Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

FRST LOG kontrola

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
kroenen2
Návštěvník
Návštěvník
Příspěvky: 270
Registrován: 30 čer 2008 11:52

FRST LOG kontrola

#1 Příspěvek od kroenen2 »

Prosím skontrolovať, ntb pomalší, po prečistení ventilátora a prepastovaní cpu sa to výrazne zlepšilo, ale aj tak tu asi niečo bude.
Ďakujem.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.01.2019
Ran by Pedro (administrator) on DESKTOP-NVJD1LG (21-01-2019 18:49:01)
Running from C:\Users\Pedro\Desktop
Loaded Profiles: Pedro (Available Profiles: defaultuser0 & Pedro)
Platform: Windows 10 Home Version 1809 17763.253 (X64) Language: Slovenčina (Slovensko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1812.3-0\MsMpEng.exe
(Lenovo) C:\Program Files\Lenovo\YMC\ymc.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1812.3-0\NisSrv.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeApp.exe
() C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Nero AG) C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBridge\SkypeBridge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11810.1001.12.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe
() C:\Program Files\KMSpico\AutoPico.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Users\Pedro\AppData\Local\Microsoft\OneDrive\18.222.1104.0007\FileCoAuth.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-11] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-11] (Realtek Semiconductor)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [9309936 2015-09-10] (Realtek semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-11] (Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3961528 2016-11-04] (Synaptics Incorporated)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-622939137-141225199-2558093129-1001\...\Run: [GoogleDriveSync] => C:\Program Files\Google\Drive\googledrivesync.exe [46504696 2018-12-07] ()
HKU\S-1-5-21-622939137-141225199-2558093129-1001\...\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexStoreSvr.exe [1688872 2007-12-13] (Nero AG)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\71.0.3578.98\Installer\chrmstp.exe [2018-12-18] (Google Inc.)
GroupPolicy: Restriction ? <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ac0d6cbe-f5ed-45ea-b2e8-a97d491a4b4e}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO-x32: Foxit PhantomPDF Create PDF ToolBar Helper -> {A5DD10F7-5ABB-4EEF-B4C8-6748D44DAF2A} -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2018-09-26] ()
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2018-07-18] (Microsoft Corporation)
Toolbar: HKLM-x32 - Foxit PhantomPDF Create PDF ToolBar - {BFD9D8A8-57FF-488A-B919-065EC77CF82F} - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\IEAddin\IEAddin.dll [2018-09-26] ()
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2018-03-14] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: knaq84ry.default
FF ProfilePath: C:\Users\Pedro\AppData\Roaming\Mozilla\Firefox\Profiles\knaq84ry.default [2019-01-16]
FF Homepage: Mozilla\Firefox\Profiles\knaq84ry.default -> hxxps://www.google.com/
FF NewTab: Mozilla\Firefox\Profiles\knaq84ry.default -> hxxp://securedsearch.lavasoft.com/?pr=vmn&id=webcompa&ent=hp_WCYID10440__181226
FF HKLM\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF Extension: (Foxit PDF Creator) - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi [2018-08-15] [Legacy]
FF HKLM\...\Firefox\Extensions: [FireFoxNew-WebExtensions@foxitsoftware.com] - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi
FF Extension: (Foxit PDF Creator) - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi [2018-08-15]
FF HKLM-x32\...\Firefox\Extensions: [FFExtnHTML2PDF@foxitsoftware.com] - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FFExtnHTML2PDF.xpi
FF HKLM-x32\...\Firefox\Extensions: [FireFoxNew-WebExtensions@foxitsoftware.com] - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\FirefoxAddin\FireFoxNew-WebExtensions@foxitsoftware.com.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-08-10] (VideoLAN)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-09-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-09-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-09-19] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2018-09-19] (Foxit Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-22] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc.)
FF Plugin-x32: Web Components -> C:\Program Files (x86)\Web Components\npWebVideoPlugin.dll [2016-09-23] ()

Chrome:
=======
CHR HomePage: Default -> hxxp://google.sk/
CHR DefaultSearchKeyword: Default -> google.sk__
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default [2019-01-21]
CHR Extension: (Prezentácie) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-12-11]
CHR Extension: (BIODIGITAL HUMAN) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\agoenciogemlojlhccbcpcfflicgnaak [2018-12-11]
CHR Extension: (Dokumenty) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-12-11]
CHR Extension: (Disk Google) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-12-11]
CHR Extension: (YouTube) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-12-11]
CHR Extension: (uBlock Origin) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2018-12-11]
CHR Extension: (Tabuľky) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-12-11]
CHR Extension: (I don't care about cookies) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\fihnjjcciajhdojfnbdddfaoknhalnja [2018-12-21]
CHR Extension: (Web Components) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\filcobblndaenakhejinpjdblekilpgn [2018-12-11]
CHR Extension: (Vzdialená plocha Chrome) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2018-12-11]
CHR Extension: (Dokumenty Google v režime offline) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-12-11]
CHR Extension: (AdBlock) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-01-16]
CHR Extension: (The Great Suspender) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\klbibkeccnjlkjkiokjodocebajanakg [2018-12-11]
CHR Extension: (Google Play) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2018-12-11]
CHR Extension: (Save as PDF) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpdjmbiefanbdgnkcikhllpmjnnllbbc [2018-12-11]
CHR Extension: (Numerics Calculator & Converter) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\liglcienpnkhdajdfmnpbgmpjglonipe [2018-12-11]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-12-11]
CHR Extension: (Psykopaint) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgjchkcfmigkkhedgjedmffdepgmpfil [2018-12-11]
CHR Extension: (Gmail) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-12-11]
CHR Extension: (Chrome Media Router) - C:\Users\Pedro\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-11]
CHR HKLM\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2018-08-15]
CHR HKU\S-1-5-21-622939137-141225199-2558093129-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cifnddnffldieaamihfkhkdgnbhfmaci] - C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\Creator\ChromeAddin\ChromeAddin.crx [2018-08-15]
CHR HKLM-x32\...\Chrome\Extension: [nladljmabboanhihfkjacnnkgjhnokhj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [541896 2018-05-10] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373688 2017-06-12] (Intel Corporation)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [447784 2007-12-13] (Nero AG)
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [977088 2014-03-02] () [File not signed]
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [384512 2018-09-15] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [266424 2016-11-04] (Synaptics Incorporated)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\NisSrv.exe [3880120 2018-12-12] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MsMpEng.exe [114208 2018-12-12] (Microsoft Corporation)
R2 ymc; C:\Program Files\Lenovo\YMC\ymc.exe [49032 2016-12-23] (Lenovo)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [136720 2018-05-10] (Intel Corporation)
R3 NETwNb64; C:\WINDOWS\System32\drivers\Netwbw02.sys [3485696 2018-09-15] (Intel Corporation)
R2 NPF; C:\Program Files\iVMS-4200 Station\iVMS-4200\iVMS-4200 Client\npf64.sys [36600 2015-12-16] (Riverbed Technology, Inc.)
S3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [410880 2015-07-03] (Realsil Semiconductor Corporation)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3059440 2015-09-10] (Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [60088 2016-11-04] (Synaptics Incorporated)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2017-05-18] (Samsung Electronics Co., Ltd.)
S3 tapprotonvpn; C:\WINDOWS\System32\drivers\tapprotonvpn.sys [44976 2018-06-01] (The OpenVPN Project)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46680 2018-12-12] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [330936 2018-12-12] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [62136 2018-12-12] (Microsoft Corporation)
S3 WinDivert1.1; C:\Program Files\KMSpico\WinDivert.sys [35376 2018-12-11] (Basil Projects)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-01-21 18:49 - 2019-01-21 18:49 - 000017236 _____ C:\Users\Pedro\Desktop\FRST.txt
2019-01-21 18:38 - 2019-01-21 18:49 - 000000000 ____D C:\FRST
2019-01-21 16:02 - 2019-01-21 16:14 - 000000290 __RSH C:\ProgramData\ntuser.pol
2019-01-17 21:58 - 2019-01-17 21:58 - 000000000 ____D C:\Users\Pedro\Documents\Nero Home
2019-01-17 21:57 - 2019-01-17 21:57 - 000000000 ____D C:\Users\Pedro\AppData\Local\Nero
2019-01-17 21:49 - 2019-01-17 20:53 - 000002678 _____ C:\Users\Pedro\Desktop\Nero WaveEditor.lnk
2019-01-17 21:47 - 2019-01-17 21:47 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\Ahead
2019-01-17 20:53 - 2019-01-17 21:54 - 000002810 _____ C:\Users\Public\Desktop\Nero StartSmart.lnk
2019-01-17 20:53 - 2019-01-17 20:53 - 000000000 ____D C:\Users\Pedro\AppData\Local\Ahead
2019-01-17 20:53 - 2019-01-17 20:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 8
2019-01-17 20:52 - 2019-01-17 21:57 - 000001024 _____ C:\Users\Pedro\.rnd
2019-01-17 20:52 - 2019-01-17 21:54 - 000007867 _____ C:\WINDOWS\Irremote.ini
2019-01-17 20:51 - 2019-01-17 20:51 - 000000000 ____D C:\Program Files (x86)\Nero
2019-01-17 20:33 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2019-01-17 20:33 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
2019-01-17 20:21 - 2019-01-17 20:21 - 000001651 _____ C:\Users\Pedro\Desktop\UninstallTool.exe - odkaz.lnk
2019-01-17 20:21 - 2019-01-17 20:21 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\CrystalIdea Software
2019-01-17 20:20 - 2019-01-17 20:20 - 000000000 ____D C:\Program Files\UNINSTALL TOOL PORTABLE
2019-01-16 18:27 - 2019-01-21 18:38 - 002428416 _____ (Farbar) C:\Users\Pedro\Desktop\FRST64.exe
2019-01-16 17:37 - 2019-01-21 18:01 - 000001174 _____ C:\Users\Pedro\Desktop\Start Tor Browser.lnk
2019-01-16 17:37 - 2019-01-16 17:37 - 000001204 _____ C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2019-01-16 17:37 - 2019-01-16 17:37 - 000000000 ____D C:\Program Files\Tor Browser
2019-01-16 17:34 - 2019-01-16 17:35 - 056113480 _____ C:\Users\Pedro\Downloads\torbrowser-install-win64-8.0.4_en-US.exe
2019-01-14 17:10 - 2019-01-14 17:10 - 000000631 _____ C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\USEFUL.lnk
2019-01-12 19:40 - 2019-01-12 19:40 - 000000000 ____D C:\Users\Pedro\AppData\Local\IsolatedStorage
2019-01-12 19:38 - 2019-01-12 19:40 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\ProtonVPN AG
2019-01-11 19:26 - 2019-01-20 11:26 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2019-01-11 19:26 - 2019-01-11 19:26 - 000002888 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2019-01-11 19:26 - 2019-01-11 19:26 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2019-01-11 19:26 - 2019-01-11 19:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2019-01-11 19:26 - 2019-01-11 19:26 - 000000000 ____D C:\Program Files\CCleaner
2019-01-11 18:33 - 2018-09-14 18:05 - 008628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0019.dll
2019-01-10 19:28 - 2019-01-10 19:28 - 000000000 ____D C:\Users\Default\AppData\Local\Google
2019-01-10 19:28 - 2019-01-10 19:28 - 000000000 ____D C:\Users\Default User\AppData\Local\Google
2019-01-09 00:23 - 2019-01-17 20:51 - 000000000 ____D C:\ProgramData\Nero
2019-01-08 20:50 - 2019-01-17 21:29 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\Nero
2019-01-08 20:48 - 2019-01-08 20:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
2019-01-08 20:16 - 2019-01-08 20:16 - 000000000 ____D C:\WINDOWS\PCHEALTH
2019-01-08 20:11 - 2019-01-08 20:11 - 026806784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 023440384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 020811776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 019024384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 012858368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 012151808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 007857152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 006057984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 005440016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 003952952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 003550592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 002986352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 002469648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 002323696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 001309696 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 001201136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 001022464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 000912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 000870400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 000833536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 000663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 000662528 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Pipeline.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 000352768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-01-08 20:11 - 2019-01-08 20:11 - 000098816 ____R (Microsoft Corporation) C:\WINDOWS\system32\MixedRealityCapture.Broker.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 009677352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-01-08 20:10 - 2019-01-08 20:10 - 007645600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 006544800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 004588544 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-01-08 20:10 - 2019-01-08 20:10 - 003380224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 003338328 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 003270144 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 002929152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 002777432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 002626360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2019-01-08 20:10 - 2019-01-08 20:10 - 002594872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 002437552 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 002275896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 002186752 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 002021584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 001641616 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 001616384 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 001602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 001388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 001255736 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-01-08 20:10 - 2019-01-08 20:10 - 001212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 001058848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-01-08 20:10 - 2019-01-08 20:10 - 001050936 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-01-08 20:10 - 2019-01-08 20:10 - 000998912 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000463672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.Printing.Workflow.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000387384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.Printing.Workflow.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000178696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-01-08 20:10 - 2019-01-08 20:10 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000140808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2019-01-08 20:10 - 2019-01-08 20:10 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintWorkflowService.dll
2019-01-08 20:10 - 2019-01-08 20:10 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2019-01-08 20:10 - 2019-01-08 20:10 - 000047112 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2019-01-08 20:10 - 2019-01-08 20:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-01-08 20:10 - 2019-01-08 20:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-01-08 20:10 - 2019-01-08 20:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-01-08 20:10 - 2019-01-08 20:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-01-08 20:10 - 2019-01-08 20:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-01-08 20:10 - 2019-01-08 20:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-01-08 20:10 - 2019-01-08 20:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-01-08 20:10 - 2019-01-08 20:10 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-01-08 10:35 - 2019-01-08 11:05 - 2139777706 _____ C:\Users\Pedro\Downloads\Priserky z vesmiru 2018.mkv
2019-01-08 08:58 - 2019-01-08 08:59 - 000000000 ____D C:\AdwCleaner
2019-01-04 22:26 - 2019-01-04 23:17 - 4147648774 _____ C:\Users\Pedro\Downloads\Úžasňákovi 720p 5.1CZ EN 2004(STBR).mkv
2019-01-03 15:31 - 2019-01-03 15:31 - 007320272 _____ (Malwarebytes) C:\Users\Pedro\Desktop\adwcleaner_7.2.6.0.exe
2019-01-03 14:56 - 2019-01-03 14:56 - 000001226 _____ C:\Users\Pedro\Desktop\SUPLATA Cennik od 10_4_2017.xlsx - odkaz.lnk
2019-01-03 08:27 - 2019-01-03 08:27 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2019-01-01 23:30 - 2019-01-01 23:30 - 000003790 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP Photosmart 5510 series
2019-01-01 23:29 - 2019-01-08 23:42 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\HpUpdate
2019-01-01 23:29 - 2019-01-01 23:29 - 000000057 _____ C:\ProgramData\Ament.ini
2019-01-01 23:29 - 2019-01-01 23:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2019-01-01 23:29 - 2019-01-01 23:29 - 000000000 ____D C:\ProgramData\HP
2019-01-01 23:29 - 2019-01-01 23:29 - 000000000 ____D C:\Program Files\HP
2019-01-01 23:29 - 2019-01-01 23:29 - 000000000 ____D C:\Program Files (x86)\HP
2019-01-01 23:29 - 2012-10-17 04:31 - 000741480 ____N (Hewlett-Packard Co.) C:\WINDOWS\system32\HPDiscoPMa111.dll
2019-01-01 23:13 - 2019-01-01 23:13 - 000000000 ____D C:\Users\Pedro\AppData\Local\HP
2019-01-01 22:46 - 2019-01-01 22:46 - 000000662 _____ C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MUSIC.lnk
2018-12-31 20:29 - 2018-12-31 20:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit PhantomPDF
2018-12-30 17:53 - 2018-12-30 17:53 - 000122914 _____ C:\Users\Pedro\Downloads\ZMP_4053097_P21_5W_P_Cool_White.pdf
2018-12-30 17:51 - 2018-12-30 17:51 - 000123237 _____ C:\Users\Pedro\Downloads\ZMP_4053098_P21_5W_P_Red.pdf
2018-12-30 17:39 - 2018-12-30 17:39 - 000123058 _____ C:\Users\Pedro\Downloads\ZMP_4053099_P21_5W_P_Amber.pdf
2018-12-30 12:03 - 2018-12-30 12:03 - 000001428 _____ C:\Users\Pedro\Desktop\Plasty_odpady_text_logo.docx - odkaz.lnk
2018-12-29 23:29 - 2018-12-29 23:29 - 000007605 _____ C:\Users\Pedro\AppData\Local\Resmon.ResmonCfg
2018-12-29 19:12 - 2018-12-29 19:12 - 000000000 ____D C:\Program Files\Lenovo
2018-12-28 08:49 - 2018-12-28 08:49 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-12-28 08:46 - 2018-12-28 08:46 - 000000020 ___SH C:\Users\Pedro\ntuser.ini
2018-12-28 08:46 - 2018-12-28 08:46 - 000000000 _SHDL C:\Documents and Settings
2018-12-28 08:45 - 2019-01-21 15:35 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-12-28 08:45 - 2018-12-28 08:46 - 000003384 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-12-28 08:45 - 2018-12-28 08:46 - 000002852 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-622939137-141225199-2558093129-1001
2018-12-28 08:45 - 2018-12-28 08:46 - 000002778 _____ C:\WINDOWS\System32\Tasks\AutoPico Daily Restart
2018-12-28 08:45 - 2018-12-28 08:45 - 000011433 _____ C:\WINDOWS\diagwrn.xml
2018-12-28 08:45 - 2018-12-28 08:45 - 000011433 _____ C:\WINDOWS\diagerr.xml
2018-12-28 08:45 - 2018-12-28 08:45 - 000003160 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-12-28 08:45 - 2018-12-28 08:45 - 000002274 _____ C:\WINDOWS\System32\Tasks\DolbySelectorTask
2018-12-28 08:45 - 2018-12-28 08:45 - 000002242 _____ C:\WINDOWS\System32\Tasks\Synaptics TouchPad Enhancements
2018-12-28 08:43 - 2019-01-21 16:00 - 000795988 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-12-28 08:34 - 2018-12-28 08:34 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-12-28 08:32 - 2019-01-21 17:09 - 000000000 ____D C:\Users\Pedro
2018-12-28 08:32 - 2018-12-28 08:40 - 000000000 ____D C:\Users\defaultuser0
2018-12-28 08:32 - 2018-09-15 08:29 - 000001105 _____ C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-12-28 08:32 - 2018-09-15 08:29 - 000001105 _____ C:\Users\defaultuser0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-12-28 08:31 - 2018-12-28 08:31 - 000000000 ____D C:\ProgramData\USOShared
2018-12-28 08:31 - 2018-12-28 08:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2018-12-28 08:31 - 2018-12-28 08:31 - 000000000 ____D C:\Program Files\Dolby Digital Plus
2018-12-28 08:30 - 2018-09-15 08:28 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-12-28 08:29 - 2017-06-12 01:56 - 000103888 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2018-12-28 08:29 - 2017-06-12 01:56 - 000099792 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2018-12-28 08:27 - 2019-01-21 17:08 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-12-28 08:27 - 2018-12-28 08:36 - 005036536 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-12-28 04:46 - 2018-12-28 08:26 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-12-28 04:44 - 2018-12-28 04:46 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-12-28 04:40 - 2018-12-28 04:40 - 024617472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 019284992 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 011724288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 009941504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 007724776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 005113008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 004918784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 004488192 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2018-12-28 04:40 - 2018-12-28 04:40 - 003566080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 003442176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2018-12-28 04:40 - 2018-12-28 04:40 - 002429752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-12-28 04:40 - 2018-12-28 04:40 - 002278240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 002160160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2018-12-28 04:40 - 2018-12-28 04:40 - 001294864 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 001289400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 001282432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 001259000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-12-28 04:40 - 2018-12-28 04:40 - 001166336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2018-12-28 04:40 - 2018-12-28 04:40 - 001073448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 001057976 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 001024920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000854784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000829440 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000763032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000690688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000654848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000454144 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\regedit.exe
2018-12-28 04:40 - 2018-12-28 04:40 - 000301096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000241680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpeffects.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpdxm.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpshell.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2018-12-28 04:40 - 2018-12-28 04:40 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfts.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 022112072 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 015224832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 006925824 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 006306152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 005764608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 005585056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 005565440 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 004886016 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 004765184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 004306432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 004300800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 003744256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 003730352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 003662336 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 003577856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 003504640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 003427328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 003108864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002927104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 002893312 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002883584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002879488 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002832896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002765312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002702536 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002689536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002346496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002086400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002072384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001994768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001969464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 001899160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001884672 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001863168 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001762816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001749504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001720936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001711104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001699840 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001696216 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-12-28 04:39 - 2018-12-28 04:39 - 001688576 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001675712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001674688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001672056 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001671680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001664904 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001590288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001506304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001483264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001476096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001467344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001466872 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 001456736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001395248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001391096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 001360696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 001341376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-12-28 04:39 - 2018-12-28 04:39 - 001294848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001279024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 001267712 _____ (Microsoft Corporation) C:\WINDOWS\system32\APMon.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001254912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001249792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001221528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2018-12-28 04:39 - 2018-12-28 04:39 - 001180760 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001177632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 001162280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001110528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001097312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001064448 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\pidgenx.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001026992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 001019392 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000964976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000953856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000915968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000901632 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000889344 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000883200 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 000840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000803328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000782968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationFrame.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000609792 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000604248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.applicationmodel.datatransfer.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2018-12-28 04:39 - 2018-12-28 04:39 - 000578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000566584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000535048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000514112 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Activities.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\defragsvc.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000454160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 000451072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000449024 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000430904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Classpnp.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000429056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000400384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000398848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000383288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000373768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\coml2.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000358400 _____ (Microsoft Corporation) C:\WINDOWS\regedit.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 000349184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2018-12-28 04:39 - 2018-12-28 04:39 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wisp.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 000256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\prnntfy.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000252536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wisp.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000222720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prnntfy.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrrun.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\WPTaskScheduler.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrrun.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\CastingShellExt.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CastingShellExt.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000114344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\dab.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000094224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fileinfo.sys
2018-12-28 04:39 - 2018-12-28 04:39 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000091640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000071168 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdBth.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdBth.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfts.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\msisip.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msisip.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 017520640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 007685016 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 006132736 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 005312512 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 005130752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 004245280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 003983360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 003556352 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 003379000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 003092480 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002988544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002721792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 002654208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002630656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002618880 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002488320 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002185728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002149352 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 002085168 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001975296 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001903616 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001842600 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001830912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001824768 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001797128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001715712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001520208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001496064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001387496 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001315840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001287776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001219584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 001199104 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 001051960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 001048576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000955392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000918304 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000897848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000890368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000863752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000854016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000850960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000836096 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000818832 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.applicationmodel.datatransfer.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000801792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000756640 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000752128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000744960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000663552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000660496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000653312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000650040 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\w32time.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000604336 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000582240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000531976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000519992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000514048 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000506408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000494080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000478208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000473616 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000468992 _____ (Microsoft Corporation) C:\WINDOWS\system32\coml2.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\eeprov.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000402576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000398416 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvcext.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000306704 _____ (Microsoft Corporation) C:\WINDOWS\system32\computestorage.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000300024 _____ (Microsoft Corporation) C:\WINDOWS\system32\icsvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000298536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000294072 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000275768 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000266240 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000246784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bthserv.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000193016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\energyprov.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000175096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpioclx.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSrv.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000164344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000164288 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000156984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000151872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000130088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000114648 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000111104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000102392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000095544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storqosflt.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcnfs.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000083472 _____ (Microsoft Corporation) C:\WINDOWS\system32\vid.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vpci.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000067584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iscsiwmi.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000055608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\iorate.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000051712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mmcss.sys
2018-12-28 04:38 - 2018-12-28 04:38 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnsruprov.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2018-12-28 04:38 - 2018-12-28 04:38 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2018-12-28 04:38 - 2018-12-28 04:38 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2018-12-28 04:25 - 2018-12-28 04:25 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2018-12-28 04:25 - 2018-12-28 04:25 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2018-12-28 04:25 - 2018-12-28 04:25 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2018-12-28 04:25 - 2018-12-28 04:25 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2018-12-28 04:25 - 2018-12-28 04:25 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2018-12-28 04:25 - 2018-12-28 04:25 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2018-12-28 04:13 - 2018-12-28 04:13 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-12-28 02:57 - 2019-01-12 10:08 - 000000000 ___DC C:\WINDOWS\Panther
2018-12-28 02:49 - 2018-12-28 02:49 - 000000037 _____ C:\Users\Pedro\Desktop\verejna IP.txt
2018-12-27 18:42 - 2018-12-27 18:42 - 000000000 ____D C:\Users\Pedro\AppData\Local\ElevatedDiagnostics
2018-12-26 11:49 - 2018-12-26 12:33 - 4221927115 _____ C:\Users\Pedro\Downloads\Úžas_ákovi 2 1080p 5.1CZ 2018(STBR).mkv
2018-12-26 01:21 - 2019-01-19 14:16 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\uTorrent
2018-12-26 01:21 - 2018-12-26 01:21 - 000000876 _____ C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2018-12-22 21:23 - 2018-12-28 08:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winamp
2018-12-22 21:23 - 2009-09-04 17:29 - 001892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2018-12-22 21:23 - 2006-09-28 16:05 - 002414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
2018-12-22 21:22 - 2018-12-27 16:57 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\Winamp
2018-12-22 21:22 - 2018-12-22 21:24 - 000000000 ____D C:\Program Files (x86)\Winamp

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-01-21 18:34 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-01-21 18:33 - 2018-12-13 21:02 - 000000000 ____D C:\Users\Pedro\AppData\LocalLow\Mozilla
2019-01-21 17:40 - 2018-12-11 20:27 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2019-01-21 17:40 - 2018-12-11 20:27 - 000000000 __SHD C:\Users\Pedro\IntelGraphicsProfiles
2019-01-21 16:02 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2019-01-21 16:02 - 2016-07-16 12:47 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2019-01-21 16:00 - 2018-09-15 08:31 - 000000000 ____D C:\WINDOWS\INF
2019-01-20 20:19 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-01-19 12:50 - 2018-09-15 08:33 - 000000000 ___HD C:\Program Files\WindowsApps
2019-01-18 08:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\NDF
2019-01-17 22:16 - 2018-09-15 07:09 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2019-01-17 21:29 - 2018-12-11 19:23 - 000000000 ____D C:\Users\Pedro\AppData\Local\VirtualStore
2019-01-17 20:51 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Cursors
2019-01-17 10:49 - 2018-12-11 19:40 - 000000000 ____D C:\Users\Pedro\AppData\Local\Comms
2019-01-16 22:16 - 2018-12-11 20:09 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\vlc
2019-01-16 17:27 - 2018-12-11 19:23 - 000000000 ____D C:\Users\Pedro\AppData\Local\ConnectedDevicesPlatform
2019-01-15 08:28 - 2018-12-12 15:31 - 000000000 ____D C:\Users\Pedro\AppData\Local\PlaceholderTileLogoFolder
2019-01-15 00:16 - 2018-12-11 19:23 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-01-15 00:13 - 2018-12-12 15:21 - 000000000 ____D C:\ProgramData\Packages
2019-01-15 00:13 - 2018-12-11 19:23 - 000000000 ____D C:\Users\Pedro\AppData\Local\Packages
2019-01-11 18:35 - 2018-09-15 08:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-01-11 18:33 - 2018-09-15 17:24 - 000000000 ____D C:\WINDOWS\OCR
2019-01-11 18:25 - 2018-09-15 07:09 - 000000000 ____D C:\WINDOWS\servicing
2019-01-10 19:29 - 2018-12-11 21:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2019-01-09 17:37 - 2018-09-15 17:25 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2019-01-09 17:37 - 2018-09-15 17:25 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2019-01-09 17:37 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-01-08 20:19 - 2018-12-12 00:28 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-01-08 20:17 - 2018-12-12 00:27 - 132790320 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-01-08 20:15 - 2018-12-11 20:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2019-01-02 20:48 - 2018-09-15 08:36 - 000835480 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2019-01-02 20:48 - 2018-09-15 08:36 - 000179600 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2019-01-01 23:43 - 2018-12-16 15:36 - 000000000 ____D C:\ProgramData\Foxit Software
2018-12-31 20:30 - 2018-12-16 15:35 - 000000000 ____D C:\ProgramData\Package Cache
2018-12-29 15:29 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\appcompat
2018-12-28 18:15 - 2018-12-11 19:29 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2018-12-28 08:47 - 2018-12-12 15:10 - 000000000 ___RD C:\Users\Pedro\3D Objects
2018-12-28 08:46 - 2018-09-15 07:09 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-12-28 08:45 - 2018-09-15 08:33 - 000000000 ___RD C:\Program Files\Windows Defender
2018-12-28 08:44 - 2018-12-11 20:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Realtek
2018-12-28 08:41 - 2018-09-15 08:33 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-12-28 08:39 - 2018-12-11 19:59 - 000002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-12-28 08:34 - 2018-12-11 20:34 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-12-28 08:34 - 2018-12-11 20:05 - 000000000 ____D C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome
2018-12-28 08:34 - 2018-12-11 19:20 - 000000000 ____D C:\Users\defaultuser0\AppData\Local\Packages
2018-12-28 08:31 - 2018-09-15 08:33 - 000000000 ____D C:\ProgramData\USOPrivate
2018-12-28 08:30 - 2018-12-11 20:22 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2018-12-28 08:29 - 2018-12-11 20:27 - 000000200 _____ C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2018-12-28 08:28 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\ServiceState
2018-12-28 08:26 - 2018-12-16 17:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SADPTool
2018-12-28 08:26 - 2018-12-13 19:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WebComponents
2018-12-28 08:26 - 2018-12-12 14:02 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IrfanView
2018-12-28 08:26 - 2018-12-12 13:32 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2018-12-28 08:26 - 2018-12-11 20:40 - 000000000 ____D C:\WINDOWS\SHELLNEW
2018-12-28 08:26 - 2018-12-11 20:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-12-28 08:26 - 2018-12-11 20:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2018-12-28 08:26 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-12-28 08:26 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\spool
2018-12-28 08:26 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Registration
2018-12-28 08:26 - 2018-09-15 08:33 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-12-28 08:26 - 2018-09-15 08:31 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-12-28 08:26 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-12-28 05:03 - 2018-09-15 08:36 - 000000000 ____D C:\WINDOWS\Setup
2018-12-28 04:50 - 2018-09-15 08:33 - 000000000 __RHD C:\Users\Public\Libraries
2018-12-28 04:50 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\InfusedApps
2018-12-28 04:46 - 2018-12-16 17:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\company
2018-12-28 04:46 - 2018-12-12 18:57 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iVMS-4200 Station
2018-12-28 04:46 - 2018-12-11 20:30 - 000000000 ____D C:\Program Files\Realtek
2018-12-28 04:46 - 2018-12-11 20:21 - 000000000 ____D C:\Program Files\Intel
2018-12-28 04:46 - 2018-12-11 20:12 - 000000000 ____D C:\Program Files\Synaptics
2018-12-28 04:46 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Resources
2018-12-28 04:46 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\Help
2018-12-28 04:42 - 2018-09-15 08:33 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2018-12-28 04:42 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\TextInput
2018-12-28 04:42 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-12-28 04:42 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-12-28 04:42 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-12-28 04:42 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-12-28 04:42 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\ShellComponents
2018-12-28 04:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2018-12-28 04:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2018-12-28 04:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2018-12-28 04:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2018-12-28 04:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2018-12-28 04:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2018-12-28 04:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\et-EE
2018-12-28 04:25 - 2018-09-15 08:33 - 000000000 ____D C:\WINDOWS\system32\es-MX
2018-12-27 16:03 - 2018-12-12 13:23 - 000000000 ____D C:\Users\Pedro\AppData\Local\Adobe
2018-12-27 16:02 - 2018-12-12 15:47 - 000000132 _____ C:\Users\Pedro\AppData\Roaming\Adobe Formát PNG CS5 – předvolby

==================== Files in the root of some directories =======

2018-12-21 11:33 - 2018-10-25 17:31 - 011427840 _____ () C:\Program Files\BMC-CONFIG-1.exe
2018-12-12 15:47 - 2018-12-27 16:02 - 000000132 _____ () C:\Users\Pedro\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
2018-12-21 11:21 - 2018-12-21 11:21 - 000003584 _____ () C:\Users\Pedro\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2018-12-29 23:29 - 2018-12-29 23:29 - 000007605 _____ () C:\Users\Pedro\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\dllhost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\dllhost.exe => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

==================== End of FRST.txt ============================

kroenen2
Návštěvník
Návštěvník
Příspěvky: 270
Registrován: 30 čer 2008 11:52

Re: FRST LOG kontrola

#2 Příspěvek od kroenen2 »

# -------------------------------
# Malwarebytes AdwCleaner 7.2.6.0
# -------------------------------
# Build: 12-18-2018
# Database: 2019-01-10.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 01-21-2019
# Duration: 00:00:03
# OS: Windows 10 Home
# Cleaned: 0
# Failed: 1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

Not Deleted api.bing.com


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1902 octets] - [08/01/2019 08:58:57]
AdwCleaner[C00].txt - [1956 octets] - [08/01/2019 08:59:41]
AdwCleaner[S01].txt - [1384 octets] - [12/01/2019 10:27:57]
AdwCleaner[C01].txt - [1550 octets] - [12/01/2019 10:28:34]
AdwCleaner[S02].txt - [1506 octets] - [16/01/2019 17:23:51]
AdwCleaner[C02].txt - [1672 octets] - [16/01/2019 17:25:21]
AdwCleaner[S03].txt - [1628 octets] - [16/01/2019 17:31:07]
AdwCleaner[S04].txt - [1689 octets] - [17/01/2019 22:15:21]
AdwCleaner[C04].txt - [1855 octets] - [17/01/2019 22:15:55]
AdwCleaner[S05].txt - [1811 octets] - [21/01/2019 18:58:25]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C05].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST LOG kontrola

#3 Příspěvek od Rudy »

Zdravím!
Přidejte ještě log Addition (v souboru addition.txt na ploše). Díky.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kroenen2
Návštěvník
Návštěvník
Příspěvky: 270
Registrován: 30 čer 2008 11:52

Re: FRST LOG kontrola

#4 Příspěvek od kroenen2 »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.01.2019
Ran by Pedro (21-01-2019 18:49:45)
Running from C:\Users\Pedro\Desktop
Windows 10 Home Version 1809 17763.253 (X64) (2018-12-28 07:46:49)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-622939137-141225199-2558093129-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-622939137-141225199-2558093129-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-622939137-141225199-2558093129-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-622939137-141225199-2558093129-501 - Limited - Disabled)
Pedro (S-1-5-21-622939137-141225199-2558093129-1001 - Administrator - Enabled) => C:\Users\Pedro
WDAGUtilityAccount (S-1-5-21-622939137-141225199-2558093129-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-622939137-141225199-2558093129-1001\...\uTorrent) (Version: 3.5.5.44994 - BitTorrent Inc.)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.)
Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Backup and Sync from Google (HKLM\...\{693CADB0-962B-4AC1-A939-9524B258C997}) (Version: 3.43.2448.9071 - Google, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.51 - Piriform)
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Foxit PhantomPDF (HKLM-x32\...\{DB5A079E-C1DA-11E8-BD2C-000C296BF2A5}) (Version: 9.3.0.10826 - Foxit Software Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 71.0.3578.98 - Spoločnosť Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
HP Photosmart 5510 series Basic Device Software (HKLM\...\{CFF43B48-42A1-4967-9506-7E341BBD075F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart 5510 series Help (HKLM-x32\...\{E02964EA-0E1B-4620-A26E-CBAB0341B1BB}) (Version: 140.0.2.2 - Hewlett Packard)
HP Photosmart 5510 series Product Improvement Study (HKLM\...\{CBB98874-7884-4CC1-A78C-CB53C62BC77B}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
IrfanView 4.51 (64-bit) (HKLM\...\IrfanView64) (Version: 4.51 - Irfan Skiljan)
iVMS-4200(v2.4.1.3) (HKLM-x32\...\{7697245D-2E00-4B83-AD27-C051DE314D1F}) (Version: 2.4.1.3 - hikvision)
KMSpico v9.2.3 (HKLM\...\KMSpico_is1) (Version: 9.2.3 - )
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 6.3.9600.11103 - Realtek Semiconductor Corp.)
Lenovo Yoga Mode Control (HKLM\...\{3F2E25D6-49D3-45D5-A7BD-13F5D6F64171}_is1) (Version: 2.0.0.9 - Lenovo)
Lingea Lexicon 2002 (HKLM-x32\...\Lexicon 4.0) (Version: - )
Microsoft Office 2013 Professional Plus (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-622939137-141225199-2558093129-1001\...\OneDriveSetup.exe) (Version: 18.222.1104.0007 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 64.0 (x64 sk) (HKLM\...\Mozilla Firefox 64.0 (x64 sk)) (Version: 64.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 64.0 - Mozilla)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (HKLM\...\{90150000-001F-0405-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (HKLM\...\{90150000-001F-041B-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Nero 8 (HKLM-x32\...\{5FCCD531-1B38-4A94-924C-127F722F1051}) (Version: 8.2.89 - Nero AG)
PDF Settings CS5 (HKLM-x32\...\{A78FE97A-C0C8-49CE-89D0-EDD524A17392}) (Version: 10.0 - Adobe Systems Incorporated) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.39053 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7530 - Realtek Semiconductor Corp.)
SADPTool (HKLM-x32\...\{7D9B79C2-B1B2-433B-844F-F4299B86F26E}) (Version: 3.0.0.16 - hikvision)
Service Pack 1 for Microsoft Office 2013 (KB2850036) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{D82063A8-7C8C-4C3B-A9BB-95138CA55D26}) (Version: - Microsoft)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.9.5 - Synaptics Incorporated)
Update for Skype for Business 2015 (KB4461557) 64-Bit Edition (HKLM\...\{90150000-00C1-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{06CB9397-D762-4A2F-8D91-DFAD58D2BAED}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB4461557) 64-Bit Edition (HKLM\...\{90150000-012B-041B-1000-0000000FF1CE}_Office15.PROPLUSR_{06CB9397-D762-4A2F-8D91-DFAD58D2BAED}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB4461557) 64-Bit Edition (HKLM\...\{91150000-0011-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{06CB9397-D762-4A2F-8D91-DFAD58D2BAED}) (Version: - Microsoft)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{9CBA860F-7437-4A75-941C-8EF559F2D145}) (Version: 2.52.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden
VCRedistSetup (HKLM-x32\...\{3921A67A-5AB1-4E48-9444-C71814CF3027}) (Version: 1.0.0 - Nero AG) Hidden
VLC media player (HKLM\...\VLC media player) (Version: 3.0.4 - VideoLAN)
Web Components (HKLM-x32\...\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1) (Version: 3.0.6.8 - )
Winamp (HKLM-x32\...\Winamp) (Version: 5.8 - Winamp SA)
WinRAR archivátor (HKLM\...\WinRAR archiver) (Version: - )
WinRAR archivátor (HKLM-x32\...\WinRAR archiver) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-12-07] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-12-07] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync64.dll [2018-12-07] (Google)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero8\Nero CoverDesigner\CoverEdExtension.dll [2007-12-04] (Nero AG)
ContextMenuHandlers1-x32: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2018-09-26] (Foxit Software Inc.)
ContextMenuHandlers1-x32: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-12-07] (Google)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-02-10] ()
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-02-10] ()
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files\Google\Drive\contextmenu64.dll [2018-12-07] (Google)
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-02-10] ()
ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-02-10] ()
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-06-12] (Intel Corporation)
ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\WINDOWS\system32\igfxOSP.dll [2017-06-12] (Intel Corporation)
ContextMenuHandlers6: [Foxit_ConvertToPDF] -> {C5269811-4A29-4818-A4BB-111F9FC63A5F} => C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\Foxit PhantomPDF\plugins\ConvertToPDFShellExtension_x64.dll [2018-09-26] (Foxit Software Inc.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2010-02-10] ()
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2010-02-10] ()

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {02D0E50E-2D29-4769-A8E6-0AAD8EA7B602} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-12] (Microsoft Corporation)
Task: {33A01DC2-E3D9-4857-A46B-9CE1B8585E95} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {36640D29-E85B-4262-B733-8EBD10BFDB75} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\WINDOWS\system32\EOSNotify.exe
Task: {44B8FA4B-B7E9-4B04-9429-5AFE310BE2E6} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2014-03-02] ()
Task: {7D9A14BB-DE3E-4935-AC4F-7C59CFCD9123} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-12-10] (Piriform Software Ltd)
Task: {8554379B-3E2F-48C7-91A3-0815C8FBEAC3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-12-11] (Google Inc.)
Task: {8DC3F284-7FFF-4E7C-9563-A83A09537650} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-12] (Microsoft Corporation)
Task: {91572102-BF9A-4ECC-9828-CBEAD28F8367} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-12] (Microsoft Corporation)
Task: {9C651596-A1CC-468F-9A98-72D135E959DB} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {C972B04A-AEA0-462F-9BAC-17F6A9057946} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-12-10] (Piriform Ltd)
Task: {CD61DD15-45FB-4240-A2BD-271C39991235} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {D17FDC10-6084-4D7D-86DC-B4C29A23671E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {D682E027-D275-4906-B816-806D621E675E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1812.3-0\MpCmdRun.exe [2018-12-12] (Microsoft Corporation)
Task: {E2D3074D-B5C5-45E4-8D4E-0D32E3D0630F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-12-11] (Google Inc.)
Task: {E39F8E32-F4B6-44B2-B8AF-D84A6CFEB7B8} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-09-15] ()
Task: {EB05FDC5-C030-48BC-BA23-0D6AB6D3288E} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2016-11-04] (Synaptics Incorporated)
Task: {F067FB99-1CA1-4579-B2B1-B5786FD61F15} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\Pedro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikácie Chrome\Vzdialená plocha Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp

==================== Loaded Modules (Whitelisted) ==============

2018-09-15 08:28 - 2018-09-15 08:28 - 000834088 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-09-15 08:28 - 2018-09-15 08:28 - 000474624 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-12-28 04:39 - 2018-12-28 04:39 - 002801152 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-12-11 20:33 - 2010-02-10 18:10 - 000166400 _____ () C:\Program Files\WinRAR\rarext.dll
2017-06-12 01:56 - 2017-06-12 01:56 - 000401848 _____ () C:\WINDOWS\system32\igfxTray.exe
2018-09-15 08:28 - 2018-09-15 08:28 - 001740288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-12-14 20:08 - 2018-12-14 20:13 - 000182272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe
2018-12-14 20:08 - 2018-12-14 20:13 - 000019456 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\SkypeProxiesAndStubs.dll
2018-12-12 15:30 - 2018-12-12 15:33 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\ImagePipelineNative.dll
2018-12-14 20:08 - 2018-12-14 20:13 - 000060416 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\ChakraBridge.dll
2018-12-14 20:08 - 2018-12-14 20:13 - 010927616 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\LibWrapper.dll
2018-12-14 20:08 - 2018-12-14 20:13 - 002916864 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\skypert.dll
2018-12-14 20:08 - 2018-12-14 20:13 - 000688128 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.36.52.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2019-01-10 15:19 - 2019-01-10 15:19 - 005172224 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\YourPhone.exe
2019-01-10 15:19 - 2019-01-10 15:19 - 002172928 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\YourPhone.AppCore.dll
2019-01-10 15:19 - 2019-01-10 15:19 - 001795584 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\PhoneContentDataStore.dll
2018-12-12 15:27 - 2018-12-12 15:29 - 001004032 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2019-01-10 15:19 - 2019-01-10 15:19 - 002907136 _____ () C:\Program Files\WindowsApps\Microsoft.YourPhone_1.0.20094.0_x64__8wekyb3d8bbwe\PhoneCommunicationAppService.dll
2018-12-07 03:37 - 2018-12-07 03:37 - 046504696 _____ () C:\Program Files\Google\Drive\googledrivesync.exe
2019-01-21 17:41 - 2019-01-21 17:41 - 000113664 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\_ctypes.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000080896 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\bz2.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 001792512 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\_hashlib.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000128512 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32api.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000137728 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\pywintypes27.dll
2019-01-21 17:41 - 2019-01-21 17:41 - 000548864 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\pythoncom27.dll
2019-01-21 17:41 - 2019-01-21 17:41 - 000689664 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\unicodedata.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000438784 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32com.shell.shell.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 001489408 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\wx._core_.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 001007104 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\wx._gdi_.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 001039872 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\wx._windows_.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 001325056 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\wx._controls_.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000916992 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\wx._misc_.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 001084416 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\pysqlite2._sqlite.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000149504 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32file.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000136192 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32security.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000007680 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\hashobjs_ext.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000020992 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\thumbnails_ext.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000118784 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\usb_ext.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000047616 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\_socket.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 002224640 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\_ssl.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000014848 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\common.time34.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000023040 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32event.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000034304 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\windows.conditional.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000020480 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\windows.winwrap.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000110080 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\windows.volumes.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000223232 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32gui.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000173568 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\_elementtree.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000169472 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\pyexpat.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000048128 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32inet.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000103424 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\wx._html2.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000046080 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\_psutil_windows.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000633272 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\windows._cacheinvalidation.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000011776 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32crypt.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000301568 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\PIL._imaging.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000032256 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\_multiprocessing.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 005752320 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\cello.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000026112 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\_yappi.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000044032 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32process.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000027648 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32pipe.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000010752 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\select.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000029696 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32pdh.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000038400 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\windows.connectivity.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000073216 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\windows.device_monitor.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000020480 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32profile.pyd
2019-01-21 17:41 - 2019-01-21 17:41 - 000026624 _____ () C:\Users\Pedro\AppData\Local\Temp\_MEI65562\win32ts.pyd
2018-12-11 20:55 - 2018-12-11 20:56 - 000194048 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11810.1001.12.0_x64__8wekyb3d8bbwe\WinStore.Preview.dll
2018-12-11 20:55 - 2018-12-11 20:56 - 002538056 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11810.1001.12.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-12-11 20:55 - 2018-12-11 20:56 - 001754112 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11810.1001.12.0_x64__8wekyb3d8bbwe\Microsoft.Membership.MeControl.dll
2018-12-11 21:02 - 2014-03-02 21:58 - 000977600 _____ () C:\Program Files\KMSpico\AutoPico.exe

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-622939137-141225199-2558093129-1001\...\localhost -> localhost

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 12:47 - 2019-01-13 09:49 - 000002538 _____ C:\WINDOWS\system32\drivers\etc\hosts

217.77.219.101 firststart.nero.com
127.0.0.1 www.nero.com
127.0.0.1 www.nero.com/rus/index.html
127.0.0.1 www.nero.com/rus/support.html
127.0.0.1 http://www.nero.com/rus/support-custome ... ation.html
127.0.0.1 www.nero.com/rus/store-upgrade-center.html
127.0.0.1 www.nero.com/rus/store-volume-licensing.html
127.0.0.1 http://www.nero.com/eng/support.html?Ne ... 25e97a3b80
127.0.0.1 http://www.nero.com/eng/store-upgrade-c ... 25e97a3b80
127.0.0.1 http://www.nero.com/eng/support-custome ... 25e97a3b80
127.0.0.1 www.nero.com/eng/index.html
127.0.0.1 www.nero.com/enu/support-nero8.html
127.0.0.1 my.nero.com
127.0.0.1 secure.nero.com/us/secure.asp
127.0.0.1 activation@nero.com
127.0.0.1 registernero.com
127.0.0.1 www.registernero.com
127.0.0.1 www.nero.com/eng/privacy.html
127.0.0.1 legal@nero.com
127.0.0.1 support.nero.com
127.0.0.1 http://www.nero.com/esp/index.php?NeroS ... 5faf35093e
127.0.0.1 http://www.nero.com/esl/index.php?NeroS ... 5faf35093e
127.0.0.1 http://www.nero.com/esp/support.html?Ne ... 5faf35093e
127.0.0.1 http://www.nero.com/esl/support.html?Ne ... 5faf35093e

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-622939137-141225199-2558093129-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "SwitchBoard"
HKLM\...\StartupApproved\Run32: => "AdobeCS5ServiceManager"
HKLM\...\StartupApproved\Run32: => "HP Software Update"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{0B9605DE-7787-4987-B411-2F1876C02B42}] => (Allow) C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
FirewallRules: [{2DDE39A1-850E-4706-98AF-E52635C3EDD5}] => (Allow) C:\Users\Pedro\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
FirewallRules: [{C4C0FA74-A80E-472E-8E9C-333FD52D29E0}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA)
FirewallRules: [{D902211D-9354-4BFE-A06C-26A896976BF0}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Winamp SA)
FirewallRules: [{D2571339-56D8-4EDC-8F58-66F73461413D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
FirewallRules: [UDP Query User{DEE7462F-B1CE-4F95-B29C-E1A10CCAA945}C:\program files (x86)\sadptool\sadptool.exe] => (Allow) C:\program files (x86)\sadptool\sadptool.exe ()
FirewallRules: [TCP Query User{E7E5FC45-0E57-41F4-B6E0-16FA99B27206}C:\program files (x86)\sadptool\sadptool.exe] => (Allow) C:\program files (x86)\sadptool\sadptool.exe ()
FirewallRules: [{46CA0B6B-A7A8-4B4F-94BA-98259D07327E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [{497F3415-CA52-44AA-A2AC-1268AFD39677}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [UDP Query User{4B72AB8F-20C9-483F-A209-F1D1AF828E67}C:\program files\ivms-4200 station\ivms-4200\ivms-4200 client\ivms-4200.exe] => (Allow) C:\program files\ivms-4200 station\ivms-4200\ivms-4200 client\ivms-4200.exe ()
FirewallRules: [TCP Query User{D7AFD402-0D73-4241-9E4B-96FC807FFC1E}C:\program files\ivms-4200 station\ivms-4200\ivms-4200 client\ivms-4200.exe] => (Allow) C:\program files\ivms-4200 station\ivms-4200\ivms-4200 client\ivms-4200.exe ()
FirewallRules: [{9752767B-1506-490A-B4B7-D994CD313053}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe ()
FirewallRules: [{E4D753BB-5302-44D2-BD71-C0CB703D3561}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe ()
FirewallRules: [{99195CAB-EA85-4848-A184-9E2FEADEA948}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe ()
FirewallRules: [{2E10BC42-CBEB-4159-BE7D-930FD65450AE}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe ()
FirewallRules: [{E0E9858A-A385-4F44-94C5-D2D9EF0F49A3}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe ()
FirewallRules: [{527C7397-7DA3-44B7-A455-84903F3C0A9D}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe ()
FirewallRules: [{26563D16-3209-4CE2-8F60-24BAE4493AB9}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\DeviceSetup.exe (Hewlett-Packard Co.)
FirewallRules: [{CF50206D-590E-4962-A0C4-72C6F3CBD34B}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe (Hewlett-Packard Co.)
FirewallRules: [{5E897D20-3147-433F-92F6-641D739FA360}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicatorCom.exe (Hewlett-Packard Co.)
FirewallRules: [{AAD5C933-D3A9-423E-92A8-5266D5522771}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)
FirewallRules: [{DA41A567-E6A4-491E-8D10-D57F70C954FD}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)

==================== Restore Points =========================

08-01-2019 20:02:18 Windows Update
12-01-2019 19:39:17 Installed ProtonVPN
17-01-2019 20:49:56 Installed Nero 8 Trial. Available with Windows Installer version 1.2 and later.

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/21/2019 04:00:34 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (01/21/2019 04:00:33 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (01/17/2019 10:22:19 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (01/17/2019 10:22:19 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (01/17/2019 10:19:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program WindowsInternal.ComposableShell.Experiences.TextInput.InputApp. version 10.0.17763.1 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 1c20

Start Time: 01d4aeaa495e5dfb

Termination Time: 4294967295

Application Path: C:\Windows\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe

Report Id: f92912c0-4f5e-4f11-b118-258dcb6cf853

Faulting package full name: InputApp_1000.17763.1.0_neutral_neutral_cw5n1h2txyewy

Faulting package-relative application ID: App

Hang type: Quiesce

Error: (01/17/2019 10:18:37 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (01/17/2019 10:18:37 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (01/17/2019 10:14:27 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.17763.107 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: b78

Start Time: 01d4aea980872640

Termination Time: 0

Application Path: C:\Windows\explorer.exe

Report Id: c48dc7fe-7919-49c9-9f21-6f97e4829c97

Faulting package full name:

Faulting package-relative application ID:

Hang type: Unknown


System errors:
=============
Error: (01/21/2019 06:48:38 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-NVJD1LG)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-NVJD1LG\Pedro SID (S-1-5-21-622939137-141225199-2558093129-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/21/2019 05:43:50 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-NVJD1LG)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-NVJD1LG\Pedro SID (S-1-5-21-622939137-141225199-2558093129-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/21/2019 05:40:39 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/21/2019 05:40:39 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/21/2019 04:01:22 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-NVJD1LG)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}
and APPID
{15C20B67-12E7-4BB6-92BB-7AFF07997402}
to the user DESKTOP-NVJD1LG\Pedro SID (S-1-5-21-622939137-141225199-2558093129-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/21/2019 04:00:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
Windows.SecurityCenter.WscBrokerManager
and APPID
Unavailable
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/21/2019 04:00:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
Windows.SecurityCenter.SecurityAppBroker
and APPID
Unavailable
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (01/21/2019 04:00:13 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
Windows.SecurityCenter.WscDataProtection
and APPID
Unavailable
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


Windows Defender:
===================================
Date: 2019-01-18 20:18:51.298
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {00848CB0-9CF6-40BD-8055-77F441B2358D}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-01-18 20:14:28.251
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {DD80844C-A664-440B-8800-ED918E2CC16D}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-01-18 18:51:27.952
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {9CE5057D-E760-497E-9646-BDBDB4841E26}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-01-18 18:45:25.211
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {9D920AB8-D6B5-45DF-BD86-FF15AF799405}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2019-01-18 18:16:32.377
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {4B1B162A-CE67-4BCF-A1F8-42C6204734D3}
Scan Type: Antimalware
Scan Parameters: Quick Scan

Date: 2018-12-28 10:50:21.490
Description:
Windows Defender Antivirus has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version: 1.283.1664.0
Update Source: Microsoft Update Server
Signature Type: AntiVirus
Update Type: Full
Current Engine Version:
Previous Engine Version: 1.1.15500.2
Error code: 0x8024402c
Error description: Počas vyhľadávania aktualizácií sa vyskytol neočakávaný problém. Informácie o inštalácii aktualizácií a riešení problémov s aktualizáciami nájdete v Pomoci a technickej podpore.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-4030U CPU @ 1.90GHz
Percentage of memory in use: 47%
Total physical RAM: 4016.96 MB
Available physical RAM: 2128.75 MB
Total Virtual: 6704.96 MB
Available Virtual: 4262.33 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:174.44 GB) (Free:119.43 GB) NTFS
Drive d: () (Fixed) (Total:289.98 GB) (Free:70.62 GB) NTFS

\\?\Volume{c42e0060-dd36-4a0a-b90a-e93a14540c60}\ () (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{3033b16a-2a35-45a7-b950-de364193d5ce}\ () (Fixed) (Total:0.78 GB) (Free:0.32 GB) NTFS
\\?\Volume{b9545704-433d-4fc6-af0d-de40f2ded245}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 2B66F383)

Partition: GPT.

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST LOG kontrola

#5 Příspěvek od Rudy »

OK. Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {8554379B-3E2F-48C7-91A3-0815C8FBEAC3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-12-11] (Google Inc.)
Task: {E2D3074D-B5C5-45E4-8D4E-0D32E3D0630F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-12-11] (Google Inc.)
C:\Users\Pedro\AppData\Local\Temp
C:\Program Files\KMSpico
FirewallRules: [{9752767B-1506-490A-B4B7-D994CD313053}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe ()
FirewallRules: [{E4D753BB-5302-44D2-BD71-C0CB703D3561}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe ()
FirewallRules: [{99195CAB-EA85-4848-A184-9E2FEADEA948}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe ()
FirewallRules: [{2E10BC42-CBEB-4159-BE7D-930FD65450AE}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe ()
FirewallRules: [{E0E9858A-A385-4F44-94C5-D2D9EF0F49A3}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe ()
FirewallRules: [{527C7397-7DA3-44B7-A455-84903F3C0A9D}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe ()
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Restriction ? <==== ATTENTION
FF NewTab: Mozilla\Firefox\Profiles\knaq84ry.default -> hxxp://securedsearch.lavasoft.com/?pr=v ... 40__181226
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [977088 2014-03-02] () [File not signed]
C:\WINDOWS\System32\Tasks\AutoPico Daily Restart
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
C:\Users\Pedro\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

EmptyTemp:
Hosts:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kroenen2
Návštěvník
Návštěvník
Příspěvky: 270
Registrován: 30 čer 2008 11:52

Re: FRST LOG kontrola

#6 Příspěvek od kroenen2 »

Fix result of Farbar Recovery Scan Tool (x64) Version: 20.01.2019
Ran by Pedro (21-01-2019 21:12:05) Run:1
Running from C:\Users\Pedro\Desktop
Loaded Profiles: Pedro (Available Profiles: defaultuser0 & Pedro)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Task: {8554379B-3E2F-48C7-91A3-0815C8FBEAC3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-12-11] (Google Inc.)
Task: {E2D3074D-B5C5-45E4-8D4E-0D32E3D0630F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-12-11] (Google Inc.)
C:\Users\Pedro\AppData\Local\Temp
C:\Program Files\KMSpico
FirewallRules: [{9752767B-1506-490A-B4B7-D994CD313053}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe ()
FirewallRules: [{E4D753BB-5302-44D2-BD71-C0CB703D3561}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe ()
FirewallRules: [{99195CAB-EA85-4848-A184-9E2FEADEA948}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe ()
FirewallRules: [{2E10BC42-CBEB-4159-BE7D-930FD65450AE}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe ()
FirewallRules: [{E0E9858A-A385-4F44-94C5-D2D9EF0F49A3}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe ()
FirewallRules: [{527C7397-7DA3-44B7-A455-84903F3C0A9D}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe ()
HKLM-x32\...\Run: [] => [X]
GroupPolicy: Restriction ? <==== ATTENTION
FF NewTab: Mozilla\Firefox\Profiles\knaq84ry.default -> hxxp://securedsearch.lavasoft.com/?pr=v ... 40__181226
S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [977088 2014-03-02] () [File not signed]
C:\WINDOWS\System32\Tasks\AutoPico Daily Restart
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
C:\Users\Pedro\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

EmptyTemp:
Hosts:
End
*****************

Processes closed successfully.
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8554379B-3E2F-48C7-91A3-0815C8FBEAC3}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8554379B-3E2F-48C7-91A3-0815C8FBEAC3}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E2D3074D-B5C5-45E4-8D4E-0D32E3D0630F}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2D3074D-B5C5-45E4-8D4E-0D32E3D0630F}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
C:\Users\Pedro\AppData\Local\Temp => moved successfully
C:\Program Files\KMSpico => moved successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9752767B-1506-490A-B4B7-D994CD313053}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E4D753BB-5302-44D2-BD71-C0CB703D3561}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{99195CAB-EA85-4848-A184-9E2FEADEA948}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2E10BC42-CBEB-4159-BE7D-930FD65450AE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E0E9858A-A385-4F44-94C5-D2D9EF0F49A3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{527C7397-7DA3-44B7-A455-84903F3C0A9D}" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
"Firefox newtab" => removed successfully
HKLM\System\CurrentControlSet\Services\Service KMSELDI => removed successfully
Service KMSELDI => service removed successfully
C:\WINDOWS\System32\Tasks\AutoPico Daily Restart => moved successfully
"C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore" => not found
C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully
C:\WINDOWS\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat => moved successfully
C:\Users\Pedro\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 7626752 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 19432770 B
Java, Flash, Steam htmlcache => 343 B
Windows/system/drivers => 483558 B
Edge => 4332 B
Chrome => 263979640 B
Firefox => 23079962 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
LocalService => 0 B
NetworkService => 17454 B
NetworkService => 0 B
defaultuser0 => 7168 B
Pedro => 3211448 B

RecycleBin => 153790391 B
EmptyTemp: => 449.8 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 21:13:07 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST LOG kontrola

#7 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kroenen2
Návštěvník
Návštěvník
Příspěvky: 270
Registrován: 30 čer 2008 11:52

Re: FRST LOG kontrola

#8 Příspěvek od kroenen2 »

Ano, vyzerá to OK.

Ešte otázočka, FRST mi vždy po FIX-e zmaže z Chrom-u všetky otvorené karty. Dá sa to mu nejak predísť do budúcna?
Ďakujem.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST LOG kontrola

#9 Příspěvek od Rudy »

Těžko, FRST je nastaven tak, aby mazal vše, co autor chce. Snad si to můžete jen zazálohovat pomocí ChromeBackup: https://www.stahuj.cz/internet_a_site/p ... me-backup/ . Dělají to jen poslední verze, dříve jsem se s tím nesetkal.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kroenen2
Návštěvník
Návštěvník
Příspěvky: 270
Registrován: 30 čer 2008 11:52

Re: FRST LOG kontrola

#10 Příspěvek od kroenen2 »

Ano, vyzerá to dobre.

Dá sa nejak do budúcna zabrániť zmazaniu kariet v Chrome? Teraz je to OK, ale vždy po aplikácii fixlistu mi v Chrome zmiznú pootvárané karty. Či iba ich záloha? V tom fixliste to nejde nejak vynechať?
... ďakujem :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST LOG kontrola

#11 Příspěvek od Rudy »

Vynechat to asi nepůjde, nikde jsem nazadával příkaz k jejich smazání. Zřejmě nezbude, než zazálohovat. Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

kroenen2
Návštěvník
Návštěvník
Příspěvky: 270
Registrován: 30 čer 2008 11:52

Re: FRST LOG kontrola

#12 Příspěvek od kroenen2 »

OK, v poriadku.

Ďakujem ešte raz :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118251
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: FRST LOG kontrola

#13 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno