Pripojil jsem zbyle HDD a nejsem si jistej...
Napsal: 02 dub 2017 14:02
Kouknete na to nekdo prosim, pripojil jsem dva HDD a nevim jestli se vir zase nerozjel? Dekuju
FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by cOrnA (administrator) on UKRUTNOST-PC (02-04-2017 14:57:59)
Running from C:\Users\cOrnA\Desktop\ViR
Loaded Profiles: cOrnA (Available Profiles: cOrnA)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
() C:\UsbFix\UsbFix.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-03-22] (Apple Inc.)
HKLM-x32\...\RunOnce: [] => [X]
GroupPolicyScripts: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{C0442F51-0C83-4890-96F6-BAA0C786EB46}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{E109A109-F29E-4485-BD79-FF85CD7C8DA6}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKU\S-1-5-21-1086005725-1489657867-4169034137-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-28] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default [2017-04-02]
CHR Extension: (Prezentace Google) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-28]
CHR Extension: (Dokumenty Google) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-28]
CHR Extension: (Disk Google) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-28]
CHR Extension: (YouTube) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-28]
CHR Extension: (Tabulky Google) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-28]
CHR Extension: (Dokumenty Google offline) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-28]
CHR Extension: (Gmail) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-28]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-03-17] (Apple Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-03-24] ()
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-03-31] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-04-02] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-04-02] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2017-04-02] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-04-02] (Malwarebytes)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-02 14:29 - 2017-04-02 14:30 - 03820160 _____ (SOSVirus) C:\Users\cOrnA\Downloads\UsbFix.exe
2017-04-02 14:23 - 2017-04-02 14:23 - 00001448 _____ C:\Users\cOrnA\Desktop\UsbFix.lnk
2017-04-02 14:22 - 2017-04-02 14:22 - 03820152 _____ (SOSVirus) C:\Users\cOrnA\Downloads\UsbFix_9.039 (1).exe
2017-04-02 14:22 - 2017-04-02 14:22 - 01663904 _____ (Malwarebytes) C:\Users\cOrnA\Downloads\JRT.exe
2017-04-02 14:17 - 2017-04-02 14:17 - 03820152 _____ (SOSVirus) C:\Users\cOrnA\Downloads\UsbFix_9.039.exe
2017-04-02 00:04 - 2017-03-31 21:45 - 178264368 ____N C:\Users\cOrnA\Desktop\IMG_1285.mp4
2017-04-01 19:32 - 1970-01-01 02:00 - 180138298 ____N C:\Users\cOrnA\Desktop\IMG_1297.mp4
2017-04-01 16:16 - 2017-04-01 16:16 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2017-04-01 08:04 - 2017-04-01 09:08 - 00146660 _____ C:\Windows\ntbtlog.txt
2017-04-01 07:29 - 2017-04-01 07:29 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\MPC-HC
2017-04-01 07:27 - 2017-04-01 07:27 - 00001147 _____ C:\Users\cOrnA\Desktop\mpc-hc64.exe – zástupce.lnk
2017-04-01 07:27 - 2017-04-01 07:27 - 00000000 ____D C:\Users\cOrnA\Desktop\MPC-HC.1.7.11.x64
2017-04-01 07:26 - 2017-04-01 07:26 - 20043267 _____ C:\Users\cOrnA\Downloads\MPC-HC.1.7.11.x64.zip
2017-04-01 06:20 - 2015-02-04 05:16 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2017-04-01 06:20 - 2015-02-04 04:54 - 00318464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2017-04-01 06:20 - 2013-10-12 04:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2017-04-01 06:20 - 2013-10-12 04:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2017-04-01 06:20 - 2013-10-12 04:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2017-04-01 06:20 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2017-04-01 06:20 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2017-04-01 06:20 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-04-01 00:39 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-01 00:39 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-04-01 00:39 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-04-01 00:39 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-01 00:39 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-04-01 00:39 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-01 00:39 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-04-01 00:39 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-03-31 12:29 - 2017-03-31 12:29 - 08687765 _____ C:\Users\cOrnA\Downloads\Xperia_Go_driver.zip
2017-03-31 12:24 - 2017-03-31 12:24 - 00001296 _____ C:\Users\cOrnA\Downloads\downloadinf_v1.01.zip
2017-03-31 12:12 - 2017-03-31 12:12 - 00001202 _____ C:\Users\cOrnA\Desktop\Emma.lnk
2017-03-31 12:12 - 2017-03-31 12:12 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Mobile
2017-03-31 12:11 - 2017-03-31 12:11 - 00000000 ____D C:\ProgramData\Oracle
2017-03-31 12:11 - 2017-03-31 12:11 - 00000000 ____D C:\Program Files (x86)\Sony Mobile
2017-03-31 12:06 - 2017-03-31 12:07 - 112452184 _____ C:\Users\cOrnA\Downloads\Flash_tool_for_Xperia_9.exe
2017-03-31 12:00 - 2017-03-31 12:02 - 00000000 ____D C:\Users\cOrnA\Desktop\16Gb
2017-03-31 11:55 - 2017-03-31 11:55 - 00000000 ____D C:\ProgramData\HP
2017-03-31 11:54 - 2017-03-31 11:54 - 00002008 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2017-03-31 11:54 - 2017-03-31 11:54 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\HPPSDr
2017-03-31 11:54 - 2017-03-31 11:54 - 00000000 ____D C:\Program Files (x86)\HP
2017-03-31 11:49 - 2017-03-31 11:51 - 01557208 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-03-31 11:42 - 2017-03-31 11:42 - 00000000 ____D C:\Windows\System32\Tasks\Hewlett-Packard
2017-03-31 11:41 - 2017-03-31 11:41 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2017-03-31 11:39 - 2017-03-31 11:40 - 04057776 _____ (Oleg N. Scherbakov) C:\Users\cOrnA\Downloads\HPSupportSolutionsFramework-12.5.32.203.exe
2017-03-31 11:39 - 2017-03-31 11:39 - 10572472 _____ C:\Users\cOrnA\Downloads\HPPSdr.exe
2017-03-31 11:39 - 2017-03-31 11:39 - 01283432 _____ C:\Users\cOrnA\Downloads\dot4patch_reboot.exe
2017-03-31 11:28 - 2017-03-31 11:28 - 00031934 _____ C:\Users\cOrnA\Desktop\Diagnostika iTunes.spx
2017-03-31 11:20 - 2017-03-31 11:24 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\Apple Computer
2017-03-31 11:20 - 2017-03-31 11:20 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-03-31 11:20 - 2017-03-31 11:20 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Apple Computer
2017-03-31 11:20 - 2017-03-31 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-03-31 11:19 - 2017-03-31 11:20 - 00000000 ____D C:\Program Files\iTunes
2017-03-31 11:19 - 2017-03-31 11:19 - 00000000 ____D C:\ProgramData\Apple Computer
2017-03-31 11:19 - 2017-03-31 11:19 - 00000000 ____D C:\Program Files\iPod
2017-03-31 11:18 - 2017-03-31 11:18 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2017-03-31 11:18 - 2017-03-31 11:18 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_netaapl64_01009.Wdf
2017-03-31 11:18 - 2017-03-31 11:18 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Apple
2017-03-31 11:18 - 2017-03-31 11:18 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2017-03-31 11:17 - 2017-03-31 11:18 - 00000000 ____D C:\ProgramData\Apple
2017-03-31 11:17 - 2017-03-31 11:17 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-03-31 11:17 - 2017-03-31 11:17 - 00000000 ____D C:\Program Files\Bonjour
2017-03-31 11:17 - 2017-03-31 11:17 - 00000000 ____D C:\Program Files (x86)\Bonjour
2017-03-31 11:12 - 2017-03-31 11:15 - 257659208 _____ (Apple Inc.) C:\Users\cOrnA\Downloads\iTunes64Setup.exe
2017-03-31 10:59 - 2017-03-31 10:59 - 00000000 ____D C:\Users\cOrnA\Desktop\wpd
2017-03-31 10:19 - 2017-03-31 10:18 - 00002116 _____ C:\Users\cOrnA\ipconfig.all.txt
2017-03-31 05:58 - 2017-04-02 14:06 - 00000000 ____D C:\Users\cOrnA\Desktop\ViR
2017-03-30 05:15 - 2017-03-31 10:15 - 00000000 ____D C:\Users\cOrnA\AppData\Local\ElevatedDiagnostics
2017-03-30 03:00 - 2012-07-26 06:55 - 00785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2017-03-30 03:00 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2017-03-30 03:00 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2017-03-30 03:00 - 2012-06-02 16:35 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2017-03-29 23:20 - 2017-03-30 16:05 - 00000000 ___DC C:\Users\cOrnA\AppData\Local\MigWiz
2017-03-29 21:54 - 2017-03-29 21:54 - 00000000 ____D C:\Users\cOrnA\AppData\Local\VirtualStore
2017-03-29 21:45 - 2017-03-29 21:23 - 00024064 _____ C:\Windows\zoek-delete.exe
2017-03-29 21:23 - 2017-03-29 21:40 - 00000000 ____D C:\zoek_backup
2017-03-29 20:53 - 2017-04-02 14:47 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-03-29 20:53 - 2017-04-02 14:47 - 00082720 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-03-29 20:53 - 2017-03-31 05:56 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-03-29 20:52 - 2017-04-02 14:47 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-03-29 20:52 - 2017-04-02 14:47 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-03-29 20:52 - 2017-03-31 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-03-29 20:52 - 2017-03-29 20:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-03-29 20:52 - 2017-03-29 20:52 - 00000000 ____D C:\Program Files\Malwarebytes
2017-03-29 20:52 - 2017-03-24 04:10 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-03-29 20:48 - 2017-03-31 01:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune
2017-03-29 20:48 - 2017-03-29 20:48 - 00000000 ____D C:\Program Files (x86)\HD Tune
2017-03-29 20:40 - 2017-03-31 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2017-03-29 20:40 - 2017-03-31 01:01 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2017-03-29 20:15 - 2017-03-31 01:01 - 00000000 ____D C:\AdwCleaner
2017-03-29 20:14 - 2017-03-29 20:14 - 00000000 ____D C:\USB File Resc
2017-03-29 19:57 - 2017-04-02 14:48 - 00000000 ____D C:\UsbFix
2017-03-29 19:56 - 2017-03-29 19:56 - 03820160 _____ (SOSVirus) C:\Users\cOrnA\Desktop\UsbFix_9.038.exe
2017-03-29 19:45 - 2017-03-29 19:45 - 00000000 ____D C:\rsit
2017-03-29 19:45 - 2017-03-29 19:45 - 00000000 ____D C:\Program Files\trend micro
2017-03-29 19:23 - 2017-04-02 14:57 - 00000000 ____D C:\FRST
2017-03-29 18:24 - 2017-03-29 18:25 - 00000000 ____D C:\Users\cOrnA\Desktop\tomahawk
2017-03-29 14:23 - 2012-02-17 08:38 - 01112064 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-03-29 14:23 - 2012-02-17 08:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-03-29 14:23 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-03-29 14:23 - 2012-02-17 06:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2017-03-29 14:23 - 2012-02-17 06:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2017-03-28 21:28 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2017-03-28 21:28 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2017-03-28 21:28 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2017-03-28 21:28 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2017-03-28 21:28 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2017-03-28 21:28 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2017-03-28 21:28 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2017-03-28 21:28 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2017-03-28 15:13 - 2017-04-02 14:39 - 00000000 ____D C:\Windows\System32\Tasks\Úlohy prohlížeče událostí
2017-03-28 09:24 - 2017-03-28 09:24 - 00007605 _____ C:\Users\cOrnA\AppData\Local\Resmon.ResmonCfg
2017-03-28 07:48 - 2017-03-28 07:57 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Google
2017-03-28 07:48 - 2017-03-28 07:48 - 00002271 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-28 07:48 - 2017-03-28 07:48 - 00000000 ____D C:\Program Files (x86)\Google
2017-03-28 07:47 - 2017-03-28 07:48 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Deployment
2017-03-28 07:47 - 2017-03-28 07:47 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Apps\2.0
2017-03-28 07:46 - 2017-03-28 07:46 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2017-03-28 07:46 - 2017-03-28 07:46 - 00000000 ____D C:\Users\cOrnA\Desktop\Certifikat KB(8.3 (copy).2017)
2017-03-28 07:06 - 2017-03-28 07:06 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2017-03-28 03:17 - 2017-03-28 03:17 - 00000000 ____D C:\Users\cOrnA\AppData\Local\CEF
2017-03-28 03:16 - 2017-04-02 12:02 - 00000000 ____D C:\Users\cOrnA\AppData\Local\PokerStars.CZ
2017-03-28 03:16 - 2017-03-31 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.CZ
2017-03-28 03:16 - 2017-03-28 03:16 - 00001986 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PokerStars.cz.lnk
2017-03-28 03:16 - 2017-03-28 03:16 - 00000000 ____D C:\Program Files (x86)\PokerStars.CZ
2017-03-27 17:26 - 2017-03-27 16:32 - 00000000 ____D C:\Windows\Panther
2017-03-27 16:57 - 2017-03-31 11:43 - 00058688 _____ C:\Users\cOrnA\AppData\Local\GDIPFONTCACHEV1.DAT
2017-03-27 16:33 - 2017-03-27 16:33 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2017-03-27 16:32 - 2017-03-31 10:19 - 00000000 ____D C:\Users\cOrnA
2017-03-27 16:32 - 2017-03-27 16:32 - 00001447 _____ C:\Users\cOrnA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-03-27 16:32 - 2017-03-27 16:32 - 00001413 _____ C:\Users\cOrnA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2017-03-27 16:32 - 2017-03-27 16:32 - 00000020 ___SH C:\Users\cOrnA\ntuser.ini
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Public\Documents\Obrázky
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Public\Documents\Hudba
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Public\Documents\Filmy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Šablony
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Poslední
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Okolní síť
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Dokumenty
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Šablony
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Soubory cookie
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Poslední
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Okolní tiskárny
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Okolní síť
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Nabídka Start
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Dokumenty
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\AppData\Local\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 ____D C:\Recovery3
2017-03-27 16:32 - 2010-11-21 11:38 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\Media Center Programs
2017-03-27 16:28 - 2017-03-27 16:28 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2017-03-27 16:28 - 2017-03-27 16:28 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2017-03-27 16:27 - 2017-03-27 16:27 - 00000000 _____ C:\Windows\system32\atiicdxx.dat
2017-03-27 16:27 - 2017-03-27 16:27 - 00000000 _____ C:\Windows\ativpsrm.bin
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-02 14:54 - 2010-11-21 11:27 - 00668138 _____ C:\Windows\system32\perfh005.dat
2017-04-02 14:54 - 2010-11-21 11:27 - 00140798 _____ C:\Windows\system32\perfc005.dat
2017-04-02 14:54 - 2009-07-14 07:13 - 01582262 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-02 14:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-04-02 14:46 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-02 13:11 - 2009-07-14 06:45 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-02 13:11 - 2009-07-14 06:45 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-01 09:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2017-03-31 11:42 - 2009-07-14 06:45 - 00271408 _____ C:\Windows\system32\FNTCACHE.DAT
2017-03-31 11:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2017-03-31 01:02 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\addins
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2017-03-31 01:01 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-03-31 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Setup
2017-03-31 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\security
2017-03-31 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2017-03-28 11:25 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-03-28 03:03 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2017-03-28 01:13 - 2010-11-21 11:38 - 00000000 ___RD C:\Users\Public\Recorded TV
2017-03-28 01:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2017-03-27 17:26 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2017-03-27 16:32 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT
2017-03-27 16:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2017-03-27 16:27 - 2010-11-21 11:38 - 00000000 ____D C:\Windows\CSC
==================== Files in the root of some directories =======
2017-03-28 09:24 - 2017-03-28 09:24 - 0007605 _____ () C:\Users\cOrnA\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-27 17:43
==================== End of FRST.txt ============================
FRST
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by cOrnA (administrator) on UKRUTNOST-PC (02-04-2017 14:57:59)
Running from C:\Users\cOrnA\Desktop\ViR
Loaded Profiles: cOrnA (Available Profiles: cOrnA)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
() C:\UsbFix\UsbFix.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-03-22] (Apple Inc.)
HKLM-x32\...\RunOnce: [] => [X]
GroupPolicyScripts: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{C0442F51-0C83-4890-96F6-BAA0C786EB46}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{E109A109-F29E-4485-BD79-FF85CD7C8DA6}: [DhcpNameServer] 192.168.42.129
Internet Explorer:
==================
HKU\S-1-5-21-1086005725-1489657867-4169034137-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
FireFox:
========
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2017-03-28] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default [2017-04-02]
CHR Extension: (Prezentace Google) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-03-28]
CHR Extension: (Dokumenty Google) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-03-28]
CHR Extension: (Disk Google) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-03-28]
CHR Extension: (YouTube) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-03-28]
CHR Extension: (Tabulky Google) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-03-28]
CHR Extension: (Dokumenty Google offline) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-03-28]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-28]
CHR Extension: (Gmail) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\cOrnA\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-03-28]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-03-17] (Apple Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-03-24] ()
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [186304 2017-03-31] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-04-02] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-04-02] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2017-04-02] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [82720 2017-04-02] (Malwarebytes)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [8192 2005-03-29] ()
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-02 14:29 - 2017-04-02 14:30 - 03820160 _____ (SOSVirus) C:\Users\cOrnA\Downloads\UsbFix.exe
2017-04-02 14:23 - 2017-04-02 14:23 - 00001448 _____ C:\Users\cOrnA\Desktop\UsbFix.lnk
2017-04-02 14:22 - 2017-04-02 14:22 - 03820152 _____ (SOSVirus) C:\Users\cOrnA\Downloads\UsbFix_9.039 (1).exe
2017-04-02 14:22 - 2017-04-02 14:22 - 01663904 _____ (Malwarebytes) C:\Users\cOrnA\Downloads\JRT.exe
2017-04-02 14:17 - 2017-04-02 14:17 - 03820152 _____ (SOSVirus) C:\Users\cOrnA\Downloads\UsbFix_9.039.exe
2017-04-02 00:04 - 2017-03-31 21:45 - 178264368 ____N C:\Users\cOrnA\Desktop\IMG_1285.mp4
2017-04-01 19:32 - 1970-01-01 02:00 - 180138298 ____N C:\Users\cOrnA\Desktop\IMG_1297.mp4
2017-04-01 16:16 - 2017-04-01 16:16 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2017-04-01 08:04 - 2017-04-01 09:08 - 00146660 _____ C:\Windows\ntbtlog.txt
2017-04-01 07:29 - 2017-04-01 07:29 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\MPC-HC
2017-04-01 07:27 - 2017-04-01 07:27 - 00001147 _____ C:\Users\cOrnA\Desktop\mpc-hc64.exe – zástupce.lnk
2017-04-01 07:27 - 2017-04-01 07:27 - 00000000 ____D C:\Users\cOrnA\Desktop\MPC-HC.1.7.11.x64
2017-04-01 07:26 - 2017-04-01 07:26 - 20043267 _____ C:\Users\cOrnA\Downloads\MPC-HC.1.7.11.x64.zip
2017-04-01 06:20 - 2015-02-04 05:16 - 00392192 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2017-04-01 06:20 - 2015-02-04 04:54 - 00318464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2017-04-01 06:20 - 2013-10-12 04:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2017-04-01 06:20 - 2013-10-12 04:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2017-04-01 06:20 - 2013-10-12 04:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2017-04-01 06:20 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2017-04-01 06:20 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2017-04-01 06:20 - 2013-08-28 03:12 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-04-01 00:39 - 2014-05-14 18:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-04-01 00:39 - 2014-05-14 18:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-01 00:39 - 2014-05-14 18:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-04-01 00:39 - 2014-05-14 18:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-04-01 00:39 - 2014-05-14 18:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-01 00:39 - 2014-05-14 09:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-04-01 00:39 - 2014-05-14 09:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-01 00:39 - 2014-05-14 09:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-04-01 00:39 - 2014-05-14 09:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-03-31 12:29 - 2017-03-31 12:29 - 08687765 _____ C:\Users\cOrnA\Downloads\Xperia_Go_driver.zip
2017-03-31 12:24 - 2017-03-31 12:24 - 00001296 _____ C:\Users\cOrnA\Downloads\downloadinf_v1.01.zip
2017-03-31 12:12 - 2017-03-31 12:12 - 00001202 _____ C:\Users\cOrnA\Desktop\Emma.lnk
2017-03-31 12:12 - 2017-03-31 12:12 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sony Mobile
2017-03-31 12:11 - 2017-03-31 12:11 - 00000000 ____D C:\ProgramData\Oracle
2017-03-31 12:11 - 2017-03-31 12:11 - 00000000 ____D C:\Program Files (x86)\Sony Mobile
2017-03-31 12:06 - 2017-03-31 12:07 - 112452184 _____ C:\Users\cOrnA\Downloads\Flash_tool_for_Xperia_9.exe
2017-03-31 12:00 - 2017-03-31 12:02 - 00000000 ____D C:\Users\cOrnA\Desktop\16Gb
2017-03-31 11:55 - 2017-03-31 11:55 - 00000000 ____D C:\ProgramData\HP
2017-03-31 11:54 - 2017-03-31 11:54 - 00002008 _____ C:\Users\Public\Desktop\HP Print and Scan Doctor.lnk
2017-03-31 11:54 - 2017-03-31 11:54 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\HPPSDr
2017-03-31 11:54 - 2017-03-31 11:54 - 00000000 ____D C:\Program Files (x86)\HP
2017-03-31 11:49 - 2017-03-31 11:51 - 01557208 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-03-31 11:42 - 2017-03-31 11:42 - 00000000 ____D C:\Windows\System32\Tasks\Hewlett-Packard
2017-03-31 11:41 - 2017-03-31 11:41 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2017-03-31 11:39 - 2017-03-31 11:40 - 04057776 _____ (Oleg N. Scherbakov) C:\Users\cOrnA\Downloads\HPSupportSolutionsFramework-12.5.32.203.exe
2017-03-31 11:39 - 2017-03-31 11:39 - 10572472 _____ C:\Users\cOrnA\Downloads\HPPSdr.exe
2017-03-31 11:39 - 2017-03-31 11:39 - 01283432 _____ C:\Users\cOrnA\Downloads\dot4patch_reboot.exe
2017-03-31 11:28 - 2017-03-31 11:28 - 00031934 _____ C:\Users\cOrnA\Desktop\Diagnostika iTunes.spx
2017-03-31 11:20 - 2017-03-31 11:24 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\Apple Computer
2017-03-31 11:20 - 2017-03-31 11:20 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-03-31 11:20 - 2017-03-31 11:20 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Apple Computer
2017-03-31 11:20 - 2017-03-31 11:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-03-31 11:19 - 2017-03-31 11:20 - 00000000 ____D C:\Program Files\iTunes
2017-03-31 11:19 - 2017-03-31 11:19 - 00000000 ____D C:\ProgramData\Apple Computer
2017-03-31 11:19 - 2017-03-31 11:19 - 00000000 ____D C:\Program Files\iPod
2017-03-31 11:18 - 2017-03-31 11:18 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2017-03-31 11:18 - 2017-03-31 11:18 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_netaapl64_01009.Wdf
2017-03-31 11:18 - 2017-03-31 11:18 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Apple
2017-03-31 11:18 - 2017-03-31 11:18 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2017-03-31 11:17 - 2017-03-31 11:18 - 00000000 ____D C:\ProgramData\Apple
2017-03-31 11:17 - 2017-03-31 11:17 - 00000000 ____D C:\Program Files\Common Files\Apple
2017-03-31 11:17 - 2017-03-31 11:17 - 00000000 ____D C:\Program Files\Bonjour
2017-03-31 11:17 - 2017-03-31 11:17 - 00000000 ____D C:\Program Files (x86)\Bonjour
2017-03-31 11:12 - 2017-03-31 11:15 - 257659208 _____ (Apple Inc.) C:\Users\cOrnA\Downloads\iTunes64Setup.exe
2017-03-31 10:59 - 2017-03-31 10:59 - 00000000 ____D C:\Users\cOrnA\Desktop\wpd
2017-03-31 10:19 - 2017-03-31 10:18 - 00002116 _____ C:\Users\cOrnA\ipconfig.all.txt
2017-03-31 05:58 - 2017-04-02 14:06 - 00000000 ____D C:\Users\cOrnA\Desktop\ViR
2017-03-30 05:15 - 2017-03-31 10:15 - 00000000 ____D C:\Users\cOrnA\AppData\Local\ElevatedDiagnostics
2017-03-30 03:00 - 2012-07-26 06:55 - 00785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2017-03-30 03:00 - 2012-07-26 06:55 - 00054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2017-03-30 03:00 - 2012-07-26 04:36 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2017-03-30 03:00 - 2012-06-02 16:35 - 00000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2017-03-29 23:20 - 2017-03-30 16:05 - 00000000 ___DC C:\Users\cOrnA\AppData\Local\MigWiz
2017-03-29 21:54 - 2017-03-29 21:54 - 00000000 ____D C:\Users\cOrnA\AppData\Local\VirtualStore
2017-03-29 21:45 - 2017-03-29 21:23 - 00024064 _____ C:\Windows\zoek-delete.exe
2017-03-29 21:23 - 2017-03-29 21:40 - 00000000 ____D C:\zoek_backup
2017-03-29 20:53 - 2017-04-02 14:47 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-03-29 20:53 - 2017-04-02 14:47 - 00082720 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-03-29 20:53 - 2017-03-31 05:56 - 00186304 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-03-29 20:52 - 2017-04-02 14:47 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-03-29 20:52 - 2017-04-02 14:47 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-03-29 20:52 - 2017-03-31 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-03-29 20:52 - 2017-03-29 20:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-03-29 20:52 - 2017-03-29 20:52 - 00000000 ____D C:\Program Files\Malwarebytes
2017-03-29 20:52 - 2017-03-24 04:10 - 00077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-03-29 20:48 - 2017-03-31 01:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune
2017-03-29 20:48 - 2017-03-29 20:48 - 00000000 ____D C:\Program Files (x86)\HD Tune
2017-03-29 20:40 - 2017-03-31 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2017-03-29 20:40 - 2017-03-31 01:01 - 00000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2017-03-29 20:15 - 2017-03-31 01:01 - 00000000 ____D C:\AdwCleaner
2017-03-29 20:14 - 2017-03-29 20:14 - 00000000 ____D C:\USB File Resc
2017-03-29 19:57 - 2017-04-02 14:48 - 00000000 ____D C:\UsbFix
2017-03-29 19:56 - 2017-03-29 19:56 - 03820160 _____ (SOSVirus) C:\Users\cOrnA\Desktop\UsbFix_9.038.exe
2017-03-29 19:45 - 2017-03-29 19:45 - 00000000 ____D C:\rsit
2017-03-29 19:45 - 2017-03-29 19:45 - 00000000 ____D C:\Program Files\trend micro
2017-03-29 19:23 - 2017-04-02 14:57 - 00000000 ____D C:\FRST
2017-03-29 18:24 - 2017-03-29 18:25 - 00000000 ____D C:\Users\cOrnA\Desktop\tomahawk
2017-03-29 14:23 - 2012-02-17 08:38 - 01112064 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-03-29 14:23 - 2012-02-17 08:38 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-03-29 14:23 - 2012-02-17 07:34 - 00826880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-03-29 14:23 - 2012-02-17 06:58 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2017-03-29 14:23 - 2012-02-17 06:57 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdtcp.sys
2017-03-28 21:28 - 2014-07-01 00:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\system32\icardres.dll
2017-03-28 21:28 - 2014-07-01 00:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2017-03-28 21:28 - 2014-06-06 08:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2017-03-28 21:28 - 2014-06-06 08:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2017-03-28 21:28 - 2014-03-09 23:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\system32\icardagt.exe
2017-03-28 21:28 - 2014-03-09 23:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\system32\infocardapi.dll
2017-03-28 21:28 - 2014-03-09 23:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2017-03-28 21:28 - 2014-03-09 23:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2017-03-28 15:13 - 2017-04-02 14:39 - 00000000 ____D C:\Windows\System32\Tasks\Úlohy prohlížeče událostí
2017-03-28 09:24 - 2017-03-28 09:24 - 00007605 _____ C:\Users\cOrnA\AppData\Local\Resmon.ResmonCfg
2017-03-28 07:48 - 2017-03-28 07:57 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Google
2017-03-28 07:48 - 2017-03-28 07:48 - 00002271 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-03-28 07:48 - 2017-03-28 07:48 - 00000000 ____D C:\Program Files (x86)\Google
2017-03-28 07:47 - 2017-03-28 07:48 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Deployment
2017-03-28 07:47 - 2017-03-28 07:47 - 00000000 ____D C:\Users\cOrnA\AppData\Local\Apps\2.0
2017-03-28 07:46 - 2017-03-28 07:46 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2017-03-28 07:46 - 2017-03-28 07:46 - 00000000 ____D C:\Users\cOrnA\Desktop\Certifikat KB(8.3 (copy).2017)
2017-03-28 07:06 - 2017-03-28 07:06 - 00000374 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2017-03-28 03:17 - 2017-03-28 03:17 - 00000000 ____D C:\Users\cOrnA\AppData\Local\CEF
2017-03-28 03:16 - 2017-04-02 12:02 - 00000000 ____D C:\Users\cOrnA\AppData\Local\PokerStars.CZ
2017-03-28 03:16 - 2017-03-31 01:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PokerStars.CZ
2017-03-28 03:16 - 2017-03-28 03:16 - 00001986 _____ C:\ProgramData\Microsoft\Windows\Start Menu\PokerStars.cz.lnk
2017-03-28 03:16 - 2017-03-28 03:16 - 00000000 ____D C:\Program Files (x86)\PokerStars.CZ
2017-03-27 17:26 - 2017-03-27 16:32 - 00000000 ____D C:\Windows\Panther
2017-03-27 16:57 - 2017-03-31 11:43 - 00058688 _____ C:\Users\cOrnA\AppData\Local\GDIPFONTCACHEV1.DAT
2017-03-27 16:33 - 2017-03-27 16:33 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2017-03-27 16:32 - 2017-03-31 10:19 - 00000000 ____D C:\Users\cOrnA
2017-03-27 16:32 - 2017-03-27 16:32 - 00001447 _____ C:\Users\cOrnA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-03-27 16:32 - 2017-03-27 16:32 - 00001413 _____ C:\Users\cOrnA\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
2017-03-27 16:32 - 2017-03-27 16:32 - 00000020 ___SH C:\Users\cOrnA\ntuser.ini
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Public\Documents\Obrázky
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Public\Documents\Hudba
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Public\Documents\Filmy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Šablony
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Poslední
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Okolní síť
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Dokumenty
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Šablony
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Soubory cookie
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Poslední
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Okolní tiskárny
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Okolní síť
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Nabídka Start
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Dokumenty
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 _SHDL C:\Users\cOrnA\AppData\Local\Data aplikací
2017-03-27 16:32 - 2017-03-27 16:32 - 00000000 ____D C:\Recovery3
2017-03-27 16:32 - 2010-11-21 11:38 - 00000000 ____D C:\Users\cOrnA\AppData\Roaming\Media Center Programs
2017-03-27 16:28 - 2017-03-27 16:28 - 00001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2017-03-27 16:28 - 2017-03-27 16:28 - 00001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2017-03-27 16:27 - 2017-03-27 16:27 - 00000000 _____ C:\Windows\system32\atiicdxx.dat
2017-03-27 16:27 - 2017-03-27 16:27 - 00000000 _____ C:\Windows\ativpsrm.bin
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-04-02 14:54 - 2010-11-21 11:27 - 00668138 _____ C:\Windows\system32\perfh005.dat
2017-04-02 14:54 - 2010-11-21 11:27 - 00140798 _____ C:\Windows\system32\perfc005.dat
2017-04-02 14:54 - 2009-07-14 07:13 - 01582262 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-02 14:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf
2017-04-02 14:46 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-02 13:11 - 2009-07-14 06:45 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-02 13:11 - 2009-07-14 06:45 - 00016832 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-01 09:42 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2017-03-31 11:42 - 2009-07-14 06:45 - 00271408 _____ C:\Windows\system32\FNTCACHE.DAT
2017-03-31 11:29 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2017-03-31 01:02 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\Downloaded Program Files
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\addins
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Microsoft Games
2017-03-31 01:01 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Sidebar
2017-03-31 01:01 - 2009-07-14 05:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-03-31 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\Setup
2017-03-31 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\security
2017-03-31 01:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2017-03-28 11:25 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-03-28 03:03 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2017-03-28 01:13 - 2010-11-21 11:38 - 00000000 ___RD C:\Users\Public\Recorded TV
2017-03-28 01:13 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2017-03-27 17:26 - 2009-07-14 07:32 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2017-03-27 16:32 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT
2017-03-27 16:28 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\sysprep
2017-03-27 16:27 - 2010-11-21 11:38 - 00000000 ____D C:\Windows\CSC
==================== Files in the root of some directories =======
2017-03-28 09:24 - 2017-03-28 09:24 - 0007605 _____ () C:\Users\cOrnA\AppData\Local\Resmon.ResmonCfg
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-27 17:43
==================== End of FRST.txt ============================
