Stránka 1 z 1

reklamy,přesměrování na nevyžádané stránky

Napsal: 30 říj 2017 15:18
od ebola
-prosim o kontrolu logu děkuji log-
Logfile of random's system information tool 1.10 (written by random/random)
Run by jemin at 2017-10-30 15:15:48
Microsoft Windows 7 Ultimate Service Pack 1
System drive C: has 14 GB (8%) free of 172 GB
Total RAM: 8079 MB (57% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15:15:48, on 30.10.2017
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18817)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe
C:\Fraps\fraps.exe
C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter\SpyHunter4.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\jemin\AppData\Local\Mail.Ru\MailRuUpdater.exe
C:\Users\jemin\AppData\Roaming\MediaPlayerApplication\MediaPlayerApplication.exe
C:\Users\jemin\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe
C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe
C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe
C:\Program Files (x86)\Noční obloha\vesmir.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe
C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe
C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Disk\WebService.exe
C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
C:\Disk\WEBSER~1.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
C:\Program Files (x86)\ZfJRwqLPhIE\landhTGixw.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe
C:\Program Files\trend micro\jemin.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://time-to-read.ru/?

utm_source=uoua03n&utm_content=e739009bccd5f1e6d71a91bff5994529&utm_term=256F29F2108A5A51F6A9F0E8D3607E4C&utm_d=20171030
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: True Key Helper - {0F4B8786-5502-4803-8EBC-F652A1153BB6} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: MRSearchPlugin - {8E8F97CD-60B5-456F-A201-73065652D099} - C:\Users\jemin\AppData\Local\Mail.Ru\Sputnik\ie_addon_dll.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: McAfee WebAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: YoutubeAdBlock - {C0D38E5A-7CF8-4105-8FE8-31B81443A114} - C:\Program Files (x86)\ZfJRwqLPhIE\k7zVdU1Vp.dll
O2 - BHO: cenbho32.TCentrumCZBHOObject - {C91BA35D-6516-489F-A203-2992ED9A4132} - C:\Program Files (x86)\Centrum Holdings s.r.o\Lišta Centrum.cz\cenbho32.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll (file missing)
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [ProductUpdater] C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
O4 - HKCU\..\Run: [Svátky a výročí] C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe
O4 - HKCU\..\Run: [HP Deskjet 3520 series (NET)] "C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN42H2G0CM05SZ:NW" -scfn "HP Deskjet 3520 series (NET)"

-AutoStart 1
O4 - HKCU\..\Run: [jemin] explorer.exe http://kb-ribaki.org
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [MailRuUpdater] C:\Users\jemin\AppData\Local\Mail.Ru\MailRuUpdater.exe
O4 - HKCU\..\Run: [MediaPlayerApplication] "C:\Users\jemin\AppData\Roaming\MediaPlayerApplication\MediaPlayerApplication.exe"
O4 - HKCU\..\Run: [ttkutpvogu] explorer "http://granena.ru/?

utm_source=uoua03n&utm_content=e739009bccd5f1e6d71a91bff5994529&utm_term=256F29F2108A5A51F6A9F0E8D3607E4C&utm_d=20171030"
O4 - HKCU\..\Run: [KometaLaunchPanel] C:\Users\jemin\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe
O4 - HKCU\..\Run: [ycAutoLaunch_8BD45C324E1801E78C906E73D35C9CF9] "C:\Users\jemin\AppData\Local\yc\Application\yc.exe" /prefetch:5
O4 - HKCU\..\Run: [KometaAutoLaunch_99329504B9DDFAA4DB3EFCC619BA3175] "C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe" --no-startup-window
O4 - Startup: Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk = ?
O4 - Startup: Vesmír na dlani.lnk = ?
O4 - Global Startup: GamePark klient 2.lnk = C:\Program Files\GamePark2\gpcl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files (x86)\Hewlett-Packard\Smart Print 2.0\smartprintsetup.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O9 - Extra 'Tools' menuitem: McAfee WebAdvisor - {48A61126-9A19-4C50-A214-FF08CB94995C} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~3\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ABBYY FineReader 10 HE Licensing Service (ABBYY.Licensing.FineReader.Home.10.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\Home

\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AppleChargerSrv - Unknown owner - C:\Windows\system32\AppleChargerSrv.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Freemake Improver - Freemake - C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
O23 - Service: Futuremark SystemInfo Service - Futuremark Corporation - C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: Mail.Ru Update Service (mrupdsrv) - Mail.Ru - C:\Program Files (x86)\Mail.Ru\Update Service\mrupdsrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Unknown owner - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: PAExec - Power Admin LLC - C:\Windows\PAExec.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: SlimWare Utility Service Launcher (SlimService) - Unknown owner - C:\Program Files\SlimService\SlimServiceFactory.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SInstalátor (ssinstall) - PS Media s.r.o. - C:\Windows\SysWOW64\ssins.exe
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SvcHost Service Host - Unknown owner - C:\Windows\Microsoft\svchost.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Updater.Mail.Ru - Mail.Ru - C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 14862 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3

ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3

ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:

\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Program Files\Microsoft Security Client\MsMpEng.exe"
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation

\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"taskhost.exe"
"C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\Home\NetworkLicenseServer.exe" -service
taskeng.exe {F792665E-3B10-4AF6-9A0E-C795239A6279}
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\Windows\System32\svchost.exe -k utcsvc
"C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe"
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe"
"C:\Program Files (x86)\Mail.Ru\Update Service\mrupdsrv.exe" --s
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation

\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA

Corporation\NvTelemetry\plugins" -r
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\PnkBstrB.exe
C:\Windows\SysWOW64\ssins.exe
"C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe" --s
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%dSPUser.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins

\SPUser" -r -l 3 -p 30000 -c
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3

-p 30000 -st "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
taskeng.exe {99EFF703-24F4-4C95-BA10-E0DB404DCDEC}
"C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe" -boot
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
C:\Fraps\fraps.exe
"C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter\SpyHunter4.exe"
"C:\Program Files\Microsoft Security Client\NisSrv.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe" -userServiceMode
igfxEM.exe
"C:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN42H2G0CM05SZ:NW" -scfn "HP Deskjet 3520 series (NET)" -AutoStart 1
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe"
"C:\Program Files (x86)\Steam\Steam.exe" -silent
"C:\Users\jemin\AppData\Local\Mail.Ru\MailRuUpdater.exe"
"C:\Users\jemin\AppData\Roaming\MediaPlayerApplication\MediaPlayerApplication.exe"
"C:\Users\jemin\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe"
"C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe" --no-startup-window /prefetch:5
C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe --type=crashpad-handler --no-rate-limit "--database=C:\Users\jemin\AppData\Local\Chromium\User Data\Crashpad" --

annotation=channel=unknown --annotation=plat=Win32 --annotation=prod=Kometa --annotation=ver=52.0.2743.82-devel --handshake-handle=0xbc
"C:\Windows\system32\RunDll32.exe" "C:\Program Files\HP\HP Deskjet 3520 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN42H2G0CM05SZ;CONNECTION=NW;MONITOR=1;
"C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe"
"C:\Program Files (x86)\Noční obloha\vesmir.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe"
"C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe" --type=gpu-process --channel="4092.0.1178314280\628069049" --mojo-application-channel-token=334F24BFCB2F3DC794CEA9DA8295C786

--enable-

features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingDisableUpload<SafeBrowsingIncidentReportingService,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingSer

viceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,MainFrameBeforeActivation<MainFrameBeforeActivation,NetworkTimeServiceQuerying<NetworkTi

meQueries,PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow,WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,WebRTC-

H264WithOpenH264FFmpeg<WebRTC-H264WithOpenH264FFmpeg,token-binding<TokenBinding,use-new-media-cache<use-new-media-cache --disable-

features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame --force-

fieldtrials=AutofillClassifier/Enabled/AutofillFieldMetadata/Enabled/AutofillProfileOrderByFrecency/EnabledLimitTo3/AutomaticTabDiscarding/Enabled_Once_10-

gen2/BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Enabled/ChromotingQUIC/Enabled/DefaultBrowserInfobar/SettingsText/DisallowFetchForD

ocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup/EnableGoogleCachedCopyTextExperiment/Button/EnableMediaRouter/Enabled/EnableMediaRouterWithCastExtension/Enabled/EnableSessionC

rashedBubbleUI/Enabled/ExtensionActionRedesign/Enabled/ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleBrandedContextMenu/branded/GoogleNow/Enable/IconNTP/Default

/InstanceID/Enabled/IntelligentSessionRestore/Enabled/LocalNTPSuggestionsService/Enabled/MainFrameBeforeActivation/Enabled/MaterialDesignDownloads/Enabled/MojoChannel/Enabled/*NetworkQualityE

stimator/Enabled/NetworkTimeQueries/NetworkTimeQueriesEnabled/NewProfileManagement/Enabled/OfferUploadCreditCards/Enabled/OutOfProcessPac/Enabled/PageRevisitInstrumentation/Enabled/Passw

ordBranding/SmartLockBrandingSavePromptOnly/PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PreRead/NoPrefetchArgument2/Preconn

ectMore/Enabled/*QUIC/Enabled/RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/ResourcePriorities/Launch50pct_11011_1_1_10/SRTPromptFieldTrial/On/SSLCommonName

MismatchHandling/Enabled/SafeBrowsingIncidentReportingService/Enabled/SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingReportPhishingErrorLink/Enabled/Sa

feBrowsingUpdateFrequency/UpdateTime15m/SafeBrowsingV4LocalDatabaseManagerEnabled/Enabled/SchedulerExpensiveTaskBlocking/Enabled/SdchPersistence/Enabled/SettingsEnforcement/enforce_alw

ays_with_extensions_and_dse/StrictSecureCookies/Enabled/SyncHttpContentCompression/Enabled/TabSyncByRecency/Enabled/*TokenBinding/TokenBinding/TriggeredResetFieldTrial/On/*UMA_CheckStates/

Checks/V8CacheStrategiesForCacheStorage/none/VarationsServiceControl/Interval_30min/WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Enabled/WebRTC-

H264WithOpenH264FFmpeg/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/use-new-media-cache/Enabled/ --disable-direct-composition --supports-dual-

gpus=false --gpu-driver-bug-workarounds=4,12,13,27,55,71 --gpu-vendor-id=0x10de --gpu-device-id=0x1184 --gpu-driver-vendor=NVIDIA --gpu-driver-version=23.21.13.8800 --gpu-driver-date=10-12-2017 --

gpu-secondary-vendor-ids=0x8086 --gpu-secondary-device-ids=0x0412 --mojo-platform-channel-handle=1072 --ignored=" --type=renderer "
"C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe" -Embedding
"C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe" --type=renderer --enable-

features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingDisableUpload<SafeBrowsingIncidentReportingService,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingSer

viceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,MainFrameBeforeActivation<MainFrameBeforeActivation,NetworkTimeServiceQuerying<NetworkTi

meQueries,PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow,WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,WebRTC-

H264WithOpenH264FFmpeg<WebRTC-H264WithOpenH264FFmpeg,token-binding<TokenBinding,use-new-media-cache<use-new-media-cache --disable-

features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame --force-

fieldtrials=AutofillClassifier/Enabled/AutofillFieldMetadata/Enabled/AutofillProfileOrderByFrecency/EnabledLimitTo3/*AutomaticTabDiscarding/Enabled_Once_10-

gen2/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Enabled/ChromotingQUIC/Enabled/DefaultBrowserInfobar/SettingsText/*DisallowFetchFor

DocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup/EnableGoogleCachedCopyTextExperiment/Button/*EnableMediaRouter/Enabled/EnableMediaRouterWithCastExtension/Enabled/EnableSessio

nCrashedBubbleUI/Enabled/ExtensionActionRedesign/Enabled/*ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleBrandedContextMenu/branded/GoogleNow/Enable/IconNTP/Def

ault/InstanceID/Enabled/IntelligentSessionRestore/Enabled/*LocalNTPSuggestionsService/Enabled/*MainFrameBeforeActivation/Enabled/MaterialDesignDownloads/Enabled/MojoChannel/Enabled/*NetworkQu

alityEstimator/Enabled/NetworkTimeQueries/NetworkTimeQueriesEnabled/*NewProfileManagement/Enabled/OfferUploadCreditCards/Enabled/OutOfProcessPac/Enabled/*PageRevisitInstrumentation/Enabled

/PasswordBranding/SmartLockBrandingSavePromptOnly/PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PreRead/NoPrefetchArgument2/

PreconnectMore/Enabled/*QUIC/Enabled/RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SRTPromptFieldTrial/On/SSLComm

onNameMismatchHandling/Enabled/*SafeBrowsingIncidentReportingService/Enabled/SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingReportPhishingErrorLink/En

abled/SafeBrowsingUpdateFrequency/UpdateTime15m/SafeBrowsingV4LocalDatabaseManagerEnabled/Enabled/SchedulerExpensiveTaskBlocking/Enabled/SdchPersistence/Enabled/*SettingsEnforcement/en

force_always_with_extensions_and_dse/StrictSecureCookies/Enabled/SyncHttpContentCompression/Enabled/TabSyncByRecency/Enabled/*TokenBinding/TokenBinding/*TriggeredResetFieldTrial/On/*UMA_Ch

eckStates/Checks/V8CacheStrategiesForCacheStorage/none/VarationsServiceControl/Interval_30min/WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Enabled/WebRTC-

H264WithOpenH264FFmpeg/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/use-new-media-cache/Enabled/ --primordial-pipe-

token=77BE1E29B0DC69B9B04CACA047788EBA --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-

settings=disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-

factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-

texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=E5CC7BB8128EE7FD2958CF7493CB19FA --mojo-application-channel-

token=A1F57F64C9FEF13301CB2D81A05B300E --channel="4092.2.1566782575\18009519" --mojo-platform-channel-handle=1824
"C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe" --type=renderer --enable-

features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingDisableUpload<SafeBrowsingIncidentReportingService,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingSer

viceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,MainFrameBeforeActivation<MainFrameBeforeActivation,NetworkTimeServiceQuerying<NetworkTi

meQueries,PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow,WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,WebRTC-

H264WithOpenH264FFmpeg<WebRTC-H264WithOpenH264FFmpeg,token-binding<TokenBinding,use-new-media-cache<use-new-media-cache --disable-

features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame --force-

fieldtrials=AutofillClassifier/Enabled/AutofillFieldMetadata/Enabled/AutofillProfileOrderByFrecency/EnabledLimitTo3/*AutomaticTabDiscarding/Enabled_Once_10-

gen2/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Enabled/ChromotingQUIC/Enabled/DefaultBrowserInfobar/SettingsText/*DisallowFetchFor

DocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup/EnableGoogleCachedCopyTextExperiment/Button/*EnableMediaRouter/Enabled/EnableMediaRouterWithCastExtension/Enabled/EnableSessio

nCrashedBubbleUI/Enabled/ExtensionActionRedesign/Enabled/*ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleBrandedContextMenu/branded/GoogleNow/Enable/IconNTP/Def

ault/InstanceID/Enabled/IntelligentSessionRestore/Enabled/*LocalNTPSuggestionsService/Enabled/*MainFrameBeforeActivation/Enabled/MaterialDesignDownloads/Enabled/MojoChannel/Enabled/*NetworkQu

alityEstimator/Enabled/NetworkTimeQueries/NetworkTimeQueriesEnabled/*NewProfileManagement/Enabled/OfferUploadCreditCards/Enabled/OutOfProcessPac/Enabled/*PageRevisitInstrumentation/Enabled

/PasswordBranding/SmartLockBrandingSavePromptOnly/PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PreRead/NoPrefetchArgument2/

PreconnectMore/Enabled/*QUIC/Enabled/RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SRTPromptFieldTrial/On/SSLComm

onNameMismatchHandling/Enabled/*SafeBrowsingIncidentReportingService/Enabled/SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingReportPhishingErrorLink/En

abled/SafeBrowsingUpdateFrequency/UpdateTime15m/SafeBrowsingV4LocalDatabaseManagerEnabled/Enabled/SchedulerExpensiveTaskBlocking/Enabled/SdchPersistence/Enabled/*SettingsEnforcement/en

force_always_with_extensions_and_dse/StrictSecureCookies/Enabled/SyncHttpContentCompression/Enabled/TabSyncByRecency/Enabled/*TokenBinding/TokenBinding/*TriggeredResetFieldTrial/On/*UMA_Ch

eckStates/Checks/V8CacheStrategiesForCacheStorage/none/VarationsServiceControl/Interval_30min/WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Enabled/WebRTC-

H264WithOpenH264FFmpeg/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/use-new-media-cache/Enabled/ --primordial-pipe-

token=6D7EFECE2BC71369FE86EE471C853CD0 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-

settings=disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-

factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-

texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=9FDA6E17E94E137ECA59D62380824359 --mojo-application-channel-

token=1007EA8ACE522432645E95796B3F0354 --channel="4092.3.1681704669\2066998142" --mojo-platform-channel-handle=1784
"C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" "-lang=cs_CZ" "-cachedir=C:\Users\jemin\AppData\Local\Steam\htmlcache" "-steampid=4804" "-buildid=1508910373" "-steamid=0" "-

clientui=C:\Program Files (x86)\Steam\clientui" --disable-spell-checking --disable-out-of-process-pac --enable-blink-features=ResizeObserver --disable-smooth-scrolling --disable-gpu-compositing --disable-gpu

--enable-direct-write "--log-file=C:\Program Files (x86)\Steam\logs\cef_log.txt"
"C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=crashpad-handler /prefetch:7 --max-uploads=5 --max-db-size=20 --max-db-age=5 --monitor-self-annotation=ptype=crashpad-

handler "--database=C:\Users\jemin\AppData\Local\CEF\User Data\Crashpad" "--metrics-dir=C:\Users\jemin\AppData\Local\CEF\User Data" --url=http://crash.steampowered.com/submit --

annotation=platform=win32 --annotation=product=cefwebhelper --annotation=version=1.0 --initial-client-data=0x184,0x188,0x18c,0x180,0x190,0x510d81ec,0x510d81fc,0x510d820c
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe "-12530563101687251150-19667980631268325306-640023768881084936-1043091120940095888
"C:\Windows\Microsoft\svchost.exe.exe" -a cryptonight -o stratum+tcp://mine.moneropool.com:3333 -u

4B9Darzi85pHxc53y1KZ6BHpFhdFSbTMYHMbK5BCByM36HsbsXqVzHYHwkybR1272oaZ4zPJ2EP79bw4dRUJR9pLSebAhDM -p x -t 4
\??\C:\Windows\system32\conhost.exe "539200508-8322232759666672901299317021155691727-17077159271957922381-1855423359
C:\Disk\WebService.exe
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerNetworkService -f "C:\ProgramData\NVIDIA\NvContainerNetworkService.log" -l 3 -d "C:\Program Files\NVIDIA Corporation

\NvContainer\plugins\NetworkService" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe" --type=renderer --disable-gpu-compositing --no-sandbox --service-pipe-

token=B82A1FF0B933EADEE00DC6370C16D2C3 --lang=en-US --lang=en-US --log-file="C:\Users\jemin\AppData\Local\NVIDIA Corporation\NVIDIA Share\CefCache\debug.log" --enable-pinch --device-

scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-

target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;

1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,35

53;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,1

0,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3

553;4,14,3553;4,15,3553;4,16,3553 --disable-accelerated-video-decode --disable-gpu-compositing --service-request-channel-token=B82A1FF0B933EADEE00DC6370C16D2C3 --renderer-client-id=2 --mojo-

platform-channel-handle=1724 /prefetch:1
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -d "C:\Program Files\NVIDIA Corporation\NvStreamSrv\SsauPlugins" -f "C:\ProgramData\NVIDIA Corporation\nvstreamsvc\NvcSSAU.log" -l

4 -r -c
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe"
rundll32.exe "C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxcore.dll" RmWindowsHookSetup
rundll32.exe "C:\Program Files (x86)\NVIDIA Corporation\NvStreamSrv\rxcore.dll" RmWindowsHookSetup
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Disk\WEBSER~1.EXE 6576
C:\Disk\securedisk.exe -o mine4.12finance.com:4444 -u 49uCjDkMQQ1aqm5efnH79E22aveF6bFGBTVhusWQYBBfdpC5s8zXqzVVjD3xdj3vCd3GeRQ4rNPGmUdHu8GbNspVEbTZ1HE -p x -k -t 2 --donate-

level=1
\??\C:\Windows\system32\conhost.exe "2112698932-261814686-1126600200-1506111497760636152-1586562062400992681999407432
"C:\Program Files\Internet Explorer\iexplore.exe" "http://izogreb.ru/?utm_d=20171030"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:2332 CREDAT:267521 /prefetch:2
"C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe"
"C:\Fraps\fraps64.dat"
"C:\Program Files (x86)\ZfJRwqLPhIE\landhTGixw.exe" -Embedding
"C:\Program Files\Internet Explorer\iexplore.exe" "http://izogreb.ru/?utm_d=20171030"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4348 CREDAT:267521 /prefetch:2
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4348 CREDAT:1447250 /prefetch:2
"C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:4348 CREDAT:4068628 /prefetch:2
"C:\Windows\Microsoft\svchost.exe" -k LocalService
"C:\Windows\Microsoft\svchost.exe.exe" -a cryptonight -o stratum+tcp://mine.moneropool.com:3333 -u

4B9Darzi85pHxc53y1KZ6BHpFhdFSbTMYHMbK5BCByM36HsbsXqVzHYHwkybR1272oaZ4zPJ2EP79bw4dRUJR9pLSebAhDM -p x -t 4
\??\C:\Windows\system32\conhost.exe "-11111682841779827271-562955083151889929370534620688376570-14398669031153010633
"C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe" --type=renderer --enable-

features=AutomaticTabDiscarding<AutomaticTabDiscarding,IncidentReportingDisableUpload<SafeBrowsingIncidentReportingService,IncidentReportingModuleLoadAnalysis<SafeBrowsingIncidentReportingSer

viceFeatures,IncidentReportingSuspiciousModuleReporting<SafeBrowsingIncidentReportingServiceFeatures,MainFrameBeforeActivation<MainFrameBeforeActivation,NetworkTimeServiceQuerying<NetworkTi

meQueries,PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow,WebRTC-EnableWebRtcEcdsa<WebRTC-EnableWebRtcEcdsa,WebRTC-

H264WithOpenH264FFmpeg<WebRTC-H264WithOpenH264FFmpeg,token-binding<TokenBinding,use-new-media-cache<use-new-media-cache --disable-

features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame --force-

fieldtrials=AutofillClassifier/Enabled/AutofillFieldMetadata/Enabled/AutofillProfileOrderByFrecency/EnabledLimitTo3/*AutomaticTabDiscarding/Enabled_Once_10-

gen2/*BrowserBlacklist/Enabled/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeDashboard/Enabled/ChromotingQUIC/Enabled/DefaultBrowserInfobar/SettingsText/*DisallowFetchFor

DocWrittenScriptsInMainFrame/DocumentWriteScriptBlockGroup/EnableGoogleCachedCopyTextExperiment/Button/*EnableMediaRouter/Enabled/EnableMediaRouterWithCastExtension/Enabled/EnableSessio

nCrashedBubbleUI/Enabled/ExtensionActionRedesign/Enabled/*ExtensionContentVerification/Enforce/ExtensionInstallVerification/Enforce/GoogleBrandedContextMenu/branded/GoogleNow/Enable/IconNTP/Def

ault/InstanceID/Enabled/IntelligentSessionRestore/Enabled/*LocalNTPSuggestionsService/Enabled/*MainFrameBeforeActivation/Enabled/MaterialDesignDownloads/Enabled/MojoChannel/Enabled/*NetworkQu

alityEstimator/Enabled/NetworkTimeQueries/NetworkTimeQueriesEnabled/*NewProfileManagement/Enabled/OfferUploadCreditCards/Enabled/OutOfProcessPac/Enabled/*PageRevisitInstrumentation/Enabled

/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/*PreRead/NoPrefetchArgument

2/PreconnectMore/Enabled/*QUIC/Enabled/RefreshTokenDeviceId/Enabled/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Launch50pct_11011_1_1_10/SRTPromptFieldTrial/On/SSLCom

monNameMismatchHandling/Enabled/*SafeBrowsingIncidentReportingService/Enabled/SafeBrowsingIncidentReportingServiceFeatures/WithSuspiciousModuleReporting/SafeBrowsingReportPhishingErrorLink/

Enabled/SafeBrowsingUpdateFrequency/UpdateTime15m/SafeBrowsingV4LocalDatabaseManagerEnabled/Enabled/*SchedulerExpensiveTaskBlocking/Enabled/SdchPersistence/Enabled/*SettingsEnforcement

/enforce_always_with_extensions_and_dse/*StrictSecureCookies/Enabled/SyncHttpContentCompression/Enabled/TabSyncByRecency/Enabled/*TokenBinding/TokenBinding/*TriggeredResetFieldTrial/On/*UMA

_CheckStates/Checks/*V8CacheStrategiesForCacheStorage/none/VarationsServiceControl/Interval_30min/WebFontsIntervention/Enabled/WebRTC-EnableWebRtcEcdsa/Enabled/WebRTC-

H264WithOpenH264FFmpeg/Enabled/WebRTC-LocalIPPermissionCheck/Enabled/WebRTC-PeerConnectionDTLS1.2/Enabled/use-new-media-cache/Enabled/ --primordial-pipe-

token=BF62AAFA0B981790C13FD0F38014004A --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-

settings=disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true,fetchDeferLateScripts=true,fetchIncreaseFontPriority=true,fetchIncreasePriorities=true --enable-pinch --device-scale-

factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-

texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=4752BF0ADC382C86B7FE8A7CBD1E0266 --mojo-application-channel-

token=4B508E9D0EACDAEB3E5679276F94AE79 --channel="4092.12.1379402529\1792081144" --mojo-platform-channel-handle=3064
"C:\Windows\system32\NOTEPAD.EXE" C:\Users\jemin\Desktop\Nový textový dokument.txt
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe5_ Global\UsGthrCtrlFltPipeMssGthrPipe5 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible;

MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 520 524 532 65536 528
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\jemin\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\PjDfytumxbayONn.job - rundll32 "C:\Program Files (x86)\kqEuPYMaU\GXHxKF.dll",#1
C:\Windows\tasks\SlimDrivers Startup.job - C:\Program Files (x86)\SlimDrivers\SlimDrivers.exe -boot
C:\Windows\tasks\wupdate.job - C:\Users\jemin\AppData\Local\wupdate\wupdate.exe

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F4B8786-5502-4803-8EBC-F652A1153BB6}]
True Key Helper - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2014-05-30 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-11-20 255088]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee WebAdvisor BHO - c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll [2017-09-06 189288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}]
YoutubeAdBlock - C:\Program Files (x86)\ZfJRwqLPhIE\tZcAvuy.dll [2017-10-30 569856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C91BA35D-6516-489F-A203-2992ED9A4132}]
Lišta Centrum.cz - pomocný objekt - C:\Program Files (x86)\Centrum Holdings s.r.o\Lišta Centrum.cz\cenbho64.dll [2013-01-23 621016]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-05-30 211368]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0F4B8786-5502-4803-8EBC-F652A1153BB6}]
True Key Helper - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}]
Search@Mail.Ru - C:\Users\jemin\AppData\Local\Mail.Ru\Sputnik\ie_addon_dll.dll [2017-10-30 1584856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-20 193136]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee WebAdvisor BHO - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [2017-09-06 160192]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}]
YoutubeAdBlock - C:\Program Files (x86)\ZfJRwqLPhIE\k7zVdU1Vp.dll [2017-10-30 402432]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C91BA35D-6516-489F-A203-2992ED9A4132}]
Lišta Centrum.cz - pomocný objekt - C:\Program Files (x86)\Centrum Holdings s.r.o\Lišta Centrum.cz\cenbho32.dll [2013-01-23 485848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-11-20 255088]
{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - True Key - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-20 193136]
{4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - True Key - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll []

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-08-07 36352]
"MSC"=C:\Program Files\Microsoft Security Client\msseces.exe [2016-11-14 1353680]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2000-01-01 190536]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2000-01-01 13876952]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2017-10-11 1796032]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Svátky a výročí"=C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe [2015-10-04 1019904]
"HP Deskjet 3520 series (NET)"=C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2012-10-17 2573416]
"jemin"=explorer.exe http://kb-ribaki.org []
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-08-25 27832272]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2017-10-25 3102496]
"MailRuUpdater"=C:\Users\jemin\AppData\Local\Mail.Ru\MailRuUpdater.exe [2017-08-21 4100312]
"MediaPlayerApplication"=C:\Users\jemin\AppData\Roaming\MediaPlayerApplication\MediaPlayerApplication.exe [2017-10-30 1323520]
"ttkutpvogu"=explorer http://granena.ru/?utm_source=uoua03n&u ... d=20171030 []
"KometaLaunchPanel"=C:\Users\jemin\AppData\Local\Kometa\Panel\KometaLaunchPanel.exe [2017-10-30 4105312]
"ycAutoLaunch_8BD45C324E1801E78C906E73D35C9CF9"=C:\Users\jemin\AppData\Local\yc\Application\yc.exe [2017-10-19 4018688]
"KometaAutoLaunch_99329504B9DDFAA4DB3EFCC619BA3175"=C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe [2016-08-09 1535200]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GSplay.exe]
D:\GSplay.exe [2015-10-04 4772747]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Program Killer.lnk]
C:\PROGRA~2\PROGRA~1\PROGRA~1.EXE [2015-10-04 1534976]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^jemin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk]
C:\PROGRA~2\MYPCBA~1\MYPCBA~1.EXE []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"GrooveMonitor"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [2009-02-26 30040]
""= []
"ProductUpdater"=C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe [2016-07-19 75776]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
GamePark klient 2.lnk - C:\Program Files\GamePark2\gpcl.exe

C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk - C:\Windows\system32\RunDll32.exe
Vesmír na dlani.lnk - C:\Program Files (x86)\Noční obloha\vesmir.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll [2008-03-18 275360]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26 2217832]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\26821665.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\31663166.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DA92FCC0.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\26821665.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\31663166.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DA92FCC0.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PAexec]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvyu"=msyuv.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"vidc.yvu9"=tsbyuv.dll
"msacm.l3acm"=l3codeca.acm
"VIDC.FPS1"=frapsv64.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"VIDC.FFDS"=ff_vfw.dll
"msacm.ac3acm"=ac3acm.acm
"msacm.l3codecp"=l3codecp.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1

======List of files/folders created in the last 1 month======

2017-10-30 15:12:44 ----D---- C:\rsit
2017-10-30 15:05:12 ----ASH---- C:\hiberfil.sys
2017-10-30 13:08:23 ----D---- C:\Windat
2017-10-30 13:08:22 ----D---- C:\Program Files\LaCie Private Public
2017-10-30 13:08:22 ----D---- C:\Disk
2017-10-30 13:08:00 ----D---- C:\Program Files (x86)\EnjoyWiFi
2017-10-30 13:06:47 ----D---- C:\Users\jemin\AppData\Roaming\curl
2017-10-30 13:05:23 ----D---- C:\Users\jemin\AppData\Roaming\Subversion
2017-10-30 13:04:45 ----RSHD---- C:\Windows\Microsoft
2017-10-30 13:00:54 ----D---- C:\Program Files (x86)\zTWnHlzwjSUn
2017-10-30 13:00:54 ----D---- C:\Program Files (x86)\ZfJRwqLPhIE
2017-10-30 13:00:54 ----D---- C:\Program Files (x86)\JIdcnntTvnKU2
2017-10-30 13:00:53 ----D---- C:\Program Files (x86)\kqEuPYMaU
2017-10-30 13:00:48 ----D---- C:\Users\jemin\AppData\Roaming\MediaPlayerApplication
2017-10-30 12:58:08 ----D---- C:\Program Files (x86)\Mail.Ru
2017-10-30 12:58:03 ----D---- C:\ProgramData\Mail.Ru
2017-10-30 12:43:11 ----SHD---- C:\Config.Msi
2017-10-30 09:58:22 ----D---- C:\NVIDIA
2017-10-26 18:14:06 ----D---- C:\Users\jemin\AppData\Roaming\Burnaware
2017-10-26 18:14:02 ----D---- C:\Program Files (x86)\BurnAware Free
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2017-10-23 17:55:13 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvumdshimx.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvopencl.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvoglv64.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvoglshim64.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvinitx.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\NvIFR64.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvhdap64.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\NvFBC64.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvdispgenco6438800.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvdispco6438800.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvcuvid.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvcuda.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\nvcompiler.dll
2017-10-23 17:55:13 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2017-10-23 17:55:13 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2017-10-23 17:30:34 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2017-10-16 16:42:14 ----AC---- C:\Windows\system32\MRT-KB890830.exe
2017-10-16 16:20:29 ----A---- C:\Windows\system32\mshtml.dll
2017-10-16 16:20:28 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-10-16 16:20:28 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-10-16 16:20:28 ----A---- C:\Windows\system32\ieframe.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\wininet.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\tquery.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\Query.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\jscript.dll
2017-10-16 16:20:27 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\wininet.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\win32k.sys
2017-10-16 16:20:27 ----A---- C:\Windows\system32\urlmon.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\tquery.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\rdpcorets.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\rdpcore.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\Query.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-10-16 16:20:27 ----A---- C:\Windows\system32\msfeeds.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\mf.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\jscript9.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\jscript.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\iertutil.dll
2017-10-16 16:20:27 ----A---- C:\Windows\system32\drivers\ntfs.sys
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\wlansec.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\wlanmsm.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\wlanhlp.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\wlanapi.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\themeui.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\t2embed.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\mswstr10.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\msjint40.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\msexcl40.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\msctf.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\mfps.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\mf.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2017-10-16 16:20:26 ----A---- C:\Windows\SYSWOW64\certcli.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\wlansvc.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\wlansec.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\wlanmsm.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\wlanhlp.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\wlanapi.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\webcheck.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\vbscript.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\themeui.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\t2embed.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\smss.exe
2017-10-16 16:20:26 ----A---- C:\Windows\system32\schannel.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\rrinstaller.exe
2017-10-16 16:20:26 ----A---- C:\Windows\system32\rpcrt4.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\rdpudd.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\ntdll.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\mssvp.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\mssrch.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2017-10-16 16:20:26 ----A---- C:\Windows\system32\mshtmlmedia.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\mshtmled.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\MshtmlDac.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\msctf.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\mfps.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\mfpmp.exe
2017-10-16 16:20:26 ----A---- C:\Windows\system32\lsasrv.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\kernel32.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\kerberos.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\ieui.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\iedkcs32.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\ieapfltr.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\icaapi.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\gdi32.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\dxtrans.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\dxtmsft.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\srvnet.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\srv2.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\srv.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\nwifi.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2017-10-16 16:20:26 ----A---- C:\Windows\system32\certcli.dll
2017-10-16 16:20:26 ----A---- C:\Windows\system32\advapi32.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-10-16 16:20:25 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\wow32.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\user.exe
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\srclient.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\schannel.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\setup16.exe
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\secur32.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\SearchProtocolHost.exe
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\SearchIndexer.exe
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\SearchFilterHost.exe
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\occache.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\mssvp.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\mssrch.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\mssprxy.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\mssphtb.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\mssph.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\mssitlb.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\msshooks.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\msscntrs.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\msrating.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\mferror.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\instnm.exe
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\inseng.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\ieui.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\credssp.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\bcrypt.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2017-10-16 16:20:25 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\wow64win.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\wow64cpu.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\wow64.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\winsrv.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\wdigest.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\TSpkg.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\sspisrv.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\sspicli.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\srcore.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\srclient.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\secur32.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\SearchProtocolHost.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\SearchIndexer.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\SearchFilterHost.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\rstrui.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\rpchttp.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\occache.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\ntvdm64.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\ncrypt.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\msv1_0.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\mssprxy.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\mssphtb.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\mssph.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\mssitlb.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\msshooks.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\msscntrs.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\msrating.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\msobjs.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\msaudite.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\mferror.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\lsass.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\KernelBase.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\jsproxy.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\jscript9diag.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\inseng.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\ieUnatt.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\iesetup.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\iernonce.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\ieetwproxystub.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\ieetwcollector.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\ie4uinit.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2017-10-16 16:20:25 ----A---- C:\Windows\system32\drivers\appid.sys
2017-10-16 16:20:25 ----A---- C:\Windows\system32\csrsrv.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\cryptbase.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\credssp.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\conhost.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\bcrypt.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\auditpol.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\appidsvc.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2017-10-16 16:20:25 ----A---- C:\Windows\system32\appidapi.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\apisetschema.dll
2017-10-16 16:20:25 ----A---- C:\Windows\system32\adtschema.dll
2017-10-05 04:51:50 ----D---- C:\ProgramData\Slightly Mad Studios
2017-10-04 06:21:22 ----A---- C:\Windows\system32\nvdispgenco6438569.dll
2017-10-04 06:21:22 ----A---- C:\Windows\system32\nvdispco6438569.dll
2017-10-02 20:56:22 ----D---- C:\Users\jemin\AppData\Roaming\Roaming

======List of files/folders modified in the last 1 month======

2017-10-30 15:15:48 ----D---- C:\Program Files\trend micro
2017-10-30 15:11:04 ----D---- C:\Windows\System32
2017-10-30 15:11:04 ----D---- C:\Windows\inf
2017-10-30 15:11:04 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-10-30 15:10:29 ----D---- C:\Windows\temp
2017-10-30 15:08:21 ----D---- C:\Windows\system32\config
2017-10-30 15:08:14 ----D---- C:\Users\jemin\AppData\Roaming\Skype
2017-10-30 15:05:55 ----D---- C:\Fraps
2017-10-30 15:05:54 ----D---- C:\Windows\system32\Tasks
2017-10-30 15:05:26 ----D---- C:\ProgramData\NVIDIA
2017-10-30 15:05:22 ----D---- C:\Program Files (x86)\Steam
2017-10-30 15:05:11 ----D---- C:\Windows\system32\drivers
2017-10-30 15:04:14 ----AD---- C:\ProgramData
2017-10-30 13:08:22 ----RD---- C:\Program Files
2017-10-30 13:08:00 ----RD---- C:\Program Files (x86)
2017-10-30 13:07:08 ----D---- C:\Windows\Tasks
2017-10-30 13:04:45 ----D---- C:\Windows
2017-10-30 13:00:10 ----D---- C:\Windows\SysWOW64
2017-10-30 13:00:05 ----HD---- C:\Windows\system32\GroupPolicy
2017-10-30 12:51:32 ----D---- C:\Windows\Minidump
2017-10-30 12:49:54 ----D---- C:\Windows\system32\DriverStore
2017-10-30 12:43:12 ----SHD---- C:\Windows\Installer
2017-10-30 12:43:09 ----SHD---- C:\System Volume Information
2017-10-30 12:42:40 ----D---- C:\ProgramData\Package Cache
2017-10-30 12:41:57 ----RSD---- C:\Windows\assembly
2017-10-30 12:20:48 ----D---- C:\ProgramData\NVIDIA Corporation
2017-10-27 03:46:53 ----D---- C:\Program Files (x86)\McAfee
2017-10-26 18:14:16 ----D---- C:\Program Files (x86)\Common Files
2017-10-26 18:14:05 ----D---- C:\ProgramData\McAfee
2017-10-25 18:42:41 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-10-25 18:42:40 ----D---- C:\Windows\system32\Macromed
2017-10-25 18:42:39 ----D---- C:\Windows\SYSWOW64\Macromed
2017-10-23 18:20:14 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-10-23 17:56:29 ----D---- C:\Users\jemin\AppData\Roaming\NVIDIA
2017-10-23 17:56:00 ----D---- C:\Program Files\NVIDIA Corporation
2017-10-23 17:32:16 ----D---- C:\Windows\system32\catroot2
2017-10-19 19:03:16 ----D---- C:\Users\jemin\AppData\Roaming\vlc
2017-10-16 21:09:10 ----D---- C:\Windows\rescache
2017-10-16 17:51:43 ----D---- C:\Windows\Microsoft.NET
2017-10-16 17:41:23 ----D---- C:\Windows\winsxs
2017-10-16 17:40:19 ----D---- C:\Windows\SYSWOW64\sk-SK
2017-10-16 17:40:19 ----D---- C:\Windows\SYSWOW64\migration
2017-10-16 17:40:19 ----D---- C:\Windows\SYSWOW64\en-US
2017-10-16 17:40:19 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-10-16 17:40:19 ----D---- C:\Windows\system32\sk-SK
2017-10-16 17:40:19 ----D---- C:\Windows\system32\migration
2017-10-16 17:40:19 ----D---- C:\Windows\system32\en-US
2017-10-16 17:40:19 ----D---- C:\Windows\system32\cs-CZ
2017-10-16 17:40:19 ----D---- C:\Windows\system32\Boot
2017-10-16 17:40:19 ----D---- C:\Windows\AppPatch
2017-10-16 17:40:19 ----D---- C:\Program Files\Internet Explorer
2017-10-16 17:40:19 ----D---- C:\Program Files (x86)\Internet Explorer
2017-10-16 16:44:24 ----D---- C:\Windows\system32\MRT
2017-10-16 16:42:12 ----AC---- C:\Windows\system32\MRT.exe
2017-10-12 22:33:56 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2017-10-12 22:33:56 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2017-10-12 22:33:56 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2017-10-12 22:33:56 ----A---- C:\Windows\system32\nvwgf2umx.dll
2017-10-12 22:33:56 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2017-10-12 22:33:56 ----A---- C:\Windows\system32\nvd3dumx.dll
2017-10-12 22:33:56 ----A---- C:\Windows\system32\nvapi64.dll
2017-10-12 21:25:58 ----A---- C:\Windows\NvContainerRecovery.bat
2017-10-12 20:55:22 ----A---- C:\Windows\system32\nvsvc64.dll
2017-10-12 20:55:22 ----A---- C:\Windows\system32\nvcpl.dll
2017-10-12 20:55:18 ----A---- C:\Windows\system32\nvsvcr.dll
2017-10-12 20:55:18 ----A---- C:\Windows\system32\nvshext.dll
2017-10-12 20:55:18 ----A---- C:\Windows\system32\nvmctray.dll
2017-10-12 20:55:18 ----A---- C:\Windows\system32\nv3dappshextr.dll
2017-10-12 20:55:18 ----A---- C:\Windows\system32\nv3dappshext.dll
2017-10-11 02:05:52 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2017-10-11 02:05:52 ----A---- C:\Windows\system32\nvspcap64.dll
2017-10-11 02:05:51 ----A---- C:\Windows\system32\NvRtmpStreamer64.dll
2017-10-11 02:05:47 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2017-10-11 02:05:47 ----A---- C:\Windows\system32\nvaudcap64v.dll
2017-10-11 00:26:14 ----A---- C:\Windows\NvTelemetryContainerRecovery.bat
2017-10-02 20:56:28 ----D---- C:\Games

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\Windows\system32\DRIVERS\iaStorA.sys [2013-08-07 644968]
R0 iaStorF;iaStorF; C:\Windows\system32\DRIVERS\iaStorF.sys [2013-08-07 28008]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2013-04-26 20464]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2016-08-25 295000]
R0 NBVol;Nero Backup Volume Filter Driver; C:\Windows\system32\DRIVERS\NBVol.sys [2011-07-13 72240]
R0 NBVolUp;Nero Backup Volume Upper Filter Driver; C:\Windows\system32\DRIVERS\NBVolUp.sys [2011-07-13 15920]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 213888]
R0 vmbus;@%SystemRoot%\system32\vmbusres.dll,-1000; C:\Windows\system32\drivers\vmbus.sys [2010-11-20 199552]
R1 AppleCharger;AppleCharger; C:\Windows\system32\DRIVERS\AppleCharger.sys [2013-02-19 21584]
R1 avgtp;avgtp; \??\C:\Windows\system32\drivers\avgtpx64.sys [2014-05-30 50464]
R1 CSC;@%systemroot%\system32\cscsvc.dll,-202; C:\Windows\system32\drivers\csc.sys [2010-11-20 514560]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-06-28 283064]
R1 MpKsl9d103eb1;MpKsl9d103eb1; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKsl9d103eb1.sys [2017-10-30 49392]
R1 wfcre;wfcre; C:\Windows\system32\drivers\wfcre.sys [2017-07-04 124288]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2015-12-21 3793872]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2000-01-01 4467928]
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-08-21 463112]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2013-09-16 99288]
R3 mfesapsn;McAfee Process Start Notification Service; \??\C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [2017-02-14 111608]
R3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2016-08-25 135928]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2017-10-12 225208]
R3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-10-11 30144]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2017-10-11 50624]
R3 nvvhci;NVVHCI Enumerator Service; C:\Windows\system32\DRIVERS\nvvhci.sys [2017-08-18 57792]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2012-10-25 769168]
R3 StillCam;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\system32\DRIVERS\serscan.sys [2009-07-14 12288]
S1 MpKsl6ad3767b;MpKsl6ad3767b; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKsl6ad3767b.sys [2017-10-30 49392]
S1 MpKslabc8ce25;MpKslabc8ce25; \??\C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKslabc8ce25.sys [2017-10-30 49392]
S1 UsbCharger;UsbCharger; C:\Windows\system32\DRIVERS\UsbCharger.sys [2013-05-06 21584]
S3 androidusb;ADB Interface Driver; C:\Windows\System32\Drivers\androidusb.sys [2010-04-29 32768]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 cpuz136;cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys []
S3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-07-22 130688]
S3 EagleX64;EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys []
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys []
S3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2000-01-01 395504]
S3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2000-01-01 806128]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RDPDR;Terminal Server Device Redirector Driver; C:\Windows\System32\drivers\rdpdr.sys [2010-11-20 165888]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2017-08-13 20992]
S3 s3cap;s3cap; C:\Windows\system32\drivers\vms3cap.sys [2010-11-20 6656]
S3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM); C:\Windows\system32\DRIVERS\ssadbus.sys [2011-05-13 157672]
S3 ssadmdfl;SAMSUNG Android USB Modem (Filter); C:\Windows\system32\DRIVERS\ssadmdfl.sys [2011-05-13 16872]
S3 ssadmdm;SAMSUNG Android USB Modem Drivers; C:\Windows\system32\DRIVERS\ssadmdm.sys [2011-05-13 177640]
S3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM); C:\Windows\system32\DRIVERS\ssadserd.sys [2011-05-13 146920]
S3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-07-22 164992]
S3 storvsc;storvsc; C:\Windows\system32\drivers\storvsc.sys [2010-11-20 34688]
S3 SWDUMon;SWDUMon; C:\Windows\system32\DRIVERS\SWDUMon.sys [2017-10-30 16056]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-20 59392]
S3 usb_rndisx;Adaptér USB RNDIS; C:\Windows\system32\DRIVERS\usb8023x.sys [2013-02-12 19968]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 VMBusHID;VMBusHID; C:\Windows\system32\drivers\VMBusHID.sys [2010-11-20 21760]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 ABBYY.Licensing.FineReader.Home.10.0;ABBYY FineReader 10 HE Licensing Service; C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\Home\NetworkLicenseServer.exe [2010

-07-21 814344]
R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-07-19 83032]
R2 CscService;@%systemroot%\system32\cscsvc.dll,-200; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 Freemake Improver;Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [2016-07-19 108032]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-08-07 15720]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2016-01-13 319096]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-08-27 747520]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-10-04 169432]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [2017-09-06 590880]
R2 mrupdsrv;Mail.Ru Update Service; C:\Program Files (x86)\Mail.Ru\Update Service\mrupdsrv.exe [2017-08-21 1314008]
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Client\MsMpEng.exe [2016-11-14 119864]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11 518080]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-10-12 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-10-11 460736]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2016-01-03 75064]
R2 PnkBstrB;PnkBstrB; C:\Windows\syswow64\PnkBstrB.exe [2017-01-31 214520]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [2016-07-22 754784]
R2 ssinstall;SInstalátor; C:\Windows\SysWOW64\ssins.exe [2016-11-23 4696960]
R2 SvcHost Service Host;SvcHost Service Host; C:\Windows\Microsoft\svchost.exe -k LocalService []
R2 Updater.Mail.Ru;Updater.Mail.Ru; C:\Program Files (x86)\Mail.Ru\MailRuUpdater\MailRuUpdater.exe [2017-08-21 4100312]
R3 NisSrv;@C:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 361816]
R3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11 518080]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-10-25 1641248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-04-21 107656]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-04-21 128648]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-04 144200]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2015-10-04 432088]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-07-18 317408]
S2 SlimService;SlimWare Utility Service Launcher; C:\Program Files\SlimService\SlimServiceFactory.exe []
S2 TeamViewer;TeamViewer 10; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2015-10-04 5467920]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25 272384]
S3 AppleChargerSrv;AppleChargerSrv; C:\Windows\system32\AppleChargerSrv.exe [2010-04-06 31272]
S3 AppMgmt;@appmgmts.dll,-3250; C:\Windows\system32\svchost.exe [2009-07-14 27136]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-04-21 52856]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2016-01-13 280696]
S3 Futuremark SystemInfo Service;Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\Futuremark SystemInfo\FMSISvc.exe [2015-10-04 137488]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-04 144200]
S3 gusvc;Google Software Updater; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2015-10-04 194032]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2017-09-07 116224]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-08-27 828376]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2015-10-04 64856]
S3 NBService;NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe []
S3 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2015-10-04 271920]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2015-10-04 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-10-04 145184]
S3 PAExec;PAExec; C:\Windows\PAExec.exe [2017-01-28 189112]
S3 PeerDistSvc;@%SystemRoot%\system32\peerdistsvc.dll,-9000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S3 UmRdpService;@%SystemRoot%\system32\umrdp.dll,-1000; C:\Windows\System32\svchost.exe [2009-07-14 27136]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-04-21 136312]

-----------------EOF-----------------

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 30 říj 2017 15:56
od Kodlz
Stáhni AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Ulož na plochu
Ukonči všechny programy
Klikni nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vlož.

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 30 říj 2017 16:08
od ebola
log -# AdwCleaner 7.0.4.0 - Logfile created on Mon Oct 30 15:05:23 2017
# Updated on 2017/27/10 by Malwarebytes
# Running on Windows 7 Ultimate (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

Deleted: mrupdsrv
Deleted: SvcHost Service Host
Deleted: SvcHost Service Host
Deleted: Updater.Mail.Ru
Deleted: SlimService


***** [ Folders ] *****

Deleted: C:\Users\jemin\AppData\Roaming\..\Local\\wupdate
Deleted: C:\Program Files (x86)\Common Files\freemake shared
Deleted: C:\Users\All Users\Documents\XMUpdate
Deleted: C:\Users\Public\Documents\XMUpdate
Deleted: C:\Users\jemin\AppData\Local\Поиcк в Интeрнете
Deleted: C:\Users\jemin\AppData\Local\Вoйти в Интeрнет
Deleted: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Боковая панель - Комета
Deleted: C:\Users\jemin\AppData\Local\Kometa
Deleted: C:\Users\jemin\AppData\Roaming\MediaPlayerApplication
Deleted: C:\Program Files (x86)\kqEuPYMaU
Deleted: C:\Program Files (x86)\ZfJRwqLPhIE
Deleted: C:\Program Files (x86)\JIdcnntTvnKU2
Deleted: C:\Users\jemin\AppData\Local\Kometa
Deleted: C:\Users\jemin\AppData\Local\ScriptWriter
Deleted: C:\Program Files (x86)\Enigma Software Group
Deleted: C:\Users\jemin\AppData\Roaming\Enigma Software Group
Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\spyhunter
Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpyHunter
Deleted: C:\ProgramData\Mail.Ru
Deleted: C:\ProgramData\Application Data\Mail.Ru
Deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Mail.Ru
Deleted: C:\Program Files (x86)\Mail.Ru
Deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Mail.Ru
Deleted: C:\Users\All Users\Mail.Ru
Deleted: C:\Users\jemin\AppData\Local\Mail.Ru
Deleted: C:\Program Files (x86)\zTWnHlzwjSUn
Deleted: C:\Users\jemin\AppData\Roaming\\MediaPlayerApplication
Deleted: C:\Users\jemin\AppData\Local\slimware utilities inc
Deleted: C:\ProgramData\SlimWare Utilities, Inc
Deleted: C:\ProgramData\Application Data\SlimWare Utilities, Inc
Deleted: C:\Users\All Users\SlimWare Utilities, Inc
Deleted: C:\Users\jemin\AppData\Local\SlimWare Utilities Inc
Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlimDrivers
Deleted: C:\Program Files (x86)\SlimDrivers
Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EnjoyWiFi
Deleted: C:\Program Files (x86)\EnjoyWiFi
Deleted: C:\\Users\Public\Documents\XMUpdate


***** [ Files ] *****

Deleted: C:\Users\jemin\Favorites\Mail.Ru.url
Deleted: C:\Users\jemin\Favorites\Mail.Ru Агент - используй для общения!.url
Deleted: C:\Windows\SysNative\drivers\wfcre.sys
Deleted: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Kometa.lnk
Deleted: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kometa.lnk
Deleted: C:\spyhunter.fix
Deleted: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SpyHunter.lnk
Deleted: C:\Windows\System32\sh4native.exe
Deleted: C:\Windows\SysWOW64\sh4native.exe
Deleted: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk
Deleted: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mail.Ru.lnk
Deleted: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\SlimDrivers.lnk
Deleted: C:\Windows\\Microsoft\svchost.exe.exe


***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

Cleaned: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk[url,FileProtocolHandler "http:\\www.mail.ru\cnt\20775012?gp=811008"]
Cleaned: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk[url,FileProtocolHandler "http:\\www.mail.ru\cnt\20775012?gp=811008"]
Cleaned: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mail.Ru.lnk[url,FileProtocolHandler "http:\\www.mail.ru\cnt\20775012?gp=811008"]
Cleaned: C:\Users\jemin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mail.Ru.lnk[url,FileProtocolHandler "http:\\www.mail.ru\cnt\20775012?gp=811008"]


***** [ Tasks ] *****

Deleted: wupdate
Deleted: MailRuUpdater
Deleted: LaCieS
Deleted: zjwPaeaadZaNwF
Deleted: PjDfytumxbayONn2
Deleted: PjDfytumxbayONn
Deleted: ScriptWriter
Deleted: SpyHunter4Startup
Deleted: SlimDrivers Startup


***** [ Registry ] *****

Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Gosearchq
Deleted: [Key] - HKCU\Software\Microsoft\Gosearchq
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Gosearch
Deleted: [Key] - HKCU\Software\Microsoft\Gosearch
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MailRuUpdater
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{059EACC2-1ABE-49E8-928D-DC8BD355B7A9}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{8E8F97CD-60B5-456F-A201-73065652D099}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E8F97CD-60B5-456F-A201-73065652D099}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8E8F97CD-60B5-456F-A201-73065652D099}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{8E8F97CD-60B5-456F-A201-73065652D099}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{1BD47D21-01F4-4538-9290-39FD569A0F24}
Deleted: [Key] - HKLM\SOFTWARE\Classes\AppID\{149622B2-F1C5-492D-BFDF-8E5ED85854A0}
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{A5FF3EB5-BF62-4D59-84DF-DC518E46FCB3}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AE298D-7E8A-4F53-BE55-15D2B065F6C0}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\952BA647474611149866C1269F6A0E36
Deleted: [Key] - HKLM\SOFTWARE\Classes\Installer\Features\952BA647474611149866C1269F6A0E36
Deleted: [Key] - HKLM\SOFTWARE\Classes\Installer\Products\952BA647474611149866C1269F6A0E36
Deleted: [Value] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Windows\CurrentVersion\Run|KometaLaunchPanel
Deleted: [Value] - HKCU\Software\Microsoft\Windows\CurrentVersion\Run|KometaLaunchPanel
Deleted: [Value] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Windows\CurrentVersion\Run|MailRuUpdater
Deleted: [Value] - HKCU\Software\Microsoft\Windows\CurrentVersion\Run|MailRuUpdater
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\KometaLaunchPanel
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\KometaLaunchPanel
Deleted: [Key] - HKLM\SOFTWARE\NetBox
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\NetBox
Deleted: [Key] - HKCU\Software\NetBox
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{59A09B2C-E8FD-4756-ADEA-1436E9F8A74E}_is1
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\MediaPlayerApplication
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MediaPlayerApplication
Deleted: [Key] - HKCU\Software\MediaPlayerApplication
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MediaPlayerApplication
Deleted: [Value] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Windows\CurrentVersion\Run|MediaPlayerApplication
Deleted: [Value] - HKCU\Software\Microsoft\Windows\CurrentVersion\Run|MediaPlayerApplication
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Kometa
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\Kometa
Deleted: [Key] - HKCU\Software\Kometa
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Kometa
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\MICROSOFT\KometaInstaller
Deleted: [Key] - HKCU\Software\MICROSOFT\KometaInstaller
Deleted: [Key] - HKLM\SOFTWARE\NETBOX\Kometa
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\NETBOX\Kometa
Deleted: [Key] - HKCU\Software\NETBOX\Kometa
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\E3605470-291B-44EB-8648-745EE356599A
Deleted: [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup
Deleted: [Key] - HKLM\SOFTWARE\Enigma Software Group
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Xpom
Deleted: [Key] - HKCU\Software\Xpom
Deleted: [Key] - HKLM\SOFTWARE\Mail.Ru
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Mail.Ru
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\AppDataLow\Software\Mail.Ru
Deleted: [Key] - HKCU\Software\Mail.Ru
Deleted: [Key] - HKCU\Software\AppDataLow\Software\Mail.Ru
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Amigo
Deleted: [Key] - HKCU\Software\Amigo
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\csastats
Deleted: [Key] - HKCU\Software\csastats
Deleted: [Key] - HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\PRODUCTSETUP
Deleted: [Key] - HKCU\Software\PRODUCTSETUP
Deleted: [Key] - HKLM\SOFTWARE\SlimWare Utilities Inc
Deleted: [Key] - HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{746AB259-6474-4111-8966-1C62F9A6E063}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8948C1BE-92B8-4276-8803-DC71CC78203A}


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

Plugin deleted: Поиск Mail.Ru -
Plugin deleted: Домашняя страница Mail.Ru -


*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[C1].txt - [5192 B] - [2016/6/26 9:26:33]
C:/AdwCleaner/AdwCleaner[C2].txt - [3646 B] - [2016/8/14 6:48:10]
C:/AdwCleaner/AdwCleaner[C6].txt - [1024 B] - [2015/9/15 10:56:27]
C:/AdwCleaner/AdwCleaner[C7].txt - [3493 B] - [2015/10/1 23:9:36]
C:/AdwCleaner/AdwCleaner[S0].txt - [9645 B] - [2014/6/27 10:30:53]
C:/AdwCleaner/AdwCleaner[S10].txt - [931 B] - [2015/9/15 10:48:53]
C:/AdwCleaner/AdwCleaner[S11].txt - [758 B] - [2015/9/22 14:11:56]
C:/AdwCleaner/AdwCleaner[S12].txt - [5276 B] - [2015/10/1 16:28:41]
C:/AdwCleaner/AdwCleaner[S13].txt - [3216 B] - [2015/10/1 18:38:8]
C:/AdwCleaner/AdwCleaner[S14].txt - [3216 B] - [2015/10/1 19:19:45]
C:/AdwCleaner/AdwCleaner[S15].txt - [14080 B] - [2015/10/1 19:28:32]
C:/AdwCleaner/AdwCleaner[S16].txt - [3216 B] - [2015/10/1 19:32:56]
C:/AdwCleaner/AdwCleaner[S17].txt - [3216 B] - [2015/10/1 19:33:58]
C:/AdwCleaner/AdwCleaner[S18].txt - [3216 B] - [2015/10/1 23:8:34]
C:/AdwCleaner/AdwCleaner[S19].txt - [887 B] - [2015/10/2 17:4:22]
C:/AdwCleaner/AdwCleaner[S1].txt - [9281 B] - [2014/7/11 10:39:17]
C:/AdwCleaner/AdwCleaner[S2].txt - [13751 B] - [2014/10/21 13:52:40]
C:/AdwCleaner/AdwCleaner[S3].txt - [5747 B] - [2014/11/11 17:28:40]
C:/AdwCleaner/AdwCleaner[S4].txt - [11630 B] - [2015/8/9 4:53:44]


########## EOF - C:\AdwCleaner\AdwCleaner[C4].txt ##########

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 30 říj 2017 16:11
od Kodlz
Poprosim o vlozeni logu FRST.txt a Addition.txt z aplikace FRSTLauncher.exe (Farbar Recovery Scan Tool). Navod naleznes zde: https://forum.viry.cz/viewtopic.php?f=13&t=152707
Obsah Additional.txt muzes vlozit rovnou sem do vlakna.

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 30 říj 2017 16:20
od ebola
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-10-2017
Ran by jemin (administrator) on JEMIN-PC (30-10-2017 16:18:02)
Running from C:\Users\jemin\Desktop
Loaded Profiles: jemin (Available Profiles: jemin)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\Home\NetworkLicenseServer.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
() C:\Windows\Microsoft\svchost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Beepa P/L) C:\Fraps\fraps.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Tošovský Jan) C:\Program Files (x86)\Noční obloha\vesmir.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
() C:\Windows\Microsoft\svchost.exe.exe
() C:\Program Files (x86)\ZfJRwqLPhIE\landhTGixw.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe
(Beepa P/L) C:\Fraps\fraps64.dat
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Oracle Corporation) C:\Program Files\Java\jre7\launch4j-tmp\frd.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2000-01-01] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13876952 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [Svátky a výročí] => C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe [1019904 2015-10-04] (Igor Gottwald - OKsoftware)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [HP Deskjet 3520 series (NET)] => C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [jemin] => explorer.exe hxxp://kb-ribaki.org <==== ATTENTION
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832272 2017-08-25] (Skype Technologies S.A.)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3102496 2017-10-25] (Valve Corporation)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [ttkutpvogu] => explorer "hxxp://granena.ru/?utm_source=uoua03n&utm_content=e739009bccd5f1e6d71a91bff5994529&utm_term=256F29F2108A5A51F6A9F0E8D3607E4C&utm_d=20171030" <==== ATTENTION
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [ycAutoLaunch_8BD45C324E1801E78C906E73D35C9CF9] => C:\Users\jemin\AppData\Local\yc\Application\yc.exe [4018688 2017-10-19] (The Chromium Authors)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [KometaAutoLaunch_99329504B9DDFAA4DB3EFCC619BA3175] => "C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe" --no-startup-window
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GamePark klient 2.lnk [2015-11-05]
ShortcutTarget: GamePark klient 2.lnk -> C:\Program Files\GamePark2\gpcl.exe (Allstar Group, s.r.o.)
Startup: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk [2017-10-30]
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vesmír na dlani.lnk [2014-03-28]
ShortcutTarget: Vesmír na dlani.lnk -> C:\Program Files (x86)\Noční obloha\vesmir.exe (Tošovský Jan)
BootExecute: autocheck autochk * sh4native Sh4Removal
GroupPolicy: Restriction - Chrome <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 176.12.112.2 176.12.112.1
Tcpip\..\Interfaces\{D3772582-8A4C-49F2-A2DC-A95D5181C2B6}: [DhcpNameServer] 176.12.112.2 176.12.112.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B1A42B343-A405-4CD6-81D8-E5685385E0CF%7D&gp=811014
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> {1A366EDE-D70D-49EE-A453-A757CE160C68} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> {5630B555-ECD5-4CB2-89C5-14866469CFC3} URL = hxxp://search.centrum.cz/index.php?utm_source=ch-browser&utm_medium=IE-9&utm_content=searchbox&channel_id=custom-browser,IE-9&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL =
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B1A42B343-A405-4CD6-81D8-E5685385E0CF%7D&gp=811014
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll => No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-05-30] (Oracle Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-11-20] (Google Inc.)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
BHO: Lišta Centrum.cz - pomocný objekt -> {C91BA35D-6516-489F-A203-2992ED9A4132} -> C:\Program Files (x86)\Centrum Holdings s.r.o\Lišta Centrum.cz\cenbho64.dll [2013-01-23] ()
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-05-30] (Oracle Corporation)
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll => No File
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-20] (Google Inc.)
BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
BHO-x32: YoutubeAdBlock -> {C0D38E5A-7CF8-4105-8FE8-31B81443A114} -> C:\Program Files (x86)\ZfJRwqLPhIE\k7zVdU1Vp.dll [2017-10-30] ()
BHO-x32: Lišta Centrum.cz - pomocný objekt -> {C91BA35D-6516-489F-A203-2992ED9A4132} -> C:\Program Files (x86)\Centrum Holdings s.r.o\Lišta Centrum.cz\cenbho32.dll [2013-01-23] ()
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-11-20] (Google Inc.)
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-20] (Google Inc.)
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll No File
Toolbar: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-11-20] (Google Inc.)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-07-18] (Skype Technologies)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-07-20]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-05-30] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-05-30] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\jemin\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3158200304-2993081581-1989350980-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\jemin\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF Plugin HKU\S-1-5-21-3158200304-2993081581-1989350980-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jemin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-09-05] (Unity Technologies ApS)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://mail.ru/cnt/10445?gp=811013
CHR StartupUrls: Default -> "hxxp://mail.ru/cnt/10445?gp=811013"
CHR NewTab: Default -> Active:"chrome-extension://lhemechcanjmilllmccjbjldonmnnjjj/visual-bookmarks.html"
CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B4E8C162F-3EC0-4D69-BFC1-1B7F8F65FF31%7D&gp=811014
CHR DefaultSearchKeyword: Default -> go.mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/ff3?q={searchTerms}
CHR Profile: C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default [2017-10-30]
CHR Extension: (Prezentace) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Dokumenty) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Disk Google) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-24]
CHR Extension: (Mail.Ru) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjhnafpiilpffhglajcaepjbnbjemci [2017-10-30]
CHR Extension: (YouTube) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Adobe Acrobat) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-04]
CHR Extension: (Tabulky) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-24]
CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcadgijmedbfgciegjomfpjcdchlhnif [2017-10-30]
CHR Extension: (Adblocker pro Youtube™) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\knmnopfmccchnnfdoiddbihbcboeedll [2017-10-30]
CHR Extension: (Визуальные Закладки Mail.Ru) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhemechcanjmilllmccjbjldonmnnjjj [2017-10-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (Gmail) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-28]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hcadgijmedbfgciegjomfpjcdchlhnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lhemechcanjmilllmccjbjldonmnnjjj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ABBYY.Licensing.FineReader.Home.10.0; C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\Home\NetworkLicenseServer.exe [814344 2010-07-21] (ABBYY)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2016-07-19] (Freemake) [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319096 2016-01-13] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2015-10-04] (Intel Corporation)
S2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [432088 2015-10-04] (Intel Corporation) [File not signed]
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [590880 2017-09-06] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [271920 2015-10-04] (Nero AG)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation)
R3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-10-12] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460736 2017-10-11] (NVIDIA Corporation)
S3 PAExec; C:\Windows\PAExec.exe [189112 2017-01-28] (Power Admin LLC)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75064 2016-01-03] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [214520 2017-01-31] ()
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [4696960 2016-11-23] (PS Media s.r.o.)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
R2 SvcHost Service Host; C:\Windows\Microsoft\svchost.exe [0 ] () <==== ATTENTION (zero byte File/Folder)
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5467920 2015-10-04] (TeamViewer GmbH) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21584 2013-02-19] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-05-30] (AVG Technologies)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-06-28] (Disc Soft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R1 MpKsl5c8fda79; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKsl5c8fda79.sys [49392 2017-10-30] (Microsoft Corporation)
S1 MpKsl6ad3767b; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKsl6ad3767b.sys [49392 2017-10-30] () [File not signed]
S1 MpKslabc8ce25; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKslabc8ce25.sys [49392 2017-10-30] () [File not signed]
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-10-11] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-08-18] (NVIDIA Corporation)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [21584 2013-05-06] ()
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter\esgiguard.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S1 wfcre; system32\drivers\wfcre.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-10-30 16:18 - 2017-10-30 16:18 - 000027497 _____ C:\Users\jemin\Desktop\FRST.txt
2017-10-30 16:17 - 2017-10-30 16:17 - 002403328 _____ (Farbar) C:\Users\jemin\Desktop\FRST64.exe
2017-10-30 16:16 - 2017-10-30 16:16 - 000015327 _____ C:\Users\jemin\Desktop\LM.bat
2017-10-30 16:14 - 2017-10-30 16:14 - 000112640 _____ (forum.viry.cz) C:\Users\jemin\Desktop\FRSTLauncher.exe
2017-10-30 16:12 - 2017-10-30 16:12 - 283393809 _____ C:\Users\jemin\Desktop\388.13-desktop-win8-win7-64bit-international-whql.exe.uulmsfr.partial
2017-10-30 16:01 - 2017-10-30 16:02 - 008261584 _____ (Malwarebytes) C:\Users\jemin\Desktop\adwcleaner_7.0.4.0.exe
2017-10-30 15:12 - 2017-10-30 15:12 - 001222144 _____ C:\Users\jemin\Desktop\RSITx64.exe
2017-10-30 15:12 - 2017-10-30 15:12 - 000000000 ____D C:\rsit
2017-10-30 15:10 - 2017-10-30 16:16 - 000029696 _____ C:\Users\jemin\AppData\Local\MSGBOX.EXE
2017-10-30 13:08 - 2017-10-30 13:08 - 000000000 ____D C:\Windat
2017-10-30 13:08 - 2017-10-30 13:08 - 000000000 ____D C:\Program Files\LaCie Private Public
2017-10-30 13:08 - 2017-10-30 13:08 - 000000000 ____D C:\Disk
2017-10-30 13:07 - 2017-10-30 16:06 - 000000270 __RSH C:\Users\jemin\ntuser.pol
2017-10-30 13:06 - 2017-10-30 13:06 - 000003700 _____ C:\Windows\System32\Tasks\curl
2017-10-30 13:06 - 2017-10-30 13:06 - 000003500 _____ C:\Windows\System32\Tasks\curls
2017-10-30 13:06 - 2017-10-30 13:06 - 000000000 ____D C:\Users\jemin\AppData\Roaming\curl
2017-10-30 13:05 - 2017-10-30 13:13 - 000000000 ____D C:\Users\jemin\AppData\Local\yc
2017-10-30 13:05 - 2017-10-30 13:07 - 000000000 ____D C:\Users\jemin\AppData\Roaming\Subversion
2017-10-30 13:05 - 2017-10-30 13:05 - 000000000 ____D C:\Users\jemin\AppData\Local\NetBoxLogs
2017-10-30 13:02 - 2017-10-30 15:07 - 000000000 ____D C:\Users\jemin\AppData\Local\ScriptWriter
2017-10-30 13:00 - 2017-10-30 16:04 - 000002378 __RSH C:\ProgramData\ntuser.pol
2017-10-30 13:00 - 2017-10-30 13:00 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\CelGrfgXIrZdI
2017-10-30 13:00 - 2017-10-30 13:00 - 000000000 ____D C:\Program Files (x86)\ZfJRwqLPhIE
2017-10-30 12:58 - 2017-10-30 16:05 - 000000000 ____D C:\Program Files (x86)\Mail.Ru
2017-10-30 12:51 - 2017-10-30 12:51 - 000681696 _____ C:\Windows\Minidump\103017-11996-01.dmp
2017-10-30 12:49 - 2017-10-26 19:38 - 000000000 ___RD C:\Users\jemin\Desktop\CODEX
2017-10-30 12:23 - 2017-10-30 12:23 - 000682024 _____ C:\Windows\Minidump\103017-20841-01.dmp
2017-10-30 09:58 - 2017-10-30 09:58 - 000000000 ____D C:\NVIDIA
2017-10-27 18:24 - 2017-10-27 18:24 - 000000854 _____ C:\Users\jemin\Desktop\Wolfenstein II The New Colossus.lnk
2017-10-27 18:24 - 2017-10-27 18:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfenstein II The New Colossus
2017-10-26 20:50 - 2017-10-26 20:50 - 000000000 ____D C:\Users\jemin\AppData\Local\ELEX
2017-10-26 18:22 - 2017-10-26 18:22 - 000000567 _____ C:\Users\Public\Desktop\ELEX.lnk
2017-10-26 18:22 - 2017-10-26 18:22 - 000000567 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ELEX.lnk
2017-10-26 18:14 - 2017-10-26 18:14 - 000000000 ____D C:\Users\jemin\AppData\Roaming\Burnaware
2017-10-26 18:14 - 2017-10-26 18:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
2017-10-26 18:14 - 2017-10-26 18:14 - 000000000 ____D C:\Program Files (x86)\BurnAware Free
2017-10-23 18:20 - 2017-10-23 18:20 - 000413016 _____ C:\Windows\Minidump\102317-16333-01.dmp
2017-10-23 17:55 - 2017-10-12 22:33 - 040237176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 036185208 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 035156600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 029229504 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 023261256 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 019035344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 016750528 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-10-23 17:55 - 2017-10-12 22:33 - 013863184 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 013251240 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 011777768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 010880856 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 003807864 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 003346368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 001988032 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438800.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 001606592 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438800.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 001135464 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 001098176 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 001030264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000981112 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000932472 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000885496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000615360 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000527288 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000505792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000492048 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000444144 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000407064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000225208 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-10-23 17:55 - 2017-10-12 22:33 - 000171896 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000154392 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000149552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000132256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000045496 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-10-23 17:55 - 2017-10-12 22:33 - 000000669 _____ C:\Windows\system32\nv-vk64.json
2017-10-23 17:30 - 2017-10-11 02:05 - 000050624 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-10-16 18:57 - 2017-10-16 18:57 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\CodeHorizon
2017-10-16 18:56 - 2017-10-16 18:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gold Rush The Game
2017-10-16 16:42 - 2017-10-16 16:42 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-10-16 16:20 - 2017-09-13 16:33 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-10-16 16:20 - 2017-09-13 16:32 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-10-16 16:20 - 2017-09-13 16:32 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-10-16 16:20 - 2017-09-13 16:32 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-10-16 16:20 - 2017-09-13 16:32 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-10-16 16:20 - 2017-09-13 16:31 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:13 - 004001512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-10-16 16:20 - 2017-09-13 16:13 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-10-16 16:20 - 2017-09-13 16:10 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:05 - 000324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2017-10-16 16:20 - 2017-09-13 16:00 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-10-16 16:20 - 2017-09-13 16:00 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-10-16 16:20 - 2017-09-13 16:00 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-10-16 16:20 - 2017-09-13 16:00 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-10-16 16:20 - 2017-09-13 15:57 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-10-16 16:20 - 2017-09-13 15:56 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-10-16 16:20 - 2017-09-13 15:53 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-10-16 16:20 - 2017-09-13 15:53 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-10-16 16:20 - 2017-09-13 15:53 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-10-16 16:20 - 2017-09-13 15:52 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-10-16 16:20 - 2017-09-13 15:52 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-10-16 16:20 - 2017-09-13 15:50 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-10-16 16:20 - 2017-09-13 15:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-10-16 16:20 - 2017-09-13 15:46 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-10-16 16:20 - 2017-09-13 15:46 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-10-16 16:20 - 2017-09-09 01:45 - 000395984 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-10-16 16:20 - 2017-09-09 00:47 - 000347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-10-16 16:20 - 2017-09-08 16:34 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-10-16 16:20 - 2017-09-08 16:30 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-10-16 16:20 - 2017-09-08 16:14 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-10-16 16:20 - 2017-09-08 16:13 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-10-16 16:20 - 2017-09-08 16:13 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-10-16 16:20 - 2017-09-08 16:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-10-16 16:20 - 2017-09-08 16:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-10-16 16:20 - 2017-09-08 16:10 - 000312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-10-16 16:20 - 2017-09-08 16:10 - 000109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-10-16 16:20 - 2017-09-08 16:00 - 003222016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-10-16 16:20 - 2017-09-08 16:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-10-16 16:20 - 2017-09-08 16:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-10-16 16:20 - 2017-09-08 15:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-10-16 16:20 - 2017-09-08 15:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-10-16 16:20 - 2017-09-08 15:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-10-16 16:20 - 2017-09-08 15:20 - 000345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-10-16 16:20 - 2017-09-08 15:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-10-16 16:20 - 2017-09-07 22:38 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-10-16 16:20 - 2017-09-07 22:37 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-10-16 16:20 - 2017-09-07 22:19 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-10-16 16:20 - 2017-09-07 22:18 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-10-16 16:20 - 2017-09-07 22:18 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-10-16 16:20 - 2017-09-07 22:17 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-10-16 16:20 - 2017-09-07 22:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-10-16 16:20 - 2017-09-07 22:15 - 002902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-10-16 16:20 - 2017-09-07 22:08 - 025729536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-10-16 16:20 - 2017-09-07 22:08 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-10-16 16:20 - 2017-09-07 22:07 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-10-16 16:20 - 2017-09-07 22:02 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-10-16 16:20 - 2017-09-07 22:01 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-10-16 16:20 - 2017-09-07 22:01 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-10-16 16:20 - 2017-09-07 22:01 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-10-16 16:20 - 2017-09-07 22:00 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-10-16 16:20 - 2017-09-07 21:52 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-10-16 16:20 - 2017-09-07 21:48 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-10-16 16:20 - 2017-09-07 21:40 - 005982208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-10-16 16:20 - 2017-09-07 21:39 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-10-16 16:20 - 2017-09-07 21:38 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-10-16 16:20 - 2017-09-07 21:37 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-10-16 16:20 - 2017-09-07 21:33 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-10-16 16:20 - 2017-09-07 21:32 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-10-16 16:20 - 2017-09-07 21:29 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-10-16 16:20 - 2017-09-07 21:27 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-10-16 16:20 - 2017-09-07 21:13 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-10-16 16:20 - 2017-09-07 21:10 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-10-16 16:20 - 2017-09-07 21:10 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-10-16 16:20 - 2017-09-07 21:08 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-10-16 16:20 - 2017-09-07 21:08 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-10-16 16:20 - 2017-09-07 20:44 - 015262720 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-10-16 16:20 - 2017-09-07 20:40 - 003240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-10-16 16:20 - 2017-09-07 20:27 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-10-16 16:20 - 2017-09-07 20:27 - 001548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-10-16 16:20 - 2017-09-07 20:17 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-10-16 16:20 - 2017-09-07 20:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-10-16 16:20 - 2017-09-07 20:10 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-10-16 16:20 - 2017-09-07 20:10 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-10-16 16:20 - 2017-09-07 20:10 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-10-16 16:20 - 2017-09-07 20:09 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-10-16 16:20 - 2017-09-07 20:04 - 020267008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-10-16 16:20 - 2017-09-07 20:03 - 002292736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-10-16 16:20 - 2017-09-07 20:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-10-16 16:20 - 2017-09-07 20:02 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-10-16 16:20 - 2017-09-07 19:59 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-10-16 16:20 - 2017-09-07 19:58 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-10-16 16:20 - 2017-09-07 19:58 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-10-16 16:20 - 2017-09-07 19:58 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-10-16 16:20 - 2017-09-07 19:49 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-10-16 16:20 - 2017-09-07 19:44 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-10-16 16:20 - 2017-09-07 19:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-10-16 16:20 - 2017-09-07 19:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-10-16 16:20 - 2017-09-07 19:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-10-16 16:20 - 2017-09-07 19:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-10-16 16:20 - 2017-09-07 19:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-10-16 16:20 - 2017-09-07 19:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-10-16 16:20 - 2017-09-07 19:29 - 004547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-10-16 16:20 - 2017-09-07 19:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-10-16 16:20 - 2017-09-07 19:26 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-10-16 16:20 - 2017-09-07 19:25 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-10-16 16:20 - 2017-09-07 19:25 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-10-16 16:20 - 2017-09-07 19:17 - 013677568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-10-16 16:20 - 2017-09-07 19:01 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-10-16 16:20 - 2017-09-07 18:57 - 001316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-10-16 16:20 - 2017-09-07 18:57 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-10-16 16:20 - 2017-09-07 16:31 - 002851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2017-10-16 16:20 - 2017-09-07 16:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2017-10-16 16:20 - 2017-09-07 15:55 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-10-16 16:20 - 2017-09-07 15:55 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-10-16 16:20 - 2017-09-07 15:55 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-10-16 16:20 - 2017-08-19 16:28 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-10-16 16:20 - 2017-08-19 16:28 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-10-16 16:20 - 2017-08-19 16:28 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2017-10-16 16:20 - 2017-08-19 16:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-10-16 16:20 - 2017-08-19 16:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2017-10-16 16:20 - 2017-08-19 16:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2017-10-16 16:20 - 2017-08-19 16:08 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2017-10-16 16:20 - 2017-08-19 16:08 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2017-10-16 16:20 - 2017-08-19 15:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2017-10-16 16:20 - 2017-08-19 15:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2017-10-16 16:20 - 2017-08-14 18:35 - 001032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-10-16 16:20 - 2017-08-14 18:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-10-16 16:20 - 2017-08-14 18:35 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2017-10-16 16:20 - 2017-08-13 22:46 - 001112576 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-10-16 16:20 - 2017-08-13 22:45 - 000162816 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-10-16 16:20 - 2017-08-13 22:45 - 000040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2017-10-16 16:20 - 2017-08-13 22:45 - 000020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2017-10-13 20:43 - 2017-10-13 20:43 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\JetCat Games
2017-10-13 20:28 - 2017-10-13 20:28 - 000000599 _____ C:\Users\Public\Desktop\Heliborne.lnk
2017-10-13 20:28 - 2017-10-13 20:28 - 000000599 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heliborne.lnk
2017-10-13 18:24 - 2017-10-13 18:24 - 000001138 _____ C:\Users\Public\Desktop\Middle Earth - Shadow of War.lnk
2017-10-13 17:07 - 2017-10-13 17:07 - 000000000 ____D C:\Users\jemin\AppData\Local\TangoGameworks
2017-10-13 16:49 - 2017-10-13 16:49 - 000000741 _____ C:\Users\jemin\Desktop\The Evil Within 2.lnk
2017-10-13 16:49 - 2017-10-13 16:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Evil Within 2
2017-10-05 07:29 - 2017-10-05 07:29 - 000000000 ____D C:\Users\jemin\Documents\Road Redemption
2017-10-05 07:29 - 2017-10-05 07:29 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\Dark Seas Interactive
2017-10-05 05:30 - 2017-10-05 05:30 - 000000662 _____ C:\Users\Public\Desktop\FIFA18.lnk
2017-10-05 05:30 - 2017-10-05 05:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA18
2017-10-05 04:51 - 2017-10-05 04:58 - 000000000 ____D C:\Users\jemin\Documents\Project CARS 2
2017-10-05 04:51 - 2017-10-05 04:51 - 000000000 ____D C:\ProgramData\Slightly Mad Studios
2017-10-05 04:44 - 2017-10-05 04:44 - 000000734 _____ C:\Users\jemin\Desktop\Project CARS 2.lnk
2017-10-05 04:44 - 2017-10-05 04:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project CARS 2
2017-10-04 06:21 - 2017-09-16 20:23 - 001988216 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438569.dll
2017-10-04 06:21 - 2017-09-16 20:23 - 001606592 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438569.dll
2017-10-04 05:47 - 2017-10-05 06:18 - 000000000 ____D C:\Users\jemin\Documents\FIFA 18
2017-10-02 20:55 - 2017-10-02 20:55 - 000000359 _____ C:\Users\jemin\Desktop\Počítač – zástupce.lnk

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-10-30 16:18 - 2015-10-01 18:15 - 000000000 ____D C:\FRST
2017-10-30 16:14 - 2009-07-14 05:45 - 000020192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-10-30 16:14 - 2009-07-14 05:45 - 000020192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-10-30 16:12 - 2009-07-26 19:41 - 000669904 _____ C:\Windows\system32\perfh005.dat
2017-10-30 16:12 - 2009-07-26 19:41 - 000142062 _____ C:\Windows\system32\perfc005.dat
2017-10-30 16:12 - 2009-07-14 06:13 - 001587976 _____ C:\Windows\system32\PerfStringBackup.INI
2017-10-30 16:12 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2017-10-30 16:09 - 2014-03-20 15:53 - 000000000 ____D C:\Users\jemin\AppData\Roaming\Skype
2017-10-30 16:06 - 2017-07-22 21:24 - 000000000 ____D C:\Program Files (x86)\Steam
2017-10-30 16:06 - 2017-01-28 07:32 - 000000000 ____D C:\ProgramData\NVIDIA
2017-10-30 16:06 - 2015-09-24 06:14 - 000000000 __SHD C:\Users\jemin\IntelGraphicsProfiles
2017-10-30 16:06 - 2014-11-18 15:56 - 000000000 ____D C:\Users\jemin\Documents\Assassin's Creed Unity
2017-10-30 16:06 - 2014-03-20 14:14 - 000003138 _____ C:\Windows\System32\Tasks\FRAPS
2017-10-30 16:06 - 2014-03-20 14:14 - 000000000 ____D C:\Fraps
2017-10-30 16:06 - 2014-03-18 16:12 - 000000000 ____D C:\Users\jemin
2017-10-30 16:06 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-10-30 16:05 - 2014-05-10 16:37 - 000000000 ____D C:\AdwCleaner
2017-10-30 15:15 - 2016-06-25 05:36 - 000000000 ____D C:\Program Files\trend micro
2017-10-30 13:00 - 2009-07-14 04:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2017-10-30 12:51 - 2014-04-11 18:06 - 000000000 ____D C:\Windows\Minidump
2017-10-30 12:42 - 2014-03-20 14:08 - 000000000 ____D C:\ProgramData\Package Cache
2017-10-30 12:20 - 2017-01-28 07:32 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-10-30 12:20 - 2017-01-28 07:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-10-30 10:44 - 2014-03-23 15:59 - 000003970 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{6E8F5136-D671-44DD-8634-E280556768FA}
2017-10-27 18:33 - 2017-01-28 07:34 - 000000000 ____D C:\Users\jemin\AppData\Local\NVIDIA
2017-10-27 03:46 - 2017-04-21 21:03 - 000000000 ____D C:\Program Files (x86)\McAfee
2017-10-26 18:14 - 2016-08-18 18:16 - 000000000 ____D C:\ProgramData\McAfee
2017-10-26 04:57 - 2017-04-19 18:55 - 000000000 ____D C:\Users\jemin\Documents\poruce
2017-10-25 18:42 - 2015-10-05 20:03 - 000004396 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-10-25 18:42 - 2015-04-16 11:58 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-10-25 18:42 - 2015-04-16 11:58 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-25 18:42 - 2014-03-20 14:13 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-10-25 18:42 - 2014-03-20 14:13 - 000000000 ____D C:\Windows\system32\Macromed
2017-10-23 18:20 - 2017-01-28 07:32 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-10-23 17:56 - 2017-02-20 16:21 - 000000000 ____D C:\Users\jemin\AppData\Roaming\NVIDIA
2017-10-23 17:56 - 2017-01-28 07:30 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-10-23 17:31 - 2017-08-23 18:16 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:31 - 2017-01-28 07:32 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 08:49 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-19 19:03 - 2014-03-20 15:55 - 000000000 ____D C:\Users\jemin\AppData\Roaming\vlc
2017-10-16 22:25 - 2014-03-18 16:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2017-10-16 21:09 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache
2017-10-16 17:40 - 2009-07-14 05:45 - 000418504 _____ C:\Windows\system32\FNTCACHE.DAT
2017-10-16 16:44 - 2014-03-18 17:27 - 000000000 ____D C:\Windows\system32\MRT
2017-10-16 16:42 - 2014-03-18 17:27 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-10-15 12:38 - 2009-07-14 06:08 - 000032626 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-10-13 18:53 - 2015-08-01 10:41 - 000000000 ____D C:\Users\jemin\Documents\WB Games
2017-10-12 22:33 - 2017-04-19 17:07 - 018203640 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2017-10-12 22:33 - 2017-01-28 07:31 - 021738976 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2017-10-12 22:33 - 2017-01-28 07:31 - 019008952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2017-10-12 22:33 - 2017-01-28 07:31 - 015024912 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2017-10-12 22:33 - 2017-01-28 07:31 - 004283120 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2017-10-12 22:33 - 2017-01-28 07:31 - 003796776 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-10-12 22:33 - 2017-01-28 07:31 - 001615472 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2017-10-12 22:33 - 2017-01-28 07:31 - 000046182 _____ C:\Windows\system32\nvinfo.pb
2017-10-12 21:25 - 2016-09-17 06:17 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2017-10-12 20:55 - 2017-01-28 07:32 - 005960824 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 002587584 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 001766520 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 000607352 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 000449472 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 000122816 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 000081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2017-10-12 20:54 - 2017-01-28 07:32 - 007799931 _____ C:\Windows\system32\nvcoproc.bin
2017-10-11 02:05 - 2017-01-28 08:49 - 000186304 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-10-11 02:05 - 2017-01-28 08:49 - 000152512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-10-11 02:05 - 2017-01-28 07:32 - 001796032 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-10-11 02:05 - 2017-01-28 07:32 - 001577920 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-10-11 02:05 - 2017-01-28 07:32 - 000918976 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2017-10-11 00:26 - 2017-01-28 08:49 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2017-10-04 06:31 - 2014-03-20 14:30 - 000000000 ____D C:\Users\jemin\AppData\Local\CrashDumps
2017-10-03 05:30 - 2014-03-30 06:38 - 000000000 ____D C:\Users\jemin\Documents\My Games
2017-10-03 04:08 - 2015-05-22 18:03 - 000000111 _____ C:\Users\jemin\Documents\hesla.txt
2017-10-02 20:56 - 2015-05-20 14:49 - 000000000 ____D C:\Games
2017-10-02 20:56 - 2015-03-03 14:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-10-02 20:56 - 2009-07-14 06:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games

==================== Files in the root of some directories =======

2014-03-20 18:44 - 2014-03-20 18:45 - 000000156 _____ () C:\Users\jemin\AppData\Roaming\default.rss
2014-10-08 15:49 - 2014-05-24 20:09 - 000042496 ___SH (Open Source Software community project) C:\Users\jemin\AppData\Roaming\pthreadGC2-w64.dll
2014-03-29 08:04 - 2017-07-12 19:26 - 000061952 _____ () C:\Users\jemin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-10-30 15:10 - 2017-10-30 16:16 - 000029696 _____ () C:\Users\jemin\AppData\Local\MSGBOX.EXE
2014-05-30 06:41 - 2014-06-02 05:48 - 000007618 _____ () C:\Users\jemin\AppData\Local\Resmon.ResmonCfg
2014-03-31 14:50 - 2014-03-31 14:50 - 000000080 _____ () C:\Users\jemin\AppData\Local\X-Plane Installer.prf
2017-04-06 06:41 - 2017-04-06 12:21 - 000000015 _____ () C:\Users\jemin\AppData\Local\X-Plane_drm_11.prf
2014-03-31 14:28 - 2014-03-31 14:28 - 000000020 _____ () C:\Users\jemin\AppData\Local\x-plane_install_10.txt
2017-04-06 06:38 - 2017-04-06 06:38 - 000000036 _____ () C:\Users\jemin\AppData\Local\x-plane_install_11.txt
2014-05-21 13:50 - 2014-05-21 13:50 - 000000057 _____ () C:\ProgramData\Ament.ini
2015-09-24 07:01 - 2015-09-24 07:01 - 000000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
2017-10-30 13:01 - 2017-10-30 13:01 - 002200968 _____ () C:\Users\jemin\AppData\Local\Temp\1IeTCUgoOq1i.exe
2017-10-30 13:10 - 2017-10-30 13:10 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\3iwWhHsPgNwO.exe
2017-10-30 13:10 - 2017-10-30 13:10 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\4MqZZN0MvElH.exe
2017-10-30 16:04 - 2017-10-30 15:06 - 000816112 _____ () C:\Users\jemin\AppData\Local\Temp\68C1.tmp.exe
2017-10-30 13:08 - 2017-10-30 13:08 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\6OyQjVwv2jEm.exe
2017-10-30 13:06 - 2017-10-30 13:06 - 064938720 _____ (Kometa LCC) C:\Users\jemin\AppData\Local\Temp\7s76s5uzd2nY.exe
2017-10-30 16:03 - 2017-10-30 15:06 - 000816112 _____ () C:\Users\jemin\AppData\Local\Temp\A8DC.tmp.exe
2017-10-30 13:10 - 2017-10-30 13:10 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\be8sQYgWeNnu.exe
2017-10-30 13:07 - 2017-10-30 13:07 - 002643640 _____ () C:\Users\jemin\AppData\Local\Temp\c0.tmp.exe
2017-10-30 13:14 - 2017-10-30 13:05 - 000795632 _____ () C:\Users\jemin\AppData\Local\Temp\C245.tmp.exe
2017-10-30 12:58 - 2017-10-30 12:58 - 002643640 _____ () C:\Users\jemin\AppData\Local\Temp\dDYEwABPUttv.exe
2017-10-30 13:11 - 2017-10-30 13:11 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\EIMrKiNpkUcj.exe
2017-10-30 13:10 - 2017-10-30 13:10 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\EkJTG9DB0WE7.exe
2017-10-30 13:00 - 2017-10-30 13:00 - 002318970 _____ () C:\Users\jemin\AppData\Local\Temp\gbe2PVZKXGjY.exe
2017-10-30 13:06 - 2017-10-30 13:06 - 000192000 _____ () C:\Users\jemin\AppData\Local\Temp\hBaiGNiffTKf.exe
2017-10-30 13:11 - 2017-10-30 13:11 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\i6kdd1EZEuZc.exe
2017-10-30 13:12 - 2017-10-30 13:12 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\JE5AAwttqrlm.exe
2017-10-30 13:10 - 2017-10-30 13:10 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\jI7G2764OWfL.exe
2017-10-30 13:04 - 2017-10-30 13:04 - 064938720 _____ (Kometa LCC) C:\Users\jemin\AppData\Local\Temp\M7oALalR3EVV.exe
2017-10-30 13:04 - 2017-10-30 13:04 - 000192000 _____ () C:\Users\jemin\AppData\Local\Temp\mKo21cwZTzFK.exe
2017-10-30 12:59 - 2017-10-30 13:00 - 002318970 _____ () C:\Users\jemin\AppData\Local\Temp\N2KEV1x6SNMx.exe
2017-10-23 17:56 - 2017-10-12 20:59 - 000760032 _____ (NVIDIA Corporation) C:\Users\jemin\AppData\Local\Temp\nvSCPAPI.dll
2017-10-23 17:56 - 2017-10-12 20:59 - 000874184 _____ (NVIDIA Corporation) C:\Users\jemin\AppData\Local\Temp\nvSCPAPI64.dll
2017-10-30 12:20 - 2017-10-12 20:59 - 000370112 _____ (NVIDIA Corporation) C:\Users\jemin\AppData\Local\Temp\nvStInst.exe
2017-10-30 13:05 - 2017-10-30 13:05 - 064938720 _____ (Kometa LCC) C:\Users\jemin\AppData\Local\Temp\pAf7cQivizFy.exe
2017-10-30 13:12 - 2017-10-30 13:12 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\pckJNLI8ejuI.exe
2017-10-30 13:07 - 2017-10-30 13:07 - 038316032 _____ (The Chromium Authors) C:\Users\jemin\AppData\Local\Temp\qLi0cVLqx7Z4.exe
2017-10-30 13:09 - 2017-10-30 13:09 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\qpwRYl3xEwuU.exe
2017-10-30 13:05 - 2017-10-30 13:05 - 038316032 _____ (The Chromium Authors) C:\Users\jemin\AppData\Local\Temp\Qui5KbaJHaNK.exe
2017-10-30 13:09 - 2017-10-30 13:09 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\qWFbarFSev69.exe
2017-10-30 13:09 - 2017-10-30 13:09 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\Rq7ZFelEjBCG.exe
2017-10-30 13:08 - 2017-10-30 13:08 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\SqwYFeQmGeAz.exe
2017-10-30 13:00 - 2017-10-30 13:00 - 002200968 _____ () C:\Users\jemin\AppData\Local\Temp\t6R4griumtsp.exe
2017-10-30 13:03 - 2017-10-30 13:03 - 002200968 _____ () C:\Users\jemin\AppData\Local\Temp\tNNOHa6fXfIC.exe
2017-10-30 13:11 - 2017-10-30 13:11 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\xAUw8vkYLxcr.exe
2017-10-30 13:11 - 2017-10-30 13:11 - 001795072 ____N () C:\Users\jemin\AppData\Local\Temp\yhfAi5tOiGje.exe
2017-10-30 13:09 - 2017-10-30 13:09 - 038316032 ____N (The Chromium Authors) C:\Users\jemin\AppData\Local\Temp\yK7hMgKlFzVX.exe
2017-10-30 13:07 - 2017-10-30 13:07 - 001884881 _____ ( ) C:\Users\jemin\AppData\Local\Temp\YyliUPV7PU6b.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-10-30 00:55

==================== End of FRST.txt ============================

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 30 říj 2017 16:21
od ebola
zde druhý -Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2017
Ran by jemin (30-10-2017 16:18:25)
Running from C:\Users\jemin\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2014-03-18 15:12:06)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3158200304-2993081581-1989350980-500 - Administrator - Disabled)
Guest (S-1-5-21-3158200304-2993081581-1989350980-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3158200304-2993081581-1989350980-1002 - Limited - Enabled)
jemin (S-1-5-21-3158200304-2993081581-1989350980-1000 - Administrator - Enabled) => C:\Users\jemin

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Disabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Disabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

«Alan Wake`s American Nightmare» 1.0 (HKLM-x32\...\Alan Wake`s American Nightmare_is1) (Version: 1.0 - R.G. Catalyst)
3GP Player 1.1.7 (HKLM-x32\...\3GP Player_is1) (Version: - Bobabo)
3Planesoft Screensaver Manager 1.4 (HKLM-x32\...\3Planesoft Screensaver Manager_is1) (Version: 1.4 - 3Planesoft)
7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
ABBYY FineReader 10 Home Edition (HKLM-x32\...\{F1000000-0012-0000-0000-074957833700}) (Version: 10.00.91.8953 - ABBYY)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated)
Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.183 - Adobe Systems Incorporated)
Aktualizace NVIDIA 29.1.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 29.1.0.0 - NVIDIA Corporation) Hidden
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISER_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISER_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISER_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Alternative Look for Triss (HKLM-x32\...\Alternative Look for Triss_is1) (Version: 1.0.0.0 - GOG.com)
Alternative Look for Yennefer (HKLM-x32\...\Alternative Look for Yennefer_is1) (Version: 1.0.0.0 - GOG.com)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 388.00 - NVIDIA Corporation) Hidden
AoA Audio Extractor (HKLM-x32\...\{D1725D54-279A-40C5-A70D-23C1785DB920}_is1) (Version: - AoAMedia.com)
Ballad Heroes - Neutral Gwent Card Set (HKLM-x32\...\Ballad Heroes - Neutral Gwent Card Set_is1) (Version: 1.0.0.0 - GOG.com)
Beard and Hairstyle Set (HKLM-x32\...\Beard and Hairstyle Set_is1) (Version: 1.0.0.0 - GOG.com)
Bing Bar (HKLM-x32\...\{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation)
BitTorrent (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\BitTorrent) (Version: 7.9.2.34312 - BitTorrent Inc.)
Broken Sword 5 (HKLM-x32\...\Broken Sword 5_is1) (Version: - Revolution Software Ltd)
BurnAware Free 10.6 (HKLM-x32\...\BurnAware Free_is1) (Version: - Burnaware)
Call of Duty(R) 2 (HKLM-x32\...\{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.00.0000 - Activision) Hidden
Call of Duty(R) 2 (HKLM-x32\...\InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.00.0000 - Activision)
Call of Duty(R) 2 Patch 1.3 (HKLM-x32\...\{C13E90B0-4E1C-11DB-6784-0152EAA218BE}) (Version: 1.3 - Activision)
Call of Duty: Infinite Warfare (HKLM\...\Y2FsbG9mZHV0eWluZmluaXRld2FyZmFyZQ_is1) (Version: 1 - )
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
CCleaner (HKLM-x32\...\CCleaner) (Version: 2.36 - Piriform)
CoD 2 čeština 1.1 (HKLM-x32\...\CoD 2 čeština_is1) (Version: - #'Pan[S[al!er!)
CPUID CPU-Z 1.71.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts)
Cuckoo Clock 3D Screensaver 1.0 (HKLM-x32\...\Cuckoo Clock 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 5.5.0.0387 - Disc Soft Ltd)
Depth Hunter 2 - Deep Dive (HKLM-x32\...\Depth Hunter 2 - Deep Dive_is1) (Version: - )
DROPCLOCK 1.0.1 (HKLM-x32\...\DROPCLOCK_is1) (Version: - tha ltd.)
ELEX (HKLM\...\ZWxleA_is1) (Version: 1 - )
Euro Fishing (HKLM-x32\...\Euro Fishing_is1) (Version: - )
Far Cry 4 Update v1.7 (HKLM-x32\...\RmFyQ3J5NA==_is1) (Version: 1 - )
Far Cry Primal (HKLM-x32\...\Far Cry Primal_R.G. Mechanics_is1) (Version: - R.G. Mechanics, Panky)
Farm Expert 2016 - Fruit Company (HKLM-x32\...\Farm Expert 2016 - Fruit Company_is1) (Version: - )
FIFA18 version 1.0 (HKLM\...\FIFA18_is1) (Version: 1.0 - STEAMPUNKS) <==== ATTENTION
FileZilla Client 3.17.0.1 (HKLM-x32\...\FileZilla Client) (Version: 3.17.0.1 - Tim Kosse)
Fireside Christmas 3D Screensaver 1.0 (HKLM-x32\...\Fireside Christmas 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
Fireside Christmas 3D Screensaver and Animated Wallpaper 1.1 (HKLM-x32\...\Fireside Christmas 3D Screensaver and Animated Wallpaper_is1) (Version: 1.1 - 3Planesoft)
Fraps (HKLM-x32\...\Fraps) (Version: - )
Freemake Video Converter verze 4.1.9 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.9 - Ellora Assets Corporation)
Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.15.0 - Futuremark Corporation)
Gameforge Live 2.0.5 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.5 - Gameforge)
GamePark klient 2.0.9.0 (HKLM\...\{52E5D8A7-B129-4A29-AD4B-EBB749DCC3A3}_is1) (Version: 2.0.9.0 - GamePark)
Google Drive (HKLM-x32\...\{AC117AF9-316B-4E1D-959E-F0EB85B0DC5F}) (Version: 2.34.7100.0000 - Google, Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto V (HKLM-x32\...\R3JhbmRUaGVmdEF1dG9W_is1) (Version: 1 - )
Gwent (HKLM-x32\...\1971477531_is1) (Version: 2.0.0.3 - GOG.com)
Heliborne (HKLM\...\aGVsaWJvcm5l_is1) (Version: 1 - )
Hellblade: Senua's Sacrifice (HKLM\...\aGVsbGJsYWRlc2VudWFzc2FjcmlmaWNl_is1) (Version: 1 - )
HP Deskjet 3520 series Nápověda (HKLM-x32\...\{D259C419-D776-4163-B27C-19722C555237}) (Version: 27.0.0 - Hewlett Packard)
HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Photo Creations (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\HP Photo Creations) (Version: 1.0.0.18702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\...\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
Christmas Bells 3D Screensaver 1.0 (HKLM-x32\...\Christmas Bells 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4358 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.4.51 - Intel Corporation)
Java 7 Update 55 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417055FF}) (Version: 7.0.550 - Oracle)
Kings Bounty Dark Side (HKLM-x32\...\Kings Bounty Dark Side_is1) (Version: - )
King's Bounty Dark Side (HKLM-x32\...\King's Bounty Dark Side_R.G. Gamblers_is1) (Version: - R.G. Gamblers, Fanfar)
K-Lite Mega Codec Pack 10.3.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.3.5 - )
Lišta Centrum.cz (HKLM-x32\...\{6533CC5B-8474-4E6E-A5DB-CAC502DA7C86}) (Version: 1.1.2.0 - Centrum Holdings s.r.o.)
Logitech Gaming Software 5.09 (HKLM\...\{84057C9C-2F85-4C67-A035-FD75FFE2DE88}) (Version: 5.09.131 - Logitech)
Mafia III (HKLM-x32\...\Mafia III_is1) (Version: - )
Mariáš 3.1 (HKLM-x32\...\{BA58C040-B206-41BB-92CF-D0A2975477BB}) (Version: 3.1.0 - Ganttsoft)
Matrix Mania 1.0 (HKLM-x32\...\{07D31340-4956-46EA-8CD2-7A7D3925BAC2}) (Version: 1.0 - ff Softworks Company)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.161 - McAfee, Inc.)
Metin2 (HKLM-x32\...\Metin2_is1) (Version: - Gameforge 4D GmbH)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{59E4543A-D49D-4489-B445-473D763C79AF}) (Version: 2.0.672.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Middle Earth: Shadow of War - Gold Edition version 1.0 (HKLM-x32\...\{C773C2DD-9924-4748-B51D-442E5334C113}_is1) (Version: 1.0 - )
Mortal Kombat X (HKLM\...\bW9ydGFsa29tYmF0eA_is1) (Version: 1 - )
Mortal Kombat X Premium Edition v.1.0 (HKLM-x32\...\Mortal Kombat X Premium Edition_is1) (Version: - )
Mortal Kombat X Update 20150709 (HKLM-x32\...\TW9ydGFsS29tYmF0WA==_is1) (Version: 1 - )
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MX Nitro (HKLM-x32\...\MX Nitro_is1) (Version: - )
My Program version 1.5 (HKLM-x32\...\My Program_is1) (Version: 1.5 - )
Need For Speed Rivals (HKLM-x32\...\{0657F865-25B6-4391-A3B5-9917CF291AB3}) (Version: 6.0 - Black Box)
Need for Speed Rivals Update v1.4 (HKLM-x32\...\TmVlZGZvclNwZWVkUml2YWxz_is1) (Version: 1 - )
Need for Speed™ Rivals (HKLM-x32\...\{E0A32336-AA27-4053-99B2-C3380B7B95AC}) (Version: 1.3.0.0 - Electronic Arts)
Nero 7 Ultra Edition (HKLM-x32\...\{4F2CE68F-EDBB-4592-BF07-5AC930A51029}) (Version: 7.02.6446 - Nero AG)
Nero Backup Drivers (HKLM\...\{D600D357-5CB9-4DE9-8FD4-14E208BD1970}) (Version: 1.0.10000.1.0 - Nero AG)
New Quest - Contract - Skellige's Most Wanted (HKLM-x32\...\New Quest - Contract: Skellige's Most Wanted_is1) (Version: 1.0.0.0 - GOG.com)
New Quest - Contract Missing Miners (HKLM-x32\...\New Quest - Contract Missing Miners_is1) (Version: 1.0.0.0 - GOG.com)
New Quest - Fool's Gold (HKLM-x32\...\New Quest - Fool's Gold_is1) (Version: 1.0.0.0 - GOG.com)
New Quest - Scavenger Hunt - Wolf School Gear (HKLM-x32\...\New Quest - Scavenger Hunt: Wolf School Gear_is1) (Version: 1.0.0.0 - GOG.com)
New Quest - Where the Cat and Wolf Play... (HKLM-x32\...\New Quest - Where the Cat and Wolf Play..._is1) (Version: 1.0.0.0 - GOG.com)
Noční obloha 1.5 (HKLM-x32\...\Noční obloha_is1) (Version: - )
NVIDIA GeForce Experience 3.10.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.10.0.95 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.35.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.35.1 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 388.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.00 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
ON_OFF Charge 2 B13.0910.1 (HKLM-x32\...\{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) Hidden
ON_OFF Charge 2 B13.0910.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Orca (HKLM-x32\...\{85F4CBCB-9BBC-4B50-A7D8-E1106771498D}) (Version: 3.1.3790.0000 - Microsoft Corporation)
Ori and the Blind Forest (HKLM-x32\...\Ori and the Blind Forest_is1) (Version: - )
Outlast 2 (HKLM-x32\...\Outlast 2_is1) (Version: - )
Ovládací panel NVIDIA 388.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.00 - NVIDIA Corporation) Hidden
Photo Notifier and Animation Creator (HKLM-x32\...\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.)
Polda 6 verze 1.0 (HKLM-x32\...\Polda 6_is1) (Version: 1.0 - Centauri production)
Posel Smrti 3 (HKLM-x32\...\Posel Smrti 3_is1) (Version: 1.0 - TopQer, s.r.o.)
Pressure Overdrive (HKLM-x32\...\Pressure Overdrive_is1) (Version: - )
Prey (HKLM-x32\...\Prey_is1) (Version: - )
Princezna a žabák (HKLM-x32\...\{DE5ECBF6-8A4A-4855-98D0-D6576145EBFF}) (Version: 1.00.0000 - Disney Interactive Studios)
Program Killer (HKLM-x32\...\{0E93A023-62F0-44BE-ABCA-953AB1FA409B}) (Version: 1.0.0 - DOKSoft.com / IPKomarov.ru)
Pure (HKLM\...\{FF3C203A-2F19-43A2-9C7C-EC1B5A0FC873}) (Version: 1.0 - Disney Interactive Studios)
Pure (HKLM-x32\...\{FF3C203A-2F19-43A2-9C7C-EC1B5A0FC873}) (Version: 1.0 - Disney Interactive Studios)
QuadcoreM2 (HKLM-x32\...\{101F30DF-3204-473B-A0DD-037A53983DEA}) (Version: 1.12.2012 - Quadcore Games) Hidden
QuadcoreM2 (HKLM-x32\...\QuadcoreM2 1.12.2012) (Version: 1.12.2012 - Quadcore Games)
Rainy Screensaver 2.2.17 (HKLM-x32\...\{EA94A9DF-0E66-4749-880A-637CDF37B61E}) (Version: - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.65.1025.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7503 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
Resident Evil 7 Biohazard (HKLM-x32\...\{1ECBF8F3-7079-44CA-AD32-B2AECBCF636F}_is1) (Version: - Capcom)
Rise of the Tomb Raider - Digital Deluxe Edition verze 1.0.668.1 (HKLM-x32\...\{B7A2BD94-E7DE-40F3-9B79-F46474F4AF8D}_is1) (Version: 1.0.668.1 - )
Rockstar Games Social Club (HKLM-x32\...\{08B3869E-D282-424C-9AFC-870E04A4BA14}) (Version: 1.00.0000 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games)
Rosso Rabbit in Trouble (HKLM-x32\...\Rosso Rabbit in Trouble) (Version: - )
Samsung Content Viewer (HKLM-x32\...\{980DDB3E-8957-4750-98EB-5D04F61CCEDC}) (Version: 1.0.2 - Samsung) Hidden
Samsung Content Viewer (HKLM-x32\...\InstallShield_{980DDB3E-8957-4750-98EB-5D04F61CCEDC}) (Version: 1.0.2 - Samsung)
Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.)
Santa Claus 3D Screensaver 1.0 (HKLM-x32\...\Santa Claus 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
Seznam Instalátor (HKLM-x32\...\ssinstall) (Version: - Seznam.cz)
Shadow Tactics - Blades of the Shogun 1.2.1 (HKLM-x32\...\{BB762706-65FA-44C1-B2BB-EF29CA88D7CE}_is1) (Version: 1.2.1 - Daedalic Entertainment GmbH)
Shadow Tactics: Blades of the Shogun SK verzia 0.99 (HKLM-x32\...\Shadow Tactics: Blades of the Shogun SK_is1) (Version: 0.99 - )
Sherlock Holmes - The Devil's Daughter (HKLM-x32\...\{958958D4-484A-4C90-9AB4-88977BE9EBED}_is1) (Version: - Frogwares)
Skellige Armor Set (HKLM-x32\...\Skellige Armor Set_is1) (Version: 1.0.0.0 - GOG.com)
Ski Challenge 14 (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\sc14-GAMETWIST_MAIN) (Version: - )
Ski Challenge 16 (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\sc16-GAMETWIST_MAIN) (Version: - )
Skispringen 2007 (HKLM-x32\...\Skispringen 2007_0001) (Version: - )
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
SlimCleaner Plus (HKLM\...\{C66FE9B8-B7BC-4FBE-A8F9-BB979EFBA47F}) (Version: 2.2.2 - SlimWare Utilities, Inc.)
SpyHunter (HKLM-x32\...\{B95599E4-61B5-4589-B495-CC0E35A4DC05}) (Version: 1.0.0 - Enigma Software Group) Hidden
SpyHunter (HKLM-x32\...\SpyHunter 1.0.0) (Version: 1.0.0 - Enigma Software Group)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
STEEP (HKLM-x32\...\Uplay Install 3445) (Version: - Ubisoft)
Studie vylepšování produktu HP Deskjet 3520 series (HKLM\...\{B7AED02F-7D1B-4806-831B-C06841A282C4}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Super Ovladač (HKLM-x32\...\Super Ovladač_is1) (Version: 10.0 - Driver-Soft Inc.)
Svátky a výročí (HKLM-x32\...\{CB28705C-ED60-499A-90DE-E8BC41F75B65}) (Version: 2.09.0115 - Igor Gottwald - OKsoftware)
Syberia 3 (HKLM-x32\...\Syberia 3_is1) (Version: - )
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp)
Temerian Armor Set (HKLM-x32\...\Temerian Armor Set_is1) (Version: 1.0.0.0 - GOG.com)
The Sims 4 (HKLM-x32\...\The Sims 4_is1) (Version: - )
The Witcher 3 Wild Hunt (HKLM-x32\...\The Witcher 3 Wild Hunt_is1) (Version: 1.21 - RePack by Valdeni)
The Witcher 3: Wild Hunt - Alternative Look for Ciri (HKLM-x32\...\Alternative Look for Ciri_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - New Finisher Animations (HKLM-x32\...\New Finisher Animations_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt (Not-cracked Repack) (HKLM-x32\...\The Witcher 3: Wild Hunt (Not-cracked Repack)_is1) (Version: - )
Tom Clancy's Ghost Recon Wildlands (HKLM\...\Tom Clancys Ghost Recon Wildlands_is1) (Version: 1.0 - )
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.50 - Ghisler Software GmbH)
Toy Story 3 (HKLM-x32\...\{AAFD160A-2333-40D8-AA25-42D1989CA0F2}) (Version: 1.00.0000 - Disney Interactive Studios)
Trine 3 The Artifacts of Power (HKLM-x32\...\Trine 3 The Artifacts of Power_is1) (Version: - )
Tux Racer (HKLM-x32\...\{F49F7B74-71A2-44C2-AB2B-F02812B409BD}) (Version: 1.01.0000 - Sunspire Studios) Hidden
Tux Racer (HKLM-x32\...\InstallShield_{F49F7B74-71A2-44C2-AB2B-F02812B409BD}) (Version: 1.01.0000 - Sunspire Studios)
UE4 Prerequisites (x64) (HKLM\...\{DC9D63C3-E5D5-4DA2-8141-2435DE3B6C90}) (Version: 1.0.10.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{31b49e1e-03f8-4a04-8faa-f6476d8fad02}) (Version: 1.0.10.0 - Epic Games, Inc.)
Unity Web Player (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\UnityWebPlayer) (Version: 4.5.4f1 - Unity Technologies ApS)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Unravel (HKLM\...\Unravel_is1) (Version: 1.0.0.0 - )
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 24.0.1 - Ubisoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vypínač na dobrou noc verze 2.0 (HKLM-x32\...\Vypínač na dobrou noc_is1) (Version: - )
WATCH_DOGS (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Wolfenstein II The New Colossus (HKLM-x32\...\Wolfenstein II The New Colossus_is1) (Version: - )
Wolfenstein The Old Blood (HKLM-x32\...\Wolfenstein The Old Blood_is1) (Version: - )
WRC 6 FIA Word Rally Championship (HKLM\...\WRC 6 FIA Word Rally Championship_is1) (Version: 1.0 - )
Xilisoft Download YouTube Video (HKLM-x32\...\Xilisoft Download YouTube Video) (Version: 5.1.1.20131226 - Xilisoft)
X-Morph: Defense (HKLM\...\eG1vcnBoZGVmZW5zZQ_is1) (Version: 1 - )
Youtubers Life (HKLM-x32\...\Youtubers Life_is1) (Version: - )
Základní software zařízení HP Deskjet 3520 series (HKLM\...\{7EBD8BA7-DF64-4BF9-9BC1-B0D53984FC6E}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Zkušební verze produktu Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISER) (Version: 12.0.6612.1000 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-10-09] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-10-09] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-10-09] (Google)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => -> No File
ShellIconOverlayIdentifiers: [TortoiseOverlay] -> {CBF88FC2-F150-4F29-BC80-CE30EFD1B62C} => C:\Users\jemin\AppData\Roaming\Subversion\TortoiseSVN.dll [2017-10-30] ()
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll -> No File
ContextMenuHandlers1-x32: [DaemonShellExtImage] -> {40966797-8FFE-46C8-9EF8-7003F33CCF0F} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2014-02-19] (Disc Soft Ltd)
ContextMenuHandlers1-x32: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1-x32: [FRHEAddInContextMenu10.FRHEAddInContextMenu10.1] -> {95CF7ACA-9F00-4789-8C3B-797AD701B1AD} => C:\Program Files (x86)\ABBYY FineReader 10 Home Edition\SprintIntegration.x64.dll [2010-07-30] (ABBYY.)
ContextMenuHandlers1-x32: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-10-09] (Google)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDrive] -> {A5415364-784A-41A5-B47A-D452909CA8FF} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2014-02-19] (Disc Soft Ltd)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll -> No File
ContextMenuHandlers3: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] ()
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-10-09] (Google)
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2014-03-14] (Piriform Ltd)
ContextMenuHandlers5: [DreamScene] -> {BE800AEB-A440-4B63-94CD-AA6B43647DF9} => C:\Windows\System32\DreamScene.dll [2008-03-18] (Microsoft Corporation)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2015-12-21] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-10-12] (NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [FRHEAddInContextMenu10.FRHEAddInContextMenu10.1] -> {95CF7ACA-9F00-4789-8C3B-797AD701B1AD} => C:\Program Files (x86)\ABBYY FineReader 10 Home Edition\SprintIntegration.x64.dll [2010-07-30] (ABBYY.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll -> No File
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2014-03-14] (Piriform Ltd)
ContextMenuHandlers6: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] ()
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {056500A8-0435-4561-8384-A496FBAC97C7} - System32\Tasks\curl => C:\Users\jemin\AppData\Roaming\curl\curl_7_54.exe [2017-10-30] (curl, hxxps://curl.haxx.se/) <==== ATTENTION
Task: {07E9C263-377B-4790-8BA8-4000EC526F33} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25] (Adobe Systems Incorporated)
Task: {1941AEF7-DF9D-4217-8D67-2F7659B66842} - System32\Tasks\{D27AFE4E-B181-4D0A-9FBC-C05DA6B64160} => C:\Windows\system32\pcalua.exe -a E:\FreeRapid-0.9u3\frd.exe -d E:\FreeRapid-0.9u3
Task: {1E7B4DAF-F5F3-47D0-A498-9289928F5684} - System32\Tasks\HP AR Program Upload - 15bdd154090248ff83bf738ef41d8acb0a8af20927154115b3f4bb34278b954e => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {2070A2F1-D2F6-4169-8BAA-A3DD5D5871D4} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-10-11] (NVIDIA Corporation)
Task: {4223730D-4C12-4254-BE01-86CC6A888AB6} - System32\Tasks\jemin => cmd.exe /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v jemin /t REG_SZ /d "explorer.exe hxxp://kb-ribaki.org" <==== ATTENTION
Task: {50DD5D55-17B4-41B7-9FAC-5F8F23945C92} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11] (NVIDIA Corporation)
Task: {517F3191-92BA-4F67-8705-734550650116} - System32\Tasks\HPCustParticipation HP Deskjet 3520 series => C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {557BC1F0-85C2-4457-8C51-BAB17AAD538E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {5E502661-C251-457F-B0FA-8CAF52FB20EB} - System32\Tasks\HP AR Program Upload - ebd9bb931b784a29a946f5237ef49361000942cece6b438a93db3d0b7fc6e111 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {5F8E9919-F403-4E5B-AC2A-1793FC28D3D2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-04] (Google Inc.)
Task: {63F7A68F-5E3D-4F60-A8A2-B2A2C53A2E0B} - System32\Tasks\{4BCA7948-C65E-4C04-9FA6-5C67D67565F2} => C:\Windows\system32\pcalua.exe -a G:\setup.exe -d G:\
Task: {64918761-A7A3-4CF6-9A83-AC5BBF40580D} - System32\Tasks\{73001685-F357-48A1-99C6-356222FF07ED} => C:\Windows\system32\pcalua.exe -a H:\Setup.exe -d H:\
Task: {64F87439-92E3-4E79-80C9-37B8496ABBEC} - System32\Tasks\HP AR Program Upload - ee281cd3164949909d054632e6dccc66fee3533cfade49c99672947277d7e396 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {6555226B-5010-4FE7-A347-C7253B537264} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe [2015-10-04] (Beepa P/L)
Task: {6874E146-675C-4465-A470-025DE68F6074} - System32\Tasks\{55B5D951-DA1A-47CA-A5FA-7A51408516CE} => E:\jemin\animace\dreams aktivátor\Windows 7 DreamScene Activator 1.1.exe [2015-10-04] (The Windows Club)
Task: {6A7BE2F3-7224-49A5-A36C-AE3F9786F3D5} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {7B1A4023-D554-4426-85F8-22386A238F39} - System32\Tasks\HP AR Program Upload - 00c03cb91a6a4f9ab32b2baea62b347d288bfe6122e049a19a255c663bcd58e1 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {7E77D404-BBBD-4245-8E3D-553687AEF778} - System32\Tasks\{F221DBD7-CF1E-4115-BE48-E3959564C6FB} => H:\Setup.exe
Task: {81307D74-7351-46A4-91CB-55962CD5FDB8} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation)
Task: {8B9AC6D1-7677-4D3E-A503-ABD472D60C6C} - System32\Tasks\{C7E5DACB-30DE-4AFA-94EF-103A67B00706} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\IncrediMail\Bin\ImSetup.exe" -d "C:\Program Files (x86)\IncrediMail\Bin"
Task: {8FC84B15-C239-4530-A98E-57602B5F81FE} - System32\Tasks\Java Updater => C:\Users\jemin\AppData\Roaming\nircmd.exe <==== ATTENTION
Task: {94DFC7C4-254F-4093-A383-C1F69E47AB9D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-04] (Google Inc.)
Task: {9EFD5EAA-8262-456C-9945-6821529DB8B5} - System32\Tasks\{19792CD0-F7CF-4B73-BDE8-0960E3D89A0D} => C:\Windows\system32\pcalua.exe -a H:\Setup.exe -d H:\
Task: {A8C1B3DD-0075-4CA6-9668-6830FDFDEB85} - System32\Tasks\HP AR Program Upload - 5c8d2ed5a782435ba5b0a095fdc5b1d40552e7933d5b47bdaf8da7c26a509121 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {AEB8354C-A836-4690-AAF1-1415577A3B75} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation)
Task: {B0022371-1BE0-4513-9BEB-C6CCF9F90B49} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation)
Task: {B02A64E8-0A65-486F-9410-F6E5926388E9} - System32\Tasks\savhost => C:\Users\jemin\AppData\Local\Temp\tmpFFB7.tmp.exe <==== ATTENTION
Task: {B2779A83-89FA-4E99-B78E-BDA73CA4E384} - System32\Tasks\curls => C:\Users\jemin\AppData\Roaming\curl\curl.exe <==== ATTENTION
Task: {B6125790-276E-4C6B-8F29-E7755A6ECC43} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {BCB114CF-1799-48A7-8AC4-3B232B56B0B5} - System32\Tasks\{E3135F68-FF59-4CBF-80A4-A30959DBD722} => C:\Windows\system32\pcalua.exe -a "E:\jemin\Hry\Call of Duty 2\CallOfDuty2.exe" -d "E:\jemin\Hry\Call of Duty 2"
Task: {C41CF9CE-6A6C-4223-BE3F-4B2062DBA6A1} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-10-11] (NVIDIA Corporation)
Task: {CA79BF71-3FD6-4AD5-BD11-A3A359953F42} - System32\Tasks\HP AR Program Upload - d7a49cf9c21c4f4082bf4fbbef9a7dad4ca28bdfe5cf4ff3b8b74043d305b73e => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {D0C843E2-B17B-4C18-9378-048B6E5BB715} - System32\Tasks\{C6242714-9FFA-4F3B-858C-0D95F2C9C642} => C:\Windows\system32\pcalua.exe -a H:\SETUP.EXE -d H:\
Task: {DCD71949-19EB-4860-BA96-B18BACB04D71} - System32\Tasks\{E03B9112-FF17-4C3F-BF73-85BEE52C441A} => C:\Windows\system32\pcalua.exe -a "C:\Users\jemin\Desktop\NHL 2009 Cestina+Cesky Komentar\NHL09_CZ.exe" -d "C:\Users\jemin\Desktop\NHL 2009 Cestina+Cesky Komentar"
Task: {EECF3B5E-B37B-4185-97F6-3B5DA5E32784} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-10-11] (NVIDIA Corporation)
Task: {F10C09C5-604A-4000-A811-3DFB777B48D9} - \{FB6429D6-6C14-4633-A83B-164E822229EA} -> No File <==== ATTENTION
Task: {FCBBF8B4-7EAA-47FA-B81F-A51F344721B5} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation)
Task: {FE0D20C1-BCDE-41E0-B819-8136411B500B} - System32\Tasks\{B9C5C637-D195-4826-B163-FC338A55A564} => E:\soft\Soft - Bosch Esitronic 2013\Esi2.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-01-28 07:32 - 2017-10-11 02:05 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2014-03-21 23:31 - 2016-01-03 16:30 - 000075064 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-03-21 23:31 - 2017-01-31 20:36 - 000214520 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
- - 000000000 __RSH () C:\Windows\Microsoft\svchost.exe
2017-10-30 13:05 - 2017-10-30 13:05 - 000148992 _____ () C:\Users\jemin\AppData\Roaming\Subversion\TortoiseSVN.dll
2016-05-09 08:22 - 2016-05-09 08:22 - 000052912 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2010-07-15 05:44 - 2010-07-15 05:44 - 000020032 _____ () C:\Program Files\Unlocker\UnlockerCOM.dll
- - 000000000 _____ () C:\Windows\Microsoft\svchost.exe.exe
2017-10-30 13:00 - 2017-10-30 13:00 - 000304128 ____N () C:\Program Files (x86)\ZfJRwqLPhIE\landhTGixw.exe
2017-01-28 07:32 - 2017-10-11 02:05 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-08-17 15:51 - 2017-08-17 15:51 - 001993184 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
2017-07-22 21:25 - 2017-09-09 20:25 - 000688416 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2017-07-22 21:25 - 2016-09-01 02:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2017-07-22 21:25 - 2016-09-01 02:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2017-07-22 21:25 - 2016-09-01 02:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2017-07-22 21:25 - 2017-10-25 06:00 - 002546976 _____ () C:\Program Files (x86)\Steam\video.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 002549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 000442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 000491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 000332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 000485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2017-07-22 21:25 - 2017-10-25 06:00 - 000901408 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2017-10-23 17:30 - 2017-10-11 02:05 - 000018880 _____ () c:\program files (x86)\nvidia corporation\nvstreamsrv\detoured.dll
2017-07-22 21:25 - 2016-07-04 23:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2017-10-30 13:00 - 2017-10-30 13:00 - 000402432 ____N () C:\Program Files (x86)\ZfJRwqLPhIE\k7zVdU1Vp.dll
2017-01-28 07:32 - 2017-10-11 02:05 - 070805952 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2017-07-22 21:26 - 2017-08-16 23:28 - 073130272 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2017-07-22 21:26 - 2017-09-07 03:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2017-07-22 21:25 - 2015-09-25 00:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll
2017-10-30 13:00 - 2017-10-30 13:00 - 000548864 ____N () C:\Program Files (x86)\ZfJRwqLPhIE\7ipk0.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\Users\All Users:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\ProgramData\Application Data:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\ProgramData\Data aplikací:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\ProgramData\TEMP:8CE646EE [145]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{4D006E00-6200-4A00-6600-730072007200} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{51007100-4F00-6F00-5300-4F0072005900} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{68005900-5000-5500-3600-31007A003200} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{78002F00-7800-4A00-5900-670073006400} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup:{51007100-4F00-6F00-5300-4F0072005900} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup:{6C007200-6300-7500-3800-4F0036006F00} [832]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\26821665.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\31663166.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DA92FCC0.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\26821665.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\31663166.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DA92FCC0.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PAexec => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2017-04-24 09:44 - 000000033 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 176.12.112.2 - 176.12.112.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Program Killer.lnk => C:\Windows\pss\Program Killer.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^jemin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk => C:\Windows\pss\MyPC Backup.lnk.Startup
MSCONFIG\startupreg: GSplay.exe => D:\GSplay.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{EC9F93CA-EAB4-4BA5-8439-06F1E85ADB9E}] => (Allow) D:\Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{FF96ED0C-31D5-48A0-8884-224972FBBE25}] => (Allow) D:\Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [TCP Query User{926C15F9-B9E5-4E5A-A3C7-5750472C1E6E}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{0C535B2A-95EF-48C7-940A-CC352591D8C3}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{93E44B6C-F664-4F3E-8349-D6815A8DFE17}C:\program files (x86)\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [UDP Query User{0A1331B3-B10A-48E4-AE77-7AF6496A5413}C:\program files (x86)\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [{C29D7043-3F90-4CAD-AD0D-20429043E7A9}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{23586E04-0CE6-4129-9338-D5085F64A374}] => (Allow) D:\Games\Need for Speed Rivals\NFS14_x86.exe
FirewallRules: [{5EE8387E-9245-4C4F-BE84-3431A6AA675F}] => (Allow) D:\Games\Need for Speed Rivals\NFS14_x86.exe
FirewallRules: [{19B04F70-CB5C-4DC2-9928-088A254D0B5A}] => (Allow) D:\Games\Need for Speed Rivals\NFS14.exe
FirewallRules: [{450917FA-4471-4C79-9AC0-FAEC65D8209F}] => (Allow) D:\Games\Need for Speed Rivals\NFS14.exe
FirewallRules: [{B5E1DE1D-2ECB-44D1-BA69-E41DAFB2DD6B}] => (Allow) D:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
FirewallRules: [{26107DBA-396A-4DBD-8131-97FF203E84F5}] => (Allow) D:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
FirewallRules: [{9FBC0D03-DC3E-486D-978D-B52CBDD16742}] => (Allow) D:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [{419F148D-477E-41A8-B71B-39628FB7F4EA}] => (Allow) D:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [TCP Query User{6638CA37-529A-4308-9B92-3D1367B8695E}D:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe] => (Block) D:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe
FirewallRules: [UDP Query User{2F4BAC82-FA21-48D9-9CDF-2A5B0403F0E2}D:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe] => (Block) D:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe
FirewallRules: [TCP Query User{E1032D29-2390-40BA-A592-A9D1175B1E67}D:\program files (x86)\activision\call of duty 2\cod2mp_s.exe] => (Allow) D:\program files (x86)\activision\call of duty 2\cod2mp_s.exe
FirewallRules: [UDP Query User{EA1C51AF-BD92-47F8-A3DE-6BBDC30D258A}D:\program files (x86)\activision\call of duty 2\cod2mp_s.exe] => (Allow) D:\program files (x86)\activision\call of duty 2\cod2mp_s.exe
FirewallRules: [TCP Query User{0647F3C4-B230-4E23-837F-9C49F331CBC4}C:\users\jemin\gsplay\counter-strike\hl.exe] => (Block) C:\users\jemin\gsplay\counter-strike\hl.exe
FirewallRules: [UDP Query User{B29FF24F-D5E9-4B7F-94F5-91E4EEEA7A20}C:\users\jemin\gsplay\counter-strike\hl.exe] => (Block) C:\users\jemin\gsplay\counter-strike\hl.exe
FirewallRules: [TCP Query User{DC4D6EA1-9025-4B5C-A336-88326C026F7F}D:\program files (x86)\battlefield 4\bf4_x86.exe] => (Block) D:\program files (x86)\battlefield 4\bf4_x86.exe
FirewallRules: [UDP Query User{04BE027B-75E2-4C61-9774-A3C05864A30E}D:\program files (x86)\battlefield 4\bf4_x86.exe] => (Block) D:\program files (x86)\battlefield 4\bf4_x86.exe
FirewallRules: [TCP Query User{E9B865DB-7F1F-4482-85BA-3D6217996E0A}D:\program files (x86)\battlefield 4\bf4.exe] => (Block) D:\program files (x86)\battlefield 4\bf4.exe
FirewallRules: [UDP Query User{8F2E56A9-D064-4184-AF8E-011C84569BD1}D:\program files (x86)\battlefield 4\bf4.exe] => (Block) D:\program files (x86)\battlefield 4\bf4.exe
FirewallRules: [TCP Query User{674B0ADD-CA97-4B76-A3A2-F763924AA51D}D:\program files (x86)\mxgp\mxgp.exe] => (Block) D:\program files (x86)\mxgp\mxgp.exe
FirewallRules: [UDP Query User{E29E23DE-D12E-44A1-974E-8A710BEC5B4E}D:\program files (x86)\mxgp\mxgp.exe] => (Block) D:\program files (x86)\mxgp\mxgp.exe
FirewallRules: [TCP Query User{A9A381D7-2A47-4A32-BD24-FE9AD3A5A09D}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe
FirewallRules: [UDP Query User{1BFE3E96-FCB6-4B05-B3BD-D3D03C0EAB15}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe
FirewallRules: [TCP Query User{EF825647-5D12-470A-9457-ADDC535CFA4C}D:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe] => (Block) D:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe
FirewallRules: [UDP Query User{F9887EB4-44A5-430C-82E7-7AF0E4F930A7}D:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe] => (Block) D:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe
FirewallRules: [{70A14FFA-288A-4E1F-A900-FE69E1177396}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\DeviceSetup.exe
FirewallRules: [{A0109409-1BB2-4935-9C4E-79DDD2829F52}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{7B9E5515-D8C5-4C22-8A73-834C820F5543}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{72C76A57-4851-47A8-A9B4-D7E213094DB8}D:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe] => (Block) D:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe
FirewallRules: [UDP Query User{B1A1D8ED-9CC3-4F1F-A72A-1210A3529AEE}D:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe] => (Block) D:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe
FirewallRules: [{12BCDDCC-3BB7-4367-BAFF-6AA818C7EB99}] => (Allow) D:\Program Files\Ubisoft\WATCH_DOGS\bin\Watch_Dogs.exe
FirewallRules: [{F9636AD5-884A-44A5-BB24-727BEF15F7BB}] => (Allow) D:\Program Files\Ubisoft\WATCH_DOGS\bin\Watch_Dogs.exe
FirewallRules: [TCP Query User{DA40A7B5-2CF5-48A2-8BA1-796F9304B857}C:\program files\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [UDP Query User{F1CF21AF-A2FC-48A3-9BAE-20514FE0F853}C:\program files\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [TCP Query User{DF666C7D-7013-4AD6-9F55-DB3FF2FC49A9}C:\users\jemin\gsplay\csko\hl.exe] => (Block) C:\users\jemin\gsplay\csko\hl.exe
FirewallRules: [UDP Query User{33A94344-B2F7-4912-AF6A-7183D630529F}C:\users\jemin\gsplay\csko\hl.exe] => (Block) C:\users\jemin\gsplay\csko\hl.exe
FirewallRules: [TCP Query User{11A502A9-D141-4337-98C0-7F5FF26E0438}D:\program files (x86)\enemy front proper\bin32\enemyfront.exe] => (Block) D:\program files (x86)\enemy front proper\bin32\enemyfront.exe
FirewallRules: [UDP Query User{B6D65920-8EFD-44E4-9EAE-6BCE0DECD2C7}D:\program files (x86)\enemy front proper\bin32\enemyfront.exe] => (Block) D:\program files (x86)\enemy front proper\bin32\enemyfront.exe
FirewallRules: [{261E553F-8589-4B8E-BF46-F386B9465BED}] => (Allow) C:\Users\jemin\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{FD71908E-03D7-46E6-9B33-6040291186B8}] => (Allow) C:\Users\jemin\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [TCP Query User{B2B7F401-5ADA-412D-9863-CD0A3BD0806C}D:\program files (x86)\real boxing\binaries\win32\realboxing.exe] => (Block) D:\program files (x86)\real boxing\binaries\win32\realboxing.exe
FirewallRules: [UDP Query User{6E6A316E-857B-4F39-8E52-5F3C22F75A9E}D:\program files (x86)\real boxing\binaries\win32\realboxing.exe] => (Block) D:\program files (x86)\real boxing\binaries\win32\realboxing.exe
FirewallRules: [TCP Query User{E6576750-61E5-404B-86FA-58D414FB0CB1}C:\program files (x86)\quadcorem2\pack\core.bin] => (Allow) C:\program files (x86)\quadcorem2\pack\core.bin
FirewallRules: [UDP Query User{10CFF7EB-A58E-4FA6-B4C5-468171558AD4}C:\program files (x86)\quadcorem2\pack\core.bin] => (Allow) C:\program files (x86)\quadcorem2\pack\core.bin
FirewallRules: [TCP Query User{00F2E9F2-A2F1-437E-8A79-97D384C5A709}C:\users\jemin\desktop\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\spaceworldlauncher.exe
FirewallRules: [UDP Query User{4C330470-572B-47B7-AF1C-5103966A5B1D}C:\users\jemin\desktop\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\spaceworldlauncher.exe
FirewallRules: [TCP Query User{0DA20475-78B6-43B7-BA7C-602E13126D17}C:\users\jemin\desktop\nová složka\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\nová složka\spaceworldlauncher.exe
FirewallRules: [UDP Query User{D5DDED2A-B7ED-4D0E-BCED-72A7C97DE860}C:\users\jemin\desktop\nová složka\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\nová složka\spaceworldlauncher.exe
FirewallRules: [TCP Query User{6CABB974-EE02-4BE4-9056-443D1BB0FB5B}C:\users\jemin\desktop\spaceworld\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\spaceworld\spaceworldlauncher.exe
FirewallRules: [UDP Query User{114D6444-3AF3-41F9-88D6-5DF829CFA147}C:\users\jemin\desktop\spaceworld\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\spaceworld\spaceworldlauncher.exe
FirewallRules: [TCP Query User{7C6DB9DE-E974-4981-B6B7-4D76752A12A1}C:\users\jemin\desktop\spaceworld\zcsk.dll] => (Allow) C:\users\jemin\desktop\spaceworld\zcsk.dll
FirewallRules: [UDP Query User{048A9E14-77F3-48B0-90D8-0FE111E4D647}C:\users\jemin\desktop\spaceworld\zcsk.dll] => (Allow) C:\users\jemin\desktop\spaceworld\zcsk.dll
FirewallRules: [TCP Query User{AD284F0E-F35E-494D-ACE3-FAB78938F2E8}D:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe] => (Block) D:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe
FirewallRules: [UDP Query User{60D70A45-0FC4-40DE-9F3A-3292F3150836}D:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe] => (Block) D:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe
FirewallRules: [TCP Query User{F10050C1-7767-4A42-9B1A-90F0C2D690A9}D:\program files (x86)\lichdom battlemage\bin32\lichdombattlemage.exe] => (Block) D:\program files (x86)\lichdom battlemage\bin32\lichdombattlemage.exe
FirewallRules: [UDP Query User{25860A31-7CB2-45D8-9338-B8CD49F86F86}D:\program files (x86)\lichdom battlemage\bin32\lichdombattlemage.exe] => (Block) D:\program files (x86)\lichdom battlemage\bin32\lichdombattlemage.exe
FirewallRules: [{6F898F04-5959-4514-A10C-C0125F49B556}] => (Allow) C:\Program Files (x86)\GameforgeLive\gfl_client.exe
FirewallRules: [TCP Query User{5F448F50-63AC-4EFD-94EE-CDF53D1DF42C}D:\program files (x86)\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe] => (Block) D:\program files (x86)\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe
FirewallRules: [UDP Query User{8B174938-BA0E-47F1-B417-7B3F71B6C0F3}D:\program files (x86)\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe] => (Block) D:\program files (x86)\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe
FirewallRules: [TCP Query User{AB4EBAAA-9306-4B0E-99B3-00E6AF1D6AEC}D:\program files (x86)\alien isolation\ai.exe] => (Block) D:\program files (x86)\alien isolation\ai.exe
FirewallRules: [UDP Query User{A477087F-9B32-4134-B611-F88EE3601D03}D:\program files (x86)\alien isolation\ai.exe] => (Block) D:\program files (x86)\alien isolation\ai.exe
FirewallRules: [TCP Query User{AF18B9DC-D514-47EE-8260-EEADAE19D6F0}D:\attomey ---\metin2client.bin] => (Allow) D:\attomey ---\metin2client.bin
FirewallRules: [UDP Query User{728CAEFD-BD93-428B-9920-8ADDA1BEF20F}D:\attomey ---\metin2client.bin] => (Allow) D:\attomey ---\metin2client.bin
FirewallRules: [TCP Query User{C4EAF14C-B9C9-4EA0-9741-2EF205E01F62}D:\program files (x86)\far cry 4\bin\farcry4.exe] => (Block) D:\program files (x86)\far cry 4\bin\farcry4.exe
FirewallRules: [UDP Query User{C46FF19A-8F17-4DAB-A67B-6358AC4B0B3E}D:\program files (x86)\far cry 4\bin\farcry4.exe] => (Block) D:\program files (x86)\far cry 4\bin\farcry4.exe
FirewallRules: [TCP Query User{82FEE81E-5F40-4C6C-98FC-C6EA13FDE949}D:\program files (x86)\motorcycle club\motorcycleclub.exe] => (Block) D:\program files (x86)\motorcycle club\motorcycleclub.exe
FirewallRules: [UDP Query User{705A062D-89EE-4621-BD91-030D8F6CDF4A}D:\program files (x86)\motorcycle club\motorcycleclub.exe] => (Block) D:\program files (x86)\motorcycle club\motorcycleclub.exe
FirewallRules: [{F3AE242D-661A-4E38-8F94-8C02791F51BD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{D9A754BC-0A38-47AD-A9EA-09CCBACA7012}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{D41201DB-7A7E-4864-87B2-5EAE7150DE55}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{3568D9B6-3947-40D6-A9B1-1A996409D579}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{CA4AEBC9-9736-40E3-B0E7-5AE2D1E03DAF}D:\program files (x86)\dying light\dyinglightgame.exe] => (Block) D:\program files (x86)\dying light\dyinglightgame.exe
FirewallRules: [UDP Query User{E112A944-E494-4999-88B8-09AE7A5A5F96}D:\program files (x86)\dying light\dyinglightgame.exe] => (Block) D:\program files (x86)\dying light\dyinglightgame.exe
FirewallRules: [TCP Query User{AD894AE0-5682-4F01-BA3D-0B8273ED72C3}E:\program files (x86)\evolve\bin64_steamretail\evolve.exe] => (Block) E:\program files (x86)\evolve\bin64_steamretail\evolve.exe
FirewallRules: [UDP Query User{085B61B9-76E4-4F66-BFF9-B24784B0AF7C}E:\program files (x86)\evolve\bin64_steamretail\evolve.exe] => (Block) E:\program files (x86)\evolve\bin64_steamretail\evolve.exe
FirewallRules: [TCP Query User{FCBB2A40-EF8A-4DE2-A7F9-EA7C4D71298F}E:\gog games\oddworld - new 'n' tasty\nnt.exe] => (Block) E:\gog games\oddworld - new 'n' tasty\nnt.exe
FirewallRules: [UDP Query User{FB974618-CBCA-460E-98E2-4349CEFC001C}E:\gog games\oddworld - new 'n' tasty\nnt.exe] => (Block) E:\gog games\oddworld - new 'n' tasty\nnt.exe
FirewallRules: [TCP Query User{D406DDB8-736C-4D64-8A64-330F6EF33AA2}D:\program files (x86)\ride\ride.exe] => (Block) D:\program files (x86)\ride\ride.exe
FirewallRules: [UDP Query User{3280A57F-A878-498E-BF7A-225EE091E953}D:\program files (x86)\ride\ride.exe] => (Block) D:\program files (x86)\ride\ride.exe
FirewallRules: [TCP Query User{E1BF8BCD-FBB7-493F-A294-C611CC18DC09}D:\gog games\oddworld - new 'n' tasty\nnt.exe] => (Block) D:\gog games\oddworld - new 'n' tasty\nnt.exe
FirewallRules: [UDP Query User{A73E6B8D-3692-4768-84BA-659FC11A5CB1}D:\gog games\oddworld - new 'n' tasty\nnt.exe] => (Block) D:\gog games\oddworld - new 'n' tasty\nnt.exe
FirewallRules: [TCP Query User{1920DDF9-74F5-4569-B0B8-DE4C19B53EB9}E:\gta v\gta5.exe] => (Block) E:\gta v\gta5.exe
FirewallRules: [UDP Query User{DCF4F7B1-79DA-484E-83B7-72EDF3F39F1F}E:\gta v\gta5.exe] => (Block) E:\gta v\gta5.exe
FirewallRules: [TCP Query User{4810C075-7AD4-4C94-8320-570B0DED076E}E:\gta v\gta5.exe] => (Block) E:\gta v\gta5.exe
FirewallRules: [UDP Query User{065F9BC8-7506-4C69-87BE-C7ABC24CE5DE}E:\gta v\gta5.exe] => (Block) E:\gta v\gta5.exe
FirewallRules: [{DF64C37C-20E6-4F64-946D-5ECCAB993947}] => (Block) E:\gta v\gta5.exe
FirewallRules: [{F99BD298-6530-4933-810B-D5599C854F66}] => (Block) E:\gta v\gta5.exe
FirewallRules: [TCP Query User{C855F89A-25E7-4B42-B98D-70863034358E}E:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe] => (Block) E:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [UDP Query User{A0FC2257-AF0C-4E11-9C01-E0F89CF57C08}E:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe] => (Block) E:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [TCP Query User{DB118817-FEAE-49A1-88C6-3DD782080CAC}E:\program files (x86)\grand theft auto v\gta5.exe] => (Block) E:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{05423F75-F5CE-4EED-A2B0-7AD33121FE7F}E:\program files (x86)\grand theft auto v\gta5.exe] => (Block) E:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{4C2513FC-698E-4F86-87DF-57D6E5350437}E:\program files (x86)\pro evolution soccer 2016\pes2016.exe] => (Block) E:\program files (x86)\pro evolution soccer 2016\pes2016.exe
FirewallRules: [UDP Query User{F5AF05F2-DC6E-478E-B5B9-6EEB75CE4985}E:\program files (x86)\pro evolution soccer 2016\pes2016.exe] => (Block) E:\program files (x86)\pro evolution soccer 2016\pes2016.exe
FirewallRules: [{E06C7E46-8FEE-45F2-894B-38788B1585C7}] => (Allow) C:\ProgramData\system32.exe
FirewallRules: [{470C7554-8BFE-4234-86C3-63C61596846E}] => (Allow) C:\ProgramData\system32.exe
FirewallRules: [{716A58E4-C7D9-46A6-9A00-AF54DA0C79AD}] => (Allow) C:\Users\jemin\AppData\Local\Temp\Skype.exe
FirewallRules: [{704FDEAE-22E6-4204-AE3B-362E55281C8E}] => (Allow) C:\Users\jemin\AppData\Local\Temp\Skype.exe
FirewallRules: [TCP Query User{0822A0C7-B867-4709-8F90-D740BAC06D78}D:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe] => (Block) D:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe
FirewallRules: [UDP Query User{4C200F5C-0C7C-4719-92A3-ADFEEEA8B32D}D:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe] => (Block) D:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe
FirewallRules: [TCP Query User{02A3502E-5F2F-4936-8E08-7CB5E98DB241}E:\program files (x86)\mx vs atv supercross encore edition\mxstorm_pc.exe] => (Block) E:\program files (x86)\mx vs atv supercross encore edition\mxstorm_pc.exe
FirewallRules: [UDP Query User{BDEC0405-2D55-4D5F-A5D7-40E1D08B3E9A}E:\program files (x86)\mx vs atv supercross encore edition\mxstorm_pc.exe] => (Block) E:\program files (x86)\mx vs atv supercross encore edition\mxstorm_pc.exe
FirewallRules: [TCP Query User{857767CC-B344-41EE-AD63-C578A9A3ED05}D:\program files (x86)\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe] => (Block) D:\program files (x86)\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe
FirewallRules: [UDP Query User{8E1DF42C-7A09-48A8-A032-28058AC57453}D:\program files (x86)\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe] => (Block) D:\program files (x86)\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe
FirewallRules: [TCP Query User{B59A9D01-F484-4251-BCAD-F3239455A8F3}E:\program files\call of duty black ops iii\blackops3.exe] => (Block) E:\program files\call of duty black ops iii\blackops3.exe
FirewallRules: [UDP Query User{B8E95041-7BC7-4B6E-ABD4-B66CBBBA2E32}E:\program files\call of duty black ops iii\blackops3.exe] => (Block) E:\program files\call of duty black ops iii\blackops3.exe
FirewallRules: [{4C4364ED-D71D-4CC3-AF47-B0D9DDC9E31C}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{DB78E42C-67A6-4C25-A6C8-181E8F7F51D5}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{5A93EB1F-112E-4BEE-9B2F-D2C8D6679C82}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{8FE9E101-27BC-441C-AE7A-6EA9887CC046}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{603C3D91-F630-49D4-9E63-C5890F6046DB}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{4D79B172-F8CC-4A77-ADED-FF69BDB96B7B}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{C86EB915-19E5-4708-BC7F-0C8B4A574E91}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [TCP Query User{BC3D9D1D-B157-4740-9601-562F6FF8855F}D:\program files (x86)\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe] => (Block) D:\program files (x86)\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [UDP Query User{3E33465E-DD6E-48DF-8953-DDF8BF139FB7}D:\program files (x86)\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe] => (Block) D:\program files (x86)\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [TCP Query User{1413C1DF-EFE7-490F-BFF8-A57E0DE00A92}D:\program files\dying light\dyinglightgame.exe] => (Block) D:\program files\dying light\dyinglightgame.exe
FirewallRules: [UDP Query User{B7E78098-F6A9-4B7D-978C-A4491CB6FBE7}D:\program files\dying light\dyinglightgame.exe] => (Block) D:\program files\dying light\dyinglightgame.exe
FirewallRules: [TCP Query User{1EBD6287-8656-44E6-853A-6C55127EA839}D:\program files (x86)\doom closed alpha\doomx64.exe] => (Allow) D:\program files (x86)\doom closed alpha\doomx64.exe
FirewallRules: [UDP Query User{DDD22E85-C921-4318-AE6A-C2BF463ACE25}D:\program files (x86)\doom closed alpha\doomx64.exe] => (Allow) D:\program files (x86)\doom closed alpha\doomx64.exe
FirewallRules: [{761086C3-703F-42A8-BD25-450D53DBF066}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{10FB8E33-015A-4A38-B877-C50A42C806CB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{D90D03CF-94DF-4957-867D-501B790544B4}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{D59A4271-6E8F-461D-8460-1B90439A462C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{E9B0E8BF-3411-4BF9-AF47-7AFEB8D8A069}] => (Allow) D:\SteamLibrary\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [{F9522AB2-9267-41C0-8C7C-2E7CD0538BA5}] => (Allow) D:\SteamLibrary\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [TCP Query User{A350CC02-5D3B-49E4-A91F-C240AECC771D}D:\program files (x86)\obliteracers\obliteracers\binaries\win64\obliteracers-win64-shipping.exe] => (Block) D:\program files (x86)\obliteracers\obliteracers\binaries\win64\obliteracers-win64-shipping.exe
FirewallRules: [UDP Query User{0B14F096-88D8-4132-ABAF-941D694ED20A}D:\program files (x86)\obliteracers\obliteracers\binaries\win64\obliteracers-win64-shipping.exe] => (Block) D:\program files (x86)\obliteracers\obliteracers\binaries\win64\obliteracers-win64-shipping.exe
FirewallRules: [TCP Query User{19C1B11D-1F24-4384-9FB7-4D28D329471C}D:\program files (x86)\mxgp2\mxgp_2x64.exe] => (Block) D:\program files (x86)\mxgp2\mxgp_2x64.exe
FirewallRules: [UDP Query User{D17DC52B-289D-4B72-9B54-5B8EF37C09F5}D:\program files (x86)\mxgp2\mxgp_2x64.exe] => (Block) D:\program files (x86)\mxgp2\mxgp_2x64.exe
FirewallRules: [TCP Query User{F20C4E25-45F8-4E24-A0D0-6D0BC7C6D138}D:\program files (x86)\is defense\isdefense\binaries\win64\isdefense-win64-shipping.exe] => (Block) D:\program files (x86)\is defense\isdefense\binaries\win64\isdefense-win64-shipping.exe
FirewallRules: [UDP Query User{E51888D3-BFF3-40C3-AF45-88748FA63BFA}D:\program files (x86)\is defense\isdefense\binaries\win64\isdefense-win64-shipping.exe] => (Block) D:\program files (x86)\is defense\isdefense\binaries\win64\isdefense-win64-shipping.exe
FirewallRules: [TCP Query User{141BE3F9-4170-4B81-9203-3B47BA166BA3}D:\program files\bell ringer\bellringer\binaries\win64\bellringer-win64-shipping.exe] => (Block) D:\program files\bell ringer\bellringer\binaries\win64\bellringer-win64-shipping.exe
FirewallRules: [UDP Query User{39796CB2-29A2-4807-90F7-C222E9FF9FFC}D:\program files\bell ringer\bellringer\binaries\win64\bellringer-win64-shipping.exe] => (Block) D:\program files\bell ringer\bellringer\binaries\win64\bellringer-win64-shipping.exe
FirewallRules: [TCP Query User{FE5E79CC-6C94-40B3-A178-0FA9D3D8E96A}D:\doom\steamapps\common\doom\doomx64.exe] => (Allow) D:\doom\steamapps\common\doom\doomx64.exe
FirewallRules: [UDP Query User{F3F979DB-575A-478A-8454-DF3087D3141C}D:\doom\steamapps\common\doom\doomx64.exe] => (Allow) D:\doom\steamapps\common\doom\doomx64.exe
FirewallRules: [TCP Query User{64A4790D-0C45-4F12-92DC-2C210153AC5D}D:\games\grim dawn\grim dawn.exe] => (Block) D:\games\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{D5632D50-BC4F-413A-9E1C-45296C274414}D:\games\grim dawn\grim dawn.exe] => (Block) D:\games\grim dawn\grim dawn.exe
FirewallRules: [TCP Query User{D4C4FAC6-4DA5-441E-9E71-FFE5B471E857}D:\program files (x86)\microsoft studios\quantum break\dx11\quantumbreak.exe] => (Block) D:\program files (x86)\microsoft studios\quantum break\dx11\quantumbreak.exe
FirewallRules: [UDP Query User{1872C9F0-B06F-412F-B6E4-2E0F91D05006}D:\program files (x86)\microsoft studios\quantum break\dx11\quantumbreak.exe] => (Block) D:\program files (x86)\microsoft studios\quantum break\dx11\quantumbreak.exe
FirewallRules: [TCP Query User{C7135B46-D1FF-433E-BA8A-1ABBB38AED2D}D:\program files\call of duty infinite warfare\iw7_ship.exe] => (Allow) D:\program files\call of duty infinite warfare\iw7_ship.exe
FirewallRules: [UDP Query User{864705B0-1401-493E-9498-E63AFA0B4AC1}D:\program files\call of duty infinite warfare\iw7_ship.exe] => (Allow) D:\program files\call of duty infinite warfare\iw7_ship.exe
FirewallRules: [{9F66FC26-EF21-433E-8611-568620639D23}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\STEEP\steep.exe
FirewallRules: [{00EA6016-950E-4377-AF23-15BBB14D9BC6}] => (Allow) D:\Program Files (x86)\Daedalic Entertainment GmbH\Shadow Tactics - Blades of the Shogun\Shadow Tactics.exe
FirewallRules: [{740AFE78-8A14-4333-83A6-4116FC7F61BC}] => (Allow) D:\Program Files (x86)\Daedalic Entertainment GmbH\Shadow Tactics - Blades of the Shogun\Shadow Tactics.exe
FirewallRules: [{5B621055-5E76-4F13-811C-57A72712FE1B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{A387B7B0-80DC-4AB9-B6E5-284E432FFAB5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{5607EE13-0BE0-4A55-AD22-32C0FF19B780}D:\games\far cry primal\bin\fcprimal.exe] => (Block) D:\games\far cry primal\bin\fcprimal.exe
FirewallRules: [UDP Query User{4F22BF3C-D31B-40EB-9859-2E7D0D3FA823}D:\games\far cry primal\bin\fcprimal.exe] => (Block) D:\games\far cry primal\bin\fcprimal.exe
FirewallRules: [{4EFF3BF1-E56A-4EE1-BD31-E8F6C025E7DA}] => (Allow) D:\DOOM\steamapps\common\Moto Racer 4\MR4.exe
FirewallRules: [{BA167BF8-32C6-417C-A81E-9C3804335A8F}] => (Allow) D:\DOOM\steamapps\common\Moto Racer 4\MR4.exe
FirewallRules: [TCP Query User{40E99C32-1450-4486-9051-E7D735633C29}D:\doom\steamapps\common\moto racer 4\mr4\binaries\win64\mr4-win64-shipping.exe] => (Allow) D:\doom\steamapps\common\moto racer 4\mr4\binaries\win64\mr4-win64-shipping.exe
FirewallRules: [UDP Query User{F9345190-4059-4B21-B0FC-18D5012DDFED}D:\doom\steamapps\common\moto racer 4\mr4\binaries\win64\mr4-win64-shipping.exe] => (Allow) D:\doom\steamapps\common\moto racer 4\mr4\binaries\win64\mr4-win64-shipping.exe
FirewallRules: [{7EE6681B-5C1B-49D4-ABA5-05B83F3DC427}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{F3B55875-1007-4947-9523-91EBCE5EFA88}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{4683609A-46CB-4162-87F6-E2282C49E888}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{54E7055D-0B29-4F9F-9440-F0F6E663CB8C}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{C668D9AD-44A2-4DA7-AAF9-DB1F90C7AB22}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{D5A04A7B-AC6A-4951-BEB5-5773B2DC3760}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{82D7559D-8557-4A0E-B8A5-02E7D3C44595}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{A6B9524C-EFD3-46C0-B1FE-E22156406CA7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5C5FDC54-29F4-4B9E-877E-D664A0AEEE14}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{8A4D30F6-2C77-492B-8DB4-8F67CE73C6D2}E:\program files (x86)\mxgp2\mxgp_2x64.exe] => (Block) E:\program files (x86)\mxgp2\mxgp_2x64.exe
FirewallRules: [UDP Query User{54F54BBC-6A68-4CEE-AA78-BA228FDA7901}E:\program files (x86)\mxgp2\mxgp_2x64.exe] => (Block) E:\program files (x86)\mxgp2\mxgp_2x64.exe
FirewallRules: [TCP Query User{BAF9E536-6209-45A1-BECD-AAC963BB629F}E:\setup\bf1.exe] => (Block) E:\setup\bf1.exe
FirewallRules: [UDP Query User{3A0660ED-B19A-4154-9C4D-68926EAD4990}E:\setup\bf1.exe] => (Block) E:\setup\bf1.exe
FirewallRules: [TCP Query User{1D628DCE-ADB5-4503-B2A1-C413082BC70C}D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe] => (Block) D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe
FirewallRules: [UDP Query User{62BEBB98-EB12-4904-8A54-E3FD23D79464}D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe] => (Block) D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe
FirewallRules: [TCP Query User{AA2E1389-9511-4214-A01F-FB93AE463408}C:\program files\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [UDP Query User{38A48E49-897F-4B08-882D-436F1D67BCEF}C:\program files\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [TCP Query User{A6937832-9E74-4138-9AB7-9E94A1393439}D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe] => (Block) D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe
FirewallRules: [UDP Query User{2902D579-82A6-48AA-B799-BBC6CC8E422C}D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe] => (Block) D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe
FirewallRules: [TCP Query User{338240D8-343A-4060-950B-728542F589A7}D:\vikings - wolves of midgard\vikings.exe] => (Block) D:\vikings - wolves of midgard\vikings.exe
FirewallRules: [UDP Query User{D91331E9-8B5D-4F5D-B1B2-F43B69AE9FC9}D:\vikings - wolves of midgard\vikings.exe] => (Block) D:\vikings - wolves of midgard\vikings.exe
FirewallRules: [TCP Query User{7F4AB0E7-070D-4584-A094-7BCC7185C7BD}D:\program files (x86)\x-plane 11\x-plane.exe] => (Block) D:\program files (x86)\x-plane 11\x-plane.exe
FirewallRules: [UDP Query User{C68DE143-9DC3-41EC-B117-CD1020E0D8F2}D:\program files (x86)\x-plane 11\x-plane.exe] => (Block) D:\program files (x86)\x-plane 11\x-plane.exe
FirewallRules: [TCP Query User{20092F69-27F2-457F-9326-59A049BCF600}D:\program files (x86)\perfect golf inc\jack nicklaus perfect golf\win64\perfect golf.exe] => (Block) D:\program files (x86)\perfect golf inc\jack nicklaus perfect golf\win64\perfect golf.exe
FirewallRules: [UDP Query User{3748F95E-3853-4845-A70A-6F3EDC3C37D2}D:\program files (x86)\perfect golf inc\jack nicklaus perfect golf\win64\perfect golf.exe] => (Block) D:\program files (x86)\perfect golf inc\jack nicklaus perfect golf\win64\perfect golf.exe
FirewallRules: [TCP Query User{587EDF74-69D1-45D6-B4E9-9562155F2657}E:\setup\bf1.exe] => (Block) E:\setup\bf1.exe
FirewallRules: [UDP Query User{F5580176-E156-42A1-AC83-71B380038717}E:\setup\bf1.exe] => (Block) E:\setup\bf1.exe
FirewallRules: [TCP Query User{AF363FD5-9EFD-41E3-AFAD-F7CA44FC8A02}E:\program files (x86)\outlast 2\binaries\win64\outlast2.exe] => (Block) E:\program files (x86)\outlast 2\binaries\win64\outlast2.exe
FirewallRules: [UDP Query User{A4D6CA65-F781-4763-924B-14F2111FCAAE}E:\program files (x86)\outlast 2\binaries\win64\outlast2.exe] => (Block) E:\program files (x86)\outlast 2\binaries\win64\outlast2.exe
FirewallRules: [TCP Query User{5782B509-5C62-47CE-89E1-54DECD35806F}E:\hry-stažené\win_x64\sgw3.exe] => (Block) E:\hry-stažené\win_x64\sgw3.exe
FirewallRules: [UDP Query User{DDC9D3D3-8827-4AEB-9DDC-F2843401D30C}E:\hry-stažené\win_x64\sgw3.exe] => (Block) E:\hry-stažené\win_x64\sgw3.exe
FirewallRules: [TCP Query User{A076EBEE-9BA8-4D8B-A155-BECDCE59078D}E:\hry-stažené\sniper ghost warrior 3\win_x64\sgw3.exe] => (Block) E:\hry-stažené\sniper ghost warrior 3\win_x64\sgw3.exe
FirewallRules: [UDP Query User{5A55DFE4-7938-4EDE-82F7-E70CE3368C6F}E:\hry-stažené\sniper ghost warrior 3\win_x64\sgw3.exe] => (Block) E:\hry-stažené\sniper ghost warrior 3\win_x64\sgw3.exe
FirewallRules: [TCP Query User{234B881B-E041-49FE-B789-2F683D871425}E:\games\prey\binaries\danielle\x64\release\prey.exe] => (Block) E:\games\prey\binaries\danielle\x64\release\prey.exe
FirewallRules: [UDP Query User{BE91F8E5-E601-4E5C-A219-59EFF101ED37}E:\games\prey\binaries\danielle\x64\release\prey.exe] => (Block) E:\games\prey\binaries\danielle\x64\release\prey.exe
FirewallRules: [TCP Query User{07971374-15DF-4880-9B5C-5E53CAC2AF50}E:\hry-stažené\oxygen.not.included.v218235.pefelie.org\oxygennotincluded.exe] => (Block) E:\hry-stažené\oxygen.not.included.v218235.pefelie.org\oxygennotincluded.exe
FirewallRules: [UDP Query User{5AD62975-7D08-495C-B797-7D2C61E95DC6}E:\hry-stažené\oxygen.not.included.v218235.pefelie.org\oxygennotincluded.exe] => (Block) E:\hry-stažené\oxygen.not.included.v218235.pefelie.org\oxygennotincluded.exe
FirewallRules: [TCP Query User{16D843CB-7C31-4C19-A58F-0668C335634B}E:\program files (x86)\titanfall 2\titanfall2.exe] => (Block) E:\program files (x86)\titanfall 2\titanfall2.exe
FirewallRules: [UDP Query User{F87246DB-9482-4068-A4A5-325E2B933F77}E:\program files (x86)\titanfall 2\titanfall2.exe] => (Block) E:\program files (x86)\titanfall 2\titanfall2.exe
FirewallRules: [TCP Query User{DCA395F8-7983-4FA5-834A-22A66C1DC13C}E:\program files\tom clancy's ghost recon wildlands\grw.exe] => (Block) E:\program files\tom clancy's ghost recon wildlands\grw.exe
FirewallRules: [UDP Query User{0963A4E5-3BCB-4CD2-AE3E-48ACF323D0D5}E:\program files\tom clancy's ghost recon wildlands\grw.exe] => (Block) E:\program files\tom clancy's ghost recon wildlands\grw.exe
FirewallRules: [TCP Query User{F1A9474A-397A-486A-B354-F942BC8E6726}E:\program files (x86)\grand theft auto v\gta5.exe] => (Block) E:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{AA83BBD8-64BA-4010-9AF4-A1DEE536D342}E:\program files (x86)\grand theft auto v\gta5.exe] => (Block) E:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [{D63D3A4C-1F6D-4062-AE9F-65C7992AF233}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{18553A5D-FBCF-4DE2-968B-FB32058B2E61}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{1F30648F-3326-4CBA-A2FF-62D1217FC3E8}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{4BA07AC8-6A99-451A-A6CE-59A2A2AF5DC7}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{9497DE23-4DAA-4467-B264-D8BD6F2DADA7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{3816CA48-CA3D-4BFA-B350-C8BA36DDB3BD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{38FC6660-0635-4BFD-BBE7-F99291ABADCA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F3D430C2-F8DD-4FB4-BC29-13A0740A49A3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A8AC45D9-34BE-45CD-ACC7-824EBA3DA095}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{9D47F75E-3F04-4C92-9C17-B37897EE2FEC}E:\program files (x86)\hob\hob.exe] => (Block) E:\program files (x86)\hob\hob.exe
FirewallRules: [UDP Query User{48B9F319-1665-4932-A683-A98CE9289CC9}E:\program files (x86)\hob\hob.exe] => (Block) E:\program files (x86)\hob\hob.exe
FirewallRules: [TCP Query User{E44AC4BD-E756-46A2-841D-0D6C21C77FDF}D:\program files\fifa18\fifa18.exe] => (Block) D:\program files\fifa18\fifa18.exe
FirewallRules: [UDP Query User{BA969D8C-18A5-4B72-B479-0F486DBA5270}D:\program files\fifa18\fifa18.exe] => (Block) D:\program files\fifa18\fifa18.exe
FirewallRules: [{93E90456-92F1-4C00-83C9-0B1ED48DA1E9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [TCP Query User{E551F476-0193-4A80-B612-35EDA7426CE5}D:\totalcmd\totalcmd64.exe] => (Allow) D:\totalcmd\totalcmd64.exe
FirewallRules: [UDP Query User{727FBAD9-696B-49B9-AF11-42832711EEE5}D:\totalcmd\totalcmd64.exe] => (Allow) D:\totalcmd\totalcmd64.exe
FirewallRules: [{7B6186B0-3581-48BC-B7F7-C4B0909FEED8}] => (Allow) C:\Users\jemin\AppData\Local\yc\Application\yc.exe

==================== Restore Points =========================

30-10-2017 12:41:42 Nainstalováno rozhraní DirectX
30-10-2017 12:42:26 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215
30-10-2017 12:42:34 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24210
30-10-2017 12:42:38 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
30-10-2017 12:43:05 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215

==================== Faulty Device Manager Devices =============

Name: MpKsl6ad3767b
Description: MpKsl6ad3767b
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKsl6ad3767b
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: MpKslabc8ce25
Description: MpKslabc8ce25
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKslabc8ce25
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name: wfcre
Description: wfcre
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: wfcre
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/30/2017 04:08:23 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: LMS.exe, verze: 9.5.10.1628, časové razítko: 0x51cb6db4
Název chybujícího modulu: LMS.exe, verze: 9.5.10.1628, časové razítko: 0x51cb6db4
Kód výjimky: 0xc0000005
Posun chyby: 0x00007672
ID chybujícího procesu: 0xde8
Čas spuštění chybující aplikace: 0x01d35190e4f09a2c
Cesta k chybující aplikaci: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
ID zprávy: 2b90513d-bd84-11e7-9a54-74d4351a4be5

Error: (10/30/2017 04:06:08 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generování kontextu aktivace pro C:\Users\jemin\AppData\Local\yc\Application\yc.exe se nezdařilo. Chyba v souboru manifestu nebo zásady C:\Users\jemin\AppData\Local\yc\Application\61.0.3163.100\61.0.3163.100.MANIFEST na řádku 0.
Neplatná syntaxe XML.

Error: (10/30/2017 04:06:07 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Název chybujícího modulu: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Kód výjimky: 0xc0000005
Posun chyby: 0x0029c1c0
ID chybujícího procesu: 0xa20
Čas spuštění chybující aplikace: 0x01d351909b634952
Cesta k chybující aplikaci: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
ID zprávy: dab9ea83-bd83-11e7-9a54-74d4351a4be5

Error: (10/30/2017 04:06:06 PM) (Source: TeamViewer) (EventID: 0) (User: )
Description: Event-ID 0

Error: (10/30/2017 03:07:29 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: LMS.exe, verze: 9.5.10.1628, časové razítko: 0x51cb6db4
Název chybujícího modulu: LMS.exe, verze: 9.5.10.1628, časové razítko: 0x51cb6db4
Kód výjimky: 0xc0000005
Posun chyby: 0x00007672
ID chybujícího procesu: 0xd38
Čas spuštění chybující aplikace: 0x01d35188630ccaf5
Cesta k chybující aplikaci: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
ID zprávy: a9bea41e-bd7b-11e7-b106-74d4351a4be5

Error: (10/30/2017 03:07:09 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generování kontextu aktivace pro C:\Users\jemin\AppData\Local\yc\Application\yc.exe se nezdařilo. Chyba v souboru manifestu nebo zásady C:\Users\jemin\AppData\Local\yc\Application\61.0.3163.100\61.0.3163.100.MANIFEST na řádku 0.
Neplatná syntaxe XML.

Error: (10/30/2017 03:05:13 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generování kontextu aktivace pro C:\Users\jemin\AppData\Local\yc\Application\yc.exe se nezdařilo. Chyba v souboru manifestu nebo zásady C:\Users\jemin\AppData\Local\yc\Application\61.0.3163.100\61.0.3163.100.MANIFEST na řádku 0.
Neplatná syntaxe XML.

Error: (10/30/2017 03:05:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Název chybujícího modulu: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Kód výjimky: 0xc0000005
Posun chyby: 0x0029c1c0
ID chybujícího procesu: 0xa50
Čas spuštění chybující aplikace: 0x01d3518818abb30d
Cesta k chybující aplikaci: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
ID zprávy: 57901231-bd7b-11e7-b106-74d4351a4be5

Error: (10/30/2017 03:05:10 PM) (Source: TeamViewer) (EventID: 0) (User: )
Description: Event-ID 0

Error: (10/30/2017 01:24:59 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generování kontextu aktivace pro C:\Users\jemin\AppData\Local\yc\Application\yc.exe se nezdařilo. Chyba v souboru manifestu nebo zásady C:\Users\jemin\AppData\Local\yc\Application\61.0.3163.100\61.0.3163.100.MANIFEST na řádku 0.
Neplatná syntaxe XML.


System errors:
=============
Error: (10/30/2017 04:08:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Intel(R) Management and Security Application Local Management Service neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/30/2017 04:08:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Intel(R) Management and Security Application Local Management Service bylo dosaženo časového limitu (30000 ms).

Error: (10/30/2017 04:06:07 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
UsbCharger
wfcre

Error: (10/30/2017 04:05:22 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.

Error: (10/30/2017 04:05:22 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 70.

Error: (10/30/2017 04:04:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Freemake Improver byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/30/2017 04:04:34 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Intel(R) Capability Licensing Service Interface byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 0 milisekund: Restartovat službu.

Error: (10/30/2017 04:04:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba NVIDIA NetworkService Container byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/30/2017 04:04:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba SInstalátor byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/30/2017 04:04:34 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba PnkBstrB byla neočekávaně ukončena. Tento stav nastal již 1krát.


CodeIntegrity:
===================================
Date: 2015-10-04 15:06:48.937
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:06:48.921
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:06:48.905
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:06:48.890
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:04:31.656
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:04:31.641
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:04:31.610
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:04:31.594
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 13:15:24.924
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 13:15:24.908
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
Percentage of memory in use: 40%
Total physical RAM: 8079.14 MB
Available physical RAM: 4804.08 MB
Total Virtual: 16156.46 MB
Available Virtual: 12303.29 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:167.58 GB) (Free:13.12 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:68.87 GB) NTFS
Drive e: () (Fixed) (Total:931.51 GB) (Free:85.6 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 167.7 GB) (Disk ID: 7B8D3EAE)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=167.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 7B8D3ED1)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 7B8D3ED9)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 30 říj 2017 16:58
od Kodlz
mam se ptat kolik toho mas legalne?

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 30 říj 2017 17:06
od ebola
to bych se musel zeptat prcka :)

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 31 říj 2017 09:12
od Kodlz
ok...radsi se nebudu dal vyjadrovat.


Na plose, tam kde mas umisteny FRST vytvor TXT soubor, ktery pojmenujes fixlist.txt a do nej vloz nasledujici text:

( Spusť znovu FRST a klikni na >Fix<. Po skončení akce se objeví log, který sem zkopíruj).
start
CreateRestorePoint:

CloseProcesses:

Hosts:

EmptyTemp:
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [jemin] => explorer.exe hxxp://kb-ribaki.org <==== ATTENTION
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [ttkutpvogu] => explorer "hxxp://granena.ru/?utm_source=uoua03n&utm_content=e739009bccd5f1e6d71a91bff5994529&utm_term=256F29F2108A5A51F6A9F0E8D3607E4C&utm_d=20171030" <==== ATTENTION
GroupPolicy: Restriction - Chrome <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> DefaultScope {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B1A42B343-A405-4CD6-81D8-E5685385E0CF%7D&gp=811014
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> {5630B555-ECD5-4CB2-89C5-14866469CFC3} URL = hxxp://search.centrum.cz/index.php?utm_ ... er,IE-9&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> {FFEBBF0A-C22C-4172-89FF-45215A135AC7} URL = hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B1A42B343-A405-4CD6-81D8-E5685385E0CF%7D&gp=811014
BHO: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll => No File
BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll => No File
Toolbar: HKLM - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie64.dll No File
Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll No File
Toolbar: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/ ... ontrol.cab
CHR HomePage: Default -> hxxp://mail.ru/cnt/10445?gp=811013
CHR StartupUrls: Default -> "hxxp://mail.ru/cnt/10445?gp=811013"
CHR DefaultSearchURL: Default -> hxxp://go.mail.ru/distib/ep/?q={searchTerms}&fr=ntg&product_id=%7B4E8C162F-3EC0-4D69-BFC1-1B7F8F65FF31%7D&gp=811014
CHR DefaultSearchKeyword: Default -> go.mail.ru
CHR DefaultSuggestURL: Default -> hxxp://suggests.go.mail.ru/ff3?q={searchTerms}
CHR Extension: (Mail.Ru) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhjhnafpiilpffhglajcaepjbnbjemci [2017-10-30]
CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcadgijmedbfgciegjomfpjcdchlhnif [2017-10-30]
CHR Extension: (Визуальные Закладки Mail.Ru) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhemechcanjmilllmccjbjldonmnnjjj [2017-10-30]
R2 SvcHost Service Host; C:\Windows\Microsoft\svchost.exe [0 ] () <==== ATTENTION (zero byte File/Folder)
S3 NBService; C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 esgiguard; \??\C:\Program Files (x86)\Enigma Software Group\SpyHunter\SpyHunter\esgiguard.sys [X]
S3 gdrv; \??\C:\Windows\gdrv.sys [X]
S1 wfcre; system32\drivers\wfcre.sys [X]
2017-10-30 13:08 - 2017-10-30 13:08 - 000000000 ____D C:\Windat
2017-10-30 13:08 - 2017-10-30 13:08 - 000000000 ____D C:\Program Files\LaCie Private Public
2017-10-30 13:08 - 2017-10-30 13:08 - 000000000 ____D C:\Disk
2017-10-30 13:07 - 2017-10-30 16:06 - 000000270 __RSH C:\Users\jemin\ntuser.pol
2017-10-30 13:06 - 2017-10-30 13:06 - 000003700 _____ C:\Windows\System32\Tasks\curl
2017-10-30 13:06 - 2017-10-30 13:06 - 000003500 _____ C:\Windows\System32\Tasks\curls
2017-10-30 13:06 - 2017-10-30 13:06 - 000000000 ____D C:\Users\jemin\AppData\Roaming\curl
2017-10-30 13:05 - 2017-10-30 13:13 - 000000000 ____D C:\Users\jemin\AppData\Local\yc
2017-10-30 13:05 - 2017-10-30 13:07 - 000000000 ____D C:\Users\jemin\AppData\Roaming\Subversion
2017-10-30 13:05 - 2017-10-30 13:05 - 000000000 ____D C:\Users\jemin\AppData\Local\NetBoxLogs
2017-10-30 13:02 - 2017-10-30 15:07 - 000000000 ____D C:\Users\jemin\AppData\Local\ScriptWriter
2017-10-30 13:00 - 2017-10-30 16:04 - 000002378 __RSH C:\ProgramData\ntuser.pol
2017-10-30 13:00 - 2017-10-30 13:00 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\CelGrfgXIrZdI
2017-10-30 13:00 - 2017-10-30 13:00 - 000000000 ____D C:\Program Files (x86)\ZfJRwqLPhIE
2017-10-30 12:58 - 2017-10-30 16:05 - 000000000 ____D C:\Program Files (x86)\Mail.Ru
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D43} => -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll -> No File
Task: {056500A8-0435-4561-8384-A496FBAC97C7} - System32\Tasks\curl => C:\Users\jemin\AppData\Roaming\curl\curl_7_54.exe [2017-10-30] (curl, hxxps://curl.haxx.se/) <==== ATTENTION
Task: {4223730D-4C12-4254-BE01-86CC6A888AB6} - System32\Tasks\jemin => cmd.exe /c REG ADD HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run /f /v jemin /t REG_SZ /d "explorer.exe hxxp://kb-ribaki.org" <==== ATTENTION
Task: {5F8E9919-F403-4E5B-AC2A-1793FC28D3D2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-04] (Google Inc.)
Task: {63F7A68F-5E3D-4F60-A8A2-B2A2C53A2E0B} - System32\Tasks\{4BCA7948-C65E-4C04-9FA6-5C67D67565F2} => C:\Windows\system32\pcalua.exe -a G:\setup.exe -d G:\
Task: {64918761-A7A3-4CF6-9A83-AC5BBF40580D} - System32\Tasks\{73001685-F357-48A1-99C6-356222FF07ED} => C:\Windows\system32\pcalua.exe -a H:\Setup.exe -d H:\
Task: {8FC84B15-C239-4530-A98E-57602B5F81FE} - System32\Tasks\Java Updater => C:\Users\jemin\AppData\Roaming\nircmd.exe <==== ATTENTION
Task: {94DFC7C4-254F-4093-A383-C1F69E47AB9D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-04] (Google Inc.)
Task: {9EFD5EAA-8262-456C-9945-6821529DB8B5} - System32\Tasks\{19792CD0-F7CF-4B73-BDE8-0960E3D89A0D} => C:\Windows\system32\pcalua.exe -a H:\Setup.exe -d H:\
Task: {B02A64E8-0A65-486F-9410-F6E5926388E9} - System32\Tasks\savhost => C:\Users\jemin\AppData\Local\Temp\tmpFFB7.tmp.exe <==== ATTENTION
Task: {B2779A83-89FA-4E99-B78E-BDA73CA4E384} - System32\Tasks\curls => C:\Users\jemin\AppData\Roaming\curl\curl.exe <==== ATTENTION
Task: {BCB114CF-1799-48A7-8AC4-3B232B56B0B5} - System32\Tasks\{E3135F68-FF59-4CBF-80A4-A30959DBD722} => C:\Windows\system32\pcalua.exe -a "E:\jemin\Hry\Call of Duty 2\CallOfDuty2.exe" -d "E:\jemin\Hry\Call of Duty 2"
Task: {D0C843E2-B17B-4C18-9378-048B6E5BB715} - System32\Tasks\{C6242714-9FFA-4F3B-858C-0D95F2C9C642} => C:\Windows\system32\pcalua.exe -a H:\SETUP.EXE -d H:\
Task: {DCD71949-19EB-4860-BA96-B18BACB04D71} - System32\Tasks\{E03B9112-FF17-4C3F-BF73-85BEE52C441A} => C:\Windows\system32\pcalua.exe -a "C:\Users\jemin\Desktop\NHL 2009 Cestina+Cesky Komentar\NHL09_CZ.exe" -d "C:\Users\jemin\Desktop\NHL 2009 Cestina+Cesky Komentar"
Task: {F10C09C5-604A-4000-A811-3DFB777B48D9} - \{FB6429D6-6C14-4633-A83B-164E822229EA} -> No File <==== ATTENTION
2017-10-30 13:00 - 2017-10-30 13:00 - 000304128 ____N () C:\Program Files (x86)\ZfJRwqLPhIE\landhTGixw.exe
2017-10-30 13:00 - 2017-10-30 13:00 - 000402432 ____N () C:\Program Files (x86)\ZfJRwqLPhIE\k7zVdU1Vp.dll
2017-10-30 13:00 - 2017-10-30 13:00 - 000548864 ____N () C:\Program Files (x86)\ZfJRwqLPhIE\7ipk0.dll
AlternateDataStreams: C:\ProgramData:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\Users\All Users:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\ProgramData\Application Data:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\ProgramData\Data aplikací:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\ProgramData\TEMP:8CE646EE [145]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{4D006E00-6200-4A00-6600-730072007200} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{51007100-4F00-6F00-5300-4F0072005900} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{68005900-5000-5500-3600-31007A003200} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{6C007200-6300-7500-3800-4F0036006F00} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Local\Temp:{78002F00-7800-4A00-5900-670073006400} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup:{51007100-4F00-6F00-5300-4F0072005900} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup:{6C007200-6300-7500-3800-4F0036006F00} [832]

end

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 31 říj 2017 12:57
od ebola
díky za pomoc-vše je pryč -
žádné stránky už neneskakujou

poslední log je zde -
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-10-2017
Ran by jemin (administrator) on JEMIN-PC (31-10-2017 12:53:57)
Running from C:\Users\jemin\Desktop
Loaded Profiles: jemin (Available Profiles: jemin)
Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\Home\NetworkLicenseServer.exe
(Freemake) C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(PS Media s.r.o.) C:\Windows\SysWOW64\ssins.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Beepa P/L) C:\Fraps\fraps.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Logitech Inc.) C:\Program Files\Logitech\Gaming Software\LWEMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe
(Disc Soft Ltd) C:\Program Files (x86)\DAEMON Tools Pro\DTShellHlp.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Tošovský Jan) C:\Program Files (x86)\Noční obloha\vesmir.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Beepa P/L) C:\Fraps\fraps64.dat
(Hewlett-Packard Co.) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [Start WingMan Profiler] => C:\Program Files\Logitech\Gaming Software\LWEMon.exe [190536 2000-01-01] (Logitech Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13876952 2000-01-01] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [Svátky a výročí] => C:\Program Files (x86)\OKsoftware\Svátky a výročí\Vyroci.exe [1019904 2015-10-04] (Igor Gottwald - OKsoftware)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [HP Deskjet 3520 series (NET)] => C:\Program Files\HP\HP Deskjet 3520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832272 2017-08-25] (Skype Technologies S.A.)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3102496 2017-10-25] (Valve Corporation)
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [ycAutoLaunch_8BD45C324E1801E78C906E73D35C9CF9] => "C:\Users\jemin\AppData\Local\yc\Application\yc.exe" /prefetch:5
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\Run: [KometaAutoLaunch_99329504B9DDFAA4DB3EFCC619BA3175] => "C:\Users\jemin\AppData\Local\Kometa\Application\kometa.exe" --no-startup-window
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\GamePark klient 2.lnk [2015-11-05]
ShortcutTarget: GamePark klient 2.lnk -> C:\Program Files\GamePark2\gpcl.exe (Allstar Group, s.r.o.)
Startup: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk [2017-10-31]
ShortcutTarget: Sledovat výstrahy inkoustu - HP Deskjet 3520 series (Síť).lnk -> C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Vesmír na dlani.lnk [2014-03-28]
ShortcutTarget: Vesmír na dlani.lnk -> C:\Program Files (x86)\Noční obloha\vesmir.exe (Tošovský Jan)
BootExecute: autocheck autochk * sh4native Sh4Removal

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 176.12.112.2 176.12.112.1
Tcpip\..\Interfaces\{D3772582-8A4C-49F2-A2DC-A95D5181C2B6}: [DhcpNameServer] 176.12.112.2 176.12.112.1

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.seznam.cz/
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> {1A366EDE-D70D-49EE-A453-A757CE160C68} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2488} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2014-05-30] (Oracle Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-11-20] (Google Inc.)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
BHO: Lišta Centrum.cz - pomocný objekt -> {C91BA35D-6516-489F-A203-2992ED9A4132} -> C:\Program Files (x86)\Centrum Holdings s.r.o\Lišta Centrum.cz\cenbho64.dll [2013-01-23] ()
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2014-05-30] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-20] (Google Inc.)
BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
BHO-x32: Lišta Centrum.cz - pomocný objekt -> {C91BA35D-6516-489F-A203-2992ED9A4132} -> C:\Program Files (x86)\Centrum Holdings s.r.o\Lišta Centrum.cz\cenbho32.dll [2013-01-23] ()
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-11-20] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-11-20] (Google Inc.)
Toolbar: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-11-20] (Google Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-09-06] (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-07-18] (Skype Technologies)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-07-20]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF Plugin: @java.com/DTPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-05-30] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.55.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2014-05-30] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-16] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\jemin\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3158200304-2993081581-1989350980-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\jemin\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-13] (RocketLife, LLP)
FF Plugin HKU\S-1-5-21-3158200304-2993081581-1989350980-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\jemin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-09-05] (Unity Technologies ApS)

Chrome:
=======
CHR DefaultProfile: Default
CHR NewTab: Default -> Active:"chrome-extension://lhemechcanjmilllmccjbjldonmnnjjj/visual-bookmarks.html"
CHR Profile: C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default [2017-10-31]
CHR Extension: (Prezentace) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-13]
CHR Extension: (Dokumenty) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-13]
CHR Extension: (Disk Google) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-24]
CHR Extension: (YouTube) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Vyhledávání Google) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Adobe Acrobat) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-04]
CHR Extension: (Tabulky) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-13]
CHR Extension: (Dokumenty Google offline) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-24]
CHR Extension: (Adblocker pro Youtube™) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\knmnopfmccchnnfdoiddbihbcboeedll [2017-10-30]
CHR Extension: (Визуальные Закладки Mail.Ru) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhemechcanjmilllmccjbjldonmnnjjj [2017-10-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (Gmail) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\jemin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-28]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bhjhnafpiilpffhglajcaepjbnbjemci] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hcadgijmedbfgciegjomfpjcdchlhnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lhemechcanjmilllmccjbjldonmnnjjj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ABBYY.Licensing.FineReader.Home.10.0; C:\Program Files (x86)\Common Files\ABBYY\FineReader\10.00\Licensing\Home\NetworkLicenseServer.exe [814344 2010-07-21] (ABBYY)
S3 AppleChargerSrv; C:\Windows\System32\AppleChargerSrv.exe [31272 2010-04-06] ()
R2 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [108032 2016-07-19] (Freemake) [File not signed]
S2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319096 2016-01-13] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2015-10-04] (Intel Corporation)
S2 LMS; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [432088 2015-10-04] (Intel Corporation) [File not signed]
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [590880 2017-09-06] (McAfee, Inc.)
R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
S3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [271920 2015-10-04] (Nero AG)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [518080 2017-10-11] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-10-12] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [460736 2017-10-11] (NVIDIA Corporation)
S3 PAExec; C:\Windows\PAExec.exe [189112 2017-01-28] (Power Admin LLC)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [75064 2016-01-03] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [214520 2017-01-31] ()
R2 ssinstall; C:\Windows\SysWOW64\ssins.exe [4696960 2016-11-23] (PS Media s.r.o.)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5467920 2015-10-04] (TeamViewer GmbH) [File not signed]
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 androidusb; C:\Windows\System32\Drivers\androidusb.sys [32768 2010-04-29] (Google Inc)
R1 AppleCharger; C:\Windows\System32\DRIVERS\AppleCharger.sys [21584 2013-02-19] ()
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [50464 2014-05-30] (AVG Technologies)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [130688 2016-07-22] (Samsung Electronics Co., Ltd.)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2014-06-28] (Disc Soft Ltd)
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28008 2013-08-07] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-09-16] (Intel Corporation)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
S1 MpKsl5c8fda79; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKsl5c8fda79.sys [49392 2017-10-30] () [File not signed]
S1 MpKsl6ad3767b; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKsl6ad3767b.sys [49392 2017-10-30] () [File not signed]
S1 MpKslabc8ce25; C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{0FB98098-255E-42AD-A999-79A93E22728B}\MpKslabc8ce25.sys [49392 2017-10-30] () [File not signed]
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-10-11] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [57792 2017-08-18] (NVIDIA Corporation)
S3 ssudmdm; C:\Windows\System32\DRIVERS\ssudmdm.sys [164992 2016-07-22] (Samsung Electronics Co., Ltd.)
S1 UsbCharger; C:\Windows\System32\DRIVERS\UsbCharger.sys [21584 2013-05-06] ()

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-10-31 12:53 - 2017-10-31 12:53 - 000000008 __RSH C:\Users\jemin\ntuser.pol
2017-10-31 12:53 - 2017-10-31 12:53 - 000000008 __RSH C:\ProgramData\ntuser.pol
2017-10-31 12:52 - 2017-10-31 12:52 - 000024527 _____ C:\Users\jemin\Desktop\Fixlog.txt
2017-10-31 12:51 - 2017-10-31 12:54 - 000022838 _____ C:\Users\jemin\Desktop\FRST.txt
2017-10-31 12:51 - 2017-10-31 12:51 - 000099504 _____ C:\Users\jemin\Desktop\Addition.txt
2017-10-31 11:15 - 2017-10-31 11:15 - 000000000 _____ C:\Users\jemin\Desktop\Nový textový dokument.txt
2017-10-31 06:16 - 2017-10-31 12:51 - 000000000 ____D C:\Users\jemin\Documents\vir
2017-10-31 06:08 - 2017-10-31 06:08 - 000000854 _____ C:\Users\jemin\Desktop\Wolfenstein II The New Colossus.lnk
2017-10-31 06:08 - 2017-10-31 06:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wolfenstein II The New Colossus
2017-10-30 16:41 - 2017-10-30 16:41 - 000000000 ____D C:\Users\jemin\Desktop\Wolfenstein II The New Colossus
2017-10-30 16:34 - 2017-10-30 16:34 - 000681528 _____ C:\Windows\Minidump\103017-14414-01.dmp
2017-10-30 16:32 - 2017-10-27 18:46 - 040237688 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 036194424 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 035156928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 029236344 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 023262464 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 019037416 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 016763000 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2017-10-30 16:32 - 2017-10-27 18:46 - 013864232 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 013254520 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 011779328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 010882720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 003807680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 003346552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 001989056 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438813.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 001673848 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438813.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 001135464 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 001099200 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 001030592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000981112 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000932472 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000885680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000615360 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000527288 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000505976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000446216 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000407064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000171896 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000154392 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000149552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2017-10-30 16:32 - 2017-10-27 18:46 - 000132256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2017-10-30 16:17 - 2017-10-30 16:17 - 002403328 _____ (Farbar) C:\Users\jemin\Desktop\FRST64.exe
2017-10-30 15:12 - 2017-10-30 15:12 - 000000000 ____D C:\rsit
2017-10-30 15:10 - 2017-10-30 16:16 - 000029696 _____ C:\Users\jemin\AppData\Local\MSGBOX.EXE
2017-10-30 12:51 - 2017-10-30 12:51 - 000681696 _____ C:\Windows\Minidump\103017-11996-01.dmp
2017-10-30 12:49 - 2017-10-26 19:38 - 000000000 ___RD C:\Users\jemin\Desktop\CODEX
2017-10-30 12:23 - 2017-10-30 12:23 - 000682024 _____ C:\Windows\Minidump\103017-20841-01.dmp
2017-10-30 09:58 - 2017-10-30 09:58 - 000000000 ____D C:\NVIDIA
2017-10-26 20:50 - 2017-10-26 20:50 - 000000000 ____D C:\Users\jemin\AppData\Local\ELEX
2017-10-26 18:22 - 2017-10-26 18:22 - 000000567 _____ C:\Users\Public\Desktop\ELEX.lnk
2017-10-26 18:22 - 2017-10-26 18:22 - 000000567 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ELEX.lnk
2017-10-26 18:14 - 2017-10-26 18:14 - 000000000 ____D C:\Users\jemin\AppData\Roaming\Burnaware
2017-10-26 18:14 - 2017-10-26 18:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BurnAware Free
2017-10-26 18:14 - 2017-10-26 18:14 - 000000000 ____D C:\Program Files (x86)\BurnAware Free
2017-10-23 18:20 - 2017-10-23 18:20 - 000413016 _____ C:\Windows\Minidump\102317-16333-01.dmp
2017-10-23 17:55 - 2017-10-27 18:46 - 000492048 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 001988032 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438800.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 001606592 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438800.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000225208 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
2017-10-23 17:55 - 2017-10-12 22:33 - 000045496 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
2017-10-23 17:55 - 2017-10-12 22:33 - 000000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2017-10-23 17:55 - 2017-10-12 22:33 - 000000669 _____ C:\Windows\system32\nv-vk64.json
2017-10-23 17:30 - 2017-10-11 02:05 - 000050624 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-10-16 18:57 - 2017-10-16 18:57 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\CodeHorizon
2017-10-16 18:56 - 2017-10-16 18:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gold Rush The Game
2017-10-16 16:42 - 2017-10-16 16:42 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-10-16 16:20 - 2017-09-13 16:33 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-10-16 16:20 - 2017-09-13 16:32 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-10-16 16:20 - 2017-09-13 16:32 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-10-16 16:20 - 2017-09-13 16:32 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-10-16 16:20 - 2017-09-13 16:32 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-10-16 16:20 - 2017-09-13 16:31 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-10-16 16:20 - 2017-09-13 16:28 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:27 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:13 - 004001512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-10-16 16:20 - 2017-09-13 16:13 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-10-16 16:20 - 2017-09-13 16:10 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-10-16 16:20 - 2017-09-13 16:09 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:08 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 16:05 - 000324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2017-10-16 16:20 - 2017-09-13 16:00 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-10-16 16:20 - 2017-09-13 16:00 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-10-16 16:20 - 2017-09-13 16:00 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-10-16 16:20 - 2017-09-13 16:00 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-10-16 16:20 - 2017-09-13 15:57 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-10-16 16:20 - 2017-09-13 15:56 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-10-16 16:20 - 2017-09-13 15:53 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-10-16 16:20 - 2017-09-13 15:53 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-10-16 16:20 - 2017-09-13 15:53 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-10-16 16:20 - 2017-09-13 15:52 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-10-16 16:20 - 2017-09-13 15:52 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-10-16 16:20 - 2017-09-13 15:50 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-10-16 16:20 - 2017-09-13 15:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-10-16 16:20 - 2017-09-13 15:46 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-10-16 16:20 - 2017-09-13 15:46 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-10-16 16:20 - 2017-09-13 15:46 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-10-16 16:20 - 2017-09-09 01:45 - 000395984 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-10-16 16:20 - 2017-09-09 00:47 - 000347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-10-16 16:20 - 2017-09-08 16:34 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-10-16 16:20 - 2017-09-08 16:30 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-10-16 16:20 - 2017-09-08 16:30 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-10-16 16:20 - 2017-09-08 16:14 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-10-16 16:20 - 2017-09-08 16:13 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-10-16 16:20 - 2017-09-08 16:13 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-10-16 16:20 - 2017-09-08 16:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-10-16 16:20 - 2017-09-08 16:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-10-16 16:20 - 2017-09-08 16:10 - 000312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-10-16 16:20 - 2017-09-08 16:10 - 000109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-10-16 16:20 - 2017-09-08 16:09 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-10-16 16:20 - 2017-09-08 16:00 - 003222016 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-10-16 16:20 - 2017-09-08 16:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-10-16 16:20 - 2017-09-08 16:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-10-16 16:20 - 2017-09-08 15:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-10-16 16:20 - 2017-09-08 15:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-10-16 16:20 - 2017-09-08 15:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-10-16 16:20 - 2017-09-08 15:20 - 000345088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-10-16 16:20 - 2017-09-08 15:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-10-16 16:20 - 2017-09-07 22:38 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-10-16 16:20 - 2017-09-07 22:37 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-10-16 16:20 - 2017-09-07 22:19 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-10-16 16:20 - 2017-09-07 22:18 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-10-16 16:20 - 2017-09-07 22:18 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-10-16 16:20 - 2017-09-07 22:17 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-10-16 16:20 - 2017-09-07 22:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-10-16 16:20 - 2017-09-07 22:15 - 002902528 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-10-16 16:20 - 2017-09-07 22:08 - 025729536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-10-16 16:20 - 2017-09-07 22:08 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-10-16 16:20 - 2017-09-07 22:07 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-10-16 16:20 - 2017-09-07 22:02 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-10-16 16:20 - 2017-09-07 22:01 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-10-16 16:20 - 2017-09-07 22:01 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-10-16 16:20 - 2017-09-07 22:01 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-10-16 16:20 - 2017-09-07 22:00 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-10-16 16:20 - 2017-09-07 21:52 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-10-16 16:20 - 2017-09-07 21:48 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-10-16 16:20 - 2017-09-07 21:40 - 005982208 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-10-16 16:20 - 2017-09-07 21:39 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-10-16 16:20 - 2017-09-07 21:38 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-10-16 16:20 - 2017-09-07 21:37 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-10-16 16:20 - 2017-09-07 21:33 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-10-16 16:20 - 2017-09-07 21:32 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-10-16 16:20 - 2017-09-07 21:29 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-10-16 16:20 - 2017-09-07 21:27 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-10-16 16:20 - 2017-09-07 21:13 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-10-16 16:20 - 2017-09-07 21:10 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-10-16 16:20 - 2017-09-07 21:10 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-10-16 16:20 - 2017-09-07 21:08 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-10-16 16:20 - 2017-09-07 21:08 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-10-16 16:20 - 2017-09-07 20:44 - 015262720 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-10-16 16:20 - 2017-09-07 20:40 - 003240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-10-16 16:20 - 2017-09-07 20:27 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-10-16 16:20 - 2017-09-07 20:27 - 001548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-10-16 16:20 - 2017-09-07 20:17 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-10-16 16:20 - 2017-09-07 20:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-10-16 16:20 - 2017-09-07 20:10 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-10-16 16:20 - 2017-09-07 20:10 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-10-16 16:20 - 2017-09-07 20:10 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-10-16 16:20 - 2017-09-07 20:09 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-10-16 16:20 - 2017-09-07 20:04 - 020267008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-10-16 16:20 - 2017-09-07 20:03 - 002292736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-10-16 16:20 - 2017-09-07 20:03 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-10-16 16:20 - 2017-09-07 20:02 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-10-16 16:20 - 2017-09-07 19:59 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-10-16 16:20 - 2017-09-07 19:58 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-10-16 16:20 - 2017-09-07 19:58 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-10-16 16:20 - 2017-09-07 19:58 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-10-16 16:20 - 2017-09-07 19:49 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-10-16 16:20 - 2017-09-07 19:44 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-10-16 16:20 - 2017-09-07 19:44 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-10-16 16:20 - 2017-09-07 19:43 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-10-16 16:20 - 2017-09-07 19:40 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-10-16 16:20 - 2017-09-07 19:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-10-16 16:20 - 2017-09-07 19:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-10-16 16:20 - 2017-09-07 19:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-10-16 16:20 - 2017-09-07 19:29 - 004547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-10-16 16:20 - 2017-09-07 19:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-10-16 16:20 - 2017-09-07 19:26 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-10-16 16:20 - 2017-09-07 19:25 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-10-16 16:20 - 2017-09-07 19:25 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-10-16 16:20 - 2017-09-07 19:17 - 013677568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-10-16 16:20 - 2017-09-07 19:01 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-10-16 16:20 - 2017-09-07 18:57 - 001316864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-10-16 16:20 - 2017-09-07 18:57 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-10-16 16:20 - 2017-09-07 16:31 - 002851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2017-10-16 16:20 - 2017-09-07 16:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2017-10-16 16:20 - 2017-09-07 15:55 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-10-16 16:20 - 2017-09-07 15:55 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-10-16 16:20 - 2017-09-07 15:55 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-10-16 16:20 - 2017-08-19 16:28 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-10-16 16:20 - 2017-08-19 16:28 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-10-16 16:20 - 2017-08-19 16:28 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2017-10-16 16:20 - 2017-08-19 16:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-10-16 16:20 - 2017-08-19 16:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2017-10-16 16:20 - 2017-08-19 16:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2017-10-16 16:20 - 2017-08-19 16:08 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2017-10-16 16:20 - 2017-08-19 16:08 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2017-10-16 16:20 - 2017-08-19 15:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2017-10-16 16:20 - 2017-08-19 15:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2017-10-16 16:20 - 2017-08-14 18:35 - 001032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-10-16 16:20 - 2017-08-14 18:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-10-16 16:20 - 2017-08-14 18:35 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2017-10-16 16:20 - 2017-08-13 22:46 - 001112576 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-10-16 16:20 - 2017-08-13 22:45 - 000162816 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-10-16 16:20 - 2017-08-13 22:45 - 000040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2017-10-16 16:20 - 2017-08-13 22:45 - 000020992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys
2017-10-13 20:43 - 2017-10-13 20:43 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\JetCat Games
2017-10-13 20:28 - 2017-10-13 20:28 - 000000599 _____ C:\Users\Public\Desktop\Heliborne.lnk
2017-10-13 20:28 - 2017-10-13 20:28 - 000000599 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heliborne.lnk
2017-10-13 18:24 - 2017-10-13 18:24 - 000001138 _____ C:\Users\Public\Desktop\Middle Earth - Shadow of War.lnk
2017-10-13 17:07 - 2017-10-13 17:07 - 000000000 ____D C:\Users\jemin\AppData\Local\TangoGameworks
2017-10-13 16:49 - 2017-10-13 16:49 - 000000741 _____ C:\Users\jemin\Desktop\The Evil Within 2.lnk
2017-10-13 16:49 - 2017-10-13 16:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Evil Within 2
2017-10-05 07:29 - 2017-10-05 07:29 - 000000000 ____D C:\Users\jemin\Documents\Road Redemption
2017-10-05 07:29 - 2017-10-05 07:29 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\Dark Seas Interactive
2017-10-05 05:30 - 2017-10-05 05:30 - 000000662 _____ C:\Users\Public\Desktop\FIFA18.lnk
2017-10-05 05:30 - 2017-10-05 05:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA18
2017-10-05 04:51 - 2017-10-05 04:58 - 000000000 ____D C:\Users\jemin\Documents\Project CARS 2
2017-10-05 04:51 - 2017-10-05 04:51 - 000000000 ____D C:\ProgramData\Slightly Mad Studios
2017-10-05 04:44 - 2017-10-05 04:44 - 000000734 _____ C:\Users\jemin\Desktop\Project CARS 2.lnk
2017-10-05 04:44 - 2017-10-05 04:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project CARS 2
2017-10-04 06:21 - 2017-09-16 20:23 - 001988216 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6438569.dll
2017-10-04 06:21 - 2017-09-16 20:23 - 001606592 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6438569.dll
2017-10-04 05:47 - 2017-10-05 06:18 - 000000000 ____D C:\Users\jemin\Documents\FIFA 18
2017-10-02 20:55 - 2017-10-02 20:55 - 000000359 _____ C:\Users\jemin\Desktop\Počítač – zástupce.lnk

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-10-31 12:53 - 2017-07-22 21:24 - 000000000 ____D C:\Program Files (x86)\Steam
2017-10-31 12:53 - 2017-01-28 07:32 - 000000000 ____D C:\ProgramData\NVIDIA
2017-10-31 12:53 - 2015-10-01 18:15 - 000000000 ____D C:\FRST
2017-10-31 12:53 - 2015-09-24 06:14 - 000000000 __SHD C:\Users\jemin\IntelGraphicsProfiles
2017-10-31 12:53 - 2014-11-18 15:56 - 000000000 ____D C:\Users\jemin\Documents\Assassin's Creed Unity
2017-10-31 12:53 - 2014-03-20 15:53 - 000000000 ____D C:\Users\jemin\AppData\Roaming\Skype
2017-10-31 12:53 - 2014-03-20 14:14 - 000003138 _____ C:\Windows\System32\Tasks\FRAPS
2017-10-31 12:53 - 2014-03-20 14:14 - 000000000 ____D C:\Fraps
2017-10-31 12:53 - 2014-03-18 16:12 - 000000000 ____D C:\Users\jemin
2017-10-31 12:53 - 2009-07-14 06:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-10-31 12:52 - 2017-01-07 16:24 - 000000000 ____D C:\Users\jemin\AppData\LocalLow\Temp
2017-10-31 12:52 - 2014-03-23 15:59 - 000003970 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{6E8F5136-D671-44DD-8634-E280556768FA}
2017-10-31 12:52 - 2009-07-14 04:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
2017-10-31 11:28 - 2009-07-26 19:41 - 000669904 _____ C:\Windows\system32\perfh005.dat
2017-10-31 11:28 - 2009-07-26 19:41 - 000142062 _____ C:\Windows\system32\perfc005.dat
2017-10-31 11:28 - 2009-07-14 06:13 - 001587976 _____ C:\Windows\system32\PerfStringBackup.INI
2017-10-31 11:28 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\inf
2017-10-31 09:09 - 2009-07-14 05:45 - 000020192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-10-31 09:09 - 2009-07-14 05:45 - 000020192 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-10-30 18:34 - 2014-05-10 16:37 - 000000000 ____D C:\AdwCleaner
2017-10-30 16:34 - 2014-04-11 18:06 - 000000000 ____D C:\Windows\Minidump
2017-10-30 15:15 - 2016-06-25 05:36 - 000000000 ____D C:\Program Files\trend micro
2017-10-30 12:42 - 2014-03-20 14:08 - 000000000 ____D C:\ProgramData\Package Cache
2017-10-30 12:20 - 2017-01-28 07:32 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-10-30 12:20 - 2017-01-28 07:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-10-27 18:46 - 2017-04-19 17:07 - 018207248 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2017-10-27 18:46 - 2017-01-28 07:31 - 021744632 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2017-10-27 18:46 - 2017-01-28 07:31 - 019012232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2017-10-27 18:46 - 2017-01-28 07:31 - 015027984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2017-10-27 18:46 - 2017-01-28 07:31 - 004284496 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2017-10-27 18:46 - 2017-01-28 07:31 - 003799032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2017-10-27 18:46 - 2017-01-28 07:31 - 000046182 _____ C:\Windows\system32\nvinfo.pb
2017-10-27 18:33 - 2017-01-28 07:34 - 000000000 ____D C:\Users\jemin\AppData\Local\NVIDIA
2017-10-27 03:46 - 2017-04-21 21:03 - 000000000 ____D C:\Program Files (x86)\McAfee
2017-10-26 18:14 - 2016-08-18 18:16 - 000000000 ____D C:\ProgramData\McAfee
2017-10-26 04:57 - 2017-04-19 18:55 - 000000000 ____D C:\Users\jemin\Documents\poruce
2017-10-25 18:42 - 2015-10-05 20:03 - 000004396 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-10-25 18:42 - 2015-04-16 11:58 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-10-25 18:42 - 2015-04-16 11:58 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-25 18:42 - 2014-03-20 14:13 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-10-25 18:42 - 2014-03-20 14:13 - 000000000 ____D C:\Windows\system32\Macromed
2017-10-23 18:20 - 2017-01-28 07:32 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-10-23 17:56 - 2017-02-20 16:21 - 000000000 ____D C:\Users\jemin\AppData\Roaming\NVIDIA
2017-10-23 17:56 - 2017-01-28 07:30 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2017-10-23 17:31 - 2017-08-23 18:16 - 000003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:31 - 2017-01-28 07:32 - 000003798 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 08:49 - 000004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-23 17:30 - 2017-01-28 07:32 - 000003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-19 19:03 - 2014-03-20 15:55 - 000000000 ____D C:\Users\jemin\AppData\Roaming\vlc
2017-10-16 22:25 - 2014-03-18 16:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2017-10-16 21:09 - 2009-07-14 04:20 - 000000000 ____D C:\Windows\rescache
2017-10-16 17:40 - 2009-07-14 05:45 - 000418504 _____ C:\Windows\system32\FNTCACHE.DAT
2017-10-16 16:44 - 2014-03-18 17:27 - 000000000 ____D C:\Windows\system32\MRT
2017-10-16 16:42 - 2014-03-18 17:27 - 126925120 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-10-15 12:38 - 2009-07-14 06:08 - 000032626 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-10-13 18:53 - 2015-08-01 10:41 - 000000000 ____D C:\Users\jemin\Documents\WB Games
2017-10-12 22:33 - 2017-01-28 07:31 - 001615472 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
2017-10-12 21:25 - 2016-09-17 06:17 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2017-10-12 20:55 - 2017-01-28 07:32 - 005960824 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 002587584 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 001766520 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 000607352 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 000449472 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 000122816 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2017-10-12 20:55 - 2017-01-28 07:32 - 000081856 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2017-10-12 20:54 - 2017-01-28 07:32 - 007799931 _____ C:\Windows\system32\nvcoproc.bin
2017-10-11 02:05 - 2017-01-28 08:49 - 000186304 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-10-11 02:05 - 2017-01-28 08:49 - 000152512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-10-11 02:05 - 2017-01-28 07:32 - 001796032 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-10-11 02:05 - 2017-01-28 07:32 - 001577920 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-10-11 02:05 - 2017-01-28 07:32 - 000918976 _____ (NVIDIA Corporation) C:\Windows\system32\NvRtmpStreamer64.dll
2017-10-11 00:26 - 2017-01-28 08:49 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2017-10-04 06:31 - 2014-03-20 14:30 - 000000000 ____D C:\Users\jemin\AppData\Local\CrashDumps
2017-10-03 05:30 - 2014-03-30 06:38 - 000000000 ____D C:\Users\jemin\Documents\My Games
2017-10-03 04:08 - 2015-05-22 18:03 - 000000111 _____ C:\Users\jemin\Documents\hesla.txt
2017-10-02 20:56 - 2015-05-20 14:49 - 000000000 ____D C:\Games
2017-10-02 20:56 - 2015-03-03 14:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-10-02 20:56 - 2009-07-14 06:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games

==================== Files in the root of some directories =======

2014-03-20 18:44 - 2014-03-20 18:45 - 000000156 _____ () C:\Users\jemin\AppData\Roaming\default.rss
2014-10-08 15:49 - 2014-05-24 20:09 - 000042496 ___SH (Open Source Software community project) C:\Users\jemin\AppData\Roaming\pthreadGC2-w64.dll
2014-03-29 08:04 - 2017-07-12 19:26 - 000061952 _____ () C:\Users\jemin\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-10-30 15:10 - 2017-10-30 16:16 - 000029696 _____ () C:\Users\jemin\AppData\Local\MSGBOX.EXE
2014-05-30 06:41 - 2014-06-02 05:48 - 000007618 _____ () C:\Users\jemin\AppData\Local\Resmon.ResmonCfg
2014-03-31 14:50 - 2014-03-31 14:50 - 000000080 _____ () C:\Users\jemin\AppData\Local\X-Plane Installer.prf
2017-04-06 06:41 - 2017-04-06 12:21 - 000000015 _____ () C:\Users\jemin\AppData\Local\X-Plane_drm_11.prf
2014-03-31 14:28 - 2014-03-31 14:28 - 000000020 _____ () C:\Users\jemin\AppData\Local\x-plane_install_10.txt
2017-04-06 06:38 - 2017-04-06 06:38 - 000000036 _____ () C:\Users\jemin\AppData\Local\x-plane_install_11.txt
2014-05-21 13:50 - 2014-05-21 13:50 - 000000057 _____ () C:\ProgramData\Ament.ini
2015-09-24 07:01 - 2015-09-24 07:01 - 000000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-10-30 00:55

==================== End of FRST.txt ============================

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 31 říj 2017 12:58
od ebola
druhý log
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-10-2017
Ran by jemin (31-10-2017 12:54:15)
Running from C:\Users\jemin\Desktop
Windows 7 Ultimate Service Pack 1 (X64) (2014-03-18 15:12:06)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3158200304-2993081581-1989350980-500 - Administrator - Disabled)
Guest (S-1-5-21-3158200304-2993081581-1989350980-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3158200304-2993081581-1989350980-1002 - Limited - Enabled)
jemin (S-1-5-21-3158200304-2993081581-1989350980-1000 - Administrator - Enabled) => C:\Users\jemin

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Disabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Disabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

«Alan Wake`s American Nightmare» 1.0 (HKLM-x32\...\Alan Wake`s American Nightmare_is1) (Version: 1.0 - R.G. Catalyst)
3GP Player 1.1.7 (HKLM-x32\...\3GP Player_is1) (Version: - Bobabo)
3Planesoft Screensaver Manager 1.4 (HKLM-x32\...\3Planesoft Screensaver Manager_is1) (Version: 1.4 - 3Planesoft)
7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
7-Zip 9.20 (HKLM-x32\...\7-Zip) (Version: - )
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
ABBYY FineReader 10 Home Edition (HKLM-x32\...\{F1000000-0012-0000-0000-074957833700}) (Version: 10.00.91.8953 - ABBYY)
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated)
Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.183 - Adobe Systems Incorporated)
Aktualizace NVIDIA 29.1.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 29.1.0.0 - NVIDIA Corporation) Hidden
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_ENTERPRISER_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_ENTERPRISER_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_ENTERPRISER_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Alternative Look for Triss (HKLM-x32\...\Alternative Look for Triss_is1) (Version: 1.0.0.0 - GOG.com)
Alternative Look for Yennefer (HKLM-x32\...\Alternative Look for Yennefer_is1) (Version: 1.0.0.0 - GOG.com)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 388.00 - NVIDIA Corporation) Hidden
AoA Audio Extractor (HKLM-x32\...\{D1725D54-279A-40C5-A70D-23C1785DB920}_is1) (Version: - AoAMedia.com)
Ballad Heroes - Neutral Gwent Card Set (HKLM-x32\...\Ballad Heroes - Neutral Gwent Card Set_is1) (Version: 1.0.0.0 - GOG.com)
Beard and Hairstyle Set (HKLM-x32\...\Beard and Hairstyle Set_is1) (Version: 1.0.0.0 - GOG.com)
Bing Bar (HKLM-x32\...\{3611CA6C-5FCA-4900-A329-6A118123CCFC}) (Version: 7.1.355.0 - Microsoft Corporation)
BitTorrent (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\BitTorrent) (Version: 7.9.2.34312 - BitTorrent Inc.)
Broken Sword 5 (HKLM-x32\...\Broken Sword 5_is1) (Version: - Revolution Software Ltd)
BurnAware Free 10.6 (HKLM-x32\...\BurnAware Free_is1) (Version: - Burnaware)
Call of Duty(R) 2 (HKLM-x32\...\{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.00.0000 - Activision) Hidden
Call of Duty(R) 2 (HKLM-x32\...\InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.00.0000 - Activision)
Call of Duty(R) 2 Patch 1.3 (HKLM-x32\...\{C13E90B0-4E1C-11DB-6784-0152EAA218BE}) (Version: 1.3 - Activision)
Call of Duty: Infinite Warfare (HKLM\...\Y2FsbG9mZHV0eWluZmluaXRld2FyZmFyZQ_is1) (Version: 1 - )
CCleaner (HKLM\...\CCleaner) (Version: 4.12 - Piriform)
CCleaner (HKLM-x32\...\CCleaner) (Version: 2.36 - Piriform)
CoD 2 čeština 1.1 (HKLM-x32\...\CoD 2 čeština_is1) (Version: - #'Pan[S[al!er!)
CPUID CPU-Z 1.71.1 (HKLM\...\CPUID CPU-Z_is1) (Version: - )
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.1.0.0 - Electronic Arts)
Cuckoo Clock 3D Screensaver 1.0 (HKLM-x32\...\Cuckoo Clock 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
DAEMON Tools Pro (HKLM-x32\...\DAEMON Tools Pro) (Version: 5.5.0.0387 - Disc Soft Ltd)
Depth Hunter 2 - Deep Dive (HKLM-x32\...\Depth Hunter 2 - Deep Dive_is1) (Version: - )
DROPCLOCK 1.0.1 (HKLM-x32\...\DROPCLOCK_is1) (Version: - tha ltd.)
ELEX (HKLM\...\ZWxleA_is1) (Version: 1 - )
Euro Fishing (HKLM-x32\...\Euro Fishing_is1) (Version: - )
Far Cry 4 Update v1.7 (HKLM-x32\...\RmFyQ3J5NA==_is1) (Version: 1 - )
Far Cry Primal (HKLM-x32\...\Far Cry Primal_R.G. Mechanics_is1) (Version: - R.G. Mechanics, Panky)
Farm Expert 2016 - Fruit Company (HKLM-x32\...\Farm Expert 2016 - Fruit Company_is1) (Version: - )
FIFA18 version 1.0 (HKLM\...\FIFA18_is1) (Version: 1.0 - STEAMPUNKS) <==== ATTENTION
FileZilla Client 3.17.0.1 (HKLM-x32\...\FileZilla Client) (Version: 3.17.0.1 - Tim Kosse)
Fireside Christmas 3D Screensaver 1.0 (HKLM-x32\...\Fireside Christmas 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
Fireside Christmas 3D Screensaver and Animated Wallpaper 1.1 (HKLM-x32\...\Fireside Christmas 3D Screensaver and Animated Wallpaper_is1) (Version: 1.1 - 3Planesoft)
Fraps (HKLM-x32\...\Fraps) (Version: - )
Freemake Video Converter verze 4.1.9 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.9 - Ellora Assets Corporation)
Futuremark SystemInfo (HKLM-x32\...\{BEE64C14-BEF1-4610-8A68-A16EAA47B882}) (Version: 4.15.0 - Futuremark Corporation)
Gameforge Live 2.0.5 (HKLM-x32\...\{9C98989A-3A15-42DA-A3B9-D20331437D67}}_is1) (Version: 2.0.5 - Gameforge)
GamePark klient 2.0.9.0 (HKLM\...\{52E5D8A7-B129-4A29-AD4B-EBB749DCC3A3}_is1) (Version: 2.0.9.0 - GamePark)
Google Drive (HKLM-x32\...\{AC117AF9-316B-4E1D-959E-F0EB85B0DC5F}) (Version: 2.34.7100.0000 - Google, Inc.)
Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Grand Theft Auto IV (HKLM-x32\...\{579BA58C-F33D-4970-9953-B94B43768AC3}) (Version: 1.00.0000 - Rockstar Games)
Grand Theft Auto V (HKLM-x32\...\R3JhbmRUaGVmdEF1dG9W_is1) (Version: 1 - )
Gwent (HKLM-x32\...\1971477531_is1) (Version: 2.0.0.3 - GOG.com)
Heliborne (HKLM\...\aGVsaWJvcm5l_is1) (Version: 1 - )
Hellblade: Senua's Sacrifice (HKLM\...\aGVsbGJsYWRlc2VudWFzc2FjcmlmaWNl_is1) (Version: 1 - )
HP Deskjet 3520 series Nápověda (HKLM-x32\...\{D259C419-D776-4163-B27C-19722C555237}) (Version: 27.0.0 - Hewlett Packard)
HP Deskjet 3520 series Setup Guide (HKLM-x32\...\{AEEDCEB7-00B8-4BE1-B492-AB04803D5F1E}) (Version: 27.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Photo Creations (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\HP Photo Creations) (Version: 1.0.0.18702 - HP)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\...\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
Christmas Bells 3D Screensaver 1.0 (HKLM-x32\...\Christmas Bells 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
ImagXpress (HKLM-x32\...\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4358 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 4.0.4.51 - Intel Corporation)
Java 7 Update 55 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86417055FF}) (Version: 7.0.550 - Oracle)
Kings Bounty Dark Side (HKLM-x32\...\Kings Bounty Dark Side_is1) (Version: - )
King's Bounty Dark Side (HKLM-x32\...\King's Bounty Dark Side_R.G. Gamblers_is1) (Version: - R.G. Gamblers, Fanfar)
K-Lite Mega Codec Pack 10.3.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.3.5 - )
Lišta Centrum.cz (HKLM-x32\...\{6533CC5B-8474-4E6E-A5DB-CAC502DA7C86}) (Version: 1.1.2.0 - Centrum Holdings s.r.o.)
Logitech Gaming Software 5.09 (HKLM\...\{84057C9C-2F85-4C67-A035-FD75FFE2DE88}) (Version: 5.09.131 - Logitech)
Mafia III (HKLM-x32\...\Mafia III_is1) (Version: - )
Mariáš 3.1 (HKLM-x32\...\{BA58C040-B206-41BB-92CF-D0A2975477BB}) (Version: 3.1.0 - Ganttsoft)
Matrix Mania 1.0 (HKLM-x32\...\{07D31340-4956-46EA-8CD2-7A7D3925BAC2}) (Version: 1.0 - ff Softworks Company)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.161 - McAfee, Inc.)
Metin2 (HKLM-x32\...\Metin2_is1) (Version: - Gameforge 4D GmbH)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{59E4543A-D49D-4489-B445-473D763C79AF}) (Version: 2.0.672.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Middle Earth: Shadow of War - Gold Edition version 1.0 (HKLM-x32\...\{C773C2DD-9924-4748-B51D-442E5334C113}_is1) (Version: 1.0 - )
Mortal Kombat X (HKLM\...\bW9ydGFsa29tYmF0eA_is1) (Version: 1 - )
Mortal Kombat X Premium Edition v.1.0 (HKLM-x32\...\Mortal Kombat X Premium Edition_is1) (Version: - )
Mortal Kombat X Update 20150709 (HKLM-x32\...\TW9ydGFsS29tYmF0WA==_is1) (Version: 1 - )
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MX Nitro (HKLM-x32\...\MX Nitro_is1) (Version: - )
My Program version 1.5 (HKLM-x32\...\My Program_is1) (Version: 1.5 - )
Need For Speed Rivals (HKLM-x32\...\{0657F865-25B6-4391-A3B5-9917CF291AB3}) (Version: 6.0 - Black Box)
Need for Speed Rivals Update v1.4 (HKLM-x32\...\TmVlZGZvclNwZWVkUml2YWxz_is1) (Version: 1 - )
Need for Speed™ Rivals (HKLM-x32\...\{E0A32336-AA27-4053-99B2-C3380B7B95AC}) (Version: 1.3.0.0 - Electronic Arts)
Nero 7 Ultra Edition (HKLM-x32\...\{4F2CE68F-EDBB-4592-BF07-5AC930A51029}) (Version: 7.02.6446 - Nero AG)
Nero Backup Drivers (HKLM\...\{D600D357-5CB9-4DE9-8FD4-14E208BD1970}) (Version: 1.0.10000.1.0 - Nero AG)
New Quest - Contract - Skellige's Most Wanted (HKLM-x32\...\New Quest - Contract: Skellige's Most Wanted_is1) (Version: 1.0.0.0 - GOG.com)
New Quest - Contract Missing Miners (HKLM-x32\...\New Quest - Contract Missing Miners_is1) (Version: 1.0.0.0 - GOG.com)
New Quest - Fool's Gold (HKLM-x32\...\New Quest - Fool's Gold_is1) (Version: 1.0.0.0 - GOG.com)
New Quest - Scavenger Hunt - Wolf School Gear (HKLM-x32\...\New Quest - Scavenger Hunt: Wolf School Gear_is1) (Version: 1.0.0.0 - GOG.com)
New Quest - Where the Cat and Wolf Play... (HKLM-x32\...\New Quest - Where the Cat and Wolf Play..._is1) (Version: 1.0.0.0 - GOG.com)
Noční obloha 1.5 (HKLM-x32\...\Noční obloha_is1) (Version: - )
NVIDIA GeForce Experience 3.10.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.10.0.95 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.35.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.35.1 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 388.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.00 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
ON_OFF Charge 2 B13.0910.1 (HKLM-x32\...\{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE) Hidden
ON_OFF Charge 2 B13.0910.1 (HKLM-x32\...\InstallShield_{6B4ED6F7-BB88-4945-B0C6-01410E1BAC3A}) (Version: 1.00.0000 - GIGABYTE)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
Orca (HKLM-x32\...\{85F4CBCB-9BBC-4B50-A7D8-E1106771498D}) (Version: 3.1.3790.0000 - Microsoft Corporation)
Ori and the Blind Forest (HKLM-x32\...\Ori and the Blind Forest_is1) (Version: - )
Outlast 2 (HKLM-x32\...\Outlast 2_is1) (Version: - )
Ovládací panel NVIDIA 388.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.00 - NVIDIA Corporation) Hidden
Photo Notifier and Animation Creator (HKLM-x32\...\Photo Notifier and Animation Creator) (Version: 1.0.0.1009 - IncrediMail Ltd.)
Polda 6 verze 1.0 (HKLM-x32\...\Polda 6_is1) (Version: 1.0 - Centauri production)
Posel Smrti 3 (HKLM-x32\...\Posel Smrti 3_is1) (Version: 1.0 - TopQer, s.r.o.)
Pressure Overdrive (HKLM-x32\...\Pressure Overdrive_is1) (Version: - )
Prey (HKLM-x32\...\Prey_is1) (Version: - )
Princezna a žabák (HKLM-x32\...\{DE5ECBF6-8A4A-4855-98D0-D6576145EBFF}) (Version: 1.00.0000 - Disney Interactive Studios)
Program Killer (HKLM-x32\...\{0E93A023-62F0-44BE-ABCA-953AB1FA409B}) (Version: 1.0.0 - DOKSoft.com / IPKomarov.ru)
Pure (HKLM\...\{FF3C203A-2F19-43A2-9C7C-EC1B5A0FC873}) (Version: 1.0 - Disney Interactive Studios)
Pure (HKLM-x32\...\{FF3C203A-2F19-43A2-9C7C-EC1B5A0FC873}) (Version: 1.0 - Disney Interactive Studios)
QuadcoreM2 (HKLM-x32\...\{101F30DF-3204-473B-A0DD-037A53983DEA}) (Version: 1.12.2012 - Quadcore Games) Hidden
QuadcoreM2 (HKLM-x32\...\QuadcoreM2 1.12.2012) (Version: 1.12.2012 - Quadcore Games)
Rainy Screensaver 2.2.17 (HKLM-x32\...\{EA94A9DF-0E66-4749-880A-637CDF37B61E}) (Version: - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.65.1025.2012 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7503 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
Resident Evil 7 Biohazard (HKLM-x32\...\{1ECBF8F3-7079-44CA-AD32-B2AECBCF636F}_is1) (Version: - Capcom)
Rise of the Tomb Raider - Digital Deluxe Edition verze 1.0.668.1 (HKLM-x32\...\{B7A2BD94-E7DE-40F3-9B79-F46474F4AF8D}_is1) (Version: 1.0.668.1 - )
Rockstar Games Social Club (HKLM-x32\...\{08B3869E-D282-424C-9AFC-870E04A4BA14}) (Version: 1.00.0000 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.5.8 - Rockstar Games)
Rosso Rabbit in Trouble (HKLM-x32\...\Rosso Rabbit in Trouble) (Version: - )
Samsung Content Viewer (HKLM-x32\...\{980DDB3E-8957-4750-98EB-5D04F61CCEDC}) (Version: 1.0.2 - Samsung) Hidden
Samsung Content Viewer (HKLM-x32\...\InstallShield_{980DDB3E-8957-4750-98EB-5D04F61CCEDC}) (Version: 1.0.2 - Samsung)
Samsung Kies3 (HKLM-x32\...\{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies3 (HKLM-x32\...\InstallShield_{88547073-C566-4895-9005-EBE98EA3F7C7}) (Version: 3.2.16084.2 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.)
Santa Claus 3D Screensaver 1.0 (HKLM-x32\...\Santa Claus 3D Screensaver_is1) (Version: 1.0 - 3Planesoft)
Seznam Instalátor (HKLM-x32\...\ssinstall) (Version: - Seznam.cz)
Shadow Tactics - Blades of the Shogun 1.2.1 (HKLM-x32\...\{BB762706-65FA-44C1-B2BB-EF29CA88D7CE}_is1) (Version: 1.2.1 - Daedalic Entertainment GmbH)
Shadow Tactics: Blades of the Shogun SK verzia 0.99 (HKLM-x32\...\Shadow Tactics: Blades of the Shogun SK_is1) (Version: 0.99 - )
Sherlock Holmes - The Devil's Daughter (HKLM-x32\...\{958958D4-484A-4C90-9AB4-88977BE9EBED}_is1) (Version: - Frogwares)
Skellige Armor Set (HKLM-x32\...\Skellige Armor Set_is1) (Version: 1.0.0.0 - GOG.com)
Ski Challenge 14 (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\sc14-GAMETWIST_MAIN) (Version: - )
Ski Challenge 16 (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\sc16-GAMETWIST_MAIN) (Version: - )
Skispringen 2007 (HKLM-x32\...\Skispringen 2007_0001) (Version: - )
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
SlimCleaner Plus (HKLM\...\{C66FE9B8-B7BC-4FBE-A8F9-BB979EFBA47F}) (Version: 2.2.2 - SlimWare Utilities, Inc.)
SpyHunter (HKLM-x32\...\{B95599E4-61B5-4589-B495-CC0E35A4DC05}) (Version: 1.0.0 - Enigma Software Group) Hidden
SpyHunter (HKLM-x32\...\SpyHunter 1.0.0) (Version: 1.0.0 - Enigma Software Group)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
STEEP (HKLM-x32\...\Uplay Install 3445) (Version: - Ubisoft)
Studie vylepšování produktu HP Deskjet 3520 series (HKLM\...\{B7AED02F-7D1B-4806-831B-C06841A282C4}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Super Ovladač (HKLM-x32\...\Super Ovladač_is1) (Version: 10.0 - Driver-Soft Inc.)
Svátky a výročí (HKLM-x32\...\{CB28705C-ED60-499A-90DE-E8BC41F75B65}) (Version: 2.09.0115 - Igor Gottwald - OKsoftware)
Syberia 3 (HKLM-x32\...\Syberia 3_is1) (Version: - )
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
TechPowerUp GPU-Z (HKLM-x32\...\TechPowerUp GPU-Z) (Version: - TechPowerUp)
Temerian Armor Set (HKLM-x32\...\Temerian Armor Set_is1) (Version: 1.0.0.0 - GOG.com)
The Sims 4 (HKLM-x32\...\The Sims 4_is1) (Version: - )
The Witcher 3 Wild Hunt (HKLM-x32\...\The Witcher 3 Wild Hunt_is1) (Version: 1.21 - RePack by Valdeni)
The Witcher 3: Wild Hunt - Alternative Look for Ciri (HKLM-x32\...\Alternative Look for Ciri_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - New Finisher Animations (HKLM-x32\...\New Finisher Animations_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt (Not-cracked Repack) (HKLM-x32\...\The Witcher 3: Wild Hunt (Not-cracked Repack)_is1) (Version: - )
Tom Clancy's Ghost Recon Wildlands (HKLM\...\Tom Clancys Ghost Recon Wildlands_is1) (Version: 1.0 - )
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.50 - Ghisler Software GmbH)
Toy Story 3 (HKLM-x32\...\{AAFD160A-2333-40D8-AA25-42D1989CA0F2}) (Version: 1.00.0000 - Disney Interactive Studios)
Trine 3 The Artifacts of Power (HKLM-x32\...\Trine 3 The Artifacts of Power_is1) (Version: - )
Tux Racer (HKLM-x32\...\{F49F7B74-71A2-44C2-AB2B-F02812B409BD}) (Version: 1.01.0000 - Sunspire Studios) Hidden
Tux Racer (HKLM-x32\...\InstallShield_{F49F7B74-71A2-44C2-AB2B-F02812B409BD}) (Version: 1.01.0000 - Sunspire Studios)
UE4 Prerequisites (x64) (HKLM\...\{DC9D63C3-E5D5-4DA2-8141-2435DE3B6C90}) (Version: 1.0.10.0 - Epic Games, Inc.) Hidden
UE4 Prerequisites (x64) (HKLM-x32\...\{31b49e1e-03f8-4a04-8faa-f6476d8fad02}) (Version: 1.0.10.0 - Epic Games, Inc.)
Unity Web Player (HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\...\UnityWebPlayer) (Version: 4.5.4f1 - Unity Technologies ApS)
Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb)
Unravel (HKLM\...\Unravel_is1) (Version: 1.0.0.0 - )
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-0030-0000-0000-0000000FF1CE}_ENTERPRISER_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Uplay (HKLM-x32\...\Uplay) (Version: 24.0.1 - Ubisoft)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vypínač na dobrou noc verze 2.0 (HKLM-x32\...\Vypínač na dobrou noc_is1) (Version: - )
WATCH_DOGS (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Wolfenstein The Old Blood (HKLM-x32\...\Wolfenstein The Old Blood_is1) (Version: - )
WRC 6 FIA Word Rally Championship (HKLM\...\WRC 6 FIA Word Rally Championship_is1) (Version: 1.0 - )
Xilisoft Download YouTube Video (HKLM-x32\...\Xilisoft Download YouTube Video) (Version: 5.1.1.20131226 - Xilisoft)
X-Morph: Defense (HKLM\...\eG1vcnBoZGVmZW5zZQ_is1) (Version: 1 - )
Youtubers Life (HKLM-x32\...\Youtubers Life_is1) (Version: - )
Základní software zařízení HP Deskjet 3520 series (HKLM\...\{7EBD8BA7-DF64-4BF9-9BC1-B0D53984FC6E}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
Zkušební verze produktu Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISER) (Version: 12.0.6612.1000 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3158200304-2993081581-1989350980-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-10-09] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-10-09] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-10-09] (Google)
ShellIconOverlayIdentifiers: [TortoiseOverlay] -> {CBF88FC2-F150-4F29-BC80-CE30EFD1B62C} => C:\Users\jemin\AppData\Roaming\Subversion\TortoiseSVN.dll -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll -> No File
ContextMenuHandlers1-x32: [DaemonShellExtImage] -> {40966797-8FFE-46C8-9EF8-7003F33CCF0F} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2014-02-19] (Disc Soft Ltd)
ContextMenuHandlers1-x32: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers1-x32: [FRHEAddInContextMenu10.FRHEAddInContextMenu10.1] -> {95CF7ACA-9F00-4789-8C3B-797AD701B1AD} => C:\Program Files (x86)\ABBYY FineReader 10 Home Edition\SprintIntegration.x64.dll [2010-07-30] (ABBYY.)
ContextMenuHandlers1-x32: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-10-09] (Google)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDrive] -> {A5415364-784A-41A5-B47A-D452909CA8FF} => C:\Program Files (x86)\DAEMON Tools Pro\DTShl64.dll [2014-02-19] (Disc Soft Ltd)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => -> No File
ContextMenuHandlers3: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] ()
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-10-09] (Google)
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2014-03-14] (Piriform Ltd)
ContextMenuHandlers5: [DreamScene] -> {BE800AEB-A440-4B63-94CD-AA6B43647DF9} => C:\Windows\System32\DreamScene.dll [2008-03-18] (Microsoft Corporation)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2015-12-21] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2017-10-12] (NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => d:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [FRHEAddInContextMenu10.FRHEAddInContextMenu10.1] -> {95CF7ACA-9F00-4789-8C3B-797AD701B1AD} => C:\Program Files (x86)\ABBYY FineReader 10 Home Edition\SprintIntegration.x64.dll [2010-07-30] (ABBYY.)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2014-03-14] (Piriform Ltd)
ContextMenuHandlers6: [UnlockerShellExtension] -> {DDE4BEEB-DDE6-48fd-8EB5-035C09923F83} => C:\Program Files\Unlocker\UnlockerCOM.dll [2010-07-15] ()
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-02-15] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2015-02-15] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {07E9C263-377B-4790-8BA8-4000EC526F33} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-25] (Adobe Systems Incorporated)
Task: {1941AEF7-DF9D-4217-8D67-2F7659B66842} - System32\Tasks\{D27AFE4E-B181-4D0A-9FBC-C05DA6B64160} => C:\Windows\system32\pcalua.exe -a E:\FreeRapid-0.9u3\frd.exe -d E:\FreeRapid-0.9u3
Task: {1E7B4DAF-F5F3-47D0-A498-9289928F5684} - System32\Tasks\HP AR Program Upload - 15bdd154090248ff83bf738ef41d8acb0a8af20927154115b3f4bb34278b954e => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {2070A2F1-D2F6-4169-8BAA-A3DD5D5871D4} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-10-11] (NVIDIA Corporation)
Task: {3470E38B-BF3F-4FDF-95B4-3B045FF93C4D} - System32\Tasks\FRAPS => C:\Fraps\fraps.exe [2015-10-04] (Beepa P/L)
Task: {50DD5D55-17B4-41B7-9FAC-5F8F23945C92} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-10-11] (NVIDIA Corporation)
Task: {517F3191-92BA-4F67-8705-734550650116} - System32\Tasks\HPCustParticipation HP Deskjet 3520 series => C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {557BC1F0-85C2-4457-8C51-BAB17AAD538E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-03-18] (Piriform Ltd)
Task: {5E502661-C251-457F-B0FA-8CAF52FB20EB} - System32\Tasks\HP AR Program Upload - ebd9bb931b784a29a946f5237ef49361000942cece6b438a93db3d0b7fc6e111 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {64F87439-92E3-4E79-80C9-37B8496ABBEC} - System32\Tasks\HP AR Program Upload - ee281cd3164949909d054632e6dccc66fee3533cfade49c99672947277d7e396 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {6874E146-675C-4465-A470-025DE68F6074} - System32\Tasks\{55B5D951-DA1A-47CA-A5FA-7A51408516CE} => E:\jemin\animace\dreams aktivátor\Windows 7 DreamScene Activator 1.1.exe [2015-10-04] (The Windows Club)
Task: {7B1A4023-D554-4426-85F8-22386A238F39} - System32\Tasks\HP AR Program Upload - 00c03cb91a6a4f9ab32b2baea62b347d288bfe6122e049a19a255c663bcd58e1 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {7E77D404-BBBD-4245-8E3D-553687AEF778} - System32\Tasks\{F221DBD7-CF1E-4115-BE48-E3959564C6FB} => H:\Setup.exe
Task: {81307D74-7351-46A4-91CB-55962CD5FDB8} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation)
Task: {88331A0D-BAB0-4157-9E52-ABF6199E8A7A} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {8B9AC6D1-7677-4D3E-A503-ABD472D60C6C} - System32\Tasks\{C7E5DACB-30DE-4AFA-94EF-103A67B00706} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\IncrediMail\Bin\ImSetup.exe" -d "C:\Program Files (x86)\IncrediMail\Bin"
Task: {A8C1B3DD-0075-4CA6-9668-6830FDFDEB85} - System32\Tasks\HP AR Program Upload - 5c8d2ed5a782435ba5b0a095fdc5b1d40552e7933d5b47bdaf8da7c26a509121 => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {AEB8354C-A836-4690-AAF1-1415577A3B75} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation)
Task: {B0022371-1BE0-4513-9BEB-C6CCF9F90B49} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-10-11] (NVIDIA Corporation)
Task: {B6125790-276E-4C6B-8F29-E7755A6ECC43} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {C41CF9CE-6A6C-4223-BE3F-4B2062DBA6A1} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-10-11] (NVIDIA Corporation)
Task: {CA79BF71-3FD6-4AD5-BD11-A3A359953F42} - System32\Tasks\HP AR Program Upload - d7a49cf9c21c4f4082bf4fbbef9a7dad4ca28bdfe5cf4ff3b8b74043d305b73e => C:\Program Files\HP\HP Deskjet 3520 series\bin\HPRewards.exe [2012-10-17] (TODO: <Company name>)
Task: {EECF3B5E-B37B-4185-97F6-3B5DA5E32784} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-10-11] (NVIDIA Corporation)
Task: {FCBBF8B4-7EAA-47FA-B81F-A51F344721B5} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-10-11] (NVIDIA Corporation)
Task: {FE0D20C1-BCDE-41E0-B819-8136411B500B} - System32\Tasks\{B9C5C637-D195-4826-B163-FC338A55A564} => E:\soft\Soft - Bosch Esitronic 2013\Esi2.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-01-28 07:32 - 2017-10-11 02:05 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2014-03-21 23:31 - 2016-01-03 16:30 - 000075064 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-03-21 23:31 - 2017-01-31 20:36 - 000214520 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-03-21 19:36 - 2014-02-27 19:00 - 004375040 _____ () C:\Program Files (x86)\K-Lite Codec Pack\Filters\ffdshow64\ffdshow.ax
2017-01-28 07:32 - 2017-10-11 02:05 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-08-17 15:51 - 2017-08-17 15:51 - 001993184 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
2017-07-22 21:25 - 2017-09-09 20:25 - 000688416 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2017-07-22 21:25 - 2016-09-01 02:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2017-07-22 21:25 - 2016-09-01 02:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2017-07-22 21:25 - 2016-09-01 02:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2017-07-22 21:25 - 2017-10-25 06:00 - 002546976 _____ () C:\Program Files (x86)\Steam\video.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 002549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 000442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 000491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 000332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2017-07-22 21:25 - 2016-01-27 08:49 - 000485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2017-07-22 21:25 - 2017-10-25 06:00 - 000901408 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2017-07-22 21:25 - 2016-07-04 23:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2017-07-22 21:26 - 2017-08-16 23:28 - 073130272 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2017-07-22 21:26 - 2017-09-07 03:04 - 000678400 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2017-07-22 21:25 - 2015-09-25 00:52 - 000119208 _____ () C:\Program Files (x86)\Steam\winh264.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup:{51007100-4F00-6F00-5300-4F0072005900} [832]
AlternateDataStreams: C:\Users\jemin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup:{6C007200-6300-7500-3800-4F0036006F00} [832]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\26821665.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\31663166.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DA92FCC0.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\26821665.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\31663166.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\DA92FCC0.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PAexec => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 03:34 - 2017-10-31 12:52 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3158200304-2993081581-1989350980-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\jemin\AppData\Roaming\Microsoft\Windows DreamScene\DreamScene.jpg
DNS Servers: 176.12.112.2 - 176.12.112.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Program Killer.lnk => C:\Windows\pss\Program Killer.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^jemin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MyPC Backup.lnk => C:\Windows\pss\MyPC Backup.lnk.Startup
MSCONFIG\startupreg: GSplay.exe => D:\GSplay.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{EC9F93CA-EAB4-4BA5-8439-06F1E85ADB9E}] => (Allow) D:\Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{FF96ED0C-31D5-48A0-8884-224972FBBE25}] => (Allow) D:\Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [TCP Query User{926C15F9-B9E5-4E5A-A3C7-5750472C1E6E}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{0C535B2A-95EF-48C7-940A-CC352591D8C3}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{93E44B6C-F664-4F3E-8349-D6815A8DFE17}C:\program files (x86)\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [UDP Query User{0A1331B3-B10A-48E4-AE77-7AF6496A5413}C:\program files (x86)\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files (x86)\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [{C29D7043-3F90-4CAD-AD0D-20429043E7A9}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{23586E04-0CE6-4129-9338-D5085F64A374}] => (Allow) D:\Games\Need for Speed Rivals\NFS14_x86.exe
FirewallRules: [{5EE8387E-9245-4C4F-BE84-3431A6AA675F}] => (Allow) D:\Games\Need for Speed Rivals\NFS14_x86.exe
FirewallRules: [{19B04F70-CB5C-4DC2-9928-088A254D0B5A}] => (Allow) D:\Games\Need for Speed Rivals\NFS14.exe
FirewallRules: [{450917FA-4471-4C79-9AC0-FAEC65D8209F}] => (Allow) D:\Games\Need for Speed Rivals\NFS14.exe
FirewallRules: [{B5E1DE1D-2ECB-44D1-BA69-E41DAFB2DD6B}] => (Allow) D:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
FirewallRules: [{26107DBA-396A-4DBD-8131-97FF203E84F5}] => (Allow) D:\Program Files (x86)\Rockstar Games\Rockstar Games Social Club\RGSCLauncher.exe
FirewallRules: [{9FBC0D03-DC3E-486D-978D-B52CBDD16742}] => (Allow) D:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [{419F148D-477E-41A8-B71B-39628FB7F4EA}] => (Allow) D:\Program Files (x86)\Rockstar Games\Grand Theft Auto IV\LaunchGTAIV.exe
FirewallRules: [TCP Query User{6638CA37-529A-4308-9B92-3D1367B8695E}D:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe] => (Block) D:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe
FirewallRules: [UDP Query User{2F4BAC82-FA21-48D9-9CDF-2A5B0403F0E2}D:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe] => (Block) D:\program files (x86)\rockstar games\grand theft auto iv\gtaiv.exe
FirewallRules: [TCP Query User{E1032D29-2390-40BA-A592-A9D1175B1E67}D:\program files (x86)\activision\call of duty 2\cod2mp_s.exe] => (Allow) D:\program files (x86)\activision\call of duty 2\cod2mp_s.exe
FirewallRules: [UDP Query User{EA1C51AF-BD92-47F8-A3DE-6BBDC30D258A}D:\program files (x86)\activision\call of duty 2\cod2mp_s.exe] => (Allow) D:\program files (x86)\activision\call of duty 2\cod2mp_s.exe
FirewallRules: [TCP Query User{0647F3C4-B230-4E23-837F-9C49F331CBC4}C:\users\jemin\gsplay\counter-strike\hl.exe] => (Block) C:\users\jemin\gsplay\counter-strike\hl.exe
FirewallRules: [UDP Query User{B29FF24F-D5E9-4B7F-94F5-91E4EEEA7A20}C:\users\jemin\gsplay\counter-strike\hl.exe] => (Block) C:\users\jemin\gsplay\counter-strike\hl.exe
FirewallRules: [TCP Query User{DC4D6EA1-9025-4B5C-A336-88326C026F7F}D:\program files (x86)\battlefield 4\bf4_x86.exe] => (Block) D:\program files (x86)\battlefield 4\bf4_x86.exe
FirewallRules: [UDP Query User{04BE027B-75E2-4C61-9774-A3C05864A30E}D:\program files (x86)\battlefield 4\bf4_x86.exe] => (Block) D:\program files (x86)\battlefield 4\bf4_x86.exe
FirewallRules: [TCP Query User{E9B865DB-7F1F-4482-85BA-3D6217996E0A}D:\program files (x86)\battlefield 4\bf4.exe] => (Block) D:\program files (x86)\battlefield 4\bf4.exe
FirewallRules: [UDP Query User{8F2E56A9-D064-4184-AF8E-011C84569BD1}D:\program files (x86)\battlefield 4\bf4.exe] => (Block) D:\program files (x86)\battlefield 4\bf4.exe
FirewallRules: [TCP Query User{674B0ADD-CA97-4B76-A3A2-F763924AA51D}D:\program files (x86)\mxgp\mxgp.exe] => (Block) D:\program files (x86)\mxgp\mxgp.exe
FirewallRules: [UDP Query User{E29E23DE-D12E-44A1-974E-8A710BEC5B4E}D:\program files (x86)\mxgp\mxgp.exe] => (Block) D:\program files (x86)\mxgp\mxgp.exe
FirewallRules: [TCP Query User{A9A381D7-2A47-4A32-BD24-FE9AD3A5A09D}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe
FirewallRules: [UDP Query User{1BFE3E96-FCB6-4B05-B3BD-D3D03C0EAB15}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe
FirewallRules: [TCP Query User{EF825647-5D12-470A-9457-ADDC535CFA4C}D:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe] => (Block) D:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe
FirewallRules: [UDP Query User{F9887EB4-44A5-430C-82E7-7AF0E4F930A7}D:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe] => (Block) D:\program files (x86)\mortal kombat komplete edition\disccontentpc\mkke.exe
FirewallRules: [{70A14FFA-288A-4E1F-A900-FE69E1177396}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\DeviceSetup.exe
FirewallRules: [{A0109409-1BB2-4935-9C4E-79DDD2829F52}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{7B9E5515-D8C5-4C22-8A73-834C820F5543}] => (Allow) C:\Program Files\HP\HP Deskjet 3520 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [TCP Query User{72C76A57-4851-47A8-A9B4-D7E213094DB8}D:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe] => (Block) D:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe
FirewallRules: [UDP Query User{B1A1D8ED-9CC3-4F1F-A72A-1210A3529AEE}D:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe] => (Block) D:\program files (x86)\wolfenstein the new order\wolfneworder_x64.exe
FirewallRules: [{12BCDDCC-3BB7-4367-BAFF-6AA818C7EB99}] => (Allow) D:\Program Files\Ubisoft\WATCH_DOGS\bin\Watch_Dogs.exe
FirewallRules: [{F9636AD5-884A-44A5-BB24-727BEF15F7BB}] => (Allow) D:\Program Files\Ubisoft\WATCH_DOGS\bin\Watch_Dogs.exe
FirewallRules: [TCP Query User{DA40A7B5-2CF5-48A2-8BA1-796F9304B857}C:\program files\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [UDP Query User{F1CF21AF-A2FC-48A3-9BAE-20514FE0F853}C:\program files\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [TCP Query User{DF666C7D-7013-4AD6-9F55-DB3FF2FC49A9}C:\users\jemin\gsplay\csko\hl.exe] => (Block) C:\users\jemin\gsplay\csko\hl.exe
FirewallRules: [UDP Query User{33A94344-B2F7-4912-AF6A-7183D630529F}C:\users\jemin\gsplay\csko\hl.exe] => (Block) C:\users\jemin\gsplay\csko\hl.exe
FirewallRules: [TCP Query User{11A502A9-D141-4337-98C0-7F5FF26E0438}D:\program files (x86)\enemy front proper\bin32\enemyfront.exe] => (Block) D:\program files (x86)\enemy front proper\bin32\enemyfront.exe
FirewallRules: [UDP Query User{B6D65920-8EFD-44E4-9EAE-6BCE0DECD2C7}D:\program files (x86)\enemy front proper\bin32\enemyfront.exe] => (Block) D:\program files (x86)\enemy front proper\bin32\enemyfront.exe
FirewallRules: [{261E553F-8589-4B8E-BF46-F386B9465BED}] => (Allow) C:\Users\jemin\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [{FD71908E-03D7-46E6-9B33-6040291186B8}] => (Allow) C:\Users\jemin\AppData\Roaming\BitTorrent\BitTorrent.exe
FirewallRules: [TCP Query User{B2B7F401-5ADA-412D-9863-CD0A3BD0806C}D:\program files (x86)\real boxing\binaries\win32\realboxing.exe] => (Block) D:\program files (x86)\real boxing\binaries\win32\realboxing.exe
FirewallRules: [UDP Query User{6E6A316E-857B-4F39-8E52-5F3C22F75A9E}D:\program files (x86)\real boxing\binaries\win32\realboxing.exe] => (Block) D:\program files (x86)\real boxing\binaries\win32\realboxing.exe
FirewallRules: [TCP Query User{E6576750-61E5-404B-86FA-58D414FB0CB1}C:\program files (x86)\quadcorem2\pack\core.bin] => (Allow) C:\program files (x86)\quadcorem2\pack\core.bin
FirewallRules: [UDP Query User{10CFF7EB-A58E-4FA6-B4C5-468171558AD4}C:\program files (x86)\quadcorem2\pack\core.bin] => (Allow) C:\program files (x86)\quadcorem2\pack\core.bin
FirewallRules: [TCP Query User{00F2E9F2-A2F1-437E-8A79-97D384C5A709}C:\users\jemin\desktop\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\spaceworldlauncher.exe
FirewallRules: [UDP Query User{4C330470-572B-47B7-AF1C-5103966A5B1D}C:\users\jemin\desktop\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\spaceworldlauncher.exe
FirewallRules: [TCP Query User{0DA20475-78B6-43B7-BA7C-602E13126D17}C:\users\jemin\desktop\nová složka\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\nová složka\spaceworldlauncher.exe
FirewallRules: [UDP Query User{D5DDED2A-B7ED-4D0E-BCED-72A7C97DE860}C:\users\jemin\desktop\nová složka\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\nová složka\spaceworldlauncher.exe
FirewallRules: [TCP Query User{6CABB974-EE02-4BE4-9056-443D1BB0FB5B}C:\users\jemin\desktop\spaceworld\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\spaceworld\spaceworldlauncher.exe
FirewallRules: [UDP Query User{114D6444-3AF3-41F9-88D6-5DF829CFA147}C:\users\jemin\desktop\spaceworld\spaceworldlauncher.exe] => (Allow) C:\users\jemin\desktop\spaceworld\spaceworldlauncher.exe
FirewallRules: [TCP Query User{7C6DB9DE-E974-4981-B6B7-4D76752A12A1}C:\users\jemin\desktop\spaceworld\zcsk.dll] => (Allow) C:\users\jemin\desktop\spaceworld\zcsk.dll
FirewallRules: [UDP Query User{048A9E14-77F3-48B0-90D8-0FE111E4D647}C:\users\jemin\desktop\spaceworld\zcsk.dll] => (Allow) C:\users\jemin\desktop\spaceworld\zcsk.dll
FirewallRules: [TCP Query User{AD284F0E-F35E-494D-ACE3-FAB78938F2E8}D:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe] => (Block) D:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe
FirewallRules: [UDP Query User{60D70A45-0FC4-40DE-9F3A-3292F3150836}D:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe] => (Block) D:\program files (x86)\lichdom battlemage\bin64\lichdombattlemage.exe
FirewallRules: [TCP Query User{F10050C1-7767-4A42-9B1A-90F0C2D690A9}D:\program files (x86)\lichdom battlemage\bin32\lichdombattlemage.exe] => (Block) D:\program files (x86)\lichdom battlemage\bin32\lichdombattlemage.exe
FirewallRules: [UDP Query User{25860A31-7CB2-45D8-9338-B8CD49F86F86}D:\program files (x86)\lichdom battlemage\bin32\lichdombattlemage.exe] => (Block) D:\program files (x86)\lichdom battlemage\bin32\lichdombattlemage.exe
FirewallRules: [{6F898F04-5959-4514-A10C-C0125F49B556}] => (Allow) C:\Program Files (x86)\GameforgeLive\gfl_client.exe
FirewallRules: [TCP Query User{5F448F50-63AC-4EFD-94EE-CDF53D1DF42C}D:\program files (x86)\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe] => (Block) D:\program files (x86)\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe
FirewallRules: [UDP Query User{8B174938-BA0E-47F1-B417-7B3F71B6C0F3}D:\program files (x86)\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe] => (Block) D:\program files (x86)\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe
FirewallRules: [TCP Query User{AB4EBAAA-9306-4B0E-99B3-00E6AF1D6AEC}D:\program files (x86)\alien isolation\ai.exe] => (Block) D:\program files (x86)\alien isolation\ai.exe
FirewallRules: [UDP Query User{A477087F-9B32-4134-B611-F88EE3601D03}D:\program files (x86)\alien isolation\ai.exe] => (Block) D:\program files (x86)\alien isolation\ai.exe
FirewallRules: [TCP Query User{AF18B9DC-D514-47EE-8260-EEADAE19D6F0}D:\attomey ---\metin2client.bin] => (Allow) D:\attomey ---\metin2client.bin
FirewallRules: [UDP Query User{728CAEFD-BD93-428B-9920-8ADDA1BEF20F}D:\attomey ---\metin2client.bin] => (Allow) D:\attomey ---\metin2client.bin
FirewallRules: [TCP Query User{C4EAF14C-B9C9-4EA0-9741-2EF205E01F62}D:\program files (x86)\far cry 4\bin\farcry4.exe] => (Block) D:\program files (x86)\far cry 4\bin\farcry4.exe
FirewallRules: [UDP Query User{C46FF19A-8F17-4DAB-A67B-6358AC4B0B3E}D:\program files (x86)\far cry 4\bin\farcry4.exe] => (Block) D:\program files (x86)\far cry 4\bin\farcry4.exe
FirewallRules: [TCP Query User{82FEE81E-5F40-4C6C-98FC-C6EA13FDE949}D:\program files (x86)\motorcycle club\motorcycleclub.exe] => (Block) D:\program files (x86)\motorcycle club\motorcycleclub.exe
FirewallRules: [UDP Query User{705A062D-89EE-4621-BD91-030D8F6CDF4A}D:\program files (x86)\motorcycle club\motorcycleclub.exe] => (Block) D:\program files (x86)\motorcycle club\motorcycleclub.exe
FirewallRules: [{F3AE242D-661A-4E38-8F94-8C02791F51BD}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{D9A754BC-0A38-47AD-A9EA-09CCBACA7012}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{D41201DB-7A7E-4864-87B2-5EAE7150DE55}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{3568D9B6-3947-40D6-A9B1-1A996409D579}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{CA4AEBC9-9736-40E3-B0E7-5AE2D1E03DAF}D:\program files (x86)\dying light\dyinglightgame.exe] => (Block) D:\program files (x86)\dying light\dyinglightgame.exe
FirewallRules: [UDP Query User{E112A944-E494-4999-88B8-09AE7A5A5F96}D:\program files (x86)\dying light\dyinglightgame.exe] => (Block) D:\program files (x86)\dying light\dyinglightgame.exe
FirewallRules: [TCP Query User{AD894AE0-5682-4F01-BA3D-0B8273ED72C3}E:\program files (x86)\evolve\bin64_steamretail\evolve.exe] => (Block) E:\program files (x86)\evolve\bin64_steamretail\evolve.exe
FirewallRules: [UDP Query User{085B61B9-76E4-4F66-BFF9-B24784B0AF7C}E:\program files (x86)\evolve\bin64_steamretail\evolve.exe] => (Block) E:\program files (x86)\evolve\bin64_steamretail\evolve.exe
FirewallRules: [TCP Query User{FCBB2A40-EF8A-4DE2-A7F9-EA7C4D71298F}E:\gog games\oddworld - new 'n' tasty\nnt.exe] => (Block) E:\gog games\oddworld - new 'n' tasty\nnt.exe
FirewallRules: [UDP Query User{FB974618-CBCA-460E-98E2-4349CEFC001C}E:\gog games\oddworld - new 'n' tasty\nnt.exe] => (Block) E:\gog games\oddworld - new 'n' tasty\nnt.exe
FirewallRules: [TCP Query User{D406DDB8-736C-4D64-8A64-330F6EF33AA2}D:\program files (x86)\ride\ride.exe] => (Block) D:\program files (x86)\ride\ride.exe
FirewallRules: [UDP Query User{3280A57F-A878-498E-BF7A-225EE091E953}D:\program files (x86)\ride\ride.exe] => (Block) D:\program files (x86)\ride\ride.exe
FirewallRules: [TCP Query User{E1BF8BCD-FBB7-493F-A294-C611CC18DC09}D:\gog games\oddworld - new 'n' tasty\nnt.exe] => (Block) D:\gog games\oddworld - new 'n' tasty\nnt.exe
FirewallRules: [UDP Query User{A73E6B8D-3692-4768-84BA-659FC11A5CB1}D:\gog games\oddworld - new 'n' tasty\nnt.exe] => (Block) D:\gog games\oddworld - new 'n' tasty\nnt.exe
FirewallRules: [TCP Query User{1920DDF9-74F5-4569-B0B8-DE4C19B53EB9}E:\gta v\gta5.exe] => (Block) E:\gta v\gta5.exe
FirewallRules: [UDP Query User{DCF4F7B1-79DA-484E-83B7-72EDF3F39F1F}E:\gta v\gta5.exe] => (Block) E:\gta v\gta5.exe
FirewallRules: [TCP Query User{4810C075-7AD4-4C94-8320-570B0DED076E}E:\gta v\gta5.exe] => (Block) E:\gta v\gta5.exe
FirewallRules: [UDP Query User{065F9BC8-7506-4C69-87BE-C7ABC24CE5DE}E:\gta v\gta5.exe] => (Block) E:\gta v\gta5.exe
FirewallRules: [{DF64C37C-20E6-4F64-946D-5ECCAB993947}] => (Block) E:\gta v\gta5.exe
FirewallRules: [{F99BD298-6530-4933-810B-D5599C854F66}] => (Block) E:\gta v\gta5.exe
FirewallRules: [TCP Query User{C855F89A-25E7-4B42-B98D-70863034358E}E:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe] => (Block) E:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [UDP Query User{A0FC2257-AF0C-4E11-9C01-E0F89CF57C08}E:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe] => (Block) E:\program files (x86)\assassins creed chronicles china\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [TCP Query User{DB118817-FEAE-49A1-88C6-3DD782080CAC}E:\program files (x86)\grand theft auto v\gta5.exe] => (Block) E:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{05423F75-F5CE-4EED-A2B0-7AD33121FE7F}E:\program files (x86)\grand theft auto v\gta5.exe] => (Block) E:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{4C2513FC-698E-4F86-87DF-57D6E5350437}E:\program files (x86)\pro evolution soccer 2016\pes2016.exe] => (Block) E:\program files (x86)\pro evolution soccer 2016\pes2016.exe
FirewallRules: [UDP Query User{F5AF05F2-DC6E-478E-B5B9-6EEB75CE4985}E:\program files (x86)\pro evolution soccer 2016\pes2016.exe] => (Block) E:\program files (x86)\pro evolution soccer 2016\pes2016.exe
FirewallRules: [{E06C7E46-8FEE-45F2-894B-38788B1585C7}] => (Allow) C:\ProgramData\system32.exe
FirewallRules: [{470C7554-8BFE-4234-86C3-63C61596846E}] => (Allow) C:\ProgramData\system32.exe
FirewallRules: [{716A58E4-C7D9-46A6-9A00-AF54DA0C79AD}] => (Allow) C:\Users\jemin\AppData\Local\Temp\Skype.exe
FirewallRules: [{704FDEAE-22E6-4204-AE3B-362E55281C8E}] => (Allow) C:\Users\jemin\AppData\Local\Temp\Skype.exe
FirewallRules: [TCP Query User{0822A0C7-B867-4709-8F90-D740BAC06D78}D:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe] => (Block) D:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe
FirewallRules: [UDP Query User{4C200F5C-0C7C-4719-92A3-ADFEEEA8B32D}D:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe] => (Block) D:\program files (x86)\wrc 4 fia world rally championship\wrc4.exe
FirewallRules: [TCP Query User{02A3502E-5F2F-4936-8E08-7CB5E98DB241}E:\program files (x86)\mx vs atv supercross encore edition\mxstorm_pc.exe] => (Block) E:\program files (x86)\mx vs atv supercross encore edition\mxstorm_pc.exe
FirewallRules: [UDP Query User{BDEC0405-2D55-4D5F-A5D7-40E1D08B3E9A}E:\program files (x86)\mx vs atv supercross encore edition\mxstorm_pc.exe] => (Block) E:\program files (x86)\mx vs atv supercross encore edition\mxstorm_pc.exe
FirewallRules: [TCP Query User{857767CC-B344-41EE-AD63-C578A9A3ED05}D:\program files (x86)\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe] => (Block) D:\program files (x86)\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe
FirewallRules: [UDP Query User{8E1DF42C-7A09-48A8-A032-28058AC57453}D:\program files (x86)\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe] => (Block) D:\program files (x86)\euro fishing\windowsnoeditor\fishinggame\binaries\win64\fishinggame-win64-shipping.exe
FirewallRules: [TCP Query User{B59A9D01-F484-4251-BCAD-F3239455A8F3}E:\program files\call of duty black ops iii\blackops3.exe] => (Block) E:\program files\call of duty black ops iii\blackops3.exe
FirewallRules: [UDP Query User{B8E95041-7BC7-4B6E-ABD4-B66CBBBA2E32}E:\program files\call of duty black ops iii\blackops3.exe] => (Block) E:\program files\call of duty black ops iii\blackops3.exe
FirewallRules: [{4C4364ED-D71D-4CC3-AF47-B0D9DDC9E31C}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{DB78E42C-67A6-4C25-A6C8-181E8F7F51D5}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{5A93EB1F-112E-4BEE-9B2F-D2C8D6679C82}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{8FE9E101-27BC-441C-AE7A-6EA9887CC046}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{603C3D91-F630-49D4-9E63-C5890F6046DB}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{4D79B172-F8CC-4A77-ADED-FF69BDB96B7B}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [{C86EB915-19E5-4708-BC7F-0C8B4A574E91}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImpCnt.exe
FirewallRules: [TCP Query User{BC3D9D1D-B157-4740-9601-562F6FF8855F}D:\program files (x86)\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe] => (Block) D:\program files (x86)\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [UDP Query User{3E33465E-DD6E-48DF-8953-DDF8BF139FB7}D:\program files (x86)\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe] => (Block) D:\program files (x86)\assassin s creed chronicles india\binaries\win32\accgame-win32-shipping.exe
FirewallRules: [TCP Query User{1413C1DF-EFE7-490F-BFF8-A57E0DE00A92}D:\program files\dying light\dyinglightgame.exe] => (Block) D:\program files\dying light\dyinglightgame.exe
FirewallRules: [UDP Query User{B7E78098-F6A9-4B7D-978C-A4491CB6FBE7}D:\program files\dying light\dyinglightgame.exe] => (Block) D:\program files\dying light\dyinglightgame.exe
FirewallRules: [TCP Query User{1EBD6287-8656-44E6-853A-6C55127EA839}D:\program files (x86)\doom closed alpha\doomx64.exe] => (Allow) D:\program files (x86)\doom closed alpha\doomx64.exe
FirewallRules: [UDP Query User{DDD22E85-C921-4318-AE6A-C2BF463ACE25}D:\program files (x86)\doom closed alpha\doomx64.exe] => (Allow) D:\program files (x86)\doom closed alpha\doomx64.exe
FirewallRules: [{761086C3-703F-42A8-BD25-450D53DBF066}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{10FB8E33-015A-4A38-B877-C50A42C806CB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{D90D03CF-94DF-4957-867D-501B790544B4}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{D59A4271-6E8F-461D-8460-1B90439A462C}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{E9B0E8BF-3411-4BF9-AF47-7AFEB8D8A069}] => (Allow) D:\SteamLibrary\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [{F9522AB2-9267-41C0-8C7C-2E7CD0538BA5}] => (Allow) D:\SteamLibrary\steamapps\common\SteamVRPerformanceTest\bin\win64\vr.exe
FirewallRules: [TCP Query User{A350CC02-5D3B-49E4-A91F-C240AECC771D}D:\program files (x86)\obliteracers\obliteracers\binaries\win64\obliteracers-win64-shipping.exe] => (Block) D:\program files (x86)\obliteracers\obliteracers\binaries\win64\obliteracers-win64-shipping.exe
FirewallRules: [UDP Query User{0B14F096-88D8-4132-ABAF-941D694ED20A}D:\program files (x86)\obliteracers\obliteracers\binaries\win64\obliteracers-win64-shipping.exe] => (Block) D:\program files (x86)\obliteracers\obliteracers\binaries\win64\obliteracers-win64-shipping.exe
FirewallRules: [TCP Query User{19C1B11D-1F24-4384-9FB7-4D28D329471C}D:\program files (x86)\mxgp2\mxgp_2x64.exe] => (Block) D:\program files (x86)\mxgp2\mxgp_2x64.exe
FirewallRules: [UDP Query User{D17DC52B-289D-4B72-9B54-5B8EF37C09F5}D:\program files (x86)\mxgp2\mxgp_2x64.exe] => (Block) D:\program files (x86)\mxgp2\mxgp_2x64.exe
FirewallRules: [TCP Query User{F20C4E25-45F8-4E24-A0D0-6D0BC7C6D138}D:\program files (x86)\is defense\isdefense\binaries\win64\isdefense-win64-shipping.exe] => (Block) D:\program files (x86)\is defense\isdefense\binaries\win64\isdefense-win64-shipping.exe
FirewallRules: [UDP Query User{E51888D3-BFF3-40C3-AF45-88748FA63BFA}D:\program files (x86)\is defense\isdefense\binaries\win64\isdefense-win64-shipping.exe] => (Block) D:\program files (x86)\is defense\isdefense\binaries\win64\isdefense-win64-shipping.exe
FirewallRules: [TCP Query User{141BE3F9-4170-4B81-9203-3B47BA166BA3}D:\program files\bell ringer\bellringer\binaries\win64\bellringer-win64-shipping.exe] => (Block) D:\program files\bell ringer\bellringer\binaries\win64\bellringer-win64-shipping.exe
FirewallRules: [UDP Query User{39796CB2-29A2-4807-90F7-C222E9FF9FFC}D:\program files\bell ringer\bellringer\binaries\win64\bellringer-win64-shipping.exe] => (Block) D:\program files\bell ringer\bellringer\binaries\win64\bellringer-win64-shipping.exe
FirewallRules: [TCP Query User{FE5E79CC-6C94-40B3-A178-0FA9D3D8E96A}D:\doom\steamapps\common\doom\doomx64.exe] => (Allow) D:\doom\steamapps\common\doom\doomx64.exe
FirewallRules: [UDP Query User{F3F979DB-575A-478A-8454-DF3087D3141C}D:\doom\steamapps\common\doom\doomx64.exe] => (Allow) D:\doom\steamapps\common\doom\doomx64.exe
FirewallRules: [TCP Query User{64A4790D-0C45-4F12-92DC-2C210153AC5D}D:\games\grim dawn\grim dawn.exe] => (Block) D:\games\grim dawn\grim dawn.exe
FirewallRules: [UDP Query User{D5632D50-BC4F-413A-9E1C-45296C274414}D:\games\grim dawn\grim dawn.exe] => (Block) D:\games\grim dawn\grim dawn.exe
FirewallRules: [TCP Query User{D4C4FAC6-4DA5-441E-9E71-FFE5B471E857}D:\program files (x86)\microsoft studios\quantum break\dx11\quantumbreak.exe] => (Block) D:\program files (x86)\microsoft studios\quantum break\dx11\quantumbreak.exe
FirewallRules: [UDP Query User{1872C9F0-B06F-412F-B6E4-2E0F91D05006}D:\program files (x86)\microsoft studios\quantum break\dx11\quantumbreak.exe] => (Block) D:\program files (x86)\microsoft studios\quantum break\dx11\quantumbreak.exe
FirewallRules: [TCP Query User{C7135B46-D1FF-433E-BA8A-1ABBB38AED2D}D:\program files\call of duty infinite warfare\iw7_ship.exe] => (Allow) D:\program files\call of duty infinite warfare\iw7_ship.exe
FirewallRules: [UDP Query User{864705B0-1401-493E-9498-E63AFA0B4AC1}D:\program files\call of duty infinite warfare\iw7_ship.exe] => (Allow) D:\program files\call of duty infinite warfare\iw7_ship.exe
FirewallRules: [{9F66FC26-EF21-433E-8611-568620639D23}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\STEEP\steep.exe
FirewallRules: [{00EA6016-950E-4377-AF23-15BBB14D9BC6}] => (Allow) D:\Program Files (x86)\Daedalic Entertainment GmbH\Shadow Tactics - Blades of the Shogun\Shadow Tactics.exe
FirewallRules: [{740AFE78-8A14-4333-83A6-4116FC7F61BC}] => (Allow) D:\Program Files (x86)\Daedalic Entertainment GmbH\Shadow Tactics - Blades of the Shogun\Shadow Tactics.exe
FirewallRules: [{5B621055-5E76-4F13-811C-57A72712FE1B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{A387B7B0-80DC-4AB9-B6E5-284E432FFAB5}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{5607EE13-0BE0-4A55-AD22-32C0FF19B780}D:\games\far cry primal\bin\fcprimal.exe] => (Block) D:\games\far cry primal\bin\fcprimal.exe
FirewallRules: [UDP Query User{4F22BF3C-D31B-40EB-9859-2E7D0D3FA823}D:\games\far cry primal\bin\fcprimal.exe] => (Block) D:\games\far cry primal\bin\fcprimal.exe
FirewallRules: [{4EFF3BF1-E56A-4EE1-BD31-E8F6C025E7DA}] => (Allow) D:\DOOM\steamapps\common\Moto Racer 4\MR4.exe
FirewallRules: [{BA167BF8-32C6-417C-A81E-9C3804335A8F}] => (Allow) D:\DOOM\steamapps\common\Moto Racer 4\MR4.exe
FirewallRules: [TCP Query User{40E99C32-1450-4486-9051-E7D735633C29}D:\doom\steamapps\common\moto racer 4\mr4\binaries\win64\mr4-win64-shipping.exe] => (Allow) D:\doom\steamapps\common\moto racer 4\mr4\binaries\win64\mr4-win64-shipping.exe
FirewallRules: [UDP Query User{F9345190-4059-4B21-B0FC-18D5012DDFED}D:\doom\steamapps\common\moto racer 4\mr4\binaries\win64\mr4-win64-shipping.exe] => (Allow) D:\doom\steamapps\common\moto racer 4\mr4\binaries\win64\mr4-win64-shipping.exe
FirewallRules: [{7EE6681B-5C1B-49D4-ABA5-05B83F3DC427}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{F3B55875-1007-4947-9523-91EBCE5EFA88}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{4683609A-46CB-4162-87F6-E2282C49E888}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{54E7055D-0B29-4F9F-9440-F0F6E663CB8C}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{C668D9AD-44A2-4DA7-AAF9-DB1F90C7AB22}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{D5A04A7B-AC6A-4951-BEB5-5773B2DC3760}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{82D7559D-8557-4A0E-B8A5-02E7D3C44595}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{A6B9524C-EFD3-46C0-B1FE-E22156406CA7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5C5FDC54-29F4-4B9E-877E-D664A0AEEE14}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{8A4D30F6-2C77-492B-8DB4-8F67CE73C6D2}E:\program files (x86)\mxgp2\mxgp_2x64.exe] => (Block) E:\program files (x86)\mxgp2\mxgp_2x64.exe
FirewallRules: [UDP Query User{54F54BBC-6A68-4CEE-AA78-BA228FDA7901}E:\program files (x86)\mxgp2\mxgp_2x64.exe] => (Block) E:\program files (x86)\mxgp2\mxgp_2x64.exe
FirewallRules: [TCP Query User{BAF9E536-6209-45A1-BECD-AAC963BB629F}E:\setup\bf1.exe] => (Block) E:\setup\bf1.exe
FirewallRules: [UDP Query User{3A0660ED-B19A-4154-9C4D-68926EAD4990}E:\setup\bf1.exe] => (Block) E:\setup\bf1.exe
FirewallRules: [TCP Query User{1D628DCE-ADB5-4503-B2A1-C413082BC70C}D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe] => (Block) D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe
FirewallRules: [UDP Query User{62BEBB98-EB12-4904-8A54-E3FD23D79464}D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe] => (Block) D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe
FirewallRules: [TCP Query User{AA2E1389-9511-4214-A01F-FB93AE463408}C:\program files\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [UDP Query User{38A48E49-897F-4B08-882D-436F1D67BCEF}C:\program files\java\jre7\launch4j-tmp\frd.exe] => (Allow) C:\program files\java\jre7\launch4j-tmp\frd.exe
FirewallRules: [TCP Query User{A6937832-9E74-4138-9AB7-9E94A1393439}D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe] => (Block) D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe
FirewallRules: [UDP Query User{2902D579-82A6-48AA-B799-BBC6CC8E422C}D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe] => (Block) D:\program files (x86)\thehunter call of the wild\thehuntercotw_f.exe
FirewallRules: [TCP Query User{338240D8-343A-4060-950B-728542F589A7}D:\vikings - wolves of midgard\vikings.exe] => (Block) D:\vikings - wolves of midgard\vikings.exe
FirewallRules: [UDP Query User{D91331E9-8B5D-4F5D-B1B2-F43B69AE9FC9}D:\vikings - wolves of midgard\vikings.exe] => (Block) D:\vikings - wolves of midgard\vikings.exe
FirewallRules: [TCP Query User{7F4AB0E7-070D-4584-A094-7BCC7185C7BD}D:\program files (x86)\x-plane 11\x-plane.exe] => (Block) D:\program files (x86)\x-plane 11\x-plane.exe
FirewallRules: [UDP Query User{C68DE143-9DC3-41EC-B117-CD1020E0D8F2}D:\program files (x86)\x-plane 11\x-plane.exe] => (Block) D:\program files (x86)\x-plane 11\x-plane.exe
FirewallRules: [TCP Query User{20092F69-27F2-457F-9326-59A049BCF600}D:\program files (x86)\perfect golf inc\jack nicklaus perfect golf\win64\perfect golf.exe] => (Block) D:\program files (x86)\perfect golf inc\jack nicklaus perfect golf\win64\perfect golf.exe
FirewallRules: [UDP Query User{3748F95E-3853-4845-A70A-6F3EDC3C37D2}D:\program files (x86)\perfect golf inc\jack nicklaus perfect golf\win64\perfect golf.exe] => (Block) D:\program files (x86)\perfect golf inc\jack nicklaus perfect golf\win64\perfect golf.exe
FirewallRules: [TCP Query User{587EDF74-69D1-45D6-B4E9-9562155F2657}E:\setup\bf1.exe] => (Block) E:\setup\bf1.exe
FirewallRules: [UDP Query User{F5580176-E156-42A1-AC83-71B380038717}E:\setup\bf1.exe] => (Block) E:\setup\bf1.exe
FirewallRules: [TCP Query User{AF363FD5-9EFD-41E3-AFAD-F7CA44FC8A02}E:\program files (x86)\outlast 2\binaries\win64\outlast2.exe] => (Block) E:\program files (x86)\outlast 2\binaries\win64\outlast2.exe
FirewallRules: [UDP Query User{A4D6CA65-F781-4763-924B-14F2111FCAAE}E:\program files (x86)\outlast 2\binaries\win64\outlast2.exe] => (Block) E:\program files (x86)\outlast 2\binaries\win64\outlast2.exe
FirewallRules: [TCP Query User{5782B509-5C62-47CE-89E1-54DECD35806F}E:\hry-stažené\win_x64\sgw3.exe] => (Block) E:\hry-stažené\win_x64\sgw3.exe
FirewallRules: [UDP Query User{DDC9D3D3-8827-4AEB-9DDC-F2843401D30C}E:\hry-stažené\win_x64\sgw3.exe] => (Block) E:\hry-stažené\win_x64\sgw3.exe
FirewallRules: [TCP Query User{A076EBEE-9BA8-4D8B-A155-BECDCE59078D}E:\hry-stažené\sniper ghost warrior 3\win_x64\sgw3.exe] => (Block) E:\hry-stažené\sniper ghost warrior 3\win_x64\sgw3.exe
FirewallRules: [UDP Query User{5A55DFE4-7938-4EDE-82F7-E70CE3368C6F}E:\hry-stažené\sniper ghost warrior 3\win_x64\sgw3.exe] => (Block) E:\hry-stažené\sniper ghost warrior 3\win_x64\sgw3.exe
FirewallRules: [TCP Query User{234B881B-E041-49FE-B789-2F683D871425}E:\games\prey\binaries\danielle\x64\release\prey.exe] => (Block) E:\games\prey\binaries\danielle\x64\release\prey.exe
FirewallRules: [UDP Query User{BE91F8E5-E601-4E5C-A219-59EFF101ED37}E:\games\prey\binaries\danielle\x64\release\prey.exe] => (Block) E:\games\prey\binaries\danielle\x64\release\prey.exe
FirewallRules: [TCP Query User{07971374-15DF-4880-9B5C-5E53CAC2AF50}E:\hry-stažené\oxygen.not.included.v218235.pefelie.org\oxygennotincluded.exe] => (Block) E:\hry-stažené\oxygen.not.included.v218235.pefelie.org\oxygennotincluded.exe
FirewallRules: [UDP Query User{5AD62975-7D08-495C-B797-7D2C61E95DC6}E:\hry-stažené\oxygen.not.included.v218235.pefelie.org\oxygennotincluded.exe] => (Block) E:\hry-stažené\oxygen.not.included.v218235.pefelie.org\oxygennotincluded.exe
FirewallRules: [TCP Query User{16D843CB-7C31-4C19-A58F-0668C335634B}E:\program files (x86)\titanfall 2\titanfall2.exe] => (Block) E:\program files (x86)\titanfall 2\titanfall2.exe
FirewallRules: [UDP Query User{F87246DB-9482-4068-A4A5-325E2B933F77}E:\program files (x86)\titanfall 2\titanfall2.exe] => (Block) E:\program files (x86)\titanfall 2\titanfall2.exe
FirewallRules: [TCP Query User{DCA395F8-7983-4FA5-834A-22A66C1DC13C}E:\program files\tom clancy's ghost recon wildlands\grw.exe] => (Block) E:\program files\tom clancy's ghost recon wildlands\grw.exe
FirewallRules: [UDP Query User{0963A4E5-3BCB-4CD2-AE3E-48ACF323D0D5}E:\program files\tom clancy's ghost recon wildlands\grw.exe] => (Block) E:\program files\tom clancy's ghost recon wildlands\grw.exe
FirewallRules: [TCP Query User{F1A9474A-397A-486A-B354-F942BC8E6726}E:\program files (x86)\grand theft auto v\gta5.exe] => (Block) E:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{AA83BBD8-64BA-4010-9AF4-A1DEE536D342}E:\program files (x86)\grand theft auto v\gta5.exe] => (Block) E:\program files (x86)\grand theft auto v\gta5.exe
FirewallRules: [{D63D3A4C-1F6D-4062-AE9F-65C7992AF233}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{18553A5D-FBCF-4DE2-968B-FB32058B2E61}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\IncMail.exe
FirewallRules: [{1F30648F-3326-4CBA-A2FF-62D1217FC3E8}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{4BA07AC8-6A99-451A-A6CE-59A2A2AF5DC7}] => (Allow) C:\Program Files (x86)\IncrediMail\Bin\ImApp.exe
FirewallRules: [{9497DE23-4DAA-4467-B264-D8BD6F2DADA7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{3816CA48-CA3D-4BFA-B350-C8BA36DDB3BD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{38FC6660-0635-4BFD-BBE7-F99291ABADCA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F3D430C2-F8DD-4FB4-BC29-13A0740A49A3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{A8AC45D9-34BE-45CD-ACC7-824EBA3DA095}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{9D47F75E-3F04-4C92-9C17-B37897EE2FEC}E:\program files (x86)\hob\hob.exe] => (Block) E:\program files (x86)\hob\hob.exe
FirewallRules: [UDP Query User{48B9F319-1665-4932-A683-A98CE9289CC9}E:\program files (x86)\hob\hob.exe] => (Block) E:\program files (x86)\hob\hob.exe
FirewallRules: [TCP Query User{E44AC4BD-E756-46A2-841D-0D6C21C77FDF}D:\program files\fifa18\fifa18.exe] => (Block) D:\program files\fifa18\fifa18.exe
FirewallRules: [UDP Query User{BA969D8C-18A5-4B72-B479-0F486DBA5270}D:\program files\fifa18\fifa18.exe] => (Block) D:\program files\fifa18\fifa18.exe
FirewallRules: [{93E90456-92F1-4C00-83C9-0B1ED48DA1E9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [TCP Query User{E551F476-0193-4A80-B612-35EDA7426CE5}D:\totalcmd\totalcmd64.exe] => (Allow) D:\totalcmd\totalcmd64.exe
FirewallRules: [UDP Query User{727FBAD9-696B-49B9-AF11-42832711EEE5}D:\totalcmd\totalcmd64.exe] => (Allow) D:\totalcmd\totalcmd64.exe
FirewallRules: [{7B6186B0-3581-48BC-B7F7-C4B0909FEED8}] => (Allow) C:\Users\jemin\AppData\Local\yc\Application\yc.exe

==================== Restore Points =========================

30-10-2017 18:17:19 Naplánovaný kontrolní bod
31-10-2017 12:52:02 Restore Point Created by FRST

==================== Faulty Device Manager Devices =============

Name: MpKsl5c8fda79
Description: MpKsl5c8fda79
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKsl5c8fda79
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: MpKsl6ad3767b
Description: MpKsl6ad3767b
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKsl6ad3767b
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name: MpKslabc8ce25
Description: MpKslabc8ce25
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: MpKslabc8ce25
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/31/2017 12:53:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Název chybujícího modulu: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Kód výjimky: 0xc0000005
Posun chyby: 0x0029c1c0
ID chybujícího procesu: 0x960
Čas spuštění chybující aplikace: 0x01d3523ece613814
Cesta k chybující aplikaci: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
ID zprávy: 0d2dc976-be32-11e7-9e09-74d4351a4be5

Error: (10/31/2017 12:53:03 PM) (Source: TeamViewer) (EventID: 0) (User: )
Description: Event-ID 0

Error: (10/31/2017 12:52:02 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
Shromažďování dat modulu pro zápis

Kontext:
ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
Název modulu pro zápis: System Writer
ID instance modulu pro zápis: {b8193c7a-0b18-4c57-b0b6-cec2de125d7d}

Error: (10/30/2017 06:37:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: LMS.exe, verze: 9.5.10.1628, časové razítko: 0x51cb6db4
Název chybujícího modulu: LMS.exe, verze: 9.5.10.1628, časové razítko: 0x51cb6db4
Kód výjimky: 0xc0000005
Posun chyby: 0x00007672
ID chybujícího procesu: 0xc14
Čas spuštění chybující aplikace: 0x01d351a5cde87a98
Cesta k chybující aplikaci: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
ID zprávy: 0b98979e-bd99-11e7-9adb-74d4351a4be5

Error: (10/30/2017 06:35:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Název chybujícího modulu: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Kód výjimky: 0xc0000005
Posun chyby: 0x0029c1c0
ID chybujícího procesu: 0x9c4
Čas spuštění chybující aplikace: 0x01d351a584dc7bce
Cesta k chybující aplikaci: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
ID zprávy: c3ccc1d4-bd98-11e7-9adb-74d4351a4be5

Error: (10/30/2017 06:35:48 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generování kontextu aktivace pro C:\Users\jemin\AppData\Local\yc\Application\yc.exe se nezdařilo. Chyba v souboru manifestu nebo zásady C:\Users\jemin\AppData\Local\yc\Application\61.0.3163.100\61.0.3163.100.MANIFEST na řádku 0.
Neplatná syntaxe XML.

Error: (10/30/2017 06:35:47 PM) (Source: TeamViewer) (EventID: 0) (User: )
Description: Event-ID 0

Error: (10/30/2017 06:34:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: LMS.exe, verze: 9.5.10.1628, časové razítko: 0x51cb6db4
Název chybujícího modulu: LMS.exe, verze: 9.5.10.1628, časové razítko: 0x51cb6db4
Kód výjimky: 0xc0000005
Posun chyby: 0x00007672
ID chybujícího procesu: 0x1fa8
Čas spuštění chybující aplikace: 0x01d351a563696ac8
Cesta k chybující aplikaci: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
ID zprávy: a119aedf-bd98-11e7-ba09-74d4351a4be5

Error: (10/30/2017 06:32:49 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Název chybujícího modulu: TeamViewer_Service.exe, verze: 10.0.36897.0, časové razítko: 0x548ec3a6
Kód výjimky: 0xc0000005
Posun chyby: 0x0029c1c0
ID chybujícího procesu: 0x9bc
Čas spuštění chybující aplikace: 0x01d351a51a5adbd4
Cesta k chybující aplikaci: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
ID zprávy: 595245fa-bd98-11e7-ba09-74d4351a4be5

Error: (10/30/2017 06:32:49 PM) (Source: SideBySide) (EventID: 59) (User: )
Description: Generování kontextu aktivace pro C:\Users\jemin\AppData\Local\yc\Application\yc.exe se nezdařilo. Chyba v souboru manifestu nebo zásady C:\Users\jemin\AppData\Local\yc\Application\61.0.3163.100\61.0.3163.100.MANIFEST na řádku 0.
Neplatná syntaxe XML.


System errors:
=============
Error: (10/31/2017 12:53:04 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: Zavedení následujícího ovladače pro spouštění počítače nebo systému se nezdařilo:
UsbCharger

Error: (10/31/2017 12:52:38 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě:
Instance této služby je již spuštěna.

Error: (10/31/2017 12:52:31 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: Byla přijata následující výstraha o závažné chybě: 20.

Error: (10/31/2017 12:52:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (10/31/2017 12:52:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba PnkBstrB byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/31/2017 12:52:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Rapid Storage Technology byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/31/2017 12:52:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Dynamic Application Loader Host Interface Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/31/2017 12:52:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Služba Windows Media Player Network Sharing byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.

Error: (10/31/2017 12:52:08 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Steam Client Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/31/2017 12:52:08 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.


CodeIntegrity:
===================================
Date: 2015-10-04 15:06:48.937
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:06:48.921
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:06:48.905
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:06:48.890
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:04:31.656
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:04:31.641
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:04:31.610
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 15:04:31.594
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 13:15:24.924
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2015-10-04 13:15:24.908
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-4670K CPU @ 3.40GHz
Percentage of memory in use: 28%
Total physical RAM: 8079.14 MB
Available physical RAM: 5764.6 MB
Total Virtual: 16156.46 MB
Available Virtual: 13555.79 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:167.58 GB) (Free:32.97 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:73.57 GB) NTFS
Drive e: () (Fixed) (Total:931.51 GB) (Free:43.24 GB) NTFS
Drive i: (ADATA UFD) (Removable) (Total:28.89 GB) (Free:2.36 GB) FAT32

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 167.7 GB) (Disk ID: 7B8D3EAE)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=167.6 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 7B8D3ED1)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 7B8D3ED9)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

========================================================
Disk: 3 (MBR Code: Windows XP) (Size: 28.9 GB) (Disk ID: C3072E18)
Partition 1: (Not Active) - (Size=28.9 GB) - (Type=0C)

==================== End of Addition.txt ============================

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 31 říj 2017 13:02
od Kodlz
toto neni log z toho cisteni.

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 31 říj 2017 13:30
od ebola
ono po čištění nic nevyskočilo -tak jsem to pustil znovu -každopádně je to pryč - :thumbsup: -ještě jednou dík -poslal jsem něco na podporu ,abych si udělal očko :)

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 31 říj 2017 15:53
od Kodlz
ok... jsem rad, ze to pomohlo.

Re: reklamy,přesměrování na nevyžádané stránky

Napsal: 27 pro 2017 22:12
od Kodlz
:closed: