Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Policejní virus

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Ondor
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 27 bře 2018 18:50

Policejní virus

#1 Příspěvek od Ondor »

Ahoj, prosím o kontrolu logu.
Předem díky
Ondor
Logfile of random's system information tool 1.10 (written by random/random)
Run by admin at 2018-03-27 19:33:52
Microsoft Windows 10 Home
System drive C: has 149 GB (65%) free of 228 GB
Total RAM: 8138 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:34:02, on 27.03.2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.16299.0015)
Boot mode: Normal

Running processes:
C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files\trend micro\admin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll
O4 - HKLM\..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Logitech . Registrace produktu.lnk = C:\Program Files (x86)\Logitech\Ereg\eReg.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Security\ekrn.exe
O23 - Service: ESET Firewall Helper (ekrnEpfw) - ESET - C:\Program Files\ESET\ESET Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\igfxCUIService.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: @%systemroot%\system32\xbgmsvc.exe,-100 (xbgm) - Unknown owner - C:\Windows\system32\xbgmsvc.exe (file missing)

--
End of file - 10423 bytes

======Listing Processes======








C:\Windows\system32\lsass.exe
c:\windows\system32\svchost.exe -k dcomlaunch -p -s PlugPlay
C:\Windows\system32\svchost.exe -k DcomLaunch -p
"fontdrvhost.exe"
c:\windows\system32\svchost.exe -k rpcss -p
c:\windows\system32\svchost.exe -k dcomlaunch -p -s LSM
winlogon.exe
"fontdrvhost.exe"
"dwm.exe"
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s lmhosts
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k netsvcs -p -s Schedule
c:\windows\system32\svchost.exe -k localservice -p -s EventSystem
c:\windows\system32\svchost.exe -k netsvcs -p -s ProfSvc
c:\windows\system32\svchost.exe -k netsvcs -p -s SENS
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s EventLog
C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\igfxCUIService.exe
c:\windows\system32\svchost.exe -k netsvcs -p -s UserManager

c:\windows\system32\svchost.exe -k localservice -p -s nsi
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s Dhcp
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork -p
c:\windows\system32\svchost.exe -k networkservice -p -s NlaSvc
c:\windows\system32\svchost.exe -k localservice -p -s netprofm
C:\Windows\system32\atiesrxx.exe
c:\windows\system32\svchost.exe -k networkservice -p -s Dnscache
c:\windows\system32\svchost.exe -k localservicenonetwork -p -s NcdAutoSetup
c:\windows\system32\svchost.exe -k localservice -p -s fdPHost
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -p -s FDResPub
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k netsvcs -p -s Winmgmt
c:\windows\system32\svchost.exe -k netsvcs -p -s Themes
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s SysMain
atieclxx
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -p -s FontCache

c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s HomeGroupProvider
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s DeviceAssociationService
c:\windows\system32\svchost.exe -k appmodel -p -s StateRepository
dashost.exe {2ea1ae52-1027-48ce-98502fb5c76a98fd}
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted -p
c:\windows\system32\svchost.exe -k netsvcs -p -s ShellHWDetection
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -p -s LanmanWorkstation
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc -p
c:\windows\system32\svchost.exe -k networkservice -p -s CryptSvc
C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\IntelCpHDCPSvc.exe
c:\windows\system32\svchost.exe -k localservicenonetwork -p -s DPS
c:\windows\system32\svchost.exe -k netsvcs -p -s IKEEXT
"C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe" -/service
c:\windows\system32\svchost.exe -k netsvcs -p -s iphlpsvc
c:\windows\system32\svchost.exe -k localservice -p -s SstpSvc
c:\windows\system32\svchost.exe -k netsvcs -p -s WpnService
C:\Windows\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s TrkWks
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -p -s SSDPSRV

c:\windows\system32\svchost.exe -k netsvcs -p -s LanmanServer
c:\windows\system32\svchost.exe -k networkservice -p -s TapiSrv
c:\windows\system32\svchost.exe -k localservice -p -s WdiServiceHost
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k appmodel -p -s tiledatamodelsvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted -p
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s NgcSvc
sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s TabletInputService
c:\windows\system32\svchost.exe -k netsvcs -p -s TokenBroker
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"ctfmon.exe"
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -p -s PolicyAgent
C:\Windows\Explorer.EXE
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe atlogon
c:\windows\system32\svchost.exe -k localservice -p -s LicenseManager
c:\windows\system32\svchost.exe -k localservice -p -s CDPSvc
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s PcaSvc
"C:\Program Files\ESET\ESET Security\egui.exe" /hide
"C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Steam\Steam.exe" -silent
c:\windows\system32\svchost.exe -k netsvcs -p -s Appinfo
"C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe"
"C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe" -hide
"C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe" /hide
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" "-lang=cs_CZ" "-cachedir=C:\Users\admin\AppData\Local\Steam\htmlcache" "-steampid=8940" "-buildid=1522101301" "-steamid=0" "-clientui=C:\Program Files (x86)\Steam\clientui" --disable-spell-checking --disable-out-of-process-pac --enable-blink-features=ResizeObserver --disable-smooth-scrolling --disable-gpu-compositing --disable-gpu --enable-direct-write "--log-file=C:\Program Files (x86)\Steam\logs\cef_log.txt"
"C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=crashpad-handler /prefetch:7 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\CEF\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\CEF\User Data" --url=http://crash.steampowered.com/submit --annotation=platform=win32 --annotation=product=cefwebhelper --annotation=version=1.0 --initial-client-data=0x318,0x31c,0x320,0x2f4,0x324,0x68bf81a4,0x68bf81b4,0x68bf81c4
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --disable-smooth-scrolling --enable-pinch --service-pipe-token=9C9C89F457DE97C2FEE5CE0FA39F0262 --enable-blink-features=ResizeObserver --lang=en-US --lang=cs-CZ --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --webview-urls=http://localhost/*,http://steamloopback ... localhost/* --disable-spell-checking --buildid=1522101301 --steamid=0 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --disable-accelerated-video-decode --disable-gpu-compositing --enable-gpu-async-worker-context --service-request-channel-token=9C9C89F457DE97C2FEE5CE0FA39F0262 --renderer-client-id=2 --mojo-platform-channel-handle=1904 /prefetch:1
c:\windows\system32\svchost.exe -k unistacksvcgroup
c:\windows\system32\svchost.exe -k networkservice -p -s DoSvc
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s StorSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -p -s wscsvc
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
c:\windows\system32\svchost.exe -k netsvcs -p -s lfsvc
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.WindowsStore_11802.1001.11.0_x64__8wekyb3d8bbwe\WinStore.App.exe" -ServerName:App.AppXc75wvwned5vhz4xyxxecvgdjhdkgsdza.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17122.16211.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
"C:\Program Files\WindowsApps\Microsoft.MSPaint_4.1803.16027.0_x64__8wekyb3d8bbwe\PaintStudio.View.exe" -ServerName:Microsoft.MSPaint.AppX437q68k2qc2asvaagas2prv9tjej6ja9.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -p -s DsSvc
"C:\Program Files\Mozilla Firefox\firefox.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="9080.0.1534087757\1144793727" -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" "C:\Users\admin\AppData\LocalLow\Mozilla\Temp-{94a51922-562f-47c3-b4bc-00833e1136cd}" 9080 "\\.\pipe\gecko-crash-server-pipe.9080" gpu
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="9080.3.1432588519\771339563" -childID 1 -isForBrowser -intPrefs 6:50|7:-1|34:1000|42:20|43:5|44:10|51:0|57:128|58:10000|63:0|65:400|66:1|67:0|68:0|69:100|74:0|75:120|76:120|159:2|160:1|164:60|165:30|166:512000|175:5000|177:6|191:8192|192:524288|193:5|206:10000|227:24|228:32768|230:0|231:0|240:5|244:1048576|246:100|247:5000|249:600|251:1|260:2000|277:4|281:0|290:60000|308:300|309:30| -boolPrefs 1:0|2:0|4:1|5:0|24:1|27:0|28:1|29:1|31:1|32:1|33:1|36:0|37:0|38:1|41:1|45:1|46:0|47:0|48:1|49:1|50:1|52:0|55:1|56:1|59:0|60:0|61:0|62:0|64:0|70:1|71:1|72:0|73:1|77:1|78:1|79:0|80:0|81:1|82:1|83:0|84:1|87:0|88:0|91:1|92:1|96:1|97:1|98:0|99:1|100:0|101:0|103:0|104:0|105:1|106:1|107:1|110:1|111:1|112:1|113:1|114:1|115:0|116:0|117:0|119:0|120:1|121:1|122:0|123:0|124:0|125:0|127:1|128:0|129:1|130:1|131:1|132:0|133:0|134:1|135:1|136:1|137:1|138:0|139:1|140:1|141:1|142:1|143:1|144:1|145:0|146:1|147:1|148:0|149:1|150:0|152:0|153:0|154:0|155:1|156:1|157:1|158:1|161:1|162:0|172:0|173:0|174:1|178:1|181:0|182:1|184:1|186:0|188:1|194:1|195:0|196:1|197:1|198:0|201:1|205:1|207:1|208:0|210:1|213:0|219:0|220:1|221:0|222:1|225:0|226:0|229:1|232:0|234:1|235:1|237:1|238:0|245:1|248:1|253:0|254:0|255:0|256:1|257:1|258:0|259:1|264:0|267:1|268:1|269:1|270:1|271:0|272:0|273:0|279:0|282:0|283:0|284:1|285:1|286:0|287:1|288:1|289:1|291:0|292:0|294:0|303:1|304:1|305:0|306:0|307:0| -stringPrefs "3:7;release|151:0;|212:3;1.0|223:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|224:4;high|278:38;{94a51922-562f-47c3-b4bc-00833e1136cd}|" -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" 9080 "\\.\pipe\gecko-crash-server-pipe.9080" tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="9080.13.1429514393\327368284" -childID 2 -isForBrowser -intPrefs 6:50|7:-1|34:1000|42:20|43:5|44:10|51:0|57:128|58:10000|63:0|65:400|66:1|67:0|68:0|69:100|74:0|75:120|76:120|159:2|160:1|164:60|165:30|166:512000|175:5000|177:6|191:8192|192:524288|193:5|206:10000|227:24|228:32768|230:0|231:0|240:5|244:1048576|246:100|247:5000|249:600|251:1|260:2000|277:4|281:0|290:60000|308:300|309:30| -boolPrefs 1:0|2:0|4:1|5:0|24:1|27:0|28:1|29:1|31:1|32:1|33:1|36:0|37:0|38:1|41:1|45:1|46:0|47:0|48:1|49:1|50:1|52:0|55:1|56:1|59:0|60:0|61:0|62:0|64:0|70:1|71:1|72:0|73:1|77:1|78:1|79:0|80:0|81:1|82:1|83:0|84:1|87:0|88:0|91:1|92:1|96:1|97:1|98:0|99:1|100:0|101:0|103:0|104:0|105:1|106:1|107:1|110:1|111:1|112:1|113:1|114:1|115:0|116:0|117:0|119:0|120:1|121:1|122:0|123:0|124:0|125:0|127:1|128:0|129:1|130:1|131:1|132:0|133:0|134:1|135:1|136:1|137:1|138:0|139:1|140:1|141:1|142:1|143:1|144:1|145:0|146:1|147:1|148:0|149:1|150:0|152:0|153:0|154:0|155:1|156:1|157:1|158:1|161:1|162:0|172:0|173:0|174:1|178:1|181:0|182:1|184:1|186:0|188:1|194:1|195:0|196:1|197:1|198:0|201:1|205:1|207:1|208:0|210:1|213:0|219:0|220:1|221:0|222:1|225:0|226:0|229:1|232:0|234:1|235:1|237:1|238:0|245:1|248:1|253:0|254:0|255:0|256:1|257:1|258:0|259:1|264:0|267:1|268:1|269:1|270:1|271:0|272:0|273:0|279:0|282:0|283:0|284:1|285:1|286:0|287:1|288:1|289:1|291:0|292:0|294:0|303:1|304:1|305:0|306:0|307:0| -stringPrefs "3:7;release|151:0;|212:3;1.0|223:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|224:4;high|278:38;{94a51922-562f-47c3-b4bc-00833e1136cd}|" -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" 9080 "\\.\pipe\gecko-crash-server-pipe.9080" tab
"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="9080.20.614370916\500561220" -childID 3 -isForBrowser -intPrefs 6:50|7:-1|34:1000|42:20|43:5|44:10|51:0|57:128|58:10000|63:0|65:400|66:1|67:0|68:0|69:100|74:0|75:120|76:120|159:2|160:1|164:60|165:30|166:512000|175:5000|177:6|191:8192|192:524288|193:5|206:10000|227:24|228:32768|230:0|231:0|240:5|244:1048576|246:100|247:5000|249:600|251:1|260:2000|277:4|281:0|290:60000|308:300|309:30| -boolPrefs 1:0|2:0|4:1|5:0|24:1|27:0|28:1|29:1|31:1|32:1|33:1|36:0|37:0|38:1|41:1|45:1|46:0|47:0|48:1|49:1|50:1|52:0|55:1|56:1|59:0|60:0|61:0|62:0|64:0|70:1|71:1|72:0|73:1|77:1|78:1|79:0|80:0|81:1|82:1|83:0|84:1|87:0|88:0|91:1|92:1|96:1|97:1|98:0|99:1|100:0|101:0|103:0|104:0|105:1|106:1|107:1|110:1|111:1|112:1|113:1|114:1|115:0|116:0|117:0|119:0|120:1|121:1|122:0|123:0|124:0|125:0|127:1|128:0|129:1|130:1|131:1|132:0|133:0|134:1|135:1|136:1|137:1|138:0|139:1|140:1|141:1|142:1|143:1|144:1|145:0|146:1|147:1|148:0|149:1|150:0|152:0|153:0|154:0|155:1|156:1|157:1|158:1|161:1|162:0|172:0|173:0|174:1|178:1|181:0|182:1|184:1|186:0|188:1|194:1|195:0|196:1|197:1|198:0|201:1|205:1|207:1|208:0|210:1|213:0|219:0|220:1|221:0|222:1|225:0|226:0|229:1|232:0|234:1|235:1|237:1|238:0|245:1|248:1|253:0|254:0|255:0|256:1|257:1|258:0|259:1|264:0|267:1|268:1|269:1|270:1|271:0|272:0|273:0|279:0|282:0|283:0|284:1|285:1|286:0|287:1|288:1|289:1|291:0|292:0|294:0|303:1|304:1|305:0|306:0|307:0| -stringPrefs "3:7;release|151:0;|212:3;1.0|223:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|224:4;high|278:38;{94a51922-562f-47c3-b4bc-00833e1136cd}|" -schedulerPrefs 0001,2 -greomni "C:\Program Files\Mozilla Firefox\omni.ja" -appomni "C:\Program Files\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files\Mozilla Firefox\browser" 9080 "\\.\pipe\gecko-crash-server-pipe.9080" tab
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 748 752 760 8192 756
C:\Windows\System32\smartscreen.exe -Embedding
C:\Windows\system32\AUDIODG.EXE 0x654
"C:\Users\admin\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.111.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.111.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 29.0.0.113 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0]
"Description"=Office Authorization plug-in for NPAPI browsers
"Path"=C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2018-03-17 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2018-03-17 186944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-09-29 630168]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-09-23 8903176]
"egui"=C:\Program Files\ESET\ESET Security\ecmds.exe [2018-03-15 178496]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\admin\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2018-03-10 1559200]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2018-03-27 3198752]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LWS"=C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [2012-09-13 204136]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-09-22 587288]

C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Logitech . Registrace produktu.lnk - C:\Program Files (x86)\Logitech\Ereg\eReg.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableFullTrustStartupTasks"=2
"EnableUwpStartupTasks"=2
"SupportFullTrustStartupTasks"=1
"SupportUwpStartupTasks"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=lvcod64.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"vidc.mjpg"=pvmjpgx40.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2018-03-27 19:33:52 ----D---- C:\rsit
2018-03-27 19:33:52 ----D---- C:\Program Files\trend micro
2018-03-27 18:17:19 ----D---- C:\ProgramData\ESET
2018-03-27 18:17:19 ----D---- C:\Program Files\ESET
2018-03-27 18:12:22 ----D---- C:\Windows\system32\drivers\wd
2018-03-26 20:44:31 ----D---- C:\Program Files\Mozilla Firefox
2018-03-17 18:37:05 ----D---- C:\Users\admin\AppData\Roaming\Sun
2018-03-17 18:37:02 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2018-03-17 18:36:52 ----D---- C:\ProgramData\Oracle
2018-03-17 18:36:50 ----D---- C:\Program Files (x86)\Java
2018-03-13 19:26:38 ----A---- C:\Windows\SYSWOW64\webplatstorageserver.dll
2018-03-13 19:26:38 ----A---- C:\Windows\SYSWOW64\usoapi.dll
2018-03-13 19:26:38 ----A---- C:\Windows\SYSWOW64\msIso.dll
2018-03-13 19:26:38 ----A---- C:\Windows\SYSWOW64\IndexedDbLegacy.dll
2018-03-13 19:26:38 ----A---- C:\Windows\SYSWOW64\EdgeManager.dll
2018-03-13 19:26:38 ----A---- C:\Windows\SYSWOW64\edgeIso.dll
2018-03-13 19:26:38 ----A---- C:\Windows\SYSWOW64\AcSpecfc.dll
2018-03-13 19:26:38 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2018-03-13 19:26:38 ----A---- C:\Windows\system32\SecurityHealthProxyStub.dll
2018-03-13 19:26:37 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2018-03-13 19:26:37 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2018-03-13 19:26:37 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2018-03-13 19:26:36 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2018-03-13 19:26:36 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2018-03-13 19:26:36 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2018-03-13 19:26:36 ----A---- C:\Windows\SYSWOW64\jscript.dll
2018-03-13 19:26:36 ----A---- C:\Windows\system32\drivers\USBXHCI.SYS
2018-03-13 19:26:36 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2018-03-13 19:26:36 ----A---- C:\Windows\system32\drivers\dumpsd.sys
2018-03-13 19:26:35 ----A---- C:\Windows\SYSWOW64\win32kfull.sys
2018-03-13 19:26:35 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2018-03-13 19:26:35 ----A---- C:\Windows\system32\rdpudd.dll
2018-03-13 19:26:35 ----A---- C:\Windows\system32\drivers\volmgr.sys
2018-03-13 19:26:35 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2018-03-13 19:26:35 ----A---- C:\Windows\system32\drivers\storahci.sys
2018-03-13 19:26:35 ----A---- C:\Windows\system32\drivers\sdbus.sys
2018-03-13 19:26:35 ----A---- C:\Windows\system32\drivers\hidparse.sys
2018-03-13 19:26:35 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2018-03-13 19:26:35 ----A---- C:\Windows\system32\drivers\acpi.sys
2018-03-13 19:26:34 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2018-03-13 19:26:34 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2018-03-13 19:26:34 ----A---- C:\Windows\system32\vbscript.dll
2018-03-13 19:26:34 ----A---- C:\Windows\system32\jscript9.dll
2018-03-13 19:26:34 ----A---- C:\Windows\system32\drivers\wcifs.sys
2018-03-13 19:26:34 ----A---- C:\Windows\system32\drivers\storufs.sys
2018-03-13 19:26:34 ----A---- C:\Windows\system32\drivers\pci.sys
2018-03-13 19:26:34 ----A---- C:\Windows\system32\drivers\BasicRender.sys
2018-03-13 19:26:33 ----A---- C:\Windows\SYSWOW64\wininet.dll
2018-03-13 19:26:33 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2018-03-13 19:26:33 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2018-03-13 19:26:33 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2018-03-13 19:26:33 ----A---- C:\Windows\SYSWOW64\d3d10warp.dll
2018-03-13 19:26:33 ----A---- C:\Windows\system32\StorSvc.dll
2018-03-13 19:26:33 ----A---- C:\Windows\system32\samsrv.dll
2018-03-13 19:26:33 ----A---- C:\Windows\system32\iertutil.dll
2018-03-13 19:26:33 ----A---- C:\Windows\system32\edgeIso.dll
2018-03-13 19:26:33 ----A---- C:\Windows\system32\drivers\UcmUcsi.sys
2018-03-13 19:26:33 ----A---- C:\Windows\system32\drivers\stornvme.sys
2018-03-13 19:26:33 ----A---- C:\Windows\system32\drivers\srv2.sys
2018-03-13 19:26:33 ----A---- C:\Windows\system32\DbgModel.dll
2018-03-13 19:26:32 ----A---- C:\Windows\system32\win32kfull.sys
2018-03-13 19:26:32 ----A---- C:\Windows\system32\win32kbase.sys
2018-03-13 19:26:32 ----A---- C:\Windows\system32\ntoskrnl.exe
2018-03-13 19:26:32 ----A---- C:\Windows\system32\ieframe.dll
2018-03-13 19:26:31 ----A---- C:\Windows\SYSWOW64\winmde.dll
2018-03-13 19:26:31 ----A---- C:\Windows\SYSWOW64\msvproc.dll
2018-03-13 19:26:31 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2018-03-13 19:26:31 ----A---- C:\Windows\system32\rdpcorets.dll
2018-03-13 19:26:31 ----A---- C:\Windows\system32\lsasrv.dll
2018-03-13 19:26:31 ----A---- C:\Windows\system32\jscript9diag.dll
2018-03-13 19:26:31 ----A---- C:\Windows\system32\jscript.dll
2018-03-13 19:26:31 ----A---- C:\Windows\system32\Chakra.dll
2018-03-13 19:26:31 ----A---- C:\Windows\system32\hvloader.dll
2018-03-13 19:26:31 ----A---- C:\Windows\system32\hvax64.exe
2018-03-13 19:26:31 ----A---- C:\Windows\system32\drivers\vmbus.sys
2018-03-13 19:26:31 ----A---- C:\Windows\system32\drivers\spaceport.sys
2018-03-13 19:26:31 ----A---- C:\Windows\system32\drivers\netvsc.sys
2018-03-13 19:26:31 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2018-03-13 19:26:30 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2018-03-13 19:26:30 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2018-03-13 19:26:30 ----A---- C:\Windows\system32\dbgeng.dll
2018-03-13 19:26:30 ----A---- C:\Windows\system32\d3d10warp.dll
2018-03-13 19:26:29 ----A---- C:\Windows\system32\wininet.dll
2018-03-13 19:26:29 ----A---- C:\Windows\system32\msIso.dll
2018-03-13 19:26:29 ----A---- C:\Windows\system32\KernelBase.dll
2018-03-13 19:26:29 ----A---- C:\Windows\system32\drivers\WdiWiFi.sys
2018-03-13 19:26:29 ----A---- C:\Windows\system32\drivers\nwifi.sys
2018-03-13 19:26:29 ----A---- C:\Windows\system32\AcSpecfc.dll
2018-03-13 19:26:28 ----A---- C:\Windows\system32\winmde.dll
2018-03-13 19:26:28 ----A---- C:\Windows\system32\msvproc.dll
2018-03-13 19:26:28 ----A---- C:\Windows\system32\mshtml.dll
2018-03-13 19:26:28 ----A---- C:\Windows\system32\hvix64.exe
2018-03-13 19:26:28 ----A---- C:\Windows\system32\drivers\vhdmp.sys
2018-03-13 19:26:27 ----A---- C:\Windows\SYSWOW64\zipfldr.dll
2018-03-13 19:26:27 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2018-03-13 19:26:27 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2018-03-13 19:26:27 ----A---- C:\Windows\system32\wintrust.dll
2018-03-13 19:26:27 ----A---- C:\Windows\system32\pcalua.exe
2018-03-13 19:26:27 ----A---- C:\Windows\system32\mfplat.dll
2018-03-13 19:26:27 ----A---- C:\Windows\system32\edgehtml.dll
2018-03-13 19:26:26 ----A---- C:\Windows\SYSWOW64\daxexec.dll
2018-03-13 19:26:26 ----A---- C:\Windows\system32\zipfldr.dll
2018-03-13 19:26:26 ----A---- C:\Windows\system32\winsrv.dll
2018-03-13 19:26:26 ----A---- C:\Windows\system32\windows.storage.dll
2018-03-13 19:26:26 ----A---- C:\Windows\system32\shell32.dll
2018-03-13 19:26:26 ----A---- C:\Windows\system32\rpcrt4.dll
2018-03-13 19:26:26 ----A---- C:\Windows\system32\aitstatic.exe
2018-03-13 19:26:25 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2018-03-13 19:26:25 ----A---- C:\Windows\SYSWOW64\shell32.dll
2018-03-13 19:26:25 ----A---- C:\Windows\system32\HologramCompositor.dll
2018-03-13 19:26:24 ----A---- C:\Windows\system32\usocore.dll
2018-03-13 19:26:24 ----A---- C:\Windows\system32\usoapi.dll
2018-03-13 19:26:24 ----A---- C:\Windows\system32\updatehandlers.dll
2018-03-13 19:26:24 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2018-03-13 19:26:24 ----A---- C:\Windows\system32\MusNotificationUx.exe
2018-03-13 19:26:24 ----A---- C:\Windows\system32\MusNotification.exe
2018-03-13 19:26:24 ----A---- C:\Windows\system32\musdialoghandlers.dll
2018-03-13 19:26:21 ----A---- C:\Windows\SYSWOW64\aepic.dll
2018-03-13 19:26:21 ----A---- C:\Windows\system32\winresume.exe
2018-03-13 19:26:21 ----A---- C:\Windows\system32\winload.exe
2018-03-13 19:26:21 ----A---- C:\Windows\system32\win32appinventorycsp.dll
2018-03-13 19:26:21 ----A---- C:\Windows\system32\pcasvc.dll
2018-03-13 19:26:21 ----A---- C:\Windows\system32\invagent.dll
2018-03-13 19:26:21 ----A---- C:\Windows\system32\drivers\cng.sys
2018-03-13 19:26:21 ----A---- C:\Windows\system32\CompatTelRunner.exe
2018-03-13 19:26:21 ----A---- C:\Windows\system32\aepic.dll
2018-03-13 19:26:20 ----A---- C:\Windows\SYSWOW64\Windows.Payments.dll
2018-03-13 19:26:20 ----A---- C:\Windows\SYSWOW64\cldapi.dll
2018-03-13 19:26:20 ----A---- C:\Windows\SYSWOW64\cdp.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\wlidsvc.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\Windows.Payments.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\webplatstorageserver.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\Spectrum.exe
2018-03-13 19:26:20 ----A---- C:\Windows\system32\SecurityHealthService.exe
2018-03-13 19:26:20 ----A---- C:\Windows\system32\SecurityHealthAgent.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\MSVidCtl.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\HolographicExtensions.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\generaltel.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\EdgeManager.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\devinv.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\DeviceCensus.exe
2018-03-13 19:26:20 ----A---- C:\Windows\system32\dcntel.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\daxexec.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\cldapi.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\cdp.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\appraiser.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\aeinv.dll
2018-03-13 19:26:20 ----A---- C:\Windows\system32\acmigration.dll
2018-03-13 19:26:19 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2018-03-13 19:26:19 ----A---- C:\Windows\SYSWOW64\MSVPXENC.dll
2018-03-13 19:26:19 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2018-03-13 19:26:19 ----A---- C:\Windows\SYSWOW64\msi.dll
2018-03-13 19:26:19 ----A---- C:\Windows\SYSWOW64\MicrosoftAccountWAMExtension.dll
2018-03-13 19:26:19 ----A---- C:\Windows\SYSWOW64\AuthFWSnapin.dll
2018-03-13 19:26:19 ----A---- C:\Windows\system32\Windows.Internal.Feedback.Analog.dll
2018-03-13 19:26:19 ----A---- C:\Windows\system32\TSpkg.dll
2018-03-13 19:26:19 ----A---- C:\Windows\system32\MusNotifyIcon.exe
2018-03-13 19:26:19 ----A---- C:\Windows\system32\MSVPXENC.dll
2018-03-13 19:26:19 ----A---- C:\Windows\system32\MSVideoDSP.dll
2018-03-13 19:26:19 ----A---- C:\Windows\system32\msra.exe
2018-03-13 19:26:19 ----A---- C:\Windows\system32\msi.dll
2018-03-13 19:26:19 ----A---- C:\Windows\system32\MicrosoftAccountWAMExtension.dll
2018-03-13 19:26:19 ----A---- C:\Windows\system32\drivers\sdstor.sys
2018-03-13 19:26:19 ----A---- C:\Windows\system32\drivers\RfxVmt.sys
2018-03-13 19:26:19 ----A---- C:\Windows\system32\cdpusersvc.dll
2018-03-13 19:26:19 ----A---- C:\Windows\system32\AuthFWSnapin.dll
2018-03-13 19:26:18 ----A---- C:\Windows\SYSWOW64\offlinesam.dll
2018-03-13 19:26:18 ----A---- C:\Windows\SYSWOW64\offlinelsa.dll
2018-03-13 19:26:18 ----A---- C:\Windows\SYSWOW64\MSVideoDSP.dll
2018-03-13 19:26:18 ----A---- C:\Windows\SYSWOW64\msisip.dll
2018-03-13 19:26:18 ----A---- C:\Windows\SYSWOW64\HoloShellRuntime.dll
2018-03-13 19:26:18 ----A---- C:\Windows\SYSWOW64\credssp.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\UsoClient.exe
2018-03-13 19:26:18 ----A---- C:\Windows\system32\updatecsp.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\svf.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\SpectrumSyncClient.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\racpldlg.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\offlinesam.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\offlinelsa.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\msisip.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\IndexedDbLegacy.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\HoloShellRuntime.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\HeadTrackerStorage.dll
2018-03-13 19:26:18 ----A---- C:\Windows\system32\drivers\wcnfs.sys
2018-03-13 19:26:18 ----A---- C:\Windows\system32\drivers\tpm.sys
2018-03-13 19:26:18 ----A---- C:\Windows\system32\drivers\msrpc.sys
2018-03-13 19:26:18 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2018-03-13 19:26:18 ----A---- C:\Windows\system32\drivers\isapnp.sys
2018-03-13 19:26:18 ----A---- C:\Windows\system32\drivers\HdAudio.sys
2018-03-13 19:26:18 ----A---- C:\Windows\system32\drivers\ataport.sys
2018-03-13 19:26:18 ----A---- C:\Windows\system32\credssp.dll
2018-03-06 17:50:28 ----D---- C:\Users\admin\AppData\Roaming\Macromedia
2018-03-06 17:24:16 ----SD---- C:\Windows\SYSWOW64\Microsoft
2018-02-28 16:45:09 ----D---- C:\Users\admin\AppData\Roaming\Warner Bros. Interactive Entertainment
2018-02-28 16:45:07 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2018-02-28 16:45:07 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2018-02-28 16:45:07 ----A---- C:\Windows\system32\XAudio2_7.dll
2018-02-28 16:45:07 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2018-02-28 16:45:06 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2018-02-28 16:45:06 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2018-02-28 16:45:06 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2018-02-28 16:45:06 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2018-02-28 16:45:06 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2018-02-28 16:45:06 ----A---- C:\Windows\system32\xactengine3_7.dll
2018-02-28 16:45:06 ----A---- C:\Windows\system32\d3dx11_43.dll
2018-02-28 16:45:06 ----A---- C:\Windows\system32\d3dx10_43.dll
2018-02-28 16:45:06 ----A---- C:\Windows\system32\d3dcsx_43.dll
2018-02-28 16:45:06 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2018-02-28 16:45:05 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2018-02-28 16:45:05 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2018-02-28 16:45:05 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2018-02-28 16:45:05 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2018-02-28 16:45:05 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2018-02-28 16:45:05 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2018-02-28 16:45:05 ----A---- C:\Windows\system32\XAudio2_6.dll
2018-02-28 16:45:05 ----A---- C:\Windows\system32\XAudio2_5.dll
2018-02-28 16:45:05 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2018-02-28 16:45:05 ----A---- C:\Windows\system32\xactengine3_6.dll
2018-02-28 16:45:05 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2018-02-28 16:45:05 ----A---- C:\Windows\system32\D3DX9_43.dll
2018-02-28 16:45:04 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2018-02-28 16:45:04 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2018-02-28 16:45:04 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2018-02-28 16:45:04 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2018-02-28 16:45:04 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2018-02-28 16:45:04 ----A---- C:\Windows\system32\xactengine3_5.dll
2018-02-28 16:45:04 ----A---- C:\Windows\system32\d3dx11_42.dll
2018-02-28 16:45:04 ----A---- C:\Windows\system32\d3dx10_42.dll
2018-02-28 16:45:04 ----A---- C:\Windows\system32\d3dcsx_42.dll
2018-02-28 16:45:04 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2018-02-28 16:45:03 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2018-02-28 16:45:03 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2018-02-28 16:45:03 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2018-02-28 16:45:03 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2018-02-28 16:45:03 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2018-02-28 16:45:03 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2018-02-28 16:45:03 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2018-02-28 16:45:03 ----A---- C:\Windows\system32\XAudio2_4.dll
2018-02-28 16:45:03 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2018-02-28 16:45:03 ----A---- C:\Windows\system32\xactengine3_4.dll
2018-02-28 16:45:03 ----A---- C:\Windows\system32\D3DX9_42.dll
2018-02-28 16:45:03 ----A---- C:\Windows\system32\D3DX9_41.dll
2018-02-28 16:45:03 ----A---- C:\Windows\system32\d3dx10_41.dll
2018-02-28 16:45:03 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2018-02-28 16:45:02 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2018-02-28 16:45:02 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2018-02-28 16:45:02 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2018-02-28 16:45:02 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2018-02-28 16:45:02 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2018-02-28 16:45:02 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2018-02-28 16:45:02 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2018-02-28 16:45:02 ----A---- C:\Windows\system32\XAudio2_3.dll
2018-02-28 16:45:02 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2018-02-28 16:45:02 ----A---- C:\Windows\system32\xactengine3_3.dll
2018-02-28 16:45:02 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2018-02-28 16:45:02 ----A---- C:\Windows\system32\D3DX9_40.dll
2018-02-28 16:45:02 ----A---- C:\Windows\system32\d3dx10_40.dll
2018-02-28 16:45:02 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2018-02-28 16:45:01 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2018-02-28 16:45:01 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2018-02-28 16:45:01 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2018-02-28 16:45:01 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2018-02-28 16:45:01 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2018-02-28 16:45:01 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2018-02-28 16:45:01 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2018-02-28 16:45:01 ----A---- C:\Windows\system32\XAudio2_2.dll
2018-02-28 16:45:01 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2018-02-28 16:45:01 ----A---- C:\Windows\system32\xactengine3_2.dll
2018-02-28 16:45:01 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2018-02-28 16:45:01 ----A---- C:\Windows\system32\D3DX9_39.dll
2018-02-28 16:45:01 ----A---- C:\Windows\system32\d3dx10_39.dll
2018-02-28 16:45:01 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2018-02-28 16:45:00 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2018-02-28 16:45:00 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2018-02-28 16:45:00 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2018-02-28 16:45:00 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2018-02-28 16:45:00 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2018-02-28 16:45:00 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2018-02-28 16:45:00 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2018-02-28 16:45:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2018-02-28 16:45:00 ----A---- C:\Windows\system32\XAudio2_1.dll
2018-02-28 16:45:00 ----A---- C:\Windows\system32\XAudio2_0.dll
2018-02-28 16:45:00 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2018-02-28 16:45:00 ----A---- C:\Windows\system32\xactengine3_1.dll
2018-02-28 16:45:00 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2018-02-28 16:45:00 ----A---- C:\Windows\system32\D3DX9_38.dll
2018-02-28 16:45:00 ----A---- C:\Windows\system32\d3dx10_38.dll
2018-02-28 16:45:00 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2018-02-28 16:44:59 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2018-02-28 16:44:59 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2018-02-28 16:44:59 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2018-02-28 16:44:59 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2018-02-28 16:44:59 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2018-02-28 16:44:59 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2018-02-28 16:44:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2018-02-28 16:44:59 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2018-02-28 16:44:59 ----A---- C:\Windows\system32\xactengine3_0.dll
2018-02-28 16:44:59 ----A---- C:\Windows\system32\xactengine2_10.dll
2018-02-28 16:44:59 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2018-02-28 16:44:59 ----A---- C:\Windows\system32\D3DX9_37.dll
2018-02-28 16:44:59 ----A---- C:\Windows\system32\d3dx10_37.dll
2018-02-28 16:44:59 ----A---- C:\Windows\system32\d3dx10_36.dll
2018-02-28 16:44:59 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2018-02-28 16:44:59 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2018-02-28 16:44:58 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\xactengine2_9.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\xactengine2_8.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\d3dx9_36.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\d3dx9_35.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\d3dx10_35.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\d3dx10_34.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2018-02-28 16:44:58 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2018-02-28 16:44:57 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2018-02-28 16:44:57 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2018-02-28 16:44:57 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2018-02-28 16:44:57 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2018-02-28 16:44:57 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2018-02-28 16:44:57 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2018-02-28 16:44:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2018-02-28 16:44:57 ----A---- C:\Windows\system32\xinput1_3.dll
2018-02-28 16:44:57 ----A---- C:\Windows\system32\xactengine2_7.dll
2018-02-28 16:44:57 ----A---- C:\Windows\system32\xactengine2_6.dll
2018-02-28 16:44:57 ----A---- C:\Windows\system32\d3dx9_34.dll
2018-02-28 16:44:57 ----A---- C:\Windows\system32\d3dx9_33.dll
2018-02-28 16:44:57 ----A---- C:\Windows\system32\d3dx10_33.dll
2018-02-28 16:44:57 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2018-02-28 16:44:56 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2018-02-28 16:44:56 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2018-02-28 16:44:56 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2018-02-28 16:44:56 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2018-02-28 16:44:56 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2018-02-28 16:44:56 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2018-02-28 16:44:56 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2018-02-28 16:44:56 ----A---- C:\Windows\system32\xactengine2_5.dll
2018-02-28 16:44:56 ----A---- C:\Windows\system32\xactengine2_4.dll
2018-02-28 16:44:56 ----A---- C:\Windows\system32\xactengine2_3.dll
2018-02-28 16:44:56 ----A---- C:\Windows\system32\x3daudio1_1.dll
2018-02-28 16:44:56 ----A---- C:\Windows\system32\d3dx9_32.dll
2018-02-28 16:44:56 ----A---- C:\Windows\system32\d3dx9_31.dll
2018-02-28 16:44:56 ----A---- C:\Windows\system32\d3dx10.dll
2018-02-28 16:44:55 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2018-02-28 16:44:55 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2018-02-28 16:44:55 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2018-02-28 16:44:55 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2018-02-28 16:44:55 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2018-02-28 16:44:55 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2018-02-28 16:44:55 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2018-02-28 16:44:55 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2018-02-28 16:44:55 ----A---- C:\Windows\system32\xinput1_2.dll
2018-02-28 16:44:55 ----A---- C:\Windows\system32\xinput1_1.dll
2018-02-28 16:44:55 ----A---- C:\Windows\system32\xactengine2_2.dll
2018-02-28 16:44:55 ----A---- C:\Windows\system32\xactengine2_1.dll
2018-02-28 16:44:55 ----A---- C:\Windows\system32\xactengine2_0.dll
2018-02-28 16:44:55 ----A---- C:\Windows\system32\x3daudio1_0.dll
2018-02-28 16:44:55 ----A---- C:\Windows\system32\d3dx9_30.dll
2018-02-28 16:44:55 ----A---- C:\Windows\system32\d3dx9_29.dll
2018-02-28 16:44:54 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2018-02-28 16:44:54 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2018-02-28 16:44:54 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2018-02-28 16:44:54 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2018-02-28 16:44:54 ----A---- C:\Windows\system32\d3dx9_28.dll
2018-02-28 16:44:54 ----A---- C:\Windows\system32\d3dx9_27.dll
2018-02-28 16:44:54 ----A---- C:\Windows\system32\d3dx9_26.dll
2018-02-28 16:44:54 ----A---- C:\Windows\system32\d3dx9_25.dll
2018-02-28 16:44:53 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2018-02-28 16:44:53 ----A---- C:\Windows\system32\d3dx9_24.dll
2018-02-28 15:58:38 ----D---- C:\Program Files (x86)\Steam

======List of files/folders modified in the last 1 month======

2018-03-27 19:33:52 ----RD---- C:\Program Files
2018-03-27 19:33:04 ----D---- C:\Windows\Temp
2018-03-27 19:25:00 ----D---- C:\Windows\system32\sru
2018-03-27 19:08:20 ----D---- C:\Windows\system32\SleepStudy
2018-03-27 19:08:01 ----D---- C:\Windows\Prefetch
2018-03-27 18:45:47 ----D---- C:\Windows\INF
2018-03-27 18:45:46 ----D---- C:\Windows\system32\catroot2
2018-03-27 18:45:45 ----D---- C:\Windows\system32\DriverStore
2018-03-27 18:45:06 ----SHD---- C:\System Volume Information
2018-03-27 18:37:06 ----RD---- C:\Windows\Microsoft.NET
2018-03-27 18:31:30 ----D---- C:\Windows\System32
2018-03-27 18:31:30 ----A---- C:\Windows\system32\PerfStringBackup.INI
2018-03-27 18:24:33 ----D---- C:\ProgramData\Avg
2018-03-27 18:24:33 ----D---- C:\Program Files (x86)\AVG
2018-03-27 18:24:32 ----D---- C:\Windows\system32\drivers
2018-03-27 18:17:27 ----SHD---- C:\Windows\Installer
2018-03-27 18:17:26 ----HD---- C:\Windows\ELAMBKUP
2018-03-27 18:17:19 ----HD---- C:\ProgramData
2018-03-27 18:12:27 ----D---- C:\Windows\system32\Tasks
2018-03-27 12:09:00 ----D---- C:\Windows\AppReadiness
2018-03-27 12:08:59 ----HD---- C:\Program Files\WindowsApps
2018-03-27 12:04:55 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-26 19:03:01 ----D---- C:\Windows\system32\LogFiles
2018-03-26 18:22:54 ----D---- C:\Windows\Logs
2018-03-22 11:09:58 ----D---- C:\Windows\system32\config
2018-03-21 20:09:20 ----D---- C:\Windows\WinSxS
2018-03-17 20:14:22 ----D---- C:\Windows\rescache
2018-03-17 18:37:15 ----D---- C:\Program Files (x86)\Common Files
2018-03-17 18:37:02 ----D---- C:\Windows\SysWOW64
2018-03-17 18:36:50 ----RD---- C:\Program Files (x86)
2018-03-13 20:03:52 ----D---- C:\Windows\CbsTemp
2018-03-13 19:57:32 ----D---- C:\Windows\TextInput
2018-03-13 19:57:32 ----D---- C:\Windows\system32\cs-CZ
2018-03-13 19:57:32 ----D---- C:\Windows\system32\appraiser
2018-03-13 19:57:31 ----D---- C:\Windows\system32\Boot
2018-03-13 19:57:31 ----D---- C:\Windows\ShellExperiences
2018-03-13 19:57:31 ----D---- C:\Windows\apppatch
2018-03-13 19:57:27 ----D---- C:\Windows\system32\drivers\UMDF
2018-03-13 19:30:29 ----D---- C:\Windows\system32\MRT
2018-03-13 19:29:12 ----AC---- C:\Windows\system32\MRT-KB890830.exe
2018-03-13 19:29:09 ----AC---- C:\Windows\system32\MRT.exe
2018-03-13 19:27:26 ----A---- C:\Windows\SYSWOW64\Chakradiag.dll
2018-03-13 19:27:26 ----A---- C:\Windows\system32\Chakradiag.dll
2018-03-13 19:13:30 ----D---- C:\Windows\system32\Macromed
2018-03-13 19:13:29 ----D---- C:\Windows\SYSWOW64\Macromed
2018-03-13 15:32:14 ----D---- C:\Windows
2018-03-08 19:58:02 ----SD---- C:\Users\admin\AppData\Roaming\Microsoft
2018-03-05 18:41:20 ----D---- C:\Windows\DeliveryOptimization
2018-03-02 23:09:11 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2018-02-28 16:44:49 ----D---- C:\ProgramData\Package Cache
2018-02-28 16:44:22 ----D---- C:\Program Files\Common Files\microsoft shared

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2018-01-08 110432]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2016-09-19 795640]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\Windows\system32\drivers\iorate.sys [2017-09-29 56728]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2014-09-09 15232]
R1 bam;@%SystemRoot%\system32\drivers\bam.sys,-100; C:\Windows\system32\drivers\bam.sys [2018-01-01 59800]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2018-02-14 137928]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2018-01-08 196112]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2018-01-08 82816]
R1 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2018-01-08 108320]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2017-09-29 55808]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2017-09-29 8192]
R2 CldFlt;Windows Cloud Files Filter Driver; C:\Windows\system32\drivers\cldflt.sys [2018-02-10 385536]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2018-01-08 50136]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2017-09-29 43520]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2017-09-29 79872]
R3 amdkmdag;amdkmdag; C:\Windows\System32\DriverStore\FileRepository\c0316391.inf_amd64_1432aea035144561\atikmdag.sys [2017-07-25 38439848]
R3 amdkmdap;amdkmdap; C:\Windows\System32\DriverStore\FileRepository\c0316391.inf_amd64_1432aea035144561\atikmpag.sys [2017-07-25 549800]
R3 AtiHDAudioService;@oem14.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdWT6.sys [2017-04-26 110088]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-09-23 5324808]
R3 MEIx64;@oem11.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\TeeDriverW8x64.sys [2016-09-06 204896]
R3 rt640x64;@oem13.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\Windows\System32\drivers\rt640x64.sys [2016-08-22 943112]
S0 amdkmafd;@oem15.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\Windows\System32\drivers\amdkmafd.sys [2016-08-18 49448]
S0 bttflt;@virtdisk.inf,%service_desc%;Microsoft Hyper-V VHDPMEM BTT Filter; C:\Windows\System32\drivers\bttflt.sys [2017-09-29 37784]
S0 eelam;eelam; C:\Windows\system32\DRIVERS\eelam.sys [2018-01-05 15872]
S0 cht4iscsi;cht4iscsi; C:\Windows\System32\drivers\cht4sx64.sys [2017-09-29 357272]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2017-09-29 123800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2017-09-29 103320]
S0 megasas2i;megasas2i; C:\Windows\System32\drivers\MegaSas2i.sys [2017-09-29 63520]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2017-09-29 58776]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2017-09-29 61848]
S0 Ramdisk;Windows RAM Disk Driver; C:\Windows\system32\DRIVERS\ramdisk.sys [2017-09-29 39832]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\Windows\System32\drivers\scmbus.sys [2017-09-29 118168]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2018-02-22 45472]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\Windows\System32\drivers\AcpiDev.sys [2017-09-29 20480]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\Windows\system32\drivers\applockerfltr.sys [2017-09-29 18432]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2017-09-29 39424]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\Windows\System32\drivers\CAD.sys [2017-09-29 60312]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2017-09-29 122368]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2017-09-29 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2017-09-29 50584]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\Windows\system32\drivers\hvservice.sys [2017-09-29 73112]
S3 HwNClx0101;Microsoft Hardware Notifications Class Extension Driver; C:\Windows\System32\Drivers\mshwnclx.sys [2017-09-29 27136]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\Windows\System32\drivers\cht4vx64.sys [2017-09-29 1723288]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\Windows\System32\drivers\iagpio.sys [2017-09-29 36864]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\Windows\System32\drivers\iai2c.sys [2017-09-29 91648]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [2017-09-29 79360]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\Windows\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-09-29 88576]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [2017-09-29 171520]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-09-29 174592]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2017-09-29 526232]
S3 igfx;igfx; C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\igdkmd64.sys [2018-01-30 11093952]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\Windows\System32\drivers\IndirectKmd.sys [2017-09-29 39424]
S3 IntcDAud;@oem22.inf,%IntcAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2017-06-26 825376]
S3 invdimm;@invdimm.inf,%invdimm.SvcDesc%;Microsoft iNVDIMM device driver; C:\Windows\System32\drivers\invdimm.sys [2017-09-29 38912]
S3 IPT;IPT; C:\Windows\System32\drivers\ipt.sys [2017-09-29 26112]
S3 irda;IrDA; C:\Windows\system32\drivers\irda.sys [2017-09-29 119808]
S3 LVRS64;@oem18.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-10-26 351520]
S3 LVUVC64;@oem17.inf,%PID_0825_DD%(UVC);Logitech HD Webcam C270(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-10-26 4758176]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\Windows\System32\drivers\mausbhost.sys [2017-09-29 505240]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\Windows\System32\drivers\mausbip.sys [2017-09-29 55840]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2017-09-29 842648]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2017-09-29 108952]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\Windows\system32\drivers\NetAdapterCx.sys [2017-09-29 132608]
S3 nvdimmn;@nvdimmn.inf,%nvdimmn.SvcDesc%;Microsoft NVDIMM-N device driver; C:\Windows\System32\drivers\nvdimmn.sys [2017-09-29 88576]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\Windows\System32\drivers\pmem.sys [2017-09-29 100352]
S3 PNPMEM;@memory.inf,%PNPMEM.SvcDesc%;Microsoft Memory Module Driver; C:\Windows\System32\drivers\pnpmem.sys [2017-09-29 16896]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2017-09-29 936856]
S3 rhproxy;@rhproxy.inf,%rhproxy.SVCDESC%;Resource Hub proxy driver; C:\Windows\System32\drivers\rhproxy.sys [2017-09-29 103936]
S3 SDFRd;@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector; C:\Windows\System32\drivers\SDFRd.sys [2017-09-29 33176]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter; C:\Windows\System32\drivers\SpatialGraphFilter.sys [2017-09-30 56216]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2018-02-09 83984]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2017-07-25 560552]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R2 CDPUserSvc_3c875;Uživatelská služba platformy připojených zařízení_3c875; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R2 cplspcon;Intel(R) Content Protection HDCP Service; C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\IntelCpHDCPSvc.exe [2018-01-30 480704]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2017-09-29 48688]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\System32\svchost.exe [2017-09-29 48688]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\Windows\System32\svchost.exe [2017-09-29 48688]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Security\ekrn.exe [2018-03-15 2213344]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [2017-07-26 192200]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\igfxCUIService.exe [2018-01-30 341448]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2016-09-14 177440]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2016-09-14 419616]
R2 OneSyncSvc_3c875;Hostitel synchronizace_3c875; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R2 SecurityHealthService;@%systemroot%\system32\SecurityHealthAgent.dll,-1002; C:\Windows\system32\SecurityHealthService.exe [2018-03-01 519152]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2017-09-29 48688]
R3 ekrnEpfw;ESET Firewall Helper; C:\Program Files\ESET\ESET Security\ekrn.exe [2018-03-15 2213344]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2017-09-29 48688]
R3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R3 PimIndexMaintenanceSvc_3c875;Data kontaktů_3c875; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2018-03-27 1671968]
R3 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\Windows\system32\svchost.exe [2017-09-29 48688]
R3 TokenBroker;@%systemroot%\system32\tokenbroker.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-02-03 153168]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-03-13 272384]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 camsvc;@%SystemRoot%\system32\CapabilityAccessManager.dll,-1; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\IntelCpHeciSvc.exe [2018-01-30 502720]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 DevicesFlowUserSvc_3c875;Tok zařízení_3c875; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-09-29 85504]
S3 diagsvc;@%systemroot%\system32\DiagSvc.dll,-100; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 GraphicsPerfSvc;@%SystemRoot%\system32\GraphicsPerfSvc.dll,-100; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-02-03 153168]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 InstallService;@%SystemRoot%\system32\InstallService.dll,-200; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2016-07-26 987432]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 MessagingService_3c875;Služba zasílání zpráv_3c875; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2018-03-26 194512]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 PrintWorkflowUserSvc;@%SystemRoot%\system32\PrintWorkflowService.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 PrintWorkflowUserSvc_3c875;PrintWorkflow_3c875; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 PushToInstall;@%SystemRoot%\system32\pushtoinstall.dll,-200; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\Windows\System32\svchost.exe [2017-09-29 48688]
S3 SEMgrSvc;@%SystemRoot%\System32\SEMgrSvc.dll,-1001; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2017-09-29 1288704]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 SharedRealitySvc;@%SystemRoot%\system32\SharedRealitySvc.dll,-100; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2017-09-29 48688]
S3 spectrum;@%systemroot%\system32\spectrum.exe,-101; C:\Windows\system32\spectrum.exe [2018-03-02 956416]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\Windows\system32\TieringEngineService.exe [2017-09-29 302592]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\Windows\System32\svchost.exe [2017-09-29 48688]

-----------------EOF-----------------

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Policejní virus

#2 Příspěvek od Conder »

Ahoj :)

:arrow: Co konkretne myslis pod policajnym virusom? Je v PC nieco zablokovane/nefunkcne alebo iba v prehliadaci vyskocila nejaka hlaska?

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Scan (Skenovanie) a pockaj na dokoncenie
  • Klikni na Clean (Cistenie) a potvrd kliknutim na OK
  • AdwCleaner si vyziada restart PC, potvrd kliknutim na Restart Now (Restartovat teraz)
  • Po dokonceni a restartovani PC vyskoci log, jeho obsah sem skopiruj
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Ondor
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 27 bře 2018 18:50

Re: Policejní virus

#3 Příspěvek od Ondor »

Naskočila hláška jako od PČR, že mám zaplatit 4 tisíce, protože mám v PC zakázaný obsah - dětské porno...atd. Pak začaly v prohlížeči naskakovat porno hlášky a stránky.

# AdwCleaner 7.0.8.0 - Logfile created on Tue Mar 27 20:36:10 2018
# Updated on 2018/08/02 by Malwarebytes
# Running on Windows 10 Home (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\slunecnice.cz
Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.slunecnice.cz
Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\slunecnice.cz
Deleted: [Key] - HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.slunecnice.cz
Deleted: [Key] - HKU\S-1-5-21-3273614194-3348390461-1479779135-1001\Software\csastats
Deleted: [Key] - HKCU\Software\csastats


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [1981 B] - [2018/3/27 20:19:21]
C:/AdwCleaner/AdwCleaner[S1].txt - [2049 B] - [2018/3/27 20:25:2]
C:/AdwCleaner/AdwCleaner[S2].txt - [2116 B] - [2018/3/27 20:33:47]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Policejní virus

#4 Příspěvek od Conder »

:arrow: Poprosim o obidva logy z FRST podla tohto navodu (FRST.txt a Addition.txt): https://forum.viry.cz/viewtopic.php?f=13&t=152707

:arrow: V pripade, ze sa FRSTLauncher nebude dat stiahnut alebo spustit, pouzi iba samotny FRST.

:arrow: Ak sa logy nezmestia do jedneho prispevku, zabal ich do archivu RAR alebo ZIP a posli ako prilohu.
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Ondor
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 27 bře 2018 18:50

Re: Policejní virus

#5 Příspěvek od Ondor »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
Ran by admin (administrator) on DESKTOP-8IPFSNK (28-03-2018 07:20:02)
Running from C:\Users\admin\Desktop
Loaded Profiles: admin (Available Profiles: admin)
Platform: Windows 10 Home Version 1709 16299.309 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64_4839_64bit.inf_amd64_d6aee56abac60177\igfxCUIService.exe
(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
() C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(AMD) C:\Windows\System32\atieclxx.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1811.248.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Spotify Ltd) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.75.483.0_x86__zpdnekdrzrea0\SpotifyWebHelper.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
() C:\Program Files (x86)\Logitech\LWS\Webcam Software\CameraHelperShell.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(forum.viry.cz) C:\Users\admin\Downloads\FRSTLauncher.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8903176 2016-09-23] (Realtek Semiconductor)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmds.exe [178496 2018-03-15] (ESET)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKU\S-1-5-21-3273614194-3348390461-1479779135-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3198752 2018-03-27] (Valve Corporation)
HKU\S-1-5-21-3273614194-3348390461-1479779135-1001\...\MountPoints2: {6d27f96f-0e78-11e8-a18d-2cfda17081b1} - "E:\HiSuiteDownLoader.exe"
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registrace produktu.lnk [2018-03-27]
ShortcutTarget: Logitech . Registrace produktu.lnk -> C:\Program Files (x86)\Logitech\Ereg\eReg.exe (Leader Technologies/Logitech)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{2dd54337-878b-4703-ba55-74cc28e88923}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-3273614194-3348390461-1479779135-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2018-03-17] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2018-03-17] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: ysu13zbi.default
FF ProfilePath: C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default [2018-03-28]
FF user.js: detected! => C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\user.js [2018-03-17]
FF Extension: (Web Security) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\Extensions\contact@web-security.com.xpi [2018-03-17]
FF Extension: (FF Gallery) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\Extensions\{1dc6315f-9990-4e2e-a021-8d5341488603}.xpi [2018-03-17]
FF Extension: (TLS 1.3 gradual roll-out) - C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\features\{5870a187-da75-4ab4-8953-bf0d3ff7db2b}\tls13-rollout-bug1442042@mozilla.org.xpi [2018-03-23] [Legacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_29_0_0_113.dll [2018-03-13] ()
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_113.dll [2018-03-13] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2018-03-17] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2018-03-17] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-02-03] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR Profile: C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default [2018-03-27]
CHR Extension: (Prezentace) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-02-03]
CHR Extension: (Dokumenty) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-02-03]
CHR Extension: (Disk Google) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-02-03]
CHR Extension: (YouTube) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-02-03]
CHR Extension: (Adobe Acrobat) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-02-19]
CHR Extension: (Tabulky) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-02-03]
CHR Extension: (Dokumenty Google offline) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-02-19]
CHR Extension: (AVG SafePrice) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbckjcfnjmoiinpgddefodcighgikkgn [2018-03-27]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-02-03]
CHR Extension: (Gmail) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-02-03]
CHR Extension: (Chrome Media Router) - C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-27]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2213344 2018-03-15] (ESET)
R3 ekrnEpfw; C:\Program Files\ESET\ESET Security\ekrn.exe [2213344 2018-03-15] (ESET)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2017-07-26] () [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [987432 2016-07-26] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [177440 2016-09-14] (Intel Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-01-25] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-01-25] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\Windows\System32\DriverStore\FileRepository\c0316391.inf_amd64_1432aea035144561\atikmdag.sys [38439848 2017-07-25] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DriverStore\FileRepository\c0316391.inf_amd64_1432aea035144561\atikmpag.sys [549800 2017-07-25] (Advanced Micro Devices, Inc.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] ()
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [110088 2017-04-26] (Advanced Micro Devices)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [137928 2018-02-14] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [110432 2018-01-08] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15872 2018-01-05] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [196112 2018-01-08] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [50136 2018-01-08] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [82816 2018-01-08] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [108320 2018-01-08] (ESET)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2017-07-26] (Huawei Technologies Co., Ltd.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [943112 2016-08-22] (Realtek )
S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [46072 2018-01-25] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [288848 2018-01-25] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [129616 2018-01-25] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-28 07:20 - 2018-03-28 07:20 - 000012924 _____ C:\Users\admin\Desktop\FRST.txt
2018-03-28 07:19 - 2018-03-28 07:20 - 000000000 ____D C:\FRST
2018-03-28 07:17 - 2018-03-28 07:18 - 000112640 _____ (forum.viry.cz) C:\Users\admin\Downloads\FRSTLauncher.exe
2018-03-28 07:15 - 2018-03-28 07:16 - 002403328 _____ (Farbar) C:\Users\admin\Desktop\FRST64.exe
2018-03-27 22:21 - 2018-03-27 22:22 - 008222496 _____ (Malwarebytes) C:\Users\admin\Desktop\adwcleaner_7.0.8.0(1).exe
2018-03-27 22:17 - 2018-03-27 22:36 - 000000000 ____D C:\AdwCleaner
2018-03-27 22:16 - 2018-03-27 22:16 - 008222496 _____ (Malwarebytes) C:\Users\admin\Downloads\adwcleaner_7.0.8.0.exe
2018-03-27 19:33 - 2018-03-27 19:34 - 000000000 ____D C:\rsit
2018-03-27 19:33 - 2018-03-27 19:34 - 000000000 ____D C:\Program Files\trend micro
2018-03-27 19:33 - 2018-03-27 19:33 - 001222144 _____ C:\Users\admin\Downloads\RSITx64.exe
2018-03-27 18:17 - 2018-03-27 18:17 - 000002016 _____ C:\Users\Public\Desktop\ESET Ochrana bankovnictví a online plateb.lnk
2018-03-27 18:17 - 2018-03-27 18:17 - 000000000 ____D C:\Users\admin\AppData\Local\ESET
2018-03-27 18:17 - 2018-03-27 18:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2018-03-27 18:17 - 2018-03-27 18:17 - 000000000 ____D C:\ProgramData\ESET
2018-03-27 18:17 - 2018-03-27 18:17 - 000000000 ____D C:\Program Files\ESET
2018-03-27 18:12 - 2018-03-27 18:12 - 000000000 ____D C:\Windows\system32\Drivers\wd
2018-03-27 18:09 - 2018-03-27 18:09 - 004279416 _____ (ESET) C:\Users\admin\Downloads\eset_internet_security_live_installer.exe
2018-03-27 16:27 - 2018-03-27 16:27 - 000001242 _____ C:\Users\admin\Downloads\Lovecká sezóna 4 CZ dab – zástupce.lnk
2018-03-27 13:00 - 2018-03-27 13:43 - 788720008 _____ C:\Users\admin\Downloads\Lovecká sezóna 4 CZ dab.avi
2018-03-27 12:14 - 2018-03-27 12:54 - 732096512 _____ C:\Users\admin\Downloads\lovecka sezona 3 CZ.avi
2018-03-26 20:44 - 2018-03-27 12:04 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-03-22 21:06 - 2018-03-22 21:33 - 000000000 ___RD C:\Users\admin\Documents\Scanned Documents
2018-03-22 21:06 - 2018-03-22 21:06 - 000000000 ____D C:\Users\admin\Documents\Fax
2018-03-17 18:37 - 2018-03-17 18:37 - 000000000 ____D C:\Users\admin\AppData\Roaming\Sun
2018-03-17 18:37 - 2018-03-17 18:37 - 000000000 ____D C:\Users\admin\AppData\LocalLow\Sun
2018-03-17 18:37 - 2018-03-17 18:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-03-17 18:37 - 2018-03-17 18:36 - 000097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2018-03-17 18:36 - 2018-03-17 18:37 - 000000000 ____D C:\ProgramData\Oracle
2018-03-17 18:36 - 2018-03-17 18:36 - 000000000 ____D C:\Program Files (x86)\Java
2018-03-17 18:35 - 2018-03-17 18:35 - 056134208 _____ (Oracle Corporation) C:\Users\admin\Downloads\JavaSetup.exe
2018-03-13 19:26 - 2018-03-02 05:36 - 017085440 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll
2018-03-13 19:26 - 2018-03-02 05:02 - 000037888 _____ C:\Windows\system32\SpectrumSyncClient.dll
2018-03-13 19:26 - 2018-03-02 05:01 - 000640000 _____ (Microsoft Corporation) C:\Windows\system32\HeadTrackerStorage.dll
2018-03-13 19:26 - 2018-03-02 05:00 - 000329728 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Feedback.Analog.dll
2018-03-13 19:26 - 2018-03-02 05:00 - 000248320 _____ (Microsoft Corporation) C:\Windows\system32\svf.dll
2018-03-13 19:26 - 2018-03-02 05:00 - 000230912 _____ (Microsoft Corporation) C:\Windows\system32\HoloShellRuntime.dll
2018-03-13 19:26 - 2018-03-02 04:59 - 000956416 _____ (Microsoft Corporation) C:\Windows\system32\Spectrum.exe
2018-03-13 19:26 - 2018-03-01 22:28 - 000181760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\HoloShellRuntime.dll
2018-03-13 19:26 - 2018-03-01 09:50 - 000270744 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-03-13 19:26 - 2018-03-01 09:49 - 000389536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-03-13 19:26 - 2018-03-01 09:48 - 000664472 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-03-13 19:26 - 2018-03-01 09:47 - 000749464 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-03-13 19:26 - 2018-03-01 09:47 - 000035224 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe
2018-03-13 19:26 - 2018-03-01 09:46 - 002003352 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-03-13 19:26 - 2018-03-01 09:46 - 001568664 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-03-13 19:26 - 2018-03-01 09:46 - 000609176 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-03-13 19:26 - 2018-03-01 09:46 - 000138144 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-03-13 19:26 - 2018-03-01 09:45 - 000070040 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll
2018-03-13 19:26 - 2018-03-01 09:40 - 002514936 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-03-13 19:26 - 2018-03-01 09:40 - 000461720 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll
2018-03-13 19:26 - 2018-03-01 09:40 - 000273304 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-03-13 19:26 - 2018-03-01 09:37 - 007831760 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2018-03-13 19:26 - 2018-03-01 09:31 - 008602520 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-03-13 19:26 - 2018-03-01 09:30 - 000540064 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2018-03-13 19:26 - 2018-03-01 09:30 - 000264040 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe
2018-03-13 19:26 - 2018-03-01 09:29 - 000733592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2018-03-13 19:26 - 2018-03-01 09:27 - 001173576 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-03-13 19:26 - 2018-03-01 09:26 - 000170912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-03-13 19:26 - 2018-03-01 09:25 - 000377752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-03-13 19:26 - 2018-03-01 09:23 - 000749976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2018-03-13 19:26 - 2018-03-01 09:19 - 000710768 _____ (Microsoft Corporation) C:\Windows\system32\MSVideoDSP.dll
2018-03-13 19:26 - 2018-03-01 09:17 - 002710736 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-03-13 19:26 - 2018-03-01 09:17 - 000519152 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe
2018-03-13 19:26 - 2018-03-01 09:17 - 000408984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2018-03-13 19:26 - 2018-03-01 09:15 - 002574232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2018-03-13 19:26 - 2018-03-01 09:14 - 007675784 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2018-03-13 19:26 - 2018-03-01 09:14 - 007384576 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2018-03-13 19:26 - 2018-03-01 09:14 - 005105664 _____ (Microsoft Corporation) C:\Windows\system32\AuthFWSnapin.dll
2018-03-13 19:26 - 2018-03-01 09:14 - 001694224 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2018-03-13 19:26 - 2018-03-01 09:14 - 000356952 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2018-03-13 19:26 - 2018-03-01 09:14 - 000147872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wcifs.sys
2018-03-13 19:26 - 2018-03-01 09:14 - 000128928 _____ (Microsoft Corporation) C:\Windows\system32\offlinelsa.dll
2018-03-13 19:26 - 2018-03-01 09:12 - 000677272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2018-03-13 19:26 - 2018-03-01 09:12 - 000250264 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll
2018-03-13 19:26 - 2018-03-01 09:12 - 000189344 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthAgent.dll
2018-03-13 19:26 - 2018-03-01 09:11 - 000093600 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2018-03-13 19:26 - 2018-03-01 09:10 - 001779936 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2018-03-13 19:26 - 2018-03-01 09:10 - 000075168 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthProxyStub.dll
2018-03-13 19:26 - 2018-03-01 09:10 - 000022936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\isapnp.sys
2018-03-13 19:26 - 2018-03-01 09:09 - 001054272 _____ (Microsoft Corporation) C:\Windows\system32\msvproc.dll
2018-03-13 19:26 - 2018-03-01 08:51 - 000777904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-03-13 19:26 - 2018-03-01 08:48 - 001930736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-03-13 19:26 - 2018-03-01 08:39 - 000213400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll
2018-03-13 19:26 - 2018-03-01 08:30 - 005615968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2018-03-13 19:26 - 2018-03-01 08:29 - 006092152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2018-03-13 19:26 - 2018-03-01 08:29 - 000574960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVideoDSP.dll
2018-03-13 19:26 - 2018-03-01 08:28 - 006480616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-03-13 19:26 - 2018-03-01 08:28 - 002193168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-03-13 19:26 - 2018-03-01 08:28 - 000115096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offlinelsa.dll
2018-03-13 19:26 - 2018-03-01 08:27 - 000284112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2018-03-13 19:26 - 2018-03-01 08:27 - 000221592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offlinesam.dll
2018-03-13 19:26 - 2018-03-01 08:26 - 001524776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2018-03-13 19:26 - 2018-03-01 08:26 - 001057816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvproc.dll
2018-03-13 19:26 - 2018-03-01 08:23 - 005105664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthFWSnapin.dll
2018-03-13 19:26 - 2018-03-01 08:21 - 001558856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2018-03-13 19:26 - 2018-03-01 08:09 - 025251840 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2018-03-13 19:26 - 2018-03-01 08:03 - 002902528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2018-03-13 19:26 - 2018-03-01 08:03 - 000471552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AcSpecfc.dll
2018-03-13 19:26 - 2018-03-01 08:03 - 000344576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgeIso.dll
2018-03-13 19:26 - 2018-03-01 08:03 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IndexedDbLegacy.dll
2018-03-13 19:26 - 2018-03-01 08:03 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usoapi.dll
2018-03-13 19:26 - 2018-03-01 08:01 - 019354624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-03-13 19:26 - 2018-03-01 08:01 - 006575616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2018-03-13 19:26 - 2018-03-01 08:01 - 000155648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EdgeManager.dll
2018-03-13 19:26 - 2018-03-01 08:01 - 000019456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-03-13 19:26 - 2018-03-01 08:00 - 000098304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-03-13 19:26 - 2018-03-01 07:59 - 000220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MicrosoftAccountWAMExtension.dll
2018-03-13 19:26 - 2018-03-01 07:58 - 004839424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2018-03-13 19:26 - 2018-03-01 07:58 - 000459776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webplatstorageserver.dll
2018-03-13 19:26 - 2018-03-01 07:58 - 000405504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Payments.dll
2018-03-13 19:26 - 2018-03-01 07:58 - 000368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2018-03-13 19:26 - 2018-03-01 07:57 - 000369152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msIso.dll
2018-03-13 19:26 - 2018-03-01 07:56 - 018922496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2018-03-13 19:26 - 2018-03-01 07:56 - 000559104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-03-13 19:26 - 2018-03-01 07:55 - 000346112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2018-03-13 19:26 - 2018-03-01 07:54 - 003664384 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2018-03-13 19:26 - 2018-03-01 07:54 - 003181568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2018-03-13 19:26 - 2018-03-01 07:54 - 001296896 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2018-03-13 19:26 - 2018-03-01 07:54 - 000665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-03-13 19:26 - 2018-03-01 07:54 - 000496128 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2018-03-13 19:26 - 2018-03-01 07:54 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-03-13 19:26 - 2018-03-01 07:53 - 000863232 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2018-03-13 19:26 - 2018-03-01 07:53 - 000536576 _____ (Microsoft Corporation) C:\Windows\system32\edgeIso.dll
2018-03-13 19:26 - 2018-03-01 07:53 - 000399872 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2018-03-13 19:26 - 2018-03-01 07:53 - 000246272 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2018-03-13 19:26 - 2018-03-01 07:53 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\IndexedDbLegacy.dll
2018-03-13 19:26 - 2018-03-01 07:53 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
2018-03-13 19:26 - 2018-03-01 07:53 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\updatecsp.dll
2018-03-13 19:26 - 2018-03-01 07:53 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\usoapi.dll
2018-03-13 19:26 - 2018-03-01 07:53 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\AcSpecfc.dll
2018-03-13 19:26 - 2018-03-01 07:53 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\UsoClient.exe
2018-03-13 19:26 - 2018-03-01 07:52 - 011923968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-03-13 19:26 - 2018-03-01 07:52 - 006030336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2018-03-13 19:26 - 2018-03-01 07:51 - 002329088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2018-03-13 19:26 - 2018-03-01 07:51 - 000201728 _____ (Microsoft Corporation) C:\Windows\system32\EdgeManager.dll
2018-03-13 19:26 - 2018-03-01 07:51 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BasicRender.sys
2018-03-13 19:26 - 2018-03-01 07:51 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-03-13 19:26 - 2018-03-01 07:50 - 003677184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-03-13 19:26 - 2018-03-01 07:50 - 002869760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-03-13 19:26 - 2018-03-01 07:50 - 000526336 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2018-03-13 19:26 - 2018-03-01 07:50 - 000118272 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-03-13 19:26 - 2018-03-01 07:50 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wcnfs.sys
2018-03-13 19:26 - 2018-03-01 07:49 - 000675328 _____ (Microsoft Corporation) C:\Windows\system32\webplatstorageserver.dll
2018-03-13 19:26 - 2018-03-01 07:49 - 000529408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2018-03-13 19:26 - 2018-03-01 07:49 - 000301056 _____ (Microsoft Corporation) C:\Windows\system32\MicrosoftAccountWAMExtension.dll
2018-03-13 19:26 - 2018-03-01 07:49 - 000066048 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-03-13 19:26 - 2018-03-01 07:48 - 000543232 _____ (Microsoft Corporation) C:\Windows\system32\HolographicExtensions.dll
2018-03-13 19:26 - 2018-03-01 07:48 - 000431616 _____ (Microsoft Corporation) C:\Windows\system32\msIso.dll
2018-03-13 19:26 - 2018-03-01 07:47 - 023674368 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-03-13 19:26 - 2018-03-01 07:47 - 000579584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Payments.dll
2018-03-13 19:26 - 2018-03-01 07:47 - 000484352 _____ (Microsoft Corporation) C:\Windows\system32\cdpusersvc.dll
2018-03-13 19:26 - 2018-03-01 07:46 - 004051968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2018-03-13 19:26 - 2018-03-01 07:46 - 000770048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2018-03-13 19:26 - 2018-03-01 07:46 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msisip.dll
2018-03-13 19:26 - 2018-03-01 07:45 - 000708096 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-03-13 19:26 - 2018-03-01 07:45 - 000594944 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-03-13 19:26 - 2018-03-01 07:45 - 000386560 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-03-13 19:26 - 2018-03-01 07:44 - 008030720 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2018-03-13 19:26 - 2018-03-01 07:44 - 005195776 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2018-03-13 19:26 - 2018-03-01 07:43 - 012830208 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-03-13 19:26 - 2018-03-01 07:42 - 003505664 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2018-03-13 19:26 - 2018-03-01 07:42 - 002084352 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2018-03-13 19:26 - 2018-03-01 07:41 - 008103936 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2018-03-13 19:26 - 2018-03-01 07:41 - 004745728 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-03-13 19:26 - 2018-03-01 07:41 - 003334144 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-03-13 19:26 - 2018-03-01 07:41 - 001548288 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-03-13 19:26 - 2018-03-01 07:41 - 000812032 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-03-13 19:26 - 2018-03-01 07:40 - 005833216 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2018-03-13 19:26 - 2018-03-01 07:39 - 002222592 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2018-03-13 19:26 - 2018-03-01 07:39 - 002035712 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2018-03-13 19:26 - 2018-03-01 07:39 - 000899584 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2018-03-13 19:26 - 2018-03-01 07:39 - 000666624 _____ (Microsoft Corporation) C:\Windows\system32\DbgModel.dll
2018-03-13 19:26 - 2018-03-01 07:38 - 000963072 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll
2018-03-13 19:26 - 2018-03-01 07:38 - 000726016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-03-13 19:26 - 2018-03-01 07:36 - 004050432 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-03-13 19:26 - 2018-03-01 07:36 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\msisip.dll
2018-03-13 19:26 - 2018-03-01 07:35 - 000568320 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2018-03-13 19:26 - 2018-03-01 07:35 - 000128000 _____ (Microsoft Corporation) C:\Windows\system32\racpldlg.dll
2018-03-13 19:26 - 2018-03-01 07:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2018-03-13 19:26 - 2018-02-22 04:23 - 001092016 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-03-13 19:26 - 2018-02-22 04:23 - 000924648 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2018-03-13 19:26 - 2018-02-22 04:13 - 000279456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2018-03-13 19:26 - 2018-02-22 04:13 - 000077216 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll
2018-03-13 19:26 - 2018-02-22 04:11 - 000109984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbus.sys
2018-03-13 19:26 - 2018-02-22 04:10 - 000285080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys
2018-03-13 19:26 - 2018-02-22 04:08 - 001206688 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2018-03-13 19:26 - 2018-02-22 04:08 - 001055648 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2018-03-13 19:26 - 2018-02-22 04:08 - 000571288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2018-03-13 19:26 - 2018-02-22 04:07 - 001415296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-03-13 19:26 - 2018-02-22 04:07 - 001209248 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-03-13 19:26 - 2018-02-22 04:07 - 000194456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ataport.sys
2018-03-13 19:26 - 2018-02-22 04:03 - 000712600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2018-03-13 19:26 - 2018-02-22 04:03 - 000082848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-03-13 19:26 - 2018-02-22 04:02 - 000149400 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storahci.sys
2018-03-13 19:26 - 2018-02-22 04:00 - 000187296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys
2018-03-13 19:26 - 2018-02-22 03:59 - 021351624 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-03-13 19:26 - 2018-02-22 03:54 - 000437144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS
2018-03-13 19:26 - 2018-02-22 03:52 - 000103328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2018-03-13 19:26 - 2018-02-22 03:51 - 000555424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2018-03-13 19:26 - 2018-02-22 03:51 - 000097176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdstor.sys
2018-03-13 19:26 - 2018-02-22 03:51 - 000045472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storufs.sys
2018-03-13 19:26 - 2018-02-22 03:50 - 000362904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-03-13 19:26 - 2018-02-22 03:50 - 000229272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys
2018-03-13 19:26 - 2018-02-22 02:41 - 020286120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-03-13 19:26 - 2018-02-22 02:31 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UcmUcsi.sys
2018-03-13 19:26 - 2018-02-22 02:30 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netvsc.sys
2018-03-13 19:26 - 2018-02-22 02:30 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-03-13 19:26 - 2018-02-22 02:30 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\RfxVmt.sys
2018-03-13 19:26 - 2018-02-22 02:27 - 001282048 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
2018-03-13 19:26 - 2018-02-22 02:26 - 000441344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
2018-03-13 19:26 - 2018-02-22 02:25 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\cldapi.dll
2018-03-13 19:26 - 2018-02-22 02:16 - 001286144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2018-03-13 19:26 - 2018-02-22 02:12 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cldapi.dll
2018-03-13 19:13 - 2018-03-13 19:13 - 000004644 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-03-06 17:50 - 2018-03-13 19:13 - 000004506 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-03-06 17:50 - 2018-03-06 17:50 - 000000000 ____D C:\Users\admin\AppData\Roaming\Macromedia
2018-02-28 16:45 - 2018-02-28 16:45 - 000000000 ____D C:\Users\admin\AppData\Roaming\Warner Bros. Interactive Entertainment
2018-02-28 16:45 - 2010-06-02 05:55 - 000527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2018-02-28 16:45 - 2010-06-02 05:55 - 000518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2018-02-28 16:45 - 2010-06-02 05:55 - 000239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2018-02-28 16:45 - 2010-06-02 05:55 - 000176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2018-02-28 16:45 - 2010-06-02 05:55 - 000077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2018-02-28 16:45 - 2010-06-02 05:55 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 002526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 002401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 002106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 001998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 001907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 001868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 000511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 000470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 000276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2018-02-28 16:45 - 2010-05-26 12:41 - 000248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2018-02-28 16:45 - 2010-02-04 11:01 - 000530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2018-02-28 16:45 - 2010-02-04 11:01 - 000528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2018-02-28 16:45 - 2010-02-04 11:01 - 000238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2018-02-28 16:45 - 2010-02-04 11:01 - 000176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2018-02-28 16:45 - 2010-02-04 11:01 - 000078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2018-02-28 16:45 - 2010-02-04 11:01 - 000074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2018-02-28 16:45 - 2010-02-04 11:01 - 000024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2018-02-28 16:45 - 2010-02-04 11:01 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2018-02-28 16:45 - 2009-09-04 18:44 - 000517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2018-02-28 16:45 - 2009-09-04 18:44 - 000515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2018-02-28 16:45 - 2009-09-04 18:44 - 000238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2018-02-28 16:45 - 2009-09-04 18:44 - 000176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2018-02-28 16:45 - 2009-09-04 18:44 - 000073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2018-02-28 16:45 - 2009-09-04 18:44 - 000069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 005554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 005501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 002582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 002475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 001974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 001892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 000523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 000285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2018-02-28 16:45 - 2009-09-04 18:29 - 000235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2018-02-28 16:45 - 2009-03-16 15:18 - 000521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2018-02-28 16:45 - 2009-03-16 15:18 - 000517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2018-02-28 16:45 - 2009-03-16 15:18 - 000235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2018-02-28 16:45 - 2009-03-16 15:18 - 000174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2018-02-28 16:45 - 2009-03-16 15:18 - 000024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2018-02-28 16:45 - 2009-03-16 15:18 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2018-02-28 16:45 - 2009-03-09 16:27 - 005425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2018-02-28 16:45 - 2009-03-09 16:27 - 004178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2018-02-28 16:45 - 2009-03-09 16:27 - 002430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2018-02-28 16:45 - 2009-03-09 16:27 - 001846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2018-02-28 16:45 - 2009-03-09 16:27 - 000520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2018-02-28 16:45 - 2009-03-09 16:27 - 000453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2018-02-28 16:45 - 2008-10-27 11:04 - 000518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2018-02-28 16:45 - 2008-10-27 11:04 - 000514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2018-02-28 16:45 - 2008-10-27 11:04 - 000235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2018-02-28 16:45 - 2008-10-27 11:04 - 000175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2018-02-28 16:45 - 2008-10-27 11:04 - 000074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2018-02-28 16:45 - 2008-10-27 11:04 - 000070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2018-02-28 16:45 - 2008-10-27 11:04 - 000025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2018-02-28 16:45 - 2008-10-27 11:04 - 000023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2018-02-28 16:45 - 2008-10-15 07:22 - 005631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2018-02-28 16:45 - 2008-10-15 07:22 - 004379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2018-02-28 16:45 - 2008-10-15 07:22 - 002605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2018-02-28 16:45 - 2008-10-15 07:22 - 002036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2018-02-28 16:45 - 2008-10-15 07:22 - 000519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2018-02-28 16:45 - 2008-10-15 07:22 - 000452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2018-02-28 16:45 - 2008-07-31 11:41 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2018-02-28 16:45 - 2008-07-31 11:41 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2018-02-28 16:45 - 2008-07-31 11:41 - 000072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2018-02-28 16:45 - 2008-07-31 11:41 - 000068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2018-02-28 16:45 - 2008-07-31 11:40 - 000513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2018-02-28 16:45 - 2008-07-31 11:40 - 000509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2018-02-28 16:45 - 2008-07-10 12:01 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2018-02-28 16:45 - 2008-07-10 12:00 - 004992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2018-02-28 16:45 - 2008-07-10 12:00 - 003851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2018-02-28 16:45 - 2008-07-10 12:00 - 001942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2018-02-28 16:45 - 2008-07-10 12:00 - 001493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2018-02-28 16:45 - 2008-07-10 12:00 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2018-02-28 16:45 - 2008-05-30 15:19 - 000511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2018-02-28 16:45 - 2008-05-30 15:19 - 000507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2018-02-28 16:45 - 2008-05-30 15:18 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2018-02-28 16:45 - 2008-05-30 15:18 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2018-02-28 16:45 - 2008-05-30 15:17 - 000068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2018-02-28 16:45 - 2008-05-30 15:17 - 000065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2018-02-28 16:45 - 2008-05-30 15:17 - 000025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2018-02-28 16:45 - 2008-05-30 15:16 - 000028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2018-02-28 16:45 - 2008-05-30 15:11 - 004991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2018-02-28 16:45 - 2008-05-30 15:11 - 003850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2018-02-28 16:45 - 2008-05-30 15:11 - 001941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2018-02-28 16:45 - 2008-05-30 15:11 - 001491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2018-02-28 16:45 - 2008-05-30 15:11 - 000540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2018-02-28 16:45 - 2008-05-30 15:11 - 000467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2018-02-28 16:45 - 2008-03-05 17:04 - 000489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2018-02-28 16:45 - 2008-03-05 17:03 - 000479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2018-02-28 16:44 - 2008-03-05 17:03 - 000238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2018-02-28 16:44 - 2008-03-05 17:03 - 000177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2018-02-28 16:44 - 2008-03-05 17:00 - 000028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2018-02-28 16:44 - 2008-03-05 17:00 - 000025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2018-02-28 16:44 - 2008-03-05 16:56 - 004910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2018-02-28 16:44 - 2008-03-05 16:56 - 003786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2018-02-28 16:44 - 2008-03-05 16:56 - 001860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2018-02-28 16:44 - 2008-03-05 16:56 - 001420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2018-02-28 16:44 - 2008-02-06 00:07 - 000529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2018-02-28 16:44 - 2008-02-06 00:07 - 000462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2018-02-28 16:44 - 2007-10-22 04:40 - 000411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2018-02-28 16:44 - 2007-10-22 04:39 - 000267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2018-02-28 16:44 - 2007-10-22 04:37 - 000021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2018-02-28 16:44 - 2007-10-22 04:37 - 000017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2018-02-28 16:44 - 2007-10-12 16:14 - 005081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2018-02-28 16:44 - 2007-10-12 16:14 - 003734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2018-02-28 16:44 - 2007-10-12 16:14 - 002006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2018-02-28 16:44 - 2007-10-12 16:14 - 001374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2018-02-28 16:44 - 2007-10-02 10:56 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2018-02-28 16:44 - 2007-10-02 10:56 - 000444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2018-02-28 16:44 - 2007-07-20 01:57 - 000411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2018-02-28 16:44 - 2007-07-20 01:57 - 000267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2018-02-28 16:44 - 2007-07-19 19:14 - 005073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2018-02-28 16:44 - 2007-07-19 19:14 - 003727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2018-02-28 16:44 - 2007-07-19 19:14 - 001985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2018-02-28 16:44 - 2007-07-19 19:14 - 001358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2018-02-28 16:44 - 2007-07-19 19:14 - 000508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2018-02-28 16:44 - 2007-07-19 19:14 - 000444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2018-02-28 16:44 - 2007-06-20 21:49 - 000409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2018-02-28 16:44 - 2007-06-20 21:46 - 000266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2018-02-28 16:44 - 2007-05-16 17:45 - 004496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2018-02-28 16:44 - 2007-05-16 17:45 - 003497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2018-02-28 16:44 - 2007-05-16 17:45 - 001401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2018-02-28 16:44 - 2007-05-16 17:45 - 001124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2018-02-28 16:44 - 2007-05-16 17:45 - 000506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2018-02-28 16:44 - 2007-05-16 17:45 - 000443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2018-02-28 16:44 - 2007-04-04 19:55 - 000403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2018-02-28 16:44 - 2007-04-04 19:55 - 000261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2018-02-28 16:44 - 2007-04-04 19:54 - 000107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2018-02-28 16:44 - 2007-04-04 19:53 - 000081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2018-02-28 16:44 - 2007-03-15 17:57 - 000506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2018-02-28 16:44 - 2007-03-15 17:57 - 000443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2018-02-28 16:44 - 2007-03-12 17:42 - 004494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2018-02-28 16:44 - 2007-03-12 17:42 - 003495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2018-02-28 16:44 - 2007-03-12 17:42 - 001400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2018-02-28 16:44 - 2007-03-12 17:42 - 001123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2018-02-28 16:44 - 2007-03-05 13:42 - 000017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2018-02-28 16:44 - 2007-03-05 13:42 - 000015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2018-02-28 16:44 - 2007-01-24 16:27 - 000393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2018-02-28 16:44 - 2007-01-24 16:27 - 000255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2018-02-28 16:44 - 2006-12-08 13:02 - 000251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2018-02-28 16:44 - 2006-12-08 13:00 - 000390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2018-02-28 16:44 - 2006-11-29 14:06 - 004398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2018-02-28 16:44 - 2006-11-29 14:06 - 003426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2018-02-28 16:44 - 2006-11-29 14:06 - 000469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2018-02-28 16:44 - 2006-11-29 14:06 - 000440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2018-02-28 16:44 - 2006-09-28 17:05 - 003977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2018-02-28 16:44 - 2006-09-28 17:05 - 002414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2018-02-28 16:44 - 2006-09-28 17:05 - 000237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2018-02-28 16:44 - 2006-09-28 17:04 - 000364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2018-02-28 16:44 - 2006-07-28 10:31 - 000083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2018-02-28 16:44 - 2006-07-28 10:30 - 000363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2018-02-28 16:44 - 2006-07-28 10:30 - 000236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2018-02-28 16:44 - 2006-07-28 10:30 - 000062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2018-02-28 16:44 - 2006-05-31 08:24 - 000230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2018-02-28 16:44 - 2006-05-31 08:22 - 000354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2018-02-28 16:44 - 2006-03-31 13:41 - 003927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2018-02-28 16:44 - 2006-03-31 13:40 - 002388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2018-02-28 16:44 - 2006-03-31 13:40 - 000352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2018-02-28 16:44 - 2006-03-31 13:39 - 000229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2018-02-28 16:44 - 2006-03-31 13:39 - 000083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2018-02-28 16:44 - 2006-03-31 13:39 - 000062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2018-02-28 16:44 - 2006-02-03 09:43 - 003830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2018-02-28 16:44 - 2006-02-03 09:43 - 002332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2018-02-28 16:44 - 2006-02-03 09:42 - 000355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2018-02-28 16:44 - 2006-02-03 09:42 - 000230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2018-02-28 16:44 - 2006-02-03 09:41 - 000016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2018-02-28 16:44 - 2006-02-03 09:41 - 000014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2018-02-28 16:44 - 2005-12-05 19:09 - 003815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2018-02-28 16:44 - 2005-12-05 19:09 - 002323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2018-02-28 16:44 - 2005-07-22 20:59 - 003807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2018-02-28 16:44 - 2005-07-22 20:59 - 002319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2018-02-28 16:44 - 2005-05-26 16:34 - 003767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2018-02-28 16:44 - 2005-05-26 16:34 - 002297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2018-02-28 16:44 - 2005-03-18 18:19 - 003823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2018-02-28 16:44 - 2005-03-18 18:19 - 002337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2018-02-28 16:44 - 2005-02-05 20:45 - 003544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2018-02-28 16:44 - 2005-02-05 20:45 - 002222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2018-02-28 16:09 - 2018-02-28 16:09 - 000000222 _____ C:\Users\admin\Desktop\LEGO Worlds.url
2018-02-28 16:09 - 2018-02-28 16:09 - 000000000 ____D C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-02-28 16:01 - 2018-02-28 16:02 - 000000000 ____D C:\Users\admin\AppData\Local\Steam
2018-02-28 15:58 - 2018-03-28 07:05 - 000000000 ____D C:\Program Files (x86)\Steam
2018-02-28 15:58 - 2018-02-28 15:58 - 000001036 _____ C:\Users\Public\Desktop\Steam.lnk
2018-02-28 15:58 - 2018-02-28 15:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2018-02-28 15:57 - 2018-02-28 15:57 - 001446792 _____ C:\Users\admin\Downloads\SteamSetup.exe
2018-02-27 17:43 - 2018-02-27 17:43 - 001004031 _____ C:\Users\admin\Documents\domaci-kino-philips-htb3580g-1498203638-soubor-77379.pdf
2018-02-27 17:40 - 2018-02-27 17:40 - 000934770 _____ C:\Users\admin\Documents\domaci-kino-philips-htb3580g-1449472501-soubor-37132.pdf
2018-02-27 11:20 - 2018-02-27 11:20 - 016905853 _____ C:\Users\admin\Documents\A5_Octavia_UsersManual.pdf
2018-02-26 19:57 - 2018-02-26 19:57 - 000134507 _____ C:\Users\admin\Desktop\bláto.tif

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-03-28 07:06 - 2018-02-05 23:05 - 000000000 ____D C:\Users\admin\AppData\LocalLow\Mozilla
2018-03-27 22:43 - 2018-01-25 14:48 - 003239856 _____ C:\Windows\system32\PerfStringBackup.INI
2018-03-27 22:43 - 2017-09-30 16:31 - 001504496 _____ C:\Windows\system32\perfh005.dat
2018-03-27 22:43 - 2017-09-30 16:31 - 000385414 _____ C:\Windows\system32\perfc005.dat
2018-03-27 22:36 - 2018-01-25 21:39 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-03-27 22:36 - 2018-01-25 14:56 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-03-27 22:36 - 2017-09-29 10:45 - 000524288 _____ C:\Windows\system32\config\BBI
2018-03-27 22:12 - 2018-01-25 21:39 - 000000000 ____D C:\Windows\system32\SleepStudy
2018-03-27 18:45 - 2017-09-29 15:44 - 000000000 ____D C:\Windows\INF
2018-03-27 18:24 - 2018-02-03 18:48 - 000000000 ____D C:\Program Files (x86)\AVG
2018-03-27 18:24 - 2018-02-03 18:46 - 000000000 ____D C:\Users\admin\AppData\Local\Avg
2018-03-27 18:24 - 2018-02-03 18:46 - 000000000 ____D C:\ProgramData\Avg
2018-03-27 18:17 - 2017-09-29 15:46 - 000000000 ___HD C:\Windows\ELAMBKUP
2018-03-27 12:09 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\AppReadiness
2018-03-27 12:08 - 2017-09-29 15:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-03-27 12:04 - 2018-02-05 23:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-03-26 23:06 - 2018-02-05 23:21 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-03-22 23:13 - 2018-02-03 18:52 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-03-22 23:13 - 2018-02-03 18:52 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-03-19 00:17 - 2018-01-25 14:52 - 000000000 ____D C:\Users\admin
2018-03-17 20:14 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\rescache
2018-03-13 20:03 - 2017-09-29 15:37 - 000000000 ____D C:\Windows\CbsTemp
2018-03-13 19:58 - 2018-01-25 21:39 - 000402136 _____ C:\Windows\system32\FNTCACHE.DAT
2018-03-13 19:58 - 2018-01-25 14:52 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-03-13 19:58 - 2018-01-25 14:52 - 000000000 ___RD C:\Users\admin\3D Objects
2018-03-13 19:57 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\TextInput
2018-03-13 19:57 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\system32\appraiser
2018-03-13 19:57 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\ShellExperiences
2018-03-13 19:30 - 2018-01-25 15:54 - 000000000 ____D C:\Windows\system32\MRT
2018-03-13 19:29 - 2018-01-25 15:54 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-03-13 19:29 - 2018-01-25 15:53 - 130364688 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-03-13 19:27 - 2017-09-29 15:41 - 000140800 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2018-03-13 19:27 - 2017-09-29 15:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2018-03-13 19:13 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-03-13 19:13 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\system32\Macromed
2018-03-10 16:05 - 2018-01-25 14:54 - 000003378 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3273614194-3348390461-1479779135-1001
2018-03-10 16:05 - 2018-01-25 14:54 - 000002391 _____ C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-03-10 16:05 - 2018-01-25 14:54 - 000000000 ___RD C:\Users\admin\OneDrive
2018-03-06 23:15 - 2018-02-03 23:44 - 000000000 ____D C:\Users\admin\Documents\Soubory aplikace Outlook
2018-03-06 17:50 - 2018-02-05 23:33 - 000000000 ____D C:\Users\admin\AppData\Local\Adobe
2018-03-05 18:41 - 2017-09-29 15:46 - 000000000 ____D C:\Windows\DeliveryOptimization
2018-03-04 20:43 - 2018-02-03 17:22 - 000000000 ____D C:\Users\admin\AppData\Local\ElevatedDiagnostics
2018-03-02 23:09 - 2018-01-25 16:01 - 000834552 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-03-02 23:09 - 2018-01-25 16:01 - 000179704 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-02-28 22:13 - 2018-02-05 23:36 - 000004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-02-28 19:50 - 2018-02-11 23:23 - 000000000 ____D C:\Users\admin\Documents\práce
2018-02-28 16:44 - 2018-01-25 14:56 - 000000000 ____D C:\ProgramData\Package Cache
2018-02-28 16:44 - 2017-09-29 15:46 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-02-28 16:01 - 2018-01-25 14:56 - 000000000 ____D C:\Users\admin\AppData\Local\AMD
2018-02-26 19:14 - 2018-02-20 19:23 - 005311983 _____ C:\Users\admin\Desktop\sauronovo oko.tif

==================== Files in the root of some directories =======


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-03-21 20:03

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:222.97 GB) (Free:145.1 GB) NTFS
Drive e: (Uloziste) (Fixed) (Total:931.39 GB) (Free:730.34 GB) NTFS
\\?\Volume{6c9826b7-022c-4972-9eb0-00e86f7cf01f}\ (Obnovení) (Fixed) (Total:0.49 GB) (Free:0.14 GB) NTFS
\\?\Volume{fcdf3ad6-7a99-4901-b60f-6e4f7162c387}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

Available physical RAM: 5204.27 MB
Total physical RAM: 8137.68 MB
Percentage of memory in use: 36%

==================== MBR and Partition Table ==================

Disk: 0 (Protective MBR) (Size: 223.6 GB) (Disk ID: 00000000)
Disk: 1 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Internet Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
Verze podpisu: AV: 1.261.707.0, AS: 1.261.707.0, NIS: 118.2.0.0
Verze podpisu: AV: 1.261.707.0, AS: 1.261.707.0, NIS: 118.2.0.0
Verze podpisu: AV: 1.261.707.0, AS: 1.261.707.0, NIS: 118.2.0.0
Verze podpisu: AV: 1.261.707.0, AS: 1.261.707.0, NIS: 118.2.0.0
AS: ESET Internet Security (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
Verze podpisu: AV: 1.261.707.0, AS: 1.261.707.0, NIS: 118.2.0.0
Verze podpisu: AV: 1.261.707.0, AS: 1.261.707.0, NIS: 118.2.0.0
Verze podpisu: AV: 1.261.707.0, AS: 1.261.707.0, NIS: 118.2.0.0
Verze podpisu: AV: 1.261.707.0, AS: 1.261.707.0, NIS: 118.2.0.0
FW: ESET Firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\admin\Desktop" je 443 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]


==================== End Of Log ==============================
Přílohy
Addition log.zip
(10.85 KiB) Staženo 52 x

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Policejní virus

#6 Příspěvek od Conder »

:arrow: Velikost slozky "C:\Users\admin\Desktop" je 443 MB.
  • Presun vsetky subory a zlozky z plochy do dokumentov a na ploche nechaj iba odkazy/zastupcov. Prilis velka velkost plochy moze sposobit spomalenie systemu.
:arrow: V PC je nainstalovana zastarala verzia Javy (Java 8 Update 111), odporucam odinstalovat. Ak Javu potrebujes, nainstaluj aktualnu verziu (momentalne Java 8 Update 161) z https://java.com/en/download/

:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    CMD: type "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\user.js"
    HKU\S-1-5-21-3273614194-3348390461-1479779135-1001\...\MountPoints2: {6d27f96f-0e78-11e8-a18d-2cfda17081b1} - "E:\HiSuiteDownLoader.exe" 
    SearchScopes: HKU\S-1-5-21-3273614194-3348390461-1479779135-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    FF user.js: detected! => C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\user.js [2018-03-17]
    ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
    Task: {A2A2CCA8-E89A-4691-B48E-40AC62C0ABE9} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
    
    Hosts:
    EmptyTemp:
    End
  • Uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Ondor
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 27 bře 2018 18:50

Re: Policejní virus

#7 Příspěvek od Ondor »

Dostal jsem se do fáze kdy jsem spustil FRST a dal Fix, ale vyskočila mi hláška: No fixlist.txt found. The fixlist.txt should be in the same folder/directory the tool is located.

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Policejní virus

#8 Příspěvek od Conder »

:arrow: FRST aj fixlist.txt musia byt v tej istej zlozke. Skontroluj, ci mas obidve na ploche.
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Ondor
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 27 bře 2018 18:50

Re: Policejní virus

#9 Příspěvek od Ondor »

Fix result of Farbar Recovery Scan Tool (x64) Version: 14.03.2018
Ran by admin (28-03-2018 19:10:43) Run:1
Running from C:\Users\admin\Desktop
Loaded Profiles: admin (Available Profiles: admin)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

CMD: type "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\user.js"
HKU\S-1-5-21-3273614194-3348390461-1479779135-1001\...\MountPoints2: {6d27f96f-0e78-11e8-a18d-2cfda17081b1} - "E:\HiSuiteDownLoader.exe"
SearchScopes: HKU\S-1-5-21-3273614194-3348390461-1479779135-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF user.js: detected! => C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\user.js [2018-03-17]
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {A2A2CCA8-E89A-4691-B48E-40AC62C0ABE9} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.

========= type "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\user.js" =========

user_pref("extensions.blocklist.enabled",false);
user_pref("extensions.blocklist.interval",31536000);
user_pref("extensions.blocklist.url","");
user_pref("extensions.blocklist.itemURL","");
user_pref("extensions.blocklist.detailsURL","");
user_pref("security.mixed_content.block_active_content",false);
user_pref("security.mixed_content.block_display_content",false);
user_pref("app.update.staging.enabled",true);
user_pref("browser.safebrowsing.appRepURL","");
user_pref("app.update.silent",true);
user_pref("browser.safebrowsing.updateURL","");
user_pref("browser.safebrowsing.reportURL","");
user_pref("browser.safebrowsing.reportMalwareURL","");
user_pref("browser.safebrowsing.reportMalwareErrorURL","");
user_pref("browser.safebrowsing.malware.reportURL","");
user_pref("services.sync.prefs.sync.browser.safebrowsing.enabled",false);
user_pref("services.sync.prefs.sync.browser.safebrowsing.malware.enabled",false);

========= End of CMD: =========

"HKU\S-1-5-21-3273614194-3348390461-1479779135-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6d27f96f-0e78-11e8-a18d-2cfda17081b1}" => removed successfully
HKLM\Software\Classes\CLSID\{6d27f96f-0e78-11e8-a18d-2cfda17081b1} => not found
"HKU\S-1-5-21-3273614194-3348390461-1479779135-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\ysu13zbi.default\user.js => moved successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg" => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui" => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{A2A2CCA8-E89A-4691-B48E-40AC62C0ABE9}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A2A2CCA8-E89A-4691-B48E-40AC62C0ABE9}" => removed successfully
C:\Windows\System32\Tasks\AVG EUpdate Task => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVG EUpdate Task" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 122708478 B
Java, Flash, Steam htmlcache => 12005627 B
Windows/system/drivers => 8240442 B
Edge => 3670660 B
Chrome => 235388660 B
Firefox => 401610532 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 42356 B
NetworkService => 70516 B
admin => 66540750 B

RecycleBin => 1086 B
EmptyTemp: => 819.7 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 19:11:43 ====

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Policejní virus

#10 Příspěvek od Conder »

:arrow: Vyzera to OK. Nastala nejaka zmena, pripadne su este nejake problemy s PC?
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Ondor
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 27 bře 2018 18:50

Re: Policejní virus

#11 Příspěvek od Ondor »

Zatím je všechno OK, přestaly se objevovat hlášky o zablokování straánky s nevhodným obsahem od ESETu. Mám to považovat za vyléčené?

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Policejní virus

#12 Příspěvek od Conder »

:arrow: Ano, vyzera to ciste. Preventivne mozes este preskenovat PC cez ESET.

:arrow: Tak este upraceme po pouzitych nastrojoch:
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Ondor
Návštěvník
Návštěvník
Příspěvky: 7
Registrován: 27 bře 2018 18:50

Re: Policejní virus

#13 Příspěvek od Ondor »

Všechno perfektní, díky za pomoc a za čas.
Jak můžu pdpořit fórum?

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Policejní virus

#14 Příspěvek od Conder »

Nie je zaco, rad som pomohol :)

Forum je mozne podporit tu: https://platba.viry.cz/payment/

Dakujeme :)
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Odpovědět