Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Asi virus prosím o pomoc

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Asi virus prosím o pomoc

#1 Příspěvek od enzo1 »

Zdravím vás, mám určitě zavirováno. Únos prohlížeče, popup okna, jiný vyhledávač a jiné nestandartní chování notebooku. Posílám log RSIT:
Logfile of random's system information tool 1.16 (written by random/random)
Run by Pepa at 2017-04-11 11:48:01
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 10 GB (4%) free of 226 GB
Total RAM: 3003 MB (53% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:52:07, on 11.4.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18618)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
C:\Windows\PLFSetI.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files (x86)\Eastone\Application\chrome.exe
C:\Program Files\trend micro\Pepa_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.ourluckysites.com/search/?ty ... earchTerms}
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.ourluckysites.com/search/?ty ... earchTerms}
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.200.3:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Pomocná služba pro přihlášení ke službě Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {a1e75a0e-4397-4ba8-bb50-e19fb66890f4} - (no file)
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files (x86)\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [GarminExpressTrayApp] "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe" (User 'Default user')
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Canon LBP2900 Status Window.lnk = C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Office Excel - res://C:\PROGRA~2\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Odeslat obrázek do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Odeslat stránku do zařízení &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Zdroje informací - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD - Unknown owner - C:\Users\Pepa\AppData\Local\AMD\amd.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Update Service(FirefoxU) (FirefoxU) - Unknown owner - C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
O23 - Service: Garmin Device Interaction Service - Garmin Ltd. or its subsidiaries - C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: YAC Service (iSafeService) - Elex do Brasil Participaçoes Ltda - C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: ScsiAccess - Unknown owner - C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spy Emergency Health Check (SpyEmrgHealth) - Unknown owner - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11984 bytes

====== Enumerating Processes ======

C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
c:\windows\system32\svchost.exe -k dcomlaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k localservicenetworkrestricted
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe"
"C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted
c:\windows\system32\svchost.exe -k localservice
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k networkservice
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localservicenonetwork
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Users\Pepa\AppData\Local\AMD\amd.exe -s
"C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe"
c:\windows\system32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe"
C:\Windows\system32\taskhost.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe"
C:\Windows\system32\CNAB4RPD.EXE
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe"
"C:\Program Files (x86)\Acer\Registration\GregHSRW.exe"
"C:\Windows\PLFSetI.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe"
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe"
"C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe"
"C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe"
"C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe"
c:\windows\system32\svchost.exe -k snarer
c:\windows\system32\svchost.exe -k imgsvc
"C:\Program Files\Acer\Acer Updater\UpdaterService.exe"
C:\Windows\SysWOW64\svchost.exe -k WinSAPSvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Synaptics\SynTP\SynTPHelper.exe"
"C:\Program Files (x86)\Launch Manager\LManager.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe"
"C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe"
C:\Program Files (x86)\CCleaner\CCleaner64.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation
"C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe"
C:\Windows\SysWOW64\svchost.exe -k MVCService
C:\Windows\SysWOW64\rundll32.exe
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\igfxext.exe -Embedding
C:\Windows\system32\igfxsrvc.exe -Embedding
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --original-process-start-time=13136376734388911 --fast-start
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=watcher --main-thread-id=6028 --on-initialized-event-handle=328 --parent-handle=340 /prefetch:6
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=E9302A7FFE6C71B3D8ED9287CE602E90 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-accelerated-video-decode --disable-webrtc-hw-vp8-encoding --disable-gpu-compositing --service-request-channel-token=E9302A7FFE6C71B3D8ED9287CE602E90 --renderer-client-id=5 --mojo-platform-channel-handle=1776 /prefetch:1
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=D19BDB4FC9AAD6DAC0B82D663D9C2C83 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-gpu-compositing --service-request-channel-token=D19BDB4FC9AAD6DAC0B82D663D9C2C83 --renderer-client-id=3 --mojo-platform-channel-handle=2144 /prefetch:1
"C:\Program Files (x86)\Eastone\Application\chrome.exe" --type=renderer --field-trial-handle=1764 --primordial-pipe-token=409628F110F14FCDEB60AA4173CA5DCA --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --disable-gpu-compositing --service-request-channel-token=409628F110F14FCDEB60AA4173CA5DCA --renderer-client-id=4 --mojo-platform-channel-handle=2284 /prefetch:1
"C:\Users\Pepa\Desktop\RSITx64.exe"
C:\Windows\system32\taskeng.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\msiexec.exe /V

====== Scheduled tasks folder ======

C:\Windows\tasks\{011B8E39-CE88-41E0-B0D4-311E33EC992A}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{17533D0E-A9DE-49DD-93CD-ADE62A97FD62}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{1A89CBC3-1771-4C0D-8B7E-E785109150BA}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{25381E09-4350-4CEB-8375-8F9B5FC882B8}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{2C34D498-06D7-4808-AD10-2C290AFC7C68}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{3E70DE31-F555-4BF7-ACCE-E9AF4AEE522B}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{42441CAB-D394-4ED2-B527-BF8586500CBF}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{6B0B2E13-DD0E-4974-82C3-7F7BCAB85C41}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{9355D9FC-1AAB-4933-A742-7E47402C6D12}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{A9827EA4-461C-4E96-BBCE-3BD151F2CAA6}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{B08D7569-C085-4F1D-A2F4-D594EEAE262A}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\tasks\{C91DE031-215F-4A00-AADF-39A56BA2C4DA}.job - C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\scheduleCall.exe -T
C:\Windows\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Atafogh Helper - "C:\Program Files (x86)\Prervoly\anerserly.exe" 7f10ac44-c09a-4c46-92a9-247afe0ea6f6
C:\Windows\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\Windows\system32\tasks\avastBCLRestartS-1-5-21-2349173935-1687467584-554729351-1000 - C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\tasks\CCleanerSkipUAC - "C:\Program Files (x86)\CCleaner\CCleaner.exe" $(Arg0)
C:\Windows\system32\tasks\GarminUpdaterTask - C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Milimili - "C:\Program Files (x86)\MIO\MIO.exe" -bindurl http://api.suibianmaimaicom.com/toshiba ... bs1kns.dat cmd=
C:\Windows\system32\tasks\Puhasy - "msiexec" /i HtTp://d2buh1bf1g584w.cloudfront.net/ms ... v=20170324 /q
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1458737292 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\Windows-PG - C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe C:\Update\psgo\psgo.ps1
C:\Windows\system32\tasks\{20E2C8C3-5DB4-408A-89D1-4C38BD54A02E} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\2\SSM_Uninstall.exe
C:\Windows\system32\tasks\{2AC11547-3FF8-4A4D-912B-D9B2947164FC} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\AppData\Local\Temp\Data\MapSource\MapSource_6163.exe -d C:\Users\Pepa\AppData\Local\Temp\
C:\Windows\system32\tasks\{36A219C0-6B08-4296-802B-D29B8D49A9F3} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\Desktop\irfanviewcestina.exe -d C:\Users\Pepa\Desktop
C:\Windows\system32\tasks\{53F16E9A-9782-4582-8922-367414AEFD68} - D:\AOESETUP.EXE
C:\Windows\system32\tasks\{5A65194E-DB10-41AA-9266-5D0C4D4E2908} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\1\SS_Uninstall.exe
C:\Windows\system32\tasks\{7C64D715-407E-45A2-98B1-E29A1D4DE4B6} - C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Windows\system32\tasks\{88FB3DD7-0BE2-4D38-BFD8-1AD9D8AC2FF4} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\3\SSCDUninstall.exe
C:\Windows\system32\tasks\{B8A9D966-BF69-41CF-9882-B525641CD7F7} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\AppData\Local\Temp\jre-8u45-windows-au.exe -d C:\Windows\SysWOW64 -c /installmethod=jau FAMILYUPGRADE=1
C:\Windows\system32\tasks\{DD770AF6-E648-43B5-9840-2FCE3E8082BA} - C:\Windows\system32\pcalua.exe -a "C:\Users\Pepa\Documents\Ze starého počítače\Prográmky\aoe2pack_v3.01_saj.exe" -d "C:\Users\Pepa\Documents\Ze starého počítače\Prográmky"
C:\Windows\system32\tasks\{E33F0E26-0D8E-4EE7-9ACD-034474810FB3} - C:\Windows\system32\pcalua.exe -a D:\aoesetup.exe -d D:\ -c /autorun
C:\Windows\system32\tasks\{E58CCF12-DBFD-4155-A9A2-B9BCAAED3D6F} - C:\Windows\system32\pcalua.exe -a C:\Windows\SysWOW64\Samsung_USB_Drivers\5\SSSDUninstall.exe
C:\Windows\system32\tasks\{EC838D8B-8D3E-42B4-B99C-E856EBC4DBE6} - C:\Windows\system32\pcalua.exe -a C:\Users\Pepa\Desktop\frd.exe -d C:\Users\Pepa\Desktop
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-2349173935-1687467584-554729351-1000 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup - %systemroot%\system32\rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\ConfigNotification - %systemroot%\System32\sdclt.exe /CONFIGNOTIFICATION
C:\Windows\system32\tasks\Microsoft\Windows\WindowsBackup\Windows Backup Monitor - %systemroot%\system32\sdclt.exe /CHECKSKIPPED
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTask - %SystemRoot%\system32\Wat\WatAdminSvc.exe /run
C:\Windows\system32\tasks\Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline - %SystemRoot%\system32\schtasks.exe /run /I /TN "\Microsoft\Windows\Windows Activation Technologies\ValidationTask"
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask - sc.exe start sppsvc
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem - %SystemRoot%\System32\powercfg.exe -energy -auto
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Lpksetup - C:\Windows\System32\lpksetup.exe -v
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\Windows\System32\mcbuilder.exe
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\StartRecording - %SystemRoot%\ehome\ehrec /StartRecording
C:\Windows\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs

=========Mozilla firefox=========

ProfilePath - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default

prefs.js - "browser.search.suggest.enabled" - false
prefs.js - "browser.startup.homepage" - "http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
prefs.js - "extensions.enabledItems" - "{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}:6.0.17, {b9db16a4-6edc-47ec-a1f4-b86292ed211d}:4.8, {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20, {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21, {AB2CE124-6272-4b12-94A9-7303C7397BD1}:4.2.0.5198, {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22, {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23, {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24, {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3, {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.6.17"
prefs.js - "keyword.URL" - "http://search.conduit.com/ResultsExt.as ... 2475029&q="
prefs.js - "browser.search.useDBForOrder" - true

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF48
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF48


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Google.com/GoogleEarthPlugin]
"Description"=Google Earth in your browser
"Path"=C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109]
"Description"=WLPG Install MIME type
"Path"=C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.127 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll

C:\Program Files (x86)\Mozilla Firefox\extensions\
{AB2CE124-6272-4b12-94A9-7303C7397BD1}
{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}

C:\Program Files (x86)\Mozilla Firefox\plugins\
NPOFFICE.DLL
nppdf32.dll

C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\
{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
{ea614400-e918-4741-9a97-7a972ff7c30b}

C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\
c1bwvxob.xml
luck.xml
ourluckysites.xml
startpageing123.xml

C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\addons.json
Garmin Communicator - extension - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
Seznam lištička - extension - {ea614400-e918-4741-9a97-7a972ff7c30b}
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d}
Mozilla Firefox hotfix - extension - firefox-hotfix@mozilla.org

C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions.json
Garmin Communicator - extension - {195A3098-0BD5-4e90-AE22-BA1C540AFD1E} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\firefox@getpocket.com.xpi
Firefox Hello - extension - loop@mozilla.org - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\features\{520be955-30e9-4205-a269-01fb5292bc8a}\loop@mozilla.org.xpi
Video DownloadHelper - extension - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi
Seznam lištička - extension - {ea614400-e918-4741-9a97-7a972ff7c30b} - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
Multi-process staged rollout - extension - e10srollout@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\e10srollout@mozilla.org.xpi
Pocket - extension - firefox@getpocket.com - C:\Program Files (x86)\Mozilla Firefox\browser\features\firefox@getpocket.com.xpi
Application Update Service Helper - extension - aushelper@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\aushelper@mozilla.org.xpi
Site Deployment Checker - extension - deployment-checker@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi
Web Compat - extension - webcompat@mozilla.org - C:\Program Files (x86)\Mozilla Firefox\browser\features\webcompat@mozilla.org.xpi
Default - theme - {972ce4c6-7e08-4474-a285-3208198ce6fd} - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi
Avast Online Security - webextension - wrc@avast.com - C:\Program Files\AVAST Software\Avast\WebRep\FF48
Avast SafePrice - webextension - sp@avast.com - C:\Program Files\AVAST Software\Avast\SafePrice\FF48

C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\pluginreg.dat
Plugin - Shockwave Flash - 25.0.0.127 - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll

=========Google Chrome=========


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={33BB0A4E-99AF-4226-BDF6-49120163DE86}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL"=http://www.ourluckysites.com/search/?ty ... earchTerms}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={33BB0A4E-99AF-4226-BDF6-49120163DE86}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}]
"URL"=http://www.ourluckysites.com/search/?ty ... earchTerms}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}]
"URL"=http://www.google.com/search?sourceid=i ... lz=1I7ACAW
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}]
"URL"=http://search.conduit.com/ResultsExt.as ... =CT2475029

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-03-31 895528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 529280]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-26 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-31 773920]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocná služba pro přihlášení ke službě Windows Live ID - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-26 186944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F}

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{a1e75a0e-4397-4ba8-bb50-e19fb66890f4}

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2009-09-17 1842472]
"Acer ePower Management"=C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [2009-10-03 496160]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2009-07-06 7940128]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-07-06 1833504]
"PLFSetI"=C:\Windows\PLFSetI.exe [2009-11-21 200704]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2010-08-25 161304]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2010-08-25 386584]
"Persistence"=C:\Windows\system32\igfxpers.exe [2010-08-25 415256]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-03-31 213824]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Program Files (x86)\CCleaner\CCleaner64.exe [2017-03-03 9364696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19 1160408]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BackupManagerTray]
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2009-09-25 261888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BlazeServoTool]
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boxoft Tools]
C:\ProgramData\Boxtools\Boxofttoolbox.exe [2010-12-15 514048]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCleaner Monitoring]
C:\Program Files (x86)\CCleaner\CCleaner64.exe [2017-03-03 9364696]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GarminExpressTrayApp]
C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [2015-10-29 1403304]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Media Codec Update Service]
C:\Program Files (x86)\Essentials Codec Pack\update.exe [2007-04-08 303104]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeznamInstall-uninstall:62298f0e8f87a174e880190b05ada38f]
C:\Users\Pepa\AppData\Local\Temp\\{E638ABC1-0067-474b-A379-87CFE81E7848}.exe -c C:\Users\Pepa\AppData\Roaming\Seznam.cz []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files (x86)\Skype\Phone\Skype.exe /nosplash /minimized []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^Pepa^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\Pepa\AppData\Roaming\Dropbox\bin\Dropbox.exe [2014-03-19 32667896]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2009-11-01 1091152]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-12-12 587288]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer VCM.lnk - C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
Bluetooth.lnk - C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
Canon LBP2900 Status Window.lnk - C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{D0668D3A-0EF4-11E7-B3CD-64006A5CFC35}"=C:\Users\Pepa\AppData\Roaming\Kulerty\Clifly.dll []

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2017-04-11 11:48:02 ----D---- C:\Program Files\trend micro
2017-04-11 11:48:01 ----D---- C:\rsit
2017-04-11 09:15:19 ----D---- C:\ProgramData\SWCUTemp
2017-04-10 23:02:13 ----D---- C:\Program Files (x86)\deskapp
2017-04-10 20:44:51 ----D---- C:\Update
2017-04-06 17:48:36 ----D---- C:\Users\Pepa\AppData\Roaming\SNARER
2017-04-05 10:39:54 ----D---- C:\Program Files (x86)\WINSNARE(4.4.6)
2017-04-01 20:58:39 ----A---- C:\Windows\system32\drivers\iSafeNetFilter.sys
2017-04-01 20:58:39 ----A---- C:\Windows\system32\drivers\iSafeKrnlBoot.sys
2017-04-01 20:58:36 ----D---- C:\Windows\system32\log
2017-04-01 20:58:11 ----D---- C:\Program Files (x86)\Elex-tech
2017-04-01 20:58:06 ----D---- C:\Users\Pepa\AppData\Roaming\Elex-tech
2017-04-01 20:57:48 ----D---- C:\Users\Pepa\AppData\Roaming\Firefox
2017-04-01 20:57:32 ----A---- C:\Windows\SYSWOW64\DB83.tmp
2017-04-01 20:56:57 ----AD---- C:\Program Files (x86)\Firefox
2017-04-01 20:56:38 ----D---- C:\Program Files (x86)\Eastone
2017-03-31 14:23:45 ----A---- C:\Windows\system32\aswBoot.exe
2017-03-31 11:50:05 ----D---- C:\Program Files\MK
2017-03-29 12:15:19 ----D---- C:\ProgramData\Pinnacle VideoSpin
2017-03-29 12:10:56 ----D---- C:\Users\Pepa\AppData\Roaming\Kyubey
2017-03-29 12:10:54 ----D---- C:\Program Files (x86)\MIO
2017-03-29 12:10:48 ----D---- C:\Users\Pepa\AppData\Roaming\WINSNARE
2017-03-29 12:10:47 ----D---- C:\Users\Pepa\AppData\Roaming\WinSAPSvc
2017-03-29 12:09:24 ----D---- C:\Program Files (x86)\MK
2017-03-29 12:07:56 ----D---- C:\Program Files\c1bwvxob
2017-03-27 21:36:55 ----HD---- C:\$AV_ASW
2017-03-26 22:29:02 ----D---- C:\Users\Pepa\AppData\Roaming\Sun
2017-03-26 20:37:55 ----D---- C:\Users\Pepa\AppData\Roaming\Netscape
2017-03-26 20:37:55 ----D---- C:\Program Files (x86)\Photodex Presenter
2017-03-26 20:37:38 ----D---- C:\Program Files (x86)\Photodex
2017-03-26 20:37:06 ----D---- C:\Users\Pepa\AppData\Roaming\Photodex
2017-03-24 16:19:51 ----D---- C:\ProgramData\Pinnacle Studio Ultimate Collection
2017-03-24 16:05:51 ----D---- C:\Program Files (x86)\Pinnacle
2017-03-24 16:03:37 ----A---- C:\ProgramData\__wdump.txt
2017-03-24 15:56:15 ----D---- C:\ProgramData\Pinnacle
2017-03-24 15:53:02 ----A---- C:\Windows\system32\drivers\dtsoftbus01.sys
2017-03-24 15:52:37 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2017-03-24 15:28:54 ----A---- C:\Windows\system32\drivers\dtultrausbbus.sys
2017-03-24 15:28:21 ----A---- C:\Windows\system32\drivers\dtultrascsibus.sys
2017-03-24 15:28:18 ----D---- C:\Users\Pepa\AppData\Roaming\DAEMON Tools Ultra
2017-03-24 15:26:20 ----D---- C:\ProgramData\DAEMON Tools Ultra
2017-03-24 15:04:25 ----D---- C:\Users\Pepa\AppData\Roaming\Kulerty
2017-03-24 15:03:29 ----D---- C:\Program Files (x86)\Atafogh Helper
2017-03-24 15:03:24 ----D---- C:\Users\Pepa\AppData\Roaming\Profiles
2017-03-24 15:03:24 ----D---- C:\Program Files (x86)\Prervoly
2017-03-24 15:01:25 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2017-03-24 15:00:16 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2017-03-16 22:12:27 ----A---- C:\Windows\system32\aepic.dll
2017-03-16 22:12:27 ----A---- C:\Windows\system32\aeinv.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\invagent.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\generaltel.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\devinv.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\centel.dll
2017-03-16 22:12:26 ----A---- C:\Windows\system32\appraiser.dll
2017-03-16 22:12:25 ----A---- C:\Windows\system32\CompatTelRunner.exe
2017-03-16 22:12:25 ----A---- C:\Windows\system32\acmigration.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\inseng.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2017-03-15 16:48:25 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\iertutil.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\iernonce.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-03-15 16:48:25 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-03-15 16:48:24 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-03-15 16:48:24 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\occache.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-03-15 16:48:23 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\inseng.dll
2017-03-15 16:48:23 ----A---- C:\Windows\system32\ie4uinit.exe
2017-03-15 16:48:22 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-03-15 16:48:22 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\jscript.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2017-03-15 16:48:20 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\urlmon.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\occache.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-03-15 16:48:20 ----A---- C:\Windows\system32\iedkcs32.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\ieui.dll
2017-03-15 16:48:19 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2017-03-15 16:48:19 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-03-15 16:48:19 ----A---- C:\Windows\system32\msfeeds.dll
2017-03-15 16:48:19 ----A---- C:\Windows\system32\dxtrans.dll
2017-03-15 16:48:18 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-03-15 16:48:17 ----A---- C:\Windows\system32\iesetup.dll
2017-03-15 16:48:17 ----A---- C:\Windows\system32\ieapfltr.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2017-03-15 16:48:15 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-03-15 16:48:15 ----A---- C:\Windows\system32\vbscript.dll
2017-03-15 16:48:14 ----A---- C:\Windows\SYSWOW64\msrating.dll
2017-03-15 16:48:14 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2017-03-15 16:48:14 ----A---- C:\Windows\system32\jsproxy.dll
2017-03-15 16:48:14 ----A---- C:\Windows\system32\ieUnatt.exe
2017-03-15 16:48:13 ----A---- C:\Windows\system32\ieui.dll
2017-03-15 16:48:13 ----A---- C:\Windows\system32\dxtmsft.dll
2017-03-15 16:48:12 ----A---- C:\Windows\system32\ieframe.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\webcheck.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-03-15 16:48:11 ----A---- C:\Windows\system32\mshtmled.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript9diag.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript9.dll
2017-03-15 16:48:10 ----A---- C:\Windows\system32\jscript.dll
2017-03-15 16:48:09 ----A---- C:\Windows\system32\wininet.dll
2017-03-15 16:48:08 ----A---- C:\Windows\system32\msrating.dll
2017-03-15 16:48:08 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-03-15 16:48:06 ----A---- C:\Windows\system32\mshtml.dll
2017-03-15 16:48:02 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-03-15 16:48:01 ----A---- C:\Windows\system32\win32k.sys
2017-03-15 16:48:00 ----A---- C:\Windows\system32\ntdll.dll
2017-03-15 16:47:59 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2017-03-15 16:47:59 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2017-03-15 16:47:59 ----A---- C:\Windows\system32\lsasrv.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\rpcrt4.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\msxml3.dll
2017-03-15 16:47:58 ----A---- C:\Windows\system32\kerberos.dll
2017-03-15 16:47:57 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-03-15 16:47:57 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\schannel.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\KernelBase.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\DWrite.dll
2017-03-15 16:47:57 ----A---- C:\Windows\system32\advapi32.dll
2017-03-15 16:47:56 ----A---- C:\Windows\SYSWOW64\schannel.dll
2017-03-15 16:47:56 ----A---- C:\Windows\system32\msv1_0.dll
2017-03-15 16:47:56 ----A---- C:\Windows\system32\kernel32.dll
2017-03-15 16:47:55 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2017-03-15 16:47:55 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\usp10.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\quartz.dll
2017-03-15 16:47:55 ----A---- C:\Windows\system32\FntCache.dll
2017-03-15 16:47:55 ----A---- C:\Windows\HelpPane.exe
2017-03-15 16:47:54 ----A---- C:\Windows\SYSWOW64\msxml3.dll
2017-03-15 16:47:54 ----A---- C:\Windows\system32\rpchttp.dll
2017-03-15 16:47:54 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\usp10.dll
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2017-03-15 16:47:53 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\ncrypt.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\gdi32.dll
2017-03-15 16:47:53 ----A---- C:\Windows\system32\drivers\srv.sys
2017-03-15 16:47:53 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-03-15 16:47:53 ----A---- C:\Windows\system32\certcli.dll
2017-03-15 16:47:52 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\quartz.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2017-03-15 16:47:51 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\wow64win.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\inetcomm.dll
2017-03-15 16:47:51 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-03-15 16:47:51 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-03-15 16:47:51 ----A---- C:\Windows\system32\adtschema.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2017-03-15 16:47:50 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\wow64.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\winsrv.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\wdigest.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\TSpkg.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\srcore.dll
2017-03-15 16:47:50 ----A---- C:\Windows\system32\appidsvc.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\certcli.dll
2017-03-15 16:47:49 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\mscms.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-03-15 16:47:49 ----A---- C:\Windows\system32\drivers\appid.sys
2017-03-15 16:47:49 ----A---- C:\Windows\system32\csrsrv.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\conhost.exe
2017-03-15 16:47:49 ----A---- C:\Windows\system32\bcrypt.dll
2017-03-15 16:47:49 ----A---- C:\Windows\system32\appidapi.dll
2017-03-15 16:47:48 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2017-03-15 16:47:48 ----A---- C:\Windows\system32\icm32.dll
2017-03-15 16:47:48 ----A---- C:\Windows\system32\cryptbase.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 16:47:47 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\wow32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\WcsPlugInService.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\srclient.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\setup16.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\secur32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\mscms.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\instnm.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\icm32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\credssp.dll
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2017-03-15 16:47:47 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\wow64cpu.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\WcsPlugInService.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\sspisrv.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\sspicli.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\srclient.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\smss.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\secur32.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\rstrui.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\ntvdm64.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\msaudite.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\lsass.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\credssp.dll
2017-03-15 16:47:47 ----A---- C:\Windows\system32\auditpol.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-03-15 16:47:47 ----A---- C:\Windows\system32\apisetschema.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 16:47:46 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-03-15 16:47:46 ----A---- C:\Windows\SYSWOW64\user.exe
2017-03-15 16:47:46 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2017-03-15 16:47:46 ----A---- C:\Windows\system32\INETRES.dll
2017-03-15 16:47:46 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-03-15 16:47:46 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-03-15 16:47:45 ----A---- C:\Windows\SYSWOW64\msxml3r.dll
2017-03-15 16:47:45 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2017-03-15 16:47:45 ----A---- C:\Windows\system32\msxml3r.dll
2017-03-15 16:47:45 ----A---- C:\Windows\system32\msobjs.dll

====== List of files/folders modified in the last 1 month ======

2017-04-11 11:51:22 ----D---- C:\Windows\Temp
2017-04-11 11:50:59 ----SHD---- C:\Windows\Installer
2017-04-11 11:50:59 ----SHD---- C:\Config.Msi
2017-04-11 11:48:02 ----D---- C:\Program Files
2017-04-11 11:46:02 ----RD---- C:\Program Files (x86)
2017-04-11 11:34:59 ----AD---- C:\Windows\system32\drivers
2017-04-11 09:30:18 ----D---- C:\Windows\system32\config
2017-04-11 09:15:19 ----HD---- C:\ProgramData
2017-04-10 22:48:31 ----SHD---- C:\System Volume Information
2017-04-10 20:44:58 ----D---- C:\Windows\system32\Tasks
2017-04-09 19:53:09 ----D---- C:\Windows
2017-04-09 10:43:08 ----D---- C:\Windows\Prefetch
2017-04-06 17:48:42 ----D---- C:\Windows\SysWOW64
2017-04-06 14:04:56 ----D---- C:\Users\Pepa\AppData\Roaming\vlc
2017-04-06 13:29:31 ----D---- C:\Windows\inf
2017-04-03 10:30:15 ----HD---- C:\Program Files (x86)\Temp
2017-04-02 17:13:23 ----D---- C:\Windows\System32
2017-04-02 17:13:23 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-04-01 20:57:11 ----D---- C:\ProgramData\Package Cache
2017-03-30 17:53:14 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-03-30 01:51:47 ----D---- C:\Windows\winsxs
2017-03-30 01:49:17 ----D---- C:\Users\Pepa\AppData\Roaming\DAEMON Tools Lite
2017-03-29 17:04:41 ----D---- C:\Program Files (x86)\Common Files
2017-03-29 15:57:19 ----D---- C:\Windows\system32\DriverStore
2017-03-29 15:50:13 ----RSD---- C:\Windows\Fonts
2017-03-26 22:27:21 ----N---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2017-03-26 22:26:47 ----D---- C:\Program Files (x86)\Java
2017-03-26 22:25:13 ----N---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-03-26 22:25:02 ----D---- C:\Windows\system32\Macromed
2017-03-26 22:24:56 ----D---- C:\Windows\SYSWOW64\Macromed
2017-03-26 20:37:55 ----D---- C:\Users\Pepa\AppData\Roaming\Mozilla
2017-03-24 16:37:04 ----D---- C:\Users\Pepa\AppData\Roaming\uTorrent
2017-03-24 16:35:57 ----D---- C:\Windows\debug
2017-03-24 14:59:45 ----D---- C:\ProgramData\DAEMON Tools Lite
2017-03-20 19:14:21 ----D---- C:\Users\Pepa\AppData\Roaming\dvdcss
2017-03-17 13:10:37 ----D---- C:\Windows\rescache
2017-03-17 08:13:36 ----SD---- C:\Windows\system32\CompatTel
2017-03-17 08:13:34 ----D---- C:\Windows\system32\appraiser
2017-03-17 08:13:33 ----D---- C:\Windows\AppPatch
2017-03-16 21:42:15 ----D---- C:\Program Files (x86)\Internet Explorer
2017-03-16 21:42:14 ----D---- C:\Program Files\Internet Explorer
2017-03-16 21:42:12 ----D---- C:\Windows\SYSWOW64\migration
2017-03-16 21:42:12 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-03-16 21:42:12 ----D---- C:\Program Files\DVD Maker
2017-03-16 21:42:10 ----D---- C:\Windows\SYSWOW64\en-US
2017-03-16 21:42:02 ----D---- C:\Windows\system32\migration
2017-03-16 21:42:02 ----D---- C:\Windows\system32\cs-CZ
2017-03-16 21:42:00 ----D---- C:\Windows\system32\en-US
2017-03-16 21:41:45 ----D---- C:\Windows\system32\Boot
2017-03-16 00:08:09 ----D---- C:\Windows\system32\MRT
2017-03-16 00:02:47 ----AC---- C:\Windows\system32\MRT.exe
2017-03-15 23:57:05 ----D---- C:\Program Files\Microsoft Silverlight
2017-03-15 23:57:05 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2017-03-15 16:32:42 ----D---- C:\Windows\system32\catroot2

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-03-30 189768]
R0 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-03-30 334088]
R0 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-03-30 48528]
R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-03-31 75704]
R0 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-03-31 339696]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2009-06-05 408600]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [2010-03-18 834544]
R1 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-03-30 307736]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-03-31 32600]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-03-31 101152]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-03-31 1005048]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-03-31 556784]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2017-03-24 254528]
R1 iSafeKrnl;YAC Mini-Filter Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [2016-05-23 262344]
R1 iSafeKrnlKit;YAC Kit Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [2016-05-23 110112]
R1 iSafeKrnlMon;YAC Monitor Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlMon.sys [2016-05-23 52440]
R1 iSafeKrnlR3;YAC Ring3 Driver; \??\C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [2016-05-23 103904]
R1 iSafeNetFilter;YAC NDIS Driver; C:\Windows\system32\DRIVERS\iSafeNetFilter.sys [2016-05-19 52392]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-03-31 127112]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-03-31 164064]
R3 DKbFltr;Dritek Keyboard Filter Driver (64-bit); SysWOW64\Drivers\DKbFltr.sys []
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2010-08-25 10611552]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2009-07-06 1824672]
R3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI; C:\Windows\system32\drivers\IntcHdmi.sys [2009-07-10 139264]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20); C:\Windows\system32\DRIVERS\L1C62x64.sys [2009-07-27 58880]
R3 MarvinBus;Pinnacle Marvin Bus 64; C:\Windows\system32\DRIVERS\MarvinBus64.sys [2005-09-23 261120]
R3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit; C:\Windows\system32\DRIVERS\NETw5s64.sys [2009-09-15 6952960]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2009-05-06 18432]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2009-09-17 292912]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2009-05-06 16896]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 AF15BDA;AF9015 BDA Device; C:\Windows\system32\DRIVERS\AF15BDA.sys [2011-10-19 507392]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-03-31 38296]
S3 BthEnum;Ovladač pro Bluetooth Request Block; C:\Windows\system32\drivers\BthEnum.sys [2009-07-14 41984]
S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2012-07-06 552960]
S3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2011-04-28 80384]
S3 btusbflt;Bluetooth USB Filter; C:\Windows\system32\drivers\btusbflt.sys [2009-07-01 52264]
S3 btwaudio;Bluetooth Audio Device Service; C:\Windows\system32\drivers\btwaudio.sys [2009-07-01 98344]
S3 btwavdt;Bluetooth AVDT Service; C:\Windows\system32\drivers\btwavdt.sys [2009-07-01 132648]
S3 btwl2cap;Bluetooth L2CAP Service; C:\Windows\system32\DRIVERS\btwl2cap.sys [2009-04-07 35104]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2009-07-01 21160]
S3 dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2009-07-14 145920]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2010-11-20 19968]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2009-07-14 43008]
S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtlitescsibus.sys [2017-03-24 30264]
S3 dtliteusbbus;DAEMON Tools Lite Virtual USB Bus; C:\Windows\system32\DRIVERS\dtliteusbbus.sys [2017-03-24 47672]
S3 dtultrascsibus;DAEMON Tools Ultra Virtual SCSI Bus; C:\Windows\system32\DRIVERS\dtultrascsibus.sys [2017-03-24 30264]
S3 dtultrausbbus;DAEMON Tools Ultra Virtual USB Bus; C:\Windows\system32\DRIVERS\dtultrausbbus.sys [2017-03-24 47672]
S3 fssfltr;FssFltr; C:\Windows\system32\DRIVERS\fssfltr.sys [2010-09-23 48488]
S3 iSafeKrnlBoot;YAC Boot Driver; C:\Windows\system32\DRIVERS\iSafeKrnlBoot.sys [2016-05-23 55056]
S3 LgBttPort;LGE Bluetooth TransPort; C:\Windows\system32\DRIVERS\lgbtpt64.sys []
S3 lgbusenum;LG Bluetooth Bus Enumerator; C:\Windows\system32\DRIVERS\lgbtbs64.sys []
S3 lgmdbus;LG Mobile driver (WDM); C:\Windows\system32\DRIVERS\lgmdbus.sys [2008-07-08 115200]
S3 lgmdmdfl;LG Mobile USB WMC Modem Filter; C:\Windows\system32\DRIVERS\lgmdmdfl.sys [2008-07-08 18944]
S3 lgmdmdm;LG Mobile USB WMC Modem Driver; C:\Windows\system32\DRIVERS\lgmdmdm.sys [2008-07-08 158720]
S3 lgmdmgmt;LG Mobile USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\lgmdmgmt.sys [2008-07-08 137216]
S3 lgmdobex;LG Mobile USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\lgmdobex.sys [2008-07-08 136704]
S3 LGVMODEM;LGE Virtual Modem; C:\Windows\system32\DRIVERS\lgvmdm64.sys []
S3 massfilter;Mass Storage Filter Driver; C:\Windows\system32\drivers\massfilter.sys []
S3 netw5v64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit; C:\Windows\system32\DRIVERS\netw5v64.sys [2009-08-22 5435904]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys [2009-05-08 215552]
S3 RtsUIR;Realtek IR Driver; C:\Windows\system32\DRIVERS\Rts516xIR.sys []
S3 TsUsbFlt;@%SystemRoot%\system32\drivers\tsusbflt.sys,-1; C:\Windows\System32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 USBCCID;Realtek Smartcard Reader Driver; C:\Windows\system32\DRIVERS\RtsUCcid.sys []
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 usbser;USB Modem Driver; C:\Windows\system32\DRIVERS\usbser.sys [2013-08-29 33280]
S4 VBoxAswDrv;VBoxAsw Support Driver; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys []

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
R2 AMD;AMD; C:\Users\Pepa\AppData\Local\AMD\amd.exe [2017-03-31 112128]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-03-31 261712]
R2 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe [2009-07-18 864032]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll" = %SystemRoot%\system32\diagtrack.dll
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2009-08-24 107016]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [2009-10-03 786976]
R2 Greg_Service;GRegService; C:\Program Files (x86)\Acer\Registration\GregHSRW.exe [2009-08-28 1150496]
R2 iSafeService;YAC Service; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [2016-12-02 131024]
R2 MDM;Machine Debug Manager; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2009-09-25 62720]
R2 RS_Service;Raw Socket Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [2009-07-10 253952]
R2 ScsiAccess;ScsiAccess; C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe [2017-03-26 181312]
R2 SNARER;SNARER; C:\Windows\System32\svchost.exe -k SNARER;"ServiceDll" = C:\Users\Pepa\AppData\Local\SNARER\Snarer.dll
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2009-07-04 240160]
R3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-03-30 7398336]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-11-29 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-11-29 125112]
S2 FirefoxU;Update Service(FirefoxU); C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [2017-04-01 132272]
S2 Garmin Device Interaction Service;Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [2015-10-29 777744]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
S2 MVCSrv;VC IDE Base Service; %SystemRoot%\System32\svchost.exe -k MVCService;"ServiceDll" = C:\ProgramData\Package Cache\{2A002F88-FD5D-379B-A350-A25D84AF128B}v14.0.25420\packages\VisualC_D14\VC_IDE.Base\VC_IDE_Base.dll
S2 SpyEmrgHealth;Spy Emergency Health Check; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe []
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-03-26 271960]
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2010-09-23 1493352]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-30 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-03-04 114688]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-11-29 146888]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2010-05-21 1255736]
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-11-29 51384]
S4 AvastVBoxSvc;AvastVBox COM Service; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe []
S4 Kyubey;Kyubey; C:\Users\Pepa\AppData\Roaming\Kyubey\Kyubey.exe [2017-03-29 240128]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-11-29 135848]

-----------------EOF-----------------

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Asi virus prosím o pomoc

#2 Příspěvek od JaRon »

ahoj,
citat:
. Junkware removal tool: http://thisisudax.org/downloads/JRT.exe
•Ulozte nejlepe na plochu
•Po spusteni se zobrazi licencni podminky, stisknete libovolnou klavesu
•Probehne vytvoreni zalohy a nasledne prohledavani
•Probehne skenovani a pak se objevi log, pripadne bude ulozen v c:\JRT jako JRT.txt, ten sem vlozte.
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Re: Asi virus prosím o pomoc

#3 Příspěvek od enzo1 »

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 7 Home Premium x64
Ran by Pepa (Administrator) on Łt 11.04.2017 at 13:16:49,58
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 38

Failed to delete: C:\Users\Pepa\AppData\Roaming\elex-tech (Folder)
Failed to delete: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\user.js (File)
Failed to delete: C:\Program Files (x86)\elex-tech (Folder)
Successfully deleted: C:\ProgramData\ask (Folder)
Successfully deleted: C:\ProgramData\partner (Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\{5EC1EEDE-7F70-426B-89C1-0E53FB564E34} (Empty Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\{87BEFB5E-61BF-42AC-90ED-F15AA4AB898A} (Empty Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\{A6EE115C-9B04-46E5-9E3F-E4D514A93018} (Empty Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\{AF017BD1-334C-4296-9592-9377C5CC793A} (Empty Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\{B1641067-7E47-4EAC-8C04-165281BAC53F} (Empty Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\{ED850EBD-8B30-48B1-BF9D-0C1A61F2B9BF} (Empty Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\{F480676D-DC13-4260-A4A1-D8A040B72515} (Empty Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\{FB3CE00F-D09C-4924-A261-C8AD4FA29FB3} (Empty Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\conduit (Folder)
Successfully deleted: C:\Users\Pepa\Appdata\LocalLow\conduit (Folder)
Successfully deleted: C:\Users\Pepa\Appdata\LocalLow\myashampoo (Folder)
Successfully deleted: C:\Users\Pepa\Appdata\LocalLow\pricegong (Folder)
Successfully deleted: C:\Windows\system32\drivers\isafenetfilter.sys (File)
Successfully deleted: C:\Windows\SysWOW64\conduitengine.tmp (File)
Successfully deleted: C:\Windows\wininit.ini (File)
Successfully deleted: C:\Program Files (x86)\conduit (Folder)
Successfully deleted: C:\Program Files (x86)\myashampoo (Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\351JFXNO (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BDQBQ9C (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UA7SFVUS (Temporary Internet Files Folder)
Successfully deleted: C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VUDL2OFL (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\351JFXNO (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BDQBQ9C (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UA7SFVUS (Temporary Internet Files Folder)
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VUDL2OFL (Temporary Internet Files Folder)

Deleted the following from C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\prefs.js
user_pref(CT2475029.AboutPrivacyUrl, hxxp://www.conduit.com/privacy/Default.aspx);
user_pref(CT2475029.CT2481033.CommunityChanged, false);
user_pref(CT2475029.CT2481033.DialogsAlignMode, LTR);
user_pref(CT2475029.CT2481033.GroupingInvalidateCache, false);
user_pref(CT2475029.CT2481033.GroupingLastCheckTime, Tue Jun 22 2010 20:57:35 GMT+0200);
user_pref(CT2475029.CT2481033.GroupingLastErrorCode, );
user_pref(CT2475029.CT2481033.GroupingLastResponse, true);
user_pref(CT2475029.CT2481033.GroupingLastServerUpdateTime, 129211894149200000);
user_pref(CT2475029.CT2481033.InvalidateCache, false);
user_pref(CT2475029.CT2481033.LanguagePackLastCheckTime, Tue Jun 22 2010 20:57:39 GMT+0200);
user_pref(CT2475029.CT2481033.Locale, pl-pl);
user_pref(CT2475029.CT2481033.RadioLastCheckTime, Tue Jun 22 2010 20:57:35 GMT+0200);
user_pref(CT2475029.CT2481033.RadioLastUpdateIPServer, 3);
user_pref(CT2475029.CT2481033.RadioLastUpdateServer, 3);
user_pref(CT2475029.CT2481033.SearchEngine, Szukaj||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2481033&octid=EB_ORIGINAL_CTID&SearchSource=1);
user_pref(CT2475029.CT2481033.SearchInNewTabLastCheckTime, Tue Jun 22 2010 20:57:35 GMT+0200);
user_pref(CT2475029.CT2481033.SettingsCheckIntervalMin, 120);
user_pref(CT2475029.CT2481033.SettingsLastCheckTime, Tue Jun 22 2010 20:57:35 GMT+0200);
user_pref(CT2475029.CT2481033.SettingsLastUpdate, 1276708614);
user_pref(CT2475029.CT2481033.ThirdPartyComponentsLastCheck, Tue Jun 22 2010 20:57:34 GMT+0200);
user_pref(CT2475029.CT2481033.ThirdPartyComponentsLastUpdate, 1276708614);
user_pref(CT2475029.CTID, CT2481033);
user_pref(CT2475029.CommunitiesChangesLastCheckTime, Tue Jun 22 2010 20:56:49 GMT+0200);
user_pref(CT2475029.CommunitiesStatus.CT2481033, 0);
user_pref(CT2475029.CommunityChanged, true);
user_pref(CT2475029.CurrentServerDate, 22-6-2010);
user_pref(CT2475029.DialogsAlignMode, LTR);
user_pref(CT2475029.DownloadDomainsCheckInterval, 168);
user_pref(CT2475029.DownloadDomainsListLastCheckTime, Tue Jun 22 2010 20:56:49 GMT+0200);
user_pref(CT2475029.DownloadDomainsListLastServerUpdateTime, 1201073583);
user_pref(CT2475029.EMailNotifierPollDate, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.ExternalComponentPollDate129078508355624514, Tue Jun 22 2010 20:56:50 GMT+0200);
user_pref(CT2475029.ExternalComponentPollDate129078532061710433, Tue Jun 22 2010 20:56:51 GMT+0200);
user_pref(CT2475029.FeedPollDate129132307482029379, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129132307482029381, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129132307482029382, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129133095459686870, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129133095459686871, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129137437659687146, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129137437659687147, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129137437659687148, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065408750, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065408756, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065408762, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065408768, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065408774, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409636, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409642, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409648, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409654, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409660, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409666, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409672, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409678, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409684, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409690, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409696, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409702, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409708, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409714, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409720, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409726, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409732, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409738, Tue Jun 22 2010 20:56:53 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065409744, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565030, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565036, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565042, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565048, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565054, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565060, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565066, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565072, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565078, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565084, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565090, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565096, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565102, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565108, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565114, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565120, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565126, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565132, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565138, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565144, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565150, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565156, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565162, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565168, Tue Jun 22 2010 20:56:56 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565174, Tue Jun 22 2010 20:56:57 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565180, Tue Jun 22 2010 20:56:57 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565186, Tue Jun 22 2010 20:56:57 GMT+0200);
user_pref(CT2475029.FeedPollDate129212393065565192, Tue Jun 22 2010 20:56:57 GMT+0200);
user_pref(CT2475029.FeedTTL129132307482029379, 40);
user_pref(CT2475029.FeedTTL129132307482029381, 40);
user_pref(CT2475029.FeedTTL129132307482029382, 40);
user_pref(CT2475029.FeedTTL129133095459686870, 40);
user_pref(CT2475029.FeedTTL129133095459686871, 40);
user_pref(CT2475029.FeedTTL129137437659687146, 40);
user_pref(CT2475029.FeedTTL129137437659687147, 40);
user_pref(CT2475029.FeedTTL129137437659687148, 40);
user_pref(CT2475029.FeedTTL129212393065408750, 5);
user_pref(CT2475029.FeedTTL129212393065408756, 5);
user_pref(CT2475029.FeedTTL129212393065408768, 5);
user_pref(CT2475029.FeedTTL129212393065409648, 15);
user_pref(CT2475029.FeedTTL129212393065409660, 60);
user_pref(CT2475029.FeedTTL129212393065409714, 60);
user_pref(CT2475029.FeedTTL129212393065409720, 15);
user_pref(CT2475029.FeedTTL129212393065409726, 2);
user_pref(CT2475029.FeedTTL129212393065409732, 15);
user_pref(CT2475029.FeedTTL129212393065409744, 30);
user_pref(CT2475029.FeedTTL129212393065565030, 30);
user_pref(CT2475029.FeedTTL129212393065565036, 30);
user_pref(CT2475029.FeedTTL129212393065565060, 15);
user_pref(CT2475029.FeedTTL129212393065565072, 15);
user_pref(CT2475029.FeedTTL129212393065565078, 15);
user_pref(CT2475029.FeedTTL129212393065565084, 15);
user_pref(CT2475029.FeedTTL129212393065565102, 1440);
user_pref(CT2475029.FeedTTL129212393065565132, 10);
user_pref(CT2475029.FeedTTL129212393065565150, 5);
user_pref(CT2475029.FirstServerDate, 22-6-2010);
user_pref(CT2475029.FirstTime, true);
user_pref(CT2475029.FirstTimeFF3, true);
user_pref(CT2475029.FixPageNotFoundErrors, true);
user_pref(CT2475029.GroupingLastCheckTime, Tue Jun 22 2010 20:56:49 GMT+0200);
user_pref(CT2475029.GroupingLastErrorCode, );
user_pref(CT2475029.GroupingLastResponse, true);
user_pref(CT2475029.GroupingLastServerUpdateTime, 129212566712530000);
user_pref(CT2475029.GroupingServerCheckInterval, 1440);
user_pref(CT2475029.GroupingServiceUrl, hxxp://grouping.services.conduit.com/);
user_pref(CT2475029.Initialize, true);
user_pref(CT2475029.InitializeCommonPrefs, true);
user_pref(CT2475029.InstalledDate, Tue Jun 22 2010 20:56:49 GMT+0200);
user_pref(CT2475029.IsGrouping, true);
user_pref(CT2475029.IsMulticommunity, true);
user_pref(CT2475029.IsOpenThankYouPage, false);
user_pref(CT2475029.IsOpenUninstallPage, true);
user_pref(CT2475029.LanguagePackLastCheckTime, Tue Jun 22 2010 20:56:54 GMT+0200);
user_pref(CT2475029.LanguagePackReloadIntervalMM, 1440);
user_pref(CT2475029.LanguagePackServiceUrl, hxxp://translation.users.conduit.com/Translation.ashx);
user_pref(CT2475029.LastLogin_2.5.6.0, Tue Jun 22 2010 20:56:54 GMT+0200);
user_pref(CT2475029.LatestVersion, 2.1.0.18);
user_pref(CT2475029.Locale, en);
user_pref(CT2475029.LoginCache, 4);
user_pref(CT2475029.MCDetectTooltipHeight, 83);
user_pref(CT2475029.MCDetectTooltipShow, false);
user_pref(CT2475029.MCDetectTooltipUrl, hxxp://@EB_INSTALL_LINK@/rank/tooltip/?version=1);
user_pref(CT2475029.MCDetectTooltipWidth, 295);
user_pref(CT2475029.RadioIsPodcast, false);
user_pref(CT2475029.RadioMediaID, 9962);
user_pref(CT2475029.RadioMediaType, Media Player);
user_pref(CT2475029.RadioMenuSelectedID, EBRadioMenu_CT24750299962);
user_pref(CT2475029.RadioStationName, California%20Rock);
user_pref(CT2475029.RadioStationURL, hxxp://feedlive.net/california.asx);
user_pref(CT2475029.SHRINK_TOOLBAR, 1);
user_pref(CT2475029.SavedHomepage, hxxp://seznam.cz/);
user_pref(CT2475029.SearchEngine, Search||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2475029&octid=EB_ORIGINAL_CTID&SearchSource=1);
user_pref(CT2475029.SearchFromAddressBarIsInit, true);
user_pref(CT2475029.SearchFromAddressBarUrl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=);
user_pref(CT2475029.SearchInNewTabEnabled, true);
user_pref(CT2475029.SearchInNewTabIntervalMM, 1440);
user_pref(CT2475029.SearchInNewTabLastCheckTime, Tue Jun 22 2010 20:56:52 GMT+0200);
user_pref(CT2475029.SearchInNewTabServiceUrl, hxxp://newtab.conduit-hosting.com/newtab/?ctid=EB_TOOLBAR_ID);
user_pref(CT2475029.SearchInNewTabUsageUrl, hxxp://Usage.Hosting.conduit-services.com/UsageService.asmx/UsersRequests?ctid=EB_TOOLBAR_ID);
user_pref(CT2475029.SettingsCheckIntervalMin, 120);
user_pref(CT2475029.SettingsLastCheckTime, Tue Jun 22 2010 20:56:46 GMT+0200);
user_pref(CT2475029.SettingsLastUpdate, 1276775871);
user_pref(CT2475029.ThirdPartyComponentsInterval, 504);
user_pref(CT2475029.ThirdPartyComponentsLastCheck, Tue Jun 22 2010 20:56:45 GMT+0200);
user_pref(CT2475029.ThirdPartyComponentsLastUpdate, 1276775871);
user_pref(CT2475029.TrusteLinkUrl, hxxp://www.truste.org/pvr.php?page=validate&so ... sealid=112);
user_pref(CT2475029.Uninstall, true);
user_pref(CT2475029.UserID, UN33006978512873130);
user_pref(CT2475029.ValidationData_Toolbar, 1);
user_pref(CT2475029.WeatherNetwork, );
user_pref(CT2475029.WeatherPollDate, Tue Jun 22 2010 20:57:35 GMT+0200);
user_pref(CT2475029.WeatherUnit, C);
user_pref(CT2475029.clientLogIsEnabled, false);
user_pref(CT2475029.clientLogServiceUrl, hxxp://clientlog.users.conduit.com/ClientDiagnostics.asmx/ReportDiagnosticsEvent);
user_pref(CT2475029.ct2481033.DialogsAlignMode, LTR);
user_pref(CT2475029.ct2481033.GroupingInvalidateCache, false);
user_pref(CT2475029.ct2481033.GroupingLastCheckTime, Tue Jun 22 2010 20:56:51 GMT+0200);
user_pref(CT2475029.ct2481033.GroupingLastErrorCode, );
user_pref(CT2475029.ct2481033.GroupingLastResponse, true);
user_pref(CT2475029.ct2481033.GroupingLastServerUpdateTime, 129211894149200000);
user_pref(CT2475029.ct2481033.InvalidateCache, false);
user_pref(CT2475029.ct2481033.LanguagePackLastCheckTime, Tue Jun 22 2010 20:56:54 GMT+0200);
user_pref(CT2475029.ct2481033.Locale, pl-pl);
user_pref(CT2475029.ct2481033.RadioLastCheckTime, Tue Jun 22 2010 20:56:55 GMT+0200);
user_pref(CT2475029.ct2481033.RadioLastUpdateIPServer, 3);
user_pref(CT2475029.ct2481033.RadioLastUpdateServer, 3);
user_pref(CT2475029.ct2481033.SearchEngine, Szukaj||hxxp://search.conduit.com/Results.aspx?q=UCM_SEARCH_TERM&ctid=ct2481033&octid=EB_ORIGINAL_CTID&SearchSource=1);
user_pref(CT2475029.ct2481033.SettingsCheckIntervalMin, 120);
user_pref(CT2475029.ct2481033.SettingsLastCheckTime, Tue Jun 22 2010 20:56:49 GMT+0200);
user_pref(CT2475029.ct2481033.SettingsLastUpdate, 1276708614);
user_pref(CT2475029.ct2481033.ThirdPartyComponentsLastCheck, Tue Jun 22 2010 20:56:49 GMT+0200);
user_pref(CT2475029.ct2481033.ThirdPartyComponentsLastUpdate, 1276708614);
user_pref(CT2475029.myStuffEnabled, true);
user_pref(CT2475029.myStuffPublihserMinWidth, 400);
user_pref(CT2475029.myStuffSearchUrl, hxxp://Apps.conduit.com/search?q=SEARCH_TERM&SearchSourceOrigin=29&ctid=EB_TOOLBAR_ID&octid=EB_ORIGINAL_CTID);
user_pref(CT2475029.myStuffServiceIntervalMM, 1440);
user_pref(CT2475029.myStuffServiceUrl, hxxp://mystuff.conduit-services.com/MyStuffService.ashx?ComponentId=EB_MY_STUFF_INSTANCE_GUID&lut=EB_MY_STUFF_LUT);
user_pref(CT2475029.uninstallLogServiceUrl, hxxp://uninstall.users.conduit.com/Uninstall.asmx/RegisterToolbarUninstallation);
user_pref(CommunityToolbar.SearchFromAddressBarSavedUrl, chrome://browser-region/locale/region.properties);
user_pref(CommunityToolbar.ToolbarsList, CT2475029);
user_pref(CommunityToolbar.ToolbarsList2, CT2475029);
user_pref(CommunityToolbar.facebook.settingsLastCheckTime, Tue Jun 22 2010 20:57:35 GMT+0200);
user_pref(CommunityToolbar.keywordURLSelectedCTID, CT2475029);
user_pref(CommunityToolbar.twitter.user_1344951.LastCheckTime, Tue Jun 22 2010 20:56:51 GMT+0200);
user_pref(browser.search.defaultengine, Ask.com Search);
user_pref(browser.search.defaultthis.engineName, MyAshampoo Customized Web Search);
user_pref(browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms});
user_pref(keyword.URL, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=);



Registry: 14

Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnl (Registry Key)
Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlBoot (Registry Key)
Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlKit (Registry Key)
Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlR3 (Registry Key)
Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeNetFilter (Registry Key)
Failed to delete: HKLM\SYSTEM\CurrentControlSet\services\iSafeService (Registry Key)
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\iSafeKrnlMon (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} (Registry Value)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{353C407B-9D65-4682-8848-F03A340CD6D1} (Registry Key)
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{a1e75a0e-4397-4ba8-bb50-e19fb66890f4} (Registry Value)




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Łt 11.04.2017 at 13:23:10,55
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Asi virus prosím o pomoc

#4 Příspěvek od JaRon »

vycisti PC s ADWCleanerom a vloz log FRST
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Re: Asi virus prosím o pomoc

#5 Příspěvek od enzo1 »

vyčištění provedeno a log FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by Pepa (administrator) on PEPA-PC (11-04-2017 14:34:36)
Running from C:\Users\Pepa\Desktop
Loaded Profiles: Pepa (Available Profiles: Pepa & w & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Users\Pepa\AppData\Local\AMD\amd.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
() C:\Program Files (x86)\Photodex\ProShowProducer\scsiaccess.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(CANON INC.) C:\Windows\System32\CNAB4RPD.EXE
(Elex do Brasil Participações Ltda) C:\Program Files (x86)\Elex-tech\YAC\iSafeTray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Windows\PLFSetI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Piriform Ltd) C:\Program Files (x86)\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [496160 2009-10-03] (Acer Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7940128 2009-07-06] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-07-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2009-11-21] ()
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-03-31] (AVAST Software)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1091152 2009-11-01] (Dritek System Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\...\Run: [CCleaner Monitoring] => C:\Program Files (x86)\CCleaner\CCleaner64.exe [9364696 2017-03-03] (Piriform Ltd)
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\...\MountPoints2: {303114a3-32d2-11df-b0b6-001e3324deb8} - D:\aoesetup.exe /autorun
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\...\MountPoints2: {3f4e072b-7bf8-11e5-bdab-001e3324deb8} - E:\Startme.exe
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\...\MountPoints2: {b6092651-107b-11e7-abbc-001e3324deb8} - F:\Welcome\Welcome.exe
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1403304 2015-10-29] (Garmin Ltd. or its subsidiaries)
HKLM\...\Providers\c1bwvxob: C:\Program Files (x86)\Atafogh Helper\local64spl.dll [308736 2017-03-24] ()
ShellExecuteHooks: No Name - {D0668D3A-0EF4-11E7-B3CD-64006A5CFC35} - C:\Users\Pepa\AppData\Roaming\Kulerty\Clifly.dll -> No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-31] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-31] (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Pepa\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Pepa\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Pepa\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Pepa\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Pepa\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Pepa\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Pepa\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll [2013-09-11] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk [2009-10-17]
ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2010-01-29]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Canon LBP2900 Status Window.lnk [2011-02-24]
ShortcutTarget: Canon LBP2900 Status Window.lnk -> C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE (CANON INC.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyEnable: [S-1-5-21-2349173935-1687467584-554729351-1000] => Proxy is enabled.
ProxyServer: [S-1-5-21-2349173935-1687467584-554729351-1000] => 192.168.200.3:3128
Tcpip\Parameters: [DhcpNameServer] 192.168.20.193 192.168.20.194
Tcpip\..\Interfaces\{2DD15C90-6C43-45C2-91D3-7EC78BA3F243}: [DhcpNameServer] 192.168.20.193 192.168.20.194
Tcpip\..\Interfaces\{40488FB7-C443-467F-9E4A-B3905333493D}: [DhcpNameServer] 10.10.10.1
ManualProxies: 1192.168.200.3:3128

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7ACAW
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {353C407B-9D65-4682-8848-F03A340CD6D1} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^CZ&apn_uid=9CEC2DF9-6625-4DE6-80EC-4D96138FFDBE&apn_sauid=18ECB9C6-4E57-43FE-B0B9-B2DFFFDC94A0
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... AW_csCZ371
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {DE98D20C-B3DA-4927-B1EF-B70C559498CA} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-03-31] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-26] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-31] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-26] (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File

FireFox:
========
FF ProfilePath: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default [2017-04-11]
FF user.js: detected! => C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\user.js [2017-04-06]
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\hgzo6iz3.default -> hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}
FF Homepage: Mozilla\Firefox\Profiles\hgzo6iz3.default -> hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
FF Keyword.URL: Mozilla\Firefox\Profiles\hgzo6iz3.default -> hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\hgzo6iz3.default -> luck
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\hgzo6iz3.default -> luck
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\hgzo6iz3.default -> luck
FF Extension: (Garmin Communicator) - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-06-14] [not signed]
FF Extension: (Video DownloadHelper) - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-12-30]
FF Extension: (Seznam lištička) - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-02-04]
FF SearchPlugin: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\c1bwvxob.xml [2017-03-24]
FF SearchPlugin: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\luck.xml [2017-04-06]
FF SearchPlugin: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\ourluckysites.xml [2017-04-05]
FF SearchPlugin: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\startpageing123.xml [2017-03-31]
FF Extension: (No Name) - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2016-11-29] [not signed]
FF Extension: (Java Console) - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-11-29] [not signed]
FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-30] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-03-31]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-03-31]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-26] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-26] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-26] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50905.0\npctrl.dll [2017-02-10] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Pepa\AppData\Roaming\mozilla\plugins\npPxPlay.dll [2017-03-26] ( )

Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS"
CHR DefaultSearchURL: ChromeDefaultData -> hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
CHR DefaultSearchKeyword: ChromeDefaultData -> ourluckysites
CHR Profile: C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-04-11] <==== ATTENTION
CHR Extension: (Prezentace Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-20]
CHR Extension: (Dokumenty Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-23]
CHR Extension: (Disk Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-20]
CHR Extension: (YouTube) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-20]
CHR Extension: (Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cbkpdmnjjnoecjoplgjofdbekmmkldhb [2015-11-12]
CHR Extension: (Tabulky Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-20]
CHR Extension: (Dokumenty Google offline) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-20]
CHR Extension: (Avast Online Security) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Gmail) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-20]
CHR Extension: (Chrome Media Router) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-06]
CHR Profile: C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\System Profile [2017-04-03]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD; C:\Users\Pepa\AppData\Local\AMD\amd.exe [112128 2017-03-31] () [File not signed]
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-03-30] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-03-31] (AVAST Software)
R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [786976 2009-10-03] (Acer Incorporated)
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [777744 2015-10-29] (Garmin Ltd. or its subsidiaries)
R2 iSafeService; C:\Program Files (x86)\Elex-tech\YAC\iSafeSvc.exe [131024 2016-12-02] (Elex do Brasil Participações Ltda)
R2 MVCSrv; C:\ProgramData\Package Cache\{2A002F88-FD5D-379B-A350-A25D84AF128B}v14.0.25420\packages\VisualC_D14\VC_IDE.Base\VC_IDE_Base.dll [104448 2017-03-31] () [File not signed]
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated) [File not signed]
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShowProducer\ScsiAccess.exe [181312 2017-03-26] () [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]
S2 SpyEmrgHealth; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [307736 2017-03-30] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-30] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334088 2017-03-30] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-30] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-31] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32600 2017-03-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [127112 2017-03-31] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-03-31] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-31] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1005048 2017-03-31] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [556784 2017-03-31] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [164064 2017-03-31] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-03-31] (AVAST Software)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-03-24] (Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-03-24] (Disc Soft Ltd)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [254528 2017-03-24] (DT Soft Ltd)
S3 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [30264 2017-03-24] (Disc Soft Ltd)
S3 dtultrausbbus; C:\Windows\System32\DRIVERS\dtultrausbbus.sys [47672 2017-03-24] (Disc Soft Ltd)
R1 iSafeKrnl; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnl.sys [262344 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlKit; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlKit.sys [110112 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeKrnlR3; C:\Program Files (x86)\Elex-tech\YAC\iSafeKrnlR3.sys [103904 2016-05-23] (Elex do Brasil Participações Ltda)
R1 iSafeNetFilter; C:\Windows\System32\DRIVERS\iSafeNetFilter.sys [52392 2016-05-19] (Elex do Brasil Participações Ltda)
S3 lgmdbus; C:\Windows\System32\DRIVERS\lgmdbus.sys [115200 2008-07-08] (MCCI Corporation)
S3 lgmdmdfl; C:\Windows\System32\DRIVERS\lgmdmdfl.sys [18944 2008-07-08] (MCCI Corporation)
S3 lgmdmdm; C:\Windows\System32\DRIVERS\lgmdmdm.sys [158720 2008-07-08] (MCCI Corporation)
S3 lgmdmgmt; C:\Windows\System32\DRIVERS\lgmdmgmt.sys [137216 2008-07-08] (MCCI Corporation)
S3 lgmdobex; C:\Windows\System32\DRIVERS\lgmdobex.sys [136704 2008-07-08] (MCCI Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-03-18] () [File not signed]
S3 iSafeKrnlBoot; system32\DRIVERS\iSafeKrnlBoot.sys [X]
S3 LgBttPort; system32\DRIVERS\lgbtpt64.sys [X]
S3 lgbusenum; system32\DRIVERS\lgbtbs64.sys [X]
S3 LGVMODEM; system32\DRIVERS\lgvmdm64.sys [X]
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
U2 WinSnare; no ImagePath
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-11 14:34 - 2017-04-11 14:35 - 00029068 _____ C:\Users\Pepa\Desktop\FRST.txt
2017-04-11 14:34 - 2017-04-11 14:34 - 00000000 ____D C:\FRST
2017-04-11 14:32 - 2017-04-11 14:33 - 02424832 _____ (Farbar) C:\Users\Pepa\Desktop\FRST64.exe
2017-04-11 14:25 - 2017-04-11 14:25 - 00000022 _____ C:\Users\Public\Documents\temp.dat
2017-04-11 14:23 - 2017-04-11 14:23 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-04-11 14:22 - 2016-05-19 08:42 - 00052392 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys
2017-04-11 13:47 - 2017-04-11 14:18 - 00000000 ____D C:\AdwCleaner
2017-04-11 13:40 - 2017-04-11 13:43 - 04089296 _____ C:\Users\Pepa\Desktop\adwcleaner_6.045.exe
2017-04-11 13:23 - 2017-04-11 13:23 - 00022435 _____ C:\Users\Pepa\Desktop\JRT.txt
2017-04-11 13:14 - 2017-04-11 13:15 - 01663672 _____ (Malwarebytes) C:\Users\Pepa\Desktop\JRT.exe
2017-04-11 11:48 - 2017-04-11 11:52 - 00000000 ____D C:\rsit
2017-04-11 11:48 - 2017-04-11 11:52 - 00000000 ____D C:\Program Files\trend micro
2017-04-11 11:44 - 2017-04-11 11:46 - 01329152 _____ C:\Users\Pepa\Desktop\RSITx64.exe
2017-04-10 21:05 - 2017-04-10 21:05 - 00000000 ____D C:\Users\Pepa\AppData\Local\AMD
2017-04-10 20:44 - 2017-04-10 20:44 - 00000000 ____D C:\Update
2017-04-06 17:48 - 2017-04-09 13:40 - 00000000 ____D C:\Users\Pepa\AppData\Local\clean
2017-04-06 17:48 - 2017-04-09 10:39 - 00000000 _____ C:\Windows\SysWOW64\4
2017-04-03 10:32 - 2017-04-03 10:32 - 09274608 _____ (Piriform Ltd) C:\Users\Pepa\Downloads\ccsetup528.exe
2017-04-01 20:58 - 2017-04-11 14:13 - 00000000 ____D C:\Windows\system32\log
2017-04-01 20:58 - 2017-04-01 20:58 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Elex-tech
2017-04-01 20:58 - 2017-04-01 20:58 - 00000000 ____D C:\Program Files (x86)\Elex-tech
2017-04-01 20:57 - 2017-04-01 20:57 - 00002004 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-04-01 20:57 - 2017-04-01 20:57 - 00000007 _____ C:\Windows\SysWOW64\DB83.tmp
2017-03-31 14:23 - 2017-03-31 14:23 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-03-31 14:00 - 2017-04-10 20:58 - 00000000 ____D C:\Users\Pepa\AppData\LocalLow\Mozilla
2017-03-31 11:50 - 2017-04-10 21:05 - 00000000 ____D C:\Program Files\MK
2017-03-29 12:32 - 2017-03-29 12:32 - 00000889 _____ C:\Users\Pepa\Documents\Fotky – zástupce.lnk
2017-03-29 12:28 - 2017-03-29 12:28 - 00000000 ____D C:\Users\Pepa\Documents\Pinnacle VideoSpin
2017-03-29 12:16 - 2017-03-29 12:16 - 00001111 _____ C:\Users\Public\Desktop\Pinnacle VideoSpin.lnk
2017-03-29 12:15 - 2017-03-29 12:28 - 00000000 ____D C:\ProgramData\Pinnacle VideoSpin
2017-03-29 12:15 - 2017-03-29 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pinnacle VideoSpin
2017-03-29 12:12 - 2017-03-29 15:53 - 00000000 ____D C:\Users\Pepa\AppData\Local\Downloaded Installations
2017-03-29 12:10 - 2017-03-29 12:11 - 00000000 ____D C:\Program Files (x86)\MIO
2017-03-29 12:09 - 2017-03-29 12:10 - 00000000 ____D C:\Program Files (x86)\MK
2017-03-29 12:07 - 2017-04-10 21:01 - 00000000 ____D C:\Program Files\c1bwvxob
2017-03-28 18:06 - 2017-03-28 18:10 - 170203312 _____ C:\Users\Pepa\Downloads\VideoSpin_2_0_Setup.exe
2017-03-27 21:36 - 2017-03-27 21:36 - 00000000 ___HD C:\$AV_ASW
2017-03-26 22:29 - 2017-03-26 22:29 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Sun
2017-03-26 22:24 - 2017-03-26 22:25 - 00004408 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-03-26 20:38 - 2017-03-26 20:38 - 00002136 _____ C:\Users\Public\Desktop\ProShow Producer.lnk
2017-03-26 20:38 - 2017-03-26 20:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProShow Producer
2017-03-26 20:37 - 2017-03-26 20:37 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Photodex
2017-03-26 20:37 - 2017-03-26 20:37 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Netscape
2017-03-26 20:37 - 2017-03-26 20:37 - 00000000 ____D C:\Program Files (x86)\Photodex Presenter
2017-03-26 20:37 - 2017-03-26 20:37 - 00000000 ____D C:\Program Files (x86)\Photodex
2017-03-24 16:31 - 2017-03-24 16:31 - 00000000 ____D C:\Users\Pepa\AppData\Local\Pinnacle
2017-03-24 16:19 - 2017-03-24 16:19 - 00000000 ____D C:\ProgramData\Pinnacle Studio Ultimate Collection
2017-03-24 16:12 - 2017-03-29 12:15 - 00000000 ____D C:\Users\Public\Documents\Pinnacle
2017-03-24 16:08 - 2017-04-10 21:09 - 00000349 _____ C:\Users\Public\Documents\PCLECHAL.INI
2017-03-24 16:05 - 2017-03-29 17:07 - 00000000 ____D C:\Program Files (x86)\Pinnacle
2017-03-24 16:03 - 2017-03-24 16:03 - 00001494 _____ C:\ProgramData\__wdump.txt
2017-03-24 15:56 - 2017-03-29 15:46 - 00000000 ____D C:\ProgramData\Pinnacle
2017-03-24 15:53 - 2017-03-24 15:53 - 00254528 _____ (DT Soft Ltd) C:\Windows\system32\Drivers\dtsoftbus01.sys
2017-03-24 15:52 - 2017-03-24 15:53 - 00000000 ____D C:\Program Files (x86)\DAEMON Tools Lite
2017-03-24 15:52 - 2017-03-24 15:52 - 00001954 _____ C:\Users\Public\Desktop\DAEMON Tools Lite.lnk
2017-03-24 15:52 - 2017-03-24 15:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2017-03-24 15:51 - 2017-03-24 15:51 - 11193664 _____ (DT Soft Ltd.) C:\Users\Pepa\Downloads\Lite 4.40.2_DTLite4402-0131.exe
2017-03-24 15:46 - 2017-03-24 15:46 - 00692072 _____ (Disc Soft Ltd.) C:\Users\Pepa\Downloads\DTLiteInstaller.exe
2017-03-24 15:28 - 2017-03-24 15:30 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\DAEMON Tools Ultra
2017-03-24 15:28 - 2017-03-24 15:28 - 00047672 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtultrausbbus.sys
2017-03-24 15:28 - 2017-03-24 15:28 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtultrascsibus.sys
2017-03-24 15:26 - 2017-03-24 15:26 - 00000000 ____D C:\ProgramData\DAEMON Tools Ultra
2017-03-24 15:09 - 2017-03-24 15:31 - 00000000 ____D C:\Users\Pepa\AppData\Local\Disc_Soft_Ltd
2017-03-24 15:05 - 2017-03-24 15:05 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2017-03-24 15:04 - 2017-03-26 09:33 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Kulerty
2017-03-24 15:03 - 2017-04-11 09:10 - 00000000 ____D C:\Program Files (x86)\Prervoly
2017-03-24 15:03 - 2017-03-24 15:04 - 00000000 ____D C:\Users\Pepa\AppData\Local\Guziphdceied
2017-03-24 15:03 - 2017-03-24 15:03 - 00006034 _____ C:\Windows\System32\Tasks\Atafogh Helper
2017-03-24 15:03 - 2017-03-24 15:03 - 00000000 ____D C:\Program Files (x86)\Atafogh Helper
2017-03-24 15:01 - 2017-03-24 15:01 - 00047672 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtliteusbbus.sys
2017-03-24 15:00 - 2017-03-24 15:00 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2017-03-16 22:12 - 2017-02-23 01:42 - 00084712 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2017-03-16 22:12 - 2017-02-23 01:37 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-03-16 22:12 - 2017-02-18 16:05 - 01609216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-03-16 22:12 - 2017-02-18 16:05 - 00646656 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-03-15 16:48 - 2017-03-04 19:24 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-03-15 16:48 - 2017-03-04 18:39 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-03-15 16:48 - 2017-03-04 10:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-03-15 16:48 - 2017-03-04 10:20 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-03-15 16:48 - 2017-03-04 10:02 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-03-15 16:48 - 2017-03-04 10:01 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-03-15 16:48 - 2017-03-04 10:01 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-03-15 16:48 - 2017-03-04 10:01 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-03-15 16:48 - 2017-03-04 10:01 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-03-15 16:48 - 2017-03-04 09:59 - 02895360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-03-15 16:48 - 2017-03-04 09:52 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-03-15 16:48 - 2017-03-04 09:51 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-03-15 16:48 - 2017-03-04 09:48 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-03-15 16:48 - 2017-03-04 09:46 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-03-15 16:48 - 2017-03-04 09:45 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-03-15 16:48 - 2017-03-04 09:45 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-03-15 16:48 - 2017-03-04 09:45 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-03-15 16:48 - 2017-03-04 09:44 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-03-15 16:48 - 2017-03-04 09:36 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-03-15 16:48 - 2017-03-04 09:32 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-03-15 16:48 - 2017-03-04 09:31 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-03-15 16:48 - 2017-03-04 09:23 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-03-15 16:48 - 2017-03-04 09:21 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-03-15 16:48 - 2017-03-04 09:16 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-03-15 16:48 - 2017-03-04 09:16 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-03-15 16:48 - 2017-03-04 09:13 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-03-15 16:48 - 2017-03-04 09:11 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-03-15 16:48 - 2017-03-04 08:57 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-03-15 16:48 - 2017-03-04 08:55 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-03-15 16:48 - 2017-03-04 08:54 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-03-15 16:48 - 2017-03-04 08:52 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-03-15 16:48 - 2017-03-04 08:52 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-03-15 16:48 - 2017-03-04 08:26 - 15259648 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-03-15 16:48 - 2017-03-04 08:25 - 03241984 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-03-15 16:48 - 2017-03-04 08:12 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-03-15 16:48 - 2017-03-04 08:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-03-15 16:48 - 2017-03-04 06:18 - 20281856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-03-15 16:48 - 2017-03-02 20:16 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-03-15 16:48 - 2017-03-02 20:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-03-15 16:48 - 2017-03-02 20:01 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-03-15 16:48 - 2017-03-02 20:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-03-15 16:48 - 2017-03-02 20:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-03-15 16:48 - 2017-03-02 20:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-03-15 16:48 - 2017-03-02 19:55 - 02287104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-03-15 16:48 - 2017-03-02 19:54 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-03-15 16:48 - 2017-03-02 19:53 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-03-15 16:48 - 2017-03-02 19:51 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-03-15 16:48 - 2017-03-02 19:50 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-03-15 16:48 - 2017-03-02 19:49 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-03-15 16:48 - 2017-03-02 19:49 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-03-15 16:48 - 2017-03-02 19:41 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-03-15 16:48 - 2017-03-02 19:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-03-15 16:48 - 2017-03-02 19:35 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-03-15 16:48 - 2017-03-02 19:32 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-03-15 16:48 - 2017-03-02 19:31 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-03-15 16:48 - 2017-03-02 19:29 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-03-15 16:48 - 2017-03-02 19:28 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-03-15 16:48 - 2017-03-02 19:22 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-03-15 16:48 - 2017-03-02 19:21 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-03-15 16:48 - 2017-03-02 19:19 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-03-15 16:48 - 2017-03-02 19:17 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-03-15 16:48 - 2017-03-02 19:17 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-03-15 16:48 - 2017-03-02 19:11 - 13654528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-03-15 16:48 - 2017-03-02 18:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-03-15 16:48 - 2017-03-02 18:50 - 01312768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-03-15 16:48 - 2017-03-02 18:50 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-03-15 16:48 - 2017-02-09 18:35 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-03-15 16:48 - 2017-02-09 18:33 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-03-15 16:48 - 2017-02-09 18:00 - 03220480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-03-15 16:47 - 2017-02-11 17:58 - 00462848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-03-15 16:47 - 2017-02-11 17:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-03-15 16:47 - 2017-02-11 17:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-03-15 16:47 - 2017-02-10 18:32 - 00803328 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-03-15 16:47 - 2017-02-10 18:32 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-03-15 16:47 - 2017-02-10 18:17 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-03-15 16:47 - 2017-02-10 18:17 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-03-15 16:47 - 2017-02-10 16:33 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-03-15 16:47 - 2017-02-09 18:36 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-03-15 16:47 - 2017-02-09 18:35 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-03-15 16:47 - 2017-02-09 18:35 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-03-15 16:47 - 2017-02-09 18:35 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-03-15 16:47 - 2017-02-09 18:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:19 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-03-15 16:47 - 2017-02-09 18:19 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-03-15 16:47 - 2017-02-09 18:16 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 18:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-03-15 16:47 - 2017-02-09 18:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-03-15 16:47 - 2017-02-09 18:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-03-15 16:47 - 2017-02-09 18:02 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-03-15 16:47 - 2017-02-09 17:59 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-03-15 16:47 - 2017-02-09 17:58 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-03-15 16:47 - 2017-02-09 17:55 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-03-15 16:47 - 2017-02-09 17:55 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-03-15 16:47 - 2017-02-09 17:55 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-03-15 16:47 - 2017-02-09 17:54 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-03-15 16:47 - 2017-02-09 17:54 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-03-15 16:47 - 2017-02-09 17:53 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-03-15 16:47 - 2017-02-09 17:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2017-03-15 16:47 - 2017-02-09 17:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-03-15 16:47 - 2017-02-09 17:50 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-03-15 16:47 - 2017-02-09 17:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-03-15 16:47 - 2017-02-09 17:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-03-15 16:47 - 2017-02-09 17:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-03-15 16:47 - 2017-02-09 17:49 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 17:49 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 17:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 17:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-03-15 16:47 - 2017-02-09 16:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-03-15 16:47 - 2017-02-09 16:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-03-15 16:47 - 2017-02-06 18:14 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-03-15 16:47 - 2017-01-13 20:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-03-15 16:47 - 2017-01-13 20:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2017-03-15 16:47 - 2017-01-13 19:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-03-15 16:47 - 2017-01-13 19:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2017-03-15 16:47 - 2017-01-11 20:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-03-15 16:47 - 2017-01-11 20:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2017-03-15 16:47 - 2017-01-11 19:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-03-15 16:47 - 2017-01-11 19:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2017-03-15 16:47 - 2017-01-06 20:00 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-03-15 16:47 - 2017-01-06 19:44 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-03-12 23:44 - 2017-03-12 23:44 - 00183090 _____ C:\Users\Pepa\Downloads\00798652-02-2017-EVP.zip

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-11 14:33 - 2009-07-14 06:45 - 00019056 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-11 14:33 - 2009-07-14 06:45 - 00019056 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-11 14:27 - 2017-03-06 18:43 - 00004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-04-11 14:21 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-11 11:45 - 2010-08-01 19:51 - 00003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-11 11:45 - 2010-08-01 19:51 - 00003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-09 10:51 - 2011-01-13 21:33 - 00016384 _____ C:\Users\Pepa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-04-06 14:04 - 2016-01-06 19:40 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\vlc
2017-04-06 13:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-04-06 10:04 - 2010-03-17 03:43 - 00001703 _____ C:\Users\Pepa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-04-05 22:04 - 2010-08-01 19:54 - 00002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-05 22:04 - 2010-08-01 19:54 - 00002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-03 10:34 - 2015-11-26 16:19 - 00001021 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-04-03 10:30 - 2010-01-29 06:02 - 00000000 ___HD C:\Program Files (x86)\Temp
2017-04-02 17:13 - 2010-01-29 06:36 - 00669132 _____ C:\Windows\system32\perfh005.dat
2017-04-02 17:13 - 2010-01-29 06:36 - 00141760 _____ C:\Windows\system32\perfc005.dat
2017-04-02 17:13 - 2009-07-14 07:13 - 01584626 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-01 20:57 - 2014-06-14 09:56 - 00000000 ____D C:\ProgramData\Package Cache
2017-04-01 20:57 - 2010-03-17 06:26 - 00001934 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-03-31 14:26 - 2016-03-23 14:48 - 00003890 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1458737292
2017-03-31 14:23 - 2014-05-11 20:01 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-03-31 14:22 - 2016-03-23 14:47 - 00032600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-03-31 14:22 - 2013-12-22 22:16 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-03-30 17:53 - 2016-11-29 13:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-30 01:49 - 2010-03-18 23:04 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\DAEMON Tools Lite
2017-03-30 01:24 - 2017-03-06 18:43 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-03-30 01:24 - 2017-03-06 18:43 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-03-30 01:24 - 2017-03-06 18:43 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-03-30 01:24 - 2017-03-06 18:43 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-03-29 16:06 - 2009-07-14 06:45 - 00517560 _____ C:\Windows\system32\FNTCACHE.DAT
2017-03-29 15:58 - 2010-03-17 03:38 - 00148360 _____ C:\Users\Pepa\AppData\Local\GDIPFONTCACHEV1.DAT
2017-03-26 22:30 - 2016-01-06 23:48 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-03-26 22:28 - 2013-11-25 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-03-26 22:27 - 2013-11-25 10:09 - 00097856 ____N (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2017-03-26 22:26 - 2013-03-05 14:06 - 00000000 ____D C:\Program Files (x86)\Java
2017-03-26 22:25 - 2012-04-02 08:31 - 00802904 ____N (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-03-26 22:25 - 2011-11-20 11:37 - 00000000 ____D C:\Windows\system32\Macromed
2017-03-26 22:25 - 2011-05-19 08:48 - 00144472 ____N (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-26 22:24 - 2009-10-17 00:38 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-03-26 20:37 - 2010-03-17 06:30 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Mozilla
2017-03-26 20:25 - 2015-03-02 01:08 - 00000000 ____D C:\Users\Pepa\Documents\film
2017-03-26 20:24 - 2011-02-10 21:47 - 00000000 ____D C:\Users\Pepa\Documents\www
2017-03-26 20:18 - 2017-01-14 01:28 - 00000000 ____D C:\Users\Pepa\Documents\Karty života
2017-03-24 16:37 - 2013-07-28 21:11 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\uTorrent
2017-03-24 14:59 - 2010-03-18 23:04 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2017-03-21 20:32 - 2012-02-26 17:56 - 00000000 ____D C:\Users\Pepa\Desktop\Pro Peťu
2017-03-20 19:14 - 2017-03-08 22:22 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\dvdcss
2017-03-17 13:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2017-03-17 08:13 - 2014-12-12 11:16 - 00000000 ____D C:\Windows\system32\appraiser
2017-03-17 08:13 - 2014-05-06 14:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2017-03-16 21:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2017-03-16 00:08 - 2013-08-06 21:59 - 00000000 ____D C:\Windows\system32\MRT
2017-03-16 00:02 - 2010-03-21 21:19 - 138634176 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-03-15 23:59 - 2012-05-11 23:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-03-15 23:57 - 2012-05-11 23:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-03-15 23:57 - 2012-05-11 23:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-03-12 23:58 - 2011-11-07 12:23 - 00000000 ____D C:\Users\Pepa\Documents\Angličtina

==================== Files in the root of some directories =======

2009-10-17 00:12 - 2009-02-10 21:23 - 0192484 _____ () C:\Program Files (x86)\Common Files\Acer GameZone online.ico
2012-10-20 08:47 - 2012-12-25 22:37 - 0000040 _____ () C:\Users\Pepa\AppData\Roaming\cdr.ini
2011-12-23 21:30 - 2011-12-23 21:30 - 0021854 _____ () C:\Users\Pepa\AppData\Roaming\Hodnoty oddělené čárkami (Windows).ADR
2010-03-17 04:11 - 2010-03-17 04:11 - 0000000 _____ () C:\Users\Pepa\AppData\Roaming\wklnhst.dat
2011-01-13 21:33 - 2017-04-09 10:51 - 0016384 _____ () C:\Users\Pepa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-03-17 05:01 - 2010-03-17 05:12 - 0011452 _____ () C:\Users\Pepa\AppData\Local\MyWinLockerInstaller.txt-20100317.log
2016-04-20 20:36 - 2016-04-20 20:36 - 0002876 _____ () C:\Users\Pepa\AppData\Local\recently-used.xbel
2011-12-26 07:40 - 2011-12-26 07:40 - 0000000 _____ () C:\Users\Pepa\AppData\Local\{79BA3A8D-E466-4B2E-90A3-978643A1A4A0}
2010-09-08 13:28 - 2010-09-08 13:28 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2009-10-17 00:12 - 2009-07-18 03:57 - 0036136 _____ (Oberon Media) C:\ProgramData\FullRemove.exe
2011-10-19 16:36 - 2011-10-19 17:40 - 0000769 _____ () C:\ProgramData\LmeUSB.log
2011-10-19 16:36 - 2011-10-19 17:40 - 0000769 _____ () C:\ProgramData\LSDmbTH.log
2017-03-24 16:03 - 2017-03-24 16:03 - 0001494 _____ () C:\ProgramData\__wdump.txt

Files to move or delete:
====================
C:\Windows\Tasks\{011B8E39-CE88-41E0-B0D4-311E33EC992A}.job
C:\Windows\Tasks\{17533D0E-A9DE-49DD-93CD-ADE62A97FD62}.job
C:\Windows\Tasks\{1A89CBC3-1771-4C0D-8B7E-E785109150BA}.job
C:\Windows\Tasks\{25381E09-4350-4CEB-8375-8F9B5FC882B8}.job
C:\Windows\Tasks\{2C34D498-06D7-4808-AD10-2C290AFC7C68}.job
C:\Windows\Tasks\{3E70DE31-F555-4BF7-ACCE-E9AF4AEE522B}.job
C:\Windows\Tasks\{42441CAB-D394-4ED2-B527-BF8586500CBF}.job
C:\Windows\Tasks\{6B0B2E13-DD0E-4974-82C3-7F7BCAB85C41}.job
C:\Windows\Tasks\{9355D9FC-1AAB-4933-A742-7E47402C6D12}.job
C:\Windows\Tasks\{A9827EA4-461C-4E96-BBCE-3BD151F2CAA6}.job
C:\Windows\Tasks\{B08D7569-C085-4F1D-A2F4-D594EEAE262A}.job
C:\Windows\Tasks\{C91DE031-215F-4A00-AADF-39A56BA2C4DA}.job


Some files in TEMP:
====================
2010-07-02 09:28 - 2010-07-02 09:29 - 0921376 _____ (Sun Microsystems, Inc.) C:\Users\Guest\AppData\Local\Temp\firefoxjre_exe.exe
2012-11-07 22:45 - 2012-11-07 22:45 - 0001536 _____ () C:\Users\w\AppData\Local\Temp\NOSEventMessages.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-04-03 12:45

==================== End of FRST.txt ============================

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Asi virus prosím o pomoc

#6 Příspěvek od JaRon »

pokus sa odinstalovat Elex-tech\YAC - zajtra pokracujeme
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Re: Asi virus prosím o pomoc

#7 Příspěvek od enzo1 »

Díky moc za pomoc. Odinstalováno a čekám na pokyny. Asi nebudu přítomen zítra, jedu pryč. Ozvu se asi ve čtvrtek. Díky Leoš

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Asi virus prosím o pomoc

#8 Příspěvek od JaRon »

Vycisti PC s CCleanerom, vcetne registrov
Restart a vloz aktualny log FRST, potom docistime
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Re: Asi virus prosím o pomoc

#9 Příspěvek od enzo1 »

Ahoj, jsem zpět :-)
Projel jsem to CCleanerom i registry, restart a následný sken FRST. Jeho Log:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by Pepa (administrator) on PEPA-PC (13-04-2017 14:45:09)
Running from C:\Users\Pepa\Desktop
Loaded Profiles: Pepa (Available Profiles: Pepa & w & Guest)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
() C:\Users\Pepa\AppData\Local\AMD\amd.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(CANON INC.) C:\Windows\System32\CNAB4RPD.EXE
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe
(Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Windows\PLFSetI.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerEvent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Piriform Ltd) C:\Program Files (x86)\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated)
HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTrayLauncher.exe [496160 2009-10-03] (Acer Incorporated)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7940128 2009-07-06] (Realtek Semiconductor)
HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-07-06] (Realtek Semiconductor Corp.)
HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2009-11-21] ()
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-03-31] (AVAST Software)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1091152 2009-11-01] (Dritek System Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\...\Run: [CCleaner Monitoring] => C:\Program Files (x86)\CCleaner\CCleaner64.exe [9364696 2017-03-03] (Piriform Ltd)
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\...\MountPoints2: {303114a3-32d2-11df-b0b6-001e3324deb8} - D:\aoesetup.exe /autorun
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\...\MountPoints2: {3f4e072b-7bf8-11e5-bdab-001e3324deb8} - E:\Startme.exe
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\...\MountPoints2: {b6092651-107b-11e7-abbc-001e3324deb8} - F:\Welcome\Welcome.exe
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1403304 2015-10-29] (Garmin Ltd. or its subsidiaries)
HKLM\...\Providers\c1bwvxob: C:\Program Files (x86)\Atafogh Helper\local64spl.dll [308736 2017-03-24] ()
ShellExecuteHooks: No Name - {D0668D3A-0EF4-11E7-B3CD-64006A5CFC35} - -> No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-31] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-03-31] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk [2009-10-17]
ShortcutTarget: Acer VCM.lnk -> C:\Program Files (x86)\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2010-01-29]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Canon LBP2900 Status Window.lnk [2011-02-24]
ShortcutTarget: Canon LBP2900 Status Window.lnk -> C:\Windows\System32\spool\drivers\x64\3\CNAB4LAD.EXE (CANON INC.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-2349173935-1687467584-554729351-1000] => 192.168.200.3:3128
Tcpip\Parameters: [DhcpNameServer] 62.129.50.20 85.135.32.100
Tcpip\..\Interfaces\{2DD15C90-6C43-45C2-91D3-7EC78BA3F243}: [DhcpNameServer] 62.129.50.20 85.135.32.100
Tcpip\..\Interfaces\{40488FB7-C443-467F-9E4A-B3905333493D}: [DhcpNameServer] 10.10.10.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
HKU\S-1-5-21-2349173935-1687467584-554729351-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... lz=1I7ACAW
SearchScopes: HKLM-x32 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.ourluckysites.com/search/?type=ds&t ... earchTerms}
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {353C407B-9D65-4682-8848-F03A340CD6D1} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000027&src=crm&q={searchTerms}&locale=en_EU&apn_ptnrs=^U3&apn_dtid=^OSJ000^YY^CZ&apn_uid=9CEC2DF9-6625-4DE6-80EC-4D96138FFDBE&apn_sauid=18ECB9C6-4E57-43FE-B0B9-B2DFFFDC94A0
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={s ... AW_csCZ371
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2475029
SearchScopes: HKU\S-1-5-21-2349173935-1687467584-554729351-1000 -> {DE98D20C-B3DA-4927-B1EF-B70C559498CA} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-03-31] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-26] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-03-31] (AVAST Software)
BHO-x32: Pomocná služba pro přihlášení ke službě Windows Live ID -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-26] (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File

FireFox:
========
FF ProfilePath: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default [2017-04-13]
FF user.js: detected! => C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\user.js [2017-04-06]
FF DefaultSearchUrl: Mozilla\Firefox\Profiles\hgzo6iz3.default -> hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&SearchSource=3&q={searchTerms}
FF Homepage: Mozilla\Firefox\Profiles\hgzo6iz3.default -> hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
FF Keyword.URL: Mozilla\Firefox\Profiles\hgzo6iz3.default -> hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2475029&q=
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\hgzo6iz3.default -> luck
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\hgzo6iz3.default -> luck
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\hgzo6iz3.default -> luck
FF Extension: (Garmin Communicator) - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-06-14] [not signed]
FF Extension: (Video DownloadHelper) - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-12-30]
FF Extension: (Seznam lištička) - C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-02-04]
FF SearchPlugin: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\c1bwvxob.xml [2017-03-24]
FF SearchPlugin: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\luck.xml [2017-04-06]
FF SearchPlugin: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\ourluckysites.xml [2017-04-05]
FF SearchPlugin: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\searchplugins\startpageing123.xml [2017-03-31]
FF Extension: (No Name) - C:\Program Files (x86)\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2016-11-29] [not signed]
FF Extension: (Java Console) - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2016-11-29] [not signed]
FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\deployment-checker@mozilla.org.xpi [2017-03-30] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-03-31]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF48 [2017-03-31]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF48
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_127.dll [2017-03-26] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll [2017-03-26] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-26] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFFICE.DLL [2007-03-22] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2016-12-17] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Pepa\AppData\Roaming\mozilla\plugins\npPxPlay.dll [2017-03-26] ( )

Chrome:
=======
CHR DefaultProfile: ChromeDefaultData
CHR HomePage: ChromeDefaultData -> hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS
CHR StartupUrls: ChromeDefaultData -> "hxxp://www.ourluckysites.com/?type=hp&ts=14913 ... X594BS1KNS"
CHR Profile: C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData [2017-04-13] <==== ATTENTION
CHR Extension: (Prezentace Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-20]
CHR Extension: (Dokumenty Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-23]
CHR Extension: (Disk Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-20]
CHR Extension: (YouTube) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-20]
CHR Extension: (Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\cbkpdmnjjnoecjoplgjofdbekmmkldhb [2015-11-12]
CHR Extension: (Tabulky Google) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-20]
CHR Extension: (Dokumenty Google offline) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-20]
CHR Extension: (Avast Online Security) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (Gmail) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-20]
CHR Extension: (Chrome Media Router) - C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\ChromeDefaultData\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-06]
CHR Profile: C:\Users\Pepa\AppData\Local\Google\Chrome\User Data\System Profile [2017-04-13]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx <not found>

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD; C:\Users\Pepa\AppData\Local\AMD\amd.exe [112128 2017-03-31] () [File not signed]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-03-30] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-03-31] (AVAST Software)
R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [786976 2009-10-03] (Acer Incorporated)
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [777744 2015-10-29] (Garmin Ltd. or its subsidiaries)
R2 MVCSrv; C:\ProgramData\Package Cache\{2A002F88-FD5D-379B-A350-A25D84AF128B}v14.0.25420\packages\VisualC_D14\VC_IDE.Base\VC_IDE_Base.dll [104448 2017-03-31] () [File not signed]
R2 RS_Service; C:\Program Files (x86)\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
U4 AvastVBoxSvc; "C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [307736 2017-03-30] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-03-30] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334088 2017-03-30] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-03-30] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-03-31] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32600 2017-03-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [127112 2017-03-31] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-03-31] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-03-31] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1005048 2017-03-31] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [556784 2017-03-31] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [164064 2017-03-31] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-03-31] (AVAST Software)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-03-24] (Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-03-24] (Disc Soft Ltd)
S3 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [30264 2017-03-24] (Disc Soft Ltd)
S3 dtultrausbbus; C:\Windows\System32\DRIVERS\dtultrausbbus.sys [47672 2017-03-24] (Disc Soft Ltd)
S3 lgmdbus; C:\Windows\System32\DRIVERS\lgmdbus.sys [115200 2008-07-08] (MCCI Corporation)
S3 lgmdmdfl; C:\Windows\System32\DRIVERS\lgmdmdfl.sys [18944 2008-07-08] (MCCI Corporation)
S3 lgmdmdm; C:\Windows\System32\DRIVERS\lgmdmdm.sys [158720 2008-07-08] (MCCI Corporation)
S3 lgmdmgmt; C:\Windows\System32\DRIVERS\lgmdmgmt.sys [137216 2008-07-08] (MCCI Corporation)
S3 lgmdobex; C:\Windows\System32\DRIVERS\lgmdobex.sys [136704 2008-07-08] (MCCI Corporation)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2010-03-18] () [File not signed]
S3 LgBttPort; system32\DRIVERS\lgbtpt64.sys [X]
S3 lgbusenum; system32\DRIVERS\lgbtbs64.sys [X]
S3 LGVMODEM; system32\DRIVERS\lgvmdm64.sys [X]
S3 massfilter; system32\drivers\massfilter.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
U2 WinSnare; no ImagePath
S3 ZTEusbmdm6k; system32\DRIVERS\ZTEusbmdm6k.sys [X]
S3 ZTEusbnmea; system32\DRIVERS\ZTEusbnmea.sys [X]
S3 ZTEusbser6k; system32\DRIVERS\ZTEusbser6k.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-13 14:35 - 2017-04-13 14:35 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-04-12 20:57 - 2017-04-12 20:57 - 00000000 _____ C:\Windows\SysWOW64\1
2017-04-12 20:42 - 2017-03-27 20:13 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-04-12 20:42 - 2017-03-27 19:28 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-04-12 20:42 - 2017-03-25 21:39 - 20284416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-04-12 20:42 - 2017-03-25 21:07 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-04-12 20:42 - 2017-03-25 21:06 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-04-12 20:42 - 2017-03-25 20:55 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-04-12 20:42 - 2017-03-25 20:52 - 02289152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-04-12 20:42 - 2017-03-25 20:51 - 01313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-04-12 20:42 - 2017-03-25 20:47 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-04-12 20:42 - 2017-03-25 20:10 - 02898432 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-04-12 20:42 - 2017-03-25 19:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-04-12 20:42 - 2017-03-25 19:52 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-04-12 20:42 - 2017-03-25 18:59 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-04-12 20:42 - 2017-03-25 18:57 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-04-12 20:42 - 2017-03-25 18:28 - 15259136 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-04-12 20:42 - 2017-03-25 18:27 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-04-12 20:42 - 2017-03-25 18:24 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-04-12 20:42 - 2017-03-25 18:10 - 01546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-04-12 20:42 - 2017-03-25 00:50 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-04-12 20:42 - 2017-03-25 00:42 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-04-12 20:42 - 2017-03-22 17:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-04-12 20:42 - 2017-03-22 17:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-12 20:42 - 2017-03-22 17:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-12 20:42 - 2017-03-22 17:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-12 20:42 - 2017-03-14 17:34 - 00986344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-04-12 20:42 - 2017-03-14 17:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-04-12 20:42 - 2017-03-10 18:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-04-12 20:42 - 2017-03-10 18:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-12 20:42 - 2017-03-10 18:00 - 03219968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-04-12 20:42 - 2017-03-08 22:20 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-04-12 20:42 - 2017-03-08 06:37 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-04-12 20:42 - 2017-03-08 06:33 - 02064384 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-04-12 20:42 - 2017-03-08 06:26 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-04-12 20:42 - 2017-03-08 06:26 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-04-12 20:42 - 2017-03-08 06:22 - 01416192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-04-12 20:42 - 2017-03-04 03:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-04-12 20:42 - 2017-03-04 03:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-12 20:42 - 2017-02-14 18:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-04-12 20:42 - 2017-02-14 18:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-04-12 20:42 - 2017-02-09 18:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-12 20:42 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-12 20:41 - 2017-03-25 20:48 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-04-12 20:41 - 2017-03-25 20:47 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-04-12 20:41 - 2017-03-25 20:47 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-04-12 20:41 - 2017-03-25 20:46 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-04-12 20:41 - 2017-03-25 20:46 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-04-12 20:41 - 2017-03-25 20:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-04-12 20:41 - 2017-03-25 20:46 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-04-12 20:41 - 2017-03-25 20:46 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-04-12 20:41 - 2017-03-25 20:46 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-04-12 20:41 - 2017-03-25 20:46 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-12 20:41 - 2017-03-25 20:46 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-04-12 20:41 - 2017-03-25 20:45 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-04-12 20:41 - 2017-03-25 20:45 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-04-12 20:41 - 2017-03-25 20:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-04-12 20:41 - 2017-03-25 20:45 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-04-12 20:41 - 2017-03-25 20:45 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-04-12 20:41 - 2017-03-25 20:45 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-04-12 20:41 - 2017-03-25 20:45 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-04-12 20:41 - 2017-03-25 20:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-04-12 20:41 - 2017-03-25 20:44 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-04-12 20:41 - 2017-03-25 20:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-04-12 20:41 - 2017-03-25 20:35 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-04-12 20:41 - 2017-03-25 20:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-04-12 20:41 - 2017-03-25 20:14 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-04-12 20:41 - 2017-03-25 20:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-04-12 20:41 - 2017-03-25 20:13 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-04-12 20:41 - 2017-03-25 20:13 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-04-12 20:41 - 2017-03-25 20:04 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-04-12 20:41 - 2017-03-25 20:02 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-04-12 20:41 - 2017-03-25 19:57 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-04-12 20:41 - 2017-03-25 19:56 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-04-12 20:41 - 2017-03-25 19:56 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-04-12 20:41 - 2017-03-25 19:56 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-04-12 20:41 - 2017-03-25 19:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-04-12 20:41 - 2017-03-25 19:41 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-04-12 20:41 - 2017-03-25 19:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-04-12 20:41 - 2017-03-25 19:30 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-04-12 20:41 - 2017-03-25 19:29 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-04-12 20:41 - 2017-03-25 19:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-04-12 20:41 - 2017-03-25 19:23 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-04-12 20:41 - 2017-03-25 19:20 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-04-12 20:41 - 2017-03-25 19:19 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-04-12 20:41 - 2017-03-25 19:17 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-04-12 20:41 - 2017-03-25 19:06 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-04-12 20:41 - 2017-03-25 19:04 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-04-12 20:41 - 2017-03-25 19:00 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-04-12 20:41 - 2017-03-25 18:57 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-04-12 20:41 - 2017-03-25 18:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-04-12 20:41 - 2017-03-22 17:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-04-12 20:41 - 2017-03-22 17:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-04-12 20:41 - 2017-03-22 17:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-04-12 20:41 - 2017-03-22 17:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-12 20:41 - 2017-03-22 17:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-04-12 20:41 - 2017-03-22 17:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-04-12 20:41 - 2017-03-22 17:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-04-12 20:41 - 2017-03-22 17:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-04-12 20:41 - 2017-03-22 17:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-04-12 20:41 - 2017-03-22 17:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-12 20:41 - 2017-03-22 17:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-04-12 20:41 - 2017-03-22 17:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-12 20:41 - 2017-03-14 17:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-04-12 20:41 - 2017-03-10 18:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-04-12 20:41 - 2017-03-10 18:31 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-04-12 20:41 - 2017-03-10 18:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-04-12 20:41 - 2017-03-10 18:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-04-12 20:41 - 2017-03-10 18:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-04-12 20:41 - 2017-03-10 18:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-04-12 20:41 - 2017-03-10 18:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-04-12 20:41 - 2017-03-10 17:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-12 20:41 - 2017-03-08 22:10 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-04-12 20:41 - 2017-03-08 06:36 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-04-12 20:41 - 2017-03-08 06:36 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-04-12 20:41 - 2017-03-08 06:36 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-04-12 20:41 - 2017-03-08 06:36 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-04-12 20:41 - 2017-03-08 06:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:24 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-04-12 20:41 - 2017-03-08 06:22 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 06:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-04-12 20:41 - 2017-03-08 06:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-04-12 20:41 - 2017-03-08 06:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-04-12 20:41 - 2017-03-08 06:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-04-12 20:41 - 2017-03-08 06:00 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-04-12 20:41 - 2017-03-08 05:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-04-12 20:41 - 2017-03-08 05:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-04-12 20:41 - 2017-03-08 05:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-04-12 20:41 - 2017-03-08 05:56 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-04-12 20:41 - 2017-03-08 05:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-04-12 20:41 - 2017-03-08 05:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-04-12 20:41 - 2017-03-08 05:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-04-12 20:41 - 2017-03-08 05:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-04-12 20:41 - 2017-03-08 05:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-04-12 20:41 - 2017-03-08 05:54 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-04-12 20:41 - 2017-03-08 05:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-04-12 20:41 - 2017-03-08 05:53 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-04-12 20:41 - 2017-03-08 05:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 05:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 05:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 20:41 - 2017-03-08 05:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-12 20:41 - 2017-03-07 18:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-04-12 20:41 - 2017-03-07 18:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-12 20:41 - 2017-03-04 03:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-04-12 20:41 - 2017-03-04 03:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-12 20:41 - 2017-02-11 18:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-04-12 20:41 - 2017-02-11 18:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-04-12 20:41 - 2017-02-09 18:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-04-12 20:41 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-04-11 16:19 - 2017-04-11 16:19 - 00003098 _____ C:\Windows\System32\Tasks\{BD800605-25EA-4B8C-AF0B-E27469251622}
2017-04-11 14:37 - 2017-04-11 14:39 - 00045010 _____ C:\Users\Pepa\Desktop\Addition.txt
2017-04-11 14:34 - 2017-04-13 14:45 - 00025721 _____ C:\Users\Pepa\Desktop\FRST.txt
2017-04-11 14:34 - 2017-04-13 14:39 - 00000000 ____D C:\FRST
2017-04-11 14:32 - 2017-04-11 14:33 - 02424832 _____ (Farbar) C:\Users\Pepa\Desktop\FRST64.exe
2017-04-11 14:25 - 2017-04-13 14:38 - 00000154 _____ C:\Users\Public\Documents\temp.dat
2017-04-11 14:22 - 2016-05-19 08:42 - 00052392 _____ (Elex do Brasil Participações Ltda) C:\Windows\system32\Drivers\iSafeNetFilter.sys
2017-04-11 13:47 - 2017-04-11 14:18 - 00000000 ____D C:\AdwCleaner
2017-04-11 13:40 - 2017-04-11 13:43 - 04089296 _____ C:\Users\Pepa\Desktop\adwcleaner_6.045.exe
2017-04-11 13:23 - 2017-04-11 13:23 - 00022435 _____ C:\Users\Pepa\Desktop\JRT.txt
2017-04-11 13:14 - 2017-04-11 13:15 - 01663672 _____ (Malwarebytes) C:\Users\Pepa\Desktop\JRT.exe
2017-04-11 11:48 - 2017-04-11 11:52 - 00000000 ____D C:\rsit
2017-04-11 11:48 - 2017-04-11 11:52 - 00000000 ____D C:\Program Files\trend micro
2017-04-11 11:44 - 2017-04-11 11:46 - 01329152 _____ C:\Users\Pepa\Desktop\RSITx64.exe
2017-04-10 21:05 - 2017-04-10 21:05 - 00000000 ____D C:\Users\Pepa\AppData\Local\AMD
2017-04-10 20:44 - 2017-04-10 20:44 - 00000000 ____D C:\Update
2017-04-06 17:48 - 2017-04-09 13:40 - 00000000 ____D C:\Users\Pepa\AppData\Local\clean
2017-04-06 17:48 - 2017-04-09 10:39 - 00000000 _____ C:\Windows\SysWOW64\4
2017-04-03 10:32 - 2017-04-03 10:32 - 09274608 _____ (Piriform Ltd) C:\Users\Pepa\Downloads\ccsetup528.exe
2017-04-01 20:58 - 2017-04-11 14:13 - 00000000 ____D C:\Windows\system32\log
2017-04-01 20:57 - 2017-04-01 20:57 - 00002004 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-04-01 20:57 - 2017-04-01 20:57 - 00000007 _____ C:\Windows\SysWOW64\DB83.tmp
2017-03-31 14:23 - 2017-03-31 14:23 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-03-31 14:00 - 2017-04-10 20:58 - 00000000 ____D C:\Users\Pepa\AppData\LocalLow\Mozilla
2017-03-31 11:50 - 2017-04-10 21:05 - 00000000 ____D C:\Program Files\MK
2017-03-29 12:32 - 2017-03-29 12:32 - 00000889 _____ C:\Users\Pepa\Documents\Fotky – zástupce.lnk
2017-03-29 12:28 - 2017-03-29 12:28 - 00000000 ____D C:\Users\Pepa\Documents\Pinnacle VideoSpin
2017-03-29 12:16 - 2017-03-29 12:16 - 00001111 _____ C:\Users\Public\Desktop\Pinnacle VideoSpin.lnk
2017-03-29 12:15 - 2017-03-29 12:28 - 00000000 ____D C:\ProgramData\Pinnacle VideoSpin
2017-03-29 12:15 - 2017-03-29 12:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Pinnacle VideoSpin
2017-03-29 12:12 - 2017-03-29 15:53 - 00000000 ____D C:\Users\Pepa\AppData\Local\Downloaded Installations
2017-03-29 12:10 - 2017-03-29 12:11 - 00000000 ____D C:\Program Files (x86)\MIO
2017-03-29 12:09 - 2017-03-29 12:10 - 00000000 ____D C:\Program Files (x86)\MK
2017-03-29 12:07 - 2017-04-10 21:01 - 00000000 ____D C:\Program Files\c1bwvxob
2017-03-28 18:06 - 2017-03-28 18:10 - 170203312 _____ C:\Users\Pepa\Downloads\VideoSpin_2_0_Setup.exe
2017-03-27 21:36 - 2017-03-27 21:36 - 00000000 ___HD C:\$AV_ASW
2017-03-26 22:29 - 2017-03-26 22:29 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Sun
2017-03-26 22:24 - 2017-03-26 22:25 - 00004408 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-03-26 20:37 - 2017-03-26 20:37 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Photodex
2017-03-26 20:37 - 2017-03-26 20:37 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Netscape
2017-03-26 20:37 - 2017-03-26 20:37 - 00000000 ____D C:\Program Files (x86)\Photodex Presenter
2017-03-26 20:37 - 2017-03-26 20:37 - 00000000 ____D C:\Program Files (x86)\Photodex
2017-03-24 16:31 - 2017-03-24 16:31 - 00000000 ____D C:\Users\Pepa\AppData\Local\Pinnacle
2017-03-24 16:19 - 2017-03-24 16:19 - 00000000 ____D C:\ProgramData\Pinnacle Studio Ultimate Collection
2017-03-24 16:12 - 2017-03-29 12:15 - 00000000 ____D C:\Users\Public\Documents\Pinnacle
2017-03-24 16:08 - 2017-04-10 21:09 - 00000349 _____ C:\Users\Public\Documents\PCLECHAL.INI
2017-03-24 16:05 - 2017-03-29 17:07 - 00000000 ____D C:\Program Files (x86)\Pinnacle
2017-03-24 16:03 - 2017-03-24 16:03 - 00001494 _____ C:\ProgramData\__wdump.txt
2017-03-24 15:56 - 2017-03-29 15:46 - 00000000 ____D C:\ProgramData\Pinnacle
2017-03-24 15:51 - 2017-03-24 15:51 - 11193664 _____ (DT Soft Ltd.) C:\Users\Pepa\Downloads\Lite 4.40.2_DTLite4402-0131.exe
2017-03-24 15:46 - 2017-03-24 15:46 - 00692072 _____ (Disc Soft Ltd.) C:\Users\Pepa\Downloads\DTLiteInstaller.exe
2017-03-24 15:28 - 2017-03-24 15:30 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\DAEMON Tools Ultra
2017-03-24 15:28 - 2017-03-24 15:28 - 00047672 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtultrausbbus.sys
2017-03-24 15:28 - 2017-03-24 15:28 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtultrascsibus.sys
2017-03-24 15:26 - 2017-03-24 15:26 - 00000000 ____D C:\ProgramData\DAEMON Tools Ultra
2017-03-24 15:09 - 2017-03-24 15:31 - 00000000 ____D C:\Users\Pepa\AppData\Local\Disc_Soft_Ltd
2017-03-24 15:05 - 2017-03-24 15:05 - 00000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2017-03-24 15:04 - 2017-03-26 09:33 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Kulerty
2017-03-24 15:03 - 2017-04-13 14:30 - 00006036 _____ C:\Windows\System32\Tasks\Atafogh Helper
2017-03-24 15:03 - 2017-04-11 09:10 - 00000000 ____D C:\Program Files (x86)\Prervoly
2017-03-24 15:03 - 2017-03-24 15:04 - 00000000 ____D C:\Users\Pepa\AppData\Local\Guziphdceied
2017-03-24 15:03 - 2017-03-24 15:03 - 00000000 ____D C:\Program Files (x86)\Atafogh Helper
2017-03-24 15:01 - 2017-03-24 15:01 - 00047672 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtliteusbbus.sys
2017-03-24 15:00 - 2017-03-24 15:00 - 00030264 _____ (Disc Soft Ltd) C:\Windows\system32\Drivers\dtlitescsibus.sys
2017-03-20 00:48 - 2017-03-20 00:48 - 00028352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll
2017-03-20 00:48 - 2017-03-20 00:48 - 00019112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110_clr0400.dll
2017-03-20 00:48 - 2017-03-20 00:48 - 00019112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100_clr0400.dll
2017-03-20 00:48 - 2017-03-20 00:48 - 00019112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110_clr0400.dll
2017-03-20 00:41 - 2017-03-20 00:41 - 00030400 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll
2017-03-20 00:41 - 2017-03-20 00:41 - 00019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcr110_clr0400.dll
2017-03-20 00:41 - 2017-03-20 00:41 - 00019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll
2017-03-20 00:41 - 2017-03-20 00:41 - 00019112 _____ (Microsoft Corporation) C:\Windows\system32\msvcp110_clr0400.dll
2017-03-16 22:12 - 2017-02-23 01:42 - 00084712 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2017-03-16 22:12 - 2017-02-23 01:37 - 01285632 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-03-16 22:12 - 2017-02-18 16:05 - 01609216 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-03-16 22:12 - 2017-02-18 16:05 - 00646656 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00556544 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00335360 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00233984 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-03-16 22:12 - 2016-12-31 17:36 - 00133632 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-03-15 16:47 - 2017-02-11 17:58 - 00462848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-03-15 16:47 - 2017-02-11 17:58 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-03-15 16:47 - 2017-02-11 17:58 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-03-15 16:47 - 2017-02-10 18:32 - 00803328 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-03-15 16:47 - 2017-02-10 18:17 - 00628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-03-15 16:47 - 2017-02-10 16:33 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-03-15 16:47 - 2017-02-09 18:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2017-03-15 16:47 - 2017-02-09 18:31 - 00250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2017-03-15 16:47 - 2017-02-09 18:14 - 00215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2017-03-15 16:47 - 2017-02-09 17:51 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2017-03-15 16:47 - 2017-02-09 16:06 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-03-15 16:47 - 2017-02-09 16:06 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-03-15 16:47 - 2017-02-06 18:14 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-03-15 16:47 - 2017-01-13 20:00 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-03-15 16:47 - 2017-01-13 20:00 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2017-03-15 16:47 - 2017-01-13 19:45 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-03-15 16:47 - 2017-01-13 19:45 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2017-03-15 16:47 - 2017-01-11 20:01 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-03-15 16:47 - 2017-01-11 20:01 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2017-03-15 16:47 - 2017-01-11 19:43 - 01241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-03-15 16:47 - 2017-01-11 19:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-04-13 14:45 - 2009-07-14 06:45 - 00019056 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-13 14:45 - 2009-07-14 06:45 - 00019056 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-13 14:33 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-13 14:31 - 2016-11-09 15:18 - 00003100 _____ C:\Windows\System32\Tasks\{EC838D8B-8D3E-42B4-B99C-E856EBC4DBE6}
2017-04-13 14:21 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-04-13 14:20 - 2013-08-25 20:56 - 00000000 ____D C:\Users\Pepa\Documents\registry
2017-04-13 14:00 - 2010-01-29 06:36 - 00669132 _____ C:\Windows\system32\perfh005.dat
2017-04-13 14:00 - 2010-01-29 06:36 - 00141760 _____ C:\Windows\system32\perfc005.dat
2017-04-13 14:00 - 2009-07-14 07:13 - 01584626 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-13 13:51 - 2009-07-14 06:45 - 00517560 _____ C:\Windows\system32\FNTCACHE.DAT
2017-04-12 21:00 - 2012-05-11 23:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-04-12 20:58 - 2012-05-11 23:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-12 20:58 - 2012-05-11 23:23 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-12 20:56 - 2010-03-21 21:19 - 148601744 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-04-12 20:49 - 2014-02-28 07:16 - 01560276 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-04-11 16:44 - 2017-03-06 18:43 - 00004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-04-11 16:14 - 2010-03-17 03:48 - 00000000 ____D C:\Program Files (x86)\Windows Live
2017-04-11 16:12 - 2016-04-27 21:33 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Philipp Winterberg
2017-04-11 16:11 - 2009-10-17 00:02 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-04-11 16:10 - 2011-05-04 21:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefly Studios
2017-04-11 11:45 - 2010-08-01 19:51 - 00003384 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-11 11:45 - 2010-08-01 19:51 - 00003256 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-09 10:51 - 2011-01-13 21:33 - 00016384 _____ C:\Users\Pepa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-04-06 14:04 - 2016-01-06 19:40 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\vlc
2017-04-06 10:04 - 2010-03-17 03:43 - 00001703 _____ C:\Users\Pepa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-04-05 22:04 - 2010-08-01 19:54 - 00002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-05 22:04 - 2010-08-01 19:54 - 00002187 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-03 10:34 - 2015-11-26 16:19 - 00001021 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-04-03 10:30 - 2010-01-29 06:02 - 00000000 ___HD C:\Program Files (x86)\Temp
2017-04-01 20:57 - 2014-06-14 09:56 - 00000000 ____D C:\ProgramData\Package Cache
2017-04-01 20:57 - 2010-03-17 06:26 - 00001934 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-03-31 14:26 - 2016-03-23 14:48 - 00003890 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1458737292
2017-03-31 14:23 - 2014-05-11 20:01 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-03-31 14:23 - 2013-12-22 22:16 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-03-31 14:22 - 2016-03-23 14:47 - 00032600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-03-31 14:22 - 2013-12-22 22:16 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-03-30 17:53 - 2016-11-29 13:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-30 01:49 - 2010-03-18 23:04 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\DAEMON Tools Lite
2017-03-30 01:24 - 2017-03-06 18:43 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-03-30 01:24 - 2017-03-06 18:43 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-03-30 01:24 - 2017-03-06 18:43 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-03-30 01:24 - 2017-03-06 18:43 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-03-29 15:58 - 2010-03-17 03:38 - 00148360 _____ C:\Users\Pepa\AppData\Local\GDIPFONTCACHEV1.DAT
2017-03-26 22:30 - 2016-01-06 23:48 - 00001070 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-03-26 22:28 - 2013-11-25 10:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-03-26 22:27 - 2013-11-25 10:09 - 00097856 ____N (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2017-03-26 22:26 - 2013-03-05 14:06 - 00000000 ____D C:\Program Files (x86)\Java
2017-03-26 22:25 - 2012-04-02 08:31 - 00802904 ____N (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-03-26 22:25 - 2011-11-20 11:37 - 00000000 ____D C:\Windows\system32\Macromed
2017-03-26 22:25 - 2011-05-19 08:48 - 00144472 ____N (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-26 22:24 - 2009-10-17 00:38 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-03-26 20:37 - 2010-03-17 06:30 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\Mozilla
2017-03-26 20:25 - 2015-03-02 01:08 - 00000000 ____D C:\Users\Pepa\Documents\film
2017-03-26 20:24 - 2011-02-10 21:47 - 00000000 ____D C:\Users\Pepa\Documents\www
2017-03-26 20:18 - 2017-01-14 01:28 - 00000000 ____D C:\Users\Pepa\Documents\Karty života
2017-03-24 16:37 - 2013-07-28 21:11 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\uTorrent
2017-03-24 14:59 - 2010-03-18 23:04 - 00000000 ____D C:\ProgramData\DAEMON Tools Lite
2017-03-21 20:32 - 2012-02-26 17:56 - 00000000 ____D C:\Users\Pepa\Desktop\Pro Peťu
2017-03-20 19:14 - 2017-03-08 22:22 - 00000000 ____D C:\Users\Pepa\AppData\Roaming\dvdcss
2017-03-17 13:10 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2017-03-17 08:13 - 2014-12-12 11:16 - 00000000 ____D C:\Windows\system32\appraiser
2017-03-17 08:13 - 2014-05-06 14:01 - 00000000 ___SD C:\Windows\system32\CompatTel
2017-03-16 21:42 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2017-03-16 00:08 - 2013-08-06 21:59 - 00000000 ____D C:\Windows\system32\MRT

==================== Files in the root of some directories =======

2009-10-17 00:12 - 2009-02-10 21:23 - 0192484 _____ () C:\Program Files (x86)\Common Files\Acer GameZone online.ico
2012-10-20 08:47 - 2012-12-25 22:37 - 0000040 _____ () C:\Users\Pepa\AppData\Roaming\cdr.ini
2011-12-23 21:30 - 2011-12-23 21:30 - 0021854 _____ () C:\Users\Pepa\AppData\Roaming\Hodnoty oddělené čárkami (Windows).ADR
2010-03-17 04:11 - 2010-03-17 04:11 - 0000000 _____ () C:\Users\Pepa\AppData\Roaming\wklnhst.dat
2011-01-13 21:33 - 2017-04-09 10:51 - 0016384 _____ () C:\Users\Pepa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-03-17 05:01 - 2010-03-17 05:12 - 0011452 _____ () C:\Users\Pepa\AppData\Local\MyWinLockerInstaller.txt-20100317.log
2016-04-20 20:36 - 2016-04-20 20:36 - 0002876 _____ () C:\Users\Pepa\AppData\Local\recently-used.xbel
2011-12-26 07:40 - 2011-12-26 07:40 - 0000000 _____ () C:\Users\Pepa\AppData\Local\{79BA3A8D-E466-4B2E-90A3-978643A1A4A0}
2010-09-08 13:28 - 2010-09-08 13:28 - 0000056 ____H () C:\ProgramData\ezsidmv.dat
2009-10-17 00:12 - 2009-07-18 03:57 - 0036136 _____ (Oberon Media) C:\ProgramData\FullRemove.exe
2011-10-19 16:36 - 2011-10-19 17:40 - 0000769 _____ () C:\ProgramData\LmeUSB.log
2011-10-19 16:36 - 2011-10-19 17:40 - 0000769 _____ () C:\ProgramData\LSDmbTH.log
2017-03-24 16:03 - 2017-03-24 16:03 - 0001494 _____ () C:\ProgramData\__wdump.txt

Files to move or delete:
====================
C:\Windows\Tasks\{011B8E39-CE88-41E0-B0D4-311E33EC992A}.job
C:\Windows\Tasks\{17533D0E-A9DE-49DD-93CD-ADE62A97FD62}.job
C:\Windows\Tasks\{1A89CBC3-1771-4C0D-8B7E-E785109150BA}.job
C:\Windows\Tasks\{25381E09-4350-4CEB-8375-8F9B5FC882B8}.job
C:\Windows\Tasks\{2C34D498-06D7-4808-AD10-2C290AFC7C68}.job
C:\Windows\Tasks\{3E70DE31-F555-4BF7-ACCE-E9AF4AEE522B}.job
C:\Windows\Tasks\{42441CAB-D394-4ED2-B527-BF8586500CBF}.job
C:\Windows\Tasks\{6B0B2E13-DD0E-4974-82C3-7F7BCAB85C41}.job
C:\Windows\Tasks\{9355D9FC-1AAB-4933-A742-7E47402C6D12}.job
C:\Windows\Tasks\{A9827EA4-461C-4E96-BBCE-3BD151F2CAA6}.job
C:\Windows\Tasks\{B08D7569-C085-4F1D-A2F4-D594EEAE262A}.job
C:\Windows\Tasks\{C91DE031-215F-4A00-AADF-39A56BA2C4DA}.job


Some files in TEMP:
====================
2010-07-02 09:28 - 2010-07-02 09:29 - 0921376 _____ (Sun Microsystems, Inc.) C:\Users\Guest\AppData\Local\Temp\firefoxjre_exe.exe
2017-04-13 14:25 - 2017-04-13 14:25 - 0041984 _____ () C:\Users\Pepa\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpkxtndd.dll
2012-11-07 22:45 - 2012-11-07 22:45 - 0001536 _____ () C:\Users\w\AppData\Local\Temp\NOSEventMessages.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-04-03 12:45

==================== End of FRST.txt ============================

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Asi virus prosím o pomoc

#10 Příspěvek od JaRon »

FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Re: Asi virus prosím o pomoc

#11 Příspěvek od enzo1 »

Tak konečně se to povedlo - ZOEK mi asi vytuhnul, jelo to celou noc a nic až dnes se to podařilo. Zde je LOG:


Zoek.exe v5.0.0.1 Updated 27-09-2015
Tool run by Pepa on p  14.04.2017 at 9:17:26,95.
Microsoft Windows 7 Home Premium 6.1.7601 Service Pack 1 x64
Running in: Normal Mode No Internet Access Detected
Launched: C:\Users\Pepa\Desktop\zoek.exe [Scan all users] [Script inserted]

==== Older Logs ======================

C:\zoek-results2017-04-13-165934.log 15596 bytes

==== Reset Hosts File ======================

# Copyright (c) 1993-2006 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

# localhost name resolution is handled within DNS itself.
127.0.0.1 localhost
::1 localhost

==== Deleting CLSID Registry Keys ======================


==== Deleting CLSID Registry Values ======================


==== Deleting Services ======================


==== FireFox Fix ======================

Deleted from C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\yccqxzn8.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\yccqxzn8.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Pepa\AppData\Roaming\Profiles\Mowadom.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\Pepa\AppData\Roaming\Profiles\Mowadom.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Deleted from C:\Users\w\AppData\Roaming\Mozilla\Firefox\Profiles\agmqryo7.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

Added to C:\Users\w\AppData\Roaming\Mozilla\Firefox\Profiles\agmqryo7.default\prefs.js:
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Deleting Files \ Folders ======================

"C:\Windows\Installer\ee45c.msi" not found

==== Firefox Start and Search pages ======================

ProfilePath: C:\Users\Guest\AppData\Roaming\Mozilla\Firefox\Profiles\yccqxzn8.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Pepa\AppData\Roaming\Profiles\Mowadom.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

ProfilePath: C:\Users\w\AppData\Roaming\Mozilla\Firefox\Profiles\agmqryo7.default
user_pref("browser.startup.homepage", "about:home");
user_pref("browser.newtab.url", "about:newtab");

==== Firefox Extensions Registry ======================

[HKEY_LOCAL_MACHINE\Software\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF48" [31.03.2017 14:23]
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Mozilla\Firefox\Extensions]
"sp@avast.com"="C:\Program Files\AVAST Software\Avast\SafePrice\FF48" [31.03.2017 14:23]

==== Firefox Extensions ======================

ProfilePath: C:\Users\Pepa\AppData\Roaming\Profiles\Mowadom.default
- Undetermined - %ProfilePath%\extensions\trash
- Garmin Communicator - %ProfilePath%\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Firefox Hotfix - %ProfilePath%\extensions\firefox-hotfix@mozilla.org.xpi
- Video DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi

ProfilePath: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default
- Garmin Communicator - %ProfilePath%\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
- Seznam litika - %ProfilePath%\extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}
- Video DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi

ProfilePath: C:\Users\w\AppData\Roaming\Mozilla\Firefox\Profiles\agmqryo7.default
- DownloadHelper - %ProfilePath%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}

AppDir: C:\Program Files (x86)\Mozilla Firefox
- Undetermined - %AppDir%\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
- Java Console - %AppDir%\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
- Undetermined - %AppDir%\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi

==== Firefox Plugins ======================

Profilepath: C:\Users\Pepa\AppData\Roaming\Mozilla\Firefox\Profiles\hgzo6iz3.default
1035EE27D0EFEDE9D97C7C91499A41CC - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_127.dll - Shockwave Flash
37C74F0C5C36BD6744E807089D1CC893 - C:\Users\Pepa\AppData\Roaming\Mozilla\plugins\npPxPlay.dll - Photodex Presenter Plugin


==== Fake Chromium Profiles Check ======================

Fake profile C:\Users\Default\AppData\Local\Google\Chrome deleted

==== Chromium Look ======================

Google Chrome Version: 46.0.2490.86

HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions
eofcbnmajmjmplflapaojjnihcjkigck - No path found[]
gomekmidlodglbbmalcneegieacbdmki - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx[]

Docs - Guest\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake

==== Chromium Startpages ======================

C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences
"homepage": "http://homepage.acer.com/rdr.aspx?b=ACA ... 5t54k1t46s",


==== Set IE to Default ======================

Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
"Default_Page_URL"="http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.ourluckysites.com/search/?ty ... earchTerms}"
"Default_Page_URL"="http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
"Start Page"="http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
"Search Page"="http://www.ourluckysites.com/search/?ty ... earchTerms}"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://www.ourluckysites.com/search/?ty ... earchTerms}"
"Default_Page_URL"="http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
"Start Page"="http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
"Search Page"="http://www.ourluckysites.com/search/?ty ... earchTerms}"

New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://www.ourluckysites.com/?type=hp&t ... X594BS1KNS"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\Main]
"Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Search Page"="http://go.microsoft.com/fwlink/?LinkId=54896"
"Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
"Start Page"="http://go.microsoft.com/fwlink/?LinkId=69157"

==== All HKCU SearchScopes ======================

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{33BB0A4E-99AF-4226-BDF6-49120163DE86}"
{012E1000-F331-11DB-8314-0800200C9A66} Google Url="http://www.google.com/search?q={searchTerms}"
{0633EE93-D776-472f-A0FF-E1416B8B2E3A} Bing Url="http://www.bing.com/search?q={searchTer ... ORM=IESR02"
{33BB0A4E-99AF-4226-BDF6-49120163DE86} ourluckysites Url="http://www.ourluckysites.com/search/?ty ... earchTerms}"
{67A2568C-7A0A-4EED-AECC-B5405DE63B64} Google Url="http://www.google.com/search?sourceid=i ... AW_csCZ371"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google Url="http://www.google.com/search?q={searchT ... urceid=ie7"
{DE98D20C-B3DA-4927-B1EF-B70C559498CA} Seznam TV Program Url="http://tv.seznam.cz/hledej?w={searchTer ... arch_12454"

==== Reset Google Chrome ======================

C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Preferences was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data was reset successfully
C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web Data-journal was reset successfully

==== Deleting Registry Keys ======================

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\BC11171D299C9A24D9651C395901A2AA deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki deleted successfully
HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{D17111CB-C992-42A9-9D56-C19395102AAA} deleted successfully
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Installer\Products\BC11171D299C9A24D9651C395901A2AA deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SeznamInstall-uninstall:62298f0e8f87a174e880190b05ada38f deleted successfully
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype deleted successfully

==== Empty IE Cache ======================

C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Guest\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Guest\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Pepa\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\w\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\w\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\w\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\sysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully

==== Empty FireFox Cache ======================

C:\Users\Guest\AppData\Local\Mozilla\Firefox\Profiles\yccqxzn8.default\cache2 emptied successfully
C:\Users\w\AppData\Local\Mozilla\Firefox\Profiles\agmqryo7.default\Cache emptied successfully

==== Empty Chrome Cache ======================

C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Cache emptied successfully

==== Empty All Flash Cache ======================

Flash Cache Emptied Successfully

==== Empty All Java Cache ======================

Java Cache cleared successfully

==== C:\zoek_backup content ======================

C:\zoek_backup (files=595 folders=154 114395545 bytes)

==== Empty Temp Folders ======================

C:\Users\Default\AppData\Local\Temp emptied successfully
C:\Users\Default User\AppData\Local\Temp emptied successfully
C:\Users\Guest\AppData\Local\Temp emptied successfully
C:\Users\Pepa\AppData\Local\Temp will be emptied at reboot
C:\Users\w\AppData\Local\Temp emptied successfully
C:\Windows\sysWoW64\config\systemprofile\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\networkservice\AppData\Local\Temp emptied successfully
C:\Windows\serviceprofiles\Localservice\AppData\Local\Temp emptied successfully
C:\Windows\Temp will be emptied at reboot

==== After Reboot ======================

==== Empty Temp Folders ======================

C:\Windows\Temp successfully emptied
C:\Users\Pepa\AppData\Local\Temp successfully emptied

==== Empty Recycle Bin ======================

C:\$RECYCLE.BIN successfully emptied

==== Deleting Files / Folders ======================

"C:\PROGRA~2\Atafogh Helper" not found
"C:\PROGRA~3\Package Cache" not found

==== EOF on p  14.04.2017 at 15:36:45,27 ======================

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15796
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Asi virus prosím o pomoc

#12 Příspěvek od JaRon »

Fajn, su este nejake problemy?
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Re: Asi virus prosím o pomoc

#13 Příspěvek od enzo1 »

Otestuju to a dám vědět.

enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Re: Asi virus prosím o pomoc

#14 Příspěvek od enzo1 »

První postřeh - Mozilla Firefox je asi poškozen, nelze spustit, já to odinstaluju a uvidím.
Některé ikony na ploše jsou bez obrázků a po kliku na ně to píše, že soubor byl přesunut nebo odinstalován. Udělám pořádek a pošlu echo.
Zatím moc díky Leoš

enzo1
Návštěvník
Návštěvník
Příspěvky: 37
Registrován: 23 čer 2010 09:15

Re: Asi virus prosím o pomoc

#15 Příspěvek od enzo1 »

Tak otestováno a asi je to ok, zatím jsem nenašel nic co by to dělalo jako před léčbou. Uvidíme jak se to zachová v plném zatížení :-)

Moc díky za vaši pomoc. :idea:
Leoš

Odpovědět