:27 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-06-14 22:13 - 2016-05-20 23:27 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-06-14 22:13 - 2016-05-20 23:26 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-06-14 22:13 - 2016-05-20 23:25 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-06-14 22:13 - 2016-05-20 23:23 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-06-14 22:13 - 2016-05-20 23:23 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-06-14 22:13 - 2016-05-20 23:22 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-06-14 22:13 - 2016-05-20 23:21 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-06-14 22:13 - 2016-05-20 23:19 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-06-14 22:13 - 2016-05-20 23:14 - 04610048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-06-14 22:13 - 2016-05-20 23:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-06-14 22:13 - 2016-05-20 23:11 - 15420928 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-06-14 22:13 - 2016-05-20 23:11 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-06-14 22:13 - 2016-05-20 23:09 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-06-14 22:13 - 2016-05-20 23:09 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-06-14 22:13 - 2016-05-20 23:08 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-06-14 22:13 - 2016-05-20 23:08 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-06-14 22:13 - 2016-05-20 23:07 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-06-14 22:13 - 2016-05-20 23:07 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-06-14 22:13 - 2016-05-20 23:06 - 02131968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-06-14 22:13 - 2016-05-20 22:46 - 02597888 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-06-14 22:13 - 2016-05-20 22:42 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-06-14 22:13 - 2016-05-20 22:38 - 01310208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-06-14 22:13 - 2016-05-20 22:38 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-06-14 22:13 - 2016-05-20 22:34 - 01544192 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-06-14 22:13 - 2016-05-20 22:23 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-06-13 02:25 - 2016-06-14 22:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-06-12 18:54 - 2016-06-12 18:54 - 00000000 ____D C:\Users\Host\AppData\Roaming\Gyazo
2016-06-11 22:48 - 2016-06-12 14:34 - 00000000 ____D C:\Program Files (x86)\Gyazo
2016-06-11 22:48 - 2016-06-11 22:48 - 00003392 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachineDaily
2016-06-11 22:48 - 2016-06-11 22:48 - 00003266 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine
2016-06-11 22:48 - 2016-06-11 22:48 - 00000986 _____ C:\Users\Public\Desktop\Gyazo.lnk
2016-06-11 22:48 - 2016-06-11 22:48 - 00000986 _____ C:\Users\Public\Desktop\Gyazo GIF.lnk
2016-06-11 22:48 - 2016-06-11 22:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gyazo
2016-06-11 22:43 - 2016-06-11 22:43 - 15669424 _____ (Nota Inc. ) C:\Users\Host\Downloads\Gyazo-3.2.2.exe
2016-06-11 19:15 - 2016-06-11 19:15 - 00002066 _____ C:\Users\Host\AppData\Local\recently-used.xbel
2016-06-11 19:09 - 2016-06-11 19:15 - 00001283 _____ C:\Users\Host\Desktop\meleeprot.xcf
2016-06-11 18:45 - 2016-06-11 18:45 - 00000532 _____ C:\Users\Host\Desktop\dld.htm
2016-06-11 18:40 - 2012-06-01 07:39 - 00014848 _____ (Microsoft Corporation) C:\Windows\system32\wamregps.dll
2016-06-11 18:40 - 2012-06-01 07:36 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\iisRtl.dll
2016-06-11 18:40 - 2012-06-01 07:36 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\iisrstap.dll
2016-06-11 18:40 - 2012-06-01 07:35 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\ahadmin.dll
2016-06-11 18:40 - 2012-06-01 07:34 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\admwprox.dll
2016-06-11 18:40 - 2012-06-01 07:33 - 00016896 _____ (Microsoft Corporation) C:\Windows\system32\iisreset.exe
2016-06-11 18:40 - 2012-06-01 06:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wamregps.dll
2016-06-11 18:40 - 2012-06-01 06:37 - 00154624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisRtl.dll
2016-06-11 18:40 - 2012-06-01 06:37 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisrstap.dll
2016-06-11 18:40 - 2012-06-01 06:35 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\admwprox.dll
2016-06-11 18:40 - 2012-06-01 06:35 - 00026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ahadmin.dll
2016-06-11 18:40 - 2012-06-01 06:34 - 00015360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iisreset.exe
2016-06-11 17:46 - 2016-06-11 17:49 - 07069441 _____ C:\Users\Host\Desktop\Julkkis.mp4
2016-06-10 02:12 - 2016-06-10 02:32 - 00040035 _____ C:\Users\Host\Desktop\ok.wlmp
2016-06-10 01:26 - 2016-06-10 01:26 - 00000000 ____D C:\inetpub
2016-06-10 00:40 - 2016-06-10 00:40 - 00000000 ____D C:\Program Files\Hyper-V
2016-06-09 23:35 - 2016-06-18 15:58 - 00000000 ____D C:\Users\Host\Desktop\100ANDRO
2016-06-09 22:50 - 2009-07-14 03:41 - 00010240 _____ (Microsoft Corporation) C:\Windows\system32\wts.dll
2016-06-09 22:49 - 2009-07-14 03:33 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\umcRes.dll
2016-06-09 22:48 - 2010-11-20 14:44 - 00450560 _____ (Microsoft Corporation) C:\Windows\system32\tsadmin.dll
2016-06-09 22:48 - 2010-11-20 14:27 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\mstsmhst.dll
2016-06-09 22:48 - 2010-11-20 14:24 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\dnscmd.exe
2016-06-09 22:48 - 2010-11-20 14:15 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\RemoteFileBrowse.dll
2016-06-09 22:48 - 2009-07-14 03:40 - 00024064 _____ (Microsoft Corporation) C:\Windows\system32\certpick.dll
2016-06-09 22:48 - 2009-06-10 22:33 - 00063978 _____ C:\Windows\system32\tsadmin.msc
2016-06-09 22:47 - 2010-11-20 14:27 - 00246272 _____ (Microsoft Corporation) C:\Windows\system32\mstsmmc.dll
2016-06-09 22:47 - 2010-11-20 14:27 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\tsuserex.dll
2016-06-09 22:47 - 2010-11-05 02:55 - 00146694 _____ C:\Windows\system32\dhcpmgmt.msc
2016-06-09 22:47 - 2010-11-05 02:55 - 00042131 _____ C:\Windows\system32\tsmmc.msc
2016-06-09 22:47 - 2009-07-14 03:41 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\TlsBrand.dll
2016-06-09 22:46 - 2010-11-20 14:26 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\dnsmgr.dll
2016-06-09 22:46 - 2010-11-05 02:55 - 00145867 _____ C:\Windows\system32\dnsmgmt.msc
2016-06-09 22:46 - 2009-07-14 03:41 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\rsatclient.dll
2016-06-09 22:46 - 2009-07-14 03:40 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dhcpmon.dll
2016-06-09 22:46 - 2009-07-14 03:15 - 00238592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dhcpmon.dll
2016-06-09 22:45 - 2010-11-20 14:26 - 03582464 _____ (Microsoft Corporation) C:\Windows\system32\dhcpsnap.dll
2016-06-09 22:25 - 2016-06-09 22:28 - 251170997 _____ C:\Users\Host\Downloads\Windows6.1-KB958830-x64-RefreshPkg.msu
2016-06-08 01:55 - 2016-06-08 01:55 - 37452844 _____ C:\Users\Host\Desktop\yellowcoldplay.wav
2016-06-08 01:42 - 2016-06-08 01:42 - 39083564 _____ C:\Users\Host\Desktop\takemetochurch.wav
2016-06-06 23:40 - 2016-06-06 23:40 - 00108174 _____ C:\Users\Host\Downloads\CrazyMembPack 1.2.rms
2016-06-06 17:23 - 2016-06-06 17:24 - 00013886 _____ C:\Users\Host\Downloads\cenik (2).xlsx
2016-06-06 17:18 - 2016-06-06 17:18 - 00013886 _____ C:\Users\Host\Downloads\cenik (1).xlsx
2016-06-04 02:55 - 2016-06-04 02:55 - 00013886 _____ C:\Users\Host\Downloads\cenik.xlsx
2016-06-03 20:01 - 2016-06-19 18:17 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2016-05-31 20:10 - 2016-05-31 20:10 - 13163744 _____ (Microsoft Corporation) C:\Users\Host\Downloads\Silverlight_x64.exe
2016-05-30 23:16 - 2016-05-30 23:16 - 00141294 _____ C:\Users\Host\Downloads\P16416.A01 (1).pdf
2016-05-30 23:13 - 2016-05-30 23:13 - 00141294 _____ C:\Users\Host\Downloads\P16416.A01.pdf
2016-05-27 18:06 - 2016-05-28 22:20 - 00000000 ____D C:\Users\Host\AppData\LocalLow\BitTorrent
2016-05-27 08:07 - 2016-05-27 08:07 - 00001551 _____ C:\Users\Host\Desktop\VirtualBox – zástupce.lnk
2016-05-26 22:14 - 2016-05-26 22:19 - 1520762880 ____R C:\Users\Host\Downloads\kubuntu-16.04-desktop-amd64.iso
2016-05-26 22:13 - 2016-05-26 22:13 - 00058248 _____ C:\Users\Host\Downloads\kubuntu-16.04-desktop-amd64.iso.torrent
2016-05-26 22:06 - 2016-05-26 22:07 - 05111240 _____ (Piriform Ltd) C:\Users\Host\Downloads\spsetup129 (1).exe
2016-05-26 22:05 - 2016-06-02 19:48 - 00000840 _____ C:\Users\Public\Desktop\Speccy.lnk
2016-05-26 22:04 - 2016-05-26 22:05 - 00000000 ____D C:\Program Files\Speccy
2016-05-26 22:04 - 2016-05-26 22:04 - 05111240 _____ (Piriform Ltd) C:\Users\Host\Downloads\spsetup129.exe
2016-05-26 21:40 - 2016-05-26 21:42 - 258998272 _____ C:\Users\Host\Downloads\debian-8.4.0-amd64-netinst.iso
2016-05-26 21:19 - 2016-05-27 08:11 - 00000000 ____D C:\Users\Host\VirtualBox VMs
2016-05-26 21:18 - 2016-05-27 08:12 - 00000000 ____D C:\Users\Host\.VirtualBox
2016-05-26 21:17 - 2016-05-26 22:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
2016-05-26 21:17 - 2016-05-26 21:17 - 00000000 ____D C:\Program Files\Oracle
2016-05-26 21:17 - 2016-04-28 15:05 - 00916520 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxDrv.sys
2016-05-26 21:17 - 2016-04-28 15:05 - 00143568 _____ (Oracle Corporation) C:\Windows\system32\Drivers\VBoxUSBMon.sys
2016-05-24 22:22 - 2016-06-08 01:55 - 00000000 ____D C:\Users\Host\AppData\Roaming\Audacity
2016-05-24 22:21 - 2016-05-24 22:21 - 00001023 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2016-05-24 22:21 - 2016-05-24 22:21 - 00001011 _____ C:\Users\Public\Desktop\Audacity.lnk
2016-05-24 22:21 - 2016-05-24 22:21 - 00000000 ____D C:\Program Files (x86)\Audacity
2016-05-24 22:16 - 2016-05-24 22:16 - 24210616 _____ (Audacity Team ) C:\Users\Host\Downloads\audacity-win-2.1.0.exe
2016-05-24 22:05 - 2016-06-12 00:30 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-05-24 22:04 - 2016-06-19 18:14 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-05-24 22:04 - 2016-05-24 22:04 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-05-24 22:04 - 2016-05-24 22:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-05-24 22:04 - 2016-05-24 22:04 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-05-24 22:04 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2016-05-24 22:04 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-05-24 22:04 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2016-05-24 21:58 - 2016-05-24 21:59 - 22851472 _____ (Malwarebytes ) C:\Users\Host\Downloads\mbam-setup-2.2.1.1043.exe
2016-05-24 21:57 - 2016-05-24 22:01 - 1485881344 _____ C:\Users\Host\Downloads\ubuntu-16.04-desktop-amd64.iso
2016-05-24 21:57 - 2016-05-24 21:58 - 113110496 _____ (Oracle Corporation) C:\Users\Host\Downloads\VirtualBox-5.0.20-106931-Win.exe
2016-05-24 20:35 - 2016-05-24 20:35 - 00000000 ____D C:\_OTL
2016-05-22 22:51 - 2016-05-22 22:53 - 00068199 _____ C:\Users\Host\Downloads\OTL (1).zip
2016-05-22 22:48 - 2016-05-22 22:49 - 00068199 _____ C:\Users\Host\Downloads\OTL.zip
2016-05-22 22:35 - 2016-05-22 22:46 - 00097192 _____ C:\Users\Host\Downloads\Extras.Txt
2016-05-22 22:33 - 2016-05-22 22:33 - 00564854 _____ C:\Users\Host\Downloads\OTL.Txt
2016-05-22 20:54 - 2016-05-22 20:54 - 00880432 _____ C:\Users\Host\Downloads\OSBuddy (1).exe
2016-05-22 19:31 - 2016-05-22 19:31 - 00000512 _____ C:\PhysicalMBR.bin
2016-05-22 19:26 - 2016-05-22 19:26 - 00602112 _____ (OldTimer Tools) C:\Users\Host\Downloads\OTL.exe
2016-05-22 14:43 - 2016-05-22 14:43 - 00307495 _____ C:\Users\Host\Downloads\CV_2015_AJ.pdf
2016-05-22 13:01 - 2016-05-22 13:01 - 00786432 _____ C:\Windows\mod_frst.exe
2016-05-22 12:55 - 2016-06-19 20:57 - 00000000 ____D C:\FRST

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-06-19 20:53 - 2015-02-26 18:38 - 00000043 _____ C:\Users\Host\jagex_cl_oldschool_LIVE.dat
2016-06-19 20:41 - 2009-07-14 06:45 - 00027168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-06-19 20:41 - 2009-07-14 06:45 - 00027168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-06-19 19:08 - 2013-06-26 13:04 - 00000000 ____D C:\Users\Host\Desktop\Fcb
2016-06-19 18:42 - 2016-05-01 14:25 - 00000000 ____D C:\Users\Host\Desktop\algebra
2016-06-19 18:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\inetsrv
2016-06-19 18:18 - 2013-06-26 10:08 - 00000000 ____D C:\Users\Host
2016-06-19 18:18 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-06-19 18:17 - 2016-04-16 16:01 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Battle for Wesnoth 1.9.6
2016-06-19 18:17 - 2016-03-28 01:39 - 00000000 ___SD C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Battle for Wesnoth 1.13.4
2016-06-19 18:17 - 2016-03-18 02:05 - 00000000 ____D C:\ProgramData\OO Software
2016-06-19 18:17 - 2016-01-07 03:47 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software
2016-06-19 18:17 - 2015-12-19 14:35 - 00000000 ____D C:\ProgramData\Visan
2016-06-19 18:17 - 2015-12-19 14:35 - 00000000 ____D C:\ProgramData\HP Photo Creations
2016-06-19 18:17 - 2015-12-19 14:34 - 00000000 ____D C:\ProgramData\HP
2016-06-19 18:17 - 2015-10-10 16:58 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Battle for Wesnoth 1.12.4
2016-06-19 18:17 - 2015-09-28 21:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2016-06-19 18:17 - 2015-09-28 21:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2016-06-19 18:17 - 2015-07-06 15:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AutoHotkey
2016-06-19 18:17 - 2015-05-23 16:18 - 00000000 ____D C:\Users\Host\Desktop\Games
2016-06-19 18:17 - 2015-03-23 18:10 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2016-06-19 18:17 - 2015-03-02 23:02 - 00000000 ____D C:\Users\Host\OSBuddy
2016-06-19 18:17 - 2014-12-21 18:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dragon Age Origins
2016-06-19 18:17 - 2014-12-21 18:03 - 00000000 ____D C:\ProgramData\Media Center Programs
2016-06-19 18:17 - 2014-10-08 13:51 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2016-06-19 18:17 - 2014-09-22 12:03 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Heroes of Might and Magic V - Collectors Edition
2016-06-19 18:17 - 2014-08-14 19:10 - 00000000 ____D C:\ProgramData\Riot Games
2016-06-19 18:17 - 2014-06-21 17:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CorelDRAW Graphics Suite X6 (64-Bit)
2016-06-19 18:17 - 2014-06-10 15:06 - 00000000 ____D C:\ProgramData\RogueKiller
2016-06-19 18:17 - 2014-03-16 23:21 - 00000000 ____D C:\Program Files (x86)\Vypínač na dobrou noc
2016-06-19 18:17 - 2014-01-08 02:35 - 00000000 ____D C:\ProgramData\NVIDIA
2016-06-19 18:17 - 2013-12-15 16:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AoC 1.0e Patch
2016-06-19 18:17 - 2013-12-13 22:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2016-06-19 18:17 - 2013-12-13 22:26 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-06-19 18:17 - 2013-12-13 22:22 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2016-06-19 18:17 - 2013-11-03 13:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DOSBox-0.74
2016-06-19 18:17 - 2013-08-26 21:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2016-06-19 18:17 - 2013-08-22 21:30 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-06-19 18:17 - 2013-08-20 15:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Counter-Strike 1.6 Non-Steam patch v36
2016-06-19 18:17 - 2013-08-04 17:42 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2016-06-19 18:17 - 2013-08-01 20:35 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Battle for Wesnoth 1.10.6
2016-06-19 18:17 - 2013-06-26 10:46 - 00000000 ____D C:\ProgramData\Skype
2016-06-19 18:17 - 2013-06-26 10:45 - 00000000 ____D C:\Users\Host\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-06-19 18:17 - 2013-06-26 10:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BS.Player
2016-06-19 18:17 - 2013-06-26 10:42 - 00000000 ____D C:\Users\UpdatusUser
2016-06-19 18:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2016-06-19 18:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2016-06-19 18:16 - 2014-05-27 19:09 - 00000000 ____D C:\ProgramData\Steam
2016-06-19 18:16 - 2013-10-27 21:25 - 00000000 ____D C:\ProgramData\Oracle
2016-06-19 18:15 - 2013-06-26 10:41 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-06-19 18:14 - 2016-03-12 15:52 - 00000000 ____D C:\ProgramData\MindGems
2016-06-19 18:14 - 2015-09-28 21:16 - 00000000 ____D C:\ProgramData\Battle.net
2016-06-19 18:14 - 2014-06-21 17:59 - 00000000 ____D C:\ProgramData\Corel
2016-06-19 18:14 - 2013-06-26 10:32 - 00000000 ____D C:\ProgramData\Adobe
2016-06-16 00:31 - 2013-06-26 10:46 - 00000000 ____D C:\Users\Host\AppData\Roaming\Skype
2016-06-15 22:40 - 2010-11-21 05:27 - 00484008 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-06-15 18:42 - 2009-07-14 06:45 - 00489176 _____ C:\Windows\system32\FNTCACHE.DAT
2016-06-15 18:36 - 2014-12-17 16:04 - 00000000 ____D C:\Windows\system32\appraiser
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\lv-LV
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\lt-LT
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\et-EE
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lv-LV
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\lt-LT
2016-06-15 18:36 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\et-EE
2016-06-15 18:35 - 2013-06-27 08:48 - 00000000 ____D C:\Windows\et-EE
2016-06-15 18:35 - 2013-06-27 08:47 - 00000000 ____D C:\Windows\lt-LT
2016-06-15 18:35 - 2013-06-27 08:38 - 00000000 ____D C:\Windows\lv-LV
2016-06-15 00:45 - 2013-08-15 03:03 - 00000000 ____D C:\Windows\system32\MRT
2016-06-15 00:38 - 2013-06-26 10:39 - 142482544 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-06-14 22:33 - 2016-03-14 00:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Voobly
2016-06-14 22:02 - 2013-06-27 15:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-06-12 14:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\SysWOW64\inetsrv
2016-06-11 19:15 - 2015-10-07 23:44 - 00000000 ____D C:\Users\Host\.gimp-2.8
2016-06-11 19:12 - 2015-10-07 23:46 - 00000000 ____D C:\Users\Host\AppData\Local\gtk-2.0
2016-06-11 19:10 - 2015-10-07 23:42 - 00001120 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
2016-06-10 01:45 - 2015-10-08 22:13 - 00000000 ____D C:\Users\Host\AppData\Local\Windows Live
2016-06-10 01:27 - 2013-06-27 09:53 - 00744326 _____ C:\Windows\system32\perfh013.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00741090 _____ C:\Windows\system32\perfh015.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00729598 _____ C:\Windows\system32\prfh0816.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00724534 _____ C:\Windows\system32\perfh019.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00714344 _____ C:\Windows\system32\prfh0416.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00663708 _____ C:\Windows\system32\perfh01D.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00656784 _____ C:\Windows\system32\perfh01F.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00608290 _____ C:\Windows\system32\perfh008.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00509868 _____ C:\Windows\system32\perfh006.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00494606 _____ C:\Windows\system32\perfh014.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00481932 _____ C:\Windows\system32\perfh00B.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00425894 _____ C:\Windows\system32\perfh012.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00415534 _____ C:\Windows\system32\perfh011.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00398048 _____ C:\Windows\system32\prfh0404.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00380876 _____ C:\Windows\system32\prfh0804.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00159574 _____ C:\Windows\system32\perfc015.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00156352 _____ C:\Windows\system32\perfc013.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00156248 _____ C:\Windows\system32\prfc0816.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00154216 _____ C:\Windows\system32\perfc019.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00150878 _____ C:\Windows\system32\prfc0416.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00145506 _____ C:\Windows\system32\perfc01D.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00143286 _____ C:\Windows\system32\perfc01F.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00124684 _____ C:\Windows\system32\perfc011.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00122968 _____ C:\Windows\system32\perfc012.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00122176 _____ C:\Windows\system32\prfc0804.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00117674 _____ C:\Windows\system32\prfc0404.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00114676 _____ C:\Windows\system32\perfc008.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00105064 _____ C:\Windows\system32\perfc00B.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00101764 _____ C:\Windows\system32\perfc006.dat
2016-06-10 01:27 - 2013-06-27 09:53 - 00097988 _____ C:\Windows\system32\perfc014.dat
2016-06-10 01:27 - 2013-06-26 14:23 - 00684992 _____ C:\Windows\system32\perfh00E.dat
2016-06-10 01:27 - 2013-06-26 14:23 - 00174978 _____ C:\Windows\system32\perfc00E.dat
2016-06-10 01:27 - 2013-06-26 14:10 - 00745996 _____ C:\Windows\system32\perfh00A.dat
2016-06-10 01:27 - 2013-06-26 14:10 - 00161930 _____ C:\Windows\system32\perfc00A.dat
2016-06-10 01:27 - 2013-06-26 14:02 - 00391514 _____ C:\Windows\system32\perfh00D.dat
2016-06-10 01:27 - 2013-06-26 14:02 - 00087342 _____ C:\Windows\system32\perfc00D.dat
2016-06-10 01:27 - 2013-06-26 13:46 - 00740304 _____ C:\Windows\system32\perfh010.dat
2016-06-10 01:27 - 2013-06-26 13:46 - 00150090 _____ C:\Windows\system32\perfc010.dat
2016-06-10 01:27 - 2013-06-26 13:40 - 00746190 _____ C:\Windows\system32\perfh00C.dat
2016-06-10 01:27 - 2013-06-26 13:40 - 00480192 _____ C:\Windows\system32\perfh001.dat
2016-06-10 01:27 - 2013-06-26 13:40 - 00152696 _____ C:\Windows\system32\perfc00C.dat
2016-06-10 01:27 - 2013-06-26 13:40 - 00097356 _____ C:\Windows\system32\perfc001.dat
2016-06-10 01:27 - 2013-06-26 13:28 - 00697596 _____ C:\Windows\system32\perfh007.dat
2016-06-10 01:27 - 2013-06-26 13:28 - 00152158 _____ C:\Windows\system32\perfc007.dat
2016-06-10 01:27 - 2011-04-12 10:34 - 00677906 _____ C:\Windows\system32\perfh005.dat
2016-06-10 01:27 - 2011-04-12 10:34 - 00145658 _____ C:\Windows\system32\perfc005.dat
2016-06-10 01:26 - 2013-06-27 08:56 - 00000000 ____D C:\Windows\system32\ja
2016-06-10 01:26 - 2013-06-27 08:54 - 00000000 ____D C:\Windows\system32\zh-CHT
2016-06-10 01:26 - 2013-06-27 08:52 - 00000000 ____D C:\Windows\system32\pt
2016-06-10 01:26 - 2013-06-27 08:51 - 00000000 ____D C:\Windows\system32\pl
2016-06-10 01:26 - 2013-06-27 08:50 - 00000000 ____D C:\Windows\system32\tr
2016-06-10 01:26 - 2013-06-27 08:49 - 00000000 ____D C:\Windows\system32\zh-CHS
2016-06-10 01:26 - 2013-06-27 08:47 - 00000000 ____D C:\Windows\system32\ru
2016-06-10 01:26 - 2013-06-27 08:44 - 00000000 ____D C:\Windows\system32\sv
2016-06-10 01:26 - 2013-06-27 08:42 - 00000000 ____D C:\Windows\system32\ko
2016-06-10 01:26 - 2013-06-27 08:39 - 00000000 ____D C:\Windows\system32\nl
2016-06-10 01:26 - 2013-06-26 14:22 - 00000000 ____D C:\Windows\system32\hu
2016-06-10 01:26 - 2013-06-26 14:09 - 00000000 ____D C:\Windows\system32\es
2016-06-10 01:26 - 2013-06-26 13:45 - 00000000 ____D C:\Windows\system32\it
2016-06-10 01:26 - 2013-06-26 13:39 - 00000000 ____D C:\Windows\system32\fr
2016-06-10 01:26 - 2013-06-26 13:26 - 00000000 ____D C:\Windows\system32\de
2016-06-10 01:26 - 2011-04-12 10:34 - 00000000 ____D C:\Windows\system32\cs
2016-06-06 16:50 - 2009-07-14 07:13 - 17544796 _____ C:\Windows\system32\PerfStringBackup.INI
2016-06-05 14:34 - 2014-09-10 09:45 - 00000000 ____D C:\Users\Host\AppData\Local\CrashDumps
2016-06-04 22:44 - 2015-09-11 19:23 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-06-03 20:01 - 2013-08-13 19:19 - 00000000 ____D C:\Users\Host\AppData\Roaming\Dropbox
2016-06-02 23:25 - 2015-09-28 21:17 - 00000000 ____D C:\Users\Host\AppData\Local\Battle.net
2016-06-02 21:29 - 2015-09-28 21:16 - 00000000 ____D C:\Program Files (x86)\Battle.net
2016-06-02 19:53 - 2014-05-12 18:42 - 00000000 ____D C:\Users\Host\Desktop\Movie
2016-06-02 19:53 - 2013-07-05 13:07 - 00000000 ____D C:\Users\Host\Desktop\BitTorrent
2016-06-01 18:13 - 2016-05-17 21:57 - 00000000 ____D C:\Users\Host\Desktop\Morpho
2016-06-01 17:41 - 2013-07-01 23:07 - 00000000 ____D C:\Peete
2016-05-31 21:28 - 2016-04-18 20:37 - 00000000 ____D C:\Users\Host\AppData\Roaming\HearthstoneDeckTracker
2016-05-28 22:22 - 2015-02-22 04:46 - 00000000 ____D C:\Users\Host\AppData\Roaming\BitTorrent
2016-05-27 18:03 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PLA
2016-05-27 08:33 - 2016-04-18 00:12 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2016-05-27 08:33 - 2016-04-18 00:12 - 00000000 ___SD C:\Windows\system32\GWX
2016-05-27 01:32 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2016-05-26 22:50 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-05-26 21:10 - 2013-12-13 22:24 - 00000000 ____D C:\Users\Host\AppData\Roaming\DAEMON Tools Lite
2016-05-25 18:24 - 2013-06-28 08:52 - 00000000 ____D C:\Windows\System32\Tasks\HardDiskSentinel

==================== Files in the root of some directories =======

2016-06-18 17:16 - 2016-06-18 17:16 - 6867968 _____ () C:\Users\Host\AppData\Roaming\agent.dat
2016-06-18 17:15 - 2016-06-18 17:15 - 0128512 _____ () C:\Users\Host\AppData\Roaming\Installer.dat
2016-06-18 17:16 - 2016-06-18 17:16 - 0018432 _____ () C:\Users\Host\AppData\Roaming\Main.dat
2013-08-20 23:30 - 2016-02-28 22:14 - 0045270 _____ () C:\Users\Host\AppData\Roaming\room_v3.dat
2016-06-11 19:15 - 2016-06-11 19:15 - 0002066 _____ () C:\Users\Host\AppData\Local\recently-used.xbel
2015-12-19 16:17 - 2015-12-19 16:17 - 0007641 _____ () C:\Users\Host\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Host\AppData\Local\Temp\SkypeSetup.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-06-09 21:41

==================== End of FRST.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118289
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: V normálním módu nelze spustit žádný program

#6 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2504773853-1791968555-2413179023-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [No File]
CHR HomePage: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72% ... PfVLvypZg,,
C:\Users\Host\AppData\Local\Temp
End
Uložte do C:\Users\Host\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

Re: V normálním módu nelze spustit žádný program

#7 Příspěvek od detox »

Fix result of Farbar Recovery Scan Tool (x64) Version: 19-06-2016 01
Ran by Host (2016-06-19 22:09:43) Run:1
Running from C:\Users\Host\Downloads
Loaded Profiles: Host (Available Profiles: Host)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2504773853-1791968555-2413179023-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [No File]
CHR HomePage: Default -> hxxp://%66%65%65%64.%68%65%6C%70%65%72% ... PfVLvypZg,,
C:\Users\Host\AppData\Local\Temp
End
*****************

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
HKU\S-1-5-21-2504773853-1791968555-2413179023-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@pandonetworks.com/PandoWebPlugin" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@t.garena.com/garenatalk" => key removed successfully
Chrome HomePage => removed successfully

"C:\Users\Host\AppData\Local\Temp" folder move:

Could not move "C:\Users\Host\AppData\Local\Temp" => Scheduled to move on reboot.


Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 2016-06-19 22:11:58)

C:\Users\Host\AppData\Local\Temp => moved successfully

==== End of Fixlog 22:12:00 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118289
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: V normálním módu nelze spustit žádný program

#8 Příspěvek od Rudy »

Smazáno. Log by již měl být OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

detox
Návštěvník
Návštěvník
Příspěvky: 75
Registrován: 12 čer 2009 16:43

Re: V normálním módu nelze spustit žádný program

#9 Příspěvek od detox »

Děkuji mockrát.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118289
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: V normálním módu nelze spustit žádný program

#10 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět