Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Infikován PC, nejdou nainstalovat antiviry, přikládám logy

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Infikován PC, nejdou nainstalovat antiviry, přikládám logy

#1 Příspěvek od Henry0607 »

Zdravím,
mám problém s PC. Včera večer po zapnutí a přihlášení jsem viděl černé pozadí plochy a na něm tak 10 ikon, místo obvyklé plochy. Složky jako dokumenty a stažené soubory se jevily jako prázdné. Pak jsem je nalezl v C:\Users\Administrator ale PC se dále choval divně. Mám nainstalovaný avast, který mi na začátku problému zobrazil nějaké chybové hlášení (jehož znění si již nepamatuji), po spuštění avastu mi to píše "jste chráněni" ale místo zelené fajfky vidím červený křížek. Rovněž se mi "pokřivily" fonty, písmo prostě nevypadá normálně.
Tak jsem začal číst po internetu a pak chtěl jsem nainstalovat mbam - neúspěšně, mb antirootkit - neúspěšně, rkill - nespustí se. Asi to bude nějaký malware, který pozná, že se snažím nainstalovat něco proti němu a blokuje to. Spustit se mi povedlo superantispyware, který našel cca 1000 tracking cookies a AdwCleaner exe, který našel 2 položky.

Každopádně jsem spustil FRST a tady jsou logy:

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09.03.2019 01
Ran by Administrator (administrator) on ADMIN-PC (10-03-2019 20:14:08)
Running from C:\Windows\System32\config\systemprofile\Downloads
Loaded Profiles: Helena & Administrator & Guest (Available Profiles: Helena & Administrator & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices) [File not signed] C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Smart Connect software -> ) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Renesas Electronics Corporation -> Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
(CyberLink -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(McAfee, Inc. -> McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\Power2Go9\CLMLSvc_P2G9.exe
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler64.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Support.com, Inc. -> SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-27] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [446400 2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [259976 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
HKLM-x32\...\Run: [RUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink -> CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] => C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [223096 2012-04-17] (CyberLink -> CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer_For_P2G9] => C:\Program Files (x86)\CyberLink\Power2Go9\CLMLSvc_P2G9.exe [110344 2013-12-31] (CyberLink Corp. -> CyberLink)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [259976 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-257039076-1346926551-2253569639-1000\...\Run: [HydraVisionDesktopManager] => "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
HKU\S-1-5-21-257039076-1346926551-2253569639-1000\...\MountPoints2: {ac9abd4b-90fb-11e3-a786-806e6f6e6963} - D:\SETUP.EXE
HKU\S-1-5-21-257039076-1346926551-2253569639-500\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Run: [Akamai NetSession Interface] => C:\Users\Administrator\AppData\Local\Akamai\netsession_win.exe [4586456 2018-04-17] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Run: [World of Tanks] => C:\Games\World_of_Tanks\WargamingGameUpdater.exe [3135752 2016-11-18] (Wargaming.net LLP -> Wargaming.net) [File not signed]
HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Run: [World of Warships] => C:\Games\World_of_Warships\WargamingGameUpdater.exe [3134216 2017-04-18] (Wargaming.net LLP -> Wargaming.net) [File not signed]
HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3113768 2019-02-19] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-257039076-1346926551-2253569639-501\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-257039076-1346926551-2253569639-501\...\Run: [HydraVisionDesktopManager] => "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
HKU\S-1-5-21-257039076-1346926551-2253569639-501\...\MountPoints2: D - D:\autorun.exe
HKU\S-1-5-21-257039076-1346926551-2253569639-501\...\MountPoints2: G - G:\bootstrap.exe
HKU\S-1-5-18\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [9001904 2019-02-11] (Support.com, Inc. -> SUPERAntiSpyware)
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\system32\lagarith.dll [148992 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\system32\x264vfw64.dll [3554304 2013-03-17] (x264vfw project) [File not signed]
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\system32\xvidvfw.dll [258560 2011-06-24] () [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\system32\ac3acm.acm [180736 2012-07-21] (fccHandler) [File not signed]
HKLM\...\Drivers32: [msacm.l3codecp] => C:\Windows\system32\l3codecp.acm [182272 2009-07-14] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3649536 2013-03-17] (x264vfw project) [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [File not signed]
HKLM\...\Drivers32: [msacm.l3codecp] => C:\Windows\SysWOW64\l3codecp.acm [220672 2009-07-14] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\...\Drivers32: [vidc.VP60] => C:\Windows\SysWOW64\vp6vfw.dll [447752 2008-09-04] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [vidc.VP61] => C:\Windows\SysWOW64\vp6vfw.dll [447752 2008-09-04] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\SysWOW64\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.121\Installer\chrmstp.exe [2019-03-05] (Google LLC -> Google Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\72.0.1174.121\Installer\chrmstp.exe [2019-03-08] (AVAST Software s.r.o. -> AVAST Software)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2018-11-06] (Adobe Systems, Incorporated -> Adobe Systems, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{65CD7F9B-E8F3-4bb0-82EB-6F6875B745DF}] -> C:\Windows\system32\LMIinit.dll [2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP DeskJet 2130 series.lnk [2019-03-09]
ShortcutTarget: Sledovat výstrahy inkoustu - HP DeskJet 2130 series.lnk -> C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPStatusBL.dll (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\iSCTsysTray.lnk [2013-12-17]
ShortcutTarget: iSCTsysTray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel(R) Smart Connect software -> Intel Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2019-03-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe (McAfee, Inc. -> McAfee, Inc.)
BootExecute: autocheck autochk * bootdelete
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-257039076-1346926551-2253569639-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{0132C53B-9E00-4E3A-B867-5215A0563262}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{083798B9-92FA-4B60-9686-AB7D6B0EC0E2}: [DhcpNameServer] 8.8.4.4 8.8.8.8
Tcpip\..\Interfaces\{6E3DFC9C-AB8A-41DB-9AE9-E1897B48493F}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{88D9DA17-B962-47ED-B5E9-C272B21358BD}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{8E0C624D-982F-4F34-BE54-C0188AEB53F0}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{9940B725-E8C6-4167-B279-980CA3640939}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{B6D84921-421A-4395-9179-C783E44D6F34}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{EDE5265F-D149-4735-892A-0E6266029618}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-257039076-1346926551-2253569639-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-257039076-1346926551-2253569639-1000 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-257039076-1346926551-2253569639-1000 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2019-01-16] (Microsoft Corporation -> Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll => No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2019-01-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2019-01-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {2D49AE4D-5236-2916-FDF7-E35D7E3C6C78} -> No File
BHO-x32: No Name -> {30FFDA66-22C6-1E64-BAD4-1ECE736319CC} -> No File
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2017-08-15] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {33D9F886-4A04-FD74-1E88-60D9F74C28FA} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\ssv.dll [2018-11-17] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2019-01-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-01-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-11-17] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-07-18] (Microsoft Corporation -> Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - No File

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_148.dll [2018-11-17] (Adobe Systems Incorporated -> )
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_148.dll [2018-11-17] (Adobe Systems Incorporated -> )
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-05-17] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-05-17] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-11-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-11-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-06-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-11-27] (Nero AG -> Nero AG)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Administrator\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-11-15] (RocketLife -> RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc -> Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-02-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Administrator\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2009-11-30] (Unity Technologies ApS -> Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2019-02-14] (Ubisoft Entertainment Sweden AB -> )

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [543112 2017-06-12] (Advanced Micro Devices, Inc. -> AMD)
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2017-06-12] (Advanced Micro Devices) [File not signed]
S2 appdrvrem01; C:\Windows\System32\appdrvrem01.exe [551896 2016-02-28] (Protection Technology, Ltd. -> Protection Technology)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6758976 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-22] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [357304 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-22] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\72.0.1174.121\elevation_service.exe [1070600 2019-03-06] (AVAST Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1465352 2017-07-02] (BattlEye Innovations e.K. -> )
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-09-01] (BitRaider -> BitRaider, LLC)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058392 2017-12-12] (Microsoft Corporation -> Microsoft Corporation)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242664 2012-05-09] (CyberLink -> CyberLink)
S3 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel® Trusted Connect Service -> Intel(R) Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [180200 2013-02-13] (Intel(R) Smart Connect software -> )
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-17] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [420296 2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
S4 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [588232 2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
S4 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2015-06-15] (LogMeIn, Inc. -> LogMeIn, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.968\McCHSvc.exe [405392 2019-02-27] (McAfee, Inc. -> McAfee, Inc.)
R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD. -> MICRO-STAR INTERNATIONAL CO., LTD.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2298688 2019-02-19] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3171144 2019-02-19] (Electronic Arts, Inc. -> Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2017-07-02] (Even Balance, Inc. -> )
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-10-04] (Microsoft Windows -> Microsoft Corporation)
S3 DAUpdaterSvc; C:\Program Files (x86)\Steam\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [X]
S2 PlaysService; "C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [305544 2017-06-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [36562312 2017-06-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [520584 2017-06-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [138152 2013-11-26] (SlySoft, Inc. -> SlySoft, Inc.)
R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [138152 2013-11-26] (SlySoft, Inc. -> SlySoft, Inc.)
R1 appdrv01; C:\Windows\System32\Drivers\appdrv01.sys [3852976 2016-02-28] (Protection Technology, Ltd. -> Protection Technology)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [37104 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [205400 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [225680 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [196072 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswblog.sys [320696 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [57960 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [249672 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [42288 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [167304 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [112312 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [87944 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1034432 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [474456 2019-02-15] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [216784 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
S3 aswTap; C:\Windows\System32\DRIVERS\aswTap.sys [53904 2017-02-21] (AVAST Software s.r.o. -> The OpenVPN Project)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [379952 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [96256 2016-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-12-29] (Tages SA -> )
R1 CLVirtualDrive1.1; C:\Windows\System32\DRIVERS\CLVirtualDrive1_1.sys [91912 2013-11-13] (CyberLink Corp. -> CyberLink)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-24] (Disc Soft Ltd -> Disc Soft Ltd)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [54736 2016-11-02] (SurfRight B.V. -> )
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21048 2013-02-13] (Intel(R) Smart Connect software -> )
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21048 2013-02-13] (Intel(R) Smart Connect software -> )
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-02-13] (Intel(R) Smart Connect software -> )
S3 leusbser; C:\Windows\System32\DRIVERS\leusbser.sys [238080 2012-05-30] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-12-29] (Tages SA -> )
R2 LMIInfo; C:\Windows\system32\drivers\LMIInfo.sys [30432 2017-01-11] (LogMeIn, Inc. -> LogMeIn, Inc.)
S4 LMIRfsClientNP; no ImagePath
R3 MRV6X64U; C:\Windows\System32\DRIVERS\MRVW24C.sys [340480 2007-10-28] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc)
S3 qcusbnet; C:\Windows\System32\DRIVERS\qcusbnet.sys [428600 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [254520 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [114568 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [230280 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [163644 2018-03-16] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2019-03-10] (Intel(R) Smart Connect software -> )
R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54168 2017-04-18] (Intel Corporation -> Intel Corporation)
U1 aswbdisk; no ImagePath
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\Norton Security\NortonData\22.8.0.50\Definitions\SDSDefs\20170829.006\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\Norton Security\NortonData\22.8.0.50\Definitions\SDSDefs\20170829.006\EX64.SYS [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-03-10 20:13 - 2019-03-10 20:14 - 000000000 ____D C:\FRST
2019-03-10 19:36 - 2019-03-10 19:36 - 000000000 ____D C:\KVRT_Data
2019-03-10 17:55 - 2019-03-10 17:55 - 000003620 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task e0753663-4f82-43bb-9fee-97b95ff7ab79
2019-03-10 17:55 - 2019-03-10 17:55 - 000003546 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 9d2d795a-b34c-49d3-814c-de6cf94ec229
2019-03-10 17:55 - 2019-03-10 17:55 - 000001771 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2019-03-10 17:55 - 2019-03-10 17:55 - 000000526 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e0753663-4f82-43bb-9fee-97b95ff7ab79.job
2019-03-10 17:55 - 2019-03-10 17:55 - 000000526 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9d2d795a-b34c-49d3-814c-de6cf94ec229.job
2019-03-10 17:55 - 2019-03-10 17:55 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2019-03-10 17:55 - 2019-03-10 17:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2019-03-10 17:55 - 2019-03-10 17:55 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2019-03-10 17:41 - 2019-03-10 17:41 - 000094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2019-03-09 23:58 - 2017-07-25 21:56 - 001792640 _____ (Bleeping Computer, LLC) C:\rl.exe
2019-03-09 21:55 - 2019-03-09 21:55 - 000000000 ____D C:\Users\Helena\AppData\Roaming\Sun
2019-03-09 21:55 - 2019-03-09 21:55 - 000000000 ____D C:\Users\Helena\AppData\LocalLow\Sun
2019-03-09 21:49 - 2019-03-09 21:49 - 000000000 ____D C:\Users\Helena\AppData\Local\AVAST Software
2019-03-09 21:26 - 2019-03-09 21:26 - 000000000 ____D C:\Users\TEMP\AppData\LocalLow\Sun
2019-03-09 21:11 - 2019-03-09 21:11 - 000000000 ____D C:\Users\TEMP\AppData\Local\mbamtray
2019-03-09 20:59 - 2019-03-09 20:59 - 000000000 ____D C:\Users\TEMP\AppData\LocalLow\AMD
2019-03-09 20:55 - 2019-03-09 21:42 - 000000000 ____D C:\Users\TEMP\AppData\Local\Google
2019-03-09 20:55 - 2019-03-09 20:55 - 000001356 _____ C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2019-03-09 20:55 - 2019-03-09 20:55 - 000000000 ____D C:\Users\Default\AppData\Local\mbamtray
2019-03-09 20:55 - 2019-03-09 20:55 - 000000000 ____D C:\Users\Default User\AppData\Local\mbamtray
2019-03-09 20:52 - 2019-03-09 20:52 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\DAEMON Tools Pro
2019-03-09 20:52 - 2019-03-09 20:52 - 000000000 ____D C:\Users\TEMP\AppData\Local\LogMeIn
2019-03-09 20:52 - 2019-03-09 20:52 - 000000000 ____D C:\Users\TEMP\AppData\Local\AVAST Software
2019-03-09 20:52 - 2015-09-25 14:19 - 000000000 __SHD C:\Users\TEMP\AppData\Local\EmieUserList
2019-03-09 20:52 - 2015-09-25 14:19 - 000000000 __SHD C:\Users\TEMP\AppData\Local\EmieSiteList
2019-03-09 20:52 - 2015-09-25 14:19 - 000000000 __SHD C:\Users\TEMP\AppData\Local\EmieBrowserModeList
2019-03-09 20:52 - 2015-08-29 23:39 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Adobe
2019-03-09 20:52 - 2015-06-11 22:39 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Macromedia
2019-03-09 20:52 - 2014-02-04 23:30 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\AVAST Software
2019-03-09 20:52 - 2010-11-21 10:38 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Media Center Programs
2019-03-09 15:26 - 2019-02-14 21:51 - 000362888 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2019-03-09 14:46 - 2019-03-09 14:46 - 000714936 _____ C:\Windows\Minidump\030919-25974-01.dmp
2019-03-07 21:56 - 2019-03-07 22:23 - 503862934 _____ C:\Users\Administrator\Downloads\(kralovsti bratranci ve valce) 02 do propasti (dokumentarni) -14' -DVBT-(romin).mkv
2019-03-07 20:04 - 2019-03-07 20:40 - 549484562 _____ C:\Users\Administrator\Downloads\(kralovsti bratranci ve valce) 01 rozdeleny trun (dokumentarni) -14' -DVBT-(romin).mkv
2019-03-06 14:08 - 2019-03-06 14:15 - 000000000 ____D C:\ProgramData\McAfee Security Scan
2019-03-06 14:08 - 2019-03-06 14:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2019-03-04 23:10 - 2019-03-10 14:39 - 000000000 ____D C:\Users\Administrator\Desktop\ZSV otázky
2019-03-04 23:09 - 2019-03-04 23:09 - 001264619 _____ C:\Users\Administrator\Downloads\zasilka-KQMWH8FRCHT7IE2M.zip
2019-03-02 19:24 - 2019-03-02 20:09 - 494469816 _____ C:\Users\Administrator\Downloads\The Walking Dead S09E03-cz.tit.avi
2019-03-01 23:56 - 2019-03-01 23:56 - 000314368 _____ C:\Users\Administrator\Downloads\Klasicky_liberalismus.ppt
2019-03-01 19:52 - 2019-03-01 19:52 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\launcher
2019-02-27 15:31 - 2019-02-27 17:40 - 1420436580 _____ C:\Users\Administrator\Downloads\Ostre sledovane vlaky-1966.mp4
2019-02-27 15:30 - 2019-02-27 15:51 - 375751558 _____ C:\Users\Administrator\Downloads\Modlitba pro Katerinu Horovitzovou 1965 480p.mp4
2019-02-27 10:38 - 2019-02-27 10:38 - 000240964 _____ C:\Users\Administrator\Downloads\prihlaska_812531.pdf
2019-02-26 20:57 - 2019-02-26 20:57 - 000239591 _____ C:\Users\Administrator\Downloads\prihlaska_811087 (1).pdf
2019-02-26 20:30 - 2019-02-26 20:30 - 000236231 _____ C:\Users\Administrator\Downloads\prihlaska_811087.pdf
2019-02-26 20:16 - 2019-02-26 20:16 - 000051685 _____ C:\Users\Administrator\Downloads\MOD.pdf
2019-02-26 19:38 - 2019-02-26 19:38 - 000033989 _____ C:\Users\Administrator\Downloads\protokol_o_predani_pozvanek.pdf
2019-02-26 19:37 - 2019-02-26 19:37 - 000051577 _____ C:\Users\Administrator\Downloads\pozvanka.pdf
2019-02-25 00:39 - 2019-02-25 00:39 - 000000012 _____ C:\Users\Administrator\Desktop\Nový textový dokument.txt
2019-02-21 21:55 - 2019-02-21 21:55 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbam
2019-02-21 21:53 - 2019-02-21 21:53 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbamtray
2019-02-21 21:50 - 2019-02-21 21:50 - 000000000 ____D C:\Program Files\Malwarebytes
2019-02-21 21:48 - 2019-02-21 21:50 - 064324200 _____ (Malwarebytes ) C:\Users\Administrator\Downloads\mb3-setup-consumer-3.7.1.2839-1.0.538-1.0.9350.exe
2019-02-20 13:54 - 2019-02-20 15:42 - 1176738978 _____ C:\Users\Administrator\Downloads\2019-02-16 Maturitní ples 8.A a IV.A Čelákovice - male (1).zip
2019-02-20 13:23 - 2019-02-20 13:33 - 185565633 _____ C:\Users\Administrator\Downloads\2019-02-16 Maturitní ples 8.A a IV.A Čelákovice - upravene.zip
2019-02-20 13:21 - 2019-02-20 13:39 - 2083679908 _____ C:\Users\Administrator\Downloads\zasilka-KG7CN59RU498SN7S.zip
2019-02-17 20:03 - 2019-02-17 20:03 - 000000000 ____D C:\Users\Administrator\Desktop\Cesta do hospody + stuff
2019-02-15 22:22 - 2019-02-15 22:59 - 407547628 _____ C:\Users\Administrator\Downloads\The Walking Dead S09E02-cz.tit.avi
2019-02-15 20:10 - 2019-02-15 20:54 - 486489544 _____ C:\Users\Administrator\Downloads\The.Walking.Dead.S09E01 CZ tit.mkv
2019-02-14 21:53 - 2019-02-14 21:53 - 000249672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2019-02-14 07:12 - 2019-02-14 07:12 - 000225003 _____ C:\Users\Administrator\Downloads\ČJL - školní seznam děl k MZ 2017.pdf
2019-02-13 10:50 - 2019-01-27 16:23 - 000396888 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-02-13 10:50 - 2019-01-27 15:32 - 000348760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-02-13 10:50 - 2019-01-26 02:02 - 025736192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-02-13 10:50 - 2019-01-26 01:50 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2019-02-13 10:50 - 2019-01-26 01:50 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2019-02-13 10:50 - 2019-01-26 01:38 - 002902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-02-13 10:50 - 2019-01-26 01:37 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2019-02-13 10:50 - 2019-01-26 01:36 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-02-13 10:50 - 2019-01-26 01:36 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2019-02-13 10:50 - 2019-01-26 01:36 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2019-02-13 10:50 - 2019-01-26 01:35 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2019-02-13 10:50 - 2019-01-26 01:32 - 005778944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-02-13 10:50 - 2019-01-26 01:29 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2019-02-13 10:50 - 2019-01-26 01:28 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2019-02-13 10:50 - 2019-01-26 01:27 - 020279808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-02-13 10:50 - 2019-01-26 01:25 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2019-02-13 10:50 - 2019-01-26 01:24 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2019-02-13 10:50 - 2019-01-26 01:24 - 000790016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-02-13 10:50 - 2019-01-26 01:24 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2019-02-13 10:50 - 2019-01-26 01:24 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2019-02-13 10:50 - 2019-01-26 01:18 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2019-02-13 10:50 - 2019-01-26 01:17 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2019-02-13 10:50 - 2019-01-26 01:14 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2019-02-13 10:50 - 2019-01-26 01:07 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2019-02-13 10:50 - 2019-01-26 01:07 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2019-02-13 10:50 - 2019-01-26 01:06 - 000498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-02-13 10:50 - 2019-01-26 01:06 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2019-02-13 10:50 - 2019-01-26 01:06 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2019-02-13 10:50 - 2019-01-26 01:06 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2019-02-13 10:50 - 2019-01-26 01:05 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2019-02-13 10:50 - 2019-01-26 01:05 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2019-02-13 10:50 - 2019-01-26 01:03 - 002295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-02-13 10:50 - 2019-01-26 01:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2019-02-13 10:50 - 2019-01-26 01:03 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-02-13 10:50 - 2019-01-26 01:01 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-02-13 10:50 - 2019-01-26 01:00 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2019-02-13 10:50 - 2019-01-26 00:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2019-02-13 10:50 - 2019-01-26 00:59 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2019-02-13 10:50 - 2019-01-26 00:58 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2019-02-13 10:50 - 2019-01-26 00:57 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-02-13 10:50 - 2019-01-26 00:56 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2019-02-13 10:50 - 2019-01-26 00:56 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2019-02-13 10:50 - 2019-01-26 00:50 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-02-13 10:50 - 2019-01-26 00:48 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-02-13 10:50 - 2019-01-26 00:48 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-02-13 10:50 - 2019-01-26 00:48 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2019-02-13 10:50 - 2019-01-26 00:46 - 015283712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-02-13 10:50 - 2019-01-26 00:46 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-02-13 10:50 - 2019-01-26 00:46 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2019-02-13 10:50 - 2019-01-26 00:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2019-02-13 10:50 - 2019-01-26 00:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2019-02-13 10:50 - 2019-01-26 00:43 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2019-02-13 10:50 - 2019-01-26 00:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2019-02-13 10:50 - 2019-01-26 00:40 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2019-02-13 10:50 - 2019-01-26 00:39 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2019-02-13 10:50 - 2019-01-26 00:37 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2019-02-13 10:50 - 2019-01-26 00:34 - 004858880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-02-13 10:50 - 2019-01-26 00:34 - 004494336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-02-13 10:50 - 2019-01-26 00:32 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2019-02-13 10:50 - 2019-01-26 00:31 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-02-13 10:50 - 2019-01-26 00:30 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-02-13 10:50 - 2019-01-26 00:29 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-02-13 10:50 - 2019-01-26 00:29 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2019-02-13 10:50 - 2019-01-26 00:22 - 001556480 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-02-13 10:50 - 2019-01-26 00:12 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-02-13 10:50 - 2019-01-26 00:11 - 004386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-02-13 10:50 - 2019-01-26 00:08 - 001331200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-02-13 10:50 - 2019-01-26 00:06 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2019-02-13 10:50 - 2019-01-15 08:06 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-02-13 10:50 - 2019-01-15 08:06 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-02-13 10:50 - 2019-01-15 08:03 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2019-02-13 10:50 - 2019-01-15 07:51 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2019-02-13 10:50 - 2019-01-15 07:51 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2019-02-13 10:50 - 2019-01-15 07:38 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2019-02-13 10:50 - 2019-01-15 07:33 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2019-02-13 10:50 - 2019-01-15 07:32 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2019-02-13 10:50 - 2019-01-15 07:32 - 000161280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2019-02-13 10:50 - 2019-01-15 07:32 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2019-02-13 10:50 - 2019-01-15 07:31 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2019-02-13 10:50 - 2019-01-15 07:29 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2019-02-13 10:50 - 2019-01-12 04:08 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2019-02-13 10:50 - 2019-01-12 04:08 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll
2019-02-13 10:50 - 2019-01-12 03:55 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2019-02-13 10:50 - 2019-01-12 03:55 - 000004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll
2019-02-13 10:50 - 2019-01-12 03:36 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2019-02-13 10:50 - 2019-01-12 03:36 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-02-13 10:50 - 2019-01-12 03:36 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2019-02-13 10:50 - 2019-01-09 04:10 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2019-02-13 10:50 - 2019-01-09 04:09 - 005552360 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-02-13 10:50 - 2019-01-09 04:09 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-02-13 10:50 - 2019-01-09 04:09 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-02-13 10:50 - 2019-01-09 04:08 - 001664352 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 001162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:58 - 004055784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2019-02-13 10:50 - 2019-01-09 03:58 - 003960552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2019-02-13 10:50 - 2019-01-09 03:57 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:45 - 000076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2019-02-13 10:50 - 2019-01-09 03:45 - 000033408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2019-02-13 10:50 - 2019-01-09 03:45 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2019-02-13 10:50 - 2019-01-09 03:41 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2019-02-13 10:50 - 2019-01-09 03:41 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2019-02-13 10:50 - 2019-01-09 03:41 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2019-02-13 10:50 - 2019-01-09 03:38 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2019-02-13 10:50 - 2019-01-09 03:38 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2019-02-13 10:50 - 2019-01-09 03:38 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2019-02-13 10:50 - 2019-01-09 03:37 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2019-02-13 10:50 - 2019-01-09 03:35 - 000464384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2019-02-13 10:50 - 2019-01-09 03:35 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-02-13 10:50 - 2019-01-09 03:35 - 000169984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2019-02-13 10:50 - 2019-01-09 03:34 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2019-02-13 10:50 - 2019-01-09 03:34 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2019-02-13 10:50 - 2019-01-09 03:34 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2019-02-13 10:50 - 2019-01-09 03:34 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2019-02-13 10:50 - 2019-01-09 03:33 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:33 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:33 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:33 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2019-02-13 10:50 - 2019-01-07 18:19 - 003228160 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-02-13 10:50 - 2019-01-01 17:08 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2019-02-13 10:50 - 2019-01-01 17:05 - 003247104 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2019-02-13 10:50 - 2019-01-01 17:05 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2019-02-13 10:50 - 2019-01-01 17:05 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2019-02-13 10:50 - 2019-01-01 17:04 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2019-02-13 10:50 - 2019-01-01 17:04 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2019-02-13 10:50 - 2019-01-01 16:58 - 002368000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2019-02-13 10:50 - 2019-01-01 16:58 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2019-02-13 10:50 - 2019-01-01 16:58 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2019-02-13 10:50 - 2019-01-01 16:57 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2019-02-13 10:50 - 2019-01-01 16:39 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2019-02-13 10:50 - 2019-01-01 16:39 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2019-02-13 10:50 - 2018-12-28 20:59 - 002072576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-02-13 10:50 - 2018-12-28 20:59 - 000876032 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2019-02-13 10:50 - 2018-12-28 20:59 - 000516608 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2019-02-13 10:50 - 2018-12-28 20:59 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2019-02-13 10:50 - 2018-12-28 20:59 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2019-02-13 10:50 - 2018-12-28 20:48 - 001425920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2019-02-13 10:50 - 2018-12-28 20:48 - 000582144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2019-02-13 10:50 - 2018-12-28 20:48 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2019-02-13 10:50 - 2018-12-28 20:32 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2019-02-13 10:50 - 2018-12-04 17:07 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2019-02-13 10:50 - 2018-12-04 17:07 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2019-02-13 10:50 - 2018-12-04 16:55 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2019-02-13 10:50 - 2018-12-04 16:55 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2019-02-13 10:50 - 2018-12-02 17:06 - 000687616 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000998480 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000918408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000066000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000063936 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000021968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000020944 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000019408 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000018880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000017872 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000017856 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000017360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000017352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000016336 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000015824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000015808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000015296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000014312 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000014272 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000013768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000013760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000013760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000013264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012736 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012232 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012024 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011728 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011512 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2019-02-11 17:50 - 2019-02-11 17:50 - 009314380 _____ C:\Users\Administrator\Downloads\Čj.zip
2019-02-11 17:50 - 2019-02-11 17:50 - 002857117 _____ C:\Users\Administrator\Downloads\Dějepis.zip
2019-02-11 17:50 - 2019-02-11 17:50 - 000340524 _____ C:\Users\Administrator\Downloads\ZSV.zip
2019-02-11 17:50 - 2019-02-11 17:50 - 000340524 _____ C:\Users\Administrator\Downloads\ZSV (1).zip

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-03-10 17:49 - 2009-07-14 05:45 - 000022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-03-10 17:49 - 2009-07-14 05:45 - 000022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-03-10 17:41 - 2016-12-07 11:21 - 000034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2019-03-10 17:40 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-03-10 17:39 - 2013-12-17 18:14 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2019-03-10 09:24 - 2014-02-10 21:00 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\uTorrent
2019-03-09 23:38 - 2017-11-05 17:43 - 000000000 ____D C:\Users\Administrator\Desktop\Žádost o přijetí na oddělení paliativní péče
2019-03-09 22:47 - 2016-05-28 12:08 - 000000991 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Control Panel.lnk
2019-03-09 22:41 - 2018-06-13 12:43 - 000197844 _____ C:\Windows\ntbtlog.txt
2019-03-09 22:09 - 2017-11-18 16:36 - 000002526 _____ C:\Users\Administrator\Desktop\Discord.lnk
2019-03-09 22:09 - 2017-07-13 16:34 - 000002514 _____ C:\Users\Administrator\Desktop\HP Photo Creations.lnk
2019-03-09 22:09 - 2014-05-27 15:45 - 000001305 _____ C:\Users\Administrator\Desktop\µTorrent.lnk
2019-03-09 21:36 - 2019-01-20 13:34 - 000022016 ___SH C:\Users\Administrator\Thumbs.db
2019-03-09 21:13 - 2015-09-25 16:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-03-09 21:11 - 2009-07-14 05:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2019-03-09 20:56 - 2009-07-14 06:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2019-03-09 16:34 - 2013-12-28 17:25 - 000000000 ____D C:\Program Files (x86)\Steam
2019-03-09 16:33 - 2015-11-07 19:36 - 000000000 ____D C:\ProgramData\Origin
2019-03-09 16:12 - 2018-04-05 16:03 - 000000000 ____D C:\Users\Administrator\AppData\Local\AVAST Software
2019-03-09 15:27 - 2017-02-21 18:26 - 000001966 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2019-03-09 15:27 - 2017-02-21 18:25 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2019-03-09 14:46 - 2013-12-27 11:03 - 000000000 ____D C:\Windows\Minidump
2019-03-09 13:17 - 2017-01-11 16:58 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2019-03-09 11:43 - 2015-12-03 16:25 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2019-03-09 11:01 - 2016-05-28 12:05 - 000000000 ____D C:\ProgramData\LogMeIn
2019-03-08 16:31 - 2018-04-22 10:47 - 000002432 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2019-03-08 16:31 - 2018-04-22 10:47 - 000002389 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2019-03-07 23:54 - 2013-12-26 21:53 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\vlc
2019-03-07 17:57 - 2015-11-07 19:36 - 000000000 ____D C:\Program Files (x86)\Origin
2019-03-06 17:36 - 2018-06-17 12:38 - 000001971 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2019-03-06 14:08 - 2018-06-17 13:08 - 000000000 ____D C:\Program Files\McAfee Security Scan
2019-03-06 14:03 - 2013-12-24 19:54 - 000000000 ____D C:\Users\Administrator\AppData\Local\CrashDumps
2019-03-05 20:56 - 2017-12-28 14:12 - 000002186 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-03-05 20:56 - 2013-12-17 18:12 - 000002227 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-03-03 23:13 - 2017-12-22 13:55 - 000000000 ____D C:\Users\Administrator\Desktop\Práce do školy
2019-03-03 23:13 - 2010-11-21 10:27 - 000709330 _____ C:\Windows\system32\perfh005.dat
2019-03-03 23:13 - 2010-11-21 10:27 - 000157920 _____ C:\Windows\system32\perfc005.dat
2019-03-03 23:13 - 2009-07-14 06:13 - 001682108 _____ C:\Windows\system32\PerfStringBackup.INI
2019-03-03 23:13 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2019-03-03 13:05 - 2019-01-04 21:58 - 000000000 _____ C:\Windows\system32\last.dump
2019-03-02 15:07 - 2016-05-10 16:11 - 000000000 ____D C:\Users\Administrator\Desktop\Původní data aplikace Firefox
2019-03-01 19:52 - 2013-12-28 22:14 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\The Creative Assembly
2019-02-22 11:00 - 2015-11-17 15:09 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-02-21 11:10 - 2014-03-15 18:47 - 000000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics
2019-02-21 10:31 - 2014-06-13 20:50 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-02-21 10:29 - 2014-06-13 20:49 - 000000000 ____D C:\Program Files\Microsoft Office 15
2019-02-20 18:44 - 2017-08-16 13:46 - 000000000 ____D C:\Users\Administrator\Desktop\Fotky
2019-02-17 20:05 - 2017-04-22 17:01 - 000000000 ____D C:\Users\Administrator\Desktop\Helena
2019-02-17 18:09 - 2017-10-15 21:24 - 000000000 ____D C:\Users\Administrator\Desktop\scan rozsudek rozvod
2019-02-15 14:28 - 2013-12-26 13:16 - 000000000 ____D C:\Users\Administrator\AppData\Local\Ubisoft Game Launcher
2019-02-15 13:53 - 2013-12-17 18:01 - 000474456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2019-02-14 21:52 - 2016-07-11 18:26 - 000042288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2019-02-14 21:52 - 2013-12-24 06:50 - 000216784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2019-02-14 21:52 - 2013-12-17 18:01 - 000379952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2019-02-14 21:52 - 2013-12-17 18:01 - 000167304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2019-02-14 21:52 - 2013-12-17 18:01 - 000112312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2019-02-14 21:52 - 2013-12-17 18:01 - 000087944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2019-02-14 21:51 - 2019-01-14 19:40 - 000225680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2019-02-14 21:51 - 2019-01-04 10:34 - 000320696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswblog.sys
2019-02-14 21:51 - 2019-01-04 10:34 - 000196072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2019-02-14 21:51 - 2019-01-04 10:34 - 000057960 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2019-02-14 21:51 - 2019-01-04 10:34 - 000037104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2019-02-14 21:51 - 2017-11-16 13:41 - 000205400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2019-02-14 21:51 - 2013-12-17 18:01 - 001034432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2019-02-14 12:13 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache
2019-02-14 06:58 - 2009-07-14 05:45 - 005041840 _____ C:\Windows\system32\FNTCACHE.DAT
2019-02-14 00:07 - 2013-12-17 18:02 - 001656822 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2019-02-14 00:04 - 2013-12-18 09:06 - 000000000 ____D C:\Windows\system32\MRT
2019-02-14 00:01 - 2013-12-18 09:06 - 129330784 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-02-10 23:02 - 2017-11-18 16:36 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\discord
2019-02-10 11:19 - 2015-11-08 11:31 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Origin
2019-02-09 22:22 - 2019-02-06 14:04 - 000000000 ____D C:\Users\Administrator\Documents\Endless Space 2

==================== Files in the root of some directories =======

2014-01-25 10:38 - 2013-11-26 10:38 - 000000032 ____R () C:\ProgramData\hash.dat

Some files in TEMP:
====================
2018-10-05 21:38 - 2018-10-05 21:38 - 040210008 _____ () C:\Users\Administrator\AppData\Local\Temp\vlc-3.0.4-win32.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\dllhost.exe => File is digitally signed
C:\Windows\SysWOW64\dllhost.exe => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2019-03-06 15:00

==================== End of FRST.txt ============================

Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#2 Příspěvek od Henry0607 »

a ještě addition.txt


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09.03.2019 01
Ran by Administrator (10-03-2019 20:14:49)
Running from C:\Windows\System32\config\systemprofile\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2013-12-17 16:20:12)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-257039076-1346926551-2253569639-500 - Administrator - Enabled) => C:\Users\TEMP
ASPNET (S-1-5-21-257039076-1346926551-2253569639-1002 - Limited - Enabled)
Guest (S-1-5-21-257039076-1346926551-2253569639-501 - Limited - Enabled) => C:\Users\Guest
Helena (S-1-5-21-257039076-1346926551-2253569639-1000 - Limited - Enabled) => C:\Users\Helena
HomeGroupUser$ (S-1-5-21-257039076-1346926551-2253569639-1004 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ACP Application (HKLM\...\{0A1ABEEF-037C-D922-08E1-AB1798F320BE}) (Version: 2017.0612.1633.42 - Advanced Micro Devices, Inc.) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.010.20098 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 31.0.0.96 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Digital Editions 3.0 (HKLM-x32\...\Adobe Digital Editions 3.0) (Version: 3.0.1 - Adobe Systems Incorporated)
Adobe Flash Player 31 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 31.0.0.148 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.148 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Age Of Empires 3 CZ verze 1.0 (HKLM-x32\...\{A6502644-790D-4DCB-824F-45C64B22AF4D}_is1) (Version: 1.0 - tomi2k9)
Akamai NetSession Interface (HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Akamai) (Version: - Akamai Technologies, Inc)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
AnyDVD (HKLM-x32\...\AnyDVD) (Version: 7.4.2.0 - SlySoft)
Application Profiles (HKLM-x32\...\{06AEF86C-0B0B-5690-38A0-02E1520A6999}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Armies of Exigo (HKLM-x32\...\{DA825D8C-E83C-49FC-81ED-AB28E069329F}_is1) (Version: 1.4 - US - ACTION, s.r.o.)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version: - Ubisoft)
AutoREALM Version 2.2.1 (HKLM-x32\...\AutoREALM_is1) (Version: - )
Avast Driver Updater (HKLM-x32\...\{D606EFF9-3813-4875-B455-AECD2E7B0676}) (Version: 2.3.3 - AVAST Software) Hidden
Avast Driver Updater (HKLM-x32\...\Avast Driver Updater) (Version: 2.3.3 - AVAST Software)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 19.2.2364 - AVAST Software)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 72.0.1174.121 - Autoři prohlížeče Avast Secure Browser)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Battles of Napoleon (HKLM-x32\...\{77D97242-6F88-4046-B1B2-5AD790752816}) (Version: 1.00.0000 - IncaGold)
BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC)
Brain Workshop 4.8.4 (HKLM-x32\...\Brain Workshop_is1) (Version: 4.8.4 - Paul Hoskinson & Jonathan Toomim)
Caesar IV (HKLM-x32\...\{B7666229-351B-47D9-AA6F-DF777CF04BBF}) (Version: 0.18.13 - Tilted Mill Entertainment)
Castle Strike (HKLM-x32\...\{B829DDDC-BCEE-441C-BB8C-0401753E4B44}_is1) (Version: 1.2 - US - ACTION, s.r.o.)
Catalyst Control Center Next Localization BR (HKLM\...\{15979E65-792E-474B-BC5D-42257709D4D9}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{83D75873-9603-EA5A-948F-A5AEE78082C1}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{DD3A9C85-51E9-854D-EB9B-F0AE8E5B2F7C}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{A00A5425-8899-055A-404C-8F96C2EC647F}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{CB71E054-00CF-182D-6C78-F9D85D10B7BA}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{30B97DD0-3646-AD22-2E77-3792B11BB5E6}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{8342F234-A97E-D691-3C01-F060CB7DA175}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{CD47D86C-737D-4818-F059-CF8A53F37B76}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{DB0E2806-DE62-D60E-9BD9-E3A89FB2A5A8}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{D6ACA0E4-2488-AE52-E73D-24DB98F9AD65}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B8C421E8-BDF9-F598-832C-659A513F79EB}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{D4EF1657-8835-A5AE-DBA0-658EF2869048}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{ED71C4B4-4C00-F7C9-9151-60411373DC35}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{28FFCD28-01FF-9792-B1A9-B944D44FB37D}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{DAEF66AB-6EA7-B0A8-96FB-243A2F33B8B2}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{3DBC48E0-7DE6-295B-448E-5F53D1491AC3}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{CAF3DAD2-A7E8-5472-F8E3-D71E92B7FA65}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{E7666716-625F-9E54-ECB3-39CC3C7FFB14}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{30A5B188-80AB-2CF5-22D8-8E20D66907D4}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{A38C8B57-D3E6-5748-F2D3-FDC383D1203A}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{1CD84FD4-26F3-08FC-32F5-17DA9E8A4ED7}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
CyberLink LabelPrint 2.5 (HKLM-x32\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.0.6603 - CyberLink Corp.)
CyberLink LabelPrint 2.5 (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.0.6603 - CyberLink Corp.)
CyberLink Power2Go 9 (HKLM-x32\...\InstallShield_{57D68FAE-CB5E-4fd6-AE3B-A0B43375AF18}) (Version: 9.0.1231.0 - CyberLink Corp.)
CyberLink WaveEditor 2 (HKLM-x32\...\InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}) (Version: 2.0.0.4203 - CyberLink Corp.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Dark Souls Prepare to Die Edition (HKLM-x32\...\{4E4D0FA1-6B85-4824-88FC-051000028201}) (Version: 1.0.0002.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Dark Souls Prepare to Die Edition (HKLM-x32\...\{4E4D0FA1-6B85-4824-88FC-051000038201}) (Version: 1.0.0003.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Dark Souls Prepare to Die Edition (HKLM-x32\...\{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Dark Souls Prepare to Die Edition (HKLM-x32\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.)
Discord (HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Discord) (Version: 0.0.304 - Discord Inc.)
Drakensang - The River of Time (HKLM-x32\...\Drakensang_TRoT_is1) (Version: - dtp)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink)
Elder Kings CK2 Total Conversion (HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Elder Kings CK2 Total Conversion 0.1.5) (Version: 0.1.5 - Elder Kings Team)
Euro Truck Simulator 2 Multiplayer 0.2.0.1.1 Alpha (HKLM-x32\...\{A227B892-C548-4490-9C5D-DB341F8194A6}_is1) (Version: 0.2.0.1.1 Alpha - ETS2MP Team)
Fotogalerie (HKLM-x32\...\{F37D360D-9308-4BB1-8515-DC6B637B9486}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
GameRanger (HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\GameRanger) (Version: - GameRanger Technologies)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.23.9 - Google Inc.) Hidden
Gothic (HKLM-x32\...\{BBF10B37-4ED3-11D5-A818-00500435FC18}) (Version: - )
Gothic (HKLM-x32\...\Gothic_is1) (Version: - GOG.com)
Gothic II Gold (HKLM-x32\...\{8B95673D-2D4C-4216-ADA2-3660973700BF}) (Version: 1.00.0000 - CD Projekt) Hidden
Gothic II Gold (HKLM-x32\...\InstallShield_{8B95673D-2D4C-4216-ADA2-3660973700BF}) (Version: 1.00.0000 - CD Projekt)
Heroes of Might and Magic V - Hammers of Fate (HKLM-x32\...\{EEF7568A-BD2C-42B7-A22E-6D55EA287C34}) (Version: 2.1 - Ubisoft)
Heroes of Might and Magic V (HKLM-x32\...\{9B22D57A-5338-49A5-AC08-70FE3E8B878B}) (Version: 1.6 - Ubisoft)
HP DeskJet 2130 series Nápověda (HKLM-x32\...\{C8CCFDF2-9CB2-4714-BCE5-17178CB71646}) (Version: 35.0.0 - Hewlett Packard)
HP Photo Creations (HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\HP Photo Creations) (Version: 1.0.0.22192 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Intel(R) Smart Connect Technology 4.0 x64 (HKLM\...\{F971B444-C3D5-4AFD-A891-32B9DF79EBC7}) (Version: 4.0.41.2072 - Intel)
Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
Java 8 Update 191 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180191F0}) (Version: 8.0.1910.12 - Oracle Corporation)
LEGO® The Lord of the Rings™ (HKLM-x32\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: 1.0.0.0 - Warner Bros. Interactive Entertainment)
Lenovo Mobile Device Drivers (HKLM-x32\...\{473DF2D7-9A99-4CA5-8BB1-19CE1EA6D5F1}) (Version: 3.7.09 - Lenovo)
LogMeIn (HKLM-x32\...\{CEA0C06C-C352-434A-972E-04911AAB669C}) (Version: 4.1.7682 - LogMeIn, Inc.)
LogMeIn Client (HKLM-x32\...\{2FE23717-0B77-422A-A4DD-AF5191533451}) (Version: 1.3.2148 - LogMeIn, Inc.)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.968.1 - McAfee, Inc.)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.7.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 - cs-cz (HKLM\...\ProPlusRetail - cs-cz) (Version: 15.0.5111.1001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visio Professional 2013 - cs-cz (HKLM\...\VisioProRetail - cs-cz) (Version: 15.0.5111.1001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710F4C1C-CC18-4C49-8CBF-51240C89A1A2}) (Version: - )
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: - )
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Might and Magic Heroes VII (HKLM-x32\...\Uplay Install 1176) (Version: - Ubisoft)
Movie Maker (HKLM-x32\...\{3D2CF65C-B544-4308-B996-700D3E5F6C4C}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 60.0.2 (x64 cs) (HKLM\...\Mozilla Firefox 60.0.2 (x64 cs)) (Version: 60.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 60.0.2.6730 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: - )
MySQL Connector/ODBC 3.51 (HKLM-x32\...\{0CB3C535-1171-4A20-B549-E2CB5DEB9723}) (Version: 3.51.12 - MySQL AB)
Nero 2014 (HKLM-x32\...\{0128492C-AB60-43BE-9D9A-8CA622CAF06E}) (Version: 15.0.07700 - Nero AG)
Nero Info (HKLM-x32\...\{B791E0AB-87A9-41A4-8D98-D13C2E37D928}) (Version: 16.0.1003 - Nero AG)
Nero MediaHome Free (HKLM-x32\...\{B0AE1850-DA08-4E88-BC39-3D3BCCCEFF37}) (Version: 16.0.01500 - Nero AG)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.5111.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.5111.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0405-0000-0000000FF1CE}) (Version: 15.0.5111.1001 - Microsoft Corporation) Hidden
Opera Stable 54.0.2952.41 (HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\...\Opera 54.0.2952.41) (Version: 54.0.2952.41 - Opera Software)
Origin (HKLM-x32\...\Origin) (Version: 10.5.35.22222 - Electronic Arts, Inc.)
PDF Settings CS5 (HKLM-x32\...\{A78FE97A-C0C8-49CE-89D0-EDD524A17392}) (Version: 10.0 - Adobe Systems Incorporated) Hidden
Prerequisite installer (HKLM-x32\...\{5909A89E-C97F-407C-AE2B-47BDED86BF5D}) (Version: 15.0.0005 - Nero AG) Hidden
Prerequisite installer (HKLM-x32\...\{799AFA36-4EA5-4323-8689-74C06645A26B}) (Version: 16.0.0003 - Nero AG) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Raptr (HKLM-x32\...\Raptr) (Version: 5.2.11-r125663-release - Raptr, Inc)
Risen - ModStarter 1.3.4.1 (Online Mods DB version) (HKLM-x32\...\Risen - ModStarter_is1) (Version: - LordOfWAR(WorldOfRisen.de), Odin68(Mighty DWARF Mod-Team))
Risen (HKLM-x32\...\{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}) (Version: 1.00.0000 - Deep Silver)
SafeZone Stable 4.58.2552.909 (HKLM-x32\...\SafeZone 4.58.2552.909) (Version: 4.58.2552.909 - Avast Software) Hidden
Sid Meier's Civilization 4 Complete (HKLM-x32\...\{30D1F3D2-54CF-481D-A005-F94B0E98FEEC}) (Version: 1.74 - Firaxis Games)
Skype verze 8.34 (HKLM-x32\...\Skype_is1) (Version: 8.34 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 7.0.0.50 - Bioware/EA)
Studie vylepšování produktu HP DeskJet 2130 series (HKLM\...\{A6640A96-7F5D-4480-8D50-F3A0BB58C096}) (Version: 35.0.61.54677 - Hewlett-Packard Co.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1030 - SUPERAntiSpyware.com)
The Movies(TM) (HKLM-x32\...\{0556F885-2415-4666-B53E-33727E46AEA1}) (Version: 1.0 - Activision) Hidden
The Movies(TM) (HKLM-x32\...\InstallShield_{0556F885-2415-4666-B53E-33727E46AEA1}) (Version: 1.0 - Activision)
The Settlers 7 - CESTA KE KORUNĚ (HKLM-x32\...\{9C916142-C18C-429D-BFED-40094A7E0BEB}) (Version: 1.12.1396 - Ubisoft)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
The Sims™ 3 Cestovní horečka (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
The Sims™ 3 Luxusní bydlení – Kolekce (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
The Sims™ 3 Obludárium (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
The Sims™ 3 Povolání snů (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
The Sims™ 3 Roční období (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.21.0 (HKLM\...\VulkanRT1.0.21.0) (Version: 1.0.21.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0-2) (Version: 1.0.26.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1-2) (Version: 1.0.39.1 - LunarG, Inc.)
Windows Driver Package - Acer, Inc. (WinUSB) AndroidUsbDeviceClass (03/19/2013 1.0.0000.00000) (HKLM\...\8568FB1AD6B1B941521B49E8A0395C305BE3C5E3) (Version: 03/19/2013 1.0.0000.00000 - Acer, Inc.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version: - )
WinRAR 5.60 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)
YMS 3017 AMBUSH Gaming mouse (HKLM-x32\...\{DEA4CAD5-2A02-4FE2-9498-E49134876A23}_is1) (Version: 1.0 - )
Zachvev - Pod vlivem mesice v1.0z (HKLM-x32\...\{Zachvev - Pod vlivem mesice zip}_is1) (Version: - Špidla Data Processing, s.r.o.)
Základní software zařízení HP DeskJet 2130 series (HKLM\...\{E1B7356D-B08B-4B2C-A8C3-EAB12EB743DE}) (Version: 35.0.61.54677 - Hewlett-Packard Co.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [CLVDShellExt9] -> {4E20B104-5D9F-4E01-A01E-100F08E345C9} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt9.dll [2014-01-02] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers1: [DaemonShellExtImage] -> {40966797-8FFE-46C8-9EF8-7003F33CCF0F} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2013-10-17] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [CLVDShellExt9] -> {4E20B104-5D9F-4E01-A01E-100F08E345C9} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt9.dll [2014-01-02] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers2: [DaemonShellExtDrive] -> {A5415364-784A-41A5-B47A-D452909CA8FF} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2013-10-17] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers4: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2017-06-12] (Advanced Micro Devices, Inc.) [File not signed]
ContextMenuHandlers6: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0049AEA8-D3E6-4B05-968F-BA62A06AA382} - System32\Tasks\SafeZone scheduled Autoupdate 1468307900 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe (AVAST Software s.r.o. -> Avast Software)
Task: {0201B920-1E7C-4BC9-AAA6-2B4BA6485E9F} - System32\Tasks\{F78CB45C-FCB1-4431-B1B2-1603F84BD6BE} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {02A2BAF6-DE34-464D-8F60-E439AE429492} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe (AVAST Software s.r.o. -> AVAST Software)
Task: {032BA9DA-3D10-41D6-B306-374157D21126} - System32\Tasks\{1BB64DBB-9E94-431E-98A9-3EDD1A21E945} => C:\Windows\system32\pcalua.exe -a F:\Crack\Cestina\CZ_100.exe -d F:\Crack\Cestina
Task: {0659D284-B4D3-4DA1-88D7-F84CB901EC8D} - System32\Tasks\{21DB7A55-CFAC-4218-B011-FAFF49CE0216} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {07124ADC-D200-45FA-AEDB-0BC2DCC53AA0} - System32\Tasks\Avast Driver Updater Startup => C:\Program Files (x86)\Avast Driver Updater\Avast Driver Updater.exe
Task: {11838125-9FE3-4934-9693-0A57694AC2DB} - System32\Tasks\Games\UpdateCheck_S-1-5-21-257039076-1346926551-2253569639-1000
Task: {183DF887-868B-49F8-8E2E-89E9FCDCFAB8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe
Task: {1B7C4B96-B52E-4188-B849-0253AD8D7C1A} - System32\Tasks\{C1150EFD-D18C-4EB2-9861-1363666EAB60} => C:\Program Files (x86)\Age Of Empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
Task: {1BC97C63-8AE1-4BE9-9D9E-734F917EAA84} - System32\Tasks\Sstt2-TaskPlan => C:\Program Files\Gaming\YMS 3017\YMS 3017.EXE (YENKEE) [File not signed]
Task: {1BE3D2C1-3F54-4F7E-ABD2-332BE651C4CB} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {1E17EB1F-40F2-46BA-B90D-33589F5F1B02} - System32\Tasks\{5779624E-0D67-48BC-875A-C3FA23A0D588} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
Task: {1EEDB8A7-6A72-4F1C-B275-7EB807B219AC} - System32\Tasks\HP AR Program Upload - 78d5c9d5dfcd4119b9bfd7f0f1f2ee94b4f7c6d42d0c49ac9cf2460bc07956c0 => C:\Program Files\HP\HP DeskJet 2130 series\bin\HPRewards.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {1FE39584-9F57-4D5F-9A58-8B7CA48AE85E} - System32\Tasks\{CCEAF1B1-A16C-4B25-9E01-05FDBA4DA438} => C:\Windows\system32\pcalua.exe -a D:\DXREDIST\DXSETUP.exe -d D:\DXREDIST
Task: {20004A63-9B91-4220-ACC6-4AF825A114C7} - System32\Tasks\{08044EBB-3687-401F-A611-C2E1D39794B4} => C:\Windows\system32\pcalua.exe -a F:\DWA-142_drv_A1_Utility_v1.40b02(0606144500)\DWA-142_A1_Utility_v1.40b02(0606144500)\DWA-142_A1_Utility_v1.40b02\Setup.exe -d F:\DWA-142_drv_A1_Utility_v1.40b02(0606144500)\DWA-142_A1_Utility_v1.40b02(0606144500)\DWA-142_A1_Utility_v1.40b02
Task: {20227FA3-17FA-4B24-AA8D-2F8672FDDD08} - System32\Tasks\{654FFF4C-3957-4952-A1BB-7A47EF5E1919} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {228AE85A-7A1E-4A66-A811-AF67D0E87666} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {2291B476-DD07-49F3-A43F-C4751DCC5C1C} - System32\Tasks\{F3F7470E-D90C-4278-A3F8-FDC762192A40} => C:\Windows\system32\pcalua.exe -a F:\redist\tages\TagesSetup.exe -d F:\redist\tages
Task: {31F30620-0364-4231-A094-AA67B995A01C} - System32\Tasks\{FAACDF59-2C69-4850-ACC2-8A291EF9475C} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {347225D0-C98C-47F0-BE84-B6DD1D0CEE08} - System32\Tasks\{8E6251B7-E6DB-477B-AAFE-07366754CEFA} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\instmsiw.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {36054A2A-4B92-448B-9FCF-0361CE6C79CF} - System32\Tasks\{5632F9C7-B1F7-4EBB-9F34-F61482F09056} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
Task: {3A68B7FC-4C44-4EB1-A60E-5EF12612EFF5} - System32\Tasks\{BB85A9AD-6699-4ACB-9E3F-34C8711E57C2} => D:\AutoRun.exe (Electronic Arts -> Electronic Arts)
Task: {406737EF-ABC3-4359-AD6E-055C4E04AC8F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {42853439-BDBE-4808-AB0D-3AFE276124DD} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe (Nero AG -> Nero AG)
Task: {44D4474C-65B7-4B35-ACD7-98A6F9215FCF} - System32\Tasks\{7185323E-173B-4368-A943-3BBEAFB274B2} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Steam\SteamApps\common\Crusader Kings II\vcredist.exe" -d "C:\Program Files (x86)\Steam\SteamApps\common\Crusader Kings II"
Task: {460FAF64-E26D-4135-9A9B-0E845B1B3018} - System32\Tasks\HP AR Program Upload - 3efef7b0a5554c26b46c841119cf07dced4ade5085aa4d638bb85897db1b8341 => C:\Program Files\HP\HP DeskJet 2130 series\bin\HPRewards.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {461C900A-B499-4C0E-B742-0CD13D9C51CD} - System32\Tasks\{A368A8A2-454E-4EB8-94D5-11E8A3CE27AD} => C:\Program Files (x86)\Age Of Empires 3\age3.exe (Microsoft Corporation -> Ensemble Studios)
Task: {467AA5F1-D86A-41C9-9E2F-2606F3D321C7} - System32\Tasks\HPCustParticipation HP DeskJet 2130 series => C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPCustPartic.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {500721F3-2D73-4A59-8FBB-24B8E6AE6999} - System32\Tasks\{C4C1345D-E2E3-4204-AB73-DC1592E0C587} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
Task: {50F8735C-8A3F-4F7F-BE19-7EF84D7B6FFB} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe
Task: {51C9C696-9B52-40EE-B9AA-1328F52AB9F0} - System32\Tasks\{1C79B00D-D173-4C3E-8DA6-75F5B99E58B3} => D:\AutoRun.exe (Electronic Arts -> Electronic Arts)
Task: {52DB3A65-99B2-4D7C-9ED3-CB3A2EBAB1EF} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
Task: {53B92958-CD29-497A-A85B-2B33B17109AE} - System32\Tasks\{E1749980-F5DA-4590-A08E-9169D40C7718} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {54824A38-D896-425C-BCF8-AA2D26679910} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {5AA10760-BE21-4D4E-9209-42C47A435442} - System32\Tasks\{5DF00143-772E-4B3B-8507-58754AE42977} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {5ED77E08-7CD3-4397-A7C3-C0229B3A7055} - System32\Tasks\{6B31736A-6278-469F-81CD-552E77A4FA59} => C:\Program Files (x86)\Steam\SteamApps\common\Gothic II\system\Gothic2.exe
Task: {6141EC76-89A0-4D8B-8D0D-48BE8ED70F64} - System32\Tasks\{CA27AFC5-F852-4F95-8316-78BC5B743824} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {6161B3D6-2460-4CF7-9B8F-2EF76385CF0C} - System32\Tasks\{30458D52-74F8-4491-B7E7-168B3D1AB90E} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {6193C9E7-577A-4897-B199-594DCB1F18E0} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
Task: {667D910E-B2B6-45DE-BA35-B5B9D65665C9} - System32\Tasks\{FCB7722A-BA79-40AF-898B-7D917CE6F157} => C:\Windows\system32\pcalua.exe -a D:\SETUP.EXE -d D:\
Task: {67A016BE-A0D4-4D3D-9569-9EECBF67BC63} - System32\Tasks\{8726F4A6-54A3-48E5-96E0-F499B2FD155B} => D:\AutoRun.exe (Electronic Arts -> Electronic Arts)
Task: {682021CC-CAE5-4FC9-93B2-628B7138926F} - System32\Tasks\{08E8A4E1-CDBC-4505-9986-7C86FDC10D2F} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {6A82FD88-7BC2-4F2A-BFE2-4D77958F6FF3} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_148_Plugin.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {6D846D37-0C9F-4E86-99CA-0F61171B961A} - System32\Tasks\{73BDECF5-8546-4BC3-AD24-3C1FA7B26EEF} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {715A9B79-8442-40E1-B970-9A97F81D5C33} - System32\Tasks\{819117DF-2C60-4580-A8D4-1F4D28EFC4F4} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {7615721C-5ECC-49D2-A437-D831B1B0A6E9} - System32\Tasks\{E1970A79-774F-459D-A24D-CF28D1CBC85E} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {79B66D6B-B4E9-43B3-9822-C5B8038B02DF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {79E17E27-1058-4F53-9FA2-0FD37D9DBCD9} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {79EC9E25-97D3-470D-9740-7876CDB57768} - System32\Tasks\{151519CA-83FB-4941-B002-0389275A7E1B} => C:\Program Files (x86)\Age Of Empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
Task: {7EE64610-BD46-4CF0-87EE-CA404F350EDE} - System32\Tasks\{25D989B4-4A84-4CEE-B65B-024D7A84254D} => D:\Autorun.exe (Electronic Arts -> Electronic Arts)
Task: {7F6312D5-2488-4AA3-8BED-9EE519CADDA4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
Task: {892DE9C3-E66A-4F9A-8E71-BF321F2A7038} - System32\Tasks\{E0F6D1F8-EAA0-4667-9D3E-59D00319068A} => D:\Risen + Patch + vylepšená čeština\Risen Patch 1.10.exe
Task: {8AB2C11B-E1FE-48E5-B6EE-350FA3E237B4} - System32\Tasks\HP AR Program Upload - a2117a7e53ab4c84b6308c4cbe7a62061eadb7dc98024e7aacd12392bbd167b4 => C:\Program Files\HP\HP DeskJet 2130 series\bin\HPRewards.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {8C497E3E-F4EC-4AC5-BC92-9D3DCF959C14} - System32\Tasks\{746E7386-F34A-4954-9FBC-31176C530B09} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
Task: {8CD3C536-867C-40E7-899C-803B21E66796} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {8D944BC7-E1C4-41B3-8830-E010C030CC8E} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {902F7F26-B353-401F-99DF-193CEC380E9D} - System32\Tasks\{26EE770A-BCB5-4873-8D93-4DF4C0D09DBC} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {931DFD35-68FF-4794-9B63-2D0DE7F93AE5} - System32\Tasks\{DC772FFA-4A6E-4CCE-9DDA-64C517F4838D} => C:\Windows\system32\pcalua.exe -a "C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9T6CLWC5\hoi3_1.4.exe" -d C:\Users\Administrator\Desktop
Task: {98E57C38-C4CD-49D7-AEFF-5D2700809D68} - System32\Tasks\AdobeAAMUpdater-1.0-ADMIN-PC-Administrator => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {98FC3BE4-6621-4C39-B497-657CAEB28DD8} - System32\Tasks\{A3CC4A88-C591-4B54-AF4F-BFCC37B411B0} => D:\Autorun.exe (Electronic Arts -> Electronic Arts)
Task: {9C2B3EF7-5BAD-4C20-93A4-544426E7CC18} - System32\Tasks\{15036C21-3ACC-43B7-970B-A5AB6646F0C9} => C:\Program Files\CCleaner\CCleaner64.exe
Task: {9F3D494F-2DD5-4A14-829C-6E425A1E03B5} - System32\Tasks\{53F756DB-A046-428F-9044-F0F579A12653} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{CE244E07-B58F-4140-806F-34FB0CDDE8CA}\setup.exe" -d "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sega\Medieval II Total War Kingdoms" -c -runfromtemp -l0x0005
Task: {9F55B887-85F7-48E8-A7CA-AB0A0A98E2BF} - System32\Tasks\{978A0DA8-914E-48CB-9195-4078DEAF33C1} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Heroes of Might and Magic V - Tribes of the East\heroes_might_magic_5_3.01_cz.exe" -d "C:\Program Files (x86)\Ubisoft\Heroes of Might and Magic V - Tribes of the East"
Task: {A15664A1-C95A-48E4-AC4D-0A40254CCDF4} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {A37BB895-3ECB-405A-AEC1-474582D89CA0} - System32\Tasks\{BF0A20F3-0C2A-476C-9EAA-7D2C55E452D0} => D:\Risen + Patch + vylepšená čeština\Risen Patch 1.10.exe
Task: {A4C73A2E-EAF3-4341-B33C-94F0508C1168} - System32\Tasks\SUPERAntiSpyware Scheduled Task 9d2d795a-b34c-49d3-814c-de6cf94ec229 => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com)
Task: {B3F0CCB0-A727-43AA-9A69-CBBC6E56C387} - System32\Tasks\{1FE2674D-69E3-4531-BBEC-BE1CA3AF32E8} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {B5410806-C4F3-49D2-BA76-5785D26B88E5} - System32\Tasks\{1B207D06-99EA-49AE-9B2D-294F5902BC4C} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Alien Swarm\bin\addoninstaller.exe" -d "C:\Program Files (x86)\Steam\SteamApps\common\GarrysMod\garrysmod" -c C:\PROGRA~2\Steam\STEAMA~1\common\GARRYS~1\GARRYS~1\GARRYS~2.VPK
Task: {B6DF8D4B-C7B3-47AE-B8E7-ED919CD1A0DA} - System32\Tasks\{BF2DF2C2-1ECE-4CE7-AA23-E5D0BA0A06E4} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {B98D59AA-E7E0-4F45-9385-FB965E41C131} - System32\Tasks\Opera scheduled Autoupdate 1530486457 => C:\Users\Administrator\AppData\Local\Programs\Opera\launcher.exe
Task: {BA8CAC91-7C48-467F-90CA-EB3B8B113FE7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {BAA8B25F-7BCF-4498-9650-94DA9FF9E79B} - System32\Tasks\HPCustPartic.exe_{409651EB-2226-4C5E-BA50-7120A5269552} => C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPCustPartic.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {BDEA8E13-BC13-42D3-BADC-8C84FA900CFC} - System32\Tasks\{4D240894-076B-4C12-8648-D6BF9A23F377} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\Sims3EP02Setup.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {C6D6692F-78A4-40F1-B259-98FCB1462A17} - System32\Tasks\{32463B7F-F502-47E9-9143-A735E29B1503} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {C9530638-2B67-4336-9CBE-E7E8D670896E} - System32\Tasks\{98590E16-2005-47C7-A828-946948897037} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {CA32004C-6DD3-40AB-B41F-CD9D1087841C} - System32\Tasks\{7217401C-EE41-49C7-9B37-26EEE26221AF} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
Task: {CB249EC1-00BF-4718-BBF4-463D7AE12CB7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {CFDFB350-E83D-41FD-B1E3-B6640530D538} - System32\Tasks\{57C902FD-F38C-458A-8CAA-5A277FBA08CB} => C:\Program Files (x86)\Steam\steamapps\common\Empire Total War\Empire.exe
Task: {D06270C6-9179-4B62-8F62-0D952F70F89C} - System32\Tasks\{46BB9BC9-5504-4F9A-9146-98899054FB43} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
Task: {D26005B3-E9CA-4160-83A7-CD582622C48E} - System32\Tasks\{28A2DC60-0511-4AA5-A6B3-08257BC60EF0} => C:\Program Files (x86)\Lionhead Studios Ltd\The Movies\Movies.exe
Task: {D5E8E47D-F3EC-4F82-B42F-FA95291F4717} - System32\Tasks\{E37B2754-3634-4603-99D3-77DF90A15555} => C:\Program Files (x86)\Age Of Empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
Task: {DAF12EA7-D22B-44BA-A0A2-D1087FDC671A} - System32\Tasks\{51C41640-BE40-40E9-BA66-756505B87FE5} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {E3B2EC09-8EDC-4498-A505-83E88589F0C0} - System32\Tasks\{4805FB4B-9F97-4F6F-9C79-B23921F99D75} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\setup.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {EA7F8B55-7960-4E20-8DD8-0A75194CA695} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {ECC58CBC-C99B-44E6-8EDE-BC060BB24E9A} - System32\Tasks\{E78E862C-9149-4E0A-88CC-990E9FE22638} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {F1817AE5-F9A6-453B-BA6E-117B53125071} - System32\Tasks\{728C7FD9-30FD-4B5B-8F3E-8C22DADF8C6B} => D:\Autorun.exe (Electronic Arts -> Electronic Arts)
Task: {F2A89620-66EE-4B8C-B43E-93161ED0EE5D} - System32\Tasks\{832C4EA8-933D-4170-90C5-94DAEBFE1C13} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {FA3F1A23-F6D4-4716-B652-BDF0740E79C2} - System32\Tasks\{285B9AA6-8812-4D13-9D91-355216778D5F} => C:\Program Files (x86)\Steam\SteamApps\common\Empire Total War\Empire.exe
Task: {FB1AB947-7951-4ACD-9D1D-A2085A4FE933} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
Task: {FBE09F3D-BE9D-4CE9-8B29-8A49F5DA837B} - System32\Tasks\{C0A70CD7-9EB1-47A1-A89B-FBAB93237DF7} => D:\Autorun.exe (Electronic Arts -> Electronic Arts)
Task: {FDC58DD5-D1B1-4375-92E2-CAEA8588A1C0} - System32\Tasks\SUPERAntiSpyware Scheduled Task e0753663-4f82-43bb-9fee-97b95ff7ab79 => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9d2d795a-b34c-49d3-814c-de6cf94ec229.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e0753663-4f82-43bb-9fee-97b95ff7ab79.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\Wise Care 365.job => C:\anivir\Wise Care 365\WiseTray.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]

==================== Loaded Modules (Whitelisted) ==============

2017-06-12 15:34 - 2017-06-12 15:34 - 000121856 _____ (Advanced Micro Devices) [File not signed] C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
2017-06-12 15:49 - 2017-06-12 15:49 - 000851456 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\CNext\CNext\atiacm64.dll
2017-06-12 15:49 - 2017-06-12 15:49 - 000005120 _____ (Advanced Micro Devices, Inc.) [File not signed] C:\Program Files\AMD\CNext\CNext\atiamcsy.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\24502910.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\24502910.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2019-03-06 14:08 - 000000076 _____ C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost
0.0.0.1 mssplus.mcafee.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-257039076-1346926551-2253569639-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Helena\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-257039076-1346926551-2253569639-500\Control Panel\Desktop\\Wallpaper -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-257039076-1346926551-2253569639-500.bak\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-257039076-1346926551-2253569639-501\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.112.1.1 - 10.112.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

MSCONFIG\Services: MBAMService => 2
MSCONFIG\startupfolder: C:^Users^Administrator^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GameRanger.lnk => C:\Windows\pss\GameRanger.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Administrator^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Odeslat do OneNote.lnk => C:\Windows\pss\Odeslat do OneNote.lnk.Startup
MSCONFIG\startupreg: BDRegion => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: DAEMON Tools Pro Agent => "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
MSCONFIG\startupreg: LGODDFU => C:\Program Files (x86)\lg_fwupdate\lgfw.exe blrun
MSCONFIG\startupreg: Raptr => "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{BEA15B44-EA55-4145-ADA8-74F50907E605}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe (Ubisoft Entertainment Sweden AB -> Ubisoft)
FirewallRules: [{F49F752B-0C5A-4043-ADF2-C2F9D8A0FE65}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe (Ubisoft Entertainment Sweden AB -> Ubisoft)
FirewallRules: [{28D78379-A2AC-4B6A-BC37-F739C73EF18E}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
FirewallRules: [{92246CC2-E162-4CA6-B833-AE95D8F29487}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
FirewallRules: [{236F6004-510D-49D2-9C4C-9877F3BC3946}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
FirewallRules: [{A1140A13-2AA6-4439-A168-E0FA543E07A7}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
FirewallRules: [{70B338D4-8349-4DC1-B3FB-C893D00B3967}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\InitEngine.exe (Related Designs Software -> ) [File not signed]
FirewallRules: [{1C0181AE-5AF0-4A6B-9933-6AF4578E97E2}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\InitEngine.exe (Related Designs Software -> ) [File not signed]
FirewallRules: [{2F203CD0-60F6-4487-90F8-01FBE47FC961}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\Anno4.exe (Related Designs Software -> Related Designs)
FirewallRules: [{2DE102A3-5991-4C06-BA0E-111ACC705656}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\Anno4.exe (Related Designs Software -> Related Designs)
FirewallRules: [{A1F79440-7484-4990-92ED-74E5025FBAA1}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\Addon.exe (Related Designs Software -> Related Designs)
FirewallRules: [{04D03832-6D62-40ED-A2F8-1919A6E1965E}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\Addon.exe (Related Designs Software -> Related Designs)
FirewallRules: [{7C4586C6-64CC-4E15-974F-C31DFC095D05}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\Anno4Web.exe (Related Designs Software -> )
FirewallRules: [{15716AD2-0655-421A-BD62-9FA15E4B4FC7}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\Anno4Web.exe (Related Designs Software -> )
FirewallRules: [{F9AFB658-13F0-4CE8-A634-9A10C1F367A4}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\AddonWeb.exe (Related Designs Software -> )
FirewallRules: [{C3E18BC7-1492-440A-AC8F-9A9DF279968B}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\AddonWeb.exe (Related Designs Software -> )
FirewallRules: [{F4E8E005-797B-46FC-81AB-EC6ED30861A4}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\Benchmark.exe (Related Designs Software -> )
FirewallRules: [{F51FB61F-8F45-42BC-A938-49EB651CEB37}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\Benchmark.exe (Related Designs Software -> )
FirewallRules: [{C9096135-5777-4830-B8E0-C3E6ED24313E}] => (Allow) C:\Program Files (x86)\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe (Limbic Entertainment GmbH -> Black Hole Entertainment)
FirewallRules: [{EEA4E85C-904C-4349-8818-5EDEB403DFDC}] => (Allow) C:\Program Files (x86)\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe (Limbic Entertainment GmbH -> Black Hole Entertainment)
FirewallRules: [TCP Query User{985065B0-EA84-4D09-9948-447AC0BC7A47}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\anno4web.exe] => (Block) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\anno4web.exe (Related Designs Software -> )
FirewallRules: [UDP Query User{B518CA44-4DDE-4239-8676-30791E517AA6}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\anno4web.exe] => (Block) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\anno4web.exe (Related Designs Software -> )
FirewallRules: [{49AFDB75-E204-4A8C-B31D-7BAFCAD9DDFC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{3BAE2C44-1F4F-4FEC-9D89-FB7C90094D49}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{FA10FF74-CE3F-4BDC-8EBD-183723D9E650}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{BF5FB0A0-0762-432E-9BF7-2E32AF0B8F99}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{4AAD513A-0CE3-4CDB-85A4-F0F66C1A63B5}] => (Allow) C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
FirewallRules: [{24D8CAFD-65F4-4118-9830-02E0DB44DC38}] => (Allow) C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
FirewallRules: [TCP Query User{28ED862D-0A75-4BB0-8AB1-1E7EDADE347D}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\addonweb.exe] => (Block) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\addonweb.exe (Related Designs Software -> )
FirewallRules: [UDP Query User{234FB3A0-66F6-4BF7-99E5-325A3275D6B2}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\addonweb.exe] => (Block) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\addonweb.exe (Related Designs Software -> )
FirewallRules: [{743747BE-745A-41D3-B659-B1A684AA794F}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
FirewallRules: [{52846B5F-187B-4F1C-B0DF-358C885A3556}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
FirewallRules: [{7ACA7CF5-5648-4516-B900-E32AEE51A603}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
FirewallRules: [{A79F0249-8D30-4AB0-9F13-73B2BDD69E95}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
FirewallRules: [{1EB5E209-0FD9-47AD-917F-BD7C0E73DE2A}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\InitEngine.exe (Related Designs Software -> ) [File not signed]
FirewallRules: [{E75F2D6E-F57A-4C8B-B7FB-8814F19DEE1D}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\InitEngine.exe (Related Designs Software -> ) [File not signed]
FirewallRules: [TCP Query User{8BC3D5C3-530F-43BF-9E55-E8F42BD36B53}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\addon.exe] => (Allow) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\addon.exe (Related Designs Software -> Related Designs)
FirewallRules: [UDP Query User{EC753F73-60ED-47D0-BBCC-E8F204C1A6D8}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\addon.exe] => (Allow) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\addon.exe (Related Designs Software -> Related Designs)
FirewallRules: [TCP Query User{1C9F73D7-55DD-4604-A763-547883A6734E}C:\program files (x86)\age of empires 3\age3y.exe] => (Allow) C:\program files (x86)\age of empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{E6ED9DC6-D0C8-4AA6-B926-62E3AA345FD4}C:\program files (x86)\age of empires 3\age3y.exe] => (Allow) C:\program files (x86)\age of empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{92F473F0-3C42-48EB-8616-DB8C5CF5FB0D}C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe] => (Allow) C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe (Team 17 Ltd) [File not signed]
FirewallRules: [UDP Query User{D7758813-EF46-41DF-9F00-4F6ADBE36120}C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe] => (Allow) C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe (Team 17 Ltd) [File not signed]
FirewallRules: [{88E70ABE-3A7A-4931-8CCC-5777FBB48E1F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Neighbours from Hell\bin\game.exe (JoWooD Studio Vienna) [File not signed]
FirewallRules: [{BA93AC7F-6EF7-44F2-B372-48BD5D9EF752}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Neighbours from Hell\bin\game.exe (JoWooD Studio Vienna) [File not signed]
FirewallRules: [{6E6D5AE8-F635-498E-B2BE-C6F5125BD3DF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Neighbours from Hell 2\bin\game.exe (JoWooD Studio Vienna) [File not signed]
FirewallRules: [{50C6396B-AD26-4222-A2E4-3E26353E0B36}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Neighbours from Hell 2\bin\game.exe (JoWooD Studio Vienna) [File not signed]
FirewallRules: [{959F1030-AFC8-4C70-A914-2835554059E5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe (CyberLink -> CyberLink Corp.)
FirewallRules: [{FA897948-1CE6-4C02-A12A-D01225A11E7F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE (CyberLink -> CyberLink Corp.)
FirewallRules: [{DD3C6F52-6AF5-4683-AF31-281309C5E1C2}] => (Allow) C:\Users\Administrator\AppData\Roaming\uTorrent\utorrent.exe No File
FirewallRules: [{FDB85F1C-BF09-4ADB-82B1-C4FA7CFBE052}] => (Allow) C:\Users\Administrator\AppData\Roaming\uTorrent\utorrent.exe No File
FirewallRules: [{792BE7CE-54F1-4B09-A3BB-B1721EF1FC71}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe (Nero AG -> Nero AG)
FirewallRules: [{DA876E1F-91C2-49E2-8AAD-93EB70512E8D}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe (Nero AG -> Nero AG)
FirewallRules: [{CE5EF173-61F7-403D-8928-73F2FA985A4D}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe (Nero AG -> Nero AG)
FirewallRules: [{FC41B5C4-A076-48AD-B3CD-709877F781D7}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe (Nero AG -> Nero AG)
FirewallRules: [TCP Query User{C800931B-FA4C-4694-BB74-A4956C95265A}C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe] => (Allow) C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe (Team 17 Ltd) [File not signed]
FirewallRules: [UDP Query User{3B12D9CA-6EFD-459A-8A0E-C0ACF67EEAB8}C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe] => (Allow) C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe (Team 17 Ltd) [File not signed]
FirewallRules: [TCP Query User{A33FD36D-9EED-428F-8E5C-7CE5487A9E63}C:\program files\armies of exigo\exigo.exe] => (Allow) C:\program files\armies of exigo\exigo.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [UDP Query User{D064A652-5467-48AA-A5F6-9822C977D90D}C:\program files\armies of exigo\exigo.exe] => (Allow) C:\program files\armies of exigo\exigo.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [TCP Query User{079285FE-5818-43A2-A84B-40FBF2D1AE6A}C:\program files (x86)\ubisoft\heroes of might and magic v - tribes of the east\bin\h5_game.exe] => (Allow) C:\program files (x86)\ubisoft\heroes of might and magic v - tribes of the east\bin\h5_game.exe (Nival Interactive, Inc -> )
FirewallRules: [UDP Query User{A6DA11BD-42BF-4103-A1EF-FDD9A024CA41}C:\program files (x86)\ubisoft\heroes of might and magic v - tribes of the east\bin\h5_game.exe] => (Allow) C:\program files (x86)\ubisoft\heroes of might and magic v - tribes of the east\bin\h5_game.exe (Nival Interactive, Inc -> )
FirewallRules: [TCP Query User{94FB354C-B1ED-4CFC-BCB9-A94C6460BAA3}C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe] => (Block) C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe () [File not signed]
FirewallRules: [UDP Query User{E695E9DD-BB10-4A09-B909-2C12224CB70F}C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe] => (Block) C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe () [File not signed]
FirewallRules: [TCP Query User{96F8DB11-543C-455E-8BF3-6AAEE3AF1F98}C:\windows\syswow64\dplaysvr.exe] => (Block) C:\windows\syswow64\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{F62DD7FD-1344-4C79-ACBA-14E4CBCA6F9F}C:\windows\syswow64\dplaysvr.exe] => (Block) C:\windows\syswow64\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{1998C22A-6517-424F-B832-9A5CF06E8121}C:\program files\castle strike\castlestrike.exe] => (Allow) C:\program files\castle strike\castlestrike.exe (Related Designs Software GmbH) [File not signed]
FirewallRules: [UDP Query User{36EBA28E-72BE-40A0-A8CF-69B3614C5B26}C:\program files\castle strike\castlestrike.exe] => (Allow) C:\program files\castle strike\castlestrike.exe (Related Designs Software GmbH) [File not signed]
FirewallRules: [TCP Query User{09D7471D-3A6A-4DF7-8C67-76D264F45678}C:\program files (x86)\age of empires 3\age3x.exe] => (Allow) C:\program files (x86)\age of empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
FirewallRules: [UDP Query User{AE3C9E3C-3A0E-434B-94E2-309DB22BF232}C:\program files (x86)\age of empires 3\age3x.exe] => (Allow) C:\program files (x86)\age of empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
FirewallRules: [TCP Query User{6A684956-549A-4D1D-A351-335692EE8B75}C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe] => (Block) C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe () [File not signed]
FirewallRules: [UDP Query User{B8C63F59-9944-4B77-8CF8-8A6549D4C263}C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe] => (Block) C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe () [File not signed]
FirewallRules: [TCP Query User{DAB239BB-DBFF-4DA8-A30B-4AF61EA19139}C:\program files\armies of exigo\exigo.exe] => (Block) C:\program files\armies of exigo\exigo.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [UDP Query User{29E5F875-F19C-4AE6-9811-43657E62FB01}C:\program files\armies of exigo\exigo.exe] => (Block) C:\program files\armies of exigo\exigo.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [{F3730381-490D-4678-A27B-5984F1D76D7F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe () [File not signed]
FirewallRules: [{19141D14-3F33-4906-8EE0-4C03772C4931}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe () [File not signed]
FirewallRules: [{9DEE1F3A-9D01-45F9-AE41-16C18C81BBC0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SourceFilmmaker\game\sfm.exe () [File not signed]
FirewallRules: [{706AFA49-0009-4F8F-8A4F-A26C2C413720}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SourceFilmmaker\game\sfm.exe () [File not signed]
FirewallRules: [{0B9C3232-49AA-4C16-B850-8985D48A0383}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SourceFilmmaker\game\bin\qsdklauncher.exe () [File not signed]
FirewallRules: [{A1ED00FD-3001-483F-A411-9FF9408CC868}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SourceFilmmaker\game\bin\qsdklauncher.exe () [File not signed]
FirewallRules: [{89F8147B-0FFA-4A72-B8CB-FCA7A9079838}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5488EB57-8C72-4BFF-8659-76220678A9D7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader Extreme\Stronghold Crusader.exe ( ) [File not signed]
FirewallRules: [{A792D2A8-4403-4DAF-96D1-2C8D12637886}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader Extreme\Stronghold Crusader.exe ( ) [File not signed]
FirewallRules: [{4BDBE048-05F9-427E-9913-233D3DE5C3B7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader Extreme\Stronghold_Crusader_Extreme.exe ( ) [File not signed]
FirewallRules: [{CACABB5E-E625-492C-9675-6FCC58B8942B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader Extreme\Stronghold_Crusader_Extreme.exe ( ) [File not signed]
FirewallRules: [{336CB1A7-C4EE-4615-A88F-509701C92D2E}] => (Allow) C:\Program Files (x86)\NAMCO BANDAI Games\DarkSouls\DARKSOULS.exe (FromSoftware,Inc. -> NAMCO BANDAI Games Inc.)
FirewallRules: [TCP Query User{FEDF92D1-8720-4C90-A5E4-AE88EDE3449E}C:\program files (x86)\namco bandai games\darksouls\data.exe] => (Allow) C:\program files (x86)\namco bandai games\darksouls\data.exe (n-Space, Inc. -> NAMCO BANDAI Games Inc.) [File not signed]
FirewallRules: [UDP Query User{EBEF7C02-2FFE-4B89-B45F-F26AE7918B2B}C:\program files (x86)\namco bandai games\darksouls\data.exe] => (Allow) C:\program files (x86)\namco bandai games\darksouls\data.exe (n-Space, Inc. -> NAMCO BANDAI Games Inc.) [File not signed]
FirewallRules: [{872D8076-6A29-441E-BFD1-2FDB001BC732}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe () [File not signed]
FirewallRules: [{1FFCD96F-6EB1-4E43-98BB-3143D4479564}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe () [File not signed]
FirewallRules: [{5A464C4F-B26C-4FBF-AC9B-CA7175038A85}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Victoria 2\victoria2.exe (Paradox Interactive) [File not signed]
FirewallRules: [{DB8B71DD-5D74-4B8E-B0DC-300850C9BA10}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Victoria 2\victoria2.exe (Paradox Interactive) [File not signed]
FirewallRules: [TCP Query User{EDD3B532-F143-477C-ADF1-33EFF81801E5}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [UDP Query User{99B58E7D-6144-4BF5-A109-57E4323BED95}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [TCP Query User{C4305E5D-B0AC-4AD0-8AFA-4E96FCDFE600}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [UDP Query User{FA4D6115-7070-4618-87C0-593CBAA56ACB}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [{D451BB35-3691-4E87-B965-7F42C8B782CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe ( Taleworlds Entertainment) [File not signed]
FirewallRules: [{6D5D5F99-1171-4AA1-966B-7DC87F9F1B28}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe ( Taleworlds Entertainment) [File not signed]
FirewallRules: [TCP Query User{6CA5446F-DC25-405E-B02C-853092149EBA}C:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe () [File not signed]
FirewallRules: [UDP Query User{55942948-7F73-4481-BFC2-EAD09C033A3B}C:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe () [File not signed]
FirewallRules: [{010922A7-A153-408A-8DAC-F1C6D4626FFD}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe (Nero AG -> Nero AG)
FirewallRules: [{3037D520-8A85-42E5-B9CE-65A038415768}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe (Nero AG -> Nero AG)
FirewallRules: [{686E797B-AF28-4065-9E9E-B1E5B5983546}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe (Nero AG -> Nero AG)
FirewallRules: [{AB4E0414-8059-4F0F-8F2F-17008F02ED47}] => (Allow) C:\Program Files (x86)\Ubisoft\The Settlers 7 - CESTA KE KORUNĚ\Data\Base\_Dbg\Bin\Release\Settlers7R.exe (Blue Byte GmbH -> Blue Byte GmbH)
FirewallRules: [{25F5BE7E-8E0A-40A2-9025-AC27B4CDB83F}] => (Allow) C:\Program Files (x86)\Ubisoft\The Settlers 7 - CESTA KE KORUNĚ\Data\Base\_Dbg\Bin\Release\Settlers7R.exe (Blue Byte GmbH -> Blue Byte GmbH)
FirewallRules: [{CD19EA84-D5FE-414F-81DC-EA4840C67FD4}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{99DEAA28-7B30-4A0F-A7DF-BD64B327BDDF}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{89CD386B-BA42-404D-9E52-0002D57330ED}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe No File
FirewallRules: [{73E2728A-B45F-42D1-BF39-5E190A46E1D7}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe No File
FirewallRules: [{A68836BF-68D5-4F6A-A0FE-FB295ECC7F94}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{093E297B-91B8-4214-A12E-CA3E905A361B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{A2D78074-AAB7-4DFC-970D-E52F77BC6E7B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AdVenture Capitalist\adventure-capitalist.exe () [File not signed]
FirewallRules: [{4C9644D3-E787-4DAA-B271-9D034A036D11}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AdVenture Capitalist\adventure-capitalist.exe () [File not signed]
FirewallRules: [{B4D8FE70-8E56-4FAC-B112-D6ACE9C24AD2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\iambread\IamBread.exe (Unity Technologies SF -> ) [File not signed]
FirewallRules: [{1184F69A-65AA-41CA-9AE1-6708D11706E6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\iambread\IamBread.exe (Unity Technologies SF -> ) [File not signed]
FirewallRules: [{0F64D39D-FAF5-49D6-AB0C-352889F6FCF4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Apotheon\Apotheon.exe (Microsoft) [File not signed]
FirewallRules: [{061989DC-4176-4C45-9DCC-E12135418C6B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Apotheon\Apotheon.exe (Microsoft) [File not signed]
FirewallRules: [{61916A64-7406-4CEC-830F-30A323B78C83}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Guild 2 Renaissance\GuildII.exe (Runeforge Game Studio) [File not signed]
FirewallRules: [{4191FDC6-2AB3-47F2-969F-D54F3FDA8E48}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Guild 2 Renaissance\GuildII.exe (Runeforge Game Studio) [File not signed]
FirewallRules: [{BB30FFFD-4F78-48BC-ADB0-411B99F834E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Guild II - Pirates of the European Seas\GuildII.exe (4HEAD Studios) [File not signed]
FirewallRules: [{BF6419CD-BF24-42C2-AD8E-D72E63580113}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Guild II - Pirates of the European Seas\GuildII.exe (4HEAD Studios) [File not signed]
FirewallRules: [{45B6B832-6E77-4783-AC35-EF78B6FD1D63}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rock of Ages\Binaries\Win32\RoA.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{089F4BF1-254A-457D-9E55-05E6A1B2542F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rock of Ages\Binaries\Win32\RoA.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{84FC1AE5-610A-4262-BF8A-BFB685E5C163}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{60A61548-FE89-4EE8-86C2-9A8A22A80466}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{13D7323E-6794-4573-9FEF-1554C43863CA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AC22260F-443C-484D-AAC0-1BF3E9206B22}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CEF1AAB3-EB49-4866-A18C-E9A5E4216F5E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Might and Magic Heroes VII\Binaries\Win64\MMH7Game-Win64-Shipping.exe (Limbic Entertainment GmbH -> Ubisoft, Inc.)
FirewallRules: [{4ADF479A-134E-4F42-B779-B9610B3D782B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader 2\bin\win32_release\Crusader2.exe () [File not signed]
FirewallRules: [{8C3868F1-A06C-4002-844A-03913860E93E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader 2\bin\win32_release\Crusader2.exe () [File not signed]
FirewallRules: [{9BA1A3A3-E14F-4361-B1E4-CED7060C0FB2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas enplczru\FalloutNVLauncher.exe (Bethesda Softworks, Obsidian Entertainment) [File not signed]
FirewallRules: [{0A69DC94-8EE9-4CD3-AF47-43D550474BF2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas enplczru\FalloutNVLauncher.exe (Bethesda Softworks, Obsidian Entertainment) [File not signed]
FirewallRules: [{733A54AC-B9F1-49F7-B6AF-5662AA9327C6}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7812706A-B4D0-4B21-8302-90B08E8700AC}] => (Allow) LPort=2869
FirewallRules: [{2CC193C1-6D7C-48E2-BC7E-22C6B8F17323}] => (Allow) LPort=1900
FirewallRules: [{D062E605-9018-4C9F-B884-326F95BB2E28}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa 1400 The Guild - Gold Edition\Europa1400Gold.exe () [File not signed]
FirewallRules: [{55952F7D-EF02-4CEB-90AC-A4F267878AB4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa 1400 The Guild - Gold Edition\Europa1400Gold.exe () [File not signed]
FirewallRules: [{119BD324-E3F4-4977-96F4-74B4C7601E26}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa 1400 The Guild - Gold Edition\Europa1400Gold_TL.exe () [File not signed]
FirewallRules: [{2F26E480-2553-4D25-AB33-5FDE7A9EEEBC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa 1400 The Guild - Gold Edition\Europa1400Gold_TL.exe () [File not signed]
FirewallRules: [{D390311F-35A4-47CF-A52B-18D9B7DE2CAC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{6F85A45C-C855-43F5-B63E-9968781A8DD6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{EFBDABBC-E5C9-4AC1-B0F5-054281F09607}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{10591F70-AECC-4E24-8BEB-D128F2421FAA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{6696B94F-B0E6-44FA-B0DA-15EA07B53489}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sengoku\Sengoku.exe (Paradox Interactive) [File not signed]
FirewallRules: [{26F65DB8-02F9-437B-9B43-2E61EAEBFE5F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sengoku\Sengoku.exe (Paradox Interactive) [File not signed]
FirewallRules: [TCP Query User{3B72941E-6534-443C-B4D8-51646F552A41}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe No File
FirewallRules: [UDP Query User{9287E7E8-5037-4629-B719-AD2F62B30C1C}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe No File
FirewallRules: [{3F4F200E-E157-4B4E-8D67-E7648D7374F4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Haunt the House Terrortown\HauntTheHouseTerrortown.exe () [File not signed]
FirewallRules: [{236E56A2-02D5-4288-895A-FC13657FBFE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Haunt the House Terrortown\HauntTheHouseTerrortown.exe () [File not signed]
FirewallRules: [{167E6F72-D70C-4B28-8635-64896E17002F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PlagueInc\PlagueIncEvolved.exe () [File not signed]
FirewallRules: [{D4A03C79-6FCF-4E5C-B524-D862D98D01AE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PlagueInc\PlagueIncEvolved.exe () [File not signed]
FirewallRules: [TCP Query User{1F9C43EF-7928-47EA-8CC2-18DF91C90664}C:\program files (x86)\steam\steamapps\common\life is strange\binaries\win32\lifeisstrange.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\life is strange\binaries\win32\lifeisstrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [UDP Query User{4C93E747-EDF5-43BB-A80E-D7F6A8D20170}C:\program files (x86)\steam\steamapps\common\life is strange\binaries\win32\lifeisstrange.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\life is strange\binaries\win32\lifeisstrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{99AA2B2F-E91D-4554-8E0D-0EFA4F006C25}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{4C230EA1-3209-46B1-841F-ED1C20712590}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{70425B0D-CCF0-4B2B-A0A8-1F40F4485532}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis IV\eu4.exe (Paradox Interactive) [File not signed]
FirewallRules: [{78992616-1DB6-4E12-92E8-EF84662CCC17}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis IV\eu4.exe (Paradox Interactive) [File not signed]
FirewallRules: [{B771F328-B1CA-427D-A60A-A4C581EA56FF}] => (Allow) C:\Program Files\HP\HP DeskJet 2130 series\Bin\USBSetup.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
FirewallRules: [{1BF26DE9-E742-4788-AFEA-1DF14359B512}] => (Allow) C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPNetworkCommunicatorCom.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
FirewallRules: [{EC37AB6E-1F03-41A1-8687-F90E25A8750F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{FA1C9A6B-E12B-407C-9760-0A61D3188723}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{F1B7BD0F-5A29-44DA-A00B-D2A31AAA5DFA}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{F6E8E4B6-51C2-4B94-B01C-F5974294D39D}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{8A018B69-DBA9-43BA-9A32-A28F45562E4E}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{0835B4FC-82BA-41A9-B607-6BF90CB787EF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{263AC93E-3C68-4A71-95D3-BC8485B5A425}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Omerta\OmertaSteam.exe (Haemimont Games) [File not signed]
FirewallRules: [{6B749B4D-3E70-49BC-A73D-968E5C50B72E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Omerta\OmertaSteam.exe (Haemimont Games) [File not signed]
FirewallRules: [{E4A53436-6563-4133-AC00-F0EC60F33A3E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Northgard\Northgard.exe () [File not signed]
FirewallRules: [{71F8EE52-CE93-450E-8834-5BDF516D4971}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Northgard\Northgard.exe () [File not signed]
FirewallRules: [{F7C19ACC-9466-4AEC-913B-318A1F23C962}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909\SZBrowser.exe (AVAST Software s.r.o. -> Avast Software)
FirewallRules: [{34D36860-60E2-4700-A124-87FB3F575B6B}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe (AVAST Software s.r.o. -> Avast Software)
FirewallRules: [{8FE888BD-1230-4D5B-8BF6-27395D543556}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [{C7D4F23F-AFB3-4F9F-981D-AFCF901E1572}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [{AEA1ED7B-4B07-437C-B6C1-72D99D17CF8A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Crusader Kings II\CK2game.exe (Paradox Interactive) [File not signed]
FirewallRules: [{FD5BD9E0-9F7F-42E5-ADC8-8928C709F644}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Crusader Kings II\CK2game.exe (Paradox Interactive) [File not signed]
FirewallRules: [{10C184DF-D9BB-440D-A63A-9F99B1F4EB7F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risen 3\system\Risen3.exe No File
FirewallRules: [{D5D4460B-46A6-4F66-BBC1-F4639C608D9B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risen 3\system\Risen3.exe No File
FirewallRules: [{2F922116-61DD-4ED9-A2A7-C9E1AE071D12}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe (Raptr, Inc -> Raptr, Inc)
FirewallRules: [{364E8C79-1A98-41A2-95B7-CD6AF0CEE637}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe (Raptr, Inc -> Raptr, Inc)
FirewallRules: [{37A845B1-BFD2-4296-9953-96B1BE93954E}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe (Raptr, Inc -> Raptr, Inc)
FirewallRules: [{CFA73B55-CC9F-47EF-9B5E-03DD63E36759}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe (Raptr, Inc -> Raptr, Inc)
FirewallRules: [{37BC8AEE-7516-4CB9-A884-38D2D630C82A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{630B6A78-DCAC-48C5-B2FF-C12F3239F79D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{40C6F70D-6A5A-481E-A036-BF39EE3F6E2E}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9E1029F3-074C-4042-96C9-1A82835F6D78}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{B4BBD48D-01EF-40FD-90F9-FA2F4E2A6120}C:\program files (x86)\namco bandai games\darksouls\data.exe] => (Allow) C:\program files (x86)\namco bandai games\darksouls\data.exe (n-Space, Inc. -> NAMCO BANDAI Games Inc.) [File not signed]
FirewallRules: [UDP Query User{205714A3-9EE7-4CE8-A5A6-D1D59D488E11}C:\program files (x86)\namco bandai games\darksouls\data.exe] => (Allow) C:\program files (x86)\namco bandai games\darksouls\data.exe (n-Space, Inc. -> NAMCO BANDAI Games Inc.) [File not signed]
FirewallRules: [{F0BDF583-485E-4939-A2BF-203866647A21}] => (Allow) C:\Users\Administrator\AppData\Local\Programs\Opera\54.0.2952.41\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{9DE3FE1E-3486-4C46-A12D-8FE0E23A7377}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored RHCP\Binaries\Win32\Dishonored.exe No File
FirewallRules: [{3CE6FEA6-8AC7-4530-A17E-3721D5F086CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored RHCP\Binaries\Win32\Dishonored.exe No File
FirewallRules: [{43EF8F19-460A-4E44-851C-9C718E6468A2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hearts of Iron IV\hoi4.exe (Paradox Interactive) [File not signed]
FirewallRules: [{085DB354-DC3C-4D18-9DB4-E8413E8524A2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hearts of Iron IV\hoi4.exe (Paradox Interactive) [File not signed]
FirewallRules: [{6077F240-33D7-447D-B3CD-5F6A0076D735}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe No File
FirewallRules: [{70FE99BD-7C5E-45EB-9F4B-7166C1C9DC5C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe No File
FirewallRules: [{7A65586A-6D29-48FA-AAB5-D86CEDA446E4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe No File
FirewallRules: [{05664B60-AC37-4498-818C-193F3572D159}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe No File
FirewallRules: [TCP Query User{922B11E9-EB8F-4E81-B2FD-E70CD6547999}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe No File
FirewallRules: [UDP Query User{9368DB39-1DBE-4A3E-9706-469EF7786755}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe No File
FirewallRules: [{88275BB5-D4DD-4DE1-9613-A3CE269135F0}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{02CD6587-26D7-4B4C-86D9-FF717F993569}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{1B2B277E-3EF7-464E-9FAC-1ECAA5931FD4}] => (Allow) C:\Users\Administrator\AppData\Local\Temp\7zS1A30\HPDiagnosticCoreUI.exe (HP Inc. -> HPDC LP)
FirewallRules: [{2FC43F6C-4153-4307-BF8C-10CF5BEC0589}] => (Allow) C:\Users\Administrator\AppData\Local\Temp\7zS1A30\HPDiagnosticCoreUI.exe (HP Inc. -> HPDC LP)
FirewallRules: [{1C03940A-5EFA-4795-B913-320F0D001739}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{BEB74CF6-B113-4868-AADB-23A0DD9CAA48}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{CD2896DF-F83A-4EB9-AF20-A2B288C50F44}] => (Allow) C:\Users\Administrator\AppData\Local\Temp\7zS3F45\HPDiagnosticCoreUI.exe (HP Inc. -> HPDC LP)
FirewallRules: [{9E663F95-0209-4E07-AAF0-F7A9CB78BC63}] => (Allow) C:\Users\Administrator\AppData\Local\Temp\7zS3F45\HPDiagnosticCoreUI.exe (HP Inc. -> HPDC LP)
FirewallRules: [TCP Query User{B9F42142-5F81-4DA3-B982-1FB8E12C5355}C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe] => (Allow) C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe (Ubisoft Entertainment SA -> )
FirewallRules: [UDP Query User{5F3889A2-D01D-408C-BE0D-7136B9F61AD1}C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe] => (Allow) C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe (Ubisoft Entertainment SA -> )
FirewallRules: [{DFC66575-DFC9-4E21-9271-123E84F4E2E4}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2FC3779C-6D12-4946-8872-555F60E42ECA}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1B86EA66-1696-45DF-9EB2-38B8ABCE104F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\LaunchPad\LaunchPad.exe No File
FirewallRules: [{AD809563-0BF9-4069-89A8-53E03BBB95F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\LaunchPad\LaunchPad.exe No File
FirewallRules: [TCP Query User{0D0202A2-A39B-4A66-8F91-5FB106CCD2A1}C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe (Ubisoft Entertainment -> )
FirewallRules: [UDP Query User{B4DC2CCE-4889-483D-A6AA-737B8A0B270B}C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe (Ubisoft Entertainment -> )
FirewallRules: [{2AF37A29-C0BA-4933-A53B-41D681A9BA86}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe () [File not signed]
FirewallRules: [{C5D1BBAD-2610-4CBF-9A92-CDB3C0F574EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe () [File not signed]
FirewallRules: [TCP Query User{623E30DE-D980-4C37-828F-9168FB4346AA}C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe (The Creative Assembly Limited -> The Creative Assembly Ltd)
FirewallRules: [UDP Query User{16B1F275-B948-444E-B965-4C381FF9B7D3}C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe (The Creative Assembly Limited -> The Creative Assembly Ltd)
FirewallRules: [TCP Query User{FF5DAA71-36DA-475C-8F38-B7BCABDD0B4F}C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe] => (Block) C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe (The Creative Assembly Limited -> The Creative Assembly Ltd)
FirewallRules: [UDP Query User{BE9B12A1-25C5-4AFD-A65D-33C436E37E63}C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe] => (Block) C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe (The Creative Assembly Limited -> The Creative Assembly Ltd)
FirewallRules: [{65E174D2-D7EF-4F9E-9B51-E5F31F721C22}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe (QLOC S.A. -> Bethesda Softworks)
FirewallRules: [{2F81008E-0DCF-45CE-AF36-6DC9E1F0C689}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe (QLOC S.A. -> Bethesda Softworks)
FirewallRules: [{16CA4EB0-885D-4338-B121-4693ABCE15B4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V SDK\Sid Meier's Civilization V SDK.exe (Firaxis Games) [File not signed]
FirewallRules: [{47F3D35C-8C8D-4F95-B307-A20D3E3E532C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V SDK\Sid Meier's Civilization V SDK.exe (Firaxis Games) [File not signed]
FirewallRules: [{3E7781C0-6DDB-414D-BA6E-81DAF620B441}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\KB.exe () [File not signed]
FirewallRules: [{3374B9B3-E5B3-4396-9123-DE9E87156DAD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\KB.exe () [File not signed]
FirewallRules: [{C886E6EE-8F6F-4C6E-B2EA-DDB4143544C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\save_fixer.exe () [File not signed]
FirewallRules: [{FC4B0EC7-503E-490F-80E4-DB4C35753753}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\save_fixer.exe () [File not signed]
FirewallRules: [{F0932F59-A91F-4D9B-81C2-019B38076CF7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space 2\EndlessSpace2.exe () [File not signed]
FirewallRules: [{9BA90DD1-C184-4CB7-A6AD-7B678AFE9EA4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space 2\EndlessSpace2.exe () [File not signed]
FirewallRules: [{3168BDE7-D3B7-43B5-9433-12D5645CFDEF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe (FromSoftware,Inc. -> NAMCO BANDAI Games)
FirewallRules: [{BF896D5F-992A-4756-93E1-4B0A6D80EEFD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe (FromSoftware,Inc. -> NAMCO BANDAI Games)
FirewallRules: [{DC4B812D-8BAA-4259-B09A-AA0AD12CA882}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{C4F03A22-9321-455E-BD85-ADFDBDF7AD44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{D1C6E1D6-7AF9-4200-9230-4B9B8849B788}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DARK SOULS III\Game\DarkSoulsIII.exe (FromSoftware,Inc. -> BANDAI NAMCO Entertainment Inc.)
FirewallRules: [{A357B16C-589E-4472-8B9E-F4D686E0640D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DARK SOULS III\Game\DarkSoulsIII.exe (FromSoftware,Inc. -> BANDAI NAMCO Entertainment Inc.)
FirewallRules: [{FAC03FF6-6C1A-41A4-863F-C83CF907B50A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{A8847F21-CE0A-4164-8E24-6FDFE1547B7E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{9798F235-4140-4000-BA30-B07929505F74}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{132AABE4-2082-4951-9CA4-0C8D88DEAE0D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{5E97D1CA-40F8-4737-8FAC-490A284BF7B4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War WARHAMMER\launcher\launcher.exe (The Creative Assembly Limited -> Creative Assembly Ltd)
FirewallRules: [{FC122B5B-412B-4950-A0E2-1E6E6D157078}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War WARHAMMER\launcher\launcher.exe (The Creative Assembly Limited -> Creative Assembly Ltd)
FirewallRules: [{D696C22C-D26C-4F6D-98CE-F1C36D5F4435}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [{C187DFAB-236B-4FA4-9D1F-6ED1E9339F5C}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (AVAST Software s.r.o. -> AVAST Software)
FirewallRules: [{812EAF06-D81D-478D-9AB3-3CCB05066A0F}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
FirewallRules: [{BBEAC5DA-8308-489F-99AF-2229ECE7CF67}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (AVAST Software s.r.o. -> AVAST Software)

==================== Restore Points =========================

24-02-2019 19:00:21 Windows Zálohování
03-03-2019 19:00:14 Windows Zálohování
10-03-2019 19:00:26 Windows Zálohování

==================== Faulty Device Manager Devices =============

Name: Adaptér tunelového režimu Microsoft Teredo
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/10/2019 07:52:04 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.

Error: (03/10/2019 07:00:26 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny ConvertStringSidToSid(S-1-5-21-257039076-1346926551-2253569639-500.bak) došlo k neočekávané chybě. hr= 0x80070539, Struktura ID zabezpečení není platná.
.


Operace:
Událost OnIdentify
Shromažďování dat modulu pro zápis

Kontext:
Kontext spuštění: Shadow Copy Optimization Writer
ID třídy modulu pro zápis: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Název modulu pro zápis: Shadow Copy Optimization Writer
ID instance modulu pro zápis: {1dd731eb-6337-42e1-846d-1799ed4db47b}

Error: (03/10/2019 06:52:05 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.

Error: (03/10/2019 05:52:04 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.

Error: (03/10/2019 05:42:19 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (03/10/2019 05:40:51 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1505) (User: ADMIN-PC)
Description: Systém Windows nemůže načíst profil uživatele, ale byli jste přihlášeni pomocí výchozího profilu pro tento systém.

DETAIL – Přístup byl odepřen.

Error: (03/10/2019 05:40:46 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1505) (User: ADMIN-PC)
Description: Systém Windows nemůže načíst profil uživatele, ale byli jste přihlášeni pomocí výchozího profilu pro tento systém.

DETAIL – Přístup byl odepřen.

Error: (03/10/2019 04:52:06 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.


System errors:
=============
Error: (03/10/2019 05:41:22 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Plays.tv Update Service neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 12:04:34 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 12:04:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 12:04:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 12:04:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 12:04:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 12:04:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 12:04:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba eapihdrv neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.


Windows Defender:
===================================
Date: 2015-11-07 19:59:12.723
Description:
Prohledávání Windows Defender bylo zastaveno před dokončením.
ID prohledávání:{D82AC51B-8CB3-408C-825F-F9BE485EB592}
Typ prohledávání:Antispywarový program
Parametry prohledávání:Rychlé prohledávání
Uživatel:ADMIN-PC\Helena

Date: 2015-10-27 21:10:18.013
Description:
Prohledávání Windows Defender bylo zastaveno před dokončením.
ID prohledávání:{6D91FBE4-39CF-4BE3-8C0F-6F7A0FF7F976}
Typ prohledávání:Antispywarový program
Parametry prohledávání:Rychlé prohledávání
Uživatel:ADMIN-PC\Helena

Date: 2015-03-13 14:20:58.354
Description:
Prohledávání Windows Defender bylo zastaveno před dokončením.
ID prohledávání:{418C6894-C5F0-4DB9-ACAF-A7D6CB105079}
Typ prohledávání:Antispywarový program
Parametry prohledávání:Rychlé prohledávání
Uživatel:ADMIN-PC\Helena

Date: 2015-09-25 15:56:17.644
Description:
Prohledávání Windows Defender zjistilo chybu při pokusu o načtení podpisů a pokusí se o obnovení sady podpisů, jejichž správnost je potvrzena.
Podpisy, které se měly načíst:Aktuální
Kód chyby:0x80070002
Popis chyby:Systém nemůže nalézt uvedený soubor.
Verze podpisu:0.0.0.0
Verze modulu:0.0.0.0

Date: 2015-09-25 15:56:17.550
Description:
Program Windows Defender zjistil chybu při pokusu o aktualizaci.
Nová verze podpisu:
Předchozí verze podpisu:
Zdroj aktualizace:Složka aktualizace podpisů
Typ podpisu:Antispywarový program
Typ aktualizace:Delta
Uživatel:NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu:
Kód chyby:0x80070002
Popis chyby:Systém nemůže nalézt uvedený soubor.

Date: 2015-04-25 11:55:26.899
Description:
Prohledávání Windows Defender zjistilo chybu při pokusu o načtení podpisů a pokusí se o obnovení sady podpisů, jejichž správnost je potvrzena.
Podpisy, které se měly načíst:Aktuální
Kód chyby:0x80070002
Popis chyby:Systém nemůže nalézt uvedený soubor.
Verze podpisu:0.0.0.0
Verze modulu:0.0.0.0

Date: 2015-04-25 11:55:26.889
Description:
Program Windows Defender zjistil chybu při pokusu o aktualizaci.
Nová verze podpisu:
Předchozí verze podpisu:
Zdroj aktualizace:Složka aktualizace podpisů
Typ podpisu:Antispywarový program
Typ aktualizace:Delta
Uživatel:NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu:
Kód chyby:0x80070002
Popis chyby:Systém nemůže nalézt uvedený soubor.

CodeIntegrity:
===================================

Date: 2018-06-13 13:55:58.239
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-13 13:55:58.145
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-04 20:07:17.240
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atikmdag.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 20:07:17.084
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 20:06:38.630
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 20:06:38.022
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 10:32:16.410
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atikmdag.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 10:32:16.363
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz
Percentage of memory in use: 41%
Total physical RAM: 16326.67 MB
Available physical RAM: 9480.8 MB
Total Virtual: 24324.81 MB
Available Virtual: 17892.56 MB

==================== Drives ================================

Drive c: (HDD) (Fixed) (Total:931.41 GB) (Free:21.68 GB) NTFS
Drive d: (Sims3EP08) (CDROM) (Total:3.9 GB) (Free:0 GB) UDF

\\?\Volume{682e3343-6736-11e3-a7bd-806e6f6e6963}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: E1617DCA)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Děkuji předem za pomoc.
Henry0607

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#3 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#4 Příspěvek od Henry0607 »

Provedeno, log:


# -------------------------------
# Malwarebytes AdwCleaner 7.2.7.0
# -------------------------------
# Build: 01-30-2019
# Database: 2019-03-04.3 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-10-2019
# Duration: 00:00:01
# OS: Windows 7 Home Premium
# Cleaned: 1
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\.bak\Software\csastats

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2869 octets] - [13/06/2018 13:26:28]
AdwCleaner[C00].txt - [2664 octets] - [13/06/2018 13:30:05]
AdwCleaner[S01].txt - [1475 octets] - [10/03/2019 11:48:53]
AdwCleaner[C01].txt - [1621 octets] - [10/03/2019 11:49:15]
AdwCleaner[S02].txt - [1501 octets] - [10/03/2019 19:29:47]
AdwCleaner[S03].txt - [1585 octets] - [10/03/2019 21:59:20]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C03].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#5 Příspěvek od Rudy »

Dejte nové logy FRST+Addition.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#6 Příspěvek od Henry0607 »

Promiňte časovou prodlevu, tady jsou nové logy:

FRST.txt:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 09.03.2019 01
Ran by Administrator (administrator) on ADMIN-PC (11-03-2019 19:19:41)
Running from C:\Windows\System32\config\systemprofile\Downloads\frst
Loaded Profiles: Administrator (Available Profiles: Helena & Administrator & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atiesrxx.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc. -> AMD) C:\Windows\System32\atieclxx.exe
(SUPERAntiSpyware.com -> SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Advanced Micro Devices) [File not signed] C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Smart Connect software -> ) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation -> Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(LogMeIn, Inc. -> LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe
(Intel(R) Smart Connect software -> Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(McAfee, Inc. -> McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Renesas Electronics Corporation -> Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe
(CyberLink -> CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(CyberLink Corp. -> CyberLink) C:\Program Files (x86)\CyberLink\Power2Go9\CLMLSvc_P2G9.exe
(Hewlett-Packard Company -> Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.136.333\AvastBrowserCrashHandler64.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation - Software and Firmware Products -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.23\GoogleCrashHandler64.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-27] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [LogMeIn GUI] => C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe [446400 2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [259976 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation - Software and Firmware Products -> Intel Corporation)
HKLM-x32\...\Run: [RUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\rusb3mon.exe [115048 2011-09-20] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink -> CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePPShortCut] => C:\Program Files (x86)\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [223096 2012-04-17] (CyberLink -> CyberLink Corp.)
HKLM-x32\...\Run: [CLMLServer_For_P2G9] => C:\Program Files (x86)\CyberLink\Power2Go9\CLMLSvc_P2G9.exe [110344 2013-12-31] (CyberLink Corp. -> CyberLink)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard Company -> Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [259976 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-257039076-1346926551-2253569639-500\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-18\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [9001904 2019-02-11] (Support.com, Inc. -> SUPERAntiSpyware)
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\system32\lagarith.dll [148992 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\system32\x264vfw64.dll [3554304 2013-03-17] (x264vfw project) [File not signed]
HKLM\...\Drivers32: [VIDC.XVID] => C:\Windows\system32\xvidvfw.dll [258560 2011-06-24] () [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\system32\ac3acm.acm [180736 2012-07-21] (fccHandler) [File not signed]
HKLM\...\Drivers32: [msacm.l3codecp] => C:\Windows\system32\l3codecp.acm [182272 2009-07-14] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\...\Drivers32: [VIDC.LAGS] => C:\Windows\SysWOW64\lagarith.dll [216064 2011-12-07] ( ) [File not signed]
HKLM\...\Drivers32: [VIDC.X264] => C:\Windows\SysWOW64\x264vfw.dll [3649536 2013-03-17] (x264vfw project) [File not signed]
HKLM\...\Drivers32: [msacm.ac3acm] => C:\Windows\SysWOW64\ac3acm.acm [122880 2012-07-21] (fccHandler) [File not signed]
HKLM\...\Drivers32: [msacm.l3codecp] => C:\Windows\SysWOW64\l3codecp.acm [220672 2009-07-14] (Microsoft Windows -> Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\...\Drivers32: [vidc.VP60] => C:\Windows\SysWOW64\vp6vfw.dll [447752 2008-09-04] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [vidc.VP61] => C:\Windows\SysWOW64\vp6vfw.dll [447752 2008-09-04] (Electronic Arts -> On2.com)
HKLM\...\Drivers32: [VIDC.FMVC] => C:\Windows\SysWOW64\fmcodec.dll [77824 2008-08-18] (Fox Magic Software) [File not signed]
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\72.0.3626.121\Installer\chrmstp.exe [2019-03-05] (Google LLC -> Google Inc.)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{30C521FB-255B-46C8-9F0D-EE5AE371C9AA}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\72.0.1174.121\Installer\chrmstp.exe [2019-03-08] (AVAST Software s.r.o. -> AVAST Software)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A6EADE66-0000-0000-484E-7E8A45000000}] -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll [2018-11-06] (Adobe Systems, Incorporated -> Adobe Systems, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{65CD7F9B-E8F3-4bb0-82EB-6F6875B745DF}] -> C:\Windows\system32\LMIinit.dll [2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
HKLM\Software\...\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP DeskJet 2130 series.lnk [2019-03-09]
ShortcutTarget: Sledovat výstrahy inkoustu - HP DeskJet 2130 series.lnk -> C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPStatusBL.dll (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\iSCTsysTray.lnk [2013-12-17]
ShortcutTarget: iSCTsysTray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel(R) Smart Connect software -> Intel Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2019-03-06]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe (McAfee, Inc. -> McAfee, Inc.)
BootExecute: autocheck autochk * bootdelete
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{0132C53B-9E00-4E3A-B867-5215A0563262}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{083798B9-92FA-4B60-9686-AB7D6B0EC0E2}: [DhcpNameServer] 8.8.4.4 8.8.8.8
Tcpip\..\Interfaces\{6E3DFC9C-AB8A-41DB-9AE9-E1897B48493F}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{88D9DA17-B962-47ED-B5E9-C272B21358BD}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{8E0C624D-982F-4F34-BE54-C0188AEB53F0}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{9940B725-E8C6-4167-B279-980CA3640939}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{B6D84921-421A-4395-9179-C783E44D6F34}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1
Tcpip\..\Interfaces\{EDE5265F-D149-4735-892A-0E6266029618}: [DhcpNameServer] 10.112.1.1 10.112.2.1 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
SearchScopes: HKLM -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2019-01-16] (Microsoft Corporation -> Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll => No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2019-01-19] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2019-01-19] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {2D49AE4D-5236-2916-FDF7-E35D7E3C6C78} -> No File
BHO-x32: No Name -> {30FFDA66-22C6-1E64-BAD4-1ECE736319CC} -> No File
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2017-08-15] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: No Name -> {33D9F886-4A04-FD74-1E88-60D9F74C28FA} -> No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\ssv.dll [2018-11-17] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Pomocná služba pro přihlášení k účtu Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corporation -> Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2019-01-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2019-01-18] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\jp2ssv.dll [2018-11-17] (Oracle America, Inc. -> Oracle Corporation)
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-07-18] (Microsoft Corporation -> Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - No File

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_148.dll [2018-11-17] (Adobe Systems Incorporated -> )
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_148.dll [2018-11-17] (Adobe Systems Incorporated -> )
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-05-17] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-05-17] (Intel® Identity Protection Technology Software -> Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.191.2 -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\dtplugin\npDeployJava1.dll [2018-11-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.191.2 -> C:\Program Files (x86)\Java\jre1.8.0_191\bin\plugin2\npjp2.dll [2018-11-17] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-06-13] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-11-27] (Nero AG -> Nero AG)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Administrator\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-11-15] (RocketLife -> RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc -> Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.23\npGoogleUpdate3.dll [2018-12-19] (Google Inc -> Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=3.0.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2018-08-09] (VideoLAN -> VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-02-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com -> SUPERAntiSpyware.com)
R2 AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [543112 2017-06-12] (Advanced Micro Devices, Inc. -> AMD)
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2017-06-12] (Advanced Micro Devices) [File not signed]
S2 appdrvrem01; C:\Windows\System32\appdrvrem01.exe [551896 2016-02-28] (Protection Technology, Ltd. -> Protection Technology)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6758976 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
S2 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-22] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [357304 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
S3 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2018-04-22] (AVAST Software s.r.o. -> AVAST Software)
S3 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\72.0.1174.121\elevation_service.exe [1070600 2019-03-06] (AVAST Software s.r.o. -> AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1465352 2017-07-02] (BattlEye Innovations e.K. -> )
S3 BRSptSvc; C:\ProgramData\BitRaider\BRSptSvc.exe [477960 2014-09-01] (BitRaider -> BitRaider, LLC)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058392 2017-12-12] (Microsoft Corporation -> Microsoft Corporation)
S2 CLKMSVC10_38F51D56; C:\Program Files (x86)\CyberLink\PowerDVD10\NavFilter\kmsvc.exe [242664 2012-05-09] (CyberLink -> CyberLink)
S3 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel® Trusted Connect Service -> Intel(R) Corporation)
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [180200 2013-02-13] (Intel(R) Smart Connect software -> )
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-17] (Intel Corporation - Intel® Management Engine Firmware -> Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [420296 2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
S4 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [588232 2019-02-04] (LogMeIn, Inc. -> LogMeIn, Inc.)
S4 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2015-06-15] (LogMeIn, Inc. -> LogMeIn, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.968\McCHSvc.exe [405392 2019-02-27] (McAfee, Inc. -> McAfee, Inc.)
R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [29728 2013-05-28] (MICRO-STAR INTERNATIONAL CO., LTD. -> MICRO-STAR INTERNATIONAL CO., LTD.)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2298688 2019-02-19] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3171144 2019-02-19] (Electronic Arts, Inc. -> Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2017-07-02] (Even Balance, Inc. -> )
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-10-04] (Microsoft Windows -> Microsoft Corporation)
S3 DAUpdaterSvc; C:\Program Files (x86)\Steam\steamapps\common\Dragon Age Ultimate Edition\bin_ship\DAUpdaterSvc.Service.exe [X]
S2 PlaysService; "C:\Program Files (x86)\Raptr Inc\PlaysTV\plays_service.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [305544 2017-06-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices)
R3 amdkmdag; C:\Windows\System32\DRIVERS\atikmdag.sys [36562312 2017-06-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\Windows\System32\DRIVERS\atikmpag.sys [520584 2017-06-12] (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [138152 2013-11-26] (SlySoft, Inc. -> SlySoft, Inc.)
R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [138152 2013-11-26] (SlySoft, Inc. -> SlySoft, Inc.)
R1 appdrv01; C:\Windows\System32\Drivers\appdrv01.sys [3852976 2016-02-28] (Protection Technology, Ltd. -> Protection Technology)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Windows -> Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
R0 aswArDisk; C:\Windows\System32\drivers\aswArDisk.sys [37104 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [205400 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriver.sys [225680 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsh.sys [196072 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswblog.sys [320696 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniv.sys [57960 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [249672 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\Windows\System32\drivers\aswKbd.sys [42288 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [167304 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [112312 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [87944 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1034432 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [474456 2019-02-15] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [216784 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
S3 aswTap; C:\Windows\System32\DRIVERS\aswTap.sys [53904 2017-02-21] (AVAST Software s.r.o. -> The OpenVPN Project)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [379952 2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
R3 AtiHDAudioService; C:\Windows\System32\drivers\AtihdW76.sys [96256 2016-12-20] (Microsoft Windows Hardware Compatibility Publisher -> Advanced Micro Devices)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2013-12-29] (Tages SA -> )
R1 CLVirtualDrive1.1; C:\Windows\System32\DRIVERS\CLVirtualDrive1_1.sys [91912 2013-11-13] (CyberLink Corp. -> CyberLink)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-12-24] (Disc Soft Ltd -> Disc Soft Ltd)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [54736 2016-11-02] (SurfRight B.V. -> )
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [21048 2013-02-13] (Intel(R) Smart Connect software -> )
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [21048 2013-02-13] (Intel(R) Smart Connect software -> )
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-02-13] (Intel(R) Smart Connect software -> )
S3 leusbser; C:\Windows\System32\DRIVERS\leusbser.sys [238080 2012-05-30] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2013-12-29] (Tages SA -> )
R2 LMIInfo; C:\Windows\system32\drivers\LMIInfo.sys [30432 2017-01-11] (LogMeIn, Inc. -> LogMeIn, Inc.)
S4 LMIRfsClientNP; no ImagePath
R3 MRV6X64U; C:\Windows\System32\DRIVERS\MRVW24C.sys [340480 2007-10-28] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc)
S3 qcusbnet; C:\Windows\System32\DRIVERS\qcusbnet.sys [428600 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
S3 qcusbser; C:\Windows\System32\DRIVERS\qcusbser.sys [254520 2017-03-15] (Microsoft Windows Hardware Compatibility Publisher -> QUALCOMM Incorporated)
R3 rusb3hub; C:\Windows\System32\DRIVERS\rusb3hub.sys [114568 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
R3 rusb3xhc; C:\Windows\System32\DRIVERS\rusb3xhc.sys [230280 2012-08-27] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (Support.com, Inc. -> SUPERAdBlocker.com and SUPERAntiSpyware.com)
S4 secdrv; C:\Windows\SysWow64\Drivers\secdrv.sys [163644 2018-03-16] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R2 speedfan; C:\Windows\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [59904 2009-07-14] (Microsoft Windows -> Microsoft Corporation)
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2019-03-11] (Intel(R) Smart Connect software -> )
R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54168 2017-04-18] (Intel Corporation -> Intel Corporation)
U1 aswbdisk; no ImagePath
S3 BRDriver64; \??\C:\ProgramData\BitRaider\BRDriver64.sys [X]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 MSICDSetup; \??\D:\CDriver64.sys [X]
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security\Norton Security\NortonData\22.8.0.50\Definitions\SDSDefs\20170829.006\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security\Norton Security\NortonData\22.8.0.50\Definitions\SDSDefs\20170829.006\EX64.SYS [X]
S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-03-11 19:15 - 2019-03-11 19:15 - 000094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2019-03-10 20:13 - 2019-03-11 19:19 - 000000000 ____D C:\FRST
2019-03-10 19:36 - 2019-03-10 19:36 - 000000000 ____D C:\KVRT_Data
2019-03-10 17:55 - 2019-03-10 22:02 - 000000526 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e0753663-4f82-43bb-9fee-97b95ff7ab79.job
2019-03-10 17:55 - 2019-03-10 22:02 - 000000526 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9d2d795a-b34c-49d3-814c-de6cf94ec229.job
2019-03-10 17:55 - 2019-03-10 17:55 - 000003620 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task e0753663-4f82-43bb-9fee-97b95ff7ab79
2019-03-10 17:55 - 2019-03-10 17:55 - 000003546 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 9d2d795a-b34c-49d3-814c-de6cf94ec229
2019-03-10 17:55 - 2019-03-10 17:55 - 000001771 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2019-03-10 17:55 - 2019-03-10 17:55 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2019-03-10 17:55 - 2019-03-10 17:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2019-03-10 17:55 - 2019-03-10 17:55 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2019-03-09 23:58 - 2017-07-25 21:56 - 001792640 _____ (Bleeping Computer, LLC) C:\rl.exe
2019-03-09 21:55 - 2019-03-09 21:55 - 000000000 ____D C:\Users\Helena\AppData\Roaming\Sun
2019-03-09 21:55 - 2019-03-09 21:55 - 000000000 ____D C:\Users\Helena\AppData\LocalLow\Sun
2019-03-09 21:49 - 2019-03-09 21:49 - 000000000 ____D C:\Users\Helena\AppData\Local\AVAST Software
2019-03-09 21:26 - 2019-03-09 21:26 - 000000000 ____D C:\Users\TEMP\AppData\LocalLow\Sun
2019-03-09 21:11 - 2019-03-09 21:11 - 000000000 ____D C:\Users\TEMP\AppData\Local\mbamtray
2019-03-09 20:59 - 2019-03-09 20:59 - 000000000 ____D C:\Users\TEMP\AppData\LocalLow\AMD
2019-03-09 20:55 - 2019-03-09 21:42 - 000000000 ____D C:\Users\TEMP\AppData\Local\Google
2019-03-09 20:55 - 2019-03-09 20:55 - 000001356 _____ C:\Users\TEMP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2019-03-09 20:55 - 2019-03-09 20:55 - 000000000 ____D C:\Users\Default\AppData\Local\mbamtray
2019-03-09 20:55 - 2019-03-09 20:55 - 000000000 ____D C:\Users\Default User\AppData\Local\mbamtray
2019-03-09 20:52 - 2019-03-09 20:52 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\DAEMON Tools Pro
2019-03-09 20:52 - 2019-03-09 20:52 - 000000000 ____D C:\Users\TEMP\AppData\Local\LogMeIn
2019-03-09 20:52 - 2019-03-09 20:52 - 000000000 ____D C:\Users\TEMP\AppData\Local\AVAST Software
2019-03-09 20:52 - 2015-09-25 14:19 - 000000000 __SHD C:\Users\TEMP\AppData\Local\EmieUserList
2019-03-09 20:52 - 2015-09-25 14:19 - 000000000 __SHD C:\Users\TEMP\AppData\Local\EmieSiteList
2019-03-09 20:52 - 2015-09-25 14:19 - 000000000 __SHD C:\Users\TEMP\AppData\Local\EmieBrowserModeList
2019-03-09 20:52 - 2015-08-29 23:39 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Adobe
2019-03-09 20:52 - 2015-06-11 22:39 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Macromedia
2019-03-09 20:52 - 2014-02-04 23:30 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\AVAST Software
2019-03-09 20:52 - 2010-11-21 10:38 - 000000000 ____D C:\Users\TEMP\AppData\Roaming\Media Center Programs
2019-03-09 15:26 - 2019-02-14 21:51 - 000362888 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2019-03-09 14:46 - 2019-03-09 14:46 - 000714936 _____ C:\Windows\Minidump\030919-25974-01.dmp
2019-03-07 21:56 - 2019-03-07 22:23 - 503862934 _____ C:\Users\Administrator\Downloads\(kralovsti bratranci ve valce) 02 do propasti (dokumentarni) -14' -DVBT-(romin).mkv
2019-03-07 20:04 - 2019-03-07 20:40 - 549484562 _____ C:\Users\Administrator\Downloads\(kralovsti bratranci ve valce) 01 rozdeleny trun (dokumentarni) -14' -DVBT-(romin).mkv
2019-03-06 14:08 - 2019-03-06 14:15 - 000000000 ____D C:\ProgramData\McAfee Security Scan
2019-03-06 14:08 - 2019-03-06 14:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2019-03-04 23:10 - 2019-03-10 14:39 - 000000000 ____D C:\Users\Administrator\Desktop\ZSV otázky
2019-03-04 23:09 - 2019-03-04 23:09 - 001264619 _____ C:\Users\Administrator\Downloads\zasilka-KQMWH8FRCHT7IE2M.zip
2019-03-02 19:24 - 2019-03-02 20:09 - 494469816 _____ C:\Users\Administrator\Downloads\The Walking Dead S09E03-cz.tit.avi
2019-03-01 23:56 - 2019-03-01 23:56 - 000314368 _____ C:\Users\Administrator\Downloads\Klasicky_liberalismus.ppt
2019-03-01 19:52 - 2019-03-01 19:52 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\launcher
2019-02-27 15:31 - 2019-02-27 17:40 - 1420436580 _____ C:\Users\Administrator\Downloads\Ostre sledovane vlaky-1966.mp4
2019-02-27 15:30 - 2019-02-27 15:51 - 375751558 _____ C:\Users\Administrator\Downloads\Modlitba pro Katerinu Horovitzovou 1965 480p.mp4
2019-02-27 10:38 - 2019-02-27 10:38 - 000240964 _____ C:\Users\Administrator\Downloads\prihlaska_812531.pdf
2019-02-26 20:57 - 2019-02-26 20:57 - 000239591 _____ C:\Users\Administrator\Downloads\prihlaska_811087 (1).pdf
2019-02-26 20:30 - 2019-02-26 20:30 - 000236231 _____ C:\Users\Administrator\Downloads\prihlaska_811087.pdf
2019-02-26 20:16 - 2019-02-26 20:16 - 000051685 _____ C:\Users\Administrator\Downloads\MOD.pdf
2019-02-26 19:38 - 2019-02-26 19:38 - 000033989 _____ C:\Users\Administrator\Downloads\protokol_o_predani_pozvanek.pdf
2019-02-26 19:37 - 2019-02-26 19:37 - 000051577 _____ C:\Users\Administrator\Downloads\pozvanka.pdf
2019-02-25 00:39 - 2019-02-25 00:39 - 000000012 _____ C:\Users\Administrator\Desktop\Nový textový dokument.txt
2019-02-21 21:55 - 2019-02-21 21:55 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbam
2019-02-21 21:53 - 2019-02-21 21:53 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbamtray
2019-02-21 21:50 - 2019-02-21 21:50 - 000000000 ____D C:\Program Files\Malwarebytes
2019-02-21 21:48 - 2019-02-21 21:50 - 064324200 _____ (Malwarebytes ) C:\Users\Administrator\Downloads\mb3-setup-consumer-3.7.1.2839-1.0.538-1.0.9350.exe
2019-02-20 13:54 - 2019-02-20 15:42 - 1176738978 _____ C:\Users\Administrator\Downloads\2019-02-16 Maturitní ples 8.A a IV.A Čelákovice - male (1).zip
2019-02-20 13:23 - 2019-02-20 13:33 - 185565633 _____ C:\Users\Administrator\Downloads\2019-02-16 Maturitní ples 8.A a IV.A Čelákovice - upravene.zip
2019-02-20 13:21 - 2019-02-20 13:39 - 2083679908 _____ C:\Users\Administrator\Downloads\zasilka-KG7CN59RU498SN7S.zip
2019-02-17 20:03 - 2019-02-17 20:03 - 000000000 ____D C:\Users\Administrator\Desktop\Cesta do hospody + stuff
2019-02-15 22:22 - 2019-02-15 22:59 - 407547628 _____ C:\Users\Administrator\Downloads\The Walking Dead S09E02-cz.tit.avi
2019-02-15 20:10 - 2019-02-15 20:54 - 486489544 _____ C:\Users\Administrator\Downloads\The.Walking.Dead.S09E01 CZ tit.mkv
2019-02-14 21:53 - 2019-02-14 21:53 - 000249672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2019-02-14 07:12 - 2019-02-14 07:12 - 000225003 _____ C:\Users\Administrator\Downloads\ČJL - školní seznam děl k MZ 2017.pdf
2019-02-13 10:50 - 2019-01-27 16:23 - 000396888 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-02-13 10:50 - 2019-01-27 15:32 - 000348760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-02-13 10:50 - 2019-01-26 02:02 - 025736192 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-02-13 10:50 - 2019-01-26 01:50 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2019-02-13 10:50 - 2019-01-26 01:50 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2019-02-13 10:50 - 2019-01-26 01:38 - 002902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-02-13 10:50 - 2019-01-26 01:37 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2019-02-13 10:50 - 2019-01-26 01:36 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-02-13 10:50 - 2019-01-26 01:36 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2019-02-13 10:50 - 2019-01-26 01:36 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2019-02-13 10:50 - 2019-01-26 01:35 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2019-02-13 10:50 - 2019-01-26 01:32 - 005778944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-02-13 10:50 - 2019-01-26 01:29 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2019-02-13 10:50 - 2019-01-26 01:28 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2019-02-13 10:50 - 2019-01-26 01:27 - 020279808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-02-13 10:50 - 2019-01-26 01:25 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2019-02-13 10:50 - 2019-01-26 01:24 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2019-02-13 10:50 - 2019-01-26 01:24 - 000790016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-02-13 10:50 - 2019-01-26 01:24 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2019-02-13 10:50 - 2019-01-26 01:24 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2019-02-13 10:50 - 2019-01-26 01:18 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2019-02-13 10:50 - 2019-01-26 01:17 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2019-02-13 10:50 - 2019-01-26 01:14 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2019-02-13 10:50 - 2019-01-26 01:07 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2019-02-13 10:50 - 2019-01-26 01:07 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2019-02-13 10:50 - 2019-01-26 01:06 - 000498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-02-13 10:50 - 2019-01-26 01:06 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2019-02-13 10:50 - 2019-01-26 01:06 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2019-02-13 10:50 - 2019-01-26 01:06 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2019-02-13 10:50 - 2019-01-26 01:05 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2019-02-13 10:50 - 2019-01-26 01:05 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2019-02-13 10:50 - 2019-01-26 01:03 - 002295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-02-13 10:50 - 2019-01-26 01:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2019-02-13 10:50 - 2019-01-26 01:03 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-02-13 10:50 - 2019-01-26 01:01 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-02-13 10:50 - 2019-01-26 01:00 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2019-02-13 10:50 - 2019-01-26 00:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2019-02-13 10:50 - 2019-01-26 00:59 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2019-02-13 10:50 - 2019-01-26 00:58 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2019-02-13 10:50 - 2019-01-26 00:57 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-02-13 10:50 - 2019-01-26 00:56 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2019-02-13 10:50 - 2019-01-26 00:56 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2019-02-13 10:50 - 2019-01-26 00:50 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-02-13 10:50 - 2019-01-26 00:48 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-02-13 10:50 - 2019-01-26 00:48 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-02-13 10:50 - 2019-01-26 00:48 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2019-02-13 10:50 - 2019-01-26 00:46 - 015283712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-02-13 10:50 - 2019-01-26 00:46 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-02-13 10:50 - 2019-01-26 00:46 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2019-02-13 10:50 - 2019-01-26 00:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2019-02-13 10:50 - 2019-01-26 00:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2019-02-13 10:50 - 2019-01-26 00:43 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2019-02-13 10:50 - 2019-01-26 00:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2019-02-13 10:50 - 2019-01-26 00:40 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2019-02-13 10:50 - 2019-01-26 00:39 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2019-02-13 10:50 - 2019-01-26 00:37 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2019-02-13 10:50 - 2019-01-26 00:34 - 004858880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-02-13 10:50 - 2019-01-26 00:34 - 004494336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-02-13 10:50 - 2019-01-26 00:32 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2019-02-13 10:50 - 2019-01-26 00:31 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-02-13 10:50 - 2019-01-26 00:30 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-02-13 10:50 - 2019-01-26 00:29 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-02-13 10:50 - 2019-01-26 00:29 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2019-02-13 10:50 - 2019-01-26 00:22 - 001556480 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-02-13 10:50 - 2019-01-26 00:12 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-02-13 10:50 - 2019-01-26 00:11 - 004386304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-02-13 10:50 - 2019-01-26 00:08 - 001331200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-02-13 10:50 - 2019-01-26 00:06 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2019-02-13 10:50 - 2019-01-15 08:06 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-02-13 10:50 - 2019-01-15 08:06 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-02-13 10:50 - 2019-01-15 08:03 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2019-02-13 10:50 - 2019-01-15 08:03 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2019-02-13 10:50 - 2019-01-15 08:02 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2019-02-13 10:50 - 2019-01-15 07:52 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2019-02-13 10:50 - 2019-01-15 07:51 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2019-02-13 10:50 - 2019-01-15 07:51 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2019-02-13 10:50 - 2019-01-15 07:38 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2019-02-13 10:50 - 2019-01-15 07:33 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2019-02-13 10:50 - 2019-01-15 07:32 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2019-02-13 10:50 - 2019-01-15 07:32 - 000161280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2019-02-13 10:50 - 2019-01-15 07:32 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2019-02-13 10:50 - 2019-01-15 07:31 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2019-02-13 10:50 - 2019-01-15 07:29 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2019-02-13 10:50 - 2019-01-12 04:08 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll
2019-02-13 10:50 - 2019-01-12 04:08 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll
2019-02-13 10:50 - 2019-01-12 03:55 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll
2019-02-13 10:50 - 2019-01-12 03:55 - 000004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll
2019-02-13 10:50 - 2019-01-12 03:36 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2019-02-13 10:50 - 2019-01-12 03:36 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-02-13 10:50 - 2019-01-12 03:36 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2019-02-13 10:50 - 2019-01-09 04:10 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2019-02-13 10:50 - 2019-01-09 04:09 - 005552360 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-02-13 10:50 - 2019-01-09 04:09 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-02-13 10:50 - 2019-01-09 04:09 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-02-13 10:50 - 2019-01-09 04:08 - 001664352 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2019-02-13 10:50 - 2019-01-09 04:07 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 001162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 04:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:58 - 004055784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2019-02-13 10:50 - 2019-01-09 03:58 - 003960552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2019-02-13 10:50 - 2019-01-09 03:57 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:45 - 000076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2019-02-13 10:50 - 2019-01-09 03:45 - 000033408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2019-02-13 10:50 - 2019-01-09 03:45 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2019-02-13 10:50 - 2019-01-09 03:41 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2019-02-13 10:50 - 2019-01-09 03:41 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2019-02-13 10:50 - 2019-01-09 03:41 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2019-02-13 10:50 - 2019-01-09 03:38 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2019-02-13 10:50 - 2019-01-09 03:38 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2019-02-13 10:50 - 2019-01-09 03:38 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2019-02-13 10:50 - 2019-01-09 03:37 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
2019-02-13 10:50 - 2019-01-09 03:35 - 000464384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2019-02-13 10:50 - 2019-01-09 03:35 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2019-02-13 10:50 - 2019-01-09 03:35 - 000169984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2019-02-13 10:50 - 2019-01-09 03:34 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2019-02-13 10:50 - 2019-01-09 03:34 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2019-02-13 10:50 - 2019-01-09 03:34 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2019-02-13 10:50 - 2019-01-09 03:34 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2019-02-13 10:50 - 2019-01-09 03:34 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2019-02-13 10:50 - 2019-01-09 03:33 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:33 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:33 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2019-02-13 10:50 - 2019-01-09 03:33 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2019-02-13 10:50 - 2019-01-07 18:19 - 003228160 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2019-02-13 10:50 - 2019-01-01 17:08 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2019-02-13 10:50 - 2019-01-01 17:05 - 003247104 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2019-02-13 10:50 - 2019-01-01 17:05 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2019-02-13 10:50 - 2019-01-01 17:05 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2019-02-13 10:50 - 2019-01-01 17:04 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2019-02-13 10:50 - 2019-01-01 17:04 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2019-02-13 10:50 - 2019-01-01 16:58 - 002368000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2019-02-13 10:50 - 2019-01-01 16:58 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2019-02-13 10:50 - 2019-01-01 16:58 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2019-02-13 10:50 - 2019-01-01 16:57 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2019-02-13 10:50 - 2019-01-01 16:39 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2019-02-13 10:50 - 2019-01-01 16:39 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2019-02-13 10:50 - 2018-12-28 20:59 - 002072576 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2019-02-13 10:50 - 2018-12-28 20:59 - 000876032 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2019-02-13 10:50 - 2018-12-28 20:59 - 000516608 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2019-02-13 10:50 - 2018-12-28 20:59 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2019-02-13 10:50 - 2018-12-28 20:59 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2019-02-13 10:50 - 2018-12-28 20:48 - 001425920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2019-02-13 10:50 - 2018-12-28 20:48 - 000582144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2019-02-13 10:50 - 2018-12-28 20:48 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2019-02-13 10:50 - 2018-12-28 20:32 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2019-02-13 10:50 - 2018-12-04 17:07 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2019-02-13 10:50 - 2018-12-04 17:07 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2019-02-13 10:50 - 2018-12-04 16:55 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2019-02-13 10:50 - 2018-12-04 16:55 - 000142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2019-02-13 10:50 - 2018-12-02 17:06 - 000687616 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000998480 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000918408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000066000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000063936 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000021968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000020944 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000019408 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000018880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000017872 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000017856 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000017360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000017352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000016336 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000015824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000015808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000015296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000014312 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000014272 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000013768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000013760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000013760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000013264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012736 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012240 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012232 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000012024 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011728 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011512 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2019-02-13 10:50 - 2018-10-12 14:05 - 000011200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2019-02-11 17:50 - 2019-02-11 17:50 - 009314380 _____ C:\Users\Administrator\Downloads\Čj.zip
2019-02-11 17:50 - 2019-02-11 17:50 - 002857117 _____ C:\Users\Administrator\Downloads\Dějepis.zip
2019-02-11 17:50 - 2019-02-11 17:50 - 000340524 _____ C:\Users\Administrator\Downloads\ZSV.zip
2019-02-11 17:50 - 2019-02-11 17:50 - 000340524 _____ C:\Users\Administrator\Downloads\ZSV (1).zip

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-03-11 19:15 - 2016-12-07 11:21 - 000034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2019-03-11 19:15 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-03-10 23:40 - 2013-12-17 18:14 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2019-03-10 23:36 - 2009-07-14 06:08 - 000032572 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2019-03-10 22:25 - 2009-07-14 05:45 - 000022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-03-10 22:25 - 2009-07-14 05:45 - 000022064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-03-10 09:24 - 2014-02-10 21:00 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\uTorrent
2019-03-09 23:38 - 2017-11-05 17:43 - 000000000 ____D C:\Users\Administrator\Desktop\Žádost o přijetí na oddělení paliativní péče
2019-03-09 22:47 - 2016-05-28 12:08 - 000000991 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Control Panel.lnk
2019-03-09 22:41 - 2018-06-13 12:43 - 000197844 _____ C:\Windows\ntbtlog.txt
2019-03-09 22:09 - 2017-11-18 16:36 - 000002526 _____ C:\Users\Administrator\Desktop\Discord.lnk
2019-03-09 22:09 - 2017-07-13 16:34 - 000002514 _____ C:\Users\Administrator\Desktop\HP Photo Creations.lnk
2019-03-09 22:09 - 2014-05-27 15:45 - 000001305 _____ C:\Users\Administrator\Desktop\µTorrent.lnk
2019-03-09 21:36 - 2019-01-20 13:34 - 000022016 ___SH C:\Users\Administrator\Thumbs.db
2019-03-09 21:13 - 2015-09-25 16:07 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-03-09 21:11 - 2009-07-14 05:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2019-03-09 20:56 - 2009-07-14 06:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2019-03-09 16:34 - 2013-12-28 17:25 - 000000000 ____D C:\Program Files (x86)\Steam
2019-03-09 16:33 - 2015-11-07 19:36 - 000000000 ____D C:\ProgramData\Origin
2019-03-09 16:12 - 2018-04-05 16:03 - 000000000 ____D C:\Users\Administrator\AppData\Local\AVAST Software
2019-03-09 15:27 - 2017-02-21 18:26 - 000001966 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2019-03-09 15:27 - 2017-02-21 18:25 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2019-03-09 14:46 - 2013-12-27 11:03 - 000000000 ____D C:\Windows\Minidump
2019-03-09 13:17 - 2017-01-11 16:58 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2019-03-09 11:43 - 2015-12-03 16:25 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
2019-03-09 11:01 - 2016-05-28 12:05 - 000000000 ____D C:\ProgramData\LogMeIn
2019-03-08 16:31 - 2018-04-22 10:47 - 000002432 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2019-03-08 16:31 - 2018-04-22 10:47 - 000002389 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2019-03-07 23:54 - 2013-12-26 21:53 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\vlc
2019-03-07 17:57 - 2015-11-07 19:36 - 000000000 ____D C:\Program Files (x86)\Origin
2019-03-06 17:36 - 2018-06-17 12:38 - 000001971 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2019-03-06 14:08 - 2018-06-17 13:08 - 000000000 ____D C:\Program Files\McAfee Security Scan
2019-03-06 14:03 - 2013-12-24 19:54 - 000000000 ____D C:\Users\Administrator\AppData\Local\CrashDumps
2019-03-05 20:56 - 2017-12-28 14:12 - 000002186 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-03-05 20:56 - 2013-12-17 18:12 - 000002227 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-03-03 23:13 - 2017-12-22 13:55 - 000000000 ____D C:\Users\Administrator\Desktop\Práce do školy
2019-03-03 23:13 - 2010-11-21 10:27 - 000709330 _____ C:\Windows\system32\perfh005.dat
2019-03-03 23:13 - 2010-11-21 10:27 - 000157920 _____ C:\Windows\system32\perfc005.dat
2019-03-03 23:13 - 2009-07-14 06:13 - 001682108 _____ C:\Windows\system32\PerfStringBackup.INI
2019-03-03 23:13 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2019-03-03 13:05 - 2019-01-04 21:58 - 000000000 _____ C:\Windows\system32\last.dump
2019-03-02 15:07 - 2016-05-10 16:11 - 000000000 ____D C:\Users\Administrator\Desktop\Původní data aplikace Firefox
2019-03-01 19:52 - 2013-12-28 22:14 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\The Creative Assembly
2019-02-22 11:00 - 2015-11-17 15:09 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-02-21 11:10 - 2014-03-15 18:47 - 000000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics
2019-02-21 10:31 - 2014-06-13 20:50 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-02-21 10:29 - 2014-06-13 20:49 - 000000000 ____D C:\Program Files\Microsoft Office 15
2019-02-20 18:44 - 2017-08-16 13:46 - 000000000 ____D C:\Users\Administrator\Desktop\Fotky
2019-02-17 20:05 - 2017-04-22 17:01 - 000000000 ____D C:\Users\Administrator\Desktop\Helena
2019-02-17 18:09 - 2017-10-15 21:24 - 000000000 ____D C:\Users\Administrator\Desktop\scan rozsudek rozvod
2019-02-15 14:28 - 2013-12-26 13:16 - 000000000 ____D C:\Users\Administrator\AppData\Local\Ubisoft Game Launcher
2019-02-15 13:53 - 2013-12-17 18:01 - 000474456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2019-02-14 21:52 - 2016-07-11 18:26 - 000042288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2019-02-14 21:52 - 2013-12-24 06:50 - 000216784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2019-02-14 21:52 - 2013-12-17 18:01 - 000379952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2019-02-14 21:52 - 2013-12-17 18:01 - 000167304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2019-02-14 21:52 - 2013-12-17 18:01 - 000112312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2019-02-14 21:52 - 2013-12-17 18:01 - 000087944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2019-02-14 21:51 - 2019-01-14 19:40 - 000225680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriver.sys
2019-02-14 21:51 - 2019-01-04 10:34 - 000320696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswblog.sys
2019-02-14 21:51 - 2019-01-04 10:34 - 000196072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsh.sys
2019-02-14 21:51 - 2019-01-04 10:34 - 000057960 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniv.sys
2019-02-14 21:51 - 2019-01-04 10:34 - 000037104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArDisk.sys
2019-02-14 21:51 - 2017-11-16 13:41 - 000205400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2019-02-14 21:51 - 2013-12-17 18:01 - 001034432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2019-02-14 12:13 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache
2019-02-14 06:58 - 2009-07-14 05:45 - 005041840 _____ C:\Windows\system32\FNTCACHE.DAT
2019-02-14 00:07 - 2013-12-17 18:02 - 001656822 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2019-02-14 00:04 - 2013-12-18 09:06 - 000000000 ____D C:\Windows\system32\MRT
2019-02-14 00:01 - 2013-12-18 09:06 - 129330784 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-02-10 23:02 - 2017-11-18 16:36 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\discord
2019-02-10 11:19 - 2015-11-08 11:31 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Origin
2019-02-09 22:22 - 2019-02-06 14:04 - 000000000 ____D C:\Users\Administrator\Documents\Endless Space 2

==================== Files in the root of some directories =======

2014-01-25 10:38 - 2013-11-26 10:38 - 000000032 ____R () C:\ProgramData\hash.dat

Some files in TEMP:
====================
2018-10-05 21:38 - 2018-10-05 21:38 - 040210008 _____ () C:\Users\Administrator\AppData\Local\Temp\vlc-3.0.4-win32.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\dllhost.exe => File is digitally signed
C:\Windows\SysWOW64\dllhost.exe => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2019-03-06 15:00

==================== End of FRST.txt ============================

Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#7 Příspěvek od Henry0607 »

Addition.txt:

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09.03.2019 01
Ran by Administrator (11-03-2019 19:25:00)
Running from C:\Windows\System32\config\systemprofile\Downloads\frst
Windows 7 Home Premium Service Pack 1 (X64) (2013-12-17 16:20:12)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-257039076-1346926551-2253569639-500 - Administrator - Enabled) => C:\Users\TEMP
ASPNET (S-1-5-21-257039076-1346926551-2253569639-1002 - Limited - Enabled)
Guest (S-1-5-21-257039076-1346926551-2253569639-501 - Limited - Enabled) => C:\Users\Guest
Helena (S-1-5-21-257039076-1346926551-2253569639-1000 - Limited - Enabled) => C:\Users\Helena
HomeGroupUser$ (S-1-5-21-257039076-1346926551-2253569639-1004 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ACP Application (HKLM\...\{0A1ABEEF-037C-D922-08E1-AB1798F320BE}) (Version: 2017.0612.1633.42 - Advanced Micro Devices, Inc.) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.010.20098 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 31.0.0.96 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Digital Editions 3.0 (HKLM-x32\...\Adobe Digital Editions 3.0) (Version: 3.0.1 - Adobe Systems Incorporated)
Adobe Flash Player 31 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 31.0.0.148 - Adobe Systems Incorporated)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.148 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Age Of Empires 3 CZ verze 1.0 (HKLM-x32\...\{A6502644-790D-4DCB-824F-45C64B22AF4D}_is1) (Version: 1.0 - tomi2k9)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
AnyDVD (HKLM-x32\...\AnyDVD) (Version: 7.4.2.0 - SlySoft)
Application Profiles (HKLM-x32\...\{06AEF86C-0B0B-5690-38A0-02E1520A6999}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden
Armies of Exigo (HKLM-x32\...\{DA825D8C-E83C-49FC-81ED-AB28E069329F}_is1) (Version: 1.4 - US - ACTION, s.r.o.)
Assassin's Creed IV Black Flag (HKLM-x32\...\Uplay Install 273) (Version: - Ubisoft)
AutoREALM Version 2.2.1 (HKLM-x32\...\AutoREALM_is1) (Version: - )
Avast Driver Updater (HKLM-x32\...\{D606EFF9-3813-4875-B455-AECD2E7B0676}) (Version: 2.3.3 - AVAST Software) Hidden
Avast Driver Updater (HKLM-x32\...\Avast Driver Updater) (Version: 2.3.3 - AVAST Software)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 19.2.2364 - AVAST Software)
Avast Secure Browser (HKLM-x32\...\Avast Secure Browser) (Version: 72.0.1174.121 - Autoři prohlížeče Avast Secure Browser)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Battles of Napoleon (HKLM-x32\...\{77D97242-6F88-4046-B1B2-5AD790752816}) (Version: 1.00.0000 - IncaGold)
BitRaider Web Client (HKLM-x32\...\BitRaider Web Client) (Version: 1.1.9.9 - BitRaider, LLC)
Brain Workshop 4.8.4 (HKLM-x32\...\Brain Workshop_is1) (Version: 4.8.4 - Paul Hoskinson & Jonathan Toomim)
Caesar IV (HKLM-x32\...\{B7666229-351B-47D9-AA6F-DF777CF04BBF}) (Version: 0.18.13 - Tilted Mill Entertainment)
Castle Strike (HKLM-x32\...\{B829DDDC-BCEE-441C-BB8C-0401753E4B44}_is1) (Version: 1.2 - US - ACTION, s.r.o.)
Catalyst Control Center Next Localization BR (HKLM\...\{15979E65-792E-474B-BC5D-42257709D4D9}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{83D75873-9603-EA5A-948F-A5AEE78082C1}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{DD3A9C85-51E9-854D-EB9B-F0AE8E5B2F7C}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{A00A5425-8899-055A-404C-8F96C2EC647F}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{CB71E054-00CF-182D-6C78-F9D85D10B7BA}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{30B97DD0-3646-AD22-2E77-3792B11BB5E6}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{8342F234-A97E-D691-3C01-F060CB7DA175}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{CD47D86C-737D-4818-F059-CF8A53F37B76}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{DB0E2806-DE62-D60E-9BD9-E3A89FB2A5A8}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{D6ACA0E4-2488-AE52-E73D-24DB98F9AD65}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B8C421E8-BDF9-F598-832C-659A513F79EB}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{D4EF1657-8835-A5AE-DBA0-658EF2869048}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{ED71C4B4-4C00-F7C9-9151-60411373DC35}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{28FFCD28-01FF-9792-B1A9-B944D44FB37D}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{DAEF66AB-6EA7-B0A8-96FB-243A2F33B8B2}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{3DBC48E0-7DE6-295B-448E-5F53D1491AC3}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{CAF3DAD2-A7E8-5472-F8E3-D71E92B7FA65}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{E7666716-625F-9E54-ECB3-39CC3C7FFB14}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{30A5B188-80AB-2CF5-22D8-8E20D66907D4}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{A38C8B57-D3E6-5748-F2D3-FDC383D1203A}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{1CD84FD4-26F3-08FC-32F5-17DA9E8A4ED7}) (Version: 2017.0612.1651.28496 - Advanced Micro Devices, Inc.) Hidden
CyberLink LabelPrint 2.5 (HKLM-x32\...\{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.0.6603 - CyberLink Corp.)
CyberLink LabelPrint 2.5 (HKLM-x32\...\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.0.6603 - CyberLink Corp.)
CyberLink Power2Go 9 (HKLM-x32\...\InstallShield_{57D68FAE-CB5E-4fd6-AE3B-A0B43375AF18}) (Version: 9.0.1231.0 - CyberLink Corp.)
CyberLink WaveEditor 2 (HKLM-x32\...\InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}) (Version: 2.0.0.4203 - CyberLink Corp.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Dark Souls Prepare to Die Edition (HKLM-x32\...\{4E4D0FA1-6B85-4824-88FC-051000028201}) (Version: 1.0.0002.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Dark Souls Prepare to Die Edition (HKLM-x32\...\{4E4D0FA1-6B85-4824-88FC-051000038201}) (Version: 1.0.0003.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Dark Souls Prepare to Die Edition (HKLM-x32\...\{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.) Hidden
Dark Souls Prepare to Die Edition (HKLM-x32\...\GFWL_{4E4D0FA1-F880-4CCB-999A-501000008200}) (Version: 1.0.0000.130 - NAMCO BANDAI Games Europe S.A.S.)
Drakensang - The River of Time (HKLM-x32\...\Drakensang_TRoT_is1) (Version: - dtp)
DVD Shrink 3.2 (HKLM-x32\...\DVD Shrink_is1) (Version: - DVD Shrink)
Euro Truck Simulator 2 Multiplayer 0.2.0.1.1 Alpha (HKLM-x32\...\{A227B892-C548-4490-9C5D-DB341F8194A6}_is1) (Version: 0.2.0.1.1 Alpha - ETS2MP Team)
Fotogalerie (HKLM-x32\...\{F37D360D-9308-4BB1-8515-DC6B637B9486}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.23 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.23.9 - Google Inc.) Hidden
Gothic (HKLM-x32\...\{BBF10B37-4ED3-11D5-A818-00500435FC18}) (Version: - )
Gothic (HKLM-x32\...\Gothic_is1) (Version: - GOG.com)
Gothic II Gold (HKLM-x32\...\{8B95673D-2D4C-4216-ADA2-3660973700BF}) (Version: 1.00.0000 - CD Projekt) Hidden
Gothic II Gold (HKLM-x32\...\InstallShield_{8B95673D-2D4C-4216-ADA2-3660973700BF}) (Version: 1.00.0000 - CD Projekt)
Heroes of Might and Magic V - Hammers of Fate (HKLM-x32\...\{EEF7568A-BD2C-42B7-A22E-6D55EA287C34}) (Version: 2.1 - Ubisoft)
Heroes of Might and Magic V (HKLM-x32\...\{9B22D57A-5338-49A5-AC08-70FE3E8B878B}) (Version: 1.6 - Ubisoft)
HP DeskJet 2130 series Nápověda (HKLM-x32\...\{C8CCFDF2-9CB2-4714-BCE5-17178CB71646}) (Version: 35.0.0 - Hewlett Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Intel(R) Smart Connect Technology 4.0 x64 (HKLM\...\{F971B444-C3D5-4AFD-A891-32B9DF79EBC7}) (Version: 4.0.41.2072 - Intel)
Java 8 Update 171 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180171F0}) (Version: 8.0.1710.11 - Oracle Corporation)
Java 8 Update 191 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180191F0}) (Version: 8.0.1910.12 - Oracle Corporation)
LEGO® The Lord of the Rings™ (HKLM-x32\...\{C6F20FA7-342A-47A9-A3C8-EB36CABE6419}) (Version: 1.0.0.0 - Warner Bros. Interactive Entertainment)
Lenovo Mobile Device Drivers (HKLM-x32\...\{473DF2D7-9A99-4CA5-8BB1-19CE1EA6D5F1}) (Version: 3.7.09 - Lenovo)
LogMeIn (HKLM-x32\...\{CEA0C06C-C352-434A-972E-04911AAB669C}) (Version: 4.1.7682 - LogMeIn, Inc.)
LogMeIn Client (HKLM-x32\...\{2FE23717-0B77-422A-A4DD-AF5191533451}) (Version: 1.3.2148 - LogMeIn, Inc.)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.968.1 - McAfee, Inc.)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.7.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft .NET Framework 4.7.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 - cs-cz (HKLM\...\ProPlusRetail - cs-cz) (Version: 15.0.5111.1001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visio Professional 2013 - cs-cz (HKLM\...\VisioProRetail - cs-cz) (Version: 15.0.5111.1001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710F4C1C-CC18-4C49-8CBF-51240C89A1A2}) (Version: - )
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: - )
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Might and Magic Heroes VII (HKLM-x32\...\Uplay Install 1176) (Version: - Ubisoft)
Movie Maker (HKLM-x32\...\{3D2CF65C-B544-4308-B996-700D3E5F6C4C}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 60.0.2 (x64 cs) (HKLM\...\Mozilla Firefox 60.0.2 (x64 cs)) (Version: 60.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 60.0.2.6730 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: - )
MySQL Connector/ODBC 3.51 (HKLM-x32\...\{0CB3C535-1171-4A20-B549-E2CB5DEB9723}) (Version: 3.51.12 - MySQL AB)
Nero 2014 (HKLM-x32\...\{0128492C-AB60-43BE-9D9A-8CA622CAF06E}) (Version: 15.0.07700 - Nero AG)
Nero Info (HKLM-x32\...\{B791E0AB-87A9-41A4-8D98-D13C2E37D928}) (Version: 16.0.1003 - Nero AG)
Nero MediaHome Free (HKLM-x32\...\{B0AE1850-DA08-4E88-BC39-3D3BCCCEFF37}) (Version: 16.0.01500 - Nero AG)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.5111.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.5111.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0405-0000-0000000FF1CE}) (Version: 15.0.5111.1001 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 10.5.35.22222 - Electronic Arts, Inc.)
PDF Settings CS5 (HKLM-x32\...\{A78FE97A-C0C8-49CE-89D0-EDD524A17392}) (Version: 10.0 - Adobe Systems Incorporated) Hidden
Prerequisite installer (HKLM-x32\...\{5909A89E-C97F-407C-AE2B-47BDED86BF5D}) (Version: 15.0.0005 - Nero AG) Hidden
Prerequisite installer (HKLM-x32\...\{799AFA36-4EA5-4323-8689-74C06645A26B}) (Version: 16.0.0003 - Nero AG) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
Raptr (HKLM-x32\...\Raptr) (Version: 5.2.11-r125663-release - Raptr, Inc)
Risen - ModStarter 1.3.4.1 (Online Mods DB version) (HKLM-x32\...\Risen - ModStarter_is1) (Version: - LordOfWAR(WorldOfRisen.de), Odin68(Mighty DWARF Mod-Team))
Risen (HKLM-x32\...\{155F4A0E-76ED-45A2-91FB-FF2A2133C31A}) (Version: 1.00.0000 - Deep Silver)
SafeZone Stable 4.58.2552.909 (HKLM-x32\...\SafeZone 4.58.2552.909) (Version: 4.58.2552.909 - Avast Software) Hidden
Sid Meier's Civilization 4 Complete (HKLM-x32\...\{30D1F3D2-54CF-481D-A005-F94B0E98FEEC}) (Version: 1.74 - Firaxis Games)
Skype verze 8.34 (HKLM-x32\...\Skype_is1) (Version: 8.34 - Skype Technologies S.A.)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version: 7.0.0.50 - Bioware/EA)
Studie vylepšování produktu HP DeskJet 2130 series (HKLM\...\{A6640A96-7F5D-4480-8D50-F3A0BB58C096}) (Version: 35.0.61.54677 - Hewlett-Packard Co.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 8.0.1030 - SUPERAntiSpyware.com)
The Movies(TM) (HKLM-x32\...\{0556F885-2415-4666-B53E-33727E46AEA1}) (Version: 1.0 - Activision) Hidden
The Movies(TM) (HKLM-x32\...\InstallShield_{0556F885-2415-4666-B53E-33727E46AEA1}) (Version: 1.0 - Activision)
The Settlers 7 - CESTA KE KORUNĚ (HKLM-x32\...\{9C916142-C18C-429D-BFED-40094A7E0BEB}) (Version: 1.12.1396 - Ubisoft)
The Sims™ 3 (HKLM-x32\...\{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}) (Version: 1.69.43.024017 - Electronic Arts Inc.)
The Sims™ 3 Cestovní horečka (HKLM-x32\...\{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}) (Version: 2.0.86 - Electronic Arts)
The Sims™ 3 Luxusní bydlení – Kolekce (HKLM-x32\...\{71828142-5A24-4BD0-97E7-976DA08CE6CF}) (Version: 3.0.38 - Electronic Arts)
The Sims™ 3 Obludárium (HKLM-x32\...\{B37DAFA5-717D-41F8-BDFB-3A4B68C0B3A1}) (Version: 15.0.135 - Electronic Arts)
The Sims™ 3 Povolání snů (HKLM-x32\...\{910F4A29-1134-49E0-AD8B-56E4A3152BD1}) (Version: 4.0.87 - Electronic Arts)
The Sims™ 3 Roční období (HKLM-x32\...\{3DE92282-CB49-434F-81BF-94E5B380E889}) (Version: 16.0.136 - Electronic Arts)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.21.0 (HKLM\...\VulkanRT1.0.21.0) (Version: 1.0.21.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0-2) (Version: 1.0.26.0 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.3.1 (HKLM\...\VulkanRT1.0.3.1) (Version: 1.0.3.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1) (Version: 1.0.39.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.39.1 (HKLM\...\VulkanRT1.0.39.1-2) (Version: 1.0.39.1 - LunarG, Inc.)
Windows Driver Package - Acer, Inc. (WinUSB) AndroidUsbDeviceClass (03/19/2013 1.0.0000.00000) (HKLM\...\8568FB1AD6B1B941521B49E8A0395C305BE3C5E3) (Version: 03/19/2013 1.0.0000.00000 - Acer, Inc.)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version: - )
WinRAR 5.60 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.60.0 - win.rar GmbH)
YMS 3017 AMBUSH Gaming mouse (HKLM-x32\...\{DEA4CAD5-2A02-4FE2-9498-E49134876A23}_is1) (Version: 1.0 - )
Zachvev - Pod vlivem mesice v1.0z (HKLM-x32\...\{Zachvev - Pod vlivem mesice zip}_is1) (Version: - Špidla Data Processing, s.r.o.)
Základní software zařízení HP DeskJet 2130 series (HKLM\...\{E1B7356D-B08B-4B2C-A8C3-EAB12EB743DE}) (Version: 35.0.61.54677 - Hewlett-Packard Co.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [CLVDShellExt9] -> {4E20B104-5D9F-4E01-A01E-100F08E345C9} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt9.dll [2014-01-02] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers1: [DaemonShellExtImage] -> {40966797-8FFE-46C8-9EF8-7003F33CCF0F} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2013-10-17] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [CLVDShellExt9] -> {4E20B104-5D9F-4E01-A01E-100F08E345C9} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt9.dll [2014-01-02] (CyberLink Corp. -> Cyberlink)
ContextMenuHandlers2: [DaemonShellExtDrive] -> {A5415364-784A-41A5-B47A-D452909CA8FF} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2013-10-17] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers4: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2017-06-12] (Advanced Micro Devices, Inc.) [File not signed]
ContextMenuHandlers6: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-02-14] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2018-06-24] (win.rar GmbH -> Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0049AEA8-D3E6-4B05-968F-BA62A06AA382} - System32\Tasks\SafeZone scheduled Autoupdate 1468307900 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe (AVAST Software s.r.o. -> Avast Software)
Task: {0201B920-1E7C-4BC9-AAA6-2B4BA6485E9F} - System32\Tasks\{F78CB45C-FCB1-4431-B1B2-1603F84BD6BE} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {02A2BAF6-DE34-464D-8F60-E439AE429492} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe (AVAST Software s.r.o. -> AVAST Software)
Task: {032BA9DA-3D10-41D6-B306-374157D21126} - System32\Tasks\{1BB64DBB-9E94-431E-98A9-3EDD1A21E945} => C:\Windows\system32\pcalua.exe -a F:\Crack\Cestina\CZ_100.exe -d F:\Crack\Cestina
Task: {0659D284-B4D3-4DA1-88D7-F84CB901EC8D} - System32\Tasks\{21DB7A55-CFAC-4218-B011-FAFF49CE0216} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {07124ADC-D200-45FA-AEDB-0BC2DCC53AA0} - System32\Tasks\Avast Driver Updater Startup => C:\Program Files (x86)\Avast Driver Updater\Avast Driver Updater.exe
Task: {11838125-9FE3-4934-9693-0A57694AC2DB} - System32\Tasks\Games\UpdateCheck_S-1-5-21-257039076-1346926551-2253569639-1000
Task: {183DF887-868B-49F8-8E2E-89E9FCDCFAB8} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe
Task: {1B7C4B96-B52E-4188-B849-0253AD8D7C1A} - System32\Tasks\{C1150EFD-D18C-4EB2-9861-1363666EAB60} => C:\Program Files (x86)\Age Of Empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
Task: {1BC97C63-8AE1-4BE9-9D9E-734F917EAA84} - System32\Tasks\Sstt2-TaskPlan => C:\Program Files\Gaming\YMS 3017\YMS 3017.EXE (YENKEE) [File not signed]
Task: {1BE3D2C1-3F54-4F7E-ABD2-332BE651C4CB} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {1E17EB1F-40F2-46BA-B90D-33589F5F1B02} - System32\Tasks\{5779624E-0D67-48BC-875A-C3FA23A0D588} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
Task: {1EEDB8A7-6A72-4F1C-B275-7EB807B219AC} - System32\Tasks\HP AR Program Upload - 78d5c9d5dfcd4119b9bfd7f0f1f2ee94b4f7c6d42d0c49ac9cf2460bc07956c0 => C:\Program Files\HP\HP DeskJet 2130 series\bin\HPRewards.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {1FE39584-9F57-4D5F-9A58-8B7CA48AE85E} - System32\Tasks\{CCEAF1B1-A16C-4B25-9E01-05FDBA4DA438} => C:\Windows\system32\pcalua.exe -a D:\DXREDIST\DXSETUP.exe -d D:\DXREDIST
Task: {20004A63-9B91-4220-ACC6-4AF825A114C7} - System32\Tasks\{08044EBB-3687-401F-A611-C2E1D39794B4} => C:\Windows\system32\pcalua.exe -a F:\DWA-142_drv_A1_Utility_v1.40b02(0606144500)\DWA-142_A1_Utility_v1.40b02(0606144500)\DWA-142_A1_Utility_v1.40b02\Setup.exe -d F:\DWA-142_drv_A1_Utility_v1.40b02(0606144500)\DWA-142_A1_Utility_v1.40b02(0606144500)\DWA-142_A1_Utility_v1.40b02
Task: {20227FA3-17FA-4B24-AA8D-2F8672FDDD08} - System32\Tasks\{654FFF4C-3957-4952-A1BB-7A47EF5E1919} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {228AE85A-7A1E-4A66-A811-AF67D0E87666} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {2291B476-DD07-49F3-A43F-C4751DCC5C1C} - System32\Tasks\{F3F7470E-D90C-4278-A3F8-FDC762192A40} => C:\Windows\system32\pcalua.exe -a F:\redist\tages\TagesSetup.exe -d F:\redist\tages
Task: {31F30620-0364-4231-A094-AA67B995A01C} - System32\Tasks\{FAACDF59-2C69-4850-ACC2-8A291EF9475C} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {347225D0-C98C-47F0-BE84-B6DD1D0CEE08} - System32\Tasks\{8E6251B7-E6DB-477B-AAFE-07366754CEFA} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\instmsiw.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {36054A2A-4B92-448B-9FCF-0361CE6C79CF} - System32\Tasks\{5632F9C7-B1F7-4EBB-9F34-F61482F09056} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
Task: {3A68B7FC-4C44-4EB1-A60E-5EF12612EFF5} - System32\Tasks\{BB85A9AD-6699-4ACB-9E3F-34C8711E57C2} => D:\AutoRun.exe (Electronic Arts -> Electronic Arts)
Task: {406737EF-ABC3-4359-AD6E-055C4E04AC8F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {42853439-BDBE-4808-AB0D-3AFE276124DD} - System32\Tasks\Nero\Nero Info => C:\Program Files (x86)\Common Files\Nero\Nero Info\NeroInfo.exe (Nero AG -> Nero AG)
Task: {44D4474C-65B7-4B35-ACD7-98A6F9215FCF} - System32\Tasks\{7185323E-173B-4368-A943-3BBEAFB274B2} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Steam\SteamApps\common\Crusader Kings II\vcredist.exe" -d "C:\Program Files (x86)\Steam\SteamApps\common\Crusader Kings II"
Task: {460FAF64-E26D-4135-9A9B-0E845B1B3018} - System32\Tasks\HP AR Program Upload - 3efef7b0a5554c26b46c841119cf07dced4ade5085aa4d638bb85897db1b8341 => C:\Program Files\HP\HP DeskJet 2130 series\bin\HPRewards.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {461C900A-B499-4C0E-B742-0CD13D9C51CD} - System32\Tasks\{A368A8A2-454E-4EB8-94D5-11E8A3CE27AD} => C:\Program Files (x86)\Age Of Empires 3\age3.exe (Microsoft Corporation -> Ensemble Studios)
Task: {467AA5F1-D86A-41C9-9E2F-2606F3D321C7} - System32\Tasks\HPCustParticipation HP DeskJet 2130 series => C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPCustPartic.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {500721F3-2D73-4A59-8FBB-24B8E6AE6999} - System32\Tasks\{C4C1345D-E2E3-4204-AB73-DC1592E0C587} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
Task: {50F8735C-8A3F-4F7F-BE19-7EF84D7B6FFB} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe
Task: {51C9C696-9B52-40EE-B9AA-1328F52AB9F0} - System32\Tasks\{1C79B00D-D173-4C3E-8DA6-75F5B99E58B3} => D:\AutoRun.exe (Electronic Arts -> Electronic Arts)
Task: {52DB3A65-99B2-4D7C-9ED3-CB3A2EBAB1EF} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
Task: {53B92958-CD29-497A-A85B-2B33B17109AE} - System32\Tasks\{E1749980-F5DA-4590-A08E-9169D40C7718} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {54824A38-D896-425C-BCF8-AA2D26679910} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {5AA10760-BE21-4D4E-9209-42C47A435442} - System32\Tasks\{5DF00143-772E-4B3B-8507-58754AE42977} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {5ED77E08-7CD3-4397-A7C3-C0229B3A7055} - System32\Tasks\{6B31736A-6278-469F-81CD-552E77A4FA59} => C:\Program Files (x86)\Steam\SteamApps\common\Gothic II\system\Gothic2.exe
Task: {6141EC76-89A0-4D8B-8D0D-48BE8ED70F64} - System32\Tasks\{CA27AFC5-F852-4F95-8316-78BC5B743824} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {6161B3D6-2460-4CF7-9B8F-2EF76385CF0C} - System32\Tasks\{30458D52-74F8-4491-B7E7-168B3D1AB90E} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {6193C9E7-577A-4897-B199-594DCB1F18E0} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
Task: {667D910E-B2B6-45DE-BA35-B5B9D65665C9} - System32\Tasks\{FCB7722A-BA79-40AF-898B-7D917CE6F157} => C:\Windows\system32\pcalua.exe -a D:\SETUP.EXE -d D:\
Task: {67A016BE-A0D4-4D3D-9569-9EECBF67BC63} - System32\Tasks\{8726F4A6-54A3-48E5-96E0-F499B2FD155B} => D:\AutoRun.exe (Electronic Arts -> Electronic Arts)
Task: {682021CC-CAE5-4FC9-93B2-628B7138926F} - System32\Tasks\{08E8A4E1-CDBC-4505-9986-7C86FDC10D2F} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {6A82FD88-7BC2-4F2A-BFE2-4D77958F6FF3} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_148_Plugin.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {6D846D37-0C9F-4E86-99CA-0F61171B961A} - System32\Tasks\{73BDECF5-8546-4BC3-AD24-3C1FA7B26EEF} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {715A9B79-8442-40E1-B970-9A97F81D5C33} - System32\Tasks\{819117DF-2C60-4580-A8D4-1F4D28EFC4F4} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {7615721C-5ECC-49D2-A437-D831B1B0A6E9} - System32\Tasks\{E1970A79-774F-459D-A24D-CF28D1CBC85E} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {79B66D6B-B4E9-43B3-9822-C5B8038B02DF} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Adobe Systems, Incorporated -> Adobe Systems Incorporated)
Task: {79E17E27-1058-4F53-9FA2-0FD37D9DBCD9} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {79EC9E25-97D3-470D-9740-7876CDB57768} - System32\Tasks\{151519CA-83FB-4941-B002-0389275A7E1B} => C:\Program Files (x86)\Age Of Empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
Task: {7EE64610-BD46-4CF0-87EE-CA404F350EDE} - System32\Tasks\{25D989B4-4A84-4CEE-B65B-024D7A84254D} => D:\Autorun.exe (Electronic Arts -> Electronic Arts)
Task: {7F6312D5-2488-4AA3-8BED-9EE519CADDA4} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe
Task: {892DE9C3-E66A-4F9A-8E71-BF321F2A7038} - System32\Tasks\{E0F6D1F8-EAA0-4667-9D3E-59D00319068A} => D:\Risen + Patch + vylepšená čeština\Risen Patch 1.10.exe
Task: {8AB2C11B-E1FE-48E5-B6EE-350FA3E237B4} - System32\Tasks\HP AR Program Upload - a2117a7e53ab4c84b6308c4cbe7a62061eadb7dc98024e7aacd12392bbd167b4 => C:\Program Files\HP\HP DeskJet 2130 series\bin\HPRewards.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {8C497E3E-F4EC-4AC5-BC92-9D3DCF959C14} - System32\Tasks\{746E7386-F34A-4954-9FBC-31176C530B09} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
Task: {8CD3C536-867C-40E7-899C-803B21E66796} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe (AVG Technologies USA, Inc. -> AVG Technologies CZ, s.r.o.)
Task: {8D944BC7-E1C4-41B3-8830-E010C030CC8E} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe (Advanced Micro Devices, Inc. -> Advanced Micro Devices, Inc.)
Task: {902F7F26-B353-401F-99DF-193CEC380E9D} - System32\Tasks\{26EE770A-BCB5-4873-8D93-4DF4C0D09DBC} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {931DFD35-68FF-4794-9B63-2D0DE7F93AE5} - System32\Tasks\{DC772FFA-4A6E-4CCE-9DDA-64C517F4838D} => C:\Windows\system32\pcalua.exe -a "C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9T6CLWC5\hoi3_1.4.exe" -d C:\Users\Administrator\Desktop
Task: {98E57C38-C4CD-49D7-AEFF-5D2700809D68} - System32\Tasks\AdobeAAMUpdater-1.0-ADMIN-PC-Administrator => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {98FC3BE4-6621-4C39-B497-657CAEB28DD8} - System32\Tasks\{A3CC4A88-C591-4B54-AF4F-BFCC37B411B0} => D:\Autorun.exe (Electronic Arts -> Electronic Arts)
Task: {9C2B3EF7-5BAD-4C20-93A4-544426E7CC18} - System32\Tasks\{15036C21-3ACC-43B7-970B-A5AB6646F0C9} => C:\Program Files\CCleaner\CCleaner64.exe
Task: {9F3D494F-2DD5-4A14-829C-6E425A1E03B5} - System32\Tasks\{53F756DB-A046-428F-9044-F0F579A12653} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{CE244E07-B58F-4140-806F-34FB0CDDE8CA}\setup.exe" -d "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sega\Medieval II Total War Kingdoms" -c -runfromtemp -l0x0005
Task: {9F55B887-85F7-48E8-A7CA-AB0A0A98E2BF} - System32\Tasks\{978A0DA8-914E-48CB-9195-4078DEAF33C1} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Ubisoft\Heroes of Might and Magic V - Tribes of the East\heroes_might_magic_5_3.01_cz.exe" -d "C:\Program Files (x86)\Ubisoft\Heroes of Might and Magic V - Tribes of the East"
Task: {A15664A1-C95A-48E4-AC4D-0A40254CCDF4} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {A37BB895-3ECB-405A-AEC1-474582D89CA0} - System32\Tasks\{BF0A20F3-0C2A-476C-9EAA-7D2C55E452D0} => D:\Risen + Patch + vylepšená čeština\Risen Patch 1.10.exe
Task: {A4C73A2E-EAF3-4341-B33C-94F0508C1168} - System32\Tasks\SUPERAntiSpyware Scheduled Task 9d2d795a-b34c-49d3-814c-de6cf94ec229 => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com)
Task: {B3F0CCB0-A727-43AA-9A69-CBBC6E56C387} - System32\Tasks\{1FE2674D-69E3-4531-BBEC-BE1CA3AF32E8} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {B5410806-C4F3-49D2-BA76-5785D26B88E5} - System32\Tasks\{1B207D06-99EA-49AE-9B2D-294F5902BC4C} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Steam\steamapps\common\Alien Swarm\bin\addoninstaller.exe" -d "C:\Program Files (x86)\Steam\SteamApps\common\GarrysMod\garrysmod" -c C:\PROGRA~2\Steam\STEAMA~1\common\GARRYS~1\GARRYS~1\GARRYS~2.VPK
Task: {B6DF8D4B-C7B3-47AE-B8E7-ED919CD1A0DA} - System32\Tasks\{BF2DF2C2-1ECE-4CE7-AA23-E5D0BA0A06E4} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {B98D59AA-E7E0-4F45-9385-FB965E41C131} - System32\Tasks\Opera scheduled Autoupdate 1530486457 => C:\Users\Administrator\AppData\Local\Programs\Opera\launcher.exe
Task: {BA8CAC91-7C48-467F-90CA-EB3B8B113FE7} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {BAA8B25F-7BCF-4498-9650-94DA9FF9E79B} - System32\Tasks\HPCustPartic.exe_{409651EB-2226-4C5E-BA50-7120A5269552} => C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPCustPartic.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
Task: {BDEA8E13-BC13-42D3-BADC-8C84FA900CFC} - System32\Tasks\{4D240894-076B-4C12-8648-D6BF9A23F377} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\Sims3EP02Setup.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {C6D6692F-78A4-40F1-B259-98FCB1462A17} - System32\Tasks\{32463B7F-F502-47E9-9143-A735E29B1503} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {C9530638-2B67-4336-9CBE-E7E8D670896E} - System32\Tasks\{98590E16-2005-47C7-A828-946948897037} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {CA32004C-6DD3-40AB-B41F-CD9D1087841C} - System32\Tasks\{7217401C-EE41-49C7-9B37-26EEE26221AF} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
Task: {CB249EC1-00BF-4718-BBF4-463D7AE12CB7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {CFDFB350-E83D-41FD-B1E3-B6640530D538} - System32\Tasks\{57C902FD-F38C-458A-8CAA-5A277FBA08CB} => C:\Program Files (x86)\Steam\steamapps\common\Empire Total War\Empire.exe
Task: {D06270C6-9179-4B62-8F62-0D952F70F89C} - System32\Tasks\{46BB9BC9-5504-4F9A-9146-98899054FB43} => C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
Task: {D26005B3-E9CA-4160-83A7-CD582622C48E} - System32\Tasks\{28A2DC60-0511-4AA5-A6B3-08257BC60EF0} => C:\Program Files (x86)\Lionhead Studios Ltd\The Movies\Movies.exe
Task: {D5E8E47D-F3EC-4F82-B42F-FA95291F4717} - System32\Tasks\{E37B2754-3634-4603-99D3-77DF90A15555} => C:\Program Files (x86)\Age Of Empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
Task: {DAF12EA7-D22B-44BA-A0A2-D1087FDC671A} - System32\Tasks\{51C41640-BE40-40E9-BA66-756505B87FE5} => C:\Program Files (x86)\Steam\SteamApps\common\Bioshock\Builds\Release\Bioshock.exe
Task: {E3B2EC09-8EDC-4498-A505-83E88589F0C0} - System32\Tasks\{4805FB4B-9F97-4F6F-9C79-B23921F99D75} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\setup.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {EA7F8B55-7960-4E20-8DD8-0A75194CA695} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {ECC58CBC-C99B-44E6-8EDE-BC060BB24E9A} - System32\Tasks\{E78E862C-9149-4E0A-88CC-990E9FE22638} => C:\Program Files (x86)\Age Of Empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
Task: {F1817AE5-F9A6-453B-BA6E-117B53125071} - System32\Tasks\{728C7FD9-30FD-4B5B-8F3E-8C22DADF8C6B} => D:\Autorun.exe (Electronic Arts -> Electronic Arts)
Task: {F2A89620-66EE-4B8C-B43E-93161ED0EE5D} - System32\Tasks\{832C4EA8-933D-4170-90C5-94DAEBFE1C13} => C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
Task: {FA3F1A23-F6D4-4716-B652-BDF0740E79C2} - System32\Tasks\{285B9AA6-8812-4D13-9D91-355216778D5F} => C:\Program Files (x86)\Steam\SteamApps\common\Empire Total War\Empire.exe
Task: {FB1AB947-7951-4ACD-9D1D-A2085A4FE933} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
Task: {FBE09F3D-BE9D-4CE9-8B29-8A49F5DA837B} - System32\Tasks\{C0A70CD7-9EB1-47A1-A89B-FBAB93237DF7} => D:\Autorun.exe (Electronic Arts -> Electronic Arts)
Task: {FDC58DD5-D1B1-4375-92E2-CAEA8588A1C0} - System32\Tasks\SUPERAntiSpyware Scheduled Task e0753663-4f82-43bb-9fee-97b95ff7ab79 => C:\Program Files\SUPERAntiSpyware\SASTask.exe (SUPERAntiSpyware.com -> SUPERAdBlocker.com)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 9d2d795a-b34c-49d3-814c-de6cf94ec229.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task e0753663-4f82-43bb-9fee-97b95ff7ab79.job => C:\Program Files\SUPERAntiSpyware\SASTask.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Task: C:\Windows\Tasks\Wise Care 365.job => C:\anivir\Wise Care 365\WiseTray.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]

==================== Loaded Modules (Whitelisted) ==============

2017-06-12 15:34 - 2017-06-12 15:34 - 000121856 _____ (Advanced Micro Devices) [File not signed] C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\24502910.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\24502910.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2019-03-06 14:08 - 000000076 _____ C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost
0.0.0.1 mssplus.mcafee.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-257039076-1346926551-2253569639-500\Control Panel\Desktop\\Wallpaper -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 10.112.1.1 - 10.112.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

MSCONFIG\Services: MBAMService => 2
MSCONFIG\startupfolder: C:^Users^Administrator^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^GameRanger.lnk => C:\Windows\pss\GameRanger.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Administrator^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Odeslat do OneNote.lnk => C:\Windows\pss\Odeslat do OneNote.lnk.Startup
MSCONFIG\startupreg: BDRegion => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: DAEMON Tools Pro Agent => "C:\Program Files (x86)\DAEMON Tools Pro\DTAgent.exe" -autorun
MSCONFIG\startupreg: EADM => "C:\Program Files (x86)\Origin\Origin.exe" -AutoStart
MSCONFIG\startupreg: LGODDFU => C:\Program Files (x86)\lg_fwupdate\lgfw.exe blrun
MSCONFIG\startupreg: Raptr => "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{BEA15B44-EA55-4145-ADA8-74F50907E605}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe (Ubisoft Entertainment Sweden AB -> Ubisoft)
FirewallRules: [{F49F752B-0C5A-4043-ADF2-C2F9D8A0FE65}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe (Ubisoft Entertainment Sweden AB -> Ubisoft)
FirewallRules: [{28D78379-A2AC-4B6A-BC37-F739C73EF18E}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
FirewallRules: [{92246CC2-E162-4CA6-B833-AE95D8F29487}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
FirewallRules: [{236F6004-510D-49D2-9C4C-9877F3BC3946}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
FirewallRules: [{A1140A13-2AA6-4439-A168-E0FA543E07A7}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
FirewallRules: [{70B338D4-8349-4DC1-B3FB-C893D00B3967}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\InitEngine.exe (Related Designs Software -> ) [File not signed]
FirewallRules: [{1C0181AE-5AF0-4A6B-9933-6AF4578E97E2}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\InitEngine.exe (Related Designs Software -> ) [File not signed]
FirewallRules: [{2F203CD0-60F6-4487-90F8-01FBE47FC961}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\Anno4.exe (Related Designs Software -> Related Designs)
FirewallRules: [{2DE102A3-5991-4C06-BA0E-111ACC705656}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\Anno4.exe (Related Designs Software -> Related Designs)
FirewallRules: [{A1F79440-7484-4990-92ED-74E5025FBAA1}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\Addon.exe (Related Designs Software -> Related Designs)
FirewallRules: [{04D03832-6D62-40ED-A2F8-1919A6E1965E}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\Addon.exe (Related Designs Software -> Related Designs)
FirewallRules: [{7C4586C6-64CC-4E15-974F-C31DFC095D05}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\Anno4Web.exe (Related Designs Software -> )
FirewallRules: [{15716AD2-0655-421A-BD62-9FA15E4B4FC7}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\Anno4Web.exe (Related Designs Software -> )
FirewallRules: [{F9AFB658-13F0-4CE8-A634-9A10C1F367A4}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\AddonWeb.exe (Related Designs Software -> )
FirewallRules: [{C3E18BC7-1492-440A-AC8F-9A9DF279968B}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\AddonWeb.exe (Related Designs Software -> )
FirewallRules: [{F4E8E005-797B-46FC-81AB-EC6ED30861A4}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\Benchmark.exe (Related Designs Software -> )
FirewallRules: [{F51FB61F-8F45-42BC-A938-49EB651CEB37}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 1404 - Gold Edition\tools\Benchmark.exe (Related Designs Software -> )
FirewallRules: [{C9096135-5777-4830-B8E0-C3E6ED24313E}] => (Allow) C:\Program Files (x86)\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe (Limbic Entertainment GmbH -> Black Hole Entertainment)
FirewallRules: [{EEA4E85C-904C-4349-8818-5EDEB403DFDC}] => (Allow) C:\Program Files (x86)\Ubisoft\Might & Magic Heroes VI\Might & Magic Heroes VI.exe (Limbic Entertainment GmbH -> Black Hole Entertainment)
FirewallRules: [TCP Query User{985065B0-EA84-4D09-9948-447AC0BC7A47}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\anno4web.exe] => (Block) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\anno4web.exe (Related Designs Software -> )
FirewallRules: [UDP Query User{B518CA44-4DDE-4239-8676-30791E517AA6}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\anno4web.exe] => (Block) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\anno4web.exe (Related Designs Software -> )
FirewallRules: [{49AFDB75-E204-4A8C-B31D-7BAFCAD9DDFC}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{3BAE2C44-1F4F-4FEC-9D89-FB7C90094D49}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{FA10FF74-CE3F-4BDC-8EBD-183723D9E650}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{BF5FB0A0-0762-432E-9BF7-2E32AF0B8F99}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe (Valve -> Valve Corporation)
FirewallRules: [{4AAD513A-0CE3-4CDB-85A4-F0F66C1A63B5}] => (Allow) C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
FirewallRules: [{24D8CAFD-65F4-4118-9830-02E0DB44DC38}] => (Allow) C:\Program Files (x86)\Microsoft Games\Zoo Tycoon 2\zt.exe (Microsoft Corporation) [File not signed]
FirewallRules: [TCP Query User{28ED862D-0A75-4BB0-8AB1-1E7EDADE347D}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\addonweb.exe] => (Block) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\addonweb.exe (Related Designs Software -> )
FirewallRules: [UDP Query User{234FB3A0-66F6-4BF7-99E5-325A3275D6B2}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\addonweb.exe] => (Block) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\tools\addonweb.exe (Related Designs Software -> )
FirewallRules: [{743747BE-745A-41D3-B659-B1A684AA794F}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
FirewallRules: [{52846B5F-187B-4F1C-B0DF-358C885A3556}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\Anno5.exe (Related Designs Software -> Related Designs) [File not signed]
FirewallRules: [{7ACA7CF5-5648-4516-B900-E32AEE51A603}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
FirewallRules: [{A79F0249-8D30-4AB0-9F13-73B2BDD69E95}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\AutoPatcher.exe (Related Designs Software -> Related Designs Software) [File not signed]
FirewallRules: [{1EB5E209-0FD9-47AD-917F-BD7C0E73DE2A}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\InitEngine.exe (Related Designs Software -> ) [File not signed]
FirewallRules: [{E75F2D6E-F57A-4C8B-B7FB-8814F19DEE1D}] => (Allow) C:\Program Files (x86)\Ubisoft\Related Designs\ANNO 2070\InitEngine.exe (Related Designs Software -> ) [File not signed]
FirewallRules: [TCP Query User{8BC3D5C3-530F-43BF-9E55-E8F42BD36B53}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\addon.exe] => (Allow) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\addon.exe (Related Designs Software -> Related Designs)
FirewallRules: [UDP Query User{EC753F73-60ED-47D0-BBCC-E8F204C1A6D8}C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\addon.exe] => (Allow) C:\program files (x86)\ubisoft\related designs\anno 1404 - gold edition\addon.exe (Related Designs Software -> Related Designs)
FirewallRules: [TCP Query User{1C9F73D7-55DD-4604-A763-547883A6734E}C:\program files (x86)\age of empires 3\age3y.exe] => (Allow) C:\program files (x86)\age of empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [UDP Query User{E6ED9DC6-D0C8-4AA6-B926-62E3AA345FD4}C:\program files (x86)\age of empires 3\age3y.exe] => (Allow) C:\program files (x86)\age of empires 3\age3y.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{92F473F0-3C42-48EB-8616-DB8C5CF5FB0D}C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe] => (Allow) C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe (Team 17 Ltd) [File not signed]
FirewallRules: [UDP Query User{D7758813-EF46-41DF-9F00-4F6ADBE36120}C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe] => (Allow) C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe (Team 17 Ltd) [File not signed]
FirewallRules: [{88E70ABE-3A7A-4931-8CCC-5777FBB48E1F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Neighbours from Hell\bin\game.exe (JoWooD Studio Vienna) [File not signed]
FirewallRules: [{BA93AC7F-6EF7-44F2-B372-48BD5D9EF752}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Neighbours from Hell\bin\game.exe (JoWooD Studio Vienna) [File not signed]
FirewallRules: [{6E6D5AE8-F635-498E-B2BE-C6F5125BD3DF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Neighbours from Hell 2\bin\game.exe (JoWooD Studio Vienna) [File not signed]
FirewallRules: [{50C6396B-AD26-4222-A2E4-3E26353E0B36}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Neighbours from Hell 2\bin\game.exe (JoWooD Studio Vienna) [File not signed]
FirewallRules: [{959F1030-AFC8-4C70-A914-2835554059E5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe (CyberLink -> CyberLink Corp.)
FirewallRules: [{FA897948-1CE6-4C02-A12A-D01225A11E7F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE (CyberLink -> CyberLink Corp.)
FirewallRules: [{DD3C6F52-6AF5-4683-AF31-281309C5E1C2}] => (Allow) C:\Users\Administrator\AppData\Roaming\uTorrent\utorrent.exe No File
FirewallRules: [{FDB85F1C-BF09-4ADB-82B1-C4FA7CFBE052}] => (Allow) C:\Users\Administrator\AppData\Roaming\uTorrent\utorrent.exe No File
FirewallRules: [{792BE7CE-54F1-4B09-A3BB-B1721EF1FC71}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe (Nero AG -> Nero AG)
FirewallRules: [{DA876E1F-91C2-49E2-8AAD-93EB70512E8D}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe (Nero AG -> Nero AG)
FirewallRules: [{CE5EF173-61F7-403D-8928-73F2FA985A4D}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe (Nero AG -> Nero AG)
FirewallRules: [{FC41B5C4-A076-48AD-B3CD-709877F781D7}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe (Nero AG -> Nero AG)
FirewallRules: [TCP Query User{C800931B-FA4C-4694-BB74-A4956C95265A}C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe] => (Allow) C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe (Team 17 Ltd) [File not signed]
FirewallRules: [UDP Query User{3B12D9CA-6EFD-459A-8A0E-C0ACF67EEAB8}C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe] => (Allow) C:\program files (x86)\codemasters\worms 4 mayhem\worms 4 mayhem.exe (Team 17 Ltd) [File not signed]
FirewallRules: [TCP Query User{A33FD36D-9EED-428F-8E5C-7CE5487A9E63}C:\program files\armies of exigo\exigo.exe] => (Allow) C:\program files\armies of exigo\exigo.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [UDP Query User{D064A652-5467-48AA-A5F6-9822C977D90D}C:\program files\armies of exigo\exigo.exe] => (Allow) C:\program files\armies of exigo\exigo.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [TCP Query User{079285FE-5818-43A2-A84B-40FBF2D1AE6A}C:\program files (x86)\ubisoft\heroes of might and magic v - tribes of the east\bin\h5_game.exe] => (Allow) C:\program files (x86)\ubisoft\heroes of might and magic v - tribes of the east\bin\h5_game.exe (Nival Interactive, Inc -> )
FirewallRules: [UDP Query User{A6DA11BD-42BF-4103-A1EF-FDD9A024CA41}C:\program files (x86)\ubisoft\heroes of might and magic v - tribes of the east\bin\h5_game.exe] => (Allow) C:\program files (x86)\ubisoft\heroes of might and magic v - tribes of the east\bin\h5_game.exe (Nival Interactive, Inc -> )
FirewallRules: [TCP Query User{94FB354C-B1ED-4CFC-BCB9-A94C6460BAA3}C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe] => (Block) C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe () [File not signed]
FirewallRules: [UDP Query User{E695E9DD-BB10-4A09-B909-2C12224CB70F}C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe] => (Block) C:\program files (x86)\firefly studios\stronghold crusader\stronghold crusader.exe () [File not signed]
FirewallRules: [TCP Query User{96F8DB11-543C-455E-8BF3-6AAEE3AF1F98}C:\windows\syswow64\dplaysvr.exe] => (Block) C:\windows\syswow64\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [UDP Query User{F62DD7FD-1344-4C79-ACBA-14E4CBCA6F9F}C:\windows\syswow64\dplaysvr.exe] => (Block) C:\windows\syswow64\dplaysvr.exe (Microsoft Windows -> Microsoft Corporation)
FirewallRules: [TCP Query User{1998C22A-6517-424F-B832-9A5CF06E8121}C:\program files\castle strike\castlestrike.exe] => (Allow) C:\program files\castle strike\castlestrike.exe (Related Designs Software GmbH) [File not signed]
FirewallRules: [UDP Query User{36EBA28E-72BE-40A0-A8CF-69B3614C5B26}C:\program files\castle strike\castlestrike.exe] => (Allow) C:\program files\castle strike\castlestrike.exe (Related Designs Software GmbH) [File not signed]
FirewallRules: [TCP Query User{09D7471D-3A6A-4DF7-8C67-76D264F45678}C:\program files (x86)\age of empires 3\age3x.exe] => (Allow) C:\program files (x86)\age of empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
FirewallRules: [UDP Query User{AE3C9E3C-3A0E-434B-94E2-309DB22BF232}C:\program files (x86)\age of empires 3\age3x.exe] => (Allow) C:\program files (x86)\age of empires 3\age3x.exe (Microsoft Corporation -> Ensemble Studios)
FirewallRules: [TCP Query User{6A684956-549A-4D1D-A351-335692EE8B75}C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe] => (Block) C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe () [File not signed]
FirewallRules: [UDP Query User{B8C63F59-9944-4B77-8CF8-8A6549D4C263}C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe] => (Block) C:\program files (x86)\ubisoft\heroes of might and magic v\bin\h5_game.exe () [File not signed]
FirewallRules: [TCP Query User{DAB239BB-DBFF-4DA8-A30B-4AF61EA19139}C:\program files\armies of exigo\exigo.exe] => (Block) C:\program files\armies of exigo\exigo.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [UDP Query User{29E5F875-F19C-4AE6-9811-43657E62FB01}C:\program files\armies of exigo\exigo.exe] => (Block) C:\program files\armies of exigo\exigo.exe (Black Hole Entertainment) [File not signed]
FirewallRules: [{F3730381-490D-4678-A27B-5984F1D76D7F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe () [File not signed]
FirewallRules: [{19141D14-3F33-4906-8EE0-4C03772C4931}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe () [File not signed]
FirewallRules: [{9DEE1F3A-9D01-45F9-AE41-16C18C81BBC0}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SourceFilmmaker\game\sfm.exe () [File not signed]
FirewallRules: [{706AFA49-0009-4F8F-8A4F-A26C2C413720}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SourceFilmmaker\game\sfm.exe () [File not signed]
FirewallRules: [{0B9C3232-49AA-4C16-B850-8985D48A0383}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SourceFilmmaker\game\bin\qsdklauncher.exe () [File not signed]
FirewallRules: [{A1ED00FD-3001-483F-A411-9FF9408CC868}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\SourceFilmmaker\game\bin\qsdklauncher.exe () [File not signed]
FirewallRules: [{89F8147B-0FFA-4A72-B8CB-FCA7A9079838}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{5488EB57-8C72-4BFF-8659-76220678A9D7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader Extreme\Stronghold Crusader.exe ( ) [File not signed]
FirewallRules: [{A792D2A8-4403-4DAF-96D1-2C8D12637886}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader Extreme\Stronghold Crusader.exe ( ) [File not signed]
FirewallRules: [{4BDBE048-05F9-427E-9913-233D3DE5C3B7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader Extreme\Stronghold_Crusader_Extreme.exe ( ) [File not signed]
FirewallRules: [{CACABB5E-E625-492C-9675-6FCC58B8942B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader Extreme\Stronghold_Crusader_Extreme.exe ( ) [File not signed]
FirewallRules: [{336CB1A7-C4EE-4615-A88F-509701C92D2E}] => (Allow) C:\Program Files (x86)\NAMCO BANDAI Games\DarkSouls\DARKSOULS.exe (FromSoftware,Inc. -> NAMCO BANDAI Games Inc.)
FirewallRules: [TCP Query User{FEDF92D1-8720-4C90-A5E4-AE88EDE3449E}C:\program files (x86)\namco bandai games\darksouls\data.exe] => (Allow) C:\program files (x86)\namco bandai games\darksouls\data.exe (n-Space, Inc. -> NAMCO BANDAI Games Inc.) [File not signed]
FirewallRules: [UDP Query User{EBEF7C02-2FFE-4B89-B45F-F26AE7918B2B}C:\program files (x86)\namco bandai games\darksouls\data.exe] => (Allow) C:\program files (x86)\namco bandai games\darksouls\data.exe (n-Space, Inc. -> NAMCO BANDAI Games Inc.) [File not signed]
FirewallRules: [{872D8076-6A29-441E-BFD1-2FDB001BC732}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe () [File not signed]
FirewallRules: [{1FFCD96F-6EB1-4E43-98BB-3143D4479564}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\State of Decay\StateOfDecay.exe () [File not signed]
FirewallRules: [{5A464C4F-B26C-4FBF-AC9B-CA7175038A85}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Victoria 2\victoria2.exe (Paradox Interactive) [File not signed]
FirewallRules: [{DB8B71DD-5D74-4B8E-B0DC-300850C9BA10}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Victoria 2\victoria2.exe (Paradox Interactive) [File not signed]
FirewallRules: [TCP Query User{EDD3B532-F143-477C-ADF1-33EFF81801E5}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [UDP Query User{99B58E7D-6144-4BF5-A109-57E4323BED95}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [TCP Query User{C4305E5D-B0AC-4AD0-8AFA-4E96FCDFE600}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [UDP Query User{FA4D6115-7070-4618-87C0-593CBAA56ACB}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [{D451BB35-3691-4E87-B965-7F42C8B782CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe ( Taleworlds Entertainment) [File not signed]
FirewallRules: [{6D5D5F99-1171-4AA1-966B-7DC87F9F1B28}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\MountBlade Warband\mb_warband.exe ( Taleworlds Entertainment) [File not signed]
FirewallRules: [TCP Query User{6CA5446F-DC25-405E-B02C-853092149EBA}C:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe () [File not signed]
FirewallRules: [UDP Query User{55942948-7F73-4481-BFC2-EAD09C033A3B}C:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\garrysmod\hl2.exe () [File not signed]
FirewallRules: [{010922A7-A153-408A-8DAC-F1C6D4626FFD}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe (Nero AG -> Nero AG)
FirewallRules: [{3037D520-8A85-42E5-B9CE-65A038415768}] => (Allow) C:\Program Files (x86)\Nero\Nero Blu-ray Player\Blu-rayPlayer.exe (Nero AG -> Nero AG)
FirewallRules: [{686E797B-AF28-4065-9E9E-B1E5B5983546}] => (Allow) C:\Program Files (x86)\Nero\KM\NMDllHost.exe (Nero AG -> Nero AG)
FirewallRules: [{AB4E0414-8059-4F0F-8F2F-17008F02ED47}] => (Allow) C:\Program Files (x86)\Ubisoft\The Settlers 7 - CESTA KE KORUNĚ\Data\Base\_Dbg\Bin\Release\Settlers7R.exe (Blue Byte GmbH -> Blue Byte GmbH)
FirewallRules: [{25F5BE7E-8E0A-40A2-9025-AC27B4CDB83F}] => (Allow) C:\Program Files (x86)\Ubisoft\The Settlers 7 - CESTA KE KORUNĚ\Data\Base\_Dbg\Bin\Release\Settlers7R.exe (Blue Byte GmbH -> Blue Byte GmbH)
FirewallRules: [{CD19EA84-D5FE-414F-81DC-EA4840C67FD4}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{99DEAA28-7B30-4A0F-A7DF-BD64B327BDDF}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{89CD386B-BA42-404D-9E52-0002D57330ED}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe No File
FirewallRules: [{73E2728A-B45F-42D1-BF39-5E190A46E1D7}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe No File
FirewallRules: [{A68836BF-68D5-4F6A-A0FE-FB295ECC7F94}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{093E297B-91B8-4214-A12E-CA3E905A361B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{A2D78074-AAB7-4DFC-970D-E52F77BC6E7B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AdVenture Capitalist\adventure-capitalist.exe () [File not signed]
FirewallRules: [{4C9644D3-E787-4DAA-B271-9D034A036D11}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\AdVenture Capitalist\adventure-capitalist.exe () [File not signed]
FirewallRules: [{B4D8FE70-8E56-4FAC-B112-D6ACE9C24AD2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\iambread\IamBread.exe (Unity Technologies SF -> ) [File not signed]
FirewallRules: [{1184F69A-65AA-41CA-9AE1-6708D11706E6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\iambread\IamBread.exe (Unity Technologies SF -> ) [File not signed]
FirewallRules: [{0F64D39D-FAF5-49D6-AB0C-352889F6FCF4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Apotheon\Apotheon.exe (Microsoft) [File not signed]
FirewallRules: [{061989DC-4176-4C45-9DCC-E12135418C6B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Apotheon\Apotheon.exe (Microsoft) [File not signed]
FirewallRules: [{61916A64-7406-4CEC-830F-30A323B78C83}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Guild 2 Renaissance\GuildII.exe (Runeforge Game Studio) [File not signed]
FirewallRules: [{4191FDC6-2AB3-47F2-969F-D54F3FDA8E48}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Guild 2 Renaissance\GuildII.exe (Runeforge Game Studio) [File not signed]
FirewallRules: [{BB30FFFD-4F78-48BC-ADB0-411B99F834E8}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Guild II - Pirates of the European Seas\GuildII.exe (4HEAD Studios) [File not signed]
FirewallRules: [{BF6419CD-BF24-42C2-AD8E-D72E63580113}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\The Guild II - Pirates of the European Seas\GuildII.exe (4HEAD Studios) [File not signed]
FirewallRules: [{45B6B832-6E77-4783-AC35-EF78B6FD1D63}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rock of Ages\Binaries\Win32\RoA.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{089F4BF1-254A-457D-9E55-05E6A1B2542F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Rock of Ages\Binaries\Win32\RoA.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{84FC1AE5-610A-4262-BF8A-BFB685E5C163}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{60A61548-FE89-4EE8-86C2-9A8A22A80466}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{13D7323E-6794-4573-9FEF-1554C43863CA}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{AC22260F-443C-484D-AAC0-1BF3E9206B22}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{CEF1AAB3-EB49-4866-A18C-E9A5E4216F5E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Might and Magic Heroes VII\Binaries\Win64\MMH7Game-Win64-Shipping.exe (Limbic Entertainment GmbH -> Ubisoft, Inc.)
FirewallRules: [{4ADF479A-134E-4F42-B779-B9610B3D782B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader 2\bin\win32_release\Crusader2.exe () [File not signed]
FirewallRules: [{8C3868F1-A06C-4002-844A-03913860E93E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Stronghold Crusader 2\bin\win32_release\Crusader2.exe () [File not signed]
FirewallRules: [{9BA1A3A3-E14F-4361-B1E4-CED7060C0FB2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas enplczru\FalloutNVLauncher.exe (Bethesda Softworks, Obsidian Entertainment) [File not signed]
FirewallRules: [{0A69DC94-8EE9-4CD3-AF47-43D550474BF2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas enplczru\FalloutNVLauncher.exe (Bethesda Softworks, Obsidian Entertainment) [File not signed]
FirewallRules: [{733A54AC-B9F1-49F7-B6AF-5662AA9327C6}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{7812706A-B4D0-4B21-8302-90B08E8700AC}] => (Allow) LPort=2869
FirewallRules: [{2CC193C1-6D7C-48E2-BC7E-22C6B8F17323}] => (Allow) LPort=1900
FirewallRules: [{D062E605-9018-4C9F-B884-326F95BB2E28}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa 1400 The Guild - Gold Edition\Europa1400Gold.exe () [File not signed]
FirewallRules: [{55952F7D-EF02-4CEB-90AC-A4F267878AB4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa 1400 The Guild - Gold Edition\Europa1400Gold.exe () [File not signed]
FirewallRules: [{119BD324-E3F4-4977-96F4-74B4C7601E26}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa 1400 The Guild - Gold Edition\Europa1400Gold_TL.exe () [File not signed]
FirewallRules: [{2F26E480-2553-4D25-AB33-5FDE7A9EEEBC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa 1400 The Guild - Gold Edition\Europa1400Gold_TL.exe () [File not signed]
FirewallRules: [{D390311F-35A4-47CF-A52B-18D9B7DE2CAC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{6F85A45C-C855-43F5-B63E-9968781A8DD6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{EFBDABBC-E5C9-4AC1-B0F5-054281F09607}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{10591F70-AECC-4E24-8BEB-D128F2421FAA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{6696B94F-B0E6-44FA-B0DA-15EA07B53489}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sengoku\Sengoku.exe (Paradox Interactive) [File not signed]
FirewallRules: [{26F65DB8-02F9-437B-9B43-2E61EAEBFE5F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sengoku\Sengoku.exe (Paradox Interactive) [File not signed]
FirewallRules: [TCP Query User{3B72941E-6534-443C-B4D8-51646F552A41}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe No File
FirewallRules: [UDP Query User{9287E7E8-5037-4629-B719-AD2F62B30C1C}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe No File
FirewallRules: [{3F4F200E-E157-4B4E-8D67-E7648D7374F4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Haunt the House Terrortown\HauntTheHouseTerrortown.exe () [File not signed]
FirewallRules: [{236E56A2-02D5-4288-895A-FC13657FBFE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Haunt the House Terrortown\HauntTheHouseTerrortown.exe () [File not signed]
FirewallRules: [{167E6F72-D70C-4B28-8635-64896E17002F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PlagueInc\PlagueIncEvolved.exe () [File not signed]
FirewallRules: [{D4A03C79-6FCF-4E5C-B524-D862D98D01AE}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\PlagueInc\PlagueIncEvolved.exe () [File not signed]
FirewallRules: [TCP Query User{1F9C43EF-7928-47EA-8CC2-18DF91C90664}C:\program files (x86)\steam\steamapps\common\life is strange\binaries\win32\lifeisstrange.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\life is strange\binaries\win32\lifeisstrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [UDP Query User{4C93E747-EDF5-43BB-A80E-D7F6A8D20170}C:\program files (x86)\steam\steamapps\common\life is strange\binaries\win32\lifeisstrange.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\life is strange\binaries\win32\lifeisstrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{99AA2B2F-E91D-4554-8E0D-0EFA4F006C25}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{4C230EA1-3209-46B1-841F-ED1C20712590}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{70425B0D-CCF0-4B2B-A0A8-1F40F4485532}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis IV\eu4.exe (Paradox Interactive) [File not signed]
FirewallRules: [{78992616-1DB6-4E12-92E8-EF84662CCC17}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Europa Universalis IV\eu4.exe (Paradox Interactive) [File not signed]
FirewallRules: [{B771F328-B1CA-427D-A60A-A4C581EA56FF}] => (Allow) C:\Program Files\HP\HP DeskJet 2130 series\Bin\USBSetup.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
FirewallRules: [{1BF26DE9-E742-4788-AFEA-1DF14359B512}] => (Allow) C:\Program Files\HP\HP DeskJet 2130 series\Bin\HPNetworkCommunicatorCom.exe (Hewlett Packard -> Hewlett-Packard Development Company, LP)
FirewallRules: [{EC37AB6E-1F03-41A1-8687-F90E25A8750F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{FA1C9A6B-E12B-407C-9760-0A61D3188723}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\GoatSimulator\Binaries\Win32\GoatGame-Win32-Shipping.exe (Epic Games, Inc.) [File not signed]
FirewallRules: [{F1B7BD0F-5A29-44DA-A00B-D2A31AAA5DFA}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{F6E8E4B6-51C2-4B94-B01C-F5974294D39D}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{8A018B69-DBA9-43BA-9A32-A28F45562E4E}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{0835B4FC-82BA-41A9-B607-6BF90CB787EF}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{263AC93E-3C68-4A71-95D3-BC8485B5A425}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Omerta\OmertaSteam.exe (Haemimont Games) [File not signed]
FirewallRules: [{6B749B4D-3E70-49BC-A73D-968E5C50B72E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Omerta\OmertaSteam.exe (Haemimont Games) [File not signed]
FirewallRules: [{E4A53436-6563-4133-AC00-F0EC60F33A3E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Northgard\Northgard.exe () [File not signed]
FirewallRules: [{71F8EE52-CE93-450E-8834-5BDF516D4971}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Northgard\Northgard.exe () [File not signed]
FirewallRules: [{F7C19ACC-9466-4AEC-913B-318A1F23C962}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909\SZBrowser.exe (AVAST Software s.r.o. -> Avast Software)
FirewallRules: [{34D36860-60E2-4700-A124-87FB3F575B6B}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe (AVAST Software s.r.o. -> Avast Software)
FirewallRules: [{8FE888BD-1230-4D5B-8BF6-27395D543556}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [{C7D4F23F-AFB3-4F9F-981D-AFCF901E1572}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Terraria\Terraria.exe (Re-Logic) [File not signed]
FirewallRules: [{AEA1ED7B-4B07-437C-B6C1-72D99D17CF8A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Crusader Kings II\CK2game.exe (Paradox Interactive) [File not signed]
FirewallRules: [{FD5BD9E0-9F7F-42E5-ADC8-8928C709F644}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Crusader Kings II\CK2game.exe (Paradox Interactive) [File not signed]
FirewallRules: [{10C184DF-D9BB-440D-A63A-9F99B1F4EB7F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risen 3\system\Risen3.exe No File
FirewallRules: [{D5D4460B-46A6-4F66-BBC1-F4639C608D9B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risen 3\system\Risen3.exe No File
FirewallRules: [{2F922116-61DD-4ED9-A2A7-C9E1AE071D12}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe (Raptr, Inc -> Raptr, Inc)
FirewallRules: [{364E8C79-1A98-41A2-95B7-CD6AF0CEE637}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe (Raptr, Inc -> Raptr, Inc)
FirewallRules: [{37A845B1-BFD2-4296-9953-96B1BE93954E}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe (Raptr, Inc -> Raptr, Inc)
FirewallRules: [{CFA73B55-CC9F-47EF-9B5E-03DD63E36759}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe (Raptr, Inc -> Raptr, Inc)
FirewallRules: [{37BC8AEE-7516-4CB9-A884-38D2D630C82A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{630B6A78-DCAC-48C5-B2FF-C12F3239F79D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{40C6F70D-6A5A-481E-A036-BF39EE3F6E2E}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{9E1029F3-074C-4042-96C9-1A82835F6D78}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [TCP Query User{B4BBD48D-01EF-40FD-90F9-FA2F4E2A6120}C:\program files (x86)\namco bandai games\darksouls\data.exe] => (Allow) C:\program files (x86)\namco bandai games\darksouls\data.exe (n-Space, Inc. -> NAMCO BANDAI Games Inc.) [File not signed]
FirewallRules: [UDP Query User{205714A3-9EE7-4CE8-A5A6-D1D59D488E11}C:\program files (x86)\namco bandai games\darksouls\data.exe] => (Allow) C:\program files (x86)\namco bandai games\darksouls\data.exe (n-Space, Inc. -> NAMCO BANDAI Games Inc.) [File not signed]
FirewallRules: [{F0BDF583-485E-4939-A2BF-203866647A21}] => (Allow) C:\Users\Administrator\AppData\Local\Programs\Opera\54.0.2952.41\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{9DE3FE1E-3486-4C46-A12D-8FE0E23A7377}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored RHCP\Binaries\Win32\Dishonored.exe No File
FirewallRules: [{3CE6FEA6-8AC7-4530-A17E-3721D5F086CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored RHCP\Binaries\Win32\Dishonored.exe No File
FirewallRules: [{43EF8F19-460A-4E44-851C-9C718E6468A2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hearts of Iron IV\hoi4.exe (Paradox Interactive) [File not signed]
FirewallRules: [{085DB354-DC3C-4D18-9DB4-E8413E8524A2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Hearts of Iron IV\hoi4.exe (Paradox Interactive) [File not signed]
FirewallRules: [{6077F240-33D7-447D-B3CD-5F6A0076D735}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe No File
FirewallRules: [{70FE99BD-7C5E-45EB-9F4B-7166C1C9DC5C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe No File
FirewallRules: [{7A65586A-6D29-48FA-AAB5-D86CEDA446E4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe No File
FirewallRules: [{05664B60-AC37-4498-818C-193F3572D159}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe No File
FirewallRules: [TCP Query User{922B11E9-EB8F-4E81-B2FD-E70CD6547999}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe No File
FirewallRules: [UDP Query User{9368DB39-1DBE-4A3E-9706-469EF7786755}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe No File
FirewallRules: [{88275BB5-D4DD-4DE1-9613-A3CE269135F0}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{02CD6587-26D7-4B4C-86D9-FF717F993569}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{1B2B277E-3EF7-464E-9FAC-1ECAA5931FD4}] => (Allow) C:\Users\Administrator\AppData\Local\Temp\7zS1A30\HPDiagnosticCoreUI.exe (HP Inc. -> HPDC LP)
FirewallRules: [{2FC43F6C-4153-4307-BF8C-10CF5BEC0589}] => (Allow) C:\Users\Administrator\AppData\Local\Temp\7zS1A30\HPDiagnosticCoreUI.exe (HP Inc. -> HPDC LP)
FirewallRules: [{1C03940A-5EFA-4795-B913-320F0D001739}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{BEB74CF6-B113-4868-AADB-23A0DD9CAA48}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{CD2896DF-F83A-4EB9-AF20-A2B288C50F44}] => (Allow) C:\Users\Administrator\AppData\Local\Temp\7zS3F45\HPDiagnosticCoreUI.exe (HP Inc. -> HPDC LP)
FirewallRules: [{9E663F95-0209-4E07-AAF0-F7A9CB78BC63}] => (Allow) C:\Users\Administrator\AppData\Local\Temp\7zS3F45\HPDiagnosticCoreUI.exe (HP Inc. -> HPDC LP)
FirewallRules: [TCP Query User{B9F42142-5F81-4DA3-B982-1FB8E12C5355}C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe] => (Allow) C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe (Ubisoft Entertainment SA -> )
FirewallRules: [UDP Query User{5F3889A2-D01D-408C-BE0D-7136B9F61AD1}C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe] => (Allow) C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfmp.exe (Ubisoft Entertainment SA -> )
FirewallRules: [{DFC66575-DFC9-4E21-9271-123E84F4E2E4}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{2FC3779C-6D12-4946-8872-555F60E42ECA}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{1B86EA66-1696-45DF-9EB2-38B8ABCE104F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\LaunchPad\LaunchPad.exe No File
FirewallRules: [{AD809563-0BF9-4069-89A8-53E03BBB95F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\LaunchPad\LaunchPad.exe No File
FirewallRules: [TCP Query User{0D0202A2-A39B-4A66-8F91-5FB106CCD2A1}C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe (Ubisoft Entertainment -> )
FirewallRules: [UDP Query User{B4DC2CCE-4889-483D-A6AA-737B8A0B270B}C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe] => (Allow) C:\program files (x86)\ubisoft\ubisoft game launcher\games\assassin's creed iv black flag\ac4bfsp.exe (Ubisoft Entertainment -> )
FirewallRules: [{2AF37A29-C0BA-4933-A53B-41D681A9BA86}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe () [File not signed]
FirewallRules: [{C5D1BBAD-2610-4CBF-9A92-CDB3C0F574EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Left 4 Dead 2\left4dead2.exe () [File not signed]
FirewallRules: [TCP Query User{623E30DE-D980-4C37-828F-9168FB4346AA}C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe (The Creative Assembly Limited -> The Creative Assembly Ltd)
FirewallRules: [UDP Query User{16B1F275-B948-444E-B965-4C381FF9B7D3}C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe (The Creative Assembly Limited -> The Creative Assembly Ltd)
FirewallRules: [TCP Query User{FF5DAA71-36DA-475C-8F38-B7BCABDD0B4F}C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe] => (Block) C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe (The Creative Assembly Limited -> The Creative Assembly Ltd)
FirewallRules: [UDP Query User{BE9B12A1-25C5-4AFD-A65D-33C436E37E63}C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe] => (Block) C:\program files (x86)\steam\steamapps\common\total war warhammer\warhammer.exe (The Creative Assembly Limited -> The Creative Assembly Ltd)
FirewallRules: [{65E174D2-D7EF-4F9E-9B51-E5F31F721C22}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe (QLOC S.A. -> Bethesda Softworks)
FirewallRules: [{2F81008E-0DCF-45CE-AF36-6DC9E1F0C689}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe (QLOC S.A. -> Bethesda Softworks)
FirewallRules: [{16CA4EB0-885D-4338-B121-4693ABCE15B4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V SDK\Sid Meier's Civilization V SDK.exe (Firaxis Games) [File not signed]
FirewallRules: [{47F3D35C-8C8D-4F95-B307-A20D3E3E532C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V SDK\Sid Meier's Civilization V SDK.exe (Firaxis Games) [File not signed]
FirewallRules: [{3E7781C0-6DDB-414D-BA6E-81DAF620B441}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\KB.exe () [File not signed]
FirewallRules: [{3374B9B3-E5B3-4396-9123-DE9E87156DAD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\KB.exe () [File not signed]
FirewallRules: [{C886E6EE-8F6F-4C6E-B2EA-DDB4143544C2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\save_fixer.exe () [File not signed]
FirewallRules: [{FC4B0EC7-503E-490F-80E4-DB4C35753753}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\King's Bounty - The Legend\save_fixer.exe () [File not signed]
FirewallRules: [{F0932F59-A91F-4D9B-81C2-019B38076CF7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space 2\EndlessSpace2.exe () [File not signed]
FirewallRules: [{9BA90DD1-C184-4CB7-A6AD-7B678AFE9EA4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Endless Space 2\EndlessSpace2.exe () [File not signed]
FirewallRules: [{3168BDE7-D3B7-43B5-9433-12D5645CFDEF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe (FromSoftware,Inc. -> NAMCO BANDAI Games)
FirewallRules: [{BF896D5F-992A-4756-93E1-4B0A6D80EEFD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dark Souls II\Game\DarkSoulsII.exe (FromSoftware,Inc. -> NAMCO BANDAI Games)
FirewallRules: [{DC4B812D-8BAA-4259-B09A-AA0AD12CA882}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{C4F03A22-9321-455E-BD85-ADFDBDF7AD44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Life Is Strange\Binaries\Win32\LifeIsStrange.exe (DONTNOD Entertainment) [File not signed]
FirewallRules: [{D1C6E1D6-7AF9-4200-9230-4B9B8849B788}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DARK SOULS III\Game\DarkSoulsIII.exe (FromSoftware,Inc. -> BANDAI NAMCO Entertainment Inc.)
FirewallRules: [{A357B16C-589E-4472-8B9E-F4D686E0640D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\DARK SOULS III\Game\DarkSoulsIII.exe (FromSoftware,Inc. -> BANDAI NAMCO Entertainment Inc.)
FirewallRules: [{FAC03FF6-6C1A-41A4-863F-C83CF907B50A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{A8847F21-CE0A-4164-8E24-6FDFE1547B7E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{9798F235-4140-4000-BA30-B07929505F74}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{132AABE4-2082-4951-9CA4-0C8D88DEAE0D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
FirewallRules: [{5E97D1CA-40F8-4737-8FAC-490A284BF7B4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War WARHAMMER\launcher\launcher.exe (The Creative Assembly Limited -> Creative Assembly Ltd)
FirewallRules: [{FC122B5B-412B-4950-A0E2-1E6E6D157078}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War WARHAMMER\launcher\launcher.exe (The Creative Assembly Limited -> Creative Assembly Ltd)
FirewallRules: [{D696C22C-D26C-4F6D-98CE-F1C36D5F4435}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google Inc.)
FirewallRules: [{C187DFAB-236B-4FA4-9D1F-6ED1E9339F5C}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (AVAST Software s.r.o. -> AVAST Software)
FirewallRules: [{812EAF06-D81D-478D-9AB3-3CCB05066A0F}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (AVAST Software s.r.o. -> AVAST Software)
FirewallRules: [{BBEAC5DA-8308-489F-99AF-2229ECE7CF67}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe (AVAST Software s.r.o. -> AVAST Software)

==================== Restore Points =========================

24-02-2019 19:00:21 Windows Zálohování
03-03-2019 19:00:14 Windows Zálohování
10-03-2019 19:00:26 Windows Zálohování

==================== Faulty Device Manager Devices =============

Name: Adaptér tunelového režimu Microsoft Teredo
Description: Adaptér tunelového režimu Microsoft Teredo
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (03/11/2019 07:25:36 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.

Error: (03/11/2019 07:16:20 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1505) (User: ADMIN-PC)
Description: Systém Windows nemůže načíst profil uživatele, ale byli jste přihlášeni pomocí výchozího profilu pro tento systém.

DETAIL – Přístup byl odepřen.

Error: (03/11/2019 07:16:20 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1505) (User: ADMIN-PC)
Description: Systém Windows nemůže načíst profil uživatele, ale byli jste přihlášeni pomocí výchozího profilu pro tento systém.

DETAIL – Přístup byl odepřen.

Error: (03/11/2019 07:16:17 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (03/10/2019 11:38:23 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (03/10/2019 11:36:50 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1505) (User: ADMIN-PC)
Description: Systém Windows nemůže načíst profil uživatele, ale byli jste přihlášeni pomocí výchozího profilu pro tento systém.

DETAIL – Přístup byl odepřen.

Error: (03/10/2019 11:36:45 PM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1505) (User: ADMIN-PC)
Description: Systém Windows nemůže načíst profil uživatele, ale byli jste přihlášeni pomocí výchozího profilu pro tento systém.

DETAIL – Přístup byl odepřen.

Error: (03/10/2019 10:52:05 PM) (Source: MsiInstaller) (EventID: 11316) (User: NT AUTHORITY)
Description: Product: Avast Update Helper -- Error 1316. Zadaný účet již existuje.


System errors:
=============
Error: (03/11/2019 07:15:32 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Plays.tv Update Service neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 11:37:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Plays.tv Update Service neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 11:27:48 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR2.

Error: (03/10/2019 11:27:46 PM) (Source: Disk) (EventID: 11) (User: )
Description: Ovladač zjistil chybu řadiče na \Device\Harddisk1\DR2.

Error: (03/10/2019 10:14:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Plays.tv Update Service neuspěla při spuštění v důsledku následující chyby:
Systém nemůže nalézt uvedený soubor.

Error: (03/10/2019 10:13:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Ochrana softwaru byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (03/10/2019 10:13:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Origin Web Helper Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (03/10/2019 10:13:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba modulů systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.


Windows Defender:
===================================
Date: 2015-11-07 19:59:12.723
Description:
Prohledávání Windows Defender bylo zastaveno před dokončením.
ID prohledávání:{D82AC51B-8CB3-408C-825F-F9BE485EB592}
Typ prohledávání:Antispywarový program
Parametry prohledávání:Rychlé prohledávání
Uživatel:ADMIN-PC\Helena

Date: 2015-10-27 21:10:18.013
Description:
Prohledávání Windows Defender bylo zastaveno před dokončením.
ID prohledávání:{6D91FBE4-39CF-4BE3-8C0F-6F7A0FF7F976}
Typ prohledávání:Antispywarový program
Parametry prohledávání:Rychlé prohledávání
Uživatel:ADMIN-PC\Helena

Date: 2015-03-13 14:20:58.354
Description:
Prohledávání Windows Defender bylo zastaveno před dokončením.
ID prohledávání:{418C6894-C5F0-4DB9-ACAF-A7D6CB105079}
Typ prohledávání:Antispywarový program
Parametry prohledávání:Rychlé prohledávání
Uživatel:ADMIN-PC\Helena

Date: 2015-09-25 15:56:17.644
Description:
Prohledávání Windows Defender zjistilo chybu při pokusu o načtení podpisů a pokusí se o obnovení sady podpisů, jejichž správnost je potvrzena.
Podpisy, které se měly načíst:Aktuální
Kód chyby:0x80070002
Popis chyby:Systém nemůže nalézt uvedený soubor.
Verze podpisu:0.0.0.0
Verze modulu:0.0.0.0

Date: 2015-09-25 15:56:17.550
Description:
Program Windows Defender zjistil chybu při pokusu o aktualizaci.
Nová verze podpisu:
Předchozí verze podpisu:
Zdroj aktualizace:Složka aktualizace podpisů
Typ podpisu:Antispywarový program
Typ aktualizace:Delta
Uživatel:NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu:
Kód chyby:0x80070002
Popis chyby:Systém nemůže nalézt uvedený soubor.

Date: 2015-04-25 11:55:26.899
Description:
Prohledávání Windows Defender zjistilo chybu při pokusu o načtení podpisů a pokusí se o obnovení sady podpisů, jejichž správnost je potvrzena.
Podpisy, které se měly načíst:Aktuální
Kód chyby:0x80070002
Popis chyby:Systém nemůže nalézt uvedený soubor.
Verze podpisu:0.0.0.0
Verze modulu:0.0.0.0

Date: 2015-04-25 11:55:26.889
Description:
Program Windows Defender zjistil chybu při pokusu o aktualizaci.
Nová verze podpisu:
Předchozí verze podpisu:
Zdroj aktualizace:Složka aktualizace podpisů
Typ podpisu:Antispywarový program
Typ aktualizace:Delta
Uživatel:NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu:
Kód chyby:0x80070002
Popis chyby:Systém nemůže nalézt uvedený soubor.

CodeIntegrity:
===================================

Date: 2018-06-13 13:55:58.239
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-06-13 13:55:58.145
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-04 20:07:17.240
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atikmdag.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 20:07:17.084
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 20:06:38.630
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 20:06:38.022
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 10:32:16.410
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atikmdag.sys because the set of per-page image hashes could not be found on the system.

Date: 2016-08-04 10:32:16.363
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\atikmpag.sys because the set of per-page image hashes could not be found on the system.

==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz
Percentage of memory in use: 31%
Total physical RAM: 16326.67 MB
Available physical RAM: 11214.8 MB
Total Virtual: 24324.81 MB
Available Virtual: 19118.14 MB

==================== Drives ================================

Drive c: (HDD) (Fixed) (Total:931.41 GB) (Free:21.09 GB) NTFS
Drive d: (Sims3EP08) (CDROM) (Total:3.9 GB) (Free:0 GB) UDF

\\?\Volume{682e3343-6736-11e3-a7bd-806e6f6e6963}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: E1617DCA)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#8 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
ContextMenuHandlers1: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers4: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
Task: {1FE39584-9F57-4D5F-9A58-8B7CA48AE85E} - System32\Tasks\{CCEAF1B1-A16C-4B25-9E01-05FDBA4DA438} => C:\Windows\system32\pcalua.exe -a D:\DXREDIST\DXSETUP.exe -d D:\DXREDIST
Task: {20004A63-9B91-4220-ACC6-4AF825A114C7} - System32\Tasks\{08044EBB-3687-401F-A611-C2E1D39794B4} => C:\Windows\system32\pcalua.exe -a F:\DWA-142_drv_A1_Utility_v1.40b02(0606144500)
Task: {347225D0-C98C-47F0-BE84-B6DD1D0CEE08} - System32\Tasks\{8E6251B7-E6DB-477B-AAFE-07366754CEFA} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\instmsiw.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {BDEA8E13-BC13-42D3-BADC-8C84FA900CFC} - System32\Tasks\{4D240894-076B-4C12-8648-D6BF9A23F377} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\Sims3EP02Setup.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {CB249EC1-00BF-4718-BBF4-463D7AE12CB7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {E3B2EC09-8EDC-4498-A505-83E88589F0C0} - System32\Tasks\{4805FB4B-9F97-4F6F-9C79-B23921F99D75} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\setup.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {EA7F8B55-7960-4E20-8DD8-0A75194CA695} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
FirewallRules: [{DD3C6F52-6AF5-4683-AF31-281309C5E1C2}] => (Allow) C:\Users\Administrator\AppData\Roaming\uTorrent\utorrent.exe No File
FirewallRules: [{FDB85F1C-BF09-4ADB-82B1-C4FA7CFBE052}] => (Allow) C:\Users\Administrator\AppData\Roaming\uTorrent\utorrent.exe No File
FirewallRules: [UDP Query User{99B58E7D-6144-4BF5-A109-57E4323BED95}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [TCP Query User{C4305E5D-B0AC-4AD0-8AFA-4E96FCDFE600}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [UDP Query User{FA4D6115-7070-4618-87C0-593CBAA56ACB}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [{89CD386B-BA42-404D-9E52-0002D57330ED}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe No File
FirewallRules: [{73E2728A-B45F-42D1-BF39-5E190A46E1D7}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe No File
FirewallRules: [TCP Query User{3B72941E-6534-443C-B4D8-51646F552A41}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe No File
FirewallRules: [UDP Query User{9287E7E8-5037-4629-B719-AD2F62B30C1C}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe No File
FirewallRules: [{99AA2B2F-E91D-4554-8E0D-0EFA4F006C25}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{4C230EA1-3209-46B1-841F-ED1C20712590}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{10C184DF-D9BB-440D-A63A-9F99B1F4EB7F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risen 3\system\Risen3.exe No File
FirewallRules: [{D5D4460B-46A6-4F66-BBC1-F4639C608D9B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risen 3\system\Risen3.exe No File
FirewallRules: [{37BC8AEE-7516-4CB9-A884-38D2D630C82A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{630B6A78-DCAC-48C5-B2FF-C12F3239F79D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{9DE3FE1E-3486-4C46-A12D-8FE0E23A7377}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored RHCP\Binaries\Win32\Dishonored.exe No File
FirewallRules: [{3CE6FEA6-8AC7-4530-A17E-3721D5F086CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored RHCP\Binaries\Win32\Dishonored.exe No File
FirewallRules: [{6077F240-33D7-447D-B3CD-5F6A0076D735}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe No File
FirewallRules: [{70FE99BD-7C5E-45EB-9F4B-7166C1C9DC5C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe No File
FirewallRules: [{7A65586A-6D29-48FA-AAB5-D86CEDA446E4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe No File
FirewallRules: [{05664B60-AC37-4498-818C-193F3572D159}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe No File
FirewallRules: [TCP Query User{922B11E9-EB8F-4E81-B2FD-E70CD6547999}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe No File
FirewallRules: [UDP Query User{9368DB39-1DBE-4A3E-9706-469EF7786755}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe No File
FirewallRules: [{1C03940A-5EFA-4795-B913-320F0D001739}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{BEB74CF6-B113-4868-AADB-23A0DD9CAA48}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{1B86EA66-1696-45DF-9EB2-38B8ABCE104F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\LaunchPad\LaunchPad.exe No File
FirewallRules: [{AD809563-0BF9-4069-89A8-53E03BBB95F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\LaunchPad\LaunchPad.exe No File
C:\Program Files\McAfee Security Scan
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe (McAfee, Inc. -> McAfee, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll => No File
BHO-x32: No Name -> {2D49AE4D-5236-2916-FDF7-E35D7E3C6C78} -> No File
BHO-x32: No Name -> {30FFDA66-22C6-1E64-BAD4-1ECE736319CC} -> No File
BHO-x32: No Name -> {33D9F886-4A04-FD74-1E88-60D9F74C28FA} -> No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
S4 LMIRfsClientNP; no ImagePath
U1 aswbdisk; no ImagePath
C:\ProgramData\McAfee Security Scan
C:\Users\Administrator\AppData\Local\Temp

EmptyTemp:
Hosts:
End
Uložte do C:\Windows\System32\config\systemprofile\Downloads\frst jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#9 Příspěvek od Henry0607 »

Fixlog.txt:

Fix result of Farbar Recovery Scan Tool (x64) Version: 11.03.2019
Ran by Administrator (11-03-2019 20:32:40) Run:1
Running from C:\Windows\System32\config\systemprofile\Downloads\frst
Loaded Profiles: Administrator (Available Profiles: Helena & Administrator & Guest)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
ContextMenuHandlers1: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers4: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers6: [iSafeRKScan] -> {5411D116-5A37-47D4-B154-5F7FCD9062F0} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
Task: {1FE39584-9F57-4D5F-9A58-8B7CA48AE85E} - System32\Tasks\{CCEAF1B1-A16C-4B25-9E01-05FDBA4DA438} => C:\Windows\system32\pcalua.exe -a D:\DXREDIST\DXSETUP.exe -d D:\DXREDIST
Task: {20004A63-9B91-4220-ACC6-4AF825A114C7} - System32\Tasks\{08044EBB-3687-401F-A611-C2E1D39794B4} => C:\Windows\system32\pcalua.exe -a F:\DWA-142_drv_A1_Utility_v1.40b02(0606144500)
Task: {347225D0-C98C-47F0-BE84-B6DD1D0CEE08} - System32\Tasks\{8E6251B7-E6DB-477B-AAFE-07366754CEFA} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\instmsiw.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {BDEA8E13-BC13-42D3-BADC-8C84FA900CFC} - System32\Tasks\{4D240894-076B-4C12-8648-D6BF9A23F377} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\Sims3EP02Setup.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {CB249EC1-00BF-4718-BBF4-463D7AE12CB7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
Task: {E3B2EC09-8EDC-4498-A505-83E88589F0C0} - System32\Tasks\{4805FB4B-9F97-4F6F-9C79-B23921F99D75} => C:\Windows\system32\pcalua.exe -a C:\Users\Administrator\AppData\Roaming\CyberLink\Power2Go9\9.0\Temp\setup.exe -d "C:\Program Files (x86)\CyberLink\Power2Go9" <==== ATTENTION
Task: {EA7F8B55-7960-4E20-8DD8-0A75194CA695} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (Google Inc -> Google Inc.)
FirewallRules: [{DD3C6F52-6AF5-4683-AF31-281309C5E1C2}] => (Allow) C:\Users\Administrator\AppData\Roaming\uTorrent\utorrent.exe No File
FirewallRules: [{FDB85F1C-BF09-4ADB-82B1-C4FA7CFBE052}] => (Allow) C:\Users\Administrator\AppData\Roaming\uTorrent\utorrent.exe No File
FirewallRules: [UDP Query User{99B58E7D-6144-4BF5-A109-57E4323BED95}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [TCP Query User{C4305E5D-B0AC-4AD0-8AFA-4E96FCDFE600}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [UDP Query User{FA4D6115-7070-4618-87C0-593CBAA56ACB}C:\users\administrator\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\administrator\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [{89CD386B-BA42-404D-9E52-0002D57330ED}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe No File
FirewallRules: [{73E2728A-B45F-42D1-BF39-5E190A46E1D7}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe No File
FirewallRules: [TCP Query User{3B72941E-6534-443C-B4D8-51646F552A41}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe No File
FirewallRules: [UDP Query User{9287E7E8-5037-4629-B719-AD2F62B30C1C}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe No File
FirewallRules: [{99AA2B2F-E91D-4554-8E0D-0EFA4F006C25}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{4C230EA1-3209-46B1-841F-ED1C20712590}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe No File
FirewallRules: [{10C184DF-D9BB-440D-A63A-9F99B1F4EB7F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risen 3\system\Risen3.exe No File
FirewallRules: [{D5D4460B-46A6-4F66-BBC1-F4639C608D9B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Risen 3\system\Risen3.exe No File
FirewallRules: [{37BC8AEE-7516-4CB9-A884-38D2D630C82A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{630B6A78-DCAC-48C5-B2FF-C12F3239F79D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{9DE3FE1E-3486-4C46-A12D-8FE0E23A7377}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored RHCP\Binaries\Win32\Dishonored.exe No File
FirewallRules: [{3CE6FEA6-8AC7-4530-A17E-3721D5F086CB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dishonored RHCP\Binaries\Win32\Dishonored.exe No File
FirewallRules: [{6077F240-33D7-447D-B3CD-5F6A0076D735}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe No File
FirewallRules: [{70FE99BD-7C5E-45EB-9F4B-7166C1C9DC5C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI.exe No File
FirewallRules: [{7A65586A-6D29-48FA-AAB5-D86CEDA446E4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe No File
FirewallRules: [{05664B60-AC37-4498-818C-193F3572D159}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\Base\Binaries\Win64Steam\CivilizationVI_DX12.exe No File
FirewallRules: [TCP Query User{922B11E9-EB8F-4E81-B2FD-E70CD6547999}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe No File
FirewallRules: [UDP Query User{9368DB39-1DBE-4A3E-9706-469EF7786755}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe No File
FirewallRules: [{1C03940A-5EFA-4795-B913-320F0D001739}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{BEB74CF6-B113-4868-AADB-23A0DD9CAA48}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe No File
FirewallRules: [{1B86EA66-1696-45DF-9EB2-38B8ABCE104F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\LaunchPad\LaunchPad.exe No File
FirewallRules: [{AD809563-0BF9-4069-89A8-53E03BBB95F6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization VI\LaunchPad\LaunchPad.exe No File
C:\Program Files\McAfee Security Scan
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle America, Inc. -> Oracle Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe (McAfee, Inc. -> McAfee, Inc.)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll => No File
BHO-x32: No Name -> {2D49AE4D-5236-2916-FDF7-E35D7E3C6C78} -> No File
BHO-x32: No Name -> {30FFDA66-22C6-1E64-BAD4-1ECE736319CC} -> No File
BHO-x32: No Name -> {33D9F886-4A04-FD74-1E88-60D9F74C28FA} -> No File
Toolbar: HKLM - No Name - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - No File
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
S4 LMIRfsClientNP; no ImagePath
U1 aswbdisk; no ImagePath
C:\ProgramData\McAfee Security Scan
C:\Users\Administrator\AppData\Local\Temp

EmptyTemp:
Hosts:
End
*****************

Processes closed successfully.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\iSafeRKScan => removed successfully
HKLM\Software\Classes\CLSID\{5411D116-5A37-47D4-B154-5F7FCD9062F0} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\iSafeRKScan => removed successfully
HKLM\Software\Classes\CLSID\{5411D116-5A37-47D4-B154-5F7FCD9062F0} => not found
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\iSafeRKScan => removed successfully
HKLM\Software\Classes\CLSID\{5411D116-5A37-47D4-B154-5F7FCD9062F0} => not found
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\CLSID\{474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1FE39584-9F57-4D5F-9A58-8B7CA48AE85E}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1FE39584-9F57-4D5F-9A58-8B7CA48AE85E}" => removed successfully
C:\Windows\System32\Tasks\{CCEAF1B1-A16C-4B25-9E01-05FDBA4DA438} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{CCEAF1B1-A16C-4B25-9E01-05FDBA4DA438}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{20004A63-9B91-4220-ACC6-4AF825A114C7}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{20004A63-9B91-4220-ACC6-4AF825A114C7}" => removed successfully
C:\Windows\System32\Tasks\{08044EBB-3687-401F-A611-C2E1D39794B4} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{08044EBB-3687-401F-A611-C2E1D39794B4}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{347225D0-C98C-47F0-BE84-B6DD1D0CEE08}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{347225D0-C98C-47F0-BE84-B6DD1D0CEE08}" => removed successfully
C:\Windows\System32\Tasks\{8E6251B7-E6DB-477B-AAFE-07366754CEFA} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{8E6251B7-E6DB-477B-AAFE-07366754CEFA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BDEA8E13-BC13-42D3-BADC-8C84FA900CFC}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BDEA8E13-BC13-42D3-BADC-8C84FA900CFC}" => removed successfully
C:\Windows\System32\Tasks\{4D240894-076B-4C12-8648-D6BF9A23F377} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4D240894-076B-4C12-8648-D6BF9A23F377}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{CB249EC1-00BF-4718-BBF4-463D7AE12CB7}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CB249EC1-00BF-4718-BBF4-463D7AE12CB7}" => removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E3B2EC09-8EDC-4498-A505-83E88589F0C0}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3B2EC09-8EDC-4498-A505-83E88589F0C0}" => removed successfully
C:\Windows\System32\Tasks\{4805FB4B-9F97-4F6F-9C79-B23921F99D75} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{4805FB4B-9F97-4F6F-9C79-B23921F99D75}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EA7F8B55-7960-4E20-8DD8-0A75194CA695}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA7F8B55-7960-4E20-8DD8-0A75194CA695}" => removed successfully
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DD3C6F52-6AF5-4683-AF31-281309C5E1C2}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{FDB85F1C-BF09-4ADB-82B1-C4FA7CFBE052}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{99B58E7D-6144-4BF5-A109-57E4323BED95}C:\users\administrator\appdata\local\akamai\netsession_win.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C4305E5D-B0AC-4AD0-8AFA-4E96FCDFE600}C:\users\administrator\appdata\local\akamai\netsession_win.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{FA4D6115-7070-4618-87C0-593CBAA56ACB}C:\users\administrator\appdata\local\akamai\netsession_win.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{89CD386B-BA42-404D-9E52-0002D57330ED}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{73E2728A-B45F-42D1-BF39-5E190A46E1D7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{3B72941E-6534-443C-B4D8-51646F552A41}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9287E7E8-5037-4629-B719-AD2F62B30C1C}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{99AA2B2F-E91D-4554-8E0D-0EFA4F006C25}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4C230EA1-3209-46B1-841F-ED1C20712590}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{10C184DF-D9BB-440D-A63A-9F99B1F4EB7F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D5D4460B-46A6-4F66-BBC1-F4639C608D9B}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{37BC8AEE-7516-4CB9-A884-38D2D630C82A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{630B6A78-DCAC-48C5-B2FF-C12F3239F79D}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9DE3FE1E-3486-4C46-A12D-8FE0E23A7377}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3CE6FEA6-8AC7-4530-A17E-3721D5F086CB}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6077F240-33D7-447D-B3CD-5F6A0076D735}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{70FE99BD-7C5E-45EB-9F4B-7166C1C9DC5C}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7A65586A-6D29-48FA-AAB5-D86CEDA446E4}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{05664B60-AC37-4498-818C-193F3572D159}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{922B11E9-EB8F-4E81-B2FD-E70CD6547999}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{9368DB39-1DBE-4A3E-9706-469EF7786755}C:\program files (x86)\steam\steamapps\common\dishonored rhcp\binaries\win32\dishonored.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1C03940A-5EFA-4795-B913-320F0D001739}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{BEB74CF6-B113-4868-AADB-23A0DD9CAA48}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1B86EA66-1696-45DF-9EB2-38B8ABCE104F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AD809563-0BF9-4069-89A8-53E03BBB95F6}" => removed successfully
C:\Program Files\McAfee Security Scan => moved successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => removed successfully
"C:\Program Files\McAfee Security Scan\3.11.968\SSScheduler.exe" => not found
HKLM\SOFTWARE\Policies\Google => removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} => removed successfully
HKLM\Software\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} => removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2D49AE4D-5236-2916-FDF7-E35D7E3C6C78} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{2D49AE4D-5236-2916-FDF7-E35D7E3C6C78} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30FFDA66-22C6-1E64-BAD4-1ECE736319CC} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{30FFDA66-22C6-1E64-BAD4-1ECE736319CC} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{33D9F886-4A04-FD74-1E88-60D9F74C28FA} => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{33D9F886-4A04-FD74-1E88-60D9F74C28FA} => not found
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5}" => removed successfully
HKLM\Software\Classes\CLSID\{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} => not found
HKLM\Software\Classes\PROTOCOLS\Handler\skypec2c => removed successfully
HKLM\Software\Classes\CLSID\{91774881-D725-4E58-B298-07617B9B86A8} => removed successfully
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => removed successfully
HKLM\System\CurrentControlSet\Services\LMIRfsClientNP => removed successfully
LMIRfsClientNP => service removed successfully
HKLM\System\CurrentControlSet\Services\aswbdisk => could not remove, key could be protected
C:\ProgramData\McAfee Security Scan => moved successfully
C:\Users\Administrator\AppData\Local\Temp => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10843739 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 51630658 B
Edge => 0 B
Chrome => 0 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 757994 B
systemprofile32 => 66356 B
LocalService => 66228 B
NetworkService => 0 B
Helena => 1901869 B
TEMP => 35813 B
Administrator => 72764486 B
Guest => 65858 B

RecycleBin => 0 B
EmptyTemp: => 139.7 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 11-03-2019 20:35:19)


Result of scheduled keys to remove after reboot:

HKLM\System\CurrentControlSet\Services\aswbdisk => could not remove, key could be protected

==== End of Fixlog 20:35:19 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#10 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#11 Příspěvek od Henry0607 »

Bohužel, žádná změna nenastala.
Plocha je pořád černá jen s pár ikonami, mbar a mbam nejdou nainstalovat a rkill nejde spustit.

Logům vůbec nerozumím, ale v posledním logu jsem si všiml, že:
HKLM\System\CurrentControlSet\Services\aswbdisk => could not remove, key could be protected

To zřejmě není dobře.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#12 Příspěvek od Rudy »

Udělejte ještě kompletní sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 . Utilitu stáhněte, spusťte, nechte pracovat a po skončení akce smažte vše, co najde.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#13 Příspěvek od Henry0607 »

Zkoušel jsem to provést dle Vámi poskytnutého návodu. CCleaner ani Cleanup! nemůžu po stažení nainstalovat. KVRT - po spuštění to chce odsouhlasit podmínky, ok, pak inicializace do 30% a následně chybová hláška: Can't initialize services.
Scan bohužel nemohu provést :/

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#14 Příspěvek od Rudy »

Udělejte tedy sken ComboFix:
Stahnete a ulozte nejlepe na plochu ComboFix: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

pote spustte aplikaci pod uctem s administratorskym opravnenim

hned po startu se zobrazi obrazovka s licencnimi podminkami, pokracujte kliknutim na tlacitko Ano.

v klidu si postavte na kafe (cela akce trva cca. 5-10 minut, nekdy i dele - dle toho, o jak rychly stroj se

jedna a kolika soubory se skener bude muset prodirat), behem skenu se nepokousejte spoustet zadne jine

aplikace ani nic jineho

behem skenovani nepropadejte panice, vas stroj muze byt restartovan (predevsim pri prvni aplikaci skeneru)

upozorneni: pokud pouzivate antispyware s rezidentnim stitem, prepnete jeho rezidentni stit do Install Mode,

pripadne jej po dobu skenu uplne deaktivujte, protoze dochazi pri skenu a vymazu pripadneho malware k

nezadoucim kolizim s rezidentem antispyware.
a dejte log.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Henry0607
Návštěvník
Návštěvník
Příspěvky: 13
Registrován: 10 bře 2019 20:51

Re: Infikován PC, nejdou nainstalovat antiviry, přikládám lo

#15 Příspěvek od Henry0607 »

ComboFix také nejde spustit...

Odpovědět