Stránka 2 z 2

Re: Problem s virem

Napsal: 14 srp 2015 14:40
od vyosek
Jak se chova PC??

Re: Problem s virem

Napsal: 14 srp 2015 19:20
od Anovertis1
v prohlížeči se mi objevují stále 4 reklamy Razor Web ads, přestal se mi zatím zasekávat zvuk ten se mi vypínal i když v nastavení bylo všechno v pořádku, tet jak mi to běží nezdá se, že by se nějak zpomaloval, ale od toho fixnutí jsem ještě nerestartoval jinak pomalu mi načítal vidle a co jsem přišel z práce a zapnul jsem to tak jsem tam měl kritickou chybu nefungovala mi celá spodní lišta jak je tam ten start až napotřetí se mi chytla mam docela strach to tet restartovat i když potom restartu jak jsem sem házel ten log se mi to nestalo

Re: Problem s virem

Napsal: 15 srp 2015 08:30
od Anovertis1
Tak tet ráno jsem už bez reklam a vypadá to v pořádku. Díky moc, kdyby něco tak dam vědět.

Re: Problem s virem

Napsal: 16 srp 2015 18:56
od Anovertis1
Tak to vypadá, že tam mam ještě nějakej ten Adware, pokud mam počítač puštěnej delší dobu tak se reklamy přestanou objěvovat a počítač je rychlejší. Jinak včera sem měl problemy spustit vůbec windowsy házelo mi to krytickou chybu ohledně hdd ale ten mam ani ne 3 měsíce úplně novej nechci to dávat do továrního nastavení kvůli widlím mam 7 upgreadovanou na 10 a nerad bych o to přišel

Re: Problem s virem

Napsal: 16 srp 2015 18:59
od Anovertis1
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:16-08-2015
Ran by MSI (administrator) on MSI-PC (16-08-2015 19:53:32)
Running from C:\Users\MSI\Downloads
Loaded Profiles: MSI & UpdatusUser (Available Profiles: MSI & UpdatusUser)
Platform: Windows 10 Home (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
() C:\Windows\System32\FspService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera_crashreporter.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
(Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe
(Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe
(Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe
(Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [6319440 2015-05-29] (Sentelic Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6109776 2015-07-21] (AVAST Software)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [863960 2015-03-24] (BlueStack Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-07-10] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [167312 2015-06-29] (NVIDIA Corporation)
AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [167312 2015-06-29] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [147760 2015-06-29] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-21] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {09787082-D5ED-4D45-9066-7FE92B23D1FE} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {258E1DB8-93F3-46A2-B029-39F5F53BB3B4} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {539429F8-7109-4AFA-BF72-E39156B5EA68} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {559AACB1-3CAA-4FFD-887C-8D467168726C} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {6C89DD5C-EE6C-4C1F-A370-F1DA2F3FCD6F} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {8ED899FB-7B09-441C-A590-61B07F78746A} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {D411984E-F086-4A10-8908-0FB6BFEC264A} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {F0357247-F176-42E7-AA71-6A69D11F57E3} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {FCBE0762-14F6-4FAC-95ED-205DC67D3F45} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-21] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-21] (AVAST Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9ee0b185-0bb8-4a9c-82eb-df7b8d5f503d}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\MSI\AppData\Roaming\Mozilla\Firefox\Profiles\6ch307pd.default
FF DefaultSearchEngine: Yahoo Search!
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2010-12-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2010-12-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: Razor Web - C:\Users\MSI\AppData\Roaming\Mozilla\Firefox\Profiles\6ch307pd.default\Extensions\{7c3288cb-3846-4d30-8f57-c5450fe01c2d}.xpi [2015-06-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-24]

Chrome:
=======
CHR Profile: C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-28]
CHR Extension: (Google Docs) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-28]
CHR Extension: (Google Drive) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-28]
CHR Extension: (Seznam Lištička - Email) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-05-07]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2015-05-07]
CHR Extension: (YouTube) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-28]
CHR Extension: (Google Search) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-28]
CHR Extension: (Avast SafePrice) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-04-02]
CHR Extension: (Google Sheets) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-28]
CHR Extension: (Avast Online Security) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-28]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-05-07]
CHR Extension: (Gmail) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-07-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-21]

Opera:
=======
OPR Extension: (Razor Web) - C:\Users\MSI\AppData\Roaming\Opera Software\Opera Stable\Extensions\ccnmmcllpopemhcbgccmbnlleblllojc [2015-07-11]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-07-21] (AVAST Software)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433880 2015-03-24] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2015-03-24] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [798424 2015-03-24] (BlueStack Systems, Inc.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [326144 2015-07-10] (Microsoft Corporation)
S3 CDPSvc; C:\Windows\System32\CDPSvc.dll [134144 2015-07-10] (Microsoft Corporation)
R2 CoreMessagingRegistrar; C:\Windows\system32\coremessaging.dll [808856 2015-08-07] (Microsoft Corporation)
R2 CoreMessagingRegistrar; C:\Windows\SysWOW64\coremessaging.dll [510976 2015-08-07] (Microsoft Corporation)
S3 diagnosticshub.standardcollector.service; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [27136 2015-07-10] (Microsoft Corporation)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
S3 DmEnrollmentSvc; C:\Windows\system32\Windows.Internal.Management.dll [267776 2015-07-10] (Microsoft Corporation)
S3 DmEnrollmentSvc; C:\Windows\SysWOW64\Windows.Internal.Management.dll [193024 2015-07-10] (Microsoft Corporation)
S3 embeddedmode; C:\Windows\System32\embeddedmodesvc.dll [87040 2015-07-10] (Microsoft Corporation)
S3 EntAppSvc; C:\Windows\system32\EnterpriseAppMgmtSvc.dll [275456 2015-07-10] (Microsoft Corporation)
R2 FspSvc; C:\Windows\System32\FspService.exe [2178896 2015-05-29] ()
S3 icssvc; C:\Windows\System32\tetheringservice.dll [148992 2015-08-07] (Microsoft Corporation)
R3 lfsvc; C:\Windows\SysWOW64\lfsvc.dll [22528 2015-07-10] (Microsoft Corporation)
R3 LicenseManager; C:\Windows\system32\LicenseManagerSvc.dll [21504 2015-07-10] (Microsoft Corporation)
R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [File not signed]
S2 MapsBroker; C:\Windows\System32\moshost.dll [62464 2015-07-10] (Microsoft Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-07] (Microsoft Corporation)
S2 OneSyncSvc; C:\Windows\System32\APHostService.dll [296960 2015-07-10] (Microsoft Corporation)
R2 OneSyncSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R2 OneSyncSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 PimIndexMaintenanceSvc; C:\Windows\System32\PimIndexMaintenance.dll [289280 2015-07-10] (Microsoft Corporation)
S3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
S3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 RetailDemo; C:\Windows\system32\RDXService.dll [988672 2015-08-03] (Microsoft Corporation)
S3 SensorDataService; C:\Windows\System32\SensorDataService.exe [1031680 2015-08-07] (Microsoft Corporation)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026944 2015-08-15] (Enigma Software Group USA, LLC.)
R3 StateRepository; C:\Windows\system32\windows.staterepository.dll [2674176 2015-07-10] (Microsoft Corporation)
R3 StateRepository; C:\Windows\SysWOW64\windows.staterepository.dll [2049024 2015-07-10] (Microsoft Corporation)
S3 UnistoreSvc; C:\Windows\System32\unistore.dll [1203200 2015-08-07] (Microsoft Corporation)
S3 UnistoreSvc; C:\Windows\SysWOW64\unistore.dll [925696 2015-08-07] (Microsoft Corporation)
S3 UnistoreSvc_Session1; C:\WINDOWS\System32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
S3 UnistoreSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed]
S3 UserDataSvc; C:\Windows\System32\userdataservice.dll [1420288 2015-07-30] (Microsoft Corporation)
S3 UserDataSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
S3 UserDataSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 vmicvmsession; C:\Windows\System32\ICSvc.dll [506880 2015-07-10] (Microsoft Corporation)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-07] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-07] (Microsoft Corporation)
S3 WalletService; C:\Windows\system32\WalletService.dll [504320 2015-07-10] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S3 XblAuthManager; C:\Windows\System32\XblAuthManager.dll [918016 2015-07-10] (Microsoft Corporation)
S3 XblGameSave; C:\Windows\System32\XblGameSave.dll [1149440 2015-07-10] (Microsoft Corporation)
S3 XboxNetApiSvc; C:\Windows\system32\XboxNetApiSvc.dll [1019392 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-07-21] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-07-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-07-21] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048856 2015-07-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-07-21] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150160 2015-07-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-07-21] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athwbx.sys [3837440 2013-08-14] (Qualcomm Atheros Communications, Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [144600 2015-03-24] (BlueStack Systems)
R3 CompositeBus; C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys [39936 2015-07-10] (Microsoft Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-06-25] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3436896 2015-07-10] (QLogic Corporation)
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-08-15] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-08-15] ()
R1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [83968 2015-07-10] (Microsoft Corporation)
R3 fspad_win764; C:\Windows\system32\DRIVERS\fspad_win764.sys [209232 2015-05-29] (Sentelic Corporation)
S3 genericusbfn; C:\Windows\System32\drivers\genericusbfn.sys [20992 2015-07-10] (Microsoft Corporation)
R1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8192 2015-07-10] (Microsoft Corporation)
S3 ibbus; C:\Windows\System32\drivers\ibbus.sys [424800 2015-07-10] (Mellanox)
S3 IoQos; C:\Windows\System32\drivers\ioqos.sys [26624 2015-07-10] (Microsoft Corporation)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2015-06-28] ()
S0 LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [99168 2015-07-10] (Avago Technologies)
S3 mlx4_bus; C:\Windows\System32\drivers\mlx4_bus.sys [705376 2015-07-10] (Mellanox)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-07] (Microsoft Corporation)
S3 ndfltr; C:\Windows\System32\drivers\ndfltr.sys [76128 2015-07-10] (Mellanox)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
R2 storqosflt; C:\Windows\System32\drivers\storqosflt.sys [61952 2015-07-10] (Microsoft Corporation)
R3 swenum; C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys [17760 2015-07-10] (Microsoft Corporation)
S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [61952 2015-07-10] (Microsoft Corporation)
S3 UcmUcsi; C:\Windows\System32\drivers\UcmUcsi.sys [46080 2015-08-07] (Microsoft Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R0 WindowsTrustedRT; C:\Windows\System32\drivers\WindowsTrustedRT.sys [106520 2015-07-10] (Microsoft Corporation)
R0 WindowsTrustedRTProxy; C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [17944 2015-07-10] (Microsoft Corporation)
S3 WinMad; C:\Windows\System32\drivers\winmad.sys [26976 2015-07-10] (Mellanox)
S3 WinVerbs; C:\Windows\System32\drivers\winverbs.sys [59232 2015-07-10] (Mellanox)
S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [222720 2015-07-10] (Microsoft Corporation)
S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [25600 2015-07-10] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

NETSVC: XblGameSave -> C:\Windows\System32\XblGameSave.dll (Microsoft Corporation)
NETSVC: XboxNetApiSvc -> C:\Windows\system32\XboxNetApiSvc.dll (Microsoft Corporation)
NETSVC: UserManager -> C:\Windows\System32\usermgr.dll (Microsoft Corporation)
NETSVC: XblAuthManager -> C:\Windows\System32\XblAuthManager.dll (Microsoft Corporation)
NETSVCx32: UserManager -> C:\Windows\SysWOW64\usermgr.dll ==> No File

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-16 19:53 - 2015-08-16 19:54 - 00022596 _____ C:\Users\MSI\Downloads\FRST.txt
2015-08-16 07:13 - 2015-08-16 07:13 - 00016148 _____ C:\WINDOWS\system32\MSI-PC_MSI_HistoryPrediction.bin
2015-08-15 23:03 - 2015-08-16 00:13 - 00000000 ___HD C:\$SysReset
2015-08-15 22:41 - 2015-08-15 22:48 - 51076312 _____ (Microsoft Corporation) C:\Users\MSI\Downloads\Windows-KB890830-x64-V5.27.exe
2015-08-15 22:30 - 2015-08-15 22:30 - 00000000 _____ C:\autoexec.bat
2015-08-15 22:29 - 2015-08-15 22:29 - 00003398 _____ C:\WINDOWS\System32\Tasks\SpyHunter4Startup
2015-08-15 22:29 - 2015-08-15 22:29 - 00001132 _____ C:\Users\MSI\Desktop\SpyHunter.lnk
2015-08-15 22:29 - 2015-08-15 22:29 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Enigma Software Group
2015-08-15 22:29 - 2015-08-15 22:29 - 00000000 ____D C:\sh4ldr
2015-08-15 22:27 - 2015-08-15 22:27 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-08-15 22:27 - 2015-08-15 22:27 - 00000000 ____D C:\Program Files\Enigma Software Group
2015-08-15 22:26 - 2015-08-15 22:26 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\MSI\Downloads\SpyHunter-Installer.exe
2015-08-15 22:13 - 2015-07-21 00:37 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB629.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB63A.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00150160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB63B.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB4CD.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB50E.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB619.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB4FD.tmp
2015-08-15 22:13 - 2015-07-21 00:36 - 01048856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB48E.tmp
2015-08-15 22:12 - 2015-07-21 00:37 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-08-15 21:35 - 2015-08-15 21:35 - 00000039 _____ C:\WINDOWS\setupact.log
2015-08-15 21:35 - 2015-08-15 21:35 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-08-15 18:25 - 2015-08-16 18:43 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-15 18:05 - 2015-08-15 18:05 - 00002147 _____ C:\AdwCleaner[C2].txt
2015-08-15 18:03 - 2015-08-15 18:05 - 00001945 _____ C:\AdwCleaner[S3].txt
2015-08-15 18:03 - 2015-08-15 18:03 - 00000000 ____D C:\AdwCleaner
2015-08-15 13:14 - 2015-08-15 13:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-08-14 15:14 - 2015-08-16 19:53 - 00000000 ____D C:\Users\MSI\Downloads\FRST-OlderVersion
2015-08-13 02:48 - 2015-08-13 02:48 - 00831344 _____ (Internet Web soft ) C:\Users\MSI\Downloads\adobe_flash_player (1).exe
2015-08-12 21:07 - 2015-08-16 19:53 - 00000000 ____D C:\FRST
2015-08-12 02:27 - 2015-08-08 09:30 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 02:27 - 2015-08-08 08:24 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 02:27 - 2015-08-08 08:24 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 02:27 - 2015-08-08 08:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 02:27 - 2015-08-06 04:36 - 21874176 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-08-12 02:27 - 2015-08-06 04:03 - 18805248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-08-12 02:27 - 2015-08-05 06:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-08-12 02:27 - 2015-08-05 06:03 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-12 02:27 - 2015-08-05 05:47 - 03588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-08-12 02:27 - 2015-08-05 05:43 - 01916416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-08-12 02:27 - 2015-08-04 06:08 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-08-12 02:27 - 2015-08-04 06:06 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-08-12 02:27 - 2015-08-04 05:50 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-08-12 02:27 - 2015-08-04 05:21 - 16709120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-12 02:27 - 2015-08-04 05:10 - 13025792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-08-12 02:27 - 2015-08-04 04:59 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-08-12 02:27 - 2015-08-04 04:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-08-12 02:27 - 2015-08-03 04:18 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 02:27 - 2015-08-03 04:18 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-08-12 02:27 - 2015-08-03 04:13 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-12 02:27 - 2015-08-03 03:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 02:27 - 2015-08-03 03:50 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-08-12 02:27 - 2015-08-03 03:24 - 24592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-12 02:27 - 2015-08-03 03:22 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-08-12 02:27 - 2015-08-03 03:22 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-08-12 02:27 - 2015-08-03 03:18 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 02:27 - 2015-08-03 03:18 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-08-12 02:27 - 2015-08-03 03:15 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-12 02:27 - 2015-08-03 03:15 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-08-12 02:27 - 2015-08-03 03:12 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-12 02:27 - 2015-08-03 03:12 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-08-12 02:27 - 2015-08-03 03:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-08-12 02:27 - 2015-08-03 03:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-08-12 02:27 - 2015-08-03 03:01 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 02:26 - 2015-08-08 09:29 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 02:26 - 2015-08-08 09:19 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-08-12 02:26 - 2015-08-08 09:01 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 02:26 - 2015-08-08 08:48 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-08-12 02:26 - 2015-08-08 08:40 - 00365056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 02:26 - 2015-08-08 08:22 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-12 02:26 - 2015-08-08 08:21 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-08-12 02:26 - 2015-08-08 08:15 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 02:26 - 2015-08-06 05:18 - 00290768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-08-12 02:26 - 2015-08-06 05:17 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-08-12 02:26 - 2015-08-06 05:17 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-08-12 02:26 - 2015-08-06 04:22 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-08-12 02:26 - 2015-08-05 06:49 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-08-12 02:26 - 2015-08-05 06:00 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-08-12 02:26 - 2015-08-05 05:54 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-08-12 02:26 - 2015-08-05 05:47 - 01383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-08-12 02:26 - 2015-08-05 05:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-08-12 02:26 - 2015-08-04 06:07 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 02:26 - 2015-08-04 06:06 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-08-12 02:26 - 2015-08-04 05:23 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-08-12 02:26 - 2015-08-03 04:32 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-08-12 02:26 - 2015-08-03 04:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-08-12 02:26 - 2015-08-03 04:19 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-08-12 02:26 - 2015-08-03 04:19 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-08-12 02:26 - 2015-08-03 04:18 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 02:26 - 2015-08-03 04:18 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-08-12 02:26 - 2015-08-03 04:17 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-08-12 02:26 - 2015-08-03 04:17 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-08-12 02:26 - 2015-08-03 04:12 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-08-12 02:26 - 2015-08-03 03:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-08-12 02:26 - 2015-08-03 03:31 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-08-12 02:26 - 2015-08-03 03:30 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-08-12 02:26 - 2015-08-03 03:24 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-08-12 02:26 - 2015-08-03 03:24 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-08-12 02:26 - 2015-08-03 03:24 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-08-12 02:26 - 2015-08-03 03:23 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-08-12 02:26 - 2015-08-03 03:23 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-08-12 02:26 - 2015-08-03 03:22 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-08-12 02:26 - 2015-08-03 03:22 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-08-12 02:26 - 2015-08-03 03:21 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-08-12 02:26 - 2015-08-03 03:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 02:26 - 2015-08-03 03:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 02:26 - 2015-08-03 03:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-08-12 02:26 - 2015-08-03 03:18 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 00988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-08-12 02:26 - 2015-08-03 03:14 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 02:26 - 2015-08-03 03:14 - 00247808 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-08-12 02:26 - 2015-08-03 03:12 - 01890304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-12 02:26 - 2015-08-03 03:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-08-12 02:26 - 2015-08-03 03:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-08-12 02:26 - 2015-08-03 03:11 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-12 02:26 - 2015-08-03 03:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-08-12 02:26 - 2015-08-03 03:11 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-08-12 02:26 - 2015-08-03 03:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 02:26 - 2015-08-03 03:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-08-12 02:26 - 2015-08-03 03:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 02:26 - 2015-08-03 03:00 - 01593856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-08-12 02:26 - 2015-08-03 02:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-08-12 01:31 - 2015-08-12 01:31 - 00011327 _____ C:\Users\MSI\Downloads\hijackthis.log
2015-08-12 01:29 - 2015-08-12 01:30 - 00401720 _____ (Trend Micro Inc.) C:\Users\MSI\Downloads\HijackThis.exe
2015-08-12 01:21 - 2015-08-16 19:53 - 02173440 _____ (Farbar) C:\Users\MSI\Downloads\FRST64.exe
2015-08-12 01:21 - 2015-08-12 01:21 - 00831344 _____ (Internet Web soft ) C:\Users\MSI\Downloads\adobe_flash_player.exe
2015-08-12 01:05 - 2015-08-16 19:46 - 00004186 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{84446A00-08E0-45FA-AC08-3383BD19BB60}
2015-08-12 00:24 - 2015-08-12 00:24 - 00000000 ____D C:\Program Files (x86)\100e225e-5822-4502-a1f7-a89bfc77e287
2015-08-12 00:23 - 2015-08-12 00:23 - 00000004 _____ C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-11 23:41 - 2015-08-11 23:42 - 00000000 ____D C:\Users\MSI\Desktop\aaa
2015-08-11 23:05 - 2015-08-11 23:05 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Macromedia
2015-08-11 23:01 - 2015-08-11 23:01 - 00000000 ____D C:\Users\MSI\AppData\Local\MicrosoftEdge
2015-08-11 22:59 - 2015-08-11 22:59 - 00000000 ____D C:\Program Files (x86)\DLLSuite
2015-08-11 22:52 - 2015-08-11 22:52 - 00000000 ____D C:\Program Files\DLLSuite
2015-08-11 22:41 - 2015-08-11 22:41 - 00002101 _____ C:\Users\MSI\Desktop\KnightShift.lnk
2015-08-11 22:41 - 2015-08-11 22:41 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Reality Pump
2015-08-11 22:29 - 2015-08-11 22:29 - 00000000 ____D C:\Program Files (x86)\Reality Pump
2015-08-11 21:50 - 2015-08-11 22:02 - 00000000 ____D C:\Users\MSI\Downloads\KnightShift
2015-08-11 21:09 - 2015-08-11 21:09 - 00014007 _____ C:\Users\MSI\Downloads\[CzT]KnightShift_2003_CZ_.torrent
2015-08-11 21:07 - 2015-08-15 22:04 - 00000000 ____D C:\Users\MSI\Downloads\Rise of Nations - Rise of Legends
2015-08-11 20:55 - 2015-08-11 20:55 - 00012822 _____ C:\Users\MSI\Downloads\[CzT]Rise_of_Nations_Rise_of_Legends.torrent
2015-08-08 15:49 - 2015-08-08 15:49 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-08-07 13:33 - 2015-07-30 08:24 - 01561872 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-08-07 13:33 - 2015-07-30 08:23 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-08-07 13:33 - 2015-07-30 08:21 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-08-07 13:33 - 2015-07-30 08:17 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-08-07 13:33 - 2015-07-30 08:17 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-08-07 13:33 - 2015-07-30 08:16 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-08-07 13:33 - 2015-07-30 08:14 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-08-07 13:33 - 2015-07-30 08:09 - 01562968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-08-07 13:33 - 2015-07-30 08:06 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-07 13:33 - 2015-07-30 08:05 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-07 13:33 - 2015-07-30 08:05 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-08-07 13:33 - 2015-07-30 08:04 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-07 13:33 - 2015-07-30 08:03 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-08-07 13:33 - 2015-07-30 06:29 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-08-07 13:33 - 2015-07-30 06:26 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2015-08-07 13:33 - 2015-07-30 06:26 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-08-07 13:33 - 2015-07-30 06:25 - 01356368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-08-07 13:33 - 2015-07-30 06:25 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2015-08-07 13:33 - 2015-07-30 06:24 - 01769056 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-08-07 13:33 - 2015-07-30 06:21 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-08-07 13:33 - 2015-07-30 06:12 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-08-07 13:33 - 2015-07-30 06:12 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-08-07 13:33 - 2015-07-30 05:52 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-07 13:33 - 2015-07-30 05:52 - 00521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-08-07 13:33 - 2015-07-30 05:49 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-08-07 13:33 - 2015-07-30 05:49 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-08-07 13:33 - 2015-07-30 05:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-08-07 13:33 - 2015-07-30 05:46 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-08-07 13:33 - 2015-07-30 05:44 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-08-07 13:33 - 2015-07-30 05:44 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-08-07 13:33 - 2015-07-30 05:42 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-08-07 13:33 - 2015-07-30 05:41 - 00407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-08-07 13:33 - 2015-07-30 05:40 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-08-07 13:33 - 2015-07-30 05:38 - 01420288 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-08-07 13:33 - 2015-07-30 05:29 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-08-07 13:33 - 2015-07-30 05:15 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-08-07 13:33 - 2015-07-30 05:10 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-08-07 13:33 - 2015-07-30 05:06 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-08-07 13:33 - 2015-07-30 05:04 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-08-07 13:33 - 2015-07-30 05:04 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-08-07 13:32 - 2015-07-30 08:15 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-08-07 13:32 - 2015-07-30 07:24 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-08-07 13:32 - 2015-07-30 06:42 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-07 13:32 - 2015-07-30 06:24 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-08-07 13:32 - 2015-07-30 06:24 - 00407616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-08-07 13:32 - 2015-07-30 06:24 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2015-08-07 13:32 - 2015-07-30 06:22 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2015-08-07 13:32 - 2015-07-30 06:22 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2015-08-07 13:32 - 2015-07-30 06:09 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-08-07 13:32 - 2015-07-30 06:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-08-07 13:32 - 2015-07-30 06:08 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-07 13:32 - 2015-07-30 06:08 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2015-08-07 13:32 - 2015-07-30 05:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-08-07 13:32 - 2015-07-30 05:52 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2015-08-07 13:32 - 2015-07-30 05:49 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-07 13:32 - 2015-07-30 05:46 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-08-07 13:32 - 2015-07-30 05:46 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-08-07 13:32 - 2015-07-30 05:45 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2015-08-07 13:32 - 2015-07-30 05:45 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2015-08-07 13:32 - 2015-07-30 05:44 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-08-07 13:32 - 2015-07-30 05:44 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-08-07 13:32 - 2015-07-30 05:44 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-08-07 13:32 - 2015-07-30 05:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll
2015-08-07 13:32 - 2015-07-30 05:41 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2015-08-07 13:32 - 2015-07-30 05:38 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-08-07 13:32 - 2015-07-30 05:34 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-08-07 13:32 - 2015-07-30 05:10 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-07 13:32 - 2015-07-30 05:07 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2015-08-07 13:32 - 2015-07-30 05:06 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-08-07 13:32 - 2015-07-30 05:06 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2015-08-07 13:32 - 2015-07-30 05:06 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll
2015-08-07 13:32 - 2015-07-30 04:59 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-08-07 13:32 - 2015-07-30 04:58 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-08-07 11:23 - 2015-08-07 11:24 - 00002388 _____ C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-07 11:23 - 2015-08-07 11:24 - 00000000 ___RD C:\Users\MSI\OneDrive
2015-08-07 11:21 - 2015-08-07 11:21 - 00000000 ____D C:\Users\MSI\AppData\Local\NetworkTiles
2015-08-07 11:21 - 2015-08-07 11:21 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-08-07 11:19 - 2015-07-09 20:39 - 04847104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2015-08-07 11:19 - 2015-07-09 20:36 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-08-07 11:19 - 2015-07-09 20:28 - 06358016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2015-08-07 11:19 - 2015-07-09 20:25 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2015-08-07 11:19 - 2015-07-09 20:25 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-08-07 11:18 - 2015-08-07 11:18 - 00001047 _____ C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Volitelné funkce.lnk
2015-08-07 11:17 - 2015-08-07 11:17 - 00000000 ____D C:\Users\MSI\AppData\Local\Publishers
2015-08-07 11:15 - 2015-08-08 14:06 - 00000000 ____D C:\Users\MSI\AppData\Local\Packages
2015-08-07 11:15 - 2015-08-07 11:15 - 00000020 ___SH C:\Users\MSI\ntuser.ini
2015-08-07 11:15 - 2015-08-07 11:15 - 00000000 ____D C:\Users\MSI\AppData\Local\TileDataLayer
2015-08-07 07:58 - 2015-08-16 00:08 - 00000000 ___DC C:\WINDOWS\Panther
2015-08-07 07:54 - 2015-08-07 07:54 - 00000000 ____D C:\Windows.old

Re: Problem s virem

Napsal: 16 srp 2015 18:59
od Anovertis1
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:16-08-2015
Ran by MSI (administrator) on MSI-PC (16-08-2015 19:53:32)
Running from C:\Users\MSI\Downloads
Loaded Profiles: MSI & UpdatusUser (Available Profiles: MSI & UpdatusUser)
Platform: Windows 10 Home (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
() C:\Windows\System32\FspService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera_crashreporter.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-Agent.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Opera Software) C:\Program Files (x86)\Opera\31.0.1889.99\opera.exe
(Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
(Microsoft Corporation) C:\Windows\System32\LocationNotificationWindows.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe
(Enigma Software Group USA, LLC.) C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter4.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\ngentask.exe
(Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe
(Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe
(Microsoft Corporation) C:\Windows\System32\backgroundTaskHost.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [6319440 2015-05-29] (Sentelic Corporation)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6109776 2015-07-21] (AVAST Software)
HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [863960 2015-03-24] (BlueStack Systems, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-07-10] (Microsoft Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [167312 2015-06-29] (NVIDIA Corporation)
AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [167312 2015-06-29] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [147760 2015-06-29] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-07-21] (AVAST Software)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {09787082-D5ED-4D45-9066-7FE92B23D1FE} URL = hxxp://search.seznam.cz/?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {258E1DB8-93F3-46A2-B029-39F5F53BB3B4} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=cz_en&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {539429F8-7109-4AFA-BF72-E39156B5EA68} URL = hxxp://encyklopedie.seznam.cz/search?q={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {559AACB1-3CAA-4FFD-887C-8D467168726C} URL = hxxp://www.zbozi.cz/?q={searchTerms}&r=campmoz ... arch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {6C89DD5C-EE6C-4C1F-A370-F1DA2F3FCD6F} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {8ED899FB-7B09-441C-A590-61B07F78746A} URL = hxxp://www.mapy.cz/?query={searchTerms}&source ... arch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {D411984E-F086-4A10-8908-0FB6BFEC264A} URL = hxxp://slovnik.seznam.cz/?q={searchTerms}&lang=en_cz&sourceid=QuickSearch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {F0357247-F176-42E7-AA71-6A69D11F57E3} URL = hxxp://www.firmy.cz/?q={searchTerms}&sourceid= ... arch_16194
SearchScopes: HKU\S-1-5-21-3121232644-64818644-3227324357-1000 -> {FCBE0762-14F6-4FAC-95ED-205DC67D3F45} URL = hxxp://www.novinky.cz/hledej?w={searchTerms}&s ... arch_16194
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-07-21] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-07-21] (AVAST Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9ee0b185-0bb8-4a9c-82eb-df7b8d5f503d}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\MSI\AppData\Roaming\Mozilla\Firefox\Profiles\6ch307pd.default
FF DefaultSearchEngine: Yahoo Search!
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2010-12-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2010-12-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-15] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-02-05] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
FF Extension: Razor Web - C:\Users\MSI\AppData\Roaming\Mozilla\Firefox\Profiles\6ch307pd.default\Extensions\{7c3288cb-3846-4d30-8f57-c5450fe01c2d}.xpi [2015-06-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-03-24]

Chrome:
=======
CHR Profile: C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-28]
CHR Extension: (Google Docs) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-28]
CHR Extension: (Google Drive) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-28]
CHR Extension: (Seznam Lištička - Email) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2015-05-07]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2015-05-07]
CHR Extension: (YouTube) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-28]
CHR Extension: (Google Search) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-28]
CHR Extension: (Avast SafePrice) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2015-04-02]
CHR Extension: (Google Sheets) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-28]
CHR Extension: (Avast Online Security) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-03-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-28]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2015-05-07]
CHR Extension: (Gmail) - C:\Users\MSI\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-07-21]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-07-21]

Opera:
=======
OPR Extension: (Razor Web) - C:\Users\MSI\AppData\Roaming\Opera Software\Opera Stable\Extensions\ccnmmcllpopemhcbgccmbnlleblllojc [2015-07-11]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-07-21] (AVAST Software)
S2 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433880 2015-03-24] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [388824 2015-03-24] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [798424 2015-03-24] (BlueStack Systems, Inc.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [326144 2015-07-10] (Microsoft Corporation)
S3 CDPSvc; C:\Windows\System32\CDPSvc.dll [134144 2015-07-10] (Microsoft Corporation)
R2 CoreMessagingRegistrar; C:\Windows\system32\coremessaging.dll [808856 2015-08-07] (Microsoft Corporation)
R2 CoreMessagingRegistrar; C:\Windows\SysWOW64\coremessaging.dll [510976 2015-08-07] (Microsoft Corporation)
S3 diagnosticshub.standardcollector.service; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [27136 2015-07-10] (Microsoft Corporation)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1268568 2015-06-18] (Disc Soft Ltd)
S3 DmEnrollmentSvc; C:\Windows\system32\Windows.Internal.Management.dll [267776 2015-07-10] (Microsoft Corporation)
S3 DmEnrollmentSvc; C:\Windows\SysWOW64\Windows.Internal.Management.dll [193024 2015-07-10] (Microsoft Corporation)
S3 embeddedmode; C:\Windows\System32\embeddedmodesvc.dll [87040 2015-07-10] (Microsoft Corporation)
S3 EntAppSvc; C:\Windows\system32\EnterpriseAppMgmtSvc.dll [275456 2015-07-10] (Microsoft Corporation)
R2 FspSvc; C:\Windows\System32\FspService.exe [2178896 2015-05-29] ()
S3 icssvc; C:\Windows\System32\tetheringservice.dll [148992 2015-08-07] (Microsoft Corporation)
R3 lfsvc; C:\Windows\SysWOW64\lfsvc.dll [22528 2015-07-10] (Microsoft Corporation)
R3 LicenseManager; C:\Windows\system32\LicenseManagerSvc.dll [21504 2015-07-10] (Microsoft Corporation)
R2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [262144 2009-09-30] (Intel Corporation) [File not signed]
S2 MapsBroker; C:\Windows\System32\moshost.dll [62464 2015-07-10] (Microsoft Corporation)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-07] (Microsoft Corporation)
S2 OneSyncSvc; C:\Windows\System32\APHostService.dll [296960 2015-07-10] (Microsoft Corporation)
R2 OneSyncSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R2 OneSyncSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 PimIndexMaintenanceSvc; C:\Windows\System32\PimIndexMaintenance.dll [289280 2015-07-10] (Microsoft Corporation)
S3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
S3 PimIndexMaintenanceSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 RetailDemo; C:\Windows\system32\RDXService.dll [988672 2015-08-03] (Microsoft Corporation)
S3 SensorDataService; C:\Windows\System32\SensorDataService.exe [1031680 2015-08-07] (Microsoft Corporation)
R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026944 2015-08-15] (Enigma Software Group USA, LLC.)
R3 StateRepository; C:\Windows\system32\windows.staterepository.dll [2674176 2015-07-10] (Microsoft Corporation)
R3 StateRepository; C:\Windows\SysWOW64\windows.staterepository.dll [2049024 2015-07-10] (Microsoft Corporation)
S3 UnistoreSvc; C:\Windows\System32\unistore.dll [1203200 2015-08-07] (Microsoft Corporation)
S3 UnistoreSvc; C:\Windows\SysWOW64\unistore.dll [925696 2015-08-07] (Microsoft Corporation)
S3 UnistoreSvc_Session1; C:\WINDOWS\System32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
S3 UnistoreSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
R2 UNS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2314240 2009-09-30] (Intel Corporation) [File not signed]
S3 UserDataSvc; C:\Windows\System32\userdataservice.dll [1420288 2015-07-30] (Microsoft Corporation)
S3 UserDataSvc_Session1; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
S3 UserDataSvc_Session1; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 vmicvmsession; C:\Windows\System32\ICSvc.dll [506880 2015-07-10] (Microsoft Corporation)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-07] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-07] (Microsoft Corporation)
S3 WalletService; C:\Windows\system32\WalletService.dll [504320 2015-07-10] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S3 XblAuthManager; C:\Windows\System32\XblAuthManager.dll [918016 2015-07-10] (Microsoft Corporation)
S3 XblGameSave; C:\Windows\System32\XblGameSave.dll [1149440 2015-07-10] (Microsoft Corporation)
S3 XboxNetApiSvc; C:\Windows\system32\XboxNetApiSvc.dll [1019392 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-07-21] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-07-21] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-07-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-07-21] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1048856 2015-07-21] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [447944 2015-07-21] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [150160 2015-07-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-07-21] (AVAST Software)
R3 athr; C:\Windows\System32\drivers\athwbx.sys [3837440 2013-08-14] (Qualcomm Atheros Communications, Inc.)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [144600 2015-03-24] (BlueStack Systems)
R3 CompositeBus; C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys [39936 2015-07-10] (Microsoft Corporation)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-06-25] (Disc Soft Ltd)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3436896 2015-07-10] (QLogic Corporation)
R3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2015-08-15] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\Windows\System32\DRIVERS\EsgScanner.sys [22704 2015-08-15] ()
R1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [83968 2015-07-10] (Microsoft Corporation)
R3 fspad_win764; C:\Windows\system32\DRIVERS\fspad_win764.sys [209232 2015-05-29] (Sentelic Corporation)
S3 genericusbfn; C:\Windows\System32\drivers\genericusbfn.sys [20992 2015-07-10] (Microsoft Corporation)
R1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8192 2015-07-10] (Microsoft Corporation)
S3 ibbus; C:\Windows\System32\drivers\ibbus.sys [424800 2015-07-10] (Mellanox)
S3 IoQos; C:\Windows\System32\drivers\ioqos.sys [26624 2015-07-10] (Microsoft Corporation)
R2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [42696 2015-06-28] ()
S0 LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [99168 2015-07-10] (Avago Technologies)
S3 mlx4_bus; C:\Windows\System32\drivers\mlx4_bus.sys [705376 2015-07-10] (Mellanox)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-07] (Microsoft Corporation)
S3 ndfltr; C:\Windows\System32\drivers\ndfltr.sys [76128 2015-07-10] (Mellanox)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
R2 storqosflt; C:\Windows\System32\drivers\storqosflt.sys [61952 2015-07-10] (Microsoft Corporation)
R3 swenum; C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys [17760 2015-07-10] (Microsoft Corporation)
S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [61952 2015-07-10] (Microsoft Corporation)
S3 UcmUcsi; C:\Windows\System32\drivers\UcmUcsi.sys [46080 2015-08-07] (Microsoft Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R0 WindowsTrustedRT; C:\Windows\System32\drivers\WindowsTrustedRT.sys [106520 2015-07-10] (Microsoft Corporation)
R0 WindowsTrustedRTProxy; C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [17944 2015-07-10] (Microsoft Corporation)
S3 WinMad; C:\Windows\System32\drivers\winmad.sys [26976 2015-07-10] (Mellanox)
S3 WinVerbs; C:\Windows\System32\drivers\winverbs.sys [59232 2015-07-10] (Mellanox)
S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [222720 2015-07-10] (Microsoft Corporation)
S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [25600 2015-07-10] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

NETSVC: XblGameSave -> C:\Windows\System32\XblGameSave.dll (Microsoft Corporation)
NETSVC: XboxNetApiSvc -> C:\Windows\system32\XboxNetApiSvc.dll (Microsoft Corporation)
NETSVC: UserManager -> C:\Windows\System32\usermgr.dll (Microsoft Corporation)
NETSVC: XblAuthManager -> C:\Windows\System32\XblAuthManager.dll (Microsoft Corporation)
NETSVCx32: UserManager -> C:\Windows\SysWOW64\usermgr.dll ==> No File

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-16 19:53 - 2015-08-16 19:54 - 00022596 _____ C:\Users\MSI\Downloads\FRST.txt
2015-08-16 07:13 - 2015-08-16 07:13 - 00016148 _____ C:\WINDOWS\system32\MSI-PC_MSI_HistoryPrediction.bin
2015-08-15 23:03 - 2015-08-16 00:13 - 00000000 ___HD C:\$SysReset
2015-08-15 22:41 - 2015-08-15 22:48 - 51076312 _____ (Microsoft Corporation) C:\Users\MSI\Downloads\Windows-KB890830-x64-V5.27.exe
2015-08-15 22:30 - 2015-08-15 22:30 - 00000000 _____ C:\autoexec.bat
2015-08-15 22:29 - 2015-08-15 22:29 - 00003398 _____ C:\WINDOWS\System32\Tasks\SpyHunter4Startup
2015-08-15 22:29 - 2015-08-15 22:29 - 00001132 _____ C:\Users\MSI\Desktop\SpyHunter.lnk
2015-08-15 22:29 - 2015-08-15 22:29 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Enigma Software Group
2015-08-15 22:29 - 2015-08-15 22:29 - 00000000 ____D C:\sh4ldr
2015-08-15 22:27 - 2015-08-15 22:27 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
2015-08-15 22:27 - 2015-08-15 22:27 - 00000000 ____D C:\Program Files\Enigma Software Group
2015-08-15 22:26 - 2015-08-15 22:26 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\MSI\Downloads\SpyHunter-Installer.exe
2015-08-15 22:13 - 2015-07-21 00:37 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB629.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB63A.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00150160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB63B.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB4CD.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB50E.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB619.tmp
2015-08-15 22:13 - 2015-07-21 00:37 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB4FD.tmp
2015-08-15 22:13 - 2015-07-21 00:36 - 01048856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB48E.tmp
2015-08-15 22:12 - 2015-07-21 00:37 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-08-15 21:35 - 2015-08-15 21:35 - 00000039 _____ C:\WINDOWS\setupact.log
2015-08-15 21:35 - 2015-08-15 21:35 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-08-15 18:25 - 2015-08-16 18:43 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-08-15 18:05 - 2015-08-15 18:05 - 00002147 _____ C:\AdwCleaner[C2].txt
2015-08-15 18:03 - 2015-08-15 18:05 - 00001945 _____ C:\AdwCleaner[S3].txt
2015-08-15 18:03 - 2015-08-15 18:03 - 00000000 ____D C:\AdwCleaner
2015-08-15 13:14 - 2015-08-15 13:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Games
2015-08-14 15:14 - 2015-08-16 19:53 - 00000000 ____D C:\Users\MSI\Downloads\FRST-OlderVersion
2015-08-13 02:48 - 2015-08-13 02:48 - 00831344 _____ (Internet Web soft ) C:\Users\MSI\Downloads\adobe_flash_player (1).exe
2015-08-12 21:07 - 2015-08-16 19:53 - 00000000 ____D C:\FRST
2015-08-12 02:27 - 2015-08-08 09:30 - 08020320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-08-12 02:27 - 2015-08-08 08:24 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-08-12 02:27 - 2015-08-08 08:24 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-08-12 02:27 - 2015-08-08 08:00 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-08-12 02:27 - 2015-08-06 04:36 - 21874176 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-08-12 02:27 - 2015-08-06 04:03 - 18805248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-08-12 02:27 - 2015-08-05 06:29 - 00644128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-08-12 02:27 - 2015-08-05 06:03 - 02416640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-08-12 02:27 - 2015-08-05 05:47 - 03588096 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-08-12 02:27 - 2015-08-05 05:43 - 01916416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-08-12 02:27 - 2015-08-04 06:08 - 02462648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-08-12 02:27 - 2015-08-04 06:06 - 00583128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-08-12 02:27 - 2015-08-04 05:50 - 02151208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-08-12 02:27 - 2015-08-04 05:21 - 16709120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-08-12 02:27 - 2015-08-04 05:10 - 13025792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-08-12 02:27 - 2015-08-04 04:59 - 01212416 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-08-12 02:27 - 2015-08-04 04:47 - 00898560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-08-12 02:27 - 2015-08-03 04:18 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-08-12 02:27 - 2015-08-03 04:18 - 01983840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-08-12 02:27 - 2015-08-03 04:13 - 22322624 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-08-12 02:27 - 2015-08-03 03:56 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-12 02:27 - 2015-08-03 03:50 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-08-12 02:27 - 2015-08-03 03:24 - 24592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-08-12 02:27 - 2015-08-03 03:22 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-08-12 02:27 - 2015-08-03 03:22 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-08-12 02:27 - 2015-08-03 03:18 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-08-12 02:27 - 2015-08-03 03:18 - 03780096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-08-12 02:27 - 2015-08-03 03:15 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-08-12 02:27 - 2015-08-03 03:15 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-08-12 02:27 - 2015-08-03 03:12 - 19323392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-08-12 02:27 - 2015-08-03 03:12 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-08-12 02:27 - 2015-08-03 03:10 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-08-12 02:27 - 2015-08-03 03:03 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-08-12 02:27 - 2015-08-03 03:01 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-08-12 02:26 - 2015-08-08 09:29 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-08-12 02:26 - 2015-08-08 09:19 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-08-12 02:26 - 2015-08-08 09:01 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-08-12 02:26 - 2015-08-08 08:48 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-08-12 02:26 - 2015-08-08 08:40 - 00365056 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-08-12 02:26 - 2015-08-08 08:22 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-08-12 02:26 - 2015-08-08 08:21 - 00642048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-08-12 02:26 - 2015-08-08 08:15 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-08-12 02:26 - 2015-08-06 05:18 - 00290768 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-08-12 02:26 - 2015-08-06 05:17 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-08-12 02:26 - 2015-08-06 05:17 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-08-12 02:26 - 2015-08-06 04:22 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-08-12 02:26 - 2015-08-05 06:49 - 00783112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-08-12 02:26 - 2015-08-05 06:00 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-08-12 02:26 - 2015-08-05 05:54 - 01274880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-08-12 02:26 - 2015-08-05 05:47 - 01383424 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-08-12 02:26 - 2015-08-05 05:39 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-08-12 02:26 - 2015-08-04 06:07 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-08-12 02:26 - 2015-08-04 06:06 - 00243248 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-08-12 02:26 - 2015-08-04 05:23 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-08-12 02:26 - 2015-08-03 04:32 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-08-12 02:26 - 2015-08-03 04:28 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-08-12 02:26 - 2015-08-03 04:19 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-08-12 02:26 - 2015-08-03 04:19 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-08-12 02:26 - 2015-08-03 04:18 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-08-12 02:26 - 2015-08-03 04:18 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-08-12 02:26 - 2015-08-03 04:17 - 00516960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-08-12 02:26 - 2015-08-03 04:17 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-08-12 02:26 - 2015-08-03 04:12 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-08-12 02:26 - 2015-08-03 03:49 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-08-12 02:26 - 2015-08-03 03:31 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-08-12 02:26 - 2015-08-03 03:30 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-08-12 02:26 - 2015-08-03 03:24 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-08-12 02:26 - 2015-08-03 03:24 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-08-12 02:26 - 2015-08-03 03:24 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-08-12 02:26 - 2015-08-03 03:23 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-08-12 02:26 - 2015-08-03 03:23 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-08-12 02:26 - 2015-08-03 03:22 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-08-12 02:26 - 2015-08-03 03:22 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-08-12 02:26 - 2015-08-03 03:21 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-08-12 02:26 - 2015-08-03 03:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-08-12 02:26 - 2015-08-03 03:19 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-08-12 02:26 - 2015-08-03 03:18 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-08-12 02:26 - 2015-08-03 03:18 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 01290752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 00988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 00384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-08-12 02:26 - 2015-08-03 03:15 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-08-12 02:26 - 2015-08-03 03:14 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-12 02:26 - 2015-08-03 03:14 - 00247808 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-08-12 02:26 - 2015-08-03 03:12 - 01890304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-08-12 02:26 - 2015-08-03 03:12 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-08-12 02:26 - 2015-08-03 03:12 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-08-12 02:26 - 2015-08-03 03:11 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-08-12 02:26 - 2015-08-03 03:11 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-08-12 02:26 - 2015-08-03 03:11 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-08-12 02:26 - 2015-08-03 03:06 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-08-12 02:26 - 2015-08-03 03:02 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-08-12 02:26 - 2015-08-03 03:02 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-12 02:26 - 2015-08-03 03:00 - 01593856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-08-12 02:26 - 2015-08-03 02:59 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-08-12 01:31 - 2015-08-12 01:31 - 00011327 _____ C:\Users\MSI\Downloads\hijackthis.log
2015-08-12 01:29 - 2015-08-12 01:30 - 00401720 _____ (Trend Micro Inc.) C:\Users\MSI\Downloads\HijackThis.exe
2015-08-12 01:21 - 2015-08-16 19:53 - 02173440 _____ (Farbar) C:\Users\MSI\Downloads\FRST64.exe
2015-08-12 01:21 - 2015-08-12 01:21 - 00831344 _____ (Internet Web soft ) C:\Users\MSI\Downloads\adobe_flash_player.exe
2015-08-12 01:05 - 2015-08-16 19:46 - 00004186 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{84446A00-08E0-45FA-AC08-3383BD19BB60}
2015-08-12 00:24 - 2015-08-12 00:24 - 00000000 ____D C:\Program Files (x86)\100e225e-5822-4502-a1f7-a89bfc77e287
2015-08-12 00:23 - 2015-08-12 00:23 - 00000004 _____ C:\WINDOWS\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
2015-08-11 23:41 - 2015-08-11 23:42 - 00000000 ____D C:\Users\MSI\Desktop\aaa
2015-08-11 23:05 - 2015-08-11 23:05 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Macromedia
2015-08-11 23:01 - 2015-08-11 23:01 - 00000000 ____D C:\Users\MSI\AppData\Local\MicrosoftEdge
2015-08-11 22:59 - 2015-08-11 22:59 - 00000000 ____D C:\Program Files (x86)\DLLSuite
2015-08-11 22:52 - 2015-08-11 22:52 - 00000000 ____D C:\Program Files\DLLSuite
2015-08-11 22:41 - 2015-08-11 22:41 - 00002101 _____ C:\Users\MSI\Desktop\KnightShift.lnk
2015-08-11 22:41 - 2015-08-11 22:41 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Reality Pump
2015-08-11 22:29 - 2015-08-11 22:29 - 00000000 ____D C:\Program Files (x86)\Reality Pump
2015-08-11 21:50 - 2015-08-11 22:02 - 00000000 ____D C:\Users\MSI\Downloads\KnightShift
2015-08-11 21:09 - 2015-08-11 21:09 - 00014007 _____ C:\Users\MSI\Downloads\[CzT]KnightShift_2003_CZ_.torrent
2015-08-11 21:07 - 2015-08-15 22:04 - 00000000 ____D C:\Users\MSI\Downloads\Rise of Nations - Rise of Legends
2015-08-11 20:55 - 2015-08-11 20:55 - 00012822 _____ C:\Users\MSI\Downloads\[CzT]Rise_of_Nations_Rise_of_Legends.torrent
2015-08-08 15:49 - 2015-08-08 15:49 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-08-07 13:33 - 2015-07-30 08:24 - 01561872 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-08-07 13:33 - 2015-07-30 08:23 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-08-07 13:33 - 2015-07-30 08:21 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-08-07 13:33 - 2015-07-30 08:17 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-08-07 13:33 - 2015-07-30 08:17 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-08-07 13:33 - 2015-07-30 08:16 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-08-07 13:33 - 2015-07-30 08:14 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-08-07 13:33 - 2015-07-30 08:09 - 01562968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-08-07 13:33 - 2015-07-30 08:06 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-08-07 13:33 - 2015-07-30 08:05 - 02498808 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-07 13:33 - 2015-07-30 08:05 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-08-07 13:33 - 2015-07-30 08:04 - 01396064 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-08-07 13:33 - 2015-07-30 08:03 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-08-07 13:33 - 2015-07-30 06:29 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-08-07 13:33 - 2015-07-30 06:26 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2015-08-07 13:33 - 2015-07-30 06:26 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-08-07 13:33 - 2015-07-30 06:25 - 01356368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-08-07 13:33 - 2015-07-30 06:25 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2015-08-07 13:33 - 2015-07-30 06:24 - 01769056 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-08-07 13:33 - 2015-07-30 06:21 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-08-07 13:33 - 2015-07-30 06:12 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-08-07 13:33 - 2015-07-30 06:12 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-08-07 13:33 - 2015-07-30 05:52 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-08-07 13:33 - 2015-07-30 05:52 - 00521216 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-08-07 13:33 - 2015-07-30 05:49 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-08-07 13:33 - 2015-07-30 05:49 - 00777728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-08-07 13:33 - 2015-07-30 05:46 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-08-07 13:33 - 2015-07-30 05:46 - 00593920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-08-07 13:33 - 2015-07-30 05:44 - 02662400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-08-07 13:33 - 2015-07-30 05:44 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-08-07 13:33 - 2015-07-30 05:42 - 00518144 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-08-07 13:33 - 2015-07-30 05:41 - 00407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-08-07 13:33 - 2015-07-30 05:40 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-08-07 13:33 - 2015-07-30 05:38 - 01420288 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-08-07 13:33 - 2015-07-30 05:29 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-08-07 13:33 - 2015-07-30 05:15 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-08-07 13:33 - 2015-07-30 05:10 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-08-07 13:33 - 2015-07-30 05:06 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-08-07 13:33 - 2015-07-30 05:04 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-08-07 13:33 - 2015-07-30 05:04 - 00335360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-08-07 13:32 - 2015-07-30 08:15 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-08-07 13:32 - 2015-07-30 07:24 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-08-07 13:32 - 2015-07-30 06:42 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-08-07 13:32 - 2015-07-30 06:24 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-08-07 13:32 - 2015-07-30 06:24 - 00407616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-08-07 13:32 - 2015-07-30 06:24 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2015-08-07 13:32 - 2015-07-30 06:22 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2015-08-07 13:32 - 2015-07-30 06:22 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2015-08-07 13:32 - 2015-07-30 06:09 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-08-07 13:32 - 2015-07-30 06:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-08-07 13:32 - 2015-07-30 06:08 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-08-07 13:32 - 2015-07-30 06:08 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2015-08-07 13:32 - 2015-07-30 05:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-08-07 13:32 - 2015-07-30 05:52 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2015-08-07 13:32 - 2015-07-30 05:49 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-07 13:32 - 2015-07-30 05:46 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-08-07 13:32 - 2015-07-30 05:46 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-08-07 13:32 - 2015-07-30 05:45 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2015-08-07 13:32 - 2015-07-30 05:45 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2015-08-07 13:32 - 2015-07-30 05:44 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-08-07 13:32 - 2015-07-30 05:44 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-08-07 13:32 - 2015-07-30 05:44 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-08-07 13:32 - 2015-07-30 05:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll
2015-08-07 13:32 - 2015-07-30 05:41 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2015-08-07 13:32 - 2015-07-30 05:38 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-08-07 13:32 - 2015-07-30 05:34 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-08-07 13:32 - 2015-07-30 05:10 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-07 13:32 - 2015-07-30 05:07 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2015-08-07 13:32 - 2015-07-30 05:06 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-08-07 13:32 - 2015-07-30 05:06 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2015-08-07 13:32 - 2015-07-30 05:06 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll
2015-08-07 13:32 - 2015-07-30 04:59 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-08-07 13:32 - 2015-07-30 04:58 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-08-07 11:23 - 2015-08-07 11:24 - 00002388 _____ C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-07 11:23 - 2015-08-07 11:24 - 00000000 ___RD C:\Users\MSI\OneDrive
2015-08-07 11:21 - 2015-08-07 11:21 - 00000000 ____D C:\Users\MSI\AppData\Local\NetworkTiles
2015-08-07 11:21 - 2015-08-07 11:21 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-08-07 11:19 - 2015-07-09 20:39 - 04847104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2015-08-07 11:19 - 2015-07-09 20:36 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2015-08-07 11:19 - 2015-07-09 20:28 - 06358016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2015-08-07 11:19 - 2015-07-09 20:25 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2015-08-07 11:19 - 2015-07-09 20:25 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2015-08-07 11:18 - 2015-08-07 11:18 - 00001047 _____ C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Volitelné funkce.lnk
2015-08-07 11:17 - 2015-08-07 11:17 - 00000000 ____D C:\Users\MSI\AppData\Local\Publishers
2015-08-07 11:15 - 2015-08-08 14:06 - 00000000 ____D C:\Users\MSI\AppData\Local\Packages
2015-08-07 11:15 - 2015-08-07 11:15 - 00000020 ___SH C:\Users\MSI\ntuser.ini
2015-08-07 11:15 - 2015-08-07 11:15 - 00000000 ____D C:\Users\MSI\AppData\Local\TileDataLayer
2015-08-07 07:58 - 2015-08-16 00:08 - 00000000 ___DC C:\WINDOWS\Panther
2015-08-07 07:54 - 2015-08-07 07:54 - 00000000 ____D C:\Windows.old

Re: Problem s virem

Napsal: 16 srp 2015 19:00
od Anovertis1
2015-08-07 07:53 - 2015-08-07 07:53 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 07051264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 06488312 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 06305792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 05118024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 05076480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 04760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 04611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 04169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 04047288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 03362816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02878000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02741760 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02235904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02224128 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02207744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01773056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01611264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01591856 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01521664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01411072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01365072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01334784 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-08-07 07:53 - 2015-08-07 07:53 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01203200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01177600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 01135312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 01112064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01101792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01085776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-08-07 07:53 - 2015-08-07 07:53 - 00991584 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-08-07 07:53 - 2015-08-07 07:53 - 00966424 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00934752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00916800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00828416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00808856 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00762896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00695136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00658568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00607008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00601344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 00562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00521568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00505344 _____ C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00448512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00425824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00412672 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00403968 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00335248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00325984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00303616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00290312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00242264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00208736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00185856 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd(192).dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00061280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2015-08-07 07:53 - 2015-08-07 07:53 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00032768 _____ C:\WINDOWS\system32\LicenseManagerApi.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-08-07 07:53 - 2015-08-07 07:53 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-08-07 07:49 - 2015-08-07 07:49 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\WINDOWS\system32\msmq
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\Program Files\MSBuild
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-08-07 07:46 - 2015-08-07 07:46 - 00000000 ____D C:\inetpub
2015-08-07 07:45 - 2015-06-17 19:10 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-08-07 07:45 - 2015-06-17 19:10 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-07 07:45 - 2015-06-17 19:10 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-08-07 07:45 - 2015-05-29 22:07 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-08-07 07:45 - 2015-05-29 22:07 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-07 07:45 - 2015-05-29 22:07 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Šablony
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Poslední
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Okolní síť
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Dokumenty
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\Data aplikací
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2015-08-07 07:30 - 2015-08-07 07:30 - 00000000 __SHD C:\Recovery
2015-08-07 07:28 - 2015-08-07 07:28 - 00022924 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-08-07 07:26 - 2015-08-12 21:34 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-07 07:24 - 2015-08-07 07:24 - 00000020 ___SH C:\Users\UpdatusUser\ntuser.ini
2015-08-07 07:22 - 2015-07-10 12:59 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-08-07 07:15 - 2015-08-07 07:15 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-08-07 07:12 - 2015-08-07 07:12 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-08-07 07:10 - 2015-08-15 22:29 - 00000000 ____D C:\Users\MSI
2015-08-07 07:10 - 2015-08-12 21:37 - 00000000 ___RD C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-07 07:10 - 2015-08-07 07:11 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Šablony
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Soubory cookie
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Poslední
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní tiskárny
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Okolní síť
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Nabídka Start
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Dokumenty
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Obrázky
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Hudba
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Documents\Filmy
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\Data aplikací
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\UpdatusUser\AppData\Local\Data aplikací
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Šablony
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Soubory cookie
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Poslední
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Okolní tiskárny
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Okolní síť
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Nabídka Start
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Dokumenty
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Documents\Obrázky
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Documents\Hudba
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Documents\Filmy
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\Data aplikací
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2015-08-07 07:10 - 2015-08-07 07:10 - 00000000 _SHDL C:\Users\MSI\AppData\Local\Data aplikací
2015-08-07 07:10 - 2015-07-10 13:04 - 00000000 __RSD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-07 07:10 - 2015-07-10 13:04 - 00000000 __RSD C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-07 07:10 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-07 07:10 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-07 07:10 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-07 07:10 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-07 07:10 - 2015-07-10 13:04 - 00000000 ____D C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-07 07:10 - 2015-07-10 13:04 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-07 07:08 - 2015-08-10 03:41 - 02030404 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-08-07 07:08 - 2015-08-07 07:08 - 01940726 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-08-07 07:05 - 2015-08-15 22:06 - 00000000 ____D C:\ProgramData\NVIDIA
2015-08-07 07:05 - 2015-08-07 07:17 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2015-08-07 07:05 - 2015-08-07 07:17 - 00000000 ____D C:\WINDOWS\system32\NV
2015-08-07 07:05 - 2015-08-07 07:05 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_fspad_win764_01009.Wdf
2015-08-07 07:05 - 2015-08-07 07:05 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-08-07 07:05 - 2015-08-07 07:05 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2015-08-07 07:05 - 2015-08-07 07:05 - 00000000 ____D C:\WINDOWS\system32\DAX2
2015-08-07 07:05 - 2015-08-07 07:05 - 00000000 ____D C:\Program Files\Realtek
2015-08-07 07:05 - 2015-08-07 07:05 - 00000000 ____D C:\Program Files\FSP
2015-08-07 07:05 - 2015-06-29 22:42 - 06783304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-08-07 07:05 - 2015-06-29 22:42 - 03522192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-08-07 07:05 - 2015-06-29 22:42 - 02558792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-08-07 07:05 - 2015-06-29 22:42 - 01083536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2015-08-07 07:05 - 2015-06-29 22:42 - 00932040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-08-07 07:05 - 2015-06-29 22:42 - 00385352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-08-07 07:05 - 2015-06-29 22:42 - 00067072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2015-08-07 07:05 - 2015-06-29 22:42 - 00062792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-08-07 07:05 - 2015-06-29 13:02 - 04437364 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-08-07 07:04 - 2015-08-07 07:12 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-08-07 07:04 - 2015-08-07 07:05 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-08-07 07:04 - 2015-08-07 07:04 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-08-07 07:04 - 2015-08-07 07:04 - 00000000 ____D C:\Intel
2015-08-07 07:01 - 2015-08-07 07:01 - 00024787 _____ C:\WINDOWS\system32\NetSetupMig.log
2015-08-07 06:27 - 2015-08-07 07:29 - 00014259 _____ C:\WINDOWS\diagerr.xml
2015-08-07 06:27 - 2015-08-07 07:29 - 00013338 _____ C:\WINDOWS\diagwrn.xml
2015-07-22 17:45 - 2015-08-07 07:11 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Original War
2015-07-22 17:30 - 2015-08-07 07:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Virgin Interactive
2015-07-22 17:28 - 2015-07-22 17:28 - 00000000 ____D C:\Program Files (x86)\Virgin Interactive
2015-07-22 17:10 - 2015-07-22 17:17 - 00000000 ____D C:\Users\MSI\Downloads\Original War install subory
2015-07-22 17:09 - 2015-07-22 17:09 - 00017560 _____ C:\Users\MSI\Downloads\[CzT]Original_War_CZ_.torrent
2015-07-21 00:37 - 2015-07-21 00:37 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-07-18 19:13 - 2015-07-18 19:13 - 00108144 _____ (Sony DADC Austria AG.) C:\WINDOWS\SysWOW64\CmdLineExt.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-16 19:31 - 2015-03-28 01:26 - 00000914 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-08-16 19:30 - 2015-03-28 01:26 - 00000952 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-16 19:25 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-08-16 11:13 - 2015-03-27 09:36 - 00000000 ____D C:\Program Files (x86)\Opera
2015-08-16 01:01 - 2015-07-10 12:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-08-15 23:30 - 2015-03-28 01:26 - 00000948 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-15 22:26 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-08-15 22:18 - 2015-04-11 20:11 - 00000000 ____D C:\Users\MSI\AppData\Roaming\uTorrent
2015-08-15 22:14 - 2015-03-24 12:33 - 00001967 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-08-15 22:13 - 2015-03-24 12:32 - 00004006 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-08-15 22:06 - 2015-07-10 14:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-08-15 22:05 - 2015-07-10 11:05 - 00131072 ___SH C:\WINDOWS\system32\config\BBI
2015-08-15 22:04 - 2015-07-10 11:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-08-15 22:04 - 2015-03-24 16:01 - 00000000 ____D C:\Users\MSI\AppData\Roaming\GHISLER
2015-08-15 21:55 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\registration
2015-08-14 15:22 - 2015-06-26 06:24 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-08-14 15:21 - 2015-07-10 11:05 - 00131072 ___SH C:\WINDOWS\system32\config\BBI(193)
2015-08-14 15:16 - 2009-07-14 05:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2015-08-14 15:01 - 2015-05-05 17:29 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Seznam.cz
2015-08-12 21:37 - 2015-07-11 11:27 - 00001063 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk
2015-08-12 21:37 - 2015-03-28 01:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-12 21:37 - 2015-03-24 12:31 - 00001130 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-08-12 16:34 - 2015-06-25 18:39 - 00000000 ____D C:\ProgramData\4776dc07-f30f-4d0b-87a6-e2d583c890d4
2015-08-12 16:31 - 2015-03-28 01:26 - 00003888 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-08-12 13:48 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\rescache
2015-08-12 03:32 - 2015-07-10 14:20 - 00256312 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-08-12 03:31 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 03:31 - 2015-07-10 13:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-12 03:30 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-08-12 03:30 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-08-12 03:30 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-08-12 02:56 - 2015-03-30 22:47 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-08-12 01:44 - 2015-07-10 12:59 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
2015-08-12 01:44 - 2015-07-10 12:59 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
2015-08-12 01:44 - 2015-07-10 12:59 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
2015-08-12 01:44 - 2015-07-10 12:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00005120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
2015-08-12 01:44 - 2015-07-10 12:59 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
2015-08-12 01:30 - 2015-03-24 11:36 - 00000000 ____D C:\Users\MSI\AppData\Local\VirtualStore
2015-08-12 00:24 - 2015-04-11 21:30 - 00000000 ____D C:\Program Files (x86)\AVG
2015-08-11 23:16 - 2015-04-11 21:25 - 00000000 ____D C:\Users\MSI\AppData\Roaming\DAEMON Tools Lite
2015-08-11 21:01 - 2015-07-15 01:14 - 00000000 ____D C:\ProgramData\Origin
2015-08-11 21:01 - 2015-07-15 01:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-08-11 21:00 - 2015-06-06 22:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ
2015-08-11 21:00 - 2015-03-24 12:26 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-08-11 20:59 - 2015-05-26 01:30 - 00000000 ____D C:\Program Files (x86)\THQ
2015-08-11 20:58 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-08-10 03:41 - 2015-07-10 18:02 - 00840160 _____ C:\WINDOWS\system32\perfh005.dat
2015-08-10 03:41 - 2015-07-10 18:02 - 00191452 _____ C:\WINDOWS\system32\perfc005.dat
2015-08-10 03:31 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-08-08 17:38 - 2015-07-10 13:06 - 00794088 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-08-08 17:38 - 2015-07-10 13:06 - 00179688 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-08 04:39 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\appcompat
2015-08-07 13:33 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\restore
2015-08-07 11:19 - 2015-07-10 18:03 - 00000000 ____D C:\WINDOWS\OCR
2015-08-07 11:17 - 2015-07-10 13:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-08-07 11:17 - 2015-07-10 13:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-08-07 11:17 - 2015-07-10 13:04 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-08-07 11:16 - 2015-07-10 13:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-08-07 07:58 - 2015-07-10 13:04 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-08-07 07:54 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2015-08-07 07:54 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-08-07 07:54 - 2015-07-10 11:05 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-08-07 07:54 - 2015-07-10 11:05 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-08-07 07:46 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2015-08-07 07:46 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-08-07 07:46 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\MUI
2015-08-07 07:46 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-08-07 07:46 - 2015-07-10 13:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2015-08-07 07:46 - 2015-07-10 13:01 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2015-08-07 07:46 - 2015-07-10 13:01 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2015-08-07 07:46 - 2015-07-10 13:01 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2015-08-07 07:46 - 2015-07-10 13:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2015-08-07 07:46 - 2015-07-10 13:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2015-08-07 07:46 - 2015-07-10 13:01 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2015-08-07 07:46 - 2015-07-10 13:00 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2015-08-07 07:46 - 2015-07-10 13:00 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2015-08-07 07:46 - 2015-07-10 13:00 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2015-08-07 07:46 - 2015-07-10 13:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2015-08-07 07:46 - 2015-07-10 13:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2015-08-07 07:46 - 2015-07-10 13:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-08-07 07:46 - 2015-07-10 13:00 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-08-07 07:46 - 2015-07-10 13:00 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2015-08-07 07:45 - 2015-07-10 13:01 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2015-08-07 07:45 - 2015-07-10 13:00 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2015-08-07 07:45 - 2015-07-10 13:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2015-08-07 07:30 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Windows NT
2015-08-07 07:30 - 2015-07-10 11:05 - 00000000 __RHD C:\Users\Default
2015-08-07 07:28 - 2015-07-11 11:27 - 00003936 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1436606843
2015-08-07 07:28 - 2015-06-26 06:26 - 00003996 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-08-07 07:28 - 2015-06-01 20:08 - 00003384 _____ C:\WINDOWS\System32\Tasks\{EB20C7B5-5CA9-4908-A61E-F7DAAD511DC7}
2015-08-07 07:28 - 2015-05-23 22:42 - 00003296 _____ C:\WINDOWS\System32\Tasks\{176401CC-AA44-4DCD-AB39-6853F7E9DC12}
2015-08-07 07:28 - 2015-05-23 22:41 - 00003298 _____ C:\WINDOWS\System32\Tasks\{5A4A2BDA-5117-47D4-943B-AEBD5339B524}
2015-08-07 07:28 - 2015-05-19 19:08 - 00002892 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-08-07 07:28 - 2015-04-11 21:44 - 00003804 _____ C:\WINDOWS\System32\Tasks\Adobe Reader and Acrobat Manager
2015-08-07 07:28 - 2015-04-11 21:27 - 00003478 _____ C:\WINDOWS\System32\Tasks\SidebarExecute
2015-08-07 07:28 - 2015-03-28 01:26 - 00004058 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-07 07:28 - 2015-03-28 01:26 - 00003806 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-07 07:27 - 2015-07-10 13:04 - 00000000 __RSD C:\WINDOWS\Media
2015-08-07 07:27 - 2015-07-10 13:04 - 00000000 __RHD C:\Users\Public\Libraries
2015-08-07 07:25 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\spool
2015-08-07 07:17 - 2015-07-10 13:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-07 07:17 - 2015-07-10 11:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-08-07 07:17 - 2015-07-03 20:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpeedFan
2015-08-07 07:17 - 2015-07-03 19:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\James Cameron's Avatar - The Game
2015-08-07 07:17 - 2015-06-25 18:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2015-08-07 07:17 - 2015-06-06 06:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LOTR - War in the North
2015-08-07 07:17 - 2015-05-25 00:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tomi2k9 Repacky
2015-08-07 07:17 - 2015-05-19 19:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-08-07 07:17 - 2015-04-11 20:11 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2015-08-07 07:17 - 2015-04-04 12:26 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-07 07:17 - 2015-03-28 16:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\W7 Changer Pro
2015-08-07 07:17 - 2015-03-27 10:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BlueStacks
2015-08-07 07:17 - 2015-03-24 12:36 - 00000000 ___SD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.3
2015-08-07 07:17 - 2015-03-24 12:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-08-07 07:17 - 2015-03-24 12:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-08-07 07:17 - 2015-03-24 12:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-08-07 07:15 - 2009-07-14 05:20 - 00000000 ____D C:\Users\Default.migrated
2015-08-07 07:14 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK
2015-08-07 07:14 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR
2015-08-07 07:14 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-08-07 07:14 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-08-07 07:14 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-08-07 07:14 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-08-07 07:13 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-08-07 07:13 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\IME
2015-08-07 07:13 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\schemas
2015-08-07 07:13 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-08-07 07:13 - 2015-07-09 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ubisoft
2015-08-07 07:13 - 2015-06-07 15:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Xfire
2015-08-07 07:12 - 2015-07-10 13:04 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-08-07 07:12 - 2015-07-10 13:04 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-08-07 07:12 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-08-07 07:12 - 2015-07-10 13:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-08-07 07:12 - 2015-06-29 15:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpellForce
2015-08-07 07:12 - 2015-06-28 19:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sunflowers
2015-08-07 07:12 - 2015-05-23 23:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2015-08-07 07:12 - 2015-05-23 20:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2015-08-07 07:12 - 2015-03-24 13:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-08-07 07:12 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games
2015-08-07 07:12 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-08-07 07:11 - 2015-06-29 15:04 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpellForce
2015-08-07 07:05 - 2015-07-10 13:04 - 00000000 ____D C:\WINDOWS\Help
2015-08-07 07:05 - 2015-05-26 01:49 - 00000000 ____D C:\temp
2015-08-07 06:36 - 2009-07-14 06:45 - 00021472 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-07 06:36 - 2009-07-14 06:45 - 00021472 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-07 06:27 - 2015-07-10 18:25 - 00000000 ___HD C:\$Windows.~BT
2015-07-28 10:59 - 2015-03-30 22:47 - 132483416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-07-26 22:37 - 2009-07-14 07:09 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2015-07-22 17:15 - 2015-06-28 18:11 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
2015-07-21 00:37 - 2015-03-24 12:32 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-07-21 00:37 - 2015-03-24 12:32 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-07-21 00:37 - 2015-03-24 12:32 - 00150160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-07-21 00:37 - 2015-03-24 12:32 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-07-21 00:37 - 2015-03-24 12:32 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-07-21 00:37 - 2015-03-24 12:32 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-07-21 00:37 - 2015-03-24 12:32 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-07-21 00:36 - 2015-03-24 12:32 - 01048856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-07-18 01:53 - 2015-07-03 20:30 - 00000000 ____D C:\Program Files (x86)\SpeedFan

==================== Files in the root of some directories =======

2015-05-26 14:52 - 2003-09-03 07:46 - 0010960 _____ () C:\Program Files (x86)\EULA.txt
2015-05-26 14:52 - 2015-06-02 06:53 - 0001517 _____ () C:\Program Files (x86)\INSTALL.LOG
2015-05-26 14:52 - 2003-12-18 11:33 - 0020102 _____ () C:\Program Files (x86)\Readme.txt
2015-08-07 07:05 - 2015-08-07 07:05 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-07 06:59

==================== End of log ============================

Re: Problem s virem

Napsal: 16 srp 2015 19:01
od Anovertis1
Additional scan result of Farbar Recovery Scan Tool (x64) Version:16-08-2015
Ran by MSI (2015-08-16 19:55:27)
Running from C:\Users\MSI\Downloads
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3121232644-64818644-3227324357-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3121232644-64818644-3227324357-503 - Limited - Disabled)
Guest (S-1-5-21-3121232644-64818644-3227324357-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3121232644-64818644-3227324357-1003 - Limited - Enabled)
MSI (S-1-5-21-3121232644-64818644-3227324357-1000 - Administrator - Enabled) => C:\Users\MSI
UpdatusUser (S-1-5-21-3121232644-64818644-3227324357-1001 - Limited - Enabled) => C:\Users\UpdatusUser

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM-x32\...\uTorrent) (Version: 2.2.1.25534 - emc, uTorrent.CZ)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 18 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.3.2223 - AVAST Software)
BlueStacks App Player (HKLM-x32\...\BlueStacks App Player) (Version: 0.9.18.5016 - BlueStack Systems, Inc.)
BlueStacks Notification Center (HKLM-x32\...\{011580CB-3D7F-47A6-A5D2-1287A4E43C73}) (Version: 0.9.18.5016 - BlueStack Systems, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.05 - Piriform)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.1.0.0074 - Disc Soft Ltd)
Fallout New Vegas - Ultimate Edition (HKLM-x32\...\Fallout New Vegas - Ultimate Edition_is1) (Version: - )
Finger Sensing Pad Driver (HKLM\...\{E86906FF-C63D-4EAF-ACE7-5F8D55FBEA9A}) (Version: 9.4.9.5 - Sentelic)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.7 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Heroes of Might & Magic V: Hammers of Fate (HKLM-x32\...\{07BE4679-4318-4413-9701-B3D91354F10C}) (Version: - )
Heroes of Might and Magic V - Tribes of the East (HKLM-x32\...\{66FF4C48-0083-4E60-8556-B883AB200092}) (Version: - )
Heroes of Might and Magic V (HKLM-x32\...\{8829DAD4-8F07-4A96-B995-15498EBB8045}) (Version: - )
Homeworld2 (HKLM-x32\...\Homeworld2) (Version: - Sierra)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 6.0.0.1179 - Intel Corporation)
James Cameron's Avatar - The Game version 1.02 (HKLM-x32\...\James Cameron's Avatar - The Game_is1) (Version: 1.02 - )
KnightShift (HKLM-x32\...\KnightShift) (Version: 1.0.1 - ZUXXEZ Entertainment AG)
LibreOffice 4.3.5.2 (HKLM-x32\...\{1D4E90DA-C33C-40ED-BA00-75F6E6DF9CB0}) (Version: 4.3.5.2 - The Document Foundation)
LOTR - War in the North verze 1.0.0.1 (HKLM-x32\...\{1A291E00-90FF-4EE8-A1B2-A113AD36D95D}_is1) (Version: 1.0.0.1 - tomi2k9)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 31.0 (x86 cs) (HKLM-x32\...\Mozilla Firefox 31.0 (x86 cs)) (Version: 31.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
NVIDIA Ovladač 3D Vision 266.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 266.39 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 266.39 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 266.39 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{9530AE42-DAE1-4619-9594-B23487285D17}) (Version: 9.11.1107 - NVIDIA Corporation)
Opera Stable 31.0.1889.99 (HKLM-x32\...\Opera 31.0.1889.99) (Version: 31.0.1889.99 - Opera Software)
Original War (HKLM-x32\...\Original War) (Version: - )
Ovládací panel NVIDIA 341.74 (Version: 341.74 - NVIDIA Corporation) Hidden
ParaWorld (HKLM-x32\...\{EAA01BA0-6991-4296-A404-4FFF2DAC2225}) (Version: 1.05 - Sunflowers)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Seznam Software (HKU\S-1-5-21-3121232644-64818644-3227324357-1000\...\SeznamInstall) (Version: - Seznam.cz)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Spellforce 2 Gold (HKLM-x32\...\{746F49C9-3789-4F8E-AF3A-3A4B42ACFAF8}) (Version: 1.00.0000 - JoWooD Productions Software AG)
SpyHunter 4 (HKLM-x32\...\SpyHunter) (Version: 4.20.9.4533 - Enigma Software Group, LLC)
StarCraft II: Heart of the Swarm (c) Blizzard Entertainment version 1 (HKLM-x32\...\U3RhckNyYWZ0IElJOiBIZWFydCBvZiB0aGUgU3dhcm0gKGMp~BFC02D25_is1) (Version: 1 - )
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.4.7.0 - Elaborate Bytes)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
W7 Background Changer (HKLM-x32\...\{0D8B938C-2838-4C29-B163-AB016E5A45AF}) (Version: 3.9 - FD MS Ltd)
Xfire (remove only) (HKLM-x32\...\Xfire) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3121232644-64818644-3227324357-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\MSI\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncApi64.dll (Microsoft Corporation)

==================== Restore Points =========================

08-08-2015 13:59:31 Windows Update
11-08-2015 20:56:38 Odstraněno ArcaniA - Gothic 4
14-08-2015 14:35:29 Instalační služba modulů systému Windows
14-08-2015 15:15:18 Restore Point Created by FRST
15-08-2015 09:37:48 clear
15-08-2015 21:42:31 Operace obnovení

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:34 - 2015-08-14 15:17 - 00000027 ____N C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {00EEBA9C-F9EF-4272-B793-C830FBADD359} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-07-10] (Microsoft Corporation)
Task: {046B0933-ECC9-4E5F-A3C3-B8E284DA60C2} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {05B37FF2-DA99-4998-A040-E6D49F585138} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {089CE5BD-06F0-4CAE-A928-A49593F8999E} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {0CCA7916-2916-4F12-BD32-1E3BE31E1269} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-07-10] (Microsoft Corporation)
Task: {12F4F4D9-B31D-4204-AFCE-421E613D3B52} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {138DD52D-59D7-453E-90D4-A0F76561D32E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {1505FB00-2BD8-4E79-A513-8D79F78BCC97} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {19865544-CE08-40BE-8B8C-87C47681433D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {1BCD4535-AC54-45E2-9C08-5DD27EDAA4A4} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {2170FB0F-B6D7-49A2-9EEA-1ECB0507CD68} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {26247725-8857-4B06-AEBB-9BA0346E2701} - System32\Tasks\{5A4A2BDA-5117-47D4-943B-AEBD5339B524} => pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\The Godfather The Game\Odinstalovat.exe"
Task: {2FC735AE-5C10-4707-97F4-EB29D41A8D0F} - System32\Tasks\{EB20C7B5-5CA9-4908-A61E-F7DAAD511DC7} => pcalua.exe -a C:\Users\MSI\AppData\Local\Temp\GLFB7D~1.EXE -d C:\Users\MSI\AppData\Local\Temp -c C:\Program Files (x86)\Sierra\Homeworld2
Task: {3938E79D-5DF9-4E0A-8D2E-03A5F1B834BE} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {3A1775B4-675D-453E-9057-1D7D0531F742} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW
Task: {402F1538-9213-41FE-AC44-06A57FF9A234} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {41160EA0-208B-4C3E-B4DB-805BBABC6B93} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-07-10] (Microsoft Corporation)
Task: {4604C7CB-5D69-4AC7-805C-35E1489EC8DD} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {48D4855D-176F-477F-8AE6-3D32A794D6A5} - System32\Tasks\Adobe Reader and Acrobat Manager => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {4CB7575C-DA61-4C25-89ED-F3FE25819D99} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {4E5DF8F5-E737-450D-A7B8-23A599A651C3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-28] (Google Inc.)
Task: {4EF46012-D8EA-4DD8-858B-3EAF9A183831} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated)
Task: {51D8275B-21FF-43F0-A387-8C995E69DC20} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {5B61B08F-B342-4871-A2B8-45C2E7187D93} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {663BEF06-08F9-4E2E-8D1F-B25F4C8FEF32} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-07-21] (AVAST Software)
Task: {67647D34-5C34-4C2D-BDED-DB984A189B0B} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6C31CABD-6C4B-420B-AA88-E5DD165AA120} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {733F4C38-0E0C-42D6-AD09-2A2742F5E352} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {73551810-E5F4-433E-9494-0D00B55C855E} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask
Task: {782A514B-1945-44B4-B8A1-1198572296B8} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {78B77FA3-9D97-441D-97B6-68CEA40B4F74} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance
Task: {81FF1D92-28D8-4BAD-9B6B-1174A7EB3E65} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {829B0A75-294D-4659-802C-733D2ADAF059} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {8384E0C4-6FA2-4F34-A93E-7B6BEA24651F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-04-23] (Piriform Ltd)
Task: {844BF627-1857-4D4B-BF6A-20A1B15D1603} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {858D4D5D-CB22-4652-960D-EEB30D2203B0} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {88165E9C-9171-4296-BBAD-6D919AD20A6A} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {8AAE3EA0-5428-4003-9D50-6CEC8E1A7E2C} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {8DF84CB3-D8E0-4307-A35B-CA74E21786DB} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-08-07] (Microsoft Corporation)
Task: {91377C9A-EA21-490E-820B-ABCF8FEAC347} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {944040A5-B0A8-4E5D-843E-DF023F8AE115} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {A5B6CD85-1B57-49B9-BA80-5D5D65F02826} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager
Task: {AE55210A-F9D2-4572-8C6C-9A914292C500} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {B173FB70-A792-4CF6-8DF1-1C9EDEC4AC63} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {B2F456E3-14E6-4B33-B7E4-7A658BEA795B} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {BD9AC52C-F6FD-4252-8166-12892F8FBD5D} - System32\Tasks\Opera scheduled Autoupdate 1436606843 => C:\Program Files (x86)\Opera\launcher.exe [2015-07-30] (Opera Software)
Task: {BF208C96-8D27-4674-AC94-91D3E2CDD72E} - System32\Tasks\SpyHunter4Startup => C:\Program Files\Enigma Software Group\SpyHunter\Spyhunter4.exe [2015-08-15] (Enigma Software Group USA, LLC.)
Task: {C095A869-A2C8-4FB6-916D-067AC2512FDF} - System32\Tasks\{176401CC-AA44-4DCD-AB39-6853F7E9DC12} => pcalua.exe -a "C:\Program Files (x86)\Electronic Arts\The Godfather The Game\EAUninstall.exe"
Task: {C56AFFD3-06B8-4A16-AF7E-F7A6EB3FAE9E} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr
Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {C673DA2D-91EF-4B9C-A7F5-4FCD5B87AA66} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {C7A236B2-12E1-46DC-9501-3B1B0209CC09} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-07-10] (Microsoft Corporation)
Task: {C871E354-A299-42B8-AC20-49F0FC3E4134} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {CA796FC3-7E99-4DF8-8A8E-1CB304140380} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {D2B3E267-F25E-4F78-A66D-4D957140E7C5} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {E2263E45-8769-42A6-8048-B2F340F015A7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {E963519A-AA5F-41DC-9ADF-9083E86C1BF3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-03-28] (Google Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-08-07 07:53 - 2015-08-07 07:53 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-08-07 07:05 - 2015-06-29 22:42 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-08-07 07:53 - 2015-08-07 07:53 - 00403968 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-05-29 07:29 - 2015-05-29 07:29 - 02178896 _____ () C:\Windows\System32\FspService.exe
2015-08-07 13:33 - 2015-07-30 08:05 - 02498808 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-08-07 13:33 - 2015-07-30 08:05 - 02498808 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-08-12 02:26 - 2015-08-03 03:11 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-07-10 13:00 - 2015-07-10 18:05 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-08-12 02:26 - 2015-08-03 03:08 - 01806848 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-08-12 02:26 - 2015-08-03 03:09 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2012-11-26 23:54 - 2012-11-26 23:54 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2015-07-10 12:59 - 2015-07-10 12:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-08-12 02:26 - 2015-08-03 03:30 - 00642048 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2015-07-10 12:59 - 2015-07-10 12:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2015-08-12 02:26 - 2015-08-03 04:13 - 02590560 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentDeliveryManager.Background.dll
2015-08-12 02:26 - 2015-08-03 04:12 - 02108256 _____ () C:\Windows\SystemApps\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\ContentManagementSDK.dll
2015-08-07 12:01 - 2015-08-07 12:01 - 00049152 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.8.3.0_x64__8wekyb3d8bbwe\WinStoreTasksWrapper.dll
2015-07-21 00:37 - 2015-07-21 00:37 - 00102864 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-07-21 00:37 - 2015-07-21 00:37 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-08-14 23:26 - 2015-08-14 23:26 - 02962432 _____ () C:\Program Files\AVAST Software\Avast\defs\15081406\algo.dll
2015-08-15 22:14 - 2015-08-15 22:14 - 02962432 _____ () C:\Program Files\AVAST Software\Avast\defs\15081502\algo.dll
2015-08-06 11:13 - 2015-08-06 11:13 - 58599032 _____ () C:\Program Files (x86)\Opera\31.0.1889.99\opera.dll
2015-07-21 00:37 - 2015-07-21 00:37 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-08-06 11:13 - 2015-08-06 11:12 - 01781368 _____ () C:\Program Files (x86)\Opera\31.0.1889.99\libglesv2.dll
2015-08-06 11:13 - 2015-08-06 11:12 - 00081528 _____ () C:\Program Files (x86)\Opera\31.0.1889.99\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service"

==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3121232644-64818644-3227324357-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\MSI\Desktop\72775eb8-a403-4539-b1a9-3d447971e627_6.jpg
HKU\S-1-5-21-3121232644-64818644-3227324357-1001\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [UDP Query User{DAF9C3F2-C8D2-41C5-A21C-3E53CD4D6AB3}C:\program files (x86)\virgin interactive\original war\owarfull.exe] => (Allow) C:\program files (x86)\virgin interactive\original war\owarfull.exe
FirewallRules: [TCP Query User{3E0DC473-32B0-42D4-BB5A-A50624C57126}C:\program files (x86)\virgin interactive\original war\owarfull.exe] => (Allow) C:\program files (x86)\virgin interactive\original war\owarfull.exe
FirewallRules: [UDP Query User{A485D66D-E886-427C-B965-467DC491844D}C:\games\james cameron's avatar - the game\bin\avatar.exe] => (Allow) C:\games\james cameron's avatar - the game\bin\avatar.exe
FirewallRules: [TCP Query User{4C48028A-E742-45A2-8D3A-7ED14F82BA72}C:\games\james cameron's avatar - the game\bin\avatar.exe] => (Allow) C:\games\james cameron's avatar - the game\bin\avatar.exe
FirewallRules: [{2ED9D240-C7B0-4A80-AB52-DD8917E2E0EE}] => (Allow) C:\Program Files (x86)\StarCraft II\Versions\Base24944\SC2.exe
FirewallRules: [{502F4920-15F8-489B-9FDF-E7C82D7C6126}] => (Allow) C:\Program Files (x86)\StarCraft II\Versions\Base24944\SC2.exe
FirewallRules: [{7D8AC519-19E5-4CB7-B8E0-7159BB5960FB}] => (Block) C:\Program Files (x86)\StarCraft II\Versions\Base24944\SC2.exe
FirewallRules: [UDP Query User{62007E3B-ED2A-4C9B-AE03-A170FBD2BD8C}C:\program files (x86)\empire earth\empire earth.exe] => (Allow) C:\program files (x86)\empire earth\empire earth.exe
FirewallRules: [TCP Query User{02C1A875-B7BC-41BD-8E45-B0DE4A53F626}C:\program files (x86)\empire earth\empire earth.exe] => (Allow) C:\program files (x86)\empire earth\empire earth.exe
FirewallRules: [{0DAAB36D-1FF4-4FE2-B39F-5746B3819E32}] => (Allow) C:\Users\MSI\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{4C8F72F8-1B19-49FA-90CA-D6987C5D21D0}] => (Allow) C:\Users\MSI\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [UDP Query User{1B110BBE-43B0-4BC8-BA5A-1B46872A1E06}C:\program files (x86)\starcraft-broodwar\starcraft.exe] => (Allow) C:\program files (x86)\starcraft-broodwar\starcraft.exe
FirewallRules: [TCP Query User{6E3F6012-2AA9-427E-970F-3645CB90C019}C:\program files (x86)\starcraft-broodwar\starcraft.exe] => (Allow) C:\program files (x86)\starcraft-broodwar\starcraft.exe
FirewallRules: [UDP Query User{E0D66E2D-11D3-4B4E-8856-B3C60257B901}C:\program files (x86)\starcraft\brood\starcraft.exe] => (Allow) C:\program files (x86)\starcraft\brood\starcraft.exe
FirewallRules: [TCP Query User{9F96B6DF-12F9-422E-A118-275AE066C553}C:\program files (x86)\starcraft\brood\starcraft.exe] => (Allow) C:\program files (x86)\starcraft\brood\starcraft.exe
FirewallRules: [{39D0C69E-04D9-48AE-8C0F-9923B11A5C56}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{739A6B2B-2336-430F-AD26-CBAB9F2AEF58}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
FirewallRules: [{1CBF4C4C-4D0D-4FAE-982B-7920CE96FDBB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/16/2015 07:13:46 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MSI-PC)
Description: Aplikaci Microsoft.Windows.Photos_8wekyb3d8bbwe!App se nepovedlo aktivovat, protože došlo k chybě: -2147023170. Další informace najdete v protokolu Microsoft-Windows-TWinUI/Operational.

Error: (08/15/2015 10:12:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program ShellExperienceHost.exe verze 10.0.10240.16425 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: bfc

Čas spuštění: 01d0d7960e3eee2c

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe

ID hlášení: e63e8ca1-4389-11e5-9bcd-406186b5bd5d

Úplný název balíčku s chybou: Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy

ID aplikace související s balíčkem s chybou: App

Error: (08/15/2015 10:12:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: RuntimeBroker.exe, verze: 10.0.10240.16384, časové razítko: 0x559f39eb
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00007ffb8ddd000a
ID chybujícího procesu: 0x8ec
Čas spuštění chybující aplikace: 0xRuntimeBroker.exe0
Cesta k chybující aplikaci: RuntimeBroker.exe1
Cesta k chybujícímu modulu: RuntimeBroker.exe2
ID zprávy: RuntimeBroker.exe3
Úplný název chybujícího balíčku: RuntimeBroker.exe4
ID aplikace související s chybujícím balíčkem: RuntimeBroker.exe5

Error: (08/15/2015 10:12:00 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: MSI-PC)
Description: Balíček Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy+App se ukončil, protože jeho pozastavování trvalo moc dlouho.

Error: (08/15/2015 10:09:43 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (08/15/2015 10:08:42 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: Během obnovení systému došlo k nespecifikované chybě: (clear). Další informace: 0xc0000022.

Error: (08/15/2015 10:06:28 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1584) SRUJet: Při otevírání souboru protokolu C:\WINDOWS\system32\SRU\SRU000D4.log došlo k chybě -1811 (0xfffff8ed).

Error: (08/15/2015 09:42:40 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (08/15/2015 07:55:14 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SystemSettings.exe verze 10.0.10240.16384 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 1710

Čas spuštění: 01d0d781e38d5ae9

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\ImmersiveControlPanel\SystemSettings.exe

ID hlášení: be841ba9-4376-11e5-9bcf-406186b5bd5d

Úplný název balíčku s chybou: windows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewy

ID aplikace související s balíčkem s chybou: microsoft.windows.immersivecontrolpanel

Error: (08/15/2015 07:42:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program SearchUI.exe verze 10.0.10240.16425 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: fb8

Čas spuštění: 01d0d781992185f8

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe

ID hlášení: e41ee229-4374-11e5-9bcf-406186b5bd5d

Úplný název balíčku s chybou: Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewy

ID aplikace související s balíčkem s chybou: CortanaUI


System errors:
=============
Error: (08/16/2015 07:13:39 AM) (Source: i8042prt) (EventID: 41) (User: )
Description: Při zapnutí přenosu informací myší došlo k chybě. Zařízení bylo resetováno, aby se zajistila jeho funkčnost.

Error: (08/16/2015 07:13:36 AM) (Source: i8042prt) (EventID: 41) (User: )
Description: Při zapnutí přenosu informací myší došlo k chybě. Zařízení bylo resetováno, aby se zajistila jeho funkčnost.

Error: (08/16/2015 04:51:42 AM) (Source: i8042prt) (EventID: 41) (User: )
Description: Při zapnutí přenosu informací myší došlo k chybě. Zařízení bylo resetováno, aby se zajistila jeho funkčnost.

Error: (08/16/2015 04:51:39 AM) (Source: i8042prt) (EventID: 41) (User: )
Description: Při zapnutí přenosu informací myší došlo k chybě. Zařízení bylo resetováno, aby se zajistila jeho funkčnost.

Error: (08/16/2015 01:01:29 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Instalace se nezdařila: Instalování následující aktualizace se nezdařilo z důvodu chyby (0x80073701): Kumulativní aktualizace pro Windows 10 pro systémy x64 (KB3081438).

Error: (08/15/2015 10:22:14 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: specifické pro aplikaciMístníAktivace{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (pomocí LRPC)Není k dispoziciNení k dispozici

Error: (08/15/2015 10:14:58 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba NVIDIA Update Service Daemon přestala během spouštění reagovat.

Error: (08/15/2015 10:11:02 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Optimalizace doručení přestala během spouštění reagovat.

Error: (08/15/2015 10:09:43 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba BlueStacks Android Service byla ukončena s následující chybou:
%%1064

Error: (08/15/2015 10:06:55 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Adaptér naslouchání Net.Pipe neuspěla při spuštění v důsledku následující chyby:
%%1053


Microsoft Office:
=========================
Error: (08/16/2015 07:13:46 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: MSI-PC)
Description: Microsoft.Windows.Photos_8wekyb3d8bbwe!App-2147023170

Error: (08/15/2015 10:12:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: ShellExperienceHost.exe10.0.10240.16425bfc01d0d7960e3eee2c4294967295C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exee63e8ca1-4389-11e5-9bcd-406186b5bd5dMicrosoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewyApp

Error: (08/15/2015 10:12:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: RuntimeBroker.exe10.0.10240.16384559f39ebunknown0.0.0.000000000c000000500007ffb8ddd000a8ec01d0d79613298165C:\Windows\System32\RuntimeBroker.exeunknown3d6d4d51-08e6-4cf5-8bb1-c97c7eb210aa

Error: (08/15/2015 10:12:00 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: MSI-PC)
Description: Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewy+App

Error: (08/15/2015 10:09:43 PM) (Source: BstHdAndroidSvc) (EventID: 0) (User: )
Description: Službu nelze spustit. System.ApplicationException: Cannot start service. Service did not stop gracefully the last time it was run.
v BlueStacks.hyperDroid.Service.Service.OnStart(String[] args)
v System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

Error: (08/15/2015 10:08:42 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: clear0xc0000022

Error: (08/15/2015 10:06:28 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost1584SRUJet: C:\WINDOWS\system32\SRU\SRU000D4.log-1811 (0xfffff8ed)

Error: (08/15/2015 09:42:40 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.

Error: (08/15/2015 07:55:14 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: SystemSettings.exe10.0.10240.16384171001d0d781e38d5ae94294967295C:\Windows\ImmersiveControlPanel\SystemSettings.exebe841ba9-4376-11e5-9bcf-406186b5bd5dwindows.immersivecontrolpanel_6.2.0.0_neutral_neutral_cw5n1h2txyewymicrosoft.windows.immersivecontrolpanel

Error: (08/15/2015 07:42:16 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: SearchUI.exe10.0.10240.16425fb801d0d781992185f84294967295C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exee41ee229-4374-11e5-9bcf-406186b5bd5dMicrosoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyCortanaUI


==================== Memory info ===========================

Processor: Intel(R) Pentium(R) CPU P6100 @ 2.00GHz
Percentage of memory in use: 59%
Total physical RAM: 3886 MB
Available physical RAM: 1563.08 MB
Total Virtual: 7854 MB
Available Virtual: 4692.44 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.22 GB) (Free:102.54 GB) NTFS

==================== MBR & Partition Table ==================

==================== End of log ============================

Re: Problem s virem

Napsal: 21 srp 2015 10:54
od vyosek
:arrow: Tvorba fixlistu pro FRST
  • Spustte poznamkovy blok (Start-spustit-notepad)
  • Zkopirujte skript nize
  • Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    HKU\S-1-5-21-3121232644-64818644-3227324357-1001\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
    
    FF DefaultSearchEngine: Yahoo Search!
    FF Extension: Razor Web - C:\Users\MSI\AppData\Roaming\Mozilla\Firefox\Profiles\6ch307pd.default\Extensions\{7c3288cb-3846-4d30-8f57-c5450fe01c2d}.xpi [2015-06-25]
    
    OPR Extension: (Razor Web) - C:\Users\MSI\AppData\Roaming\Opera Software\Opera Stable\Extensions\ccnmmcllpopemhcbgccmbnlleblllojc [2015-07-11]
    
    R2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\SH4Service.exe [1026944 2015-08-15] (Enigma Software Group USA, LLC.)
    
    C:\Program Files\Enigma Software Group
    2015-08-16 19:53 - 2015-08-16 19:54 - 00022596 _____ C:\Users\MSI\Downloads\FRST.txt
    2015-08-15 22:29 - 2015-08-15 22:29 - 00003398 _____ C:\WINDOWS\System32\Tasks\SpyHunter4Startup
    2015-08-15 22:29 - 2015-08-15 22:29 - 00001132 _____ C:\Users\MSI\Desktop\SpyHunter.lnk
    2015-08-15 22:29 - 2015-08-15 22:29 - 00000000 ____D C:\Users\MSI\AppData\Roaming\Enigma Software Group
    2015-08-15 22:29 - 2015-08-15 22:29 - 00000000 ____D C:\sh4ldr
    2015-08-15 22:27 - 2015-08-15 22:27 - 00022704 _____ C:\WINDOWS\system32\Drivers\EsgScanner.sys
    2015-08-15 22:27 - 2015-08-15 22:27 - 00000000 ____D C:\Program Files\Enigma Software Group
    2015-08-15 22:26 - 2015-08-15 22:26 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\MSI\Downloads\SpyHunter-Installer.exe
    2015-08-15 22:13 - 2015-07-21 00:37 - 00447944 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB629.tmp
    2015-08-15 22:13 - 2015-07-21 00:37 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB63A.tmp
    2015-08-15 22:13 - 2015-07-21 00:37 - 00150160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB63B.tmp
    2015-08-15 22:13 - 2015-07-21 00:37 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB4CD.tmp
    2015-08-15 22:13 - 2015-07-21 00:37 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB50E.tmp
    2015-08-15 22:13 - 2015-07-21 00:37 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB619.tmp
    2015-08-15 22:13 - 2015-07-21 00:37 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB4FD.tmp
    2015-08-15 22:13 - 2015-07-21 00:36 - 01048856 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswB48E.tmp
    2015-08-14 15:14 - 2015-08-16 19:53 - 00000000 ____D C:\Users\MSI\Downloads\FRST-OlderVersion
    
    Task: {2170FB0F-B6D7-49A2-9EEA-1ECB0507CD68} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {3A1775B4-675D-453E-9057-1D7D0531F742} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {51D8275B-21FF-43F0-A387-8C995E69DC20} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {6C31CABD-6C4B-420B-AA88-E5DD165AA120} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    Task: {733F4C38-0E0C-42D6-AD09-2A2742F5E352} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {829B0A75-294D-4659-802C-733D2ADAF059} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {AE55210A-F9D2-4572-8C6C-9A914292C500} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {B173FB70-A792-4CF6-8DF1-1C9EDEC4AC63} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {C871E354-A299-42B8-AC20-49F0FC3E4134} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {E2263E45-8769-42A6-8048-B2F340F015A7} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    
    Hosts:
    EmptyTemp:
    Reboot:
    End
    
  • Ulozte vytvoreny TXT jako fixlist.txt
  • Presunte vytvoreny fixlist vedle FRST
:arrow: Spustte znovu FRST.exe
  • Kliknete na Fix
  • Probehne oprava a vytvori log Fixlog.txt
:arrow: Restart PC a dejte mi sem fixlog.txt