Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Nakažení počítače Malwarem? Firefox se chová nestandardně.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Nakažení počítače Malwarem? Firefox se chová nestandardně.

#1 Příspěvek od Spawnik »

Dobrý den, chtěl bych vás požádat o pomoc při řešení problému se svým notebookem. Včera vše běželo bez problému, dnes po zapnutí sleduji u prohlížeče (Firefox) zvláštní chování. Při prvním zapnutí mi otevřel divnou stránku, která se snažila vypadat jako dlaždice při otevření nového panelu. Při vyhledávání přes adresní řádek mi občas výsledky z googlu přeskočí na jiný zvláštní vyhledávač. Antivir (ESET) mi každou chvíli vyhazuje zprávu o zablokování určité adresy.

Když jsem spustil AdwCleaner, našlo mi to pár chyb, které se již po "vyléčení" v tomto programu znovu nezobrazují. (první výsledný log přikládám jako txt)

Mohu tedy poprosit o kontrolu a případně radu, co v tomto případě dělat?

Zde ještě log z RSIT:

Logfile of random's system information tool 1.16 (written by random/random)
Run by Jiří at 2017-05-31 11:35:54
Microsoft Windows 8.1
System drive C: has 44 GB (52%) free of 85 GB
Total RAM: 6030 MB (61% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:35:55, on 31. 5. 2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
C:\WINDOWS\SysWOW64\RunDll32.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
D:\World_of_Tanks\WoTLauncher.exe
C:\Program Files\trend micro\Jiří_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ASUSPRP] "C:\Program Files (x86)\ASUS\APRP\APRP.EXE"
O4 - HKLM\..\Run: [ASUSWebStorage] C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe /S
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKUS\S-1-5-21-1196467569-3603037678-3961814420-1001\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'UpdatusUser')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - ASUSTek Computer Inc. - C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ASUS InstantOn Service (ASUS InstantOn) - ASUS - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - ASUS - C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
O23 - Service: @oem10.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10556 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\wininit.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
"C:\Windows\system32\nvvsvc.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k NetworkService
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe"
C:\WINDOWS\system32\WLANExt.exe 613912941776
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\taskhostex.exe
"C:\Program Files (x86)\ASUS\Splendid\ACMON.exe"
"C:\Program Files\ASUS\P4G\BatteryLife.exe"
"C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe"
"C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe"
"C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe"
C:\WINDOWS\system32\dashost.exe
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\ESET\ESET Security\egui.exe" /hide
C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe"
C:\Windows\system32\igfxpers.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe"
"C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe"
"C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX3
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe" -Embedding
"C:\WINDOWS\system32\igfxsrvc.exe" -Embedding
"C:\WINDOWS\SysWOW64\RunDll32.exe" "C:\Program Files\WIDCOMM\Bluetooth Software\SysWOW64\BtMmHook.dll",SetAndWaitBtMmHook
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="1272.0.1858147329\1306753492" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 1272 "\\.\pipe\gecko-crash-server-pipe.1272" gpu
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -contentproc --channel="1272.11.1232464394\1853151054" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 1272 "\\.\pipe\gecko-crash-server-pipe.1272" tab
"D:\World_of_Tanks\WoTLauncher.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\DllHost.exe /Processid:{B366DEBE-645B-43A5-B865-DDD82C345492}
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.18384_none_fa1d93c39b41b41a\TiWorker.exe -Embedding
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\WINDOWS\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"F:\Stáhnuté\RSITx64.exe"

====== Scheduled tasks folder ======

C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\Adobe Flash Player Updater - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\system32\tasks\ASUS InstantOn Config - C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnCfg.exe
C:\WINDOWS\system32\tasks\ASUS Live Update1 - C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe -critical
C:\WINDOWS\system32\tasks\ASUS Live Update2 - C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe -check
C:\WINDOWS\system32\tasks\ASUS P4G - C:\Program Files\ASUS\P4G\BatteryLife.exe
C:\WINDOWS\system32\tasks\ASUS Smart Gesture Launcher - C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe
C:\WINDOWS\system32\tasks\ASUS Splendid ACMON - C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
C:\WINDOWS\system32\tasks\ASUS Splendid ColorU - C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
C:\WINDOWS\system32\tasks\ASUS USB Charger Plus - "C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe"
C:\WINDOWS\system32\tasks\AsusVibeSchedule - "C:\Program Files (x86)\Asus\AsusVibe\AsusVibeLauncher.exe" /start
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\SafeZone scheduled Autoupdate 1494279331 - D:\Programy\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\WINDOWS\system32\tasks\Update Checker - C:\Program Files (x86)\ASUS\ASUS Live Update\UpdateChecker.exe
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-1196467569-3603037678-3961814420-1002 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\WINDOWS\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\Lpksetup - C:\WINDOWS\System32\lpksetup.exe -v
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent /increment
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\WINDOWS\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe /WatchService
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeTelemetryAgentFallBack - C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe scan upload mininterval:2880
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeTelemetryAgentLogOn - C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe scan upload

=========Mozilla firefox=========

ProfilePath - C:\Users\jirka_000\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042

prefs.js - "browser.startup.homepage" - "https://www.google.com/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.171 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.171 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll


C:\Users\jirka_000\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\addons.json
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
Classic Theme Restorer - extension - ClassicThemeRestorer@ArisT2Noia4dev
Mozilla Firefox hotfix - extension - firefox-hotfix@mozilla.org

C:\Users\jirka_000\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\extensions.json
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Adblock Plus - extension - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - C:\Users\jirka_000\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
Classic Theme Restorer - extension - ClassicThemeRestorer@ArisT2Noia4dev - C:\Users\jirka_000\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi
Shield Recipe Client - extension - shield-recipe-client@mozilla.org - C:\Users\jirka_000\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\features\{62efdbe2-123d-4ac9-add2-a62f3516801a}\shield-recipe-client@mozilla.org.xpi

C:\Users\jirka_000\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\pluginreg.dat
Plugin - Shockwave Flash - 25.0.0.171 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll

=========Google Chrome=========

C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension felcaaldnbdncclmgdcncolpebgiejap
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm
Homepage: http://www.google.com
default_search_provider.search_url:
C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\ccjleegmemocfpghkhpjmiccjcacackp]
"Path"=


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTer ... &pc=ASU2JS


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTer ... &pc=ASU2JS

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-05-16 229064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-05-16 2351920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2017-05-16 163528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2017-05-16 1744176]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2013-10-01 391128]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2013-10-01 771032]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2013-10-01 769496]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2013-05-30 13550152]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2013-05-20 1308232]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe []
"ASUSPRP"=C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2013-05-01 3187360]
"ASUSWebStorage"=C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSPanel.exe [2012-12-19 3576784]
"RemoteControl10"=C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [2013-03-08 95192]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLinkedConnections"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2017-05-31 11:34:04 ----D---- C:\rsit
2017-05-31 11:34:04 ----D---- C:\Program Files\trend micro
2017-05-31 10:26:30 ----D---- C:\AdwCleaner
2017-05-31 10:21:55 ----D---- C:\Users\jirka_000\AppData\Roaming\ESET
2017-05-31 09:40:42 ----D---- C:\ProgramData\clp
2017-05-31 08:33:27 ----D---- C:\ProgramData\ESET
2017-05-31 08:33:27 ----D---- C:\Program Files\ESET
2017-05-31 08:25:16 ----A---- C:\WINDOWS\wininit.ini
2017-05-31 08:13:35 ----D---- C:\ProgramData\Spybot - Search & Destroy
2017-05-30 16:46:59 ----D---- C:\Users\jirka_000\AppData\Roaming\vlc
2017-05-22 19:50:27 ----D---- C:\Users\jirka_000\AppData\Roaming\Wargaming.net
2017-05-18 00:29:13 ----D---- C:\ProgramData\HP
2017-05-15 08:40:27 ----D---- C:\Program Files (x86)\Adobe
2017-05-15 08:39:37 ----D---- C:\Users\jirka_000\AppData\Roaming\WinRAR
2017-05-14 19:39:39 ----D---- C:\Program Files\Microsoft Office 15
2017-05-12 14:15:57 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2017-05-12 10:18:28 ----D---- C:\Users\jirka_000\AppData\Roaming\Acronis
2017-05-12 10:17:15 ----D---- C:\ProgramData\Acronis
2017-05-12 10:17:03 ----D---- C:\Program Files (x86)\Acronis
2017-05-12 09:28:08 ----A---- C:\WINDOWS\SYSWOW64\aspnet_counters.dll
2017-05-12 09:28:08 ----A---- C:\WINDOWS\system32\aspnet_counters.dll
2017-05-12 01:45:35 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2017-05-12 01:40:59 ----D---- C:\WINDOWS\system32\appraiser
2017-05-12 01:40:15 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-05-12 01:40:15 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-05-12 01:22:12 ----A---- C:\WINDOWS\system32\sppsvc.exe
2017-05-12 01:22:12 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-05-12 01:22:09 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-05-12 01:22:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-05-12 01:21:58 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2017-05-12 01:21:57 ----A---- C:\WINDOWS\system32\drivers\fvevol.sys
2017-05-12 01:21:57 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-05-12 01:21:55 ----A---- C:\WINDOWS\system32\sppwinob.dll
2017-05-12 01:21:54 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2017-05-12 01:21:54 ----A---- C:\WINDOWS\system32\winhttp.dll
2017-05-12 01:21:51 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-05-12 01:21:51 ----A---- C:\WINDOWS\system32\kerberos.dll
2017-05-12 01:21:51 ----A---- C:\WINDOWS\system32\drivers\mup.sys
2017-05-12 01:21:50 ----A---- C:\WINDOWS\system32\drivers\ndiswan.sys
2017-05-12 01:21:49 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2017-05-12 01:21:49 ----A---- C:\WINDOWS\system32\webio.dll
2017-05-12 01:21:49 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-05-12 01:21:49 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2017-05-12 01:21:48 ----AC---- C:\WINDOWS\system32\drivers\hidclass.sys
2017-05-12 01:21:48 ----A---- C:\WINDOWS\SYSWOW64\webio.dll
2017-05-12 01:21:48 ----A---- C:\WINDOWS\SYSWOW64\rdpcore.dll
2017-05-12 01:21:48 ----A---- C:\WINDOWS\system32\Windows.Devices.Geolocation.dll
2017-05-12 01:21:48 ----A---- C:\WINDOWS\system32\tpmvsc.dll
2017-05-12 01:21:48 ----A---- C:\WINDOWS\system32\rdpcore.dll
2017-05-12 01:21:48 ----A---- C:\WINDOWS\system32\drivers\dumpfve.sys
2017-05-12 01:21:48 ----A---- C:\WINDOWS\system32\drivers\Classpnp.sys
2017-05-12 01:21:48 ----A---- C:\WINDOWS\system32\certutil.exe
2017-05-12 01:21:45 ----AC---- C:\WINDOWS\system32\drivers\hidusb.sys
2017-05-12 01:21:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Geolocation.dll
2017-05-12 01:21:44 ----A---- C:\WINDOWS\system32\LocationApi.dll
2017-05-12 01:21:44 ----A---- C:\WINDOWS\system32\gpresult.exe
2017-05-12 01:21:43 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2017-05-12 01:21:43 ----A---- C:\WINDOWS\SYSWOW64\UserAccountBroker.exe
2017-05-12 01:21:43 ----A---- C:\WINDOWS\SYSWOW64\LocationApi.dll
2017-05-12 01:21:43 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2017-05-12 01:21:43 ----A---- C:\WINDOWS\SYSWOW64\cryptxml.dll
2017-05-12 01:21:43 ----A---- C:\WINDOWS\system32\WebClnt.dll
2017-05-12 01:21:43 ----A---- C:\WINDOWS\system32\UserAccountBroker.exe
2017-05-12 01:21:43 ----A---- C:\WINDOWS\system32\fveapi.dll
2017-05-12 01:21:43 ----A---- C:\WINDOWS\system32\FirewallAPI.dll
2017-05-12 01:21:43 ----A---- C:\WINDOWS\system32\cryptxml.dll
2017-05-12 01:21:42 ----A---- C:\WINDOWS\system32\wfapigp.dll
2017-05-12 01:21:42 ----A---- C:\WINDOWS\system32\hbaapi.dll
2017-05-12 01:21:42 ----A---- C:\WINDOWS\system32\BdeHdCfgLib.dll
2017-05-12 01:21:41 ----AC---- C:\WINDOWS\system32\drivers\hidparse.sys
2017-05-12 01:21:41 ----A---- C:\WINDOWS\SYSWOW64\wfapigp.dll
2017-05-12 01:21:41 ----A---- C:\WINDOWS\SYSWOW64\hbaapi.dll
2017-05-12 01:21:41 ----A---- C:\WINDOWS\SYSWOW64\gpresult.exe
2017-05-12 01:21:41 ----A---- C:\WINDOWS\SYSWOW64\certutil.exe
2017-05-12 01:21:41 ----A---- C:\WINDOWS\SYSWOW64\certenc.dll
2017-05-12 01:21:41 ----A---- C:\WINDOWS\system32\httpprxp.dll
2017-05-12 01:21:41 ----A---- C:\WINDOWS\system32\httpprxm.dll
2017-05-12 01:21:41 ----A---- C:\WINDOWS\system32\fvecpl.dll
2017-05-12 01:21:41 ----A---- C:\WINDOWS\system32\certenc.dll
2017-05-12 01:21:41 ----A---- C:\WINDOWS\system32\bdesvc.dll
2017-05-12 01:21:41 ----A---- C:\WINDOWS\system32\adhsvc.dll
2017-05-12 01:20:59 ----A---- C:\WINDOWS\SYSWOW64\tracerpt.exe
2017-05-12 01:20:59 ----A---- C:\WINDOWS\SYSWOW64\sechost.dll
2017-05-12 01:20:59 ----A---- C:\WINDOWS\system32\tracerpt.exe
2017-05-12 01:20:59 ----A---- C:\WINDOWS\system32\sechost.dll
2017-05-12 01:10:59 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-05-12 01:10:59 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-05-12 01:10:59 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-05-12 01:10:57 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-05-12 01:10:54 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-05-12 01:10:54 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-05-12 01:10:54 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-05-12 01:10:53 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-05-12 01:10:52 ----A---- C:\WINDOWS\system32\win32k.sys
2017-05-12 01:10:52 ----A---- C:\WINDOWS\system32\rpcss.dll
2017-05-12 01:10:51 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-05-12 01:10:51 ----A---- C:\WINDOWS\system32\wininet.dll
2017-05-12 01:10:50 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-05-12 01:10:50 ----A---- C:\WINDOWS\system32\ole32.dll
2017-05-12 01:10:50 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-05-12 01:10:50 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-05-12 01:10:49 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-05-12 01:10:49 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2017-05-12 01:10:49 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-05-12 01:10:49 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2017-05-12 01:10:49 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-05-12 01:10:49 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-05-12 01:10:49 ----A---- C:\WINDOWS\system32\crypt32.dll
2017-05-12 01:10:49 ----A---- C:\WINDOWS\system32\combase.dll
2017-05-12 01:10:48 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2017-05-12 01:10:48 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-05-12 01:10:48 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2017-05-12 01:10:48 ----A---- C:\WINDOWS\system32\WsmSvc.dll
2017-05-12 01:10:48 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-05-12 01:10:48 ----A---- C:\WINDOWS\system32\gdi32.dll
2017-05-12 01:10:48 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2017-05-12 01:10:45 ----AC---- C:\WINDOWS\system32\drivers\msiscsi.sys
2017-05-12 01:10:45 ----A---- C:\WINDOWS\SYSWOW64\wmitomi.dll
2017-05-12 01:10:45 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2017-05-12 01:10:45 ----A---- C:\WINDOWS\system32\wmitomi.dll
2017-05-12 01:10:45 ----A---- C:\WINDOWS\system32\wisp.dll
2017-05-12 01:10:45 ----A---- C:\WINDOWS\system32\oleaut32.dll
2017-05-12 01:10:45 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2017-05-12 01:10:44 ----A---- C:\WINDOWS\SYSWOW64\wisp.dll
2017-05-12 01:10:44 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2017-05-12 01:10:43 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-05-12 01:10:43 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-05-12 01:10:43 ----A---- C:\WINDOWS\system32\msfeeds.dll
2017-05-12 01:10:43 ----A---- C:\WINDOWS\system32\ieetwcollector.exe
2017-05-12 01:10:42 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2017-05-12 01:10:42 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2017-05-12 01:10:42 ----A---- C:\WINDOWS\system32\vbscript.dll
2017-05-12 01:10:42 ----A---- C:\WINDOWS\system32\jscript.dll
2017-05-12 01:10:41 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2017-05-12 01:10:41 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-05-12 01:10:37 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2017-05-12 01:10:37 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2017-05-12 01:10:36 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2017-05-12 01:10:36 ----A---- C:\WINDOWS\system32\dxtrans.dll
2017-05-12 01:10:35 ----A---- C:\WINDOWS\SYSWOW64\wincorlib.dll
2017-05-12 01:10:35 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2017-05-12 01:10:35 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2017-05-12 01:10:35 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2017-05-12 01:10:35 ----A---- C:\WINDOWS\system32\webcheck.dll
2017-05-12 01:10:35 ----A---- C:\WINDOWS\system32\mshtmled.dll
2017-05-12 01:10:35 ----A---- C:\WINDOWS\system32\iepeers.dll
2017-05-12 01:10:35 ----A---- C:\WINDOWS\system32\certcli.dll
2017-05-12 01:10:34 ----A---- C:\WINDOWS\SYSWOW64\WsmWmiPl.dll
2017-05-12 01:10:34 ----A---- C:\WINDOWS\system32\WsmWmiPl.dll
2017-05-12 01:10:34 ----A---- C:\WINDOWS\system32\inetcomm.dll
2017-05-12 01:10:34 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2017-05-12 01:10:34 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-05-12 01:10:33 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2017-05-12 01:10:33 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2017-05-12 01:10:33 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2017-05-12 01:10:33 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2017-05-12 01:10:33 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-05-12 01:10:33 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2017-05-12 01:10:33 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2017-05-12 01:04:25 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-05-12 01:04:22 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-05-12 01:04:20 ----A---- C:\WINDOWS\system32\twinui.dll
2017-05-12 01:04:16 ----A---- C:\WINDOWS\system32\shell32.dll
2017-05-12 01:04:14 ----A---- C:\WINDOWS\explorer.exe
2017-05-12 01:04:13 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-05-12 01:04:13 ----A---- C:\WINDOWS\system32\RestoreOptIn.exe
2017-05-12 01:04:12 ----A---- C:\WINDOWS\SYSWOW64\RestoreOptIn.exe
2017-05-12 01:03:57 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2017-05-12 01:03:57 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2017-05-12 00:59:05 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2017-05-12 00:59:05 ----A---- C:\WINDOWS\system32\aepic.dll
2017-05-12 00:59:04 ----A---- C:\WINDOWS\system32\aeinv.dll
2017-05-12 00:59:04 ----A---- C:\WINDOWS\system32\acmigration.dll
2017-05-12 00:59:03 ----A---- C:\WINDOWS\system32\pcasvc.dll
2017-05-12 00:59:03 ----A---- C:\WINDOWS\system32\invagent.dll
2017-05-12 00:59:03 ----A---- C:\WINDOWS\system32\appraiser.dll
2017-05-12 00:59:01 ----A---- C:\WINDOWS\system32\devinv.dll
2017-05-12 00:58:57 ----A---- C:\WINDOWS\system32\generaltel.dll
2017-05-12 00:58:54 ----A---- C:\WINDOWS\system32\centel.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\SYSWOW64\mprdim.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\SYSWOW64\mprddm.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\system32\vpnike.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\system32\rasmans.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\system32\rasapi32.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\system32\mprdim.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\system32\mprddm.dll
2017-05-11 07:10:48 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2017-05-11 07:10:48 ----A---- C:\WINDOWS\system32\drivers\mountmgr.sys
2017-05-11 07:10:46 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2017-05-11 07:10:46 ----A---- C:\WINDOWS\system32\dssenh.dll
2017-05-11 07:10:44 ----A---- C:\WINDOWS\SYSWOW64\dssenh.dll
2017-05-11 07:10:44 ----A---- C:\WINDOWS\system32\rasppp.dll
2017-05-11 07:10:44 ----A---- C:\WINDOWS\system32\rasman.dll
2017-05-11 07:10:44 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys
2017-05-11 07:10:42 ----A---- C:\WINDOWS\system32\rascustom.dll
2017-05-11 07:10:40 ----A---- C:\WINDOWS\system32\rdpclip.exe
2017-05-11 07:10:38 ----A---- C:\WINDOWS\SYSWOW64\rasppp.dll
2017-05-11 07:10:38 ----A---- C:\WINDOWS\SYSWOW64\rasman.dll
2017-05-11 07:10:38 ----A---- C:\WINDOWS\SYSWOW64\iprtrmgr.dll
2017-05-11 07:10:38 ----A---- C:\WINDOWS\system32\nshwfp.dll
2017-05-11 07:10:38 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2017-05-11 07:10:32 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2017-05-11 07:10:32 ----A---- C:\WINDOWS\system32\advapi32.dll
2017-05-11 07:09:58 ----A---- C:\WINDOWS\system32\poqexec.exe
2017-05-11 07:09:54 ----A---- C:\WINDOWS\SYSWOW64\poqexec.exe
2017-05-11 07:09:49 ----A---- C:\WINDOWS\system32\tzsync.exe
2017-05-11 07:09:35 ----A---- C:\WINDOWS\SYSWOW64\appidapi.dll
2017-05-11 07:09:35 ----A---- C:\WINDOWS\system32\appidsvc.dll
2017-05-11 07:09:35 ----A---- C:\WINDOWS\system32\appidapi.dll
2017-05-11 07:06:50 ----A---- C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2017-05-09 15:48:47 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_7.dll
2017-05-09 15:48:47 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_43.dll
2017-05-09 15:48:47 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2017-05-09 15:48:47 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2017-05-09 15:48:46 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_43.dll
2017-05-09 15:48:46 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2017-05-09 15:48:45 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_6.dll
2017-05-09 15:48:45 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_4.dll
2017-05-09 15:48:45 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_43.dll
2017-05-09 15:48:45 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2017-05-09 15:48:45 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2017-05-09 15:48:45 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2017-05-09 15:48:44 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_6.dll
2017-05-09 15:48:44 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_7.dll
2017-05-09 15:48:44 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2017-05-09 15:48:44 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2017-05-09 15:48:43 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_5.dll
2017-05-09 15:48:43 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2017-05-09 15:48:41 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2017-05-09 15:48:41 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2017-05-09 15:48:40 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2017-05-09 15:48:40 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2017-05-09 15:48:39 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2017-05-09 15:48:39 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2017-05-09 15:48:39 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2017-05-09 15:48:39 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2017-05-09 15:48:39 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2017-05-09 15:48:39 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2017-05-09 15:48:38 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2017-05-09 15:48:38 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2017-05-09 15:48:38 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2017-05-09 15:48:38 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2017-05-09 15:48:37 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2017-05-09 15:48:37 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_3.dll
2017-05-09 15:48:37 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2017-05-09 15:48:37 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2017-05-09 15:48:36 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2017-05-09 15:48:36 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2017-05-09 15:48:36 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2017-05-09 15:48:36 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2017-05-09 15:48:36 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2017-05-09 15:48:36 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2017-05-09 15:48:36 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2017-05-09 15:48:36 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2017-05-09 15:48:35 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2017-05-09 15:48:35 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2017-05-09 15:48:34 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2017-05-09 15:48:34 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2017-05-09 15:48:34 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2017-05-09 15:48:34 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2017-05-09 15:48:34 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2017-05-09 15:48:34 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2017-05-09 15:48:33 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2017-05-09 15:48:33 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2017-05-09 15:48:32 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2017-05-09 15:48:31 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2017-05-09 15:48:31 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2017-05-09 15:48:29 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2017-05-09 15:48:29 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2017-05-09 15:48:29 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2017-05-09 15:48:29 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2017-05-09 15:48:28 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2017-05-09 15:48:28 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2017-05-09 15:48:28 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2017-05-09 15:48:28 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2017-05-09 15:48:28 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2017-05-09 15:48:28 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2017-05-09 15:48:28 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2017-05-09 15:48:28 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2017-05-09 15:48:27 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2017-05-09 15:48:27 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2017-05-09 15:48:24 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2017-05-09 15:48:24 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2017-05-09 15:48:24 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2017-05-09 15:48:24 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2017-05-09 15:48:24 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2017-05-09 15:48:24 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2017-05-09 15:48:24 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2017-05-09 15:48:24 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2017-05-09 15:48:23 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2017-05-09 15:48:23 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2017-05-09 15:48:23 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2017-05-09 15:48:23 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2017-05-09 15:48:23 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2017-05-09 15:48:23 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2017-05-09 15:48:22 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2017-05-09 15:48:22 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2017-05-09 15:48:22 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2017-05-09 15:48:22 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2017-05-09 15:48:22 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2017-05-09 15:48:22 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2017-05-09 15:48:21 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2017-05-09 15:48:21 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2017-05-09 15:48:21 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2017-05-09 15:48:21 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2017-05-09 15:48:21 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2017-05-09 15:48:21 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2017-05-09 15:48:21 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2017-05-09 15:48:21 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2017-05-09 15:48:20 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2017-05-09 15:48:20 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2017-05-09 15:48:20 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2017-05-09 15:48:20 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2017-05-09 15:48:20 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2017-05-09 15:48:20 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2017-05-09 15:48:20 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2017-05-09 15:48:20 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2017-05-09 15:48:19 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2017-05-09 15:48:19 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2017-05-09 15:48:19 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2017-05-09 15:48:19 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2017-05-09 15:48:17 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2017-05-09 15:48:17 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2017-05-09 15:48:17 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2017-05-09 15:48:17 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2017-05-09 15:48:17 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2017-05-09 15:48:17 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2017-05-09 15:48:17 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2017-05-09 15:48:17 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2017-05-09 15:48:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2017-05-09 15:48:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2017-05-09 15:48:16 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2017-05-09 15:48:16 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2017-05-09 15:48:16 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2017-05-09 15:48:16 ----A---- C:\WINDOWS\system32\d3dx10.dll
2017-05-09 15:48:15 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2017-05-09 15:48:15 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2017-05-09 15:48:15 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2017-05-09 15:48:15 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2017-05-09 15:48:15 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2017-05-09 15:48:15 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2017-05-09 15:48:14 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2017-05-09 15:48:14 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2017-05-09 15:48:14 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2017-05-09 15:48:14 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2017-05-09 15:48:14 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2017-05-09 15:48:14 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2017-05-09 15:48:13 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2017-05-09 15:48:13 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2017-05-09 15:48:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2017-05-09 15:48:13 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2017-05-09 15:48:13 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2017-05-09 15:48:13 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2017-05-09 15:48:11 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2017-05-09 15:48:11 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2017-05-09 15:48:11 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2017-05-09 15:48:11 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2017-05-09 15:48:10 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2017-05-09 15:48:10 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2017-05-09 15:48:09 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2017-05-09 15:48:09 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2017-05-09 15:48:09 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2017-05-09 15:48:09 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2017-05-09 15:48:09 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2017-05-09 15:48:09 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2017-05-09 15:48:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2017-05-09 15:48:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2017-05-09 15:48:08 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2017-05-09 15:48:08 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2017-05-09 14:46:58 ----D---- C:\Users\jirka_000\AppData\Roaming\TS3Client
2017-05-09 14:46:23 ----D---- C:\ProgramData\Package Cache
2017-05-09 14:42:42 ----D---- C:\Program Files\TeamSpeak 3 Client
2017-05-09 14:11:15 ----D---- C:\WINDOWS\SYSWOW64\directx
2017-05-09 13:27:07 ----D---- C:\Users\jirka_000\AppData\Roaming\Identities
2017-05-09 13:16:27 ----DC---- C:\WINDOWS\Panther
2017-05-09 13:04:49 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2017-05-09 13:00:06 ----A---- C:\WINDOWS\system32\fhcpl.dll
2017-05-09 12:59:50 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2017-05-09 12:59:50 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-05-09 12:59:50 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2017-05-09 12:59:50 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-05-09 12:49:15 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2017-05-09 12:49:15 ----A---- C:\WINDOWS\system32\d2d1.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\rasser.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\rasmxs.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\rasdiag.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\rascfg.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\QSVRMGMT.DLL
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\QSHVHOST.DLL
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\system32\mfplat.dll
2017-05-09 12:48:48 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-05-09 12:48:46 ----AC---- C:\WINDOWS\system32\drivers\intelpep.sys
2017-05-09 12:48:46 ----A---- C:\WINDOWS\SYSWOW64\WSDApi.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\SYSWOW64\vsstrace.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\SYSWOW64\vssapi.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\SYSWOW64\eventcls.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\WSDMon.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\WSDApi.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\vsstrace.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\vssapi.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\spoolsv.exe
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\rasser.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\rasmxs.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\rasdiag.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\rascfg.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\eventcls.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2017-05-09 12:48:46 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2017-05-09 12:48:46 ----A---- C:\WINDOWS\splwow64.exe
2017-05-09 12:47:47 ----A---- C:\WINDOWS\system32\msra.exe
2017-05-09 12:40:51 ----A---- C:\WINDOWS\SYSWOW64\dhcpsapi.dll
2017-05-09 12:40:51 ----A---- C:\WINDOWS\system32\dhcpsapi.dll
2017-05-09 12:40:39 ----A---- C:\WINDOWS\SYSWOW64\dbghelp.dll
2017-05-09 12:40:39 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-05-09 12:40:39 ----A---- C:\WINDOWS\system32\dbghelp.dll
2017-05-09 12:40:39 ----A---- C:\WINDOWS\system32\dbgeng.dll
2017-05-09 12:40:23 ----SD---- C:\Users\jirka_000\AppData\Roaming\Microsoft
2017-05-09 12:39:17 ----A---- C:\WINDOWS\SYSWOW64\wscapi.dll
2017-05-09 12:39:17 ----A---- C:\WINDOWS\system32\wscsvc.dll
2017-05-09 12:39:17 ----A---- C:\WINDOWS\system32\wscapi.dll
2017-05-09 12:39:00 ----AC---- C:\WINDOWS\system32\SysFxUI.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMVXENCD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMVSENCD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMVSDECD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMVENCOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOE.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMADMOE.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\VIDRESZR.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\RESAMPLEDMO.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2adec.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\MPG4DECD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\MP4SDECD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\MP43DECD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\MP3DMOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\MFWMAAEC.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\mfvdsp.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\devenum.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\SYSWOW64\COLORCNV.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMVXENCD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMVSENCD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMVSDECD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMVENCOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMSPDMOE.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMSPDMOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMADMOE.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\VIDRESZR.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\RESAMPLEDMO.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\qdvd.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\msmpeg2adec.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\MPG4DECD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\MP4SDECD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\MP43DECD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\MP3DMOD.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\MFWMAAEC.DLL
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\mfvdsp.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\mfps.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\evr.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\devenum.dll
2017-05-09 12:39:00 ----A---- C:\WINDOWS\system32\COLORCNV.DLL
2017-05-09 12:38:28 ----A---- C:\WINDOWS\SYSWOW64\PhotoMetadataHandler.dll
2017-05-09 12:38:28 ----A---- C:\WINDOWS\system32\PhotoMetadataHandler.dll
2017-05-09 12:38:15 ----A---- C:\WINDOWS\SYSWOW64\notepad.exe
2017-05-09 12:38:15 ----A---- C:\WINDOWS\system32\notepad.exe
2017-05-09 12:38:15 ----A---- C:\WINDOWS\notepad.exe
2017-05-09 12:38:04 ----A---- C:\WINDOWS\system32\drivers\udfs.sys
2017-05-09 12:37:42 ----A---- C:\WINDOWS\SYSWOW64\authz.dll
2017-05-09 12:37:42 ----A---- C:\WINDOWS\system32\authz.dll
2017-05-09 12:37:31 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2017-05-09 12:37:31 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2017-05-09 12:37:19 ----AC---- C:\WINDOWS\system32\drivers\disk.sys
2017-05-09 12:37:03 ----A---- C:\WINDOWS\system32\SystemSettingsDatabase.dll
2017-05-09 12:37:03 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-05-09 12:37:03 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2017-05-09 12:36:44 ----A---- C:\WINDOWS\system32\seclogon.dll
2017-05-09 12:36:08 ----D---- C:\WINDOWS\en-GB
2017-05-09 12:36:08 ----D---- C:\Program Files\Windows Journal
2017-05-09 12:36:07 ----D---- C:\WINDOWS\SYSWOW64\drivers\en-GB
2017-05-09 12:36:07 ----D---- C:\WINDOWS\system32\drivers\en-GB
2017-05-09 12:25:45 ----A---- C:\WINDOWS\system32\apphelp.dll
2017-05-09 12:25:43 ----A---- C:\WINDOWS\system32\drivers\RTWAVES30.dat
2017-05-09 12:25:35 ----D---- C:\Program Files\Realtek
2017-05-09 12:25:34 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2017-05-09 12:25:26 ----D---- C:\Program Files (x86)\Intel
2017-05-09 12:25:23 ----AC---- C:\WINDOWS\system32\drivers\sermouse.sys
2017-05-09 12:25:23 ----AC---- C:\WINDOWS\system32\drivers\mouhid.sys
2017-05-09 12:25:23 ----AC---- C:\WINDOWS\system32\drivers\mouclass.sys
2017-05-09 12:25:23 ----AC---- C:\WINDOWS\system32\drivers\kbdhid.sys
2017-05-09 12:25:23 ----AC---- C:\WINDOWS\system32\drivers\kbdclass.sys
2017-05-09 12:25:23 ----AC---- C:\WINDOWS\system32\drivers\i8042prt.sys
2017-05-09 12:25:23 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.DLL
2017-05-09 12:25:23 ----A---- C:\WINDOWS\system32\OpenCL.DLL
2017-05-09 12:24:51 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2017-05-09 12:24:51 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2017-05-09 12:24:35 ----D---- C:\ProgramData\NVIDIA Corporation
2017-05-09 12:24:26 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-05-09 12:24:25 ----D---- C:\Program Files\NVIDIA Corporation
2017-05-09 12:24:21 ----A---- C:\WINDOWS\SYSWOW64\EncDec.dll
2017-05-09 12:24:21 ----A---- C:\WINDOWS\SYSWOW64\CPFilters.dll
2017-05-09 12:24:21 ----A---- C:\WINDOWS\SYSWOW64\cfgbkend.dll
2017-05-09 12:24:21 ----A---- C:\WINDOWS\system32\EncDec.dll
2017-05-09 12:24:21 ----A---- C:\WINDOWS\system32\CPFilters.dll
2017-05-09 12:24:21 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2017-05-09 12:24:05 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2017-05-09 12:23:41 ----A---- C:\WINDOWS\SYSWOW64\ws2_32.dll
2017-05-09 12:23:41 ----A---- C:\WINDOWS\SYSWOW64\mswsock.dll
2017-05-09 12:23:41 ----A---- C:\WINDOWS\system32\ws2_32.dll
2017-05-09 12:23:41 ----A---- C:\WINDOWS\system32\mswsock.dll
2017-05-09 12:23:41 ----A---- C:\WINDOWS\system32\drivers\netbt.sys
2017-05-09 12:23:32 ----A---- C:\WINDOWS\SYSWOW64\ntprint.dll
2017-05-09 12:23:32 ----A---- C:\WINDOWS\system32\ntprint.dll
2017-05-09 12:23:32 ----A---- C:\WINDOWS\system32\inetpp.dll
2017-05-09 12:23:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-05-09 12:23:22 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-05-09 12:23:13 ----AC---- C:\WINDOWS\system32\drivers\bthhfenum.sys
2017-05-09 12:22:54 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2017-05-09 12:22:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-05-09 12:22:54 ----A---- C:\WINDOWS\system32\WSShared.dll
2017-05-09 12:22:54 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-05-09 12:22:31 ----A---- C:\WINDOWS\system32\nlasvc.dll
2017-05-09 12:22:31 ----A---- C:\WINDOWS\system32\ncsi.dll
2017-05-09 12:22:23 ----A---- C:\WINDOWS\system32\LockScreenContentServer.exe
2017-05-09 12:22:07 ----A---- C:\WINDOWS\SYSWOW64\eapphost.dll
2017-05-09 12:22:07 ----A---- C:\WINDOWS\SYSWOW64\eappgnui.dll
2017-05-09 12:22:07 ----A---- C:\WINDOWS\SYSWOW64\eappcfg.dll
2017-05-09 12:22:07 ----A---- C:\WINDOWS\SYSWOW64\eapp3hst.dll
2017-05-09 12:22:07 ----A---- C:\WINDOWS\system32\eapphost.dll
2017-05-09 12:22:07 ----A---- C:\WINDOWS\system32\eappgnui.dll
2017-05-09 12:22:07 ----A---- C:\WINDOWS\system32\eappcfg.dll
2017-05-09 12:22:07 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2017-05-09 12:21:51 ----A---- C:\WINDOWS\SYSWOW64\dsparse.dll
2017-05-09 12:21:51 ----A---- C:\WINDOWS\system32\dsparse.dll
2017-05-09 12:21:43 ----A---- C:\WINDOWS\SYSWOW64\tdh.dll
2017-05-09 12:21:43 ----A---- C:\WINDOWS\system32\tdh.dll
2017-05-09 12:20:54 ----A---- C:\WINDOWS\SYSWOW64\comctl32.dll
2017-05-09 12:20:54 ----A---- C:\WINDOWS\system32\comctl32.dll
2017-05-09 12:20:46 ----A---- C:\WINDOWS\SYSWOW64\WMPhoto.dll
2017-05-09 12:20:46 ----A---- C:\WINDOWS\system32\WMPhoto.dll
2017-05-09 12:20:33 ----D---- C:\WINDOWS\Prefetch
2017-05-09 12:20:31 ----A---- C:\WINDOWS\SYSWOW64\clfsw32.dll
2017-05-09 12:20:31 ----A---- C:\WINDOWS\system32\clfsw32.dll
2017-05-09 12:20:21 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2017-05-09 12:20:14 ----A---- C:\WINDOWS\SYSWOW64\WinSync.dll
2017-05-09 12:20:14 ----A---- C:\WINDOWS\system32\WinSync.dll
2017-05-09 12:20:05 ----AC---- C:\WINDOWS\system32\drivers\sdbus.sys
2017-05-09 12:20:05 ----AC---- C:\WINDOWS\system32\drivers\dumpsd.sys
2017-05-09 12:19:57 ----A---- C:\WINDOWS\SYSWOW64\sspicli.dll
2017-05-09 12:19:57 ----A---- C:\WINDOWS\system32\sspicli.dll
2017-05-09 12:19:57 ----A---- C:\WINDOWS\system32\drivers\ksecdd.sys
2017-05-09 12:19:45 ----A---- C:\WINDOWS\system32\WindowsAnytimeUpgradeui.exe
2017-05-09 12:19:37 ----AC---- C:\WINDOWS\system32\drivers\bthpan.sys
2017-05-09 12:19:30 ----A---- C:\WINDOWS\system32\drivers\ahcache.sys
2017-05-09 12:19:22 ----A---- C:\WINDOWS\system32\winlogon.exe
2017-05-09 12:19:13 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2017-05-09 12:19:13 ----A---- C:\WINDOWS\SYSWOW64\msvcp120_clr0400.dll
2017-05-09 12:19:13 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2017-05-09 12:19:13 ----A---- C:\WINDOWS\system32\msvcp120_clr0400.dll
2017-05-09 12:18:52 ----A---- C:\WINDOWS\system32\TSWbPrxy.exe
2017-05-09 12:18:44 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2017-05-09 12:18:28 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2017-05-09 12:18:28 ----A---- C:\WINDOWS\system32\rsaenh.dll
2017-05-09 12:17:41 ----AC---- C:\WINDOWS\system32\drivers\rfcomm.sys
2017-05-09 12:17:41 ----AC---- C:\WINDOWS\system32\drivers\hidbth.sys

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#2 Příspěvek od Spawnik »

2017-05-09 12:17:41 ----AC---- C:\WINDOWS\system32\drivers\bthport.sys
2017-05-09 12:16:40 ----A---- C:\WINDOWS\SYSWOW64\wpdshext.dll
2017-05-09 12:16:40 ----A---- C:\WINDOWS\system32\wpdshext.dll
2017-05-09 12:16:32 ----A---- C:\WINDOWS\SYSWOW64\mfc42u.dll
2017-05-09 12:16:32 ----A---- C:\WINDOWS\SYSWOW64\mfc42.dll
2017-05-09 12:16:32 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-05-09 12:16:32 ----A---- C:\WINDOWS\system32\mfc42u.dll
2017-05-09 12:16:32 ----A---- C:\WINDOWS\system32\mfc42.dll
2017-05-09 12:16:32 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-05-09 12:16:16 ----A---- C:\WINDOWS\SYSWOW64\qedit.dll
2017-05-09 12:16:16 ----A---- C:\WINDOWS\system32\qedit.dll
2017-05-09 12:15:55 ----A---- C:\WINDOWS\system32\basesrv.dll
2017-05-09 12:15:41 ----AC---- C:\WINDOWS\system32\drivers\tpm.sys
2017-05-09 12:15:33 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2017-05-09 12:15:26 ----A---- C:\WINDOWS\system32\ubpm.dll
2017-05-09 12:15:14 ----A---- C:\WINDOWS\SYSWOW64\WsmAuto.dll
2017-05-09 12:15:14 ----A---- C:\WINDOWS\SYSWOW64\WsmAgent.dll
2017-05-09 12:15:14 ----A---- C:\WINDOWS\system32\WsmAuto.dll
2017-05-09 12:15:14 ----A---- C:\WINDOWS\system32\WsmAgent.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\themecpl.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\SettingMonitor.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\hgcpl.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\usercpl.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\themecpl.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\stobject.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\SettingSync.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\SettingMonitor.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\hgcpl.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2017-05-09 12:15:03 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2017-05-09 12:14:40 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-05-09 12:14:40 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2017-05-09 12:14:25 ----A---- C:\WINDOWS\system32\lsm.dll
2017-05-09 12:14:16 ----AC---- C:\WINDOWS\system32\drivers\USBXHCI.SYS
2017-05-09 12:14:01 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2017-05-09 12:13:54 ----A---- C:\WINDOWS\SYSWOW64\rgb9rast.dll
2017-05-09 12:13:47 ----A---- C:\WINDOWS\system32\workfolderssvc.dll
2017-05-09 12:13:47 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2017-05-09 12:13:31 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2017-05-09 12:13:31 ----A---- C:\WINDOWS\SYSWOW64\ncryptsslp.dll
2017-05-09 12:13:31 ----A---- C:\WINDOWS\system32\schannel.dll
2017-05-09 12:13:31 ----A---- C:\WINDOWS\system32\ncryptsslp.dll
2017-05-09 12:13:14 ----A---- C:\WINDOWS\SYSWOW64\WMASF.DLL
2017-05-09 12:13:14 ----A---- C:\WINDOWS\system32\WMASF.DLL
2017-05-09 12:12:50 ----A---- C:\WINDOWS\SYSWOW64\StorageContextHandler.dll
2017-05-09 12:12:50 ----A---- C:\WINDOWS\system32\StorageContextHandler.dll
2017-05-09 12:12:18 ----A---- C:\WINDOWS\SYSWOW64\polstore.dll
2017-05-09 12:12:18 ----A---- C:\WINDOWS\SYSWOW64\gpapi.dll
2017-05-09 12:12:18 ----A---- C:\WINDOWS\SYSWOW64\FwRemoteSvr.dll
2017-05-09 12:12:18 ----A---- C:\WINDOWS\system32\polstore.dll
2017-05-09 12:12:18 ----A---- C:\WINDOWS\system32\IPSECSVC.DLL
2017-05-09 12:12:18 ----A---- C:\WINDOWS\system32\gpsvc.dll
2017-05-09 12:12:18 ----A---- C:\WINDOWS\system32\gpapi.dll
2017-05-09 12:12:18 ----A---- C:\WINDOWS\system32\FwRemoteSvr.dll
2017-05-09 12:12:08 ----A---- C:\WINDOWS\SYSWOW64\DeviceSetupStatusProvider.dll
2017-05-09 12:12:08 ----A---- C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
2017-05-09 12:12:00 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2017-05-09 12:12:00 ----A---- C:\WINDOWS\SYSWOW64\FWPUCLNT.DLL
2017-05-09 12:12:00 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2017-05-09 12:12:00 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2017-05-09 12:12:00 ----A---- C:\WINDOWS\system32\BFE.DLL
2017-05-09 12:11:52 ----A---- C:\WINDOWS\system32\csrsrv.dll
2017-05-09 12:11:27 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2017-05-09 12:11:27 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2017-05-09 12:11:11 ----AC---- C:\WINDOWS\system32\drivers\winusb.sys
2017-05-09 12:11:11 ----AC---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2017-05-09 12:11:04 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2017-05-09 12:10:57 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2017-05-09 12:10:57 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2017-05-09 12:10:57 ----A---- C:\WINDOWS\system32\comsvcs.dll
2017-05-09 12:10:57 ----A---- C:\WINDOWS\system32\catsrvut.dll
2017-05-09 12:10:47 ----A---- C:\WINDOWS\system32\services.exe
2017-05-09 12:10:40 ----A---- C:\WINDOWS\system32\wwanmm.dll
2017-05-09 12:10:40 ----A---- C:\WINDOWS\system32\wwanconn.dll
2017-05-09 12:10:40 ----A---- C:\WINDOWS\system32\pnidui.dll
2017-05-09 12:10:31 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2017-05-09 12:10:31 ----A---- C:\WINDOWS\system32\netcfgx.dll
2017-05-09 12:10:11 ----A---- C:\WINDOWS\SYSWOW64\shacct.dll
2017-05-09 12:10:11 ----A---- C:\WINDOWS\system32\shacct.dll
2017-05-09 12:10:04 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2017-05-09 12:10:04 ----A---- C:\WINDOWS\system32\SRH.dll
2017-05-09 12:09:49 ----A---- C:\WINDOWS\SYSWOW64\taskeng.exe
2017-05-09 12:09:49 ----A---- C:\WINDOWS\SYSWOW64\schtasks.exe
2017-05-09 12:09:49 ----A---- C:\WINDOWS\system32\taskeng.exe
2017-05-09 12:09:49 ----A---- C:\WINDOWS\system32\schtasks.exe
2017-05-09 12:09:49 ----A---- C:\WINDOWS\system32\schedsvc.dll
2017-05-09 12:09:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-05-09 12:09:41 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-05-09 12:09:34 ----A---- C:\WINDOWS\SYSWOW64\calc.exe
2017-05-09 12:09:34 ----A---- C:\WINDOWS\system32\calc.exe
2017-05-09 12:09:27 ----A---- C:\WINDOWS\SYSWOW64\davclnt.dll
2017-05-09 12:09:27 ----A---- C:\WINDOWS\system32\davclnt.dll
2017-05-09 12:09:19 ----A---- C:\WINDOWS\system32\storewuauth.dll
2017-05-09 12:09:04 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-05-09 12:09:04 ----A---- C:\WINDOWS\system32\msxml6.dll
2017-05-09 12:08:55 ----A---- C:\WINDOWS\system32\drivers\vpci.sys
2017-05-09 12:08:48 ----A---- C:\WINDOWS\system32\AuthHost.exe
2017-05-09 12:08:40 ----AC---- C:\WINDOWS\system32\drivers\usbuhci.sys
2017-05-09 12:08:40 ----AC---- C:\WINDOWS\system32\drivers\usbport.sys
2017-05-09 12:08:40 ----AC---- C:\WINDOWS\system32\drivers\usbohci.sys
2017-05-09 12:08:40 ----AC---- C:\WINDOWS\system32\drivers\usbhub.sys
2017-05-09 12:08:40 ----AC---- C:\WINDOWS\system32\drivers\usbehci.sys
2017-05-09 12:08:40 ----AC---- C:\WINDOWS\system32\drivers\usbd.sys
2017-05-09 12:08:18 ----A---- C:\WINDOWS\system32\drivers\IPMIDrv.sys
2017-05-09 12:08:12 ----A---- C:\WINDOWS\SYSWOW64\pku2u.dll
2017-05-09 12:08:12 ----A---- C:\WINDOWS\system32\pku2u.dll
2017-05-09 12:08:01 ----A---- C:\WINDOWS\system32\sysmain.dll
2017-05-09 12:07:50 ----A---- C:\WINDOWS\SYSWOW64\InkEd.dll
2017-05-09 12:07:50 ----A---- C:\WINDOWS\system32\InkEd.dll
2017-05-09 12:07:39 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-05-09 12:07:39 ----A---- C:\WINDOWS\system32\SHCore.dll
2017-05-09 12:07:17 ----A---- C:\WINDOWS\system32\drivers\tunnel.sys
2017-05-09 12:07:03 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2017-05-09 12:06:56 ----AC---- C:\WINDOWS\system32\drivers\volmgr.sys
2017-05-09 12:06:49 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2017-05-09 12:06:49 ----A---- C:\WINDOWS\system32\dwmcore.dll
2017-05-09 12:06:42 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2017-05-09 12:06:42 ----A---- C:\WINDOWS\system32\scesrv.dll
2017-05-09 12:06:35 ----A---- C:\WINDOWS\SYSWOW64\atlthunk.dll
2017-05-09 12:06:27 ----A---- C:\WINDOWS\SYSWOW64\mtxoci.dll
2017-05-09 12:06:27 ----A---- C:\WINDOWS\SYSWOW64\msorcl32.dll
2017-05-09 12:06:27 ----A---- C:\WINDOWS\system32\mtxoci.dll
2017-05-09 12:06:14 ----A---- C:\WINDOWS\system32\profsvc.dll
2017-05-09 12:06:01 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2017-05-09 12:06:01 ----A---- C:\WINDOWS\system32\mfds.dll
2017-05-09 11:55:37 ----A---- C:\WINDOWS\system32\VSSVC.exe
2017-05-09 11:55:32 ----AC---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2017-05-09 11:55:28 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-05-09 11:55:28 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2017-05-09 11:55:28 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2017-05-09 11:55:28 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2017-05-09 11:55:28 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2017-05-09 11:55:28 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2017-05-09 11:55:28 ----A---- C:\WINDOWS\system32\tquery.dll
2017-05-09 11:55:28 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2017-05-09 11:55:28 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2017-05-09 11:55:28 ----A---- C:\WINDOWS\system32\mssvp.dll
2017-05-09 11:55:28 ----A---- C:\WINDOWS\system32\mssrch.dll
2017-05-09 11:55:28 ----A---- C:\WINDOWS\system32\mssphtb.dll
2017-05-09 11:55:28 ----A---- C:\WINDOWS\system32\mssph.dll
2017-05-09 11:55:23 ----A---- C:\WINDOWS\SYSWOW64\untfs.dll
2017-05-09 11:55:23 ----A---- C:\WINDOWS\system32\untfs.dll
2017-05-09 11:55:17 ----AC---- C:\WINDOWS\system32\drivers\volsnap.sys
2017-05-09 11:55:07 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2017-05-09 11:55:07 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2017-05-09 11:54:35 ----A---- C:\WINDOWS\SYSWOW64\GeofenceMonitorService.dll
2017-05-09 11:54:35 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2017-05-09 11:54:25 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2017-05-09 11:54:25 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\winshfhc.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\msobjs.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\SYSWOW64\adtschema.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\wu.upgrade.ps.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\winshfhc.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\UtcResources.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\storagewmi.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\microsoft-windows-system-events.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\drivers\cmimcext.sys
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-05-09 11:53:32 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\wmploc.DLL
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\MSVidCtl.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\mfmjpegdec.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\hlink.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\wmploc.DLL
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\wmp.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\rdpudd.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\mfsvr.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\mfmjpegdec.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\apisetschema.dll
2017-05-09 11:53:31 ----A---- C:\WINDOWS\system32\actxprxy.dll
2017-05-09 11:53:30 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2017-05-09 11:53:30 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2017-05-09 11:53:30 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2017-05-09 11:53:29 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\xolehlp.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\WinSCard.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\user.exe
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\shsetup.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\setup16.exe
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\samlib.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\rastapi.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\pdh.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\offreg.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\ntshrui.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\ncrypt.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\msiexec.exe
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\msdtcprx.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\IPHLPAPI.DLL
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\instnm.exe
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\GlobCollationHost.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\glcndFilter.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\esent.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\bcrypt.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\asycfilt.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\SYSWOW64\adsmsext.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\winresume.exe
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\winload.exe
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\win32spl.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\user32.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\UIAnimation.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\shsetup.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\SessEnv.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\rastapi.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\puiobj.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\puiapi.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\ntshrui.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\MSVidCtl.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\msrating.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\msctf.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\mscms.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\localspl.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\inseng.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\input.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\ieui.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\icm32.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\hlink.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\glcndFilter.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\FntCache.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\DWrite.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\drivers\vwifimp.sys
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\drivers\vwififlt.sys
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\drivers\vwifibus.sys
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\drivers\refs.sys
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\dab.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\d3d11.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\d3d10level9.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\compstui.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\authui.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\atmlib.dll
2017-05-09 11:53:26 ----A---- C:\WINDOWS\system32\atmfd.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wuwebv.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wups2.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wups.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wudriver.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wucltux.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wuauclt.exe
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wuapp.exe
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\wuaext.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\WinSCard.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\ScDeviceEnum.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\msxml3.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\drivers\scfilter.sys
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\consent.exe
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\certprop.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\appinfo.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\system32\adsmsext.dll
2017-05-09 11:53:25 ----A---- C:\WINDOWS\HelpPane.exe
2017-05-09 11:53:22 ----AC---- C:\WINDOWS\system32\drivers\vhdmp.sys
2017-05-09 11:53:22 ----AC---- C:\WINDOWS\system32\drivers\stornvme.sys
2017-05-09 11:53:22 ----AC---- C:\WINDOWS\system32\drivers\spaceport.sys
2017-05-09 11:53:22 ----AC---- C:\WINDOWS\system32\drivers\serial.sys
2017-05-09 11:53:22 ----AC---- C:\WINDOWS\system32\drivers\serenum.sys
2017-05-09 11:53:22 ----AC---- C:\WINDOWS\system32\drivers\parport.sys
2017-05-09 11:53:22 ----AC---- C:\WINDOWS\system32\drivers\BasicRender.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\UIAnimation.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\SessEnv.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\mscms.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\iscsiwmi.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\iscsidsc.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\icm32.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\d3d10level9.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\xolehlp.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\wow64cpu.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\wow64.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\wintrust.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\wininit.exe
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\wbengine.exe
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\vmrdvcore.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\samsrv.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\samlib.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\quartz.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\pdh.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\offreg.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\ntdll.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\netlogon.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\ncrypt.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\msv1_0.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\msobjs.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\msiexec.exe
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\msi.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\mispace.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\iscsiwmi.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\iscsiexe.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\iscsidsc.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\IPHLPAPI.DLL
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\GlobCollationHost.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\esent.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\tm.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\srvnet.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\http.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\drivers\bowser.sys
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\dnsapi.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\bcrypt.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\asycfilt.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\adtschema.dll
2017-05-09 11:53:22 ----A---- C:\WINDOWS\system32\ActionQueue.dll
2017-05-09 11:49:07 ----A---- C:\WINDOWS\system32\dpapisrv.dll
2017-05-09 11:48:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-05-09 11:48:40 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-05-09 11:48:35 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-05-09 11:48:35 ----A---- C:\WINDOWS\system32\msftedit.dll
2017-05-09 11:48:32 ----A---- C:\WINDOWS\SYSWOW64\photowiz.dll
2017-05-09 11:48:32 ----A---- C:\WINDOWS\system32\photowiz.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\SYSWOW64\WerFaultSecure.exe
2017-05-09 11:48:28 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\SYSWOW64\Faultrep.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\system32\WerFaultSecure.exe
2017-05-09 11:48:28 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\system32\wer.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\system32\Faultrep.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\system32\EncDump.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\system32\ci.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\system32\audiosrv.dll
2017-05-09 11:48:28 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-05-09 11:45:23 ----D---- C:\Program Files (x86)\Reference Assemblies
2017-05-09 11:45:23 ----D---- C:\Program Files (x86)\MSBuild
2017-05-09 11:45:22 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2017-05-09 11:45:22 ----D---- C:\Program Files\Reference Assemblies
2017-05-09 11:45:22 ----D---- C:\Program Files\MSBuild
2017-05-09 11:44:34 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2017-05-09 11:44:29 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-05-09 11:44:07 ----A---- C:\WINDOWS\SYSWOW64\sdbinst.exe
2017-05-09 11:44:05 ----A---- C:\WINDOWS\system32\sdbinst.exe
2017-05-09 00:28:00 ----D---- C:\WINDOWS\pss
2017-05-08 23:34:35 ----D---- C:\Program Files (x86)\Google
2017-05-08 23:10:46 ----D---- C:\Program Files\Common Files\AV
2017-05-08 21:52:33 ----D---- C:\WINDOWS\system32\AutoUpdateLicense
2017-05-08 20:46:08 ----D---- C:\ProgramData\AVAST Software
2017-05-08 20:40:23 ----D---- C:\Users\jirka_000\AppData\Roaming\Mozilla
2017-05-08 20:40:15 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2017-05-08 20:40:12 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-05-08 20:16:05 ----D---- C:\WINDOWS\Migration
2017-05-08 19:45:42 ----D---- C:\WINDOWS\system32\MRT
2017-05-08 19:45:38 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-05-08 16:05:28 ----D---- C:\Users\jirka_000\AppData\Roaming\ASUS WebStorage
2017-05-08 16:00:56 ----A---- C:\Users\jirka_000\AppData\Roaming\sp_data.sys
2017-05-08 16:00:05 ----D---- C:\Users\jirka_000\AppData\Roaming\Macromedia
2017-05-08 16:00:00 ----D---- C:\Users\jirka_000\AppData\Roaming\Adobe
2017-05-08 15:51:19 ----SHD---- C:\ProgramData\Šablony
2017-05-08 15:51:19 ----SHD---- C:\ProgramData\Nabídka Start
2017-05-08 15:51:19 ----SHD---- C:\ProgramData\Dokumenty
2017-05-08 15:51:19 ----SHD---- C:\ProgramData\Data aplikací
2017-05-08 15:51:18 ----SHD---- C:\ProgramData\Plocha
2017-05-08 15:09:31 ----HD---- C:\$SysReset
2017-05-04 13:18:04 ----A---- C:\WINDOWS\system32\drivers\epfwwfpr.sys
2017-05-04 13:18:04 ----A---- C:\WINDOWS\system32\drivers\ehdrv.sys
2017-05-04 13:18:04 ----A---- C:\WINDOWS\system32\drivers\eelam.sys
2017-05-04 13:18:04 ----A---- C:\WINDOWS\system32\drivers\eamonm.sys

====== List of files/folders modified in the last 1 month ======

2017-05-31 11:35:40 ----D---- C:\WINDOWS\Temp
2017-05-31 11:34:04 ----RD---- C:\Program Files
2017-05-31 11:00:00 ----D---- C:\WINDOWS\system32\sru
2017-05-31 10:45:47 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2017-05-31 10:43:05 ----D---- C:\WINDOWS\Inf
2017-05-31 10:36:27 ----SHD---- C:\WINDOWS\Installer
2017-05-31 10:36:23 ----SHD---- C:\Config.Msi
2017-05-31 10:36:23 ----HD---- C:\ProgramData
2017-05-31 10:36:17 ----D---- C:\Program Files (x86)
2017-05-31 10:36:16 ----D---- C:\Program Files (x86)\Common Files
2017-05-31 10:36:13 ----D---- C:\WINDOWS\system32\drivers
2017-05-31 09:40:22 ----SHD---- C:\System Volume Information
2017-05-31 08:33:46 ----D---- C:\WINDOWS\system32\DriverStore
2017-05-31 08:33:44 ----HD---- C:\WINDOWS\ELAMBKUP
2017-05-31 08:31:29 ----D---- C:\WINDOWS\System32
2017-05-31 08:31:27 ----D---- C:\WINDOWS\system32\Tasks
2017-05-31 08:25:53 ----D---- C:\WINDOWS\Logs
2017-05-31 08:25:17 ----SD---- C:\ProgramData\Microsoft
2017-05-31 08:25:16 ----D---- C:\Windows
2017-05-30 08:18:19 ----D---- C:\WINDOWS\Microsoft.NET
2017-05-26 15:22:46 ----D---- C:\WINDOWS\system32\NDF
2017-05-26 15:10:40 ----D---- C:\WINDOWS\system32\config
2017-05-23 10:29:18 ----D---- C:\WINDOWS\WinSxS
2017-05-23 10:20:51 ----RSD---- C:\WINDOWS\assembly
2017-05-19 08:31:01 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2017-05-19 08:27:51 ----D---- C:\WINDOWS\SysWOW64
2017-05-16 22:17:24 ----D---- C:\WINDOWS\system32\catroot2
2017-05-15 08:40:23 ----D---- C:\ProgramData\Adobe
2017-05-14 19:41:26 ----D---- C:\Program Files (x86)\Microsoft.NET
2017-05-14 19:40:54 ----RSD---- C:\WINDOWS\Fonts
2017-05-14 15:30:26 ----D---- C:\WINDOWS\rescache
2017-05-14 15:25:01 ----D---- C:\WINDOWS\CbsTemp
2017-05-14 15:20:20 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-05-14 15:20:20 ----D---- C:\WINDOWS\WinStore
2017-05-14 15:20:20 ----D---- C:\WINDOWS\SYSWOW64\WCN
2017-05-14 15:20:20 ----D---- C:\WINDOWS\SYSWOW64\wbem
2017-05-14 15:20:20 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2017-05-14 15:20:20 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2017-05-14 15:20:20 ----D---- C:\WINDOWS\SYSWOW64\oobe
2017-05-14 15:20:20 ----D---- C:\WINDOWS\SYSWOW64\drivers
2017-05-14 15:20:20 ----D---- C:\WINDOWS\system32\Sysprep
2017-05-14 15:20:20 ----D---- C:\WINDOWS\system32\slmgr
2017-05-14 15:20:20 ----D---- C:\WINDOWS\system32\sk-SK
2017-05-14 15:20:20 ----D---- C:\WINDOWS\system32\oobe
2017-05-14 15:20:20 ----D---- C:\WINDOWS\system32\migwiz
2017-05-14 15:20:20 ----D---- C:\WINDOWS\servicing
2017-05-14 15:20:20 ----D---- C:\WINDOWS\PolicyDefinitions
2017-05-14 15:20:20 ----D---- C:\Program Files\Windows Photo Viewer
2017-05-14 15:20:20 ----D---- C:\Program Files\Windows Media Player
2017-05-14 15:20:20 ----D---- C:\Program Files\Windows Mail
2017-05-14 15:20:20 ----D---- C:\Program Files\Windows Defender
2017-05-14 15:20:20 ----D---- C:\Program Files\Internet Explorer
2017-05-14 15:20:20 ----D---- C:\Program Files\Common Files\System
2017-05-14 15:20:20 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-05-14 15:20:20 ----D---- C:\Program Files (x86)\Windows Media Player
2017-05-14 15:20:20 ----D---- C:\Program Files (x86)\Windows Mail
2017-05-14 15:20:20 ----D---- C:\Program Files (x86)\Windows Defender
2017-05-14 15:20:20 ----D---- C:\Program Files (x86)\Internet Explorer
2017-05-14 15:20:19 ----D---- C:\WINDOWS\system32\WCN
2017-05-14 15:20:19 ----D---- C:\WINDOWS\system32\wbem
2017-05-14 15:20:19 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2017-05-14 15:20:19 ----D---- C:\WINDOWS\Help
2017-05-14 15:08:49 ----D---- C:\WINDOWS\SYSWOW64\winrm
2017-05-14 15:08:49 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2017-05-14 15:08:49 ----D---- C:\WINDOWS\SYSWOW64\MUI
2017-05-14 15:08:49 ----D---- C:\WINDOWS\SYSWOW64\migration
2017-05-14 15:08:49 ----D---- C:\WINDOWS\SYSWOW64\Dism
2017-05-14 15:08:48 ----D---- C:\WINDOWS\SYSWOW64\Printing_Admin_Scripts
2017-05-14 15:08:48 ----D---- C:\WINDOWS\SYSWOW64\Com
2017-05-14 15:08:48 ----D---- C:\WINDOWS\system32\winrm
2017-05-14 15:08:48 ----D---- C:\WINDOWS\system32\pl-PL
2017-05-14 15:08:48 ----D---- C:\WINDOWS\system32\MUI
2017-05-14 15:08:48 ----D---- C:\WINDOWS\system32\migration
2017-05-14 15:08:48 ----D---- C:\WINDOWS\system32\drivers\UMDF
2017-05-14 15:08:48 ----D---- C:\WINDOWS\system32\Dism
2017-05-14 15:08:48 ----D---- C:\WINDOWS\system32\Boot
2017-05-14 15:08:48 ----D---- C:\WINDOWS\IME
2017-05-14 15:08:47 ----D---- C:\WINDOWS\system32\Printing_Admin_Scripts
2017-05-14 15:08:47 ----D---- C:\WINDOWS\system32\Com
2017-05-14 15:08:47 ----D---- C:\WINDOWS\apppatch
2017-05-14 14:59:26 ----D---- C:\WINDOWS\SYSWOW64\hu-HU
2017-05-14 14:59:25 ----D---- C:\WINDOWS\system32\hu-HU
2017-05-14 10:43:25 ----D---- C:\WINDOWS\AppReadiness
2017-05-14 10:28:58 ----D---- C:\WINDOWS\system32\LogFiles
2017-05-13 01:10:52 ----D---- C:\WINDOWS\AppCompat
2017-05-12 20:34:04 ----HD---- C:\Program Files\WindowsApps
2017-05-12 16:49:18 ----D---- C:\ProgramData\Temp
2017-05-12 15:48:37 ----D---- C:\WINDOWS\system32\wdi
2017-05-12 12:35:55 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-12 09:29:06 ----D---- C:\WINDOWS\system32\SecureBootUpdates
2017-05-12 09:10:20 ----D---- C:\WINDOWS\SYSWOW64\en-US
2017-05-12 09:10:20 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2017-05-12 09:10:20 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2017-05-12 09:10:20 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-05-12 09:10:20 ----D---- C:\WINDOWS\system32\en-US
2017-05-12 09:10:20 ----D---- C:\WINDOWS\system32\en-GB
2017-05-12 09:10:13 ----D---- C:\WINDOWS\system32\drivers\en-US
2017-05-12 09:10:11 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-05-12 09:10:11 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2017-05-12 09:10:11 ----D---- C:\WINDOWS\system32\cs-CZ
2017-05-12 02:09:14 ----D---- C:\Program Files (x86)\ASUS
2017-05-12 01:40:59 ----SD---- C:\WINDOWS\system32\CompatTel
2017-05-12 01:40:59 ----D---- C:\WINDOWS\SYSWOW64\setup
2017-05-12 01:40:59 ----D---- C:\WINDOWS\system32\setup
2017-05-12 01:40:53 ----RD---- C:\WINDOWS\ToastData
2017-05-09 15:35:09 ----D---- C:\WINDOWS\system32\Macromed
2017-05-09 15:35:07 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-05-09 14:43:59 ----D---- C:\WINDOWS\system32\restore
2017-05-09 14:35:54 ----D---- C:\WINDOWS\Log
2017-05-09 13:27:46 ----SHD---- C:\$Recycle.Bin
2017-05-09 13:26:36 ----D---- C:\WINDOWS\SoftwareDistribution
2017-05-09 13:16:15 ----SHD---- C:\Recovery
2017-05-09 13:06:49 ----D---- C:\Program Files\Windows NT
2017-05-09 13:06:22 ----D---- C:\WINDOWS\debug
2017-05-09 13:05:21 ----D---- C:\WINDOWS\Registration
2017-05-09 12:58:53 ----D---- C:\WINDOWS\FileManager
2017-05-09 12:58:51 ----RSD---- C:\WINDOWS\Media
2017-05-09 12:54:24 ----D---- C:\WINDOWS\SYSWOW64\NV
2017-05-09 12:54:23 ----D---- C:\WINDOWS\system32\NV
2017-05-09 12:48:04 ----D---- C:\WINDOWS\sk
2017-05-09 12:48:04 ----D---- C:\WINDOWS\pl
2017-05-09 12:48:03 ----D---- C:\WINDOWS\hu
2017-05-09 12:48:03 ----D---- C:\WINDOWS\cs
2017-05-09 12:44:58 ----D---- C:\WINDOWS\SYSWOW64\sysprep
2017-05-09 12:44:58 ----D---- C:\WINDOWS\SYSWOW64\SMI
2017-05-09 12:44:58 ----D---- C:\WINDOWS\SYSWOW64\sda
2017-05-09 12:44:57 ----D---- C:\WINDOWS\SYSWOW64\migwiz
2017-05-09 12:44:57 ----D---- C:\WINDOWS\SYSWOW64\LogFiles
2017-05-09 12:44:56 ----D---- C:\WINDOWS\SYSWOW64\IME
2017-05-09 12:44:55 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2017-05-09 12:44:54 ----D---- C:\WINDOWS\SYSWOW64\catroot
2017-05-09 12:44:50 ----D---- C:\WINDOWS\system32\spool
2017-05-09 12:44:47 ----D---- C:\WINDOWS\system32\IME
2017-05-09 12:43:05 ----D---- C:\WINDOWS\DigitalLocker
2017-05-09 12:43:03 ----RD---- C:\Users
2017-05-09 12:43:03 ----D---- C:\ProgramData\PRICache
2017-05-09 12:42:59 ----SHD---- C:\Program Files (x86)\Windows Sidebar
2017-05-09 12:42:53 ----SHD---- C:\Program Files\Windows Sidebar
2017-05-09 12:42:52 ----D---- C:\Program Files\Common Files\microsoft shared
2017-05-09 12:42:50 ----D---- C:\Program Files\Common Files
2017-05-09 12:41:33 ----D---- C:\WINDOWS\system32\Recovery
2017-05-09 12:36:08 ----D---- C:\WINDOWS\SYSWOW64\en
2017-05-09 12:36:07 ----D---- C:\WINDOWS\SYSWOW64\drivers\en-US
2017-05-09 12:36:07 ----D---- C:\WINDOWS\system32\en
2017-05-09 12:36:07 ----D---- C:\WINDOWS\en-US
2017-05-09 12:25:29 ----D---- C:\WINDOWS\system32\catroot
2017-05-09 11:54:05 ----D---- C:\WINDOWS\system32\CodeIntegrity
2017-05-09 11:48:30 ----D---- C:\WINDOWS\system32\AdvancedInstallers
2017-05-09 11:48:07 ----SD---- C:\WINDOWS\system32\Microsoft
2017-05-09 09:17:00 ----D---- C:\WINDOWS\AUInstallAgent
2017-05-09 00:41:29 ----D---- C:\Program Files\mcafee

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2012-09-14 647736]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2016-04-21 47048]
R1 ATKWMIACPIIO;ATKWMIACPI Driver; \??\C:\Program Files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [2013-07-02 19768]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2017-05-04 132848]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2017-05-04 178056]
R1 epfwwfpr;epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [2017-05-04 77224]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2017-05-09 71680]
R2 ASMMAP64;ASMMAP64; \??\C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [2009-07-02 15416]
R3 AiCharger;ASUS Charger Driver; C:\WINDOWS\system32\DRIVERS\AiCharger.sys [2012-09-18 17152]
R3 ATP;@oem21.inf,%PS2.DeviceDesc%;ASUS Input Device; C:\WINDOWS\System32\drivers\AsusTP.sys [2013-12-12 70928]
R3 bcbtums;@oem10.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2013-08-08 170712]
R3 BCM43XX;@oem5.inf,%BCM43XX_Service_DispName%;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2014-04-18 8462000]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2014-11-21 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2017-05-09 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-11-21 81920]
R3 btwampfl;@oem10.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2013-09-05 166104]
R3 btwaudio;@oem6.inf,%btaudio.SvcDesc%;Bluetooth Audio Device Service; C:\WINDOWS\system32\drivers\btwaudio.sys [2013-10-10 189144]
R3 btwavdt;@oem7.inf,%btwavdt.SVCDESC%;Bluetooth AVDT Service; C:\WINDOWS\System32\drivers\btwavdt.sys [2013-10-10 230104]
R3 btwl2cap;@oem9.inf,%btwl2cap.SVCDESC%;Bluetooth L2CAP Service; C:\WINDOWS\system32\DRIVERS\btwl2cap.sys [2012-07-27 40248]
R3 btwrchid;btwrchid; C:\WINDOWS\System32\drivers\btwrchid.sys [2013-10-10 38616]
R3 HIDSwitch;@oem12.inf,%ASSW.DisplayName%;ASUS Wireless Radio Control; C:\WINDOWS\System32\drivers\AsHIDSwitch64.sys [2013-10-08 20280]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2013-10-01 4177920]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2013-06-04 3441992]
R3 IntcDAud;@oem17.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\WINDOWS\system32\DRIVERS\IntcDAud.sys [2013-01-09 342528]
R3 iwdbus;@oem28.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\WINDOWS\System32\drivers\iwdbus.sys [2013-08-23 26008]
R3 kbfiltr;@oem14.inf,%kbfiltr.SvcDesc%;Keyboard Filter; C:\WINDOWS\System32\drivers\kbfiltr.sys [2012-08-02 14992]
R3 MEIx64;@oem13.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-04-21 11141056]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2017-05-09 167424]
R3 RSBASTOR;@oem3.inf,%Rts5208%;Realtek PCIE CardReader Driver - BA; C:\WINDOWS\system32\DRIVERS\RtsBaStor.sys [2012-10-08 298640]
R3 RTL8168;@netrt630x64.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt630x64.sys [2013-06-18 591360]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-11-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2017-05-09 38912]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2017-05-04 14880]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2017-05-09 1201664]
S3 intaud_WaveExtensible;@oem27.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\WINDOWS\system32\drivers\intelaud.sys [2013-08-23 39320]
S3 usbscan;@sti.inf,%usbscan.SvcDesc%;Ovladač skeneru USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2014-11-21 44544]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 ASLDRService;ASLDR Service; C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe [2013-09-09 111416]
R2 ASUS InstantOn;ASUS InstantOn Service; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [2012-04-13 277120]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe [2011-11-21 96896]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2013-10-25 976600]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2017-03-14 3042544]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Security\ekrn.exe [2017-04-26 2625368]
R2 IconMan_R;IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-09-13 2466448]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 Intel(R) ME Service;Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [2012-06-27 129856]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-06-25 166720]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-17 277824]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2013-07-08 884512]
R2 nvUpdatusService;NVIDIA Update Service Daemon; C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe [2013-05-16 1826592]
R2 UNS;Intel(R) Management and Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2012-07-17 365376]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2012-04-24 169752]
S2 BcmBtRSupport;@oem10.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2013-08-08 2252504]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-09 153168]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-09 271864]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll" = %SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2013-10-01 279000]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-09 153168]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-05-21 173512]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2013-02-01 150600]
S4 Asus WebStorage Windows Service;Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.18.159\AsusWSWinService.exe [2012-12-19 72192]

-----------------EOF-----------------

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#3 Příspěvek od Spawnik »

Nevidím, že by se k příspěvku připojil ten log z AdwCleaneru.. Zde aspoň zkopírovaný text (snad v něčem pomůže):

# AdwCleaner v6.047 - Log vytvořen 31/05/2017 v 10:32:24
# Aktualizováno dne 19/05/2017 z Malwarebytes
# Databáze : 2017-05-30.2 [Server]
# Operační systém : Windows 8.1 (X64)
# Uživatelské jméno : Jiří - ASUS-JIRI
# Spuštěno z : F:\Stáhnuté\adwcleaner_6.047.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****

[-] Služba smazána: Suite Service


***** [ Složky ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****

[-] Zástupce vyléčen: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
[-] Zástupce vyléčen: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast SafeZone Browser.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast SafeZone Browser.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Avast SafeZone Browser.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[-] Zástupce vyléčen: C:\Users\jirka_000\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk


***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKU\S-1-5-21-1196467569-3603037678-3961814420-1002\Software\Conduit
[#] Klíč smazán po restartu: HKCU\Software\Conduit
[-] Klíč smazán: HKLM\SOFTWARE\Conduit
[#] Klíč smazán po restartu: [x64] HKCU\Software\Conduit
[-] Hodnota smazána: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [CommonToolkitTray]


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [3305 Bajty] - [31/05/2017 10:32:24]
C:\AdwCleaner\AdwCleaner[S0].txt - [5289 Bajty] - [31/05/2017 10:28:27]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3451 Bajty] ##########

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#4 Příspěvek od JaRon »

FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#5 Příspěvek od Spawnik »

Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by Jiýˇ on st 31. 05. 2017 at 14:39:45,36.
Microsoft Windows 8.1 6.3.9600 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\jirka_000\Desktop\zoek.exe [Scan all users] [Script inserted]

==== System Restore Info ======================

31. 5. 2017 14:40:15 Zoek.exe System Restore Point Created Successfully.

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost

==== Empty Folders Check ======================

C:\PROGRA~2\AGEIA Technologies deleted successfully
C:\PROGRA~2\COMMON~1\AV deleted successfully
C:\Program Files\Common Files\AV deleted successfully
C:\Users\jirka_000\AppData\Local\VirtualStore deleted successfully

==== Deleting CLSID Registry Keys ======================

HKEY_USERS\S-1-5-21-1196467569-3603037678-3961814420-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} deleted successfully
HKEY_USERS\S-1-5-21-1196467569-3603037678-3961814420-1002\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{18DF081C-E8AD-4283-A596-FA578C2EBDC3} deleted successfully

==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\JIRKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\prefs.js:
user_pref("browser.startup.homepage", "https://www.google.com/");

Added to C:\Users\JIRKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\JIRKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042

user.js not found
---- Lines searches removed from prefs.js ----
user_pref("browser.urlbar.suggest.searches", true);
---- Lines browser.startup.page removed from prefs.js ----
user_pref("browser.startup.page", 3);
---- FireFox user.js and prefs.js backups ----

prefs_201731.05._1450_.backup

==== Deleting Files \ Folders ======================

C:\PROGRA~2\AGEIA Technologies not found
C:\PROGRA~3\SetStretch.VBS deleted
C:\PROGRA~3\Package Cache deleted
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk deleted
C:\Users\jirka_000\AppData\LocalLow\Unity deleted
C:\WINDOWS\wininit.ini deleted

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\JIRKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions ======================

ProfilePath: C:\Users\JIRKA_~1\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042
- Classic Theme Restorer - %ProfilePath%\extensions\ClassicThemeRestorer@ArisT2Noia4dev.xpi
- Adblock Plus - %ProfilePath%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\jirka_000\AppData\Roaming\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042
80320392DCC61B22F0BB23DD5AD7D341 - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll - Shockwave Flash
18CF51689186AEB9D1D149AEB0E92D03 - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL - Microsoft Office 2013
F987F944D2B9A9D5D7886061B0D87120 - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll - Microsoft Office 2013


==== Chromium Look ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
ccjleegmemocfpghkhpjmiccjcacackp - No path found[]

Chrome Cleaner Pro - jirka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccjleegmemocfpghkhpjmiccjcacackp
Chrome Media Router - jirka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm

==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] not found

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="{012E1000-F331-11DB-8314-0800200C9A66}"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IE8SRC"

==== Reset Google Chrome ======================

C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences was reset successfully
C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Empty IE Cache ======================

C:\WINDOWS\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\jirka_000\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\WINDOWS\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\Content.IE5 emptied successfully
C:\Users\jirka_000\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully
C:\WINDOWS\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\INetCache\IE emptied successfully

==== Empty FireFox Cache ======================

C:\Users\jirka_000\AppData\Local\Mozilla\Firefox\Profiles\q9nkacjh.default-1496220436042\cache2 emptied successfully

==== Empty Chrome Cache ======================

C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=57 folders=31 318277392 bytes)

==== Empty Temp Folders ======================

C:\Users\Administrator\AppData\Local\Temp emptied successfully
C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\jirka_000\AppData\Local\Temp will be emptied at reboot
C:\Users\UpdatusUser\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\WINDOWS\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\WINDOWS\Temp successfully emptied
C:\Users\JIRKA_~1\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== EOF on st 31. 05. 2017 at 14:54:05,26 ======================

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#6 Příspěvek od Spawnik »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 8.1 x64
Ran by Jiýˇ (Administrator) on st 31. 05. 2017 at 14:56:16,64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 0




Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on st 31. 05. 2017 at 14:58:02,16
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#7 Příspěvek od JaRon »

Je to uz OK?
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#8 Příspěvek od Spawnik »

Bohužel ne, antivir stále vyhazuje okno o zablokované adrese. Zhruba jednou za minutu.

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#9 Příspěvek od JaRon »

Prescanuj PC s MBAM, log sem
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#10 Příspěvek od Spawnik »

Tohle MBAM vyplivl, když jsem dal sken z úvodní obrazovky... Nebyla tam ale zahrnuta kontrola rootkitů, takže jsem test pustil znovu, zatím stále běží (už 9 hodin), snad brzy dojede a hodím sem log i z něj.

Malwarebytes
http://www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 02.06.17
Čas skenování: 7:29
Logovací soubor: sken.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.1.2.1733
Verze komponentů: 1.0.139
Aktualizovat verzi balíku komponent: 1.0.2069
Licence: Zkušební

-Systémová informace-
OS: Windows 8.1
CPU: x64
Systém souborů: NTFS
Uživatel: ASUS-Jiri\Ji\u00c5\u0099\u00c3\u00ad

-Shrnutí skenování-
Typ skenování: Skenování hrozeb (Threat Scan)
Výsledek: Dokončeno
Skenované objekty: 412606
Zjištěné hrozby: 2
Hrozby umístěné do karantény: 0
(Nebyly zjištěny žádné škodlivé položky)
Uplynulý čas: 1 min, 3 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Zakázáno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 2
PUP.Optional.FFHijacker, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\204046703.CFG, Žádná uživatelská akce, [1140], [345408],1.0.2069
PUP.Optional.FFHijacker, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\DEFAULTS\PREF\204046703.JS, Žádná uživatelská akce, [1140], [330892],1.0.2069

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)
Naposledy upravil(a) Spawnik dne 02 čer 2017 16:23, celkem upraveno 1 x.

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#11 Příspěvek od Spawnik »

Ok, tady tedy celkový sken... 9 a půl hodiny.. Našlo mi to něco ve starých instalačních souborech. Podle mě to nemá spojitost s aktuálními problémy, protože tyto soubory mám již několik let, ale nemám problém se jich zbavit :) Jinak předpokládám, že umístění souborů z toho rychlého testu z rána do karantény má za následek to, že tento "důkladný" sken už ty soubory znovu nenašel. Je tak? Jak tedy prosím ohledně mého přetrvávajícího postupu pokračovat dále?

Malwarebytes
www.malwarebytes.com

-Podrobnosti logovacího souboru-
Datum skenování: 02.06.17
Čas skenování: 7:43
Logovací soubor: sken2.txt
Správce: Ano

-Informace o softwaru-
Verze: 3.1.2.1733
Verze komponentů: 1.0.139
Aktualizovat verzi balíku komponent: 1.0.2069
Licence: Zkušební

-Systémová informace-
OS: Windows 8.1
CPU: x64
Systém souborů: NTFS
Uživatel: ASUS-Jiri\Ji\u00c5\u0099\u00c3\u00ad

-Shrnutí skenování-
Typ skenování: Vlastní skenování
Výsledek: Dokončeno
Skenované objekty: 719940
Zjištěné hrozby: 6
Hrozby umístěné do karantény: 0
(Nebyly zjištěny žádné škodlivé položky)
Uplynulý čas: 9 hod, 36 min, 45 sek

-Možnosti skenování-
Paměť: Povoleno
Start: Povoleno
Systém souborů: Povoleno
Archivy: Povoleno
Rootkity: Povoleno
Heuristika: Povoleno
Potenciálně nežádoucí program: Povoleno
Potenciálně nežádoucí modifikace: Povoleno

-Podrobnosti skenování-
Proces: 0
(Nebyly zjištěny žádné škodlivé položky)

Modul: 0
(Nebyly zjištěny žádné škodlivé položky)

Klíč registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Hodnota v registru: 0
(Nebyly zjištěny žádné škodlivé položky)

Data registrů: 0
(Nebyly zjištěny žádné škodlivé položky)

Datové proudy: 0
(Nebyly zjištěny žádné škodlivé položky)

Adresář: 0
(Nebyly zjištěny žádné škodlivé položky)

Soubor: 6
Heuristics.Shuriken, F:\DOKUMENTY\INSTALAčKY\AUTOCAD\BIN\ACADFEUI\SETUP.EXE, Žádná uživatelská akce, [1787], [167],0.0.0
Heuristics.Shuriken, F:\DOKUMENTY\INSTALAčKY\AUTOCAD\BIN\ACADFEUI\SUPPORT\ADNIW\SETUP.EXE, Žádná uživatelská akce, [1787], [167],0.0.0
Heuristics.Shuriken, F:\DOKUMENTY\INSTALAčKY\AUTOCAD\BIN\ACADFEUI\SUPPORT\CADMANAGER\SETUP.EXE, Žádná uživatelská akce, [1787], [167],0.0.0
Heuristics.Shuriken, F:\DOKUMENTY\INSTALAčKY\AUTOCAD\BIN\ACADFEUI\SUPPORT\EXPRESS\SETUP.EXE, Žádná uživatelská akce, [1787], [167],0.0.0
Heuristics.Shuriken, F:\DOKUMENTY\INSTALAčKY\AUTOCAD\BIN\ACADFEUI\SUPPORT\NLM\SETUP.EXE, Žádná uživatelská akce, [1787], [167],0.0.0
Heuristics.Shuriken, F:\DOKUMENTY\INSTALAčKY\AUTOCAD\BIN\ACADFEUI\SUPPORT\NSA\SETUP.EXE, Žádná uživatelská akce, [1787], [167],0.0.0

Fyzický sektor: 0
(Nebyly zjištěny žádné škodlivé položky)


(end)

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#12 Příspěvek od Spawnik »

Tak po restartu zdá se zatím bez problému. AdwCleaner ale stejně zase něco našel...

# AdwCleaner v6.047 - Log vytvořen 02/06/2017 v 19:41:21
# Aktualizováno dne 19/05/2017 z Malwarebytes
# Databáze : 2017-06-02.1 [Server]
# Operační systém : Windows 8.1 (X64)
# Uživatelské jméno : Jiří - ASUS-JIRI
# Spuštěno z : F:\Stáhnuté\adwcleaner_6.047.exe
# Mod: Skenování
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****

Nebyly nalezeny žádné škodlivé služby.


***** [ Složky ] *****

Složka nalezena: C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccjleegmemocfpghkhpjmiccjcacackp
Složka nalezena: C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccjleegmemocfpghkhpjmiccjcacackp
Složka nalezena: C:\Users\jirka_000\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccjleegmemocfpghkhpjmiccjcacackp


***** [ Soubory ] *****

Nebyly nalezeny žádné škodlivé soubory.


***** [ DLL ] *****

Nebyly nalezeny žádné škodlivé DLL.


***** [ WMI ] *****

Nebyly nalezeny žádné škodlivé klíče.


***** [ Zástupci ] *****

Žádný infikovaný zástupce nenalezen.


***** [ Naplánované úlohy ] *****

Žádná nebezpečná úloha nenalezena.


***** [ Registry ] *****

Klíč nalezen: HKLM\SOFTWARE\Google\Chrome\Extensions\ccjleegmemocfpghkhpjmiccjcacackp


***** [ Internetové prohlížeče ] *****

Nebyly nalezeny žádné škodlivé položky prohlížeče Firefox.
Nebyly nalezeny žádné škodlivé položky prohlížeče Chromium.

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [3534 Bajty] - [31/05/2017 10:32:24]
C:\AdwCleaner\AdwCleaner[C2].txt - [1153 Bajty] - [31/05/2017 10:42:52]
C:\AdwCleaner\AdwCleaner[S0].txt - [5289 Bajty] - [31/05/2017 10:28:27]
C:\AdwCleaner\AdwCleaner[S1].txt - [1500 Bajty] - [31/05/2017 10:42:43]
C:\AdwCleaner\AdwCleaner[S2].txt - [1646 Bajty] - [31/05/2017 10:54:54]
C:\AdwCleaner\AdwCleaner[S3].txt - [1719 Bajty] - [31/05/2017 11:13:28]
C:\AdwCleaner\AdwCleaner[S4].txt - [1790 Bajty] - [01/06/2017 07:59:51]
C:\AdwCleaner\AdwCleaner[S5].txt - [2082 Bajty] - [02/06/2017 19:41:21]

########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt - [2155 Bajty] ##########

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#13 Příspěvek od JaRon »

Najdene nechaj odstranit Adwcleanerom, su to drobnosti
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Spawnik
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 31 kvě 2017 10:24

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#14 Příspěvek od Spawnik »

Dobře. Nějaký další postup? Dočištění nebo znovu kontrola logu?

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15216
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Nakažení počítače Malwarem? Firefox se chová nestandardn

#15 Příspěvek od JaRon »

Nateraz by som nic neriesil, zastav sa za 2-3 tyzdne na preventivku :)
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Zamčeno