Stránka 1 z 5

Malware jménem Initial Page 123

Napsal: 13 kvě 2017 11:00
od cunik.cz
Ahoj, jednou jsem takhle večer si řekl že si na Notebooku nainstaluju novou verzi Deamon Tools Lite. A hned po nainstalování když jsem spustil Google Chrome tak se mi domovská stránka z Googlu změnila na Initial Page 123. Koukal jsem na to a prý se jedná o nějaký druh Malwaru či Spywaru nebo tak něco. Vyskenoval jsem si PC AVG Internet Security a odstranilo mi to tam něco ale problém přetvrával dále. Dnes jsem si PC vyskenoval ADW Cleanerem a odstranilo mi to asi 10 hrozeb. Taky jsem Chrome odinstaloval a ještě jsem ho nenainstaloval ale také stejné příznaky byli na mém stolním PC kde jsem nic takovýho neinstaloval. Log z RSIT vložím pod tímto postem.

Re: Malware jménem Initial Page 123

Napsal: 13 kvě 2017 11:05
od cunik.cz
Logfile of random's system information tool 1.10 (written by random/random)
Run by Tomáš Kouba at 2017-05-13 12:01:42
Microsoft Windows 10 Home
System drive C: has 328 GB (69%) free of 476 GB
Total RAM: 4017 MB (38% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:01:56, on 13.05.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\SpotifyWebHelper.exe
C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
C:\Users\Tomáš Kouba\Downloads\esetonlinescanner_csy.exe
C:\Program Files\trend micro\Tomáš Kouba.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
O4 - HKLM\..\Run: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=av
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Tomáš Kouba\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [download.ninja] C:\Program Files\Ninja Download Manager\download.ninja.exe
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Spotify] "C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Mozilla Thunderbird.lnk = C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AvgAMPS - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgamps.exe
O23 - Service: AVG Firewall (avgfws) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgfwsa.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
O23 - Service: AVG Service (avgsvc) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
O23 - Service: @oem13.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\Windows\system32\BtwRSupportService.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: EaseUS Agent Service (EaseUS Agent) - CHENGDU YIWO Tech Development Co., Ltd - C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @oem12.inf,%ServiceDisplayName%;ESIF Upper Framework Service (esifsvc) - Intel Corporation - C:\Windows\SysWoW64\esif_uf.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Futuremark SystemInfo Service - Futuremark - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - CyberLink - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 12 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 12046 bytes

======Listing Processes======




c:\PROGRA~2\AVG\Av\avgrsa.exe /boot
C:\Program Files (x86)\AVG\Av\avgcsrva.exe /pipeName=44800c66-0200-0000-5018-36168920d348 /binaryPath="C:\Program Files (x86)\AVG\Av\\" /logPath=C:\Windows\system32\config\systemprofile\AppData\Local\Avg\log\av16 /logCfgPath=C:\ProgramData\Avg\log\av16




C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-c385e843-4d59-4fa3-9971-f5770fee28b7 -SystemEventPortName:HostProcess-ec073693-c3c9-4abc-b047-d067baca00a2 -IoCancelEventPortName:HostProcess-a6ebeea0-cf50-4cd3-8f78-5e4acb89b950 -NonStateChangingEventPortName:HostProcess-57967389-c282-4d49-ab82-ec8bd3cb4820 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:a8f7a04e-ae88-40da-8837-914b1a587cc8 -DeviceGroupId:
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\WLANExt.exe 2626191473648
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
"C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe"
"C:\Program Files (x86)\AVG\Av\avgfwsa.exe"

"C:\Program Files (x86)\AVG\Av\avgwdsvca.exe"
C:\Windows\SysWoW64\esif_uf.exe
"C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe"
C:\Windows\system32\BtwRSupportService.exe
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
dashost.exe {719e6908-c158-4cd7-906ecb7a61839769}
C:\Windows\system32\svchost.exe -k appmodel
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"

"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Windows\TEMP\DPTF\esif_assist_64.exe"
sihost.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\System32\vds.exe
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe"
igfxEM.exe
igfxHK.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files (x86)\AVG\Av\avgnsa.exe"
"C:\Program Files (x86)\AVG\Av\avgemca.exe"
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe" /AUTORUN
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer12_Logfile.log
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
"C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe"
/fmw.trayonly
/TRAYONLY
"C:\Windows\system32\taskmgr.exe" /4
C:\Windows\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe" -Embedding
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"fontdrvhost.exe"
ctfmon.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe" -ServerName:MicrosoftEdge.AppXdnhjhccw3zf0j06tkg3jtqr00qdm0khc.mca
C:\Windows\system32\browser_broker.exe -Embedding
"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe" SCODEF:2580 CREDAT:140545 /prefetch:2
C:\Windows\System32\smartscreen.exe -Embedding
C:\Windows\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\Users\Tomáš Kouba\Downloads\esetonlinescanner_csy.exe" EULA
taskhostw.exe
"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe" SCODEF:2580 CREDAT:271680 /prefetch:2
"C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\microsoftedgecp.exe" SCODEF:2580 CREDAT:271681 /prefetch:2
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe_S-1-5-21-725424127-4130822466-1493971447-100112_ Global\UsGthrCtrlFltPipeMssGthrPipe_S-1-5-21-725424127-4130822466-1493971447-100112 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" "1"
"C:\Windows\system32\SearchFilterHost.exe" 0 608 612 620 8192 616
C:\Windows\system32\AUDIODG.EXE 0x420
"C:\Users\Tomáš Kouba\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-02-26 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-02-26 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-05-11 149704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-02-26 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-13 2075440]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-02-26 141496]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-02-26 171704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-02-26 141496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-10-15 8911872]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Tomáš Kouba\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-03-05 1518304]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-12-20 27262432]
"GoogleDriveSync"=C:\Program Files (x86)\Google\Drive\googledrivesync.exe [2017-03-21 23819304]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2017-04-26 3019552]
"download.ninja"=C:\Program Files\Ninja Download Manager\download.ninja.exe []
"Spotify Web Helper"=C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2017-05-07 1446000]
"Spotify"=C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\Spotify.exe [2017-05-07 7064176]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2017-02-07 4701888]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"AvgUi"=C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [2016-12-06 240400]
"AVG_UI"=C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [2016-12-06 240400]
"Acrobat Assistant 8.0"=C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [2017-04-05 1870928]
""= []

C:\Users\Tomáš Kouba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Mozilla Thunderbird.lnk - C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{E9AC8DEE-308A-11E7-865E-64006A5CFC23}"=C:\Users\Tomáš Kouba\AppData\Roaming\Ghegiward\Shemuing.dll []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.pDAD"=prodad-codec.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-05-11 20:41:50 ----D---- C:\Program Files\Common Files\DESIGNER
2017-05-11 20:06:44 ----D---- C:\Program Files\MK
2017-05-11 20:06:35 ----D---- C:\Reerdition
2017-05-08 21:23:14 ----D---- C:\Users\Tomáš Kouba\AppData\Roaming\Ghegiward
2017-05-08 21:23:14 ----D---- C:\Program Files (x86)\Tuationfoty Launcher
2017-05-08 21:23:01 ----D---- C:\Users\Tomáš Kouba\AppData\Roaming\Profiles
2017-05-08 21:23:00 ----D---- C:\Program Files (x86)\Reicoge
2017-05-08 21:22:37 ----D---- C:\Program Files\DAEMON Tools Lite
2017-05-08 12:43:49 ----D---- C:\AdwCleaner
2017-05-08 10:10:11 ----A---- C:\Windows\GPU-Z.INI
2017-05-08 09:59:00 ----D---- C:\ProgramData\Futuremark
2017-05-08 09:59:00 ----D---- C:\Program Files\Futuremark
2017-05-08 09:58:23 ----D---- C:\Program Files (x86)\Futuremark
2017-05-08 07:31:30 ----D---- C:\Program Files (x86)\Welcome to the Game
2017-05-07 20:37:38 ----D---- C:\GOG Games
2017-05-07 18:21:30 ----D---- C:\Users\Tomáš Kouba\AppData\Roaming\Spotify
2017-05-07 16:11:39 ----D---- C:\Program Files\trend micro
2017-05-07 16:11:38 ----D---- C:\rsit
2017-04-23 11:56:03 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-04-23 11:56:01 ----A---- C:\Windows\SYSWOW64\shell32.dll
2017-04-23 11:56:00 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2017-04-23 11:55:59 ----A---- C:\Windows\SYSWOW64\mos.dll
2017-04-23 11:55:58 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2017-04-23 11:55:58 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2017-04-23 11:55:57 ----A---- C:\Windows\SYSWOW64\win32kfull.sys
2017-04-23 11:55:56 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2017-04-23 11:55:55 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2017-04-23 11:55:55 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2017-04-23 11:55:55 ----A---- C:\Windows\SYSWOW64\mfasfsrcsnk.dll
2017-04-23 11:55:55 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-04-23 11:55:54 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-04-23 11:55:54 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2017-04-23 11:55:54 ----A---- C:\Windows\SYSWOW64\mfnetcore.dll
2017-04-23 11:55:53 ----A---- C:\Windows\SYSWOW64\WindowsCodecs.dll
2017-04-23 11:55:53 ----A---- C:\Windows\SYSWOW64\TSWorkspace.dll
2017-04-23 11:55:53 ----A---- C:\Windows\SYSWOW64\ole32.dll
2017-04-23 11:55:53 ----A---- C:\Windows\SYSWOW64\MCRecvSrc.dll
2017-04-23 11:55:53 ----A---- C:\Windows\SYSWOW64\gdi32full.dll
2017-04-23 11:55:52 ----A---- C:\Windows\SYSWOW64\Windows.Networking.Connectivity.dll
2017-04-23 11:55:52 ----A---- C:\Windows\SYSWOW64\quartz.dll
2017-04-23 11:55:52 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2017-04-23 11:55:52 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-04-23 11:55:51 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-04-23 11:55:51 ----A---- C:\Windows\SYSWOW64\LicenseManager.dll
2017-04-23 11:55:51 ----A---- C:\Windows\SYSWOW64\fontdrvhost.exe
2017-04-23 11:55:51 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2017-04-23 11:55:51 ----A---- C:\Windows\SYSWOW64\apprepsync.dll
2017-04-23 11:55:50 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-04-23 11:55:50 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-04-23 11:55:50 ----A---- C:\Windows\SYSWOW64\mbsmsapi.dll
2017-04-23 11:55:50 ----A---- C:\Windows\SYSWOW64\cdp.dll
2017-04-23 11:55:49 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.dll
2017-04-23 11:55:49 ----A---- C:\Windows\SYSWOW64\Windows.Media.Speech.dll
2017-04-23 11:55:49 ----A---- C:\Windows\SYSWOW64\msxml6.dll
2017-04-23 11:55:48 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Picker.dll
2017-04-23 11:55:48 ----A---- C:\Windows\SYSWOW64\Windows.AccountsControl.dll
2017-04-23 11:55:47 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2017-04-23 11:55:47 ----A---- C:\Windows\SYSWOW64\UserDataTimeUtil.dll
2017-04-23 11:55:47 ----A---- C:\Windows\SYSWOW64\updatepolicy.dll
2017-04-23 11:55:47 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2017-04-23 11:55:46 ----A---- C:\Windows\SYSWOW64\Windows.Web.dll
2017-04-23 11:55:46 ----A---- C:\Windows\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-04-23 11:55:46 ----A---- C:\Windows\SYSWOW64\Windows.Devices.PointOfService.dll
2017-04-23 11:55:46 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Perception.dll
2017-04-23 11:55:46 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2017-04-23 11:55:45 ----A---- C:\Windows\SYSWOW64\Windows.UI.Input.Inking.dll
2017-04-23 11:55:45 ----A---- C:\Windows\SYSWOW64\Windows.Networking.dll
2017-04-23 11:55:45 ----A---- C:\Windows\SYSWOW64\Windows.Media.Editing.dll
2017-04-23 11:55:45 ----A---- C:\Windows\SYSWOW64\twinapi.appcore.dll
2017-04-23 11:55:45 ----A---- C:\Windows\SYSWOW64\StoreAgent.dll
2017-04-23 11:55:45 ----A---- C:\Windows\SYSWOW64\aadtb.dll
2017-04-23 11:55:44 ----A---- C:\Windows\SYSWOW64\WinTypes.dll
2017-04-23 11:55:44 ----A---- C:\Windows\SYSWOW64\MiracastReceiver.dll
2017-04-23 11:55:44 ----A---- C:\Windows\SYSWOW64\mfnetsrc.dll
2017-04-23 11:55:44 ----A---- C:\Windows\SYSWOW64\CompPkgSup.dll
2017-04-23 11:55:44 ----A---- C:\Windows\SYSWOW64\CloudExperienceHostCommon.dll
2017-04-23 11:55:43 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Usb.dll
2017-04-23 11:55:43 ----A---- C:\Windows\SYSWOW64\twinui.appcore.dll
2017-04-23 11:55:43 ----A---- C:\Windows\SYSWOW64\InputService.dll
2017-04-23 11:55:43 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2017-04-23 11:55:42 ----A---- C:\Windows\SYSWOW64\Windows.Media.MediaControl.dll
2017-04-23 11:55:42 ----A---- C:\Windows\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-04-23 11:55:42 ----A---- C:\Windows\SYSWOW64\wer.dll
2017-04-23 11:55:42 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2017-04-23 11:55:42 ----A---- C:\Windows\SYSWOW64\CloudExperienceHostUser.dll
2017-04-23 11:55:41 ----A---- C:\Windows\SYSWOW64\wscapi.dll
2017-04-23 11:55:41 ----A---- C:\Windows\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-04-23 11:55:41 ----A---- C:\Windows\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-04-23 11:55:41 ----A---- C:\Windows\SYSWOW64\Windows.Media.Audio.dll
2017-04-23 11:55:41 ----A---- C:\Windows\SYSWOW64\ShareHost.dll
2017-04-23 11:55:41 ----A---- C:\Windows\SYSWOW64\CoreUIComponents.dll
2017-04-23 11:55:40 ----A---- C:\Windows\SYSWOW64\Windows.Devices.SmartCards.dll
2017-04-23 11:55:40 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-04-23 11:55:40 ----A---- C:\Windows\SYSWOW64\MbaeApiPublic.dll
2017-04-23 11:55:40 ----A---- C:\Windows\SYSWOW64\efswrt.dll
2017-04-23 11:55:39 ----A---- C:\Windows\SYSWOW64\Windows.System.SystemManagement.dll
2017-04-23 11:55:39 ----A---- C:\Windows\SYSWOW64\Windows.Media.Import.dll
2017-04-23 11:55:39 ----A---- C:\Windows\SYSWOW64\Windows.Devices.LowLevel.dll
2017-04-23 11:55:39 ----A---- C:\Windows\SYSWOW64\CertEnroll.dll
2017-04-23 11:55:39 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2017-04-23 11:55:38 ----A---- C:\Windows\SYSWOW64\Windows.Web.Http.dll
2017-04-23 11:55:38 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-04-23 11:55:38 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-04-23 11:55:38 ----A---- C:\Windows\SYSWOW64\Windows.Graphics.Printing.dll
2017-04-23 11:55:38 ----A---- C:\Windows\SYSWOW64\Windows.Gaming.Input.dll
2017-04-23 11:55:38 ----A---- C:\Windows\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-04-23 11:55:37 ----A---- C:\Windows\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-04-23 11:55:37 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Sensors.dll
2017-04-23 11:55:37 ----A---- C:\Windows\SYSWOW64\PlayToManager.dll
2017-04-23 11:55:37 ----A---- C:\Windows\SYSWOW64\dlnashext.dll
2017-04-23 11:55:37 ----A---- C:\Windows\SYSWOW64\AppContracts.dll
2017-04-23 11:55:36 ----A---- C:\Windows\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-04-23 11:55:36 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Midi.dll
2017-04-23 11:55:36 ----A---- C:\Windows\SYSWOW64\TokenBroker.dll
2017-04-23 11:55:36 ----A---- C:\Windows\SYSWOW64\SyncSettings.dll
2017-04-23 11:55:36 ----A---- C:\Windows\SYSWOW64\PlayToDevice.dll
2017-04-23 11:55:36 ----A---- C:\Windows\SYSWOW64\dialclient.dll
2017-04-23 11:55:36 ----A---- C:\Windows\SYSWOW64\CryptoWinRT.dll
2017-04-23 11:55:35 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2017-04-23 11:55:35 ----A---- C:\Windows\SYSWOW64\Windows.Perception.Stub.dll
2017-04-23 11:55:35 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-04-23 11:55:35 ----A---- C:\Windows\SYSWOW64\UserDataAccountApis.dll
2017-04-23 11:55:35 ----A---- C:\Windows\SYSWOW64\RTMediaFrame.dll
2017-04-23 11:55:35 ----A---- C:\Windows\SYSWOW64\msdtcprx.dll
2017-04-23 11:55:34 ----A---- C:\Windows\SYSWOW64\wlidcli.dll
2017-04-23 11:55:34 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.InkControls.dll
2017-04-23 11:55:34 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Bluetooth.dll
2017-04-23 11:55:34 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Radios.dll
2017-04-23 11:55:34 ----A---- C:\Windows\SYSWOW64\SettingSyncCore.dll
2017-04-23 11:55:34 ----A---- C:\Windows\SYSWOW64\bcastdvr.exe
2017-04-23 11:55:34 ----A---- C:\Windows\SYSWOW64\apprepapi.dll
2017-04-23 11:55:34 ----A---- C:\Windows\system32\drivers\BasicRender.sys
2017-04-23 11:55:33 ----A---- C:\Windows\SYSWOW64\Windows.UI.dll
2017-04-23 11:55:33 ----A---- C:\Windows\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-04-23 11:55:33 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Scanners.dll
2017-04-23 11:55:33 ----A---- C:\Windows\SYSWOW64\UserDeviceRegistration.dll
2017-04-23 11:55:33 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2017-04-23 11:55:33 ----A---- C:\Windows\SYSWOW64\DisplayManager.dll
2017-04-23 11:55:32 ----A---- C:\Windows\SYSWOW64\WinRtTracing.dll
2017-04-23 11:55:32 ----A---- C:\Windows\SYSWOW64\Windows.System.UserDeviceAssociation.dll
2017-04-23 11:55:32 ----A---- C:\Windows\SYSWOW64\Windows.Devices.WiFi.dll
2017-04-23 11:55:32 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.dll
2017-04-23 11:55:32 ----A---- C:\Windows\SYSWOW64\RADCUI.dll
2017-04-23 11:55:32 ----A---- C:\Windows\SYSWOW64\PlayToReceiver.dll
2017-04-23 11:55:30 ----A---- C:\Windows\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-04-23 11:55:30 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Management.dll
2017-04-23 11:55:30 ----A---- C:\Windows\SYSWOW64\netshell.dll
2017-04-23 11:55:30 ----A---- C:\Windows\SYSWOW64\AboveLockAppHost.dll
2017-04-23 11:55:29 ----A---- C:\Windows\SYSWOW64\wpnapps.dll
2017-04-23 11:55:27 ----A---- C:\Windows\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-04-23 11:55:27 ----A---- C:\Windows\SYSWOW64\Windows.Globalization.dll
2017-04-23 11:55:27 ----A---- C:\Windows\SYSWOW64\ErrorDetails.dll
2017-04-23 11:55:26 ----A---- C:\Windows\SYSWOW64\Windows.Media.Ocr.dll
2017-04-23 11:55:26 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-04-23 11:55:26 ----A---- C:\Windows\SYSWOW64\UserMgrProxy.dll
2017-04-23 11:55:26 ----A---- C:\Windows\SYSWOW64\mfmjpegdec.dll
2017-04-23 11:55:26 ----A---- C:\Windows\SYSWOW64\CredProvDataModel.dll
2017-04-23 11:55:26 ----A---- C:\Windows\SYSWOW64\AppointmentActivation.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\WwaApi.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryClient.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\vaultcli.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\StructuredQuery.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\Geolocation.dll
2017-04-23 11:55:25 ----A---- C:\Windows\SYSWOW64\deviceaccess.dll
2017-04-23 11:55:24 ----A---- C:\Windows\SYSWOW64\ipsecsnp.dll
2017-04-23 11:55:24 ----A---- C:\Windows\SYSWOW64\apds.dll
2017-04-23 11:55:23 ----A---- C:\Windows\SYSWOW64\Windows.Media.Devices.dll
2017-04-23 11:55:23 ----A---- C:\Windows\SYSWOW64\Windows.Devices.Lights.dll
2017-04-23 11:55:23 ----A---- C:\Windows\SYSWOW64\Windows.ApplicationModel.Core.dll
2017-04-23 11:55:23 ----A---- C:\Windows\SYSWOW64\mspaint.exe
2017-04-23 11:55:23 ----A---- C:\Windows\SYSWOW64\ipsmsnap.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\XblAuthTokenBrokerExt.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\XblAuthManagerProxy.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\TokenBrokerUI.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\sbe.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\enrollmentapi.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\dmenrollengine.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\AzureSettingSyncProvider.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\AuthBroker.dll
2017-04-23 11:55:22 ----A---- C:\Windows\SYSWOW64\actxprxy.dll
2017-04-23 11:55:22 ----A---- C:\Windows\system32\drivers\BasicDisplay.sys
2017-04-23 11:55:21 ----A---- C:\Windows\SYSWOW64\Windows.Web.Diagnostics.dll
2017-04-23 11:55:21 ----A---- C:\Windows\SYSWOW64\Windows.Networking.HostName.dll
2017-04-23 11:55:21 ----A---- C:\Windows\SYSWOW64\usoapi.dll
2017-04-23 11:55:21 ----A---- C:\Windows\SYSWOW64\InstallAgent.exe
2017-04-23 11:55:21 ----A---- C:\Windows\SYSWOW64\ExSMime.dll
2017-04-23 11:55:21 ----A---- C:\Windows\SYSWOW64\AppXDeploymentClient.dll
2017-04-23 11:55:20 ----A---- C:\Windows\SYSWOW64\odbcconf.dll
2017-04-23 11:55:20 ----A---- C:\Windows\SYSWOW64\NaturalLanguage6.dll
2017-04-23 11:55:20 ----A---- C:\Windows\SYSWOW64\InstallAgentUserBroker.exe
2017-04-23 11:55:20 ----A---- C:\Windows\SYSWOW64\D3DCompiler_47.dll
2017-04-23 11:55:20 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2017-04-23 11:55:18 ----A---- C:\Windows\SYSWOW64\atmlib.dll
2017-04-23 11:55:17 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2017-04-23 11:55:15 ----A---- C:\Windows\system32\Windows.UI.Input.Inking.dll
2017-04-23 11:55:14 ----A---- C:\Windows\system32\xpsrchvw.exe
2017-04-23 11:55:14 ----A---- C:\Windows\system32\Windows.Devices.Perception.dll
2017-04-23 11:55:13 ----A---- C:\Windows\SYSWOW64\xpsrchvw.exe
2017-04-23 11:55:13 ----A---- C:\Windows\SYSWOW64\WebcamUi.dll
2017-04-23 11:55:13 ----A---- C:\Windows\system32\wuuhext.dll
2017-04-23 11:55:13 ----A---- C:\Windows\system32\Windows.UI.Xaml.Phone.dll
2017-04-23 11:55:13 ----A---- C:\Windows\system32\Windows.UI.Xaml.Maps.dll
2017-04-23 11:55:13 ----A---- C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll
2017-04-23 11:55:12 ----A---- C:\Windows\system32\Windows.UI.Xaml.InkControls.dll
2017-04-23 11:55:12 ----A---- C:\Windows\system32\Windows.UI.dll
2017-04-23 11:55:12 ----A---- C:\Windows\system32\Windows.ApplicationModel.Wallet.dll
2017-04-23 11:55:12 ----A---- C:\Windows\system32\Windows.ApplicationModel.dll
2017-04-23 11:55:12 ----A---- C:\Windows\system32\mssprxy.dll
2017-04-23 11:55:11 ----A---- C:\Windows\system32\WwaApi.dll
2017-04-23 11:55:11 ----A---- C:\Windows\system32\WinRtTracing.dll
2017-04-23 11:55:11 ----A---- C:\Windows\system32\Windows.Media.Ocr.dll
2017-04-23 11:55:11 ----A---- C:\Windows\system32\WebcamUi.dll
2017-04-23 11:55:10 ----A---- C:\Windows\system32\Windows.UI.Cred.dll
2017-04-23 11:55:10 ----A---- C:\Windows\system32\Windows.ApplicationModel.Core.dll
2017-04-23 11:55:09 ----A---- C:\Windows\system32\Windows.Web.Diagnostics.dll
2017-04-23 11:55:07 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2017-04-23 11:55:06 ----A---- C:\Windows\system32\shell32.dll
2017-04-23 11:55:04 ----A---- C:\Windows\system32\windows.storage.dll
2017-04-23 11:55:02 ----A---- C:\Windows\system32\Windows.Media.dll
2017-04-23 11:55:00 ----A---- C:\Windows\system32\mos.dll
2017-04-23 11:54:57 ----A---- C:\Windows\system32\MFMediaEngine.dll
2017-04-23 11:54:56 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2017-04-23 11:54:55 ----A---- C:\Windows\system32\mfsrcsnk.dll
2017-04-23 11:54:55 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-04-23 11:54:55 ----A---- C:\Windows\system32\diagtrack.dll
2017-04-23 11:54:54 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2017-04-23 11:54:54 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2017-04-23 11:54:52 ----A---- C:\Windows\system32\rdpcorets.dll
2017-04-23 11:54:52 ----A---- C:\Windows\system32\mfnetcore.dll
2017-04-23 11:54:52 ----A---- C:\Windows\system32\KernelBase.dll
2017-04-23 11:54:50 ----A---- C:\Windows\system32\mstscax.dll
2017-04-23 11:54:49 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-04-23 11:54:49 ----A---- C:\Windows\system32\usocore.dll
2017-04-23 11:54:49 ----A---- C:\Windows\system32\puiobj.dll
2017-04-23 11:54:48 ----A---- C:\Windows\system32\updatehandlers.dll
2017-04-23 11:54:48 ----A---- C:\Windows\system32\TSWorkspace.dll
2017-04-23 11:54:48 ----A---- C:\Windows\system32\oleaut32.dll
2017-04-23 11:54:48 ----A---- C:\Windows\system32\NetworkBindingEngineMigPlugin.dll
2017-04-23 11:54:48 ----A---- C:\Windows\system32\LsaIso.exe
2017-04-23 11:54:47 ----A---- C:\Windows\system32\smartscreen.exe
2017-04-23 11:54:47 ----A---- C:\Windows\system32\MusNotification.exe
2017-04-23 11:54:47 ----A---- C:\Windows\system32\drivers\ndis.sys
2017-04-23 11:54:46 ----A---- C:\Windows\system32\wmpps.dll
2017-04-23 11:54:46 ----A---- C:\Windows\system32\Windows.ApplicationModel.Store.dll
2017-04-23 11:54:46 ----A---- C:\Windows\system32\StoreAgent.dll
2017-04-23 11:54:46 ----A---- C:\Windows\system32\MusNotificationUx.exe
2017-04-23 11:54:45 ----A---- C:\Windows\system32\Windows.Media.Streaming.dll
2017-04-23 11:54:45 ----A---- C:\Windows\system32\EmailApis.dll
2017-04-23 11:54:44 ----A---- C:\Windows\system32\Windows.Media.Editing.dll
2017-04-23 11:54:44 ----A---- C:\Windows\system32\MSVP9DEC.dll
2017-04-23 11:54:41 ----A---- C:\Windows\system32\Windows.Devices.Sensors.dll
2017-04-23 11:54:41 ----A---- C:\Windows\system32\UserDataTimeUtil.dll
2017-04-23 11:54:41 ----A---- C:\Windows\system32\musdialoghandlers.dll
2017-04-23 11:54:41 ----A---- C:\Windows\system32\mfcore.dll
2017-04-23 11:54:40 ----A---- C:\Windows\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2017-04-23 11:54:40 ----A---- C:\Windows\system32\SystemSettingsAdminFlows.exe
2017-04-23 11:54:31 ----A---- C:\Windows\system32\LicenseManager.dll
2017-04-23 11:54:22 ----A---- C:\Windows\system32\wscapi.dll
2017-04-23 11:54:11 ----A---- C:\Windows\system32\Windows.Graphics.Printing.dll
2017-04-23 11:54:03 ----A---- C:\Windows\system32\rdpudd.dll
2017-04-23 11:54:02 ----A---- C:\Windows\system32\RTMediaFrame.dll
2017-04-23 11:54:02 ----A---- C:\Windows\system32\mbsmsapi.dll
2017-04-23 11:54:01 ----A---- C:\Windows\system32\efswrt.dll
2017-04-23 11:53:59 ----A---- C:\Windows\system32\Windows.Media.Audio.dll
2017-04-23 11:53:59 ----A---- C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-04-23 11:53:59 ----A---- C:\Windows\system32\MbaeApiPublic.dll
2017-04-23 11:53:59 ----A---- C:\Windows\system32\AccountsRt.dll
2017-04-23 11:53:58 ----A---- C:\Windows\system32\wpnapps.dll
2017-04-23 11:53:58 ----A---- C:\Windows\system32\Windows.Devices.Scanners.dll
2017-04-23 11:53:42 ----A---- C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-04-23 11:53:42 ----A---- C:\Windows\system32\Windows.Perception.Stub.dll
2017-04-23 11:53:42 ----A---- C:\Windows\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-23 11:53:42 ----A---- C:\Windows\system32\SensorsApi.dll
2017-04-23 11:53:42 ----A---- C:\Windows\system32\RDXTaskFactory.dll
2017-04-23 11:53:42 ----A---- C:\Windows\system32\rdpencom.dll
2017-04-23 11:53:42 ----A---- C:\Windows\system32\AboveLockAppHost.dll
2017-04-23 11:53:41 ----A---- C:\Windows\system32\localspl.dll
2017-04-23 11:53:40 ----A---- C:\Windows\system32\wpninprc.dll
2017-04-23 11:53:40 ----A---- C:\Windows\system32\RdpRelayTransport.dll
2017-04-23 11:53:40 ----A---- C:\Windows\system32\AzureSettingSyncProvider.dll
2017-04-23 11:53:39 ----A---- C:\Windows\system32\InstallAgentUserBroker.exe
2017-04-23 11:53:39 ----A---- C:\Windows\system32\InstallAgent.exe
2017-04-23 11:53:35 ----A---- C:\Windows\system32\mshtml.dll
2017-04-23 11:53:31 ----A---- C:\Windows\system32\edgehtml.dll
2017-04-23 11:53:28 ----A---- C:\Windows\system32\ieframe.dll
2017-04-23 11:53:26 ----A---- C:\Windows\system32\Chakra.dll
2017-04-23 11:53:24 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-04-23 11:53:24 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2017-04-23 11:53:23 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-04-23 11:53:21 ----A---- C:\Windows\system32\iertutil.dll
2017-04-23 11:53:20 ----A---- C:\Windows\system32\WindowsCodecs.dll
2017-04-23 11:53:18 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2017-04-23 11:53:17 ----A---- C:\Windows\system32\urlmon.dll
2017-04-23 11:53:16 ----A---- C:\Windows\system32\quartz.dll
2017-04-23 11:53:16 ----A---- C:\Windows\system32\MCRecvSrc.dll
2017-04-23 11:53:16 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-04-23 11:53:15 ----A---- C:\Windows\system32\win32kbase.sys
2017-04-23 11:53:15 ----A---- C:\Windows\system32\ole32.dll
2017-04-23 11:53:15 ----A---- C:\Windows\system32\kerberos.dll
2017-04-23 11:53:14 ----A---- C:\Windows\system32\wininet.dll
2017-04-23 11:53:13 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-04-23 11:53:13 ----A---- C:\Windows\system32\msfeeds.dll
2017-04-23 11:53:13 ----A---- C:\Windows\HelpPane.exe
2017-04-23 11:53:12 ----A---- C:\Windows\system32\Windows.Networking.dll
2017-04-23 11:53:12 ----A---- C:\Windows\system32\Windows.Devices.SmartCards.dll
2017-04-23 11:53:12 ----A---- C:\Windows\system32\ieapfltr.dll
2017-04-23 11:53:11 ----A---- C:\Windows\system32\MiracastReceiver.dll
2017-04-23 11:53:10 ----A---- C:\Windows\system32\twinapi.appcore.dll
2017-04-23 11:53:10 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2017-04-23 11:53:09 ----A---- C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2017-04-23 11:53:08 ----A---- C:\Windows\system32\Windows.Internal.Bluetooth.dll
2017-04-23 11:53:07 ----A---- C:\Windows\system32\Windows.Devices.Usb.dll
2017-04-23 11:53:07 ----A---- C:\Windows\system32\Windows.Devices.Bluetooth.dll
2017-04-23 11:53:07 ----A---- C:\Windows\system32\FlightSettings.dll
2017-04-23 11:53:06 ----A---- C:\Windows\system32\RDXService.dll
2017-04-23 11:53:06 ----A---- C:\Windows\system32\msdtctm.dll
2017-04-23 11:53:05 ----A---- C:\Windows\system32\Windows.Web.dll
2017-04-23 11:53:05 ----A---- C:\Windows\system32\Windows.Storage.ApplicationData.dll
2017-04-23 11:53:05 ----A---- C:\Windows\system32\Windows.Devices.Picker.dll
2017-04-23 11:53:05 ----A---- C:\Windows\system32\Windows.Devices.LowLevel.dll
2017-04-23 11:53:05 ----A---- C:\Windows\system32\CellularAPI.dll
2017-04-23 11:53:04 ----A---- C:\Windows\system32\Windows.Devices.PointOfService.dll
2017-04-23 11:53:04 ----A---- C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-04-23 11:53:03 ----A---- C:\Windows\system32\CoreUIComponents.dll
2017-04-23 11:53:01 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-04-23 11:53:00 ----A---- C:\Windows\system32\d2d1.dll
2017-04-23 11:53:00 ----A---- C:\Windows\system32\CloudExperienceHost.dll
2017-04-23 11:52:59 ----A---- C:\Windows\SYSWOW64\ieproxy.dll
2017-04-23 11:52:59 ----A---- C:\Windows\system32\Windows.UI.Search.dll
2017-04-23 11:52:59 ----A---- C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2017-04-23 11:52:59 ----A---- C:\Windows\system32\CloudExperienceHostBroker.dll
2017-04-23 11:52:59 ----A---- C:\Windows\system32\asycfilt.dll
2017-04-23 11:52:58 ----A---- C:\Windows\system32\Windows.Web.Http.dll
2017-04-23 11:52:58 ----A---- C:\Windows\system32\Windows.Devices.WiFiDirect.dll
2017-04-23 11:52:58 ----A---- C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll
2017-04-23 11:52:57 ----A---- C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2017-04-23 11:52:57 ----A---- C:\Windows\system32\Windows.Networking.Connectivity.dll
2017-04-23 11:52:57 ----A---- C:\Windows\system32\Windows.Devices.Lights.dll
2017-04-23 11:52:57 ----A---- C:\Windows\system32\SyncSettings.dll
2017-04-23 11:52:57 ----A---- C:\Windows\system32\PlayToManager.dll
2017-04-23 11:52:57 ----A---- C:\Windows\system32\iedkcs32.dll
2017-04-23 11:52:56 ----A---- C:\Windows\system32\Windows.Devices.SerialCommunication.dll
2017-04-23 11:52:56 ----A---- C:\Windows\system32\dafpos.dll
2017-04-23 11:52:55 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-04-23 11:52:55 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-04-23 11:52:55 ----A---- C:\Windows\system32\WpAXHolder.dll
2017-04-23 11:52:55 ----A---- C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2017-04-23 11:52:55 ----A---- C:\Windows\system32\TokenBroker.dll
2017-04-23 11:52:55 ----A---- C:\Windows\system32\PlayToDevice.dll
2017-04-23 11:52:54 ----A---- C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2017-04-23 11:52:54 ----A---- C:\Windows\system32\ie4uinit.exe
2017-04-23 11:52:54 ----A---- C:\Windows\system32\Geolocation.dll
2017-04-23 11:52:54 ----A---- C:\Windows\system32\FontProvider.dll
2017-04-23 11:52:53 ----A---- C:\Windows\system32\Windows.Graphics.Printing.3D.dll
2017-04-23 11:52:53 ----A---- C:\Windows\system32\mfmjpegdec.dll
2017-04-23 11:52:52 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2017-04-23 11:52:52 ----A---- C:\Windows\system32\dxtrans.dll
2017-04-23 11:52:52 ----A---- C:\Windows\system32\DisplayManager.dll
2017-04-23 11:52:51 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2017-04-23 11:52:51 ----A---- C:\Windows\system32\Windows.Devices.Printers.dll
2017-04-23 11:52:51 ----A---- C:\Windows\system32\webcheck.dll
2017-04-23 11:52:51 ----A---- C:\Windows\system32\mshtmled.dll
2017-04-23 11:52:50 ----A---- C:\Windows\SYSWOW64\WpcWebFilter.dll
2017-04-23 11:52:50 ----A---- C:\Windows\system32\PlayToReceiver.dll
2017-04-23 11:52:50 ----A---- C:\Windows\system32\DeviceDirectoryClient.dll
2017-04-23 11:52:49 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-04-23 11:52:49 ----A---- C:\Windows\system32\flvprophandler.dll
2017-04-23 11:52:49 ----A---- C:\Windows\system32\DdcWnsListener.dll
2017-04-23 11:52:48 ----A---- C:\Windows\system32\indexeddbserver.dll
2017-04-23 11:52:48 ----A---- C:\Windows\system32\dosvc.dll
2017-04-23 11:52:48 ----A---- C:\Windows\system32\aadtb.dll
2017-04-23 11:52:48 ----A---- C:\Windows\system32\aadcloudap.dll
2017-04-23 11:52:47 ----A---- C:\Windows\system32\odbcconf.dll
2017-04-23 11:52:47 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2017-04-23 11:52:46 ----A---- C:\Windows\system32\WpcWebFilter.dll
2017-04-23 11:52:46 ----A---- C:\Windows\system32\NaturalLanguage6.dll
2017-04-23 11:52:46 ----A---- C:\Windows\system32\CastLaunch.dll
2017-04-23 11:52:39 ----A---- C:\Windows\system32\win32kfull.sys
2017-04-23 11:52:38 ----A---- C:\Windows\system32\wuaueng.dll
2017-04-23 11:52:37 ----A---- C:\Windows\system32\SharedStartModel.dll
2017-04-23 11:52:37 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2017-04-23 11:52:36 ----A---- C:\Windows\system32\enterprisecsps.dll
2017-04-23 11:52:35 ----A---- C:\Windows\system32\actxprxy.dll
2017-04-23 11:52:33 ----A---- C:\Windows\system32\gdi32full.dll
2017-04-23 11:52:32 ----A---- C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2017-04-23 11:52:31 ----A---- C:\Windows\system32\fontdrvhost.exe
2017-04-23 11:52:29 ----A---- C:\Windows\system32\sppobjs.dll
2017-04-23 11:52:28 ----A---- C:\Windows\system32\Windows.Media.Speech.dll
2017-04-23 11:52:28 ----A---- C:\Windows\system32\Windows.AccountsControl.dll
2017-04-23 11:52:28 ----A---- C:\Windows\system32\atmfd.dll
2017-04-23 11:52:27 ----A---- C:\Windows\system32\twinui.dll
2017-04-23 11:52:26 ----A---- C:\Windows\system32\Windows.Devices.Midi.dll
2017-04-23 11:52:26 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2017-04-23 11:52:25 ----A---- C:\Windows\system32\WinTypes.dll
2017-04-23 11:52:25 ----A---- C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2017-04-23 11:52:25 ----A---- C:\Windows\system32\updatepolicy.dll
2017-04-23 11:52:25 ----A---- C:\Windows\system32\hvax64.exe
2017-04-23 11:52:25 ----A---- C:\Windows\system32\drivers\cng.sys
2017-04-23 11:52:25 ----A---- C:\Windows\system32\apprepsync.dll
2017-04-23 11:52:24 ----A---- C:\Windows\system32\Windows.Devices.AllJoyn.dll
2017-04-23 11:52:24 ----A---- C:\Windows\system32\ShareHost.dll
2017-04-23 11:52:24 ----A---- C:\Windows\system32\sbe.dll
2017-04-23 11:52:24 ----A---- C:\Windows\system32\qedit.dll
2017-04-23 11:52:24 ----A---- C:\Windows\system32\hvix64.exe
2017-04-23 11:52:24 ----A---- C:\Windows\system32\CompPkgSup.dll
2017-04-23 11:52:24 ----A---- C:\Windows\system32\CloudExperienceHostCommon.dll
2017-04-23 11:52:23 ----A---- C:\Windows\system32\UserDeviceRegistration.dll
2017-04-23 11:52:23 ----A---- C:\Windows\system32\OneBackupHandler.dll
2017-04-23 11:52:23 ----A---- C:\Windows\system32\dlnashext.dll
2017-04-23 11:52:23 ----A---- C:\Windows\system32\CertEnroll.dll
2017-04-23 11:52:22 ----A---- C:\Windows\system32\Windows.Media.MediaControl.dll
2017-04-23 11:52:22 ----A---- C:\Windows\system32\wer.dll
2017-04-23 11:52:22 ----A---- C:\Windows\system32\msxml6.dll
2017-04-23 11:52:22 ----A---- C:\Windows\system32\CoreMessaging.dll
2017-04-23 11:52:22 ----A---- C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2017-04-23 11:52:21 ----A---- C:\Windows\system32\Windows.System.SystemManagement.dll
2017-04-23 11:52:21 ----A---- C:\Windows\system32\Windows.Gaming.Input.dll
2017-04-23 11:52:21 ----A---- C:\Windows\system32\dmcertinst.exe
2017-04-23 11:52:21 ----A---- C:\Windows\system32\CloudExperienceHostUser.dll
2017-04-23 11:52:21 ----A---- C:\Windows\system32\AppContracts.dll
2017-04-23 11:52:20 ----A---- C:\Windows\system32\SettingSyncCore.dll
2017-04-23 11:52:20 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2017-04-23 11:52:20 ----A---- C:\Windows\system32\invagent.dll
2017-04-23 11:52:20 ----A---- C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll
2017-04-23 11:52:20 ----A---- C:\Windows\system32\appraiser.dll
2017-04-23 11:52:19 ----A---- C:\Windows\system32\Windows.Media.Import.dll
2017-04-23 11:52:19 ----A---- C:\Windows\system32\Windows.Media.Devices.dll
2017-04-23 11:52:19 ----A---- C:\Windows\system32\Windows.Internal.Management.dll
2017-04-23 11:52:19 ----A---- C:\Windows\system32\Windows.Globalization.dll
2017-04-23 11:52:19 ----A---- C:\Windows\system32\psmsrv.dll
2017-04-23 11:52:19 ----A---- C:\Windows\system32\devinv.dll
2017-04-23 11:52:19 ----A---- C:\Windows\system32\CryptoWinRT.dll
2017-04-23 11:52:19 ----A---- C:\Windows\system32\acmigration.dll
2017-04-23 11:52:18 ----A---- C:\Windows\system32\Windows.System.UserDeviceAssociation.dll
2017-04-23 11:52:18 ----A---- C:\Windows\system32\Windows.Devices.Radios.dll
2017-04-23 11:52:18 ----A---- C:\Windows\system32\Family.SyncEngine.dll
2017-04-23 11:52:18 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2017-04-23 11:52:17 ----A---- C:\Windows\system32\Windows.Devices.WiFi.dll
2017-04-23 11:52:17 ----A---- C:\Windows\system32\UserMgrProxy.dll
2017-04-23 11:52:17 ----A---- C:\Windows\system32\oleacc.dll
2017-04-23 11:52:17 ----A---- C:\Windows\system32\apprepapi.dll
2017-04-23 11:52:17 ----A---- C:\Windows\system32\aeinv.dll
2017-04-23 11:52:16 ----A---- C:\Windows\system32\Windows.StateRepositoryClient.dll
2017-04-23 11:52:16 ----A---- C:\Windows\system32\deviceaccess.dll
2017-04-23 11:52:15 ----A---- C:\Windows\system32\wuapi.dll
2017-04-23 11:52:15 ----A---- C:\Windows\system32\vss_ps.dll
2017-04-23 11:52:15 ----A---- C:\Windows\system32\UserDeviceRegistration.Ngc.dll
2017-04-23 11:52:15 ----A---- C:\Windows\system32\SettingsHandlers_ClosedCaptioning.dll
2017-04-23 11:52:15 ----A---- C:\Windows\system32\AuthBroker.dll
2017-04-23 11:52:14 ----A---- C:\Windows\system32\XblAuthTokenBrokerExt.dll
2017-04-23 11:52:14 ----A---- C:\Windows\system32\TokenBrokerUI.dll
2017-04-23 11:52:14 ----A---- C:\Windows\system32\ErrorDetails.dll
2017-04-23 11:52:14 ----A---- C:\Windows\system32\CloudDomainJoinDataModelServer.dll
2017-04-23 11:52:13 ----A---- C:\Windows\system32\XblAuthManagerProxy.dll
2017-04-23 11:52:13 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2017-04-23 11:52:13 ----A---- C:\Windows\system32\winsrv.dll
2017-04-23 11:52:13 ----A---- C:\Windows\system32\vaultcli.dll
2017-04-23 11:52:13 ----A---- C:\Windows\system32\GamePanel.exe
2017-04-23 11:52:13 ----A---- C:\Windows\system32\Family.Client.dll
2017-04-23 11:52:13 ----A---- C:\Windows\system32\enrollmentapi.dll
2017-04-23 11:52:13 ----A---- C:\Windows\system32\cdp.dll
2017-04-23 11:52:12 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2017-04-23 11:52:12 ----A---- C:\Windows\system32\UIRibbonRes.dll
2017-04-23 11:52:12 ----A---- C:\Windows\system32\atmlib.dll
2017-04-22 17:03:29 ----D---- C:\Program Files (x86)\SpeedFan
2017-04-17 20:58:46 ----A---- C:\Windows\system32\drivers\47D63ED4.sys
2017-04-17 14:52:38 ----D---- C:\ProgramData\HP
2017-04-17 14:52:28 ----D---- C:\Users\Tomáš Kouba\AppData\Roaming\HP_Easy_Start
2017-04-16 17:17:55 ----A---- C:\Windows\system32\drivers\40B147AA.sys

======List of files/folders modified in the last 1 month======

2017-05-13 11:58:27 ----D---- C:\Windows\Temp
2017-05-13 11:50:48 ----D---- C:\Users\Tomáš Kouba\AppData\Roaming\Skype
2017-05-13 11:37:08 ----D---- C:\Windows\Prefetch
2017-05-13 11:29:03 ----D---- C:\Windows\system32\sru
2017-05-13 11:27:14 ----D---- C:\Windows\system32\SleepStudy
2017-05-13 10:37:36 ----AD---- C:\ProgramData\TEMP
2017-05-13 10:34:32 ----D---- C:\ProgramData\MFAData
2017-05-13 10:32:36 ----SHD---- C:\Windows\Installer
2017-05-13 10:32:34 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2017-05-13 10:32:00 ----RD---- C:\Windows\Microsoft.NET
2017-05-13 10:28:28 ----D---- C:\Windows\System32
2017-05-13 10:28:28 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-05-13 10:23:59 ----AD---- C:\Program Files\Microsoft Office
2017-05-13 10:22:43 ----D---- C:\Windows\system32\config
2017-05-13 10:13:18 ----D---- C:\Windows\system32\catroot2
2017-05-13 10:13:10 ----SHD---- C:\System Volume Information
2017-05-13 10:07:35 ----D---- C:\Program Files (x86)\Steam
2017-05-13 10:04:18 ----D---- C:\Windows\AppReadiness
2017-05-11 20:49:14 ----HD---- C:\Program Files\WindowsApps
2017-05-11 20:41:50 ----D---- C:\Program Files\Common Files
2017-05-11 20:41:50 ----AD---- C:\Program Files\Common Files\microsoft shared
2017-05-11 20:37:55 ----D---- C:\Windows\WinSxS
2017-05-11 20:23:02 ----D---- C:\Windows\CbsTemp
2017-05-11 20:06:55 ----D---- C:\Windows\SysWOW64
2017-05-11 20:06:48 ----D---- C:\Windows\system32\drivers
2017-05-11 20:06:44 ----RD---- C:\Program Files
2017-05-11 20:06:43 ----D---- C:\Windows\system32\Macromed
2017-05-11 20:06:40 ----D---- C:\Windows\SYSWOW64\Macromed
2017-05-11 20:05:16 ----AD---- C:\Program Files (x86)\TeamViewer
2017-05-11 20:05:15 ----D---- C:\Windows\system32\Tasks
2017-05-08 21:23:22 ----RD---- C:\Users
2017-05-08 21:23:14 ----RD---- C:\Program Files (x86)
2017-05-08 21:22:25 ----D---- C:\ProgramData\DAEMON Tools Lite
2017-05-08 20:29:27 ----D---- C:\Windows\system32\DriverStore
2017-05-08 10:14:57 ----D---- C:\Windows\system32\NDF
2017-05-08 10:10:11 ----D---- C:\Windows
2017-05-08 10:09:28 ----D---- C:\Windows\INF
2017-05-08 10:07:56 ----D---- C:\ProgramData\Package Cache
2017-05-08 09:59:00 ----HD---- C:\ProgramData
2017-05-08 08:10:21 ----D---- C:\Windows\rescache
2017-05-07 21:50:17 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-05-07 18:16:05 ----AD---- C:\Program Files (x86)\Fallout 3 Game of the Year Edition
2017-05-07 17:12:12 ----RD---- C:\Windows\assembly
2017-05-07 16:22:01 ----D---- C:\Windows\system32\appraiser
2017-04-30 19:08:29 ----D---- C:\Program Files\Internet Explorer
2017-04-30 19:08:29 ----D---- C:\Program Files (x86)\Internet Explorer
2017-04-23 20:08:05 ----SD---- C:\Windows\SYSWOW64\F12
2017-04-23 20:08:05 ----D---- C:\Windows\SYSWOW64\sr-Latn-CS
2017-04-23 20:08:05 ----D---- C:\Windows\SYSWOW64\setup
2017-04-23 20:08:05 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-04-23 20:07:56 ----D---- C:\Windows\system32\wbem
2017-04-23 20:07:56 ----D---- C:\Windows\system32\sr-Latn-CS
2017-04-23 20:07:55 ----SD---- C:\Windows\system32\F12
2017-04-23 20:07:55 ----D---- C:\Windows\system32\setup
2017-04-23 20:07:55 ----D---- C:\Windows\system32\migration
2017-04-23 20:07:55 ----D---- C:\Windows\system32\Dism
2017-04-23 20:07:55 ----D---- C:\Windows\system32\cs-CZ
2017-04-23 20:07:47 ----D---- C:\Windows\ShellExperiences
2017-04-23 20:07:47 ----D---- C:\Windows\Provisioning
2017-04-23 20:07:46 ----RD---- C:\Windows\ImmersiveControlPanel
2017-04-23 20:07:46 ----RD---- C:\Program Files\Windows Defender
2017-04-23 20:07:46 ----D---- C:\Program Files\Windows Photo Viewer
2017-04-23 20:07:46 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-04-23 20:07:46 ----D---- C:\Program Files (x86)\Windows Defender
2017-04-15 13:24:00 ----AD---- C:\Program Files (x86)\Hard Disk Sentinel

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AVGIDSHA;AVGIDSHA; C:\Windows\system32\DRIVERS\avgidsha.sys [2016-10-05 267008]
R0 Avgloga;AVG Logging Driver; C:\Windows\system32\DRIVERS\avgloga.sys [2016-02-16 360736]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield; C:\Windows\system32\DRIVERS\avgmfx64.sys [2017-04-11 253184]
R0 Avgrkx64;AVG Anti-Rootkit Driver; C:\Windows\system32\DRIVERS\avgrkx64.sys [2016-06-01 52992]
R0 avguniva;AVG Universal Driver; C:\Windows\system32\DRIVERS\avguniva.sys [2016-06-20 77056]
R0 EUBAKUP;EUBAKUP; C:\Windows\system32\drivers\eubakup.sys [2015-12-10 60968]
R0 EUBKMON;EUBKMON; C:\Windows\system32\drivers\EUBKMON.sys [2015-12-10 48168]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\Windows\system32\drivers\iorate.sys [2016-11-02 48992]
R1 Avgdiska;AVG Disk Driver; C:\Windows\system32\DRIVERS\avgdiska.sys [2016-05-13 163072]
R1 Avgfwfd;@oem18.inf,%AvgfwfdService_Desc%;AVG network filter service; C:\Windows\system32\DRIVERS\avgfwd6a.sys [2016-10-23 73992]
R1 AVGIDSDriver;AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [2017-02-20 313088]
R1 Avgldx64;AVG AVI Loader Driver; C:\Windows\system32\DRIVERS\avgldx64.sys [2016-11-30 298240]
R1 Avgwfpa;AVG Firewall Driver; C:\Windows\system32\DRIVERS\avgwfpa.sys [2016-08-04 313096]
R1 EUDSKACS;EUDSKACS; \??\C:\Windows\system32\drivers\eudskacs.sys [2015-12-10 18472]
R1 EUFDDISK;EUFDDISK; \??\C:\Windows\system32\drivers\EuFdDisk.sys [2015-12-10 192552]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2016-07-16 88576]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2016-07-16 8192]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\Windows\System32\drivers\registry.sys [2016-07-16 70144]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2016-07-16 48128]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\Windows\system32\drivers\storqosflt.sys [2016-07-16 78336]
R3 bcbtums;@oem13.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\Windows\system32\drivers\bcbtums.sys [2015-10-01 208176]
R3 BCMWL63A;@oem2.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2017-01-17 11774712]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\drivers\BTHUSB.sys [2016-08-20 84992]
R3 dptf_cpu;dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [2015-08-13 53752]
R3 dptf_pch;dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [2015-08-13 50696]
R3 dtlitescsibus;@oem16.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2017-01-25 30264]
R3 dtliteusbbus;@oem17.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\Windows\System32\drivers\dtliteusbbus.sys [2017-01-25 47672]
R3 esif_lf;esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [2015-08-13 261624]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2017-01-13 7969752]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-10-15 5346312]
R3 MEIx64;@oem7.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\TeeDriverW8x64.sys [2015-06-23 192312]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\Windows\System32\drivers\rt640x64.sys [2016-07-16 589824]
R3 SmbDrvI;SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [2016-10-05 79960]
R3 SynTP;@oem9.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2016-10-05 872024]
S0 Avgboota;AVG Early Launch Anti-Malware Driver; C:\Windows\system32\DRIVERS\avgboota.sys [2016-01-07 21632]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2016-07-16 105824]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2016-07-16 101216]
S0 megasas2i;megasas2i; C:\Windows\System32\drivers\MegaSas2i.sys [2016-10-05 64352]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2016-07-16 58720]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2016-07-16 61792]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\Windows\System32\drivers\scmbus.sys [2016-07-16 88416]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\Windows\System32\drivers\storufs.sys [2016-07-16 32096]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\Windows\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\Windows\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 – ovladač síťového adaptéru; C:\Windows\system32\DRIVERS\bcmwl63a.sys [2017-01-17 11774712]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\Windows\System32\drivers\bcmfn.sys [2016-07-16 9728]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2016-08-20 114176]
S3 BthLEEnum;@BthLEEnum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\Windows\System32\drivers\BthLEEnum.sys [2016-09-15 249856]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2016-10-05 128512]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\drivers\BTHport.sys [2016-11-11 967168]
S3 btwampfl;@oem13.inf,%btwampfl.ServiceName%;btwampfl; C:\Windows\system32\DRIVERS\btwampfl.sys [2015-10-01 223024]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2016-07-16 38912]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2016-09-10 118272]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2016-07-16 20480]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2016-07-16 50016]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\Windows\system32\drivers\hvservice.sys [2016-08-06 73568]
S3 cht4iscsi;cht4iscsi; C:\Windows\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\Windows\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\Windows\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\Windows\System32\drivers\iai2c.sys [2016-07-16 81408]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [2016-07-16 176384]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2016-07-16 526176]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\Windows\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 IntcDAud;@oem5.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2016-05-12 481768]
S3 irda;IrDA; C:\Windows\system32\drivers\irda.sys [2016-07-16 120320]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2016-07-16 842584]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2016-07-16 108896]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\Windows\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 ReFSv1;ReFSv1; C:\Windows\system32\drivers\ReFSv1.sys [2016-07-16 928608]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\System32\drivers\rfcomm.sys [2016-07-16 183808]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\Windows\System32\drivers\scmdisk0101.sys [2016-07-16 123904]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-04-25 83056]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2017-02-27 2227312]
R2 avgfws;AVG Firewall; C:\Program Files (x86)\AVG\Av\avgfwsa.exe [2017-04-11 1824184]
R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [2017-04-11 5334432]
R2 avgsvc;AVG Service; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [2016-12-06 1146128]
R2 avgwd;AVG WatchDog; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [2017-04-11 729048]
R2 BcmBtRSupport;@oem13.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\Windows\system32\BtwRSupportService.exe [2015-10-01 2286848]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2016-07-16 44496]
R2 ClickToRunSvc;Microsoft Office Click-to-Run Service; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2017-05-03 3971264]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2016-07-16 44496]
R2 EaseUS Agent;EaseUS Agent Service; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [2016-06-03 39616]
R2 esifsvc;@oem12.inf,%ServiceDisplayName%;ESIF Upper Framework Service; C:\Windows\SysWoW64\esif_uf.exe [2015-08-13 1394360]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2017-01-13 373720]
R2 OneSyncSvc_49ce4;Hostitel synchronizace_49ce4; C:\Windows\system32\svchost.exe [2016-07-16 44496]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2015-09-03 614664]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2016-10-15 326656]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2016-10-05 269400]
R2 TeamViewer;TeamViewer 12; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2017-04-25 10888944]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\Windows\system32\svchost.exe [2016-07-16 44496]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2016-07-16 44496]
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\Windows\System32\svchost.exe [2016-07-16 44496]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\Windows\system32\svchost.exe [2016-07-16 44496]
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S2 CDPUserSvc_49ce4;CDPUserSvc_49ce4; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-29 153752]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-09-20 324224]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-11 271864]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 AvgAMPS;AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [2017-04-11 1002552]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2017-01-13 301528]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2017-02-07 1471168]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [2017-03-09 342456]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-29 153752]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 MessagingService_49ce4;Služba zasílání zpráv_49ce4; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-05-03 257216]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 PimIndexMaintenanceSvc_49ce4;Data kontaktů_49ce4; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\Windows\System32\SensorDataService.exe [2017-03-04 1312768]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-04-26 1590048]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\Windows\system32\TieringEngineService.exe [2016-07-16 287744]
S4 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2016-07-16 93184]
S4 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2016-07-16 44496]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\Windows\System32\svchost.exe [2016-07-16 44496]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\Windows\system32\svchost.exe [2016-07-16 44496]

-----------------EOF-----------------

Re: Malware jménem Initial Page 123

Napsal: 13 kvě 2017 11:17
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Malware jménem Initial Page 123

Napsal: 14 kvě 2017 09:34
od cunik.cz
Jo sorry za to že to sem vkládám až tak pozdě ale dřív to nešlo.

# AdwCleaner v6.046 - Log vytvořen 14/05/2017 v 10:29:01
# Aktualizováno dne 24/04/2017 z Malwarebytes
# Databáze : 2017-05-13.1 [Místní]
# Operační systém : Windows 10 Home (X64)
# Uživatelské jméno : Tomáš Kouba - DESKTOP-UH48FV1
# Spuštěno z : C:\Users\Tomáš Kouba\Desktop\adwcleaner_6.046.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Složky ] *****



***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****



***** [ Registry ] *****

[-] Klíč smazán: HKLM\SOFTWARE\ecb`nl
[-] Klíč smazán: [x64] HKLM\SOFTWARE\ecb`nl


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [2308 Bajty] - [13/05/2017 10:25:28]
C:\AdwCleaner\AdwCleaner[C2].txt - [976 Bajty] - [14/05/2017 10:29:01]
C:\AdwCleaner\AdwCleaner[S0].txt - [1388 Bajty] - [08/05/2017 12:46:39]
C:\AdwCleaner\AdwCleaner[S1].txt - [2468 Bajty] - [13/05/2017 10:22:29]
C:\AdwCleaner\AdwCleaner[S2].txt - [1635 Bajty] - [13/05/2017 12:35:51]
C:\AdwCleaner\AdwCleaner[S3].txt - [1708 Bajty] - [13/05/2017 15:11:52]
C:\AdwCleaner\AdwCleaner[S4].txt - [1779 Bajty] - [14/05/2017 10:28:47]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1413 Bajty] ##########

Re: Malware jménem Initial Page 123

Napsal: 14 kvě 2017 10:58
od Rudy

Re: Malware jménem Initial Page 123

Napsal: 14 kvě 2017 15:11
od cunik.cz
Rudy píše:Teď dejte log FRST: http://forum.viry.cz/viewtopic.php?f=24&t=132509 .
Applikaci Farbar Recovery Scan Tool stáhnout můžu ale to druhé mi oba dva prohlížeče blokují. Jak Chrome tak Edge.

Re: Malware jménem Initial Page 123

Napsal: 14 kvě 2017 16:38
od Rudy
Použijte tedy běžný FRST. V desítkách nemohu mazat z RSIT logu, riskuji poškození systému.

Re: Malware jménem Initial Page 123

Napsal: 15 kvě 2017 15:49
od cunik.cz
Zde první půlka logu

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-05-2017
Ran by Tomáš Kouba (administrator) on DESKTOP-UH48FV1 (15-05-2017 16:39:59)
Running from C:\Users\Tomáš Kouba\Downloads
Loaded Profiles: Tomáš Kouba (Available Profiles: defaultuser0 & Tomáš Kouba)
Platform: Windows 10 Home Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgwdsvca.exe
(Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(CyberLink) C:\Program Files\Cyberlink\Shared files\RichVideo64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgidsagenta.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgemca.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgfwsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgrsa.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(H.D.S. Hungary) C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
() C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Spotify Ltd) C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Av\avgui.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AcroCEF\AcroCEF.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Microsoft Corporation) C:\Windows\System32\SrTasks.exe
(Microsoft Corporation) C:\Windows\System32\SrTasks.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8911872 2016-10-15] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [240400 2016-12-06] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1870928 2017-04-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27262432 2016-12-20] (Skype Technologies S.A.)
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23819304 2017-03-21] (Google)
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3019552 2017-04-26] (Valve Corporation)
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Run: [download.ninja] => C:\Program Files\Ninja Download Manager\download.ninja.exe
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Run: [Spotify Web Helper] => C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1446000 2017-05-07] (Spotify Ltd)
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Run: [Spotify] => C:\Users\Tomáš Kouba\AppData\Roaming\Spotify\Spotify.exe [7064176 2017-05-07] (Spotify Ltd)
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4701888 2017-02-07] (Disc Soft Ltd)
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\MountPoints2: {5297f475-332d-11e7-9502-308d99f20ed4} - "H:\setup_dead_space_2.0.0.2.exe"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\MountPoints2: {7b1383fe-387f-11e7-9505-308d99f20ed4} - "E:\setup_dead_space_2.0.0.2.exe"
HKLM\...\Providers\4ds9bvs2: C:\Program Files (x86)\Tuationfoty Launcher\local64spl.dll
ShellExecuteHooks: No Name - {E9AC8DEE-308A-11E7-865E-64006A5CFC23} - C:\Users\Tomáš Kouba\AppData\Roaming\Ghegiward\Shemuing.dll -> No File
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
Startup: C:\Users\Tomáš Kouba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Mozilla Thunderbird.lnk [2017-01-22]
ShortcutTarget: Mozilla Thunderbird.lnk -> C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe (Mozilla Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{d0472a43-d15d-4377-8873-672385571790}: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{fc0214b8-3b37-4f64-8969-a972108cdc96}: [DhcpNameServer] 192.168.2.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-02-26] (Adobe Systems Incorporated)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-02-26] (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2017-05-11] (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-02-26] (Adobe Systems Incorporated)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-13] (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-02-26] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-02-26] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-02-26] (Adobe Systems Incorporated)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-13] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-05-13] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-13] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-05-13] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-13] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-05-13] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-13] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2017-05-13] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: bwzvh64p.default
FF ProfilePath: C:\Users\Tomáš Kouba\AppData\Roaming\Mozilla\Firefox\Profiles\bwzvh64p.default [2017-03-18]
FF Extension: (Adblock Plus) - C:\Users\Tomáš Kouba\AppData\Roaming\Mozilla\Firefox\Profiles\bwzvh64p.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-01-25]
FF Extension: (Adobe Acrobat DC - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2017-04-15]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-11] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-11] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-07-29] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-11] ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2017-05-11] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-30] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-07-29] (Adobe Systems)

Chrome:
=======
CHR Profile: C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default [2017-05-14]
CHR Extension: (Google Slides) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-05-14]
CHR Extension: (Google Docs) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-14]
CHR Extension: (Google Drive) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-14]
CHR Extension: (YouTube) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-14]
CHR Extension: (Adobe Acrobat) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-05-14]
CHR Extension: (Google Docs Offline) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-14]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2017-05-14]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-14]
CHR Extension: (Gmail) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-14]
CHR Extension: (Chrome Media Router) - C:\Users\Tomáš Kouba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-14]
CHR HKU\S-1-5-21-725424127-4130822466-1493971447-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-02-27] (Adobe Systems, Incorporated)
S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [1002552 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 avgfws; C:\Program Files (x86)\AVG\Av\avgfwsa.exe [1824184 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5334432 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1146128 2016-12-06] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [729048 2017-04-11] (AVG Technologies CZ, s.r.o.)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2286848 2015-10-01] (Broadcom Corporation.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3971264 2017-05-03] (Microsoft Corporation)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-02-07] (Disc Soft Ltd)
R2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [39616 2016-06-03] (CHENGDU YIWO Tech Development Co., Ltd)
R2 esifsvc; C:\Windows\SysWoW64\esif_uf.exe [1394360 2015-08-13] (Intel Corporation)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342456 2017-03-09] (Futuremark)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373720 2017-01-13] (Intel Corporation)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2015-09-03] (CyberLink)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [326656 2016-10-15] (Realtek Semiconductor)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [269400 2016-10-05] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10888944 2017-04-25] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-28] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-28] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21632 2016-01-07] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\system32\DRIVERS\avgfwd6a.sys [73992 2016-10-23] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313088 2017-02-20] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [267008 2016-10-05] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [298240 2016-11-30] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [253184 2017-04-11] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
R0 avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [77056 2016-06-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [313096 2016-08-04] (AVG Technologies CZ, s.r.o.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [208176 2015-10-01] (Broadcom Corporation.)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [11774712 2017-01-17] (Broadcom Corp)
R3 BCMWL63A; C:\Windows\system32\DRIVERS\bcmwl63a.sys [11774712 2017-01-17] (Broadcom Corp)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [53752 2015-08-13] (Intel Corporation)
R3 dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [50696 2015-08-13] (Intel Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2017-01-25] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2017-01-25] (Disc Soft Ltd)
R3 esif_lf; C:\Windows\system32\DRIVERS\esif_lf.sys [261624 2015-08-13] (Intel Corporation)
R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [48168 2015-12-10] ()
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek )
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [79960 2016-10-05] (Synaptics Incorporated)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\Windows\system32\DRIVERS\WirelessButtonDriver64.sys [31656 2016-04-14] (HP)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-15 16:39 - 2017-05-15 16:39 - 00022312 _____ C:\Users\Tomáš Kouba\Downloads\FRST.txt
2017-05-15 16:39 - 2017-05-15 16:39 - 00000000 ____D C:\Users\Tomáš Kouba\Downloads\FRST-OlderVersion
2017-05-15 16:38 - 2017-05-15 16:39 - 00000000 ____D C:\FRST
2017-05-15 16:34 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2017-05-15 16:34 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2017-05-15 16:34 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2017-05-15 16:34 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2017-05-15 16:34 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2017-05-15 16:34 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2017-05-15 16:29 - 2017-05-15 16:29 - 00001693 _____ C:\Users\Public\Desktop\Dead Space.lnk
2017-05-15 16:29 - 2017-05-15 16:29 - 00000000 ____D C:\Users\Tomáš Kouba\Documents\Electronic Arts
2017-05-15 16:29 - 2017-05-15 16:29 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Local\Electronic Arts
2017-05-15 16:29 - 2017-05-15 16:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dead Space [GOG.com]
2017-05-14 16:05 - 2017-05-14 16:05 - 00002344 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-14 16:05 - 2017-05-14 16:05 - 00002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-14 16:03 - 2017-05-14 16:03 - 01130328 _____ (Google Inc.) C:\Users\Tomáš Kouba\Downloads\ChromeSetup.exe
2017-05-14 15:59 - 2017-05-15 16:39 - 02429952 _____ (Farbar) C:\Users\Tomáš Kouba\Downloads\FRST64.exe
2017-05-14 10:26 - 2017-05-08 12:43 - 04102600 _____ C:\Users\Tomáš Kouba\Desktop\adwcleaner_6.046.exe
2017-05-13 12:54 - 2017-05-13 12:55 - 00000000 ____D C:\Program Files\UNP
2017-05-13 12:54 - 2017-05-13 12:54 - 00000000 ____D C:\Windows\system32\UNP
2017-05-13 12:38 - 2017-04-28 02:46 - 05722320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-05-13 12:38 - 2017-04-28 02:46 - 01504056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-05-13 12:38 - 2017-04-28 02:46 - 01431232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2017-05-13 12:38 - 2017-04-28 02:45 - 02263832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-05-13 12:38 - 2017-04-28 02:45 - 00116576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostCommon.dll
2017-05-13 12:38 - 2017-04-28 02:43 - 00846560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll
2017-05-13 12:38 - 2017-04-28 02:40 - 06665952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-05-13 12:38 - 2017-04-28 02:40 - 04023008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2017-05-13 12:38 - 2017-04-28 02:40 - 01851696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-05-13 12:38 - 2017-04-28 02:40 - 01360456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2017-05-13 12:38 - 2017-04-28 02:40 - 01277856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2017-05-13 12:38 - 2017-04-28 02:40 - 01202936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2017-05-13 12:38 - 2017-04-28 02:40 - 00981888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2017-05-13 12:38 - 2017-04-28 02:39 - 20967840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-05-13 12:38 - 2017-04-28 02:29 - 05685760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-05-13 12:38 - 2017-04-28 02:22 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll
2017-05-13 12:38 - 2017-04-28 02:21 - 00224256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExSMime.dll
2017-05-13 12:38 - 2017-04-28 02:20 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Radios.dll
2017-05-13 12:38 - 2017-04-28 02:19 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDeviceRegistration.dll
2017-05-13 12:38 - 2017-04-28 02:19 - 00138240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2017-05-13 12:38 - 2017-04-28 02:18 - 00255488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\unimdm.tsp
2017-05-13 12:38 - 2017-04-28 02:17 - 00142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFi.dll
2017-05-13 12:38 - 2017-04-28 02:17 - 00136192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinRtTracing.dll
2017-05-13 12:38 - 2017-04-28 02:17 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2017-05-13 12:38 - 2017-04-28 02:16 - 00392192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.Input.dll
2017-05-13 12:38 - 2017-04-28 02:16 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.LowLevel.dll
2017-05-13 12:38 - 2017-04-28 02:16 - 00315904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-05-13 12:38 - 2017-04-28 02:16 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-05-13 12:38 - 2017-04-28 02:16 - 00113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Lights.dll
2017-05-13 12:38 - 2017-04-28 02:15 - 00557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2017-05-13 12:38 - 2017-04-28 02:15 - 00237568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
2017-05-13 12:38 - 2017-04-28 02:15 - 00117760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AuthBroker.dll
2017-05-13 12:38 - 2017-04-28 02:15 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Core.dll
2017-05-13 12:38 - 2017-04-28 02:14 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-05-13 12:38 - 2017-04-28 02:13 - 13873664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 01243136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.FaceAnalysis.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SmartCards.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00426496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Wallet.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00386048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.WiFiDirect.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00325120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleacc.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00218624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WwaApi.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00202752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-05-13 12:38 - 2017-04-28 02:13 - 00175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Scanners.dll
2017-05-13 12:38 - 2017-04-28 02:12 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mbsmsapi.dll
2017-05-13 12:38 - 2017-04-28 02:12 - 00431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll
2017-05-13 12:38 - 2017-04-28 02:12 - 00262144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Picker.dll
2017-05-13 12:38 - 2017-04-28 02:10 - 00314368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Usb.dll
2017-05-13 12:38 - 2017-04-28 02:09 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2017-05-13 12:38 - 2017-04-28 02:08 - 00653312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.AccountsControl.dll
2017-05-13 12:38 - 2017-04-28 02:08 - 00288256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CryptoWinRT.dll
2017-05-13 12:38 - 2017-04-28 02:06 - 04614656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-05-13 12:38 - 2017-04-28 02:06 - 02333184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-05-13 12:38 - 2017-04-28 02:06 - 00675840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.dll
2017-05-13 12:38 - 2017-04-28 02:05 - 03733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-05-13 12:38 - 2017-04-28 02:05 - 00589312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2017-05-13 12:38 - 2017-04-28 02:03 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Editing.dll
2017-05-13 12:38 - 2017-04-28 02:03 - 00355328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTMediaFrame.dll
2017-05-13 12:38 - 2017-04-28 02:02 - 03307008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2017-05-13 12:38 - 2017-04-28 02:01 - 00795648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MiracastReceiver.dll
2017-05-13 12:38 - 2017-04-28 02:01 - 00343040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToDevice.dll
2017-05-13 12:38 - 2017-04-28 02:01 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dlnashext.dll
2017-05-13 12:38 - 2017-04-28 02:01 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dialclient.dll
2017-05-13 12:38 - 2017-04-28 01:59 - 00895488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Streaming.dll
2017-05-13 12:38 - 2017-04-28 01:59 - 00220672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToReceiver.dll
2017-05-13 12:38 - 2017-04-28 01:58 - 07468544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-05-13 12:38 - 2017-04-28 01:58 - 00134144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ErrorDetails.dll
2017-05-13 12:38 - 2017-04-28 01:57 - 01247232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Globalization.dll
2017-05-13 12:38 - 2017-04-28 01:57 - 01221120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Audio.dll
2017-05-13 12:38 - 2017-04-28 01:57 - 00641024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2017-05-13 12:38 - 2017-04-28 01:56 - 00400384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2017-05-13 12:38 - 2017-04-28 01:56 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Geolocation.dll
2017-05-13 12:38 - 2017-04-28 01:56 - 00103936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Devices.dll
2017-05-13 12:38 - 2017-04-28 01:55 - 01656320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Perception.dll
2017-05-13 12:38 - 2017-04-28 01:55 - 01232384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-05-13 12:38 - 2017-04-28 01:55 - 01004544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll
2017-05-13 12:38 - 2017-04-28 01:54 - 02646528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll
2017-05-13 12:38 - 2017-04-28 01:54 - 02483200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-05-13 12:38 - 2017-04-28 01:54 - 01013248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Http.dll
2017-05-13 12:38 - 2017-04-28 01:54 - 00654336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2017-05-13 12:38 - 2017-04-28 01:54 - 00598528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.dll
2017-05-13 12:38 - 2017-04-28 01:53 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-05-13 12:38 - 2017-04-28 01:53 - 00751104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2017-05-13 12:38 - 2017-04-28 01:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2017-05-13 12:38 - 2017-04-28 01:52 - 03106304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2017-05-13 12:38 - 2017-04-28 01:52 - 02994176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-05-13 12:38 - 2017-04-28 01:52 - 01600000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-05-13 12:38 - 2017-04-28 01:50 - 00783360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll
2017-05-13 12:38 - 2017-03-04 09:57 - 00484584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-05-13 12:38 - 2017-03-04 08:22 - 00265728 _____ C:\Windows\SysWOW64\Windows.Perception.Stub.dll
2017-05-13 12:38 - 2017-03-04 08:17 - 00529920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2017-05-13 12:38 - 2017-03-04 08:00 - 00691200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll
2017-05-13 12:37 - 2017-04-28 02:59 - 00601712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-05-13 12:37 - 2017-04-28 02:56 - 02048488 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2017-05-13 12:37 - 2017-04-28 02:48 - 00263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2017-05-13 12:37 - 2017-04-28 02:45 - 00975744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2017-05-13 12:37 - 2017-04-28 02:45 - 00861024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2017-05-13 12:37 - 2017-04-28 02:43 - 02168288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll
2017-05-13 12:37 - 2017-04-28 02:43 - 01980768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2017-05-13 12:37 - 2017-04-28 02:39 - 04312248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-05-13 12:37 - 2017-04-28 02:39 - 00962760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-05-13 12:37 - 2017-04-28 02:35 - 01414208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll
2017-05-13 12:37 - 2017-04-28 02:23 - 00095232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll
2017-05-13 12:37 - 2017-04-28 02:16 - 00184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2017-05-13 12:37 - 2017-04-28 02:16 - 00118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppointmentActivation.dll
2017-05-13 12:37 - 2017-04-28 02:14 - 00670208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.PointOfService.dll
2017-05-13 12:37 - 2017-04-28 02:14 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.AllJoyn.dll
2017-05-13 12:37 - 2017-04-28 02:13 - 00271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll
2017-05-13 12:37 - 2017-04-28 02:11 - 00747520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Ocr.dll
2017-05-13 12:37 - 2017-04-28 02:10 - 00819200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppContracts.dll
2017-05-13 12:37 - 2017-04-28 02:10 - 00816640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NaturalLanguage6.dll
2017-05-13 12:37 - 2017-04-28 02:10 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.dll
2017-05-13 12:37 - 2017-04-28 02:10 - 00238080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AboveLockAppHost.dll
2017-05-13 12:37 - 2017-04-28 02:08 - 07626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-05-13 12:37 - 2017-04-28 02:08 - 01534464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.3D.dll
2017-05-13 12:37 - 2017-04-28 02:06 - 00901120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2017-05-13 12:37 - 2017-04-28 02:05 - 00886272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2017-05-13 12:37 - 2017-04-28 02:01 - 00713216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2017-05-13 12:37 - 2017-04-28 02:00 - 02749440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mispace.dll
2017-05-13 12:37 - 2017-04-28 02:00 - 01255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-05-13 12:37 - 2017-04-28 01:59 - 02154496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\storagewmi.dll
2017-05-13 12:37 - 2017-04-28 01:58 - 00090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-05-13 12:37 - 2017-04-28 01:55 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-05-13 12:37 - 2017-04-28 01:55 - 01170944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
2017-05-13 12:37 - 2017-04-28 01:54 - 01883648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2017-05-13 12:37 - 2017-04-28 01:54 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll
2017-05-13 12:37 - 2017-04-28 01:54 - 00348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Midi.dll
2017-05-13 12:37 - 2017-04-28 01:30 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2017-05-13 12:37 - 2017-03-04 08:16 - 00500224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Graphics.Printing.dll
2017-05-13 12:37 - 2017-03-04 08:01 - 00827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2017-05-13 12:35 - 2017-04-28 01:55 - 01993216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2017-05-13 12:34 - 2017-04-28 01:54 - 02747904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-05-13 12:33 - 2017-04-28 02:04 - 01323008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_fs.dll
2017-05-13 12:33 - 2017-04-28 01:52 - 02008576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-05-13 12:32 - 2017-04-28 02:42 - 00601952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupEngine.dll
2017-05-13 12:32 - 2017-04-28 02:12 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll
2017-05-13 12:32 - 2017-04-28 02:03 - 01137152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_health.dll
2017-05-13 12:31 - 2017-04-28 02:45 - 00781144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-05-13 12:31 - 2017-04-28 02:43 - 01557224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-05-13 12:31 - 2017-04-28 02:16 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-05-13 12:31 - 2017-04-28 02:07 - 00525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2017-05-13 12:31 - 2017-04-28 01:57 - 00719872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsp_sr.dll
2017-05-13 12:31 - 2017-03-04 08:23 - 00299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataAccountApis.dll
2017-05-13 12:30 - 2017-04-28 02:53 - 00616048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-05-13 12:30 - 2017-04-28 02:45 - 00493920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2017-05-13 12:30 - 2017-04-28 02:40 - 00352760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll
2017-05-13 12:30 - 2017-04-28 02:39 - 00715104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2017-05-13 12:30 - 2017-04-28 02:38 - 00557408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\spaceport.sys
2017-05-13 12:30 - 2017-04-28 02:13 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll
2017-05-13 12:30 - 2017-04-28 02:11 - 00075776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
2017-05-13 12:30 - 2017-04-28 02:10 - 00764928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprddm.dll
2017-05-13 12:30 - 2017-04-28 02:07 - 00256512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\thumbcache.dll
2017-05-13 12:30 - 2017-04-28 02:00 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthLEEnum.sys
2017-05-13 12:30 - 2017-04-28 01:58 - 00546304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uReFS.dll
2017-05-13 12:30 - 2017-04-28 01:55 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OpcServices.dll
2017-05-13 12:30 - 2017-04-28 01:54 - 00967680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys
2017-05-13 12:30 - 2017-04-28 01:53 - 00798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2017-05-13 12:29 - 2017-04-28 02:41 - 00361104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
2017-05-13 12:29 - 2017-04-28 02:09 - 00352256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll
2017-05-13 12:29 - 2017-04-28 02:08 - 01228288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll
2017-05-13 12:28 - 2017-04-28 02:55 - 00088416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scmbus.sys
2017-05-13 12:28 - 2017-04-28 02:23 - 01631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-05-13 12:28 - 2017-04-28 02:10 - 00857600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EmailApis.dll
2017-05-13 12:28 - 2017-04-28 02:05 - 00709120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll
2017-05-13 12:27 - 2017-04-28 03:28 - 00965472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2017-05-13 12:27 - 2017-04-28 02:35 - 00276832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2017-05-13 12:27 - 2017-04-28 02:20 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\virtdisk.dll
2017-05-13 12:27 - 2017-04-28 02:18 - 00450560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2017-05-13 12:27 - 2017-04-28 02:17 - 00095232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BluetoothApis.dll
2017-05-13 12:27 - 2017-04-28 02:16 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credprovhost.dll
2017-05-13 12:27 - 2017-04-28 02:15 - 00404992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dsreg.dll
2017-05-13 12:27 - 2017-04-28 02:15 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bthprops.cpl
2017-05-13 12:27 - 2017-04-28 02:13 - 01755136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DeviceFlows.DataModel.dll
2017-05-13 12:27 - 2017-04-28 02:13 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll
2017-05-13 12:27 - 2017-04-28 02:13 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupugc.exe
2017-05-13 12:27 - 2017-04-28 02:09 - 00525824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintDialogs.dll
2017-05-13 12:27 - 2017-04-28 02:09 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-05-13 12:27 - 2017-04-28 02:07 - 03689984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2017-05-13 12:27 - 2017-04-28 02:03 - 00318464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll
2017-05-13 12:27 - 2017-04-28 02:03 - 00291328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsnt.dll
2017-05-13 12:26 - 2017-04-28 02:22 - 00165376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReInfo.dll
2017-05-13 12:26 - 2017-04-28 02:21 - 00027648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BthTelemetry.dll
2017-05-13 12:26 - 2017-04-28 02:18 - 00285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-05-13 12:26 - 2017-04-28 02:17 - 00328192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll
2017-05-13 12:26 - 2017-04-28 02:15 - 00334848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastlsext.dll
2017-05-13 12:26 - 2017-04-28 02:13 - 00206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vaultcli.dll
2017-05-13 12:26 - 2017-04-28 02:09 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll
2017-05-13 12:26 - 2017-04-28 02:03 - 00134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Energy.dll
2017-05-13 12:26 - 2017-04-28 02:01 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\unimdm.tsp
2017-05-13 12:26 - 2017-04-28 01:58 - 00433664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imapi2.dll
2017-05-13 12:26 - 2017-04-28 01:57 - 00089600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CameraCaptureUI.dll
2017-05-13 12:26 - 2017-04-28 01:56 - 00333312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2017-05-13 12:26 - 2017-04-28 01:39 - 04596224 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2017-05-13 12:26 - 2017-03-04 08:25 - 01388544 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Cred.dll
2017-05-13 12:26 - 2017-03-04 08:05 - 03520512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2017-05-13 12:25 - 2017-04-28 02:11 - 00846336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebcamUi.dll
2017-05-13 12:25 - 2017-04-28 02:02 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-05-13 12:25 - 2017-04-28 02:00 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\WinRtTracing.dll
2017-05-13 12:25 - 2017-04-28 02:00 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Core.dll
2017-05-13 12:25 - 2017-04-28 01:59 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.XboxLive.Storage.dll
2017-05-13 12:25 - 2017-04-28 01:56 - 00358912 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.dll
2017-05-13 12:25 - 2017-04-28 01:55 - 00561664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Wallet.dll
2017-05-13 12:25 - 2017-04-28 01:53 - 00245760 _____ (Microsoft Corporation) C:\Windows\system32\WwaApi.dll
2017-05-13 12:25 - 2017-04-28 01:43 - 00963584 _____ (Microsoft Corporation) C:\Windows\system32\WebcamUi.dll
2017-05-13 12:25 - 2017-04-28 01:41 - 01080320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Ocr.dll
2017-05-13 12:25 - 2017-04-28 01:40 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2017-05-13 12:25 - 2017-04-28 01:38 - 02424320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Perception.dll
2017-05-13 12:25 - 2017-04-28 01:37 - 02538496 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-05-13 12:25 - 2017-04-28 01:37 - 01424896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Maps.dll
2017-05-13 12:25 - 2017-04-28 01:37 - 01266176 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll
2017-05-13 12:25 - 2017-04-28 01:37 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2017-05-13 12:25 - 2017-03-04 08:06 - 01369088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Phone.dll
2017-05-13 12:23 - 2017-04-28 02:01 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2017-05-13 12:23 - 2017-04-28 01:44 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2017-05-13 12:22 - 2017-04-28 02:40 - 00857440 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2017-05-13 12:21 - 2017-04-28 01:57 - 01507840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.FaceAnalysis.dll
2017-05-13 12:21 - 2017-04-28 01:56 - 00293888 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2017-05-13 12:20 - 2017-04-28 02:58 - 01706488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-05-13 12:20 - 2017-04-28 02:57 - 00794928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2017-05-13 12:20 - 2017-04-28 02:53 - 02213760 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-05-13 12:20 - 2017-04-28 02:53 - 00774224 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-05-13 12:20 - 2017-04-28 02:40 - 07220184 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2017-05-13 12:20 - 2017-04-28 02:40 - 01860288 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2017-05-13 12:20 - 2017-04-28 02:38 - 00847200 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupEngine.dll
2017-05-13 12:20 - 2017-04-28 02:36 - 00408600 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
2017-05-13 12:20 - 2017-04-28 02:36 - 00092512 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-05-13 12:20 - 2017-04-28 02:35 - 08170600 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2017-05-13 12:20 - 2017-04-28 02:35 - 04260576 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2017-05-13 12:20 - 2017-04-28 02:35 - 01988048 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2017-05-13 12:20 - 2017-04-28 02:35 - 01702392 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2017-05-13 12:20 - 2017-04-28 02:35 - 01302136 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2017-05-13 12:20 - 2017-04-28 02:35 - 00596040 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-05-13 12:20 - 2017-04-28 02:34 - 22220856 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-05-13 12:20 - 2017-04-28 02:34 - 01072248 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2017-05-13 12:20 - 2017-04-28 02:34 - 00443232 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll
2017-05-13 12:20 - 2017-04-28 02:34 - 00244824 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll

Re: Malware jménem Initial Page 123

Napsal: 15 kvě 2017 15:50
od cunik.cz
Zde druhá půlka logu

2017-05-13 12:20 - 2017-04-28 02:28 - 00453536 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2017-05-13 12:20 - 2017-04-28 02:28 - 00387864 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll
2017-05-13 12:20 - 2017-04-28 02:07 - 00372736 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll
2017-05-13 12:20 - 2017-04-28 02:04 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll
2017-05-13 12:20 - 2017-04-28 02:02 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bridge.sys
2017-05-13 12:20 - 2017-04-28 02:02 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vwifimp.sys
2017-05-13 12:20 - 2017-04-28 02:00 - 12349440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2017-05-13 12:20 - 2017-04-28 01:58 - 00418304 _____ C:\Windows\system32\Windows.Perception.Stub.dll
2017-05-13 12:20 - 2017-04-28 01:58 - 00211968 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2017-05-13 12:20 - 2017-04-28 01:57 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Scanners.dll
2017-05-13 12:20 - 2017-04-28 01:56 - 00748544 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2017-05-13 12:20 - 2017-04-28 01:56 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll
2017-05-13 12:20 - 2017-04-28 01:56 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2017-05-13 12:20 - 2017-04-28 01:55 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs3D.dll
2017-05-13 12:20 - 2017-04-28 01:55 - 00252416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-05-13 12:20 - 2017-04-28 01:54 - 00284160 _____ (Microsoft Corporation) C:\Windows\system32\AboveLockAppHost.dll
2017-05-13 12:20 - 2017-04-28 01:53 - 06288384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2017-05-13 12:20 - 2017-04-28 01:53 - 03059200 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2017-05-13 12:20 - 2017-04-28 01:53 - 00671744 _____ (Microsoft Corporation) C:\Windows\system32\mbsmsapi.dll
2017-05-13 12:20 - 2017-04-28 01:51 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-05-13 12:20 - 2017-04-28 01:51 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\RTMediaFrame.dll
2017-05-13 12:20 - 2017-04-28 01:51 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-05-13 12:20 - 2017-04-28 01:50 - 03778048 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2017-05-13 12:20 - 2017-04-28 01:49 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2017-05-13 12:20 - 2017-04-28 01:47 - 01908224 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2017-05-13 12:20 - 2017-04-28 01:47 - 01078784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Streaming.dll
2017-05-13 12:20 - 2017-04-28 01:47 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\SpaceControl.dll
2017-05-13 12:20 - 2017-04-28 01:45 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Audio.dll
2017-05-13 12:20 - 2017-04-28 01:45 - 00411648 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2017-05-13 12:20 - 2017-04-28 01:44 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2017-05-13 12:20 - 2017-04-28 01:44 - 01145344 _____ (Microsoft Corporation) C:\Windows\system32\EmailApis.dll
2017-05-13 12:20 - 2017-04-28 01:44 - 00583680 _____ (Microsoft Corporation) C:\Windows\system32\PrintDialogs.dll
2017-05-13 12:20 - 2017-04-28 01:43 - 00646656 _____ (Microsoft Corporation) C:\Windows\system32\wiaservc.dll
2017-05-13 12:20 - 2017-04-28 01:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2017-05-13 12:20 - 2017-04-28 01:43 - 00331264 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnrSvc.dll
2017-05-13 12:20 - 2017-04-28 01:42 - 13441536 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2017-05-13 12:20 - 2017-04-28 01:42 - 08076288 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-05-13 12:20 - 2017-04-28 01:42 - 02390016 _____ (Microsoft Corporation) C:\Windows\system32\smartscreen.exe
2017-05-13 12:20 - 2017-04-28 01:41 - 00983040 _____ (Microsoft Corporation) C:\Windows\system32\ngcsvc.dll
2017-05-13 12:20 - 2017-04-28 01:41 - 00860160 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2017-05-13 12:20 - 2017-04-28 01:41 - 00611328 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.dll
2017-05-13 12:20 - 2017-04-28 01:39 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2017-05-13 12:20 - 2017-04-28 01:38 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll
2017-05-13 12:20 - 2017-04-28 01:38 - 00765440 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
2017-05-13 12:20 - 2017-04-28 01:37 - 04149248 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-05-13 12:20 - 2017-04-28 01:37 - 03134976 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-05-13 12:20 - 2017-04-28 01:37 - 01984000 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2017-05-13 12:20 - 2017-04-28 01:36 - 01131008 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-05-13 12:20 - 2017-04-28 01:35 - 03299840 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2017-05-13 12:20 - 2017-04-28 01:34 - 00999424 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll
2017-05-13 12:20 - 2017-03-04 09:09 - 01293152 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2017-05-13 12:20 - 2017-03-04 08:27 - 00456192 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2017-05-13 12:20 - 2017-03-04 08:19 - 01403392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Editing.dll
2017-05-13 12:19 - 2017-04-28 02:53 - 07784288 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-05-13 12:19 - 2017-04-28 02:49 - 02681200 _____ C:\Windows\system32\CoreUIComponents.dll
2017-05-13 12:19 - 2017-04-28 02:42 - 00328008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
2017-05-13 12:19 - 2017-04-28 02:40 - 02759704 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-05-13 12:19 - 2017-04-28 02:40 - 02187104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-05-13 12:19 - 2017-04-28 02:40 - 01738560 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-05-13 12:19 - 2017-04-28 02:40 - 01157000 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2017-05-13 12:19 - 2017-04-28 02:40 - 00402784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-05-13 12:19 - 2017-04-28 02:34 - 01277824 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-05-13 12:19 - 2017-04-28 02:19 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-05-13 12:19 - 2017-04-28 02:14 - 00270336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-05-13 12:19 - 2017-04-28 02:11 - 00340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-05-13 12:19 - 2017-04-28 02:08 - 18365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-05-13 12:19 - 2017-04-28 02:06 - 22569472 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2017-05-13 12:19 - 2017-04-28 02:06 - 00691712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-05-13 12:19 - 2017-04-28 02:05 - 19414016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-05-13 12:19 - 2017-04-28 02:03 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\raspppoe.sys
2017-05-13 12:19 - 2017-04-28 02:03 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll
2017-05-13 12:19 - 2017-04-28 02:00 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2017-05-13 12:19 - 2017-04-28 01:59 - 12187136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-05-13 12:19 - 2017-04-28 01:59 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll
2017-05-13 12:19 - 2017-04-28 01:59 - 00375296 _____ (Microsoft Corporation) C:\Windows\system32\rastlsext.dll
2017-05-13 12:19 - 2017-04-28 01:58 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2017-05-13 12:19 - 2017-04-28 01:58 - 00276992 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-05-13 12:19 - 2017-04-28 01:57 - 00502784 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2017-05-13 12:19 - 2017-04-28 01:57 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-05-13 12:19 - 2017-04-28 01:57 - 00132096 _____ (Microsoft Corporation) C:\Windows\system32\PrintWSDAHost.dll
2017-05-13 12:19 - 2017-04-28 01:56 - 00387584 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-05-13 12:19 - 2017-04-28 01:56 - 00311296 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll
2017-05-13 12:19 - 2017-04-28 01:56 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-05-13 12:19 - 2017-04-28 01:55 - 06042624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-05-13 12:19 - 2017-04-28 01:55 - 00431616 _____ (Microsoft Corporation) C:\Windows\system32\WpAXHolder.dll
2017-05-13 12:19 - 2017-04-28 01:54 - 02027008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-05-13 12:19 - 2017-04-28 01:54 - 01509376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-05-13 12:19 - 2017-04-28 01:54 - 00425984 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2017-05-13 12:19 - 2017-04-28 01:53 - 00579584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-05-13 12:19 - 2017-04-28 01:51 - 01589760 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll
2017-05-13 12:19 - 2017-04-28 01:50 - 00329728 _____ (Microsoft Corporation) C:\Windows\system32\fvecpl.dll
2017-05-13 12:19 - 2017-04-28 01:47 - 00796672 _____ (Microsoft Corporation) C:\Windows\system32\fvewiz.dll
2017-05-13 12:19 - 2017-04-28 01:45 - 23677440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-05-13 12:19 - 2017-04-28 01:44 - 13091328 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-05-13 12:19 - 2017-04-28 01:44 - 00937984 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2017-05-13 12:19 - 2017-04-28 01:43 - 01184256 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
2017-05-13 12:19 - 2017-04-28 01:43 - 00539136 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2017-05-13 12:19 - 2017-04-28 01:43 - 00467968 _____ (Microsoft Corporation) C:\Windows\system32\Geolocation.dll
2017-05-13 12:19 - 2017-04-28 01:42 - 08125440 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2017-05-13 12:19 - 2017-04-28 01:41 - 00759296 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-05-13 12:19 - 2017-04-28 01:40 - 04474368 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-05-13 12:19 - 2017-04-28 01:40 - 02096640 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-05-13 12:19 - 2017-04-28 01:40 - 01040896 _____ (Microsoft Corporation) C:\Windows\system32\NaturalLanguage6.dll
2017-05-13 12:19 - 2017-04-28 01:40 - 00913920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.dll
2017-05-13 12:19 - 2017-04-28 01:38 - 05611008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-05-13 12:19 - 2017-04-28 01:37 - 02895872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-05-13 12:19 - 2017-04-28 01:37 - 01783296 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-05-13 12:19 - 2017-04-28 01:37 - 01637888 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-05-13 12:19 - 2017-04-28 01:37 - 00875520 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll
2017-05-13 12:19 - 2017-04-28 01:36 - 01513472 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2017-05-13 12:19 - 2017-04-28 01:36 - 01328640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Http.dll
2017-05-13 12:19 - 2017-04-28 01:36 - 00774656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.dll
2017-05-13 12:19 - 2017-04-28 01:35 - 00924672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.dll
2017-05-13 12:19 - 2017-04-28 01:34 - 00439296 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe
2017-05-13 12:19 - 2017-04-28 01:34 - 00394240 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe
2017-05-13 12:19 - 2017-03-04 08:26 - 00261632 _____ (Microsoft Corporation) C:\Windows\system32\indexeddbserver.dll
2017-05-13 12:18 - 2017-04-28 02:57 - 00603488 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2017-05-13 12:18 - 2017-04-28 02:40 - 00026976 _____ (Microsoft Corporation) C:\Windows\system32\browser_broker.exe
2017-05-13 12:18 - 2017-04-28 02:38 - 02446704 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2017-05-13 12:18 - 2017-04-28 02:38 - 00431968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2017-05-13 12:18 - 2017-04-28 02:34 - 00241504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2017-05-13 12:18 - 2017-04-28 02:21 - 00073728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-05-13 12:18 - 2017-04-28 02:15 - 00822784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2017-05-13 12:18 - 2017-04-28 02:15 - 00126464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-05-13 12:18 - 2017-04-28 02:14 - 00306688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2017-05-13 12:18 - 2017-04-28 02:12 - 00635904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-05-13 12:18 - 2017-04-28 02:12 - 00236544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-05-13 12:18 - 2017-04-28 02:10 - 00661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll
2017-05-13 12:18 - 2017-04-28 02:05 - 01631232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-05-13 12:18 - 2017-04-28 02:03 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-05-13 12:18 - 2017-04-28 02:01 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2017-05-13 12:18 - 2017-04-28 02:01 - 00090624 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Printers.dll
2017-05-13 12:18 - 2017-04-28 02:00 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll
2017-05-13 12:18 - 2017-04-28 01:58 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2017-05-13 12:18 - 2017-04-28 01:58 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2017-05-13 12:18 - 2017-04-28 01:58 - 00144896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Lights.dll
2017-05-13 12:18 - 2017-04-28 01:57 - 00568320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.LowLevel.dll
2017-05-13 12:18 - 2017-04-28 01:57 - 00505856 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFiDirect.dll
2017-05-13 12:18 - 2017-04-28 01:57 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-05-13 12:18 - 2017-04-28 01:57 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\credprovhost.dll
2017-05-13 12:18 - 2017-04-28 01:57 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2017-05-13 12:18 - 2017-04-28 01:56 - 00912384 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.dll
2017-05-13 12:18 - 2017-04-28 01:56 - 00692224 _____ (Microsoft Corporation) C:\Windows\system32\CellularAPI.dll
2017-05-13 12:18 - 2017-04-28 01:56 - 00691200 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2017-05-13 12:18 - 2017-04-28 01:56 - 00379904 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll
2017-05-13 12:18 - 2017-04-28 01:55 - 02084352 _____ (Microsoft Corporation) C:\Windows\system32\DeviceFlows.DataModel.dll
2017-05-13 12:18 - 2017-04-28 01:55 - 00657920 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2017-05-13 12:18 - 2017-04-28 01:55 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\oleacc.dll
2017-05-13 12:18 - 2017-04-28 01:55 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Picker.dll
2017-05-13 12:18 - 2017-04-28 01:55 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll
2017-05-13 12:18 - 2017-04-28 01:54 - 03664384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-05-13 12:18 - 2017-04-28 01:54 - 00949248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.PointOfService.dll
2017-05-13 12:18 - 2017-04-28 01:54 - 00472064 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2017-05-13 12:18 - 2017-04-28 01:54 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\ConhostV2.dll
2017-05-13 12:18 - 2017-04-28 01:53 - 00458752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll
2017-05-13 12:18 - 2017-04-28 01:53 - 00437248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Usb.dll
2017-05-13 12:18 - 2017-04-28 01:51 - 02104320 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2017-05-13 12:18 - 2017-04-28 01:51 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Energy.dll
2017-05-13 12:18 - 2017-04-28 01:49 - 17198592 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2017-05-13 12:18 - 2017-04-28 01:49 - 01105408 _____ (Microsoft Corporation) C:\Windows\system32\MiracastReceiver.dll
2017-05-13 12:18 - 2017-04-28 01:49 - 00442368 _____ (Microsoft Corporation) C:\Windows\system32\PlayToDevice.dll
2017-05-13 12:18 - 2017-04-28 01:48 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\dlnashext.dll
2017-05-13 12:18 - 2017-04-28 01:48 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\dialclient.dll
2017-05-13 12:18 - 2017-04-28 01:47 - 01790464 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll
2017-05-13 12:18 - 2017-04-28 01:46 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\PlayToReceiver.dll
2017-05-13 12:18 - 2017-04-28 01:46 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\catsrvps.dll
2017-05-13 12:18 - 2017-04-28 01:45 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-05-13 12:18 - 2017-04-28 01:45 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\CameraCaptureUI.dll
2017-05-13 12:18 - 2017-04-28 01:44 - 04749824 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2017-05-13 12:18 - 2017-04-28 01:44 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2017-05-13 12:18 - 2017-04-28 01:44 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
2017-05-13 12:18 - 2017-04-28 01:43 - 00634368 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2017-05-13 12:18 - 2017-04-28 01:43 - 00320512 _____ (Microsoft Corporation) C:\Windows\system32\thumbcache.dll
2017-05-13 12:18 - 2017-04-28 01:42 - 01692160 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2017-05-13 12:18 - 2017-04-28 01:42 - 00945664 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2017-05-13 12:18 - 2017-04-28 01:42 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2017-05-13 12:18 - 2017-04-28 01:41 - 01359872 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2017-05-13 12:18 - 2017-04-28 01:41 - 00650752 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
2017-05-13 12:18 - 2017-04-28 01:41 - 00591360 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-05-13 12:18 - 2017-04-28 01:40 - 02914816 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll
2017-05-13 12:18 - 2017-04-28 01:40 - 02208768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Graphics.Printing.3D.dll
2017-05-13 12:18 - 2017-04-28 01:40 - 01586176 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll
2017-05-13 12:18 - 2017-04-28 01:40 - 00971264 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2017-05-13 12:18 - 2017-04-28 01:38 - 01275392 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
2017-05-13 12:18 - 2017-04-28 01:37 - 04744192 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-05-13 12:18 - 2017-04-28 01:37 - 02286592 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2017-05-13 12:18 - 2017-04-28 01:36 - 02691072 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2017-05-13 12:18 - 2017-04-28 01:36 - 02478080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-05-13 12:18 - 2017-04-28 01:36 - 01844224 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-05-13 12:18 - 2017-04-28 01:36 - 00735744 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2017-05-13 12:18 - 2017-04-28 01:35 - 01121280 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2017-05-13 12:17 - 2017-04-28 02:52 - 02255712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-05-13 12:17 - 2017-04-28 02:49 - 00764392 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2017-05-13 12:17 - 2017-04-28 02:46 - 00410464 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-05-13 12:17 - 2017-04-28 02:40 - 00578400 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2017-05-13 12:17 - 2017-04-28 02:39 - 00624048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-05-13 12:17 - 2017-04-28 02:38 - 02915704 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll
2017-05-13 12:17 - 2017-04-28 02:38 - 01852200 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-05-13 12:17 - 2017-04-28 02:38 - 01267512 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll
2017-05-13 12:17 - 2017-04-28 02:34 - 04674360 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-05-13 12:17 - 2017-04-28 02:34 - 01600624 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2017-05-13 12:17 - 2017-04-28 02:30 - 01569184 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll
2017-05-13 12:17 - 2017-04-28 02:19 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2017-05-13 12:17 - 2017-04-28 02:10 - 07216640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-05-13 12:17 - 2017-04-28 02:03 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2017-05-13 12:17 - 2017-04-28 02:01 - 00259072 _____ (Microsoft Corporation) C:\Windows\system32\Family.SyncEngine.dll
2017-05-13 12:17 - 2017-04-28 02:01 - 00156160 _____ (Microsoft Corporation) C:\Windows\system32\Family.Client.dll
2017-05-13 12:17 - 2017-04-28 02:00 - 00196096 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.dll
2017-05-13 12:17 - 2017-04-28 02:00 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.WiFi.dll
2017-05-13 12:17 - 2017-04-28 02:00 - 00101888 _____ (Microsoft Corporation) C:\Windows\system32\UserDeviceRegistration.Ngc.dll
2017-05-13 12:17 - 2017-04-28 01:59 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Radios.dll
2017-05-13 12:17 - 2017-04-28 01:58 - 00547840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Gaming.Input.dll
2017-05-13 12:17 - 2017-04-28 01:58 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll
2017-05-13 12:17 - 2017-04-28 01:57 - 00651264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.AllJoyn.dll
2017-05-13 12:17 - 2017-04-28 01:57 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2017-05-13 12:17 - 2017-04-28 01:56 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.Handlers.dll
2017-05-13 12:17 - 2017-04-28 01:56 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2017-05-13 12:17 - 2017-04-28 01:56 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-05-13 12:17 - 2017-04-28 01:55 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2017-05-13 12:17 - 2017-04-28 01:54 - 00329728 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll
2017-05-13 12:17 - 2017-04-28 01:54 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
2017-05-13 12:17 - 2017-04-28 01:51 - 01913856 _____ (Microsoft Corporation) C:\Windows\system32\wsp_fs.dll
2017-05-13 12:17 - 2017-04-28 01:51 - 01584128 _____ (Microsoft Corporation) C:\Windows\system32\wsp_health.dll
2017-05-13 12:17 - 2017-04-28 01:47 - 09131008 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-05-13 12:17 - 2017-04-28 01:47 - 03290112 _____ (Microsoft Corporation) C:\Windows\system32\mispace.dll
2017-05-13 12:17 - 2017-04-28 01:46 - 02861056 _____ (Microsoft Corporation) C:\Windows\system32\storagewmi.dll
2017-05-13 12:17 - 2017-04-28 01:45 - 00946688 _____ (Microsoft Corporation) C:\Windows\system32\wsp_sr.dll
2017-05-13 12:17 - 2017-04-28 01:45 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\uReFS.dll
2017-05-13 12:17 - 2017-04-28 01:45 - 00167936 _____ (Microsoft Corporation) C:\Windows\system32\ErrorDetails.dll
2017-05-13 12:17 - 2017-04-28 01:44 - 01010176 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2017-05-13 12:17 - 2017-04-28 01:44 - 00896512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.AccountsControl.dll
2017-05-13 12:17 - 2017-04-28 01:44 - 00139776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Devices.dll
2017-05-13 12:17 - 2017-04-28 01:43 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Midi.dll
2017-05-13 12:17 - 2017-04-28 01:42 - 01021440 _____ (Microsoft Corporation) C:\Windows\system32\usermgr.dll
2017-05-13 12:17 - 2017-04-28 01:41 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\CryptoWinRT.dll
2017-05-13 12:17 - 2017-04-28 01:40 - 02510848 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2017-05-13 12:17 - 2017-04-28 01:40 - 01643008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
2017-05-13 12:17 - 2017-04-28 01:38 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-05-13 12:17 - 2017-04-28 01:37 - 02316288 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-05-13 12:17 - 2017-04-28 01:37 - 02216960 _____ (Microsoft Corporation) C:\Windows\system32\OpcServices.dll
2017-05-13 12:17 - 2017-04-28 01:36 - 03613184 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2017-05-13 12:17 - 2017-04-28 01:36 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll
2017-05-13 12:17 - 2017-03-04 08:25 - 01060352 _____ (Microsoft Corporation) C:\Windows\system32\AppContracts.dll
2017-05-13 12:17 - 2016-12-21 09:09 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\OneBackupHandler.dll
2017-05-13 12:16 - 2017-04-28 02:49 - 00700936 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-05-13 12:16 - 2017-04-28 02:40 - 00146784 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostCommon.dll
2017-05-13 12:16 - 2017-04-28 02:01 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_ClosedCaptioning.dll
2017-05-13 12:16 - 2017-04-28 01:59 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll
2017-05-13 12:16 - 2017-04-28 01:47 - 00942080 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2017-05-13 12:16 - 2017-04-28 01:46 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\resutils.dll
2017-05-13 12:16 - 2017-04-28 01:41 - 00828416 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl
2017-05-13 12:16 - 2017-04-28 01:37 - 00881664 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2017-05-13 12:15 - 2017-04-28 02:56 - 01117024 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2017-05-13 12:15 - 2017-04-28 02:47 - 00699744 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2017-05-13 12:15 - 2017-04-28 02:47 - 00501088 _____ (Microsoft Corporation) C:\Windows\system32\spwizeng.dll
2017-05-13 12:15 - 2017-04-28 02:44 - 00062816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fsdepends.sys
2017-05-13 12:15 - 2017-04-28 02:42 - 00526176 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2017-05-13 12:15 - 2017-04-28 02:30 - 00322912 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2017-05-13 12:15 - 2017-04-28 02:28 - 00455520 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2017-05-13 12:15 - 2017-04-28 02:03 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\BthTelemetry.dll
2017-05-13 12:15 - 2017-04-28 02:02 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-05-13 12:15 - 2017-04-28 02:01 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\virtdisk.dll
2017-05-13 12:15 - 2017-04-28 02:00 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Profile.RetailInfo.dll
2017-05-13 12:15 - 2017-04-28 02:00 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\BluetoothApis.dll
2017-05-13 12:15 - 2017-04-28 02:00 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker.dll
2017-05-13 12:15 - 2017-04-28 01:59 - 00567296 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2017-05-13 12:15 - 2017-04-28 01:59 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-05-13 12:15 - 2017-04-28 01:58 - 00150016 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.AppDefaults.dll
2017-05-13 12:15 - 2017-04-28 01:58 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\ConsentUX.dll
2017-05-13 12:15 - 2017-04-28 01:57 - 00241152 _____ (Microsoft Corporation) C:\Windows\system32\dafBth.dll
2017-05-13 12:15 - 2017-04-28 01:57 - 00157184 _____ (Microsoft Corporation) C:\Windows\system32\bthserv.dll
2017-05-13 12:15 - 2017-04-28 01:56 - 00267264 _____ (Microsoft Corporation) C:\Windows\system32\vaultcli.dll
2017-05-13 12:15 - 2017-04-28 01:56 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\AuthBroker.dll
2017-05-13 12:15 - 2017-04-28 01:55 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\bthprops.cpl
2017-05-13 12:15 - 2017-04-28 01:50 - 01476608 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2017-05-13 12:15 - 2017-04-28 01:50 - 00380416 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll
2017-05-13 12:15 - 2017-04-28 01:50 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\adsnt.dll
2017-05-13 12:15 - 2017-04-28 01:48 - 00337920 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2017-05-13 12:15 - 2017-04-28 01:47 - 00649216 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe
2017-05-13 12:15 - 2017-04-28 01:46 - 01547264 _____ (Microsoft Corporation) C:\Windows\system32\wbengine.exe
2017-05-13 12:15 - 2017-04-28 01:46 - 01443328 _____ (Microsoft Corporation) C:\Windows\system32\VSSVC.exe
2017-05-13 12:15 - 2017-04-28 01:46 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\imapi2.dll
2017-05-13 12:15 - 2017-04-28 01:45 - 00130560 _____ (Microsoft Corporation) C:\Windows\system32\SpaceAgent.exe
2017-05-13 12:15 - 2017-04-28 01:43 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2017-05-13 12:15 - 2017-04-28 01:43 - 00560128 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll
2017-05-13 12:15 - 2017-04-28 01:41 - 00890368 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-05-13 12:15 - 2017-04-28 01:40 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll
2017-05-13 12:15 - 2017-04-28 01:40 - 00770560 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll
2017-05-13 12:15 - 2017-04-28 01:39 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2017-05-13 12:15 - 2017-04-28 01:34 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\spaceman.exe
2017-05-13 12:15 - 2017-04-28 01:33 - 01817088 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll
2017-05-13 12:09 - 2017-05-13 12:09 - 00000162 ____H C:\Users\Tomáš Kouba\Desktop\~$ deníík.odt
2017-05-13 10:41 - 2017-05-13 10:42 - 06751872 _____ (ESET spol. s r.o.) C:\Users\Tomáš Kouba\Downloads\esetonlinescanner_csy.exe
2017-05-13 10:10 - 2017-05-13 10:10 - 01663672 _____ (Malwarebytes) C:\Users\Tomáš Kouba\Downloads\JRT.exe
2017-05-11 20:41 - 2017-05-11 20:41 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2017-05-11 20:06 - 2017-05-13 11:35 - 00000000 ____D C:\Reerdition
2017-05-11 20:06 - 2017-05-11 20:08 - 00000000 ____D C:\Program Files\MK
2017-05-11 20:04 - 2017-05-11 20:04 - 00001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
2017-05-11 20:04 - 2017-05-11 20:04 - 00001028 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
2017-05-08 21:23 - 2017-05-13 17:48 - 00000000 ____D C:\Program Files (x86)\Tuationfoty Launcher
2017-05-08 21:23 - 2017-05-13 10:28 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Roaming\Ghegiward
2017-05-08 21:23 - 2017-05-11 20:06 - 00000000 ____D C:\Program Files (x86)\Reicoge
2017-05-08 21:23 - 2017-05-08 21:24 - 00000000 ____D C:\Users\Tom£レ Kouba\AppData\Local\Noherry
2017-05-08 21:23 - 2017-05-08 21:23 - 00006160 _____ C:\Windows\System32\Tasks\Tuationfoty Launcher
2017-05-08 21:23 - 2017-05-08 21:23 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Local\Noherry
2017-05-08 21:23 - 2017-05-08 21:23 - 00000000 ____D C:\Users\Tom£レ Kouba
2017-05-08 21:22 - 2017-05-08 21:24 - 00000000 ____D C:\Program Files\DAEMON Tools Lite
2017-05-08 21:22 - 2017-05-08 21:22 - 00001814 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2017-05-08 12:43 - 2017-05-14 10:29 - 00000000 ____D C:\AdwCleaner
2017-05-08 12:43 - 2017-05-08 12:43 - 04102600 _____ C:\Users\Tomáš Kouba\Downloads\adwcleaner_6.046.exe
2017-05-08 12:17 - 2017-05-08 20:51 - 00000000 ____D C:\Users\Tomáš Kouba\Downloads\G3969
2017-05-08 10:10 - 2017-05-08 10:16 - 00000022 _____ C:\Windows\GPU-Z.INI
2017-05-08 10:07 - 2017-05-08 10:07 - 00001085 _____ C:\Users\Public\Desktop\3DMark.lnk
2017-05-08 10:07 - 2017-05-08 10:07 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Local\Futuremark
2017-05-08 09:59 - 2017-05-08 10:18 - 00000000 ____D C:\Users\Tomáš Kouba\Documents\3DMark
2017-05-08 09:59 - 2017-05-08 09:59 - 00000000 ____D C:\Users\Tomáš Kouba\.oracle_jre_usage
2017-05-08 09:59 - 2017-05-08 09:59 - 00000000 ____D C:\ProgramData\Futuremark
2017-05-08 09:59 - 2017-05-08 09:59 - 00000000 ____D C:\Program Files\Futuremark
2017-05-08 09:58 - 2017-05-08 09:58 - 00000000 ____D C:\Program Files (x86)\Futuremark
2017-05-08 09:23 - 2017-05-08 09:23 - 01704136 _____ ( ) C:\Users\Tomáš Kouba\Downloads\cpu-z_1.79-en.exe
2017-05-08 09:23 - 2017-05-08 09:23 - 00000914 _____ C:\Users\Public\Desktop\CPUID CPU-Z.lnk
2017-05-08 09:23 - 2017-05-08 09:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2017-05-08 09:12 - 2017-05-08 09:42 - 00000000 ____D C:\Users\Tomáš Kouba\Downloads\G3843
2017-05-08 07:47 - 2017-05-08 09:48 - 3988072406 _____ C:\Users\Tomáš Kouba\Downloads\3DMark-v2-3-3693.zip
2017-05-08 07:34 - 2017-05-08 07:34 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\LocalLow\Reflect Studios
2017-05-08 07:31 - 2017-05-08 11:03 - 00000000 ____D C:\Program Files (x86)\Welcome to the Game
2017-05-07 21:22 - 2017-05-07 21:23 - 25239031 _____ C:\Users\Tomáš Kouba\Downloads\Max-Payne-Mobile-v1.0.apk
2017-05-07 20:56 - 2017-05-07 20:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-05-07 20:37 - 2017-05-15 16:14 - 00000000 ____D C:\GOG Games
2017-05-07 18:26 - 2017-05-08 12:16 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Local\Spotify
2017-05-07 18:26 - 2017-05-07 18:26 - 00001880 _____ C:\Users\Tomáš Kouba\Desktop\Spotify.lnk
2017-05-07 18:26 - 2017-05-07 18:26 - 00001866 _____ C:\Users\Tomáš Kouba\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2017-05-07 18:21 - 2017-05-13 10:01 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Roaming\Spotify
2017-05-07 18:21 - 2017-05-07 18:21 - 00278224 _____ (Spotify Ltd) C:\Users\Tomáš Kouba\Downloads\SpotifySetup.exe
2017-05-07 16:20 - 2017-05-07 20:24 - 00000000 ____D C:\Users\Tomáš Kouba\Downloads\G0785 V02
2017-05-07 16:11 - 2017-05-14 16:01 - 00000000 ____D C:\rsit
2017-05-07 16:11 - 2017-05-13 12:01 - 00000000 ____D C:\Program Files\trend micro
2017-05-07 16:11 - 2017-05-07 16:10 - 01222144 _____ C:\Users\Tomáš Kouba\Desktop\RSITx64.exe
2017-05-07 16:10 - 2017-05-07 16:10 - 01222144 _____ C:\Users\Tomáš Kouba\Downloads\RSITx64.exe
2017-04-30 11:16 - 2017-05-08 15:31 - 00005833 _____ C:\Users\Tomáš Kouba\Desktop\ČT deníík.odt
2017-04-23 11:55 - 2017-03-28 09:10 - 00315744 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-23 11:55 - 2017-03-28 08:21 - 00167848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll
2017-04-23 11:55 - 2017-03-28 08:04 - 00277344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2017-04-23 11:55 - 2017-03-28 08:04 - 00136032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudExperienceHostUser.dll
2017-04-23 11:55 - 2017-03-28 08:02 - 00576408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-04-23 11:55 - 2017-03-28 07:58 - 01344448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2017-04-23 11:55 - 2017-03-28 07:53 - 00545944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2017-04-23 11:55 - 2017-03-28 07:52 - 00306800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.MediaControl.dll
2017-04-23 11:55 - 2017-03-28 07:42 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usoapi.dll
2017-04-23 11:55 - 2017-03-28 07:40 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XblAuthManagerProxy.dll
2017-04-23 11:55 - 2017-03-28 07:40 - 00037376 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-23 11:55 - 2017-03-28 07:39 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerUI.dll
2017-04-23 11:55 - 2017-03-28 07:38 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XblAuthTokenBrokerExt.dll
2017-04-23 11:55 - 2017-03-28 07:37 - 00215552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apds.dll
2017-04-23 11:55 - 2017-03-28 07:37 - 00177664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll
2017-04-23 11:55 - 2017-03-28 07:37 - 00123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.HostName.dll
2017-04-23 11:55 - 2017-03-28 07:37 - 00097792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.SystemManagement.dll
2017-04-23 11:55 - 2017-03-28 07:37 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BasicRender.sys
2017-04-23 11:55 - 2017-03-28 07:36 - 00769024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ipsecsnp.dll
2017-04-23 11:55 - 2017-03-28 07:36 - 00237568 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Diagnostics.dll
2017-04-23 11:55 - 2017-03-28 07:36 - 00129024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.SerialCommunication.dll
2017-04-23 11:55 - 2017-03-28 07:36 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-23 11:55 - 2017-03-28 07:36 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.UserDeviceAssociation.dll
2017-04-23 11:55 - 2017-03-28 07:36 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BasicDisplay.sys
2017-04-23 11:55 - 2017-03-28 07:35 - 00505856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
2017-04-23 11:55 - 2017-03-28 07:35 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-04-23 11:55 - 2017-03-28 07:33 - 00609280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
2017-04-23 11:55 - 2017-03-28 07:33 - 00436736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ipsmsnap.dll
2017-04-23 11:55 - 2017-03-28 07:31 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-23 11:55 - 2017-03-28 07:31 - 00390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2017-04-23 11:55 - 2017-03-28 07:30 - 00787968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sbe.dll
2017-04-23 11:55 - 2017-03-28 07:28 - 00755712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-04-23 11:55 - 2017-03-28 07:28 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2017-04-23 11:55 - 2017-03-28 07:26 - 00642048 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.InkControls.dll
2017-04-23 11:55 - 2017-03-28 07:26 - 00468992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.InkControls.dll
2017-04-23 11:55 - 2017-03-28 07:26 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2017-04-23 11:55 - 2017-03-28 07:25 - 01196544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl
2017-04-23 11:55 - 2017-03-28 07:24 - 06474752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspaint.exe
2017-04-23 11:55 - 2017-03-28 07:23 - 00395264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmenrollengine.dll
2017-04-23 11:55 - 2017-03-28 07:22 - 00516096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlidcli.dll
2017-04-23 11:55 - 2017-03-28 07:22 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\enrollmentapi.dll
2017-04-23 11:55 - 2017-03-28 07:20 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-23 11:55 - 2017-03-28 07:19 - 07655424 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2017-04-23 11:55 - 2017-03-28 07:19 - 00746496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdtcprx.dll
2017-04-23 11:55 - 2017-03-28 07:17 - 06109696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2017-04-23 11:55 - 2017-03-28 07:16 - 03198464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll
2017-04-23 11:55 - 2017-03-28 07:13 - 02138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll
2017-04-23 11:55 - 2017-03-28 07:13 - 00079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-23 11:55 - 2017-03-28 07:12 - 02682880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll
2017-04-23 11:55 - 2017-03-28 07:12 - 00862208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2017-04-23 11:55 - 2017-03-28 07:12 - 00542208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2017-04-23 11:55 - 2017-03-28 07:11 - 01576448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2017-04-23 11:55 - 2017-03-28 07:08 - 01564160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-23 11:55 - 2017-03-28 07:08 - 00299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RADCUI.dll
2017-04-23 11:55 - 2017-03-16 06:38 - 00034088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CompPkgSup.dll
2017-04-23 11:54 - 2017-03-28 08:32 - 00198856 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll
2017-04-23 11:54 - 2017-03-28 08:26 - 00218520 _____ (Microsoft Corporation) C:\Windows\system32\LsaIso.exe
2017-04-23 11:54 - 2017-03-28 08:20 - 01181024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2017-04-23 11:54 - 2017-03-28 08:11 - 00360040 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe
2017-04-23 11:54 - 2017-03-28 08:09 - 00097128 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Credentials.UI.CredentialPicker.dll
2017-04-23 11:54 - 2017-03-28 08:05 - 01848584 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2017-04-23 11:54 - 2017-03-28 07:59 - 02533728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-04-23 11:54 - 2017-03-28 07:37 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
2017-04-23 11:54 - 2017-03-28 07:35 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2017-04-23 11:54 - 2017-03-28 07:31 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\NetworkBindingEngineMigPlugin.dll
2017-04-23 11:54 - 2017-03-28 07:14 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\MSVP9DEC.dll
2017-04-23 11:53 - 2017-03-28 07:36 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\RdpRelayTransport.dll
2017-04-23 11:53 - 2017-03-28 07:34 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-04-23 11:53 - 2017-03-28 07:27 - 00441856 _____ (Microsoft Corporation) C:\Windows\system32\AccountsRt.dll
2017-04-23 11:53 - 2017-03-28 07:24 - 01220096 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl
2017-04-23 11:53 - 2017-03-28 07:23 - 00932864 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-04-23 11:53 - 2017-03-28 07:22 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-04-23 11:53 - 2017-03-28 07:18 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\wpninprc.dll
2017-04-23 11:53 - 2017-03-28 07:14 - 00975872 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-04-23 11:53 - 2017-03-28 07:05 - 01633792 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-04-23 11:52 - 2017-03-28 08:36 - 01617760 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-04-23 11:52 - 2017-03-28 08:36 - 01294688 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-04-23 11:52 - 2017-03-28 08:36 - 00565088 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-04-23 11:52 - 2017-03-28 08:36 - 00343904 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-04-23 11:52 - 2017-03-28 08:36 - 00142176 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-04-23 11:52 - 2017-03-28 08:35 - 00379232 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-04-23 11:52 - 2017-03-28 08:10 - 00178528 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostUser.dll
2017-04-23 11:52 - 2017-03-28 08:09 - 00682816 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-04-23 11:52 - 2017-03-28 08:08 - 01100128 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2017-04-23 11:52 - 2017-03-28 08:08 - 00989024 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2017-04-23 11:52 - 2017-03-28 08:04 - 00160088 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHostBroker.dll
2017-04-23 11:52 - 2017-03-28 08:00 - 00628552 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2017-04-23 11:52 - 2017-03-28 07:58 - 00372440 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.MediaControl.dll
2017-04-23 11:52 - 2017-03-28 07:37 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthManagerProxy.dll
2017-04-23 11:52 - 2017-03-28 07:37 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\DdcWnsListener.dll
2017-04-23 11:52 - 2017-03-28 07:36 - 00045056 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-04-23 11:52 - 2017-03-28 07:35 - 00124416 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.SystemManagement.dll
2017-04-23 11:52 - 2017-03-28 07:34 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe
2017-04-23 11:52 - 2017-03-28 07:34 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\XblAuthTokenBrokerExt.dll
2017-04-23 11:52 - 2017-03-28 07:33 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\DeviceDirectoryClient.dll
2017-04-23 11:52 - 2017-03-28 07:33 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.UserDeviceAssociation.dll
2017-04-23 11:52 - 2017-03-28 07:31 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SmartCards.Phone.dll
2017-04-23 11:52 - 2017-03-28 07:31 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\CloudDomainJoinDataModelServer.dll
2017-04-23 11:52 - 2017-03-28 07:31 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.SerialCommunication.dll
2017-04-23 11:52 - 2017-03-28 07:30 - 00239104 _____ (Microsoft Corporation) C:\Windows\system32\dafpos.dll
2017-04-23 11:52 - 2017-03-28 07:30 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerUI.dll
2017-04-23 11:52 - 2017-03-28 07:29 - 00852480 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Import.dll
2017-04-23 11:52 - 2017-03-28 07:29 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2017-04-23 11:52 - 2017-03-28 07:27 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2017-04-23 11:52 - 2017-03-28 07:25 - 00966144 _____ (Microsoft Corporation) C:\Windows\system32\sbe.dll
2017-04-23 11:52 - 2017-03-28 07:24 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2017-04-23 11:52 - 2017-03-28 07:21 - 00104960 _____ (Microsoft Corporation) C:\Windows\system32\CastLaunch.dll
2017-04-23 11:52 - 2017-03-28 07:20 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-04-23 11:52 - 2017-03-28 07:19 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\flvprophandler.dll
2017-04-23 11:52 - 2017-03-28 07:17 - 05114368 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll
2017-04-23 11:52 - 2017-03-28 07:16 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\vss_ps.dll
2017-04-23 11:52 - 2017-03-28 07:15 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll
2017-04-23 11:52 - 2017-03-28 07:14 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-23 11:52 - 2017-03-28 07:14 - 00089088 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-04-23 11:52 - 2017-03-28 07:10 - 01231872 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2017-04-23 11:52 - 2017-03-28 07:09 - 01064448 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2017-04-23 11:52 - 2017-03-28 07:08 - 03542016 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2017-04-23 11:52 - 2017-03-28 07:08 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\enrollmentapi.dll
2017-04-23 11:52 - 2017-03-28 07:07 - 00908800 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2017-04-23 11:52 - 2017-03-28 07:07 - 00701952 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll
2017-04-23 11:52 - 2017-03-28 07:07 - 00122368 _____ (Microsoft Corporation) C:\Windows\system32\FontProvider.dll
2017-04-23 11:52 - 2017-03-18 18:50 - 00956416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2017-04-23 11:52 - 2017-03-18 18:35 - 02278400 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2017-04-23 11:52 - 2017-03-16 06:47 - 00038768 _____ (Microsoft Corporation) C:\Windows\system32\CompPkgSup.dll
2017-04-22 17:03 - 2017-04-29 10:54 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2017-04-22 17:03 - 2017-04-22 17:03 - 03086696 _____ C:\Users\Tomáš Kouba\Downloads\instspeedfan452.exe
2017-04-22 17:03 - 2017-04-22 17:03 - 00000045 _____ C:\Windows\SysWOW64\initdebug.nfo
2017-04-21 22:22 - 2017-05-15 15:39 - 00004222 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{AC7F0182-8288-4B6F-AB27-6E25733BDCA1}
2017-04-17 20:58 - 2017-04-17 20:58 - 00251840 _____ (Malwarebytes) C:\Windows\system32\Drivers\47D63ED4.sys
2017-04-17 14:52 - 2017-04-17 14:52 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Roaming\HP_Easy_Start
2017-04-17 14:52 - 2017-04-17 14:52 - 00000000 ____D C:\ProgramData\HP
2017-04-17 14:51 - 2017-04-17 14:51 - 05618000 _____ C:\Users\Tomáš Kouba\Downloads\HPEasyStart_5_0_3133_35.exe
2017-04-17 11:56 - 2017-04-17 11:56 - 07614370 _____ C:\Users\Tomáš Kouba\Downloads\dTest-04---2017.pdf
2017-04-16 17:17 - 2017-04-16 17:17 - 00251840 _____ (Malwarebytes) C:\Windows\system32\Drivers\40B147AA.sys
2017-04-15 13:35 - 2017-04-15 14:29 - 1426079794 _____ C:\Users\Tomáš Kouba\Downloads\NOOBS_v2_4_0 (1).zip
2017-04-15 13:18 - 2017-04-15 13:18 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Local\Downloaded Installations

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-15 16:42 - 2017-01-22 13:53 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Roaming\Skype
2017-05-15 16:16 - 2017-01-25 12:56 - 00000000 ____D C:\ProgramData\MFAData
2017-05-15 16:04 - 2017-01-17 18:14 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-05-15 15:41 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\AppReadiness
2017-05-15 15:38 - 2016-07-16 08:04 - 00032768 _____ C:\Windows\system32\config\ELAM
2017-05-15 15:35 - 2017-01-17 20:14 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-05-15 15:35 - 2017-01-17 20:14 - 00000000 __SHD C:\Users\Tomáš Kouba\IntelGraphicsProfiles
2017-05-14 16:05 - 2017-01-29 21:01 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Local\Google
2017-05-14 15:25 - 2017-01-25 12:56 - 00003668 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-05-14 15:17 - 2017-01-17 18:24 - 02139594 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-14 15:17 - 2016-07-17 00:25 - 00794346 _____ C:\Windows\system32\perfh005.dat
2017-05-14 15:17 - 2016-07-17 00:25 - 00186346 _____ C:\Windows\system32\perfc005.dat
2017-05-14 10:30 - 2017-01-17 18:15 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-14 10:29 - 2017-01-17 18:35 - 00000000 ____D C:\Users\Tomáš Kouba
2017-05-14 10:29 - 2016-07-16 08:04 - 00524288 _____ C:\Windows\system32\config\BBI
2017-05-13 17:51 - 2017-01-17 18:35 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-05-13 17:49 - 2016-07-16 13:45 - 00000000 ____D C:\Windows\INF
2017-05-13 17:48 - 2017-01-17 18:14 - 00340760 _____ C:\Windows\system32\FNTCACHE.DAT
2017-05-13 17:46 - 2016-07-16 13:47 - 00000000 ___SD C:\Windows\SysWOW64\F12
2017-05-13 17:46 - 2016-07-16 13:47 - 00000000 ___SD C:\Windows\system32\F12
2017-05-13 17:46 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2017-05-13 17:46 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\system32\oobe
2017-05-13 17:46 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\system32\appraiser
2017-05-13 17:46 - 2016-07-16 08:04 - 00000000 ____D C:\Windows\SysWOW64\Dism
2017-05-13 17:45 - 2016-07-16 13:47 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2017-05-13 17:45 - 2016-07-16 13:47 - 00000000 ___RD C:\Program Files\Windows Defender
2017-05-13 17:45 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\ShellExperiences
2017-05-13 17:45 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\Provisioning
2017-05-13 17:45 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-05-13 17:45 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-05-13 17:45 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-05-13 17:45 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-05-13 13:17 - 2016-07-16 13:36 - 00000000 ____D C:\Windows\CbsTemp
2017-05-13 12:51 - 2016-07-16 13:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-13 10:37 - 2017-01-30 21:07 - 00000000 ____D C:\ProgramData\TEMP
2017-05-13 10:32 - 2016-07-16 13:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-13 10:23 - 2017-01-25 15:45 - 00000000 ____D C:\Program Files\Microsoft Office
2017-05-13 10:07 - 2017-02-01 18:25 - 00000000 ____D C:\Program Files (x86)\Steam
2017-05-11 20:41 - 2016-07-16 13:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-05-11 20:32 - 2016-07-16 13:42 - 00073728 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2017-05-11 20:06 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-05-11 20:06 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\system32\Macromed
2017-05-11 20:05 - 2017-01-25 12:14 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-05-08 21:22 - 2017-01-25 12:39 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2017-05-08 21:00 - 2017-01-27 13:42 - 00000000 ____D C:\Users\Tomáa Kouba\AppData\Local\JDownloader v2.0
2017-05-08 10:14 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\system32\NDF
2017-05-08 10:07 - 2017-01-17 20:04 - 00000000 ____D C:\ProgramData\Package Cache
2017-05-08 08:10 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\rescache
2017-05-07 20:56 - 2017-02-01 16:58 - 00000000 ____D C:\Users\Tomáš Kouba\Documents\My Games
2017-05-07 18:16 - 2017-02-01 15:59 - 00000000 ____D C:\Program Files (x86)\Fallout 3 Game of the Year Edition
2017-05-07 16:24 - 2017-01-17 18:35 - 00000000 ____D C:\Users\Tomáš Kouba\AppData\Local\Packages
2017-05-07 15:55 - 2017-01-25 18:30 - 00004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-04-30 14:44 - 2017-01-29 21:01 - 00003470 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-30 14:44 - 2017-01-29 21:01 - 00003346 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-29 10:52 - 2017-01-30 14:51 - 2147483648 _____ C:\Users\Tomáš Kouba\Desktop\Akta Twix.avgfv
2017-04-29 10:52 - 2017-01-30 14:51 - 00000582 _____ C:\Users\Tomáš Kouba\Desktop\Akta Twix.lnk
2017-04-29 02:59 - 2016-07-16 13:49 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-04-29 02:59 - 2016-07-16 13:49 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-04-28 03:01 - 2017-01-17 18:22 - 02717184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2017-04-23 20:08 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\SysWOW64\setup
2017-04-23 20:07 - 2016-07-16 13:47 - 00000000 ____D C:\Windows\system32\setup
2017-04-23 20:07 - 2016-07-16 08:04 - 00000000 ____D C:\Windows\system32\Dism
2017-04-23 09:42 - 2017-01-25 12:58 - 00001009 _____ C:\Users\Public\Desktop\AVG Protection.lnk
2017-04-23 09:42 - 2017-01-25 12:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-04-22 17:26 - 2017-02-11 14:46 - 00000000 ____D C:\Users\Tomáš Kouba\Desktop\Výstřižky
2017-04-17 14:54 - 2017-01-29 21:04 - 00000000 ___RD C:\Users\Tomáš Kouba\Disk Google
2017-04-15 13:24 - 2017-01-25 17:13 - 00000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2017-04-15 11:52 - 2017-01-25 18:29 - 00002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2017-04-15 11:52 - 2017-01-25 18:29 - 00002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2017-04-15 10:42 - 2017-01-28 11:16 - 00004470 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

Some files in TEMP:
====================
2017-05-08 21:20 - 2017-05-08 21:20 - 0694744 _____ (Disc Soft Ltd.) C:\Users\Tomáš Kouba\AppData\Local\Temp\DAEMON Tools Lite.exe
2017-05-08 20:59 - 2017-05-08 20:59 - 0040448 ____N () C:\Users\Tomáš Kouba\AppData\Local\Temp\proxy_vole2673823651997685212.dll
2017-05-08 09:10 - 2017-05-08 09:10 - 0040448 ____N () C:\Users\Tomáš Kouba\AppData\Local\Temp\proxy_vole4167280209536320301.dll
2017-05-08 20:59 - 2017-05-08 20:59 - 0040448 ____N () C:\Users\Tomáš Kouba\AppData\Local\Temp\proxy_vole5572303181851255918.dll
2017-05-08 09:09 - 2017-05-08 09:09 - 0040448 ____N () C:\Users\Tomáš Kouba\AppData\Local\Temp\proxy_vole67465842072003963.dll
2017-05-08 20:59 - 2017-05-08 20:59 - 0040448 ____N () C:\Users\Tomáš Kouba\AppData\Local\Temp\proxy_vole7179675214572321285.dll
2017-04-22 17:05 - 2017-04-22 17:05 - 0192512 _____ () C:\Users\Tomáš Kouba\AppData\Local\Temp\sfamcc00001.dll
2017-04-22 17:05 - 2017-04-22 17:05 - 0158720 _____ () C:\Users\Tomáš Kouba\AppData\Local\Temp\sfareca00001.dll
2015-02-10 19:56 - 2015-02-10 19:56 - 0105984 _____ () C:\Users\Tomáš Kouba\AppData\Local\Temp\sfextra.dll
2017-02-17 12:47 - 2016-11-10 16:35 - 1174552 _____ (proDAD GmbH) C:\Users\Tomáš Kouba\AppData\Local\Temp\uninstall.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-05-13 13:58

==================== End of FRST.txt ============================

Re: Malware jménem Initial Page 123

Napsal: 15 kvě 2017 15:50
od cunik.cz
A zde je ještě něco dalšího

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-05-2017
Ran by Tomáš Kouba (15-05-2017 16:45:05)
Running from C:\Users\Tomáš Kouba\Downloads
Windows 10 Home Version 1607 (X64) (2017-01-17 16:33:46)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-725424127-4130822466-1493971447-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-725424127-4130822466-1493971447-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-725424127-4130822466-1493971447-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-725424127-4130822466-1493971447-501 - Limited - Disabled)
Tomáš Kouba (S-1-5-21-725424127-4130822466-1493971447-1001 - Administrator - Enabled) => C:\Users\Tomáš Kouba

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Internet Security (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Internet Security (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
FW: AVG Internet Security (Enabled) {757AB44A-78C2-7D1A-E37F-CA42A037B368}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

3DMark (HKLM-x32\...\{39f8dcb1-5f2e-4057-980e-f463756a0465}) (Version: 2.3.3693.0 - Futuremark)
3DMark (Version: 2.3.3693.0 - Futuremark) Hidden
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.171 - Adobe Systems Incorporated)
Artipic (HKLM-x32\...\{C8A6CFF8-9D80-4C6C-B490-805AD9F2906B}}_is1) (Version: 2.4.1.11 - Artipic AB)
Ashampoo Burning Studio 2017 (HKLM-x32\...\{91B33C97-C878-6579-69BA-23E5405C7AAB}_is1) (Version: 18.0.0 - Ashampoo GmbH & Co. KG)
AVG (Version: 16.151.8013 - AVG Technologies) Hidden
AVG 2016 (Version: 16.0.4776 - AVG Technologies) Hidden
AVG Protection (HKLM\...\AVG) (Version: 2016.151.8013 - AVG Technologies)
Broadcom 802.11 Network Adapter (HKLM\...\Broadcom 802.11 Network Adapter) (Version: 7.35.333.0 - Broadcom Corporation)
CPUID CPU-Z 1.79 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
CyberLink PowerDirector 14 (HKLM-x32\...\{6BADCD73-E925-46F7-A295-FF2448632728}) (Version: 14.0.2820.0 - CyberLink Corp.)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.5.1.0230 - Disc Soft Ltd)
Dead Space (HKLM-x32\...\1312818781_is1) (Version: 2.0.0.2 - GOG.com)
EaseUS Todo Backup Home 9.2 (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 9.2 - CHENGDU YIWO Tech Development Co., Ltd)
FMW 1 (Version: 1.143.3 - AVG Technologies) Hidden
Futuremark SystemInfo (HKLM-x32\...\{6583B359-134F-480D-9B31-9B94EFFAFE40}) (Version: 5.0.609.0 - Futuremark)
Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.)
Google Earth (HKLM-x32\...\{F6430171-B86B-4639-839E-374913E7911D}) (Version: 7.1.8.3036 - Google)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
Hard Disk Sentinel PRO (HKLM-x32\...\Hard Disk Sentinel_is1) (Version: - HDS)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4549 - Intel Corporation)
Intel® Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
JetDrive (HKLM-x32\...\{D54572D5-2BD4-40AF-A956-25B4BEA7868E}}_is1) (Version: 9 - Abelssoft)
Kodi (HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Kodi) (Version: - XBMC-Foundation)
Malwarebytes Anti-Malware versione 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProplusRetail - cs-cz) (Version: 16.0.8067.2102 - Microsoft Corporation)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProplusRetail - en-us) (Version: 16.0.8067.2102 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\OneDriveSetup.exe) (Version: 17.3.6798.0207 - Microsoft Corporation)
Microsoft Project Professional 2016 - cs-cz (HKLM\...\ProjectProRetail - cs-cz) (Version: 16.0.8067.2102 - Microsoft Corporation)
Microsoft Project Professional 2016 - en-us (HKLM\...\ProjectProRetail - en-us) (Version: 16.0.8067.2102 - Microsoft Corporation)
Microsoft Visio Professional 2016 - cs-cz (HKLM\...\VisioProRetail - cs-cz) (Version: 16.0.8067.2102 - Microsoft Corporation)
Microsoft Visio Professional 2016 - en-us (HKLM\...\VisioProRetail - en-us) (Version: 16.0.8067.2102 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Thunderbird 45.8.0 (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 45.8.0 (x86 cs)) (Version: 45.8.0 - Mozilla)
Office 16 Click-to-Run Extensibility Component (Version: 16.0.8067.2102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.8067.2102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (Version: 16.0.8067.2070 - Microsoft Corporation) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7944 - Realtek Semiconductor Corp.)
Skype™ 7.31 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.31.104 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\Spotify) (Version: 1.0.53.758.gde3fc4b2 - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.2.4.10 - Synaptics Incorporated)
TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.77242 - TeamViewer)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.0a - Ghisler Software GmbH)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
Your Uninstaller! 7 (HKLM-x32\...\YU2010_is1) (Version: 7.5.2014.3 - URSoft, Inc.)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3DFFBEBE-3441-4EB3-9B01-4CB7003F1E8F} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-03] (Microsoft Corporation)
Task: {4880D321-CBEA-4721-A74A-EDCDB1B3CA2D} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {6AA174DC-0ED9-47AC-BD03-17C0CD1D74CD} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {730759B3-6F5F-4658-80EB-47D2E431F259} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-05-11] ()
Task: {7EB91B96-5E53-45A7-8316-3F360DD6632D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-29] (Google Inc.)
Task: {89388AE2-A274-42B9-B743-92C3DAE05693} - \Microsoft\Windows\DeviceSettings\Perotviguse -> No File <==== ATTENTION
Task: {93A2B7E3-B719-466C-B5A2-C6F23E31173A} - System32\Tasks\ABRC_RegularCheck => C:/Program Files (x86)/RegistryCleaner/RegistryCleaner.exe
Task: {9E6A75C3-2C58-4578-A8C4-90ED6B0DDEA8} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_Tom_E1_9A_20Kouba => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [2017-01-25] (H.D.S. Hungary)
Task: {AD381EEA-D9DB-4F41-A956-754623B7F230} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-03] (Microsoft Corporation)
Task: {AE599621-A4EB-445D-95CB-167D939673A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-29] (Google Inc.)
Task: {B4F02224-DEB2-4328-8021-C136DD6CD1D0} - System32\Tasks\Tuationfoty Launcher => C:\Program Files (x86)\Reicoge\dpach.exe
Task: {B9B4DA41-3DEF-4BA8-A57A-99FC9161865E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-05-13] (Microsoft Corporation)
Task: {CEEEEF57-8756-44D6-AAC7-17D48D55AE3F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files\Microsoft Office\root\Office16\msoia.exe [2017-05-13] (Microsoft Corporation)
Task: {E8A286B4-6BC5-4104-879C-FBA2A5727CE3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-05-11] (Adobe Systems Incorporated)
Task: {EABD432A-5972-4114-B8D9-2DA57C876922} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-05-11] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2016-07-16 13:42 - 2016-07-16 13:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll
2017-05-13 12:19 - 2017-04-28 02:49 - 02681200 _____ () C:\Windows\System32\CoreUIComponents.dll
2017-05-13 12:19 - 2017-04-28 02:49 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll
2017-05-13 12:19 - 2017-04-28 02:49 - 02681200 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll
2017-01-17 21:04 - 2016-09-07 06:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-19 10:24 - 2017-03-04 08:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-01-30 16:44 - 2016-06-03 13:15 - 00278720 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
2017-05-11 20:16 - 2017-05-11 20:19 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-05-11 20:16 - 2017-05-11 20:19 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.15.597.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-03-19 10:24 - 2017-03-04 08:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-19 10:24 - 2017-03-04 08:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-19 10:24 - 2017-03-04 08:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-05-13 12:19 - 2017-04-28 01:36 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-05-13 12:19 - 2017-04-28 01:37 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00080936 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CodeLog.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00017448 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CompressFile.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00088616 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBGetRemoteNetInfo.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 01296424 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\libxml2.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00060968 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\zlib1.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00024768 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CmcTbProxy.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00188608 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCPipeCenter.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00173760 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCAdapt.dll
2017-01-30 16:44 - 2016-06-03 13:13 - 00056512 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBInfo.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00018112 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CMCNetTokenProxy.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00128192 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActivationOnline.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00485416 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EULicenseDLL.DLL
2017-01-30 16:44 - 2016-06-03 13:13 - 00085184 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\logsys.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00030760 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DiskSearchImg.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00068136 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\MountImg.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00158248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ImgFile.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00281128 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DsImgFile.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00072232 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CheckImg.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00139816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\vhdvmdk.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00040128 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\BootDriver.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00769064 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ExImage.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00193064 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBackupSize.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00443944 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidImage.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00148008 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumDisk.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00207912 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSLib.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00076840 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FatLib.dll
2017-01-30 16:44 - 2016-06-03 13:13 - 00114880 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FileStorage.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00169512 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CloudInterface.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00501800 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\StorageMgr.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00024616 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\GetDriverInfo.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00020520 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CorrectMbr.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00032296 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumTapeDevice.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00034856 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbTapeBrowse.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00064040 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\RegLib.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00026816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AccountManager.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00059944 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NasOperator.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00220864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBrowser.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00077864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CloudOperator.dll
2017-01-30 16:44 - 2016-06-03 13:12 - 00021184 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActiveOnline.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00136232 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\VMConfig.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00020008 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidDeviceManager.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00043048 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbDataSwap.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00353832 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DeviceManager.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00027176 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DeviceAdapter.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00138792 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\Device.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00146984 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\Partition.dll
2017-01-30 16:44 - 2016-04-13 17:49 - 00432320 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\uexper.dll
2017-01-30 16:44 - 2015-12-10 07:04 - 00224808 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SmartBackup.dll
2017-01-26 22:44 - 2017-01-26 22:43 - 48920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2017-04-05 02:38 - 2017-04-05 02:38 - 69743184 _____ () C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AcroCEF\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:1CE11B51 [152]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-01-25 18:19 - 2017-02-18 10:45 - 00005470 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com
127.0.0.1 na1r.services.adobe.com
127.0.0.1 hlrcv.stage.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 activate.adobe.com
0.0.0.0 a.ads1.msn.com
0.0.0.0 a.ads2.msads.net
0.0.0.0 a.ads2.msn.com
0.0.0.0 a.rad.msn.com
0.0.0.0 a-0001.a-msedge.net
0.0.0.0 a-0002.a-msedge.net
0.0.0.0 a-0003.a-msedge.net
0.0.0.0 a-0004.a-msedge.net
0.0.0.0 a-0005.a-msedge.net
0.0.0.0 a-0006.a-msedge.net
0.0.0.0 a-0007.a-msedge.net
0.0.0.0 a-0008.a-msedge.net
0.0.0.0 a-0009.a-msedge.net
0.0.0.0 ac3.msn.com
0.0.0.0 ad.doubleclick.net
0.0.0.0 adnexus.net
0.0.0.0 adnxs.com
0.0.0.0 ads.msn.com
0.0.0.0 ads1.msads.net
0.0.0.0 ads1.msn.com
0.0.0.0 aidps.atdmt.com
0.0.0.0 aka-cdn-ns.adtech.de
0.0.0.0 a-msedge.net
0.0.0.0 apps.skype.com

There are 96 more lines.


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-725424127-4130822466-1493971447-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img2.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\StartupApproved\Run: => "GoogleDriveSync"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\StartupApproved\Run: => "download.ninja"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\StartupApproved\Run: => "Spotify"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{A07832B6-A5AB-4D5D-ADAD-72F46C9D10AB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D869BEBC-CBE9-45E7-AFF0-395F07E149CE}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{64BDE352-D656-4E09-ABB8-D86884272E3C}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{76E30064-6781-4AF0-B478-F5C48FE8B22B}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{996DD2A5-B818-4F41-87A5-DEE86DB6EEB6}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
FirewallRules: [{F205F9F8-FD1C-4DF0-A767-E80CB680E21D}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
FirewallRules: [{0CDDEB3A-B1BD-4423-994F-49DA3C122C44}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
FirewallRules: [{B9787DB2-BA37-4CD6-9EFE-061CB2421E7A}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
FirewallRules: [{C17C5AF8-1948-4F55-AFCA-1FE8C8DC5C2F}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{494DB2C2-7BE8-4911-9DB9-DA88FC8130D8}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{60E6D465-398E-4850-BE86-7EF7620A2377}] => (Block) C:\windows\system32\svchost.exe
FirewallRules: [{2765E0F4-2918-4A46-B9C9-43CDD8FCBA2B}] => (Block) C:\windows\systemapps\microsoft.windows.cortana_cw5n1h2txyewy\searchui.exe
FirewallRules: [{83F78990-10A0-4A4D-B52A-8CA56D5F80A4}] => (Block) C:\Windows\explorer.exe
FirewallRules: [{0167CB73-E2D1-4E3E-97D8-C823B2C98127}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{39FE755A-6342-440E-B02E-14FDB73453C6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{BFEAF2C0-9A61-4CC0-90BE-25657EBA88C3}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{4674ED84-9439-4575-9A81-D25100248F4F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{18DD034F-063B-4901-8974-F407E1D9B9E7}] => (Allow) C:\Program Files (x86)\PowerDirector14\PDR10.EXE
FirewallRules: [TCP Query User{6683A6D0-FDB2-4C6C-81FE-829233E13D81}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{0816B588-B5C9-422B-814F-DEDD884C9901}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{2AD7CC47-9EE8-4CF3-81FC-9B310D5D83F7}] => (Allow) C:\Users\Tomáš Kouba\AppData\Local\Temp\7zS25FD\HP.EasyStart.exe
FirewallRules: [{8634E459-1E3D-4C07-AEF8-C9CA172E7434}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{53E11FC2-F010-4D67-B9D9-7F0B8A9E22C8}] => (Allow) C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{296B9C04-8841-40C7-8963-6AE717A34DEC}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{33F42900-0B82-47AA-8BF7-582654090F1E}] => (Allow) C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{8775214C-6DFC-44F9-9A7F-C90D75D9ACD8}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{4CAE83F6-3468-42CA-B051-B8CB1D3E536D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{CE5ABB58-0A44-4E92-B1DF-97097FD79214}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{6BDB3D1A-A8C2-4082-9EB1-6F2FE0363733}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{F8F4FCB9-3669-4990-B976-98F21DF566DF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{4C029E1A-3AD6-4A07-A1B6-231CEEFFB20C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

13-05-2017 12:53:03 Windows Update
13-05-2017 12:54:51 Windows Update
15-05-2017 16:29:26 Nainstalováno: Microsoft Visual C++ 2005 Redistributable
15-05-2017 16:31:25 Nainstalováno: Microsoft Visual C++ 2005 Redistributable (x64)

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/15/2017 04:31:26 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (05/15/2017 04:29:45 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (05/14/2017 04:19:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program MicrosoftEdgeCP.exe verze 11.0.14393.953 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 2b58

Čas spuštění: 01d2ccbc1845d8d2

Čas ukončení: 12

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe

ID hlášení: 5d1b51eb-38b0-11e7-9505-308d99f20ed4

Úplný název balíčku s chybou: Microsoft.MicrosoftEdge_38.14393.1066.0_neutral__8wekyb3d8bbwe

ID aplikace související s balíčkem s chybou: MicrosoftEdge

Error: (05/14/2017 03:15:12 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: Systém Windows nemůže načíst knihovnu DLL rozšiřitelných čítačů rdyboost. První čtyři bajty (DWORD) datové sekce obsahují kód chyby systému Windows.

Error: (05/14/2017 03:15:11 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Procedura Open pro službu BITS v knihovně DLL C:\Windows\System32\bitsperf.dll se nezdařila. Výkonnostní data pro tuto službu nebudou k dispozici. Vrácený kód stavu představují první čtyři bajty (DWORD) datové části.

Error: (05/14/2017 03:14:53 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10603.192) TYPE: ERROR

DPTF Build Version: 8.1.10603.192
DPTF Build Date: Aug 7 2015 10:44:44
Source File: ..\..\..\..\Sources\Policies\PassivePolicy\PassivePolicy.cpp @ line 288
Executing Function: PassivePolicy::onDomainPerformanceControlCapabilityChanged
Message: The feature is not implemented.
Policy: Passive Policy [5]

Error: (05/14/2017 03:14:53 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10603.192) TYPE: ERROR

DPTF Build Version: 8.1.10603.192
DPTF Build Date: Aug 7 2015 10:44:44
Source File: ..\..\..\..\Sources\Policies\ConfigTdpPolicy\ConfigTdpPolicy.cpp @ line 219
Executing Function: ConfigTdpPolicy::onDomainPerformanceControlCapabilityChanged
Message: The feature is not implemented.
Participant: TCPU [1]
Domain: GFX [2]
Policy: ConfigTDP Policy [1]

Error: (05/14/2017 10:30:22 AM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10603.192) TYPE: ERROR FUNC: rsrc_file_extract_resource_file FILE: rsrc_file.c LINE: 384 TIME: 39370 ms

Error: Unable to create resource file.

Error: (05/14/2017 10:30:22 AM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10603.192) TYPE: ERROR FUNC: rsrc_file_extract_resource_file FILE: rsrc_file.c LINE: 384 TIME: 39362 ms

Error: Unable to create resource file.

Error: (05/14/2017 10:28:52 AM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10603.192) TYPE: ERROR FUNC: rsrc_file_extract_resource_file FILE: rsrc_file.c LINE: 384 TIME: 60066590 ms

Error: Unable to create resource file.


System errors:
=============
Error: (05/15/2017 03:35:34 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba CDPUserSvc_a1f99b byla ukončena s následující chybou:
Nespecifikovaná chyba

Error: (05/14/2017 04:45:21 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/14/2017 12:10:54 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
a APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (05/14/2017 10:30:39 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba CDPUserSvc_82431 byla ukončena s následující chybou:
Nespecifikovaná chyba

Error: (05/14/2017 10:30:27 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Volání ScRegSetValueExW skončilo neúspěšné pro FailureActions s touto chybou:
Přístup byl odepřen.

Error: (05/14/2017 10:30:23 AM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: Volání ScRegSetValueExW skončilo neúspěšné pro FailureActions s touto chybou:
Přístup byl odepřen.

Error: (05/14/2017 10:29:25 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Windows Search neuspěla při spuštění v důsledku následující chyby:
Služba nebyla zahájena, protože se nepodařilo přihlásit.

Error: (05/14/2017 10:29:25 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: Služba WSearch se nemohla přihlásit jako NT AUTHORITY\SYSTEM s aktuálně konfigurovaným heslem z důvodu následující chyby:
Požadavek není podporován.


Chcete-li zajistit správnou konfiguraci služby, použijte modul snap-in Služby konzoly Microsoft Management Console (MMC).

Error: (05/14/2017 10:29:24 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\Windows\System32\bcmihvsrv64.dll

Error: (05/14/2017 10:29:24 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
Description: Rozšiřující modul sítě WLAN byl neočekávaně ukončen.

Cesta k modulu: C:\Windows\System32\bcmihvsrv64.dll


CodeIntegrity:
===================================
Date: 2017-05-15 16:16:50.065
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-15 15:40:58.150
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-15 15:38:35.742
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-15 15:38:32.710
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-15 15:38:06.283
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-15 15:38:04.685
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-15 15:38:04.480
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-15 15:38:04.019
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-15 15:37:55.634
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.

Date: 2017-05-14 16:16:42.123
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVG\Av\avgidsagenta.exe) attempted to load \Device\HarddiskVolume4\Windows\WinSxS\amd64_avg.vc140.crt_f92d94485545da78_14.0.24210.0_none_69fa0197d9b096ae\vcruntime140.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-4005U CPU @ 1.70GHz
Percentage of memory in use: 65%
Total physical RAM: 4017.39 MB
Available physical RAM: 1370.3 MB
Total Virtual: 6001.39 MB
Available Virtual: 2693.53 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.21 GB) (Free:317.07 GB) NTFS
Drive e: () (CDROM) (Total:8.13 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 1693CAEA)

Partition: GPT.

==================== End of Addition.txt ============================

Re: Malware jménem Initial Page 123

Napsal: 15 kvě 2017 16:57
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start
Task: {89388AE2-A274-42B9-B743-92C3DAE05693} - \Microsoft\Windows\DeviceSettings\Perotviguse -> No File <==== ATTENTION
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\Users\Tomáš Kouba\AppData\Local\Temp
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\MountPoints2: {5297f475-332d-11e7-9502-308d99f20ed4} - "H:\setup_dead_space_2.0.0.2.exe"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\MountPoints2: {7b1383fe-387f-11e7-9505-308d99f20ed4} - "E:\setup_dead_space_2.0.0.2.exe"
ShellExecuteHooks: No Name - {E9AC8DEE-308A-11E7-865E-64006A5CFC23} - C:\Users\Tomáš Kouba\AppData\Roaming\Ghegiward\Shemuing.dll -> No File
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =

EmptyTemp:
ResetHosts:
End
Uložte do C:\Users\Tomáš Kouba\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Malware jménem Initial Page 123

Napsal: 15 kvě 2017 20:07
od cunik.cz
Fix result of Farbar Recovery Scan Tool (x64) Version: 14-05-2017
Ran by Tomáš Kouba (15-05-2017 20:28:31) Run:1
Running from C:\Users\Tomáš Kouba\Downloads
Loaded Profiles: Tomáš Kouba (Available Profiles: defaultuser0 & Tomáš Kouba)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
Task: {89388AE2-A274-42B9-B743-92C3DAE05693} - \Microsoft\Windows\DeviceSettings\Perotviguse -> No File <==== ATTENTION
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\Users\Tom� Kouba\AppData\Local\Temp
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\MountPoints2: {5297f475-332d-11e7-9502-308d99f20ed4} - "H:\setup_dead_space_2.0.0.2.exe"
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\...\MountPoints2: {7b1383fe-387f-11e7-9505-308d99f20ed4} - "E:\setup_dead_space_2.0.0.2.exe"
ShellExecuteHooks: No Name - {E9AC8DEE-308A-11E7-865E-64006A5CFC23} - C:\Users\Tom� Kouba\AppData\Roaming\Ghegiward\Shemuing.dll -> No File
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =

EmptyTemp:
ResetHosts:
End
*****************

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89388AE2-A274-42B9-B743-92C3DAE05693} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89388AE2-A274-42B9-B743-92C3DAE05693} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\DeviceSettings\Perotviguse => key removed successfully
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat => moved successfully

"C:\Users\Tomáš Kouba\AppData\Local\Temp" folder move:

Could not move "C:\Users\Tomáš Kouba\AppData\Local\Temp" => Scheduled to move on reboot.

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5297f475-332d-11e7-9502-308d99f20ed4} => key removed successfully
HKCR\CLSID\{5297f475-332d-11e7-9502-308d99f20ed4} => key not found.
HKU\S-1-5-21-725424127-4130822466-1493971447-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7b1383fe-387f-11e7-9505-308d99f20ed4} => key removed successfully
HKCR\CLSID\{7b1383fe-387f-11e7-9505-308d99f20ed4} => key not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{E9AC8DEE-308A-11E7-865E-64006A5CFC23} => value removed successfully
HKCR\CLSID\{E9AC8DEE-308A-11E7-865E-64006A5CFC23} => key not found.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully
ResetHosts: => Error: No automatic fix found for this entry.

=========== EmptyTemp: ==========

BITS transfer queue => 296323 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 141589635 B
Java, Flash, Steam htmlcache => 25945563 B
Windows/system/drivers => 40648934 B
Edge => 264434753 B
Chrome => 11808979 B
Firefox => 387306610 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 128 B
LocalService => 5149188 B
NetworkService => 21722 B
defaultuser0 => 7296 B
Tomáš Kouba => 564056733 B

RecycleBin => 8338469438 B
EmptyTemp: => 9.1 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 15-05-2017 20:33:55)

C:\Users\Tomáš Kouba\AppData\Local\Temp => moved successfully

==== End of Fixlog 20:34:01 ====

Re: Malware jménem Initial Page 123

Napsal: 15 kvě 2017 20:13
od Rudy
Smazáno. Log je již OK. Změnilo se něco?

Re: Malware jménem Initial Page 123

Napsal: 15 kvě 2017 20:16
od cunik.cz
Chvilku to budu testovat. Jestli 3 dny nic nenapíšu můžete klidně LOCK :D

Re: Malware jménem Initial Page 123

Napsal: 15 kvě 2017 21:01
od Rudy
OK.