Re: prepinanie na nechcene stranky
Napsal: 17 pro 2016 10:57
prikladam fixlog
Fix result of Farbar Recovery Scan Tool (x64) Version: 07-12-2016
Ran by Michal (17-12-2016 10:48:28) Run:1
Running from C:\Users\Michal\Desktop
Loaded Profiles: Michal (Available Profiles: Michal)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
StartRegedit:
[HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=dword:00000000
EndRegedit:
cmd: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost"
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.com/ww.special-uninstall ... gBQAEEATgA"&"inst=NwA3AC0AMwA0AD (the data entry has 109 more characters).
Winlogon\Notify\xranhgo-x32: C:\Users\Michal\AppData\Local\xranhgo.dll [X]
File: C:\Users\Michal\AppData\Local\xranhgo.dll
C:\Users\Michal\AppData\Local\xranhgo.dll
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9108184 2016-11-07] (Piriform Ltd)
HKLM\...\Providers\jelxymt5: C:\Program Files (x86)\Adobe\\local64spl.dll [142848 2016-12-10] ()
File: C:\Program Files (x86)\Adobe\\local64spl.dll
C:\Program Files (x86)\Adobe\\local64spl.dll
ShellExecuteHooks: - {4A39289E-AB73-11E6-B57F-64006A5CFC23} - C:\Users\Michal\AppData\Roaming\Graqsp\Kerich.dll [145920 2016-12-09] ()
File: C:\Users\Michal\AppData\Roaming\Graqsp\Kerich.dll
C:\Users\Michal\AppData\Roaming\Graqsp
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
GroupPolicy: Restriction - Chrome <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG9\avgssiea.dll => No File
C:\Program Files (x86)\AVG
cmd: type "C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\user.js"
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\crsahtbq.default -> luck
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\crsahtbq.default -> luck
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\crsahtbq.default -> Bing
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\crsahtbq.default -> luck
FF Keyword.URL: Mozilla\Firefox\Profiles\crsahtbq.default -> hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q=
FF Extension: (No Name) - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\extensions\arthurj8283@gmail.com [not found]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\searchplugins\luck.xml [2016-12-12]
cmd: type "C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\user.js"
FF DefaultSearchEngine: Firefox\Firefox\Profiles\crsahtbq.default -> luck
FF SearchEngineOrder.1: Firefox\Firefox\Profiles\crsahtbq.default -> luck
FF SearchEngineOrder.3: Firefox\Firefox\Profiles\crsahtbq.default -> Bing
FF SelectedSearchEngine: Firefox\Firefox\Profiles\crsahtbq.default -> luck
FF Keyword.URL: Firefox\Firefox\Profiles\crsahtbq.default -> hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q=
FF Extension: (FF Adr) - C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2016-12-10] [not signed]
FF Extension: (xRocket Toolbar) - C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\arthurj8283@gmail.com [2016-12-12] [not signed]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\luck.xml [2016-12-12]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\searchinme.xml [2016-12-10]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\zmlfca7u.xml [2016-12-09]
File: C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
R2 Convxxxx; C:\Users\Michal\AppData\Roaming\cfjcf\UvConverter.exe [403968 2016-12-07] () [File not signed]
File: C:\Users\Michal\AppData\Roaming\cfjcf\UvConverter.exe
C:\Users\Michal\AppData\Roaming\cfjcf
R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [100352 2016-12-12] () [File not signed]
U0 aswVmm; no ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
Folder: C:\Users\Michal\AppData\Local\Tempzxpsigneb139762080477ae
Folder: C:\Users\Michal\AppData\Local\Tempzxpsigne52d9fbe0f737919
2016-12-12 13:19 - 2016-12-12 13:19 - 01323520 _____ C:\Users\Michal\Downloads\RSITx64.exe
2016-12-12 13:19 - 2016-12-12 13:19 - 00000000 ____D C:\rsit
2016-12-12 12:37 - 2016-12-12 12:37 - 00000000 ____D C:\Program Files (x86)\amuleC1
2016-12-10 09:18 - 2016-12-17 08:22 - 00000000 _____ C:\Users\Public\Documents\report.dat
2016-12-10 09:18 - 2016-12-12 12:38 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2016-12-10 09:12 - 2016-12-10 09:12 - 00000000 ____D C:\Users\Michal\Documents\aMule Downloads
2016-12-10 09:01 - 2016-12-10 09:12 - 00000000 ____D C:\Users\Michal\AppData\Roaming\aMule
2016-12-10 09:01 - 2016-12-10 09:01 - 00000000 ____D C:\Users\Michal\AppData\Roaming\cfjcf
2016-12-10 08:56 - 2016-12-12 12:33 - 00000000 ____D C:\Program Files (x86)\ft1xx095
Folder: C:\ProgramData\Avira
2016-12-09 17:50 - 2016-12-09 17:50 - 00006050 _____ C:\Windows\System32\Tasks\Vuktionliqat Helper
2016-12-09 17:50 - 2016-12-09 17:50 - 00003530 _____ C:\Windows\System32\Tasks\54f4f7b41a6f7a369d678a5e04483ba2
2016-12-09 17:49 - 2016-12-12 12:49 - 00000000 ____D C:\Program Files (x86)\Merpetionannage
2016-12-09 17:49 - 2016-12-09 17:50 - 00000000 ____D C:\Users\Michal\AppData\Local\Smedom
2016-12-09 17:49 - 2016-12-09 17:49 - 00000000 ____D C:\Users\Michal\AppData\Roaming\Graqsp
2016-11-19 15:20 - 2016-12-12 13:19 - 00000000 ____D C:\Program Files\trend micro
Folder: C:\f74ac6a2e4cd4e3b05d865d22c91ca77
Folder: C:\065499413fda718ad23a4eeb3e452f
Folder: C:\ProgramData\AVAST Software
2016-11-21 19:43 - 2016-12-09 17:51 - 00000000 ____D C:\ProgramData\Avg
2016-11-21 19:42 - 2016-11-21 20:13 - 00000000 ____D C:\Users\Michal\AppData\Local\AvgSetupLog
2016-11-21 19:42 - 2016-11-21 19:42 - 00000000 ____D C:\Users\Michal\AppData\Local\Avg
2016-12-09 17:51 - 2016-10-28 10:16 - 00000000 ____D C:\ProgramData\AVAST Software
2016-12-09 17:50 - 2016-10-07 14:25 - 00000000 ____D C:\Program Files (x86)\AVG
Task: {43A81866-A5C4-44F9-8EB6-F43090120092} - System32\Tasks\{9FEBF33B-2074-414C-8502-E337530B2EEE} => pcalua.exe -a "C:\Users\Michal\Desktop\Nový priečinok\Windows.Media.Player.12.v.2.CZ..exe" -d "C:\Users\Michal\Desktop\Nový priečinok"
Task: {898120DD-BF52-4B72-ACAB-45372AEE08B5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-10-28] (AVAST Software)
Task: {917AB143-3543-4ED5-86D1-DAE72919DC3A} - System32\Tasks\{ED0C19EC-E733-47DA-A367-34EAE657BBBF} => pcalua.exe -a C:\Users\Michal\Desktop\wsusoffline\client\cpp\vcredist2008_x64.exe -d C:\Users\Michal\Desktop\wsusoffline\client\cpp
Task: {D33665A0-6187-430A-A0AD-41B0FF27D0EB} - System32\Tasks\54f4f7b41a6f7a369d678a5e04483ba2 => Rundll32.exe "C:\Program Files (x86)\Common Files\elxymt.dll",e62dc6c6547f46bda862da2d05af6862 <==== ATTENTION
File: C:\Program Files (x86)\Merpetionannage\copay.exe
Folder: C:\Program Files (x86)\Merpetionannage
C:\Program Files (x86)\Merpetionannage
File: C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
File: C:\Program Files (x86)\SrpnFiles\downloader.exe
Folder: C:\Program Files (x86)\SrpnFiles
C:\Program Files (x86)\SrpnFiles
FirewallRules: [{F659C450-8F90-4046-A97E-1180E871D417}] => C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{0B8B91FE-FEBA-440A-A18C-3C6BE8C5DA64}] => C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{1222AFB4-9C0C-4EDA-8C20-13C097DD10F4}] => C:\Program Files (x86)\SrpnFiles\downloader.exe
FirewallRules: [{6779D280-A173-47C3-8F50-16A2B0B6246B}] => C:\Program Files (x86)\SrpnFiles\downloader.exe
File: C:\program files (x86)\brackets\node.exe
FirewallRules: [{D960489A-096B-4277-B260-B3A53D48840B}] => C:\Windows\system32\rundll32.exe
FirewallRules: [{D0EEFAF9-098E-47B6-9B63-7350707B6846}] => C:\Windows\system32\rundll32.exe
FirewallRules: [TCP Query User{8DD6A48A-6951-45BC-AEFC-F01B5F82D210}C:\windows\syswow64\rundll32.exe] => C:\windows\syswow64\rundll32.exe
FirewallRules: [UDP Query User{22D498AC-C9A7-4644-8629-2152CFF322E4}C:\windows\syswow64\rundll32.exe] => C:\windows\syswow64\rundll32.exe
FirewallRules: [{1B40F44E-E1D2-4215-92FA-39146AD5B265}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{63F33A42-180C-41E1-BCF6-57335200B66A}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{365856DD-96B8-4104-9F77-79233DA5E047}] => C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{4881B295-8618-4ECF-A9F4-87F43A7AD39E}] => C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{5BD9BFF5-B75A-4C45-9DDC-58FF8D31CBB6}] => C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{190C0C9C-33C1-4DCD-AF81-C64EC28370D9}] => C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [TCP Query User{76B13A3E-8F9B-4C28-91DB-0C9AA6127DB7}C:\program files (x86)\amulec1\amule.exe] => C:\program files (x86)\amulec1\amule.exe
FirewallRules: [UDP Query User{23CA4E45-1996-47BC-8004-407722F3B376}C:\program files (x86)\amulec1\amule.exe] => C:\program files (x86)\amulec1\amule.exe
FirewallRules: [{B8155EEF-AFCA-4B69-AC19-4053C03B567C}] => C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
FirewallRules: [{6114AE8A-EA9C-4BBF-B064-BB4015DEE52A}] => C:\Program Files (x86)\Firefox\Firefox.exe
File: C:\Program Files (x86)\Firefox\Firefox.exe
File: C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
CMD: dir "C:\Windows\System32\Tasks"
CMD: dir "C:\PROGRA~1"
CMD: dir "C:\PROGRA~2"
CMD: dir "C:\PROGRA~3"
CMD: dir "%localappdata%"
CMD: dir "%appdata%"
Hosts:
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
====> Registry
========= reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost" =========
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost
netsvcs REG_MULTI_SZ AeLookupSvc\0CertPropSvc\0SCPolicySvc\0lanmanserver\0gpsvc\0AudioSrv\0FastUserSwitchingCompatibility\0Ias\0Irmon\0Nla\0Ntmssvc\0NWCWorkstation\0Nwsapagent\0Rasauto\0Rasman\0Remoteaccess\0SENS\0Sharedaccess\0SRService\0Tapisrv\0Wmi\0WmdmPmSp\0TermService\0wuauserv\0BITS\0ShellHWDetection\0LogonHours\0PCAudit\0helpsvc\0uploadmgr\0iphlpsvc\0msiscsi\0schedule\0SessionEnv\0winmgmt\0AppMgmt
LocalService REG_MULTI_SZ RemoteRegistry\0WinHttpAutoProxySvc\0sppuinotify\0netprofm\0WebClient
LocalSystemNetworkRestricted REG_MULTI_SZ Netman\0AudioEndpointBuilder\0dot3svc\0wlansvc\0WPDBusEnum
LocalServiceNoNetwork REG_MULTI_SZ PLA
rpcss REG_MULTI_SZ RpcSs
LocalServiceNetworkRestricted REG_MULTI_SZ AudioSrv\0BthHFSrv\0LmHosts\0wscsvc\0WPCSvc
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV\0upnphost\0SCardSvr\0QWAVE\0wcncsvc
DcomLaunch REG_MULTI_SZ Power\0PlugPlay\0DcomLaunch
NetworkService REG_MULTI_SZ CryptSvc\0DHCP\0TermService\0DNSCache\0NapAgent\0nlasvc\0WinRM\0WECSVC\0Tapisrv
imgsvc REG_MULTI_SZ StiSvc
wcssvc REG_MULTI_SZ WcsPlugInService
Musadom REG_MULTI_SZ Musadom
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNetworkRestricted
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNoNetwork
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopHyperVAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopPublishing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\termsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\wcssvc
========= End of CMD: =========
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\AvgUninstallURL => value removed successfully
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xranhgo" => key removed successfully
========================= File: C:\Users\Michal\AppData\Local\xranhgo.dll ========================
"C:\Users\Michal\AppData\Local\xranhgo.dll" => not found.
====== End of File: ======
"C:\Users\Michal\AppData\Local\xranhgo.dll" => not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => value removed successfully
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
"HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\jelxymt5" => key removed successfully
HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\\order jelxymt5 could not remove.
========================= File: C:\Program Files (x86)\Adobe\\local64spl.dll ========================
File not signed
MD5: DB8C644FCF5BA2B948643FD02D13041B
Creation and modification date: 2016-12-10 09:50 - 2016-12-10 17:50
Size: 0142848
Attributes: ----H
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
C:\Program Files (x86)\Adobe\\local64spl.dll => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{4A39289E-AB73-11E6-B57F-64006A5CFC23} => value removed successfully
"HKCR\CLSID\{4A39289E-AB73-11E6-B57F-64006A5CFC23}" => key removed successfully
========================= File: C:\Users\Michal\AppData\Roaming\Graqsp\Kerich.dll ========================
File not signed
MD5: 79DBA1067B2275915A82D1A164F0790E
Creation and modification date: 2016-12-09 17:49 - 2016-12-09 17:49
Size: 0145920
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
C:\Users\Michal\AppData\Roaming\Graqsp => moved successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" => key removed successfully
"HKCR\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" => key removed successfully
C:\Program Files (x86)\AVG => moved successfully
========= type "C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\user.js" =========
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
*/
user_pref("browser.search.defaultenginename", "luck");
user_pref("browser.search.order.1", "luck");
user_pref("browser.search.searchengine.alias", "");
user_pref("browser.search.searchengine.name", "luck");
user_pref("browser.search.searchengine.ref", "");
user_pref("browser.search.searchengine.ts", "1481542656");
user_pref("browser.search.searchengine.type", "");
user_pref("browser.search.searchengine.uid", "st500lm000-1ej162_w370kzblxxxxw370kzbl");
user_pref("browser.search.selectedEngine", "luck");
user_pref("browser.search.useDBForOrder", true);
user_pref("browser.sessionstore.max_tabs_undo", 0);
user_pref("browser.sessionstore.max_windows_undo", 0);
user_pref("browser.sessionstore.resume_from_crash", false);
user_pref("browser.sessionstore.resume_session_once", false);
========= End of CMD: =========
Firefox DefaultSearchEngine removed successfully
Firefox SearchEngineOrder.1 removed successfully
Firefox SearchEngineOrder.3 removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox "Keyword.URL" removed successfully
C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\extensions\arthurj8283@gmail.com => path removed successfully
C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\searchplugins\luck.xml => moved successfully
========= type "C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\user.js" =========
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
*/
user_pref("browser.search.defaultenginename", "luck");
user_pref("browser.search.order.1", "luck");
user_pref("browser.search.searchengine.alias", "");
user_pref("browser.search.searchengine.name", "luck");
user_pref("browser.search.searchengine.ref", "");
user_pref("browser.search.searchengine.ts", "1481542656");
user_pref("browser.search.searchengine.type", "");
user_pref("browser.search.searchengine.uid", "st500lm000-1ej162_w370kzblxxxxw370kzbl");
user_pref("browser.search.selectedEngine", "luck");
user_pref("browser.search.useDBForOrder", true);
user_pref("browser.sessionstore.max_tabs_undo", 0);
user_pref("browser.sessionstore.max_windows_undo", 0);
user_pref("browser.sessionstore.resume_from_crash", false);
user_pref("browser.sessionstore.resume_session_once", false);
========= End of CMD: =========
Firefox DefaultSearchEngine removed successfully
Firefox SearchEngineOrder.1 removed successfully
Firefox SearchEngineOrder.3 removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox "Keyword.URL" removed successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi => moved successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\arthurj8283@gmail.com => moved successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\arthurj8283@gmail.com => path removed successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\luck.xml => moved successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\searchinme.xml => moved successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\zmlfca7u.xml => moved successfully
========================= File: C:\Program Files (x86)\Bluetooth Suite\adminservice.exe ========================
File not signed
MD5: A917E4F753B90A5181ECBFA56D5C154A
Creation and modification date: 2013-01-24 23:12 - 2013-01-24 23:12
Size: 0227456
Attributes: ----A
Company Name: Qualcomm Atheros Commnucations
Internal Name: AdminService
Original Name: AdminService.exe
Product: Bluetooth Software
Description: AdminService Application
File Version: 8.0.0.220
Product Version: 8.0.0.220
Copyright: Copyright (c) 2001-2010 Qualcomm Atheros Communications, Inc. All rights reserved.
====== End of File: ======
Convxxxx => service removed successfully
========================= File: C:\Users\Michal\AppData\Roaming\cfjcf\UvConverter.exe ========================
File not signed
MD5: A1D70DA7E4A94E51DB76CF9D58D5B8B4
Creation and modification date: 2016-12-10 09:01 - 2016-12-07 11:54
Size: 0403968
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
C:\Users\Michal\AppData\Roaming\cfjcf => moved successfully
FirefoxU => service removed successfully
aswVmm => service removed successfully
catchme => service removed successfully
========================= Folder: C:\Users\Michal\AppData\Local\Tempzxpsigneb139762080477ae ========================
====== End of Folder: ======
========================= Folder: C:\Users\Michal\AppData\Local\Tempzxpsigne52d9fbe0f737919 ========================
====== End of Folder: ======
C:\Users\Michal\Downloads\RSITx64.exe => moved successfully
C:\rsit => moved successfully
C:\Program Files (x86)\amuleC1 => moved successfully
C:\Users\Public\Documents\report.dat => moved successfully
C:\Users\Public\Documents\temp.dat => moved successfully
C:\Users\Michal\Documents\aMule Downloads => moved successfully
C:\Users\Michal\AppData\Roaming\aMule => moved successfully
"C:\Users\Michal\AppData\Roaming\cfjcf" => not found.
C:\Program Files (x86)\ft1xx095 => moved successfully
========================= Folder: C:\ProgramData\Avira ========================
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\Avira\AntiVir Desktop
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\Avira\AntiVir Desktop\CONFIG
2016-12-09 17:51 - 2016-12-09 17:51 - 0000494 _____ () C:\ProgramData\Avira\AntiVir Desktop\CONFIG\AVWIN.INI
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\Avira\Antivirus
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\Avira\Antivirus\CONFIG
2016-12-09 17:51 - 2016-12-09 17:51 - 0000494 _____ () C:\ProgramData\Avira\Antivirus\CONFIG\AVWIN.INI
====== End of Folder: ======
C:\Windows\System32\Tasks\Vuktionliqat Helper => moved successfully
C:\Windows\System32\Tasks\54f4f7b41a6f7a369d678a5e04483ba2 => moved successfully
C:\Program Files (x86)\Merpetionannage => moved successfully
C:\Users\Michal\AppData\Local\Smedom => moved successfully
"C:\Users\Michal\AppData\Roaming\Graqsp" => not found.
C:\Program Files\trend micro => moved successfully
========================= Folder: C:\f74ac6a2e4cd4e3b05d865d22c91ca77 ========================
2016-11-18 16:36 - 2016-02-13 18:16 - 22011749 _____ () C:\f74ac6a2e4cd4e3b05d865d22c91ca77\Windows6.1-KB3134760-x64.cab
2016-11-18 16:36 - 2016-02-13 18:17 - 0000498 _____ () C:\f74ac6a2e4cd4e3b05d865d22c91ca77\Windows6.1-KB3134760-x64.xml
2016-11-18 16:36 - 2016-02-13 18:17 - 0000395 _____ () C:\f74ac6a2e4cd4e3b05d865d22c91ca77\Windows6.1-KB3134760-x64-pkgProperties.txt
2016-11-18 16:36 - 2016-02-13 18:18 - 0198044 _____ () C:\f74ac6a2e4cd4e3b05d865d22c91ca77\WSUSSCAN.cab
====== End of Folder: ======
========================= Folder: C:\065499413fda718ad23a4eeb3e452f ========================
2016-11-18 15:24 - 2016-01-11 16:10 - 3177773 _____ () C:\065499413fda718ad23a4eeb3e452f\Windows6.1-KB3135445-x64.cab
2016-11-18 15:24 - 2016-01-11 16:11 - 0000446 _____ () C:\065499413fda718ad23a4eeb3e452f\Windows6.1-KB3135445-x64.xml
2016-11-18 15:24 - 2016-01-11 16:11 - 0000521 _____ () C:\065499413fda718ad23a4eeb3e452f\Windows6.1-KB3135445-x64-pkgProperties.txt
2016-11-18 15:24 - 2016-01-11 16:19 - 0181156 _____ () C:\065499413fda718ad23a4eeb3e452f\WSUSSCAN.cab
====== End of Folder: ======
========================= Folder: C:\ProgramData\AVAST Software ========================
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\AVAST Software\Avast
2016-12-09 17:51 - 2016-12-09 17:51 - 0000312 _____ () C:\ProgramData\AVAST Software\Avast\exclusions.ini
2016-10-28 10:16 - 2016-10-28 10:16 - 0000000 ____D () C:\ProgramData\AVAST Software\Persistent Data
2016-10-28 10:16 - 2016-10-30 09:17 - 0000000 ____D () C:\ProgramData\AVAST Software\Persistent Data\Avast
2016-10-28 10:16 - 2016-10-28 10:20 - 0000000 ____D () C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs
2016-10-28 10:16 - 2016-10-29 08:44 - 0005921 _____ () C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\event_manager.log
2016-10-28 10:16 - 2016-10-28 10:20 - 0976174 ____C () C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log
2016-10-28 10:20 - 2016-10-29 08:44 - 3020140 ____C () C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log
====== End of Folder: ======
C:\ProgramData\Avg => moved successfully
C:\Users\Michal\AppData\Local\AvgSetupLog => moved successfully
C:\Users\Michal\AppData\Local\Avg => moved successfully
C:\ProgramData\AVAST Software => moved successfully
"C:\Program Files (x86)\AVG" => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{43A81866-A5C4-44F9-8EB6-F43090120092}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{43A81866-A5C4-44F9-8EB6-F43090120092}" => key removed successfully
C:\Windows\System32\Tasks\{9FEBF33B-2074-414C-8502-E337530B2EEE} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9FEBF33B-2074-414C-8502-E337530B2EEE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{898120DD-BF52-4B72-ACAB-45372AEE08B5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{898120DD-BF52-4B72-ACAB-45372AEE08B5}" => key removed successfully
C:\Windows\System32\Tasks\AVAST Software\Avast settings backup => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software\Avast settings backup" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{917AB143-3543-4ED5-86D1-DAE72919DC3A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{917AB143-3543-4ED5-86D1-DAE72919DC3A}" => key removed successfully
C:\Windows\System32\Tasks\{ED0C19EC-E733-47DA-A367-34EAE657BBBF} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{ED0C19EC-E733-47DA-A367-34EAE657BBBF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D33665A0-6187-430A-A0AD-41B0FF27D0EB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D33665A0-6187-430A-A0AD-41B0FF27D0EB}" => key removed successfully
C:\Windows\System32\Tasks\54f4f7b41a6f7a369d678a5e04483ba2 => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\54f4f7b41a6f7a369d678a5e04483ba2" => key removed successfully
========================= File: C:\Program Files (x86)\Merpetionannage\copay.exe ========================
"C:\Program Files (x86)\Merpetionannage\copay.exe" => not found.
====== End of File: ======
========================= Folder: C:\Program Files (x86)\Merpetionannage ========================
not found.
====== End of Folder: ======
"C:\Program Files (x86)\Merpetionannage" => not found.
========================= File: C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe ========================
"C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe" => not found.
====== End of File: ======
========================= File: C:\Program Files (x86)\SrpnFiles\downloader.exe ========================
"C:\Program Files (x86)\SrpnFiles\downloader.exe" => not found.
====== End of File: ======
========================= Folder: C:\Program Files (x86)\SrpnFiles ========================
not found.
====== End of Folder: ======
"C:\Program Files (x86)\SrpnFiles" => not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F659C450-8F90-4046-A97E-1180E871D417} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0B8B91FE-FEBA-440A-A18C-3C6BE8C5DA64} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1222AFB4-9C0C-4EDA-8C20-13C097DD10F4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6779D280-A173-47C3-8F50-16A2B0B6246B} => value removed successfully
========================= File: C:\program files (x86)\brackets\node.exe ========================
"C:\program files (x86)\brackets\node.exe" => not found.
====== End of File: ======
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D960489A-096B-4277-B260-B3A53D48840B} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D0EEFAF9-098E-47B6-9B63-7350707B6846} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8DD6A48A-6951-45BC-AEFC-F01B5F82D210}C:\windows\syswow64\rundll32.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{22D498AC-C9A7-4644-8629-2152CFF322E4}C:\windows\syswow64\rundll32.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1B40F44E-E1D2-4215-92FA-39146AD5B265} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{63F33A42-180C-41E1-BCF6-57335200B66A} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{365856DD-96B8-4104-9F77-79233DA5E047} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4881B295-8618-4ECF-A9F4-87F43A7AD39E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5BD9BFF5-B75A-4C45-9DDC-58FF8D31CBB6} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{190C0C9C-33C1-4DCD-AF81-C64EC28370D9} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{76B13A3E-8F9B-4C28-91DB-0C9AA6127DB7}C:\program files (x86)\amulec1\amule.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{23CA4E45-1996-47BC-8004-407722F3B376}C:\program files (x86)\amulec1\amule.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B8155EEF-AFCA-4B69-AC19-4053C03B567C} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6114AE8A-EA9C-4BBF-B064-BB4015DEE52A} => value removed successfully
========================= File: C:\Program Files (x86)\Firefox\Firefox.exe ========================
File not signed
MD5: F0425A2AEA6AB764D3E7B6EC8E8D3A74
Creation and modification date: 2016-12-12 12:54 - 2016-12-12 03:46
Size: 0492544
Attributes: ----A
Company Name: Mozilla Corporation
Internal Name: Firefox
Original Name: Firefox.exe
Product: Firefox
Description: Firefox
File Version: 50.0
Product Version: 50.0
Copyright: Firefox and Mozilla Developers; available under the MPL 2 license.
====== End of File: ======
========================= File: C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe ========================
File not signed
MD5: D1D91682A1F1AAB35B54DDC5273EE7DC
Creation and modification date: 2016-12-12 12:54 - 2016-12-12 07:31
Size: 0100352
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product: Firefox
Description: Firefox
File Version: 50.0.8.336
Product Version: 50.0.8.336
Copyright: Copyright (C) 2016 Firefox Authors
====== End of File: ======
========= dir "C:\Windows\System32\Tasks" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\Windows\System32\Tasks
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
08. 11. 2016 12:31 4˙476 Adobe Acrobat Update Task
13. 12. 2016 12:46 3˙768 Adobe Flash Player Updater
17. 12. 2016 10:48 <DIR> AVAST Software
16. 11. 2016 17:12 2˙794 CCleanerSkipUAC
16. 12. 2016 22:10 3˙240 GoogleUpdateTaskMachineCore
16. 12. 2016 22:10 3˙368 GoogleUpdateTaskMachineUA
16. 10. 2016 09:43 3˙620 HPCustParticipation HP Deskjet 1510 series
18. 11. 2016 16:45 <DIR> Microsoft
08. 10. 2016 15:37 <DIR> OfficeSoftwareProtectionPlatform
22. 11. 2016 13:30 <DIR> WPD
6 File(s) 21˙266 bytes
6 Dir(s) 288˙364˙494˙848 bytes free
========= End of CMD: =========
========= dir "C:\PROGRA~1" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\PROGRA~1
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
16. 11. 2016 21:13 <DIR> Adobe
07. 10. 2016 14:13 <DIR> ATI
07. 10. 2016 14:14 <DIR> ATI Technologies
16. 11. 2016 17:12 <DIR> CCleaner
09. 10. 2016 09:43 <DIR> Cisco Packet Tracer 7.0
23. 11. 2016 17:43 <DIR> Common Files
07. 10. 2016 13:53 <DIR> CONEXANT
07. 10. 2016 14:04 <DIR> DIFX
19. 11. 2016 13:34 <DIR> DVD Maker
07. 10. 2016 13:41 <DIR> Elantech
16. 10. 2016 09:40 <DIR> HP
07. 10. 2016 13:39 <DIR> Intel
08. 10. 2016 10:33 <DIR> Intel Security
18. 11. 2016 19:27 <DIR> Internet Explorer
07. 10. 2016 14:04 <DIR> Lenovo
08. 10. 2016 15:31 <DIR> Microsoft Office
18. 11. 2016 08:50 <DIR> Microsoft Silverlight
14. 07. 2009 06:38 <DIR> MSBuild
17. 10. 2016 14:48 <DIR> Oracle
14. 07. 2009 06:38 <DIR> Reference Assemblies
18. 11. 2016 17:59 <DIR> Windows Defender
12. 04. 2011 14:29 <DIR> Windows Mail
20. 11. 2016 15:35 <DIR> Windows Media Player
14. 07. 2009 06:38 <DIR> Windows NT
12. 04. 2011 14:29 <DIR> Windows Photo Viewer
19. 11. 2016 13:34 <DIR> Windows Portable Devices
12. 04. 2011 14:29 <DIR> Windows Sidebar
19. 11. 2016 10:00 <DIR> WindowsPowerShell
08. 10. 2016 12:25 <DIR> WinRAR
0 File(s) 0 bytes
31 Dir(s) 288˙364˙494˙848 bytes free
========= End of CMD: =========
========= dir "C:\PROGRA~2" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\PROGRA~2
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
17. 12. 2016 10:48 <DIR> Adobe
09. 12. 2016 17:50 <DIR> AMD APP
09. 12. 2016 17:50 <DIR> AMD AVT
10. 12. 2016 13:16 <DIR> AnthemScore
09. 12. 2016 17:50 <DIR> ATI Technologies
09. 12. 2016 17:50 <DIR> Audacity
09. 12. 2016 17:50 <DIR> Bluetooth Suite
09. 12. 2016 17:50 <DIR> Brackets
09. 12. 2016 17:50 <DIR> Cisco
14. 12. 2016 20:28 <DIR> Common Files
09. 12. 2016 17:50 <DIR> DAEMON Tools Lite
14. 12. 2016 20:31 <DIR> Firefox
09. 12. 2016 17:50 <DIR> Google
09. 12. 2016 17:51 <DIR> Hewlett-Packard
09. 12. 2016 17:50 <DIR> HP
09. 12. 2016 17:50 <DIR> HP Photo Creations
09. 12. 2016 17:50 <DIR> Intel
09. 12. 2016 17:50 <DIR> Internet Explorer
09. 12. 2016 17:51 <DIR> JSignPdf
09. 12. 2016 17:50 <DIR> K-Lite Codec Pack
09. 12. 2016 17:50 <DIR> Lenovo
09. 12. 2016 17:50 <DIR> McAfee
09. 12. 2016 17:50 <DIR> Microsoft Analysis Services
09. 12. 2016 17:50 <DIR> Microsoft Office
09. 12. 2016 17:50 <DIR> Microsoft Silverlight
09. 12. 2016 17:50 <DIR> Microsoft SQL Server Compact Edition
09. 12. 2016 17:50 <DIR> Microsoft Sync Framework
09. 12. 2016 17:50 <DIR> Microsoft Synchronization Services
09. 12. 2016 17:50 <DIR> Microsoft Visual Studio 8
09. 12. 2016 17:50 <DIR> Microsoft.NET
10. 12. 2016 11:20 <DIR> Mozilla Firefox
11. 12. 2016 09:05 <DIR> Mozilla Maintenance Service
09. 12. 2016 17:50 <DIR> MSBuild
10. 12. 2016 13:16 <DIR> MuseScore 2
09. 12. 2016 17:50 <DIR> Neuratron
10. 12. 2016 09:41 <DIR> Neuratron AudioScore Ultimate Demo
09. 12. 2016 17:50 <DIR> Notepad++
09. 12. 2016 17:51 <DIR> Opera
09. 12. 2016 17:50 <DIR> Qualcomm Atheros
09. 12. 2016 17:50 <DIR> Realtek
09. 12. 2016 17:50 <DIR> Reference Assemblies
09. 12. 2016 17:50 <DIR> Renesas Electronics
09. 12. 2016 17:50 <DIR> RightMark
10. 12. 2016 11:39 <DIR> ScoreCloud Studio
09. 12. 2016 17:50 <DIR> Sibelius Software
09. 12. 2016 17:50 <DIR> Skype
09. 12. 2016 17:50 <DIR> The Witcher 3 Wild Hunt Blood and Wine
09. 12. 2016 17:50 <DIR> VideoLAN
09. 12. 2016 17:50 <DIR> Windows Defender
09. 12. 2016 17:50 <DIR> Windows Mail
09. 12. 2016 17:50 <DIR> Windows Media Player
09. 12. 2016 17:50 <DIR> Windows NT
09. 12. 2016 17:50 <DIR> Windows Photo Viewer
09. 12. 2016 17:50 <DIR> Windows Portable Devices
09. 12. 2016 17:50 <DIR> Windows Sidebar
09. 12. 2016 17:50 <DIR> WindowsPowerShell
0 File(s) 0 bytes
58 Dir(s) 288˙364˙490˙752 bytes free
========= End of CMD: =========
========= dir "C:\PROGRA~3" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\PROGRA~3
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
09. 12. 2016 15:31 <DIR> Acoustica
23. 11. 2016 18:41 <DIR> Adobe
07. 10. 2016 14:15 <DIR> AMD
16. 10. 2016 09:40 57 Ament.ini
18. 11. 2016 09:41 <DIR> Atheros
07. 10. 2016 14:27 <DIR> ATI
09. 12. 2016 17:51 <DIR> Avira
07. 10. 2016 13:50 <DIR> Conexant
07. 10. 2016 14:19 <DIR> DAEMON Tools Lite
07. 10. 2016 14:02 <DIR> Downloaded Installations
16. 10. 2016 09:42 <DIR> HP
16. 10. 2016 09:43 <DIR> HP Photo Creations
07. 10. 2016 13:48 <DIR> Intel
08. 10. 2016 10:44 <DIR> McAfee
22. 11. 2016 13:29 <DIR> MFAData
20. 11. 2016 16:47 <DIR> Microsoft Help
23. 11. 2016 17:43 <DIR> Package Cache
07. 10. 2016 13:36 <DIR> Qualcomm Atheros
07. 10. 2016 13:35 <DIR> Roaming
08. 12. 2016 08:42 <DIR> Skype
16. 10. 2016 09:43 <DIR> Visan
1 File(s) 57 bytes
22 Dir(s) 288˙364˙486˙656 bytes free
========= End of CMD: =========
========= dir "%localappdata%" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\Users\Michal\AppData\Local
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
25. 11. 2016 10:35 <DIR> Adobe
10. 12. 2016 14:12 <DIR> AnthemScore
07. 10. 2016 17:23 <DIR> Apps
07. 10. 2016 14:27 <DIR> ATI
07. 10. 2016 14:10 <DIR> BMExplorer
07. 10. 2016 17:51 <DIR> CEF
14. 12. 2016 20:18 <DIR> CrashDumps
10. 12. 2016 13:01 <DIR> Deployment
23. 11. 2016 07:18 <DIR> Diagnostics
17. 11. 2016 09:48 <DIR> ElevatedDiagnostics
10. 12. 2016 09:21 <DIR> Firefox
10. 12. 2016 12:08 124˙608 GDIPFONTCACHEV1.DAT
04. 11. 2016 08:38 <DIR> Google
16. 10. 2016 09:43 <DIR> HP
08. 10. 2016 10:48 <DIR> Macromedia
21. 11. 2016 19:44 <DIR> MFAData
29. 11. 2016 13:15 <DIR> Microsoft
15. 11. 2016 17:55 <DIR> Microsoft Help
07. 10. 2016 17:22 <DIR> Mozilla
10. 12. 2016 13:16 <DIR> MuseScore
07. 10. 2016 14:17 <DIR> Programs
19. 11. 2016 09:36 7˙605 Resmon.ResmonCfg
17. 12. 2016 10:48 <DIR> Temp
25. 11. 2016 16:11 <DIR> Tempzxpsign0129c5ea464d1bd0
29. 11. 2016 12:41 <DIR> Tempzxpsign0869e5917f164ad8
07. 12. 2016 19:18 <DIR> Tempzxpsign08708443e994ca5f
02. 12. 2016 08:35 <DIR> Tempzxpsign089f88d9de54e320
01. 12. 2016 14:28 <DIR> Tempzxpsign093bb2eebf52505b
23. 11. 2016 18:12 <DIR> Tempzxpsign0b64d6facd5b380b
01. 12. 2016 14:47 <DIR> Tempzxpsign0c6c77f61ea482b9
25. 11. 2016 14:33 <DIR> Tempzxpsign0d50ec84559762e7
25. 11. 2016 10:49 <DIR> Tempzxpsign0e05eb4c4a3dcf5f
30. 11. 2016 18:23 <DIR> Tempzxpsign0e2689382ab7988b
01. 12. 2016 14:05 <DIR> Tempzxpsign0f35eaf1cde8fff5
25. 11. 2016 09:30 <DIR> Tempzxpsign1054cf807590fa05
25. 11. 2016 09:26 <DIR> Tempzxpsign16e3469ef7cbb3d5
25. 11. 2016 14:33 <DIR> Tempzxpsign1a19d272fff3af72
08. 12. 2016 14:26 <DIR> Tempzxpsign1a4957ae9e010c42
01. 12. 2016 14:33 <DIR> Tempzxpsign2030b3848e1630f2
25. 11. 2016 16:50 <DIR> Tempzxpsign22fbe70e649a2567
08. 12. 2016 09:09 <DIR> Tempzxpsign2368e15f51aa66f0
07. 12. 2016 19:18 <DIR> Tempzxpsign26187949b09a3374
24. 11. 2016 16:05 <DIR> Tempzxpsign29d1708b5d4b643f
30. 11. 2016 18:31 <DIR> Tempzxpsign2ae16539ec40858b
26. 11. 2016 17:11 <DIR> Tempzxpsign2c2cd75c0b565547
26. 11. 2016 17:14 <DIR> Tempzxpsign2e2e77420baffa19
26. 11. 2016 18:30 <DIR> Tempzxpsign315e73162b4dc7e7
25. 11. 2016 10:43 <DIR> Tempzxpsign327e396fd5df5acb
25. 11. 2016 16:12 <DIR> Tempzxpsign3322123ed736752e
08. 12. 2016 09:09 <DIR> Tempzxpsign3431ccb9f2be5af8
25. 11. 2016 09:30 <DIR> Tempzxpsign357a12175afd1c22
25. 11. 2016 16:17 <DIR> Tempzxpsign36c0d5a735365b31
25. 11. 2016 16:12 <DIR> Tempzxpsign36e3f51eedc3d245
25. 11. 2016 14:33 <DIR> Tempzxpsign37ee5b7be7723430
29. 11. 2016 15:42 <DIR> Tempzxpsign38237170c6290eb9
25. 11. 2016 16:11 <DIR> Tempzxpsign3c6005916f9dd753
23. 11. 2016 18:02 <DIR> Tempzxpsign3e3f66ca8c66aa74
01. 12. 2016 09:50 <DIR> Tempzxpsign3f0c97113d683f5b
07. 12. 2016 19:10 <DIR> Tempzxpsign4049943a7c9bee0e
25. 11. 2016 10:49 <DIR> Tempzxpsign447d2b9e4e81afab
26. 11. 2016 18:30 <DIR> Tempzxpsign44f91b5941852f0a
24. 11. 2016 16:04 <DIR> Tempzxpsign49eb3cd7f4b7f320
04. 12. 2016 15:26 <DIR> Tempzxpsign4a446d41aab2d9ce
02. 12. 2016 08:36 <DIR> Tempzxpsign4dfed01b68589eff
25. 11. 2016 09:29 <DIR> Tempzxpsign519b2990f93cb040
30. 11. 2016 18:23 <DIR> Tempzxpsign54ffb038181ccd4d
23. 11. 2016 18:07 <DIR> Tempzxpsign56c048b2693f68d5
25. 11. 2016 16:12 <DIR> Tempzxpsign5703aadb952e53fd
07. 12. 2016 18:38 <DIR> Tempzxpsign58387ca720608c0e
23. 11. 2016 18:01 <DIR> Tempzxpsign58da6dbb7fd1acb1
25. 11. 2016 16:50 <DIR> Tempzxpsign5c6ba150a70edfdd
08. 12. 2016 09:09 <DIR> Tempzxpsign5caf336a714ad62c
08. 12. 2016 14:39 <DIR> Tempzxpsign5f5d0463584beaab
08. 12. 2016 09:09 <DIR> Tempzxpsign5fa04cddc00c2968
25. 11. 2016 09:31 <DIR> Tempzxpsign6101293415ace175
08. 12. 2016 09:09 <DIR> Tempzxpsign617167e66810f387
10. 12. 2016 11:16 <DIR> Tempzxpsign6280dd11afb9dba7
08. 12. 2016 09:13 <DIR> Tempzxpsign63449d47d21786f7
03. 12. 2016 12:36 <DIR> Tempzxpsign637f95dfd3deab22
25. 11. 2016 09:31 <DIR> Tempzxpsign64291c0b5a0926b9
08. 12. 2016 09:09 <DIR> Tempzxpsign6630ea7a2aaaea6f
24. 11. 2016 15:40 <DIR> Tempzxpsign676e0b6a7a46bb3b
23. 11. 2016 18:07 <DIR> Tempzxpsign67ece1634f88fc75
25. 11. 2016 09:30 <DIR> Tempzxpsign684ff9c364f03851
25. 11. 2016 09:51 <DIR> Tempzxpsign6b9cc90398a0cb1e
07. 12. 2016 18:38 <DIR> Tempzxpsign6dcc49399f8c408e
25. 11. 2016 09:30 <DIR> Tempzxpsign6e0ff71341284eb7
07. 12. 2016 19:03 <DIR> Tempzxpsign6f2861bb349627f7
01. 12. 2016 09:12 <DIR> Tempzxpsign712e33010fec095c
01. 12. 2016 09:38 <DIR> Tempzxpsign726672b45aceab45
25. 11. 2016 09:29 <DIR> Tempzxpsign73b85cb532a49866
25. 11. 2016 14:49 <DIR> Tempzxpsign749b30851f685ccf
08. 12. 2016 09:09 <DIR> Tempzxpsign75c2f24933b279cf
29. 11. 2016 14:34 <DIR> Tempzxpsign760eae1ed084535c
04. 12. 2016 15:22 <DIR> Tempzxpsign76352d9288f330e9
25. 11. 2016 16:50 <DIR> Tempzxpsign76cb548188a4d357
25. 11. 2016 10:49 <DIR> Tempzxpsign77c9488ef26f1957
29. 11. 2016 14:17 <DIR> Tempzxpsign7ba0c41e17cff74f
25. 11. 2016 16:51 <DIR> Tempzxpsign7c50c242c36dec9a
01. 12. 2016 08:43 <DIR> Tempzxpsign7dd9662d1863cfba
25. 11. 2016 10:35 <DIR> Tempzxpsign7e69804d9b986f44
25. 11. 2016 08:17 <DIR> Tempzxpsign7f0a6b69175290fb
25. 11. 2016 14:29 <DIR> Tempzxpsign81fe6f6e41476c4f
25. 11. 2016 08:17 <DIR> Tempzxpsign8360ad92f119fba9
01. 12. 2016 14:33 <DIR> Tempzxpsign836b3f85dac8e120
01. 12. 2016 14:21 <DIR> Tempzxpsign83da037ce220920b
07. 12. 2016 19:31 <DIR> Tempzxpsign84b58b53f9301053
25. 11. 2016 14:28 <DIR> Tempzxpsign84f007c38e52055b
24. 11. 2016 15:40 <DIR> Tempzxpsign84fcebf5ab499b2f
25. 11. 2016 09:26 <DIR> Tempzxpsign8618836b38fb0f06
13. 12. 2016 13:09 <DIR> Tempzxpsign8924fc58313f079a
02. 12. 2016 08:36 <DIR> Tempzxpsign8a48116b133eec3d
13. 12. 2016 13:08 <DIR> Tempzxpsign8b1b574b55534ede
24. 11. 2016 15:54 <DIR> Tempzxpsign8c637eb919a2e78b
29. 11. 2016 14:18 <DIR> Tempzxpsign8d8256ce50bbc819
01. 12. 2016 08:43 <DIR> Tempzxpsign8f0f885cd9fcb2c8
01. 12. 2016 14:21 <DIR> Tempzxpsign8f2c1411af27bf28
24. 11. 2016 15:41 <DIR> Tempzxpsign8fad4dd83e783b7e
01. 12. 2016 09:50 <DIR> Tempzxpsign90b3543d86bb94b7
26. 11. 2016 17:12 <DIR> Tempzxpsign911d90bba4c005a5
25. 11. 2016 10:50 <DIR> Tempzxpsign915294f1d99e4f2e
25. 11. 2016 14:29 <DIR> Tempzxpsign92a69d7d9dd97171
23. 11. 2016 17:59 <DIR> Tempzxpsign9583690508cdc442
25. 11. 2016 09:31 <DIR> Tempzxpsign95a95dbbbee73014
01. 12. 2016 14:05 <DIR> Tempzxpsign981669be21ccd874
25. 11. 2016 16:51 <DIR> Tempzxpsign9aca18065b137984
25. 11. 2016 14:33 <DIR> Tempzxpsign9b36d278d0a4d778
24. 11. 2016 16:03 <DIR> Tempzxpsign9bd2492a5695ddd6
26. 11. 2016 17:11 <DIR> Tempzxpsign9c1abd5d31566242
25. 11. 2016 10:49 <DIR> Tempzxpsign9c6039ea2b84dba5
24. 11. 2016 16:05 <DIR> Tempzxpsign9dd3a42e09c39db5
23. 11. 2016 14:09 <DIR> Tempzxpsigna10c87b8ec352cb1
07. 12. 2016 18:41 <DIR> Tempzxpsigna4112098cba3b545
07. 12. 2016 19:19 <DIR> Tempzxpsigna64625fb825af44a
25. 11. 2016 14:28 <DIR> Tempzxpsigna66c9190cdaad7ed
24. 11. 2016 16:05 <DIR> Tempzxpsigna734fffac3057565
13. 12. 2016 13:09 <DIR> Tempzxpsignaa0a89b2b72d676c
25. 11. 2016 09:27 <DIR> Tempzxpsignac277e113a0ac49f
29. 11. 2016 15:58 <DIR> Tempzxpsignad766ffe9529aa1c
01. 12. 2016 14:46 <DIR> Tempzxpsignafa4cfdfa387e7f7
25. 11. 2016 09:30 <DIR> Tempzxpsignb0bad4c992317797
03. 12. 2016 12:36 <DIR> Tempzxpsignb9a0456209b0fb90
13. 12. 2016 13:08 <DIR> Tempzxpsignb9d28553828958ec
08. 12. 2016 14:26 <DIR> Tempzxpsignbbb6b284072599f2
04. 12. 2016 15:23 <DIR> Tempzxpsignbbb9965e4c421aac
08. 12. 2016 09:09 <DIR> Tempzxpsignbee8659ec374bfd9
25. 11. 2016 16:51 <DIR> Tempzxpsignbffc69d2e5d60b32
24. 11. 2016 15:56 <DIR> Tempzxpsignc0213cc5ef6d97b1
25. 11. 2016 10:52 <DIR> Tempzxpsignc172002c811ca5f4
25. 11. 2016 09:30 <DIR> Tempzxpsignc19a8417ded9332d
25. 11. 2016 14:29 <DIR> Tempzxpsignc1c3e7637aa83065
24. 11. 2016 15:56 <DIR> Tempzxpsignc1d0bd168acb068e
01. 12. 2016 14:05 <DIR> Tempzxpsignc416a405298374d2
04. 12. 2016 15:23 <DIR> Tempzxpsignc45ea8219c449654
24. 11. 2016 15:54 <DIR> Tempzxpsignc6439a6e31866387
24. 11. 2016 15:57 <DIR> Tempzxpsignc73dcb2132a228ae
29. 11. 2016 12:39 <DIR> Tempzxpsignc95b42e29036466e
07. 12. 2016 19:31 <DIR> Tempzxpsignc98638ed7eea07cb
01. 12. 2016 09:12 <DIR> Tempzxpsignc9a5cc778c404459
02. 12. 2016 08:35 <DIR> Tempzxpsignca2078198d882286
10. 12. 2016 11:16 <DIR> Tempzxpsignca5c412747d76b3f
01. 12. 2016 09:50 <DIR> Tempzxpsigncde8aac452b4324e
01. 12. 2016 08:43 <DIR> Tempzxpsignce36f1c8dc468bf1
07. 12. 2016 19:32 <DIR> Tempzxpsigncee4ec77b8cd039b
07. 12. 2016 19:03 <DIR> Tempzxpsigncf9de7cb9f6227d4
04. 12. 2016 15:27 <DIR> Tempzxpsignd1bf3c4c02a0b68b
24. 11. 2016 15:40 <DIR> Tempzxpsignd396a344c325b7df
24. 11. 2016 16:03 <DIR> Tempzxpsignd3e8951f534be6da
03. 12. 2016 12:36 <DIR> Tempzxpsignd5da385de6fd2890
29. 11. 2016 14:17 <DIR> Tempzxpsignd65fbc1f5a9677ef
07. 12. 2016 18:47 <DIR> Tempzxpsignd67b7683074df9c9
25. 11. 2016 08:18 <DIR> Tempzxpsignd694ce34272bd123
26. 11. 2016 18:37 <DIR> Tempzxpsignd7cb58767b595773
25. 11. 2016 10:50 <DIR> Tempzxpsigndbd601fe96fcde09
23. 11. 2016 14:05 <DIR> Tempzxpsigndbe751830fc4ef17
25. 11. 2016 14:29 <DIR> Tempzxpsigndcf4469ddea8caf5
02. 12. 2016 08:35 <DIR> Tempzxpsignde71e76c18358e83
08. 12. 2016 14:33 <DIR> Tempzxpsigne006d29ead18caf3
29. 11. 2016 12:39 <DIR> Tempzxpsigne0d742a69f007cec
08. 12. 2016 14:36 <DIR> Tempzxpsigne1ced321dfdfb9a4
23. 11. 2016 18:07 <DIR> Tempzxpsigne208c4645b61e0ca
23. 11. 2016 17:59 <DIR> Tempzxpsigne28d99f7ba0940de
25. 11. 2016 10:48 <DIR> Tempzxpsigne3bfa15279d8cc61
13. 12. 2016 13:09 <DIR> Tempzxpsigne52d9fbe0f737919
24. 11. 2016 15:54 <DIR> Tempzxpsigne7114b6c0570ce14
04. 12. 2016 15:22 <DIR> Tempzxpsigne825740709a62977
24. 11. 2016 16:05 <DIR> Tempzxpsignea5367d43c3157e8
25. 11. 2016 09:27 <DIR> Tempzxpsignea69996a3d358db7
26. 11. 2016 18:37 <DIR> Tempzxpsignea81d48a8b65529b
13. 12. 2016 13:09 <DIR> Tempzxpsigneb139762080477ae
29. 11. 2016 12:39 <DIR> Tempzxpsignebb2588b068b8ce7
02. 12. 2016 08:55 <DIR> Tempzxpsignedd1f5a77ec3e170
08. 12. 2016 14:26 <DIR> Tempzxpsignee60114fb4b1736e
04. 12. 2016 15:23 <DIR> Tempzxpsignee9598d774c5a0ab
25. 11. 2016 10:35 <DIR> Tempzxpsignef004a92cf6d8dd3
01. 12. 2016 14:33 <DIR> Tempzxpsignef86ed7a47234b5f
25. 11. 2016 10:50 <DIR> Tempzxpsignf17d395d597a11d7
08. 12. 2016 14:34 <DIR> Tempzxpsignf1f638c1177a31b0
23. 11. 2016 14:05 <DIR> Tempzxpsignf268b732b53d6e41
29. 11. 2016 15:59 <DIR> Tempzxpsignf2f5363d549be76a
01. 12. 2016 14:46 <DIR> Tempzxpsignf5b96ce0dbd76646
26. 11. 2016 18:37 <DIR> Tempzxpsignf638436609388d93
23. 11. 2016 17:59 <DIR> Tempzxpsignfb2bea506765f1fd
08. 12. 2016 14:33 <DIR> Tempzxpsignfc3eb4accfdb44f1
23. 11. 2016 14:05 <DIR> Tempzxpsignfdbca61b281d99b4
26. 11. 2016 18:37 <DIR> Tempzxpsignfdc10a1f9615cd11
10. 12. 2016 11:16 <DIR> Tempzxpsignff25e483c072c8cf
08. 10. 2016 10:44 <DIR> tkdata
10. 12. 2016 13:22 <DIR> VirtualStore
09. 10. 2016 09:44 17˙408 WebpageIcons.db
3 File(s) 149˙621 bytes
209 Dir(s) 288˙364˙474˙368 bytes free
========= End of CMD: =========
========= dir "%appdata%" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\Users\Michal\AppData\Roaming
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
09. 12. 2016 15:31 <DIR> Acoustica
23. 11. 2016 18:41 <DIR> Adobe
07. 10. 2016 14:06 <DIR> Atheros
07. 10. 2016 14:27 <DIR> ATI
11. 12. 2016 13:06 <DIR> Audacity
30. 11. 2016 18:22 <DIR> Brackets
07. 10. 2016 14:19 <DIR> DAEMON Tools Lite
08. 10. 2016 10:51 <DIR> Easeware
10. 12. 2016 09:21 <DIR> Firefox
23. 10. 2016 10:10 <DIR> HpUpdate
07. 10. 2016 13:20 <DIR> Identities
07. 10. 2016 13:39 <DIR> InstallShield
07. 10. 2016 13:35 <DIR> Intel
07. 10. 2016 13:38 <DIR> Intel Corporation
07. 10. 2016 17:13 <DIR> Macromedia
16. 11. 2016 17:13 <DIR> Media Player Classic
07. 10. 2016 17:16 <DIR> Mozilla
10. 12. 2016 17:52 <DIR> MuseScore
09. 12. 2016 16:40 <DIR> Neuratron
01. 11. 2016 11:44 <DIR> Notepad++
09. 12. 2016 17:50 <DIR> Profiles
11. 10. 2016 21:35 607˙138 Scorch_Install.log
10. 12. 2016 14:55 <DIR> ScoreCloud
11. 10. 2016 21:36 <DIR> Sibelius Software
17. 12. 2016 10:23 <DIR> Skype
09. 12. 2016 15:32 <DIR> SynthMaker
10. 12. 2016 20:08 <DIR> uTorrent
09. 12. 2016 15:31 <DIR> vlc
08. 10. 2016 12:25 <DIR> WinRAR
1 File(s) 607˙138 bytes
30 Dir(s) 288˙364˙470˙272 bytes free
========= End of CMD: =========
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 35875942 B
Java, Flash, Steam htmlcache => 5451 B
Windows/system/drivers => 1006964 B
Edge => 0 B
Chrome => 1545542 B
Firefox => 391636641 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 33058 B
Public => 0 B
ProgramData => 0 B
systemprofile => 33186 B
systemprofile32 => 5405476 B
LocalService => 66228 B
NetworkService => 461788 B
Michal => 160251609 B
WOUTempAdmin => 25942 B
RecycleBin => 4019192 B
EmptyTemp: => 580.6 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 10:48:54 ====
Fix result of Farbar Recovery Scan Tool (x64) Version: 07-12-2016
Ran by Michal (17-12-2016 10:48:28) Run:1
Running from C:\Users\Michal\Desktop
Loaded Profiles: Michal (Available Profiles: Michal)
Boot Mode: Normal
==============================================
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
StartRegedit:
[HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
"NoAutoUpdate"=dword:00000000
EndRegedit:
cmd: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost"
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\RunOnce: [AvgUninstallURL] => cmd.exe /c start hxxp://www.avg.com/ww.special-uninstall ... gBQAEEATgA"&"inst=NwA3AC0AMwA0AD (the data entry has 109 more characters).
Winlogon\Notify\xranhgo-x32: C:\Users\Michal\AppData\Local\xranhgo.dll [X]
File: C:\Users\Michal\AppData\Local\xranhgo.dll
C:\Users\Michal\AppData\Local\xranhgo.dll
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [357696 2010-04-01] (DT Soft Ltd)
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9108184 2016-11-07] (Piriform Ltd)
HKLM\...\Providers\jelxymt5: C:\Program Files (x86)\Adobe\\local64spl.dll [142848 2016-12-10] ()
File: C:\Program Files (x86)\Adobe\\local64spl.dll
C:\Program Files (x86)\Adobe\\local64spl.dll
ShellExecuteHooks: - {4A39289E-AB73-11E6-B57F-64006A5CFC23} - C:\Users\Michal\AppData\Roaming\Graqsp\Kerich.dll [145920 2016-12-09] ()
File: C:\Users\Michal\AppData\Roaming\Graqsp\Kerich.dll
C:\Users\Michal\AppData\Roaming\Graqsp
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => No File
GroupPolicy: Restriction - Chrome <======= ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Internet Explorer\Main,Start Page =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files (x86)\AVG\AVG9\avgssiea.dll => No File
C:\Program Files (x86)\AVG
cmd: type "C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\user.js"
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\crsahtbq.default -> luck
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\crsahtbq.default -> luck
FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\crsahtbq.default -> Bing
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\crsahtbq.default -> luck
FF Keyword.URL: Mozilla\Firefox\Profiles\crsahtbq.default -> hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q=
FF Extension: (No Name) - C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\extensions\arthurj8283@gmail.com [not found]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\searchplugins\luck.xml [2016-12-12]
cmd: type "C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\user.js"
FF DefaultSearchEngine: Firefox\Firefox\Profiles\crsahtbq.default -> luck
FF SearchEngineOrder.1: Firefox\Firefox\Profiles\crsahtbq.default -> luck
FF SearchEngineOrder.3: Firefox\Firefox\Profiles\crsahtbq.default -> Bing
FF SelectedSearchEngine: Firefox\Firefox\Profiles\crsahtbq.default -> luck
FF Keyword.URL: Firefox\Firefox\Profiles\crsahtbq.default -> hxxp://www.bing.com/search?FORM=SK216DF&PC=SK216&q=
FF Extension: (FF Adr) - C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi [2016-12-10] [not signed]
FF Extension: (xRocket Toolbar) - C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\arthurj8283@gmail.com [2016-12-12] [not signed]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\luck.xml [2016-12-12]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\searchinme.xml [2016-12-10]
FF SearchPlugin: C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\zmlfca7u.xml [2016-12-09]
File: C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
R2 Convxxxx; C:\Users\Michal\AppData\Roaming\cfjcf\UvConverter.exe [403968 2016-12-07] () [File not signed]
File: C:\Users\Michal\AppData\Roaming\cfjcf\UvConverter.exe
C:\Users\Michal\AppData\Roaming\cfjcf
R2 FirefoxU; C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe [100352 2016-12-12] () [File not signed]
U0 aswVmm; no ImagePath
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
Folder: C:\Users\Michal\AppData\Local\Tempzxpsigneb139762080477ae
Folder: C:\Users\Michal\AppData\Local\Tempzxpsigne52d9fbe0f737919
2016-12-12 13:19 - 2016-12-12 13:19 - 01323520 _____ C:\Users\Michal\Downloads\RSITx64.exe
2016-12-12 13:19 - 2016-12-12 13:19 - 00000000 ____D C:\rsit
2016-12-12 12:37 - 2016-12-12 12:37 - 00000000 ____D C:\Program Files (x86)\amuleC1
2016-12-10 09:18 - 2016-12-17 08:22 - 00000000 _____ C:\Users\Public\Documents\report.dat
2016-12-10 09:18 - 2016-12-12 12:38 - 00000000 _____ C:\Users\Public\Documents\temp.dat
2016-12-10 09:12 - 2016-12-10 09:12 - 00000000 ____D C:\Users\Michal\Documents\aMule Downloads
2016-12-10 09:01 - 2016-12-10 09:12 - 00000000 ____D C:\Users\Michal\AppData\Roaming\aMule
2016-12-10 09:01 - 2016-12-10 09:01 - 00000000 ____D C:\Users\Michal\AppData\Roaming\cfjcf
2016-12-10 08:56 - 2016-12-12 12:33 - 00000000 ____D C:\Program Files (x86)\ft1xx095
Folder: C:\ProgramData\Avira
2016-12-09 17:50 - 2016-12-09 17:50 - 00006050 _____ C:\Windows\System32\Tasks\Vuktionliqat Helper
2016-12-09 17:50 - 2016-12-09 17:50 - 00003530 _____ C:\Windows\System32\Tasks\54f4f7b41a6f7a369d678a5e04483ba2
2016-12-09 17:49 - 2016-12-12 12:49 - 00000000 ____D C:\Program Files (x86)\Merpetionannage
2016-12-09 17:49 - 2016-12-09 17:50 - 00000000 ____D C:\Users\Michal\AppData\Local\Smedom
2016-12-09 17:49 - 2016-12-09 17:49 - 00000000 ____D C:\Users\Michal\AppData\Roaming\Graqsp
2016-11-19 15:20 - 2016-12-12 13:19 - 00000000 ____D C:\Program Files\trend micro
Folder: C:\f74ac6a2e4cd4e3b05d865d22c91ca77
Folder: C:\065499413fda718ad23a4eeb3e452f
Folder: C:\ProgramData\AVAST Software
2016-11-21 19:43 - 2016-12-09 17:51 - 00000000 ____D C:\ProgramData\Avg
2016-11-21 19:42 - 2016-11-21 20:13 - 00000000 ____D C:\Users\Michal\AppData\Local\AvgSetupLog
2016-11-21 19:42 - 2016-11-21 19:42 - 00000000 ____D C:\Users\Michal\AppData\Local\Avg
2016-12-09 17:51 - 2016-10-28 10:16 - 00000000 ____D C:\ProgramData\AVAST Software
2016-12-09 17:50 - 2016-10-07 14:25 - 00000000 ____D C:\Program Files (x86)\AVG
Task: {43A81866-A5C4-44F9-8EB6-F43090120092} - System32\Tasks\{9FEBF33B-2074-414C-8502-E337530B2EEE} => pcalua.exe -a "C:\Users\Michal\Desktop\Nový priečinok\Windows.Media.Player.12.v.2.CZ..exe" -d "C:\Users\Michal\Desktop\Nový priečinok"
Task: {898120DD-BF52-4B72-ACAB-45372AEE08B5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-10-28] (AVAST Software)
Task: {917AB143-3543-4ED5-86D1-DAE72919DC3A} - System32\Tasks\{ED0C19EC-E733-47DA-A367-34EAE657BBBF} => pcalua.exe -a C:\Users\Michal\Desktop\wsusoffline\client\cpp\vcredist2008_x64.exe -d C:\Users\Michal\Desktop\wsusoffline\client\cpp
Task: {D33665A0-6187-430A-A0AD-41B0FF27D0EB} - System32\Tasks\54f4f7b41a6f7a369d678a5e04483ba2 => Rundll32.exe "C:\Program Files (x86)\Common Files\elxymt.dll",e62dc6c6547f46bda862da2d05af6862 <==== ATTENTION
File: C:\Program Files (x86)\Merpetionannage\copay.exe
Folder: C:\Program Files (x86)\Merpetionannage
C:\Program Files (x86)\Merpetionannage
File: C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
File: C:\Program Files (x86)\SrpnFiles\downloader.exe
Folder: C:\Program Files (x86)\SrpnFiles
C:\Program Files (x86)\SrpnFiles
FirewallRules: [{F659C450-8F90-4046-A97E-1180E871D417}] => C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{0B8B91FE-FEBA-440A-A18C-3C6BE8C5DA64}] => C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe
FirewallRules: [{1222AFB4-9C0C-4EDA-8C20-13C097DD10F4}] => C:\Program Files (x86)\SrpnFiles\downloader.exe
FirewallRules: [{6779D280-A173-47C3-8F50-16A2B0B6246B}] => C:\Program Files (x86)\SrpnFiles\downloader.exe
File: C:\program files (x86)\brackets\node.exe
FirewallRules: [{D960489A-096B-4277-B260-B3A53D48840B}] => C:\Windows\system32\rundll32.exe
FirewallRules: [{D0EEFAF9-098E-47B6-9B63-7350707B6846}] => C:\Windows\system32\rundll32.exe
FirewallRules: [TCP Query User{8DD6A48A-6951-45BC-AEFC-F01B5F82D210}C:\windows\syswow64\rundll32.exe] => C:\windows\syswow64\rundll32.exe
FirewallRules: [UDP Query User{22D498AC-C9A7-4644-8629-2152CFF322E4}C:\windows\syswow64\rundll32.exe] => C:\windows\syswow64\rundll32.exe
FirewallRules: [{1B40F44E-E1D2-4215-92FA-39146AD5B265}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{63F33A42-180C-41E1-BCF6-57335200B66A}] => C:\Program Files (x86)\AVG\Av\avgnsa.exe
FirewallRules: [{365856DD-96B8-4104-9F77-79233DA5E047}] => C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{4881B295-8618-4ECF-A9F4-87F43A7AD39E}] => C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{5BD9BFF5-B75A-4C45-9DDC-58FF8D31CBB6}] => C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [{190C0C9C-33C1-4DCD-AF81-C64EC28370D9}] => C:\Program Files (x86)\AVG\Av\avgemca.exe
FirewallRules: [TCP Query User{76B13A3E-8F9B-4C28-91DB-0C9AA6127DB7}C:\program files (x86)\amulec1\amule.exe] => C:\program files (x86)\amulec1\amule.exe
FirewallRules: [UDP Query User{23CA4E45-1996-47BC-8004-407722F3B376}C:\program files (x86)\amulec1\amule.exe] => C:\program files (x86)\amulec1\amule.exe
FirewallRules: [{B8155EEF-AFCA-4B69-AC19-4053C03B567C}] => C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
FirewallRules: [{6114AE8A-EA9C-4BBF-B064-BB4015DEE52A}] => C:\Program Files (x86)\Firefox\Firefox.exe
File: C:\Program Files (x86)\Firefox\Firefox.exe
File: C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe
CMD: dir "C:\Windows\System32\Tasks"
CMD: dir "C:\PROGRA~1"
CMD: dir "C:\PROGRA~2"
CMD: dir "C:\PROGRA~3"
CMD: dir "%localappdata%"
CMD: dir "%appdata%"
Hosts:
EmptyTemp:
End
*****************
Restore point was successfully created.
Processes closed successfully.
====> Registry
========= reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost" =========
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost
netsvcs REG_MULTI_SZ AeLookupSvc\0CertPropSvc\0SCPolicySvc\0lanmanserver\0gpsvc\0AudioSrv\0FastUserSwitchingCompatibility\0Ias\0Irmon\0Nla\0Ntmssvc\0NWCWorkstation\0Nwsapagent\0Rasauto\0Rasman\0Remoteaccess\0SENS\0Sharedaccess\0SRService\0Tapisrv\0Wmi\0WmdmPmSp\0TermService\0wuauserv\0BITS\0ShellHWDetection\0LogonHours\0PCAudit\0helpsvc\0uploadmgr\0iphlpsvc\0msiscsi\0schedule\0SessionEnv\0winmgmt\0AppMgmt
LocalService REG_MULTI_SZ RemoteRegistry\0WinHttpAutoProxySvc\0sppuinotify\0netprofm\0WebClient
LocalSystemNetworkRestricted REG_MULTI_SZ Netman\0AudioEndpointBuilder\0dot3svc\0wlansvc\0WPDBusEnum
LocalServiceNoNetwork REG_MULTI_SZ PLA
rpcss REG_MULTI_SZ RpcSs
LocalServiceNetworkRestricted REG_MULTI_SZ AudioSrv\0BthHFSrv\0LmHosts\0wscsvc\0WPCSvc
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV\0upnphost\0SCardSvr\0QWAVE\0wcncsvc
DcomLaunch REG_MULTI_SZ Power\0PlugPlay\0DcomLaunch
NetworkService REG_MULTI_SZ CryptSvc\0DHCP\0TermService\0DNSCache\0NapAgent\0nlasvc\0WinRM\0WECSVC\0Tapisrv
imgsvc REG_MULTI_SZ StiSvc
wcssvc REG_MULTI_SZ WcsPlugInService
Musadom REG_MULTI_SZ Musadom
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalService
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceAndNoImpersonation
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNetworkRestricted
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalServiceNoNetwork
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\LocalSystemNetworkRestricted
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\netsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkService
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopHyperVAgent
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\NetworkServiceRemoteDesktopPublishing
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\termsvcs
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Svchost\wcssvc
========= End of CMD: =========
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\BCSSync => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\HP Software Update => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\AvgUninstallURL => value removed successfully
"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\xranhgo" => key removed successfully
========================= File: C:\Users\Michal\AppData\Local\xranhgo.dll ========================
"C:\Users\Michal\AppData\Local\xranhgo.dll" => not found.
====== End of File: ======
"C:\Users\Michal\AppData\Local\xranhgo.dll" => not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\EnableShellExecuteHooks => value removed successfully
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Windows\CurrentVersion\Run\\DAEMON Tools Lite => value removed successfully
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value removed successfully
"HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\jelxymt5" => key removed successfully
HKLM\SYSTEM\CurrentControlSet\Control\Print\Providers\\order jelxymt5 could not remove.
========================= File: C:\Program Files (x86)\Adobe\\local64spl.dll ========================
File not signed
MD5: DB8C644FCF5BA2B948643FD02D13041B
Creation and modification date: 2016-12-10 09:50 - 2016-12-10 17:50
Size: 0142848
Attributes: ----H
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
C:\Program Files (x86)\Adobe\\local64spl.dll => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{4A39289E-AB73-11E6-B57F-64006A5CFC23} => value removed successfully
"HKCR\CLSID\{4A39289E-AB73-11E6-B57F-64006A5CFC23}" => key removed successfully
========================= File: C:\Users\Michal\AppData\Roaming\Graqsp\Kerich.dll ========================
File not signed
MD5: 79DBA1067B2275915A82D1A164F0790E
Creation and modification date: 2016-12-09 17:49 - 2016-12-09 17:49
Size: 0145920
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
C:\Users\Michal\AppData\Roaming\Graqsp => moved successfully
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast" => key removed successfully
HKCR\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKU\S-1-5-21-1152366391-2464299941-3798222694-1000\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => key removed successfully
HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" => key removed successfully
"HKCR\CLSID\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}" => key removed successfully
C:\Program Files (x86)\AVG => moved successfully
========= type "C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\user.js" =========
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
*/
user_pref("browser.search.defaultenginename", "luck");
user_pref("browser.search.order.1", "luck");
user_pref("browser.search.searchengine.alias", "");
user_pref("browser.search.searchengine.name", "luck");
user_pref("browser.search.searchengine.ref", "");
user_pref("browser.search.searchengine.ts", "1481542656");
user_pref("browser.search.searchengine.type", "");
user_pref("browser.search.searchengine.uid", "st500lm000-1ej162_w370kzblxxxxw370kzbl");
user_pref("browser.search.selectedEngine", "luck");
user_pref("browser.search.useDBForOrder", true);
user_pref("browser.sessionstore.max_tabs_undo", 0);
user_pref("browser.sessionstore.max_windows_undo", 0);
user_pref("browser.sessionstore.resume_from_crash", false);
user_pref("browser.sessionstore.resume_session_once", false);
========= End of CMD: =========
Firefox DefaultSearchEngine removed successfully
Firefox SearchEngineOrder.1 removed successfully
Firefox SearchEngineOrder.3 removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox "Keyword.URL" removed successfully
C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\extensions\arthurj8283@gmail.com => path removed successfully
C:\Users\Michal\AppData\Roaming\Mozilla\Firefox\Profiles\crsahtbq.default\searchplugins\luck.xml => moved successfully
========= type "C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\user.js" =========
# Mozilla User Preferences
/* Do not edit this file.
*
* If you make changes to this file while the application is running,
* the changes will be overwritten when the application exits.
*
* To make a manual change to preferences, you can visit the URL about:config
*/
user_pref("browser.search.defaultenginename", "luck");
user_pref("browser.search.order.1", "luck");
user_pref("browser.search.searchengine.alias", "");
user_pref("browser.search.searchengine.name", "luck");
user_pref("browser.search.searchengine.ref", "");
user_pref("browser.search.searchengine.ts", "1481542656");
user_pref("browser.search.searchengine.type", "");
user_pref("browser.search.searchengine.uid", "st500lm000-1ej162_w370kzblxxxxw370kzbl");
user_pref("browser.search.selectedEngine", "luck");
user_pref("browser.search.useDBForOrder", true);
user_pref("browser.sessionstore.max_tabs_undo", 0);
user_pref("browser.sessionstore.max_windows_undo", 0);
user_pref("browser.sessionstore.resume_from_crash", false);
user_pref("browser.sessionstore.resume_session_once", false);
========= End of CMD: =========
Firefox DefaultSearchEngine removed successfully
Firefox SearchEngineOrder.1 removed successfully
Firefox SearchEngineOrder.3 removed successfully
Firefox SelectedSearchEngine removed successfully
Firefox "Keyword.URL" removed successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\@H99KV4DO-UCCF-9PFO-9ZLK-8RRP4FVOKD9O.xpi => moved successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\arthurj8283@gmail.com => moved successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\Extensions\arthurj8283@gmail.com => path removed successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\luck.xml => moved successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\searchinme.xml => moved successfully
C:\Users\Michal\AppData\Roaming\Firefox\Firefox\Profiles\crsahtbq.default\searchplugins\zmlfca7u.xml => moved successfully
========================= File: C:\Program Files (x86)\Bluetooth Suite\adminservice.exe ========================
File not signed
MD5: A917E4F753B90A5181ECBFA56D5C154A
Creation and modification date: 2013-01-24 23:12 - 2013-01-24 23:12
Size: 0227456
Attributes: ----A
Company Name: Qualcomm Atheros Commnucations
Internal Name: AdminService
Original Name: AdminService.exe
Product: Bluetooth Software
Description: AdminService Application
File Version: 8.0.0.220
Product Version: 8.0.0.220
Copyright: Copyright (c) 2001-2010 Qualcomm Atheros Communications, Inc. All rights reserved.
====== End of File: ======
Convxxxx => service removed successfully
========================= File: C:\Users\Michal\AppData\Roaming\cfjcf\UvConverter.exe ========================
File not signed
MD5: A1D70DA7E4A94E51DB76CF9D58D5B8B4
Creation and modification date: 2016-12-10 09:01 - 2016-12-07 11:54
Size: 0403968
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
====== End of File: ======
C:\Users\Michal\AppData\Roaming\cfjcf => moved successfully
FirefoxU => service removed successfully
aswVmm => service removed successfully
catchme => service removed successfully
========================= Folder: C:\Users\Michal\AppData\Local\Tempzxpsigneb139762080477ae ========================
====== End of Folder: ======
========================= Folder: C:\Users\Michal\AppData\Local\Tempzxpsigne52d9fbe0f737919 ========================
====== End of Folder: ======
C:\Users\Michal\Downloads\RSITx64.exe => moved successfully
C:\rsit => moved successfully
C:\Program Files (x86)\amuleC1 => moved successfully
C:\Users\Public\Documents\report.dat => moved successfully
C:\Users\Public\Documents\temp.dat => moved successfully
C:\Users\Michal\Documents\aMule Downloads => moved successfully
C:\Users\Michal\AppData\Roaming\aMule => moved successfully
"C:\Users\Michal\AppData\Roaming\cfjcf" => not found.
C:\Program Files (x86)\ft1xx095 => moved successfully
========================= Folder: C:\ProgramData\Avira ========================
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\Avira\AntiVir Desktop
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\Avira\AntiVir Desktop\CONFIG
2016-12-09 17:51 - 2016-12-09 17:51 - 0000494 _____ () C:\ProgramData\Avira\AntiVir Desktop\CONFIG\AVWIN.INI
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\Avira\Antivirus
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\Avira\Antivirus\CONFIG
2016-12-09 17:51 - 2016-12-09 17:51 - 0000494 _____ () C:\ProgramData\Avira\Antivirus\CONFIG\AVWIN.INI
====== End of Folder: ======
C:\Windows\System32\Tasks\Vuktionliqat Helper => moved successfully
C:\Windows\System32\Tasks\54f4f7b41a6f7a369d678a5e04483ba2 => moved successfully
C:\Program Files (x86)\Merpetionannage => moved successfully
C:\Users\Michal\AppData\Local\Smedom => moved successfully
"C:\Users\Michal\AppData\Roaming\Graqsp" => not found.
C:\Program Files\trend micro => moved successfully
========================= Folder: C:\f74ac6a2e4cd4e3b05d865d22c91ca77 ========================
2016-11-18 16:36 - 2016-02-13 18:16 - 22011749 _____ () C:\f74ac6a2e4cd4e3b05d865d22c91ca77\Windows6.1-KB3134760-x64.cab
2016-11-18 16:36 - 2016-02-13 18:17 - 0000498 _____ () C:\f74ac6a2e4cd4e3b05d865d22c91ca77\Windows6.1-KB3134760-x64.xml
2016-11-18 16:36 - 2016-02-13 18:17 - 0000395 _____ () C:\f74ac6a2e4cd4e3b05d865d22c91ca77\Windows6.1-KB3134760-x64-pkgProperties.txt
2016-11-18 16:36 - 2016-02-13 18:18 - 0198044 _____ () C:\f74ac6a2e4cd4e3b05d865d22c91ca77\WSUSSCAN.cab
====== End of Folder: ======
========================= Folder: C:\065499413fda718ad23a4eeb3e452f ========================
2016-11-18 15:24 - 2016-01-11 16:10 - 3177773 _____ () C:\065499413fda718ad23a4eeb3e452f\Windows6.1-KB3135445-x64.cab
2016-11-18 15:24 - 2016-01-11 16:11 - 0000446 _____ () C:\065499413fda718ad23a4eeb3e452f\Windows6.1-KB3135445-x64.xml
2016-11-18 15:24 - 2016-01-11 16:11 - 0000521 _____ () C:\065499413fda718ad23a4eeb3e452f\Windows6.1-KB3135445-x64-pkgProperties.txt
2016-11-18 15:24 - 2016-01-11 16:19 - 0181156 _____ () C:\065499413fda718ad23a4eeb3e452f\WSUSSCAN.cab
====== End of Folder: ======
========================= Folder: C:\ProgramData\AVAST Software ========================
2016-12-09 17:51 - 2016-12-09 17:51 - 0000000 ____D () C:\ProgramData\AVAST Software\Avast
2016-12-09 17:51 - 2016-12-09 17:51 - 0000312 _____ () C:\ProgramData\AVAST Software\Avast\exclusions.ini
2016-10-28 10:16 - 2016-10-28 10:16 - 0000000 ____D () C:\ProgramData\AVAST Software\Persistent Data
2016-10-28 10:16 - 2016-10-30 09:17 - 0000000 ____D () C:\ProgramData\AVAST Software\Persistent Data\Avast
2016-10-28 10:16 - 2016-10-28 10:20 - 0000000 ____D () C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs
2016-10-28 10:16 - 2016-10-29 08:44 - 0005921 _____ () C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\event_manager.log
2016-10-28 10:16 - 2016-10-28 10:20 - 0976174 ____C () C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Setup.log
2016-10-28 10:20 - 2016-10-29 08:44 - 3020140 ____C () C:\ProgramData\AVAST Software\Persistent Data\Avast\Logs\Update.log
====== End of Folder: ======
C:\ProgramData\Avg => moved successfully
C:\Users\Michal\AppData\Local\AvgSetupLog => moved successfully
C:\Users\Michal\AppData\Local\Avg => moved successfully
C:\ProgramData\AVAST Software => moved successfully
"C:\Program Files (x86)\AVG" => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{43A81866-A5C4-44F9-8EB6-F43090120092}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{43A81866-A5C4-44F9-8EB6-F43090120092}" => key removed successfully
C:\Windows\System32\Tasks\{9FEBF33B-2074-414C-8502-E337530B2EEE} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{9FEBF33B-2074-414C-8502-E337530B2EEE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{898120DD-BF52-4B72-ACAB-45372AEE08B5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{898120DD-BF52-4B72-ACAB-45372AEE08B5}" => key removed successfully
C:\Windows\System32\Tasks\AVAST Software\Avast settings backup => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software\Avast settings backup" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{917AB143-3543-4ED5-86D1-DAE72919DC3A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{917AB143-3543-4ED5-86D1-DAE72919DC3A}" => key removed successfully
C:\Windows\System32\Tasks\{ED0C19EC-E733-47DA-A367-34EAE657BBBF} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{ED0C19EC-E733-47DA-A367-34EAE657BBBF}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D33665A0-6187-430A-A0AD-41B0FF27D0EB}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D33665A0-6187-430A-A0AD-41B0FF27D0EB}" => key removed successfully
C:\Windows\System32\Tasks\54f4f7b41a6f7a369d678a5e04483ba2 => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\54f4f7b41a6f7a369d678a5e04483ba2" => key removed successfully
========================= File: C:\Program Files (x86)\Merpetionannage\copay.exe ========================
"C:\Program Files (x86)\Merpetionannage\copay.exe" => not found.
====== End of File: ======
========================= Folder: C:\Program Files (x86)\Merpetionannage ========================
not found.
====== End of Folder: ======
"C:\Program Files (x86)\Merpetionannage" => not found.
========================= File: C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe ========================
"C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe" => not found.
====== End of File: ======
========================= File: C:\Program Files (x86)\SrpnFiles\downloader.exe ========================
"C:\Program Files (x86)\SrpnFiles\downloader.exe" => not found.
====== End of File: ======
========================= Folder: C:\Program Files (x86)\SrpnFiles ========================
not found.
====== End of Folder: ======
"C:\Program Files (x86)\SrpnFiles" => not found.
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{F659C450-8F90-4046-A97E-1180E871D417} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0B8B91FE-FEBA-440A-A18C-3C6BE8C5DA64} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1222AFB4-9C0C-4EDA-8C20-13C097DD10F4} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6779D280-A173-47C3-8F50-16A2B0B6246B} => value removed successfully
========================= File: C:\program files (x86)\brackets\node.exe ========================
"C:\program files (x86)\brackets\node.exe" => not found.
====== End of File: ======
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D960489A-096B-4277-B260-B3A53D48840B} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{D0EEFAF9-098E-47B6-9B63-7350707B6846} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{8DD6A48A-6951-45BC-AEFC-F01B5F82D210}C:\windows\syswow64\rundll32.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{22D498AC-C9A7-4644-8629-2152CFF322E4}C:\windows\syswow64\rundll32.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1B40F44E-E1D2-4215-92FA-39146AD5B265} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{63F33A42-180C-41E1-BCF6-57335200B66A} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{365856DD-96B8-4104-9F77-79233DA5E047} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{4881B295-8618-4ECF-A9F4-87F43A7AD39E} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5BD9BFF5-B75A-4C45-9DDC-58FF8D31CBB6} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{190C0C9C-33C1-4DCD-AF81-C64EC28370D9} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{76B13A3E-8F9B-4C28-91DB-0C9AA6127DB7}C:\program files (x86)\amulec1\amule.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{23CA4E45-1996-47BC-8004-407722F3B376}C:\program files (x86)\amulec1\amule.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{B8155EEF-AFCA-4B69-AC19-4053C03B567C} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6114AE8A-EA9C-4BBF-B064-BB4015DEE52A} => value removed successfully
========================= File: C:\Program Files (x86)\Firefox\Firefox.exe ========================
File not signed
MD5: F0425A2AEA6AB764D3E7B6EC8E8D3A74
Creation and modification date: 2016-12-12 12:54 - 2016-12-12 03:46
Size: 0492544
Attributes: ----A
Company Name: Mozilla Corporation
Internal Name: Firefox
Original Name: Firefox.exe
Product: Firefox
Description: Firefox
File Version: 50.0
Product Version: 50.0
Copyright: Firefox and Mozilla Developers; available under the MPL 2 license.
====== End of File: ======
========================= File: C:\Program Files (x86)\Firefox\bin\FirefoxUpdate.exe ========================
File not signed
MD5: D1D91682A1F1AAB35B54DDC5273EE7DC
Creation and modification date: 2016-12-12 12:54 - 2016-12-12 07:31
Size: 0100352
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product: Firefox
Description: Firefox
File Version: 50.0.8.336
Product Version: 50.0.8.336
Copyright: Copyright (C) 2016 Firefox Authors
====== End of File: ======
========= dir "C:\Windows\System32\Tasks" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\Windows\System32\Tasks
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
08. 11. 2016 12:31 4˙476 Adobe Acrobat Update Task
13. 12. 2016 12:46 3˙768 Adobe Flash Player Updater
17. 12. 2016 10:48 <DIR> AVAST Software
16. 11. 2016 17:12 2˙794 CCleanerSkipUAC
16. 12. 2016 22:10 3˙240 GoogleUpdateTaskMachineCore
16. 12. 2016 22:10 3˙368 GoogleUpdateTaskMachineUA
16. 10. 2016 09:43 3˙620 HPCustParticipation HP Deskjet 1510 series
18. 11. 2016 16:45 <DIR> Microsoft
08. 10. 2016 15:37 <DIR> OfficeSoftwareProtectionPlatform
22. 11. 2016 13:30 <DIR> WPD
6 File(s) 21˙266 bytes
6 Dir(s) 288˙364˙494˙848 bytes free
========= End of CMD: =========
========= dir "C:\PROGRA~1" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\PROGRA~1
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
16. 11. 2016 21:13 <DIR> Adobe
07. 10. 2016 14:13 <DIR> ATI
07. 10. 2016 14:14 <DIR> ATI Technologies
16. 11. 2016 17:12 <DIR> CCleaner
09. 10. 2016 09:43 <DIR> Cisco Packet Tracer 7.0
23. 11. 2016 17:43 <DIR> Common Files
07. 10. 2016 13:53 <DIR> CONEXANT
07. 10. 2016 14:04 <DIR> DIFX
19. 11. 2016 13:34 <DIR> DVD Maker
07. 10. 2016 13:41 <DIR> Elantech
16. 10. 2016 09:40 <DIR> HP
07. 10. 2016 13:39 <DIR> Intel
08. 10. 2016 10:33 <DIR> Intel Security
18. 11. 2016 19:27 <DIR> Internet Explorer
07. 10. 2016 14:04 <DIR> Lenovo
08. 10. 2016 15:31 <DIR> Microsoft Office
18. 11. 2016 08:50 <DIR> Microsoft Silverlight
14. 07. 2009 06:38 <DIR> MSBuild
17. 10. 2016 14:48 <DIR> Oracle
14. 07. 2009 06:38 <DIR> Reference Assemblies
18. 11. 2016 17:59 <DIR> Windows Defender
12. 04. 2011 14:29 <DIR> Windows Mail
20. 11. 2016 15:35 <DIR> Windows Media Player
14. 07. 2009 06:38 <DIR> Windows NT
12. 04. 2011 14:29 <DIR> Windows Photo Viewer
19. 11. 2016 13:34 <DIR> Windows Portable Devices
12. 04. 2011 14:29 <DIR> Windows Sidebar
19. 11. 2016 10:00 <DIR> WindowsPowerShell
08. 10. 2016 12:25 <DIR> WinRAR
0 File(s) 0 bytes
31 Dir(s) 288˙364˙494˙848 bytes free
========= End of CMD: =========
========= dir "C:\PROGRA~2" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\PROGRA~2
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
17. 12. 2016 10:48 <DIR> Adobe
09. 12. 2016 17:50 <DIR> AMD APP
09. 12. 2016 17:50 <DIR> AMD AVT
10. 12. 2016 13:16 <DIR> AnthemScore
09. 12. 2016 17:50 <DIR> ATI Technologies
09. 12. 2016 17:50 <DIR> Audacity
09. 12. 2016 17:50 <DIR> Bluetooth Suite
09. 12. 2016 17:50 <DIR> Brackets
09. 12. 2016 17:50 <DIR> Cisco
14. 12. 2016 20:28 <DIR> Common Files
09. 12. 2016 17:50 <DIR> DAEMON Tools Lite
14. 12. 2016 20:31 <DIR> Firefox
09. 12. 2016 17:50 <DIR> Google
09. 12. 2016 17:51 <DIR> Hewlett-Packard
09. 12. 2016 17:50 <DIR> HP
09. 12. 2016 17:50 <DIR> HP Photo Creations
09. 12. 2016 17:50 <DIR> Intel
09. 12. 2016 17:50 <DIR> Internet Explorer
09. 12. 2016 17:51 <DIR> JSignPdf
09. 12. 2016 17:50 <DIR> K-Lite Codec Pack
09. 12. 2016 17:50 <DIR> Lenovo
09. 12. 2016 17:50 <DIR> McAfee
09. 12. 2016 17:50 <DIR> Microsoft Analysis Services
09. 12. 2016 17:50 <DIR> Microsoft Office
09. 12. 2016 17:50 <DIR> Microsoft Silverlight
09. 12. 2016 17:50 <DIR> Microsoft SQL Server Compact Edition
09. 12. 2016 17:50 <DIR> Microsoft Sync Framework
09. 12. 2016 17:50 <DIR> Microsoft Synchronization Services
09. 12. 2016 17:50 <DIR> Microsoft Visual Studio 8
09. 12. 2016 17:50 <DIR> Microsoft.NET
10. 12. 2016 11:20 <DIR> Mozilla Firefox
11. 12. 2016 09:05 <DIR> Mozilla Maintenance Service
09. 12. 2016 17:50 <DIR> MSBuild
10. 12. 2016 13:16 <DIR> MuseScore 2
09. 12. 2016 17:50 <DIR> Neuratron
10. 12. 2016 09:41 <DIR> Neuratron AudioScore Ultimate Demo
09. 12. 2016 17:50 <DIR> Notepad++
09. 12. 2016 17:51 <DIR> Opera
09. 12. 2016 17:50 <DIR> Qualcomm Atheros
09. 12. 2016 17:50 <DIR> Realtek
09. 12. 2016 17:50 <DIR> Reference Assemblies
09. 12. 2016 17:50 <DIR> Renesas Electronics
09. 12. 2016 17:50 <DIR> RightMark
10. 12. 2016 11:39 <DIR> ScoreCloud Studio
09. 12. 2016 17:50 <DIR> Sibelius Software
09. 12. 2016 17:50 <DIR> Skype
09. 12. 2016 17:50 <DIR> The Witcher 3 Wild Hunt Blood and Wine
09. 12. 2016 17:50 <DIR> VideoLAN
09. 12. 2016 17:50 <DIR> Windows Defender
09. 12. 2016 17:50 <DIR> Windows Mail
09. 12. 2016 17:50 <DIR> Windows Media Player
09. 12. 2016 17:50 <DIR> Windows NT
09. 12. 2016 17:50 <DIR> Windows Photo Viewer
09. 12. 2016 17:50 <DIR> Windows Portable Devices
09. 12. 2016 17:50 <DIR> Windows Sidebar
09. 12. 2016 17:50 <DIR> WindowsPowerShell
0 File(s) 0 bytes
58 Dir(s) 288˙364˙490˙752 bytes free
========= End of CMD: =========
========= dir "C:\PROGRA~3" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\PROGRA~3
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
09. 12. 2016 15:31 <DIR> Acoustica
23. 11. 2016 18:41 <DIR> Adobe
07. 10. 2016 14:15 <DIR> AMD
16. 10. 2016 09:40 57 Ament.ini
18. 11. 2016 09:41 <DIR> Atheros
07. 10. 2016 14:27 <DIR> ATI
09. 12. 2016 17:51 <DIR> Avira
07. 10. 2016 13:50 <DIR> Conexant
07. 10. 2016 14:19 <DIR> DAEMON Tools Lite
07. 10. 2016 14:02 <DIR> Downloaded Installations
16. 10. 2016 09:42 <DIR> HP
16. 10. 2016 09:43 <DIR> HP Photo Creations
07. 10. 2016 13:48 <DIR> Intel
08. 10. 2016 10:44 <DIR> McAfee
22. 11. 2016 13:29 <DIR> MFAData
20. 11. 2016 16:47 <DIR> Microsoft Help
23. 11. 2016 17:43 <DIR> Package Cache
07. 10. 2016 13:36 <DIR> Qualcomm Atheros
07. 10. 2016 13:35 <DIR> Roaming
08. 12. 2016 08:42 <DIR> Skype
16. 10. 2016 09:43 <DIR> Visan
1 File(s) 57 bytes
22 Dir(s) 288˙364˙486˙656 bytes free
========= End of CMD: =========
========= dir "%localappdata%" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\Users\Michal\AppData\Local
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
25. 11. 2016 10:35 <DIR> Adobe
10. 12. 2016 14:12 <DIR> AnthemScore
07. 10. 2016 17:23 <DIR> Apps
07. 10. 2016 14:27 <DIR> ATI
07. 10. 2016 14:10 <DIR> BMExplorer
07. 10. 2016 17:51 <DIR> CEF
14. 12. 2016 20:18 <DIR> CrashDumps
10. 12. 2016 13:01 <DIR> Deployment
23. 11. 2016 07:18 <DIR> Diagnostics
17. 11. 2016 09:48 <DIR> ElevatedDiagnostics
10. 12. 2016 09:21 <DIR> Firefox
10. 12. 2016 12:08 124˙608 GDIPFONTCACHEV1.DAT
04. 11. 2016 08:38 <DIR> Google
16. 10. 2016 09:43 <DIR> HP
08. 10. 2016 10:48 <DIR> Macromedia
21. 11. 2016 19:44 <DIR> MFAData
29. 11. 2016 13:15 <DIR> Microsoft
15. 11. 2016 17:55 <DIR> Microsoft Help
07. 10. 2016 17:22 <DIR> Mozilla
10. 12. 2016 13:16 <DIR> MuseScore
07. 10. 2016 14:17 <DIR> Programs
19. 11. 2016 09:36 7˙605 Resmon.ResmonCfg
17. 12. 2016 10:48 <DIR> Temp
25. 11. 2016 16:11 <DIR> Tempzxpsign0129c5ea464d1bd0
29. 11. 2016 12:41 <DIR> Tempzxpsign0869e5917f164ad8
07. 12. 2016 19:18 <DIR> Tempzxpsign08708443e994ca5f
02. 12. 2016 08:35 <DIR> Tempzxpsign089f88d9de54e320
01. 12. 2016 14:28 <DIR> Tempzxpsign093bb2eebf52505b
23. 11. 2016 18:12 <DIR> Tempzxpsign0b64d6facd5b380b
01. 12. 2016 14:47 <DIR> Tempzxpsign0c6c77f61ea482b9
25. 11. 2016 14:33 <DIR> Tempzxpsign0d50ec84559762e7
25. 11. 2016 10:49 <DIR> Tempzxpsign0e05eb4c4a3dcf5f
30. 11. 2016 18:23 <DIR> Tempzxpsign0e2689382ab7988b
01. 12. 2016 14:05 <DIR> Tempzxpsign0f35eaf1cde8fff5
25. 11. 2016 09:30 <DIR> Tempzxpsign1054cf807590fa05
25. 11. 2016 09:26 <DIR> Tempzxpsign16e3469ef7cbb3d5
25. 11. 2016 14:33 <DIR> Tempzxpsign1a19d272fff3af72
08. 12. 2016 14:26 <DIR> Tempzxpsign1a4957ae9e010c42
01. 12. 2016 14:33 <DIR> Tempzxpsign2030b3848e1630f2
25. 11. 2016 16:50 <DIR> Tempzxpsign22fbe70e649a2567
08. 12. 2016 09:09 <DIR> Tempzxpsign2368e15f51aa66f0
07. 12. 2016 19:18 <DIR> Tempzxpsign26187949b09a3374
24. 11. 2016 16:05 <DIR> Tempzxpsign29d1708b5d4b643f
30. 11. 2016 18:31 <DIR> Tempzxpsign2ae16539ec40858b
26. 11. 2016 17:11 <DIR> Tempzxpsign2c2cd75c0b565547
26. 11. 2016 17:14 <DIR> Tempzxpsign2e2e77420baffa19
26. 11. 2016 18:30 <DIR> Tempzxpsign315e73162b4dc7e7
25. 11. 2016 10:43 <DIR> Tempzxpsign327e396fd5df5acb
25. 11. 2016 16:12 <DIR> Tempzxpsign3322123ed736752e
08. 12. 2016 09:09 <DIR> Tempzxpsign3431ccb9f2be5af8
25. 11. 2016 09:30 <DIR> Tempzxpsign357a12175afd1c22
25. 11. 2016 16:17 <DIR> Tempzxpsign36c0d5a735365b31
25. 11. 2016 16:12 <DIR> Tempzxpsign36e3f51eedc3d245
25. 11. 2016 14:33 <DIR> Tempzxpsign37ee5b7be7723430
29. 11. 2016 15:42 <DIR> Tempzxpsign38237170c6290eb9
25. 11. 2016 16:11 <DIR> Tempzxpsign3c6005916f9dd753
23. 11. 2016 18:02 <DIR> Tempzxpsign3e3f66ca8c66aa74
01. 12. 2016 09:50 <DIR> Tempzxpsign3f0c97113d683f5b
07. 12. 2016 19:10 <DIR> Tempzxpsign4049943a7c9bee0e
25. 11. 2016 10:49 <DIR> Tempzxpsign447d2b9e4e81afab
26. 11. 2016 18:30 <DIR> Tempzxpsign44f91b5941852f0a
24. 11. 2016 16:04 <DIR> Tempzxpsign49eb3cd7f4b7f320
04. 12. 2016 15:26 <DIR> Tempzxpsign4a446d41aab2d9ce
02. 12. 2016 08:36 <DIR> Tempzxpsign4dfed01b68589eff
25. 11. 2016 09:29 <DIR> Tempzxpsign519b2990f93cb040
30. 11. 2016 18:23 <DIR> Tempzxpsign54ffb038181ccd4d
23. 11. 2016 18:07 <DIR> Tempzxpsign56c048b2693f68d5
25. 11. 2016 16:12 <DIR> Tempzxpsign5703aadb952e53fd
07. 12. 2016 18:38 <DIR> Tempzxpsign58387ca720608c0e
23. 11. 2016 18:01 <DIR> Tempzxpsign58da6dbb7fd1acb1
25. 11. 2016 16:50 <DIR> Tempzxpsign5c6ba150a70edfdd
08. 12. 2016 09:09 <DIR> Tempzxpsign5caf336a714ad62c
08. 12. 2016 14:39 <DIR> Tempzxpsign5f5d0463584beaab
08. 12. 2016 09:09 <DIR> Tempzxpsign5fa04cddc00c2968
25. 11. 2016 09:31 <DIR> Tempzxpsign6101293415ace175
08. 12. 2016 09:09 <DIR> Tempzxpsign617167e66810f387
10. 12. 2016 11:16 <DIR> Tempzxpsign6280dd11afb9dba7
08. 12. 2016 09:13 <DIR> Tempzxpsign63449d47d21786f7
03. 12. 2016 12:36 <DIR> Tempzxpsign637f95dfd3deab22
25. 11. 2016 09:31 <DIR> Tempzxpsign64291c0b5a0926b9
08. 12. 2016 09:09 <DIR> Tempzxpsign6630ea7a2aaaea6f
24. 11. 2016 15:40 <DIR> Tempzxpsign676e0b6a7a46bb3b
23. 11. 2016 18:07 <DIR> Tempzxpsign67ece1634f88fc75
25. 11. 2016 09:30 <DIR> Tempzxpsign684ff9c364f03851
25. 11. 2016 09:51 <DIR> Tempzxpsign6b9cc90398a0cb1e
07. 12. 2016 18:38 <DIR> Tempzxpsign6dcc49399f8c408e
25. 11. 2016 09:30 <DIR> Tempzxpsign6e0ff71341284eb7
07. 12. 2016 19:03 <DIR> Tempzxpsign6f2861bb349627f7
01. 12. 2016 09:12 <DIR> Tempzxpsign712e33010fec095c
01. 12. 2016 09:38 <DIR> Tempzxpsign726672b45aceab45
25. 11. 2016 09:29 <DIR> Tempzxpsign73b85cb532a49866
25. 11. 2016 14:49 <DIR> Tempzxpsign749b30851f685ccf
08. 12. 2016 09:09 <DIR> Tempzxpsign75c2f24933b279cf
29. 11. 2016 14:34 <DIR> Tempzxpsign760eae1ed084535c
04. 12. 2016 15:22 <DIR> Tempzxpsign76352d9288f330e9
25. 11. 2016 16:50 <DIR> Tempzxpsign76cb548188a4d357
25. 11. 2016 10:49 <DIR> Tempzxpsign77c9488ef26f1957
29. 11. 2016 14:17 <DIR> Tempzxpsign7ba0c41e17cff74f
25. 11. 2016 16:51 <DIR> Tempzxpsign7c50c242c36dec9a
01. 12. 2016 08:43 <DIR> Tempzxpsign7dd9662d1863cfba
25. 11. 2016 10:35 <DIR> Tempzxpsign7e69804d9b986f44
25. 11. 2016 08:17 <DIR> Tempzxpsign7f0a6b69175290fb
25. 11. 2016 14:29 <DIR> Tempzxpsign81fe6f6e41476c4f
25. 11. 2016 08:17 <DIR> Tempzxpsign8360ad92f119fba9
01. 12. 2016 14:33 <DIR> Tempzxpsign836b3f85dac8e120
01. 12. 2016 14:21 <DIR> Tempzxpsign83da037ce220920b
07. 12. 2016 19:31 <DIR> Tempzxpsign84b58b53f9301053
25. 11. 2016 14:28 <DIR> Tempzxpsign84f007c38e52055b
24. 11. 2016 15:40 <DIR> Tempzxpsign84fcebf5ab499b2f
25. 11. 2016 09:26 <DIR> Tempzxpsign8618836b38fb0f06
13. 12. 2016 13:09 <DIR> Tempzxpsign8924fc58313f079a
02. 12. 2016 08:36 <DIR> Tempzxpsign8a48116b133eec3d
13. 12. 2016 13:08 <DIR> Tempzxpsign8b1b574b55534ede
24. 11. 2016 15:54 <DIR> Tempzxpsign8c637eb919a2e78b
29. 11. 2016 14:18 <DIR> Tempzxpsign8d8256ce50bbc819
01. 12. 2016 08:43 <DIR> Tempzxpsign8f0f885cd9fcb2c8
01. 12. 2016 14:21 <DIR> Tempzxpsign8f2c1411af27bf28
24. 11. 2016 15:41 <DIR> Tempzxpsign8fad4dd83e783b7e
01. 12. 2016 09:50 <DIR> Tempzxpsign90b3543d86bb94b7
26. 11. 2016 17:12 <DIR> Tempzxpsign911d90bba4c005a5
25. 11. 2016 10:50 <DIR> Tempzxpsign915294f1d99e4f2e
25. 11. 2016 14:29 <DIR> Tempzxpsign92a69d7d9dd97171
23. 11. 2016 17:59 <DIR> Tempzxpsign9583690508cdc442
25. 11. 2016 09:31 <DIR> Tempzxpsign95a95dbbbee73014
01. 12. 2016 14:05 <DIR> Tempzxpsign981669be21ccd874
25. 11. 2016 16:51 <DIR> Tempzxpsign9aca18065b137984
25. 11. 2016 14:33 <DIR> Tempzxpsign9b36d278d0a4d778
24. 11. 2016 16:03 <DIR> Tempzxpsign9bd2492a5695ddd6
26. 11. 2016 17:11 <DIR> Tempzxpsign9c1abd5d31566242
25. 11. 2016 10:49 <DIR> Tempzxpsign9c6039ea2b84dba5
24. 11. 2016 16:05 <DIR> Tempzxpsign9dd3a42e09c39db5
23. 11. 2016 14:09 <DIR> Tempzxpsigna10c87b8ec352cb1
07. 12. 2016 18:41 <DIR> Tempzxpsigna4112098cba3b545
07. 12. 2016 19:19 <DIR> Tempzxpsigna64625fb825af44a
25. 11. 2016 14:28 <DIR> Tempzxpsigna66c9190cdaad7ed
24. 11. 2016 16:05 <DIR> Tempzxpsigna734fffac3057565
13. 12. 2016 13:09 <DIR> Tempzxpsignaa0a89b2b72d676c
25. 11. 2016 09:27 <DIR> Tempzxpsignac277e113a0ac49f
29. 11. 2016 15:58 <DIR> Tempzxpsignad766ffe9529aa1c
01. 12. 2016 14:46 <DIR> Tempzxpsignafa4cfdfa387e7f7
25. 11. 2016 09:30 <DIR> Tempzxpsignb0bad4c992317797
03. 12. 2016 12:36 <DIR> Tempzxpsignb9a0456209b0fb90
13. 12. 2016 13:08 <DIR> Tempzxpsignb9d28553828958ec
08. 12. 2016 14:26 <DIR> Tempzxpsignbbb6b284072599f2
04. 12. 2016 15:23 <DIR> Tempzxpsignbbb9965e4c421aac
08. 12. 2016 09:09 <DIR> Tempzxpsignbee8659ec374bfd9
25. 11. 2016 16:51 <DIR> Tempzxpsignbffc69d2e5d60b32
24. 11. 2016 15:56 <DIR> Tempzxpsignc0213cc5ef6d97b1
25. 11. 2016 10:52 <DIR> Tempzxpsignc172002c811ca5f4
25. 11. 2016 09:30 <DIR> Tempzxpsignc19a8417ded9332d
25. 11. 2016 14:29 <DIR> Tempzxpsignc1c3e7637aa83065
24. 11. 2016 15:56 <DIR> Tempzxpsignc1d0bd168acb068e
01. 12. 2016 14:05 <DIR> Tempzxpsignc416a405298374d2
04. 12. 2016 15:23 <DIR> Tempzxpsignc45ea8219c449654
24. 11. 2016 15:54 <DIR> Tempzxpsignc6439a6e31866387
24. 11. 2016 15:57 <DIR> Tempzxpsignc73dcb2132a228ae
29. 11. 2016 12:39 <DIR> Tempzxpsignc95b42e29036466e
07. 12. 2016 19:31 <DIR> Tempzxpsignc98638ed7eea07cb
01. 12. 2016 09:12 <DIR> Tempzxpsignc9a5cc778c404459
02. 12. 2016 08:35 <DIR> Tempzxpsignca2078198d882286
10. 12. 2016 11:16 <DIR> Tempzxpsignca5c412747d76b3f
01. 12. 2016 09:50 <DIR> Tempzxpsigncde8aac452b4324e
01. 12. 2016 08:43 <DIR> Tempzxpsignce36f1c8dc468bf1
07. 12. 2016 19:32 <DIR> Tempzxpsigncee4ec77b8cd039b
07. 12. 2016 19:03 <DIR> Tempzxpsigncf9de7cb9f6227d4
04. 12. 2016 15:27 <DIR> Tempzxpsignd1bf3c4c02a0b68b
24. 11. 2016 15:40 <DIR> Tempzxpsignd396a344c325b7df
24. 11. 2016 16:03 <DIR> Tempzxpsignd3e8951f534be6da
03. 12. 2016 12:36 <DIR> Tempzxpsignd5da385de6fd2890
29. 11. 2016 14:17 <DIR> Tempzxpsignd65fbc1f5a9677ef
07. 12. 2016 18:47 <DIR> Tempzxpsignd67b7683074df9c9
25. 11. 2016 08:18 <DIR> Tempzxpsignd694ce34272bd123
26. 11. 2016 18:37 <DIR> Tempzxpsignd7cb58767b595773
25. 11. 2016 10:50 <DIR> Tempzxpsigndbd601fe96fcde09
23. 11. 2016 14:05 <DIR> Tempzxpsigndbe751830fc4ef17
25. 11. 2016 14:29 <DIR> Tempzxpsigndcf4469ddea8caf5
02. 12. 2016 08:35 <DIR> Tempzxpsignde71e76c18358e83
08. 12. 2016 14:33 <DIR> Tempzxpsigne006d29ead18caf3
29. 11. 2016 12:39 <DIR> Tempzxpsigne0d742a69f007cec
08. 12. 2016 14:36 <DIR> Tempzxpsigne1ced321dfdfb9a4
23. 11. 2016 18:07 <DIR> Tempzxpsigne208c4645b61e0ca
23. 11. 2016 17:59 <DIR> Tempzxpsigne28d99f7ba0940de
25. 11. 2016 10:48 <DIR> Tempzxpsigne3bfa15279d8cc61
13. 12. 2016 13:09 <DIR> Tempzxpsigne52d9fbe0f737919
24. 11. 2016 15:54 <DIR> Tempzxpsigne7114b6c0570ce14
04. 12. 2016 15:22 <DIR> Tempzxpsigne825740709a62977
24. 11. 2016 16:05 <DIR> Tempzxpsignea5367d43c3157e8
25. 11. 2016 09:27 <DIR> Tempzxpsignea69996a3d358db7
26. 11. 2016 18:37 <DIR> Tempzxpsignea81d48a8b65529b
13. 12. 2016 13:09 <DIR> Tempzxpsigneb139762080477ae
29. 11. 2016 12:39 <DIR> Tempzxpsignebb2588b068b8ce7
02. 12. 2016 08:55 <DIR> Tempzxpsignedd1f5a77ec3e170
08. 12. 2016 14:26 <DIR> Tempzxpsignee60114fb4b1736e
04. 12. 2016 15:23 <DIR> Tempzxpsignee9598d774c5a0ab
25. 11. 2016 10:35 <DIR> Tempzxpsignef004a92cf6d8dd3
01. 12. 2016 14:33 <DIR> Tempzxpsignef86ed7a47234b5f
25. 11. 2016 10:50 <DIR> Tempzxpsignf17d395d597a11d7
08. 12. 2016 14:34 <DIR> Tempzxpsignf1f638c1177a31b0
23. 11. 2016 14:05 <DIR> Tempzxpsignf268b732b53d6e41
29. 11. 2016 15:59 <DIR> Tempzxpsignf2f5363d549be76a
01. 12. 2016 14:46 <DIR> Tempzxpsignf5b96ce0dbd76646
26. 11. 2016 18:37 <DIR> Tempzxpsignf638436609388d93
23. 11. 2016 17:59 <DIR> Tempzxpsignfb2bea506765f1fd
08. 12. 2016 14:33 <DIR> Tempzxpsignfc3eb4accfdb44f1
23. 11. 2016 14:05 <DIR> Tempzxpsignfdbca61b281d99b4
26. 11. 2016 18:37 <DIR> Tempzxpsignfdc10a1f9615cd11
10. 12. 2016 11:16 <DIR> Tempzxpsignff25e483c072c8cf
08. 10. 2016 10:44 <DIR> tkdata
10. 12. 2016 13:22 <DIR> VirtualStore
09. 10. 2016 09:44 17˙408 WebpageIcons.db
3 File(s) 149˙621 bytes
209 Dir(s) 288˙364˙474˙368 bytes free
========= End of CMD: =========
========= dir "%appdata%" =========
Volume in drive C has no label.
Volume Serial Number is 0815-D1D2
Directory of C:\Users\Michal\AppData\Roaming
17. 12. 2016 10:48 <DIR> .
17. 12. 2016 10:48 <DIR> ..
09. 12. 2016 15:31 <DIR> Acoustica
23. 11. 2016 18:41 <DIR> Adobe
07. 10. 2016 14:06 <DIR> Atheros
07. 10. 2016 14:27 <DIR> ATI
11. 12. 2016 13:06 <DIR> Audacity
30. 11. 2016 18:22 <DIR> Brackets
07. 10. 2016 14:19 <DIR> DAEMON Tools Lite
08. 10. 2016 10:51 <DIR> Easeware
10. 12. 2016 09:21 <DIR> Firefox
23. 10. 2016 10:10 <DIR> HpUpdate
07. 10. 2016 13:20 <DIR> Identities
07. 10. 2016 13:39 <DIR> InstallShield
07. 10. 2016 13:35 <DIR> Intel
07. 10. 2016 13:38 <DIR> Intel Corporation
07. 10. 2016 17:13 <DIR> Macromedia
16. 11. 2016 17:13 <DIR> Media Player Classic
07. 10. 2016 17:16 <DIR> Mozilla
10. 12. 2016 17:52 <DIR> MuseScore
09. 12. 2016 16:40 <DIR> Neuratron
01. 11. 2016 11:44 <DIR> Notepad++
09. 12. 2016 17:50 <DIR> Profiles
11. 10. 2016 21:35 607˙138 Scorch_Install.log
10. 12. 2016 14:55 <DIR> ScoreCloud
11. 10. 2016 21:36 <DIR> Sibelius Software
17. 12. 2016 10:23 <DIR> Skype
09. 12. 2016 15:32 <DIR> SynthMaker
10. 12. 2016 20:08 <DIR> uTorrent
09. 12. 2016 15:31 <DIR> vlc
08. 10. 2016 12:25 <DIR> WinRAR
1 File(s) 607˙138 bytes
30 Dir(s) 288˙364˙470˙272 bytes free
========= End of CMD: =========
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 35875942 B
Java, Flash, Steam htmlcache => 5451 B
Windows/system/drivers => 1006964 B
Edge => 0 B
Chrome => 1545542 B
Firefox => 391636641 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 33058 B
Public => 0 B
ProgramData => 0 B
systemprofile => 33186 B
systemprofile32 => 5405476 B
LocalService => 66228 B
NetworkService => 461788 B
Michal => 160251609 B
WOUTempAdmin => 25942 B
RecycleBin => 4019192 B
EmptyTemp: => 580.6 MB temporary data Removed.
================================
The system needed a reboot.
==== End of Fixlog 10:48:54 ====