Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu.

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
ab021
Návštěvník
Návštěvník
Příspěvky: 323
Registrován: 11 lis 2007 15:54

Prosím o kontrolu.

#1 Příspěvek od ab021 »

Prosím o kontrolu. PC je veľmi spomalené asi týždeň. MBAM, ADWCleaner a ani ESS nehlásia problém. Ďakujem. Prikladám log z RSIT:
Logfile of random's system information tool 1.10 (written by random/random)
Run by ab021 at 2017-05-02 07:14:38
Microsoft Windows 7 Professional Service Pack 1
System drive C: has 316 GB (76%) free of 417 GB
Total RAM: 4096 MB (67% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:14:45, on 2. 5. 2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18639)
Boot mode: Normal

Running processes:
E:\Install 2\RSIT\RSIT.exe
C:\Program Files (x86)\trend micro\ab021.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.sk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: WebTransBHO Class - {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} - D:\TRANSLAT\WebIE.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll
O2 - BHO: Pomocník pri prihlasovaní v konte Microsoft - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe Acrobat Create PDF Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O3 - Toolbar: WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - D:\TRANSLAT\WebIE.dll
O3 - Toolbar: Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm
O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm
O9 - Extra button: WebTran - {7E6A20FB-153F-402c-A84B-1A64E1955D3D} - D:\TRANSLAT\WebIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - (no file)
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748449} - D:\TRANSLAT\WebIE.dll
O9 - Extra 'Tools' menuitem: &Nastaviť prekladač - {CC963627-B1DC-40E0-B52A-CF21EE748449} - D:\TRANSLAT\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748450} - D:\TRANSLAT\WebIE.dll
O9 - Extra 'Tools' menuitem: &Slovník - {CC963627-B1DC-40E0-B52A-CF21EE748450} - D:\TRANSLAT\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748451} - D:\TRANSLAT\WebIE.dll
O9 - Extra 'Tools' menuitem: Preložiť &označený text - {CC963627-B1DC-40E0-B52A-CF21EE748451} - D:\TRANSLAT\WebIE.dll
O9 - Extra button: (no name) - {CC963627-B1DC-40E0-B52A-CF21EE748452} - D:\TRANSLAT\WebIE.dll
O9 - Extra 'Tools' menuitem: Preložiť &stránku - {CC963627-B1DC-40E0-B52A-CF21EE748452} - D:\TRANSLAT\WebIE.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - http://www.nvidia.com/content/DriverDow ... rtScan.cab
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: CrossLoop Service (CrossLoopService) - CrossLoop - C:\Users\ab021\AppData\Local\CrossLoop\CrossLoopService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes - D:\Malwarebytes Anti-Malware Premium 2.2.1.1043 Final Portable (CZ)\App\Malwarebytes\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: TightVNC Server (tvnserver) - GlavSoft LLC. - C:\Users\ab021\AppData\Local\CrossLoop\tvnserver.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: Wise Boot Assistant (WiseBootAssistant) - Unknown owner - D:\WiseCare365\WiseCare365 Portable\BootTime.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9478 bytes

=========Mozilla firefox=========

ProfilePath - C:\Users\ab021\AppData\Roaming\Mozilla\Firefox\Profiles\ghyo11pn.default

prefs.js - "browser.startup.homepage" - "www.google.sk"

"web2pdfextension.15@web2pdf.adobedotcom"=D:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 25.0.0.148 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0]
"Description"=DivX Web Player
"Path"=D:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.121.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.121.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/GENUINE]
"Description"=
"Path"=disabled

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\Adobe Acrobat]
"Description"=Handles PDFs in-place in Firefox
"Path"=D:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\adobe.com/AdobeAAMDetect]
"Description"=
"Path"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll


C:\Users\ab021\AppData\Roaming\Mozilla\Firefox\Profiles\ghyo11pn.default\extensions\
staged

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2DB66063-BB98-466A-AA0D-3E7ACF5ED853}]
WebTransBHO Class - D:\TRANSLAT\WebIE.dll [2017-03-20 503808]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-08 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Pomocník pri prihlasovaní v konte Microsoft - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17 441592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe Acrobat Create PDF Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-03-28 140512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-08 186944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
Adobe Acrobat Create PDF from Selection - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-03-28 140512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BFC32E1D-EE75-4A48-BC60-104E11EE2431} - WebTranslator - D:\TRANSLAT\WebIE.dll [2017-03-20 503808]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe Acrobat Create PDF Toolbar - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-03-28 140512]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
""= []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2010-11-20 1475584]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"SoftwareSASGeneration"=3

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221
"NoSimpleNetIDList"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\SysWOW64\l3codeca.acm
"vidc.cvid"=iccvid.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"msacm.l3codec"=l3codecp.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-05-02 07:14:38 ----D---- C:\rsit
2017-05-02 07:14:38 ----D---- C:\Program Files (x86)\trend micro
2017-05-01 21:40:43 ----D---- C:\ProgramData\Malwarebytes
2017-05-01 05:55:31 ----D---- C:\Windows\Prefetch
2017-04-30 06:21:15 ----A---- C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-04-29 20:58:21 ----D---- C:\Users\ab021\AppData\Roaming\YoWindow
2017-04-29 20:58:19 ----D---- C:\ProgramData\YoWindow
2017-04-29 20:57:59 ----D---- C:\Program Files (x86)\YoWindow
2017-04-22 05:51:49 ----D---- C:\Users\ab021\AppData\Roaming\Mozilla
2017-04-22 05:51:35 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2017-04-22 05:51:30 ----D---- C:\Program Files (x86)\Mozilla Firefox
2017-04-16 20:51:33 ----D---- C:\Users\ab021\AppData\Roaming\SolidDocuments
2017-04-16 20:48:03 ----D---- C:\Users\ab021\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2017-04-16 20:40:36 ----D---- C:\ProgramData\Adobe
2017-04-12 20:45:38 ----D---- C:\Program Files (x86)\Common Files\Skype
2017-04-11 20:38:51 ----A---- C:\Windows\SysWOW64\mshtml.dll
2017-04-11 20:38:49 ----A---- C:\Windows\SysWOW64\jscript9.dll
2017-04-11 20:38:49 ----A---- C:\Windows\SysWOW64\ieframe.dll
2017-04-11 20:38:48 ----A---- C:\Windows\SysWOW64\wininet.dll
2017-04-11 20:38:48 ----A---- C:\Windows\SysWOW64\iertutil.dll
2017-04-11 20:38:47 ----A---- C:\Windows\SysWOW64\win32spl.dll
2017-04-11 20:38:47 ----A---- C:\Windows\SysWOW64\urlmon.dll
2017-04-11 20:38:46 ----A---- C:\Windows\SysWOW64\wuapi.dll
2017-04-11 20:38:46 ----A---- C:\Windows\SysWOW64\quartz.dll
2017-04-11 20:38:46 ----A---- C:\Windows\SysWOW64\ole32.dll
2017-04-11 20:38:46 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2017-04-11 20:38:46 ----A---- C:\Windows\SysWOW64\gdi32.dll
2017-04-11 20:38:46 ----A---- C:\Windows\SysWOW64\atmfd.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\ucrtbase.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\mshtmlmedia.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-11 20:38:45 ----A---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-11 20:38:44 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2017-04-11 20:38:44 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2017-04-11 20:38:42 ----A---- C:\Windows\SysWOW64\ntdll.dll
2017-04-11 20:38:42 ----A---- C:\Windows\SysWOW64\asycfilt.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\wuwebv.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\wups.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\wudriver.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\webcheck.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\vbscript.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\samlib.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\jscript.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\certcli.dll
2017-04-11 20:38:41 ----A---- C:\Windows\SysWOW64\cdosys.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\sspicli.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\srclient.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\rpcrt4.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\occache.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\msv1_0.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\kerberos.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\jscript9diag.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\ieui.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\ieapfltr.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\dxtrans.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\dxtmsft.dll
2017-04-11 20:38:40 ----A---- C:\Windows\SysWOW64\advapi32.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-11 20:38:39 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\wuapp.exe
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\wow32.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\wdigest.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\TSpkg.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\schannel.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\secur32.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\rpchttp.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\ntvdm64.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\ncrypt.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\msrating.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\MshtmlDac.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\lpk.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\KernelBase.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\kernel32.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\inseng.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\ieUnatt.exe
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\iesetup.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\iernonce.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\ieetwproxystub.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\fontsub.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\dciman32.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\cryptbase.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\credssp.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\bcrypt.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\auditpol.exe
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\atmlib.dll
2017-04-11 20:38:39 ----A---- C:\Windows\SysWOW64\appidapi.dll
2017-04-11 20:38:38 ----AH---- C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-11 20:38:38 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-11 20:38:38 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-11 20:38:38 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-11 20:38:38 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-11 20:38:38 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-11 20:38:38 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-11 20:38:38 ----AH---- C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-11 20:38:38 ----A---- C:\Windows\SysWOW64\user.exe
2017-04-11 20:38:38 ----A---- C:\Windows\SysWOW64\tzres.dll
2017-04-11 20:38:38 ----A---- C:\Windows\SysWOW64\setup16.exe
2017-04-11 20:38:38 ----A---- C:\Windows\SysWOW64\msobjs.dll
2017-04-11 20:38:38 ----A---- C:\Windows\SysWOW64\msaudite.dll
2017-04-11 20:38:38 ----A---- C:\Windows\SysWOW64\instnm.exe
2017-04-11 20:38:38 ----A---- C:\Windows\SysWOW64\apisetschema.dll
2017-04-11 20:38:38 ----A---- C:\Windows\SysWOW64\adtschema.dll

======List of files/folders modified in the last 1 month======

2017-05-02 07:14:40 ----D---- C:\Windows\Temp
2017-05-02 07:14:38 ----RD---- C:\Program Files (x86)
2017-05-01 21:40:43 ----HD---- C:\ProgramData
2017-05-01 21:36:41 ----D---- C:\Windows\System32
2017-05-01 21:36:41 ----D---- C:\Windows\inf
2017-05-01 21:10:30 ----D---- C:\Windows\SysWOW64\config
2017-05-01 19:42:28 ----D---- C:\Windows
2017-05-01 06:02:31 ----D---- C:\Users\ab021\AppData\Roaming\MPC-HC
2017-05-01 06:01:21 ----SHD---- C:\System Volume Information
2017-04-30 17:32:39 ----D---- C:\Users\ab021\AppData\Roaming\Skype
2017-04-30 06:22:32 ----D---- C:\Windows\SysWOW64\Macromed
2017-04-30 06:21:15 ----D---- C:\Windows\SysWOW64
2017-04-29 19:58:45 ----D---- C:\Windows\SoftwareDistribution
2017-04-29 19:55:34 ----D---- C:\Windows\debug
2017-04-28 11:15:28 ----SHD---- C:\Windows\Installer
2017-04-20 16:59:17 ----D---- C:\Users\ab021\AppData\Roaming\vlc
2017-04-16 20:51:04 ----D---- C:\Users\ab021\AppData\Roaming\Adobe
2017-04-16 20:47:03 ----D---- C:\Windows\winsxs
2017-04-16 20:44:32 ----D---- C:\Program Files (x86)\Common Files\Adobe
2017-04-16 20:40:40 ----RSD---- C:\Windows\Fonts
2017-04-16 16:02:00 ----RD---- C:\Program Files
2017-04-16 16:02:00 ----D---- C:\Program Files (x86)\Common Files
2017-04-15 10:14:10 ----D---- C:\Windows\rescache
2017-04-13 10:23:08 ----D---- C:\Windows\Microsoft.NET
2017-04-12 20:45:38 ----RD---- C:\Program Files (x86)\Skype
2017-04-12 20:45:33 ----D---- C:\ProgramData\Skype
2017-04-12 07:09:41 ----RSD---- C:\Windows\assembly
2017-04-11 20:53:53 ----D---- C:\Windows\SysWOW64\sk-SK
2017-04-11 20:53:53 ----D---- C:\Windows\SysWOW64\en-US
2017-04-11 20:53:49 ----D---- C:\Windows\AppPatch
2017-04-11 20:53:49 ----D---- C:\Program Files (x86)\Internet Explorer
2017-04-11 20:53:23 ----D---- C:\ProgramData\Microsoft Help
2017-04-11 20:43:45 ----A---- C:\Windows\SysWOW64\PerfStringBackup.INI
2017-04-06 20:14:20 ----SD---- C:\Users\ab021\AppData\Roaming\Microsoft
2017-04-04 12:09:05 ----SHD---- C:\$Recycle.Bin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys []
R0 MBAMSwissArmy;MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys []
R0 nvstor64;nvstor64; C:\Windows\system32\DRIVERS\nvstor64.sys []
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys []
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys []
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys []
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys []
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys []
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys []
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys []
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys []
R3 NVNET;NVIDIA nForce Ethernet Driver; C:\Windows\system32\DRIVERS\nvmf6264.sys []
R3 PAC7302;Trust Webcam 16175; C:\Windows\system32\DRIVERS\PAC7302.SYS []
R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys []
S3 atikmdag;atikmdag; C:\Windows\system32\DRIVERS\atikmdag.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys []
S3 ew_usbccgpfilter;HwHandSet_CompositeFilter; C:\Windows\system32\DRIVERS\ew_usbccgpfilter.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2017-02-14 25640]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys []
S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm62x64.sys []
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys []
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys []
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys []
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys []
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys []
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys []
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys []
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys []
S3 WiseHDInfo;WiseHDInfo; \??\C:\Windows\WiseHDInfo64.dll [2017-03-25 14800]
S3 WiseRegNotify;WiseRegNotify; \??\C:\Windows\WiseRegNotify.sys [2017-03-03 28080]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-12-19 82640]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2017-02-27 2227312]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe []
R2 CrossLoopService;CrossLoop Service; C:\Users\ab021\AppData\Local\CrossLoop\CrossLoopService.exe [2012-01-06 569072]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 20992]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2013-03-21 1341664]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2012-07-17 2292480]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-03-20 105096]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-03-20 125064]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-26 107848]
S2 MBAMService;MBAMService; D:\Malwarebytes Anti-Malware Premium 2.2.1.1043 Final Portable (CZ)\App\Malwarebytes\mbamservice.exe [2017-03-25 1136608]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-03-14 317400]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-30 271448]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 20992]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-26 107848]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe /V []
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2017-04-14 173512]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 StorSvc;@%SystemRoot%\System32\StorSvc.dll,-100; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 tvnserver;TightVNC Server; C:\Users\ab021\AppData\Local\CrossLoop\tvnserver.exe [2010-07-21 814080]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 20992]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S3 WiseBootAssistant;Wise Boot Assistant; D:\WiseCare365\WiseCare365 Portable\BootTime.exe []
S4 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-03-20 51320]
S4 MBAMScheduler;MBAMScheduler; \mbamscheduler.exe []
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-20 135800]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-20 135800]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-20 135800]

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu.

#2 Příspěvek od altrok »

Krasny den Vam preju :bye:



:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vysypani Kose a tempu, vyprazdneni cache prohlizecu apod.).


:arrow: Dejte logy FRST.txt a Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pokud budete mit problemy se stazenim FRSTLauncheru, staci kdyz pouzijete samotny FRST.exe/FRST64.exe.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

ab021
Návštěvník
Návštěvník
Příspěvky: 323
Registrován: 11 lis 2007 15:54

Re: Prosím o kontrolu.

#3 Příspěvek od ab021 »

Posielam log z FRST:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-05-2017
Ran by ab021 (administrator) on AB021-PC (02-05-2017 12:54:14)
Running from E:\Install 2\RSIT
Loaded Profiles: ab021 (Available Profiles: ab021)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(CrossLoop) C:\Users\ab021\AppData\Local\CrossLoop\CrossLoopService.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Smart Security\egui.exe [6330568 2013-03-21] (ESET)
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {7e5361fa-0a73-11e7-9ebb-00241da22745} - H:\Lenovo_Suite.exe
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {d2dd7725-d0eb-11e6-a229-00241da22745} - H:\HiSuiteDownLoader.exe
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {d2dd7735-d0eb-11e6-a229-00241da22745} - H:\HiSuiteDownLoader.exe
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\ssText3d.scr [333824 2010-11-20] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: Hosts file not detected in the default directory
Tcpip\Parameters: [DhcpNameServer] 192.168.3.1
Tcpip\..\Interfaces\{1D09F30E-7C59-4C0D-8511-C1BA8CD749CD}: [DhcpNameServer] 192.168.3.1

Internet Explorer:
==================
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.sk/
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-03-28] (Adobe Systems Incorporated)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-03-28] (Adobe Systems Incorporated)
BHO-x32: WebTransBHO Class -> {2DB66063-BB98-466A-AA0D-3E7ACF5ED853} -> D:\TRANSLAT\WebIE.dll [2017-03-20] ()
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-08] (Oracle Corporation)
BHO-x32: Pomocník pri prihlasovaní v konte Microsoft -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-03-28] (Adobe Systems Incorporated)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-08] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-03-28] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2017-03-28] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - WebTranslator - {BFC32E1D-EE75-4A48-BC60-104E11EE2431} - D:\TRANSLAT\WebIE.dll [2017-03-20] ()
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2017-03-28] (Adobe Systems Incorporated)
DPF: HKLM-x32 {74DBCB52-F298-4110-951D-AD2FF67BC8AB} hxxp://www.nvidia.com/content/DriverDownload/n ... rtScan.cab

FireFox:
========
FF DefaultProfile: ghyo11pn.default
FF ProfilePath: C:\Users\ab021\AppData\Roaming\Mozilla\Firefox\Profiles\ghyo11pn.default [2017-05-01]
FF Homepage: Mozilla\Firefox\Profiles\ghyo11pn.default -> www.google.sk
FF Extension: (Nepi Jano!) - C:\Users\ab021\AppData\Roaming\Mozilla\Firefox\Profiles\ghyo11pn.default\Extensions\@nepi-jano.xpi [2017-02-09]
FF Extension: (Adguard AdBlocker) - C:\Users\ab021\AppData\Roaming\Mozilla\Firefox\Profiles\ghyo11pn.default\Extensions\adguardadblocker@adguard.com.xpi [2017-04-22]
FF Extension: (ImTranslator) - C:\Users\ab021\AppData\Roaming\Mozilla\Firefox\Profiles\ghyo11pn.default\Extensions\{9AA46F4F-4DC7-4c06-97AF-5035170634FE}.xpi [2016-10-06]
FF Extension: (Video DownloadHelper) - C:\Users\ab021\AppData\Roaming\Mozilla\Firefox\Profiles\ghyo11pn.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2017-04-30]
FF Extension: (Adobe Acrobat - Create PDF) - D:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2017-04-16]
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: (ESET Smart Security Extension) - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2016-07-26] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - D:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-30] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-07-29] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-30] ()
FF Plugin-x32: @divx.com/DivX Browser Plugin,version=1.0.0 -> D:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2009-05-12] (DivX,Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-08] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> D:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> D:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2017-03-28] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-07-29] (Adobe Systems)

Chrome:
=======
CHR StartupUrls: Default -> "hxxp://www.google.sk/"
CHR Profile: C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default [2017-05-02]
CHR Extension: (Prezentácie Google) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-26]
CHR Extension: (h264ify) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\aleakchihdccplidncghkekgioiakgal [2016-10-22]
CHR Extension: (Dokumenty Google) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-26]
CHR Extension: (Disk Google) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-26]
CHR Extension: (Adguard blokovač reklamy) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2016-12-22]
CHR Extension: (YouTube) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-26]
CHR Extension: (Nepi Jano!) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmiebaglkdeebobffhbomapifjjjjakj [2017-03-03]
CHR Extension: (Adobe Acrobat) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-04-16]
CHR Extension: (Tabuľky Google) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-26]
CHR Extension: (Ugly Email) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgiafaliifpknmgofiifianlnbgflgj [2017-03-31]
CHR Extension: (Video DownloadHelper) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjnegcaeklhafolokijcfjliaokphfk [2016-12-22]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-09]
CHR Extension: (ImTranslator: Translator, Dictionary, TTS) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\noaijdpnepcgjemiklgfkcfbkokogabh [2017-03-22]
CHR Extension: (Gmail) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-26]
CHR Extension: (Chrome Media Router) - C:\Users\ab021\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-25]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - D:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2017-03-28]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-02-27] (Adobe Systems, Incorporated)
R2 CrossLoopService; C:\Users\ab021\AppData\Local\CrossLoop\CrossLoopService.exe [569072 2012-01-06] (CrossLoop)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1341664 2013-03-21] (ESET)
S3 tvnserver; C:\Users\ab021\AppData\Local\CrossLoop\tvnserver.exe [814080 2010-07-21] (GlavSoft LLC.) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 WiseBootAssistant; D:\WiseCare365\WiseCare365 Portable\BootTime.exe [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2013-02-14] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [150616 2013-01-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [190232 2013-01-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2013-01-10] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [58416 2013-02-14] (ESET)
S3 ew_usbccgpfilter; C:\Windows\System32\DRIVERS\ew_usbccgpfilter.sys [18816 2016-11-25] (Huawei Technologies Co., Ltd.)
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2016-11-25] (Huawei Technologies Co., Ltd.)
R3 PAC7302; C:\Windows\System32\DRIVERS\PAC7302.SYS [532480 2009-04-28] (PixArt Imaging Inc.)
R3 pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [82048 2016-07-26] (VSO Software) [File not signed]
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2017-03-25] (wisecleaner.com)
S3 WiseRegNotify; C:\Windows\WiseRegNotify.sys [28080 2017-03-03] (WiseCleaner.com)
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-02 12:53 - 2017-05-02 12:54 - 00000000 ____D C:\FRST
2017-05-02 07:14 - 2017-05-02 07:14 - 00000000 ____D C:\Program Files (x86)\trend micro
2017-05-01 21:40 - 2017-03-25 17:51 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-05-01 21:40 - 2017-03-25 17:51 - 00065408 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2017-05-01 21:40 - 2017-03-25 17:51 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-04-30 06:21 - 2017-04-30 06:22 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-04-30 06:21 - 2017-04-30 06:22 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-04-29 20:58 - 2017-04-29 21:02 - 00000000 ____D C:\Users\ab021\AppData\Roaming\YoWindow
2017-04-29 20:58 - 2017-04-29 20:58 - 00000704 _____ C:\Users\Public\Desktop\YoWindow.lnk
2017-04-29 20:58 - 2017-04-29 20:58 - 00000000 ____D C:\ProgramData\YoWindow
2017-04-29 20:58 - 2017-04-29 20:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YoWindow
2017-04-29 20:57 - 2017-04-29 20:57 - 00000000 ____D C:\Program Files (x86)\YoWindow
2017-04-29 20:09 - 2017-04-29 20:09 - 00113264 _____ C:\Users\ab021\AppData\Local\GDIPFONTCACHEV1.DAT
2017-04-29 19:55 - 2017-04-29 19:55 - 00419160 _____ C:\Windows\system32\FNTCACHE.DAT
2017-04-22 05:52 - 2017-04-30 18:15 - 00000000 ____D C:\Users\ab021\AppData\LocalLow\Mozilla
2017-04-22 05:51 - 2017-04-22 13:29 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-04-22 05:51 - 2017-04-22 05:56 - 00000000 ____D C:\Users\ab021\AppData\Local\Mozilla
2017-04-22 05:51 - 2017-04-22 05:54 - 00001165 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-04-22 05:51 - 2017-04-22 05:54 - 00001153 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-04-22 05:51 - 2017-04-22 05:54 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-04-22 05:51 - 2017-04-22 05:52 - 00000000 ____D C:\Users\ab021\AppData\Roaming\Mozilla
2017-04-16 20:51 - 2017-04-16 20:51 - 00000000 ____D C:\Users\ab021\AppData\Roaming\SolidDocuments
2017-04-16 20:48 - 2017-04-16 20:48 - 00000000 ____D C:\Users\ab021\AppData\Roaming\com.adobe.formscentral.FormsCentralForAcrobat
2017-04-16 20:47 - 2017-04-16 20:54 - 00000000 ____D C:\Users\ab021\AppData\LocalLow\Adobe
2017-04-16 20:44 - 2017-04-30 06:22 - 00000000 ____D C:\Users\ab021\AppData\Local\Adobe
2017-04-16 20:43 - 2017-04-16 20:43 - 00002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat XI Pro.lnk
2017-04-16 20:43 - 2017-04-16 20:43 - 00001909 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe FormsCentral.lnk
2017-04-16 20:43 - 2017-04-16 20:43 - 00001786 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller XI.lnk
2017-04-16 20:43 - 2017-04-16 20:43 - 00001777 _____ C:\Users\Public\Desktop\Adobe Acrobat XI Pro.lnk
2017-04-16 20:40 - 2017-04-16 20:51 - 00000000 ____D C:\ProgramData\Adobe
2017-04-11 20:38 - 2017-03-27 20:13 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-04-11 20:38 - 2017-03-27 19:28 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-04-11 20:38 - 2017-03-25 21:39 - 20284416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-04-11 20:38 - 2017-03-25 21:07 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-04-11 20:38 - 2017-03-25 21:06 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-04-11 20:38 - 2017-03-25 20:55 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-04-11 20:38 - 2017-03-25 20:52 - 02289152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-04-11 20:38 - 2017-03-25 20:51 - 01313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-04-11 20:38 - 2017-03-25 20:48 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-04-11 20:38 - 2017-03-25 20:47 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-04-11 20:38 - 2017-03-25 20:47 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-04-11 20:38 - 2017-03-25 20:47 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-04-11 20:38 - 2017-03-25 20:46 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-04-11 20:38 - 2017-03-25 20:46 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-04-11 20:38 - 2017-03-25 20:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-04-11 20:38 - 2017-03-25 20:46 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-04-11 20:38 - 2017-03-25 20:46 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-04-11 20:38 - 2017-03-25 20:46 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-04-11 20:38 - 2017-03-25 20:46 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-11 20:38 - 2017-03-25 20:46 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-04-11 20:38 - 2017-03-25 20:45 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-04-11 20:38 - 2017-03-25 20:45 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-04-11 20:38 - 2017-03-25 20:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-04-11 20:38 - 2017-03-25 20:45 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-04-11 20:38 - 2017-03-25 20:45 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-04-11 20:38 - 2017-03-25 20:45 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-04-11 20:38 - 2017-03-25 20:45 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-04-11 20:38 - 2017-03-25 20:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-04-11 20:38 - 2017-03-25 20:44 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-04-11 20:38 - 2017-03-25 20:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-04-11 20:38 - 2017-03-25 20:35 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-04-11 20:38 - 2017-03-25 20:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-04-11 20:38 - 2017-03-25 20:14 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-04-11 20:38 - 2017-03-25 20:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-04-11 20:38 - 2017-03-25 20:13 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-04-11 20:38 - 2017-03-25 20:13 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-04-11 20:38 - 2017-03-25 20:10 - 02898432 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-04-11 20:38 - 2017-03-25 20:04 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-04-11 20:38 - 2017-03-25 20:02 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-04-11 20:38 - 2017-03-25 19:57 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-04-11 20:38 - 2017-03-25 19:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-04-11 20:38 - 2017-03-25 19:56 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-04-11 20:38 - 2017-03-25 19:56 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-04-11 20:38 - 2017-03-25 19:56 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-04-11 20:38 - 2017-03-25 19:52 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-04-11 20:38 - 2017-03-25 19:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-04-11 20:38 - 2017-03-25 19:41 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-04-11 20:38 - 2017-03-25 19:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-04-11 20:38 - 2017-03-25 19:30 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-04-11 20:38 - 2017-03-25 19:29 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-04-11 20:38 - 2017-03-25 19:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-04-11 20:38 - 2017-03-25 19:23 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-04-11 20:38 - 2017-03-25 19:20 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-04-11 20:38 - 2017-03-25 19:19 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-04-11 20:38 - 2017-03-25 19:17 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-04-11 20:38 - 2017-03-25 19:06 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-04-11 20:38 - 2017-03-25 19:04 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-04-11 20:38 - 2017-03-25 19:00 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-04-11 20:38 - 2017-03-25 18:59 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-04-11 20:38 - 2017-03-25 18:57 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-04-11 20:38 - 2017-03-25 18:57 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-04-11 20:38 - 2017-03-25 18:28 - 15259136 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-04-11 20:38 - 2017-03-25 18:27 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-04-11 20:38 - 2017-03-25 18:24 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-04-11 20:38 - 2017-03-25 18:10 - 01546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-04-11 20:38 - 2017-03-25 18:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-04-11 20:38 - 2017-03-25 00:50 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-04-11 20:38 - 2017-03-25 00:42 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-04-11 20:38 - 2017-03-22 17:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-04-11 20:38 - 2017-03-22 17:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-04-11 20:38 - 2017-03-22 17:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-04-11 20:38 - 2017-03-22 17:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-04-11 20:38 - 2017-03-22 17:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-11 20:38 - 2017-03-22 17:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-11 20:38 - 2017-03-22 17:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-11 20:38 - 2017-03-22 17:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-04-11 20:38 - 2017-03-22 17:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-04-11 20:38 - 2017-03-22 17:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-04-11 20:38 - 2017-03-22 17:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-04-11 20:38 - 2017-03-22 17:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-04-11 20:38 - 2017-03-22 17:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-11 20:38 - 2017-03-22 17:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-11 20:38 - 2017-03-22 17:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-04-11 20:38 - 2017-03-22 17:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-11 20:38 - 2017-03-14 17:34 - 00986344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-04-11 20:38 - 2017-03-14 17:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-04-11 20:38 - 2017-03-14 17:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-04-11 20:38 - 2017-03-10 18:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-04-11 20:38 - 2017-03-10 18:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-04-11 20:38 - 2017-03-10 18:31 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-04-11 20:38 - 2017-03-10 18:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-04-11 20:38 - 2017-03-10 18:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-04-11 20:38 - 2017-03-10 18:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-11 20:38 - 2017-03-10 18:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-04-11 20:38 - 2017-03-10 18:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-04-11 20:38 - 2017-03-10 18:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-04-11 20:38 - 2017-03-10 18:00 - 03219968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-04-11 20:38 - 2017-03-10 17:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-11 20:38 - 2017-03-08 22:20 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-04-11 20:38 - 2017-03-08 22:10 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-04-11 20:38 - 2017-03-08 06:37 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-04-11 20:38 - 2017-03-08 06:36 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-04-11 20:38 - 2017-03-08 06:36 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-04-11 20:38 - 2017-03-08 06:36 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-04-11 20:38 - 2017-03-08 06:36 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-04-11 20:38 - 2017-03-08 06:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 02064384 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:26 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-04-11 20:38 - 2017-03-08 06:26 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-04-11 20:38 - 2017-03-08 06:24 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 01416192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-04-11 20:38 - 2017-03-08 06:22 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 06:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-04-11 20:38 - 2017-03-08 06:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-04-11 20:38 - 2017-03-08 06:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-04-11 20:38 - 2017-03-08 06:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-04-11 20:38 - 2017-03-08 06:00 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-04-11 20:38 - 2017-03-08 05:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-04-11 20:38 - 2017-03-08 05:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-04-11 20:38 - 2017-03-08 05:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-04-11 20:38 - 2017-03-08 05:56 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-04-11 20:38 - 2017-03-08 05:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-04-11 20:38 - 2017-03-08 05:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-04-11 20:38 - 2017-03-08 05:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-04-11 20:38 - 2017-03-08 05:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-04-11 20:38 - 2017-03-08 05:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-04-11 20:38 - 2017-03-08 05:54 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-04-11 20:38 - 2017-03-08 05:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-04-11 20:38 - 2017-03-08 05:53 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-04-11 20:38 - 2017-03-08 05:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 05:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 05:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-11 20:38 - 2017-03-08 05:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-11 20:38 - 2017-03-07 18:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-04-11 20:38 - 2017-03-07 18:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-11 20:38 - 2017-03-04 03:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-04-11 20:38 - 2017-03-04 03:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-04-11 20:38 - 2017-03-04 03:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-11 20:38 - 2017-03-04 03:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-11 20:38 - 2017-02-14 18:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-04-11 20:38 - 2017-02-14 18:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-04-11 20:38 - 2017-02-11 18:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-04-11 20:38 - 2017-02-11 18:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-04-11 20:38 - 2017-02-09 18:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-04-11 20:38 - 2017-02-09 18:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-04-11 20:38 - 2017-02-09 18:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-11 20:38 - 2017-01-18 17:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-08 15:18 - 2017-04-08 15:18 - 00000000 ___RD C:\Users\ab021\Documents\Scanned Documents
2017-04-08 15:18 - 2017-04-08 15:18 - 00000000 ____D C:\Users\ab021\Documents\Fax
2017-04-06 19:19 - 2017-04-06 19:19 - 00000000 ____D C:\Users\ab021\AppData\Local\CEF

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-02 11:20 - 2009-07-14 06:45 - 00014256 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-02 11:20 - 2009-07-14 06:45 - 00014256 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-02 11:18 - 2009-07-14 07:13 - 00785366 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-02 11:18 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-05-02 11:11 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-02 07:16 - 2016-07-26 09:41 - 00003970 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{9EB6B6E5-7DE0-45CD-89E5-35A8E2669CA7}
2017-05-01 21:39 - 2016-07-26 09:18 - 00000000 ____D C:\Users\ab021
2017-05-01 06:02 - 2016-09-13 17:05 - 00000000 ____D C:\Users\ab021\AppData\Roaming\MPC-HC
2017-04-30 19:34 - 2017-01-18 10:14 - 00000000 ___RD C:\Users\ab021\Documents\video
2017-04-30 17:34 - 2017-01-01 15:39 - 00000000 _____ C:\Windows\XXLGSC
2017-04-30 17:32 - 2016-07-26 19:51 - 00000000 ____D C:\Users\ab021\AppData\Roaming\Skype
2017-04-30 06:22 - 2016-07-26 10:35 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-04-30 06:22 - 2016-07-26 10:35 - 00000000 ____D C:\Windows\system32\Macromed
2017-04-28 17:34 - 2017-01-18 10:12 - 00000000 ____D C:\Users\ab021\Documents\Včely
2017-04-24 18:31 - 2009-07-14 07:08 - 00032606 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-04-24 06:45 - 2017-01-18 10:20 - 00000000 ____D C:\Users\ab021\Documents\Recepty
2017-04-22 22:00 - 2016-07-26 09:55 - 00000696 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-04-22 15:25 - 2016-07-26 12:39 - 00002213 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-22 15:25 - 2016-07-26 12:39 - 00002201 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-20 16:59 - 2016-07-26 22:41 - 00000000 ____D C:\Users\ab021\AppData\Roaming\vlc
2017-04-16 20:51 - 2016-07-26 10:36 - 00000000 ____D C:\Users\ab021\AppData\Roaming\Adobe
2017-04-16 20:38 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2017-04-15 10:14 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2017-04-12 20:45 - 2016-07-26 19:51 - 00000000 ___RD C:\Program Files (x86)\Skype
2017-04-12 20:45 - 2016-07-26 19:51 - 00000000 ____D C:\ProgramData\Skype
2017-04-11 20:49 - 2016-07-26 09:43 - 00000000 ____D C:\Windows\system32\MRT
2017-04-11 20:46 - 2016-07-26 09:43 - 148601744 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-04-11 20:43 - 2016-07-26 15:12 - 00769348 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-04-06 20:15 - 2009-07-14 09:54 - 00000000 ___RD C:\Users\Public\Recorded TV

==================== Files in the root of some directories =======

2016-07-26 21:59 - 2016-07-26 21:59 - 0093696 _____ () C:\Users\ab021\AppData\Roaming\ezpinst.exe
2016-07-26 21:59 - 2016-07-26 21:59 - 0007176 _____ () C:\Users\ab021\AppData\Roaming\pcouffin.cat
2016-07-26 21:59 - 2016-07-26 21:59 - 0001167 _____ () C:\Users\ab021\AppData\Roaming\pcouffin.inf
2016-07-26 21:59 - 2016-07-26 22:01 - 0000034 _____ () C:\Users\ab021\AppData\Roaming\pcouffin.log
2016-07-26 21:59 - 2016-07-26 21:59 - 0082048 _____ (VSO Software) C:\Users\ab021\AppData\Roaming\pcouffin.sys
2017-02-15 05:33 - 2017-02-15 05:34 - 0007605 _____ () C:\Users\ab021\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-05-02 07:54

==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-05-2017
Ran by ab021 (02-05-2017 12:55:46)
Running from E:\Install 2\RSIT
Windows 7 Professional Service Pack 1 (X64) (2016-07-26 07:17:16)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

ab021 (S-1-5-21-4105794192-3944765755-37458331-1000 - Administrator - Enabled) => C:\Users\ab021
Administrator (S-1-5-21-4105794192-3944765755-37458331-500 - Administrator - Disabled)
Guest (S-1-5-21-4105794192-3944765755-37458331-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4105794192-3944765755-37458331-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: ESET Smart Security 6.0 (Enabled - Up to date) {77DEAFED-8149-104B-25A1-21771CA47CD1}
AS: ESET Smart Security 6.0 (Enabled - Up to date) {CCBF4E09-A773-1FC5-1F11-1A056723366C}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET personal firewall (Enabled) {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
Adobe Acrobat XI Pro (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-000000000006}) (Version: 11.0.20 - Adobe Systems)
Adobe Flash Player 25 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Adobe Flash Player 25 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Aktualizácia Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-041B-0000-0000000FF1CE}_PROPLUS_{9A8C39B0-D27F-4F81-BE74-2FECF164707E}) (Version: - Microsoft)
Aktualizácia Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-041B-0000-0000000FF1CE}_PROPLUS_{CE23B3DC-18CC-46FC-A309-81D6670F8D3D}) (Version: - Microsoft)
Aktualizácia Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-041B-0000-0000000FF1CE}_PROPLUS_{D6DBF512-87C0-4F6A-8FB9-AC3A389D9DE5}) (Version: - Microsoft)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.8 - Advanced Micro Devices, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.29 - Piriform)
CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6321 - CDBurnerXP)
ConvertHelper 3.0 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF52}}_is1) (Version: - DownloadHelper)
CorelDRAW Graphics Suite X3 (HKLM-x32\...\{7C5123A9-30A8-4C44-89CA-A8C87A1FCC91}) (Version: 13.0 - Corel Corporation)
CPUID HWMonitor 1.30 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
CrossLoop 2.82 (HKLM-x32\...\CrossLoop_is1) (Version: 2.82 - CrossLoop, Inc.)
CZ (x32 Version: 13.0 - Corel Corporation) Hidden
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DivX Web Player (HKLM-x32\...\{B7050CBDB2504B34BC2A9CA0A692CC29}) (Version: 1.5.0 - DivX,Inc.)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - )
ESET Smart Security (HKLM\...\{F0235BC5-889C-442D-B831-7F894E5C9AD1}) (Version: 6.0.316.2 - ESET, spol s r. o.)
FontNav (x32 Version: 5.0 - Corel Corporation) Hidden
Free Studio version 2014 (HKLM-x32\...\Free Studio_is1) (Version: 6.2.4.1230 - DVDVideoSoft Ltd.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.81 - Spoločnosť Google Inc.)
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
HD Tune Pro 5.60 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software)
IsoBuster 3.6 (HKLM-x32\...\IsoBuster_is1) (Version: 3.6 - Smart Projects)
Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUS) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mozilla Firefox 53.0 (x86 sk) (HKLM-x32\...\Mozilla Firefox 53.0 (x86 sk)) (Version: 53.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0 - Mozilla)
MPC-HC 1.7.11 (64-bit) (HKLM\...\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.11 - MPC-HC Team)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version: - )
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.10.57.35 - NVIDIA Corporation)
Pamela Pro 4.8 (HKLM-x32\...\Pamela) (Version: 4.8 - Scendix Software-Vertriebsges. mbH)
Popisovač CD/DVD 4.0 (HKLM-x32\...\Popisovač CD/DVD_is1) (Version: - PS Media s.r.o.)
Skype™ 7.35 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.35.101 - Skype Technologies S.A.)
Software tiskárny EPSON (HKLM\...\EPSON Printer and Utilities) (Version: - )
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.52 - Ghisler Software GmbH)
Trust Webcam 16175 (HKLM-x32\...\{7B1E8FA3-32BB-4902-AF7E-B9D9DAD6A675}) (Version: 1.0.0.0 - )
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0011-0000-0000-0000000FF1CE}_PROPLUS_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update Manager (x32 Version: 4.60 - Corel Corporation) Hidden
VBA (x32 Version: 6.2 - Corel Corporation) Hidden
VC80CRTRedist - 8.0.50727.762 (x32 Version: 1.0.0 - DivX, Inc) Hidden
Video Convert Master 8.0.8.24 (HKLM-x32\...\Video Convert Master_is1) (Version: - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
YoWindow (HKLM-x32\...\yowindow) (Version: 3 - RepkaSoft)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {91E3A65C-3842-45C3-9331-7A7860C574B6} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\Windows\system32\EOSNotify.exe [2016-06-25] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\ab021\Desktop\CrossLoop Connect.lnk -> C:\Users\ab021\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\ab021\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CrossLoop\CrossLoop.lnk -> C:\Users\ab021\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server
ShortcutWithArgument: C:\Users\ab021\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\CrossLoop.lnk -> C:\Users\ab021\AppData\Local\CrossLoop\CrossLoopConnect.exe (CrossLoop) -> -ap=crossloop -port=5910 -udp=www.CrossLoop.com -webserver=server.crossloop.com -webservice=www.crossloop.com -startup=server

==================== Loaded Modules (Whitelisted) ==============

2017-04-22 15:25 - 2017-04-19 06:04 - 02864984 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\libglesv2.dll
2017-04-22 15:25 - 2017-04-19 06:04 - 00087384 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\skype.com -> hxxps://apps.skype.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-4105794192-3944765755-37458331-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\ab021\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.3.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: PAC7302_Monitor => C:\Windows\PixArt\PAC7302\Monitor.exe
MSCONFIG\startupreg: PACTray => C:\Windows\Pixart\PAC7302\PACTray.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{9008BCF1-79D1-465B-94A1-042D71E1ACFB}] => (Allow) LPort=5910
FirewallRules: [{005ADEA0-97D4-45F1-9856-685D735642C1}] => (Allow) C:\Users\ab021\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{0ED6F4F8-183E-4315-8E1D-EA815DEE4028}] => (Allow) C:\Users\ab021\AppData\Local\CrossLoop\vncviewer.exe
FirewallRules: [{6C62BFE2-4307-4E91-A605-6E25E3F76F26}] => (Allow) C:\Users\ab021\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{21649500-C343-4374-A1A2-A85E48A3CB0B}] => (Allow) C:\Users\ab021\AppData\Local\CrossLoop\tvnserver.exe
FirewallRules: [{CA444743-FF69-44B0-A50D-97E1F94C1189}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{B2DC0AEF-4D3C-4C5D-A9A9-85B93093F888}] => (Allow) D:\Users\ab021\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{A70EF58E-1036-4BF3-9597-642C24088E0B}] => (Allow) D:\Users\ab021\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{CBB504A1-5F53-40A9-B069-D7F07E103B00}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{F05F0FFF-1CA1-4082-8F2D-AD5A216D44C5}] => (Allow) LPort=2869
FirewallRules: [{2F3C071B-613F-49B3-BE06-5DC6DB247273}] => (Allow) LPort=1900
FirewallRules: [{F6F5AC99-E3B2-4EDC-9560-89B5B81784BA}] => (Allow) D:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe
FirewallRules: [{C8EF1ECC-DB14-4922-A2C2-71E3BA3F89B8}] => (Allow) D:\Program Files (x86)\DVDVideoSoft\Free Torrent Download\FreeTorrentDownload.exe
FirewallRules: [{CCA0783D-AA9C-40A0-9EFE-64C06A68DB79}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{751F5BC5-ADC8-4184-B569-968A56C738DD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{862DB295-0E0A-4637-9447-FC2EF112BAD9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

01-05-2017 06:01:04 Bod obnovenia
02-05-2017 07:16:29 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (05/02/2017 11:18:00 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/02/2017 11:18:00 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/02/2017 08:00:26 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/02/2017 08:00:26 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/02/2017 07:18:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/02/2017 07:18:57 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/01/2017 09:36:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/01/2017 09:36:41 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/01/2017 09:05:19 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.

Error: (05/01/2017 09:05:19 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3006) (User: NT AUTHORITY)
Description: Unable to read the performance counter strings defined for the 01B language ID. The first DWORD in the Data section contains the Win32 error code.


System errors:
=============
Error: (05/02/2017 12:41:04 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (05/02/2017 12:25:10 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (05/02/2017 12:25:10 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (05/02/2017 12:09:38 PM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (05/02/2017 11:41:04 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (05/02/2017 11:11:26 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (05/02/2017 11:11:25 AM) (Source: WMPNetworkSvc) (EventID: 14332) (User: )
Description: Služba WMPNetworkSvc sa nespustila správne, pretože sa vo funkcii CoCreateInstance(CLSID_UPnPDeviceFinder) vyskytla chyba 0x80004005. Uistite sa, že je služba UPnPHost spustená a že je súčasť UPnPHost systému Windows správne nainštalovaná.

Error: (05/02/2017 11:11:18 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (05/02/2017 11:11:17 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.

Error: (05/02/2017 11:11:14 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: There was an error while attempting to read the local hosts file.


==================== Memory info ===========================

Processor: AMD Athlon(tm) II X2 240 Processor
Percentage of memory in use: 52%
Total physical RAM: 4095.55 MB
Available physical RAM: 1940.27 MB
Total Virtual: 8189.29 MB
Available Virtual: 6027.52 MB

==================== Drives ================================

Drive c: (Systém) (Fixed) (Total:407.06 GB) (Free:308.26 GB) NTFS
Drive d: (Programy) (Fixed) (Total:117.19 GB) (Free:98.26 GB) NTFS
Drive e: (Záloha) (Fixed) (Total:407.16 GB) (Free:215.61 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 21A4C592)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=407.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=524.3 GB) - (Type=05)

==================== End of Addition.txt ============================

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu.

#4 Příspěvek od altrok »

:arrow: Pouzivate ESET Smart Security 6.0 - dnes je k dispozici verze 10. Velice doporucuji upgrade na tuto aktualni verzi. Dale trvale vypnete Windows Defender - http://windows.microsoft.com/cs-cz/wind ... =windows-7



  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CreateRestorePoint:
    CloseProcesses:
    HKLM-x32\...\Run: [] => [X]
    HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
    HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {7e5361fa-0a73-11e7-9ebb-00241da22745} - H:\Lenovo_Suite.exe
    HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {d2dd7725-d0eb-11e6-a229-00241da22745} - H:\HiSuiteDownLoader.exe
    HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {d2dd7735-d0eb-11e6-a229-00241da22745} - H:\HiSuiteDownLoader.exe
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    S3 WiseBootAssistant; D:\WiseCare365\WiseCare365 Portable\BootTime.exe [X]
    D:\WiseCare365
    S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
    S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2017-03-25] (wisecleaner.com)
    C:\Windows\WiseHDInfo64.dll
    S3 WiseRegNotify; C:\Windows\WiseRegNotify.sys [28080 2017-03-03] (WiseCleaner.com)
    C:\Windows\WiseRegNotify.sys
    2017-05-02 07:14 - 2017-05-02 07:14 - 00000000 ____D C:\Program Files (x86)\trend micro
    CMD: dir "C:\Windows\Inf" /AD
    CMD: dir "C:\PROGRA~1"
    CMD: dir "C:\PROGRA~2"
    CMD: dir "C:\PROGRA~3"
    CMD: dir "%localappdata%"
    CMD: dir "%appdata%"
    Hosts:
    EmptyTemp:
    End
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

ab021
Návštěvník
Návštěvník
Příspěvky: 323
Registrován: 11 lis 2007 15:54

Re: Prosím o kontrolu.

#5 Příspěvek od ab021 »

Posielam log:
Fix result of Farbar Recovery Scan Tool (x64) Version: 01-05-2017
Ran by ab021 (02-05-2017 13:38:31) Run:1
Running from C:\Users\ab021\Desktop
Loaded Profiles: ab021 (Available Profiles: ab021)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\...\Run: [] => [X]
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {7e5361fa-0a73-11e7-9ebb-00241da22745} - H:\Lenovo_Suite.exe
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {d2dd7725-d0eb-11e6-a229-00241da22745} - H:\HiSuiteDownLoader.exe
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\...\MountPoints2: {d2dd7735-d0eb-11e6-a229-00241da22745} - H:\HiSuiteDownLoader.exe
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
S3 WiseBootAssistant; D:\WiseCare365\WiseCare365 Portable\BootTime.exe [X]
D:\WiseCare365
S4 nvlddmkm; system32\DRIVERS\nvlddmkm.sys [X]
S3 WiseHDInfo; C:\Windows\WiseHDInfo64.dll [14800 2017-03-25] (wisecleaner.com)
C:\Windows\WiseHDInfo64.dll
S3 WiseRegNotify; C:\Windows\WiseRegNotify.sys [28080 2017-03-03] (WiseCleaner.com)
C:\Windows\WiseRegNotify.sys
2017-05-02 07:14 - 2017-05-02 07:14 - 00000000 ____D C:\Program Files (x86)\trend micro
CMD: dir "C:\Windows\Inf" /AD
CMD: dir "C:\PROGRA~1"
CMD: dir "C:\PROGRA~2"
CMD: dir "C:\PROGRA~3"
CMD: dir "%localappdata%"
CMD: dir "%appdata%"
Hosts:
EmptyTemp:
End
*****************

Restore point was successfully created.
Processes closed successfully.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value removed successfully
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7e5361fa-0a73-11e7-9ebb-00241da22745} => key removed successfully
HKCR\CLSID\{7e5361fa-0a73-11e7-9ebb-00241da22745} => key not found.
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d2dd7725-d0eb-11e6-a229-00241da22745} => key removed successfully
HKCR\CLSID\{d2dd7725-d0eb-11e6-a229-00241da22745} => key not found.
HKU\S-1-5-21-4105794192-3944765755-37458331-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d2dd7735-d0eb-11e6-a229-00241da22745} => key removed successfully
HKCR\CLSID\{d2dd7735-d0eb-11e6-a229-00241da22745} => key not found.
HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE => key removed successfully
HKLM\System\CurrentControlSet\Services\WiseBootAssistant => key removed successfully
WiseBootAssistant => service removed successfully
"D:\WiseCare365" => not found.
HKLM\System\CurrentControlSet\Services\nvlddmkm => key removed successfully
nvlddmkm => service removed successfully
HKLM\System\CurrentControlSet\Services\WiseHDInfo => key removed successfully
WiseHDInfo => service removed successfully
C:\Windows\WiseHDInfo64.dll => moved successfully
HKLM\System\CurrentControlSet\Services\WiseRegNotify => key removed successfully
WiseRegNotify => service removed successfully
C:\Windows\WiseRegNotify.sys => moved successfully
C:\Program Files (x86)\trend micro => moved successfully

========= dir "C:\Windows\Inf" /AD =========

Volume in drive C is Syst‚m
Volume Serial Number is A098-FA5C

Directory of C:\Windows\Inf

02. 05. 2017 11:18 <DIR> .
02. 05. 2017 11:18 <DIR> ..
14. 07. 2009 09:44 <DIR> .NET CLR Data
14. 07. 2009 09:44 <DIR> .NET CLR Networking
26. 07. 2016 15:12 <DIR> .NET CLR Networking 4.0.0.0
14. 07. 2009 09:44 <DIR> .NET Data Provider for Oracle
14. 07. 2009 09:44 <DIR> .NET Data Provider for SqlServer
26. 07. 2016 15:11 <DIR> .NET Memory Cache 4.0
14. 07. 2009 09:44 <DIR> .NETFramework
11. 04. 2017 20:43 <DIR> ASP.NET
26. 07. 2016 15:12 <DIR> ASP.NET_4.0.30319
11. 04. 2017 20:43 <DIR> aspnet_state
14. 07. 2009 09:44 <DIR> BITS
14. 07. 2009 09:44 <DIR> en-US
14. 07. 2009 09:44 <DIR> ESENT
14. 07. 2009 09:44 <DIR> MSDTC
14. 07. 2009 09:44 <DIR> MSDTC Bridge 3.0.0.0
26. 07. 2016 15:12 <DIR> MSDTC Bridge 4.0.0.0
10. 10. 2016 21:12 <DIR> Outlook
14. 07. 2009 09:44 <DIR> PERFLIB
14. 07. 2009 07:37 <DIR> PNRPSvc
14. 07. 2009 09:44 <DIR> rdyboost
14. 07. 2009 07:37 <DIR> RemoteAccess
14. 07. 2009 09:44 <DIR> ServiceModelEndpoint 3.0.0.0
14. 07. 2009 09:44 <DIR> ServiceModelOperation 3.0.0.0
14. 07. 2009 09:44 <DIR> ServiceModelService 3.0.0.0
14. 07. 2009 09:44 <DIR> SMSvcHost 3.0.0.0
26. 07. 2016 15:12 <DIR> SMSvcHost 4.0.0.0
14. 07. 2009 09:44 <DIR> TAPISRV
14. 07. 2009 09:44 <DIR> TermService
14. 07. 2009 09:44 <DIR> UGatherer
14. 07. 2009 09:44 <DIR> UGTHRSVC
14. 07. 2009 07:37 <DIR> usbhub
14. 07. 2009 09:44 <DIR> Windows Workflow Foundation 3.0.0.0
26. 07. 2016 15:12 <DIR> Windows Workflow Foundation 4.0.0.0
02. 05. 2017 11:18 <DIR> WmiApRpl
14. 07. 2009 09:44 <DIR> wsearchidxpi
0 File(s) 0 bytes
37 Dir(s) 331˙067˙404˙288 bytes free

========= End of CMD: =========


========= dir "C:\PROGRA~1" =========

Volume in drive C is Syst‚m
Volume Serial Number is A098-FA5C

Directory of C:\PROGRA~1

16. 04. 2017 16:02 <DIR> .
16. 04. 2017 16:02 <DIR> ..
17. 01. 2017 13:08 <DIR> AMD
17. 01. 2017 12:40 <DIR> Common Files
14. 03. 2017 21:56 <DIR> DVD Maker
26. 07. 2016 18:30 <DIR> EPSON
26. 07. 2016 10:06 <DIR> ESET
11. 04. 2017 20:53 <DIR> Internet Explorer
26. 07. 2016 12:30 <DIR> Microsoft Games
26. 07. 2016 10:21 <DIR> Microsoft Office
14. 07. 2009 07:32 <DIR> MSBuild
17. 01. 2017 11:59 <DIR> NVIDIA Corporation
14. 07. 2009 07:32 <DIR> Reference Assemblies
26. 07. 2016 17:07 <DIR> Windows Defender
26. 07. 2016 22:19 <DIR> Windows Live
26. 07. 2016 10:55 <DIR> Windows Mail
11. 10. 2016 21:01 <DIR> Windows Media Player
14. 07. 2009 07:32 <DIR> Windows NT
26. 07. 2016 10:55 <DIR> Windows Photo Viewer
26. 07. 2016 10:55 <DIR> Windows Portable Devices
26. 07. 2016 10:55 <DIR> Windows Sidebar
0 File(s) 0 bytes
21 Dir(s) 331˙067˙400˙192 bytes free

========= End of CMD: =========


========= dir "C:\PROGRA~2" =========

Volume in drive C is Syst‚m
Volume Serial Number is A098-FA5C

Directory of C:\PROGRA~2

02. 05. 2017 13:38 <DIR> .
02. 05. 2017 13:38 <DIR> ..
16. 04. 2017 16:02 <DIR> Common Files
26. 07. 2016 18:31 <DIR> epson
10. 12. 2016 16:44 <DIR> FreeCodecPack
26. 07. 2016 12:38 <DIR> Google
11. 04. 2017 20:53 <DIR> Internet Explorer
08. 03. 2017 18:39 <DIR> Java
26. 07. 2016 15:07 <DIR> Microsoft Office
26. 07. 2016 10:23 <DIR> Microsoft Visual Studio
26. 07. 2016 10:21 <DIR> Microsoft Visual Studio 8
26. 07. 2016 10:26 <DIR> Microsoft Works
26. 07. 2016 15:10 <DIR> Microsoft.NET
22. 04. 2017 05:54 <DIR> Mozilla Firefox
22. 04. 2017 13:29 <DIR> Mozilla Maintenance Service
26. 07. 2016 10:23 <DIR> MSBuild
26. 07. 2016 18:13 <DIR> MSXML 4.0
14. 07. 2009 07:32 <DIR> Reference Assemblies
12. 04. 2017 20:45 <DIR> Skype
26. 07. 2016 09:53 <DIR> Trust Webcam 16175
26. 07. 2016 17:07 <DIR> Windows Defender
26. 07. 2016 22:20 <DIR> Windows Live
26. 07. 2016 10:55 <DIR> Windows Mail
11. 10. 2016 21:01 <DIR> Windows Media Player
14. 07. 2009 07:32 <DIR> Windows NT
26. 07. 2016 10:55 <DIR> Windows Photo Viewer
26. 07. 2016 10:55 <DIR> Windows Portable Devices
26. 07. 2016 10:55 <DIR> Windows Sidebar
29. 04. 2017 20:57 <DIR> YoWindow
0 File(s) 0 bytes
29 Dir(s) 331˙067˙400˙192 bytes free

========= End of CMD: =========


========= dir "C:\PROGRA~3" =========

Volume in drive C is Syst‚m
Volume Serial Number is A098-FA5C

Directory of C:\PROGRA~3

16. 04. 2017 20:51 <DIR> Adobe
26. 07. 2016 13:37 <DIR> Canneverbe Limited
26. 07. 2016 10:06 <DIR> ESET
26. 07. 2016 13:49 <DIR> InstallShield
20. 03. 2017 11:51 <DIR> LangSoft
11. 04. 2017 20:53 <DIR> Microsoft Help
08. 03. 2017 18:40 <DIR> Oracle
21. 02. 2017 09:47 <DIR> Package Cache
12. 04. 2017 20:45 <DIR> Skype
29. 04. 2017 20:58 <DIR> YoWindow
0 File(s) 0 bytes
10 Dir(s) 331˙067˙400˙192 bytes free

========= End of CMD: =========


========= dir "%localappdata%" =========

Volume in drive C is Syst‚m
Volume Serial Number is A098-FA5C

Directory of C:\Users\ab021\AppData\Local

01. 05. 2017 19:44 <DIR> .
01. 05. 2017 19:44 <DIR> ..
30. 04. 2017 06:22 <DIR> Adobe
06. 04. 2017 19:19 <DIR> CEF
26. 07. 2016 13:42 <DIR> CrossLoop
26. 07. 2016 10:11 <DIR> ESET
29. 04. 2017 20:09 113˙264 GDIPFONTCACHEV1.DAT
27. 07. 2016 04:26 <DIR> GHISLER
03. 11. 2016 17:08 <DIR> Google
27. 07. 2016 04:20 <DIR> GWX
19. 01. 2017 15:19 <DIR> Hisuite
26. 07. 2016 13:25 <DIR> Macromedia
06. 04. 2017 20:14 <DIR> Microsoft
23. 10. 2016 06:28 <DIR> Microsoft Games
26. 07. 2016 10:20 <DIR> Microsoft Help
22. 04. 2017 05:56 <DIR> Mozilla
26. 07. 2016 13:35 <DIR> Programs
15. 02. 2017 05:34 7˙605 resmon.resmoncfg
02. 05. 2017 13:38 <DIR> Temp
26. 07. 2016 09:18 <DIR> VirtualStore
30. 07. 2016 05:13 <DIR> Windows Live
26. 07. 2016 22:21 <DIR> Windows Live Writer
26. 07. 2016 09:42 <DIR> WindowsUpdate
2 File(s) 120˙869 bytes
21 Dir(s) 331˙067˙396˙096 bytes free

========= End of CMD: =========


========= dir "%appdata%" =========

Volume in drive C is Syst‚m
Volume Serial Number is A098-FA5C

Directory of C:\Users\ab021\AppData\Roaming

01. 05. 2017 21:31 <DIR> .
01. 05. 2017 21:31 <DIR> ..
16. 04. 2017 20:51 <DIR> Adobe
26. 07. 2016 13:37 <DIR> Canneverbe Limited
16. 04. 2017 20:48 <DIR> com.adobe.formscentral.FormsCentralForAcrobat
26. 07. 2016 13:50 <DIR> Corel
10. 12. 2016 17:07 <DIR> DVDVideoSoft
09. 09. 2016 21:12 <DIR> EPSON
26. 07. 2016 10:11 <DIR> ESET
10. 12. 2016 22:39 <DIR> EurekaLog
26. 07. 2016 21:59 93˙696 ezpinst.exe
01. 03. 2017 09:39 <DIR> GHISLER
12. 03. 2017 22:13 <DIR> HD Tune Pro
26. 07. 2016 09:18 <DIR> Identities
26. 07. 2016 09:53 <DIR> InstallShield
20. 03. 2017 11:53 <DIR> LangSoft
18. 10. 2016 15:26 <DIR> Logitech
26. 07. 2016 13:25 <DIR> Macromedia
14. 07. 2009 09:54 <DIR> Media Center Programs
22. 04. 2017 05:52 <DIR> Mozilla
02. 05. 2017 13:28 <DIR> MPC-HC
19. 09. 2016 22:52 <DIR> Pamela
26. 07. 2016 21:59 7˙176 pcouffin.cat
26. 07. 2016 21:59 1˙167 pcouffin.inf
26. 07. 2016 22:01 34 pcouffin.log
26. 07. 2016 21:59 82˙048 pcouffin.sys
26. 07. 2016 13:39 <DIR> Popisovac
30. 04. 2017 17:32 <DIR> Skype
16. 04. 2017 20:51 <DIR> SolidDocuments
26. 07. 2016 12:36 <DIR> Sun
20. 04. 2017 16:59 <DIR> vlc
26. 07. 2016 22:01 <DIR> Vso
18. 08. 2016 20:35 <DIR> Windows Live Writer
26. 07. 2016 09:51 <DIR> WinRAR
29. 04. 2017 21:02 <DIR> YoWindow
5 File(s) 184˙121 bytes
30 Dir(s) 331˙067˙396˙096 bytes free

========= End of CMD: =========

Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 11714629 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 5825662 B
Edge => 0 B
Chrome => 231880507 B
Firefox => 5325459 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 4164 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 65960 B
LocalService => 0 B
NetworkService => 0 B
ab021 => 7093723 B
UpdatusUser => 0 B
UpdatusUser => 0 B
UpdatusUser => 0 B
UpdatusUser => 0 B
UpdatusUser => 0 B
UpdatusUser => 0 B
UpdatusUser => 0 B

RecycleBin => 0 B
EmptyTemp: => 257.8 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 13:39:08 ====

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu.

#6 Příspěvek od altrok »

  • Stahnete Crystal Disk Info (CDI) https://osdn.jp/frs/redir.php?m=cznic&f ... o6_7_5.zip
  • archiv extrahujte a spustte vyextrahovany soubor DiskInfo.exe
  • ve spustenem programu kliknete nahore na Upravy -> Kopirovat (log mate nyni zkopirovany ve schrance)
  • log vlozte do dalsi odpovedi (Ctrl + V)



:arrow: Start -> vepiste cmd
  • na vysledek vyhledavani kliknete pravym a zvolte Spustit jako spravce
  • do spusteneho okna vepiste: sfc /scannow
  • a odentrujte
  • po jeho skonceni jeste do otevreneho prikazoveho radku vepiste (pripadne text zkopirujte do schranky pomoci Ctrl+C a vlozte pres pravy klik a vlozit)
    findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >> "%userprofile%\desktop\sfcdetails.txt"
  • a odentrujte
  • obsah logu sfcdetails.txt umisteneho na plose zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

ab021
Návštěvník
Návštěvník
Příspěvky: 323
Registrován: 11 lis 2007 15:54

Re: Prosím o kontrolu.

#7 Příspěvek od ab021 »

----------------------------------------------------------------------------
CrystalDiskInfo 6.2.2 (C) 2008-2014 hiyohiyo
Crystal Dew World : http://crystalmark.info/
----------------------------------------------------------------------------

OS : Windows 7 Professional SP1 [6.1 Build 7601] (x64)
Date : 2017/05/03 11:56:19

-- Controller Map ----------------------------------------------------------
+ NVIDIA nForce Serial ATA Controller [ATA]
- WDC WD10 EARS-00Y5B1 SCSI Disk Device
+ Standard Dual Channel PCI IDE Controller [ATA]
+ ATA Channel 0 (0)
- HL-DT-ST DVDRAM GSA-H10N ATA Device
- SONY DVD RW DW-Q28A ATA Device
- ATA Channel 1 (1)

-- Disk List ---------------------------------------------------------------
(1) WDC WD10EARS-00Y5B1 : 1000,2 GB [0/2/0, sm] - wd

----------------------------------------------------------------------------
(1) WDC WD10EARS-00Y5B1
----------------------------------------------------------------------------
Model : WDC WD10EARS-00Y5B1
Firmware : 80.00A80
Serial Number : WD-WCAV5J217395
Disk Size : 1000,2 GB (8,4/137,4/1000,2/1000,2)
Buffer Size : Neznámy údaj
Queue Depth : 32
# of Sectors : 1953523055
Rotation Rate : Neznámy údaj
Interface : Serial ATA
Major Version : ATA8-ACS
Minor Version : ----
Transfer Mode : ---- | SATA/300
Power On Hours : 36044 hod.
Power On Count : 4512 krát
Temperature : 26 C (78 F)
Health Status : Dobrý
Features : S.M.A.R.T., AAM, 48bit LBA, NCQ
APM Level : ----
AAM Level : 80FEh [ON]

-- S.M.A.R.T. --------------------------------------------------------------
ID Cur Wor Thr RawValues(6) Attribute Name
01 200 200 _51 000000000209 Počet chybných čítaní
03 128 125 _21 0000000019BF Čas na roztočenie platní
04 _96 _96 __0 0000000011B4 Počet spustení/zastavení
05 200 200 140 000000000000 Počet premapovaných sektorov
07 200 200 __0 000000000000 Počet chybných vyhľadávaní
09 _51 _51 __0 000000008CCC Počet odpracovaných hodín
0A 100 100 __0 000000000000 Počet opakovaných pokusov o roztočenie platní
0B 100 100 __0 000000000000 Počet pokusov o prekalibrovanie
0C _96 _96 __0 0000000011A0 Počet cyklov zapnutia zariadenia
C0 200 200 __0 0000000000A4 Počet vypnutí disku
C1 173 173 __0 000000014728 Počet cyklov načítania/vymazania
C2 121 103 __0 00000000001A Teplota
C4 200 200 __0 000000000000 Počet udalostí s cieľom realokovania sektorov
C5 200 200 __0 000000000000 Počet podozrivých sektorov
C6 200 200 __0 000000000000 Počet neopraviteľných sektorov
C7 200 200 __0 000000000000 Počet chýb v kontrolnom súčte UltraDMA
C8 200 200 __0 000000000000 Počet chýb pri zápise sektorov

-- IDENTIFY_DEVICE ---------------------------------------------------------
0 1 2 3 4 5 6 7 8 9
000: 427A 3FFF C837 0010 0000 0000 003F 0000 0000 0000
010: 2020 2020 2057 442D 5743 4156 354A 3231 3733 3935
020: 0000 0000 0032 3830 2E30 3041 3830 5744 4320 5744
030: 3130 4541 5253 2D30 3059 3542 3120 2020 2020 2020
040: 2020 2020 2020 2020 2020 2020 2020 8010 0000 2F00
050: 4001 0000 0000 0007 3FFF 0010 003F FC10 00FB 0110
060: FFFF 0FFF 0000 0007 0003 0078 0078 0078 0078 0000
070: 0000 0000 0000 0000 0000 001F 1706 0000 0044 0040
080: 01FE 0000 746B 7F61 4123 7468 BE41 4123 407F 0064
090: 0064 0000 FFFE 0000 80FE 0000 0000 0000 0000 0000
100: 656F 7470 0000 0000 0000 0000 0000 0000 5001 4EE2
110: AFC5 40D0 0000 0000 0000 0000 0000 0000 0000 4018
120: 4018 0000 0000 0000 0000 0000 0000 0000 0021 0000
130: 0000 0000 0000 16CE 0000 0000 0000 0000 0000 0000
140: 0000 0000 0004 0000 0000 0000 0000 0000 0000 0000
150: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
160: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
170: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
180: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
190: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
200: 0000 0000 0000 0000 0000 0000 3035 0000 0000 0000
210: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
220: 0000 0000 101E 0000 0000 0000 0000 0000 0000 0000
230: 0000 0000 0000 0000 0001 1000 0000 0000 0000 0000
240: 0000 0000 0000 0000 0000 0000 0000 0000 0000 0000
250: 0000 0000 0000 0000 0000 BDA5

-- SMART_READ_DATA ---------------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 2F 00 C8 C8 09 02 00 00 00 00 00 03 27
010: 00 80 7D BF 19 00 00 00 00 00 04 32 00 60 60 B4
020: 11 00 00 00 00 00 05 33 00 C8 C8 00 00 00 00 00
030: 00 00 07 2E 00 C8 C8 00 00 00 00 00 00 00 09 32
040: 00 33 33 CC 8C 00 00 00 00 00 0A 32 00 64 64 00
050: 00 00 00 00 00 00 0B 32 00 64 64 00 00 00 00 00
060: 00 00 0C 32 00 60 60 A0 11 00 00 00 00 00 C0 32
070: 00 C8 C8 A4 00 00 00 00 00 00 C1 32 00 AD AD 28
080: 47 01 00 00 00 00 C2 22 00 79 67 1A 00 00 00 00
090: 00 00 C4 32 00 C8 C8 00 00 00 00 00 00 00 C5 32
0A0: 00 C8 C8 00 00 00 00 00 00 00 C6 30 00 C8 C8 00
0B0: 00 00 00 00 00 00 C7 32 00 C8 C8 00 00 00 00 00
0C0: 00 00 C8 08 00 C8 C8 00 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 84 00 58 4D 01 7B
170: 03 00 01 00 02 E4 05 00 00 00 00 00 00 00 00 00
180: 00 00 01 04 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 57

-- SMART_READ_THRESHOLD ----------------------------------------------------
+0 +1 +2 +3 +4 +5 +6 +7 +8 +9 +A +B +C +D +E +F
000: 10 00 01 33 C8 C8 C8 C8 00 00 00 00 00 00 03 15
010: 00 00 00 00 00 00 00 00 00 00 04 00 00 00 00 00
020: 00 00 00 00 00 00 05 8C 00 00 00 00 00 00 00 00
030: 00 00 07 00 C8 C8 C8 C8 00 00 00 00 00 00 09 00
040: 00 00 00 00 00 00 00 00 00 00 0A 00 00 00 00 00
050: 00 00 00 00 00 00 0B 00 00 00 00 00 00 00 00 00
060: 00 00 0C 00 00 00 00 00 00 00 00 00 00 00 C0 00
070: 00 00 00 00 00 00 00 00 00 00 C1 00 00 00 00 00
080: 00 00 00 00 00 00 C2 00 00 00 00 00 00 00 00 00
090: 00 00 C4 00 00 00 00 00 00 00 00 00 00 00 C5 00
0A0: 00 00 00 00 00 00 00 00 00 00 C6 00 00 00 00 00
0B0: 00 00 00 00 00 00 C7 00 00 00 00 00 00 00 00 00
0C0: 00 00 C8 00 C8 C8 C8 C8 00 00 00 00 00 00 00 00
0D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
100: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
110: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
120: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
130: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
140: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
150: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
160: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
170: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
180: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
190: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1A0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1B0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1C0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1D0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1E0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
1F0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 5D

ab021
Návštěvník
Návštěvník
Příspěvky: 323
Registrován: 11 lis 2007 15:54

Re: Prosím o kontrolu.

#8 Příspěvek od ab021 »

2017-05-03 12:05:56, Info CSI 00000009 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:05:56, Info CSI 0000000a [SR] Beginning Verify and Repair transaction
2017-05-03 12:05:57, Info CSI 0000000c [SR] Verify complete
2017-05-03 12:05:58, Info CSI 0000000d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:05:58, Info CSI 0000000e [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:00, Info CSI 00000010 [SR] Verify complete
2017-05-03 12:06:01, Info CSI 00000011 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:01, Info CSI 00000012 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:02, Info CSI 00000014 [SR] Verify complete
2017-05-03 12:06:03, Info CSI 00000015 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:03, Info CSI 00000016 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:04, Info CSI 00000018 [SR] Verify complete
2017-05-03 12:06:05, Info CSI 00000019 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:05, Info CSI 0000001a [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:06, Info CSI 0000001c [SR] Verify complete
2017-05-03 12:06:07, Info CSI 0000001d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:07, Info CSI 0000001e [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:08, Info CSI 00000020 [SR] Verify complete
2017-05-03 12:06:09, Info CSI 00000021 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:09, Info CSI 00000022 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:10, Info CSI 00000024 [SR] Verify complete
2017-05-03 12:06:11, Info CSI 00000025 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:11, Info CSI 00000026 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:12, Info CSI 00000028 [SR] Verify complete
2017-05-03 12:06:13, Info CSI 00000029 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:13, Info CSI 0000002a [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:15, Info CSI 0000002c [SR] Verify complete
2017-05-03 12:06:15, Info CSI 0000002d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:15, Info CSI 0000002e [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:17, Info CSI 00000030 [SR] Verify complete
2017-05-03 12:06:17, Info CSI 00000031 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:17, Info CSI 00000032 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:19, Info CSI 00000034 [SR] Verify complete
2017-05-03 12:06:20, Info CSI 00000035 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:20, Info CSI 00000036 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:21, Info CSI 00000038 [SR] Verify complete
2017-05-03 12:06:22, Info CSI 00000039 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:22, Info CSI 0000003a [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:23, Info CSI 0000003c [SR] Verify complete
2017-05-03 12:06:23, Info CSI 0000003d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:23, Info CSI 0000003e [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:25, Info CSI 00000040 [SR] Verify complete
2017-05-03 12:06:25, Info CSI 00000041 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:25, Info CSI 00000042 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:29, Info CSI 00000044 [SR] Verify complete
2017-05-03 12:06:29, Info CSI 00000045 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:29, Info CSI 00000046 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:31, Info CSI 00000048 [SR] Verify complete
2017-05-03 12:06:31, Info CSI 00000049 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:31, Info CSI 0000004a [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:34, Info CSI 0000004c [SR] Verify complete
2017-05-03 12:06:34, Info CSI 0000004d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:34, Info CSI 0000004e [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:36, Info CSI 00000050 [SR] Verify complete
2017-05-03 12:06:36, Info CSI 00000051 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:36, Info CSI 00000052 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:38, Info CSI 00000054 [SR] Verify complete
2017-05-03 12:06:39, Info CSI 00000055 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:39, Info CSI 00000056 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:41, Info CSI 00000058 [SR] Verify complete
2017-05-03 12:06:42, Info CSI 00000059 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:42, Info CSI 0000005a [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:43, Info CSI 0000005c [SR] Verify complete
2017-05-03 12:06:43, Info CSI 0000005d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:43, Info CSI 0000005e [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:45, Info CSI 00000060 [SR] Verify complete
2017-05-03 12:06:45, Info CSI 00000061 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:45, Info CSI 00000062 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:48, Info CSI 00000064 [SR] Verify complete
2017-05-03 12:06:48, Info CSI 00000065 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:48, Info CSI 00000066 [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:52, Info CSI 00000068 [SR] Verify complete
2017-05-03 12:06:53, Info CSI 00000069 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:53, Info CSI 0000006a [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:54, Info CSI 0000006c [SR] Verify complete
2017-05-03 12:06:54, Info CSI 0000006d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:54, Info CSI 0000006e [SR] Beginning Verify and Repair transaction
2017-05-03 12:06:56, Info CSI 00000070 [SR] Verify complete
2017-05-03 12:06:57, Info CSI 00000071 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:06:57, Info CSI 00000072 [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:02, Info CSI 00000076 [SR] Verify complete
2017-05-03 12:07:02, Info CSI 00000077 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:02, Info CSI 00000078 [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:09, Info CSI 0000007d [SR] Verify complete
2017-05-03 12:07:09, Info CSI 0000007e [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:09, Info CSI 0000007f [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:13, Info CSI 00000081 [SR] Verify complete
2017-05-03 12:07:13, Info CSI 00000082 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:13, Info CSI 00000083 [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:17, Info CSI 00000086 [SR] Verify complete
2017-05-03 12:07:18, Info CSI 00000087 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:18, Info CSI 00000088 [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:23, Info CSI 0000008a [SR] Verify complete
2017-05-03 12:07:23, Info CSI 0000008b [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:23, Info CSI 0000008c [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:29, Info CSI 000000ae [SR] Verify complete
2017-05-03 12:07:30, Info CSI 000000af [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:30, Info CSI 000000b0 [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:34, Info CSI 000000b5 [SR] Verify complete
2017-05-03 12:07:35, Info CSI 000000b6 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:35, Info CSI 000000b7 [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:41, Info CSI 000000b9 [SR] Verify complete
2017-05-03 12:07:41, Info CSI 000000ba [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:41, Info CSI 000000bb [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:44, Info CSI 000000bd [SR] Verify complete
2017-05-03 12:07:45, Info CSI 000000be [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:45, Info CSI 000000bf [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:50, Info CSI 000000c1 [SR] Verify complete
2017-05-03 12:07:50, Info CSI 000000c2 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:50, Info CSI 000000c3 [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:54, Info CSI 000000c5 [SR] Verify complete
2017-05-03 12:07:54, Info CSI 000000c6 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:54, Info CSI 000000c7 [SR] Beginning Verify and Repair transaction
2017-05-03 12:07:59, Info CSI 000000c9 [SR] Verify complete
2017-05-03 12:07:59, Info CSI 000000ca [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:07:59, Info CSI 000000cb [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:07, Info CSI 000000ee [SR] Verify complete
2017-05-03 12:08:07, Info CSI 000000ef [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:07, Info CSI 000000f0 [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:15, Info CSI 000000f2 [SR] Verify complete
2017-05-03 12:08:15, Info CSI 000000f3 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:15, Info CSI 000000f4 [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:24, Info CSI 000000f6 [SR] Verify complete
2017-05-03 12:08:24, Info CSI 000000f7 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:24, Info CSI 000000f8 [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:35, Info CSI 000000fc [SR] Verify complete
2017-05-03 12:08:35, Info CSI 000000fd [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:35, Info CSI 000000fe [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:38, Info CSI 00000100 [SR] Verify complete
2017-05-03 12:08:38, Info CSI 00000101 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:38, Info CSI 00000102 [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:39, Info CSI 00000104 [SR] Verify complete
2017-05-03 12:08:40, Info CSI 00000105 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:40, Info CSI 00000106 [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:41, Info CSI 00000108 [SR] Verify complete
2017-05-03 12:08:41, Info CSI 00000109 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:41, Info CSI 0000010a [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:47, Info CSI 00000112 [SR] Verify complete
2017-05-03 12:08:47, Info CSI 00000113 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:47, Info CSI 00000114 [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:53, Info CSI 00000121 [SR] Verify complete
2017-05-03 12:08:53, Info CSI 00000122 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:53, Info CSI 00000123 [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:55, Info CSI 00000125 [SR] Verify complete
2017-05-03 12:08:55, Info CSI 00000126 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:55, Info CSI 00000127 [SR] Beginning Verify and Repair transaction
2017-05-03 12:08:59, Info CSI 00000129 [SR] Verify complete
2017-05-03 12:08:59, Info CSI 0000012a [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:08:59, Info CSI 0000012b [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:02, Info CSI 0000012d [SR] Verify complete
2017-05-03 12:09:02, Info CSI 0000012e [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:02, Info CSI 0000012f [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:07, Info CSI 00000132 [SR] Verify complete
2017-05-03 12:09:08, Info CSI 00000133 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:08, Info CSI 00000134 [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:17, Info CSI 00000137 [SR] Verify complete
2017-05-03 12:09:17, Info CSI 00000138 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:17, Info CSI 00000139 [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:20, Info CSI 0000013b [SR] Verify complete
2017-05-03 12:09:20, Info CSI 0000013c [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:20, Info CSI 0000013d [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:23, Info CSI 0000013f [SR] Verify complete
2017-05-03 12:09:23, Info CSI 00000140 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:23, Info CSI 00000141 [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:29, Info CSI 00000143 [SR] Verify complete
2017-05-03 12:09:29, Info CSI 00000144 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:29, Info CSI 00000145 [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:34, Info CSI 00000147 [SR] Verify complete
2017-05-03 12:09:34, Info CSI 00000148 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:34, Info CSI 00000149 [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:40, Info CSI 0000014b [SR] Verify complete
2017-05-03 12:09:40, Info CSI 0000014c [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:40, Info CSI 0000014d [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:52, Info CSI 00000162 [SR] Verify complete
2017-05-03 12:09:52, Info CSI 00000163 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:52, Info CSI 00000164 [SR] Beginning Verify and Repair transaction
2017-05-03 12:09:58, Info CSI 00000169 [SR] Verify complete
2017-05-03 12:09:59, Info CSI 0000016a [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:09:59, Info CSI 0000016b [SR] Beginning Verify and Repair transaction
2017-05-03 12:10:16, Info CSI 0000016d [SR] Verify complete
2017-05-03 12:10:16, Info CSI 0000016e [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:10:16, Info CSI 0000016f [SR] Beginning Verify and Repair transaction
2017-05-03 12:10:22, Info CSI 00000171 [SR] Verify complete
2017-05-03 12:10:23, Info CSI 00000172 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:10:23, Info CSI 00000173 [SR] Beginning Verify and Repair transaction
2017-05-03 12:10:35, Info CSI 00000176 [SR] Verify complete
2017-05-03 12:10:35, Info CSI 00000177 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:10:35, Info CSI 00000178 [SR] Beginning Verify and Repair transaction
2017-05-03 12:10:41, Info CSI 0000017a [SR] Verify complete
2017-05-03 12:10:42, Info CSI 0000017b [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:10:42, Info CSI 0000017c [SR] Beginning Verify and Repair transaction
2017-05-03 12:10:47, Info CSI 0000017e [SR] Verify complete
2017-05-03 12:10:47, Info CSI 0000017f [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:10:47, Info CSI 00000180 [SR] Beginning Verify and Repair transaction
2017-05-03 12:10:53, Info CSI 00000182 [SR] Verify complete
2017-05-03 12:10:53, Info CSI 00000183 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:10:53, Info CSI 00000184 [SR] Beginning Verify and Repair transaction
2017-05-03 12:10:57, Info CSI 00000188 [SR] Verify complete
2017-05-03 12:10:58, Info CSI 00000189 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:10:58, Info CSI 0000018a [SR] Beginning Verify and Repair transaction
2017-05-03 12:11:02, Info CSI 0000018c [SR] Verify complete
2017-05-03 12:11:02, Info CSI 0000018d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:11:02, Info CSI 0000018e [SR] Beginning Verify and Repair transaction
2017-05-03 12:11:11, Info CSI 00000190 [SR] Verify complete
2017-05-03 12:11:11, Info CSI 00000191 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:11:11, Info CSI 00000192 [SR] Beginning Verify and Repair transaction
2017-05-03 12:11:20, Info CSI 00000195 [SR] Verify complete
2017-05-03 12:11:20, Info CSI 00000196 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:11:20, Info CSI 00000197 [SR] Beginning Verify and Repair transaction
2017-05-03 12:11:27, Info CSI 00000199 [SR] Verify complete
2017-05-03 12:11:28, Info CSI 0000019a [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:11:28, Info CSI 0000019b [SR] Beginning Verify and Repair transaction
2017-05-03 12:11:34, Info CSI 0000019e [SR] Verify complete
2017-05-03 12:11:34, Info CSI 0000019f [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:11:34, Info CSI 000001a0 [SR] Beginning Verify and Repair transaction
2017-05-03 12:11:42, Info CSI 000001a3 [SR] Verify complete
2017-05-03 12:11:43, Info CSI 000001a4 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:11:43, Info CSI 000001a5 [SR] Beginning Verify and Repair transaction
2017-05-03 12:11:51, Info CSI 000001a7 [SR] Verify complete
2017-05-03 12:11:51, Info CSI 000001a8 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:11:51, Info CSI 000001a9 [SR] Beginning Verify and Repair transaction
2017-05-03 12:11:57, Info CSI 000001ab [SR] Verify complete
2017-05-03 12:11:57, Info CSI 000001ac [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:11:57, Info CSI 000001ad [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:03, Info CSI 000001af [SR] Verify complete
2017-05-03 12:12:03, Info CSI 000001b0 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:03, Info CSI 000001b1 [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:08, Info CSI 000001b4 [SR] Verify complete
2017-05-03 12:12:09, Info CSI 000001b5 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:09, Info CSI 000001b6 [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:15, Info CSI 000001b8 [SR] Verify complete
2017-05-03 12:12:15, Info CSI 000001b9 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:15, Info CSI 000001ba [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:18, Info CSI 000001bc [SR] Verify complete
2017-05-03 12:12:19, Info CSI 000001bd [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:19, Info CSI 000001be [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:24, Info CSI 000001c1 [SR] Verify complete
2017-05-03 12:12:24, Info CSI 000001c2 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:24, Info CSI 000001c3 [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:31, Info CSI 000001c5 [SR] Verify complete
2017-05-03 12:12:32, Info CSI 000001c6 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:32, Info CSI 000001c7 [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:36, Info CSI 000001cb [SR] Verify complete
2017-05-03 12:12:37, Info CSI 000001cc [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:37, Info CSI 000001cd [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:43, Info CSI 000001cf [SR] Verify complete
2017-05-03 12:12:44, Info CSI 000001d0 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:44, Info CSI 000001d1 [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:50, Info CSI 000001d4 [SR] Verify complete
2017-05-03 12:12:50, Info CSI 000001d5 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:50, Info CSI 000001d6 [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:57, Info CSI 000001d8 [SR] Verify complete
2017-05-03 12:12:57, Info CSI 000001d9 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:57, Info CSI 000001da [SR] Beginning Verify and Repair transaction
2017-05-03 12:12:58, Info CSI 000001dc [SR] Verify complete
2017-05-03 12:12:59, Info CSI 000001dd [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:12:59, Info CSI 000001de [SR] Beginning Verify and Repair transaction
2017-05-03 12:13:03, Info CSI 000001e0 [SR] Verify complete
2017-05-03 12:13:03, Info CSI 000001e1 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:13:03, Info CSI 000001e2 [SR] Beginning Verify and Repair transaction
2017-05-03 12:13:07, Info CSI 000001e4 [SR] Verify complete
2017-05-03 12:13:08, Info CSI 000001e5 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:13:08, Info CSI 000001e6 [SR] Beginning Verify and Repair transaction
2017-05-03 12:13:14, Info CSI 000001e8 [SR] Verify complete
2017-05-03 12:13:14, Info CSI 000001e9 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:13:14, Info CSI 000001ea [SR] Beginning Verify and Repair transaction
2017-05-03 12:13:20, Info CSI 000001ec [SR] Verify complete
2017-05-03 12:13:21, Info CSI 000001ed [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:13:21, Info CSI 000001ee [SR] Beginning Verify and Repair transaction
2017-05-03 12:13:23, Info CSI 000001f0 [SR] Verify complete
2017-05-03 12:13:24, Info CSI 000001f1 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:13:24, Info CSI 000001f2 [SR] Beginning Verify and Repair transaction
2017-05-03 12:13:31, Info CSI 000001f4 [SR] Verify complete
2017-05-03 12:13:31, Info CSI 000001f5 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:13:31, Info CSI 000001f6 [SR] Beginning Verify and Repair transaction
2017-05-03 12:13:56, Info CSI 000001f8 [SR] Verify complete
2017-05-03 12:13:56, Info CSI 000001f9 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:13:56, Info CSI 000001fa [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:03, Info CSI 000001fc [SR] Verify complete
2017-05-03 12:14:04, Info CSI 000001fd [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:04, Info CSI 000001fe [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:08, Info CSI 00000200 [SR] Verify complete
2017-05-03 12:14:09, Info CSI 00000201 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:09, Info CSI 00000202 [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:11, Info CSI 00000204 [SR] Verify complete
2017-05-03 12:14:11, Info CSI 00000205 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:11, Info CSI 00000206 [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:15, Info CSI 00000208 [SR] Verify complete
2017-05-03 12:14:15, Info CSI 00000209 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:15, Info CSI 0000020a [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:18, Info CSI 0000020c [SR] Verify complete
2017-05-03 12:14:19, Info CSI 0000020d [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:19, Info CSI 0000020e [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:22, Info CSI 00000210 [SR] Verify complete
2017-05-03 12:14:23, Info CSI 00000211 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:23, Info CSI 00000212 [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:24, Info CSI 00000214 [SR] Verify complete
2017-05-03 12:14:24, Info CSI 00000215 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:24, Info CSI 00000216 [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:26, Info CSI 00000218 [SR] Verify complete
2017-05-03 12:14:26, Info CSI 00000219 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:26, Info CSI 0000021a [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:33, Info CSI 00000222 [SR] Verify complete
2017-05-03 12:14:34, Info CSI 00000223 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:34, Info CSI 00000224 [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:37, Info CSI 00000226 [SR] Verify complete
2017-05-03 12:14:38, Info CSI 00000227 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:38, Info CSI 00000228 [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:41, Info CSI 0000022a [SR] Verify complete
2017-05-03 12:14:42, Info CSI 0000022b [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:42, Info CSI 0000022c [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:46, Info CSI 0000022e [SR] Verify complete
2017-05-03 12:14:46, Info CSI 0000022f [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:46, Info CSI 00000230 [SR] Beginning Verify and Repair transaction
2017-05-03 12:14:53, Info CSI 00000232 [SR] Verify complete
2017-05-03 12:14:53, Info CSI 00000233 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:14:53, Info CSI 00000234 [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:00, Info CSI 00000237 [SR] Verify complete
2017-05-03 12:15:00, Info CSI 00000238 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:00, Info CSI 00000239 [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:02, Info CSI 0000023b [SR] Verify complete
2017-05-03 12:15:02, Info CSI 0000023c [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:02, Info CSI 0000023d [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:04, Info CSI 0000023f [SR] Verify complete
2017-05-03 12:15:05, Info CSI 00000240 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:05, Info CSI 00000241 [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:16, Info CSI 00000246 [SR] Verify complete
2017-05-03 12:15:16, Info CSI 00000247 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:16, Info CSI 00000248 [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:26, Info CSI 0000024b [SR] Verify complete
2017-05-03 12:15:26, Info CSI 0000024c [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:26, Info CSI 0000024d [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:32, Info CSI 00000251 [SR] Verify complete
2017-05-03 12:15:32, Info CSI 00000252 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:32, Info CSI 00000253 [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:39, Info CSI 0000025d [SR] Verify complete
2017-05-03 12:15:39, Info CSI 0000025e [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:39, Info CSI 0000025f [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:47, Info CSI 00000269 [SR] Verify complete
2017-05-03 12:15:48, Info CSI 0000026a [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:48, Info CSI 0000026b [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:52, Info CSI 0000026d [SR] Verify complete
2017-05-03 12:15:53, Info CSI 0000026e [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:53, Info CSI 0000026f [SR] Beginning Verify and Repair transaction
2017-05-03 12:15:57, Info CSI 00000273 [SR] Verify complete
2017-05-03 12:15:57, Info CSI 00000274 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:15:57, Info CSI 00000275 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:02, Info CSI 00000277 [SR] Verify complete
2017-05-03 12:16:02, Info CSI 00000278 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:02, Info CSI 00000279 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:08, Info CSI 0000029e [SR] Verify complete
2017-05-03 12:16:08, Info CSI 0000029f [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:08, Info CSI 000002a0 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:13, Info CSI 000002a2 [SR] Verify complete
2017-05-03 12:16:13, Info CSI 000002a3 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:13, Info CSI 000002a4 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:17, Info CSI 000002a6 [SR] Verify complete
2017-05-03 12:16:17, Info CSI 000002a7 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:17, Info CSI 000002a8 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:23, Info CSI 000002aa [SR] Verify complete
2017-05-03 12:16:23, Info CSI 000002ab [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:23, Info CSI 000002ac [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:27, Info CSI 000002ba [SR] Verify complete
2017-05-03 12:16:27, Info CSI 000002bb [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:27, Info CSI 000002bc [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:32, Info CSI 000002be [SR] Verify complete
2017-05-03 12:16:32, Info CSI 000002bf [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:32, Info CSI 000002c0 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:40, Info CSI 000002c6 [SR] Verify complete
2017-05-03 12:16:40, Info CSI 000002c7 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:40, Info CSI 000002c8 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:46, Info CSI 000002d2 [SR] Verify complete
2017-05-03 12:16:46, Info CSI 000002d3 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:46, Info CSI 000002d4 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:49, Info CSI 000002d6 [SR] Verify complete
2017-05-03 12:16:49, Info CSI 000002d7 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:49, Info CSI 000002d8 [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:54, Info CSI 000002db [SR] Verify complete
2017-05-03 12:16:55, Info CSI 000002dc [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:55, Info CSI 000002dd [SR] Beginning Verify and Repair transaction
2017-05-03 12:16:58, Info CSI 000002df [SR] Verify complete
2017-05-03 12:16:58, Info CSI 000002e0 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:16:58, Info CSI 000002e1 [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:00, Info CSI 000002e3 [SR] Verify complete
2017-05-03 12:17:01, Info CSI 000002e4 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:01, Info CSI 000002e5 [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:06, Info CSI 000002e7 [SR] Verify complete
2017-05-03 12:17:07, Info CSI 000002e8 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:07, Info CSI 000002e9 [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:11, Info CSI 000002eb [SR] Verify complete
2017-05-03 12:17:12, Info CSI 000002ec [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:12, Info CSI 000002ed [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:20, Info CSI 00000305 [SR] Verify complete
2017-05-03 12:17:20, Info CSI 00000306 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:20, Info CSI 00000307 [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:25, Info CSI 0000030b [SR] Verify complete
2017-05-03 12:17:25, Info CSI 0000030c [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:25, Info CSI 0000030d [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:40, Info CSI 0000030f [SR] Verify complete
2017-05-03 12:17:40, Info CSI 00000310 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:40, Info CSI 00000311 [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:45, Info CSI 00000313 [SR] Verify complete
2017-05-03 12:17:45, Info CSI 00000314 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:45, Info CSI 00000315 [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:49, Info CSI 00000318 [SR] Verify complete
2017-05-03 12:17:49, Info CSI 00000319 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:49, Info CSI 0000031a [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:53, Info CSI 0000031d [SR] Verify complete
2017-05-03 12:17:53, Info CSI 0000031e [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:53, Info CSI 0000031f [SR] Beginning Verify and Repair transaction
2017-05-03 12:17:56, Info CSI 00000321 [SR] Verify complete
2017-05-03 12:17:57, Info CSI 00000322 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:17:57, Info CSI 00000323 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:02, Info CSI 00000325 [SR] Verify complete
2017-05-03 12:18:02, Info CSI 00000326 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:02, Info CSI 00000327 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:06, Info CSI 0000032a [SR] Verify complete
2017-05-03 12:18:06, Info CSI 0000032b [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:06, Info CSI 0000032c [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:11, Info CSI 0000032e [SR] Verify complete
2017-05-03 12:18:11, Info CSI 0000032f [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:11, Info CSI 00000330 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:15, Info CSI 00000332 [SR] Verify complete
2017-05-03 12:18:15, Info CSI 00000333 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:15, Info CSI 00000334 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:20, Info CSI 00000336 [SR] Verify complete
2017-05-03 12:18:20, Info CSI 00000337 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:20, Info CSI 00000338 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:25, Info CSI 0000033b [SR] Verify complete
2017-05-03 12:18:25, Info CSI 0000033c [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:25, Info CSI 0000033d [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:28, Info CSI 0000033f [SR] Verify complete
2017-05-03 12:18:29, Info CSI 00000340 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:29, Info CSI 00000341 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:36, Info CSI 00000343 [SR] Verify complete
2017-05-03 12:18:36, Info CSI 00000344 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:36, Info CSI 00000345 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:41, Info CSI 00000347 [SR] Verify complete
2017-05-03 12:18:41, Info CSI 00000348 [SR] Verifying 100 (0x0000000000000064) components
2017-05-03 12:18:41, Info CSI 00000349 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:47, Info CSI 0000034b [SR] Verify complete
2017-05-03 12:18:48, Info CSI 0000034c [SR] Verifying 39 (0x0000000000000027) components
2017-05-03 12:18:48, Info CSI 0000034d [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:49, Info CSI 0000034f [SR] Verify complete
2017-05-03 12:18:49, Info CSI 00000350 [SR] Repairing 0 components
2017-05-03 12:18:49, Info CSI 00000351 [SR] Beginning Verify and Repair transaction
2017-05-03 12:18:49, Info CSI 00000353 [SR] Repair complete

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu.

#9 Příspěvek od altrok »

:arrow: Ulozte na plochu ComboFix.exe - http://download.bleepingcomputer.com/sUBs/ComboFix.exe
  • Vypnete antiviry a vsechny real-time ochrany
  • spustte ComboFix jako spravce (lepe pod uctem s administratorskym opravnenim)
  • s licencnimi podminkami souhlaste - Ano
  • pokud je nabidnuta instalace konzoly pro zotaveni, souhlaste
  • v prubehu skenovani nechte PC v klidu - nic nespoustejte a do okna ComboFixu neklikejte
  • vysledek skenu naleznete v C:\ComboFix.txt, jehoz obsah mi zkopirujte do pristi odpovedi.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

ab021
Návštěvník
Návštěvník
Příspěvky: 323
Registrován: 11 lis 2007 15:54

Re: Prosím o kontrolu.

#10 Příspěvek od ab021 »

ComboFix 17-04-16.01 - ab021 . 05. 2017 13:00:56.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1051.18.4096.2802 [GMT 2:00]
Running from: E:\ComboFix.exe
AV: ESET Smart Security 6.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Resident AV is active



((((((((((((((((((((((((( Files Created from 2017-04-03 to 2017-05-03 )))))))))))))))))))))))))))))))

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu.

#11 Příspěvek od altrok »

altrok píše: :arrow: Pouzivate ESET Smart Security 6.0 - dnes je k dispozici verze 10. Velice doporucuji upgrade na tuto aktualni verzi. Dale trvale vypnete Windows Defender - http://windows.microsoft.com/cs-cz/wind ... =windows-7
Ani jedno jste neprovedl, s cimz jsem nepocital, protoze jste ani nedal vedet a navic jste nedodrzel postup k bezproblemovemu chodu ComboFixu...
altrok píše:Vypnete antiviry a vsechny real-time ochrany
ab021 píše:AV: ESET Smart Security 6.0 *Enabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Enabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Enabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Resident AV is active
Proc je problem ESET aktualizovat? Proc je problem pred pouzitim ComboFixu vypnout rezidentni stit ESETu?
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

ab021
Návštěvník
Návštěvník
Příspěvky: 323
Registrován: 11 lis 2007 15:54

Re: Prosím o kontrolu.

#12 Příspěvek od ab021 »

Pri spustení ComboFixu mi sám vypol ESET, preto som neriešil manuálne vypnutie. Aktualizovať ESS na ver.10 nechcem, pretože mi potom nejde spustiť jeden externý disk. Pri ver.ESS 6 mi tento spustí. Riešil som to už aj s Esetom.

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu.

#13 Příspěvek od altrok »

Vyborne, komunikace je treba. Rucne vypnete rezidentni stity ESETu a pote znovu spustte ComboFix.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

ab021
Návštěvník
Návštěvník
Příspěvky: 323
Registrován: 11 lis 2007 15:54

Re: Prosím o kontrolu.

#14 Příspěvek od ab021 »

Vypol som ESET a v adr. C:\Combofix som našiel txt súbor:
ComboFix 17-05-04.01 - ab021 . 05. 2017 17:49:11.1.2 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1250.421.1051.18.4096.2746 [GMT 2:00]
Running from: C:\Users\ab021\Desktop\ComboFix.exe
AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET personal firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

V C:\ sa vytvoril adresár Combofix a Qoobox

altrok
Moderátor
Moderátor
Příspěvky: 7322
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Prosím o kontrolu.

#15 Příspěvek od altrok »

:arrow: Nainstalujte MBAM a udelejte vlastni sken vsech disku - http://forum.viry.cz/viewtopic.php?f=29&t=144868
  • Upozorneni: tento sken zabere od 30 minut po nekolik hodin
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Odpovědět