Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Help you files

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Nela_M
Návštěvník
Návštěvník
Příspěvky: 132
Registrován: 05 úno 2009 18:31

Help you files

#1 Příspěvek od Nela_M »

Dobrý den, v PC se mi začaly objevovat txt soubory "HELP YOUR FILES", nějak se mi to nezdá, proto prosím o kontrolu logu.
Děkuji moc Helena

Logfile of random's system information tool 1.10 (written by random/random)
Run by Helenka at 2016-03-31 18:34:25
Microsoft Windows 8.1
System drive C: has 912 GB (96%) free of 953 GB
Total RAM: 5578 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:34:35, on 31. 3. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe
C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Helenka.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/?gfe_rd=cr&ei=Hz3 ... gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe
O4 - HKLM\..\Run: [Norton Online Backup] C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Unqtmedia] regsvr32.exe C:\Users\Helenka\AppData\Local\Unqtmedia\WldPlugin.dll
O4 - HKCU\..\Run: [Adobe Reader Update32] "C:\Users\Helenka\AppData\Local\Temp\KB424328703.exe"
O4 - HKCU\..\Run: [AdobeFlashPlayers32] "C:\Users\Helenka\AppData\Roaming\AdobeFlashPlayer_c05a2ddbccba96cf.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKLM\..\Policies\Explorer\Run: [BtvStack] "C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
O4 - HKUS\S-1-5-21-2520944081-2684202109-2728405321-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Unqtmedia] regsvr32.exe C:\Users\Helenka\AppData\Local\Unqtmedia\WldPlugin.dll (User '?')
O4 - HKUS\S-1-5-21-2520944081-2684202109-2728405321-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [Adobe Reader Update32] "C:\Users\Helenka\AppData\Local\Temp\KB424328703.exe" (User '?')
O4 - HKUS\S-1-5-21-2520944081-2684202109-2728405321-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [AdobeFlashPlayers32] "C:\Users\Helenka\AppData\Roaming\AdobeFlashPlayer_c05a2ddbccba96cf.exe" (User '?')
O4 - HKUS\S-1-5-21-2520944081-2684202109-2728405321-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR (User '?')
O4 - Global Startup: Acer Backup Manager Tray.lnk = C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
O23 - Service: Conexant Audio Message Service (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: Device Fast-lane Service (DeviceFastLaneService) - Acer Incorporated - C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: EgisTec Ticket Service - Egis Technology Inc. - C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe
O23 - Service: ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: McAfee Home Network (HomeNetSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee AP Service (McAPExe) - McAfee, Inc. - C:\Program Files\McAfee\MSC\McAPExe.exe
O23 - Service: McAfee Activation Service (McAWFwk) - McAfee, Inc. - C:\Program Files\mcafee\msc\McAWFwk.exe
O23 - Service: McAfee Boot Delay Start Service (McBootDelayStartSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee CSP Service (mccspsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\CSP\1.8.267.0\McCSPServiceHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee OOBE Service (McOobeSv) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Platform Services (mcpltsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Service Controller (mfemms) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - Unknown owner - C:\Windows\system32\mfevtps.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Norton Online Backup (NOBU) - Symantec Corporation - C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
O23 - Service: NTI IScheduleSvc - NTI Corporation - C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: Intel Security PEF Service (PEFService) - Intel Security, Inc. - C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
O23 - Service: Dritek RF Button Command Service (RfButtonDriverService) - Dritek System INC. - C:\Windows\RfBtnSvc64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12981 bytes

======Listing Processes======





wininit.exe

winlogon.exe

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
atieclxx
C:\WINDOWS\system32\svchost.exe -k NetworkService
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe"
C:\Windows\system32\CxAudMsg64.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
dashost.exe {30bba33b-9ff1-4a92-9abb9c6e7144b35e}
"C:\Program Files (x86)\Launch Manager\dsiwmis.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe"
"C:\Windows\system32\mfevtps.exe"
"C:\Windows\system32\mfevtps.exe" -mms
"C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe" SERVICE
"C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe"
"C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe"
C:\Windows\RfBtnSvc64.exe
"C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe" -mms
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc
"C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe"
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\McAfee\MSC\McAPExe.exe"
"C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe"
"C:\Program Files (x86)\Launch Manager\LMutilps32.exe" --system-level --system-level-mutex="Local\{B904A927-FE6B-48fd-8C83-6B807BED1F9C}" --enable-wmi-window --enable-setforeground-window --enable-kbhook-window
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" /starttray
"C:\Program Files (x86)\Launch Manager\LManager.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
taskhostex.exe
"C:\Program Files\Common Files\McAfee\CSP\1.8.267.0\McCSPServiceHost.exe"
"C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe"
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerTray.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtTray.exe"
"C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe"
"C:\Program Files\Elantech\ETDTouch.exe"
"C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe"
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe"
C:\PROGRA~1\COMMON~1\McAfee\Platform\McUICnt.exe /platui
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" -h -k
"C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe"
"C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuBrowserIEAgent.exe"
"C:\Program Files\Acer\Acer Instant Service\InstantUpdate\iuEmailOutlookAgent.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Helenka\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=49.0.2623.110 --handshake-handle=0x14c
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto -scheduled
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="5824.0.515505187\59796848" --supports-dual-gpus=false --gpu-driver-bug-workarounds=3,11,25,54 --gpu-vendor-id=0x1002 --gpu-device-id=0x9908 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=13.251.9001.1001 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=en-US --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/14DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_39/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="5824.2.877674919\94802602" /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=en-US --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/14DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_39/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="5824.3.1487919478\420934380" /prefetch:1
"C:\Program Files\Common Files\McAfee\Platform\Core\mchost.exe" {429b534b-5bb0-4a3c-9682-62a96770e0b3} /pid=2748
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=en-US --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/14DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_39/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="5824.5.1055427798\246057597" /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --lang=en-US --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*CrossDevicePromo/14DaySingleProfile/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/IntelligentSessionRestore/Enabled2/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/Unused_2/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PreRead/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Disabled/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SpdyEnableDependencies/Default/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_39/*UMA-Uniformity-Trial-10-Percent/group_06/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_03/*UMA-Uniformity-Trial-5-Percent/group_09/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Default/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/ --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553 --channel="5824.8.1474630692\517690804" /prefetch:1
"C:\Program Files\EgisTec IPS\PMMUpdate.exe"
"C:\Program Files\EgisTec IPS\EgisUpdate.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 568 572 580 65536 576

"C:\Users\Helenka\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8D10F6C4-0E01-4BD4-8601-11AC1FDF8126}]
CIESpeechBHO Class - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll [2013-01-28 66688]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-03-19 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-03-19 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2012-11-20 2873744]
"BtPreLoad"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtPreLoad.exe [2013-01-28 64640]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2015-09-12 169744]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [2013-01-28 132736]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Unqtmedia"=regsvr32.exe C:\Users\Helenka\AppData\Local\Unqtmedia\WldPlugin.dll []
"Adobe Reader Update32"=C:\Users\Helenka\AppData\Local\Temp\KB424328703.exe [2016-03-29 83456]
"AdobeFlashPlayers32"=C:\Users\Helenka\AppData\Roaming\AdobeFlashPlayer_c05a2ddbccba96cf.exe [2016-03-29 83456]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-03-11 8686296]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2016-03-03 723904]
"LManager"= []
"AmIcoSinglun64"=C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [2012-09-26 373592]
"Norton Online Backup"=C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [2012-08-15 2994880]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-01-29 594992]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
"BtvStack"=C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [2013-01-28 132736]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Acer Backup Manager Tray.lnk - C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcapexe]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McNaiAnn]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcpltsvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfeaack]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfeaack.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfeavfk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfeavfk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefire]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfemms]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfencbdc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfencbdc.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfetdi2k]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfetdi2k.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfevtp]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableCAD"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"TaskbarNoNotification"=1
"HideSCAHealth"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"TaskbarNoNotification"=1
"HideSCAHealth"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"midi2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-03-31 18:34:25 ----D---- C:\rsit
2016-03-31 18:34:25 ----D---- C:\Program Files\trend micro
2016-03-29 21:02:13 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2016-03-29 21:01:47 ----D---- C:\ProgramData\Malwarebytes
2016-03-29 21:01:47 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-29 21:01:47 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2016-03-29 21:01:47 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2016-03-29 21:01:47 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2016-03-29 20:56:46 ----A---- C:\WINDOWS\HELP_YOUR_FILES.TXT
2016-03-29 20:55:46 ----A---- C:\Users\Helenka\AppData\Roaming\HELP_YOUR_FILES.TXT
2016-03-29 20:55:27 ----D---- C:\Program Files\CCleaner
2016-03-29 20:53:10 ----A---- C:\ProgramData\HELP_YOUR_FILES.TXT
2016-03-29 20:53:10 ----A---- C:\Program Files\HELP_YOUR_FILES.TXT
2016-03-29 20:53:10 ----A---- C:\Program Files (x86)\HELP_YOUR_FILES.TXT
2016-03-29 20:52:39 ----A---- C:\HELP_YOUR_FILES.TXT
2016-03-29 20:52:37 ----A---- C:\Users\Helenka\AppData\Roaming\AdobeFlashPlayer_c05a2ddbccba96cf.exe
2016-03-24 23:01:02 ----D---- C:\WINDOWS\Minidump
2016-03-24 10:39:34 ----D---- C:\Program Files (x86)\Microsoft Works
2016-03-24 10:39:15 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2016-03-24 10:39:01 ----D---- C:\WINDOWS\PCHEALTH
2016-03-24 10:37:06 ----D---- C:\Program Files\Microsoft Office
2016-03-24 10:35:33 ----D---- C:\ProgramData\Microsoft Help
2016-03-24 10:34:55 ----RHD---- C:\MSOCache
2016-03-24 10:32:17 ----A---- C:\WINDOWS\system32\drivers\mfeaack.sys
2016-03-24 10:29:59 ----D---- C:\ProgramData\Intel Security
2016-03-24 10:28:52 ----D---- C:\Program Files\Common Files\Intel Security
2016-03-24 10:24:42 ----D---- C:\Program Files\Common Files\AV
2016-03-23 18:29:06 ----D---- C:\ProgramData\PopCap Games
2016-03-23 15:27:35 ----D---- C:\Program Files (x86)\Apple Software Update
2016-03-23 15:12:58 ----D---- C:\ProgramData\Package Cache
2016-03-23 15:07:29 ----D---- C:\Users\Helenka\AppData\Roaming\ATI
2016-03-23 15:07:14 ----D---- C:\Users\Helenka\AppData\Roaming\Identities
2016-03-23 15:02:47 ----A---- C:\WINDOWS\system32\drivers\amdkmpfd.sys
2016-03-23 00:38:14 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2016-03-23 00:13:59 ----SD---- C:\Users\Helenka\AppData\Roaming\Microsoft
2016-03-23 00:02:33 ----D---- C:\Program Files\Elantech
2016-03-23 00:02:27 ----D---- C:\AMD
2016-03-23 00:02:16 ----D---- C:\Program Files\Common Files\ATI Technologies
2016-03-23 00:02:11 ----D---- C:\Program Files\AMD
2016-03-23 00:01:52 ----D---- C:\ProgramData\Conexant
2016-03-23 00:01:51 ----D---- C:\Program Files\CONEXANT
2016-03-23 00:00:54 ----D---- C:\WINDOWS\Prefetch
2016-03-22 23:57:08 ----SHD---- C:\Recovery
2016-03-22 23:56:53 ----DC---- C:\WINDOWS\Panther
2016-03-22 23:49:35 ----A---- C:\WINDOWS\system32\fhcpl.dll
2016-03-22 23:49:13 ----A---- C:\WINDOWS\SYSWOW64\rdvidcrl.dll
2016-03-22 23:49:13 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2016-03-22 23:49:13 ----A---- C:\WINDOWS\system32\rdvidcrl.dll
2016-03-22 23:49:13 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-03-22 23:48:48 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2016-03-22 23:48:48 ----A---- C:\WINDOWS\system32\d2d1.dll
2016-03-22 23:48:37 ----A---- C:\WINDOWS\system32\SettingsHandlers.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\WSDApi.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\WinSCard.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\vsstrace.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\vssapi.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\rasser.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\rasmxs.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\rasdiag.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\rascfg.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\QSVRMGMT.DLL
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\QSHVHOST.DLL
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\eventcls.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\WSDMon.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\WSDApi.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\WinSCard.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\VSSVC.exe
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\vsstrace.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\vssapi.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\vpnike.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\SyncEngine.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\spoolsv.exe
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\SkyDriveTelemetry.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\SkyDrive.exe
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\rasser.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\rasmxs.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\rasdiag.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\rascfg.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\rasapi32.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\QSVRMGMT.DLL
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\QSHVHOST.DLL
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\mfplat.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\eventcls.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\drivers\agilevpn.sys
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\dnsapi.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-22 23:47:51 ----A---- C:\WINDOWS\splwow64.exe
2016-03-22 23:45:37 ----A---- C:\WINDOWS\system32\msra.exe
2016-03-22 23:44:42 ----A---- C:\WINDOWS\SYSWOW64\dbghelp.dll
2016-03-22 23:44:42 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2016-03-22 23:44:42 ----A---- C:\WINDOWS\system32\dbghelp.dll
2016-03-22 23:44:42 ----A---- C:\WINDOWS\system32\dbgeng.dll
2016-03-22 23:44:19 ----A---- C:\WINDOWS\SYSWOW64\wscapi.dll
2016-03-22 23:44:19 ----A---- C:\WINDOWS\system32\wscsvc.dll
2016-03-22 23:44:19 ----A---- C:\WINDOWS\system32\wscapi.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMVXENCD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMVSENCD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMVSDECD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMVENCOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOE.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMADMOE.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\VIDRESZR.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\RESAMPLEDMO.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2adec.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\MPG4DECD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\MP4SDECD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\MP43DECD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\MP3DMOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\MFWMAAEC.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\mfvdsp.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\devenum.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\SYSWOW64\COLORCNV.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMVXENCD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMVSENCD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMVSDECD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMVENCOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMSPDMOE.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMSPDMOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMADMOE.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\VIDRESZR.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\SysFxUI.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\RESAMPLEDMO.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\quartz.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\msmpeg2adec.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\MPG4DECD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\MP4SDECD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\MP43DECD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\MP3DMOD.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\MFWMAAEC.DLL
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\mfvdsp.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\mfps.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\evr.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\devenum.dll
2016-03-22 23:43:54 ----A---- C:\WINDOWS\system32\COLORCNV.DLL
2016-03-22 23:43:14 ----A---- C:\WINDOWS\SYSWOW64\PhotoMetadataHandler.dll
2016-03-22 23:43:14 ----A---- C:\WINDOWS\system32\PhotoMetadataHandler.dll
2016-03-22 23:43:01 ----A---- C:\WINDOWS\SYSWOW64\notepad.exe
2016-03-22 23:43:01 ----A---- C:\WINDOWS\system32\notepad.exe
2016-03-22 23:43:01 ----A---- C:\WINDOWS\notepad.exe
2016-03-22 23:42:50 ----A---- C:\WINDOWS\system32\drivers\udfs.sys
2016-03-22 23:42:26 ----A---- C:\WINDOWS\SYSWOW64\authz.dll
2016-03-22 23:42:26 ----A---- C:\WINDOWS\system32\authz.dll
2016-03-22 23:42:15 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2016-03-22 23:42:15 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2016-03-22 23:41:57 ----A---- C:\WINDOWS\system32\SystemSettingsDatabase.dll
2016-03-22 23:41:57 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2016-03-22 23:41:57 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-03-22 23:41:57 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2016-03-22 23:41:57 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2016-03-22 23:41:24 ----A---- C:\WINDOWS\SYSWOW64\msiexec.exe
2016-03-22 23:41:24 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2016-03-22 23:41:24 ----A---- C:\WINDOWS\system32\msiexec.exe
2016-03-22 23:41:24 ----A---- C:\WINDOWS\system32\msi.dll
2016-03-22 23:41:05 ----A---- C:\WINDOWS\system32\seclogon.dll
2016-03-22 23:40:55 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2016-03-22 23:40:54 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2016-03-22 23:40:42 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2016-03-22 23:40:42 ----A---- C:\WINDOWS\system32\oleaut32.dll
2016-03-22 23:40:14 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-03-22 23:40:14 ----A---- C:\WINDOWS\system32\bdesvc.dll
2016-03-22 23:39:43 ----A---- C:\WINDOWS\system32\drivers\sermouse.sys
2016-03-22 23:39:43 ----A---- C:\WINDOWS\system32\drivers\mouhid.sys
2016-03-22 23:39:43 ----A---- C:\WINDOWS\system32\drivers\mouclass.sys
2016-03-22 23:39:43 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2016-03-22 23:39:43 ----A---- C:\WINDOWS\system32\drivers\kbdclass.sys
2016-03-22 23:39:43 ----A---- C:\WINDOWS\system32\drivers\i8042prt.sys
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-utility-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-time-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-string-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-process-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-private-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-math-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-locale-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-heap-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-environment-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-convert-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\SYSWOW64\api-ms-win-crt-conio-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll
2016-03-22 23:39:20 ----A---- C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll
2016-03-22 23:39:08 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-03-22 23:39:08 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-03-22 23:38:26 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-03-22 23:38:26 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\SYSWOW64\mtxoci.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\SYSWOW64\msorcl32.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\SYSWOW64\EncDec.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\SYSWOW64\CPFilters.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\SYSWOW64\cfgbkend.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\system32\mtxoci.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\system32\EncDec.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\system32\CPFilters.dll
2016-03-22 23:38:10 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2016-03-22 23:37:37 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-03-22 23:37:37 ----A---- C:\WINDOWS\system32\shell32.dll
2016-03-22 23:37:16 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-22 23:37:06 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2016-03-22 23:36:44 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-03-22 23:36:44 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-03-22 23:35:55 ----A---- C:\WINDOWS\system32\drivers\bthhfenum.sys
2016-03-22 23:35:43 ----A---- C:\WINDOWS\SYSWOW64\WSShared.dll
2016-03-22 23:35:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-22 23:35:43 ----A---- C:\WINDOWS\system32\WSShared.dll
2016-03-22 23:35:43 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-22 23:34:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-03-22 23:34:57 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-03-22 23:34:26 ----A---- C:\WINDOWS\system32\nlasvc.dll
2016-03-22 23:34:26 ----A---- C:\WINDOWS\system32\ncsi.dll
2016-03-22 23:34:07 ----A---- C:\WINDOWS\system32\LockScreenContentServer.exe
2016-03-22 23:33:34 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2016-03-22 23:33:34 ----A---- C:\WINDOWS\system32\crypt32.dll
2016-03-22 23:33:18 ----A---- C:\WINDOWS\SYSWOW64\eapphost.dll
2016-03-22 23:33:18 ----A---- C:\WINDOWS\SYSWOW64\eappgnui.dll
2016-03-22 23:33:18 ----A---- C:\WINDOWS\SYSWOW64\eappcfg.dll
2016-03-22 23:33:18 ----A---- C:\WINDOWS\SYSWOW64\eapp3hst.dll
2016-03-22 23:33:18 ----A---- C:\WINDOWS\system32\eapphost.dll
2016-03-22 23:33:18 ----A---- C:\WINDOWS\system32\eappgnui.dll
2016-03-22 23:33:18 ----A---- C:\WINDOWS\system32\eappcfg.dll
2016-03-22 23:33:18 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2016-03-22 23:32:59 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2016-03-22 23:32:59 ----A---- C:\WINDOWS\SYSWOW64\FWPUCLNT.DLL
2016-03-22 23:32:59 ----A---- C:\WINDOWS\system32\nshwfp.dll
2016-03-22 23:32:59 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2016-03-22 23:32:59 ----A---- C:\WINDOWS\system32\FWPUCLNT.DLL
2016-03-22 23:32:59 ----A---- C:\WINDOWS\system32\drivers\wfplwfs.sys
2016-03-22 23:32:59 ----A---- C:\WINDOWS\system32\BFE.DLL
2016-03-22 23:32:20 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2016-03-22 23:32:20 ----A---- C:\WINDOWS\system32\storagewmi.dll
2016-03-22 23:31:49 ----A---- C:\WINDOWS\SYSWOW64\tdh.dll
2016-03-22 23:31:49 ----A---- C:\WINDOWS\system32\UtcResources.dll
2016-03-22 23:31:49 ----A---- C:\WINDOWS\system32\tdh.dll
2016-03-22 23:31:49 ----A---- C:\WINDOWS\system32\diagtrack.dll
2016-03-22 23:31:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2016-03-22 23:31:30 ----A---- C:\WINDOWS\SYSWOW64\glcndFilter.dll
2016-03-22 23:31:30 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-22 23:31:30 ----A---- C:\WINDOWS\system32\glcndFilter.dll
2016-03-22 23:30:24 ----A---- C:\WINDOWS\system32\rdpudd.dll
2016-03-22 23:30:24 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2016-03-22 23:29:40 ----A---- C:\WINDOWS\SYSWOW64\comctl32.dll
2016-03-22 23:29:40 ----A---- C:\WINDOWS\system32\comctl32.dll
2016-03-22 23:29:21 ----A---- C:\WINDOWS\SYSWOW64\WMPhoto.dll
2016-03-22 23:29:21 ----A---- C:\WINDOWS\system32\WMPhoto.dll
2016-03-22 23:29:04 ----A---- C:\WINDOWS\SYSWOW64\clfsw32.dll
2016-03-22 23:29:04 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2016-03-22 23:29:04 ----A---- C:\WINDOWS\system32\clfsw32.dll
2016-03-22 23:28:47 ----A---- C:\WINDOWS\SYSWOW64\tracerpt.exe
2016-03-22 23:28:47 ----A---- C:\WINDOWS\SYSWOW64\sechost.dll
2016-03-22 23:28:47 ----A---- C:\WINDOWS\system32\tracerpt.exe
2016-03-22 23:28:47 ----A---- C:\WINDOWS\system32\sechost.dll
2016-03-22 23:28:22 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2016-03-22 23:28:22 ----A---- C:\WINDOWS\system32\authui.dll
2016-03-22 23:28:04 ----A---- C:\WINDOWS\system32\drivers\usb8023.sys
2016-03-22 23:27:20 ----A---- C:\WINDOWS\system32\csrsrv.dll
2016-03-22 23:27:20 ----A---- C:\WINDOWS\system32\basesrv.dll
2016-03-22 23:26:58 ----A---- C:\WINDOWS\SYSWOW64\WinSync.dll
2016-03-22 23:26:58 ----A---- C:\WINDOWS\system32\WinSync.dll
2016-03-22 23:26:42 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-03-22 23:26:42 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-03-22 23:26:27 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2016-03-22 23:26:27 ----A---- C:\WINDOWS\system32\msctf.dll
2016-03-22 23:26:11 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2016-03-22 23:26:11 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2016-03-22 23:25:53 ----A---- C:\WINDOWS\system32\drivers\bthpan.sys
2016-03-22 23:25:34 ----A---- C:\WINDOWS\SYSWOW64\wuwebv.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\SYSWOW64\wuapp.exe
2016-03-22 23:25:34 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wuwebv.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\WUSettingsProvider.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wups2.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wups.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wudriver.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wucltux.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wuapp.exe
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\wuapi.dll
2016-03-22 23:25:34 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2016-03-22 23:25:09 ----A---- C:\WINDOWS\system32\drivers\ahcache.sys
2016-03-22 23:24:53 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-03-22 23:24:31 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2016-03-22 23:24:31 ----A---- C:\WINDOWS\SYSWOW64\msvcp120_clr0400.dll
2016-03-22 23:24:31 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2016-03-22 23:24:31 ----A---- C:\WINDOWS\system32\msvcp120_clr0400.dll
2016-03-22 23:23:26 ----A---- C:\WINDOWS\system32\TSWbPrxy.exe
2016-03-22 23:23:11 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2016-03-22 23:22:41 ----A---- C:\WINDOWS\SYSWOW64\rsaenh.dll
2016-03-22 23:22:41 ----A---- C:\WINDOWS\system32\rsaenh.dll
2016-03-22 23:22:00 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2016-03-22 23:22:00 ----A---- C:\WINDOWS\system32\netlogon.dll
2016-03-22 23:21:43 ----A---- C:\WINDOWS\system32\wininit.exe
2016-03-22 23:21:03 ----A---- C:\WINDOWS\system32\drivers\rfcomm.sys
2016-03-22 23:21:03 ----A---- C:\WINDOWS\system32\drivers\hidbth.sys
2016-03-22 23:21:03 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-03-22 23:19:26 ----A---- C:\WINDOWS\SYSWOW64\wpdshext.dll
2016-03-22 23:19:26 ----A---- C:\WINDOWS\system32\wpdshext.dll
2016-03-22 23:19:09 ----A---- C:\WINDOWS\SYSWOW64\mfc42u.dll
2016-03-22 23:19:09 ----A---- C:\WINDOWS\SYSWOW64\mfc42.dll
2016-03-22 23:19:09 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2016-03-22 23:19:09 ----A---- C:\WINDOWS\system32\mfc42u.dll
2016-03-22 23:19:09 ----A---- C:\WINDOWS\system32\mfc42.dll
2016-03-22 23:19:09 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2016-03-22 23:18:37 ----A---- C:\WINDOWS\SYSWOW64\qedit.dll
2016-03-22 23:18:37 ----A---- C:\WINDOWS\system32\qedit.dll
2016-03-22 23:17:57 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2016-03-22 23:17:43 ----A---- C:\WINDOWS\system32\NcdAutoSetup.dll
2016-03-22 23:17:29 ----A---- C:\WINDOWS\system32\ubpm.dll
2016-03-22 23:17:01 ----A---- C:\WINDOWS\system32\lsm.dll
2016-03-22 23:16:39 ----A---- C:\WINDOWS\system32\drivers\USBXHCI.SYS
2016-03-22 23:16:11 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2016-03-22 23:15:57 ----A---- C:\WINDOWS\SYSWOW64\rgb9rast.dll
2016-03-22 23:15:44 ----A---- C:\WINDOWS\system32\win32k.sys
2016-03-22 23:14:56 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2016-03-22 23:14:56 ----A---- C:\WINDOWS\system32\advapi32.dll
2016-03-22 23:14:36 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-03-22 23:14:36 ----A---- C:\WINDOWS\SYSWOW64\WMASF.DLL
2016-03-22 23:14:36 ----A---- C:\WINDOWS\system32\wmp.dll
2016-03-22 23:14:36 ----A---- C:\WINDOWS\system32\WMASF.DLL
2016-03-22 23:14:05 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2016-03-22 23:14:05 ----A---- C:\WINDOWS\SYSWOW64\certcli.dll
2016-03-22 23:14:05 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-03-22 23:14:05 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-03-22 23:14:05 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2016-03-22 23:14:05 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2016-03-22 23:14:05 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-03-22 23:14:05 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-03-22 23:14:05 ----A---- C:\WINDOWS\system32\dpapisrv.dll
2016-03-22 23:14:05 ----A---- C:\WINDOWS\system32\certcli.dll
2016-03-22 23:13:31 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2016-03-22 23:13:31 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2016-03-22 23:13:01 ----A---- C:\WINDOWS\system32\apphelp.dll
2016-03-22 23:12:44 ----A---- C:\WINDOWS\SYSWOW64\StorageContextHandler.dll
2016-03-22 23:12:44 ----A---- C:\WINDOWS\system32\StorageContextHandler.dll
2016-03-22 23:12:17 ----A---- C:\WINDOWS\SYSWOW64\DeviceSetupStatusProvider.dll
2016-03-22 23:12:17 ----A---- C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
2016-03-22 23:12:00 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2016-03-22 23:12:00 ----A---- C:\WINDOWS\system32\win32spl.dll
2016-03-22 23:12:00 ----A---- C:\WINDOWS\system32\puiobj.dll
2016-03-22 23:12:00 ----A---- C:\WINDOWS\system32\localspl.dll
2016-03-22 23:12:00 ----A---- C:\WINDOWS\system32\compstui.dll
2016-03-22 23:11:40 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-03-22 23:11:40 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\SYSWOW64\wincorlib.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-03-22 23:10:51 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\system32\KernelBase.dll
2016-03-22 23:10:51 ----A---- C:\WINDOWS\system32\combase.dll
2016-03-22 23:10:08 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2016-03-22 23:09:54 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-03-22 23:09:54 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-03-22 23:09:54 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-03-22 23:09:54 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-03-22 23:09:24 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2016-03-22 23:09:24 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-22 23:08:52 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2016-03-22 23:08:52 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2016-03-22 23:08:52 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2016-03-22 23:08:52 ----A---- C:\WINDOWS\system32\winresume.exe
2016-03-22 23:08:52 ----A---- C:\WINDOWS\system32\winload.exe
2016-03-22 23:08:52 ----A---- C:\WINDOWS\system32\ntvdm64.dll
2016-03-22 23:08:52 ----A---- C:\WINDOWS\system32\comsvcs.dll
2016-03-22 23:08:52 ----A---- C:\WINDOWS\system32\catsrvut.dll
2016-03-22 23:08:31 ----A---- C:\WINDOWS\system32\services.exe
2016-03-22 23:08:13 ----A---- C:\WINDOWS\SYSWOW64\netcfgx.dll
2016-03-22 23:08:13 ----A---- C:\WINDOWS\system32\netcfgx.dll
2016-03-22 23:08:13 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2016-03-22 23:07:37 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-03-22 23:07:37 ----A---- C:\WINDOWS\system32\SRH.dll
2016-03-22 23:07:03 ----A---- C:\WINDOWS\SYSWOW64\winshfhc.dll
2016-03-22 23:07:03 ----A---- C:\WINDOWS\system32\winshfhc.dll
2016-03-22 23:07:03 ----A---- C:\WINDOWS\system32\drivers\WdNisDrv.sys
2016-03-22 23:07:03 ----A---- C:\WINDOWS\system32\drivers\WdFilter.sys
2016-03-22 23:07:03 ----A---- C:\WINDOWS\system32\drivers\WdBoot.sys
2016-03-22 23:06:40 ----A---- C:\WINDOWS\SYSWOW64\taskeng.exe
2016-03-22 23:06:40 ----A---- C:\WINDOWS\SYSWOW64\schtasks.exe
2016-03-22 23:06:40 ----A---- C:\WINDOWS\system32\taskeng.exe
2016-03-22 23:06:40 ----A---- C:\WINDOWS\system32\schtasks.exe
2016-03-22 23:06:40 ----A---- C:\WINDOWS\system32\schedsvc.dll
2016-03-22 23:06:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2016-03-22 23:06:25 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2016-03-22 23:06:13 ----A---- C:\WINDOWS\SYSWOW64\calc.exe
2016-03-22 23:06:13 ----A---- C:\WINDOWS\system32\calc.exe
2016-03-22 23:05:43 ----A---- C:\WINDOWS\SYSWOW64\WebClnt.dll
2016-03-22 23:05:43 ----A---- C:\WINDOWS\SYSWOW64\davclnt.dll
2016-03-22 23:05:43 ----A---- C:\WINDOWS\system32\WebClnt.dll
2016-03-22 23:05:43 ----A---- C:\WINDOWS\system32\davclnt.dll
2016-03-22 23:05:25 ----A---- C:\WINDOWS\system32\wuaext.dll
2016-03-22 23:05:25 ----A---- C:\WINDOWS\system32\wu.upgrade.ps.dll
2016-03-22 23:05:25 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-03-22 23:04:57 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-03-22 23:04:57 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2016-03-22 23:04:57 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-03-22 23:04:57 ----A---- C:\WINDOWS\system32\msxml3.dll
2016-03-22 23:04:30 ----A---- C:\WINDOWS\system32\AuthHost.exe
2016-03-22 23:04:17 ----A---- C:\WINDOWS\system32\drivers\usbuhci.sys
2016-03-22 23:04:17 ----A---- C:\WINDOWS\system32\drivers\usbport.sys
2016-03-22 23:04:17 ----A---- C:\WINDOWS\system32\drivers\usbohci.sys
2016-03-22 23:04:17 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2016-03-22 23:04:17 ----A---- C:\WINDOWS\system32\drivers\usbehci.sys
2016-03-22 23:04:17 ----A---- C:\WINDOWS\system32\drivers\usbd.sys
2016-03-22 23:04:08 ----A---- C:\WINDOWS\SYSWOW64\pku2u.dll
2016-03-22 23:04:08 ----A---- C:\WINDOWS\system32\pku2u.dll
2016-03-22 23:03:56 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2016-03-22 23:03:56 ----A---- C:\WINDOWS\SYSWOW64\user.exe
2016-03-22 23:03:56 ----A---- C:\WINDOWS\SYSWOW64\setup16.exe
2016-03-22 23:03:56 ----A---- C:\WINDOWS\SYSWOW64\instnm.exe
2016-03-22 23:03:56 ----A---- C:\WINDOWS\system32\wow64cpu.dll
2016-03-22 23:03:56 ----A---- C:\WINDOWS\system32\wow64.dll
2016-03-22 23:03:56 ----A---- C:\WINDOWS\system32\sysmain.dll
2016-03-22 23:03:55 ----A---- C:\WINDOWS\system32\drivers\mountmgr.sys
2016-03-22 23:03:04 ----A---- C:\WINDOWS\SYSWOW64\InkEd.dll
2016-03-22 23:03:04 ----A---- C:\WINDOWS\system32\InkEd.dll
2016-03-22 23:02:45 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2016-03-22 23:02:45 ----A---- C:\WINDOWS\system32\SHCore.dll
2016-03-22 23:02:11 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-03-22 23:01:59 ----A---- C:\WINDOWS\system32\drivers\tunnel.sys
2016-03-22 22:59:04 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2016-03-22 22:58:53 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-03-22 22:58:53 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-03-22 22:58:41 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\msrating.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\inetcomm.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\ieui.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\hlink.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\SYSWOW64\dxtmsft.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\wininet.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\webcheck.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\msrating.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\mshtmled.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\jscript.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\inseng.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\inetcomm.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\ieui.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\iepeers.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\hlink.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\dxtrans.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2016-03-22 22:57:21 ----A---- C:\WINDOWS\system32\actxprxy.dll
2016-03-22 22:57:20 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2016-03-22 22:54:59 ----A---- C:\WINDOWS\SYSWOW64\scesrv.dll
2016-03-22 22:54:59 ----A---- C:\WINDOWS\system32\scesrv.dll
2016-03-22 22:54:50 ----A---- C:\WINDOWS\SYSWOW64\atlthunk.dll
2016-03-22 22:54:41 ----A---- C:\WINDOWS\system32\profsvc.dll
2016-03-22 22:54:21 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2016-03-22 22:54:21 ----A---- C:\WINDOWS\system32\mfds.dll
2016-03-22 22:53:34 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2016-03-22 22:53:23 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2016-03-22 22:53:23 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2016-03-22 22:53:23 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2016-03-22 22:53:23 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2016-03-22 22:53:23 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2016-03-22 22:53:23 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2016-03-22 22:53:23 ----A---- C:\WINDOWS\system32\tquery.dll
2016-03-22 22:53:23 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2016-03-22 22:53:23 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2016-03-22 22:53:23 ----A---- C:\WINDOWS\system32\mssvp.dll
2016-03-22 22:53:23 ----A---- C:\WINDOWS\system32\mssrch.dll
2016-03-22 22:53:23 ----A---- C:\WINDOWS\system32\mssphtb.dll
2016-03-22 22:53:23 ----A---- C:\WINDOWS\system32\mssph.dll
2016-03-22 22:49:03 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-03-22 22:49:03 ----A---- C:\WINDOWS\explorer.exe
2016-03-22 22:48:57 ----A---- C:\WINDOWS\system32\consent.exe
2016-03-22 22:48:50 ----A---- C:\WINDOWS\SYSWOW64\untfs.dll
2016-03-22 22:48:50 ----A---- C:\WINDOWS\system32\untfs.dll
2016-03-22 22:48:35 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2016-03-22 22:48:35 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-03-22 22:48:35 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2016-03-22 22:48:35 ----A---- C:\WINDOWS\system32\user32.dll
2016-03-22 22:48:35 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-03-22 22:48:35 ----A---- C:\WINDOWS\system32\FntCache.dll
2016-03-22 22:48:35 ----A---- C:\WINDOWS\system32\DWrite.dll
2016-03-22 22:48:12 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2016-03-22 22:48:12 ----A---- C:\WINDOWS\SYSWOW64\ncryptsslp.dll
2016-03-22 22:48:12 ----A---- C:\WINDOWS\SYSWOW64\ncrypt.dll
2016-03-22 22:48:12 ----A---- C:\WINDOWS\SYSWOW64\bcryptprimitives.dll
2016-03-22 22:48:12 ----A---- C:\WINDOWS\system32\schannel.dll
2016-03-22 22:48:12 ----A---- C:\WINDOWS\system32\ncryptsslp.dll
2016-03-22 22:48:12 ----A---- C:\WINDOWS\system32\ncrypt.dll
2016-03-22 22:48:12 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2016-03-22 22:48:12 ----A---- C:\WINDOWS\system32\bcryptprimitives.dll
2016-03-22 22:47:52 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2016-03-22 22:47:52 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2016-03-22 22:47:41 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2016-03-22 22:47:41 ----A---- C:\WINDOWS\system32\mispace.dll
2016-03-22 22:47:41 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2016-03-22 22:47:41 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2016-03-22 22:47:41 ----A---- C:\WINDOWS\system32\drivers\Classpnp.sys
2016-03-22 22:47:05 ----A---- C:\WINDOWS\SYSWOW64\GeofenceMonitorService.dll
2016-03-22 22:47:05 ----A---- C:\WINDOWS\system32\GeofenceMonitorService.dll
2016-03-22 22:46:57 ----A---- C:\WINDOWS\SYSWOW64\poqexec.exe
2016-03-22 22:46:57 ----A---- C:\WINDOWS\system32\poqexec.exe
2016-03-22 22:46:43 ----A---- C:\WINDOWS\SYSWOW64\rastapi.dll
2016-03-22 22:46:43 ----A---- C:\WINDOWS\system32\rastapi.dll
2016-03-22 22:46:38 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2016-03-22 22:46:38 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2016-03-22 22:46:34 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2016-03-22 22:46:34 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2016-03-22 22:46:34 ----A---- C:\WINDOWS\SYSWOW64\asycfilt.dll
2016-03-22 22:46:34 ----A---- C:\WINDOWS\system32\ole32.dll
2016-03-22 22:46:34 ----A---- C:\WINDOWS\system32\asycfilt.dll
2016-03-22 22:46:28 ----A---- C:\WINDOWS\system32\drivers\http.sys
2016-03-22 22:45:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2016-03-22 22:45:57 ----A---- C:\WINDOWS\SYSWOW64\shacct.dll
2016-03-22 22:45:57 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2016-03-22 22:45:57 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-03-22 22:45:57 ----A---- C:\WINDOWS\system32\shacct.dll
2016-03-22 22:45:57 ----A---- C:\WINDOWS\system32\SettingSync.dll
2016-03-22 22:45:49 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-03-22 22:45:49 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-03-22 22:45:43 ----A---- C:\WINDOWS\SYSWOW64\photowiz.dll
2016-03-22 22:45:43 ----A---- C:\WINDOWS\system32\photowiz.dll
2016-03-22 22:45:10 ----A---- C:\WINDOWS\SYSWOW64\appidapi.dll
2016-03-22 22:45:10 ----A---- C:\WINDOWS\system32\appidsvc.dll
2016-03-22 22:45:10 ----A---- C:\WINDOWS\system32\appidapi.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\SYSWOW64\WerFaultSecure.exe
2016-03-22 22:45:02 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\SYSWOW64\Faultrep.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\system32\WerFaultSecure.exe
2016-03-22 22:45:02 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\system32\wer.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\system32\Faultrep.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\system32\EncDump.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\system32\ci.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-03-22 22:45:02 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-22 22:41:54 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-03-22 22:41:54 ----D---- C:\Program Files (x86)\MSBuild
2016-03-22 22:41:51 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2016-03-22 22:41:51 ----D---- C:\Program Files\Reference Assemblies
2016-03-22 22:41:51 ----D---- C:\Program Files\MSBuild
2016-03-22 22:40:53 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2016-03-22 22:40:52 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2016-03-22 22:40:51 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2016-03-22 22:40:49 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-03-22 22:40:11 ----A---- C:\WINDOWS\SYSWOW64\sdbinst.exe
2016-03-22 22:40:10 ----A---- C:\WINDOWS\system32\sdbinst.exe
2016-03-22 20:26:56 ----D---- C:\ProgramData\Atheros
2016-03-22 20:26:48 ----D---- C:\Users\Helenka\AppData\Roaming\Atheros
2016-03-22 20:14:28 ----D---- C:\WINDOWS\system32\AutoUpdateLicense
2016-03-22 20:09:07 ----D---- C:\WINDOWS\Migration
2016-03-22 19:58:13 ----D---- C:\ProgramData\STORMWARE
2016-03-22 19:58:13 ----D---- C:\Program Files (x86)\STORMWARE
2016-03-22 19:56:28 ----D---- C:\Users\Helenka\AppData\Roaming\PDF Writer
2016-03-22 19:56:28 ----D---- C:\ProgramData\PDF Writer
2016-03-22 19:56:28 ----A---- C:\WINDOWS\SYSWOW64\bzFlRdr.dll
2016-03-22 19:56:28 ----A---- C:\WINDOWS\SYSWOW64\bzDCT.dll
2016-03-22 19:56:23 ----A---- C:\WINDOWS\SYSWOW64\bzpdfc.dll
2016-03-22 19:56:13 ----D---- C:\Program Files\Common Files\STORMWARE
2016-03-22 19:56:07 ----D---- C:\Program Files\STORMWARE
2016-03-19 18:25:51 ----D---- C:\Users\Helenka\AppData\Roaming\.minecraft
2016-03-19 18:25:32 ----D---- C:\Users\Helenka\AppData\Roaming\Sun
2016-03-19 18:25:20 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2016-03-19 18:24:56 ----D---- C:\ProgramData\Oracle
2016-03-19 18:24:51 ----D---- C:\Program Files (x86)\Java
2016-03-19 18:22:41 ----D---- C:\Program Files\7-Zip
2016-03-19 15:53:12 ----D---- C:\WINDOWS\system32\MRT
2016-03-19 15:53:08 ----A---- C:\WINDOWS\system32\MRT.exe
2016-03-19 14:01:45 ----D---- C:\Users\Helenka\AppData\Roaming\uTorrent
2016-03-19 13:41:22 ----D---- C:\Users\Helenka\AppData\Roaming\Apple Computer
2016-03-19 13:40:55 ----A---- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys
2016-03-19 13:39:34 ----D---- C:\Program Files\iPod
2016-03-19 13:39:34 ----D---- C:\Program Files (x86)\iTunes
2016-03-19 13:39:33 ----D---- C:\ProgramData\E1864A66-75E3-486a-BD95-D1B7D99A84A7
2016-03-19 13:39:33 ----D---- C:\ProgramData\Apple Computer
2016-03-19 13:39:33 ----D---- C:\Program Files\iTunes
2016-03-19 13:35:59 ----D---- C:\Program Files\Bonjour
2016-03-19 13:35:59 ----D---- C:\Program Files (x86)\Bonjour
2016-03-19 13:32:19 ----D---- C:\Program Files\Common Files\Apple
2016-03-19 13:31:41 ----D---- C:\ProgramData\Apple
2016-03-19 13:14:40 ----N---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-03-19 12:14:19 ----A---- C:\WINDOWS\system32\drivers\btath_rcp.sys
2016-03-19 12:14:17 ----A---- C:\WINDOWS\system32\drivers\btath_lwflt.sys
2016-03-19 12:14:14 ----A---- C:\WINDOWS\system32\wdfcoinstaller01009.dll
2016-03-19 12:14:14 ----A---- C:\WINDOWS\system32\drivers\btath_hcrp.sys
2016-03-19 12:14:12 ----A---- C:\WINDOWS\system32\drivers\btath_flt.sys
2016-03-19 12:14:12 ----A---- C:\WINDOWS\system32\drivers\btath_avdt.sys
2016-03-19 12:14:12 ----A---- C:\WINDOWS\system32\drivers\btath_a2dp.sys
2016-03-19 12:14:10 ----A---- C:\WINDOWS\system32\drivers\btfilter.sys
2016-03-19 12:14:05 ----A---- C:\WINDOWS\system32\drivers\btath_bus.sys
2016-03-19 11:41:22 ----D---- C:\Program Files (x86)\Google
2016-03-19 02:28:01 ----D---- C:\WINDOWS\NAPP_Dism_Log
2016-03-18 20:11:06 ----A---- C:\WINDOWS\system32\drivers\HipShieldK.sys
2016-03-18 19:24:31 ----D---- C:\Users\Helenka\AppData\Roaming\lm
2016-03-18 19:24:09 ----D---- C:\Users\Helenka\AppData\Roaming\Macromedia
2016-03-18 19:24:05 ----D---- C:\Users\Helenka\AppData\Roaming\Adobe
2016-03-18 19:22:43 ----D---- C:\WINDOWS\SoftwareDistribution
2016-03-18 19:15:34 ----SHD---- C:\ProgramData\Šablony
2016-03-18 19:15:34 ----SHD---- C:\ProgramData\Nabídka Start
2016-03-18 19:15:33 ----SHD---- C:\ProgramData\Plocha
2016-03-18 19:15:33 ----SHD---- C:\ProgramData\Dokumenty
2016-03-18 19:15:33 ----SHD---- C:\ProgramData\Data aplikací
2016-03-18 18:55:34 ----D---- C:\ProgramData\CyberLink
2016-03-18 18:55:05 ----D---- C:\ProgramData\CLSK
2016-03-18 18:54:30 ----D---- C:\ProgramData\install_clap
2016-03-18 18:53:27 ----D---- C:\ProgramData\Symantec
2016-03-18 18:53:27 ----D---- C:\ProgramData\boost_interprocess
2016-03-18 18:53:27 ----D---- C:\Program Files (x86)\Symantec
2016-03-18 18:53:21 ----D---- C:\WINDOWS\system32\drivers\NARAx64
2016-03-18 18:53:21 ----D---- C:\ProgramData\Norton
2016-03-18 18:53:21 ----D---- C:\Program Files (x86)\Norton Online Backup ARA
2016-03-18 18:53:19 ----D---- C:\ProgramData\NortonInstaller
2016-03-18 18:53:19 ----D---- C:\Program Files (x86)\NortonInstaller
2016-03-18 18:53:02 ----D---- C:\ProgramData\NTI Launcher
2016-03-18 18:51:51 ----D---- C:\ProgramData\FLEXnet
2016-03-18 18:50:10 ----D---- C:\Program Files (x86)\Microsoft Office
2016-03-18 18:45:25 ----D---- C:\ProgramData\EgisTec
2016-03-18 18:45:17 ----D---- C:\ProgramData\OEM
2016-03-18 18:23:22 ----D---- C:\Program Files (x86)\Qualcomm Atheros
2016-03-18 18:21:51 ----D---- C:\ProgramData\Qualcomm Atheros
2016-03-18 18:20:37 ----D---- C:\ProgramData\AmUStor
2016-03-18 18:20:37 ----D---- C:\Program Files (x86)\AmIcoSingLun
2016-03-18 18:18:29 ----D---- C:\Dolby PCEE4
2016-03-18 18:18:17 ----A---- C:\WINDOWS\system32\CxAudMsg64.exe
2016-03-18 18:15:10 ----A---- C:\WINDOWS\Touchpad.txt
2016-03-18 18:13:51 ----A---- C:\WINDOWS\system32\drivers\aPs2Kb2Hid.sys
2016-03-18 18:13:51 ----A---- C:\WINDOWS\RfBtnSvc64.exe
2016-03-18 18:11:57 ----D---- C:\Program Files (x86)\Launch Manager
2016-03-18 18:09:32 ----D---- C:\WINDOWS\SYSWOW64\Atheros_L1e
2016-03-18 18:07:12 ----D---- C:\Program Files\AMD Quick Stream
2016-03-18 18:07:12 ----A---- C:\WINDOWS\system32\drivers\appexDrv.sys
2016-03-18 18:07:10 ----D---- C:\ProgramData\AMD
2016-03-18 18:07:08 ----D---- C:\Program Files (x86)\AMD AVT
2016-03-18 18:07:06 ----D---- C:\Program Files (x86)\AMD APP
2016-03-18 18:06:41 ----DC---- C:\WINDOWS\system32\DRVSTORE
2016-03-18 18:06:41 ----A---- C:\WINDOWS\system32\drivers\usbfilter.sys
2016-03-18 18:05:17 ----D---- C:\Program Files\ATI
2016-03-18 18:05:15 ----D---- C:\Program Files (x86)\ATI Technologies
2016-03-18 17:58:19 ----ASH---- C:\hiberfil.sys
2016-03-18 17:54:54 ----ASH---- C:\swapfile.sys
2016-03-18 17:54:54 ----ASH---- C:\pagefile.sys
2016-03-18 17:54:52 ----SHD---- C:\System Volume Information

======List of files/folders modified in the last 1 month======

2016-03-31 18:34:25 ----RD---- C:\Program Files
2016-03-31 18:27:07 ----RD---- C:\WINDOWS\System32
2016-03-31 18:27:07 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-31 18:27:06 ----D---- C:\WINDOWS\Inf
2016-03-31 18:23:25 ----D---- C:\WINDOWS\Temp
2016-03-31 18:21:42 ----D---- C:\Windows
2016-03-31 18:21:20 ----RSD---- C:\WINDOWS\Fonts
2016-03-31 18:21:20 ----D---- C:\WINDOWS\system32\drivers
2016-03-31 18:00:00 ----D---- C:\WINDOWS\system32\sru
2016-03-31 17:43:23 ----D---- C:\WINDOWS\system32\Tasks
2016-03-31 16:05:17 ----D---- C:\WINDOWS\system32\catroot
2016-03-31 16:01:05 ----D---- C:\WINDOWS\Microsoft.NET
2016-03-31 15:32:00 ----D---- C:\WINDOWS\system32\NDF
2016-03-30 15:32:59 ----D---- C:\WINDOWS\system32\wdi
2016-03-30 15:31:54 ----HD---- C:\ProgramData
2016-03-29 21:01:47 ----RD---- C:\Program Files (x86)
2016-03-29 20:56:47 ----D---- C:\WINDOWS\debug
2016-03-29 20:56:41 ----SHD---- C:\Users\Helenka\AppData\Roaming\{392CF4EB-5A71-D16A-4823-8E6BA936E5D4}
2016-03-29 20:53:32 ----D---- C:\ProgramData\WildTangent
2016-03-29 20:53:32 ----D---- C:\ProgramData\Temp
2016-03-29 20:53:31 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2016-03-29 20:53:31 ----D---- C:\ProgramData\PRICache
2016-03-29 20:53:24 ----SD---- C:\ProgramData\Microsoft
2016-03-29 20:53:16 ----D---- C:\ProgramData\McAfee
2016-03-29 20:53:15 ----D---- C:\ProgramData\EgisTec IPS
2016-03-29 20:53:12 ----D---- C:\ProgramData\BackupManager
2016-03-29 20:53:10 ----D---- C:\ProgramData\Acer
2016-03-29 20:53:10 ----D---- C:\PerfLogs
2016-03-29 20:52:46 ----HD---- C:\OEM
2016-03-29 20:52:45 ----RD---- C:\Users
2016-03-29 20:52:43 ----SHD---- C:\Boot
2016-03-29 20:52:39 ----SHD---- C:\$Recycle.Bin
2016-03-29 20:01:08 ----SHD---- C:\WINDOWS\Installer
2016-03-28 19:54:44 ----RSD---- C:\WINDOWS\assembly
2016-03-28 19:44:55 ----D---- C:\WINDOWS\Logs
2016-03-24 23:08:31 ----D---- C:\Program Files (x86)\McAfee
2016-03-24 21:29:29 ----D---- C:\WINDOWS\AppReadiness
2016-03-24 19:20:23 ----HD---- C:\Program Files\WindowsApps
2016-03-24 15:17:41 ----D---- C:\WINDOWS\system32\config
2016-03-24 13:02:16 ----D---- C:\WINDOWS\CbsTemp
2016-03-24 13:01:57 ----D---- C:\WINDOWS\system32\catroot2
2016-03-24 13:01:49 ----D---- C:\WINDOWS\WinSxS
2016-03-24 10:39:34 ----D---- C:\WINDOWS\SysWOW64
2016-03-24 10:39:15 ----D---- C:\Program Files (x86)\Common Files
2016-03-24 10:39:01 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-03-24 10:38:06 ----D---- C:\Program Files\Common Files\microsoft shared
2016-03-24 10:36:32 ----D---- C:\WINDOWS\ShellNew
2016-03-24 10:32:57 ----D---- C:\Program Files\Common Files\mcafee
2016-03-24 10:32:26 ----HD---- C:\WINDOWS\ELAMBKUP
2016-03-24 10:28:52 ----D---- C:\Program Files\Common Files
2016-03-24 10:20:43 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-03-23 16:50:35 ----D---- C:\WINDOWS\system32\DriverStore
2016-03-23 15:11:59 ----D---- C:\WINDOWS\system32\restore
2016-03-23 12:52:57 ----D---- C:\WINDOWS\system32\LogFiles
2016-03-23 00:41:13 ----D---- C:\WINDOWS\rescache
2016-03-23 00:40:45 ----D---- C:\Program Files\Windows NT
2016-03-23 00:38:46 ----D---- C:\WINDOWS\Registration
2016-03-23 00:31:56 ----RSD---- C:\WINDOWS\Media
2016-03-23 00:21:38 ----D---- C:\WINDOWS\SYSWOW64\drivers
2016-03-23 00:21:38 ----D---- C:\WINDOWS\system32\Sysprep
2016-03-23 00:21:37 ----D---- C:\WINDOWS\system32\OEM
2016-03-23 00:21:33 ----D---- C:\WINDOWS\Tasks
2016-03-23 00:21:33 ----D---- C:\WINDOWS\Help
2016-03-23 00:19:28 ----D---- C:\WINDOWS\SYSWOW64\WCN
2016-03-23 00:19:28 ----D---- C:\WINDOWS\SYSWOW64\sysprep
2016-03-23 00:19:28 ----D---- C:\WINDOWS\SYSWOW64\SMI
2016-03-23 00:19:27 ----D---- C:\WINDOWS\SYSWOW64\MUI
2016-03-23 00:19:27 ----D---- C:\WINDOWS\SYSWOW64\migwiz
2016-03-23 00:19:27 ----D---- C:\WINDOWS\SYSWOW64\LogFiles
2016-03-23 00:19:26 ----D---- C:\WINDOWS\SYSWOW64\IME
2016-03-23 00:19:26 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2016-03-23 00:19:25 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-03-23 00:19:25 ----D---- C:\WINDOWS\SYSWOW64\catroot
2016-03-23 00:19:21 ----D---- C:\WINDOWS\system32\WCN
2016-03-23 00:19:21 ----D---- C:\WINDOWS\system32\spool
2016-03-23 00:19:15 ----D---- C:\WINDOWS\system32\oobe
2016-03-23 00:19:13 ----D---- C:\WINDOWS\system32\MUI
2016-03-23 00:19:13 ----D---- C:\WINDOWS\system32\IME
2016-03-23 00:19:11 ----D---- C:\WINDOWS\system32\cs-CZ
2016-03-23 00:18:05 ----D---- C:\WINDOWS\IME
2016-03-23 00:18:05 ----D---- C:\WINDOWS\DigitalLocker
2016-03-23 00:17:56 ----SHD---- C:\Program Files (x86)\Windows Sidebar
2016-03-23 00:17:56 ----D---- C:\Program Files (x86)\Windows Media Player
2016-03-23 00:17:51 ----SHD---- C:\Program Files\Windows Sidebar
2016-03-23 00:17:51 ----D---- C:\Program Files\Windows Media Player
2016-03-23 00:15:15 ----D---- C:\WINDOWS\system32\Recovery
2016-03-22 23:49:59 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-03-22 23:48:29 ----D---- C:\WINDOWS\SYSWOW64\setup
2016-03-22 23:48:29 ----D---- C:\WINDOWS\system32\setup
2016-03-22 23:42:09 ----D---- C:\WINDOWS\system32\wbem
2016-03-22 23:42:09 ----D---- C:\WINDOWS\system32\en-US
2016-03-22 23:40:24 ----D---- C:\WINDOWS\system32\Boot
2016-03-22 23:37:53 ----RD---- C:\WINDOWS\ToastData
2016-03-22 23:35:51 ----D---- C:\WINDOWS\WinStore
2016-03-22 23:13:11 ----D---- C:\WINDOWS\apppatch
2016-03-22 23:12:00 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-03-22 23:07:16 ----D---- C:\Program Files\Windows Defender
2016-03-22 23:07:16 ----D---- C:\Program Files (x86)\Windows Defender
2016-03-22 23:04:04 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2016-03-22 23:03:14 ----D---- C:\Program Files\Windows Journal
2016-03-22 22:58:38 ----D---- C:\WINDOWS\system32\CodeIntegrity
2016-03-22 22:58:16 ----D---- C:\WINDOWS\PolicyDefinitions
2016-03-22 22:58:16 ----D---- C:\Program Files (x86)\Internet Explorer
2016-03-22 22:58:15 ----D---- C:\Program Files\Internet Explorer
2016-03-22 22:45:08 ----D---- C:\WINDOWS\system32\AdvancedInstallers
2016-03-22 21:33:19 ----D---- C:\WINDOWS\AUInstallAgent
2016-03-18 18:57:45 ----D---- C:\Program Files (x86)\Acer
2016-03-18 18:55:09 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-03-18 18:53:37 ----D---- C:\Program Files\Acer
2016-03-18 18:52:12 ----D---- C:\Program Files (x86)\NTI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 amdkmpfd;@oem25.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmpfd.sys [2014-07-21 36096]
R0 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2015-11-25 846080]
R0 mfewfpk;McAfee Inc. mfewfpk; C:\WINDOWS\system32\drivers\mfewfpk.sys [2015-11-25 245096]
R1 ccSet_NARA;NARA Settings Manager; C:\WINDOWS\system32\drivers\NARAx64\0401000.00E\ccSetx64.sys [2012-05-26 168608]
R1 mwlPSDFilter;mwlPSDFilter; C:\WINDOWS\system32\DRIVERS\mwlPSDFilter.sys [2013-03-12 22648]
R1 mwlPSDNServ;mwlPSDNServ; C:\WINDOWS\system32\DRIVERS\mwlPSDNServ.sys [2013-03-12 20520]
R1 mwlPSDVDisk;mwlPSDVDisk; C:\WINDOWS\system32\DRIVERS\mwlPSDVDisk.sys [2013-03-12 62776]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\WINDOWS\system32\DRIVERS\vwififlt.sys [2013-08-22 71680]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2014-07-21 13209088]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2014-07-21 626688]
R3 AthBTPort;@oem8.inf,%BTHSUPPORT.SvcDesc%;Qualcomm Atheros Virtual Bluetooth Class; C:\WINDOWS\system32\DRIVERS\btath_flt.sys [2013-01-28 89168]
R3 athr;@athw8x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\system32\DRIVERS\athw8x.sys [2013-06-18 3680256]
R3 AtiHDAudioService;@oem17.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdW86.sys [2012-08-21 91648]
R3 BTATH_A2DP;@oem7.inf,%BTATH_A2DP.SvcDesc%;Bluetooth A2DP Audio Driver; C:\WINDOWS\system32\drivers\btath_a2dp.sys [2013-01-28 346192]
R3 btath_avdt;@oem7.inf,%btath_avdt.SvcDesc%;Qualcomm Atheros Bluetooth AVDT Service; C:\WINDOWS\system32\drivers\btath_avdt.sys [2013-01-28 115280]
R3 BTATH_BUS;@oem4.inf,%BTATH_BUS.SVCDESC%;Qualcomm Atheros Bluetooth Bus; C:\WINDOWS\System32\drivers\btath_bus.sys [2013-01-28 34384]
R3 BTATH_HCRP;@oem11.inf,%BTATH_HCRP.SvcDesc%;Bluetooth HCRP Server driver; C:\WINDOWS\System32\drivers\btath_hcrp.sys [2013-01-28 179432]
R3 BTATH_LWFLT;@oem20.inf,%BTATH_LWFLT%;Bluetooth LWFLT Device; C:\WINDOWS\system32\DRIVERS\btath_lwflt.sys [2013-01-28 77464]
R3 BTATH_RCP;@oem15.inf,%BTATH_RCP%;Bluetooth AVRCP Device; C:\WINDOWS\System32\drivers\btath_rcp.sys [2013-01-28 136424]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2013-01-28 581200]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2014-11-21 53248]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\WINDOWS\system32\DRIVERS\BthLEEnum.sys [2014-11-21 226304]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2016-03-22 118272]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2014-11-21 81920]
R3 CnxtHdAudService;@oem22.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDRT64.sys [2012-09-20 1609376]
R3 ETD;@oem21.inf,%PS2.DeviceDesc%;ELAN PS/2 Port Input Device; C:\WINDOWS\system32\DRIVERS\ETD.sys [2012-11-20 331152]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-10-03 33240]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport – ovladač pro řadič Qualcomm Atheros AR81xx PCI-E Ethernet; C:\WINDOWS\system32\DRIVERS\L1C63x64.sys [2013-06-18 129224]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2016-03-10 27008]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2016-03-31 192216]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2016-03-10 65408]
R3 mfeaack;McAfee Inc. mfeaack; C:\WINDOWS\system32\drivers\mfeaack.sys [2015-11-25 419624]
R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2015-11-25 351144]
R3 mfefirek;McAfee Inc. mfefirek; C:\WINDOWS\system32\drivers\mfefirek.sys [2015-11-25 496368]
R3 mfencbdc;McAfee Inc. mfencbdc; C:\WINDOWS\system32\DRIVERS\mfencbdc.sys [2015-11-20 539496]
R3 mfesapsn;McAfee Process Start Notification Service; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [2016-01-19 36968]
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys [2010-04-20 18432]
R3 Ps2Kb2Hid;@oem20.inf,%Ps2Kb2Hid.SVCDESC%;PS/2 Keyboard to HID Driver; C:\WINDOWS\System32\drivers\aPs2Kb2Hid.sys [2016-03-18 26736]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2016-03-22 167424]
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys [2010-07-09 17408]
R3 usbfilter;AMD USB Filter Driver; C:\WINDOWS\system32\DRIVERS\usbfilter.sys [2012-08-28 58536]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2014-11-21 212736]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\WINDOWS\system32\DRIVERS\vwifimp.sys [2013-08-22 36864]
S0 mfeelamk;McAfee Inc. mfeelamk; C:\WINDOWS\system32\drivers\mfeelamk.sys [2015-11-25 83096]
S2 APXACC;AppEx Networks Accelerator LWF; C:\WINDOWS\system32\DRIVERS\appexDrv.sys [2012-06-23 199008]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\Drivers\BTHport.sys [2016-03-22 1201664]
S3 cfwids;McAfee Inc. cfwids; C:\WINDOWS\system32\drivers\cfwids.sys [2015-11-25 79248]
S3 HipShieldK;McAfee Inc. HipShieldK; C:\WINDOWS\system32\drivers\HipShieldK.sys [2015-05-19 207208]
S3 mfencrk;McAfee Inc. mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [2015-11-20 109480]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2014-07-21 239616]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-03-02 83768]
R2 AtherosSvc;AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [2013-01-28 227456]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-31 462184]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2012-10-25 2449552]
R2 CxAudMsg;Conexant Audio Message Service; C:\Windows\system32\CxAudMsg64.exe [2012-06-08 201376]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\WINDOWS\System32\svchost.exe [2014-11-21 38792]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2012-08-21 348784]
R2 HomeNetSvc;McAfee Home Network; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-10 1136608]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2016-03-10 1514464]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [2016-03-21 163592]
R2 McAPExe;McAfee AP Service; C:\Program Files\McAfee\MSC\McAPExe.exe [2016-03-03 863448]
R2 McBootDelayStartSvc;McAfee Boot Delay Start Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
R2 mccspsvc;McAfee CSP Service; C:\Program Files\Common Files\McAfee\CSP\1.8.267.0\McCSPServiceHost.exe [2016-02-23 1696712]
R2 McNaiAnn;McAfee VirusScan Announcer; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
R2 mcpltsvc;McAfee Platform Services; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
R2 McProxy;McAfee Proxy Service; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
R2 mfefire;McAfee Firewall Core Service; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2015-11-18 234192]
R2 mfemms;McAfee Service Controller; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [2016-01-21 380896]
R2 mfevtp;McAfee Validation Trust Protection Service; C:\Windows\system32\mfevtps.exe [2015-11-18 275368]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
R2 NOBU;Norton Online Backup; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2012-08-15 3943104]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [2012-11-03 259136]
R2 PEFService;Intel Security PEF Service; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [2015-12-14 902112]
R2 RfButtonDriverService;Dritek RF Button Command Service; C:\Windows\RfBtnSvc64.exe [2016-03-18 93296]
R3 ePowerSvc;ePower Service; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [2012-10-23 658064]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2015-09-12 643856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-19 154440]
S2 McMPFSvc;McAfee Personal Firewall Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [2016-01-03 453520]
S2 McOobeSv;McAfee OOBE Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2012-05-11 200728]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2014-11-21 38792]
S3 DeviceFastLaneService;Device Fast-lane Service; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [2012-11-16 469648]
S3 EgisTec Ticket Service;EgisTec Ticket Service; C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [2012-07-12 174160]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2016-03-18 655624]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-19 154440]
S3 McAWFwk;McAfee Activation Service; C:\Program Files\mcafee\msc\McAWFwk.exe [2012-01-26 332080]
S3 McODS;McAfee Scanner; C:\Program Files\mcafee\VirusScan\mcods.exe [2016-02-26 681680]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Help you files

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nela_M
Návštěvník
Návštěvník
Příspěvky: 132
Registrován: 05 úno 2009 18:31

Re: Help you files

#3 Příspěvek od Nela_M »

Nenašel nic, ale po restartu se mi zase objevilo - viz. obrázky

# AdwCleaner v5.108 - Log soubor vytvořen 31/03/2016 o 19:09:32
# Aktualizováno 30/03/2016 by Xplode
# Databáze : 2016-03-30.1 [Server]
# Operační systém : Windows 8.1 (x64)
# Jméno uživatele : Helenka - DOMA
# Spuštěno z : C:\Users\Helenka\Desktop\adwcleaner_5.108.exe
# Volba : Čištění
# Podpora : http://toolslib.net/forum

***** [ Služby ] *****


***** [ Složky ] *****


***** [ Soubory ] *****


***** [ DLLs ] *****


***** [ Zástupci ] *****


***** [ Naplánované úkoly ] *****


***** [ Registr ] *****


***** [ Webové prohlížeče ] *****


*************************

:: "Tracing" odstraněných kláves
:: Nastavení Winsock odstraněno

*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [741 bytes] - [31/03/2016 19:09:32]
C:\AdwCleaner\AdwCleaner[S1].txt - [784 bytes] - [31/03/2016 19:06:57]

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [885 bytes] ##########

http://leteckaposta.cz/123614199

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Help you files

#4 Příspěvek od Rudy »

Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
C:\Users\Helenka\AppData\Local\Temp\KB424328703.exe
C:\Users\Helenka\AppData\Roaming\AdobeFlashPlayer_c05a2ddbccba96cf.exe
C:\WINDOWS\HELP_YOUR_FILES.TXT
C:\Users\Helenka\AppData\Roaming\HELP_YOUR_FILES.TXT
C:\ProgramData\HELP_YOUR_FILES.TXT
C:\Program Files\HELP_YOUR_FILES.TXT
C:\Program Files (x86)\HELP_YOUR_FILES.TXT
C:\HELP_YOUR_FILES.TXT
C:\Users\Helenka\AppData\Roaming\AdobeFlashPlayer_c05a2ddbccba96cf.exe

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Unqtmedia"=-
"Adobe Reader Update32"=-
"AdobeFlashPlayers32"=-

:sevices
Bonjour Service

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Nela_M
Návštěvník
Návštěvník
Příspěvky: 132
Registrován: 05 úno 2009 18:31

Re: Help you files

#5 Příspěvek od Nela_M »

Už na mě nic nevyskočilo, tak snad OK. Díky moc za pomoc :fez:

All processes killed
========== FILES ==========
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully.
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully.
C:\Users\Helenka\AppData\Local\Temp\KB424328703.exe moved successfully.
C:\Users\Helenka\AppData\Roaming\AdobeFlashPlayer_c05a2ddbccba96cf.exe moved successfully.
C:\WINDOWS\HELP_YOUR_FILES.TXT moved successfully.
C:\Users\Helenka\AppData\Roaming\HELP_YOUR_FILES.TXT moved successfully.
C:\ProgramData\HELP_YOUR_FILES.TXT moved successfully.
C:\Program Files\HELP_YOUR_FILES.TXT moved successfully.
C:\Program Files (x86)\HELP_YOUR_FILES.TXT moved successfully.
C:\HELP_YOUR_FILES.TXT moved successfully.
File/Folder C:\Users\Helenka\AppData\Roaming\AdobeFlashPlayer_c05a2ddbccba96cf.exe not found.
========== REGISTRY ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Unqtmedia deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Update32 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeFlashPlayers32 deleted successfully.
Error: Unable to interpret <:sevices> in the current context!
Error: Unable to interpret <Bonjour Service> in the current context!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 4705 bytes
->Temporary Internet Files folder emptied: 4705 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default.migrated

User: Helenka
->Temp folder emptied: 13748939 bytes
->Temporary Internet Files folder emptied: 73587010 bytes
->Java cache emptied: 4705 bytes
->Google Chrome cache emptied: 57081382 bytes
->Flash cache emptied: 29012 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 3297238 bytes
RecycleBin emptied: 831790918 bytes

Total Files Cleaned = 934,00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Default.migrated

User: Helenka
->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0,00 mb


OTM by OldTimer - Version 3.1.21.0 log created on 03312016_194412

Files moved on Reboot...
C:\Users\Helenka\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
File move failed. C:\WINDOWS\temp\lm\Helenka\aipflib.log scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\lm\Helenka\LMutilps32.log scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\lm\dsiwmis.log scheduled to be moved on reboot.
File C:\WINDOWS\temp\WFV2DB2.tmp not found!
File C:\WINDOWS\temp\WFV35B2.tmp not found!
File C:\WINDOWS\temp\WFVA68D.tmp not found!

Registry entries deleted on Reboot...

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Help you files

#6 Příspěvek od Rudy »

OK. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Uživatelský avatar
motji
VIP
VIP
Příspěvky: 23302
Registrován: 23 říj 2008 08:02

Re: Help you files

#7 Příspěvek od motji »

Omlouvám se za vstup :oops:
Podle všeho měl vir zašifrovat některé soubory, zkontrolujte si fotky, dokumenty..všechno je ok?
Nepoužívejte COMBOFIX bez doporučení rádce, může dojít k poškození systému!
Vždy před odvirováním počítače zazálohujte důležitá data :!:
Chcete podpořit naše forum? Informace zde

Obrázek

K zastižení jsem spíše v noci, mezi 21.-23. hodinou
Pokud máte nějaké dotazy, můžete mi napsat na email Motji(zavináč)forum.viry.cz.

Nela_M
Návštěvník
Návštěvník
Příspěvky: 132
Registrován: 05 úno 2009 18:31

Re: Help you files

#8 Příspěvek od Nela_M »

Máte pravdu, zašifroval úplně všechno :shock: :shock: nezůstal ani jeden soubor v obrázkách, hudbe, dokumentech... To je ale hajzl. Naštěstí jsem předevčírem dělala zálohu, tak jsem o nic nepřišla.

Akorát ty soubory "HELP YOUR FILES" tam zůstaly a musím je mazat ručně, tak doufám, že se z toho zase nevzpamatuje.

Díky moc za pomoc :-) :wub:

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Help you files

#9 Příspěvek od Rudy »

Pokud nemáte zálohu těch souborů, na možnost dešifrování se zeptejte zde: https://neslape.cz/?utm_campaign=neslap ... ium=banner . Dešifrovat lze ovšem jen zlomek, tohoto svinstva je řada variant. I za kolegyni: nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět