Zdravím, snad se podařilo. Na konci údaje o mém počítači.
OTL logfile created on: 22. 8. 2016 11:14:20 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Admin\Desktop
An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.18427)
Locale: 00000405 | Country: Česká republika | Language: CSY | Date Format: d. M. yyyy
2,00 Gb Total Physical Memory | 1,13 Gb Available Physical Memory | 56,34% Memory free
2,62 Gb Paging File | 1,47 Gb Available in Paging File | 55,92% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 100,25 Gb Total Space | 46,08 Gb Free Space | 45,97% Space Free | Partition Type: NTFS
Drive D: | 132,29 Gb Total Space | 75,05 Gb Free Space | 56,73% Space Free | Partition Type: NTFS
Computer Name: STOLNIPC | User Name: Admin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2016/08/22 11:12:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
PRC - [2016/07/29 08:33:00 | 000,288,920 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.31.5\GoogleCrashHandler.exe
PRC - [2016/06/25 01:45:12 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2016/02/09 03:31:39 | 002,412,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2016/02/08 21:43:15 | 000,524,288 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SettingSyncHost.exe
PRC - [2015/07/23 11:30:03 | 000,138,240 | ---- | M] (Microsoft Corporation) -- C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x86__8wekyb3d8bbwe\livecomm.exe
PRC - [2015/07/14 21:06:59 | 002,631,824 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2015/07/14 21:06:54 | 001,871,504 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2015/07/14 21:06:53 | 018,680,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
PRC - [2015/07/14 21:06:53 | 005,809,808 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
PRC - [2015/07/14 21:06:53 | 004,304,528 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
PRC - [2015/07/14 21:06:53 | 000,921,232 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
PRC - [2015/07/07 11:45:10 | 000,326,016 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MpCmdRun.exe
PRC - [2014/12/13 09:30:19 | 001,818,952 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
PRC - [2014/12/13 09:30:19 | 000,971,920 | ---- | M] (NVIDIA Corporation) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
PRC - [2014/11/08 03:45:43 | 000,897,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\SkyDrive.exe
PRC - [2014/10/29 05:18:49 | 000,070,728 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhost.exe
PRC - [2014/10/29 05:18:49 | 000,067,656 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\taskhostex.exe
PRC - [2014/10/29 05:10:01 | 000,029,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\RuntimeBroker.exe
PRC - [2014/10/29 02:59:34 | 000,067,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\dasHost.exe
PRC - [2014/10/29 02:59:18 | 000,299,520 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\conhost.exe
PRC - [2009/12/02 20:40:40 | 000,068,136 | ---- | M] () -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe
========== Modules (No Company Name) ==========
MOD - [2015/07/14 21:06:59 | 000,011,920 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\Update Core\detoured.dll
========== Services (SafeList) ==========
SRV - [2016/06/25 01:45:12 | 000,082,128 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2016/05/23 15:17:32 | 000,324,224 | R--- | M] (Skype Technologies) [Auto | Stopped] -- C:\Program Files\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2016/02/08 21:37:24 | 001,175,040 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppXDeploymentServer.dll -- (AppXSvc)
SRV - [2016/02/03 17:08:59 | 001,273,856 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\workfolderssvc.dll -- (workfolderssvc)
SRV - [2015/07/22 15:50:23 | 001,172,992 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\diagtrack.dll -- (DiagTrack)
SRV - [2015/07/16 20:42:44 | 000,064,512 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV - [2015/07/14 21:06:54 | 001,871,504 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2015/07/14 21:06:53 | 004,304,528 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe -- (NvStreamSvc)
SRV - [2015/07/14 21:06:53 | 000,921,232 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV - [2015/07/07 11:45:10 | 000,284,520 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV - [2015/07/07 11:45:10 | 000,022,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV - [2015/05/30 21:24:56 | 000,193,536 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV - [2015/05/12 15:18:50 | 000,207,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV - [2015/05/07 17:05:40 | 000,367,104 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2015/02/21 01:24:23 | 000,667,648 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsm.dll -- (LSM)
SRV - [2014/12/13 09:03:05 | 000,410,768 | ---- | M] (NVIDIA Corporation) [On_Demand | Stopped] -- C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2014/10/31 05:12:14 | 000,102,912 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV - [2014/10/29 05:13:19 | 002,948,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\WSService.dll -- (WSService)
SRV - [2014/10/29 03:57:59 | 000,020,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wephostsvc.dll -- (WEPHOSTSVC)
SRV - [2014/10/29 03:57:46 | 000,028,672 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\efssvc.dll -- (EFS)
SRV - [2014/10/29 03:52:18 | 000,052,736 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wiarpc.dll -- (WiaRpc)
SRV - [2014/10/29 03:51:55 | 000,017,920 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\StorSvc.dll -- (StorSvc)
SRV - [2014/10/29 03:51:28 | 000,010,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\svsvc.dll -- (svsvc)
SRV - [2014/10/29 03:47:57 | 000,098,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\fhsvc.dll -- (fhsvc)
SRV - [2014/10/29 03:33:49 | 000,187,904 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2014/10/29 03:23:51 | 000,250,880 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\BthHFSrv.dll -- (BthHFSrv)
SRV - [2014/10/29 03:17:53 | 000,142,848 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\NcaSvc.dll -- (NcaSvc)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicheartbeat)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicvss)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmictimesync)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicshutdown)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicrdv)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmickvpexchange)
SRV - [2014/10/29 03:14:41 | 000,423,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\icsvc.dll -- (vmicguestinterface)
SRV - [2014/10/29 03:04:45 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\smphost.dll -- (smphost)
SRV - [2014/10/29 03:02:21 | 000,103,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV - [2014/10/29 03:01:27 | 000,046,592 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\keyiso.dll -- (KeyIso)
SRV - [2014/10/29 02:59:46 | 000,177,664 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\TimeBrokerServer.dll -- (TimeBroker)
SRV - [2014/10/29 02:59:06 | 000,436,224 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netprofmsvc.dll -- (netprofm)
SRV - [2014/10/29 02:57:20 | 000,126,464 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\ncbservice.dll -- (NcbService)
SRV - [2014/10/29 02:55:58 | 000,305,152 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wcmsvc.dll -- (Wcmsvc)
SRV - [2014/10/29 02:55:34 | 000,209,408 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\vaultsvc.dll -- (VaultSvc)
SRV - [2014/10/29 02:55:15 | 000,312,832 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\das.dll -- (DeviceAssociationService)
SRV - [2014/10/29 02:54:57 | 000,206,336 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\bisrv.dll -- (BrokerInfrastructure)
SRV - [2014/10/29 02:54:38 | 001,245,184 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\wlidsvc.dll -- (wlidsvc)
SRV - [2014/10/29 02:50:55 | 000,167,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\DeviceSetupManager.dll -- (DsmSvc)
SRV - [2014/10/29 02:40:35 | 000,425,472 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\AppReadiness.dll -- (AppReadiness)
SRV - [2013/08/22 07:17:49 | 002,407,936 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\spool\drivers\w32x86\3\PrintConfig.dll -- (PrintNotify)
SRV - [2013/02/04 18:43:22 | 000,155,824 | ---- | M] (Avanquest Software) [On_Demand | Stopped] -- C:\Program Files\Sony\Sony PC Companion\PCCService.exe -- (Sony PC Companion)
SRV - [2009/12/02 20:40:40 | 000,068,136 | ---- | M] () [Auto | Running] -- C:\Program Files\GIGABYTE\EnergySaver\GSvr.exe -- (GEST Service)
SRV - [2009/04/30 12:23:26 | 000,090,112 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe -- (OMSI download service)
========== Driver Services (SafeList) ==========
DRV - [2016/08/22 08:11:02 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\gdrv.sys -- (gdrv)
DRV - [2016/06/11 20:30:07 | 000,047,968 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\stornvme.sys -- (stornvme)
DRV - [2016/01/24 20:24:22 | 000,365,912 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\spaceport.sys -- (spaceport)
DRV - [2015/11/10 03:56:32 | 000,178,840 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\nvhda32v.sys -- (NVHDA)
DRV - [2015/10/11 08:39:31 | 000,377,176 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\USBHUB3.SYS -- (USBHUB3)
DRV - [2015/09/29 14:30:04 | 000,131,416 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\tpm.sys -- (TPM)
DRV - [2015/07/14 21:06:52 | 000,018,576 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV - [2015/07/07 11:45:06 | 000,233,304 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\Drivers\WdFilter.sys -- (WdFilter)
DRV - [2015/07/07 11:45:06 | 000,084,824 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\WdNisDrv.sys -- (WdNisDrv)
DRV - [2015/07/07 11:45:05 | 000,038,928 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\WdBoot.sys -- (WdBoot)
DRV - [2015/07/03 06:31:37 | 000,042,344 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\nvvad32v.sys -- (nvvad_WaveExtensible)
DRV - [2015/04/16 08:22:42 | 000,259,928 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\USBXHCI.SYS -- (USBXHCI)
DRV - [2015/03/20 03:47:40 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\ahcache.sys -- (ahcache)
DRV - [2015/03/09 03:18:05 | 000,049,664 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bthhfenum.sys -- (BthHFEnum)
DRV - [2015/03/04 12:05:35 | 000,279,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\clfs.sys -- (CLFS)
DRV - [2015/01/27 01:23:46 | 000,011,520 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2014/12/13 12:02:10 | 008,536,208 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\nvlddmkm.sys -- (nvlddmkm)
DRV - [2014/11/10 19:47:26 | 000,069,440 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\wfplwfs.sys -- (WFPLWFS)
DRV - [2014/11/04 21:28:52 | 000,051,520 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\System32\Drivers\dam.sys -- (dam)
DRV - [2014/10/29 05:10:54 | 000,045,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\wpcfltr.sys -- (wpcfltr)
DRV - [2014/10/29 05:10:13 | 000,022,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2014/10/29 05:10:05 | 000,091,792 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vmbus.sys -- (vmbus)
DRV - [2014/10/29 05:10:05 | 000,044,688 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\vmstorfl.sys -- (storflt)
DRV - [2014/10/29 04:01:33 | 000,026,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\TsUsbGD.sys -- (TsUsbGD)
DRV - [2014/10/29 04:01:08 | 000,071,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\netvsc63.sys -- (netvsc)
DRV - [2014/10/29 04:00:54 | 000,109,568 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV - [2014/10/29 04:00:52 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mslldp.sys -- (MsLldp)
DRV - [2014/10/29 04:00:32 | 000,090,112 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\System32\Drivers\Ndu.sys -- (Ndu)
DRV - [2014/10/17 05:15:58 | 000,036,160 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\intelpep.sys -- (intelpep)
DRV - [2014/10/17 05:01:38 | 000,076,096 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\pdc.sys -- (pdc)
DRV - [2014/10/07 06:13:01 | 000,163,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\UCX01000.SYS -- (UCX01000)
DRV - [2014/08/15 01:35:51 | 000,122,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msgpioclx.sys -- (GPIOClx0101)
DRV - [2014/03/13 12:12:46 | 000,138,584 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\System32\drivers\wof.sys -- (Wof)
DRV - [2014/02/22 16:40:17 | 000,064,344 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\sdstor.sys -- (sdstor)
DRV - [2014/02/22 13:22:09 | 000,025,600 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\BasicRender.sys -- (BasicRender)
DRV - [2013/10/26 22:28:41 | 000,120,152 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SerCx2.sys -- (SerCx2)
DRV - [2013/09/14 14:42:36 | 000,142,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\VerifierExt.sys -- (VerifierExt)
DRV - [2013/08/22 13:12:54 | 000,030,048 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\terminpt.sys -- (terminpt)
DRV - [2013/08/22 08:13:53 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\condrv.sys -- (condrv)
DRV - [2013/08/22 07:35:20 | 000,061,280 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\System32\Drivers\acpiex.sys -- (acpiex)
DRV - [2013/08/22 07:33:32 | 000,058,208 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\mvumis.sys -- (mvumis)
DRV - [2013/08/22 07:33:31 | 000,033,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\msgpiowin32.sys -- (msgpiowin32)
DRV - [2013/08/22 07:33:30 | 000,068,960 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV - [2013/08/22 07:33:29 | 000,069,472 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\lsi_sss.sys -- (LSI_SSS)
DRV - [2013/08/22 07:33:26 | 000,086,368 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\3ware.sys -- (3ware)
DRV - [2013/08/22 07:33:25 | 000,773,472 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\adp80xx.sys -- (ADP80XX)
DRV - [2013/08/22 07:33:25 | 000,100,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV - [2013/08/22 07:33:24 | 000,073,568 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\EhStorClass.sys -- (EhStorClass)
DRV - [2013/08/22 07:33:01 | 000,276,832 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV - [2013/08/22 07:32:57 | 000,090,976 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\storahci.sys -- (storahci)
DRV - [2013/08/22 07:32:57 | 000,059,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SpbCx.sys -- (SpbCx)
DRV - [2013/08/22 07:32:57 | 000,058,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\SerCx.sys -- (SerCx)
DRV - [2013/08/22 07:32:57 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\uaspstor.sys -- (UASPStor)
DRV - [2013/08/22 07:32:38 | 000,031,584 | ---- | M] (Microsoft Corporation) [Kernel | Disabled | Stopped] -- C:\Windows\System32\Drivers\cnghwassist.sys -- (cnghwassist)
DRV - [2013/08/22 07:24:56 | 000,023,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\uefi.sys -- (UEFI)
DRV - [2013/08/22 07:24:36 | 000,023,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV - [2013/08/22 07:20:22 | 000,042,304 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\storvsc.sys -- (storvsc)
DRV - [2013/08/22 06:11:04 | 000,043,520 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\BasicDisplay.sys -- (BasicDisplay)
DRV - [2013/08/22 06:10:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\HyperVideo.sys -- (HyperVideo)
DRV - [2013/08/22 06:10:37 | 000,008,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\mshidumdf.sys -- (mshidumdf)
DRV - [2013/08/22 06:10:28 | 000,008,704 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpitime.sys -- (acpitime)
DRV - [2013/08/22 06:10:21 | 000,009,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\acpipagr.sys -- (acpipagr)
DRV - [2013/08/22 06:10:04 | 000,018,432 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\System32\Drivers\npsvctrig.sys -- (npsvctrig)
DRV - [2013/08/22 06:10:01 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV - [2013/08/22 06:09:59 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\kdnic.sys -- (kdnic)
DRV - [2013/08/22 06:09:57 | 000,006,528 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vms3cap.sys -- (s3cap)
DRV - [2013/08/22 06:09:50 | 000,011,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\vmgencounter.sys -- (gencounter)
DRV - [2013/08/22 06:09:37 | 000,023,808 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\BthhfHid.sys -- (bthhfhid)
DRV - [2013/08/22 06:09:09 | 000,012,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hyperkbd.sys -- (hyperkbd)
DRV - [2013/08/22 06:09:03 | 000,048,640 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2013/08/22 06:09:01 | 000,032,256 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\hidi2c.sys -- (hidi2c)
DRV - [2013/08/22 06:09:01 | 000,018,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2013/08/22 06:08:37 | 000,026,624 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\dmvsc.sys -- (dmvsc)
DRV - [2013/08/22 06:08:06 | 000,013,312 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV - [2013/08/22 03:58:35 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\fxppm.sys -- (FxPPM)
DRV - [2013/08/13 01:25:32 | 000,016,088 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\bcmfn2.sys -- (bcmfn2)
DRV - [2013/08/10 02:39:44 | 000,524,784 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\System32\Drivers\iaStorAV.sys -- (iaStorAV)
DRV - [2013/07/23 23:18:30 | 000,061,936 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\iaioi2c.sys -- (iaioi2c)
DRV - [2013/07/23 23:18:30 | 000,022,016 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\iaiogpio.sys -- (GPIO)
DRV - [2013/06/18 14:23:13 | 000,490,496 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\Rt630x86.sys -- (RTL8168)
DRV - [2011/05/31 22:18:34 | 001,311,232 | ---- | M] (NXP Semiconductors) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\Ph3xIB32.sys -- (Ph3xIB32)
DRV - [2009/08/24 11:14:30 | 000,044,544 | ---- | M] (AzureWave Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\Drivers\azvusb.sys -- (azvusb)
DRV - [2008/05/16 12:33:14 | 000,115,752 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\s0016unic.sys -- (s0016unic)
DRV - [2008/05/16 12:33:14 | 000,025,512 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\s0016nd5.sys -- (s0016nd5)
DRV - [2008/05/16 12:33:14 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\s0016mdfl.sys -- (s0016mdfl)
DRV - [2008/05/16 12:33:12 | 000,120,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\s0016mdm.sys -- (s0016mdm)
DRV - [2008/05/16 12:33:12 | 000,114,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\s0016mgmt.sys -- (s0016mgmt)
DRV - [2008/05/16 12:33:12 | 000,110,632 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\s0016obex.sys -- (s0016obex)
DRV - [2008/05/16 12:33:12 | 000,089,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\s0016bus.sys -- (s0016bus)
DRV - [2006/12/18 18:53:04 | 001,121,536 | ---- | M] (Philips Semiconductors GmbH) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\Drivers\3xHybrid.sys -- (3xHybrid)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://www.seznam.cz/
IE - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page_TIMESTAMP = B7 60 30 B5 82 E5 D1 01 [binary data]
IE - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001\SOFTWARE\Microsoft\Internet Explorer\Main,SyncHomePage Protected - It is a violation of Windows Policy to modify. See aka.ms/browserpolicy = 01 00 00 00 1A 00 00 00 6F 51 F7 3D 1E 52 5B 9C 12 B9 1D 1A D7 AF E0 7B 90 F1 B3 B0 7B 41 D1 CE 0F 2D 02 00 00 00 10 00 00 00 2F 49 58 77 6D 39 70 30 6D 25 32 62 55 25 33 64 [binary data]
IE - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001\..\SearchScopes,DefaultScope = {D626AECF-D0EC-458B-BA18-55300D0F02DF}
IE - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001\..\SearchScopes\{012E1000-F331-11DB-8314-0800200C9A66}: "URL" =
http://www.google.com/search?q={searchTerms}
IE - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?FORM=U453DF& ... -SearchBox
IE - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001\..\SearchScopes\{D626AECF-D0EC-458B-BA18-55300D0F02DF}: "URL" =
https://www.google.com/search?q={search ... utEncoding?}
IE - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.1.5: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.1: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.2.4: C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
========== Chrome ==========
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek\0.9_1\
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.9_1\
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\14.1_1\
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.8_1\
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap\1.1_1\
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi\1.4_0\
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\1.0.0.0_1\
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\8.1_1\
CHR - Extension: No name found = C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm\5216.530.0.14_0\
O1 HOSTS File: ([2016/07/22 07:45:05 | 000,000,035 | ---- | M]) - C:\Windows\System32\Drivers\etc\hosts
O4 - HKLM..\Run: [NvBackend] C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [ShadowPlay] C:\Windows\System32\nvspcap.dll (NVIDIA Corporation)
O4 - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner.exe (Piriform Ltd)
O4 - HKU\S-1-5-21-4140605027-1625828158-2128847343-1001..\Run: [RemoTerm.exe] C:\Program Files\Common Files\PCTV Systems\RemoTerm\remoterm.exe (PCTV Systems S.à r.l.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: Garmin Communicator Plug-In
https://static.garmincdn.com/gcp/ie/4.2 ... rol_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 81.200.55.86 81.200.55.34
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{422FBA08-0925-4009-AE87-F2C475D44A88}: DhcpNameServer = 81.200.55.86 81.200.55.34
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/08/22 10:16:34 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs: wlidsvc - C:\Windows\System32\wlidsvc.dll (Microsoft Corporation)
NetSvcs: lfsvc - C:\Windows\System32\GeofenceMonitorService.dll (Microsoft Corporation)
NetSvcs: DsmSvc - C:\Windows\System32\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs: NcaSvc - C:\Windows\System32\NcaSvc.dll (Microsoft Corporation)
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\Windows\System32\SL_ANET.ACM (Sipro Lab Telecom Inc.)
Drivers32: MSVideo8 - C:\Windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
PhysicalDisk0 MBR saved to C:\PhysicalMBR.bin
========== Files/Folders - Created Within 30 Days ==========
[2016/08/22 11:12:17 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
[2016/08/18 18:50:01 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\KD srpen 2016.zip.53pquvo
[2016/08/09 19:42:27 | 015,158,272 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Windows.UI.Xaml.dll
[2016/08/09 19:42:22 | 002,317,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\CertEnroll.dll
[2016/08/09 19:42:22 | 000,227,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppwinob.dll
[2016/08/09 19:42:21 | 000,093,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidclass.sys
[2016/08/09 19:42:20 | 002,976,256 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcorets.dll
[2016/08/09 19:42:20 | 002,165,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wucltux.dll
[2016/08/09 19:42:19 | 000,727,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapi.dll
[2016/08/09 19:42:19 | 000,413,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\webio.dll
[2016/08/09 19:42:19 | 000,318,304 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\storport.sys
[2016/08/09 19:42:19 | 000,091,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ncryptsslp.dll
[2016/08/09 19:42:18 | 003,273,728 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\rdpcore.dll
[2016/08/09 19:42:18 | 000,063,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\dumpfve.sys
[2016/08/09 19:42:17 | 000,288,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\Classpnp.sys
[2016/08/09 19:42:17 | 000,218,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Windows.Devices.Geolocation.dll
[2016/08/09 19:42:17 | 000,047,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\stornvme.sys
[2016/08/09 19:42:16 | 001,192,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\sppobjs.dll
[2016/08/09 19:42:16 | 000,099,136 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\cryptxml.dll
[2016/08/09 19:42:15 | 000,363,520 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\tpmvsc.dll
[2016/08/09 19:42:15 | 000,281,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\LocationApi.dll
[2016/08/09 19:42:15 | 000,030,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\UserAccountBroker.exe
[2016/08/09 19:42:13 | 005,761,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ntoskrnl.exe
[2016/08/09 19:42:11 | 000,543,232 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\FirewallAPI.dll
[2016/08/09 19:42:10 | 000,592,896 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fveapi.dll
[2016/08/09 19:42:10 | 000,334,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\WUSettingsProvider.dll
[2016/08/09 19:42:10 | 000,192,512 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\gpresult.exe
[2016/08/09 19:42:10 | 000,020,480 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wfapigp.dll
[2016/08/09 19:42:09 | 000,309,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\fvecpl.dll
[2016/08/09 19:42:09 | 000,104,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\httpprxm.dll
[2016/08/09 19:42:09 | 000,066,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\hbaapi.dll
[2016/08/09 19:42:09 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\httpprxp.dll
[2016/08/09 19:42:08 | 001,060,352 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certutil.exe
[2016/08/09 19:42:08 | 000,088,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\BdeHdCfgLib.dll
[2016/08/09 19:42:08 | 000,063,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\adhsvc.dll
[2016/08/09 19:42:08 | 000,044,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\certenc.dll
[2016/08/09 19:42:08 | 000,026,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\drivers\hidparse.sys
[2016/08/09 19:42:07 | 002,464,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\authui.dll
[2016/08/09 19:42:07 | 000,124,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuwebv.dll
[2016/08/09 19:42:07 | 000,081,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wudriver.dll
[2016/08/09 19:42:07 | 000,029,696 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\wuapp.exe
[2016/08/09 19:41:40 | 003,479,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\win32k.sys
[2016/08/09 19:41:40 | 000,147,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\TpmTasks.dll
[2016/08/09 19:41:26 | 005,265,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\Windows.Data.Pdf.dll
[2016/08/09 19:41:25 | 005,270,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\glcndFilter.dll
[2016/08/09 19:41:06 | 004,608,000 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2016/08/09 19:41:05 | 002,055,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2016/08/09 19:41:05 | 000,692,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2016/08/09 19:41:04 | 000,689,152 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2016/08/09 19:41:04 | 000,330,752 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2016/08/09 19:41:02 | 000,710,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2016/08/09 19:40:31 | 001,491,456 | ---- | C] (Microsoft Corporation) -- C:\Windows\System32\GdiPlus.dll
[2016/07/29 22:13:56 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\YouTube Downloader
[2016/07/29 22:13:15 | 000,000,000 | ---D | C] -- C:\Program Files\YTD
[2016/07/29 18:18:46 | 000,000,000 | ---D | C] -- C:\Users\Admin\Desktop\tisk
[2016/07/23 17:42:32 | 000,000,000 | ---D | C] -- C:\Program Files\Defraggler
[2016/07/23 17:35:24 | 000,000,000 | ---D | C] -- C:\ProgramData\GPCWValidator
[2016/07/23 17:35:24 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Roaming\FileOpenerWindows
[2016/07/23 17:27:45 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2016/07/23 17:27:38 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2016/08/22 11:17:08 | 000,000,512 | ---- | M] () -- C:\PhysicalMBR.bin
[2016/08/22 11:12:17 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Admin\Desktop\OTL.exe
[2016/08/22 10:57:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2016/08/22 09:38:01 | 000,000,966 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/08/22 08:38:00 | 000,000,962 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/08/22 08:11:02 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) -- C:\Windows\gdrv.sys
[2016/08/22 08:10:54 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2016/08/22 08:10:49 | 1716,715,520 | -HS- | M] () -- C:\hiberfil.sys
[2016/08/21 16:02:59 | 000,113,647 | ---- | M] () -- C:\Users\Admin\Desktop\OTS přestal skenovat 2.jpg
[2016/08/21 15:43:27 | 000,116,931 | ---- | M] () -- C:\Users\Admin\Desktop\zastavení OTS.jpg
[2016/08/10 08:14:28 | 000,423,024 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2016/08/09 08:47:43 | 000,738,682 | ---- | M] () -- C:\Windows\System32\perfh005.dat
[2016/08/09 08:47:43 | 000,722,278 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2016/08/09 08:47:43 | 000,151,404 | ---- | M] () -- C:\Windows\System32\perfc005.dat
[2016/08/09 08:47:43 | 000,135,394 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2016/08/02 07:21:20 | 004,608,000 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\jscript9.dll
[2016/08/02 07:15:09 | 000,692,736 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\msfeeds.dll
[2016/08/02 07:15:01 | 000,330,752 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\iedkcs32.dll
[2016/08/02 07:14:58 | 000,689,152 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ie4uinit.exe
[2016/08/02 07:14:32 | 002,055,680 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\inetcpl.cpl
[2016/08/02 06:51:20 | 000,710,144 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\ieapfltr.dll
[2016/07/29 22:13:17 | 000,000,911 | ---- | M] () -- C:\Users\Admin\Desktop\YTD.lnk
[2016/07/29 22:09:17 | 000,170,200 | ---- | M] (Malwarebytes) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys
[2016/07/27 21:25:30 | 000,406,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\MpSigStub.exe
[2016/07/23 17:42:38 | 000,001,879 | ---- | M] () -- C:\Users\Public\Desktop\Defraggler.lnk
[2016/07/23 17:37:31 | 000,000,981 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2016/07/23 17:33:04 | 000,064,434 | ---- | M] () -- C:\Users\Admin\Documents\cc_20160723_173226-23.7.2016.reg
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2016/08/22 11:17:08 | 000,000,512 | ---- | C] () -- C:\PhysicalMBR.bin
[2016/08/21 16:02:59 | 000,113,647 | ---- | C] () -- C:\Users\Admin\Desktop\OTS přestal skenovat 2.jpg
[2016/08/21 15:43:27 | 000,116,931 | ---- | C] () -- C:\Users\Admin\Desktop\zastavení OTS.jpg
[2016/07/29 22:13:17 | 000,000,923 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD.lnk
[2016/07/29 22:13:17 | 000,000,911 | ---- | C] () -- C:\Users\Admin\Desktop\YTD.lnk
[2016/07/29 08:33:26 | 000,000,966 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2016/07/29 08:33:25 | 000,000,962 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2016/07/23 17:42:38 | 000,001,879 | ---- | C] () -- C:\Users\Public\Desktop\Defraggler.lnk
[2016/07/23 17:32:51 | 000,064,434 | ---- | C] () -- C:\Users\Admin\Documents\cc_20160723_173226-23.7.2016.reg
[2016/07/23 17:27:45 | 000,000,981 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2016/07/17 14:38:04 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2015/01/05 19:16:26 | 000,652,096 | ---- | C] () -- C:\Windows\System32\nvmcumd.dll
[2014/12/17 14:17:03 | 000,007,601 | ---- | C] () -- C:\Users\Admin\AppData\Local\Resmon.ResmonCfg
[2014/12/15 12:37:04 | 004,151,176 | ---- | C] () -- C:\Windows\System32\nvcoproc.bin
[2014/12/10 20:23:36 | 000,000,384 | ---- | C] () -- C:\Windows\ODBC.INI
[2014/12/10 13:39:11 | 000,107,008 | ---- | C] () -- C:\Windows\System32\OEMLicense.dll
[2014/12/10 13:39:02 | 000,075,264 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2014/12/10 13:38:50 | 000,046,080 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2014/12/10 13:37:58 | 000,050,745 | ---- | C] () -- C:\Windows\System32\srms.dat
[2014/12/10 12:29:34 | 000,262,335 | ---- | C] () -- C:\Windows\System32\dfpinc.dat
[2014/12/10 12:29:00 | 000,002,255 | ---- | C] () -- C:\Windows\System32\WimBootCompress.ini
========== ZeroAccess Check ==========
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2016/05/28 20:31:21 | 019,788,688 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2014/10/29 02:59:23 | 000,786,944 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2014/10/29 02:57:29 | 000,407,552 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
========== LOP Check ==========
[2014/12/17 15:06:09 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\AVAST Software
[2016/07/23 17:35:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FileOpenerWindows
[2016/08/22 08:51:18 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Garmin
[2015/01/18 09:22:16 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\LibreOffice
[2016/07/29 22:13:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\YouTube Downloader
========== Purity Check ==========
========== Custom Scans ==========
< >
[2013/08/22 09:23:44 | 000,000,006 | -H-- | C] () -- C:\Windows\Tasks\SA.DAT
[2016/07/29 08:33:25 | 000,000,962 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
[2016/07/29 08:33:26 | 000,000,966 | ---- | C] () -- C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
< MD5 for: ATAPI.SYS >
[2013/08/22 07:33:25 | 000,023,392 | ---- | M] (Microsoft Corporation) MD5=72FCAE2CE6DFEAB2AB072435017F3417 -- C:\Windows\System32\Drivers\atapi.sys
[2013/08/22 07:33:25 | 000,023,392 | ---- | M] (Microsoft Corporation) MD5=72FCAE2CE6DFEAB2AB072435017F3417 -- C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_x86_74136ef4a48e4644\atapi.sys
[2013/08/22 07:33:25 | 000,023,392 | ---- | M] (Microsoft Corporation) MD5=72FCAE2CE6DFEAB2AB072435017F3417 -- C:\Windows\WinSxS\x86_mshdc.inf_31bf3856ad364e35_6.3.9600.16384_none_71d7eca13d2363da\atapi.sys
< MD5 for: AUTOCHK.EXE >
[2014/02/22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\System32\autochk.exe
[2014/02/22 13:24:36 | 000,792,576 | ---- | M] (Microsoft Corporation) MD5=1D31E78ED5C40B5C6CC8D3DE713177A5 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.17031_none_76c6a414dd35029f\autochk.exe
[2015/01/09 16:41:35 | 000,023,596 | ---- | M] () MD5=83A4C9BE342BC296EC09492FF7594F13 -- C:\Windows\WinSxS\x86_microsoft-windows-autochk_31bf3856ad364e35_6.3.9600.16384_none_7693b1d0dd5ab82d\autochk.exe
< MD5 for: CDROM.SYS >
[2013/08/22 03:59:12 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=E2FC132D48EA4E8B04432C33EFB77801 -- C:\Windows\System32\Drivers\cdrom.sys
[2013/08/22 03:59:12 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=E2FC132D48EA4E8B04432C33EFB77801 -- C:\Windows\System32\DriverStore\FileRepository\cdrom.inf_x86_9aa051086f0faf61\cdrom.sys
[2013/08/22 03:59:12 | 000,124,928 | ---- | M] (Microsoft Corporation) MD5=E2FC132D48EA4E8B04432C33EFB77801 -- C:\Windows\WinSxS\x86_cdrom.inf_31bf3856ad364e35_6.3.9600.16384_none_f4492069bf60ff88\cdrom.sys
< MD5 for: EXPLORER.EXE >
[2015/01/26 12:41:30 | 000,351,507 | ---- | M] () MD5=19D3FE4509CC4C9EF4689B41E51E229E -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17238_none_e68e63af9529fa1e\explorer.exe
[2016/05/29 14:40:04 | 000,259,279 | ---- | M] () MD5=233904D607A2B86D1547B65FA6CDC3C4 -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17415_none_e6a10675951c7085\explorer.exe
[2015/01/26 12:41:47 | 000,338,808 | ---- | M] () MD5=3A11FC6AEAFEF280A6AC446F1C4F1BF8 -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17284_none_e65452eb95562077\explorer.exe
[2015/01/26 12:41:06 | 000,353,684 | ---- | M] () MD5=8CDECDF390F818CC230CA89423B70CD9 -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.16384_none_e6546b99955603fd\explorer.exe
[2016/02/09 03:31:39 | 002,412,576 | ---- | M] (Microsoft Corporation) MD5=97A7A0521E059D242907EFB73A844F29 -- C:\Windows\explorer.exe
[2016/02/09 03:31:39 | 002,412,576 | ---- | M] (Microsoft Corporation) MD5=97A7A0521E059D242907EFB73A844F29 -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.18231_none_e6874ae19530625e\explorer.exe
[2015/01/26 12:41:14 | 000,345,618 | ---- | M] () MD5=9CC40BBBF7F0082B3C8300BB05EE3729 -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17031_none_e6875ddd95304e6f\explorer.exe
[2015/01/26 12:41:23 | 000,345,492 | ---- | M] () MD5=D838CDA6680CFDA621671D59C4AF4016 -- C:\Windows\WinSxS\x86_microsoft-windows-explorer_31bf3856ad364e35_6.3.9600.17039_none_e68f602d95291927\explorer.exe
< MD5 for: HAL.DLL >
[2015/01/26 14:14:18 | 000,043,164 | ---- | M] () MD5=39B592A28DD1F25F7364D87EFBDCA70A -- C:\Windows\WinSxS\x86_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.16384_none_3fc8b72b7543cc93\hal.dll
[2014/06/02 03:06:29 | 000,337,752 | ---- | M] (Microsoft Corporation) MD5=894E02AA20B793F4A0AF0E815D517F62 -- C:\Windows\System32\hal.dll
[2014/06/02 03:06:29 | 000,337,752 | ---- | M] (Microsoft Corporation) MD5=894E02AA20B793F4A0AF0E815D517F62 -- C:\Windows\WinSxS\x86_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17196_none_3fbfcd3f754a3a85\hal.dll
[2015/01/26 14:14:20 | 000,014,045 | ---- | M] () MD5=970C464EEA25EDCB9B95EEF1904FF1F2 -- C:\Windows\WinSxS\x86_microsoft-windows-hal_31bf3856ad364e35_6.3.9600.17031_none_3ffba96f751e1705\hal.dll
< MD5 for: SCECLI.DLL >
[2015/01/28 19:46:27 | 000,042,572 | ---- | M] () MD5=22CDB04B964A8D34C42BB7ED150784F8 -- C:\Windows\WinSxS\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.16384_none_ccada6e2f4b50450\scecli.dll
[2014/10/29 03:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\System32\scecli.dll
[2014/10/29 03:01:41 | 000,214,016 | ---- | M] (Microsoft Corporation) MD5=FB740FE549197E7B08021EF30327921D -- C:\Windows\WinSxS\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.3.9600.17415_none_ccfa41bef47b70d8\scecli.dll
< MD5 for: SVCHOST.EXE >
[2015/01/28 19:50:49 | 000,007,517 | ---- | M] () MD5=73AA583D4FB0F05C313B38C091D94804 -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.16384_none_4a5b1e2820e75323\svchost.exe
[2014/10/29 05:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\System32\svchost.exe
[2014/10/29 05:17:51 | 000,033,088 | ---- | M] (Microsoft Corporation) MD5=D0ABC231C0B3E88C6B612B28ABBF734D -- C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.3.9600.17415_none_4aa7b90420adbfab\svchost.exe
[2016/03/10 14:07:16 | 000,960,480 | ---- | M] (MalwareBytes) MD5=F86A4139730504047F52CCFB8C47E9F5 -- C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\svchost.exe
< MD5 for: TCPIP.SYS >
[2015/01/28 20:29:10 | 000,269,467 | ---- | M] () MD5=00EAB7E27B0C1632C36C5553ABD7F999 -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17136_none_47f5cc7581d59c80\tcpip.sys
[2015/01/28 20:29:29 | 000,197,174 | ---- | M] () MD5=053CFFA5A19455A31ABECC3E011DC7AD -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17336_none_47f5d04181d596ce\tcpip.sys
[2015/01/28 20:29:35 | 000,002,510 | ---- | M] () MD5=3B07748478F004D4D4C9634F7F48C696 -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17415_none_480a71b581c642bc\tcpip.sys
[2015/01/28 20:28:50 | 000,268,710 | ---- | M] () MD5=3E98D9EB816FFC680AC9BBE019C54EA7 -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17039_none_47f8cb6d81d2eb5e\tcpip.sys
[2016/07/16 11:16:43 | 000,234,122 | ---- | M] () MD5=57B46E772C960143288374FD27495267 -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17485_none_47bec24181ff0653\tcpip.sys
[2015/01/28 20:28:28 | 000,287,906 | ---- | M] () MD5=57E96BA0CC548FDFD3E0C3D261FBE0D0 -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16384_none_47bdd6d981ffd634\tcpip.sys
[2015/01/28 20:29:16 | 000,269,131 | ---- | M] () MD5=5DE2043BCA50652CFE70F4C79331227D -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17238_none_47f7ceef81d3cc55\tcpip.sys
[2015/01/28 20:28:57 | 000,270,000 | ---- | M] () MD5=7BE3F5C68BC357A39C80BFE71CF01DDF -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17085_none_47bebaa981ff11b7\tcpip.sys
[2015/01/28 20:29:23 | 000,195,995 | ---- | M] () MD5=822F4A892E2FCF967EB462F59FBA593B -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.17278_none_47cc8f3f81f43c19\tcpip.sys
[2016/03/12 02:55:09 | 001,846,616 | ---- | M] (Microsoft Corporation) MD5=8E596E7D6E8C55433F93ACF667E37BBC -- C:\Windows\System32\Drivers\tcpip.sys
[2016/03/12 02:55:09 | 001,846,616 | ---- | M] (Microsoft Corporation) MD5=8E596E7D6E8C55433F93ACF667E37BBC -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.18265_none_47d4478581eeedc4\tcpip.sys
[2015/01/28 20:28:43 | 000,292,194 | ---- | M] () MD5=D98AC62CFD221A6F5A1A7AD73A370386 -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16521_none_47fbb94f81d1dcd7\tcpip.sys
[2015/01/28 20:28:37 | 000,290,518 | ---- | M] () MD5=F17EF69AFA223B200500EA2E579FE955 -- C:\Windows\WinSxS\x86_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.3.9600.16456_none_47e0491781e5b236\tcpip.sys
< MD5 for: USERINIT.EXE >
[2015/01/28 20:41:31 | 000,004,269 | ---- | M] () MD5=1AE98168631581DE1343C3A87A6CBCA9 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.16384_none_70c87e9ced498d49\userinit.exe
[2014/10/29 03:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\System32\userinit.exe
[2014/10/29 03:05:25 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=D10643FC0095434C819316CA6CD748C0 -- C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.3.9600.17415_none_71151978ed0ff9d1\userinit.exe
< MD5 for: WINLOGON.EXE >
[2016/01/05 16:59:45 | 000,465,408 | ---- | M] (Microsoft Corporation) MD5=2022624E358053908CB81B4E02245B8F -- C:\Windows\System32\winlogon.exe
[2016/01/05 16:59:45 | 000,465,408 | ---- | M] (Microsoft Corporation) MD5=2022624E358053908CB81B4E02245B8F -- C:\Windows\WinSxS\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.18188_none_04669569f087af83\winlogon.exe
[2015/01/28 20:52:42 | 000,087,679 | ---- | M] () MD5=46FB47056D0BA493D90A973B04E0666C -- C:\Windows\WinSxS\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17031_none_0495b7e1f0655ba5\winlogon.exe
[2016/03/13 23:24:20 | 000,059,207 | ---- | M] () MD5=E3373AA38ED8998A1D8B41A5351A022D -- C:\Windows\WinSxS\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.18083_none_04619211f08c33a9\winlogon.exe
[2015/12/25 20:26:12 | 000,050,780 | ---- | M] () MD5=E8AB39AE14615D6BAFB9D92EB0C8E621 -- C:\Windows\WinSxS\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.17415_none_04af6079f0517dbb\winlogon.exe
[2015/01/28 20:52:40 | 000,093,433 | ---- | M] () MD5=F7C808B8059A76EF5F611BCE72A92075 -- C:\Windows\WinSxS\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.3.9600.16384_none_0462c59df08b1133\winlogon.exe
[2016/03/10 14:07:16 | 000,960,480 | ---- | M] (MalwareBytes) MD5=F86A4139730504047F52CCFB8C47E9F5 -- C:\Program Files\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
< >
< %systemroot%*.* /U /s >
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[15 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp files -> C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\*.tmp -> ]
[1 C:\Windows\Installer\*.tmp files -> C:\Windows\Installer\*.tmp -> ]
[1 C:\Windows\Temp\*.tmp files -> C:\Windows\Temp\*.tmp -> ]
< %SYSTEMDRIVE%\*.exe >
< %ALLUSERSPROFILE%\Application Data\*. >
< %ALLUSERSPROFILE%\Application Data\*.exe /s >
< %APPDATA%\*. >
[2016/01/21 09:51:21 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Adobe
[2014/12/17 15:06:09 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\AVAST Software
[2014/12/10 22:10:29 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FastStone
[2016/07/23 17:35:24 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\FileOpenerWindows
[2016/08/22 08:51:18 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Garmin
[2014/12/10 14:57:44 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Identities
[2015/01/18 09:22:16 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\LibreOffice
[2016/01/21 10:52:27 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Macromedia
[2016/07/22 08:31:28 | 000,000,000 | --SD | M] -- C:\Users\Admin\AppData\Roaming\Microsoft
[2014/12/10 21:58:27 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\NVIDIA
[2016/08/20 18:55:27 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\Skype
[2016/08/17 21:38:23 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\vlc
[2016/07/29 22:13:56 | 000,000,000 | ---D | M] -- C:\Users\Admin\AppData\Roaming\YouTube Downloader