Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problem s winnet32b

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Problem s winnet32b

#1 Příspěvek od krakenus600 »

Viem ze totu je už spomínané vela krát ale potreboval by som pomoct s winnet32b a conhost32 a 64 zatazuju my pc brat my tam nieco nainstaloval a odvtedy je procák stále na 100%.Dakujem Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-10-2015
Ran by Katka (administrator) on KATKA-PC (19-10-2015 18:26:15)
Running from C:\Users\Katka\Desktop
Loaded Profiles: Katka (Available Profiles: Katka & DefaultAppPool)
Platform: Windows 10 Home (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Egis Technology Inc. ) C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
(Egis Technology Inc. ) C:\Program Files (x86)\EgisTec BioExcess\EgisService.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
() C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost32.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
() C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost64.exe
() C:\Users\Katka\AppData\Roaming\Microsoft\Networking\winnet32b.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10240.16464_none_116100d161f6ab1d\TiWorker.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Maxthon International ltd.) C:\Users\Katka\AppData\Roaming\Maxthon3\Public\MxUp\MxUp.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-10] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040792 2015-09-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-09-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-09-08] (Realtek Semiconductor)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [9769888 2011-09-23] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [5908928 2011-09-23] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [114688 2011-09-23] (Lenovo)
HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [5618456 2013-09-12] (ESET)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-11-05] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [202096 2010-11-05] (Egis Technology Inc.)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2010-12-24] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [224352 2010-12-24] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2010-07-26] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [RazerGameBooster] => C:\Program Files (x86)\Razer\Razer Game Booster\RazerGameBooster.exe [61152 2014-02-25] (Razer Inc.)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [UpdateMes] => C:\Users\Katka\AppData\Roaming\Updatem\update_days\zupdate.exe [30720 2012-03-20] ()
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [6f8a6591c8657bdc073fdcfeb43cfc54] => "C:\Users\Katka\AppData\Local\Temp\server.exe" .. <===== ATTENTION
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [51e746e8623104af4605a1df9f24a4be] => "C:\Users\Katka\AppData\Local\Temp\task.exe" .. <===== ATTENTION
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2901584 2015-10-14] (Valve Corporation)
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\RunOnce: [Uninstall C:\Users\Katka\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Katka\AppData\Local\Microsoft\OneDrive\17.3.5892.0626_1\amd64"
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {0faffbd9-a926-11e4-9048-402cf4690980} - "H:\autorun.exe"
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {64cdc4b5-511f-11e4-8c00-402cf4690980} - "F:\setup.exe"
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {64cdc4bd-511f-11e4-8c00-402cf4690980} - "G:\autorun.exe"
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Ribbons.scr [149504 2015-07-10] (Microsoft Corporation)
Lsa: [Notification Packages] scecli EgisPwdFilter EgisDSPwdFilter EgisPLPwdFilter
Startup: C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost32.exe [2015-10-16] ()
Startup: C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost64.exe [2015-10-16] ()
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{33ff87ce-89b3-4e40-9757-2e6c67009dec}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOQ1x-PB96kSc67AZQZF4XZ3PHJZcTEkRsdeWht4ldW9dMV29YChuG63zwgX6qTyadarpQJ7U48ZR1oNgFg,
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOjRO2PJzXF6_wgTQcrJUhB22QSRlPpTjw-hNT6TvfjRtfYMi8vPHPdZ7UwFYS4IHR7L6PLRuJqSEasfIKM,&q={searchTerms}
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOjRO2PJzXF6_wgTQcrJUhB22QSRlPpTjw-hNT6TvfjRtfYMi8vPHPdZ7UwFYS4IHR7L6PLRuJqSEasfIKM,&q={searchTerms}
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOjRO2PJzXF6_wgTQcrJUhB22QSRlPpTjw-hNT6TvfjRtfYMi8vPHPdZ7UwFYS4IHR7L6PLRuJqSEasfIKM,&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL =
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL =
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3563298145-570701526-3268098968-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-10-16] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-10-16] (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

FireFox:
========
FF ProfilePath: C:\Users\Katka\AppData\Roaming\Mozilla\Firefox\Profiles\uopjc5o4.default
FF Homepage: www.google.sk
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_226.dll [2015-10-16] ()
FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\windows\system32\npDeployJava1.dll [2013-09-19] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_226.dll [2015-10-16] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1219160.dll [2015-07-23] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-10-16] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-10-16] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3563298145-570701526-3268098968-1000: @my.com/Games -> C:\Users\Katka\AppData\Local\MyComGames\NPMyComDetector.dll [2015-07-19] (My.com, Inc)
FF Plugin HKU\S-1-5-21-3563298145-570701526-3268098968-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Katka\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-28] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\np-mswmp.dll [2007-04-10] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Extension: Adblock Plus - C:\Users\Katka\AppData\Roaming\Mozilla\Firefox\Profiles\uopjc5o4.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-10-09]
FF HKLM-x32\...\Firefox\Extensions: [{41ecbc0b-34d5-4cd4-935f-253a30e2cb7e}] - C:\Program Files (x86)\EgisTec BioExcess\FFExt
FF Extension: Online Accounts Extension - C:\Program Files (x86)\EgisTec BioExcess\FFExt [2011-09-23] [not signed]
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2015-10-03] [not signed]

Chrome:
=======
CHR HomePage: Default -> hxxp://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOjKAiCzo6Y00cT4Z80IPKik5Kh6ixZhpkhRMhsXC14e0_Y8gJQIJGEMcDuwiIa2o0tUOO3tiLefJs5GNYk,
CHR Profile: C:\Users\Katka\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Users\Katka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-26]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Katka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24]
CHR HKLM-x32\...\Chrome\Extension: [fgnippahjheicjenccifemomfgjofdhp] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path/update_url>

Opera:
=======
OPR Extension: (µBlock) - C:\Users\Katka\AppData\Roaming\Opera Software\Opera Stable\Extensions\kccohkcpppjjkkjppopfnflnebibpida [2015-03-22]
OPR Extension: (Adblock Plus) - C:\Users\Katka\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2015-04-24]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 appdrvrem01; C:\windows\System32\appdrvrem01.exe [551896 2014-01-21] (Protection Technology)
R2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2255064 2013-10-28] (Broadcom Corporation.)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1337752 2013-09-12] (ESET)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-10] (ELAN Microelectronics Corp.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-29] (IObit)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-20] (Microsoft Corporation)
R2 RzKLService; C:\Program Files (x86)\Razer\Razer Game Booster\RzKLService.exe [105448 2014-02-25] (Razer Inc.)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-20] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-20] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 appdrv01; C:\Windows\System32\Drivers\appdrv01.sys [3854000 2014-01-21] (Protection Technology)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4316784 2015-10-18] (Qualcomm Atheros Communications, Inc.)
R2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [314016 2015-07-07] ()
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-10-28] (Broadcom Corporation.)
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-10-11] (Disc Soft Ltd)
S1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [44120 2013-09-17] (ESET)
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [170280 2015-09-25] (ESET)
S3 hamachi; C:\Windows\system32\DRIVERS\Hamdrv.sys [45680 2015-08-03] (LogMeIn Inc.)
R1 HWiNFO32; C:\windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2014-12-17] (REALiX(tm))
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [43680 2015-07-07] ()
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2014-06-15] (Intel Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-20] (Microsoft Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [888064 2015-10-18] (Realtek )
R0 rtcrfilt64; C:\Windows\System32\DRIVERS\rtcrfilt64.sys [19600 2013-12-30] (Realtek Semiconductor Corp.)
S3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [410848 2015-08-20] (Realsil Semiconductor Corporation)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-06-15] (Synaptics Incorporated)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
S3 EagleX64; \??\C:\WINDOWS\system32\drivers\EagleX64.sys [X]
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-19 18:26 - 2015-10-19 18:28 - 00021105 _____ C:\Users\Katka\Desktop\FRST.txt
2015-10-19 18:22 - 2015-10-19 18:22 - 00016148 _____ C:\WINDOWS\system32\KATKA-PC_Katka_HistoryPrediction.bin
2015-10-19 17:58 - 2015-10-19 18:23 - 02196992 _____ (Farbar) C:\Users\Katka\Desktop\FRST64.exe
2015-10-19 17:29 - 2015-10-19 17:29 - 00000021 _____ C:\folders.log
2015-10-19 17:29 - 2015-10-19 17:29 - 00000000 ____D C:\zoek
2015-10-19 17:14 - 2015-10-19 17:17 - 00003436 _____ C:\zoek-results.log
2015-10-19 17:11 - 2015-10-19 17:29 - 00002934 _____ C:\runcheck.txt
2015-10-19 17:11 - 2015-10-19 17:11 - 01309184 _____ C:\Users\Katka\Desktop\zoek.exe
2015-10-19 17:11 - 2015-10-19 17:11 - 00000000 ____D C:\zoek_backup
2015-10-19 16:44 - 2015-10-19 16:44 - 01691648 _____ C:\Users\Katka\Desktop\adwcleaner_5.014.exe
2015-10-19 02:26 - 2015-10-19 03:35 - 00000000 ____D C:\Users\Katka\AppData\Local\CSO
2015-10-19 02:26 - 2015-10-19 02:26 - 00000000 ____D C:\ProgramData\Nexon
2015-10-19 02:21 - 2015-10-19 18:26 - 00000000 ____D C:\FRST
2015-10-19 02:20 - 2015-10-19 02:21 - 00029696 _____ C:\Users\Katka\AppData\Local\MSGBOX.EXE
2015-10-19 02:20 - 2015-10-19 02:20 - 00112640 _____ (forum.viry.cz) C:\Users\Katka\Downloads\FRSTLauncher.exe
2015-10-19 01:41 - 2015-10-19 01:41 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2015-10-19 01:41 - 2015-10-19 01:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BattleLine
2015-10-19 01:37 - 2015-10-19 01:37 - 00000000 ____D C:\BANDAI NAMCO Games America
2015-10-19 01:30 - 2015-10-19 18:24 - 00000000 ____D C:\Program Files (x86)\Steam
2015-10-19 01:30 - 2015-10-19 01:30 - 01476720 _____ C:\Users\Katka\Downloads\SteamSetup(4).exe
2015-10-19 01:30 - 2015-10-19 01:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-10-19 01:22 - 2015-10-19 01:30 - 993345616 _____ C:\Users\Katka\Downloads\Setup.exe
2015-10-19 01:21 - 2015-10-19 01:22 - 01374208 _____ (Bandai Namco) C:\Users\Katka\Downloads\DLM-BattlelineSW.exe
2015-10-19 00:20 - 2015-10-19 00:20 - 00000218 _____ C:\Users\Katka\.recently-used.xbel
2015-10-19 00:20 - 2015-10-19 00:20 - 00000000 ____D C:\Users\Katka\AppData\Roaming\gtk-2.0
2015-10-19 00:19 - 2015-10-19 00:19 - 13859135 _____ C:\Users\Katka\Downloads\com.android.vending-v5.9.12-80391200-Android-2.3(2).apk
2015-10-19 00:15 - 2015-10-19 00:20 - 00000008 _____ C:\Users\Public\youwave_size
2015-10-19 00:15 - 2015-10-19 00:20 - 00000000 ____D C:\Users\Katka\youwave
2015-10-19 00:15 - 2015-10-19 00:15 - 00000000 ____D C:\Users\Katka\Documents\webkit
2015-10-19 00:04 - 2015-10-19 00:07 - 150906576 _____ C:\Users\Katka\Downloads\YouWave-Android-Free-3-30.exe
2015-10-18 16:57 - 2015-10-18 16:57 - 04316784 _____ (Qualcomm Atheros Communications, Inc.) C:\WINDOWS\system32\Drivers\athw10x.sys
2015-10-18 16:56 - 2015-10-18 16:56 - 00888064 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2015-10-18 16:56 - 2015-10-18 16:56 - 00082544 _____ (Realtek Semiconductor Corporation) C:\WINDOWS\system32\RtNicProp64.dll
2015-10-18 02:39 - 2015-10-18 02:39 - 00011808 _____ C:\Users\Katka\Downloads\unecm.7z
2015-10-18 02:38 - 2015-10-18 02:39 - 50029558 _____ C:\Users\Katka\Downloads\Crash Bash.7z
2015-10-18 02:38 - 2015-10-18 02:38 - 00021604 _____ C:\Users\Katka\Downloads\ecm tools(1).rar
2015-10-18 02:36 - 2015-10-18 02:36 - 00021604 _____ C:\Users\Katka\Downloads\ecm tools.rar
2015-10-17 23:51 - 2015-10-17 23:51 - 00000000 ____D C:\Users\Katka\Downloads\PSXeven_v0.19-1717
2015-10-17 23:28 - 2015-10-17 23:28 - 00003635 _____ C:\WINDOWS\VGSCDAPI.VXD
2015-10-17 23:18 - 2015-10-17 23:18 - 00000000 ____D C:\Users\Katka\Downloads\EmuCR-Pcsxr-r72232-535
2015-10-17 22:47 - 2015-10-17 22:47 - 00854902 _____ C:\Users\Katka\Downloads\Connectix VGS 1.41 + Video Patch XP 1.3-517.zip
2015-10-17 22:47 - 2015-10-17 22:47 - 00695383 _____ C:\Users\Katka\Downloads\PSXeven_v0.19-1717.zip
2015-10-17 22:46 - 2015-10-17 22:46 - 08142173 _____ C:\Users\Katka\Downloads\ePSXe 1.7.0(Best One Yet)-776.rar
2015-10-17 22:46 - 2015-10-17 22:46 - 00738938 _____ C:\Users\Katka\Downloads\EmuCR-Pcsxr-r72232-535.7z
2015-10-17 22:46 - 2015-10-17 22:46 - 00666176 _____ C:\Users\Katka\Downloads\pSX_1_13-1220.rar
2015-10-17 22:46 - 2015-10-17 22:46 - 00169473 _____ C:\Users\Katka\Downloads\Pcsx-1.5-218.zip
2015-10-17 22:45 - 2015-10-17 22:46 - 09254219 _____ C:\Users\Katka\Downloads\epsxe160_full.7z
2015-10-17 22:45 - 2015-10-17 22:45 - 04495557 _____ C:\Users\Katka\Downloads\ePSXe 1.9.25 Starter Pack.zip
2015-10-17 22:27 - 2015-10-17 22:27 - 12100429 _____ C:\Users\Katka\Downloads\Epsxe_1.70_with_plugins_memcards.zip
2015-10-17 22:25 - 2015-10-17 22:25 - 00000000 ____D C:\Users\Katka\Downloads\epsxe170
2015-10-17 21:54 - 2015-10-17 21:54 - 00537228 _____ C:\Users\Katka\Downloads\gpupete177.zip
2015-10-17 21:52 - 2015-10-17 21:52 - 00635413 _____ C:\Users\Katka\Downloads\ePSXe180.zip
2015-10-17 21:51 - 2015-10-17 21:51 - 00529265 _____ C:\Users\Katka\Downloads\epsxe170.zip
2015-10-17 21:49 - 2015-10-17 21:49 - 00638836 _____ C:\Users\Katka\Downloads\ePSXe190.zip
2015-10-16 19:56 - 2015-10-16 19:56 - 00009953 _____ C:\Users\Katka\Downloads\1419934557_PS4 GTA 5 Mod Menu By Im HaxoTV.zip
2015-10-16 19:37 - 2015-10-16 19:55 - 423465643 _____ C:\Users\Katka\Downloads\Oddworld_Abes_Oddysee_PAL_0.7z
2015-10-16 14:48 - 2015-10-16 21:36 - 00000000 ____D C:\Users\Katka\AppData\Roaming\InstallDir
2015-10-16 12:14 - 2015-10-16 12:21 - 126754713 _____ C:\Users\Katka\Downloads\Minecraft-1.2.5-exe-+-technick-pack.rar
2015-10-16 12:04 - 2015-10-16 12:09 - 98272040 _____ C:\Users\Katka\Downloads\Minecraft-1.5.2-+-mody-Too-Many-Items,Reis-minimap,IC2,Traincraft,Railcraft,TreeCapitator,ComputerCraft,-atd.-+-Texture-pack-faithful-32x-1.5.2.zip
2015-10-16 11:12 - 2015-10-18 01:11 - 00003294 _____ C:\WINDOWS\System32\Tasks\Minecraft Installation Validation
2015-10-16 11:10 - 2015-10-16 11:23 - 244337124 _____ C:\Users\Katka\Downloads\Minecraft-1.1-Funkcne-100%.rar
2015-10-16 11:05 - 2015-10-16 11:05 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-16 11:05 - 2015-10-16 11:05 - 00000000 _____ C:\WINDOWS\setupact.log
2015-10-16 10:53 - 2015-10-16 10:53 - 02963998 _____ C:\Users\Katka\Downloads\TitaniumGL_2015_03.zip
2015-10-16 10:51 - 2015-10-16 10:51 - 05226037 _____ C:\Users\Katka\Downloads\Minecraft-1.7.8.-plna-hra-zdarma.rar
2015-10-16 10:50 - 2015-10-16 10:50 - 00441856 _____ C:\Users\Katka\Downloads\minecraft(2).exe
2015-10-16 10:49 - 2015-10-16 10:50 - 00352256 _____ (Cx6FPNaxHHRk) C:\Users\Katka\Downloads\minecraft(1).exe
2015-10-16 10:47 - 2015-10-16 13:56 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-10-16 10:47 - 2015-10-16 10:47 - 06520608 _____ ( ) C:\Users\Katka\Downloads\Minecraft-1.1.0-(obsahuje-Clay-Soldiers-mod-a-2-dal).exe.part
2015-10-16 10:38 - 2015-10-16 10:38 - 46297472 _____ (Microsoft Corporation) C:\Users\Katka\Downloads\directx_feb2007_redist.exe
2015-10-16 10:34 - 2015-10-16 10:34 - 00495458 _____ C:\Users\Katka\Downloads\Opengl95.exe
2015-10-16 10:22 - 2015-10-16 10:25 - 51929714 _____ C:\Users\Katka\Downloads\Minecraft-2.01-Free-Full-Premium-Version-Alpha,Beta+Crack+multiplayer-Original-Game-2014.zip
2015-10-16 10:19 - 2015-10-16 10:19 - 00000000 ____D C:\Users\Katka\AppData\Roaming\java
2015-10-16 10:17 - 2015-10-16 10:17 - 00948736 _____ ( ) C:\Users\Katka\Downloads\minecraft.exe
2015-10-16 10:15 - 2015-10-16 10:15 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2015-10-16 10:15 - 2015-10-16 10:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-10-16 10:15 - 2015-10-16 10:15 - 00000000 ____D C:\Program Files (x86)\Java
2015-10-16 10:14 - 2015-10-16 10:14 - 00584288 _____ (Oracle Corporation) C:\Users\Katka\Downloads\JavaSetup8u60(1).exe
2015-10-16 10:06 - 2015-10-16 10:06 - 00000000 ____D C:\ProgramData\Sun
2015-10-16 09:50 - 2015-10-16 09:50 - 29141928 _____ (Oracle Corporation) C:\Users\Katka\Downloads\jre-7u51-windows-i586.exe
2015-10-16 09:45 - 2015-10-16 12:07 - 00000958 _____ C:\WINDOWS\SysWOW64\peepmidasflops.bin
2015-10-16 09:45 - 2015-10-16 09:45 - 00000600 _____ C:\WINDOWS\system32\InstallUtil.InstallLog
2015-10-16 09:45 - 2015-10-16 09:45 - 00000008 _____ C:\ProgramData\-
2015-10-16 09:33 - 2015-10-16 09:40 - 140839332 _____ C:\Users\Katka\Downloads\Minecraft-1.8.3-plna-hra-zdarma-Full-Cracked-2015.rar
2015-10-15 23:22 - 2015-10-15 23:23 - 00000000 ____D C:\Users\Katka\Documents\TK_FB
2015-10-15 13:43 - 2015-10-15 13:43 - 00000000 ____D C:\Users\Katka\Downloads\Battlefield 1942 WWII Anthology HD
2015-10-15 13:20 - 2015-10-15 13:26 - 00000000 ____D C:\Users\Katka\Downloads\A.A.A
2015-10-15 10:17 - 2015-10-10 09:12 - 00078528 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-15 10:17 - 2015-10-10 08:40 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-15 10:17 - 2015-10-10 08:07 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-15 10:17 - 2015-10-06 05:03 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-15 10:17 - 2015-10-06 04:46 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-15 10:17 - 2015-10-01 06:01 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-10-15 10:17 - 2015-10-01 06:01 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-10-15 10:17 - 2015-10-01 06:01 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-10-15 10:17 - 2015-10-01 06:01 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-10-15 10:17 - 2015-10-01 06:00 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-15 10:17 - 2015-10-01 05:03 - 00757760 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2015-10-15 10:17 - 2015-09-25 06:01 - 02573768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2015-10-15 10:17 - 2015-09-25 06:01 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-10-15 10:17 - 2015-09-25 05:56 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-10-15 10:17 - 2015-09-25 05:52 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-10-15 10:17 - 2015-09-25 05:33 - 01997336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2015-10-15 10:17 - 2015-09-25 05:26 - 20858360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-10-15 10:17 - 2015-09-25 05:17 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-15 10:17 - 2015-09-25 05:11 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-15 10:17 - 2015-09-25 05:11 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-15 10:17 - 2015-09-25 05:09 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-10-15 10:17 - 2015-09-25 05:07 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-15 10:17 - 2015-09-25 05:04 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-15 10:17 - 2015-09-25 05:04 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-10-15 10:17 - 2015-09-25 05:04 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-15 10:17 - 2015-09-25 05:03 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-15 10:17 - 2015-09-25 05:03 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-10-15 10:17 - 2015-09-25 05:02 - 07523840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-15 10:17 - 2015-09-25 05:02 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-10-15 10:17 - 2015-09-25 05:02 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-15 10:17 - 2015-09-25 05:02 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-15 10:17 - 2015-09-25 05:01 - 04792320 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-15 10:17 - 2015-09-25 05:01 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-15 10:17 - 2015-09-25 05:00 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-15 10:17 - 2015-09-25 05:00 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-15 10:17 - 2015-09-25 05:00 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-15 10:17 - 2015-09-25 05:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-15 10:17 - 2015-09-25 04:59 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-15 10:17 - 2015-09-25 04:59 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-15 10:17 - 2015-09-25 04:59 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-15 10:17 - 2015-09-25 04:59 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-15 10:17 - 2015-09-25 04:59 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-15 10:17 - 2015-09-25 04:59 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-15 10:17 - 2015-09-25 04:59 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-15 10:17 - 2015-09-25 04:58 - 01871360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2015-10-15 10:17 - 2015-09-25 04:48 - 19325952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-15 10:17 - 2015-09-25 04:47 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-15 10:17 - 2015-09-25 04:47 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-15 10:17 - 2015-09-25 04:38 - 03580416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-15 10:17 - 2015-09-25 04:38 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-10-15 10:17 - 2015-09-25 04:38 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-15 10:17 - 2015-09-25 04:38 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-10-15 10:17 - 2015-09-25 04:37 - 00766976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-10-15 10:17 - 2015-09-25 04:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-15 10:17 - 2015-09-25 04:37 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-15 10:17 - 2015-09-25 04:36 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-10-15 10:17 - 2015-09-25 04:36 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-15 10:17 - 2015-09-25 04:34 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-15 10:17 - 2015-09-25 04:34 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-15 10:17 - 2015-09-25 04:34 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-15 10:17 - 2015-09-25 04:34 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-15 10:17 - 2015-09-25 04:34 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-15 10:17 - 2015-09-25 04:33 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-15 10:17 - 2015-09-25 04:32 - 01594368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2015-10-15 10:17 - 2015-09-25 04:32 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-15 00:48 - 2015-10-15 00:48 - 00002727 _____ C:\Users\Katka\Desktop\Enigmatis 2 - The Mists of Ravenwood Collectors Edition.lnk
2015-10-15 00:48 - 2015-10-15 00:48 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Enigmatis 2 - The Mists of Ravenwood Collectors Edition
2015-10-12 06:42 - 2015-10-12 06:57 - 00002528 _____ C:\Users\Katka\Desktop\~ESETUninstaller.log
2015-10-11 18:49 - 2015-10-12 06:42 - 00675528 _____ (ESET) C:\Users\Katka\Desktop\ESETUninstaller.exe
2015-10-11 17:02 - 2015-09-02 21:35 - 00000000 ____D C:\Users\Katka\Desktop\res_mods
2015-10-10 10:24 - 2015-10-10 10:24 - 00003446 _____ C:\WINDOWS\System32\Tasks\{7A06B9F4-5530-454D-832B-0A46F63EE060}
2015-10-10 10:13 - 2015-10-10 10:13 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Illusion Softworks
2015-10-10 10:13 - 2015-10-10 10:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Illusion Softworks
2015-10-10 10:11 - 2015-10-10 10:11 - 00000000 ____D C:\Program Files (x86)\Illusion Softworks
2015-10-10 03:17 - 2015-10-10 03:17 - 00000000 _____ C:\WINDOWS\SysWOW64\sho8C71.tmp
2015-10-09 10:05 - 2015-10-09 13:12 - 00000000 ____D C:\Users\Katka\Downloads\Hidden And Dangerous 2
2015-10-09 04:15 - 2015-10-09 04:15 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-10-09 04:15 - 2015-10-09 04:15 - 00001216 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-10-09 04:09 - 2015-10-09 04:15 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Mozilla
2015-10-09 04:01 - 2015-10-09 04:04 - 43319688 _____ C:\Users\Katka\Downloads\Firefox Setup 41.0.1.exe
2015-10-09 03:55 - 2015-10-09 03:55 - 00000000 ____D C:\Users\Katka\Desktop\Mozilla
2015-10-09 03:36 - 2015-10-19 16:24 - 00003840 _____ C:\WINDOWS\System32\Tasks\ESET Windows 10 upgrade – Perform upgrade
2015-10-09 02:44 - 2015-10-09 02:44 - 00000000 ____D C:\ProgramData\Mozilla
2015-10-08 18:08 - 2015-10-08 18:12 - 631193320 _____ C:\Users\Katka\Downloads\Paterčata-(13.-z-13).avi
2015-10-08 18:02 - 2015-10-08 18:06 - 644561024 _____ C:\Users\Katka\Downloads\Paterčata-(12.-z-13).avi
2015-10-08 17:57 - 2015-10-08 18:01 - 643757480 _____ C:\Users\Katka\Downloads\Paterčata-(11.-z-13).avi
2015-10-08 17:52 - 2015-10-08 17:57 - 638966920 _____ C:\Users\Katka\Downloads\Paterčata-(10.-z-13).avi
2015-10-08 17:45 - 2015-10-08 17:49 - 634209504 _____ C:\Users\Katka\Downloads\Paterčata-(9.-z-13).avi
2015-10-08 17:39 - 2015-10-08 17:43 - 638774798 _____ C:\Users\Katka\Downloads\Paterčata-(8.-z-13).avi
2015-10-08 17:08 - 2015-10-09 03:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxthon Cloud Browser
2015-10-08 16:53 - 2015-10-08 16:53 - 01168968 _____ C:\Users\Katka\Downloads\installer.zip
2015-10-08 02:20 - 2015-10-19 02:25 - 00170113 _____ C:\WINDOWS\DirectX.log
2015-10-08 01:53 - 2015-10-08 01:53 - 00000000 ____D C:\Program Files (x86)\R.G. Catalyst
2015-10-08 01:51 - 2015-10-08 01:51 - 00000102 _____ C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
2015-10-08 01:41 - 2015-10-08 01:43 - 03739648 _____ C:\Users\Katka\Downloads\SC-CBGHPPH.part1.rar.part
2015-10-08 00:53 - 2015-10-08 00:53 - 00000000 ____D C:\Users\Katka\Documents\Duke Nukem Forever
2015-10-07 23:57 - 2015-10-07 23:57 - 00000000 ____D C:\Program Files (x86)\2K Games
2015-10-07 23:26 - 2015-10-09 03:23 - 00000000 ____D C:\Users\Katka\Downloads\Duke.Nukem.Forever.Ru.En
2015-10-07 23:05 - 2015-10-07 23:12 - 503245012 _____ C:\Users\Katka\Downloads\Disney's A Bug's Life [SCUS-94288].rar
2015-10-07 10:45 - 2015-10-07 11:21 - 641726702 _____ C:\Users\Katka\Downloads\Paterčata-(7.-z-13).avi
2015-10-07 10:03 - 2015-10-07 10:40 - 661592758 _____ C:\Users\Katka\Downloads\Paterčata-(6.-z-13).avi
2015-10-07 09:01 - 2015-10-07 09:57 - 630394094 _____ C:\Users\Katka\Downloads\Paterčata-(5.-z-13).avi
2015-10-07 08:55 - 2015-10-07 08:59 - 657497118 _____ C:\Users\Katka\Downloads\Paterčata-(4.-z-13).avi
2015-10-07 08:43 - 2015-10-07 08:47 - 658603180 _____ C:\Users\Katka\Downloads\Paterčata-(3.-z-13).avi
2015-10-07 08:21 - 2015-10-07 08:26 - 635648676 _____ C:\Users\Katka\Downloads\Paterčata-(2.-z-13).avi
2015-10-07 08:15 - 2015-10-07 08:20 - 623286300 _____ C:\Users\Katka\Downloads\Paterčata-(1.-z-13).avi
2015-10-06 07:03 - 2015-10-06 07:03 - 00790095 _____ C:\Users\Katka\Downloads\Dead-Island-cestina.rar
2015-10-06 06:39 - 2015-10-06 06:39 - 00000563 _____ C:\WINDOWS\wmsetup.log
2015-10-06 06:39 - 2015-10-06 06:39 - 00000000 ____D C:\ProgramData\REVOLT
2015-10-06 04:35 - 2015-10-09 03:25 - 00000000 ____D C:\Users\Katka\Downloads\Dead Island Game of The Year Edition PC + DLCs ^^nosTEAM^^
2015-10-06 04:26 - 2015-10-09 03:23 - 00000000 ____D C:\Users\Katka\Downloads\Dead.Space.2
2015-10-06 03:49 - 2015-10-06 03:49 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\1-click run
2015-10-05 04:07 - 2015-10-05 04:07 - 00000000 _____ C:\WINDOWS\SysWOW64\shoD0A1.tmp
2015-10-03 22:22 - 2015-10-03 22:28 - 629182858 _____ C:\Users\Katka\Downloads\NEMOCNICE_NA_KRAJI_MĚSTA_PO_20_LETECH_13_Slib_CZ[@].mp4
2015-10-03 22:01 - 2015-10-03 22:06 - 625970361 _____ C:\Users\Katka\Downloads\NEMOCNICE_NA_KRAJI_MĚSTA_PO_20_LETECH_12_Diagnóza_CZ[@].mp4
2015-10-03 21:51 - 2015-10-03 21:57 - 792994856 _____ C:\Users\Katka\Downloads\Nemocnice-na-kraji-města-po-20-letech-16.9---11-Zatnuté-zuby.avi
2015-10-03 21:46 - 2015-10-03 21:51 - 628143046 _____ C:\Users\Katka\Downloads\NEMOCNICE_NA_KRAJI_MĚSTA_PO_20_LETECH_10_Synové_CZ[@].mp4
2015-10-03 21:27 - 2015-10-03 21:44 - 1999861674 _____ C:\Users\Katka\Downloads\Nemocnice-na-kraji-města-po-20.letech-9x13-Start-HDTV-1080i-[MR].mkv
2015-10-03 21:05 - 2015-10-03 21:22 - 2029352146 _____ C:\Users\Katka\Downloads\Nemocnice-na-kraji-města-po-20.letech-8x13-Útěky-HDTV-1080i-[MR].mkv
2015-10-03 20:46 - 2015-10-03 21:04 - 2001499645 _____ C:\Users\Katka\Downloads\Nemocnice-na-kraji-města-po-20.letech-7x13-Past-HDTV-1080i-[MR].mkv
2015-10-03 13:47 - 2015-10-03 13:47 - 00036027 _____ C:\Users\Katka\Downloads\Shinkansen Star Ruler 2 V1001.CT
2015-10-03 13:47 - 2015-10-03 13:47 - 00000000 ____D C:\Users\Katka\Documents\My Cheat Tables
2015-10-03 13:23 - 2015-10-03 13:23 - 00004425 _____ C:\Users\Katka\Downloads\starruler2v102update-skidro..torrent
2015-10-03 12:26 - 2015-10-03 12:26 - 00000000 ____D C:\Program Files (x86)\Blind Mind Studios
2015-10-03 03:40 - 2015-10-03 03:58 - 1982926299 _____ C:\Users\Katka\Downloads\Nemocnice-na-kraji-města-po-20.letech-5x13-Zpověď-HDTV-1080i-[MR].mkv
2015-10-03 02:47 - 2015-10-03 02:54 - 697677824 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta po dvaceti letech 06. __istka.avi
2015-10-03 02:21 - 2015-10-03 02:29 - 727842816 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta po dvaceti letech 04. Druh__ rodina.avi
2015-10-03 02:09 - 2015-10-03 02:15 - 700657664 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta po dvaceti letech 03. Balvan.avi
2015-10-03 01:46 - 2015-10-03 01:52 - 732798976 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta po dvaceti letech 02. Pomluva.avi
2015-10-03 01:29 - 2015-10-03 01:37 - 878888552 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta -20.Ode____t__n__ (1981).avi
2015-10-03 01:20 - 2015-10-03 01:26 - 734312448 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta 19 - Procento hnisav__ch komplikac__.avi
2015-10-03 01:06 - 2015-10-03 01:13 - 778461492 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 18.j.avi
2015-10-03 00:52 - 2015-10-03 01:03 - 778112326 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 17.j.avi
2015-10-03 00:42 - 2015-10-03 00:51 - 710779750 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta ___ 16. d__l ___ Z__n__t.avi
2015-10-03 00:31 - 2015-10-03 00:41 - 778586124 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 15.j.avi
2015-10-02 23:52 - 2015-10-03 00:02 - 778586124 _____ C:\Users\Katka\Downloads\download.php
2015-10-02 23:44 - 2015-10-02 19:36 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-02 23:44 - 2015-10-02 19:36 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-02 23:34 - 2015-10-02 23:34 - 00000000 ____D C:\Users\Katka\Documents\Tunngle
2015-10-02 15:05 - 2015-09-17 08:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-02 15:05 - 2015-09-17 08:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-02 15:05 - 2015-09-17 08:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-02 15:05 - 2015-09-17 08:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-02 15:05 - 2015-09-17 08:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-02 15:05 - 2015-09-17 08:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-02 15:05 - 2015-09-17 08:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-02 15:05 - 2015-09-17 08:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-02 15:05 - 2015-09-17 08:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-02 15:05 - 2015-09-17 07:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-02 15:05 - 2015-09-17 07:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-02 15:05 - 2015-09-17 07:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-02 15:05 - 2015-09-17 07:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-02 15:05 - 2015-09-17 07:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-02 15:05 - 2015-09-17 07:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-02 15:05 - 2015-09-17 07:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-02 15:05 - 2015-09-17 07:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-02 15:05 - 2015-09-17 07:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-02 15:04 - 2015-09-17 08:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-02 15:04 - 2015-09-17 08:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-02 15:04 - 2015-09-17 08:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-02 15:04 - 2015-09-17 08:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-02 15:04 - 2015-09-17 08:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-02 15:04 - 2015-09-17 08:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-02 15:04 - 2015-09-17 08:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-02 15:04 - 2015-09-17 08:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-02 15:04 - 2015-09-17 08:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-02 15:04 - 2015-09-17 08:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-02 15:04 - 2015-09-17 08:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-02 15:04 - 2015-09-17 08:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-02 15:04 - 2015-09-17 08:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-02 15:04 - 2015-09-17 08:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-02 15:04 - 2015-09-17 07:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-02 15:04 - 2015-09-17 07:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-02 15:04 - 2015-09-17 07:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-02 15:04 - 2015-09-17 07:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-02 15:04 - 2015-09-17 07:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-02 15:04 - 2015-09-17 07:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-02 15:04 - 2015-09-17 07:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-02 15:04 - 2015-09-17 07:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-02 15:04 - 2015-09-17 07:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-02 15:04 - 2015-09-17 07:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-02 15:04 - 2015-09-17 07:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-02 15:04 - 2015-09-17 07:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-02 15:04 - 2015-09-17 07:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-02 15:04 - 2015-09-17 07:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-02 15:04 - 2015-09-17 07:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-02 15:04 - 2015-09-17 07:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-02 15:04 - 2015-09-13 04:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-02 15:03 - 2015-09-19 07:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-02 15:03 - 2015-09-17 08:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-02 15:03 - 2015-09-17 08:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-02 15:03 - 2015-09-17 08:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-02 15:03 - 2015-09-17 08:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-02 15:03 - 2015-09-17 08:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-02 15:03 - 2015-09-17 08:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-02 15:03 - 2015-09-17 08:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-02 15:03 - 2015-09-17 08:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-02 15:03 - 2015-09-17 08:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-02 15:03 - 2015-09-17 08:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-02 15:03 - 2015-09-17 08:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-02 15:03 - 2015-09-17 08:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-02 15:03 - 2015-09-17 08:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-02 15:03 - 2015-09-17 08:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-02 15:03 - 2015-09-17 08:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-02 15:03 - 2015-09-17 08:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-02 15:03 - 2015-09-17 08:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-02 15:03 - 2015-09-17 08:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-02 15:03 - 2015-09-17 08:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-02 15:03 - 2015-09-17 08:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-02 15:03 - 2015-09-17 08:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-02 15:03 - 2015-09-17 08:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-02 15:03 - 2015-09-17 08:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-02 15:03 - 2015-09-17 08:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-02 15:03 - 2015-09-17 08:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-02 15:03 - 2015-09-17 08:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-02 15:03 - 2015-09-17 08:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-02 15:03 - 2015-09-17 08:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-02 15:03 - 2015-09-17 08:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-02 15:03 - 2015-09-17 08:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-02 15:03 - 2015-09-17 08:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-02 15:03 - 2015-09-17 08:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-02 15:03 - 2015-09-17 08:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-02 15:03 - 2015-09-17 08:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-02 15:03 - 2015-09-17 08:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-02 15:03 - 2015-09-17 08:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-02 15:03 - 2015-09-17 08:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-02 15:03 - 2015-09-17 08:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-02 15:03 - 2015-09-17 08:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-02 15:03 - 2015-09-17 08:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-02 15:03 - 2015-09-17 08:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-02 15:03 - 2015-09-17 08:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-02 15:03 - 2015-09-17 08:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-02 15:03 - 2015-09-17 08:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-02 15:03 - 2015-09-17 08:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-02 15:03 - 2015-09-17 08:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-02 15:03 - 2015-09-17 08:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-02 15:03 - 2015-09-17 08:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-02 15:03 - 2015-09-17 08:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-02 15:03 - 2015-09-17 08:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-02 15:03 - 2015-09-17 08:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-02 15:03 - 2015-09-17 08:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-02 15:03 - 2015-09-17 07:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-02 15:03 - 2015-09-17 07:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-02 15:03 - 2015-09-17 07:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-02 15:03 - 2015-09-17 07:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-02 15:03 - 2015-09-17 07:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-02 15:03 - 2015-09-17 07:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-02 15:03 - 2015-09-17 07:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-02 15:03 - 2015-09-17 07:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-02 15:03 - 2015-09-17 07:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-02 15:03 - 2015-09-17 07:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-02 15:03 - 2015-09-17 07:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-02 15:03 - 2015-09-17 07:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-02 15:03 - 2015-09-17 07:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-02 15:03 - 2015-09-17 07:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-02 15:03 - 2015-09-17 07:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-02 15:03 - 2015-09-17 07:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-02 15:03 - 2015-09-17 07:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-02 15:03 - 2015-09-17 07:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-02 15:03 - 2015-09-17 07:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-02 15:03 - 2015-09-17 07:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-02 15:03 - 2015-09-17 07:50 - 00929280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2015-10-02 15:03 - 2015-09-17 07:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-02 15:03 - 2015-09-17 07:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-02 15:03 - 2015-09-17 07:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-02 15:03 - 2015-09-17 07:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-02 15:03 - 2015-09-17 07:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-02 15:03 - 2015-09-17 07:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-02 15:03 - 2015-09-17 07:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-02 15:03 - 2015-09-17 07:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-02 15:03 - 2015-09-17 07:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-02 15:03 - 2015-09-17 07:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-02 15:03 - 2015-09-17 07:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-02 15:03 - 2015-09-17 07:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-02 15:03 - 2015-09-17 07:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-02 15:03 - 2015-09-17 07:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-02 15:03 - 2015-09-17 07:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-02 15:03 - 2015-09-17 07:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-02 15:03 - 2015-09-17 07:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-02 15:03 - 2015-09-17 07:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-02 15:03 - 2015-09-17 07:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-02 15:03 - 2015-09-17 07:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-02 15:03 - 2015-09-17 07:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-02 15:03 - 2015-09-17 07:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-02 15:03 - 2015-09-17 07:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-02 15:03 - 2015-09-17 07:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-02 15:03 - 2015-09-17 07:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-02 15:03 - 2015-09-17 07:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-02 15:03 - 2015-09-17 07:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-02 15:03 - 2015-09-17 07:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-02 15:03 - 2015-09-17 07:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-02 15:03 - 2015-09-17 07:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-02 15:03 - 2015-09-17 07:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-02 15:03 - 2015-09-17 07:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-02 15:03 - 2015-09-17 07:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-02 15:03 - 2015-09-17 07:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-10-02 15:03 - 2015-09-17 07:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-02 15:03 - 2015-09-17 07:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-02 15:03 - 2015-09-17 07:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-02 15:03 - 2015-09-17 07:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-02 15:03 - 2015-09-17 07:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-02 15:03 - 2015-09-17 07:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-02 15:03 - 2015-09-17 07:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-02 15:03 - 2015-09-17 07:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-02 15:03 - 2015-09-17 07:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-02 15:03 - 2015-09-17 07:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-02 15:03 - 2015-09-17 07:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-02 15:03 - 2015-09-17 07:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-02 15:03 - 2015-09-17 07:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-02 15:03 - 2015-09-17 07:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-02 15:03 - 2015-09-17 07:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-02 15:03 - 2015-09-17 07:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-02 15:03 - 2015-09-17 07:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-02 15:03 - 2015-09-17 07:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-02 15:03 - 2015-09-17 07:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-02 15:03 - 2015-09-17 07:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-02 15:03 - 2015-09-17 07:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-02 15:03 - 2015-09-17 07:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-10-02 15:03 - 2015-09-17 07:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-02 15:03 - 2015-09-13 03:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-02 14:05 - 2015-10-19 16:35 - 00000085 _____ C:\WINDOWS\wininit.ini
2015-10-01 19:11 - 2015-10-01 20:40 - 734101504 _____ C:\Users\Katka\Downloads\Nemocnice na kraji města 14 - Reooperace.avi
2015-10-01 11:55 - 2015-10-01 11:57 - 13859135 _____ C:\Users\Katka\Downloads\PlayStore_v5.9.12.apk
2015-10-01 02:06 - 2015-10-01 02:16 - 787879758 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 13.j.avi
2015-10-01 01:55 - 2015-10-01 02:04 - 644368066 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 12.j.avi
2015-10-01 01:45 - 2015-10-01 01:53 - 701528774 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 11.j.avi
2015-10-01 01:35 - 2015-10-01 01:44 - 698994900 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 10.j.avi
2015-10-01 01:23 - 2015-10-01 01:35 - 864161410 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 9.j.avi
2015-10-01 01:14 - 2015-10-01 01:23 - 711248006 _____ C:\Users\Katka\Downloads\Nemocnice na kraji mesta 8.j.avi
2015-09-30 21:19 - 2015-09-30 21:37 - 1478137896 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta 7. Ema.avi
2015-09-30 21:02 - 2015-09-30 21:17 - 734990336 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta - 6.dil.avi
2015-09-30 18:24 - 2015-09-30 18:48 - 1238084048 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta 5. Rozvod.avi
2015-09-30 13:05 - 2015-10-06 03:42 - 00000000 ____D C:\2-click run
2015-09-30 12:38 - 2015-10-06 03:23 - 00000000 ____D C:\Users\Katka\Downloads\Euro Truck Simulator 2 v1.15.1.1s (20 DLC)(2014)(2-click run)
2015-09-30 03:32 - 2015-09-30 03:38 - 674160994 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta 4 d__l Loket.avi
2015-09-30 02:38 - 2015-09-30 02:44 - 734859264 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta 3 d__l Spor.avi
2015-09-30 02:29 - 2015-09-30 02:34 - 735031296 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta - 2.dil.avi
2015-09-30 01:26 - 2015-09-30 01:35 - 734892032 _____ C:\Users\Katka\Downloads\Nemocnice na kraji m__sta - 1.dil.avi
2015-09-29 13:31 - 2015-09-29 13:31 - 00298564 _____ C:\Users\Katka\Downloads\Apk Installer(1).apk
2015-09-29 12:42 - 2015-09-29 12:42 - 13859135 _____ C:\Users\Katka\Downloads\com.android.vending-v5.9.12-80391200-Android-2.3(1).apk
2015-09-29 12:15 - 2015-09-29 12:16 - 02649508 _____ C:\Users\Katka\Downloads\market-helper-2.0.3.apk
2015-09-29 12:00 - 2015-09-29 12:00 - 01710984 _____ C:\Users\Katka\Downloads\market-helper-2.0-beta.apk
2015-09-29 11:45 - 2015-09-29 11:45 - 13859135 _____ C:\Users\Katka\Downloads\com.android.vending-v5.9.12-80391200-Android-2.3.apk
2015-09-29 11:44 - 2015-09-29 11:44 - 03995946 _____ C:\Users\Katka\Downloads\com.android.vending-3.5.15-8011015-minAPI8.apk
2015-09-29 11:29 - 2015-09-29 11:29 - 00101965 _____ C:\Users\Katka\Downloads\com.vicono.AndroidMarketEnabler-1.apk
2015-09-29 11:18 - 2015-09-29 11:18 - 09493816 _____ C:\Users\Katka\Downloads\Play Store 5038.apk
2015-09-29 11:16 - 2015-09-29 11:16 - 06126834 _____ C:\Users\Katka\Downloads\com.android.vending-4.4.22.apk
2015-09-25 10:05 - 2015-10-19 18:20 - 00021892 _____ C:\WINDOWS\PFRO.log
2015-09-24 12:52 - 2015-09-24 12:52 - 14634624 _____ (BlueStack Systems Inc.) C:\Users\Katka\Downloads\ThinInstaller_native.exe
2015-09-24 12:50 - 2015-09-29 12:59 - 00055499 _____ C:\Users\Katka\genymotion-log.zip
2015-09-24 12:49 - 2015-09-29 13:00 - 00000000 ____D C:\Users\Katka\AppData\Local\Genymobile
2015-09-24 12:47 - 2015-09-24 12:48 - 139064816 _____ (Genymobile ) C:\Users\Katka\Downloads\genymotion-2.5.4-vbox.exe
2015-09-24 12:26 - 2015-07-10 13:22 - 00922704 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxDrv.sys
2015-09-24 12:26 - 2015-07-10 13:21 - 00128592 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys
2015-09-24 12:25 - 2015-09-24 12:28 - 00000000 ____D C:\Users\Katka\Andy
2015-09-24 12:25 - 2015-09-24 12:25 - 00000000 ____D C:\ProgramData\Apple
2015-09-24 12:25 - 2015-09-24 12:25 - 00000000 ____D C:\Program Files\Oracle
2015-09-24 12:19 - 2015-09-24 12:20 - 00000000 ____D C:\Program Files\AndyOfflineInstaller45
2015-09-24 12:15 - 2015-09-24 12:28 - 00000000 ___RD C:\Users\Katka\AppData\Roaming\Andy_45_Online
2015-09-24 12:15 - 2015-09-24 12:15 - 01768016 _____ C:\Users\Katka\Downloads\Andy_Android_Emulator_v45_32.exe
2015-09-23 18:33 - 2015-09-23 18:33 - 00113560 _____ (GreenTree Applications SRL) C:\Users\Katka\Downloads\YTDSetup.exe
2015-09-23 13:53 - 2015-09-25 13:51 - 00170280 _____ (ESET) C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys
2015-09-22 19:50 - 2015-10-19 18:24 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-09-22 19:34 - 2015-09-22 19:34 - 00086602 _____ C:\Users\Katka\Documents\cc_20150922_193406.reg
2015-09-21 22:51 - 2015-09-21 23:04 - 00000000 ____D C:\Program Files (x86)\Men of War Assault Squad 2
2015-09-21 22:00 - 2015-09-21 22:00 - 00579378 _____ C:\Users\Katka\Downloads\cheatsmod482pir.rar
2015-09-21 18:14 - 2015-09-21 18:14 - 02459955 _____ C:\Users\Katka\Downloads\cheatsmod_moddbV488AS2(1).rar
2015-09-21 15:05 - 2015-09-21 15:05 - 00584288 _____ (Oracle Corporation) C:\Users\Katka\Downloads\JavaSetup8u60.exe
2015-09-21 14:43 - 2015-09-21 17:11 - 1242650166 _____ (German Soldiers ) C:\Users\Katka\Downloads\GSM_Fields_of_Honor_XII_Installer_22.08.15.exe
2015-09-21 14:01 - 2015-09-21 14:01 - 02459955 _____ C:\Users\Katka\Downloads\cheatsmod_moddbV488AS2.rar
2015-09-21 11:49 - 2015-10-16 13:59 - 00003468 _____ C:\WINDOWS\System32\Tasks\ESET Windows 10 upgrade – Refresh settings
2015-09-19 19:32 - 2015-09-19 19:32 - 00013916 _____ C:\Users\Katka\Downloads\5748645211-mnwars2u1.rar
2015-09-19 02:02 - 2015-09-19 02:02 - 07118540 _____ C:\Users\Katka\Downloads\Fiat-Ansaldo_M13_40,_North_Africa,_1942_-_Semi_Historical_-_Copy.zip
2015-09-19 02:00 - 2015-09-19 02:00 - 00671313 _____ C:\Users\Katka\Downloads\template_ussr_bt_7_1937.zip

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-19 18:26 - 2015-02-23 02:47 - 00000000 ____D C:\Program Files (x86)\Opera
2015-10-19 18:23 - 2011-09-23 16:14 - 00255566 _____ C:\WINDOWS\system32\fastboot.set
2015-10-19 18:22 - 2015-09-14 12:34 - 00001022 _____ C:\WINDOWS\Tasks\EiiC8bVNTr3NX8Ls.job
2015-10-19 18:22 - 2015-09-14 12:34 - 00001014 _____ C:\WINDOWS\Tasks\1mDHiGhEEzbW.job
2015-10-19 18:22 - 2011-09-23 16:08 - 00000958 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-19 18:21 - 2015-07-10 14:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-19 18:20 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-19 18:20 - 2015-07-10 11:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-19 17:35 - 2011-09-23 16:08 - 00000962 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-19 17:21 - 2013-06-22 08:08 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-19 17:02 - 2015-07-15 15:56 - 00000000 ____D C:\AdwCleaner
2015-10-19 16:51 - 2015-09-15 20:55 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-10-19 16:35 - 2015-09-15 20:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-10-19 16:25 - 2015-09-02 20:10 - 00004196 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{12D319B9-AC8E-42CF-BA73-862A45FF8706}
2015-10-19 16:19 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-19 16:18 - 2015-08-20 22:28 - 00000000 ____D C:\Users\Katka
2015-10-19 02:24 - 2013-11-22 08:40 - 00000000 ____D C:\ProgramData\Package Cache
2015-10-19 02:23 - 2012-03-20 16:42 - 00000000 ___RD C:\Users\Katka\Desktop\sins of solar
2015-10-18 23:03 - 2015-06-23 18:28 - 00000000 ____D C:\WarThunder
2015-10-18 20:15 - 2013-08-14 12:41 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-18 19:49 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-18 16:58 - 2015-02-23 02:19 - 00002219 _____ C:\Users\Public\Desktop\Driver Booster 2.lnk
2015-10-18 16:51 - 2013-12-17 14:48 - 00000000 ____D C:\Program Files (x86)\TeamSpeak 3 Client
2015-10-18 16:50 - 2012-03-25 11:21 - 00000000 ____D C:\Users\Katka\AppData\Roaming\.minecraft
2015-10-18 12:37 - 2015-04-24 20:49 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-10-18 11:40 - 2012-03-20 14:29 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Skype
2015-10-18 02:39 - 2014-02-17 13:50 - 00000000 ____D C:\Users\Katka\Desktop\PS1 Emulator
2015-10-18 01:49 - 2015-06-20 23:36 - 00000000 ____D C:\Users\Katka\Downloads\EA Games Generic Multi Keygen v214 - FFF By ChattChitto
2015-10-18 01:38 - 2012-03-23 08:08 - 143481208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-10-17 03:43 - 2013-12-26 16:57 - 00000000 ____D C:\ProgramData\ProductData
2015-10-16 18:05 - 2012-03-26 00:22 - 00000000 ____D C:\Users\Katka\Documents\Youcam
2015-10-16 14:41 - 2013-12-13 10:36 - 00000000 ____D C:\Users\Katka\AppData\Local\Packages
2015-10-16 13:56 - 2014-01-26 21:52 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-16 10:39 - 2014-07-24 11:41 - 00000000 ____D C:\fifo
2015-10-16 10:16 - 2013-10-14 10:44 - 00000000 ____D C:\ProgramData\Oracle
2015-10-16 10:09 - 2015-08-20 22:27 - 01220308 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-16 10:09 - 2013-07-14 07:38 - 00171000 _____ C:\WINDOWS\system32\perfh01B.dat
2015-10-16 10:09 - 2013-07-14 07:38 - 00057146 _____ C:\WINDOWS\system32\perfc01B.dat
2015-10-16 09:44 - 2014-09-24 10:54 - 00000000 ____D C:\Program Files (x86)\EA GAMES
2015-10-16 01:54 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-15 21:01 - 2013-12-17 14:48 - 00000000 ____D C:\Users\Katka\AppData\Roaming\TS3Client
2015-10-15 13:43 - 2013-05-14 10:57 - 00000000 ____D C:\Users\Katka\AppData\Roaming\uTorrent
2015-10-15 11:08 - 2015-07-10 12:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-15 10:08 - 2015-04-24 20:51 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-10-15 00:47 - 2013-05-18 03:50 - 00000000 ____D C:\Program Files (x86)\LeeGT-Games
2015-10-13 10:32 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-11 17:02 - 2013-07-01 12:24 - 00000000 ____D C:\Users\Katka\Documents\Preberanie
2015-10-11 08:40 - 2015-08-20 22:23 - 00000000 ____D C:\Program Files\Elantech
2015-10-10 13:33 - 2015-08-20 23:29 - 00056008 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\ETDCoInstaller01000.dll
2015-10-10 13:33 - 2011-04-15 07:28 - 00525512 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\Drivers\ETD.sys
2015-10-10 10:21 - 2015-07-10 12:59 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2015-10-10 10:21 - 2015-07-10 12:59 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2015-10-10 10:21 - 2015-07-10 12:59 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2015-10-10 10:21 - 2015-07-10 12:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2015-10-10 10:21 - 2015-07-10 12:59 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2015-10-10 10:17 - 2011-09-23 15:31 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-10-10 03:01 - 2013-06-15 04:25 - 00000000 ____D C:\Users\Katka\AppData\Roaming\vlc
2015-10-09 14:20 - 2014-09-16 06:46 - 00000000 ____D C:\Users\Katka\AppData\Local\Adobe
2015-10-09 03:25 - 2015-09-04 10:13 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WarThunder
2015-10-09 03:25 - 2015-08-20 22:28 - 00000000 ____D C:\Users\DefaultAppPool
2015-10-09 03:25 - 2014-06-15 19:42 - 00000000 ____D C:\Users\Katka\AppData\Roaming\ProductData
2015-10-09 03:25 - 2013-06-15 07:28 - 00000000 ____D C:\Users\Katka\AppData\LocalLow\IObit
2015-10-09 03:25 - 2012-05-03 09:58 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2015-10-09 03:25 - 2012-03-19 22:10 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-10-09 03:24 - 2012-05-03 12:21 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-10-09 03:17 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\registration
2015-10-08 02:32 - 2013-05-26 08:31 - 00000000 ____D C:\Users\Katka\Documents\EA Games
2015-10-08 02:21 - 2013-05-26 08:26 - 00000000 ____D C:\Users\Katka\AppData\Local\EA Games
2015-10-08 00:53 - 2013-06-17 13:51 - 00000000 ____D C:\Users\Katka\AppData\Local\SKIDROW
2015-10-06 03:59 - 2014-06-04 18:18 - 00000000 ____D C:\Users\Katka\Documents\Euro Truck Simulator 2
2015-10-03 16:37 - 2014-09-22 12:02 - 00000000 ____D C:\Users\Katka\Documents\Forgottenhp 2
2015-10-03 13:10 - 2013-06-07 10:11 - 00000000 ____D C:\Users\Katka\Documents\My Games
2015-10-03 12:25 - 2012-05-03 09:58 - 00000000 ____D C:\Users\Katka\AppData\Roaming\DAEMON Tools Lite
2015-10-02 23:42 - 2015-07-10 14:20 - 00352168 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-02 23:39 - 2015-07-10 13:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-02 23:39 - 2015-07-10 13:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-02 23:39 - 2015-07-10 13:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-02 23:39 - 2015-07-10 13:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 23:39 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-02 23:39 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-02 23:39 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-02 23:39 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-02 13:29 - 2014-02-07 14:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cheat Engine 6.3
2015-10-02 13:28 - 2014-02-07 14:41 - 00000000 ____D C:\Program Files (x86)\Cheat Engine 6.3
2015-10-02 13:27 - 2015-07-10 13:04 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-02 13:27 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-02 13:27 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-02 13:27 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-02 13:26 - 2015-07-10 13:04 - 00000000 __RSD C:\WINDOWS\Media
2015-10-02 13:26 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Speech_OneCore
2015-10-02 13:26 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\Speech_OneCore
2015-10-02 13:26 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\IME
2015-10-02 13:26 - 2015-07-10 11:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-02 13:26 - 2015-06-14 14:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Dev Tycoon
2015-10-02 13:26 - 2015-05-29 14:10 - 00000000 ____D C:\ProgramData\Razer
2015-10-02 13:26 - 2015-05-29 14:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-10-02 13:25 - 2015-06-14 14:45 - 00000000 ____D C:\Program Files (x86)\Game Dev Tycoon
2015-10-02 13:25 - 2015-05-29 14:10 - 00000000 ____D C:\Program Files (x86)\Razer
2015-10-02 13:15 - 2015-08-15 01:25 - 00000000 ____D C:\Windroy
2015-09-26 08:24 - 2012-03-23 10:05 - 00000000 ____D C:\Users\Katka\Documents\Súbory programu Outlook
2015-09-25 10:11 - 2015-05-29 14:12 - 00000000 ____D C:\Users\Katka\Documents\Razer
2015-09-24 14:17 - 2015-02-12 17:43 - 00000000 ____D C:\Users\Katka\Documents\MEMENTO2
2015-09-24 14:17 - 2014-11-21 22:42 - 00000000 ____D C:\Users\Katka\Documents\VirtualDJ
2015-09-24 14:17 - 2014-09-22 11:28 - 00000000 ____D C:\Users\Katka\Documents\Battlefield 2
2015-09-24 14:17 - 2014-07-31 08:57 - 00000000 ____D C:\Users\Katka\Documents\Hunting Unlimited 2010
2015-09-24 14:17 - 2014-07-20 19:12 - 00000000 ____D C:\Users\Katka\Documents\SimCity
2015-09-24 14:17 - 2014-07-13 09:51 - 00000000 ____D C:\Users\Katka\Documents\Mount&Blade Warband
2015-09-24 14:17 - 2014-01-21 10:57 - 00000000 ____D C:\Users\Katka\Documents\The Raven
2015-09-24 14:17 - 2014-01-12 00:29 - 00000000 ____D C:\Users\Katka\Documents\Mount&Blade With Fire and Sword
2015-09-24 14:17 - 2013-10-16 16:19 - 00000000 ____D C:\Users\Katka\Documents\Battleground Europe
2015-09-24 14:17 - 2013-05-31 13:29 - 00000000 ____D C:\Users\Katka\Documents\World in Conflict
2015-09-24 12:56 - 2015-08-15 00:12 - 00000000 ____D C:\ProgramData\BlueStacksSetup
2015-09-24 12:53 - 2015-07-10 13:04 - 00000000 __RHD C:\Users\Public\Libraries
2015-09-24 12:37 - 2015-08-15 00:08 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Andy
2015-09-24 12:37 - 2015-08-15 00:08 - 00000000 ____D C:\Program Files\Andy
2015-09-22 14:46 - 2015-08-20 23:07 - 00000000 ____D C:\Windows.old
2015-09-22 02:21 - 2013-06-22 08:08 - 00003804 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-09-21 11:49 - 2015-09-15 21:05 - 00000000 ____D C:\Program Files\Common Files\AV
2015-09-19 18:34 - 2014-07-28 14:44 - 00000000 ____D C:\Users\Katka\AppData\Roaming\Tunngle
2015-09-19 15:01 - 2015-08-20 23:37 - 00000000 ____D C:\Users\Katka\OneDrive

==================== Files in the root of some directories =======

2012-06-19 18:16 - 2012-06-19 18:17 - 11708452 _____ () C:\Program Files (x86)\BPClientSetup-1a.bin
2014-07-05 12:29 - 2014-05-15 22:57 - 0002100 ____R () C:\Program Files (x86)\steam_api.ini
2015-09-07 20:32 - 2015-09-07 20:34 - 0704282 _____ () C:\Program Files (x86)\unins000.exe
2015-04-19 14:20 - 2015-04-19 14:20 - 0005872 _____ () C:\Users\Katka\AppData\Roaming\1mDHiGhEEzbW
2013-06-18 11:30 - 2014-12-14 13:26 - 0000000 _____ () C:\Users\Katka\AppData\Roaming\bitlord_log.txt
2015-04-14 18:28 - 2015-04-14 18:28 - 0004387 _____ () C:\Users\Katka\AppData\Roaming\EiiC8bVNTr3NX8Ls
2012-10-31 13:59 - 2015-07-18 17:23 - 0008704 ___SH () C:\Users\Katka\AppData\Roaming\Thumbs.db
2012-03-25 04:36 - 2012-03-25 04:36 - 0033134 _____ () C:\Users\Katka\AppData\Roaming\UserTile.png
2015-10-19 02:20 - 2015-10-19 02:21 - 0029696 _____ () C:\Users\Katka\AppData\Local\MSGBOX.EXE
2014-12-14 13:26 - 2014-12-14 13:26 - 0000218 _____ () C:\Users\Katka\AppData\Local\recently-used.xbel
2012-03-25 11:55 - 2015-05-29 13:53 - 0007600 _____ () C:\Users\Katka\AppData\Local\Resmon.ResmonCfg
2012-06-01 10:52 - 2012-06-01 10:52 - 0000928 _____ () C:\Users\Katka\AppData\Local\SRDownloader.nast
2012-11-24 09:08 - 2014-01-28 17:35 - 1145382 _____ () C:\Users\Katka\AppData\Local\Tempmusic.ogg
2015-10-16 09:45 - 2015-10-16 09:45 - 0000008 _____ () C:\ProgramData\-
2015-08-20 22:23 - 2015-08-20 22:23 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2012-03-21 00:34 - 2012-03-21 00:34 - 0000106 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2015-10-08 01:51 - 2015-10-08 01:51 - 0000102 _____ () C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat

Files to move or delete:
====================
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat


Some files in TEMP:
====================
C:\Users\Katka\AppData\Local\Temp\7za.exe
C:\Users\Katka\AppData\Local\Temp\DaS_21.exe
C:\Users\Katka\AppData\Local\Temp\hijackthis.exe
C:\Users\Katka\AppData\Local\Temp\i4jdel0.exe
C:\Users\Katka\AppData\Local\Temp\InstHelper.exe
C:\Users\Katka\AppData\Local\Temp\Java Runtime Environment 1.7.0.25 (32-bit).exe
C:\Users\Katka\AppData\Local\Temp\NirCmd.exe
C:\Users\Katka\AppData\Local\Temp\PEVZ.EXE
C:\Users\Katka\AppData\Local\Temp\remove.exe
C:\Users\Katka\AppData\Local\Temp\sed.exe
C:\Users\Katka\AppData\Local\Temp\shortcut.exe
C:\Users\Katka\AppData\Local\Temp\sqlite3.dll
C:\Users\Katka\AppData\Local\Temp\swreg.exe
C:\Users\Katka\AppData\Local\Temp\swxcacls.exe
C:\Users\Katka\AppData\Local\Temp\tmp5D80.tmp.exe
C:\Users\Katka\AppData\Local\Temp\tmp7721.tmp.exe
C:\Users\Katka\AppData\Local\Temp\tmp955C.tmp.exe
C:\Users\Katka\AppData\Local\Temp\wget.exe
C:\Users\Katka\AppData\Local\Temp\zoek-delete.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-11 19:16

==================== End of FRST.txt ============================
Přílohy
Addition.rar
(22.47 KiB) Staženo 91 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problem s winnet32b

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utlitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Re: Problem s winnet32b

#3 Příspěvek od krakenus600 »

Nic nenaslo ale log vam sem hodím.Ja som asi 3 hodiny dozadu cez tento cleaner cistil vtedy tam toho dost odstranilo :)
# AdwCleaner v5.014 - Logfile created 19/10/2015 at 18:59:34
# Updated 18/10/2015 by Xplode
# Database : 2015-10-18.5 [Server]
# Operating system : Windows 10 Home (x64)
# Username : Katka - KATKA-PC
# Running from : C:\Users\Katka\Desktop\adwcleaner_5.014.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****


########## EOF - C:\AdwCleaner\AdwCleaner[S6].txt - [568 bytes] ##########

krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Re: Problem s winnet32b

#4 Příspěvek od krakenus600 »

Nebude vadit ak to odlozime na zajtra ??? Musím odíst zatial my napíste ako pokracovat a ja to zajtra vykonám :) Dakujem

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problem s winnet32b

#5 Příspěvek od Rudy »

Toto je OK. Otevřte poznámkový blok a zkopírujte do něj:
Start
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [6f8a6591c8657bdc073fdcfeb43cfc54] => "C:\Users\Katka\AppData\Local\Temp\server.exe" .. <===== ATTENTION
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [51e746e8623104af4605a1df9f24a4be] => "C:\Users\Katka\AppData\Local\Temp\task.exe" .. <===== ATTENTION
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {0faffbd9-a926-11e4-9048-402cf4690980} - "H:\autorun.exe"
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {64cdc4b5-511f-11e4-8c00-402cf4690980} - "F:\setup.exe"
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {64cdc4bd-511f-11e4-8c00-402cf4690980} - "G:\autorun.exe"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F. ... 48ZR1oNgFg,
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73 ... asfIKM,&q={searchTerms}
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73 ... asfIKM,&q={searchTerms}
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73 ... asfIKM,&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL =
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL =
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM-x32\...\Chrome\Extension: [fgnippahjheicjenccifemomfgjofdhp] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path/update_url>
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\SysWOW64\sho8C71.tmp
C:\WINDOWS\Tasks\EiiC8bVNTr3NX8Ls.job
C:\WINDOWS\Tasks\1mDHiGhEEzbW.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\ProgramData\DP45977C.lfl
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
C:\Users\Katka\AppData\Local\Temp
Task: {0709DE4B-4D8A-42C6-8466-4DB38EB64E95} - \temp_2300726e-d013-4e97-93b8-82cdb2191e24-1-6 -> No File <==== ATTENTION
Task: {11EA7051-56A4-422B-8448-9D6069F0D1D9} - \Torntv V6.0-firefoxinstaller -> No File <==== ATTENTION
Task: {22228DBB-FEAA-4626-B0A5-D6F4835E4475} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {26AD5CA4-D6F3-4EB4-A4C1-B7EB19496F93} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
ask: {4139F700-851E-45E6-A4A3-0D96A03FDE3A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {462093FE-2555-4DFF-940F-C4814D6798F3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {58CBF232-B2AE-4A6D-885E-00C9E89945AE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {60A3AB5C-9BC6-4D03-B596-69B4B8221855} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {6A5DEA37-2BC9-4CD9-B9E6-6BCEB9BC663E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {834F9BDE-9F07-44BA-A6B9-E5F90B2646A7} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {A05EA408-0942-464C-BC41-AAE1E09163FF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A772A117-6E7A-4B21-8ADB-40E815FC3847} - \temp_2300726e-d013-4e97-93b8-82cdb2191e24-6 -> No File <==== ATTENTION
Task: {B1FFB7B5-705B-4386-B8CB-C4B8A1BB6464} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {D59BC892-3522-4F8E-A6EB-1459230727EE} - \Torntv V6.0-chromeinstaller -> No File <==== ATTENTION
Task: {E717EA8A-82D8-4A7A-9AE7-4421B0FD13D2} - System32\Tasks\1mDHiGhEEzbW => C:\Users\Katka\AppData\Roaming\1mDHiGhEEzbW.exe <==== ATTENTION
Task: {EAC13133-25A0-4F1E-A404-AFB2F45C6A25} - System32\Tasks\EiiC8bVNTr3NX8Ls => C:\Users\Katka\AppData\Roaming\EiiC8bVNTr3NX8Ls.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\1mDHiGhEEzbW.job => C:\Users\Katka\AppData\Roaming\1mDHiGhEEzbW.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\EiiC8bVNTr3NX8Ls.job => C:\Users\Katka\AppData\Roaming\EiiC8bVNTr3NX8Ls.exe <==== ATTENTION
Task: {6FDB4F87-61F3-4E35-8D88-9779894B1DFE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:2AE74FF9
AlternateDataStreams: C:\ProgramData\Temp:B3196E8D
AlternateDataStreams: C:\ProgramData\Temp:C5760A8B
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1

ResetHosts:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Až se ozvete, budeme pokračovat. :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Re: Problem s winnet32b

#6 Příspěvek od krakenus600 »

Neviem či som to urobil správne ale tu je ten log :)
Fix result of Farbar Recovery Scan Tool (x64) Version:18-10-2015
Ran by Katka (2015-10-20 14:03:00) Run:1
Running from C:\Users\Katka\Desktop
Loaded Profiles: Katka (Available Profiles: Katka & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [6f8a6591c8657bdc073fdcfeb43cfc54] => "C:\Users\Katka\AppData\Local\Temp\server.exe" .. <===== ATTENTION
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\Run: [51e746e8623104af4605a1df9f24a4be] => "C:\Users\Katka\AppData\Local\Temp\task.exe" .. <===== ATTENTION
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {0faffbd9-a926-11e4-9048-402cf4690980} - "H:\autorun.exe"
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {64cdc4b5-511f-11e4-8c00-402cf4690980} - "F:\setup.exe"
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\...\MountPoints2: {64cdc4bd-511f-11e4-8c00-402cf4690980} - "G:\autorun.exe"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://%66%65%65%64.%73%6E%61%70%64%6F. ... 48ZR1oNgFg,
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73 ... asfIKM,&q={searchTerms}
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73 ... asfIKM,&q={searchTerms}
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main,SearchAssistant = hxxp://%66%65%65%64.%73%6F%6E%69%63-%73 ... asfIKM,&q={searchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL =
SearchScopes: HKLM-x32 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD22} URL =
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL =
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
CHR HKLM-x32\...\Chrome\Extension: [fgnippahjheicjenccifemomfgjofdhp] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path/update_url>
U3 idsvc; no ImagePath
U3 wpcsvc; no ImagePath
C:\WINDOWS\SysWOW64\sho8C71.tmp
C:\WINDOWS\Tasks\EiiC8bVNTr3NX8Ls.job
C:\WINDOWS\Tasks\1mDHiGhEEzbW.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
C:\ProgramData\DP45977C.lfl
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat
C:\Users\Katka\AppData\Local\Temp
Task: {0709DE4B-4D8A-42C6-8466-4DB38EB64E95} - \temp_2300726e-d013-4e97-93b8-82cdb2191e24-1-6 -> No File <==== ATTENTION
Task: {11EA7051-56A4-422B-8448-9D6069F0D1D9} - \Torntv V6.0-firefoxinstaller -> No File <==== ATTENTION
Task: {22228DBB-FEAA-4626-B0A5-D6F4835E4475} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {26AD5CA4-D6F3-4EB4-A4C1-B7EB19496F93} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
ask: {4139F700-851E-45E6-A4A3-0D96A03FDE3A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {462093FE-2555-4DFF-940F-C4814D6798F3} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {58CBF232-B2AE-4A6D-885E-00C9E89945AE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {60A3AB5C-9BC6-4D03-B596-69B4B8221855} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {6A5DEA37-2BC9-4CD9-B9E6-6BCEB9BC663E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {834F9BDE-9F07-44BA-A6B9-E5F90B2646A7} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {A05EA408-0942-464C-BC41-AAE1E09163FF} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {A772A117-6E7A-4B21-8ADB-40E815FC3847} - \temp_2300726e-d013-4e97-93b8-82cdb2191e24-6 -> No File <==== ATTENTION
Task: {B1FFB7B5-705B-4386-B8CB-C4B8A1BB6464} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {D59BC892-3522-4F8E-A6EB-1459230727EE} - \Torntv V6.0-chromeinstaller -> No File <==== ATTENTION
Task: {E717EA8A-82D8-4A7A-9AE7-4421B0FD13D2} - System32\Tasks\1mDHiGhEEzbW => C:\Users\Katka\AppData\Roaming\1mDHiGhEEzbW.exe <==== ATTENTION
Task: {EAC13133-25A0-4F1E-A404-AFB2F45C6A25} - System32\Tasks\EiiC8bVNTr3NX8Ls => C:\Users\Katka\AppData\Roaming\EiiC8bVNTr3NX8Ls.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\1mDHiGhEEzbW.job => C:\Users\Katka\AppData\Roaming\1mDHiGhEEzbW.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\EiiC8bVNTr3NX8Ls.job => C:\Users\Katka\AppData\Roaming\EiiC8bVNTr3NX8Ls.exe <==== ATTENTION
Task: {6FDB4F87-61F3-4E35-8D88-9779894B1DFE} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Temp:2AE74FF9
AlternateDataStreams: C:\ProgramData\Temp:B3196E8D
AlternateDataStreams: C:\ProgramData\Temp:C5760A8B
AlternateDataStreams: C:\ProgramData\Temp:D1B5B4F1

ResetHosts:
End
*****************

HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Windows\CurrentVersion\Run\\6f8a6591c8657bdc073fdcfeb43cfc54 => value removed successfully
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Windows\CurrentVersion\Run\\51e746e8623104af4605a1df9f24a4be => value removed successfully
"HKU\S-1-5-21-3563298145-570701526-3268098968-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0faffbd9-a926-11e4-9048-402cf4690980}" => key removed successfully
HKCR\CLSID\{0faffbd9-a926-11e4-9048-402cf4690980} => key not found.
"HKU\S-1-5-21-3563298145-570701526-3268098968-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{64cdc4b5-511f-11e4-8c00-402cf4690980}" => key removed successfully
HKCR\CLSID\{64cdc4b5-511f-11e4-8c00-402cf4690980} => key not found.
"HKU\S-1-5-21-3563298145-570701526-3268098968-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{64cdc4bd-511f-11e4-8c00-402cf4690980}" => key removed successfully
HKCR\CLSID\{64cdc4bd-511f-11e4-8c00-402cf4690980} => key not found.
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main\\Search Bar => value removed successfully
HKU\S-1-5-21-3563298145-570701526-3268098968-1000\Software\Microsoft\Internet Explorer\Main\\SearchAssistant => value removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}" => key removed successfully
HKCR\Wow6432Node\CLSID\{33BB0A4E-99AF-4226-BDF6-49120163DE86} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001}" => key removed successfully
HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22}" => key removed successfully
HKCR\Wow6432Node\CLSID\{9BB47C17-9C68-4BB3-B188-DD9AF0FD22} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}" => key removed successfully
HKCR\Wow6432Node\CLSID\{afdbddaa-5d3f-42ee-b79c-185a7020515b} => key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\fgnippahjheicjenccifemomfgjofdhp" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk" => key removed successfully
idsvc => service removed successfully
wpcsvc => service removed successfully
C:\WINDOWS\SysWOW64\sho8C71.tmp => moved successfully
C:\WINDOWS\Tasks\EiiC8bVNTr3NX8Ls.job => moved successfully
C:\WINDOWS\Tasks\1mDHiGhEEzbW.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
C:\ProgramData\DP45977C.lfl => moved successfully
C:\ProgramData\{262E20B8-6E20-4CEF-B1FD-D022AB1085F5}.dat => moved successfully
C:\Users\Katka\AppData\Local\Temp => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0709DE4B-4D8A-42C6-8466-4DB38EB64E95}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0709DE4B-4D8A-42C6-8466-4DB38EB64E95}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\temp_2300726e-d013-4e97-93b8-82cdb2191e24-1-6 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{11EA7051-56A4-422B-8448-9D6069F0D1D9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{11EA7051-56A4-422B-8448-9D6069F0D1D9}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Torntv V6.0-firefoxinstaller => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{22228DBB-FEAA-4626-B0A5-D6F4835E4475}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{22228DBB-FEAA-4626-B0A5-D6F4835E4475}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26AD5CA4-D6F3-4EB4-A4C1-B7EB19496F93}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26AD5CA4-D6F3-4EB4-A4C1-B7EB19496F93}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
ask: {4139F700-851E-45E6-A4A3-0D96A03FDE3A} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION => Error: No automatic fix found for this entry.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{462093FE-2555-4DFF-940F-C4814D6798F3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{462093FE-2555-4DFF-940F-C4814D6798F3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{58CBF232-B2AE-4A6D-885E-00C9E89945AE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{58CBF232-B2AE-4A6D-885E-00C9E89945AE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{60A3AB5C-9BC6-4D03-B596-69B4B8221855}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60A3AB5C-9BC6-4D03-B596-69B4B8221855}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A5DEA37-2BC9-4CD9-B9E6-6BCEB9BC663E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A5DEA37-2BC9-4CD9-B9E6-6BCEB9BC663E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{834F9BDE-9F07-44BA-A6B9-E5F90B2646A7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{834F9BDE-9F07-44BA-A6B9-E5F90B2646A7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A05EA408-0942-464C-BC41-AAE1E09163FF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A05EA408-0942-464C-BC41-AAE1E09163FF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A772A117-6E7A-4B21-8ADB-40E815FC3847}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A772A117-6E7A-4B21-8ADB-40E815FC3847}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\temp_2300726e-d013-4e97-93b8-82cdb2191e24-6 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B1FFB7B5-705B-4386-B8CB-C4B8A1BB6464}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B1FFB7B5-705B-4386-B8CB-C4B8A1BB6464}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D59BC892-3522-4F8E-A6EB-1459230727EE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D59BC892-3522-4F8E-A6EB-1459230727EE}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Torntv V6.0-chromeinstaller => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E717EA8A-82D8-4A7A-9AE7-4421B0FD13D2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E717EA8A-82D8-4A7A-9AE7-4421B0FD13D2}" => key removed successfully
C:\WINDOWS\System32\Tasks\1mDHiGhEEzbW => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\1mDHiGhEEzbW" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EAC13133-25A0-4F1E-A404-AFB2F45C6A25}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EAC13133-25A0-4F1E-A404-AFB2F45C6A25}" => key removed successfully
C:\WINDOWS\System32\Tasks\EiiC8bVNTr3NX8Ls => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\EiiC8bVNTr3NX8Ls" => key removed successfully
C:\WINDOWS\Tasks\1mDHiGhEEzbW.job => not found.
C:\WINDOWS\Tasks\EiiC8bVNTr3NX8Ls.job => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6FDB4F87-61F3-4E35-8D88-9779894B1DFE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6FDB4F87-61F3-4E35-8D88-9779894B1DFE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
C:\ProgramData\Temp => ":2AE74FF9" ADS removed successfully.
C:\ProgramData\Temp => ":B3196E8D" ADS removed successfully.
C:\ProgramData\Temp => ":C5760A8B" ADS removed successfully.
C:\ProgramData\Temp => ":D1B5B4F1" ADS removed successfully.
ResetHosts: => Error: No automatic fix found for this entry.

==== End of Fixlog 14:03:34 ====

krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Re: Problem s winnet32b

#7 Příspěvek od krakenus600 »

Len som zabudol pri tom zaskrtnut aditions tak neviem teraz :)

krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Re: Problem s winnet32b

#8 Příspěvek od krakenus600 »

Este chcem dodat ze my od instalacie Windows 10 nefunguje Eset píše ze by sa mala nainstalovat aktualizacia na podporu Windows 10 ale ta nainstalovat nejde cize my nejde ani Eset.A ked ho chcem odinstalovat tak my to tiez nejde a z niakeho dovodu my nejde ani prepnut notebook do nudzového rezimu.Dakujem

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problem s winnet32b

#9 Příspěvek od Rudy »

Smazáno. Eset zkuste odinstalovat touto utilitou: http://www.techsupportall.com/eset-remo ... -download/ . Pak proveďte novou instalaci.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Re: Problem s winnet32b

#10 Příspěvek od krakenus600 »

Tá utilitka funguje aj na Smart Security ??? A síce niečo zmazalo ale ten winnet tam je stále :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problem s winnet32b

#11 Příspěvek od Rudy »

¨Měla by odinstalovat jakýkoli produkt Eset. Zkuste když tak tento: http://download.eset.com/special/ESETUninstaller.exe a použijte v nouz. režimu.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Re: Problem s winnet32b

#12 Příspěvek od krakenus600 »

Eset som uz odinstaloval ale ten winnet32b a conhost tam stale sú :(

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problem s winnet32b

#13 Příspěvek od Rudy »

Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krakenus600
Návštěvník
Návštěvník
Příspěvky: 38
Registrován: 19 říj 2015 17:04

Re: Problem s winnet32b

#14 Příspěvek od krakenus600 »

Tu je hadam je správne :)
Malwarebytes Anti-Malware
www.malwarebytes.org

Dátum kontroly: 20. 10. 2015
Čas kontroly: 21:26
Protokol: mbm.txt
Správca: Áno

Verzia: 2.2.0.1024
Dazabáza malware: v2015.10.20.06
Databáza rootkitov: v2015.10.16.01
Licencia: Bezplatná verzia
Ochrana pred škodlivým softvérom: Vypnuté
Ochrana pred škodlivými webstránkami: Vypnuté
Vlastná ochrana: Vypnuté

OS: Windows 10
CPU: x64
Súborový systém: NTFS
Používateľ: Katka

Typ kontroly: Kontrola hrozieb
Výsledok: Dokončená
Skontrolovaných objektov: 400204
Uplynulý čas: 19 min, 50 s

Pamäť: Zapnuté
Pri spustení: Zapnuté
Súborový systém: Zapnuté
Archívy: Zapnuté
Rootkity: Vypnuté
Heuristika: Zapnuté
PUP: Zapnuté
PUM: Zapnuté

Procesy: 4
PUP.Optional.BitCoinMiner, C:\Users\Katka\AppData\Roaming\Microsoft\Networking\inet32upd.exe, 4880, , [f2440356cfbcd462321d4cff2ed5c040]
PUP.Optional.BitCoinMiner, C:\Users\Katka\AppData\Roaming\Microsoft\Networking\winnet32b.exe, 5092, , [64d231282f5ccd69460a51fa10f302fe]
PUP.Optional.BitCoinMiner, C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost32.exe, 500, , [82b41247acdf91a555fdf15a877c669a]
PUP.Optional.BitCoinMiner, C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost64.exe, 524, , [6cca98c1a0ebf442a6ac05467291728e]

Moduly: 0
(Žiadne škodlivé položky neboli zistené)

Kľúče databázy Registry: 3
PUP.Optional.MediaBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{c2d64ff7-0ab8-4263-89c9-ea3b0f8f050c}, , [84b214455f2cf541cf01e23b56ac9e62],
Trojan.Agent, HKU\S-1-5-21-3563298145-570701526-3268098968-1000\SOFTWARE\--((Mutex))--, , [59dd0d4c97f475c1e5417c7137cb619f],
PUP.Optional.GoHD, HKU\S-1-5-21-3563298145-570701526-3268098968-1000\SOFTWARE\--((Mutex))--, , [6dc9ce8be3a861d5ad2dfb6406fd5fa1],

Hodnoty databázy Registry: 4
PUP.Optional.Linkury.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOjRO2PJzXF6_wgTQcrJUhB22QSRlPpTjw-hNT6TvfjRtfYMi8vPHPdZ7UwFYS4IHR7L6PLRuJqSEasfIKM,&q={searchTerms}, , [2d09afaa0883f6404d2764de7a89be42]
PUP.Optional.Linkury, HKU\S-1-5-21-3563298145-570701526-3268098968-1000\ENVIRONMENT|SNP, http://%66%65%65%64.%73%6E%61%70%64%6F.%63%6F%6D?publisher=APSFRec&co=SK&userid=378851b8-1f48-2b7c-a73f-f3c400227856&searchtype=sc&installDate=15., , [e650ce8b4c3fa4921c546cfbd92a2dd3]
PUP.Optional.Linkury, HKU\S-1-5-21-3563298145-570701526-3268098968-1000\ENVIRONMENT|SNF, C:\ProgramData\ExtTags\snp.sc, , [f244acade4a747eff17eec7bdf247f81]
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-3563298145-570701526-3268098968-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|Default, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOjRO2PJzXF6_wgTQcrJUhB22QSRlPpTjw-hNT6TvfjRtfYMi8vPHPdZ7UwFYS4IHR7L6PLRuJqSEasfIKM,&q={searchTerms}, , [44f2e673f19a55e199d896accb38d32d]

Údaj databázy Registry: 1
PUP.Optional.Linkury.ShrtCln, HKU\S-1-5-21-3563298145-570701526-3268098968-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|Default_Search_URL, http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOjRO2PJzXF6_wgTQcrJUhB22QSRlPpTjw-hNT6TvfjRtfYMi8vPHPdZ7UwFYS4IHR7L6PLRuJqSEasfIKM,&q={searchTerms}, Dobrá: (www.google.com), Zlá: (http://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBUTxkij9_B3daefMIBbhJBot0dQojepyw7QhhWJV-C7itWCcceeSDzhHqdSUv2lUXmVLgslGM4SKqW4sChRuRpkOjRO2PJzXF6_wgTQcrJUhB22QSRlPpTjw-hNT6TvfjRtfYMi8vPHPdZ7UwFYS4IHR7L6PLRuJqSEasfIKM,&q={searchTerms}),,[d4623a1f3f4c0a2c34ce42e9ba4a5ea2]

Priečinky: 0
(Žiadne škodlivé položky neboli zistené)

Súbory: 12
PUP.Optional.Amonetize, C:\Users\Katka\Downloads\DivX.Web.Player.Installer__8420_il4151.exe, , [94a245146f1c2b0b20c54e2681807d83],
Trojan.Agent.PECB, C:\Users\Katka\Downloads\Malwarebytes Anti-Malware Premium 2.1.8 Keygen + Keys.zip, , [f83e6fea5e2dbe78194c32189f6119e7],
PUP.Optional.Amonetize, C:\Users\Katka\Downloads\Microsoft Office 2010 Product Key Generator Full Download__4868_il28788.exe, , [290d0f4a573467cf796cbfb5ae53ad53],
Trojan.MSIL, C:\Users\Katka\Downloads\minecraft(1).exe, , [a69060f95b309a9cedf72d7b916f6d93],
PUP.Optional.BitCoinMiner, C:\Users\Katka\AppData\Roaming\Microsoft\Networking\inet32upd.exe, , [f2440356cfbcd462321d4cff2ed5c040],
PUP.Optional.BitCoinMiner, C:\Users\Katka\AppData\Roaming\Microsoft\Networking\winnet32b.exe, , [64d231282f5ccd69460a51fa10f302fe],
PUP.Optional.BitCoinMiner, C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost32.exe, , [82b41247acdf91a555fdf15a877c669a],
PUP.Optional.BitCoinMiner, C:\Users\Katka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\conhost64.exe, , [6cca98c1a0ebf442a6ac05467291728e],
Trojan.Agent.Trace, C:\Users\Katka\AppData\Roaming\Microsoft\Windows\--((Mutex))--.cfg, , [c86ebb9e96f55ed8a340e9b014ef2cd4],
Trojan.Agent.Trace, C:\Users\Katka\AppData\Roaming\Microsoft\Windows\--((Mutex))--.dat, , [a98da6b390fb78be469dd9c01ce7c739],
Trojan.Agent.Trace, C:\Users\Katka\AppData\Roaming\Microsoft\Windows\--((Mutex))--.xtr, , [c274be9bd0bbd363865d28710ff414ec],
Trojan.Injector.BHO, C:\settings.ini, , [8da9ff5a602b2e08c6e4c29344c0c23e],

Fyzické sektory: 0
(Žiadne škodlivé položky neboli zistené)


(end)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problem s winnet32b

#15 Příspěvek od Rudy »

Všechny nálezy smažte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno