Stránka 1 z 2

Napadený NB (rundas!plock) a další havěť

Napsal: 07 lis 2016 22:06
od bejk62
dobrý večer, prosím o pomoc. Win defender detekoval a odstranil? trojana rundas!plock.
v nb se ale zahnízdilo asi více kobylek a procesor - někdy i disk jsou na 100% i několik hodin. Pokud zatížení trochu sleze a pustím prohlížeč tak jsem zase na 100% s procesorem.
Přikládám RSIT log, předem děkuji.

Logfile of random's system information tool 1.14 (written by random/random)
Run by Petr at 2016-11-07 21:49:02
Microsoft Windows 10 Pro
System drive C: has 190 GB (81%) free of 234 GB
Total RAM: 3067 MB (57% free)
X86

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:49:45, on 7.11.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\taskhostw.exe
C:\Windows\System32\RuntimeBroker.exe
C:\WINDOWS\system32\SettingSyncHost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\ApplicationFrameHost.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Defender\msascuil.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Users\Petr\Desktop\RSIT.exe
C:\WINDOWS\system32\backgroundTaskHost.exe
C:\Program Files\trend micro\Petr_RSIT.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL
O4 - HKLM\..\Run: [SysTrayApp] %ProgramFiles%\IDT\WDM\sttray.exe
O4 - HKLM\..\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell Webcam Central] "C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
O4 - HKLM\..\Run: [WindowsDefender] "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\Petr\AppData\Local\Apps\2.0\WBTT3JXD.NAM\RJGXWCJZ.374\dell..tion_6d0a76327dca4869_0007.0009_d84bde3ab35e468d\DellSystemDetect.exe 4zZn5oeQk9WMM5ZBt7fsYA==
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL

--
End of file - 5806 bytes

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\AutoPico Daily Restart - "C:\Program Files\KMSpico\AutoPico.exe" /silent
C:\WINDOWS\system32\tasks\Dell SupportAssistAgent AutoUpdate - C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe AutoUpdate
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\LaunchPreSignup - C:\Program Files\OLBPre\OLBPre.exe signup
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task - C:\Users\Petr\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\PCDEventLauncherTask - "C:\Program Files\Dell\SupportAssist\sessionchecker.exe"
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{98B660D7-67D7-4697-9966-FD94088E4F6A} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance - C:\Program Files\Windows Defender\\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup - C:\Program Files\Windows Defender\\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan - C:\Program Files\Windows Defender\\MpCmdRun.exe Scan -ScheduleJob
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification - C:\Program Files\Windows Defender\\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\WINDOWS\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe ForcedRebootReminder
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - C:\windows\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - C:\windows\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Subscription\EnableLicenseAcquisition - %SystemRoot%\system32\UpgradeSubscription.exe -e
C:\WINDOWS\system32\tasks\Microsoft\Windows\Subscription\LicenseAcquisition - %SystemRoot%\system32\UpgradeSubscription.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\WINDOWS\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\WINDOWS\system32\tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - %windir%\system32\MDMAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\Office 15 Subscription Heartbeat - %ProgramFiles%\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\WINDOWS\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Subscription Maintenance - C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeTelemetryAgentFallBack - "C:\Program Files\Microsoft Office\Office15\msoia.exe" scan upload mininterval:2880
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeTelemetryAgentLogOn - "C:\Program Files\Microsoft Office\Office15\msoia.exe" scan upload

=========Google Chrome=========

C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension beobeededemalmllhkmnkinmfembdimh 1 TV 1.0.12
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension bgjpfhpjcgdppjbgnpnjllokbmcdllig 0 Seznam Lištička - Email 1.3.14
Extension blakpkgjpemejpbmfiglncklihnhjkij 1 Volání přes Skype 0.0.0.26
Extension blmojkbhnkkphngknkmgccmlenfaelkd 0 Seznam Lištička - Slovník 1.2.14
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension ccfjbdjailljfihgkoccfbiljjapiijb
Extension cfhdojbkjhnklbpkdaibdccddilifddb 1 Adblock Plus 1.12.4
Extension dfohdbmjdkfijghgklbickfnaepghgba 0
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension hgecghmkcdefnknohcimkoemhaofpoha 0 PDF Mergy 0.5.4
Extension hlhbmnfdcklajeaeikfinieljfegamko 1 Speed Test 2.4.7
Extension jclipofobaadknkadkpgggmjkebddjam 0 PDF to Word Converter App 2.1
Extension kigpmgkoelepakabiliblldhdpnidcod 0 Translate Japanese to English 0.1
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension lneaknkopdijkpnocmklfnjbeapigfbh 0 Mapy Google 5.4.1
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension mjpieolhcmajmolkhbbeljknkcdcmffk 0 PDF Cloud Tools 2.10.2
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension olfeabkoenfaoljndfecamgilllcpiak 0 Seznam Lištička - Rychlá volba 1.7.13
Extension onlgmecjpnejhfeofkgbfgnmdlipdejb 0 Picasa 6.2.2
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5416.905.0.6
Homepage: http://www.seznam.cz/
default_search_provider.search_url:
C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-08-27 163528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~2\Office15\GROOVEEX.DLL [2016-08-16 1743664]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SysTrayApp"=C:\Program Files\IDT\WDM\sttray.exe [2008-05-06 442433]
"CDAServer"=C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [2012-03-09 350072]
"PCMService"=C:\Program Files\Dell\MediaDirect\PCMService.exe [2008-07-04 132392]
"Dell Webcam Central"=C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [2008-06-03 446635]
"WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2016-07-16 483840]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Petr\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-09-25 633024]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [2015-07-13 248176]
"DellSystemDetect"=C:\Users\Petr\AppData\Local\Apps\2.0\WBTT3JXD.NAM\RJGXWCJZ.374\dell..tion_6d0a76327dca4869_0007.0009_d84bde3ab35e468d\DellSystemDetect.exe [2016-11-03 313800]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iaioi2c.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"undockwithoutlogon"=1
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
"StubPath"=%SystemRoot%\inf\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files\Google\Chrome\Application\54.0.2840.71\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.cvid"=iccvid.dll
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-11-07 19:43:04 ----D---- C:\ProgramData\~0
2016-11-07 16:09:06 ----D---- C:\WINDOWS\Microsoft Antimalware
2016-11-03 20:09:24 ----D---- C:\ProgramData\PC-Doctor for Windows
2016-11-03 20:08:56 ----D---- C:\Program Files\Dell Support Center
2016-11-03 15:12:18 ----D---- C:\Program Files\trend micro
2016-11-03 15:12:16 ----D---- C:\rsit
2016-11-01 16:56:49 ----A---- C:\WINDOWS\system32\sppsvc.exe
2016-11-01 16:56:48 ----A---- C:\WINDOWS\system32\wininet.dll
2016-11-01 16:56:48 ----A---- C:\WINDOWS\system32\sppobjs.dll
2016-11-01 16:56:47 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-11-01 16:56:47 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-11-01 16:56:46 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-11-01 16:56:46 ----A---- C:\WINDOWS\system32\qmgr.dll
2016-11-01 16:56:45 ----A---- C:\WINDOWS\system32\winload.exe
2016-11-01 16:56:45 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-11-01 16:56:45 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-11-01 16:56:45 ----A---- C:\WINDOWS\system32\iphlpsvc.dll
2016-11-01 16:56:44 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-11-01 16:56:44 ----A---- C:\WINDOWS\system32\sppwinob.dll
2016-11-01 16:56:44 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-11-01 16:56:43 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-11-01 16:56:43 ----A---- C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-11-01 16:56:43 ----A---- C:\WINDOWS\system32\diagtrack.dll
2016-11-01 16:56:42 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2016-11-01 16:56:42 ----A---- C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-11-01 16:56:42 ----A---- C:\WINDOWS\system32\powercfg.exe
2016-11-01 16:56:42 ----A---- C:\WINDOWS\system32\HttpsDataSource.dll
2016-11-01 16:56:42 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-11-01 16:56:42 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2016-11-01 16:56:42 ----A---- C:\WINDOWS\system32\cdd.dll
2016-11-01 16:56:40 ----A---- C:\WINDOWS\system32\efsext.dll
2016-11-01 16:56:40 ----A---- C:\WINDOWS\system32\EditionUpgradeHelper.dll
2016-11-01 16:56:39 ----A---- C:\WINDOWS\system32\zipfldr.dll
2016-11-01 16:56:35 ----A---- C:\WINDOWS\system32\NotificationController.dll
2016-11-01 16:56:34 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-11-01 16:56:31 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-11-01 16:56:29 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-11-01 16:56:29 ----A---- C:\WINDOWS\system32\ClipUp.exe
2016-11-01 16:56:28 ----A---- C:\WINDOWS\system32\mispace.dll
2016-11-01 16:56:27 ----A---- C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-11-01 16:56:27 ----A---- C:\WINDOWS\system32\esent.dll
2016-11-01 16:56:26 ----A---- C:\WINDOWS\system32\WsmSvc.dll
2016-11-01 16:56:26 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2016-11-01 16:56:25 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-11-01 16:56:24 ----A---- C:\WINDOWS\system32\msctf.dll
2016-11-01 16:56:24 ----A---- C:\WINDOWS\system32\daxexec.dll
2016-11-01 16:56:24 ----A---- C:\WINDOWS\system32\d3d9.dll
2016-11-01 16:56:23 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2016-11-01 16:56:23 ----A---- C:\WINDOWS\system32\hevcdecoder.dll
2016-11-01 16:56:23 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-11-01 16:56:22 ----A---- C:\WINDOWS\system32\wer.dll
2016-11-01 16:56:22 ----A---- C:\WINDOWS\system32\inetcomm.dll
2016-11-01 16:56:22 ----A---- C:\WINDOWS\system32\drvstore.dll
2016-11-01 16:56:22 ----A---- C:\WINDOWS\system32\AudioSes.dll
2016-11-01 16:56:21 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-11-01 16:56:21 ----A---- C:\WINDOWS\system32\user32.dll
2016-11-01 16:56:21 ----A---- C:\WINDOWS\system32\mfksproxy.dll
2016-11-01 16:56:21 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-11-01 16:56:21 ----A---- C:\WINDOWS\system32\CPFilters.dll
2016-11-01 16:56:20 ----A---- C:\WINDOWS\system32\wintrust.dll
2016-11-01 16:56:20 ----A---- C:\WINDOWS\system32\usercpl.dll
2016-11-01 16:56:20 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2016-11-01 16:56:19 ----A---- C:\WINDOWS\system32\winsrv.dll
2016-11-01 16:56:19 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-11-01 16:56:19 ----A---- C:\WINDOWS\system32\weretw.dll
2016-11-01 16:56:19 ----A---- C:\WINDOWS\system32\SndVolSSO.dll
2016-11-01 16:56:19 ----A---- C:\WINDOWS\system32\drivers\storport.sys
2016-11-01 16:56:19 ----A---- C:\WINDOWS\system32\drivers\crashdmp.sys
2016-11-01 16:56:19 ----A---- C:\WINDOWS\system32\BthRadioMedia.dll
2016-11-01 16:56:19 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2016-11-01 16:56:18 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2016-11-01 16:56:18 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-11-01 16:56:18 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2016-11-01 16:56:18 ----A---- C:\WINDOWS\system32\ole32.dll
2016-11-01 16:56:18 ----A---- C:\WINDOWS\system32\cmifw.dll
2016-11-01 16:56:17 ----A---- C:\WINDOWS\system32\Geolocation.dll
2016-11-01 16:56:13 ----A---- C:\WINDOWS\system32\usocore.dll
2016-11-01 16:56:13 ----A---- C:\WINDOWS\system32\olepro32.dll
2016-11-01 16:56:13 ----A---- C:\WINDOWS\system32\esentutl.exe
2016-11-01 16:56:13 ----A---- C:\WINDOWS\system32\asycfilt.dll
2016-11-01 16:56:12 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-11-01 16:56:09 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-11-01 16:56:04 ----A---- C:\WINDOWS\system32\shell32.dll
2016-11-01 16:56:00 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2016-11-01 16:55:59 ----A---- C:\WINDOWS\system32\wsp_health.dll
2016-11-01 16:55:58 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2016-11-01 16:55:57 ----A---- C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-11-01 16:55:56 ----A---- C:\WINDOWS\system32\wpnprv.dll
2016-11-01 16:55:56 ----A---- C:\WINDOWS\system32\energy.dll
2016-11-01 16:55:55 ----A---- C:\WINDOWS\system32\wc_storage.dll
2016-11-01 16:55:54 ----A---- C:\WINDOWS\system32\wscsvc.dll
2016-11-01 16:55:54 ----A---- C:\WINDOWS\system32\twinui.pcshell.dll
2016-11-01 16:55:54 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2016-11-01 16:55:54 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2016-11-01 16:55:53 ----A---- C:\WINDOWS\system32\MusNotification.exe
2016-11-01 16:55:53 ----A---- C:\WINDOWS\system32\MDMAppInstaller.exe
2016-11-01 16:55:53 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2016-11-01 16:55:52 ----A---- C:\WINDOWS\system32\iscsiwmi.dll
2016-11-01 16:55:52 ----A---- C:\WINDOWS\system32\ieproxy.dll
2016-11-01 16:55:52 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2016-11-01 16:55:50 ----A---- C:\WINDOWS\system32\mshtmled.dll
2016-11-01 16:55:50 ----A---- C:\WINDOWS\system32\LockAppBroker.dll
2016-11-01 16:55:50 ----A---- C:\WINDOWS\system32\dxtrans.dll
2016-11-01 16:55:48 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-11-01 16:55:47 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-11-01 16:55:47 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-11-01 16:55:47 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-11-01 16:55:46 ----A---- C:\WINDOWS\system32\wmp.dll
2016-11-01 16:55:44 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-11-01 16:55:42 ----A---- C:\WINDOWS\system32\winmde.dll
2016-11-01 16:55:42 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2016-11-01 16:55:42 ----A---- C:\WINDOWS\system32\combase.dll
2016-11-01 16:55:41 ----A---- C:\WINDOWS\system32\wpncore.dll
2016-11-01 16:55:41 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-11-01 16:55:41 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2016-11-01 16:55:40 ----A---- C:\WINDOWS\system32\winhttp.dll
2016-11-01 16:55:40 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-11-01 16:55:40 ----A---- C:\WINDOWS\system32\spoolsv.exe
2016-11-01 16:55:40 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2016-11-01 16:55:40 ----A---- C:\WINDOWS\system32\crypt32.dll
2016-11-01 16:55:39 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2016-11-01 16:55:39 ----A---- C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-11-01 16:55:39 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-11-01 16:55:39 ----A---- C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-11-01 16:55:39 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-11-01 16:55:38 ----A---- C:\WINDOWS\system32\wmpshell.dll
2016-11-01 16:55:38 ----A---- C:\WINDOWS\system32\wmpeffects.dll
2016-11-01 16:55:38 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-11-01 16:55:38 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2016-11-01 16:55:38 ----A---- C:\WINDOWS\system32\drivers\dam.sys
2016-11-01 16:55:37 ----A---- C:\WINDOWS\system32\wmpdxm.dll
2016-11-01 16:55:37 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-11-01 16:55:37 ----A---- C:\WINDOWS\system32\oleaut32.dll
2016-11-01 16:55:37 ----A---- C:\WINDOWS\system32\drivers\http.sys
2016-11-01 16:55:37 ----A---- C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2016-11-01 16:55:36 ----A---- C:\WINDOWS\system32\drivers\hidclass.sys
2016-11-01 16:55:36 ----A---- C:\WINDOWS\system32\DolbyDecMFT.dll
2016-11-01 16:55:36 ----A---- C:\WINDOWS\splwow64.exe
2016-11-01 16:55:35 ----A---- C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2016-11-01 16:55:31 ----A---- C:\WINDOWS\system32\twinui.dll
2016-11-01 16:55:27 ----A---- C:\WINDOWS\system32\mos.dll
2016-11-01 16:55:26 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-11-01 16:55:25 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-11-01 16:55:23 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-11-01 16:55:23 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-11-01 16:55:22 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-11-01 16:55:20 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-11-01 16:55:20 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-11-01 16:55:19 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2016-11-01 16:55:19 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-11-01 16:55:18 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-11-01 16:55:18 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-11-01 16:55:18 ----A---- C:\WINDOWS\explorer.exe
2016-11-01 16:55:16 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-11-01 16:55:16 ----A---- C:\WINDOWS\system32\devinv.dll
2016-11-01 16:55:16 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-11-01 16:55:15 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2016-11-01 16:55:14 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-11-01 16:55:14 ----A---- C:\WINDOWS\system32\DWrite.dll
2016-11-01 16:55:13 ----A---- C:\WINDOWS\system32\mfplat.dll
2016-11-01 16:55:13 ----A---- C:\WINDOWS\system32\D3D12.dll
2016-11-01 16:55:12 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-11-01 16:55:12 ----A---- C:\WINDOWS\system32\FntCache.dll
2016-11-01 16:55:11 ----A---- C:\WINDOWS\system32\winresume.exe
2016-11-01 16:55:11 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-11-01 16:55:11 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-11-01 16:55:10 ----A---- C:\WINDOWS\system32\msvproc.dll
2016-11-01 16:55:10 ----A---- C:\WINDOWS\system32\invagent.dll
2016-11-01 16:55:10 ----A---- C:\WINDOWS\system32\FrameServer.dll
2016-11-01 16:55:09 ----A---- C:\WINDOWS\system32\pcasvc.dll
2016-11-01 16:55:09 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-11-01 16:55:09 ----A---- C:\WINDOWS\system32\aepic.dll
2016-11-01 16:55:08 ----A---- C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-11-01 16:55:08 ----A---- C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-11-01 16:55:08 ----A---- C:\WINDOWS\system32\twinapi.dll
2016-11-01 16:55:08 ----A---- C:\WINDOWS\system32\gameux.dll
2016-11-01 16:55:07 ----A---- C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-11-01 16:55:07 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-11-01 16:55:07 ----A---- C:\WINDOWS\system32\cdpsvc.dll
2016-11-01 16:55:07 ----A---- C:\WINDOWS\system32\authui.dll
2016-11-01 16:55:06 ----A---- C:\WINDOWS\system32\mfsensorgroup.dll
2016-11-01 16:55:06 ----A---- C:\WINDOWS\system32\drivers\ahcache.sys
2016-11-01 16:55:06 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2016-11-01 16:55:06 ----A---- C:\WINDOWS\system32\cdpusersvc.dll
2016-11-01 16:55:05 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-11-01 16:55:05 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-11-01 16:55:05 ----A---- C:\WINDOWS\system32\hgcpl.dll
2016-11-01 16:55:04 ----A---- C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-11-01 16:55:04 ----A---- C:\WINDOWS\system32\sud.dll
2016-11-01 16:55:04 ----A---- C:\WINDOWS\system32\autoplay.dll
2016-11-01 16:55:04 ----A---- C:\WINDOWS\system32\ActionCenterCPL.dll
2016-11-01 16:55:03 ----A---- C:\WINDOWS\system32\systemcpl.dll
2016-11-01 16:55:03 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-11-01 16:55:01 ----A---- C:\WINDOWS\system32\taskbarcpl.dll
2016-11-01 16:55:01 ----A---- C:\WINDOWS\system32\stobject.dll
2016-11-01 16:55:01 ----A---- C:\WINDOWS\system32\NetworkDesktopSettings.dll
2016-11-01 16:55:01 ----A---- C:\WINDOWS\system32\msinfo32.exe
2016-11-01 16:55:01 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2016-11-01 16:55:00 ----A---- C:\WINDOWS\system32\themecpl.dll
2016-11-01 16:55:00 ----A---- C:\WINDOWS\system32\LockScreenContent.dll
2016-11-01 16:55:00 ----A---- C:\WINDOWS\system32\chartv.dll
2016-11-01 16:55:00 ----A---- C:\WINDOWS\system32\FSClient.dll
2016-11-01 16:55:00 ----A---- C:\WINDOWS\system32\fontext.dll
2016-10-23 11:39:01 ----D---- C:\Program Files\Adobe
2016-10-23 11:39:01 ----AD---- C:\Program Files\Common Files\Adobe
2016-10-23 11:37:16 ----D---- C:\ProgramData\Adobe
2016-10-21 16:41:24 ----AD---- C:\Program Files\Common Files\DESIGNER
2016-10-12 16:37:25 ----D---- C:\Program Files\SMPlayer
2016-10-12 16:14:38 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-10-12 16:14:38 ----A---- C:\WINDOWS\system32\ShareHost.dll
2016-10-12 16:14:38 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2016-10-12 16:14:36 ----A---- C:\WINDOWS\system32\msdtctm.dll
2016-10-12 16:14:26 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-10-12 16:14:26 ----A---- C:\WINDOWS\system32\msi.dll
2016-10-12 16:14:25 ----A---- C:\WINDOWS\system32\wpx.dll
2016-10-12 16:14:25 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-10-12 16:14:24 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-12 16:14:24 ----A---- C:\WINDOWS\system32\wbiosrvc.dll
2016-10-12 16:14:24 ----A---- C:\WINDOWS\system32\nlasvc.dll
2016-10-12 16:14:24 ----A---- C:\WINDOWS\system32\ncsi.dll
2016-10-12 16:14:24 ----A---- C:\WINDOWS\system32\drivers\MegaSas2i.sys
2016-10-12 16:14:23 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2016-10-12 16:14:22 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2016-10-12 16:14:22 ----A---- C:\WINDOWS\system32\bcdedit.exe
2016-10-12 16:14:21 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-10-12 16:14:21 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-10-12 16:14:21 ----A---- C:\WINDOWS\system32\shutdownux.dll
2016-10-12 16:14:21 ----A---- C:\WINDOWS\system32\dsreg.dll
2016-10-12 16:14:20 ----A---- C:\WINDOWS\system32\Windows.Networking.HostName.dll
2016-10-12 16:14:20 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-10-12 16:14:20 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2016-10-12 16:14:14 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-10-12 16:14:11 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2016-10-12 16:14:10 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-10-12 16:14:09 ----A---- C:\WINDOWS\system32\MSVidCtl.dll
2016-10-12 16:14:08 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-10-12 16:14:08 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-10-12 16:14:07 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-10-12 16:14:07 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2016-10-12 16:14:06 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2016-10-12 16:14:06 ----A---- C:\WINDOWS\system32\cloudAP.dll
2016-10-12 16:14:05 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-10-12 16:14:05 ----A---- C:\WINDOWS\system32\mstsc.exe
2016-10-12 16:14:04 ----A---- C:\WINDOWS\system32\netshell.dll
2016-10-12 16:14:03 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-12 16:14:03 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2016-10-12 16:14:03 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-10-12 16:13:58 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2016-10-12 16:13:57 ----A---- C:\WINDOWS\system32\KernelBase.dll
2016-10-12 16:13:55 ----A---- C:\WINDOWS\system32\win32spl.dll
2016-10-12 16:13:54 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2016-10-12 16:13:53 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2016-10-12 16:13:52 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-10-12 16:13:52 ----A---- C:\WINDOWS\system32\offreg.dll
2016-10-12 16:13:52 ----A---- C:\WINDOWS\system32\efswrt.dll
2016-10-12 16:13:52 ----A---- C:\WINDOWS\system32\drivers\tm.sys
2016-10-12 16:13:52 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2016-10-12 16:13:51 ----A---- C:\WINDOWS\system32\PrintDialogs3D.dll
2016-10-12 16:13:51 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2016-10-12 16:13:51 ----A---- C:\WINDOWS\system32\cscui.dll
2016-10-12 16:13:51 ----A---- C:\WINDOWS\system32\aadtb.dll
2016-10-12 16:13:50 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-10-12 16:13:50 ----A---- C:\WINDOWS\system32\ConfigureExpandedStorage.dll
2016-10-12 16:13:43 ----A---- C:\WINDOWS\system32\smartscreen.exe
2016-10-12 16:13:43 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-10-12 16:13:41 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-10-12 16:13:40 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-10-12 16:13:40 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-10-12 16:13:40 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-10-12 16:13:40 ----A---- C:\WINDOWS\system32\apprepapi.dll
2016-10-12 16:13:39 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-10-12 16:13:39 ----A---- C:\WINDOWS\system32\ChatApis.dll
2016-10-12 16:13:39 ----A---- C:\WINDOWS\system32\EmailApis.dll
2016-10-12 16:13:39 ----A---- C:\WINDOWS\system32\credprovs.dll
2016-10-12 16:13:39 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-10-12 16:13:38 ----A---- C:\WINDOWS\system32\UserDataAccountApis.dll
2016-10-12 16:13:38 ----A---- C:\WINDOWS\system32\apprepsync.dll
2016-10-12 16:13:38 ----A---- C:\WINDOWS\system32\adsmsext.dll
2016-10-12 16:13:37 ----A---- C:\WINDOWS\system32\dialclient.dll
2016-10-12 16:13:37 ----A---- C:\WINDOWS\system32\ContactApis.dll
2016-10-12 16:13:37 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2016-10-12 16:13:36 ----A---- C:\WINDOWS\system32\mspaint.exe

======List of files/folders modified in the last 1 month======

2016-11-07 21:48:46 ----D---- C:\WINDOWS\Temp
2016-11-07 21:30:33 ----D---- C:\WINDOWS\Prefetch
2016-11-07 21:21:00 ----D---- C:\WINDOWS\system32\sru
2016-11-07 21:14:59 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-11-07 20:42:05 ----HD---- C:\ProgramData
2016-11-07 20:41:57 ----RD---- C:\Program Files
2016-11-07 20:41:48 ----SHD---- C:\WINDOWS\Installer
2016-11-07 20:41:30 ----HD---- C:\Config.Msi
2016-11-07 20:38:02 ----D---- C:\WINDOWS\System32
2016-11-07 20:37:59 ----D---- C:\WINDOWS\system32\Tasks
2016-11-07 20:37:58 ----D---- C:\WINDOWS\Tasks
2016-11-07 20:36:02 ----SHD---- C:\System Volume Information
2016-11-07 20:21:23 ----D---- C:\WINDOWS\system32\SleepStudy
2016-11-07 18:25:25 ----RD---- C:\WINDOWS\Microsoft.NET
2016-11-07 18:14:53 ----D---- C:\WINDOWS\LiveKernelReports
2016-11-07 17:14:16 ----D---- C:\WINDOWS\AppReadiness
2016-11-07 17:02:07 ----D---- C:\WINDOWS\system32\config
2016-11-07 16:09:06 ----D---- C:\Windows
2016-11-05 23:21:55 ----D---- C:\Downloads
2016-11-05 17:50:10 ----HD---- C:\Program Files\WindowsApps
2016-11-04 18:10:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-11-04 18:05:34 ----D---- C:\WINDOWS\system32\drivers
2016-11-04 18:04:42 ----D---- C:\WINDOWS\system32\catroot2
2016-11-04 08:05:58 ----D---- C:\WINDOWS\rescache
2016-11-04 07:33:52 ----D---- C:\WINDOWS\system32\DriverStore
2016-11-04 07:33:50 ----D---- C:\WINDOWS\WinSxS
2016-11-03 20:19:29 ----D---- C:\WINDOWS\system32\LogFiles
2016-11-03 20:16:04 ----D---- C:\Temp
2016-11-03 20:06:16 ----D---- C:\ProgramData\PCDr
2016-11-03 16:39:37 ----D---- C:\WINDOWS\Registration
2016-11-03 14:39:56 ----D---- C:\WINDOWS\CbsTemp
2016-11-02 15:46:12 ----D---- C:\WINDOWS\INF
2016-11-01 18:55:30 ----SHD---- C:\Boot
2016-11-01 18:51:22 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2016-11-01 18:51:22 ----D---- C:\WINDOWS\system32\wbem
2016-11-01 18:51:20 ----D---- C:\WINDOWS\system32\oobe
2016-11-01 18:51:19 ----D---- C:\WINDOWS\system32\migration
2016-11-01 18:51:19 ----D---- C:\WINDOWS\system32\en-US
2016-11-01 18:51:19 ----D---- C:\WINDOWS\system32\cs-CZ
2016-11-01 18:51:18 ----D---- C:\WINDOWS\system32\Boot
2016-11-01 18:51:18 ----D---- C:\WINDOWS\system32\appraiser
2016-11-01 18:50:57 ----RSD---- C:\WINDOWS\Fonts
2016-11-01 18:50:57 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-11-01 18:50:57 ----D---- C:\WINDOWS\PolicyDefinitions
2016-11-01 18:50:57 ----D---- C:\WINDOWS\apppatch
2016-11-01 18:50:56 ----D---- C:\Program Files\Windows Media Player
2016-11-01 11:12:20 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2016-10-25 00:30:58 ----A---- C:\WINDOWS\system32\FlashPlayerApp.exe
2016-10-23 11:42:13 ----SD---- C:\Users\Petr\AppData\Roaming\Microsoft
2016-10-23 11:42:13 ----D---- C:\Users\Petr\AppData\Roaming\Adobe
2016-10-23 11:39:01 ----D---- C:\Program Files\Common Files
2016-10-21 16:41:41 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-10-21 16:41:25 ----AD---- C:\Program Files\Common Files\microsoft shared
2016-10-21 16:16:44 ----AD---- C:\Program Files\Microsoft Office
2016-10-19 14:49:46 ----D---- C:\ProgramData\Microsoft Help
2016-10-19 14:46:52 ----RD---- C:\WINDOWS\assembly
2016-10-15 10:03:23 ----D---- C:\Program Files\VS Revo Group
2016-10-15 10:01:13 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2016-10-15 10:01:12 ----SD---- C:\WINDOWS\system32\DiagSvcs
2016-10-15 10:01:12 ----D---- C:\WINDOWS\system32\migwiz
2016-10-15 10:00:57 ----D---- C:\WINDOWS\ShellExperiences
2016-10-15 10:00:55 ----D---- C:\Program Files\Windows Photo Viewer
2016-10-15 09:57:54 ----D---- C:\WINDOWS\system32\MRT
2016-10-15 09:47:20 ----D---- C:\Users\Petr\AppData\Roaming\Spy Emergency
2016-10-15 09:38:55 ----D---- C:\WINDOWS\debug
2016-10-15 09:38:44 ----AC---- C:\WINDOWS\system32\MRT.exe
2016-10-15 09:34:13 ----A---- C:\WINDOWS\win.ini
2016-10-15 09:20:34 ----D---- C:\Users\Petr\AppData\Roaming\Philipp Winterberg

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-07-16 38240]
R1 SpyEmrg;Spy Emergency Driver; C:\WINDOWS\System32\Drivers\spyemrg.sys [2011-04-21 14168]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 58368]
R2 rismxdp;@oem1.inf,%DiskServiceDesc%;Ricoh xD-Picture Card Driver; C:\WINDOWS\System32\drivers\rixdptsk.sys [2006-11-14 37376]
R2 SSPORT;SSPORT; \??\C:\WINDOWS\system32\Drivers\SSPORT.sys [2013-04-30 5120]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-01-13 10070016]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-01-13 290304]
R3 BCM43XX;@netbc63.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 Network Adapter Driver; C:\WINDOWS\System32\drivers\bcmwl63l.sys [2016-07-16 4715008]
R3 DDDriver;DDDriver; C:\WINDOWS\system32\drivers\DDDriver32Dcsa.sys [2016-01-05 29400]
R3 DellProf;DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [2016-01-05 22192]
R3 itecir;@oem0.inf,%itecir.SVCDESC%;ITECIR Infrared Receiver; C:\WINDOWS\system32\DRIVERS\itecir.sys [2015-11-24 84600]
R3 ITECIRfilter;@oem0.inf,%filter.SvcDesc%;ITECIR Filter Driver; C:\WINDOWS\system32\DRIVERS\ITECIRfilter.sys [2015-11-24 34000]
R3 k57nd60x;@netk57x.inf,%SvcDispName%;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\WINDOWS\System32\drivers\k57nd60x.sys [2016-07-16 397824]
R3 STHDA;@oem5.inf,%ST.DeviceDesc%;IDT High Definition Audio CODEC; C:\WINDOWS\system32\DRIVERS\stwrt.sys [2008-05-06 379904]
R3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;Zobrazovací zařízení USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2016-09-23 188928]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-05 56672]
S1 MpKsla75b204a;MpKsla75b204a; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1EE3CBA8-55D1-4BCF-B82D-50D69F0306B2}\MpKsla75b204a.sys []
S2 Parvdm;Parvdm; C:\WINDOWS\System32\drivers\parvdm.sys [2016-07-16 9216]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 12800]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 12288]
S3 AppvStrm;@%systemroot%\system32\drivers\AppvStrm.sys,-101; C:\WINDOWS\system32\drivers\AppvStrm.sys [2016-09-15 94560]
S3 AppvVemgr;@%systemroot%\system32\drivers\AppvVemgr.sys,-101; C:\WINDOWS\system32\drivers\AppvVemgr.sys [2016-07-16 118112]
S3 AppvVfs;@%systemroot%\system32\drivers\AppvVfs.sys,-101; C:\WINDOWS\system32\drivers\AppvVfs.sys [2016-07-16 111456]
S3 GPIO;@iaiogpio.inf,%GPIO.SVCDESC%;Intel SoC GPIO Controller Driver; C:\WINDOWS\System32\drivers\iaiogpio.sys [2016-07-16 22016]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 25600]
S3 iaioi2c;@iaioi2c.inf,%Driver_Service.Desc%;Intel(R) Atom(TM) Processor I2C Controller Service; C:\WINDOWS\System32\drivers\iaioi2c.sys [2016-07-16 61936]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 30208]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 94720]
S3 MsSecFlt;@%SystemRoot%\System32\Drivers\mssecflt.sys,-1001; C:\WINDOWS\system32\drivers\mssecflt.sys [2016-07-16 159584]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 62976]
S3 SpyEmrgAccess;Spy Emergency OnAccess Driver; C:\WINDOWS\System32\Drivers\spyemrg_access.sys [2011-04-21 20056]
S3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver; C:\WINDOWS\System32\Drivers\spyemrg_guard.sys [2015-03-09 18872]
S3 tsusbhub;@%SystemRoot%\system32\drivers\tsusbhub.sys,-1; C:\WINDOWS\system32\drivers\tsusbhub.sys [2016-07-16 91648]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys [2016-07-16 76800]
S4 UevAgentDriver;@%systemroot%\system32\drivers\UevAgentDriver.sys,-101; C:\WINDOWS\system32\drivers\UevAgentDriver.sys [2016-07-16 36192]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CDPUserSvc_3786e;CDPUserSvc_3786e; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-10-08 2288320]
R2 OneSyncSvc_3786e;Hostitel synchronizace_3786e; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
R3 PimIndexMaintenanceSvc_3786e;Data kontaktů_3786e; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\RMapi.dll
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\TimeBrokerServer.dll
R3 UnistoreSvc_3786e;Úložiště uživatelských dat_3786e; C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
R3 UserDataSvc_3786e;Přístup k uživatelským datům_3786e; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=%SystemRoot%\System32\CDPUserSvc.dll
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll"=%SystemRoot%\system32\FrameServer.dll
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\irmon.dll
S3 MessagingService_3786e;Služba zasílání zpráv_3786e; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2016-10-07 209104]
S3 Sense;@%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2016-09-15 1887272]
S4 AESTFilters;Andrea ST Filters Service; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_x86_c8e33401effad09d\aestsrv.exe [2008-02-28 73728]
S4 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-01-13 217088]
S4 AppVClient;@%systemroot%\system32\AppVClient.exe,-102; C:\WINDOWS\system32\AppVClient.exe [2016-09-15 614752]
S4 DellDataVault;Dell Data Vault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2016-06-23 1958648]
S4 DellDataVaultWiz;Dell Data Vault Wizard; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [2016-06-23 185080]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll"=%systemroot%\system32\Windows.SharedPC.AccountManager.dll
S4 STacSV;Audio Service; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_x86_c8e33401effad09d\STacSV.exe [2008-05-06 221239]
S4 SupportAssistAgent;Dell SupportAssist Agent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [2016-09-09 31704]
S4 TomTomHOMEService;TomTomHOMEService; C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe [2015-07-13 93040]
S4 UevAgentService;@%systemroot%\system32\AgentService.exe,-102; C:\WINDOWS\system32\AgentService.exe [2016-07-16 858624]

-----------------EOF-----------------

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 07 lis 2016 22:41
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 07 lis 2016 23:21
od bejk62
přikládám log z AdwCleaner:

# AdwCleaner v6.030 - Log soubor vytvořen 07/11/2016 na 23:07:42
# Aktualizováno dne 19/10/2016 z Malwarebytes
# Databáze : 2016-11-07.1 [Server]
# Operační systém : Windows 10 Pro (X86)
# Uživatelské jméno : Petr - NOTEBOOK
# Beží od : C:\Users\Petr\Desktop\adwcleaner_6.030.exe
# Mod: Čištění
# Podpora : hxxps://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Adresáře ] *****

[-] Adresář smazán:C:\Genius
[-] Adresář smazán:C:\sh4ldr
[-] Adresář smazán:C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod
[-] Adresář smazán:C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjpieolhcmajmolkhbbeljknkcdcmffk


***** [ Soubory ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupce ] *****



***** [ Plánovač úloh ] *****



***** [ Registry ] *****

[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\solvusoft.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\store.solvusoft.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\EdpDomStorage\www.solvusoft.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\solvusoft.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\store.solvusoft.com
[-] Klíč smazán:HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.microsoftedge_8wekyb3d8bbwe\Children\001\Internet Explorer\DOMStorage\www.solvusoft.com


***** [ Prohlížeče ] *****

[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:babylon.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:isearch.avg.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:bechiro s.l.
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:inbox.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:ask search
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:daemon-search.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:buenosearch.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:ask.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:slunecnice.cz
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:search.ask.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:icq.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:search.icq.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:search.conduit.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:r
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:yahoo.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:dl.ask.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Smazání:slirsredirect.search.aol.com
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default] [extension] Smazání:dfohdbmjdkfijghgklbickfnaepghgba
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default] [extension] Smazání:kigpmgkoelepakabiliblldhdpnidcod
[-] [C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default] [extension] Smazání:mjpieolhcmajmolkhbbeljknkcdcmffk


*************************

:: "Tracing" klíč smazán
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C2].txt - [1801 Bajtů] - [22/11/2015 17:38:45]
C:\AdwCleaner\AdwCleaner[C3].txt - [4859 Bajtů] - [07/11/2016 23:07:42]
C:\AdwCleaner\AdwCleaner[R0].txt - [27860 Bajtů] - [23/05/2014 20:47:57]
C:\AdwCleaner\AdwCleaner[R1].txt - [18651 Bajtů] - [23/05/2014 21:08:02]
C:\AdwCleaner\AdwCleaner[R2].txt - [1099 Bajtů] - [23/05/2014 21:35:40]
C:\AdwCleaner\AdwCleaner[S0].txt - [8115 Bajtů] - [23/05/2014 20:53:34]
C:\AdwCleaner\AdwCleaner[S1].txt - [21081 Bajtů] - [23/05/2014 21:12:46]
C:\AdwCleaner\AdwCleaner[S2].txt - [1661 Bajtů] - [22/11/2015 17:34:52]
C:\AdwCleaner\AdwCleaner[S3].txt - [5755 Bajtů] - [07/11/2016 22:54:42]

########## EOF - C:\AdwCleaner\AdwCleaner[C3].txt - [5454 Bajtů] ##########

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 08 lis 2016 19:03
od Rudy

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 12:47
od bejk62
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 06-11-2016
Ran by Petr (administrator) on NOTEBOOK (09-11-2016 12:22:05)
Running from C:\Users\Petr\Desktop
Loaded Profiles: Petr (Available Profiles: Petr)
Platform: Microsoft Windows 10 Pro Version 1607 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Microsoft® Windows® Operating System) C:\Windows\System32\Taskmgr.exe
(Microsoft Corporation) C:\Windows\WinSxS\x86_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.350_none_e708f365ace4144b\TiWorker.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray.exe [442433 2008-05-06] (IDT, Inc.)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [350072 2012-03-09] ()
HKLM\...\Run: [PCMService] => C:\Program Files\Dell\MediaDirect\PCMService.exe [132392 2008-07-04] (CyberLink Corp.)
HKLM\...\Run: [Dell Webcam Central] => C:\Program Files\Dell Webcam\Dell Webcam Central\WebcamDell.exe [446635 2008-06-03] (Creative Technology Ltd.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [483840 2016-07-16] (Microsoft Corporation)
HKU\S-1-5-21-1778750531-1012615130-3227783400-1001\...\Run: [TomTomHOME.exe] => C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe [248176 2015-07-13] (TomTom)
HKU\S-1-5-21-1778750531-1012615130-3227783400-1001\...\Run: [DellSystemDetect] => C:\Users\Petr\AppData\Local\Apps\2.0\WBTT3JXD.NAM\RJGXWCJZ.374\dell..tion_6d0a76327dca4869_0007.0009_d84bde3ab35e468d\DellSystemDetect.exe [313800 2016-11-03] (Dell)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0accc889-1862-489d-a7cc-7f79e1f30219}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{fbe9af84-ec28-4d00-be65-b2f433205f80}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-1778750531-1012615130-3227783400-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=MSE1
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-08-27] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2016-08-16] (Microsoft Corporation)
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-10-21] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-10-21] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-08-16] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-10-21] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-10-21] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Petr\AppData\Roaming\TomTom\HOME\Profiles\87oxaybf.default [2016-07-25]
FF Extension: (Map status indicator) - C:\Program Files\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2016-06-02] [not signed]
FF Plugin: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-19] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-10-08] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-01] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.seznam.cz/
CHR StartupUrls: Default -> "hxxps://www.seznam.cz/?logged=1"
CHR Profile: C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default [2016-11-09]
CHR Extension: (Prezentace Google) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-25]
CHR Extension: (Dokumenty Google) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-25]
CHR Extension: (Disk Google) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-25]
CHR Extension: (TV) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh [2016-04-25]
CHR Extension: (Seznam Lištička - Email) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2016-04-25]
CHR Extension: (Volání přes Skype) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blakpkgjpemejpbmfiglncklihnhjkij [2016-04-25]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2016-04-25]
CHR Extension: (YouTube) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-25]
CHR Extension: (Adblock Plus) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-11-01]
CHR Extension: (Tabulky Google) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-25]
CHR Extension: (Dokumenty Google offline) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-25]
CHR Extension: (PDF Mergy) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha [2016-04-25]
CHR Extension: (Speed Test) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlhbmnfdcklajeaeikfinieljfegamko [2016-04-25]
CHR Extension: (PDF to Word Converter App) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\jclipofobaadknkadkpgggmjkebddjam [2016-04-25]
CHR Extension: (Translate Japanese to English) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod [2016-11-07]
CHR Extension: (Mapy Google) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-04-25]
CHR Extension: (PDF Cloud Tools) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjpieolhcmajmolkhbbeljknkcdcmffk [2016-11-07]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-25]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2016-09-10]
CHR Extension: (Picasa) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2016-04-25]
CHR Extension: (Gmail) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-25]
CHR Extension: (Chrome Media Router) - C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-11-01]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S4 AESTFilters; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_x86_c8e33401effad09d\aestsrv.exe [73728 2008-02-28] (Andrea Electronics Corporation)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2288320 2016-10-08] (Microsoft Corporation)
S4 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [1958648 2016-06-23] (Dell Inc.)
S4 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [185080 2016-06-23] (Dell Inc.)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [1887272 2016-09-15] (Microsoft Corporation)
S4 STacSV; C:\WINDOWS\System32\DriverStore\FileRepository\stwrt.inf_x86_c8e33401effad09d\STacSV.exe [221239 2008-05-06] (IDT, Inc.)
S4 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [31704 2016-09-09] (Dell Inc.)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [271496 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [84928 2016-07-16] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 BCM43XX; C:\WINDOWS\System32\drivers\bcmwl63l.sys [4715008 2016-07-16] (Broadcom Corporation)
R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver32Dcsa.sys [29400 2016-01-05] (Dell Computer Corporation)
R3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [22192 2016-01-05] (Dell Computer Corporation)
R3 itecir; C:\WINDOWS\system32\DRIVERS\itecir.sys [84600 2015-11-24] (ITE Tech. Inc. )
R3 ITECIRfilter; C:\WINDOWS\system32\DRIVERS\ITECIRfilter.sys [34000 2015-11-24] (ITE Tech. Inc. )
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [62976 2016-07-16] ()
R1 SpyEmrg; C:\WINDOWS\System32\Drivers\spyemrg.sys [14168 2011-04-21] (NETGATE Technologies s.r.o.)
S3 SpyEmrgAccess; C:\WINDOWS\System32\Drivers\spyemrg_access.sys [20056 2011-04-21] (NETGATE Technologies s.r.o.)
S3 SpyEmrgGuard; C:\WINDOWS\System32\Drivers\spyemrg_guard.sys [18872 2015-03-09] (NETGATE Technologies s.r.o.)
R2 SSPORT; C:\WINDOWS\system32\Drivers\SSPORT.sys [5120 2013-04-30] (Samsung Electronics) [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [37912 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [244576 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [100192 2016-07-16] (Microsoft Corporation)
S1 MpKsla75b204a; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{1EE3CBA8-55D1-4BCF-B82D-50D69F0306B2}\MpKsla75b204a.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-09 12:22 - 2016-11-09 12:30 - 00012639 _____ C:\Users\Petr\Desktop\FRST.txt
2016-11-09 12:21 - 2016-11-09 12:22 - 00000000 ____D C:\FRST
2016-11-09 12:20 - 2016-11-09 12:20 - 01759744 _____ (Farbar) C:\Users\Petr\Desktop\FRST.exe
2016-11-07 22:46 - 2016-11-07 22:46 - 03910208 _____ C:\Users\Petr\Desktop\adwcleaner_6.030.exe
2016-11-07 21:48 - 2016-11-07 21:48 - 01201664 _____ C:\Users\Petr\Desktop\RSIT.exe
2016-11-07 19:42 - 2016-11-07 20:36 - 00000000 ____D C:\Users\Petr\AppData\Local\IIIQF
2016-11-07 19:26 - 2016-11-07 19:40 - 08932000 _____ (Solvusoft Corporation ) C:\Users\Petr\Downloads\Setup_WinThruster_2016.exe
2016-11-07 16:09 - 2016-11-07 17:01 - 00000000 ____D C:\WINDOWS\Microsoft Antimalware
2016-11-06 13:28 - 2016-11-06 13:28 - 06760064 _____ (ESET spol. s r.o.) C:\Users\Petr\Desktop\ESETOnlineScanner_CSY.exe
2016-11-05 22:47 - 2016-11-05 22:47 - 00000000 ____D C:\Users\Petr\AppData\Local\ESET
2016-11-03 20:09 - 2016-11-03 20:09 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows
2016-11-03 20:08 - 2016-11-03 20:09 - 00000000 ____D C:\Program Files\Dell Support Center
2016-11-03 19:48 - 2016-11-03 19:54 - 00000000 ____D C:\Users\Petr\AppData\Local\Deployment
2016-11-03 19:47 - 2016-11-03 19:48 - 00013560 _____ C:\Users\Petr\Desktop\DellSystemDetectLauncher.Application
2016-11-03 15:12 - 2016-11-07 21:49 - 00000000 ____D C:\Program Files\trend micro
2016-11-03 15:12 - 2016-11-03 15:13 - 00000000 ____D C:\rsit
2016-11-01 16:56 - 2016-10-15 06:11 - 00484584 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-11-01 16:56 - 2016-10-15 05:40 - 01126496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2016-11-01 16:56 - 2016-10-15 05:36 - 04970224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2016-11-01 16:56 - 2016-10-15 05:34 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2016-11-01 16:56 - 2016-10-15 05:33 - 06020448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-11-01 16:56 - 2016-10-15 05:33 - 01073816 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-11-01 16:56 - 2016-10-15 05:33 - 00945760 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-11-01 16:56 - 2016-10-15 05:32 - 01583112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-11-01 16:56 - 2016-10-15 05:20 - 01898336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-11-01 16:56 - 2016-10-15 05:20 - 00550752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-11-01 16:56 - 2016-10-15 05:20 - 00342880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-11-01 16:56 - 2016-10-15 05:19 - 02256592 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-11-01 16:56 - 2016-10-15 05:19 - 00272720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2016-11-01 16:56 - 2016-10-15 05:18 - 00749920 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvstore.dll
2016-11-01 16:56 - 2016-10-15 05:18 - 00576400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-11-01 16:56 - 2016-10-15 05:18 - 00454496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2016-11-01 16:56 - 2016-10-15 05:18 - 00186424 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2016-11-01 16:56 - 2016-10-15 05:18 - 00067424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2016-11-01 16:56 - 2016-10-15 05:15 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-11-01 16:56 - 2016-10-15 05:15 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-11-01 16:56 - 2016-10-15 05:14 - 01384704 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2016-11-01 16:56 - 2016-10-15 05:14 - 00802600 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2016-11-01 16:56 - 2016-10-15 05:14 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2016-11-01 16:56 - 2016-10-15 05:11 - 01424488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2016-11-01 16:56 - 2016-10-15 05:11 - 01345504 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-11-01 16:56 - 2016-10-15 05:11 - 01263848 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-11-01 16:56 - 2016-10-15 05:11 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-11-01 16:56 - 2016-10-15 05:10 - 00482656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2016-11-01 16:56 - 2016-10-15 05:00 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-11-01 16:56 - 2016-10-15 04:59 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfksproxy.dll
2016-11-01 16:56 - 2016-10-15 04:58 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\efsext.dll
2016-11-01 16:56 - 2016-10-15 04:56 - 00327680 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2016-11-01 16:56 - 2016-10-15 04:56 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\esentutl.exe
2016-11-01 16:56 - 2016-10-15 04:56 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2016-11-01 16:56 - 2016-10-15 04:56 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2016-11-01 16:56 - 2016-10-15 04:55 - 00062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2016-11-01 16:56 - 2016-10-15 04:55 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2016-11-01 16:56 - 2016-10-15 04:54 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2016-11-01 16:56 - 2016-10-15 04:54 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-11-01 16:56 - 2016-10-15 04:54 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Flights.dll
2016-11-01 16:56 - 2016-10-15 04:54 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2016-11-01 16:56 - 2016-10-15 04:52 - 00322560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2016-11-01 16:56 - 2016-10-15 04:51 - 13868544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-11-01 16:56 - 2016-10-15 04:51 - 00132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2016-11-01 16:56 - 2016-10-15 04:50 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2016-11-01 16:56 - 2016-10-15 04:50 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2016-11-01 16:56 - 2016-10-15 04:50 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-11-01 16:56 - 2016-10-15 04:49 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2016-11-01 16:56 - 2016-10-15 04:49 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2016-11-01 16:56 - 2016-10-15 04:48 - 01323008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2016-11-01 16:56 - 2016-10-15 04:48 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\iphlpsvc.dll
2016-11-01 16:56 - 2016-10-15 04:48 - 00797696 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2016-11-01 16:56 - 2016-10-15 04:48 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2016-11-01 16:56 - 2016-10-15 04:46 - 19418112 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-11-01 16:56 - 2016-10-15 04:46 - 19416576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-11-01 16:56 - 2016-10-15 04:46 - 00097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2016-11-01 16:56 - 2016-10-15 04:43 - 02748928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2016-11-01 16:56 - 2016-10-15 04:43 - 01406976 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2016-11-01 16:56 - 2016-10-15 04:43 - 00786432 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-11-01 16:56 - 2016-10-15 04:43 - 00500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2016-11-01 16:56 - 2016-10-15 04:42 - 00090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\olepro32.dll
2016-11-01 16:56 - 2016-10-15 04:42 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\powercfg.exe
2016-11-01 16:56 - 2016-10-15 04:41 - 12174848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-11-01 16:56 - 2016-10-15 04:39 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2016-11-01 16:56 - 2016-10-15 04:39 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Geolocation.dll
2016-11-01 16:56 - 2016-10-15 04:39 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-11-01 16:56 - 2016-10-15 04:38 - 00675840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.dll
2016-11-01 16:56 - 2016-10-15 04:37 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-11-01 16:56 - 2016-10-15 04:37 - 01485312 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-11-01 16:56 - 2016-10-15 04:37 - 00884224 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-11-01 16:56 - 2016-10-15 04:37 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2016-11-01 16:56 - 2016-10-15 04:37 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-11-01 16:56 - 2016-10-15 04:36 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-11-01 16:56 - 2016-10-15 04:36 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-11-01 16:56 - 2016-10-15 04:36 - 01170944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2016-11-01 16:56 - 2016-10-15 04:36 - 00542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2016-11-01 16:56 - 2016-10-15 04:36 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmifw.dll
2016-11-01 16:56 - 2016-10-15 04:35 - 02999808 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-11-01 16:56 - 2016-10-15 04:35 - 02708992 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-11-01 16:55 - 2016-10-15 06:11 - 01415520 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-11-01 16:55 - 2016-10-15 06:11 - 01026400 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-11-01 16:55 - 2016-10-15 06:11 - 00496992 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-11-01 16:55 - 2016-10-15 06:11 - 00486752 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-11-01 16:55 - 2016-10-15 06:11 - 00277344 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-11-01 16:55 - 2016-10-15 06:11 - 00224608 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-11-01 16:55 - 2016-10-15 06:11 - 00192864 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-11-01 16:55 - 2016-10-15 06:11 - 00115552 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-11-01 16:55 - 2016-10-15 06:11 - 00069472 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-11-01 16:55 - 2016-10-15 05:35 - 00890984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-11-01 16:55 - 2016-10-15 05:35 - 00784064 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-11-01 16:55 - 2016-10-15 05:33 - 00455040 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2016-11-01 16:55 - 2016-10-15 05:32 - 00601712 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2016-11-01 16:55 - 2016-10-15 05:31 - 00570720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2016-11-01 16:55 - 2016-10-15 05:27 - 00421216 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2016-11-01 16:55 - 2016-10-15 05:26 - 00055136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2016-11-01 16:55 - 2016-10-15 05:20 - 02276736 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-11-01 16:55 - 2016-10-15 05:18 - 02166232 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-11-01 16:55 - 2016-10-15 05:18 - 01556712 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2016-11-01 16:55 - 2016-10-15 05:18 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-11-01 16:55 - 2016-10-15 05:18 - 00458592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-11-01 16:55 - 2016-10-15 05:18 - 00261984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-11-01 16:55 - 2016-10-15 05:15 - 03892352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-11-01 16:55 - 2016-10-15 05:15 - 01853776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-11-01 16:55 - 2016-10-15 05:15 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2016-11-01 16:55 - 2016-10-15 05:15 - 01123368 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-11-01 16:55 - 2016-10-15 05:15 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-11-01 16:55 - 2016-10-15 05:15 - 00687936 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2016-11-01 16:55 - 2016-10-15 05:14 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-11-01 16:55 - 2016-10-15 05:10 - 01968992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2016-11-01 16:55 - 2016-10-15 05:10 - 00781664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-11-01 16:55 - 2016-10-15 05:10 - 00254656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpeffects.dll
2016-11-01 16:55 - 2016-10-15 05:06 - 05685760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-11-01 16:55 - 2016-10-15 05:00 - 00254464 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2016-11-01 16:55 - 2016-10-15 05:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\stdole2.tlb
2016-11-01 16:55 - 2016-10-15 04:59 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-11-01 16:55 - 2016-10-15 04:58 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-11-01 16:55 - 2016-10-15 04:58 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2016-11-01 16:55 - 2016-10-15 04:57 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpdxm.dll
2016-11-01 16:55 - 2016-10-15 04:57 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2016-11-01 16:55 - 2016-10-15 04:56 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2016-11-01 16:55 - 2016-10-15 04:56 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkDesktopSettings.dll
2016-11-01 16:55 - 2016-10-15 04:55 - 00254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2016-11-01 16:55 - 2016-10-15 04:55 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2016-11-01 16:55 - 2016-10-15 04:55 - 00142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2016-11-01 16:55 - 2016-10-15 04:55 - 00116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-11-01 16:55 - 2016-10-15 04:54 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-11-01 16:55 - 2016-10-15 04:54 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-11-01 16:55 - 2016-10-15 04:54 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-11-01 16:55 - 2016-10-15 04:54 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSrvPolicyManager.dll
2016-11-01 16:55 - 2016-10-15 04:54 - 00152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\autoplay.dll
2016-11-01 16:55 - 2016-10-15 04:54 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpshell.dll
2016-11-01 16:55 - 2016-10-15 04:53 - 00705024 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskbarcpl.dll
2016-11-01 16:55 - 2016-10-15 04:53 - 00549376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenterCPL.dll
2016-11-01 16:55 - 2016-10-15 04:53 - 00270336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2016-11-01 16:55 - 2016-10-15 04:53 - 00222720 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2016-11-01 16:55 - 2016-10-15 04:53 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2016-11-01 16:55 - 2016-10-15 04:52 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2016-11-01 16:55 - 2016-10-15 04:52 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2016-11-01 16:55 - 2016-10-15 04:52 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-11-01 16:55 - 2016-10-15 04:52 - 00293888 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2016-11-01 16:55 - 2016-10-15 04:52 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2016-11-01 16:55 - 2016-10-15 04:51 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2016-11-01 16:55 - 2016-10-15 04:51 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2016-11-01 16:55 - 2016-10-15 04:51 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2016-11-01 16:55 - 2016-10-15 04:51 - 00136704 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContent.dll
2016-11-01 16:55 - 2016-10-15 04:50 - 00896512 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontext.dll
2016-11-01 16:55 - 2016-10-15 04:50 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.UserAccountsHandlers.dll
2016-11-01 16:55 - 2016-10-15 04:50 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2016-11-01 16:55 - 2016-10-15 04:50 - 00310272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-11-01 16:55 - 2016-10-15 04:50 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2016-11-01 16:55 - 2016-10-15 04:49 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-11-01 16:55 - 2016-10-15 04:49 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2016-11-01 16:55 - 2016-10-15 04:49 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-11-01 16:55 - 2016-10-15 04:48 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-11-01 16:55 - 2016-10-15 04:47 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-11-01 16:55 - 2016-10-15 04:47 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-11-01 16:55 - 2016-10-15 04:47 - 01113600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2016-11-01 16:55 - 2016-10-15 04:47 - 00488448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2016-11-01 16:55 - 2016-10-15 04:46 - 01375232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2016-11-01 16:55 - 2016-10-15 04:46 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2016-11-01 16:55 - 2016-10-15 04:46 - 00336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinfo32.exe
2016-11-01 16:55 - 2016-10-15 04:44 - 03307520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-11-01 16:55 - 2016-10-15 04:44 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2016-11-01 16:55 - 2016-10-15 04:44 - 00636928 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-11-01 16:55 - 2016-10-15 04:44 - 00470016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2016-11-01 16:55 - 2016-10-15 04:44 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2016-11-01 16:55 - 2016-10-15 04:42 - 12349440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-11-01 16:55 - 2016-10-15 04:42 - 06108672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-11-01 16:55 - 2016-10-15 04:42 - 03776000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-11-01 16:55 - 2016-10-15 04:42 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2016-11-01 16:55 - 2016-10-15 04:41 - 05376000 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-11-01 16:55 - 2016-10-15 04:41 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\system32\energy.dll
2016-11-01 16:55 - 2016-10-15 04:41 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiwmi.dll
2016-11-01 16:55 - 2016-10-15 04:40 - 01135616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-11-01 16:55 - 2016-10-15 04:40 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2016-11-01 16:55 - 2016-10-15 04:39 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2016-11-01 16:55 - 2016-10-15 04:39 - 00109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\chartv.dll
2016-11-01 16:55 - 2016-10-15 04:38 - 07468032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-11-01 16:55 - 2016-10-15 04:38 - 02458112 _____ (Microsoft Corporation) C:\WINDOWS\system32\themecpl.dll
2016-11-01 16:55 - 2016-10-15 04:38 - 01993216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-11-01 16:55 - 2016-10-15 04:37 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2016-11-01 16:55 - 2016-10-15 04:37 - 01940992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-11-01 16:55 - 2016-10-15 04:37 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-11-01 16:55 - 2016-10-15 04:37 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2016-11-01 16:55 - 2016-10-15 04:37 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-11-01 16:55 - 2016-10-15 04:36 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-11-01 16:55 - 2016-10-15 04:36 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2016-11-01 16:55 - 2016-10-15 04:36 - 01880576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-11-01 16:55 - 2016-10-15 04:36 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2016-11-01 16:55 - 2016-10-15 04:36 - 01523712 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-11-01 16:55 - 2016-10-15 04:36 - 01123328 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-11-01 16:55 - 2016-10-15 04:36 - 00580608 _____ (Microsoft Corporation) C:\WINDOWS\system32\hgcpl.dll
2016-11-01 16:55 - 2016-10-15 04:36 - 00528384 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-11-01 16:55 - 2016-10-15 04:36 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2016-11-01 16:55 - 2016-10-15 04:35 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-11-01 16:55 - 2016-10-15 04:35 - 01509376 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-11-01 16:55 - 2016-10-15 04:35 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-11-01 16:55 - 2016-10-15 04:35 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-11-01 16:55 - 2016-10-15 04:35 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2016-11-01 16:55 - 2016-10-15 04:33 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2016-10-23 11:42 - 2016-10-23 11:42 - 00000000 ____D C:\Users\Petr\AppData\LocalLow\Adobe
2016-10-23 11:42 - 2016-10-23 11:42 - 00000000 ____D C:\Users\Petr\AppData\Local\CEF
2016-10-23 11:39 - 2016-11-04 17:06 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-10-23 11:39 - 2016-10-23 11:39 - 00002096 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2016-10-23 11:39 - 2016-10-23 11:39 - 00000000 ____D C:\Program Files\Common Files\Adobe
2016-10-23 11:39 - 2016-10-23 11:39 - 00000000 ____D C:\Program Files\Adobe
2016-10-23 11:37 - 2016-10-23 11:43 - 00000000 ____D C:\ProgramData\Adobe
2016-10-23 11:35 - 2016-10-23 11:42 - 00000000 ____D C:\Users\Petr\AppData\Local\Adobe
2016-10-21 16:41 - 2016-10-21 16:41 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2016-10-15 09:17 - 2016-10-15 09:17 - 00001301 _____ C:\Users\Petr\Desktop\Revo Uninstaller.lnk
2016-10-15 09:17 - 2016-10-15 09:17 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-10-12 16:37 - 2016-10-12 16:38 - 00000000 ____D C:\Program Files\SMPlayer
2016-10-12 16:37 - 2016-10-12 16:37 - 00001040 _____ C:\Users\Public\Desktop\SMPlayer.lnk
2016-10-12 16:37 - 2016-10-12 16:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SMPlayer
2016-10-12 16:22 - 2016-10-12 16:22 - 09275928 _____ C:\Users\Petr\Downloads\VF160513_100241_flv_middle (1).mp4
2016-10-12 16:14 - 2016-10-05 10:59 - 00949600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2016-10-12 16:14 - 2016-10-05 10:54 - 01097568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2016-10-12 16:14 - 2016-10-05 10:51 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-10-12 16:14 - 2016-10-05 10:49 - 01980768 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-10-12 16:14 - 2016-10-05 10:46 - 00056672 _____ (Avago Technologies) C:\WINDOWS\system32\Drivers\MegaSas2i.sys
2016-10-12 16:14 - 2016-10-05 10:28 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2016-10-12 16:14 - 2016-10-05 10:28 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.dll
2016-10-12 16:14 - 2016-10-05 10:28 - 00123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.HostName.dll
2016-10-12 16:14 - 2016-10-05 10:27 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2016-10-12 16:14 - 2016-10-05 10:26 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-10-12 16:14 - 2016-10-05 10:26 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2016-10-12 16:14 - 2016-10-05 10:25 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-10-12 16:14 - 2016-10-05 10:25 - 00404992 _____ (Microsoft Corporation) C:\WINDOWS\system32\dsreg.dll
2016-10-12 16:14 - 2016-10-05 10:25 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2016-10-12 16:14 - 2016-10-05 10:25 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-10-12 16:14 - 2016-10-05 10:25 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-10-12 16:14 - 2016-10-05 10:23 - 00373760 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2016-10-12 16:14 - 2016-10-05 10:22 - 00325632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2016-10-12 16:14 - 2016-10-05 10:21 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2016-10-12 16:14 - 2016-10-05 10:21 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-10-12 16:14 - 2016-10-05 10:20 - 00661504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-10-12 16:14 - 2016-10-05 10:20 - 00303104 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2016-10-12 16:14 - 2016-10-05 10:18 - 01283584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2016-10-12 16:14 - 2016-10-05 10:16 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-10-12 16:14 - 2016-10-05 10:14 - 01456640 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-10-12 16:14 - 2016-10-05 10:14 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-10-12 16:14 - 2016-10-05 10:11 - 06043136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-10-12 16:14 - 2016-10-05 10:10 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-10-12 16:14 - 2016-10-05 10:08 - 02356736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-10-12 16:14 - 2016-10-05 10:08 - 00598528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2016-10-12 16:14 - 2016-10-05 10:07 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-10-12 16:14 - 2016-10-05 10:07 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2016-10-12 16:14 - 2016-10-05 10:07 - 02646016 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-10-12 16:14 - 2016-10-05 10:07 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2016-10-12 16:14 - 2016-10-05 10:07 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2016-10-12 16:14 - 2016-10-05 10:06 - 01013248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Http.dll
2016-10-12 16:14 - 2016-10-05 10:05 - 03105792 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2016-10-12 16:14 - 2016-10-05 10:05 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-10-12 16:14 - 2016-09-23 04:59 - 00446124 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-10-12 16:14 - 2016-09-07 06:18 - 00290264 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2016-10-12 16:13 - 2016-10-12 16:13 - 09275928 _____ C:\Users\Petr\Downloads\VF160513_100241_flv_middle.mp4
2016-10-12 16:13 - 2016-10-05 11:10 - 00231776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-10-12 16:13 - 2016-10-05 11:05 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2016-10-12 16:13 - 2016-10-05 11:03 - 01724584 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-10-12 16:13 - 2016-10-05 10:53 - 00154976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-10-12 16:13 - 2016-10-05 10:50 - 00116576 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2016-10-12 16:13 - 2016-10-05 10:48 - 01022304 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-10-12 16:13 - 2016-10-05 10:46 - 01360456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-10-12 16:13 - 2016-10-05 10:46 - 00980824 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-10-12 16:13 - 2016-10-05 10:45 - 00198496 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2016-10-12 16:13 - 2016-10-05 10:31 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConfigureExpandedStorage.dll
2016-10-12 16:13 - 2016-10-05 10:27 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2016-10-12 16:13 - 2016-10-05 10:26 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2016-10-12 16:13 - 2016-10-05 10:25 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-10-12 16:13 - 2016-10-05 10:24 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2016-10-12 16:13 - 2016-10-05 10:24 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-10-12 16:13 - 2016-10-05 10:23 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2016-10-12 16:13 - 2016-10-05 10:23 - 00426496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2016-10-12 16:13 - 2016-10-05 10:23 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2016-10-12 16:13 - 2016-10-05 10:23 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\PrintDialogs3D.dll
2016-10-12 16:13 - 2016-10-05 10:23 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2016-10-12 16:13 - 2016-10-05 10:21 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-10-12 16:13 - 2016-10-05 10:18 - 00858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-10-12 16:13 - 2016-10-05 10:17 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2016-10-12 16:13 - 2016-10-05 10:16 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscui.dll
2016-10-12 16:13 - 2016-10-05 10:15 - 00141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialclient.dll
2016-10-12 16:13 - 2016-10-05 10:13 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2016-10-12 16:13 - 2016-10-05 10:11 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-10-12 16:13 - 2016-10-05 10:10 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2016-10-12 16:13 - 2016-10-05 10:09 - 03369984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2016-10-12 16:13 - 2016-10-05 10:09 - 01700864 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2016-10-12 16:13 - 2016-10-05 10:09 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-10-12 16:13 - 2016-10-05 10:09 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-10-12 16:13 - 2016-10-05 10:09 - 00608256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2016-10-12 16:13 - 2016-10-05 10:08 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2016-10-12 16:13 - 2016-10-05 10:06 - 00850944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-11-09 12:10 - 2016-07-16 09:19 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-11-09 12:08 - 2016-04-25 16:43 - 00000000 ____D C:\Users\Petr\AppData\Local\Google
2016-11-09 12:04 - 2016-09-23 15:07 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-11-09 11:44 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-11-07 23:10 - 2016-09-23 15:31 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-11-07 23:10 - 2016-09-23 15:06 - 00351384 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-11-07 23:09 - 2016-07-16 03:22 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2016-11-07 23:07 - 2014-05-23 20:47 - 00000000 ____D C:\AdwCleaner
2016-11-07 21:04 - 2016-04-25 21:19 - 00000000 ____D C:\Users\Petr\Desktop\k vymazání
2016-11-07 17:14 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-11-05 17:50 - 2016-07-16 09:29 - 00000000 ___HD C:\Program Files\WindowsApps
2016-11-04 18:22 - 2016-04-16 14:29 - 00000000 ____D C:\Users\Petr\AppData\Local\Packages
2016-11-04 18:10 - 2016-07-16 18:01 - 00611424 _____ C:\WINDOWS\system32\perfh005.dat
2016-11-04 18:10 - 2016-07-16 18:01 - 00132746 _____ C:\WINDOWS\system32\perfc005.dat
2016-11-04 18:10 - 2016-04-25 18:11 - 01741480 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-11-04 08:05 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\rescache
2016-11-03 20:16 - 2013-02-27 01:01 - 00000000 ____D C:\Temp
2016-11-03 20:09 - 2016-05-28 10:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2016-11-03 20:06 - 2016-05-28 10:02 - 00000000 ____D C:\ProgramData\PCDr
2016-11-03 16:39 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\Registration
2016-11-03 15:25 - 2016-09-23 15:13 - 00000000 ____D C:\Users\Petr
2016-11-02 15:46 - 2016-07-16 09:28 - 00000000 ____D C:\WINDOWS\INF
2016-11-01 18:56 - 2016-02-13 13:12 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-11-01 18:51 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-11-01 18:51 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-11-01 18:51 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-11-01 18:50 - 2016-07-16 09:29 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-11-01 18:50 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2016-11-01 18:49 - 2016-07-16 09:30 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2016-11-01 16:49 - 2016-04-25 16:44 - 00002220 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-01 16:49 - 2016-04-25 16:44 - 00002208 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-11-01 11:37 - 2016-04-30 10:40 - 00000000 ____D C:\Users\Petr\AppData\Local\ElevatedDiagnostics
2016-11-01 11:12 - 2016-04-25 17:15 - 00407720 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2016-10-25 00:30 - 2016-07-16 09:31 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerApp.exe
2016-10-25 00:30 - 2016-07-16 09:31 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\FlashPlayerCPLApp.cpl
2016-10-24 17:50 - 2016-04-16 14:30 - 00000000 ____D C:\Users\Petr\AppData\Local\VirtualStore
2016-10-24 17:12 - 2016-06-30 12:27 - 00007625 _____ C:\Users\Petr\AppData\Local\Resmon.ResmonCfg
2016-10-23 11:42 - 2016-04-16 14:30 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Adobe
2016-10-21 16:41 - 2016-07-16 09:29 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-10-21 16:41 - 2016-07-16 09:29 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-10-21 16:16 - 2016-05-28 09:46 - 00000000 ____D C:\Program Files\Microsoft Office
2016-10-19 14:49 - 2016-09-17 20:41 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2016-10-15 10:03 - 2016-06-02 20:10 - 00000000 ____D C:\Program Files\VS Revo Group
2016-10-15 10:01 - 2016-07-16 09:29 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2016-10-15 10:01 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\system32\migwiz
2016-10-15 10:01 - 2012-07-26 07:59 - 00389400 __RSH C:\bootmgr
2016-10-15 10:00 - 2016-07-16 09:29 - 00000000 ____D C:\WINDOWS\ShellExperiences
2016-10-15 10:00 - 2016-07-16 09:29 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2016-10-15 09:57 - 2016-04-25 20:42 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-10-15 09:47 - 2016-08-30 13:06 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Spy Emergency
2016-10-15 09:38 - 2016-04-25 20:42 - 141042968 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-10-15 09:34 - 2012-07-26 05:17 - 00000167 _____ C:\WINDOWS\win.ini
2016-10-15 09:20 - 2016-09-17 20:12 - 00000000 ____D C:\Users\Petr\AppData\Roaming\Philipp Winterberg

==================== Files in the root of some directories =======

2016-06-30 12:27 - 2016-10-24 17:12 - 0007625 _____ () C:\Users\Petr\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
C:\Users\Petr\AppData\Local\Temp\libeay32.dll
C:\Users\Petr\AppData\Local\Temp\msvcr120.dll
C:\Users\Petr\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-11-04 19:07

==================== End of FRST.txt ============================

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 18:10
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start
C:\Users\Petr\AppData\Local\Temp
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 19:30
od bejk62
Fix result of Farbar Recovery Scan Tool (x86) Version: 06-11-2016
Ran by Petr (09-11-2016 18:59:43) Run:1
Running from C:\Users\Petr\Desktop
Loaded Profiles: Petr (Available Profiles: Petr)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
C:\Users\Petr\AppData\Local\Temp
End
*****************


"C:\Users\Petr\AppData\Local\Temp" folder move:

Could not move "C:\Users\Petr\AppData\Local\Temp" => Scheduled to move on reboot.


Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 09-11-2016 19:24:47)

C:\Users\Petr\AppData\Local\Temp => moved successfully

==== End of Fixlog 19:24:51 ====

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 20:12
od Rudy
Smazáno. Nastala nějaká změna?

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 20:34
od bejk62
Bohužel je vše při starém.
Načítání stránek v prohlížeči pomalé, procesor je na 90 - 100%

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 20:51
od Rudy
Udělejte kompletní sken MBAM: http://www.malwarebytes.org/mbam.php a dejte log. Předem nic nemažte.

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 22:08
od bejk62
Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 9.11.2016
Čas skenování: 21:18
Protokol: MBAM.txt
Správce: Ano

Verze: 2.2.1.1043
Databáze malwaru: v2016.11.09.07
Databáze rootkitů: v2016.10.31.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 10
CPU: x86
Souborový systém: NTFS
Uživatel: Petr

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 287291
Uplynulý čas: 45 min, 56 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 5
PUP.Optional.Solvusoft, HKLM\SOFTWARE\CLASSES\APPLICATIONS\WinThrusterSetup.exe, , [56e5566851490333c11a62b1b74eb749],
PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INSTALLER\USERDATA\S-1-5-18\COMPONENTS\07B51C13962E8BF49BAFEA042FB2D4A6, , [3ffc902ec5d56dc90b731ff714f1b14f],
PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INSTALLER\USERDATA\S-1-5-18\COMPONENTS\8E64601C02B9B8A49B2094D918AAB059, , [ba81a21c68325bdb473730e616ef2ed2],
PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INSTALLER\USERDATA\S-1-5-18\COMPONENTS\A139670AC5F063A409103EC6C72644F6, , [77c44a742f6b072fa3db01154cb96d93],
PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INSTALLER\USERDATA\S-1-5-18\COMPONENTS\AF70C113ECEA42B46B60F3B0F849D237, , [122914aa673351e5c5b963b358adbc44],

Hodnoty registru: 5
PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INSTALLER\USERDATA\S-1-5-18\COMPONENTS\07B51C13962E8BF49BAFEA042FB2D4A6|00000000000000000000000000000000, C:\?Program Files\Solvusoft\Tray\SuiteClient.dll, , [3ffc902ec5d56dc90b731ff714f1b14f]
PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INSTALLER\USERDATA\S-1-5-18\COMPONENTS\8E64601C02B9B8A49B2094D918AAB059|00000000000000000000000000000000, C:\?Program Files\Solvusoft\Tray\SolvusoftTray.exe, , [ba81a21c68325bdb473730e616ef2ed2]
PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INSTALLER\USERDATA\S-1-5-18\COMPONENTS\A139670AC5F063A409103EC6C72644F6|00000000000000000000000000000000, C:\?Program Files\Solvusoft\Tray\MsgSys.exe, , [77c44a742f6b072fa3db01154cb96d93]
PUP.Optional.Solvusoft, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INSTALLER\USERDATA\S-1-5-18\COMPONENTS\AF70C113ECEA42B46B60F3B0F849D237|00000000000000000000000000000000, C:\?Program Files\Solvusoft\Tray\sfhtml.dll, , [122914aa673351e5c5b963b358adbc44]
PUP.Optional.VulnerableDellSystemDetect, HKU\S-1-5-21-1778750531-1012615130-3227783400-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|DellSystemDetect, C:\Users\Petr\AppData\Local\Apps\2.0\WBTT3JXD.NAM\RJGXWCJZ.374\dell..tion_6d0a76327dca4869_0007.0009_d84bde3ab35e468d\DellSystemDetect.exe 4zZn5oeQk9WMM5ZBt7fsYA==, , [9e9d338b1882d264848bc80e0300eb15]

Data registru: 0
(Nenalezeny žádné škodlivé položky)

Složky: 3
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod, , [e05bd8e6fe9c96a065c95061cc363ac6],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0, , [e05bd8e6fe9c96a065c95061cc363ac6],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0\_metadata, , [e05bd8e6fe9c96a065c95061cc363ac6],

Soubory: 8
PUP.Optional.Solvusoft, C:\Users\Petr\Downloads\Setup_WinThruster_2016.exe, , [7fbccaf4e4b68bab7160f122b45126da],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0\background.js, , [e05bd8e6fe9c96a065c95061cc363ac6],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0\bookmarklet.js, , [e05bd8e6fe9c96a065c95061cc363ac6],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0\icon-128.png, , [e05bd8e6fe9c96a065c95061cc363ac6],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0\icon-16.png, , [e05bd8e6fe9c96a065c95061cc363ac6],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0\icon-48.png, , [e05bd8e6fe9c96a065c95061cc363ac6],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0\manifest.json, , [e05bd8e6fe9c96a065c95061cc363ac6],
PUP.Optional.CrossRider, C:\Users\Petr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kigpmgkoelepakabiliblldhdpnidcod\0.1_0\_metadata\verified_contents.json, , [e05bd8e6fe9c96a065c95061cc363ac6],

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 22:09
od Rudy
Smažte všechny nálezy.

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 09 lis 2016 22:37
od bejk62
smazáno, proběhl restart...ale vše je při starém, stále stejný stav - je to líný a procesor se pořád honí ke 100%

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 10 lis 2016 18:30
od Rudy
Který proces CPU nejvíce zatěžuje?

Re: Napadený NB (rundas!plock) a další havěť

Napsal: 10 lis 2016 19:25
od bejk62
dnes to je až 60% u TiWorker.exe (Windows Modules Installer Worker) na střídačku s několika Chrome.exe - ty dokážou spolknout i 75% procesoru, ale je to různé - mění se to. Tohle jsou ale největší žrouti.