Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Spuštění Chromu a stránky po zapnutí PC

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Gambac
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 47
Registrován: 29 bře 2009 10:42

Spuštění Chromu a stránky po zapnutí PC

#1 Příspěvek od Gambac »

Ahoj, od včerejška se po spustení PC automaticky spustí Chrome a otevre webovou stranku (něco v azbuce - klasika). Malvare bytes si s tim neporadil, v Autorun po spusteni nic nevidím.

Mám podezření na toto, ale nechci udělat chybu :)

2019-08-20 16:40 - 2019-08-18 03:08 - 001012640 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 001012640 _____ C:\WINDOWS\system32\vulkan-1.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000876448 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000876448 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll


Prosím tedy o kontrolu logu a predem dekuji.

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-08-2019
Ran by maxim (administrator) on LAPTOP-O3TRNGPI (LENOVO 81AC) (24-08-2019 07:55:07)
Running from D:\Downloads
Loaded Profiles: maxim (Available Profiles: maxim)
Platform: Windows 10 Home Version 1803 17134.950 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\IntelCpHeciSvc.exe
(Intel(R) Software Development Products -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_8f1fe4a9cfb9cf9c\aesm_service.exe
(Intel(R) Trust Services -> Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\NisSrv.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(philandro Software GmbH -> ) C:\Program Files (x86)\AnyDesk\AnyDesk.exe
(philandro Software GmbH -> ) C:\Program Files (x86)\AnyDesk\AnyDesk.exe
(Razer USA Ltd. -> ) C:\Program Files (x86)\Razer\Synapse3\UserProcess\Razer Synapse Service Process.exe
(Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
(Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
(Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18384352 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LVA] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493984 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493984 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493984 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [WindowsDriverScan86] => C:\Program Files (x86)\Adobe Arkalis\Arkalis86.lnk [1501 2014-08-10] () [File not signed]
HKLM-x32\...\Run: [WindowsDriverScan64] => C:\Program Files (x86)\Adobe Arkalis\Arkalis.lnk [1419 2014-08-10] () [File not signed]
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3210528 2019-08-13] (Valve -> Valve Corporation)
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3493104 2019-07-17] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [7610952 2019-06-25] (GOG Sp. z o.o. -> GOG.com)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3493104 2019-07-17] (Razer USA Ltd. -> Razer Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-07] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2019-04-16]
ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat [2018-02-04] () [File not signed]
Startup: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\reg.lnk [2019-04-16]
ShortcutAndArgument: reg.lnk -> C:\ProgramData\NVIDIA bas\reg.vbs => 1 2 3
Startup: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2019-05-20]
ShortcutTarget: Twitch.lnk -> C:\Program Files (x86)\Twitch\Bin\Twitch.exe (Twitch Interactive, Inc. -> Twitch Interactive, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0282405B-B67F-4A2C-A77D-E0C7C3090D3F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService
Task: {08B6BD70-0CE3-4920-AD99-415D5F740CF4} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1B2CFE1A-760B-4957-8C32-D144C664D5AB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {23E7A971-068D-403E-B6FE-9DDE17D2FE59} - System32\Tasks\OneDrive Standalone Update Task v2 => C:\Users\maxim\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {2B7F1F8F-5041-42DB-BE68-631A159BDDBD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4248E3D3-7ED7-48D8-8F8F-AB26E2F9EA00} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {48AA4297-FA16-48DC-BB5B-3782F4ADA20E} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226024 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {4BE32B2C-E370-4480-84E8-5C0DF9E4F505} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4F182DB5-B337-414F-B8C0-96E458127DEE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16509040 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {621BC5B8-26CD-43FD-802A-ECAE5F07C0BF} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226024 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {62974823-9836-44D0-9919-7808AB152790} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {70FEE62F-48D8-4F2B-916A-FCC296AFBDFB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-16] (Google Inc -> Google LLC)
Task: {79E6A66D-3C50-439D-ACDA-3E410BE9E791} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-16] (Google Inc -> Google LLC)
Task: {81FBBEFE-C379-49FE-9817-FD869D2D8040} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {87B3CE1A-AD49-40D7-A282-9A53F09CBF51} - System32\Tasks\LenovoUtility Task => C:\Windows\explorer.exe lenovo-utility://
Task: {896A660C-1385-4B82-BED4-EF6392B00596} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8AD9A9DD-2220-45A1-813B-76F05BBD2CA7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9D626F7D-5E11-41BA-9B6E-4D9AE30398A5} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AA1A412D-73D3-4F97-B0F3-F34C09789831} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [816960 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {AA96CCB3-7733-4D39-BB0E-3B0ABEFE9ACC} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\73777f32-ba5b-4f6b-aa97-40fa78372129 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {AAC52445-DF92-4C1A-90A8-A63C1DFA738A} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2150120 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {AD89097A-D29D-4A4F-957D-5845BF4FA5B9} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B44B93D1-F758-495D-AB5B-4BBEF485BC06} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => %windir%\system32\sc.exe START ImControllerService
Task: {B82D1894-AFBA-462D-9A6B-3FF0A124AA0D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C578D146-B2AC-4B17-BE60-7448C9604926} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CBCBB262-AFC0-407C-8FC6-35E41A11B502} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226024 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {CCB9E617-2979-4384-BDF8-3AFF625658F2} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\c8441786-6c40-480b-b6b9-78b3c6663aeb => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {D5D6C179-8055-468E-AAC4-A6D97B1C2D40} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E64961CC-157D-4AB9-9E8E-4DDEF6688279} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3788144 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {ECF3D57D-56D3-41AA-A3E0-3D11739F56A0} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [54440 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {F3AE8606-C610-4827-A3DD-14FAF31C4FFD} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\82ff5b7a-1606-4ffe-a574-8e1dd7ef5a13 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {FF101F99-DB38-4316-AFFD-4CB1523FA395} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{63f08b27-63ed-4d74-8733-a5b9a608e420}: [DhcpNameServer] 172.168.127.2
Tcpip\..\Interfaces\{7535acc9-59db-44f8-b286-cdc93b99ebc9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ccd9d27c-808f-4925-9736-ce15e8b2c2d8}: [DhcpNameServer] 213.46.172.37 213.46.172.36

Internet Explorer:
==================
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
SearchScopes: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001 -> DefaultScope {BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} URL =
SearchScopes: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001 -> {BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} URL =

FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://home.sweetim.com/?st=17&barid={A16EE4EC-9151-11E1-B822-D0DF9AE2CF44}","hxxp://www.google.com/","hxxp://www.istartsurf ... oogle.com/"
CHR Profile: C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default [2019-08-24]
CHR DownloadDir: D:\Downloads
CHR Extension: (Prezentace) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-16]
CHR Extension: (Dokumenty) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-16]
CHR Extension: (Disk Google) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-04-16]
CHR Extension: (YouTube) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-16]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-08-09]
CHR Extension: (Tabulky) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-04-16]
CHR Extension: (AdBlock) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-08-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-04-16]
CHR Extension: (Gmail) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-07]
CHR Extension: (Eiffel Tower) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppbaibkigenhdcommebegmmmpoolmpip [2019-04-16]
CHR Profile: C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-08-23]
CHR Profile: C:\Users\maxim\AppData\Local\Google\Chrome\User Data\System Profile [2019-08-23]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AESMService; C:\WINDOWS\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_8f1fe4a9cfb9cf9c\aesm_service.exe [3418392 2019-04-09] (Intel(R) Software Development Products -> Intel Corporation)
R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [2822952 2019-04-16] (philandro Software GmbH -> )
R2 Dolby DAX API Service; C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe [212784 2017-09-19] (Dolby Laboratories, Inc. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2019-06-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [1701480 2017-07-07] (Intel Corporation -> Intel Corporation)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [791112 2019-06-25] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7170632 2019-06-25] (GOG Sp. z o.o. -> GOG.com)
S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2414264 2017-07-25] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [515256 2017-08-30] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
R3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [197264 2017-09-25] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [967272 2019-07-15] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [1444512 2019-07-16] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [253776 2019-07-03] (Razer USA Ltd. -> Razer Inc)
R2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [287472 2019-07-17] (Razer USA Ltd. -> Razer Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [324576 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [532864 2019-07-11] (Razer USA Ltd. -> Razer Inc.)
S3 ThunderboltService; C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [2150120 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\NisSrv.exe [2552416 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MsMpEng.exe [108832 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [69560 2017-07-07] (Intel Corporation -> Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [382392 2017-07-07] (Intel Corporation -> Intel Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R3 iaLPSS2_GPIO2; C:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys [98976 2017-08-24] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70664 2017-07-25] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [129552 2017-08-30] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [199768 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [224408 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [116112 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
R3 Netwtw06; C:\WINDOWS\System32\drivers\Netwtw06.sys [7751176 2017-09-13] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_a472382cd8e04666\nvlddmkm.sys [22347976 2019-08-18] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-06-13] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69840 2019-03-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [75600 2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [782304 2017-04-12] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R3 rtux64w10; C:\WINDOWS\System32\drivers\rtux64w10.sys [348672 2018-04-12] (Microsoft Windows -> Realtek )
R3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [49032 2019-01-16] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_0053; C:\WINDOWS\System32\drivers\RzDev_0053.sys [51696 2018-04-22] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_0067; C:\WINDOWS\System32\drivers\RzDev_0067.sys [51696 2018-04-22] (Razer USA Ltd. -> Razer Inc)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S2 SecDrv; C:\WINDOWS\SysWOW64\drivers\SECDRV.SYS [163644 2019-08-19] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R3 SPUVCbv; C:\WINDOWS\System32\Drivers\SPUVCbv64.sys [899672 2017-10-18] (SUNPLUS INNOVATION TECHNOLOGY INC. -> Sunplus Innovation Technology Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [47496 2019-07-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [344288 2019-07-26] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54496 2019-07-26] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-08-24 07:55 - 2019-08-24 07:55 - 000000000 ____D C:\FRST
2019-08-24 07:48 - 2019-08-24 07:48 - 000224408 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2019-08-24 07:48 - 2019-08-24 07:48 - 000116112 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2019-08-24 07:48 - 2019-08-24 07:48 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2019-08-24 07:45 - 2019-08-24 07:48 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-08-24 07:45 - 2019-08-24 07:45 - 000199768 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2019-08-24 07:45 - 2019-08-24 07:45 - 000001919 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-08-24 07:45 - 2019-06-26 13:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-08-24 07:44 - 2019-08-24 07:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-08-24 07:44 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-08-23 21:15 - 2019-08-23 21:15 - 000000732 ____C C:\Users\maxim\Desktop\PC Building Simulator.lnk
2019-08-23 21:15 - 2019-08-23 21:15 - 000000000 ___DC C:\Users\maxim\AppData\LocalLow\The Irregular Corp
2019-08-23 21:15 - 2019-08-23 21:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Building Simulator
2019-08-23 21:09 - 2019-08-23 21:09 - 000000000 ___DC C:\Users\maxim\Documents\Command and Conquer Generals Data
2019-08-23 21:08 - 2019-08-23 21:08 - 000000000 ___DC C:\Users\maxim\Documents\Command And Conquer Generals Zero Hour Data
2019-08-23 21:08 - 2019-08-23 21:08 - 000000000 ___DC C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals
2019-08-23 21:03 - 2019-08-23 21:06 - 000000000 ___DC C:\Users\maxim\AppData\LocalLow\uTorrent
2019-08-23 20:33 - 2019-08-23 20:33 - 000001810 ____C C:\Users\maxim\Desktop\Warcraft III – zástupce.lnk
2019-08-23 20:29 - 2019-08-23 20:32 - 000000000 ____D C:\Program Files (x86)\Warcraft III - The Frozen Throne
2019-08-23 20:29 - 2019-08-23 20:29 - 000002148 _____ C:\Users\Public\Desktop\Frozen Throne.lnk
2019-08-23 20:27 - 2019-08-23 20:27 - 000000000 ____D C:\Users\maxim\AppData\Roaming\Blizzard
2019-08-20 22:24 - 2019-08-20 22:24 - 000139207 ____C C:\Users\maxim\Desktop\Potvrzení objednávky - IKEA.pdf
2019-08-20 19:45 - 2019-08-20 19:45 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2019-08-20 18:12 - 2019-08-23 15:08 - 000000000 ____D C:\Users\maxim\AppData\Roaming\DS4Windows
2019-08-20 18:12 - 2013-05-19 02:02 - 000039168 _____ (Scarlet.Crush Productions) C:\WINDOWS\system32\Drivers\ScpVBus.sys
2019-08-20 18:11 - 2016-10-08 23:17 - 003168256 ____C () C:\Users\maxim\Desktop\DS4Windows.exe
2019-08-20 18:11 - 2015-12-19 00:41 - 000573952 ____C () C:\Users\maxim\Desktop\DS4Updater.exe
2019-08-20 16:42 - 2019-08-20 16:42 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2019-08-20 16:40 - 2019-08-18 03:08 - 001012640 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 001012640 _____ C:\WINDOWS\system32\vulkan-1.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000876448 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000876448 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000447576 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000352344 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000301472 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2019-08-20 16:40 - 2019-08-18 03:08 - 000301472 _____ C:\WINDOWS\system32\vulkaninfo.exe
2019-08-20 16:40 - 2019-08-18 03:08 - 000273312 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2019-08-20 16:40 - 2019-08-18 03:08 - 000273312 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-08-20 16:40 - 2019-08-18 03:07 - 011560328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-08-20 16:40 - 2019-08-18 03:07 - 009935776 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 017300360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 005358016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 004696512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 002050816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001723784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443602.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001550272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001487616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443602.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001477512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001247624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001140424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000959688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000813256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000676552 _____ C:\WINDOWS\system32\nvofapi64.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000659144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000633224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000544648 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000523712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-08-20 16:40 - 2019-08-18 03:05 - 040441280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-08-20 16:40 - 2019-08-18 03:05 - 035331008 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-08-20 16:40 - 2019-08-18 03:05 - 014921088 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-08-19 05:52 - 2019-08-19 05:54 - 000163644 _____ (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) C:\WINDOWS\SysWOW64\Drivers\SECDRV.SYS
2019-08-18 20:18 - 2019-08-19 05:55 - 000000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2019-08-14 17:09 - 2019-08-14 17:09 - 000000222 ____C C:\Users\maxim\Desktop\Mafia III.url
2019-08-14 17:00 - 2019-08-07 15:13 - 001632112 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-08-14 17:00 - 2019-08-07 15:13 - 000790208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-08-14 17:00 - 2019-08-07 14:58 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2019-08-14 17:00 - 2019-08-07 14:58 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-08-14 17:00 - 2019-08-07 14:55 - 008626688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-08-14 17:00 - 2019-08-07 14:53 - 003614208 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-08-14 17:00 - 2019-08-07 14:43 - 001453416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-08-14 17:00 - 2019-08-07 14:41 - 000662112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-08-14 17:00 - 2019-08-07 14:30 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2019-08-14 17:00 - 2019-08-07 14:30 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-08-14 17:00 - 2019-08-07 14:27 - 007990272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-08-14 17:00 - 2019-08-07 14:24 - 002882048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-08-14 17:00 - 2019-08-07 10:09 - 001328440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-08-14 17:00 - 2019-08-07 10:09 - 001219896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-08-14 17:00 - 2019-08-07 10:09 - 001098064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-08-14 17:00 - 2019-08-07 10:09 - 001027384 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-08-14 17:00 - 2019-08-07 10:09 - 000192824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-08-14 17:00 - 2019-08-07 10:09 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-08-14 17:00 - 2019-08-07 10:09 - 000095008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-08-14 17:00 - 2019-08-07 10:08 - 002810680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-08-14 17:00 - 2019-08-07 10:08 - 002470648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-08-14 17:00 - 2019-08-07 10:08 - 001566736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-08-14 17:00 - 2019-08-07 10:08 - 000710232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-08-14 17:00 - 2019-08-07 10:08 - 000494992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-08-14 17:00 - 2019-08-07 10:08 - 000170296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-08-14 17:00 - 2019-08-07 10:08 - 000091568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-08-14 17:00 - 2019-08-07 10:07 - 009084432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-08-14 17:00 - 2019-08-07 10:07 - 002719240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-08-14 17:00 - 2019-08-07 10:07 - 001031696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2019-08-14 17:00 - 2019-08-07 10:07 - 000786288 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-08-14 17:00 - 2019-08-07 09:57 - 000081256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-08-14 17:00 - 2019-08-07 09:56 - 001993344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-08-14 17:00 - 2019-08-07 09:56 - 001427768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-08-14 17:00 - 2019-08-07 09:56 - 000357336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-08-14 17:00 - 2019-08-07 09:55 - 000603792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-08-14 17:00 - 2019-08-07 09:44 - 008189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-08-14 17:00 - 2019-08-07 09:42 - 022717952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-08-14 17:00 - 2019-08-07 09:38 - 006661632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-08-14 17:00 - 2019-08-07 09:38 - 004385792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-08-14 17:00 - 2019-08-07 09:36 - 007572480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-08-14 17:00 - 2019-08-07 09:36 - 000354816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2019-08-14 17:00 - 2019-08-07 09:36 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-08-14 17:00 - 2019-08-07 09:35 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-08-14 17:00 - 2019-08-07 09:35 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2019-08-14 17:00 - 2019-08-07 09:34 - 005769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-08-14 17:00 - 2019-08-07 09:34 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-08-14 17:00 - 2019-08-07 09:34 - 000786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-08-14 17:00 - 2019-08-07 09:33 - 001220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 004938240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 004516864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 002165760 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-08-14 17:00 - 2019-08-07 09:32 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 001154048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 000318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 001110016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-08-14 17:00 - 2019-08-07 09:31 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000793088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-08-14 17:00 - 2019-07-09 10:07 - 000506088 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-08-14 17:00 - 2019-07-09 09:44 - 012757504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-08-14 17:00 - 2019-07-09 09:41 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-08-14 17:00 - 2019-07-09 09:39 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2019-08-14 17:00 - 2019-07-09 09:37 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-08-14 17:00 - 2019-07-09 08:42 - 011943424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-08-14 17:00 - 2019-07-09 08:38 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2019-08-14 17:00 - 2019-07-09 05:29 - 000375312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-08-14 17:00 - 2019-07-09 05:29 - 000230200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2019-08-14 17:00 - 2019-07-09 05:29 - 000031032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys
2019-08-14 17:00 - 2019-07-09 05:20 - 000500536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2019-08-14 17:00 - 2019-07-09 05:20 - 000227640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2019-08-14 17:00 - 2019-07-09 05:19 - 002769472 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-08-14 17:00 - 2019-07-09 05:19 - 002371504 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-08-14 17:00 - 2019-07-09 05:19 - 000767232 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-08-14 17:00 - 2019-07-09 05:19 - 000152104 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2019-08-14 17:00 - 2019-07-09 05:12 - 002331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-08-14 17:00 - 2019-07-09 05:12 - 000573808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-08-14 17:00 - 2019-07-09 05:12 - 000125504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2019-08-14 17:00 - 2019-07-09 05:11 - 002257336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-08-14 17:00 - 2019-07-09 04:55 - 002700288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-08-14 17:00 - 2019-07-09 04:53 - 003708416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-08-14 17:00 - 2019-07-09 04:52 - 002258944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-08-14 17:00 - 2019-07-09 04:50 - 004861440 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-08-14 17:00 - 2019-07-09 04:50 - 000659456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-08-14 17:00 - 2019-07-09 04:50 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-08-14 17:00 - 2019-07-09 04:48 - 003402240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-08-14 17:00 - 2019-07-09 04:48 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 003392000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 002738688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 002176000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-08-14 17:00 - 2019-07-09 04:46 - 002912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-08-14 17:00 - 2019-07-09 04:46 - 001561088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-08-14 17:00 - 2019-07-09 04:46 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-08-14 17:00 - 2019-07-09 04:45 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-08-14 17:00 - 2019-07-09 04:44 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2019-08-14 16:59 - 2019-08-07 15:13 - 021389776 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-08-14 16:59 - 2019-08-07 15:13 - 001515904 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-08-14 16:59 - 2019-08-07 14:55 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2PGraph.dll
2019-08-14 16:59 - 2019-08-07 14:55 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2019-08-14 16:59 - 2019-08-07 14:54 - 004783104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2019-08-14 16:59 - 2019-08-07 14:53 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2019-08-14 16:59 - 2019-08-07 14:53 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2pnetsh.dll
2019-08-14 16:59 - 2019-08-07 14:52 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-08-14 16:59 - 2019-08-07 14:51 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2019-08-14 16:59 - 2019-08-07 14:41 - 001322688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-08-14 16:59 - 2019-08-07 14:40 - 020384344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-08-14 16:59 - 2019-08-07 14:26 - 000366592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2PGraph.dll
2019-08-14 16:59 - 2019-08-07 14:26 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2019-08-14 16:59 - 2019-08-07 14:25 - 004175360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2019-08-14 16:59 - 2019-08-07 14:24 - 001472000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-08-14 16:59 - 2019-08-07 14:24 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\p2pnetsh.dll
2019-08-14 16:59 - 2019-08-07 11:40 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2019-08-14 16:59 - 2019-08-07 10:09 - 000568104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-08-14 16:59 - 2019-08-07 10:09 - 000194352 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-08-14 16:59 - 2019-08-07 10:08 - 007435720 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-08-14 16:59 - 2019-08-07 10:08 - 001141712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-08-14 16:59 - 2019-08-07 10:08 - 000723216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-08-14 16:59 - 2019-08-07 10:08 - 000227744 _____ (Microsoft Corporation) C:\WINDOWS\system32\xmllite.dll
2019-08-14 16:59 - 2019-08-07 10:08 - 000130840 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-08-14 16:59 - 2019-08-07 10:07 - 007520112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-08-14 16:59 - 2019-08-07 10:07 - 001459328 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-08-14 16:59 - 2019-08-07 10:07 - 001260992 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-08-14 16:59 - 2019-08-07 10:07 - 000984152 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-08-14 16:59 - 2019-08-07 10:07 - 000115728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-08-14 16:59 - 2019-08-07 09:56 - 006570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-08-14 16:59 - 2019-08-07 09:56 - 006044008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-08-14 16:59 - 2019-08-07 09:56 - 000192608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xmllite.dll
2019-08-14 16:59 - 2019-08-07 09:56 - 000101400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-08-14 16:59 - 2019-08-07 09:49 - 025857536 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-08-14 16:59 - 2019-08-07 09:47 - 022017536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-08-14 16:59 - 2019-08-07 09:39 - 019372544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-08-14 16:59 - 2019-08-07 09:38 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-08-14 16:59 - 2019-08-07 09:38 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll
2019-08-14 16:59 - 2019-08-07 09:37 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2019-08-14 16:59 - 2019-08-07 09:37 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2019-08-14 16:59 - 2019-08-07 09:37 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-08-14 16:59 - 2019-08-07 09:36 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-08-14 16:59 - 2019-08-07 09:36 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2019-08-14 16:59 - 2019-08-07 09:36 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2019-08-14 16:59 - 2019-08-07 09:36 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2019-08-14 16:59 - 2019-08-07 09:35 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2019-08-14 16:59 - 2019-08-07 09:35 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-08-14 16:59 - 2019-08-07 09:35 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2019-08-14 16:59 - 2019-08-07 09:35 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-08-14 16:59 - 2019-08-07 09:35 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 001826816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 001680384 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 000521216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 000278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-08-14 16:59 - 2019-08-07 09:33 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpsrv.dll
2019-08-14 16:59 - 2019-08-07 09:33 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-08-14 16:59 - 2019-08-07 09:32 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-08-14 16:59 - 2019-08-07 09:32 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-08-14 16:59 - 2019-08-07 09:32 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll
2019-08-14 16:59 - 2019-08-07 09:31 - 000367616 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2019-08-14 16:59 - 2019-08-07 08:15 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2019-08-14 16:59 - 2019-07-11 08:48 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2019-08-14 16:59 - 2019-07-11 03:30 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-08-14 16:59 - 2019-07-11 03:30 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2019-08-14 16:59 - 2019-07-11 03:30 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2019-08-14 16:59 - 2019-07-09 10:04 - 000348664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-08-14 16:59 - 2019-07-09 10:01 - 004527792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-08-14 16:59 - 2019-07-09 10:00 - 001616824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-08-14 16:59 - 2019-07-09 09:44 - 000039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsUpdateElevatedInstaller.exe
2019-08-14 16:59 - 2019-07-09 09:43 - 004718080 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-08-14 16:59 - 2019-07-09 09:43 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2019-08-14 16:59 - 2019-07-09 09:43 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2019-08-14 16:59 - 2019-07-09 09:40 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2019-08-14 16:59 - 2019-07-09 09:39 - 001210880 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2019-08-14 16:59 - 2019-07-09 09:39 - 001193472 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2019-08-14 16:59 - 2019-07-09 09:38 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2019-08-14 16:59 - 2019-07-09 09:37 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-08-14 16:59 - 2019-07-09 09:37 - 000517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
2019-08-14 16:59 - 2019-07-09 09:37 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2019-08-14 16:59 - 2019-07-09 08:37 - 000485888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
2019-08-14 16:59 - 2019-07-09 05:23 - 001213264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-08-14 16:59 - 2019-07-09 05:23 - 001035040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-08-14 16:59 - 2019-07-09 05:21 - 005625160 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-08-14 16:59 - 2019-07-09 05:21 - 000133136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2019-08-14 16:59 - 2019-07-09 05:20 - 000275512 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2019-08-14 16:59 - 2019-07-09 05:19 - 001674216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-08-14 16:59 - 2019-07-09 05:19 - 000799248 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2019-08-14 16:59 - 2019-07-09 05:19 - 000713488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2019-08-14 16:59 - 2019-07-09 05:19 - 000142352 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2019-08-14 16:59 - 2019-07-09 05:19 - 000046608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\werkernel.sys
2019-08-14 16:59 - 2019-07-09 05:12 - 001286528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-08-14 16:59 - 2019-07-09 05:11 - 000576528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2019-08-14 16:59 - 2019-07-09 05:11 - 000108560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2019-08-14 16:59 - 2019-07-09 04:56 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2019-08-14 16:59 - 2019-07-09 04:56 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2019-08-14 16:59 - 2019-07-09 04:55 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetDriverInstall.dll
2019-08-14 16:59 - 2019-07-09 04:55 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-08-14 16:59 - 2019-07-09 04:53 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-08-14 16:59 - 2019-07-09 04:52 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DuCsps.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2019-08-14 16:59 - 2019-07-09 04:50 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-08-14 16:59 - 2019-07-09 04:50 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-08-14 16:59 - 2019-07-09 04:50 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-08-14 16:59 - 2019-07-09 04:50 - 000141312 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2019-08-14 16:59 - 2019-07-09 04:50 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2019-08-14 16:59 - 2019-07-09 04:50 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdcpw.dll
2019-08-14 16:59 - 2019-07-09 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-08-14 16:59 - 2019-07-09 04:49 - 000856576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-08-14 16:59 - 2019-07-09 04:49 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-08-14 16:59 - 2019-07-09 04:49 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-08-14 16:59 - 2019-07-09 04:49 - 000372736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2019-08-14 16:59 - 2019-07-09 04:49 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-08-14 16:59 - 2019-07-09 04:49 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-08-14 16:59 - 2019-07-09 04:49 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-08-14 16:59 - 2019-07-09 04:49 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetDriverInstall.dll
2019-08-14 16:59 - 2019-07-09 04:48 - 000697344 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-08-14 16:59 - 2019-07-09 04:48 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-08-14 16:59 - 2019-07-09 04:48 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2019-08-14 16:59 - 2019-07-09 04:48 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-08-14 16:59 - 2019-07-09 04:48 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2019-08-14 16:59 - 2019-07-09 04:47 - 000928768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-08-14 16:59 - 2019-07-09 04:46 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2019-08-14 16:59 - 2019-07-09 04:45 - 001400832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-08-14 16:59 - 2019-07-09 04:45 - 001218560 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-08-14 16:59 - 2019-07-09 04:45 - 000510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-08-14 16:59 - 2019-07-09 04:45 - 000504832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2019-08-14 16:59 - 2019-07-09 04:44 - 001058304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-08-14 16:59 - 2019-07-09 04:44 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-08-14 16:59 - 2019-07-09 04:44 - 000796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-08-14 16:59 - 2019-07-09 04:44 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-08-14 16:59 - 2019-07-09 04:44 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-08-14 16:59 - 2019-07-09 04:44 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-08-14 16:59 - 2019-07-09 04:43 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-08-14 16:59 - 2019-07-09 04:43 - 001398272 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2019-08-14 16:59 - 2019-07-09 04:43 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-08-14 16:59 - 2019-07-09 04:43 - 000582144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2019-08-14 16:59 - 2019-06-20 04:21 - 000058882 _____ C:\WINDOWS\system32\srms.dat
2019-08-13 20:33 - 2019-08-20 20:01 - 000000000 ____D C:\Users\maxim\AppData\Roaming\Discord
2019-08-13 20:33 - 2019-08-13 20:33 - 000002244 ____C C:\Users\maxim\Desktop\Discord.lnk
2019-08-13 20:33 - 2019-08-13 20:33 - 000000000 ___DC C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2019-08-13 20:33 - 2019-08-13 20:33 - 000000000 ____D C:\Users\maxim\AppData\Local\SquirrelTemp
2019-08-13 20:33 - 2019-08-13 20:33 - 000000000 ____D C:\Users\maxim\AppData\Local\Discord
2019-08-10 20:00 - 2019-08-10 20:00 - 000000000 ____D C:\ProgramData\Ubisoft
2019-08-10 19:51 - 2019-08-10 19:51 - 000000825 _____ C:\Users\Public\Desktop\Assassin's Creed.lnk
2019-08-10 19:51 - 2019-08-10 19:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed
2019-08-09 19:05 - 2019-08-09 19:05 - 000000000 ____D C:\ProgramData\Codemasters
2019-08-09 18:36 - 2019-08-09 18:36 - 000000659 ____C C:\Users\maxim\Desktop\F1 2018.lnk
2019-08-09 18:36 - 2019-08-09 18:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F1 2018
2019-08-09 18:26 - 2019-08-09 18:26 - 000000531 _____ C:\Users\Public\Desktop\Diablo III.lnk
2019-08-09 18:26 - 2019-08-09 18:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2019-08-08 17:33 - 2019-04-06 16:31 - 000000000 ___DC C:\Users\maxim\Desktop\!Questie
2019-08-04 08:36 - 2019-08-04 08:36 - 000000777 _____ C:\Users\Public\Desktop\WoW Classic.lnk
2019-08-04 08:36 - 2019-08-04 08:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft Classic
2019-07-31 15:45 - 2019-07-31 15:45 - 000000000 ____D C:\Users\maxim\AppData\Roaming\AudioVisualizerApp
2019-07-31 06:15 - 2019-07-31 06:15 - 000000000 ____D C:\WINDOWS\Panther
2019-07-27 09:51 - 2019-07-27 15:23 - 000000000 ___DC C:\Users\maxim\Documents\4A Games
2019-07-27 09:51 - 2019-07-27 15:18 - 000000000 ____D C:\Users\maxim\AppData\Local\4A Games
2019-07-27 09:51 - 2019-07-27 09:51 - 000000850 _____ C:\Users\Public\Desktop\Metro Last Light Redux.lnk
2019-07-27 09:51 - 2019-07-27 09:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metro Last Light Redux [GOG.com]
2019-07-25 17:17 - 2019-07-18 21:13 - 001721816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443160.dll
2019-07-25 17:17 - 2019-07-18 21:13 - 001468320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443160.dll
2019-07-25 17:16 - 2019-08-18 03:03 - 004264024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-08-24 07:54 - 2019-05-16 22:27 - 001689050 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-08-24 07:54 - 2018-04-12 17:50 - 000717712 _____ C:\WINDOWS\system32\perfh005.dat
2019-08-24 07:54 - 2018-04-12 17:50 - 000144954 _____ C:\WINDOWS\system32\perfc005.dat
2019-08-24 07:54 - 2018-04-12 01:36 - 000000000 ____D C:\WINDOWS\INF
2019-08-24 07:50 - 2018-06-05 21:26 - 000000000 ____D C:\ProgramData\NVIDIA
2019-08-24 07:48 - 2019-04-16 08:48 - 000000000 _SHDC C:\Users\maxim\IntelGraphicsProfiles
2019-08-24 07:48 - 2018-04-12 01:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-08-24 07:47 - 2019-06-25 15:30 - 000000000 ____D C:\Program Files (x86)\ProxyGate
2019-08-24 07:47 - 2019-05-16 22:23 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-08-24 07:47 - 2018-04-11 23:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-08-24 07:45 - 2018-04-12 01:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-08-23 23:13 - 2019-04-16 09:13 - 000000000 ___DC C:\Users\maxim\AppData\Local\Battle.net
2019-08-23 22:54 - 2019-04-16 09:30 - 000000000 ____D C:\Program Files (x86)\Steam
2019-08-23 21:06 - 2019-05-21 10:34 - 000000000 ____D C:\Users\maxim\AppData\Roaming\uTorrent
2019-08-23 21:03 - 2019-05-21 16:12 - 000000000 ____D C:\Users\maxim\AppData\Local\BitTorrentHelper
2019-08-23 20:34 - 2019-04-16 08:48 - 000000000 ___DC C:\Users\maxim\AppData\Local\VirtualStore
2019-08-23 20:20 - 2019-05-16 22:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-08-23 15:28 - 2019-04-16 08:50 - 000000000 ___DC C:\Users\maxim\AppData\Local\CrashDumps
2019-08-23 15:08 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-08-23 06:42 - 2019-04-16 20:16 - 000281688 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr
2019-08-23 06:41 - 2019-05-16 22:26 - 000000000 ____D C:\Users\maxim\AppData\Local\D3DSCache
2019-08-23 06:41 - 2019-04-16 20:11 - 000000000 ___DC C:\Users\maxim\AppData\Local\Ubisoft Game Launcher
2019-08-23 06:40 - 2019-04-16 20:11 - 000282512 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2019-08-22 20:49 - 2019-04-18 08:49 - 000000000 ___DC C:\Users\maxim\Documents\The Witcher 3
2019-08-20 16:43 - 2019-04-16 06:08 - 000000000 ____D C:\temp
2019-08-20 16:43 - 2018-06-05 21:26 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-08-20 16:42 - 2018-06-05 21:25 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-08-18 03:03 - 2019-05-12 10:21 - 005002008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2019-08-17 00:03 - 2019-05-12 10:21 - 000054700 _____ C:\WINDOWS\system32\nvinfo.pb
2019-08-17 00:03 - 2018-06-05 21:26 - 000001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2019-08-16 22:01 - 2018-06-05 21:26 - 005469552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 002635248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 001767280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000653864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000451056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000150000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000124968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000083440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2019-08-15 18:17 - 2018-06-05 21:26 - 008678412 _____ C:\WINDOWS\system32\nvcoproc.bin
2019-08-15 06:14 - 2019-04-16 09:55 - 000000000 ___DC C:\Users\maxim\AppData\Local\2K Games
2019-08-14 20:07 - 2019-05-16 22:18 - 000431488 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-08-14 20:07 - 2019-04-16 08:48 - 000000000 __RDC C:\Users\maxim\3D Objects
2019-08-14 20:07 - 2017-10-03 18:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ___SD C:\WINDOWS\system32\UNP
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\TextInput
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\Provisioning
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-08-14 17:03 - 2018-04-12 01:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-08-14 17:01 - 2018-04-12 01:34 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-08-14 16:59 - 2019-04-16 18:00 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-08-14 16:56 - 2019-04-16 18:00 - 134272480 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-08-13 18:11 - 2019-04-16 09:12 - 000000000 ____D C:\Hry
2019-08-13 18:09 - 2019-05-20 17:08 - 000000000 ____D C:\Program Files (x86)\Twitch
2019-08-10 20:00 - 2019-07-04 17:37 - 000000000 ____D C:\Users\maxim\AppData\Roaming\Ubisoft
2019-08-09 19:05 - 2019-04-16 20:16 - 000000000 ___DC C:\Users\maxim\Documents\My Games
2019-08-07 06:14 - 2019-04-16 08:50 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-07 06:14 - 2019-04-16 08:50 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-08-06 22:22 - 2019-04-16 09:20 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-08-02 17:28 - 2019-04-16 18:00 - 000000000 ____D C:\Program Files\rempl
2019-07-31 15:21 - 2019-04-16 05:57 - 000000000 ____D C:\Program Files (x86)\Razer
2019-07-26 17:57 - 2019-04-16 19:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd

==================== Files in the root of some directories ================

2019-06-25 15:31 - 2019-06-25 15:31 - 000000000 _____ () C:\Users\maxim\AppData\Roaming\FC29FA0894FE.ini
2019-04-16 18:00 - 2019-07-04 19:44 - 038596337 ____C () C:\Users\maxim\AppData\Roaming\gta5_patch.bin
2019-04-16 18:00 - 2019-04-16 18:00 - 000332800 ____C () C:\Users\maxim\AppData\Roaming\patcher.dll

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-08-2019
Ran by maxim (24-08-2019 07:56:27)
Running from D:\Downloads
Windows 10 Home Version 1803 17134.950 (X64) (2019-05-16 20:23:57)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1760070117-4179939161-3013727825-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1760070117-4179939161-3013727825-503 - Limited - Disabled)
Guest (S-1-5-21-1760070117-4179939161-3013727825-501 - Limited - Disabled)
maxim (S-1-5-21-1760070117-4179939161-3013727825-1001 - Administrator - Enabled) => C:\Users\maxim
WDAGUtilityAccount (S-1-5-21-1760070117-4179939161-3013727825-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\uTorrent) (Version: 3.5.5.45311 - BitTorrent Inc.)
Agony UNRATED (HKLM-x32\...\Agony UNRATED_is1) (Version: - )
Aktualizace NVIDIA 37.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 37.0.0.0 - NVIDIA Corporation) Hidden
AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 5.0.5 - philandro Software GmbH)
Assassin's Creed verze 1.0.0.1 (HKLM-x32\...\{A588EEF5-A2F0-4222-B1BB-E4CF3B859905}_is1) (Version: 1.0.0.1 - )
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Battlefield™ V (HKLM-x32\...\{e26b382f-e945-4f70-9318-121b683f1d61}) (Version: 1.0.59.24655 - Electronic Arts)
Call of Duty Modern Warfare 2 full game MP - SP+updater -=AviaRa=- 1.00 (HKLM-x32\...\Call of Duty Modern Warfare 2 full game MP - SP+updater -=AviaRa=- 1.00) (Version: - )
Call of Duty Modern Warfare Remastered v.1.0 (HKLM-x32\...\Call of Duty Modern Warfare Remastered_is1) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.56 - Piriform)
Commandos Strike Force (HKLM-x32\...\{9AFFF2F6-527F-4B76-821D-839298C070F9}) (Version: 1.2 - )
CPUID HWMonitor 1.40 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.40 - CPUID, Inc.)
Cuphead (HKLM-x32\...\1963513391_is1) (Version: 20170929 - GOG.com)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Discord (HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
Dolby Atmos Windows API SDK (HKLM\...\{139C7F29-696B-4EEA-B4AF-2990C2ECF7AD}) (Version: 1.1.7.32 - Dolby Laboratories, Inc.)
Doom 2016 MULTi10 - ElAmigos version 6.66 (HKLM-x32\...\{6C967A93-A95F-4F65-A33A-EC8BC8750C2D}_is1) (Version: 6.66 - Bethesda Softworks)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
F1 2018 (HKLM-x32\...\F1 2018_is1) (Version: - )
Far Cry Primal (HKLM-x32\...\{80BD47AF-CF13-49B2-99BF-7E78FBA26124}_is1) (Version: - Ubisoft)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 76.0.3809.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Intel(R) Chipset Device Software (HKLM-x32\...\{17408817-d415-4768-a160-ae6d46d6bdb0}) (Version: 10.1.1.44 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1043 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 22.20.16.4836 - Intel Corporation) Hidden
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{2b32b7d0-4f9f-47c8-adb7-807e6cb2fb75}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LibreOffice 6.2.4.2 (HKLM\...\{B8FF8670-C6F4-4868-9DB2-C23324C0E575}) (Version: 6.2.4.2 - The Document Foundation)
Malwarebytes verze 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
Max Payne 3 Česky od Being.cz (HKLM\...\MaxPayne3cz) (Version: ERROR - Being Czech Republic)
Max Payne 3 Česky od Being.cz (HKLM-x32\...\MaxPayne3cz) (Version: ERROR - Being Czech Republic)
Metro - Last Light Redux (HKLM-x32\...\1430740172_is1) (Version: 2.0.0.2 - GOG.com)
Metro Exodus v.1.0 (HKLM-x32\...\Metro Exodus_is1) (Version: - )
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
My Friend Pedro (HKLM-x32\...\1102856701_is1) (Version: 1.01 - GOG.com)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.15 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.19.0.107 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.19.0.107 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.27 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 436.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 436.02 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
Observer (HKLM-x32\...\1449856523_is1) (Version: 1.0 - GOG.com)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Ovládací panel NVIDIA 436.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 436.02 - NVIDIA Corporation) Hidden
PC Building Simulator (HKLM-x32\...\PC Building Simulator_is1) (Version: - )
PLANET.COASTER.v1.2.3.Proper.Repack verze 1.2.3 (HKLM-x32\...\{802FA473-F39B-48FB-8600-64D95D9BED93}}_is1) (Version: 1.2.3 - Ali213.net)
Razer Synapse (HKLM-x32\...\Razer Synapse) (Version: 3.4.0711.071718 - Razer Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.15063.21299 - Realtek Semiconductor Corp.)
Resident Evil 7 Biohazard (HKLM-x32\...\{1ECBF8F3-7079-44CA-AD32-B2AECBCF636F}_is1) (Version: - Capcom)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.4.1 - Rockstar Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
The Sinking City Necronomicon Edition MULTi15 - ElAmigos verze 1.0 (HKLM-x32\...\{0506F651-A1D9-417D-BB3F-35A9254A48CE}_is1) (Version: 1.0 - Bigben Interactive)
The Witcher 3: Wild Hunt - Game of the Year Edition (HKLM-x32\...\1495134320_is1) (Version: 1.32 - GOG.com)
Thunderbolt™ Software (HKLM-x32\...\{87A31923-8F18-4943-8093-17DBEE0101B7}) (Version: 16.3.61.275 - Intel Corporation)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51a - Ghisler Software GmbH)
Twitch (HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 8.0.0 - Twitch Interactive, Inc.)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{2E8B8BDD-03DF-4C1C-8C99-E6A4BCBF43CE}) (Version: 2.51.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 53.0 - Ubisoft)
Valiant Hearts The Great War (HKLM-x32\...\{4C0EAD53-2DC4-48BC-A57A-A86BED789941}) (Version: 1.0.0 - Ubisoft) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-2) (Version: 1.0.54.1 - Intel Corporation Inc.)
Warcraft III - The Frozen Throne v1.26 (HKLM-x32\...\Warcraft III - The Frozen Throne v1.26 1.26) (Version: 1.26 - Blizzard)
WinRAR 5.70 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.70.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
World of Warcraft Classic (HKLM-x32\...\World of Warcraft Classic) (Version: - Blizzard Entertainment)

Packages:
=========
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_4.27.32.0_x86__k1h2ywk1493x8 [2019-04-16] (LENOVO INC.)
LenovoUtility -> C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.0.52.0_x64__5grkq8ppsgwt4 [2019-04-16] (LENOVO INC)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.3.4032.0_x86__8wekyb3d8bbwe [2019-04-16] (Microsoft Studios) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.953.0_x64__56jybvy8sckqj [2019-05-16] (NVIDIA Corp.)
Pošta a Kalendář -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11425.20190.0_x64__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation) [MS Ad]
Rozšíření pro video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation)
XLS Viewer Free -> C:\Program Files\WindowsApps\62307pauljohn.XLSViewerFree_1.1.0.1_x86__7sv5v3m8wq0b2 [2019-06-07] (pauljohn)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\igfxDTCM.dll [2017-11-15] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-08-16] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Desinstalar todo.lnk -> D:\Hry\CnC Generals and Zero Hour\Desinstalar.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\Off.lnk -> D:\Hry\CnC Generals and Zero Hour\RankOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\On.lnk -> D:\Hry\CnC Generals and Zero Hour\RankOn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Energy.lnk -> D:\Hry\CnC Generals and Zero Hour\ModEnergy.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Holland.lnk -> D:\Hry\CnC Generals and Zero Hour\ModHolland.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Reborn.lnk -> D:\Hry\CnC Generals and Zero Hour\ModReborn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Reloaded.lnk -> D:\Hry\CnC Generals and Zero Hour\ModReloaded.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Quitar todos.lnk -> D:\Hry\CnC Generals and Zero Hour\ModOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\Off.lnk -> D:\Hry\CnC Generals and Zero Hour\MejorZoomOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\On.lnk -> D:\Hry\CnC Generals and Zero Hour\MejorZoomOn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 1.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador1.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 2.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador2.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 3.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador3.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 4.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador4.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 5.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador5.bat (No File)

==================== Loaded Modules (Whitelisted) ==============

2019-06-21 06:49 - 2018-12-18 03:20 - 001006080 _____ () [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\LenovoWiFiSecurityPlugin\x86\x86\e_sqlite3.dll
2019-04-16 08:52 - 2018-08-12 20:29 - 001255424 _____ (Robert Simpson, et al.) [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\GenericMessagingPlugin\x86\x86\SQLite.Interop.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [470]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-09-29 15:46 - 2019-04-23 19:09 - 000000901 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 patches.rockstargames.com
127.0.0.1 prod.ros.rockstargames.com

2019-04-15 23:00 - 2019-04-15 23:00 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Razer Chroma SDK\bin;C:\Program Files\Razer Chroma SDK\bin;C:\Program Files (x86)\Razer\ChromaBroadcast\bin;C:\Program Files\Razer\ChromaBroadcast\bin;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\WindowsApps;;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\maxim\Desktop\world_of_warcraft_horde_symbol_background_red_16279_1920x1080.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\StartupFolder: => "fcbd.bat"
HKLM\...\StartupApproved\Run32: => "WindowsDriverScan64"
HKLM\...\StartupApproved\Run32: => "WindowsDriverScan86"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\StartupFolder: => "reg.lnk"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\StartupFolder: => "Twitch.lnk"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "GalaxyClient"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "OneDriveSetup"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D0AEAB0F-52FC-49E5-AA69-AC0B8EB2222F}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{D385DC01-8703-48F5-9CC7-381D14D2BA62}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{CAE63EAF-BAE9-4C50-BDD8-EB41364DFAB7}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{C28A3D27-A7EC-4DF0-879B-F9EA43958758}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{64EC2492-8B31-4FC9-B9BC-73839CF89650}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [{0A1410DA-EF4B-4E02-9A1A-D505AA33FDC5}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [UDP Query User{FCCAB193-67E7-4C0F-ADA6-2CD3031F438E}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Block) C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe No File
FirewallRules: [TCP Query User{6F55B2C1-649E-4659-9D39-0D5E6961BAFA}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Block) C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe No File
FirewallRules: [UDP Query User{56EA5463-6E9C-45BC-A42C-855062F0B15D}C:\hry\far cry primal\bin\fcprimal.exe] => (Block) C:\hry\far cry primal\bin\fcprimal.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [TCP Query User{BCF64F7B-AFDE-4493-BF3B-2C91CEA6E9DA}C:\hry\far cry primal\bin\fcprimal.exe] => (Block) C:\hry\far cry primal\bin\fcprimal.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{61991C0F-0E8A-4E34-A29E-11E29292AD9F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe No File
FirewallRules: [{AD2ED130-4ED6-444B-A333-CA0292068758}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe No File
FirewallRules: [{5633D3F0-17FD-40AD-9E8C-C18D74C9E47E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{9275D04E-FE26-456A-8E23-93B20EFF4E88}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{27AAF2C8-D1AE-4E0C-84B3-94141EED2B83}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{2D6EDA30-C1A1-45B0-8862-513E6C3E0A0F}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{ACA9DA5C-812C-4502-A1FB-14397D96F5D0}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [{91E3A170-4E73-4CD9-8AAB-DC44479668AC}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [UDP Query User{AC4D7B21-F211-475B-926A-9A88178B68D5}C:\hry\outlast 2\binaries\win64\outlast2.exe] => (Block) C:\hry\outlast 2\binaries\win64\outlast2.exe No File
FirewallRules: [TCP Query User{592C6D3C-A55A-44F5-8698-B3C6F811F398}C:\hry\outlast 2\binaries\win64\outlast2.exe] => (Block) C:\hry\outlast 2\binaries\win64\outlast2.exe No File
FirewallRules: [UDP Query User{2A24BD4C-5071-48AE-AC32-19A68E23756C}C:\hry\battlefield 1\bf1.exe] => (Block) C:\hry\battlefield 1\bf1.exe No File
FirewallRules: [TCP Query User{C0BDA519-BE2F-459F-A3DA-947AE9ABE42C}C:\hry\battlefield 1\bf1.exe] => (Block) C:\hry\battlefield 1\bf1.exe No File
FirewallRules: [UDP Query User{5770D039-C276-46E2-942A-92CF849452C6}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe No File
FirewallRules: [TCP Query User{0604EF08-263B-4295-A290-45336A85DABA}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe No File
FirewallRules: [{3BCCE861-6841-453A-864D-DCE6220B1C06}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{E15EB3C7-0FB4-4518-BB9D-A360FFD87CB8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{D6BC82D1-65FD-493E-8CED-B615219779D8}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe No File
FirewallRules: [TCP Query User{2A54499B-6726-4F6F-A03D-D94F78351417}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe No File
FirewallRules: [UDP Query User{3C3278BC-C53A-412B-9EAC-0074633AF946}C:\users\maxim\utorrent.exe] => (Allow) C:\users\maxim\utorrent.exe No File
FirewallRules: [TCP Query User{0DA970E9-0CE0-44E7-BE82-9FF763C111B9}C:\users\maxim\utorrent.exe] => (Allow) C:\users\maxim\utorrent.exe No File
FirewallRules: [{A9CB756F-5137-435C-941D-4A6FC9E46A74}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{7C2CA503-8B41-42A6-80F1-48D2FBB5C326}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{D50C39C0-2644-4049-8504-98ED7164D59B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{D8063BA2-A695-4CDF-9528-B5CA028AC292}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [UDP Query User{E620B31E-9FF7-4A5B-B4A5-3F564959CE32}C:\hry\hearthstone\hearthstone.exe] => (Allow) C:\hry\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [TCP Query User{571F2852-8C5A-4600-B03B-FE0DE3698EC7}C:\hry\hearthstone\hearthstone.exe] => (Allow) C:\hry\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{5AB208EC-2327-4C5C-8993-98ADFD90A8B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe No File
FirewallRules: [{F1B94ACF-FBDE-4A92-90ED-94D138A38DF6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe No File
FirewallRules: [{2CFA598F-5FF1-4138-B690-97038E8FB821}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II\pc\mafia2.exe (Valve Corp. -> 2K Czech) [File not signed]
FirewallRules: [{E044A392-B959-40A6-AC26-A239BA19B3D7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II\pc\mafia2.exe (Valve Corp. -> 2K Czech) [File not signed]
FirewallRules: [TCP Query User{F86EEF5A-D85A-48BE-950E-78ABCDCE670D}C:\hry\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\hry\world of warcraft\_retail_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{AD3724A4-1921-4BD4-A9E2-A24F49BDDAB7}C:\hry\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\hry\world of warcraft\_retail_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{828A97B9-2196-4BCD-BA41-5FBC98605B71}] => (Allow) C:\Users\maxim\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{4EA04FAB-9FAA-4726-AAF6-8ADC42450FB4}] => (Allow) C:\Users\maxim\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{FB21996A-450D-4696-82DD-A8EB884EED64}] => (Allow) D:\Hry\steamapps\common\FarCry5\bin\FarCry5.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{4F4F4732-8BCE-4560-B1C6-CE68F061F486}] => (Allow) D:\Hry\steamapps\common\FarCry5\bin\FarCry5.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{13F1BD16-D044-4C52-AF17-4D829D20D072}] => (Allow) D:\Hry\steamapps\common\FarCry5\bin\ArcadeEditor64.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{8853D8A4-AF78-4064-992C-68C3B2AE1AE9}] => (Allow) D:\Hry\steamapps\common\FarCry5\bin\ArcadeEditor64.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{01CBA212-F9C0-45A0-8E61-78B8F5410DE1}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{F2CF6163-04C3-4661-93E8-363A942122E9}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{8A2A29E0-DCFE-4107-8898-F959552C07C9}] => (Allow) D:\Hry\steamapps\common\Left 4 Dead 2\left4dead2.exe () [File not signed]
FirewallRules: [{D4696747-0D57-454E-B0E0-25BDB8556902}] => (Allow) D:\Hry\steamapps\common\Left 4 Dead 2\left4dead2.exe () [File not signed]
FirewallRules: [TCP Query User{FFC7CB5A-CA45-4203-9BDD-B059D66FB41F}D:\hry\call of duty modern warfare remastered\h1_sp64_ship.exe] => (Block) D:\hry\call of duty modern warfare remastered\h1_sp64_ship.exe (Activision Publishing -> Activision)
FirewallRules: [UDP Query User{90696B61-AADC-4ADF-B7EA-8BC32A3BF4B0}D:\hry\call of duty modern warfare remastered\h1_sp64_ship.exe] => (Block) D:\hry\call of duty modern warfare remastered\h1_sp64_ship.exe (Activision Publishing -> Activision)
FirewallRules: [{64903511-17C0-48FB-B6BF-AD4D3D3CE09A}] => (Allow) D:\Hry\BF5\bfvTrial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{995092C2-310E-465F-9A38-42C54FB800E4}] => (Allow) D:\Hry\BF5\bfvTrial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{D153AA68-D89E-438B-ADD4-379BDF225CBC}] => (Allow) D:\Hry\BF5\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [{FDAF6DE5-F27C-43AF-9400-FB177DF8E3DD}] => (Allow) D:\Hry\BF5\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [TCP Query User{F5BFBF37-14D2-48A8-8B28-E616DC572E34}D:\hry\doom 2016\doomx64vk.exe] => (Block) D:\hry\doom 2016\doomx64vk.exe (id Software) [File not signed]
FirewallRules: [UDP Query User{DBE9D119-26BD-46E5-AC0A-C6DDAC75A633}D:\hry\doom 2016\doomx64vk.exe] => (Block) D:\hry\doom 2016\doomx64vk.exe (id Software) [File not signed]
FirewallRules: [{D7C0A1F9-C83A-4C30-B11A-82C2220F3140}] => (Allow) D:\Hry\steamapps\common\Alan Wake\AlanWake.exe (Remedy Entertainment Ltd. -> )
FirewallRules: [{7F15CCEB-9DF8-4554-9911-6818890A8F0C}] => (Allow) D:\Hry\steamapps\common\Alan Wake\AlanWake.exe (Remedy Entertainment Ltd. -> )
FirewallRules: [{30E6CAE3-2B2C-465D-B3ED-AC7169F3296F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{405B11E9-D8A0-4C62-AA34-2293BD967B57}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{F020C4E8-FD25-444F-931C-93E69F215DB2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{EACEECAB-14B4-432D-9FCC-C5C67E06D282}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C2188CCD-3474-4921-B83D-C00CBFE0E78B}] => (Allow) D:\Hry\steamapps\common\Crash Bandicoot - N Sane Trilogy\CrashBandicootNSaneTrilogy.exe (Activision Publishing Inc -> )
FirewallRules: [{966F4EBE-AA8A-4D07-9B73-7EA467FF310D}] => (Allow) D:\Hry\steamapps\common\Crash Bandicoot - N Sane Trilogy\CrashBandicootNSaneTrilogy.exe (Activision Publishing Inc -> )
FirewallRules: [{986896B7-2D35-4723-8D77-22453843A22B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{46D80308-745A-47DE-9B92-0CCD0039FB89}] => (Allow) D:\Hry\steamapps\common\Mafia III\launcher.exe (2K Games) [File not signed]
FirewallRules: [{A5F11C94-027B-4DA4-A14C-DA3D8E3DD5BF}] => (Allow) D:\Hry\steamapps\common\Mafia III\launcher.exe (2K Games) [File not signed]
FirewallRules: [{A5036139-26ED-4437-9B11-BE055686AA7E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe No File
FirewallRules: [{9D26EE61-18D8-4705-9F85-7DF650FF0114}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe No File
FirewallRules: [{25224CA8-2539-44D3-8D7A-3A7CABA5CB63}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe No File
FirewallRules: [{F6E77267-3D5B-4EA1-92CE-A089CF990907}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe No File
FirewallRules: [{E2B15F3A-6097-4020-8C1A-3F51A3DF8796}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\farcry3.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{7F70EDD9-9B49-4EAE-AF66-1444ADD14F40}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\farcry3.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{F36D1CD7-2686-4CE8-B1DB-4E38ED328D9F}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\farcry3_d3d11.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{CDA1FCE4-C835-426D-AC99-D784A7738AD0}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\farcry3_d3d11.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{75F1CF74-4284-432D-AFB7-F8C4DC78445F}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{A67E8B65-887C-4266-B138-1F670D3B76DA}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{2BFDCFC6-01A7-4E55-8A0C-15248D9B17F3}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{F0EEE5BC-1B7F-4966-ABE5-0EE15B89429D}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{C9139393-DF7D-4ADB-BEDC-BDA285C9B122}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{055ACAF7-1A02-4289-B6B9-98D1676BFBA6}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )

==================== Restore Points =========================

14-08-2019 16:56:30 Windows Update
18-08-2019 20:16:12 Installed Call of Duty(R) 2

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/23/2019 03:28:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CrashBandicootNSaneTrilogy.exe, verze: 0.0.0.0, časové razítko: 0x5b50a076
Název chybujícího modulu: CrashBandicootNSaneTrilogy.exe, verze: 0.0.0.0, časové razítko: 0x5b50a076
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000118718c
ID chybujícího procesu: 0x2584
Čas spuštění chybující aplikace: 0x01d559b3ea74f5dd
Cesta k chybující aplikaci: D:\Hry\steamapps\common\Crash Bandicoot - N Sane Trilogy\CrashBandicootNSaneTrilogy.exe
Cesta k chybujícímu modulu: D:\Hry\steamapps\common\Crash Bandicoot - N Sane Trilogy\CrashBandicootNSaneTrilogy.exe
ID zprávy: fc650260-a5a6-4911-936a-284973f3220e
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/22/2019 09:50:52 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: LAPTOP-O3TRNGPI)
Description: httphttp-2147467263

Error: (08/20/2019 07:55:12 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: LAPTOP-O3TRNGPI)
Description: httphttp-2147467263

Error: (08/20/2019 06:14:04 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: LAPTOP-O3TRNGPI)
Description: httphttp-2147467263

Error: (08/19/2019 07:34:18 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: LAPTOP-O3TRNGPI)
Description: httphttp-2147467263

Error: (08/18/2019 08:18:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: cod2.exe, verze: 2.1.12.0, časové razítko: 0x2a425e19
Název chybujícího modulu: ntdll.dll, verze: 10.0.17134.799, časové razítko: 0x636bcb43
Kód výjimky: 0xc000041d
Posun chyby: 0x00038d6b
ID chybujícího procesu: 0x275c
Čas spuštění chybující aplikace: 0x01d555f15911a1b7
Cesta k chybující aplikaci: G:\Setup\rsrc\cod2.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: 05ffbbc4-d837-4428-a9d2-177b3a98e394
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/18/2019 08:18:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: cod2.exe, verze: 2.1.12.0, časové razítko: 0x2a425e19
Název chybujícího modulu: ntdll.dll, verze: 10.0.17134.799, časové razítko: 0x636bcb43
Kód výjimky: 0xc0000005
Posun chyby: 0x00038d6b
ID chybujícího procesu: 0x275c
Čas spuštění chybující aplikace: 0x01d555f15911a1b7
Cesta k chybující aplikaci: G:\Setup\rsrc\cod2.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: f6a77d37-c370-4416-8e86-f534284f109c
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/15/2019 08:14:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Discord.exe, verze: 0.0.305.0, časové razítko: 0x5c8190a4
Název chybujícího modulu: Discord.exe, verze: 0.0.305.0, časové razítko: 0x5c8190a4
Kód výjimky: 0xc0000005
Posun chyby: 0x0007da36
ID chybujícího procesu: 0x24d8
Čas spuštění chybující aplikace: 0x01d553951da2c773
Cesta k chybující aplikaci: C:\Users\maxim\AppData\Local\Discord\app-0.0.305\Discord.exe
Cesta k chybujícímu modulu: C:\Users\maxim\AppData\Local\Discord\app-0.0.305\Discord.exe
ID zprávy: fe6b73c2-1e40-4d84-8bfe-e84cee1e8a26
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (08/24/2019 07:53:08 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 07:50:38 AM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-O3TRNGPI)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli LAPTOP-O3TRNGPI\maxim (SID: S-1-5-21-1760070117-4179939161-3013727825-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 07:50:17 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscBrokerManager
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 07:50:17 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 07:48:35 AM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-O3TRNGPI)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli LAPTOP-O3TRNGPI\maxim (SID: S-1-5-21-1760070117-4179939161-3013727825-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 07:48:04 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 07:48:04 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 07:47:58 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba SecDrv neuspěla při spuštění v důsledku následující chyby:
Načtení tohoto ovladače je blokováno.


Windows Defender:
===================================
Date: 2019-08-04 08:33:17.968
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {2CCF575C-5974-4CC0-A0C3-D20B403DE5C9}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-07-25 17:12:50.827
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {42273B18-ACD6-4958-8F20-D0639A47E155}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-07-24 06:49:05.671
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {7DF474DE-FEBA-4250-BF1B-D13003D94914}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-07-18 06:20:02.992
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {7EA780EC-9C08-4A3D-A265-3C94B5596B4F}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-07-05 20:45:00.633
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {B1D2154D-B2E6-4A32-8836-84B7BBA6DDB9}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

==================== Memory info ===========================

BIOS: LENOVO 6TCN28WW 01/24/2018
Motherboard: LENOVO LNVNB161216
Processor: Intel(R) Core(TM) i5-7300HQ CPU @ 2.50GHz
Percentage of memory in use: 56%
Total physical RAM: 7832.14 MB
Available physical RAM: 3368.85 MB
Total Virtual: 13720.14 MB
Available Virtual: 7861.08 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:212.23 GB) (Free:66.55 GB) NTFS
Drive d: (Data) (Fixed) (Total:953.85 GB) (Free:271.99 GB) NTFS
Drive e: (LENOVO) (Fixed) (Total:25 GB) (Free:22.16 GB) NTFS
Drive f: (Maxtor) (Fixed) (Total:931.51 GB) (Free:370.35 GB) NTFS

\\?\Volume{71e72131-b091-4ef6-8604-72ac5f2cc5b6}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.53 GB) NTFS
\\?\Volume{fedf1a78-544d-4a88-8b01-af00c428f589}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: F291D6E3)

Partition: GPT.

========================================================
Disk: 1 (Protective MBR) (Size: 953.9 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: F613801B)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Spuštění Chromu a stránky po zapnutí PC

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Gambac
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 47
Registrován: 29 bře 2009 10:42

Re: Spuštění Chromu a stránky po zapnutí PC

#3 Příspěvek od Gambac »

Provedeno, zasílám log, zatím se ten stejny problem stale projevuje, ale vim, ze se jeste doresi :)
Díky.

# -------------------------------
# Malwarebytes AdwCleaner 7.4.0.0
# -------------------------------
# Build: 07-23-2019
# Database: 2019-08-21.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 08-24-2019
# Duration: 00:00:02
# OS: Windows 10 Home
# Cleaned: 11
# Failed: 1


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Program Files (x86)\ProxyGate

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

Deleted AVG Secure Search
Deleted AVG Secure Search
Deleted Search the web (Softonic)
Deleted SweetIM Search
Deleted SweetIM Search
Deleted WebSearch
Deleted http://home.sweetim.com/?st=17&barid={A ... DF9AE2CF44}
Deleted http://home.sweetim.com/?st=17&barid={A ... DF9AE2CF44}
Deleted http://www.istartsurf.com/?type=hp&ts=1 ... 9578995789
Deleted istartsurf
Not Deleted AVG Secure Search

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [2159 octets] - [24/08/2019 11:52:50]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Gambac
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 47
Registrován: 29 bře 2009 10:42

Re: Spuštění Chromu a stránky po zapnutí PC

#4 Příspěvek od Gambac »

Po skonceni skenovani zde neni volba Cisteni a opravy (Clean and Repair), ale pouze Next a Quarantine (Karanténa).

Obrázek
Přílohy
Výstřižek.JPG
Výstřižek.JPG (60.32 KiB) Zobrazeno 2390 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Spuštění Chromu a stránky po zapnutí PC

#5 Příspěvek od Rudy »

Podle příspěvku výše jsou položky smazány. Dejte nové logy FRST+Addition.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Gambac
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 47
Registrován: 29 bře 2009 10:42

Re: Spuštění Chromu a stránky po zapnutí PC

#6 Příspěvek od Gambac »

EDIT: Jeste jsem zkusil vymazat v nastaveni Chromu domovské stranky a nastavit jako vychozi web google.cz, 2x restartoval a jiz se chrome znovu neotevrel


Bohužel se stále projevuje, o par sekund se zpomalil loading pc po naskenovani otisku a po nabehnuti plochy se v chromu otevrou 2 panely

Kód: Vybrat vše

http://larati.net/-12QRPE/9KCw?rndad=1499926385-1566644539
https://tonstorsharkinsand.pro/OTYPE?tag_id=604364&sub_id1=&sub_id2=-2043195332945284267&cookie_id=e0f8d398-4d9d-4252-bcf2-be67c574487e&lp=download_file&tb=redirect&allb=redirect&ob=redirect&href=https%3A%2F%2Fnameketathar.pro%2F%3Ftid%3D604364%26noocp%3D1&hop=7
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-08-2019
Ran by maxim (administrator) on LAPTOP-O3TRNGPI (LENOVO 81AC) (24-08-2019 12:57:54)
Running from D:\Downloads
Loaded Profiles: maxim (Available Profiles: maxim)
Platform: Windows 10 Home Version 1803 17134.950 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C:\Hry\Battle.net\Battle.net.exe
(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C:\Hry\Battle.net\Battle.net.exe
(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.6788\Agent.exe
(Dolby Laboratories, Inc. -> ) C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(Intel Corporation -> Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\IntelCpHDCPSvc.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\IntelCpHeciSvc.exe
(Intel(R) Software Development Products -> Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_8f1fe4a9cfb9cf9c\aesm_service.exe
(Intel(R) Trust Services -> Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
(Intel(R) Wireless Connectivity Solutions -> Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files (x86)\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.Device.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\PluginHost\Lenovo.Modern.ImController.PluginHost.SettingsApp.exe
(Lenovo -> Lenovo Group Ltd.) C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2019.19031.17720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.19031.11411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SnippingTool.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\MsMpEng.exe
(Microsoft Windows Publisher -> Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1907.4-0\NisSrv.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(philandro Software GmbH -> ) C:\Program Files (x86)\AnyDesk\AnyDesk.exe
(philandro Software GmbH -> ) C:\Program Files (x86)\AnyDesk\AnyDesk.exe
(Razer USA Ltd. -> ) C:\Program Files (x86)\Razer\Synapse3\UserProcess\Razer Synapse Service Process.exe
(Razer USA Ltd. -> Razer Inc) C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\Razer Central.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe
(Razer USA Ltd. -> Razer Inc.) C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe
(Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
(Razer USA Ltd. -> The CefSharp Authors) C:\Program Files (x86)\Razer\Razer Services\Razer Central\CefSharp.BrowserSubprocess.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Windows -> Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18384352 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LVA] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493984 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493984 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1493984 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM-x32\...\Run: [WindowsDriverScan86] => C:\Program Files (x86)\Adobe Arkalis\Arkalis86.lnk [1501 2014-08-10] () [File not signed]
HKLM-x32\...\Run: [WindowsDriverScan64] => C:\Program Files (x86)\Adobe Arkalis\Arkalis.lnk [1419 2014-08-10] () [File not signed]
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3210528 2019-08-13] (Valve -> Valve Corporation)
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3493104 2019-07-17] (Razer USA Ltd. -> Razer Inc.)
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GOG Galaxy\GalaxyClient.exe [7610952 2019-06-25] (GOG Sp. z o.o. -> GOG.com)
HKU\S-1-5-18\...\Run: [Synapse3] => C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe [3493104 2019-07-17] (Razer USA Ltd. -> Razer Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\76.0.3809.100\Installer\chrmstp.exe [2019-08-07] (Google LLC -> Google LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AnyDesk.lnk [2019-04-16]
ShortcutTarget: AnyDesk.lnk -> C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\updateSteam.bat [2018-02-04] () [File not signed]
Startup: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\reg.lnk [2019-04-16]
ShortcutAndArgument: reg.lnk -> C:\ProgramData\NVIDIA bas\reg.vbs => 1 2 3
Startup: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Twitch.lnk [2019-05-20]
ShortcutTarget: Twitch.lnk -> C:\Program Files (x86)\Twitch\Bin\Twitch.exe (Twitch Interactive, Inc. -> Twitch Interactive, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0282405B-B67F-4A2C-A77D-E0C7C3090D3F} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service when hardware is detected => sc.exe start ThunderboltService
Task: {08B6BD70-0CE3-4920-AD99-415D5F740CF4} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1B2CFE1A-760B-4957-8C32-D144C664D5AB} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {23E7A971-068D-403E-B6FE-9DDE17D2FE59} - System32\Tasks\OneDrive Standalone Update Task v2 => C:\Users\maxim\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
Task: {2B7F1F8F-5041-42DB-BE68-631A159BDDBD} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {4248E3D3-7ED7-48D8-8F8F-AB26E2F9EA00} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask => %windir%\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler /v start /t reg_dword /d 1 /f /reg:32
Task: {48AA4297-FA16-48DC-BB5B-3782F4ADA20E} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on login if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226024 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {4BE32B2C-E370-4480-84E8-5C0DF9E4F505} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {4F182DB5-B337-414F-B8C0-96E458127DEE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [16509040 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {621BC5B8-26CD-43FD-802A-ECAE5F07C0BF} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application on switch user if service is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226024 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {62974823-9836-44D0-9919-7808AB152790} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {70FEE62F-48D8-4F2B-916A-FCC296AFBDFB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-16] (Google Inc -> Google LLC)
Task: {79E6A66D-3C50-439D-ACDA-3E410BE9E791} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-16] (Google Inc -> Google LLC)
Task: {81FBBEFE-C379-49FE-9817-FD869D2D8040} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-04-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {87B3CE1A-AD49-40D7-A282-9A53F09CBF51} - System32\Tasks\LenovoUtility Task => C:\Windows\explorer.exe lenovo-utility://
Task: {896A660C-1385-4B82-BED4-EF6392B00596} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8AD9A9DD-2220-45A1-813B-76F05BBD2CA7} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {9D626F7D-5E11-41BA-9B6E-4D9AE30398A5} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [648504 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {AA1A412D-73D3-4F97-B0F3-F34C09789831} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [816960 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
Task: {AA96CCB3-7733-4D39-BB0E-3B0ABEFE9ACC} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\73777f32-ba5b-4f6b-aa97-40fa78372129 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {AAC52445-DF92-4C1A-90A8-A63C1DFA738A} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt service on boot if driver is up => C:\Program Files (x86)\Intel\Thunderbolt Software\\tbtsvc.exe [2150120 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {AD89097A-D29D-4A4F-957D-5845BF4FA5B9} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B44B93D1-F758-495D-AB5B-4BBEF485BC06} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => %windir%\system32\sc.exe START ImControllerService
Task: {B82D1894-AFBA-462D-9A6B-3FF0A124AA0D} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [897008 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {C578D146-B2AC-4B17-BE60-7448C9604926} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {CBCBB262-AFC0-407C-8FC6-35E41A11B502} - System32\Tasks\Intel\Thunderbolt\Start Thunderbolt application when hardware is detected => C:\Program Files (x86)\Intel\Thunderbolt Software\\ConditionalAppStarter.exe [226024 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
Task: {CCB9E617-2979-4384-BDF8-3AFF625658F2} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\c8441786-6c40-480b-b6b9-78b3c6663aeb => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {D5D6C179-8055-468E-AAC4-A6D97B1C2D40} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MpCmdRun.exe [469960 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
Task: {E64961CC-157D-4AB9-9E8E-4DDEF6688279} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3788144 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {ECF3D57D-56D3-41AA-A3E0-3D11739F56A0} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Monitor => C:\WINDOWS\system32\ImController.InfInstaller.exe [54440 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {F3AE8606-C610-4827-A3DD-14FAF31C4FFD} - System32\Tasks\Lenovo\ImController\TimeBasedEvents\82ff5b7a-1606-4ffe-a574-8e1dd7ef5a13 => C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
Task: {FF101F99-DB38-4316-AFFD-4CB1523FA395} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1130480 2019-06-18] (NVIDIA Corporation -> NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{63f08b27-63ed-4d74-8733-a5b9a608e420}: [DhcpNameServer] 172.168.127.2
Tcpip\..\Interfaces\{7535acc9-59db-44f8-b286-cdc93b99ebc9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{ccd9d27c-808f-4925-9736-ce15e8b2c2d8}: [DhcpNameServer] 213.46.172.37 213.46.172.36

Internet Explorer:
==================
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo17win10.msn.com/?pc=LCTE
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://mystart.lenovo.com/
SearchScopes: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001 -> DefaultScope {BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} URL =
SearchScopes: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001 -> {BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} URL =

FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.34.11\npGoogleUpdate3.dll [2019-05-15] (Google Inc -> Google LLC)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://home.sweetim.com/?st=17&barid={A16EE4EC-9151-11E1-B822-D0DF9AE2CF44}","hxxp://www.google.com/","hxxp://www.istartsurf ... oogle.com/"
CHR Profile: C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default [2019-08-24]
CHR DownloadDir: D:\Downloads
CHR Extension: (Prezentace) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-04-16]
CHR Extension: (Dokumenty) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-04-16]
CHR Extension: (Disk Google) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-04-16]
CHR Extension: (YouTube) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-04-16]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2019-08-09]
CHR Extension: (Tabulky) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-04-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2019-04-16]
CHR Extension: (AdBlock) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2019-08-15]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-04-16]
CHR Extension: (Gmail) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-08-07]
CHR Extension: (Eiffel Tower) - C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Default\Extensions\ppbaibkigenhdcommebegmmmpoolmpip [2019-04-16]
CHR Profile: C:\Users\maxim\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-08-23]
CHR Profile: C:\Users\maxim\AppData\Local\Google\Chrome\User Data\System Profile [2019-08-23]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AESMService; C:\WINDOWS\System32\DriverStore\FileRepository\sgx_psw.inf_amd64_8f1fe4a9cfb9cf9c\aesm_service.exe [3418392 2019-04-09] (Intel(R) Software Development Products -> Intel Corporation)
R2 AnyDesk; C:\Program Files (x86)\AnyDesk\AnyDesk.exe [2822952 2019-04-16] (philandro Software GmbH -> )
R2 Dolby DAX API Service; C:\Program Files\Dolby\Dolby DAX3\API\DAX3API.exe [212784 2017-09-19] (Dolby Laboratories, Inc. -> )
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [803440 2019-06-09] (EasyAntiCheat Oy -> EasyAntiCheat Ltd)
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [1701480 2017-07-07] (Intel Corporation -> Intel Corporation)
S3 GalaxyClientService; C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe [791112 2019-06-25] (GOG Sp. z o.o. -> GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [7170632 2019-06-25] (GOG Sp. z o.o. -> GOG.com)
S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2414264 2017-07-25] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R2 ibtsiva; C:\WINDOWS\system32\ibtsiva.exe [515256 2017-08-30] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [76968 2019-04-24] (Lenovo -> Lenovo Group Ltd.)
R3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [742704 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [668472 2017-09-21] (Intel(R) Trust Services -> Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [197264 2017-09-25] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [782136 2019-03-06] (NVIDIA Corporation -> NVIDIA Corporation)
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [967272 2019-07-15] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [1444512 2019-07-16] (Razer USA Ltd. -> Razer Inc.)
R2 Razer Game Manager Service; C:\Program Files (x86)\Razer\Razer Services\GMS\GameManagerService.exe [253776 2019-07-03] (Razer USA Ltd. -> Razer Inc)
R2 Razer Synapse Service; C:\Program Files (x86)\Razer\Synapse3\Service\Razer Synapse Service.exe [287472 2019-07-17] (Razer USA Ltd. -> Razer Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [324576 2017-10-18] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
R2 RzActionSvc; C:\Program Files (x86)\Razer\Razer Services\Razer Central\RazerCentralService.exe [532864 2019-07-11] (Razer USA Ltd. -> Razer Inc.)
S3 ThunderboltService; C:\Program Files (x86)\Intel\Thunderbolt Software\tbtsvc.exe [2150120 2017-03-16] (Intel(R) Client Connectivity Division SW -> Intel Corporation)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\NisSrv.exe [2552416 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1907.4-0\MsMpEng.exe [108832 2019-07-26] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [69560 2017-07-07] (Intel Corporation -> Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [382392 2017-07-07] (Intel Corporation -> Intel Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153328 2019-01-08] (Malwarebytes Corporation -> Malwarebytes)
R3 iaLPSS2_GPIO2; C:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys [98976 2017-08-24] (Intel(R) Embedded Subsystems and IP Blocks Group -> Intel Corporation)
S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70664 2017-07-25] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [129552 2017-08-30] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [199768 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [224408 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73584 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [116112 2019-08-24] (Malwarebytes Corporation -> Malwarebytes)
R3 Netwtw06; C:\WINDOWS\System32\drivers\Netwtw06.sys [7751176 2017-09-13] (Intel(R) Wireless Connectivity Solutions -> Intel Corporation)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvlti.inf_amd64_a472382cd8e04666\nvlddmkm.sys [22347976 2019-08-18] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-06-13] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69840 2019-03-19] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [75600 2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [782304 2017-04-12] (Realtek Semiconductor Corp. -> Realsil Semiconductor Corporation)
R3 rtux64w10; C:\WINDOWS\System32\drivers\rtux64w10.sys [348672 2018-04-12] (Microsoft Windows -> Realtek )
R3 RzCommon; C:\WINDOWS\System32\drivers\RzCommon.sys [49032 2019-01-16] (Razer USA Ltd. -> Razer Inc)
S3 RzDev_0053; C:\WINDOWS\System32\drivers\RzDev_0053.sys [51696 2018-04-22] (Razer USA Ltd. -> Razer Inc)
R3 RzDev_0067; C:\WINDOWS\System32\drivers\RzDev_0067.sys [51696 2018-04-22] (Razer USA Ltd. -> Razer Inc)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Bruce James -> Scarlet.Crush Productions)
S2 SecDrv; C:\WINDOWS\SysWOW64\drivers\SECDRV.SYS [163644 2019-08-19] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed]
R3 SPUVCbv; C:\WINDOWS\System32\Drivers\SPUVCbv64.sys [899672 2017-10-18] (SUNPLUS INNOVATION TECHNOLOGY INC. -> Sunplus Innovation Technology Inc.)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [47496 2019-07-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [344288 2019-07-26] (Microsoft Windows -> Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54496 2019-07-26] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-08-24 12:02 - 2019-08-24 12:02 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-08-24 12:02 - 2019-08-24 12:02 - 000224408 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2019-08-24 12:02 - 2019-08-24 12:02 - 000116112 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2019-08-24 12:02 - 2019-08-24 12:02 - 000073584 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2019-08-24 11:45 - 2019-08-24 11:53 - 000000000 ____D C:\AdwCleaner
2019-08-24 07:55 - 2019-08-24 12:57 - 000000000 ____D C:\FRST
2019-08-24 07:45 - 2019-08-24 07:45 - 000199768 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2019-08-24 07:45 - 2019-08-24 07:45 - 000001919 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-08-24 07:45 - 2019-06-26 13:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-08-24 07:44 - 2019-08-24 07:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-08-24 07:44 - 2019-01-08 16:32 - 000153328 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-08-23 21:15 - 2019-08-23 21:15 - 000000732 ____C C:\Users\maxim\Desktop\PC Building Simulator.lnk
2019-08-23 21:15 - 2019-08-23 21:15 - 000000000 ___DC C:\Users\maxim\AppData\LocalLow\The Irregular Corp
2019-08-23 21:15 - 2019-08-23 21:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PC Building Simulator
2019-08-23 21:09 - 2019-08-23 21:09 - 000000000 ___DC C:\Users\maxim\Documents\Command and Conquer Generals Data
2019-08-23 21:08 - 2019-08-23 21:08 - 000000000 ___DC C:\Users\maxim\Documents\Command And Conquer Generals Zero Hour Data
2019-08-23 21:08 - 2019-08-23 21:08 - 000000000 ___DC C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals
2019-08-23 21:03 - 2019-08-23 21:06 - 000000000 ___DC C:\Users\maxim\AppData\LocalLow\uTorrent
2019-08-23 20:33 - 2019-08-23 20:33 - 000001810 ____C C:\Users\maxim\Desktop\Warcraft III – zástupce.lnk
2019-08-23 20:29 - 2019-08-23 20:32 - 000000000 ____D C:\Program Files (x86)\Warcraft III - The Frozen Throne
2019-08-23 20:29 - 2019-08-23 20:29 - 000002148 _____ C:\Users\Public\Desktop\Frozen Throne.lnk
2019-08-23 20:27 - 2019-08-23 20:27 - 000000000 ____D C:\Users\maxim\AppData\Roaming\Blizzard
2019-08-20 22:24 - 2019-08-20 22:24 - 000139207 ____C C:\Users\maxim\Desktop\Potvrzení objednávky - IKEA.pdf
2019-08-20 19:45 - 2019-08-20 19:45 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2019-08-20 18:12 - 2019-08-23 15:08 - 000000000 ____D C:\Users\maxim\AppData\Roaming\DS4Windows
2019-08-20 18:12 - 2013-05-19 02:02 - 000039168 _____ (Scarlet.Crush Productions) C:\WINDOWS\system32\Drivers\ScpVBus.sys
2019-08-20 18:11 - 2016-10-08 23:17 - 003168256 ____C () C:\Users\maxim\Desktop\DS4Windows.exe
2019-08-20 18:11 - 2015-12-19 00:41 - 000573952 ____C () C:\Users\maxim\Desktop\DS4Updater.exe
2019-08-20 16:42 - 2019-08-20 16:42 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2019-08-20 16:40 - 2019-08-18 03:08 - 001012640 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 001012640 _____ C:\WINDOWS\system32\vulkan-1.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000876448 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000876448 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000447576 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000352344 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2019-08-20 16:40 - 2019-08-18 03:08 - 000301472 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2019-08-20 16:40 - 2019-08-18 03:08 - 000301472 _____ C:\WINDOWS\system32\vulkaninfo.exe
2019-08-20 16:40 - 2019-08-18 03:08 - 000273312 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2019-08-20 16:40 - 2019-08-18 03:08 - 000273312 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2019-08-20 16:40 - 2019-08-18 03:07 - 011560328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2019-08-20 16:40 - 2019-08-18 03:07 - 009935776 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 017300360 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 005358016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 004696512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 002050816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001723784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443602.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001550272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001487616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443602.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001477512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001247624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 001140424 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000959688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000813256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000676552 _____ C:\WINDOWS\system32\nvofapi64.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000659144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000633224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000544648 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2019-08-20 16:40 - 2019-08-18 03:06 - 000523712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2019-08-20 16:40 - 2019-08-18 03:05 - 040441280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2019-08-20 16:40 - 2019-08-18 03:05 - 035331008 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2019-08-20 16:40 - 2019-08-18 03:05 - 014921088 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2019-08-19 05:52 - 2019-08-19 05:54 - 000163644 _____ (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) C:\WINDOWS\SysWOW64\Drivers\SECDRV.SYS
2019-08-18 20:18 - 2019-08-19 05:55 - 000000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2019-08-14 17:09 - 2019-08-14 17:09 - 000000222 ____C C:\Users\maxim\Desktop\Mafia III.url
2019-08-14 17:00 - 2019-08-07 15:13 - 001632112 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2019-08-14 17:00 - 2019-08-07 15:13 - 000790208 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2019-08-14 17:00 - 2019-08-07 14:58 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2019-08-14 17:00 - 2019-08-07 14:58 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2019-08-14 17:00 - 2019-08-07 14:55 - 008626688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-08-14 17:00 - 2019-08-07 14:53 - 003614208 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-08-14 17:00 - 2019-08-07 14:43 - 001453416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2019-08-14 17:00 - 2019-08-07 14:41 - 000662112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2019-08-14 17:00 - 2019-08-07 14:30 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2019-08-14 17:00 - 2019-08-07 14:30 - 000098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2019-08-14 17:00 - 2019-08-07 14:27 - 007990272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-08-14 17:00 - 2019-08-07 14:24 - 002882048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-08-14 17:00 - 2019-08-07 10:09 - 001328440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2019-08-14 17:00 - 2019-08-07 10:09 - 001219896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-08-14 17:00 - 2019-08-07 10:09 - 001098064 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-08-14 17:00 - 2019-08-07 10:09 - 001027384 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-08-14 17:00 - 2019-08-07 10:09 - 000192824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-08-14 17:00 - 2019-08-07 10:09 - 000134968 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-08-14 17:00 - 2019-08-07 10:09 - 000095008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wldp.dll
2019-08-14 17:00 - 2019-08-07 10:08 - 002810680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-08-14 17:00 - 2019-08-07 10:08 - 002470648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-08-14 17:00 - 2019-08-07 10:08 - 001566736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2019-08-14 17:00 - 2019-08-07 10:08 - 000710232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2019-08-14 17:00 - 2019-08-07 10:08 - 000494992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcryptprimitives.dll
2019-08-14 17:00 - 2019-08-07 10:08 - 000170296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-08-14 17:00 - 2019-08-07 10:08 - 000091568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpfve.sys
2019-08-14 17:00 - 2019-08-07 10:07 - 009084432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-08-14 17:00 - 2019-08-07 10:07 - 002719240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2019-08-14 17:00 - 2019-08-07 10:07 - 001031696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2019-08-14 17:00 - 2019-08-07 10:07 - 000786288 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2019-08-14 17:00 - 2019-08-07 09:57 - 000081256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wldp.dll
2019-08-14 17:00 - 2019-08-07 09:56 - 001993344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-08-14 17:00 - 2019-08-07 09:56 - 001427768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2019-08-14 17:00 - 2019-08-07 09:56 - 000357336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2019-08-14 17:00 - 2019-08-07 09:55 - 000603792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2019-08-14 17:00 - 2019-08-07 09:44 - 008189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2019-08-14 17:00 - 2019-08-07 09:42 - 022717952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-08-14 17:00 - 2019-08-07 09:38 - 006661632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2019-08-14 17:00 - 2019-08-07 09:38 - 004385792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-08-14 17:00 - 2019-08-07 09:36 - 007572480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-08-14 17:00 - 2019-08-07 09:36 - 000354816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2019-08-14 17:00 - 2019-08-07 09:36 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-08-14 17:00 - 2019-08-07 09:35 - 000624640 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2019-08-14 17:00 - 2019-08-07 09:35 - 000265728 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2019-08-14 17:00 - 2019-08-07 09:34 - 005769728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-08-14 17:00 - 2019-08-07 09:34 - 001549824 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-08-14 17:00 - 2019-08-07 09:34 - 000786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2019-08-14 17:00 - 2019-08-07 09:33 - 001220608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 004938240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 004516864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 002165760 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-08-14 17:00 - 2019-08-07 09:32 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 001154048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 000669184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-08-14 17:00 - 2019-08-07 09:32 - 000318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 001110016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2019-08-14 17:00 - 2019-08-07 09:31 - 000965632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000947200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000793088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-08-14 17:00 - 2019-08-07 09:31 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-08-14 17:00 - 2019-07-09 10:07 - 000506088 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2019-08-14 17:00 - 2019-07-09 09:44 - 012757504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-08-14 17:00 - 2019-07-09 09:41 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2019-08-14 17:00 - 2019-07-09 09:39 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2019-08-14 17:00 - 2019-07-09 09:37 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2019-08-14 17:00 - 2019-07-09 08:42 - 011943424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-08-14 17:00 - 2019-07-09 08:38 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2019-08-14 17:00 - 2019-07-09 05:29 - 000375312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-08-14 17:00 - 2019-07-09 05:29 - 000230200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2019-08-14 17:00 - 2019-07-09 05:29 - 000031032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys
2019-08-14 17:00 - 2019-07-09 05:20 - 000500536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2019-08-14 17:00 - 2019-07-09 05:20 - 000227640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2019-08-14 17:00 - 2019-07-09 05:19 - 002769472 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-08-14 17:00 - 2019-07-09 05:19 - 002371504 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-08-14 17:00 - 2019-07-09 05:19 - 000767232 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2019-08-14 17:00 - 2019-07-09 05:19 - 000152104 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2019-08-14 17:00 - 2019-07-09 05:12 - 002331480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-08-14 17:00 - 2019-07-09 05:12 - 000573808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2019-08-14 17:00 - 2019-07-09 05:12 - 000125504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2019-08-14 17:00 - 2019-07-09 05:11 - 002257336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-08-14 17:00 - 2019-07-09 04:55 - 002700288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2019-08-14 17:00 - 2019-07-09 04:53 - 003708416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2019-08-14 17:00 - 2019-07-09 04:52 - 002258944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2019-08-14 17:00 - 2019-07-09 04:50 - 004861440 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2019-08-14 17:00 - 2019-07-09 04:50 - 000659456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2019-08-14 17:00 - 2019-07-09 04:50 - 000414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-08-14 17:00 - 2019-07-09 04:48 - 003402240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-08-14 17:00 - 2019-07-09 04:48 - 000175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 003392000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 002738688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 002176000 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 000808448 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-08-14 17:00 - 2019-07-09 04:47 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2019-08-14 17:00 - 2019-07-09 04:46 - 002912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-08-14 17:00 - 2019-07-09 04:46 - 001561088 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-08-14 17:00 - 2019-07-09 04:46 - 000300544 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2019-08-14 17:00 - 2019-07-09 04:45 - 000773120 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2019-08-14 17:00 - 2019-07-09 04:44 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2019-08-14 16:59 - 2019-08-07 15:13 - 021389776 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-08-14 16:59 - 2019-08-07 15:13 - 001515904 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-08-14 16:59 - 2019-08-07 14:55 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2PGraph.dll
2019-08-14 16:59 - 2019-08-07 14:55 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2019-08-14 16:59 - 2019-08-07 14:54 - 004783104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2019-08-14 16:59 - 2019-08-07 14:53 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2019-08-14 16:59 - 2019-08-07 14:53 - 000202752 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2pnetsh.dll
2019-08-14 16:59 - 2019-08-07 14:52 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2019-08-14 16:59 - 2019-08-07 14:51 - 000424960 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2019-08-14 16:59 - 2019-08-07 14:41 - 001322688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-08-14 16:59 - 2019-08-07 14:40 - 020384344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-08-14 16:59 - 2019-08-07 14:26 - 000366592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2PGraph.dll
2019-08-14 16:59 - 2019-08-07 14:26 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2019-08-14 16:59 - 2019-08-07 14:25 - 004175360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2019-08-14 16:59 - 2019-08-07 14:24 - 001472000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2019-08-14 16:59 - 2019-08-07 14:24 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\p2pnetsh.dll
2019-08-14 16:59 - 2019-08-07 11:40 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2019-08-14 16:59 - 2019-08-07 10:09 - 000568104 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-08-14 16:59 - 2019-08-07 10:09 - 000194352 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-08-14 16:59 - 2019-08-07 10:08 - 007435720 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-08-14 16:59 - 2019-08-07 10:08 - 001141712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-08-14 16:59 - 2019-08-07 10:08 - 000723216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-08-14 16:59 - 2019-08-07 10:08 - 000227744 _____ (Microsoft Corporation) C:\WINDOWS\system32\xmllite.dll
2019-08-14 16:59 - 2019-08-07 10:08 - 000130840 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2019-08-14 16:59 - 2019-08-07 10:07 - 007520112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-08-14 16:59 - 2019-08-07 10:07 - 001459328 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-08-14 16:59 - 2019-08-07 10:07 - 001260992 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-08-14 16:59 - 2019-08-07 10:07 - 000984152 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-08-14 16:59 - 2019-08-07 10:07 - 000115728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdnet.dll
2019-08-14 16:59 - 2019-08-07 09:56 - 006570368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-08-14 16:59 - 2019-08-07 09:56 - 006044008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-08-14 16:59 - 2019-08-07 09:56 - 000192608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xmllite.dll
2019-08-14 16:59 - 2019-08-07 09:56 - 000101400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2019-08-14 16:59 - 2019-08-07 09:49 - 025857536 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-08-14 16:59 - 2019-08-07 09:47 - 022017536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-08-14 16:59 - 2019-08-07 09:39 - 019372544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-08-14 16:59 - 2019-08-07 09:38 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2019-08-14 16:59 - 2019-08-07 09:38 - 000113664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll
2019-08-14 16:59 - 2019-08-07 09:37 - 000386048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Diagnostics.dll
2019-08-14 16:59 - 2019-08-07 09:37 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\appsruprov.dll
2019-08-14 16:59 - 2019-08-07 09:37 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2019-08-14 16:59 - 2019-08-07 09:36 - 000462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2019-08-14 16:59 - 2019-08-07 09:36 - 000326144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2019-08-14 16:59 - 2019-08-07 09:36 - 000311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Diagnostics.dll
2019-08-14 16:59 - 2019-08-07 09:36 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2019-08-14 16:59 - 2019-08-07 09:35 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2019-08-14 16:59 - 2019-08-07 09:35 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2019-08-14 16:59 - 2019-08-07 09:35 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2019-08-14 16:59 - 2019-08-07 09:35 - 000567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2019-08-14 16:59 - 2019-08-07 09:35 - 000153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 001826816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 001680384 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 000521216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 000278528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll
2019-08-14 16:59 - 2019-08-07 09:34 - 000059392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2019-08-14 16:59 - 2019-08-07 09:33 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpsrv.dll
2019-08-14 16:59 - 2019-08-07 09:33 - 000115712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-08-14 16:59 - 2019-08-07 09:32 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2019-08-14 16:59 - 2019-08-07 09:32 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2019-08-14 16:59 - 2019-08-07 09:32 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll
2019-08-14 16:59 - 2019-08-07 09:31 - 000367616 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2019-08-14 16:59 - 2019-08-07 08:15 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2019-08-14 16:59 - 2019-07-11 08:48 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2019-08-14 16:59 - 2019-07-11 03:30 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-08-14 16:59 - 2019-07-11 03:30 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2019-08-14 16:59 - 2019-07-11 03:30 - 000313344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2019-08-14 16:59 - 2019-07-09 10:04 - 000348664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-08-14 16:59 - 2019-07-09 10:01 - 004527792 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-08-14 16:59 - 2019-07-09 10:00 - 001616824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-08-14 16:59 - 2019-07-09 09:44 - 000039936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsUpdateElevatedInstaller.exe
2019-08-14 16:59 - 2019-07-09 09:43 - 004718080 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-08-14 16:59 - 2019-07-09 09:43 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2019-08-14 16:59 - 2019-07-09 09:43 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdshext.dll
2019-08-14 16:59 - 2019-07-09 09:40 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2019-08-14 16:59 - 2019-07-09 09:39 - 001210880 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdclt.exe
2019-08-14 16:59 - 2019-07-09 09:39 - 001193472 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdengin2.dll
2019-08-14 16:59 - 2019-07-09 09:38 - 000740864 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2019-08-14 16:59 - 2019-07-09 09:37 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-08-14 16:59 - 2019-07-09 09:37 - 000517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\newdev.dll
2019-08-14 16:59 - 2019-07-09 09:37 - 000167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2019-08-14 16:59 - 2019-07-09 08:37 - 000485888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\newdev.dll
2019-08-14 16:59 - 2019-07-09 05:23 - 001213264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-08-14 16:59 - 2019-07-09 05:23 - 001035040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-08-14 16:59 - 2019-07-09 05:21 - 005625160 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-08-14 16:59 - 2019-07-09 05:21 - 000133136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2019-08-14 16:59 - 2019-07-09 05:20 - 000275512 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2019-08-14 16:59 - 2019-07-09 05:19 - 001674216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-08-14 16:59 - 2019-07-09 05:19 - 000799248 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2019-08-14 16:59 - 2019-07-09 05:19 - 000713488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2019-08-14 16:59 - 2019-07-09 05:19 - 000142352 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2019-08-14 16:59 - 2019-07-09 05:19 - 000046608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\werkernel.sys
2019-08-14 16:59 - 2019-07-09 05:12 - 001286528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-08-14 16:59 - 2019-07-09 05:11 - 000576528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2019-08-14 16:59 - 2019-07-09 05:11 - 000108560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2019-08-14 16:59 - 2019-07-09 04:56 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2019-08-14 16:59 - 2019-07-09 04:56 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2019-08-14 16:59 - 2019-07-09 04:55 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetDriverInstall.dll
2019-08-14 16:59 - 2019-07-09 04:55 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2019-08-14 16:59 - 2019-07-09 04:53 - 000288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2019-08-14 16:59 - 2019-07-09 04:52 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000608768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DuCsps.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2019-08-14 16:59 - 2019-07-09 04:51 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\UsoClient.exe
2019-08-14 16:59 - 2019-07-09 04:50 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2019-08-14 16:59 - 2019-07-09 04:50 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-08-14 16:59 - 2019-07-09 04:50 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2019-08-14 16:59 - 2019-07-09 04:50 - 000141312 _____ C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2019-08-14 16:59 - 2019-07-09 04:50 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2019-08-14 16:59 - 2019-07-09 04:50 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdcpw.dll
2019-08-14 16:59 - 2019-07-09 04:50 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2019-08-14 16:59 - 2019-07-09 04:49 - 000856576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2019-08-14 16:59 - 2019-07-09 04:49 - 000735744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2019-08-14 16:59 - 2019-07-09 04:49 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-08-14 16:59 - 2019-07-09 04:49 - 000372736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2019-08-14 16:59 - 2019-07-09 04:49 - 000348160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-08-14 16:59 - 2019-07-09 04:49 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2019-08-14 16:59 - 2019-07-09 04:49 - 000145408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2019-08-14 16:59 - 2019-07-09 04:49 - 000110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetDriverInstall.dll
2019-08-14 16:59 - 2019-07-09 04:48 - 000697344 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2019-08-14 16:59 - 2019-07-09 04:48 - 000395776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2019-08-14 16:59 - 2019-07-09 04:48 - 000335360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2019-08-14 16:59 - 2019-07-09 04:48 - 000227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2019-08-14 16:59 - 2019-07-09 04:48 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2019-08-14 16:59 - 2019-07-09 04:47 - 000928768 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-08-14 16:59 - 2019-07-09 04:46 - 000532992 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuietHours.dll
2019-08-14 16:59 - 2019-07-09 04:45 - 001400832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2019-08-14 16:59 - 2019-07-09 04:45 - 001218560 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-08-14 16:59 - 2019-07-09 04:45 - 000510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-08-14 16:59 - 2019-07-09 04:45 - 000504832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2019-08-14 16:59 - 2019-07-09 04:44 - 001058304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2019-08-14 16:59 - 2019-07-09 04:44 - 000922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2019-08-14 16:59 - 2019-07-09 04:44 - 000796672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2019-08-14 16:59 - 2019-07-09 04:44 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2019-08-14 16:59 - 2019-07-09 04:44 - 000406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2019-08-14 16:59 - 2019-07-09 04:44 - 000176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2019-08-14 16:59 - 2019-07-09 04:43 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2019-08-14 16:59 - 2019-07-09 04:43 - 001398272 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2019-08-14 16:59 - 2019-07-09 04:43 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-08-14 16:59 - 2019-07-09 04:43 - 000582144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2019-08-14 16:59 - 2019-06-20 04:21 - 000058882 _____ C:\WINDOWS\system32\srms.dat
2019-08-13 20:33 - 2019-08-20 20:01 - 000000000 ____D C:\Users\maxim\AppData\Roaming\Discord
2019-08-13 20:33 - 2019-08-13 20:33 - 000002244 ____C C:\Users\maxim\Desktop\Discord.lnk
2019-08-13 20:33 - 2019-08-13 20:33 - 000000000 ___DC C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Discord Inc
2019-08-13 20:33 - 2019-08-13 20:33 - 000000000 ____D C:\Users\maxim\AppData\Local\SquirrelTemp
2019-08-13 20:33 - 2019-08-13 20:33 - 000000000 ____D C:\Users\maxim\AppData\Local\Discord
2019-08-10 20:00 - 2019-08-10 20:00 - 000000000 ____D C:\ProgramData\Ubisoft
2019-08-10 19:51 - 2019-08-10 19:51 - 000000825 _____ C:\Users\Public\Desktop\Assassin's Creed.lnk
2019-08-10 19:51 - 2019-08-10 19:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Assassin's Creed
2019-08-09 19:05 - 2019-08-09 19:05 - 000000000 ____D C:\ProgramData\Codemasters
2019-08-09 18:36 - 2019-08-09 18:36 - 000000659 ____C C:\Users\maxim\Desktop\F1 2018.lnk
2019-08-09 18:36 - 2019-08-09 18:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\F1 2018
2019-08-09 18:26 - 2019-08-09 18:26 - 000000531 _____ C:\Users\Public\Desktop\Diablo III.lnk
2019-08-09 18:26 - 2019-08-09 18:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2019-08-08 17:33 - 2019-04-06 16:31 - 000000000 ___DC C:\Users\maxim\Desktop\!Questie
2019-08-04 08:36 - 2019-08-04 08:36 - 000000777 _____ C:\Users\Public\Desktop\WoW Classic.lnk
2019-08-04 08:36 - 2019-08-04 08:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Warcraft Classic
2019-07-31 15:45 - 2019-07-31 15:45 - 000000000 ____D C:\Users\maxim\AppData\Roaming\AudioVisualizerApp
2019-07-31 06:15 - 2019-07-31 06:15 - 000000000 ____D C:\WINDOWS\Panther
2019-07-27 09:51 - 2019-07-27 15:23 - 000000000 ___DC C:\Users\maxim\Documents\4A Games
2019-07-27 09:51 - 2019-07-27 15:18 - 000000000 ____D C:\Users\maxim\AppData\Local\4A Games
2019-07-27 09:51 - 2019-07-27 09:51 - 000000850 _____ C:\Users\Public\Desktop\Metro Last Light Redux.lnk
2019-07-27 09:51 - 2019-07-27 09:51 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Metro Last Light Redux [GOG.com]
2019-07-25 17:17 - 2019-07-18 21:13 - 001721816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6443160.dll
2019-07-25 17:17 - 2019-07-18 21:13 - 001468320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6443160.dll
2019-07-25 17:16 - 2019-08-18 03:03 - 004264024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-08-24 12:58 - 2019-04-16 09:13 - 000000000 ___DC C:\Users\maxim\AppData\Local\Battle.net
2019-08-24 12:56 - 2019-05-16 22:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-08-24 12:56 - 2018-04-12 01:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-08-24 12:09 - 2019-05-16 22:27 - 001689050 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-08-24 12:09 - 2018-04-12 17:50 - 000717712 _____ C:\WINDOWS\system32\perfh005.dat
2019-08-24 12:09 - 2018-04-12 17:50 - 000144954 _____ C:\WINDOWS\system32\perfc005.dat
2019-08-24 12:09 - 2018-04-12 01:36 - 000000000 ____D C:\WINDOWS\INF
2019-08-24 12:04 - 2018-06-05 21:26 - 000000000 ____D C:\ProgramData\NVIDIA
2019-08-24 12:02 - 2019-05-16 22:23 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-08-24 12:02 - 2019-04-16 08:48 - 000000000 _SHDC C:\Users\maxim\IntelGraphicsProfiles
2019-08-24 12:02 - 2018-04-11 23:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-08-24 07:45 - 2018-04-12 01:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-08-23 22:54 - 2019-04-16 09:30 - 000000000 ____D C:\Program Files (x86)\Steam
2019-08-23 21:06 - 2019-05-21 10:34 - 000000000 ____D C:\Users\maxim\AppData\Roaming\uTorrent
2019-08-23 21:03 - 2019-05-21 16:12 - 000000000 ____D C:\Users\maxim\AppData\Local\BitTorrentHelper
2019-08-23 20:34 - 2019-04-16 08:48 - 000000000 ___DC C:\Users\maxim\AppData\Local\VirtualStore
2019-08-23 15:28 - 2019-04-16 08:50 - 000000000 ___DC C:\Users\maxim\AppData\Local\CrashDumps
2019-08-23 15:08 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-08-23 06:42 - 2019-04-16 20:16 - 000281688 _____ C:\WINDOWS\SysWOW64\PnkBstrB.xtr
2019-08-23 06:41 - 2019-05-16 22:26 - 000000000 ____D C:\Users\maxim\AppData\Local\D3DSCache
2019-08-23 06:41 - 2019-04-16 20:11 - 000000000 ___DC C:\Users\maxim\AppData\Local\Ubisoft Game Launcher
2019-08-23 06:40 - 2019-04-16 20:11 - 000282512 _____ C:\WINDOWS\SysWOW64\PnkBstrB.ex0
2019-08-22 20:49 - 2019-04-18 08:49 - 000000000 ___DC C:\Users\maxim\Documents\The Witcher 3
2019-08-20 16:43 - 2019-04-16 06:08 - 000000000 ____D C:\temp
2019-08-20 16:43 - 2018-06-05 21:26 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2019-08-20 16:42 - 2018-06-05 21:25 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2019-08-18 03:03 - 2019-05-12 10:21 - 005002008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2019-08-17 00:03 - 2019-05-12 10:21 - 000054700 _____ C:\WINDOWS\system32\nvinfo.pb
2019-08-17 00:03 - 2018-06-05 21:26 - 000001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2019-08-16 22:01 - 2018-06-05 21:26 - 005469552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 002635248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 001767280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000653864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000451056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000150000 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000124968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2019-08-16 22:01 - 2018-06-05 21:26 - 000083440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2019-08-15 18:17 - 2018-06-05 21:26 - 008678412 _____ C:\WINDOWS\system32\nvcoproc.bin
2019-08-15 06:14 - 2019-04-16 09:55 - 000000000 ___DC C:\Users\maxim\AppData\Local\2K Games
2019-08-14 20:07 - 2019-05-16 22:18 - 000431488 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-08-14 20:07 - 2019-04-16 08:48 - 000000000 __RDC C:\Users\maxim\3D Objects
2019-08-14 20:07 - 2017-10-03 18:48 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ___SD C:\WINDOWS\system32\UNP
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\TextInput
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\Provisioning
2019-08-14 20:06 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-08-14 17:03 - 2018-04-12 01:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-08-14 17:01 - 2018-04-12 01:34 - 000055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2019-08-14 16:59 - 2019-04-16 18:00 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-08-14 16:56 - 2019-04-16 18:00 - 134272480 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-08-13 18:11 - 2019-04-16 09:12 - 000000000 ____D C:\Hry
2019-08-13 18:09 - 2019-05-20 17:08 - 000000000 ____D C:\Program Files (x86)\Twitch
2019-08-10 20:00 - 2019-07-04 17:37 - 000000000 ____D C:\Users\maxim\AppData\Roaming\Ubisoft
2019-08-09 19:05 - 2019-04-16 20:16 - 000000000 ___DC C:\Users\maxim\Documents\My Games
2019-08-07 06:14 - 2019-04-16 08:50 - 000002308 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-08-07 06:14 - 2019-04-16 08:50 - 000002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2019-08-06 22:22 - 2019-04-16 09:20 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2019-08-02 17:28 - 2019-04-16 18:00 - 000000000 ____D C:\Program Files\rempl
2019-07-31 15:21 - 2019-04-16 05:57 - 000000000 ____D C:\Program Files (x86)\Razer
2019-07-26 17:57 - 2019-04-16 19:04 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd

==================== Files in the root of some directories ================

2019-06-25 15:31 - 2019-06-25 15:31 - 000000000 _____ () C:\Users\maxim\AppData\Roaming\FC29FA0894FE.ini
2019-04-16 18:00 - 2019-07-04 19:44 - 038596337 ____C () C:\Users\maxim\AppData\Roaming\gta5_patch.bin
2019-04-16 18:00 - 2019-04-16 18:00 - 000332800 ____C () C:\Users\maxim\AppData\Roaming\patcher.dll

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-08-2019
Ran by maxim (24-08-2019 12:59:11)
Running from D:\Downloads
Windows 10 Home Version 1803 17134.950 (X64) (2019-05-16 20:23:57)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1760070117-4179939161-3013727825-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1760070117-4179939161-3013727825-503 - Limited - Disabled)
Guest (S-1-5-21-1760070117-4179939161-3013727825-501 - Limited - Disabled)
maxim (S-1-5-21-1760070117-4179939161-3013727825-1001 - Administrator - Enabled) => C:\Users\maxim
WDAGUtilityAccount (S-1-5-21-1760070117-4179939161-3013727825-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\uTorrent) (Version: 3.5.5.45311 - BitTorrent Inc.)
Agony UNRATED (HKLM-x32\...\Agony UNRATED_is1) (Version: - )
Aktualizace NVIDIA 37.0.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 37.0.0.0 - NVIDIA Corporation) Hidden
AnyDesk (HKLM-x32\...\AnyDesk) (Version: ad 5.0.5 - philandro Software GmbH)
Assassin's Creed verze 1.0.0.1 (HKLM-x32\...\{A588EEF5-A2F0-4222-B1BB-E4CF3B859905}_is1) (Version: 1.0.0.1 - )
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Battlefield™ V (HKLM-x32\...\{e26b382f-e945-4f70-9318-121b683f1d61}) (Version: 1.0.59.24655 - Electronic Arts)
Call of Duty Modern Warfare 2 full game MP - SP+updater -=AviaRa=- 1.00 (HKLM-x32\...\Call of Duty Modern Warfare 2 full game MP - SP+updater -=AviaRa=- 1.00) (Version: - )
Call of Duty Modern Warfare Remastered v.1.0 (HKLM-x32\...\Call of Duty Modern Warfare Remastered_is1) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.56 - Piriform)
Commandos Strike Force (HKLM-x32\...\{9AFFF2F6-527F-4B76-821D-839298C070F9}) (Version: 1.2 - )
CPUID HWMonitor 1.40 (HKLM\...\CPUID HWMonitor_is1) (Version: 1.40 - CPUID, Inc.)
Cuphead (HKLM-x32\...\1963513391_is1) (Version: 20170929 - GOG.com)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Discord (HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\Discord) (Version: 0.0.305 - Discord Inc.)
Dolby Atmos Windows API SDK (HKLM\...\{139C7F29-696B-4EEA-B4AF-2990C2ECF7AD}) (Version: 1.1.7.32 - Dolby Laboratories, Inc.)
Doom 2016 MULTi10 - ElAmigos version 6.66 (HKLM-x32\...\{6C967A93-A95F-4F65-A33A-EC8BC8750C2D}_is1) (Version: 6.66 - Bethesda Softworks)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
F1 2018 (HKLM-x32\...\F1 2018_is1) (Version: - )
Far Cry Primal (HKLM-x32\...\{80BD47AF-CF13-49B2-99BF-7E78FBA26124}_is1) (Version: - Ubisoft)
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 76.0.3809.100 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.34.11 - Google LLC) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Intel(R) Chipset Device Software (HKLM-x32\...\{17408817-d415-4768-a160-ae6d46d6bdb0}) (Version: 10.1.1.44 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1043 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 22.20.16.4836 - Intel Corporation) Hidden
Intel(R) Trusted Connect Service Client x86 (HKLM-x32\...\{C9552825-7BF2-4344-BA91-D3CD46F4C441}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Intel(R) Trusted Connect Services Client (HKLM-x32\...\{2b32b7d0-4f9f-47c8-adb7-807e6cb2fb75}) (Version: 1.47.715.0 - Intel Corporation) Hidden
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
LibreOffice 6.2.4.2 (HKLM\...\{B8FF8670-C6F4-4868-9DB2-C23324C0E575}) (Version: 6.2.4.2 - The Document Foundation)
Malwarebytes verze 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
Max Payne 3 Česky od Being.cz (HKLM\...\MaxPayne3cz) (Version: ERROR - Being Czech Republic)
Max Payne 3 Česky od Being.cz (HKLM-x32\...\MaxPayne3cz) (Version: ERROR - Being Czech Republic)
Metro - Last Light Redux (HKLM-x32\...\1430740172_is1) (Version: 2.0.0.2 - GOG.com)
Metro Exodus v.1.0 (HKLM-x32\...\Metro Exodus_is1) (Version: - )
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
My Friend Pedro (HKLM-x32\...\1102856701_is1) (Version: 1.01 - GOG.com)
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.15 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.19.0.107 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.19.0.107 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.27 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 436.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 436.02 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
Observer (HKLM-x32\...\1449856523_is1) (Version: 1.0 - GOG.com)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Ovládací panel NVIDIA 436.02 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 436.02 - NVIDIA Corporation) Hidden
PC Building Simulator (HKLM-x32\...\PC Building Simulator_is1) (Version: - )
PLANET.COASTER.v1.2.3.Proper.Repack verze 1.2.3 (HKLM-x32\...\{802FA473-F39B-48FB-8600-64D95D9BED93}}_is1) (Version: 1.2.3 - Ali213.net)
Razer Synapse (HKLM-x32\...\Razer Synapse) (Version: 3.4.0711.071718 - Razer Inc.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.15063.21299 - Realtek Semiconductor Corp.)
Resident Evil 7 Biohazard (HKLM-x32\...\{1ECBF8F3-7079-44CA-AD32-B2AECBCF636F}_is1) (Version: - Capcom)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.4.1 - Rockstar Games)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
The Sinking City Necronomicon Edition MULTi15 - ElAmigos verze 1.0 (HKLM-x32\...\{0506F651-A1D9-417D-BB3F-35A9254A48CE}_is1) (Version: 1.0 - Bigben Interactive)
The Witcher 3: Wild Hunt - Game of the Year Edition (HKLM-x32\...\1495134320_is1) (Version: 1.32 - GOG.com)
Thunderbolt™ Software (HKLM-x32\...\{87A31923-8F18-4943-8093-17DBEE0101B7}) (Version: 16.3.61.275 - Intel Corporation)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.51a - Ghisler Software GmbH)
Twitch (HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 8.0.0 - Twitch Interactive, Inc.)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
Update for Windows 10 for x64-based Systems (KB4480730) (HKLM\...\{2E8B8BDD-03DF-4C1C-8C99-E6A4BCBF43CE}) (Version: 2.51.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 53.0 - Ubisoft)
Valiant Hearts The Great War (HKLM-x32\...\{4C0EAD53-2DC4-48BC-A57A-A86BED789941}) (Version: 1.0.0 - Ubisoft) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1) (Version: 1.0.54.1 - Intel Corporation Inc.) Hidden
Vulkan Run Time Libraries 1.0.54.1 (HKLM\...\VulkanRT1.0.54.1-2) (Version: 1.0.54.1 - Intel Corporation Inc.)
Warcraft III - The Frozen Throne v1.26 (HKLM-x32\...\Warcraft III - The Frozen Throne v1.26 1.26) (Version: 1.26 - Blizzard)
WinRAR 5.70 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.70.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
World of Warcraft Classic (HKLM-x32\...\World of Warcraft Classic) (Version: - Blizzard Entertainment)

Packages:
=========
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_4.27.32.0_x86__k1h2ywk1493x8 [2019-04-16] (LENOVO INC.)
LenovoUtility -> C:\Program Files\WindowsApps\E0469640.LenovoUtility_3.0.52.0_x64__5grkq8ppsgwt4 [2019-04-16] (LENOVO INC)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.3.4032.0_x86__8wekyb3d8bbwe [2019-04-16] (Microsoft Studios) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.28.10351.0_x64__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation) [MS Ad]
NVIDIA Control Panel -> C:\Program Files\WindowsApps\NVIDIACorp.NVIDIAControlPanel_8.1.953.0_x64__56jybvy8sckqj [2019-05-16] (NVIDIA Corp.)
Pošta a Kalendář -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.11425.20190.0_x64__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation) [MS Ad]
Rozšíření pro video MPEG-2 -> C:\Program Files\WindowsApps\Microsoft.MPEG2VideoExtension_1.0.12831.0_x64__8wekyb3d8bbwe [2019-04-16] (Microsoft Corporation)
XLS Viewer Free -> C:\Program Files\WindowsApps\62307pauljohn.XLSViewerFree_1.1.0.1_x86__7sv5v3m8wq0b2 [2019-06-07] (pauljohn)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_898849ee44462f81\igfxDTCM.dll [2017-11-15] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2019-08-16] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-02-24] (win.rar GmbH -> Alexander Roshal)

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Desinstalar todo.lnk -> D:\Hry\CnC Generals and Zero Hour\Desinstalar.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\Off.lnk -> D:\Hry\CnC Generals and Zero Hour\RankOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\On.lnk -> D:\Hry\CnC Generals and Zero Hour\RankOn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Energy.lnk -> D:\Hry\CnC Generals and Zero Hour\ModEnergy.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Holland.lnk -> D:\Hry\CnC Generals and Zero Hour\ModHolland.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Reborn.lnk -> D:\Hry\CnC Generals and Zero Hour\ModReborn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Reloaded.lnk -> D:\Hry\CnC Generals and Zero Hour\ModReloaded.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Quitar todos.lnk -> D:\Hry\CnC Generals and Zero Hour\ModOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\Off.lnk -> D:\Hry\CnC Generals and Zero Hour\MejorZoomOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\On.lnk -> D:\Hry\CnC Generals and Zero Hour\MejorZoomOn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 1.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador1.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 2.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador2.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 3.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador3.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 4.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador4.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 5.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador5.bat (No File)

==================== Loaded Modules (Whitelisted) ==============

2019-08-23 15:53 - 2019-08-23 15:53 - 085602816 _____ () [File not signed] C:\Hry\Battle.net\Battle.net.11378\libcef.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000089600 _____ () [File not signed] C:\Hry\Battle.net\Battle.net.11378\libEGL.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 003841536 _____ () [File not signed] C:\Hry\Battle.net\Battle.net.11378\libGLESv2.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 001463808 _____ (Firelight Technologies) [File not signed] C:\Hry\Battle.net\Battle.net.11378\fmod.dll
2019-04-16 08:52 - 2018-08-12 20:29 - 001255424 _____ (Robert Simpson, et al.) [File not signed] C:\ProgramData\Lenovo\iMController\Plugins\GenericMessagingPlugin\x86\x86\SQLite.Interop.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000596992 _____ (The Chromium Authors) [File not signed] C:\Hry\Battle.net\Battle.net.11378\chrome_elf.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000047104 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\audio\qtaudio_windows.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000026112 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\imageformats\qgif.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000027136 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\imageformats\qico.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000243712 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\imageformats\qjpeg.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000223744 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\imageformats\qmng.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000020992 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\imageformats\qsvg.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000332288 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\imageformats\qtiff.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 001140224 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\platforms\qwindows.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000041984 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtQml\Models.2\modelsplugin.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtQuick.2\qtquick2plugin.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000084480 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000267776 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtQuick\Controls\qtquickcontrolsplugin.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000071680 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtQuick\Layouts\qquicklayoutsplugin.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000211456 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\qml\QtQuick\Window.2\windowplugin.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 004943360 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Core.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 005022208 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Gui.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000626176 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Multimedia.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000877056 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Network.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 002908672 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Qml.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 003078656 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Quick.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000096256 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5QuickControls2.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000681472 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5QuickTemplates2.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 000259072 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Svg.dll
2019-08-23 15:53 - 2019-08-23 15:53 - 004718080 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Widgets.dll
2019-08-23 15:53 - 2019-08-23 15:54 - 000439296 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5WinExtras.dll
2019-08-23 15:54 - 2019-08-23 15:54 - 000159232 _____ (The Qt Company Ltd.) [File not signed] C:\Hry\Battle.net\Battle.net.11378\Qt5Xml.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [470]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-09-29 15:46 - 2019-04-23 19:09 - 000000901 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 patches.rockstargames.com
127.0.0.1 prod.ros.rockstargames.com

2019-04-15 23:00 - 2019-04-15 23:00 - 000000375 _____ C:\WINDOWS\system32\drivers\etc\hosts.ics


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Razer Chroma SDK\bin;C:\Program Files\Razer Chroma SDK\bin;C:\Program Files (x86)\Razer\ChromaBroadcast\bin;C:\Program Files\Razer\ChromaBroadcast\bin;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files\Intel\Intel(R) Management Engine Components\DAL;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files\Intel\Intel(R) Management Engine Components\IPT;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\WindowsApps;;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\maxim\Desktop\world_of_warcraft_horde_symbol_background_red_16279_1920x1080.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\StartupFolder: => "fcbd.bat"
HKLM\...\StartupApproved\Run32: => "WindowsDriverScan64"
HKLM\...\StartupApproved\Run32: => "WindowsDriverScan86"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\StartupFolder: => "reg.lnk"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\StartupFolder: => "Twitch.lnk"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "GalaxyClient"
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\...\StartupApproved\Run: => "OneDriveSetup"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D0AEAB0F-52FC-49E5-AA69-AC0B8EB2222F}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{D385DC01-8703-48F5-9CC7-381D14D2BA62}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{CAE63EAF-BAE9-4C50-BDD8-EB41364DFAB7}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{C28A3D27-A7EC-4DF0-879B-F9EA43958758}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{64EC2492-8B31-4FC9-B9BC-73839CF89650}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [{0A1410DA-EF4B-4E02-9A1A-D505AA33FDC5}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [UDP Query User{FCCAB193-67E7-4C0F-ADA6-2CD3031F438E}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Block) C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe No File
FirewallRules: [TCP Query User{6F55B2C1-649E-4659-9D39-0D5E6961BAFA}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Block) C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe No File
FirewallRules: [UDP Query User{56EA5463-6E9C-45BC-A42C-855062F0B15D}C:\hry\far cry primal\bin\fcprimal.exe] => (Block) C:\hry\far cry primal\bin\fcprimal.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [TCP Query User{BCF64F7B-AFDE-4493-BF3B-2C91CEA6E9DA}C:\hry\far cry primal\bin\fcprimal.exe] => (Block) C:\hry\far cry primal\bin\fcprimal.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{61991C0F-0E8A-4E34-A29E-11E29292AD9F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe No File
FirewallRules: [{AD2ED130-4ED6-444B-A333-CA0292068758}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe No File
FirewallRules: [{5633D3F0-17FD-40AD-9E8C-C18D74C9E47E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{9275D04E-FE26-456A-8E23-93B20EFF4E88}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{27AAF2C8-D1AE-4E0C-84B3-94141EED2B83}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{2D6EDA30-C1A1-45B0-8862-513E6C3E0A0F}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{ACA9DA5C-812C-4502-A1FB-14397D96F5D0}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [{91E3A170-4E73-4CD9-8AAB-DC44479668AC}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [UDP Query User{AC4D7B21-F211-475B-926A-9A88178B68D5}C:\hry\outlast 2\binaries\win64\outlast2.exe] => (Block) C:\hry\outlast 2\binaries\win64\outlast2.exe No File
FirewallRules: [TCP Query User{592C6D3C-A55A-44F5-8698-B3C6F811F398}C:\hry\outlast 2\binaries\win64\outlast2.exe] => (Block) C:\hry\outlast 2\binaries\win64\outlast2.exe No File
FirewallRules: [UDP Query User{2A24BD4C-5071-48AE-AC32-19A68E23756C}C:\hry\battlefield 1\bf1.exe] => (Block) C:\hry\battlefield 1\bf1.exe No File
FirewallRules: [TCP Query User{C0BDA519-BE2F-459F-A3DA-947AE9ABE42C}C:\hry\battlefield 1\bf1.exe] => (Block) C:\hry\battlefield 1\bf1.exe No File
FirewallRules: [UDP Query User{5770D039-C276-46E2-942A-92CF849452C6}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe No File
FirewallRules: [TCP Query User{0604EF08-263B-4295-A290-45336A85DABA}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe No File
FirewallRules: [{3BCCE861-6841-453A-864D-DCE6220B1C06}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{E15EB3C7-0FB4-4518-BB9D-A360FFD87CB8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [UDP Query User{D6BC82D1-65FD-493E-8CED-B615219779D8}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe No File
FirewallRules: [TCP Query User{2A54499B-6726-4F6F-A03D-D94F78351417}C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\grand theft auto v\gta5.exe No File
FirewallRules: [UDP Query User{3C3278BC-C53A-412B-9EAC-0074633AF946}C:\users\maxim\utorrent.exe] => (Allow) C:\users\maxim\utorrent.exe No File
FirewallRules: [TCP Query User{0DA970E9-0CE0-44E7-BE82-9FF763C111B9}C:\users\maxim\utorrent.exe] => (Allow) C:\users\maxim\utorrent.exe No File
FirewallRules: [{A9CB756F-5137-435C-941D-4A6FC9E46A74}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{7C2CA503-8B41-42A6-80F1-48D2FBB5C326}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{D50C39C0-2644-4049-8504-98ED7164D59B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{D8063BA2-A695-4CDF-9528-B5CA028AC292}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [UDP Query User{E620B31E-9FF7-4A5B-B4A5-3F564959CE32}C:\hry\hearthstone\hearthstone.exe] => (Allow) C:\hry\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [TCP Query User{571F2852-8C5A-4600-B03B-FE0DE3698EC7}C:\hry\hearthstone\hearthstone.exe] => (Allow) C:\hry\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{5AB208EC-2327-4C5C-8993-98ADFD90A8B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe No File
FirewallRules: [{F1B94ACF-FBDE-4A92-90ED-94D138A38DF6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe No File
FirewallRules: [{2CFA598F-5FF1-4138-B690-97038E8FB821}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II\pc\mafia2.exe (Valve Corp. -> 2K Czech) [File not signed]
FirewallRules: [{E044A392-B959-40A6-AC26-A239BA19B3D7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Mafia II\pc\mafia2.exe (Valve Corp. -> 2K Czech) [File not signed]
FirewallRules: [TCP Query User{F86EEF5A-D85A-48BE-950E-78ABCDCE670D}C:\hry\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\hry\world of warcraft\_retail_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [UDP Query User{AD3724A4-1921-4BD4-A9E2-A24F49BDDAB7}C:\hry\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\hry\world of warcraft\_retail_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{828A97B9-2196-4BCD-BA41-5FBC98605B71}] => (Allow) C:\Users\maxim\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{4EA04FAB-9FAA-4726-AAF6-8ADC42450FB4}] => (Allow) C:\Users\maxim\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{FB21996A-450D-4696-82DD-A8EB884EED64}] => (Allow) D:\Hry\steamapps\common\FarCry5\bin\FarCry5.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{4F4F4732-8BCE-4560-B1C6-CE68F061F486}] => (Allow) D:\Hry\steamapps\common\FarCry5\bin\FarCry5.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft Entertainment)
FirewallRules: [{13F1BD16-D044-4C52-AF17-4D829D20D072}] => (Allow) D:\Hry\steamapps\common\FarCry5\bin\ArcadeEditor64.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{8853D8A4-AF78-4064-992C-68C3B2AE1AE9}] => (Allow) D:\Hry\steamapps\common\FarCry5\bin\ArcadeEditor64.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{01CBA212-F9C0-45A0-8E61-78B8F5410DE1}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{F2CF6163-04C3-4661-93E8-363A942122E9}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe (UBISOFT ENTERTAINMENT INC. -> Ubisoft)
FirewallRules: [{8A2A29E0-DCFE-4107-8898-F959552C07C9}] => (Allow) D:\Hry\steamapps\common\Left 4 Dead 2\left4dead2.exe () [File not signed]
FirewallRules: [{D4696747-0D57-454E-B0E0-25BDB8556902}] => (Allow) D:\Hry\steamapps\common\Left 4 Dead 2\left4dead2.exe () [File not signed]
FirewallRules: [TCP Query User{FFC7CB5A-CA45-4203-9BDD-B059D66FB41F}D:\hry\call of duty modern warfare remastered\h1_sp64_ship.exe] => (Block) D:\hry\call of duty modern warfare remastered\h1_sp64_ship.exe (Activision Publishing -> Activision)
FirewallRules: [UDP Query User{90696B61-AADC-4ADF-B7EA-8BC32A3BF4B0}D:\hry\call of duty modern warfare remastered\h1_sp64_ship.exe] => (Block) D:\hry\call of duty modern warfare remastered\h1_sp64_ship.exe (Activision Publishing -> Activision)
FirewallRules: [{64903511-17C0-48FB-B6BF-AD4D3D3CE09A}] => (Allow) D:\Hry\BF5\bfvTrial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{995092C2-310E-465F-9A38-42C54FB800E4}] => (Allow) D:\Hry\BF5\bfvTrial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{D153AA68-D89E-438B-ADD4-379BDF225CBC}] => (Allow) D:\Hry\BF5\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [{FDAF6DE5-F27C-43AF-9400-FB177DF8E3DD}] => (Allow) D:\Hry\BF5\bfv.exe (EA Digital Illusions CE AB) [File not signed]
FirewallRules: [TCP Query User{F5BFBF37-14D2-48A8-8B28-E616DC572E34}D:\hry\doom 2016\doomx64vk.exe] => (Block) D:\hry\doom 2016\doomx64vk.exe (id Software) [File not signed]
FirewallRules: [UDP Query User{DBE9D119-26BD-46E5-AC0A-C6DDAC75A633}D:\hry\doom 2016\doomx64vk.exe] => (Block) D:\hry\doom 2016\doomx64vk.exe (id Software) [File not signed]
FirewallRules: [{D7C0A1F9-C83A-4C30-B11A-82C2220F3140}] => (Allow) D:\Hry\steamapps\common\Alan Wake\AlanWake.exe (Remedy Entertainment Ltd. -> )
FirewallRules: [{7F15CCEB-9DF8-4554-9911-6818890A8F0C}] => (Allow) D:\Hry\steamapps\common\Alan Wake\AlanWake.exe (Remedy Entertainment Ltd. -> )
FirewallRules: [{30E6CAE3-2B2C-465D-B3ED-AC7169F3296F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{405B11E9-D8A0-4C62-AA34-2293BD967B57}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{F020C4E8-FD25-444F-931C-93E69F215DB2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{EACEECAB-14B4-432D-9FCC-C5C67E06D282}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{C2188CCD-3474-4921-B83D-C00CBFE0E78B}] => (Allow) D:\Hry\steamapps\common\Crash Bandicoot - N Sane Trilogy\CrashBandicootNSaneTrilogy.exe (Activision Publishing Inc -> )
FirewallRules: [{966F4EBE-AA8A-4D07-9B73-7EA467FF310D}] => (Allow) D:\Hry\steamapps\common\Crash Bandicoot - N Sane Trilogy\CrashBandicootNSaneTrilogy.exe (Activision Publishing Inc -> )
FirewallRules: [{986896B7-2D35-4723-8D77-22453843A22B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{46D80308-745A-47DE-9B92-0CCD0039FB89}] => (Allow) D:\Hry\steamapps\common\Mafia III\launcher.exe (2K Games) [File not signed]
FirewallRules: [{A5F11C94-027B-4DA4-A14C-DA3D8E3DD5BF}] => (Allow) D:\Hry\steamapps\common\Mafia III\launcher.exe (2K Games) [File not signed]
FirewallRules: [{A5036139-26ED-4437-9B11-BE055686AA7E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe No File
FirewallRules: [{9D26EE61-18D8-4705-9F85-7DF650FF0114}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe No File
FirewallRules: [{25224CA8-2539-44D3-8D7A-3A7CABA5CB63}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe No File
FirewallRules: [{F6E77267-3D5B-4EA1-92CE-A089CF990907}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe No File
FirewallRules: [{E2B15F3A-6097-4020-8C1A-3F51A3DF8796}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\farcry3.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{7F70EDD9-9B49-4EAE-AF66-1444ADD14F40}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\farcry3.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{F36D1CD7-2686-4CE8-B1DB-4E38ED328D9F}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\farcry3_d3d11.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{CDA1FCE4-C835-426D-AC99-D784A7738AD0}] => (Allow) D:\Hry\steamapps\common\Far Cry 3\bin\farcry3_d3d11.exe (Ubisoft Entertainment -> Ubisoft Entertainment)
FirewallRules: [{62C37D89-3A31-4AA0-8E8B-469C964C2BFF}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{34FB16AF-5B9D-4AC1-8F0D-3DD415F4A169}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{D0BE697C-BAA2-4286-B692-6C1070C75DE2}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{0C01CB63-5699-4462-BF37-86587B19972B}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{0F0DE96C-7181-4A5F-81DA-044CC286F75F}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )
FirewallRules: [{1DE1ABA4-0997-4371-A108-E501F1317B5B}] => (Allow) C:\Program Files (x86)\AnyDesk\AnyDesk.exe (philandro Software GmbH -> )

==================== Restore Points =========================

14-08-2019 16:56:30 Windows Update
18-08-2019 20:16:12 Installed Call of Duty(R) 2

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/23/2019 03:28:57 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: CrashBandicootNSaneTrilogy.exe, verze: 0.0.0.0, časové razítko: 0x5b50a076
Název chybujícího modulu: CrashBandicootNSaneTrilogy.exe, verze: 0.0.0.0, časové razítko: 0x5b50a076
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000118718c
ID chybujícího procesu: 0x2584
Čas spuštění chybující aplikace: 0x01d559b3ea74f5dd
Cesta k chybující aplikaci: D:\Hry\steamapps\common\Crash Bandicoot - N Sane Trilogy\CrashBandicootNSaneTrilogy.exe
Cesta k chybujícímu modulu: D:\Hry\steamapps\common\Crash Bandicoot - N Sane Trilogy\CrashBandicootNSaneTrilogy.exe
ID zprávy: fc650260-a5a6-4911-936a-284973f3220e
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/22/2019 09:50:52 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: LAPTOP-O3TRNGPI)
Description: httphttp-2147467263

Error: (08/20/2019 07:55:12 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: LAPTOP-O3TRNGPI)
Description: httphttp-2147467263

Error: (08/20/2019 06:14:04 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: LAPTOP-O3TRNGPI)
Description: httphttp-2147467263

Error: (08/19/2019 07:34:18 PM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: LAPTOP-O3TRNGPI)
Description: httphttp-2147467263

Error: (08/18/2019 08:18:37 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: cod2.exe, verze: 2.1.12.0, časové razítko: 0x2a425e19
Název chybujícího modulu: ntdll.dll, verze: 10.0.17134.799, časové razítko: 0x636bcb43
Kód výjimky: 0xc000041d
Posun chyby: 0x00038d6b
ID chybujícího procesu: 0x275c
Čas spuštění chybující aplikace: 0x01d555f15911a1b7
Cesta k chybující aplikaci: G:\Setup\rsrc\cod2.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: 05ffbbc4-d837-4428-a9d2-177b3a98e394
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/18/2019 08:18:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: cod2.exe, verze: 2.1.12.0, časové razítko: 0x2a425e19
Název chybujícího modulu: ntdll.dll, verze: 10.0.17134.799, časové razítko: 0x636bcb43
Kód výjimky: 0xc0000005
Posun chyby: 0x00038d6b
ID chybujícího procesu: 0x275c
Čas spuštění chybující aplikace: 0x01d555f15911a1b7
Cesta k chybující aplikaci: G:\Setup\rsrc\cod2.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: f6a77d37-c370-4416-8e86-f534284f109c
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (08/15/2019 08:14:17 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Discord.exe, verze: 0.0.305.0, časové razítko: 0x5c8190a4
Název chybujícího modulu: Discord.exe, verze: 0.0.305.0, časové razítko: 0x5c8190a4
Kód výjimky: 0xc0000005
Posun chyby: 0x0007da36
ID chybujícího procesu: 0x24d8
Čas spuštění chybující aplikace: 0x01d553951da2c773
Cesta k chybující aplikaci: C:\Users\maxim\AppData\Local\Discord\app-0.0.305\Discord.exe
Cesta k chybujícímu modulu: C:\Users\maxim\AppData\Local\Discord\app-0.0.305\Discord.exe
ID zprávy: fe6b73c2-1e40-4d84-8bfe-e84cee1e8a26
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (08/24/2019 12:56:42 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-O3TRNGPI)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli LAPTOP-O3TRNGPI\maxim (SID: S-1-5-21-1760070117-4179939161-3013727825-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 12:26:52 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-O3TRNGPI)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli LAPTOP-O3TRNGPI\maxim (SID: S-1-5-21-1760070117-4179939161-3013727825-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 12:21:50 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-O3TRNGPI)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli LAPTOP-O3TRNGPI\maxim (SID: S-1-5-21-1760070117-4179939161-3013727825-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 12:07:54 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 12:04:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscBrokerManager
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 12:04:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID
Windows.SecurityCenter.WscDataProtection
a APPID
Není k dispozici
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 12:03:21 PM) (Source: DCOM) (EventID: 10016) (User: LAPTOP-O3TRNGPI)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli LAPTOP-O3TRNGPI\maxim (SID: S-1-5-21-1760070117-4179939161-3013727825-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (08/24/2019 12:02:50 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
a APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
uživateli NT AUTHORITY\LOCAL SERVICE (SID: S-1-5-19) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


Windows Defender:
===================================
Date: 2019-08-04 08:33:17.968
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {2CCF575C-5974-4CC0-A0C3-D20B403DE5C9}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-07-25 17:12:50.827
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {42273B18-ACD6-4958-8F20-D0639A47E155}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-07-24 06:49:05.671
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {7DF474DE-FEBA-4250-BF1B-D13003D94914}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-07-18 06:20:02.992
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {7EA780EC-9C08-4A3D-A265-3C94B5596B4F}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-07-05 20:45:00.633
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {B1D2154D-B2E6-4A32-8836-84B7BBA6DDB9}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

==================== Memory info ===========================

BIOS: LENOVO 6TCN28WW 01/24/2018
Motherboard: LENOVO LNVNB161216
Processor: Intel(R) Core(TM) i5-7300HQ CPU @ 2.50GHz
Percentage of memory in use: 54%
Total physical RAM: 7832.14 MB
Available physical RAM: 3546.34 MB
Total Virtual: 13720.14 MB
Available Virtual: 6944.16 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:212.23 GB) (Free:66.71 GB) NTFS
Drive d: (Data) (Fixed) (Total:953.85 GB) (Free:271.97 GB) NTFS
Drive e: (LENOVO) (Fixed) (Total:25 GB) (Free:22.16 GB) NTFS

\\?\Volume{71e72131-b091-4ef6-8604-72ac5f2cc5b6}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.53 GB) NTFS
\\?\Volume{fedf1a78-544d-4a88-8b01-af00c428f589}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 238.5 GB) (Disk ID: F291D6E3)

Partition: GPT.

========================================================
Disk: 1 (Protective MBR) (Size: 953.9 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Spuštění Chromu a stránky po zapnutí PC

#7 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
Task: {70FEE62F-48D8-4F2B-916A-FCC296AFBDFB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-16] (Google Inc -> Google LLC)
Task: {79E6A66D-3C50-439D-ACDA-3E410BE9E791} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-16] (Google Inc -> Google LLC)
SearchScopes: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001 -> DefaultScope {BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} URL =
SearchScopes: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001 -> {BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} URL =
CHR StartupUrls: Default -> "hxxp://home.sweetim.com/?st=17&barid={A16EE4EC-9151-11E1-B822-D0DF9AE2CF44}","hxxp://www.google.com/","hxxp://www.istartsurf ... oogle.com/"
C:\Users\maxim\AppData\Roaming\FC29FA0894FE.ini
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Desinstalar todo.lnk -> D:\Hry\CnC Generals and Zero Hour\Desinstalar.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\Off.lnk -> D:\Hry\CnC Generals and Zero Hour\RankOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\On.lnk -> D:\Hry\CnC Generals and Zero Hour\RankOn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Energy.lnk -> D:\Hry\CnC Generals and Zero Hour\ModEnergy.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Holland.lnk -> D:\Hry\CnC Generals and Zero Hour\ModHolland.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Reborn.lnk -> D:\Hry\CnC Generals and Zero Hour\ModReborn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Instalar Reloaded.lnk -> D:\Hry\CnC Generals and Zero Hour\ModReloaded.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre sí\Quitar todos.lnk -> D:\Hry\CnC Generals and Zero Hour\ModOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\Off.lnk -> D:\Hry\CnC Generals and Zero Hour\MejorZoomOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\On.lnk -> D:\Hry\CnC Generals and Zero Hour\MejorZoomOn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 1.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador1.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 2.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador2.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 3.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador3.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 4.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador4.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 5.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador5.bat (No File)
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [470]
FirewallRules: [{D0AEAB0F-52FC-49E5-AA69-AC0B8EB2222F}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{D385DC01-8703-48F5-9CC7-381D14D2BA62}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{CAE63EAF-BAE9-4C50-BDD8-EB41364DFAB7}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{C28A3D27-A7EC-4DF0-879B-F9EA43958758}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{64EC2492-8B31-4FC9-B9BC-73839CF89650}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [{0A1410DA-EF4B-4E02-9A1A-D505AA33FDC5}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [UDP Query User{FCCAB193-67E7-4C0F-ADA6-2CD3031F438E}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Block) C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe No File
FirewallRules: [TCP Query User{6F55B2C1-649E-4659-9D39-0D5E6961BAFA}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Block) C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe No File
FirewallRules: [{61991C0F-0E8A-4E34-A29E-11E29292AD9F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe No File
FirewallRules: [{AD2ED130-4ED6-444B-A333-CA0292068758}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe No File
FirewallRules: [{5633D3F0-17FD-40AD-9E8C-C18D74C9E47E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{9275D04E-FE26-456A-8E23-93B20EFF4E88}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{27AAF2C8-D1AE-4E0C-84B3-94141EED2B83}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{2D6EDA30-C1A1-45B0-8862-513E6C3E0A0F}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{ACA9DA5C-812C-4502-A1FB-14397D96F5D0}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [{91E3A170-4E73-4CD9-8AAB-DC44479668AC}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [UDP Query User{AC4D7B21-F211-475B-926A-9A88178B68D5}C:\hry\outlast 2\binaries\win64\outlast2.exe] => (Block) C:\hry\outlast 2\binaries\win64\outlast2.exe No File
FirewallRules: [TCP Query User{592C6D3C-A55A-44F5-8698-B3C6F811F398}C:\hry\outlast 2\binaries\win64\outlast2.exe] => (Block) C:\hry\outlast 2\binaries\win64\outlast2.exe No File
FirewallRules: [UDP Query User{2A24BD4C-5071-48AE-AC32-19A68E23756C}C:\hry\battlefield 1\bf1.exe] => (Block) C:\hry\battlefield 1\bf1.exe No File
FirewallRules: [TCP Query User{C0BDA519-BE2F-459F-A3DA-947AE9ABE42C}C:\hry\battlefield 1\bf1.exe] => (Block) C:\hry\battlefield 1\bf1.exe No File
FirewallRules: [UDP Query User{5770D039-C276-46E2-942A-92CF849452C6}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe No File
FirewallRules: [TCP Query User{0604EF08-263B-4295-A290-45336A85DABA}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe No File
FirewallRules: [UDP Query User{3C3278BC-C53A-412B-9EAC-0074633AF946}C:\users\maxim\utorrent.exe] => (Allow) C:\users\maxim\utorrent.exe No File
FirewallRules: [TCP Query User{0DA970E9-0CE0-44E7-BE82-9FF763C111B9}C:\users\maxim\utorrent.exe] => (Allow) C:\users\maxim\utorrent.exe No File
FirewallRules: [{5AB208EC-2327-4C5C-8993-98ADFD90A8B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe No File
FirewallRules: [{F1B94ACF-FBDE-4A92-90ED-94D138A38DF6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe No File
FirewallRules: [{A5036139-26ED-4437-9B11-BE055686AA7E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe No File
FirewallRules: [{9D26EE61-18D8-4705-9F85-7DF650FF0114}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe No File
FirewallRules: [{25224CA8-2539-44D3-8D7A-3A7CABA5CB63}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe No File
FirewallRules: [{F6E77267-3D5B-4EA1-92CE-A089CF990907}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe No File

EmptyTemp:
Hosts:
End
Uložte do D:\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Gambac
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 47
Registrován: 29 bře 2009 10:42

Re: Spuštění Chromu a stránky po zapnutí PC

#8 Příspěvek od Gambac »

Fix result of Farbar Recovery Scan Tool (x64) Version: 22-08-2019
Ran by maxim (24-08-2019 17:48:53) Run:1
Running from D:\Downloads
Loaded Profiles: maxim (Available Profiles: maxim)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
Task: {70FEE62F-48D8-4F2B-916A-FCC296AFBDFB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-16] (Google Inc -> Google LLC)
Task: {79E6A66D-3C50-439D-ACDA-3E410BE9E791} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-16] (Google Inc -> Google LLC)
SearchScopes: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001 -> DefaultScope {BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} URL =
SearchScopes: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001 -> {BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} URL =
CHR StartupUrls: Default -> "hxxp://home.sweetim.com/?st=17&barid={A16EE4EC-9151-11E1-B822-D0DF9AE2CF44}","hxxp://www.google.com/","hxxp://www.istartsurf ... oogle.com/"
C:\Users\maxim\AppData\Roaming\FC29FA0894FE.ini
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
CustomCLSID: HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\maxim\AppData\Local\Microsoft\OneDrive\19.062.0331.0006\amd64\FileSyncShell64.dll => No File
ShellIconOverlayIdentifiers: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive7] -> {C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Desinstalar todo.lnk -> D:\Hry\CnC Generals and Zero Hour\Desinstalar.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\Off.lnk -> D:\Hry\CnC Generals and Zero Hour\RankOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\On.lnk -> D:\Hry\CnC Generals and Zero Hour\RankOn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Instalar Energy.lnk -> D:\Hry\CnC Generals and Zero Hour\ModEnergy.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Instalar Holland.lnk -> D:\Hry\CnC Generals and Zero Hour\ModHolland.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Instalar Reborn.lnk -> D:\Hry\CnC Generals and Zero Hour\ModReborn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Instalar Reloaded.lnk -> D:\Hry\CnC Generals and Zero Hour\ModReloaded.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Quitar todos.lnk -> D:\Hry\CnC Generals and Zero Hour\ModOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\Off.lnk -> D:\Hry\CnC Generals and Zero Hour\MejorZoomOff.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\On.lnk -> D:\Hry\CnC Generals and Zero Hour\MejorZoomOn.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 1.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador1.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 2.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador2.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 3.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador3.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 4.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador4.bat (No File)
Shortcut: C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 5.lnk -> D:\Hry\CnC Generals and Zero Hour\Jugador5.bat (No File)
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [470]
FirewallRules: [{D0AEAB0F-52FC-49E5-AA69-AC0B8EB2222F}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{D385DC01-8703-48F5-9CC7-381D14D2BA62}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{CAE63EAF-BAE9-4C50-BDD8-EB41364DFAB7}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{C28A3D27-A7EC-4DF0-879B-F9EA43958758}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{64EC2492-8B31-4FC9-B9BC-73839CF89650}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [{0A1410DA-EF4B-4E02-9A1A-D505AA33FDC5}] => (Allow) C:\Hry\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [UDP Query User{FCCAB193-67E7-4C0F-ADA6-2CD3031F438E}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Block) C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe No File
FirewallRules: [TCP Query User{6F55B2C1-649E-4659-9D39-0D5E6961BAFA}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe] => (Block) C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe No File
FirewallRules: [{61991C0F-0E8A-4E34-A29E-11E29292AD9F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe No File
FirewallRules: [{AD2ED130-4ED6-444B-A333-CA0292068758}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Far Cry 3\bin\FC3UpdaterSteam.exe No File
FirewallRules: [{5633D3F0-17FD-40AD-9E8C-C18D74C9E47E}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{9275D04E-FE26-456A-8E23-93B20EFF4E88}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11.exe No File
FirewallRules: [{27AAF2C8-D1AE-4E0C-84B3-94141EED2B83}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{2D6EDA30-C1A1-45B0-8862-513E6C3E0A0F}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon_d3d11_b.exe No File
FirewallRules: [{ACA9DA5C-812C-4502-A1FB-14397D96F5D0}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [{91E3A170-4E73-4CD9-8AAB-DC44479668AC}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Far Cry 3 Blood Dragon\bin\fc3_blooddragon.exe No File
FirewallRules: [UDP Query User{AC4D7B21-F211-475B-926A-9A88178B68D5}C:\hry\outlast 2\binaries\win64\outlast2.exe] => (Block) C:\hry\outlast 2\binaries\win64\outlast2.exe No File
FirewallRules: [TCP Query User{592C6D3C-A55A-44F5-8698-B3C6F811F398}C:\hry\outlast 2\binaries\win64\outlast2.exe] => (Block) C:\hry\outlast 2\binaries\win64\outlast2.exe No File
FirewallRules: [UDP Query User{2A24BD4C-5071-48AE-AC32-19A68E23756C}C:\hry\battlefield 1\bf1.exe] => (Block) C:\hry\battlefield 1\bf1.exe No File
FirewallRules: [TCP Query User{C0BDA519-BE2F-459F-A3DA-947AE9ABE42C}C:\hry\battlefield 1\bf1.exe] => (Block) C:\hry\battlefield 1\bf1.exe No File
FirewallRules: [UDP Query User{5770D039-C276-46E2-942A-92CF849452C6}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe No File
FirewallRules: [TCP Query User{0604EF08-263B-4295-A290-45336A85DABA}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe No File
FirewallRules: [UDP Query User{3C3278BC-C53A-412B-9EAC-0074633AF946}C:\users\maxim\utorrent.exe] => (Allow) C:\users\maxim\utorrent.exe No File
FirewallRules: [TCP Query User{0DA970E9-0CE0-44E7-BE82-9FF763C111B9}C:\users\maxim\utorrent.exe] => (Allow) C:\users\maxim\utorrent.exe No File
FirewallRules: [{5AB208EC-2327-4C5C-8993-98ADFD90A8B9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe No File
FirewallRules: [{F1B94ACF-FBDE-4A92-90ED-94D138A38DF6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\FarCry5\bin\ArcadeEditor64.exe No File
FirewallRules: [{A5036139-26ED-4437-9B11-BE055686AA7E}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe No File
FirewallRules: [{9D26EE61-18D8-4705-9F85-7DF650FF0114}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe No File
FirewallRules: [{25224CA8-2539-44D3-8D7A-3A7CABA5CB63}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe No File
FirewallRules: [{F6E77267-3D5B-4EA1-92CE-A089CF990907}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe No File

EmptyTemp:
Hosts:
End
*****************

Processes closed successfully.
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{70FEE62F-48D8-4F2B-916A-FCC296AFBDFB}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{70FEE62F-48D8-4F2B-916A-FCC296AFBDFB}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{79E6A66D-3C50-439D-ACDA-3E410BE9E791}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{79E6A66D-3C50-439D-ACDA-3E410BE9E791}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} => removed successfully
HKLM\Software\Classes\CLSID\{BB0E9B1E-5191-4129-8B07-EB35F9DBE4A0} => not found
"Chrome StartupUrls" => removed successfully
C:\Users\maxim\AppData\Roaming\FC29FA0894FE.ini => moved successfully
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E} => removed successfully
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C} => removed successfully
HKU\S-1-5-21-1760070117-4179939161-3013727825-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E} => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
HKLM\Software\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
HKLM\Software\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
HKLM\Software\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
HKLM\Software\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
HKLM\Software\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
HKLM\Software\Classes\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3} => not found
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
HKLM\Software\Classes\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive1 => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive2 => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282} => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive3 => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30} => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive4 => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive5 => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive6 => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{9AA2F32D-362A-42D9-9328-24A483E2CCC3} => not found
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ OneDrive7 => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{C5FF006E-2AE9-408C-B85B-2DFDD5449D9C} => not found
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => not found
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Desinstalar todo.lnk => moved successfully
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\Off.lnk => moved successfully
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Trucar rango general\On.lnk => moved successfully
"C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Instalar Energy.lnk" => not found
"C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Instalar Holland.lnk" => not found
"C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Instalar Reborn.lnk" => not found
"C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Instalar Reloaded.lnk" => not found
"C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mods incompatibles entre s�\Quitar todos.lnk" => not found
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\Off.lnk => moved successfully
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Mejorar zoom\On.lnk => moved successfully
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 1.lnk => moved successfully
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 2.lnk => moved successfully
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 3.lnk => moved successfully
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 4.lnk => moved successfully
C:\Users\maxim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\C&C Generals\Cambiar a\Jugador 5.lnk => moved successfully
C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D0AEAB0F-52FC-49E5-AA69-AC0B8EB2222F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D385DC01-8703-48F5-9CC7-381D14D2BA62}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{CAE63EAF-BAE9-4C50-BDD8-EB41364DFAB7}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C28A3D27-A7EC-4DF0-879B-F9EA43958758}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{64EC2492-8B31-4FC9-B9BC-73839CF89650}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0A1410DA-EF4B-4E02-9A1A-D505AA33FDC5}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{FCCAB193-67E7-4C0F-ADA6-2CD3031F438E}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{6F55B2C1-649E-4659-9D39-0D5E6961BAFA}C:\hry\crash bandicoot n sane trilogy\crashbandicootnsanetrilogy.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{61991C0F-0E8A-4E34-A29E-11E29292AD9F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{AD2ED130-4ED6-444B-A333-CA0292068758}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5633D3F0-17FD-40AD-9E8C-C18D74C9E47E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9275D04E-FE26-456A-8E23-93B20EFF4E88}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{27AAF2C8-D1AE-4E0C-84B3-94141EED2B83}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{2D6EDA30-C1A1-45B0-8862-513E6C3E0A0F}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ACA9DA5C-812C-4502-A1FB-14397D96F5D0}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{91E3A170-4E73-4CD9-8AAB-DC44479668AC}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{AC4D7B21-F211-475B-926A-9A88178B68D5}C:\hry\outlast 2\binaries\win64\outlast2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{592C6D3C-A55A-44F5-8698-B3C6F811F398}C:\hry\outlast 2\binaries\win64\outlast2.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{2A24BD4C-5071-48AE-AC32-19A68E23756C}C:\hry\battlefield 1\bf1.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{C0BDA519-BE2F-459F-A3DA-947AE9ABE42C}C:\hry\battlefield 1\bf1.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{5770D039-C276-46E2-942A-92CF849452C6}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0604EF08-263B-4295-A290-45336A85DABA}C:\program files (x86)\steam\steamapps\common\rock of ages 2\roa2\binaries\win64\roa2-win64-shipping.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{3C3278BC-C53A-412B-9EAC-0074633AF946}C:\users\maxim\utorrent.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0DA970E9-0CE0-44E7-BE82-9FF763C111B9}C:\users\maxim\utorrent.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5AB208EC-2327-4C5C-8993-98ADFD90A8B9}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F1B94ACF-FBDE-4A92-90ED-94D138A38DF6}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{A5036139-26ED-4437-9B11-BE055686AA7E}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{9D26EE61-18D8-4705-9F85-7DF650FF0114}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{25224CA8-2539-44D3-8D7A-3A7CABA5CB63}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F6E77267-3D5B-4EA1-92CE-A089CF990907}" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 44671695 B
Java, Flash, Steam htmlcache => 374876137 B
Windows/system/drivers => 291374 B
Edge => 10645967 B
Chrome => 407699465 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
LocalService => 0 B
NetworkService => 111108 B
NetworkService => 0 B
maxim => 4769091 B

RecycleBin => 816547 B
EmptyTemp: => 813.6 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 17:49:48 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Spuštění Chromu a stránky po zapnutí PC

#9 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Gambac
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 47
Registrován: 29 bře 2009 10:42

Re: Spuštění Chromu a stránky po zapnutí PC

#10 Příspěvek od Gambac »

Po spusteni se jiz chrome nespousti, jen ten nabeh plochy po lognuti do win je lehce zpomaleny, ale to muzou byt taky aktualizace, je to v řádu několika vteřin.

Takže - za mně vyřešeno, jak vždy děkuji a klobouček, já se zase za pár let ozvu :worship:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Spuštění Chromu a stránky po zapnutí PC

#11 Příspěvek od Rudy »

OK, nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno