Stránka 1 z 1

Adware ve Firefoxu.

Napsal: 09 led 2018 13:34
od ppetr
Dobrý den, asi měsíc mi ve Firefoxu sami otevírají reklamní stránky. Malwarebytes je nedokáže odstranit.

Mám Win 10 64 bit

Nevíte si s tím rady? Případně poradit, který antivir by to odstranil.

Děkuji za odpověď

Re: Adware ve Firefoxu.

Napsal: 09 led 2018 14:51
od Rudy

Re: Adware ve Firefoxu.

Napsal: 09 led 2018 15:56
od ppetr
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.01.2018
Ran by Fedorovi (administrator) on DESKTOP-ESQS67O (09-01-2018 15:51:16)
Running from C:\Users\Fedorovi\Desktop
Loaded Profiles: Fedorovi (Available Profiles: Fedorovi)
Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\NisSrv.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(TODO: <Company name>) C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
() C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(TODO: <Company name>) C:\Program Files (x86)\ASUS\GPU TweakII\Monitor.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
() C:\Program Files (x86)\ASUS\GPU TweakII\ASUSGPUFanServiceEx.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.11.0_x64__8wekyb3d8bbwe\WinStore.App.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17112.13411.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Blizzard Entertainment) A:\Hry\Blizzard App\Battle.net.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.5996\Agent.exe
() A:\Hry\Blizzard App\Battle.net.9679\Battle.net Helper.exe
() A:\Hry\Blizzard App\Battle.net.9679\Battle.net Helper.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9229280 2017-05-18] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321096 2017-06-20] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2407008 2017-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Fedorovi\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\MountPoints2: {5977a24a-b02b-11e7-858e-2c4d54569ba0} - "I:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [36864 2017-09-29] (Microsoft Corporation)
GroupPolicy: Restriction - Windows Defender <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 178.22.112.22 178.22.118.10
Tcpip\..\Interfaces\{0d14d7ee-3e6b-4a83-a717-ef29c4020330}: [DhcpNameServer] 178.22.112.22 178.22.118.10

Internet Explorer:
==================
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131443429128854827&GUID=3FF9C467-5646-46F5-9EF4-C4C1B728B609
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> DefaultScope {5CE25775-92B7-477d-9603-852F0B34D8B0} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... &pc=MSERT1
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> {5CE25775-92B7-477d-9603-852F0B34D8B0} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... &pc=MSERT1
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> {8ACD20D1-E475-4D00-A706-CBDA4685C337} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-19] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-19] (Oracle Corporation)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> hxxp://www.seznam.cz/

FireFox:
========
FF DefaultProfile: y3gmqbck.default
FF ProfilePath: C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default [2018-01-09]
FF user.js: detected! => C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\user.js [2017-06-29]
FF Homepage: Mozilla\Firefox\Profiles\y3gmqbck.default -> hxxps://www.seznam.cz/
FF NewTabOverride: Mozilla\Firefox\Profiles\y3gmqbck.default -> Enabled: "id":"{ea614400-e918-4741-9a97-7a972ff7c30b
FF Extension: (Seznam pro Firefox - Esko) - C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\Extensions\sko-extension@firma.seznam.cz.xpi [2017-11-28]
FF Extension: (Seznam pro Firefox - Email) - C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-10-31]
FF Extension: (Seznam pro Firefox - Email) - C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}.xpi [2017-10-25]
FF Extension: (Disable JavaScript Shared Memory) - C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\features\{8dc32061-7e54-47dd-86fe-4a783d6003e0}\disable-js-shared-memory@mozilla.org.xpi [2018-01-05] [Legacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2017-12-12] ()
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-09-20] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2017-12-12] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-12-15] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-12-15] (NVIDIA Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-09-20] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1786104691-2426081519-2716709316-1001: ubisoft.com/uplaypc -> A:\Hry\Settlers 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [No File]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [817760 2017-09-20] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2257016 2017-08-23] (Adobe Systems, Incorporated)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2015-05-08] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-04-24] () [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2017-06-20] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [732448 2017-02-24] (Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [548648 2017-02-24] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [197264 2017-06-05] (Intel Corporation)
S3 MBAMService; A:\Programs\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-11-16] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-11-16] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
S2 SpyHunter 4 Service; C:\Program Files\Enigma Software Group\SpyHunter\Sh4Service.exe [868024 2017-07-08] (Enigma Software Group USA, LLC.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\NisSrv.exe [356176 2017-12-08] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MsMpEng.exe [105792 2017-12-08] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S1 aefxtnite.sys; C:\WINDOWS\system32\drivers\aefxtnite.sys [15424 2017-07-25] () [File not signed]
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] ()
S1 bemszcafb.sys; C:\WINDOWS\system32\drivers\bemszcafb.sys [7712 2017-11-27] () [File not signed]
S1 bogqlyryb.sys; C:\WINDOWS\system32\drivers\bogqlyryb.sys [7712 2017-11-24] () [File not signed]
S1 cqctmvzng.sys; C:\WINDOWS\system32\drivers\cqctmvzng.sys [7712 2017-11-18] () [File not signed]
S1 ctoofsmoa.sys; C:\WINDOWS\system32\drivers\ctoofsmoa.sys [7712 2017-11-17] () [File not signed]
S1 cuuzkpsfk.sys; C:\WINDOWS\system32\drivers\cuuzkpsfk.sys [7712 2017-11-25] () [File not signed]
S1 dbprghlhs.sys; C:\WINDOWS\system32\drivers\dbprghlhs.sys [7712 2017-11-26] () [File not signed]
S1 dekyvudve.sys; C:\WINDOWS\system32\drivers\dekyvudve.sys [142760 2017-11-15] () [File not signed]
S1 devxiwfkv.sys; C:\WINDOWS\system32\drivers\devxiwfkv.sys [7712 2017-12-02] () [File not signed]
S0 dgsjfiqr.sys; C:\WINDOWS\System32\drivers\dgsjfiqr.sys [904104 2018-01-01] () [File not signed]
S1 dqwnqlplj.sys; C:\WINDOWS\system32\drivers\dqwnqlplj.sys [7712 2017-11-08] () [File not signed]
S1 dsxhokbii.sys; C:\WINDOWS\system32\drivers\dsxhokbii.sys [7712 2017-11-13] () [File not signed]
S1 dzskyxbvb.sys; C:\WINDOWS\system32\drivers\dzskyxbvb.sys [7712 2017-11-28] () [File not signed]
S1 eavkldyag.sys; C:\WINDOWS\system32\drivers\eavkldyag.sys [7712 2017-11-30] () [File not signed]
R1 ehblsenxq.sys; C:\WINDOWS\system32\drivers\ehblsenxq.sys [142760 2018-01-07] () [File not signed]
S1 ejpgbrgry.sys; C:\WINDOWS\system32\drivers\ejpgbrgry.sys [7712 2017-11-11] () [File not signed]
S3 esgiguard; C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [15920 2017-07-08] (Enigma Software Group USA, LLC.)
S3 EsgScanner; C:\WINDOWS\System32\DRIVERS\EsgScanner.sys [22704 2017-07-08] ()
S1 fckodwrar.sys; C:\WINDOWS\system32\drivers\fckodwrar.sys [7712 2017-11-14] () [File not signed]
S1 fdftoylto.sys; C:\WINDOWS\system32\drivers\fdftoylto.sys [7712 2017-11-19] () [File not signed]
S1 gitutnzyg.sys; C:\WINDOWS\system32\drivers\gitutnzyg.sys [7712 2017-11-18] () [File not signed]
S1 gnadttrzp.sys; C:\WINDOWS\system32\drivers\gnadttrzp.sys [7712 2017-11-27] () [File not signed]
S1 gnqzjjlpt.sys; C:\WINDOWS\system32\drivers\gnqzjjlpt.sys [7712 2017-11-02] () [File not signed]
R3 GPUIO; C:\Program Files (x86)\ASUS\GPU TweakII\690b33e1-0462-4e84-9bea-c7552b45432a.sys [27120 2018-01-07] ()
S1 hfksobcgy.sys; C:\WINDOWS\system32\drivers\hfksobcgy.sys [7712 2017-11-04] () [File not signed]
R0 hktzcivb.sys; C:\WINDOWS\System32\drivers\hktzcivb.sys [904104 2018-01-01] () [File not signed]
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [27552 2017-08-06] (REALiX(tm))
S1 iajekjhzs.sys; C:\WINDOWS\system32\drivers\iajekjhzs.sys [7712 2017-11-18] () [File not signed]
S1 ikffgqzyq.sys; C:\WINDOWS\system32\drivers\ikffgqzyq.sys [7712 2017-12-01] () [File not signed]
R4 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2017-05-08] (ASUSTeK Computer Inc.)
S1 jbjtpsvjp.sys; C:\WINDOWS\system32\drivers\jbjtpsvjp.sys [7712 2017-11-12] () [File not signed]
S1 jsifawipr.sys; C:\WINDOWS\system32\drivers\jsifawipr.sys [7712 2017-10-31] () [File not signed]
S1 mdyvbjunl.sys; C:\WINDOWS\system32\drivers\mdyvbjunl.sys [15424 2017-08-06] () [File not signed]
S1 mivujvbcw.sys; C:\WINDOWS\system32\drivers\mivujvbcw.sys [7712 2017-10-31] () [File not signed]
R1 MpKslf619a452; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2B4F7414-9AAA-4913-82AC-FE3C623CA5C4}\MpKslf619a452.sys [58120 2018-01-09] (Microsoft Corporation)
S1 mtunnbbvg.sys; C:\WINDOWS\system32\drivers\mtunnbbvg.sys [7712 2018-01-07] () [File not signed]
S1 namccznua.sys; C:\WINDOWS\system32\drivers\namccznua.sys [7712 2017-11-03] () [File not signed]
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d37ca5c2cde53609\nvlddmkm.sys [17028552 2017-12-18] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-11-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-11-28] (NVIDIA Corporation)
S1 ofierptfj.sys; C:\WINDOWS\system32\drivers\ofierptfj.sys [15424 2017-08-06] () [File not signed]
S1 pfchccpjf.sys; C:\WINDOWS\system32\drivers\pfchccpjf.sys [7712 2017-11-22] () [File not signed]
S1 pgmtoudyn.sys; C:\WINDOWS\system32\drivers\pgmtoudyn.sys [7712 2017-11-05] () [File not signed]
S0 pkkjmqev.sys; C:\WINDOWS\System32\drivers\pkkjmqev.sys [15440 2018-01-01] (Acer Laboratories Inc.)
S1 plwhmuliy.sys; C:\WINDOWS\system32\drivers\plwhmuliy.sys [7712 2017-11-02] () [File not signed]
S1 poekcoojk.sys; C:\WINDOWS\system32\drivers\poekcoojk.sys [15424 2017-07-27] () [File not signed]
S1 ppctndrks.sys; C:\WINDOWS\system32\drivers\ppctndrks.sys [7712 2017-11-09] () [File not signed]
S1 pskricapm.sys; C:\WINDOWS\system32\drivers\pskricapm.sys [7712 2017-11-18] () [File not signed]
S1 qgcftitqz.sys; C:\WINDOWS\system32\drivers\qgcftitqz.sys [15424 2017-08-06] () [File not signed]
S1 qjfajkcpq.sys; C:\WINDOWS\system32\drivers\qjfajkcpq.sys [7712 2017-11-25] () [File not signed]
S1 qkvmaioxc.sys; C:\WINDOWS\system32\drivers\qkvmaioxc.sys [7712 2017-12-01] () [File not signed]
S1 qrymmgucq.sys; C:\WINDOWS\system32\drivers\qrymmgucq.sys [7712 2017-10-31] () [File not signed]
S1 qswpbwjmv.sys; C:\WINDOWS\system32\drivers\qswpbwjmv.sys [7712 2017-11-02] () [File not signed]
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-09-29] (Realtek )
S1 runcqaaii.sys; C:\WINDOWS\system32\drivers\runcqaaii.sys [7712 2017-11-29] () [File not signed]
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [41512 2017-12-07] ()
S1 tlyxkongt.sys; C:\WINDOWS\system32\drivers\tlyxkongt.sys [15424 2017-07-26] () [File not signed]
S1 ubxdpiopr.sys; C:\WINDOWS\system32\drivers\ubxdpiopr.sys [7712 2018-01-06] () [File not signed]
S1 uwtjuzxqo.sys; C:\WINDOWS\system32\drivers\uwtjuzxqo.sys [7712 2017-11-16] () [File not signed]
S1 vbziccmil.sys; C:\WINDOWS\system32\drivers\vbziccmil.sys [7712 2017-11-20] () [File not signed]
S1 vnjnxllxc.sys; C:\WINDOWS\system32\drivers\vnjnxllxc.sys [7712 2017-11-15] () [File not signed]
S1 vnwlzfuap.sys; C:\WINDOWS\system32\drivers\vnwlzfuap.sys [7712 2017-11-06] () [File not signed]
S1 vqrwxlxnu.sys; C:\WINDOWS\system32\drivers\vqrwxlxnu.sys [7712 2017-11-01] () [File not signed]
S1 vrraekqwa.sys; C:\WINDOWS\system32\drivers\vrraekqwa.sys [15424 2017-08-06] () [File not signed]
S1 vxfeoyqku.sys; C:\WINDOWS\system32\drivers\vxfeoyqku.sys [15424 2017-07-07] () [File not signed]
S1 vysgcoiqn.sys; C:\WINDOWS\system32\drivers\vysgcoiqn.sys [7712 2017-11-03] () [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2017-12-08] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2017-12-08] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2017-12-08] (Microsoft Corporation)
S1 wpinwbetm.sys; C:\WINDOWS\system32\drivers\wpinwbetm.sys [7712 2017-11-21] () [File not signed]
S1 xbcgiypin.sys; C:\WINDOWS\system32\drivers\xbcgiypin.sys [7712 2017-11-01] () [File not signed]
S1 xgsfbmoos.sys; C:\WINDOWS\system32\drivers\xgsfbmoos.sys [7712 2017-11-18] () [File not signed]
S1 xiewtpbkl.sys; C:\WINDOWS\system32\drivers\xiewtpbkl.sys [7712 2017-12-13] () [File not signed]
S1 yxixaooko.sys; C:\WINDOWS\system32\drivers\yxixaooko.sys [7712 2017-11-01] () [File not signed]
S1 zibaqtkwt.sys; C:\WINDOWS\system32\drivers\zibaqtkwt.sys [7712 2017-11-07] () [File not signed]
S1 zunfgmfni.sys; C:\WINDOWS\system32\drivers\zunfgmfni.sys [7712 2017-11-23] () [File not signed]
S3 TcHardWare; \??\C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCHW-x64_ev.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-09 15:51 - 2018-01-09 15:51 - 000022385 _____ C:\Users\Fedorovi\Desktop\FRST.txt
2018-01-09 15:50 - 2018-01-09 15:51 - 000000000 ____D C:\FRST
2018-01-09 15:48 - 2018-01-09 15:48 - 000000000 _____ C:\Users\Fedorovi\Desktop\FRSTLauncher.exe
2018-01-09 15:47 - 2018-01-09 15:48 - 002393088 _____ (Farbar) C:\Users\Fedorovi\Desktop\FRST64.exe
2018-01-07 12:53 - 2018-01-09 15:41 - 001872235 _____ C:\WINDOWS\system32\r6lstmp4.dat
2018-01-07 09:52 - 2018-01-09 14:08 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-01-07 09:52 - 2018-01-07 09:52 - 000142760 _____ C:\WINDOWS\system32\Drivers\qjwitnhms.sys
2018-01-07 09:52 - 2018-01-07 09:52 - 000007712 _____ C:\WINDOWS\system32\Drivers\mtunnbbvg.sys
2018-01-07 08:27 - 2018-01-07 09:51 - 000142760 _____ C:\WINDOWS\system32\Drivers\ehblsenxq.sys
2018-01-07 08:22 - 2018-01-09 12:27 - 000000000 ___HD C:\Users\Public\Documents\AdobeGC
2018-01-06 11:17 - 2018-01-06 11:17 - 000142760 _____ C:\WINDOWS\system32\Drivers\kigzcfcuy.sys
2018-01-06 11:17 - 2018-01-06 11:17 - 000007712 _____ C:\WINDOWS\system32\Drivers\ubxdpiopr.sys
2018-01-05 14:03 - 2018-01-01 18:15 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-01-05 14:03 - 2018-01-01 13:51 - 001055128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-01-05 14:03 - 2018-01-01 13:51 - 000059800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bam.sys
2018-01-05 14:03 - 2018-01-01 13:50 - 005905752 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2018-01-05 14:03 - 2018-01-01 13:49 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-01-05 14:03 - 2018-01-01 13:49 - 000319352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-01-05 14:03 - 2018-01-01 13:48 - 007831760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-01-05 14:03 - 2018-01-01 13:48 - 001954048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-01-05 14:03 - 2018-01-01 13:48 - 000904104 _____ C:\WINDOWS\system32\Drivers\hktzcivb.sys
2018-01-05 14:03 - 2018-01-01 13:48 - 000904104 _____ C:\WINDOWS\system32\Drivers\dgsjfiqr.sys
2018-01-05 14:03 - 2018-01-01 13:48 - 000015440 _____ (Acer Laboratories Inc.) C:\WINDOWS\system32\Drivers\pkkjmqev.sys
2018-01-05 14:03 - 2018-01-01 13:47 - 000082840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-01-05 14:03 - 2018-01-01 13:46 - 002709704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-01-05 14:03 - 2018-01-01 13:46 - 000471960 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-01-05 14:03 - 2018-01-01 13:45 - 002395032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-01-05 14:03 - 2018-01-01 13:45 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-01-05 14:03 - 2018-01-01 13:45 - 000398744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2018-01-05 14:03 - 2018-01-01 13:42 - 000571288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-01-05 14:03 - 2018-01-01 13:42 - 000184984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2018-01-05 14:03 - 2018-01-01 13:41 - 007676296 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-01-05 14:03 - 2018-01-01 13:40 - 001206680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-01-05 14:03 - 2018-01-01 13:39 - 000902416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-01-05 14:03 - 2018-01-01 13:39 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-01-05 14:03 - 2018-01-01 13:39 - 000129432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-01-05 14:03 - 2018-01-01 13:38 - 003904808 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-01-05 14:03 - 2018-01-01 13:37 - 001426664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-01-05 14:03 - 2018-01-01 13:36 - 000166296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2018-01-05 14:03 - 2018-01-01 13:35 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-01-05 14:03 - 2018-01-01 13:34 - 007385088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-01-05 14:03 - 2018-01-01 13:33 - 000603920 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-01-05 14:03 - 2018-01-01 13:32 - 004481240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-01-05 14:03 - 2018-01-01 13:27 - 000713624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-01-05 14:03 - 2018-01-01 13:26 - 000428952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-01-05 14:03 - 2018-01-01 13:25 - 000615768 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2018-01-05 14:03 - 2018-01-01 13:25 - 000147864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2018-01-05 14:03 - 2018-01-01 13:23 - 021352144 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-01-05 14:03 - 2018-01-01 13:03 - 000123512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2018-01-05 14:03 - 2018-01-01 12:53 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-01-05 14:03 - 2018-01-01 12:46 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-01-05 14:03 - 2018-01-01 12:45 - 006092152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-01-05 14:03 - 2018-01-01 12:45 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-01-05 14:03 - 2018-01-01 12:45 - 002192624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-01-05 14:03 - 2018-01-01 12:43 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-01-05 14:03 - 2018-01-01 12:42 - 006479552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-01-05 14:03 - 2018-01-01 12:42 - 004644912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-01-05 14:03 - 2018-01-01 12:42 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-01-05 14:03 - 2018-01-01 12:42 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-01-05 14:03 - 2018-01-01 12:37 - 025247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-01-05 14:03 - 2018-01-01 12:34 - 000703568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-01-05 14:03 - 2018-01-01 12:25 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-01-05 14:03 - 2018-01-01 12:25 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-01-05 14:03 - 2018-01-01 12:25 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-01-05 14:03 - 2018-01-01 12:25 - 000097792 _____ C:\WINDOWS\system32\runexehelper.exe
2018-01-05 14:03 - 2018-01-01 12:24 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-01-05 14:03 - 2018-01-01 12:24 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2018-01-05 14:03 - 2018-01-01 12:23 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-01-05 14:03 - 2018-01-01 12:23 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-01-05 14:03 - 2018-01-01 12:23 - 000250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2018-01-05 14:03 - 2018-01-01 12:21 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2018-01-05 14:03 - 2018-01-01 12:20 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-01-05 14:03 - 2018-01-01 12:20 - 018917888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 008014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2018-01-05 14:03 - 2018-01-01 12:18 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-01-05 14:03 - 2018-01-01 12:18 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-01-05 14:03 - 2018-01-01 12:18 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-01-05 14:03 - 2018-01-01 12:15 - 012687872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-01-05 14:03 - 2018-01-01 12:15 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-01-05 14:03 - 2018-01-01 12:15 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2018-01-05 14:03 - 2018-01-01 12:14 - 023655936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-01-05 14:03 - 2018-01-01 12:14 - 002465280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-01-05 14:03 - 2018-01-01 12:14 - 001495040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 013657600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 012830208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 003121664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-01-05 14:03 - 2018-01-01 12:12 - 002633216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-01-05 14:03 - 2018-01-01 12:12 - 002208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-01-05 14:03 - 2018-01-01 12:12 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-01-05 14:03 - 2018-01-01 12:12 - 001424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 008108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 003165696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-01-05 14:03 - 2018-01-01 12:09 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-01-05 14:03 - 2018-01-01 12:09 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-01-05 14:03 - 2018-01-01 12:08 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-01-05 14:03 - 2018-01-01 12:08 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2018-01-05 14:03 - 2018-01-01 12:05 - 002510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-01-05 14:03 - 2018-01-01 12:05 - 001160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-01-05 14:02 - 2018-01-01 13:54 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-01-05 14:02 - 2018-01-01 13:53 - 001090984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-01-05 14:02 - 2018-01-01 13:52 - 000066712 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2018-01-05 14:02 - 2018-01-01 13:51 - 001414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-01-05 14:02 - 2018-01-01 13:51 - 001209240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-01-05 14:02 - 2018-01-01 13:51 - 000191816 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-01-05 14:02 - 2018-01-01 13:50 - 000780464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2018-01-05 14:02 - 2018-01-01 13:50 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-01-05 14:02 - 2018-01-01 13:50 - 000077208 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-01-05 14:02 - 2018-01-01 13:49 - 000599448 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-01-05 14:02 - 2018-01-01 13:49 - 000292376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2018-01-05 14:02 - 2018-01-01 13:48 - 000382360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2018-01-05 14:02 - 2018-01-01 13:47 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-01-05 14:02 - 2018-01-01 13:46 - 000898216 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-01-05 14:02 - 2018-01-01 13:46 - 000733592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-01-05 14:02 - 2018-01-01 13:43 - 001173576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-01-05 14:02 - 2018-01-01 13:43 - 000367336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2018-01-05 14:02 - 2018-01-01 13:43 - 000062872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
2018-01-05 14:02 - 2018-01-01 13:42 - 001029016 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2018-01-05 14:02 - 2018-01-01 13:42 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-01-05 14:02 - 2018-01-01 13:42 - 000109976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2018-01-05 14:02 - 2018-01-01 13:41 - 000559512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-01-05 14:02 - 2018-01-01 13:41 - 000549552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2018-01-05 14:02 - 2018-01-01 13:39 - 000677784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-01-05 14:02 - 2018-01-01 13:39 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-01-05 14:02 - 2018-01-01 13:38 - 000727448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2018-01-05 14:02 - 2018-01-01 13:38 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-01-05 14:02 - 2018-01-01 13:38 - 000103320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-01-05 14:02 - 2018-01-01 13:38 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
2018-01-05 14:02 - 2018-01-01 13:37 - 000461720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2018-01-05 14:02 - 2018-01-01 13:36 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-01-05 14:02 - 2018-01-01 13:36 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2018-01-05 14:02 - 2018-01-01 13:36 - 000113560 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2018-01-05 14:02 - 2018-01-01 13:36 - 000057752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbios.sys
2018-01-05 14:02 - 2018-01-01 13:35 - 000075160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-01-05 14:02 - 2018-01-01 13:34 - 001336344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-01-05 14:02 - 2018-01-01 13:34 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-01-05 14:02 - 2018-01-01 13:34 - 000087384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2018-01-05 14:02 - 2018-01-01 13:33 - 002773400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-01-05 14:02 - 2018-01-01 13:32 - 000617304 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2018-01-05 14:02 - 2018-01-01 13:27 - 000163736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-01-05 14:02 - 2018-01-01 13:26 - 000081304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2018-01-05 14:02 - 2018-01-01 13:21 - 001103768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-01-05 14:02 - 2018-01-01 13:21 - 000614296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2018-01-05 14:02 - 2018-01-01 13:06 - 000311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2018-01-05 14:02 - 2018-01-01 13:03 - 000777904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-01-05 14:02 - 2018-01-01 13:03 - 000650328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2018-01-05 14:02 - 2018-01-01 13:03 - 000566664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-01-05 14:02 - 2018-01-01 12:49 - 000481464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-01-05 14:02 - 2018-01-01 12:49 - 000258808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2018-01-05 14:02 - 2018-01-01 12:46 - 000289816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2018-01-05 14:02 - 2018-01-01 12:45 - 000450928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2018-01-05 14:02 - 2018-01-01 12:42 - 001003152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-01-05 14:02 - 2018-01-01 12:42 - 000386424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2018-01-05 14:02 - 2018-01-01 12:42 - 000129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-01-05 14:02 - 2018-01-01 12:42 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2018-01-05 14:02 - 2018-01-01 12:25 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2018-01-05 14:02 - 2018-01-01 12:24 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2018-01-05 14:02 - 2018-01-01 12:24 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2018-01-05 14:02 - 2018-01-01 12:24 - 000038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2018-01-05 14:02 - 2018-01-01 12:23 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2018-01-05 14:02 - 2018-01-01 12:23 - 000385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2018-01-05 14:02 - 2018-01-01 12:23 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\convertvhd.exe
2018-01-05 14:02 - 2018-01-01 12:23 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2018-01-05 14:02 - 2018-01-01 12:23 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2018-01-05 14:02 - 2018-01-01 12:23 - 000047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2018-01-05 14:02 - 2018-01-01 12:22 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2018-01-05 14:02 - 2018-01-01 12:22 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2018-01-05 14:02 - 2018-01-01 12:22 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmApplicationHealthMonitorProxy.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspptp.sys
2018-01-05 14:02 - 2018-01-01 12:21 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2018-01-05 14:02 - 2018-01-01 12:21 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2018-01-05 14:02 - 2018-01-01 12:20 - 000524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2018-01-05 14:02 - 2018-01-01 12:20 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
2018-01-05 14:02 - 2018-01-01 12:20 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshhttp.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalAuth.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2018-01-05 14:02 - 2018-01-01 12:19 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2018-01-05 14:02 - 2018-01-01 12:19 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2018-01-05 14:02 - 2018-01-01 12:19 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoert2.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2018-01-05 14:02 - 2018-01-01 12:19 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 006564864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-01-05 14:02 - 2018-01-01 12:17 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000966656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000956928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 002349568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 000985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 000870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-01-05 14:02 - 2018-01-01 12:13 - 002013184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-01-05 14:02 - 2018-01-01 12:13 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-01-05 14:02 - 2018-01-01 12:13 - 000897024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-01-05 14:02 - 2018-01-01 12:12 - 001573376 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2018-01-05 14:02 - 2018-01-01 12:12 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2018-01-05 14:02 - 2018-01-01 12:12 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 002082304 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-01-05 14:02 - 2018-01-01 12:11 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 001343488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-01-05 14:02 - 2018-01-01 12:10 - 003126272 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-01-05 14:02 - 2018-01-01 12:10 - 002528256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-01-05 14:02 - 2018-01-01 12:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscproxystub.dll
2018-01-05 14:02 - 2018-01-01 12:09 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-01-05 14:02 - 2018-01-01 12:09 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2018-01-05 14:02 - 2018-01-01 12:08 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-01-05 14:02 - 2018-01-01 12:08 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-01-05 14:02 - 2018-01-01 12:08 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2018-01-05 14:02 - 2018-01-01 12:06 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2018-01-05 14:02 - 2018-01-01 12:05 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2018-01-03 15:08 - 2018-01-03 15:08 - 000000722 _____ C:\Users\Fedorovi\Desktop\Kleirou – zástupce.lnk
2017-12-30 07:32 - 2017-12-30 07:32 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2017-12-30 07:32 - 2017-12-15 23:47 - 000143960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2017-12-30 07:32 - 2017-09-14 00:20 - 000798008 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-12-30 07:32 - 2017-09-14 00:20 - 000490296 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-12-30 07:32 - 2017-09-14 00:19 - 000927544 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-12-30 07:32 - 2017-09-14 00:19 - 000591160 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-12-30 07:29 - 2017-12-16 01:23 - 040237456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 036350960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 035157488 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 029381936 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 023267096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 019040512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 013867656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 013255032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 011781912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 010883744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 004202992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 003615032 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001990128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438871.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001674736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438871.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001331016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001321448 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001135464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001101104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001044848 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001038496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000980880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000933360 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000885680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000794392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000740144 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000634224 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000618744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000616240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000599536 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 000506864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-12-29 15:52 - 2017-12-29 15:52 - 000003834 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2017-12-29 15:19 - 2017-12-07 23:29 - 000041512 _____ C:\WINDOWS\system32\Drivers\semav6msr64.sys
2017-12-29 15:13 - 2017-12-29 15:13 - 000000000 ____D C:\Intel
2017-12-29 14:58 - 2017-12-29 14:58 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsign6eea94283bec1be9
2017-12-29 14:58 - 2017-12-29 14:58 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsign5e21e6dbbb1a28fd
2017-12-29 14:58 - 2017-12-29 14:58 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsign352e001da65cb700
2017-12-24 19:07 - 2017-12-24 19:07 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsigne875345af2dd7e16
2017-12-24 19:06 - 2017-12-24 19:06 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsignd8bcbf80b4b6cc28
2017-12-24 19:06 - 2017-12-24 19:06 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsignae29bdadfb484294
2017-12-23 14:41 - 2018-01-05 15:31 - 000000000 ____D C:\Users\Fedorovi\Documents\Settlers7
2017-12-23 14:41 - 2017-12-23 15:46 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Ubisoft Game Launcher
2017-12-23 14:40 - 2009-09-04 17:44 - 000517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 005554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 005501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 002582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 002475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 001974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 001892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 000523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 000453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 000285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 000235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
2017-12-23 14:40 - 2009-03-16 14:18 - 000521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2017-12-23 14:40 - 2009-03-16 14:18 - 000517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
2017-12-23 14:40 - 2009-03-16 14:18 - 000235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
2017-12-23 14:40 - 2009-03-16 14:18 - 000174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 005425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 004178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 002430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 001846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 000520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 000453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
2017-12-23 14:39 - 2009-03-16 14:18 - 000024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2017-12-23 14:39 - 2009-03-16 14:18 - 000022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 005631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 004379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 002605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 002036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 000519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 000452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2017-12-23 14:39 - 2008-07-31 10:41 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
2017-12-23 14:39 - 2008-07-31 10:41 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2017-12-23 14:39 - 2008-07-31 10:41 - 000072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2017-12-23 14:39 - 2008-07-31 10:41 - 000068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2017-12-23 14:39 - 2008-07-31 10:40 - 000513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2017-12-23 14:39 - 2008-07-31 10:40 - 000509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2017-12-23 14:39 - 2008-07-10 11:01 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 004992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 003851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 001942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 001493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2017-12-23 14:39 - 2008-05-30 14:19 - 000511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2017-12-23 14:39 - 2008-05-30 14:19 - 000507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
2017-12-23 14:39 - 2008-05-30 14:18 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
2017-12-23 14:39 - 2008-05-30 14:18 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2017-12-23 14:39 - 2008-05-30 14:17 - 000068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2017-12-23 14:39 - 2008-05-30 14:17 - 000065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
2017-12-23 14:39 - 2008-05-30 14:17 - 000025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
2017-12-23 14:39 - 2008-05-30 14:16 - 000028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 004991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 003850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 001941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 001491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
2017-12-23 14:39 - 2008-03-05 16:04 - 000489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2017-12-23 14:39 - 2008-03-05 16:03 - 000479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
2017-12-23 14:39 - 2008-03-05 16:03 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
2017-12-23 14:39 - 2008-03-05 16:03 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2017-12-23 14:39 - 2008-03-05 16:00 - 000028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2017-12-23 14:39 - 2008-03-05 16:00 - 000025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
2017-12-23 14:39 - 2008-03-05 15:56 - 004910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2017-12-23 14:39 - 2008-03-05 15:56 - 003786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
2017-12-23 14:39 - 2008-03-05 15:56 - 001860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2017-12-23 14:39 - 2008-03-05 15:56 - 001420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
2017-12-23 14:39 - 2008-02-05 23:07 - 000529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2017-12-23 14:39 - 2008-02-05 23:07 - 000462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
2017-12-23 14:39 - 2007-10-22 03:40 - 000411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2017-12-23 14:39 - 2007-10-22 03:39 - 000267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
2017-12-23 14:39 - 2007-10-22 03:37 - 000021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2017-12-23 14:39 - 2007-10-22 03:37 - 000017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
2017-12-23 14:39 - 2007-10-12 15:14 - 005081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2017-12-23 14:39 - 2007-10-12 15:14 - 003734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
2017-12-23 14:39 - 2007-10-12 15:14 - 002006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2017-12-23 14:39 - 2007-10-12 15:14 - 001374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
2017-12-23 14:39 - 2007-10-02 09:56 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2017-12-23 14:39 - 2007-10-02 09:56 - 000444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
2017-12-23 14:39 - 2007-07-20 00:57 - 000411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2017-12-23 14:39 - 2007-07-20 00:57 - 000267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 005073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 003727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 001985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 001358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 000444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
2017-12-23 14:39 - 2007-06-20 20:49 - 000409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2017-12-23 14:39 - 2007-06-20 20:46 - 000266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 004496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 003497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 001401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 001124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 000443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
2017-12-23 14:39 - 2007-04-04 18:55 - 000403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2017-12-23 14:39 - 2007-04-04 18:55 - 000261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
2017-12-23 14:39 - 2007-04-04 18:54 - 000107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
2017-12-23 14:39 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
2017-12-23 14:39 - 2007-03-15 16:57 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2017-12-23 14:39 - 2007-03-15 16:57 - 000443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
2017-12-23 14:39 - 2007-03-12 16:42 - 004494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2017-12-23 14:39 - 2007-03-12 16:42 - 003495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
2017-12-23 14:39 - 2007-03-12 16:42 - 001400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2017-12-23 14:39 - 2007-03-12 16:42 - 001123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
2017-12-23 14:39 - 2007-03-05 12:42 - 000017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2017-12-23 14:39 - 2007-03-05 12:42 - 000015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
2017-12-23 14:39 - 2007-01-24 15:27 - 000393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2017-12-23 14:39 - 2007-01-24 15:27 - 000255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
2017-12-23 14:39 - 2006-12-08 12:02 - 000251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
2017-12-23 14:39 - 2006-12-08 12:00 - 000390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
2017-12-23 14:39 - 2006-11-29 13:06 - 004398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2017-12-23 14:39 - 2006-11-29 13:06 - 003426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2017-12-23 14:39 - 2006-11-29 13:06 - 000469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
2017-12-23 14:39 - 2006-11-29 13:06 - 000440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
2017-12-23 14:39 - 2006-09-28 16:05 - 003977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
2017-12-23 14:39 - 2006-09-28 16:05 - 002414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
2017-12-23 14:39 - 2006-09-28 16:05 - 000237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
2017-12-23 14:39 - 2006-09-28 16:04 - 000364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
2017-12-23 14:39 - 2006-07-28 09:31 - 000083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
2017-12-23 14:39 - 2006-07-28 09:30 - 000363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
2017-12-23 14:39 - 2006-07-28 09:30 - 000236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
2017-12-23 14:39 - 2006-07-28 09:30 - 000062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
2017-12-23 14:39 - 2006-05-31 07:24 - 000230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
2017-12-23 14:39 - 2006-05-31 07:22 - 000354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
2017-12-23 14:39 - 2006-03-31 12:41 - 003927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
2017-12-23 14:39 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2017-12-23 14:39 - 2006-03-31 12:40 - 000352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
2017-12-23 14:39 - 2006-03-31 12:39 - 000229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
2017-12-23 14:39 - 2006-03-31 12:39 - 000083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
2017-12-23 14:39 - 2006-03-31 12:39 - 000062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
2017-12-23 14:39 - 2006-02-03 08:43 - 003830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
2017-12-23 14:39 - 2006-02-03 08:43 - 002332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
2017-12-23 14:39 - 2006-02-03 08:42 - 000355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
2017-12-23 14:39 - 2006-02-03 08:42 - 000230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
2017-12-23 14:39 - 2006-02-03 08:41 - 000016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
2017-12-23 14:39 - 2006-02-03 08:41 - 000014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
2017-12-23 14:39 - 2005-12-05 18:09 - 003815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
2017-12-23 14:39 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
2017-12-23 14:39 - 2005-07-22 19:59 - 003807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
2017-12-23 14:39 - 2005-07-22 19:59 - 002319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
2017-12-23 14:39 - 2005-05-26 15:34 - 003767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
2017-12-23 14:39 - 2005-05-26 15:34 - 002297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
2017-12-23 14:39 - 2005-03-18 17:19 - 003823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
2017-12-23 14:39 - 2005-03-18 17:19 - 002337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
2017-12-23 14:39 - 2005-02-05 19:45 - 003544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
2017-12-23 14:39 - 2005-02-05 19:45 - 002222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
2017-12-23 14:38 - 2017-12-23 14:38 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2017-12-13 20:05 - 2017-12-13 20:05 - 000142760 _____ C:\WINDOWS\system32\Drivers\ykyusygrf.sys
2017-12-13 20:05 - 2017-12-13 20:05 - 000007712 _____ C:\WINDOWS\system32\Drivers\xiewtpbkl.sys
2017-12-13 17:21 - 2017-12-08 07:52 - 000666112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2017-12-13 17:21 - 2017-12-08 00:34 - 001925296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-12-13 17:21 - 2017-12-08 00:34 - 001634288 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-12-13 17:21 - 2017-12-08 00:28 - 000710912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-12-13 17:21 - 2017-12-08 00:28 - 000630752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcrt.dll
2017-12-13 17:21 - 2017-12-08 00:27 - 004504456 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2017-12-13 17:21 - 2017-12-08 00:26 - 000525208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2017-12-13 17:21 - 2017-12-08 00:24 - 000705944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2017-12-13 17:21 - 2017-12-08 00:24 - 000437144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-12-13 17:21 - 2017-12-08 00:24 - 000246168 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-12-13 17:21 - 2017-12-08 00:22 - 001003104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-12-13 17:21 - 2017-12-08 00:22 - 000979352 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-12-13 17:21 - 2017-12-08 00:22 - 000137544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2017-12-13 17:21 - 2017-12-08 00:16 - 001776272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-12-13 17:21 - 2017-12-08 00:15 - 000721592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-12-13 17:21 - 2017-12-08 00:12 - 000401304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2017-12-13 17:21 - 2017-12-07 23:56 - 001528904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-12-13 17:21 - 2017-12-07 23:55 - 001490328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-12-13 17:21 - 2017-12-07 23:55 - 000097144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2017-12-13 17:21 - 2017-12-07 23:37 - 001145104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-12-13 17:21 - 2017-12-07 23:36 - 000769096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcrt.dll
2017-12-13 17:21 - 2017-12-07 23:33 - 000747416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-12-13 17:21 - 2017-12-07 23:33 - 000592280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2017-12-13 17:21 - 2017-12-07 23:31 - 001522176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-12-13 17:21 - 2017-12-07 23:12 - 000101376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx
2017-12-13 17:21 - 2017-12-07 23:10 - 006466048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-12-13 17:21 - 2017-12-07 23:10 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2017-12-13 17:21 - 2017-12-07 23:10 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-12-13 17:21 - 2017-12-07 23:09 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\batmeter.dll
2017-12-13 17:21 - 2017-12-07 23:09 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2017-12-13 17:21 - 2017-12-07 23:09 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2017-12-13 17:21 - 2017-12-07 23:09 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2017-12-13 17:21 - 2017-12-07 23:09 - 000136704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gamingtcui.dll
2017-12-13 17:21 - 2017-12-07 23:08 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-12-13 17:21 - 2017-12-07 23:08 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2017-12-13 17:21 - 2017-12-07 23:08 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-12-13 17:21 - 2017-12-07 23:07 - 000254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\PushToInstall.dll
2017-12-13 17:21 - 2017-12-07 23:07 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-12-13 17:21 - 2017-12-07 23:07 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2017-12-13 17:21 - 2017-12-07 23:07 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-12-13 17:21 - 2017-12-07 23:06 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2017-12-13 17:21 - 2017-12-07 23:06 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcui.dll
2017-12-13 17:21 - 2017-12-07 23:06 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2017-12-13 17:21 - 2017-12-07 23:05 - 001670656 _____ (Microsoft Corporation) C:\WINDOWS\system32\batmeter.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000559616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000481792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2017-12-13 17:21 - 2017-12-07 23:05 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2017-12-13 17:21 - 2017-12-07 23:04 - 001498112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2017-12-13 17:21 - 2017-12-07 23:04 - 001321472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 000841728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\hascsp.dll
2017-12-13 17:21 - 2017-12-07 23:02 - 007545344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-12-13 17:21 - 2017-12-07 23:02 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2017-12-13 17:21 - 2017-12-07 23:02 - 002117632 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2017-12-13 17:21 - 2017-12-07 23:02 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2017-12-13 17:21 - 2017-12-07 23:01 - 004592640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-12-13 17:21 - 2017-12-07 23:01 - 001980928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2017-12-13 17:21 - 2017-12-07 23:01 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2017-12-13 17:21 - 2017-12-07 23:01 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2017-12-13 17:21 - 2017-12-07 23:00 - 001509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-12-13 17:21 - 2017-12-07 22:59 - 002105856 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-12-13 17:21 - 2017-12-07 22:59 - 001666048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-12-13 17:21 - 2017-12-07 22:59 - 001058304 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-12-13 17:21 - 2017-12-07 22:58 - 003478016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-12-13 17:21 - 2017-12-07 22:58 - 003211776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-12-13 17:21 - 2017-12-07 22:58 - 001353728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-12-13 17:21 - 2017-12-07 22:56 - 002666496 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2017-12-13 17:21 - 2017-12-07 22:56 - 001739264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-12-13 17:21 - 2017-12-07 22:54 - 001570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-12-10 07:18 - 2017-12-05 22:17 - 001989944 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438859.dll
2017-12-10 07:18 - 2017-12-05 22:17 - 001674736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438859.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-09 15:50 - 2017-06-25 05:57 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Battle.net
2018-01-09 15:45 - 2017-06-28 16:48 - 000000000 ____D C:\Users\Fedorovi\AppData\LocalLow\Mozilla
2018-01-09 14:20 - 2017-06-24 04:54 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\NVIDIA
2018-01-09 14:11 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\rescache
2018-01-09 13:41 - 2017-07-07 19:10 - 000093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2018-01-09 13:28 - 2017-07-07 19:10 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2018-01-09 13:28 - 2017-07-07 19:10 - 000101784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2018-01-09 13:28 - 2017-07-07 19:10 - 000045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2018-01-09 13:01 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-01-09 12:33 - 2017-10-26 12:01 - 001872235 _____ C:\WINDOWS\system32\r6lstmp5.dat
2018-01-09 12:26 - 2017-07-07 11:02 - 000000000 ____D C:\Users\Fedorovi\AppData\Roaming\Seznam.cz
2018-01-09 12:25 - 2017-09-29 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-01-09 12:25 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-01-09 12:25 - 2017-07-04 16:37 - 000000000 ____D C:\ProgramData\NVIDIA
2018-01-09 12:24 - 2017-12-02 08:58 - 000004218 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{633CA722-7311-444B-BD0D-C122C404D2DF}
2018-01-09 12:21 - 2017-12-02 08:58 - 000003100 _____ C:\WINDOWS\System32\Tasks\GPU Tweak II
2018-01-09 02:38 - 2017-06-28 16:54 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Adobe
2018-01-07 12:58 - 2017-12-02 08:55 - 002156588 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-01-07 12:58 - 2017-09-30 15:31 - 000944270 _____ C:\WINDOWS\system32\perfh005.dat
2018-01-07 12:58 - 2017-09-30 15:31 - 000209976 _____ C:\WINDOWS\system32\perfc005.dat
2018-01-07 12:56 - 2017-11-29 14:07 - 000571472 _____ C:\Tiem.txt
2018-01-07 09:52 - 2017-12-02 08:58 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-01-07 09:51 - 2017-09-29 09:45 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-01-07 09:29 - 2017-07-07 19:10 - 000188352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2018-01-07 07:56 - 2017-12-02 08:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-01-06 11:26 - 2017-06-25 05:10 - 000000000 ____D C:\Users\Fedorovi\Documents\My Games
2018-01-05 21:43 - 2017-09-29 14:44 - 000000000 ____D C:\WINDOWS\INF
2018-01-05 21:42 - 2017-06-30 11:45 - 000000000 ___RD C:\Users\Fedorovi\3D Objects
2018-01-05 21:42 - 2017-06-23 18:15 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-01-05 18:15 - 2017-12-02 08:41 - 000346512 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-01-05 18:15 - 2017-07-07 17:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-01-05 18:15 - 2017-07-07 17:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\Provisioning
2018-01-05 18:13 - 2017-09-29 09:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-01-05 15:32 - 2017-07-07 17:58 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2018-01-05 15:31 - 2017-06-24 04:54 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-01-05 14:06 - 2017-09-29 14:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-01-05 14:04 - 2017-09-29 14:41 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-01-05 14:04 - 2017-09-29 14:41 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-01-05 14:04 - 2017-09-29 14:41 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-01-02 14:47 - 2017-07-07 15:17 - 000000000 ____D C:\Users\Fedorovi\AppData\Roaming\Enigma Software Group
2017-12-30 07:32 - 2017-10-14 08:19 - 000000000 ____D C:\Temp
2017-12-30 07:32 - 2017-07-04 16:37 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2017-12-30 07:32 - 2017-06-24 04:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-12-30 06:39 - 2017-06-24 04:53 - 000000000 ____D C:\ProgramData\Package Cache
2017-12-29 15:52 - 2017-06-24 05:47 - 000000000 ____D C:\ProgramData\Intel
2017-12-29 15:19 - 2017-06-24 05:44 - 000000000 ____D C:\Program Files\Intel
2017-12-25 07:28 - 2017-06-28 17:54 - 000000000 ___RD C:\Users\Fedorovi\Creative Cloud Files
2017-12-23 15:47 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-12-16 01:23 - 2017-12-01 15:15 - 004485376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-12-16 01:23 - 2017-12-01 15:15 - 003817584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-12-16 01:23 - 2017-12-01 15:15 - 001032688 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-12-16 01:23 - 2017-12-01 15:15 - 000048442 _____ C:\WINDOWS\system32\nvinfo.pb
2017-12-16 00:15 - 2017-07-04 16:37 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-12-15 23:34 - 2017-07-04 16:37 - 005964688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-12-15 23:34 - 2017-07-04 16:37 - 002589168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-12-15 23:34 - 2017-07-04 16:37 - 001767408 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-12-15 23:34 - 2017-07-04 16:37 - 000608056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-12-15 23:34 - 2017-07-04 16:37 - 000450544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-12-15 23:34 - 2017-07-04 16:37 - 000123704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-12-15 23:34 - 2017-07-04 16:37 - 000082928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-12-14 19:17 - 2017-07-04 16:37 - 007917671 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-12-14 13:02 - 2017-12-02 08:45 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Packages
2017-12-13 18:55 - 2017-12-02 08:38 - 000000000 ____D C:\Windows.old
2017-12-13 17:24 - 2017-06-24 18:20 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-12-13 17:23 - 2017-10-11 14:16 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-12-13 17:23 - 2017-06-24 18:20 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-12-12 19:55 - 2017-12-02 08:58 - 000004506 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-12-12 19:55 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-12-12 19:55 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-12-10 03:07 - 2017-12-02 08:44 - 000000000 ____D C:\Users\Fedorovi

==================== Files in the root of some directories =======

2017-09-23 06:48 - 2017-10-18 17:06 - 000001206 _____ () C:\Users\Fedorovi\AppData\Roaming\DESKTOP-ESQS67O.MTBF.txt
2017-07-07 08:44 - 2017-07-07 08:44 - 102212096 _____ () C:\Users\Fedorovi\AppData\Roaming\Launcher.dat
2017-07-07 08:44 - 2017-07-07 08:44 - 025289369 _____ () C:\Users\Fedorovi\AppData\Roaming\m.fjk
2017-07-07 08:44 - 2017-07-07 16:19 - 000000009 _____ () C:\Users\Fedorovi\AppData\Roaming\update.dat
2017-09-23 06:50 - 2017-10-14 10:01 - 000005632 _____ () C:\Users\Fedorovi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-07-09 08:07 - 2017-07-24 15:12 - 000007606 _____ () C:\Users\Fedorovi\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-01-01 09:04 - 2018-01-01 09:04 - 000882176 _____ (System Process Inc.) C:\Users\Fedorovi\AppData\Local\Temp\235023546.exe
2017-12-10 07:21 - 2017-12-05 20:36 - 000760032 _____ (NVIDIA Corporation) C:\Users\Fedorovi\AppData\Local\Temp\nvSCPAPI.dll
2017-12-10 07:21 - 2017-12-05 20:36 - 000874696 _____ (NVIDIA Corporation) C:\Users\Fedorovi\AppData\Local\Temp\nvSCPAPI64.dll
2017-12-30 07:30 - 2017-12-05 20:36 - 000371184 _____ (NVIDIA Corporation) C:\Users\Fedorovi\AppData\Local\Temp\nvStInst.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-01-02 14:09

==================== End of FRST.txt ============================

Re: Adware ve Firefoxu.

Napsal: 09 led 2018 15:58
od ppetr
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.01.2018
Ran by Fedorovi (09-01-2018 15:52:12)
Running from C:\Users\Fedorovi\Desktop
Windows 10 Home Version 1709 16299.192 (X64) (2017-12-02 07:59:40)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1786104691-2426081519-2716709316-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1786104691-2426081519-2716709316-503 - Limited - Disabled)
Fedorovi (S-1-5-21-1786104691-2426081519-2716709316-1001 - Administrator - Enabled) => C:\Users\Fedorovi
Guest (S-1-5-21-1786104691-2426081519-2716709316-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1786104691-2426081519-2716709316-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.3.0.256 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.126 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_1_1) (Version: 18.1.1 - Adobe Systems Incorporated)
Aktualizace NVIDIA 31.0.1.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.0.1.0 - NVIDIA Corporation) Hidden
ASUS GPU TweakII (HKLM-x32\...\{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.4.7.3 - ASUSTek COMPUTER INC.) Hidden
ASUS GPU TweakII (HKLM-x32\...\InstallShield_{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.4.7.3 - ASUSTek COMPUTER INC.)
ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.031 - ASUSTek Computer Inc.)
AURA(GRAPHICS CARD) (HKLM-x32\...\{3507F3C9-1898-430F-B080-C603373F42D0}) (Version: 0.0.4.1 - )
Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Canon MP210 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP210_series) (Version: - )
DiRT 4 (HKLM-x32\...\DiRT 4_is1) (Version: - )
Dragon Age: Inquisition (HKLM-x32\...\Dragon Age: Inquisition_is1) (Version: - )
F1 2017 (HKLM-x32\...\F1 2017_is1) (Version: 1.6 - THE KNIGHT)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
HWiNFO64 Version 5.54 (HKLM\...\HWiNFO64_is1) (Version: 5.54 - Martin Malík - REALiX)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1028 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.7.1.1015 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{e81fcd9c-17cd-4fff-b3ac-e3b258dd998c}) (Version: 10.1.1.32 - Intel(R) Corporation) Hidden
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Malwarebytes verze 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
Microsoft Games for Windows - LIVE (HKLM-x32\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}) (Version: 3.1.99.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mortal Kombat XL (HKLM-x32\...\Mortal Kombat XL_is1) (Version: - )
Mozilla Firefox 57.0.4 (x64 cs) (HKLM\...\Mozilla Firefox 57.0.4 (x64 cs)) (Version: 57.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 54.0.1 - Mozilla)
NVIDIA GeForce Experience 3.11.0.73 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.11.0.73 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 388.71 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 388.71 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.35.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.35.1 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 388.71 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 388.71 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenOffice 4.1.3 (HKLM-x32\...\{7308600A-5231-459C-A3E2-A637F842CACA}) (Version: 4.13.9783 - Apache Software Foundation)
Ovládací panel NVIDIA 388.71 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 388.71 - NVIDIA Corporation) Hidden
Pinnacle Studio 20 (HKLM\...\{4D548AFA-B83A-4C39-A474-AAE833B320AD}) (Version: 20.5.0.295 - Corel Corporation)
Pomocník při upgradu na Windows 10 (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22175 - Microsoft Corporation)
Rapture3D 2.4.4 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8158 - Realtek Semiconductor Corp.)
Resident Evil 0 HD Remaster (HKLM-x32\...\Resident Evil 0 HD Remaster_is1) (Version: - )
Resident Evil 7 Biohazard (HKLM-x32\...\{1ECBF8F3-7079-44CA-AD32-B2AECBCF636F}_is1) (Version: - Capcom)
Resident Evil HD Remaster (HKLM-x32\...\Resident Evil HD Remaster_is1) (Version: - )
Seznam Software (HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\SeznamInstall) (Version: 2.1.29 - Seznam.cz)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
XSplit Gamecaster (HKLM-x32\...\{86D10763-A1F2-45A4-814C-3BDE40458C7E}) (Version: 3.0.1705.3128 - SplitmediaLabs)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-B85706A67B3C}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ShellIconOverlayIdentifiers: [.QMDeskTopGCIcon] -> {B7667919-3765-4815-A66D-98A09BE662D6} => C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QMGCShellExt64.dll -> No File
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ContextMenuHandlers1: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => A:\Programs\Winrar\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => A:\Programs\Winrar\rarext32.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers2: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => A:\Programs\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers4: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-12-15] (NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => A:\Programs\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => A:\Programs\Winrar\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => A:\Programs\Winrar\rarext32.dll [2016-08-14] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {061FEF69-9F62-4CCD-ACC1-29551357F7C8} - System32\Tasks\Stenougrade Monitor Free => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Stenougrade Monitor Free\Stenougrade Monitor Free.dll",dlWLLLaTbRy <==== ATTENTION
Task: {0DEFF955-D8A5-411C-8323-7F12885A7C5A} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-ESQS67O-Fedorovi => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {1A9031FA-0C46-4D6B-AA6D-EFF095CA8D13} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-08] (Microsoft Corporation)
Task: {2B7E9968-E071-4874-A653-FFC0A2018119} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-11-16] (NVIDIA Corporation)
Task: {3DA4B8D1-55BB-41B3-954C-E8FC1E24E81C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-11-16] (NVIDIA Corporation)
Task: {4B7D4DB5-B534-4A50-AAB4-62EFA3EA8821} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-08] (Microsoft Corporation)
Task: {4BCECE29-6189-417C-B395-5E357F9C1205} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {4C6FA581-E44D-42DD-9A2D-3F0C4B7F2AA2} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-11-16] (NVIDIA Corporation)
Task: {50206439-10D1-478C-A8AD-CD6B7C4731F5} - System32\Tasks\GPU Tweak II => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [2017-06-20] (TODO: <Company name>)
Task: {628926C7-536F-4144-9297-BB1855604AF2} - System32\Tasks\ASUS Live Update Task Schedule => C:\Program Files (x86)\ASUS\GPU Tweak\ASUSLiveUpdate.exe
Task: {66024546-C97F-4170-8481-F598061AADBF} - System32\Tasks\AURA => C:\Program Files (x86)\ASUS\AURA(GRAPHICS CARD)\ledcontrolservice.exe
Task: {7C58F03F-2625-4CC6-919F-6E6404A6F174} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-11-16] (NVIDIA Corporation)
Task: {99900023-089D-4C75-A5D9-6EBDB48E7B2D} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-11-16] (NVIDIA Corporation)
Task: {A8A21DE2-893F-4ED6-B194-54B02546CB8F} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-11-16] (NVIDIA Corporation)
Task: {B9707671-BE8C-4CEE-8906-BB34C856DDA7} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-05-18] ()
Task: {B9DF67A3-16FA-4DFC-ACBB-CA0766523EF7} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-11-16] (NVIDIA Corporation)
Task: {BCDF386E-7348-4294-8F75-2E67840741C0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-08] (Microsoft Corporation)
Task: {C9D1E640-6852-4E86-AE13-D7398E4F13F0} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {DC5D8F35-8B3E-45AF-8B21-063CC47A2F29} - System32\Tasks\Microsoft\Windows\Multimedia\Driver => C:\WINDOWS\SysWOW64\Easeware.Driver.exe
Task: {E682C18B-1AB5-401A-B8CA-F27403224216} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2017-02-24] (Intel(R) Corporation)
Task: {F25EDFA2-30AD-413E-9BAA-F4B022334676} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-08] (Microsoft Corporation)
Task: {FD09BCE5-82AF-4DD0-B022-DB7DE36B9BA9} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-12-12] (Adobe Systems Incorporated)
Task: {FE4EE9CD-A0BA-4075-8568-EFCBAAA1CDF8} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-11-16] (NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-09-17 13:39 - 2014-04-24 07:29 - 001360016 _____ () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
2017-09-17 13:39 - 2015-05-08 07:26 - 000936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2013-10-17 14:27 - 2013-10-17 14:27 - 000166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2017-06-25 06:06 - 2017-11-16 02:41 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-07-04 16:37 - 2017-12-15 23:34 - 000133704 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2017-09-26 01:52 - 2017-09-26 01:52 - 000491600 _____ () C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
2017-12-02 08:07 - 2017-12-02 08:07 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-12-02 08:07 - 2017-12-02 08:07 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-01-03 13:57 - 2018-01-03 14:00 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-01-03 13:57 - 2018-01-03 14:00 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-01-03 13:57 - 2018-01-03 14:00 - 024670720 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-01-03 13:57 - 2018-01-03 14:00 - 002550272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\skypert.dll
2017-09-26 01:52 - 2017-09-26 01:52 - 034879568 _____ () C:\Program Files (x86)\Adobe\Adobe Sync\Coresync\Coresync.exe
2017-03-23 15:51 - 2017-03-23 15:51 - 001727488 _____ () C:\Program Files (x86)\ASUS\GPU TweakII\ASUSGPUFanServiceEx.exe
2018-01-09 12:24 - 2018-01-09 12:24 - 004698840 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.11.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-01-03 13:57 - 2018-01-03 14:01 - 026507776 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17112.13411.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-01-03 13:57 - 2018-01-03 14:01 - 008370176 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17112.13411.0_x64__8wekyb3d8bbwe\EntCommon.dll
2017-09-26 12:55 - 2017-09-26 12:55 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17112.13411.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-01-03 13:57 - 2018-01-03 14:01 - 010137600 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17112.13411.0_x64__8wekyb3d8bbwe\EntPlat.dll
2017-12-21 04:35 - 2017-12-21 04:35 - 002350056 _____ () A:\Hry\Blizzard App\Battle.net.9679\Battle.net Helper.exe
2017-09-17 13:39 - 2018-01-07 09:52 - 000035624 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2017-09-17 13:39 - 2015-05-08 07:26 - 000104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2017-06-05 23:23 - 2017-06-05 23:23 - 001244304 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2017-06-25 06:06 - 2017-11-16 02:41 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-02-09 09:39 - 2017-02-09 09:39 - 000065536 _____ () C:\Program Files (x86)\ASUS\GPU TweakII\Exeio.dll
2017-06-02 13:11 - 2017-06-02 13:11 - 001753600 _____ () C:\Program Files (x86)\ASUS\GPU TweakII\Vender.dll
2017-12-03 07:00 - 2017-12-03 07:00 - 000102088 _____ () C:\Users\Fedorovi\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\UpdateRingSettings.dll
2017-09-20 01:42 - 2017-09-20 01:42 - 067115616 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
2017-09-06 17:11 - 2017-09-06 17:11 - 000118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node
2017-09-06 17:11 - 2017-09-06 17:11 - 000214528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2017-09-06 17:11 - 2017-09-06 17:11 - 000117248 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node
2017-09-06 17:11 - 2017-09-06 17:11 - 000125952 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node
2017-09-20 02:04 - 2017-09-20 02:04 - 000099424 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin.dll
2017-09-06 17:11 - 2017-09-06 17:11 - 000086528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node
2017-06-25 06:07 - 2017-11-16 02:40 - 066906560 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2017-06-20 14:32 - 2017-06-20 14:32 - 000940032 _____ () C:\Program Files (x86)\ASUS\GPU TweakII\glkIo.dll
2017-12-21 04:37 - 2017-12-21 04:37 - 055782888 _____ () A:\Hry\Blizzard App\Battle.net.9679\libcef.dll
2017-12-21 04:37 - 2017-12-21 04:37 - 000540336 _____ () A:\Hry\Blizzard App\Battle.net.9679\ortp.dll
2017-12-21 04:37 - 2017-12-21 04:37 - 000133632 _____ () A:\Hry\Blizzard App\Battle.net.9679\libEGL.dll
2017-12-21 04:37 - 2017-12-21 04:37 - 003384832 _____ () A:\Hry\Blizzard App\Battle.net.9679\libGLESv2.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 12:47 - 2017-07-07 11:06 - 000000865 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 plugpackdownload.net
127.0.0.1 dscdn.pw

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\Control Panel\Desktop\\Wallpaper -> A:\Kleirou\Fotky\Plumlov 15.10.2016\IMG_0147.JPG
DNS Servers: 178.22.112.22 - 178.22.118.10
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run32: => "iSkysoft Helper Compact.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D727F91A-929C-4C7F-A4D3-F4E49ED95292}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [UDP Query User{E69A0A24-2F03-451E-B534-38F2D4DFE4EB}C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [TCP Query User{A916C501-A99A-4035-92B9-25CC1034AB0B}C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [UDP Query User{725FE6E9-E2EE-4624-A6C2-D56DB12B55F8}A:\hry\divinity - original sin 2\bin\eocapp.exe] => (Block) A:\hry\divinity - original sin 2\bin\eocapp.exe
FirewallRules: [TCP Query User{41F3604A-4B35-4DFD-8F11-2FEF90AC6A86}A:\hry\divinity - original sin 2\bin\eocapp.exe] => (Block) A:\hry\divinity - original sin 2\bin\eocapp.exe
FirewallRules: [{BAB48C81-22EF-41C3-8BEA-5463B9B73A2E}] => (Allow) A:\Programs\Pinneacle studio 20\programs\UMI.exe
FirewallRules: [{80484E34-6C1F-4F74-AEBD-FDEFB66E50C5}] => (Allow) A:\Programs\Pinneacle studio 20\programs\UMI.exe
FirewallRules: [{1FE30C2E-5EFA-411D-9CB3-89FB2A16B086}] => (Allow) A:\Programs\Pinneacle studio 20\programs\NGStudio.exe
FirewallRules: [{3D97AF65-849C-4828-BA48-E8AF021F4647}] => (Allow) A:\Programs\Pinneacle studio 20\programs\NGStudio.exe
FirewallRules: [{D3A3C064-E0FF-4BC2-A841-21BDF46C4F6D}] => (Allow) A:\Programs\Pinneacle studio 20\programs\RM.exe
FirewallRules: [{869FE1B3-44D3-4A28-8CEC-B518E67E161D}] => (Allow) A:\Programs\Pinneacle studio 20\programs\RM.exe
FirewallRules: [{2C6D1F8C-2DB9-4059-A5B6-20F255F7D53F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{8F5902F3-BCD2-4A27-B011-BE4089EC5D65}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F315BA4D-4662-4833-81D1-29FE97878C64}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{B9FDAA28-0DCE-45CD-B013-8D01D9AD9034}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [UDP Query User{C69B3D91-CAA0-4C4F-A323-E26CEA759F67}C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe
FirewallRules: [TCP Query User{21290B18-F0E9-4BB5-A07D-6312817D0F37}C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe
FirewallRules: [UDP Query User{4CADEBE2-58AE-47CD-98EA-21A823A88444}A:\programs\droidjoy server\droidjoyserver.exe] => (Allow) A:\programs\droidjoy server\droidjoyserver.exe
FirewallRules: [TCP Query User{6E2DC936-E6CB-4C66-A0C1-D02279128C6E}A:\programs\droidjoy server\droidjoyserver.exe] => (Allow) A:\programs\droidjoy server\droidjoyserver.exe
FirewallRules: [UDP Query User{32AFA2AD-A844-4B2D-907C-A1F3D07EF23A}A:\games\mortal kombat xl\binaries\retail\mk10.exe] => (Allow) A:\games\mortal kombat xl\binaries\retail\mk10.exe
FirewallRules: [TCP Query User{BA026EC8-AE45-418C-A24E-75365D52A471}A:\games\mortal kombat xl\binaries\retail\mk10.exe] => (Allow) A:\games\mortal kombat xl\binaries\retail\mk10.exe
FirewallRules: [{933CF0A4-1D1F-4CE4-9A4C-E15ABC36047E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2CD46A88-B38C-46F6-9318-23EACB70327A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{56438277-D167-43AA-A48A-241BB8D93AEA}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{AAEB3D8B-7A98-417C-B0FD-5EE3D232B159}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{5C0E87EE-53C5-4B9D-90B5-52089C99A0A5}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\bugreport_xf.exe
FirewallRules: [{9B390FD1-BAF9-4963-ACBC-36B29AA183D9}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
FirewallRules: [{83B6A8D1-BE22-4646-9D6D-F0427A8D2C66}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QMAdBlock.exe
FirewallRules: [{9777DA9A-B08A-4003-A514-29697BBC455D}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QMAccountProtection.exe
FirewallRules: [{A4CF2E6A-75A0-4A2A-A354-34220264D31D}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\TpkUpdate.exe
FirewallRules: [{ED0C24C1-4327-4CF5-95E8-CDB2A080788D}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCPatch.exe
FirewallRules: [{94016C73-DA2B-48CB-970E-ABB59E1047AF}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\Uninst.exe
FirewallRules: [{DB5EEB1E-9176-455F-BFC9-9DC66EA87CBA}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQRepair.exe
FirewallRules: [{8D756FBD-8BAE-461D-83C8-BCF7C4B033DE}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCUpdateAVLib.exe
FirewallRules: [{13B1B7F5-54DB-4CA0-8EDF-3AB603910922}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCSysOptimize.exe
FirewallRules: [{7DA56DC8-29B4-4EDE-AE6D-B564996FE17F}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCSoftGame.exe
FirewallRules: [{EAA0092F-74EA-4287-AA43-C66D2EB9B49F}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QMUpdate\QQPCMgrUpdate.exe
FirewallRules: [{FC748FC4-7A9A-4391-90B3-8859836DC6E6}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCLaunch.exe
FirewallRules: [{6BF3E994-EB1D-4431-BC05-F2C1AEE9DB85}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCClinic.exe
FirewallRules: [{4786B649-668B-4B19-8E84-289436191713}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCBTU.exe
FirewallRules: [{C12B6110-B131-4FE6-8177-34DD219C907F}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\plugins\QMNetMon\QQPCNetFlow.exe
FirewallRules: [{89F8A521-DBC8-4BFC-8851-01D7F5BC1609}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCSoftMgr.exe
FirewallRules: [{68606678-60CE-4C45-9DE1-CCF9F3F975EC}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPConfig.exe
FirewallRules: [{6128D6A3-509E-48B2-BA89-4BE8598513B1}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCLeakScan.exe
FirewallRules: [{91AD0488-7FC8-4F9F-891F-1F2ABE7A34EA}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCFileOpen.exe
FirewallRules: [{55D82CF9-3EEE-4BA9-ACF8-E7D1437F447F}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\bugreport.exe
FirewallRules: [{DAABD41F-CFA0-45A7-9995-8ABF611791F6}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QMDL.exe
FirewallRules: [{591E3EEA-ECBC-435B-9022-E5D9E25F3DB0}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCRTP.exe
FirewallRules: [{182F03AC-AD10-44DC-98A8-20ABB57425B8}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCMgr.exe
FirewallRules: [{5552DEA6-9A94-42CC-B5CF-64B4AD51735A}] => (Allow) C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCTray.exe
FirewallRules: [{046E8FF4-7B2E-4BE0-A075-5E0C3450B261}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [UDP Query User{BD27B043-F03E-40BA-B877-0348933962AF}A:\programs\java\launch4j-tmp\frd.exe] => (Allow) A:\programs\java\launch4j-tmp\frd.exe
FirewallRules: [TCP Query User{FBC32753-05FB-4218-854E-AE88DCF8B291}A:\programs\java\launch4j-tmp\frd.exe] => (Allow) A:\programs\java\launch4j-tmp\frd.exe
FirewallRules: [{5C397735-D8FA-4923-AC4A-5216EFF5018A}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Gamecaster\XSplit.Gamecaster.exe
FirewallRules: [{C6DF10F1-3939-4539-BE0B-B4E636CF6335}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Gamecaster\XSplit.Gamecaster.exe
FirewallRules: [{D2AC4A8D-8ECC-43F3-906A-AB6C58C45A54}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Gamecaster\XSplit.cam.exe
FirewallRules: [{146CCDFB-5663-4890-B6F7-C372951D25A3}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Gamecaster\XSplit.cam.exe
FirewallRules: [{9BEAFB41-3AAF-4EC2-818B-96A7B7DB74BD}] => (Allow) A:\Programy\Steam.exe
FirewallRules: [{BC89C12A-DCA6-411F-94BC-B389D2B4B275}] => (Allow) A:\Programy\Steam.exe
FirewallRules: [{84249E77-AEA6-4B36-A0BD-F721151C2549}] => (Allow) A:\Programy\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F39374ED-F30F-4989-8A0C-CD5BBA65747E}] => (Allow) A:\Programy\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{A2373B1E-4DFB-4BEA-9327-04DEBB4B8E15}] => (Allow) A:\Programy\steamapps\common\Dawn of War III\RelicDoW3.exe
FirewallRules: [{0EC7343F-EF35-424A-8E9E-8A1CB29859D2}] => (Allow) A:\Programy\steamapps\common\Dawn of War III\RelicDoW3.exe
FirewallRules: [{AB099027-B4A2-45E1-BFCD-652A96A8661A}] => (Allow) A:\Programs\Steam\Steam.exe
FirewallRules: [{CE36CD76-CDED-4160-A2FA-A8351B166FE4}] => (Allow) A:\Programs\Steam\Steam.exe
FirewallRules: [{D722AA30-581B-4AC9-9739-2B94CABD0852}] => (Allow) A:\Programs\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{5C165691-47F4-4706-B19D-068967A49FB3}] => (Allow) A:\Programs\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{5349D10F-AADE-4736-94A3-1638B6F0E984}A:\programs\steam\steamapps\common\dawn of war iii\relicdow3.exe] => (Allow) A:\programs\steam\steamapps\common\dawn of war iii\relicdow3.exe
FirewallRules: [UDP Query User{3F959601-8272-46B8-93F7-3990CCC5A925}A:\programs\steam\steamapps\common\dawn of war iii\relicdow3.exe] => (Allow) A:\programs\steam\steamapps\common\dawn of war iii\relicdow3.exe
FirewallRules: [{8A2B3974-6850-4FF1-974C-196DA78FDF08}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{6B3E1C05-D906-4133-9091-965ACE27CAA8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{1752FD2E-6327-401D-9624-7D3FC3A84490}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{28416376-EBDF-4944-8D50-FF41170781AD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{863F55BF-51E5-4F8C-995C-F6DEB809EC71}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{3B0EED9F-9324-488E-8293-12A531B9D0CB}A:\hry\hearthstone\hearthstone.exe] => (Allow) A:\hry\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{75D03BED-70BA-4DEF-8FF1-859C25B333D7}A:\hry\hearthstone\hearthstone.exe] => (Allow) A:\hry\hearthstone\hearthstone.exe
FirewallRules: [{25549846-0A96-4AC7-96D6-58085FC9A0CD}] => (Allow) A:\Hry\NFS HP\Launcher.exe
FirewallRules: [{5042168E-C96D-48FD-B140-A743C6C55E9A}] => (Allow) A:\Hry\NFS HP\Launcher.exe
FirewallRules: [{5079C31D-1147-4992-870D-EF1F2B5AFA67}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{5096EA30-FE70-4415-8CDE-71D91985C3D1}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{B1AFDF11-3004-4BE1-A883-E6850C8AA9EF}] => (Allow) C:\Users\Fedorovi\AppData\Roaming\SystemProcess\SystemProcess.exe
FirewallRules: [{CAF43793-29E8-4C9B-A6DF-F9E2B70578AF}] => (Allow) C:\Users\Fedorovi\AppData\Roaming\SystemProcess\SystemProcess.exe
FirewallRules: [TCP Query User{61A0DAC0-31DC-4216-A35B-BC9338824379}A:\hry\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe] => (Block) A:\hry\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe
FirewallRules: [UDP Query User{8D14146E-A8E3-4905-8524-862D37921D2B}A:\hry\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe] => (Block) A:\hry\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/07/2018 08:29:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: GPUTweakII.exe, verze: 1.4.7.3, časové razítko: 0x5948d4d8
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000
ID chybujícího procesu: 0x17e4
Čas spuštění chybující aplikace: 0x01d387890e7663f4
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
Cesta k chybujícímu modulu: unknown
ID zprávy: 978c9396-109b-46a2-bfa1-6f31bb9c3b73
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (01/04/2018 01:54:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_InstallService, verze: 10.0.16299.15, časové razítko: 0x9c786b9a
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.16299.125, časové razítko: 0x70f70cc4
Kód výjimky: 0xc0000409
Posun chyby: 0x000000000006b70e
ID chybujícího procesu: 0x2394
Čas spuštění chybující aplikace: 0x01d3850d8e78d087
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID zprávy: c06276c2-6aa4-4a42-857d-a29b19ff881b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (01/03/2018 02:00:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_InstallService, verze: 10.0.16299.15, časové razítko: 0x9c786b9a
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.16299.125, časové razítko: 0x70f70cc4
Kód výjimky: 0xc0000409
Posun chyby: 0x000000000006b70e
ID chybujícího procesu: 0x1b08
Čas spuštění chybující aplikace: 0x01d384444772d93f
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID zprávy: c3b19a7a-743e-45cf-8586-245d08e6541d
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (01/02/2018 02:43:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Hearthstone.exe verze 10.0.0.22611 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 2128

Čas spuštění: 01d383cf5ae04a47

Čas ukončení: 9

Cesta k aplikaci: A:\Hry\Hearthstone\Hearthstone.exe

ID hlášení: 31fdf79c-c167-41a7-9ba2-64faec58f026

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (12/31/2017 02:08:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Settlers7R.exe, verze: 1.12.1396.0, časové razítko: 0x4d8744d4
Název chybujícího modulu: ntdll.dll, verze: 10.0.16299.64, časové razítko: 0xac8afc81
Kód výjimky: 0xc0000409
Posun chyby: 0x00041af0
ID chybujícího procesu: 0x73c
Čas spuštění chybující aplikace: 0x01d38235c5c846e2
Cesta k chybující aplikaci: A:\Hry\Settlers 7\Data\Base\_Dbg\Bin\Release\Settlers7R.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: d622973e-a7c5-4b90-a96f-b505a195b161
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (12/30/2017 07:35:28 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program NVStWiz.exe verze 7.17.13.8871 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 83c

Čas spuštění: 01d38138120821de

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NVStWiz.exe

ID hlášení: ff7409e6-0aa8-43e5-9fe3-60f4a96d9c60

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (12/29/2017 03:19:27 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Procedura Open pro službu BITS v knihovně DLL C:\Windows\System32\bitsperf.dll se nezdařila. Výkonnostní data pro tuto službu nebudou k dispozici. Vrácený kód stavu představují první čtyři bajty (DWORD) datové části.

Error: (12/25/2017 07:29:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: GPUTweakII.exe, verze: 1.4.7.3, časové razítko: 0x5948d4d8
Název chybujícího modulu: GPUTweakII.exe, verze: 1.4.7.3, časové razítko: 0x5948d4d8
Kód výjimky: 0xc0000005
Posun chyby: 0x000b633a
ID chybujícího procesu: 0x52a0
Čas spuštění chybující aplikace: 0x01d37d4973718130
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
ID zprávy: 1169b032-7142-4ec1-8d6b-17307d73c99a
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (12/23/2017 05:26:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: setup.tmp, verze: 51.1052.0.0, časové razítko: 0x506a75b5
Název chybujícího modulu: botva2.dll_unloaded, verze: 0.9.7.151, časové razítko: 0x2a425e19
Kód výjimky: 0xc000041d
Posun chyby: 0x00005514
ID chybujícího procesu: 0x4fe8
Čas spuštění chybující aplikace: 0x01d37c03d5e619c7
Cesta k chybující aplikaci: C:\Users\Fedorovi\AppData\Local\Temp\is-AG4S2.tmp\setup.tmp
Cesta k chybujícímu modulu: botva2.dll
ID zprávy: fad667c0-7434-4ee6-b8f1-1fa3ff551ff3
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (12/23/2017 05:26:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: setup.tmp, verze: 51.1052.0.0, časové razítko: 0x506a75b5
Název chybujícího modulu: botva2.dll_unloaded, verze: 0.9.7.151, časové razítko: 0x2a425e19
Kód výjimky: 0xc0000005
Posun chyby: 0x00005514
ID chybujícího procesu: 0x4fe8
Čas spuštění chybující aplikace: 0x01d37c03d5e619c7
Cesta k chybující aplikaci: C:\Users\Fedorovi\AppData\Local\Temp\is-AG4S2.tmp\setup.tmp
Cesta k chybujícímu modulu: botva2.dll
ID zprávy: 12ce59c3-07e8-4b44-9d74-5676ef0ae6da
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (01/07/2018 09:51:31 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ESQS67O)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/07/2018 08:23:12 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ESQS67O)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/07/2018 07:56:43 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: Předchozí vypnutí systému (19:55:28, ‎06.‎01.‎2018) bylo neočekávané.

Error: (01/07/2018 07:56:19 AM) (Source: Microsoft-Windows-Kernel-Boot) (EventID: 29) (User: NT AUTHORITY)
Description: 3221225684Při zpracování obnovovacích dat došlo k závažné chybě.

Error: (01/05/2018 09:48:25 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ESQS67O)
Description: Server Microsoft.Windows.Cortana_1.9.6.16299_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppX6jbm6fjqte5wzzrf5807m7eq0z44q5gf.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/05/2018 06:13:21 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba Update Orchestrator Service byla ukončena s následující chybou:
Daná operace se vrátila, protože vypršel časový limit.

Error: (01/05/2018 06:13:02 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ESQS67O)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/04/2018 06:45:40 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ESQS67O)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/04/2018 01:54:09 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Služba instalace Windows Store byla neočekávaně ukončena. Tento stav nastal již 2krát.

Error: (01/04/2018 04:39:51 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ESQS67O)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-6700 CPU @ 3.40GHz
Percentage of memory in use: 22%
Total physical RAM: 16329.32 MB
Available physical RAM: 12642.63 MB
Total Virtual: 18761.32 MB
Available Virtual: 14710.38 MB

==================== Drives ================================

Drive a: (Místní disk) (Fixed) (Total:833.86 GB) (Free:572.71 GB) NTFS
Drive c: () (Fixed) (Total:97.1 GB) (Free:50.12 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ===============

Re: Adware ve Firefoxu.

Napsal: 09 led 2018 17:51
od Rudy
Teď spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: Adware ve Firefoxu.

Napsal: 10 led 2018 12:35
od ppetr
# AdwCleaner 7.0.6.0 - Logfile created on Wed Jan 10 11:33:14 2018
# Updated on 2017/21/12 by Malwarebytes
# Database: 01-08-2018.1
# Running on Windows 10 Home (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

PUP.Optional.SpyHunter, SpyHunter 4 Service


***** [ Folders ] *****

PUP.Optional.Legacy, C:\ProgramData\Tencent
PUP.Optional.Legacy, C:\ProgramData\Application Data\Tencent
PUP.Optional.Legacy, C:\Users\All Users\Tencent
PUP.Optional.Legacy, C:\Users\Fedorovi\AppData\Roaming\Tencent
PUP.Optional.SpyHunter, C:\Program Files\Enigma Software Group
PUP.Optional.SpyHunter, C:\Users\Fedorovi\AppData\Roaming\Enigma Software Group
PUP.Optional.WindowsErrorReporting, C:\ProgramData\WindowsErrorReporting
PUP.Optional.WindowsErrorReporting, C:\ProgramData\WindowsErrorReporting
PUP.Optional.WindowsErrorReporting, C:\Users\All Users\WindowsErrorReporting


***** [ Files ] *****

PUP.Optional.SpyHunter, C:\Windows\SysNative\drivers\EsgScanner.sys
PUP.Optional.SpyHunter, C:\Windows\SysNative\drivers\EsgScanner.sys
PUP.Optional.Tencent, C:\Windows\SysNative\drivers\TFsFltX64_ev.sys


***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

PUP.Optional.BitCoinMiner, Microsoft\Windows\Multimedia\Driver


***** [ Registry ] *****

PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {5C0E87EE-53C5-4B9D-90B5-52089C99A0A5}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {83B6A8D1-BE22-4646-9D6D-F0427A8D2C66}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {9777DA9A-B08A-4003-A514-29697BBC455D}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {A4CF2E6A-75A0-4A2A-A354-34220264D31D}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {ED0C24C1-4327-4CF5-95E8-CDB2A080788D}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {94016C73-DA2B-48CB-970E-ABB59E1047AF}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {DB5EEB1E-9176-455F-BFC9-9DC66EA87CBA}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {8D756FBD-8BAE-461D-83C8-BCF7C4B033DE}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {13B1B7F5-54DB-4CA0-8EDF-3AB603910922}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {7DA56DC8-29B4-4EDE-AE6D-B564996FE17F}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {EAA0092F-74EA-4287-AA43-C66D2EB9B49F}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {FC748FC4-7A9A-4391-90B3-8859836DC6E6}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {6BF3E994-EB1D-4431-BC05-F2C1AEE9DB85}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {4786B649-668B-4B19-8E84-289436191713}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {C12B6110-B131-4FE6-8177-34DD219C907F}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {89F8A521-DBC8-4BFC-8851-01D7F5BC1609}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {68606678-60CE-4C45-9DE1-CCF9F3F975EC}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {6128D6A3-509E-48B2-BA89-4BE8598513B1}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {91AD0488-7FC8-4F9F-891F-1F2ABE7A34EA}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {55D82CF9-3EEE-4BA9-ACF8-E7D1437F447F}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {DAABD41F-CFA0-45A7-9995-8ABF611791F6}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {591E3EEA-ECBC-435B-9022-E5D9E25F3DB0}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {182F03AC-AD10-44DC-98A8-20ABB57425B8}
PUP.Optional.Legacy, [Value] - HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {5552DEA6-9A94-42CC-B5CF-64B4AD51735A}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{E7270EC6-0113-4A78-B610-E501D0A9E48E}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{7C260B4B-F7A0-40B5-B403-BEFCDC6A4C3B}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{B7667919-3765-4815-A66D-98A09BE662D6}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{CBDECEF7-7A29-4CBF-A009-2673D82C7BF9}
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved | {CBDECEF7-7A29-4CBF-A009-2673D82C7BF9}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{63332668-8CE1-445D-A5EE-25929176714E}
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved | {63332668-8CE1-445D-A5EE-25929176714E}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{D4801E96-E7A1-45F6-B124-7A36DFB40B81}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{D4801E96-E7A1-45F6-B124-7A36DFB40B81}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{16EE6530-8649-4F42-A9E4-F6A3295AF975}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\.QMDeskTopGCIcon
PUP.Optional.SpyHunter, [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup
PUP.Optional.SpyHunter, [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup
Adware.HPDefender, [Key] - HKLM\SOFTWARE\HPZebra
Adware.HPDefender, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 | ZebraStarter
PUP.Optional.WeatherAlerts, [Key] - HKLM\SOFTWARE\Microsoft\{cc6eb6d8-85b7-435p-8b86-51e4d16ea76d}
PUP.Optional.PowerHandler, [Key] - HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\Software\Microsoft\Etsy
PUP.Optional.PowerHandler, [Key] - HKCU\Software\Microsoft\Etsy


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************



########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########

Re: Adware ve Firefoxu.

Napsal: 10 led 2018 13:37
od Rudy
V ADW ještě klikněte na mazání, restartujte a pak dejte nový log FRST.

Re: Adware ve Firefoxu.

Napsal: 10 led 2018 14:01
od ppetr
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.01.2018
Ran by Fedorovi (administrator) on DESKTOP-ESQS67O (10-01-2018 13:58:26)
Running from A:\Download
Loaded Profiles: Fedorovi (Available Profiles: Fedorovi)
Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
() C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
() C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.12.17007.17123-0\NisSrv.exe
(TODO: <Company name>) C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
() C:\Program Files (x86)\ASUS\APRP\aprp.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AdobeGCClient.exe
() C:\Users\Fedorovi\AppData\Roaming\Seznam.cz\szninstall.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
() C:\Program Files (x86)\Adobe\Adobe Sync\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(TODO: <Company name>) C:\Program Files (x86)\ASUS\GPU TweakII\Monitor.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9229280 2017-05-18] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [321096 2017-06-20] (Intel Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2407008 2017-09-20] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [seznam-listicka-distribuce] => C:\Program Files (x86)\Seznam.cz\distribution\szninstall.exe [1062472 2013-05-16] ()
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\Run: [cz.seznam.software.autoupdate] => C:\Users\Fedorovi\AppData\Roaming\Seznam.cz\szninstall.exe [1062472 2013-05-16] ()
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\MountPoints2: {5977a24a-b02b-11e7-858e-2c4d54569ba0} - "I:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [36864 2017-09-29] (Microsoft Corporation)
GroupPolicy: Restriction - Windows Defender <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 178.22.112.22 178.22.118.10
Tcpip\..\Interfaces\{0d14d7ee-3e6b-4a83-a717-ef29c4020330}: [DhcpNameServer] 178.22.112.22 178.22.118.10

Internet Explorer:
==================
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617912&ResetID=131443429128854827&GUID=3FF9C467-5646-46F5-9EF4-C4C1B728B609
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> DefaultScope {5CE25775-92B7-477d-9603-852F0B34D8B0} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... &pc=MSERT1
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> {5CE25775-92B7-477d-9603-852F0B34D8B0} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... &pc=MSERT1
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> {8ACD20D1-E475-4D00-A706-CBDA4685C337} URL =
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-19] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-19] (Oracle Corporation)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> hxxp://www.seznam.cz/

FireFox:
========
FF DefaultProfile: y3gmqbck.default
FF ProfilePath: C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default [2018-01-10]
FF user.js: detected! => C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\user.js [2017-06-29]
FF Homepage: Mozilla\Firefox\Profiles\y3gmqbck.default -> hxxps://www.seznam.cz/
FF NewTabOverride: Mozilla\Firefox\Profiles\y3gmqbck.default -> Enabled: "id":"{ea614400-e918-4741-9a97-7a972ff7c30b
FF Extension: (Seznam pro Firefox - Esko) - C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\Extensions\sko-extension@firma.seznam.cz.xpi [2017-11-28]
FF Extension: (Seznam pro Firefox - Email) - C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b} [2017-10-31]
FF Extension: (Seznam pro Firefox - Email) - C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\Extensions\{ea614400-e918-4741-9a97-7a972ff7c30b}.xpi [2017-10-25]
FF Extension: (Disable JavaScript Shared Memory) - C:\Users\Fedorovi\AppData\Roaming\Mozilla\Firefox\Profiles\y3gmqbck.default\features\{8dc32061-7e54-47dd-86fe-4a783d6003e0}\disable-js-shared-memory@mozilla.org.xpi [2018-01-05] [Legacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-10] ()
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-09-20] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-10] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-19] (Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-01-04] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-01-04] (NVIDIA Corporation)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-09-20] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1786104691-2426081519-2716709316-1001: ubisoft.com/uplaypc -> A:\Hry\Settlers 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [No File]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [817760 2017-09-20] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2257016 2017-08-23] (Adobe Systems, Incorporated)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2015-05-08] ()
R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe [1360016 2014-04-24] () [File not signed]
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2017-06-20] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [732448 2017-02-24] (Intel(R) Corporation)
S2 Intel(R) TPM Provisioning Service; C:\Program Files\Intel\iCLS Client\TPMProvisioningService.exe [548648 2017-02-24] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [197264 2017-06-05] (Intel Corporation)
S3 MBAMService; A:\Programs\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-11-16] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [519104 2017-11-16] (NVIDIA Corporation)
R2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\NisSrv.exe [356176 2017-12-08] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MsMpEng.exe [105792 2017-12-08] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S1 aefxtnite.sys; C:\WINDOWS\system32\drivers\aefxtnite.sys [15424 2017-07-25] () [File not signed]
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2014-09-09] ()
S1 bemszcafb.sys; C:\WINDOWS\system32\drivers\bemszcafb.sys [7712 2017-11-27] () [File not signed]
S1 bogqlyryb.sys; C:\WINDOWS\system32\drivers\bogqlyryb.sys [7712 2017-11-24] () [File not signed]
S1 cqctmvzng.sys; C:\WINDOWS\system32\drivers\cqctmvzng.sys [7712 2017-11-18] () [File not signed]
S1 ctoofsmoa.sys; C:\WINDOWS\system32\drivers\ctoofsmoa.sys [7712 2017-11-17] () [File not signed]
S1 cuuzkpsfk.sys; C:\WINDOWS\system32\drivers\cuuzkpsfk.sys [7712 2017-11-25] () [File not signed]
S1 dbprghlhs.sys; C:\WINDOWS\system32\drivers\dbprghlhs.sys [7712 2017-11-26] () [File not signed]
S1 dekyvudve.sys; C:\WINDOWS\system32\drivers\dekyvudve.sys [142760 2017-11-15] () [File not signed]
S1 devxiwfkv.sys; C:\WINDOWS\system32\drivers\devxiwfkv.sys [7712 2017-12-02] () [File not signed]
S0 dgsjfiqr.sys; C:\WINDOWS\System32\drivers\dgsjfiqr.sys [904104 2018-01-01] () [File not signed]
S1 dqwnqlplj.sys; C:\WINDOWS\system32\drivers\dqwnqlplj.sys [7712 2017-11-08] () [File not signed]
S1 dsxhokbii.sys; C:\WINDOWS\system32\drivers\dsxhokbii.sys [7712 2017-11-13] () [File not signed]
S1 dzskyxbvb.sys; C:\WINDOWS\system32\drivers\dzskyxbvb.sys [7712 2017-11-28] () [File not signed]
S1 eavkldyag.sys; C:\WINDOWS\system32\drivers\eavkldyag.sys [7712 2017-11-30] () [File not signed]
S1 ejpgbrgry.sys; C:\WINDOWS\system32\drivers\ejpgbrgry.sys [7712 2017-11-11] () [File not signed]
S1 fckodwrar.sys; C:\WINDOWS\system32\drivers\fckodwrar.sys [7712 2017-11-14] () [File not signed]
S1 fdftoylto.sys; C:\WINDOWS\system32\drivers\fdftoylto.sys [7712 2017-11-19] () [File not signed]
S1 gitutnzyg.sys; C:\WINDOWS\system32\drivers\gitutnzyg.sys [7712 2017-11-18] () [File not signed]
S1 gnadttrzp.sys; C:\WINDOWS\system32\drivers\gnadttrzp.sys [7712 2017-11-27] () [File not signed]
S1 gnqzjjlpt.sys; C:\WINDOWS\system32\drivers\gnqzjjlpt.sys [7712 2017-11-02] () [File not signed]
R3 GPUIO; C:\Program Files (x86)\ASUS\GPU TweakII\690b33e1-0462-4e84-9bea-c7552b45432a.sys [27120 2018-01-10] ()
S1 hfksobcgy.sys; C:\WINDOWS\system32\drivers\hfksobcgy.sys [7712 2017-11-04] () [File not signed]
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [27552 2017-08-06] (REALiX(tm))
S1 iajekjhzs.sys; C:\WINDOWS\system32\drivers\iajekjhzs.sys [7712 2017-11-18] () [File not signed]
S1 ikffgqzyq.sys; C:\WINDOWS\system32\drivers\ikffgqzyq.sys [7712 2017-12-01] () [File not signed]
R3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2017-05-08] (ASUSTeK Computer Inc.)
S1 jbjtpsvjp.sys; C:\WINDOWS\system32\drivers\jbjtpsvjp.sys [7712 2017-11-12] () [File not signed]
S1 jsifawipr.sys; C:\WINDOWS\system32\drivers\jsifawipr.sys [7712 2017-10-31] () [File not signed]
S1 mdyvbjunl.sys; C:\WINDOWS\system32\drivers\mdyvbjunl.sys [15424 2017-08-06] () [File not signed]
S1 mivujvbcw.sys; C:\WINDOWS\system32\drivers\mivujvbcw.sys [7712 2017-10-31] () [File not signed]
S1 mrzcjjceb.sys; C:\WINDOWS\system32\drivers\mrzcjjceb.sys [7712 2018-01-10] () [File not signed]
R1 mtunnbbvg.sys; C:\WINDOWS\system32\drivers\mtunnbbvg.sys [142760 2018-01-10] () [File not signed]
S1 namccznua.sys; C:\WINDOWS\system32\drivers\namccznua.sys [7712 2017-11-03] () [File not signed]
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_5601d21ccd639df9\nvlddmkm.sys [17486096 2018-01-05] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30144 2017-11-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [50624 2017-10-11] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57792 2017-11-28] (NVIDIA Corporation)
S1 ofierptfj.sys; C:\WINDOWS\system32\drivers\ofierptfj.sys [15424 2017-08-06] () [File not signed]
S0 pbwckpzo.sys; C:\WINDOWS\System32\drivers\pbwckpzo.sys [15440 2018-01-01] (Acer Laboratories Inc.)
S1 pfchccpjf.sys; C:\WINDOWS\system32\drivers\pfchccpjf.sys [7712 2017-11-22] () [File not signed]
S1 pgmtoudyn.sys; C:\WINDOWS\system32\drivers\pgmtoudyn.sys [7712 2017-11-05] () [File not signed]
R0 pkkjmqev.sys; C:\WINDOWS\System32\drivers\pkkjmqev.sys [904104 2018-01-01] () [File not signed]
S1 plwhmuliy.sys; C:\WINDOWS\system32\drivers\plwhmuliy.sys [7712 2017-11-02] () [File not signed]
S1 poekcoojk.sys; C:\WINDOWS\system32\drivers\poekcoojk.sys [15424 2017-07-27] () [File not signed]
S1 ppctndrks.sys; C:\WINDOWS\system32\drivers\ppctndrks.sys [7712 2017-11-09] () [File not signed]
S1 pskricapm.sys; C:\WINDOWS\system32\drivers\pskricapm.sys [7712 2017-11-18] () [File not signed]
S1 qgcftitqz.sys; C:\WINDOWS\system32\drivers\qgcftitqz.sys [15424 2017-08-06] () [File not signed]
S1 qjfajkcpq.sys; C:\WINDOWS\system32\drivers\qjfajkcpq.sys [7712 2017-11-25] () [File not signed]
S1 qkvmaioxc.sys; C:\WINDOWS\system32\drivers\qkvmaioxc.sys [7712 2017-12-01] () [File not signed]
S1 qrymmgucq.sys; C:\WINDOWS\system32\drivers\qrymmgucq.sys [7712 2017-10-31] () [File not signed]
S1 qswpbwjmv.sys; C:\WINDOWS\system32\drivers\qswpbwjmv.sys [7712 2017-11-02] () [File not signed]
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2017-09-29] (Realtek )
S1 runcqaaii.sys; C:\WINDOWS\system32\drivers\runcqaaii.sys [7712 2017-11-29] () [File not signed]
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [41512 2017-12-07] ()
S1 tlyxkongt.sys; C:\WINDOWS\system32\drivers\tlyxkongt.sys [15424 2017-07-26] () [File not signed]
S1 ubxdpiopr.sys; C:\WINDOWS\system32\drivers\ubxdpiopr.sys [7712 2018-01-06] () [File not signed]
S1 uwtjuzxqo.sys; C:\WINDOWS\system32\drivers\uwtjuzxqo.sys [7712 2017-11-16] () [File not signed]
S1 vbziccmil.sys; C:\WINDOWS\system32\drivers\vbziccmil.sys [7712 2017-11-20] () [File not signed]
S1 vnjnxllxc.sys; C:\WINDOWS\system32\drivers\vnjnxllxc.sys [7712 2017-11-15] () [File not signed]
S1 vnwlzfuap.sys; C:\WINDOWS\system32\drivers\vnwlzfuap.sys [7712 2017-11-06] () [File not signed]
S1 vqrwxlxnu.sys; C:\WINDOWS\system32\drivers\vqrwxlxnu.sys [7712 2017-11-01] () [File not signed]
S1 vrraekqwa.sys; C:\WINDOWS\system32\drivers\vrraekqwa.sys [15424 2017-08-06] () [File not signed]
S1 vxfeoyqku.sys; C:\WINDOWS\system32\drivers\vxfeoyqku.sys [15424 2017-07-07] () [File not signed]
S1 vysgcoiqn.sys; C:\WINDOWS\system32\drivers\vysgcoiqn.sys [7712 2017-11-03] () [File not signed]
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46072 2017-12-08] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [288848 2017-12-08] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2017-12-08] (Microsoft Corporation)
S1 wpinwbetm.sys; C:\WINDOWS\system32\drivers\wpinwbetm.sys [7712 2017-11-21] () [File not signed]
S1 xbcgiypin.sys; C:\WINDOWS\system32\drivers\xbcgiypin.sys [7712 2017-11-01] () [File not signed]
S1 xgsfbmoos.sys; C:\WINDOWS\system32\drivers\xgsfbmoos.sys [7712 2017-11-18] () [File not signed]
S1 xiewtpbkl.sys; C:\WINDOWS\system32\drivers\xiewtpbkl.sys [7712 2017-12-13] () [File not signed]
S1 yxixaooko.sys; C:\WINDOWS\system32\drivers\yxixaooko.sys [7712 2017-11-01] () [File not signed]
S1 zibaqtkwt.sys; C:\WINDOWS\system32\drivers\zibaqtkwt.sys [7712 2017-11-07] () [File not signed]
S1 zunfgmfni.sys; C:\WINDOWS\system32\drivers\zunfgmfni.sys [7712 2017-11-23] () [File not signed]
S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [X]
S3 EsgScanner; system32\DRIVERS\EsgScanner.sys [X]
S3 TcHardWare; \??\C:\Program Files (x86)\Tencent\QQPCMgr\12.3.18487.222\QQPCHW-x64_ev.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-10 13:55 - 2018-01-10 13:55 - 000142760 _____ C:\WINDOWS\system32\Drivers\xvevcnqtu.sys
2018-01-10 13:55 - 2018-01-10 13:55 - 000007712 _____ C:\WINDOWS\system32\Drivers\mrzcjjceb.sys
2018-01-10 13:55 - 2018-01-10 13:55 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-01-10 12:31 - 2018-01-10 13:54 - 000000000 ____D C:\AdwCleaner
2018-01-10 12:31 - 2018-01-10 12:30 - 008198432 _____ (Malwarebytes) C:\Users\Fedorovi\Desktop\adwcleaner_7.0.6.0.exe
2018-01-09 17:27 - 2018-01-09 17:27 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-01-09 17:27 - 2018-01-04 01:01 - 000137528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2018-01-09 17:27 - 2017-11-02 21:15 - 000928568 _____ C:\WINDOWS\system32\vulkan-1.dll
2018-01-09 17:27 - 2017-11-02 21:15 - 000798520 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2018-01-09 17:27 - 2017-11-02 21:15 - 000490808 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2018-01-09 17:27 - 2017-11-02 21:14 - 000591672 _____ C:\WINDOWS\system32\vulkaninfo.exe
2018-01-09 17:26 - 2018-01-09 17:27 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2018-01-09 17:26 - 2018-01-09 17:26 - 000000000 ____D C:\WINDOWS\system32\Drivers\NVIDIA Corporation
2018-01-09 17:24 - 2018-01-04 02:44 - 040269624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 035179080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 019796520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 016449872 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 013430632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 012843496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 011015584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 010900432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 004306736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 003707888 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001975184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6439065.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001674544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6439065.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001334624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001325384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001134952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001125960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001053768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001049296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 001043128 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000988656 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000938896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000885680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000795928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000740336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000635248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000618928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000616248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000599536 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000506864 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2018-01-09 17:24 - 2018-01-04 02:44 - 000045600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2018-01-09 16:19 - 2018-01-09 16:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Demos
2018-01-09 15:50 - 2018-01-10 13:58 - 000000000 ____D C:\FRST
2018-01-07 12:53 - 2018-01-10 13:51 - 001872235 _____ C:\WINDOWS\system32\r6lstmp4.dat
2018-01-07 09:52 - 2018-01-10 13:55 - 000142760 _____ C:\WINDOWS\system32\Drivers\mtunnbbvg.sys
2018-01-07 08:22 - 2018-01-10 13:56 - 000000000 ___HD C:\Users\Public\Documents\AdobeGC
2018-01-06 11:17 - 2018-01-06 11:17 - 000142760 _____ C:\WINDOWS\system32\Drivers\kigzcfcuy.sys
2018-01-06 11:17 - 2018-01-06 11:17 - 000007712 _____ C:\WINDOWS\system32\Drivers\ubxdpiopr.sys
2018-01-05 14:03 - 2018-01-01 18:15 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-01-05 14:03 - 2018-01-01 13:51 - 001055128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-01-05 14:03 - 2018-01-01 13:51 - 000059800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bam.sys
2018-01-05 14:03 - 2018-01-01 13:50 - 005905752 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2018-01-05 14:03 - 2018-01-01 13:49 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-01-05 14:03 - 2018-01-01 13:49 - 000319352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-01-05 14:03 - 2018-01-01 13:48 - 007831760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-01-05 14:03 - 2018-01-01 13:48 - 001954048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-01-05 14:03 - 2018-01-01 13:48 - 000904104 _____ C:\WINDOWS\system32\Drivers\pkkjmqev.sys
2018-01-05 14:03 - 2018-01-01 13:48 - 000904104 _____ C:\WINDOWS\system32\Drivers\dgsjfiqr.sys
2018-01-05 14:03 - 2018-01-01 13:48 - 000015440 _____ (Acer Laboratories Inc.) C:\WINDOWS\system32\Drivers\pbwckpzo.sys
2018-01-05 14:03 - 2018-01-01 13:47 - 000082840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-01-05 14:03 - 2018-01-01 13:46 - 002709704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-01-05 14:03 - 2018-01-01 13:46 - 000471960 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-01-05 14:03 - 2018-01-01 13:45 - 002395032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-01-05 14:03 - 2018-01-01 13:45 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-01-05 14:03 - 2018-01-01 13:45 - 000398744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2018-01-05 14:03 - 2018-01-01 13:42 - 000571288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-01-05 14:03 - 2018-01-01 13:42 - 000184984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2018-01-05 14:03 - 2018-01-01 13:41 - 007676296 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-01-05 14:03 - 2018-01-01 13:40 - 001206680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-01-05 14:03 - 2018-01-01 13:39 - 000902416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-01-05 14:03 - 2018-01-01 13:39 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-01-05 14:03 - 2018-01-01 13:39 - 000129432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-01-05 14:03 - 2018-01-01 13:38 - 003904808 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-01-05 14:03 - 2018-01-01 13:37 - 001426664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-01-05 14:03 - 2018-01-01 13:36 - 000166296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2018-01-05 14:03 - 2018-01-01 13:35 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-01-05 14:03 - 2018-01-01 13:34 - 007385088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-01-05 14:03 - 2018-01-01 13:33 - 000603920 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-01-05 14:03 - 2018-01-01 13:32 - 004481240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-01-05 14:03 - 2018-01-01 13:27 - 000713624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-01-05 14:03 - 2018-01-01 13:26 - 000428952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-01-05 14:03 - 2018-01-01 13:25 - 000615768 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2018-01-05 14:03 - 2018-01-01 13:25 - 000147864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2018-01-05 14:03 - 2018-01-01 13:23 - 021352144 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-01-05 14:03 - 2018-01-01 13:03 - 000123512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2018-01-05 14:03 - 2018-01-01 12:53 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-01-05 14:03 - 2018-01-01 12:46 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-01-05 14:03 - 2018-01-01 12:45 - 006092152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-01-05 14:03 - 2018-01-01 12:45 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-01-05 14:03 - 2018-01-01 12:45 - 002192624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-01-05 14:03 - 2018-01-01 12:43 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-01-05 14:03 - 2018-01-01 12:42 - 006479552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-01-05 14:03 - 2018-01-01 12:42 - 004644912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-01-05 14:03 - 2018-01-01 12:42 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-01-05 14:03 - 2018-01-01 12:42 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-01-05 14:03 - 2018-01-01 12:37 - 025247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-01-05 14:03 - 2018-01-01 12:34 - 000703568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-01-05 14:03 - 2018-01-01 12:25 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-01-05 14:03 - 2018-01-01 12:25 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-01-05 14:03 - 2018-01-01 12:25 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-01-05 14:03 - 2018-01-01 12:25 - 000097792 _____ C:\WINDOWS\system32\runexehelper.exe
2018-01-05 14:03 - 2018-01-01 12:24 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-01-05 14:03 - 2018-01-01 12:24 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2018-01-05 14:03 - 2018-01-01 12:23 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-01-05 14:03 - 2018-01-01 12:23 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-01-05 14:03 - 2018-01-01 12:23 - 000250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2018-01-05 14:03 - 2018-01-01 12:21 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2018-01-05 14:03 - 2018-01-01 12:20 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-01-05 14:03 - 2018-01-01 12:20 - 018917888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 008014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-01-05 14:03 - 2018-01-01 12:19 - 000334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2018-01-05 14:03 - 2018-01-01 12:18 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-01-05 14:03 - 2018-01-01 12:18 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-01-05 14:03 - 2018-01-01 12:18 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-01-05 14:03 - 2018-01-01 12:17 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-01-05 14:03 - 2018-01-01 12:16 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-01-05 14:03 - 2018-01-01 12:15 - 012687872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-01-05 14:03 - 2018-01-01 12:15 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-01-05 14:03 - 2018-01-01 12:15 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2018-01-05 14:03 - 2018-01-01 12:14 - 023655936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-01-05 14:03 - 2018-01-01 12:14 - 002465280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-01-05 14:03 - 2018-01-01 12:14 - 001495040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 013657600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 012830208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 003121664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-01-05 14:03 - 2018-01-01 12:13 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-01-05 14:03 - 2018-01-01 12:12 - 002633216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-01-05 14:03 - 2018-01-01 12:12 - 002208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-01-05 14:03 - 2018-01-01 12:12 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-01-05 14:03 - 2018-01-01 12:12 - 001424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 008108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 003165696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-01-05 14:03 - 2018-01-01 12:11 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-01-05 14:03 - 2018-01-01 12:09 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-01-05 14:03 - 2018-01-01 12:09 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-01-05 14:03 - 2018-01-01 12:08 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-01-05 14:03 - 2018-01-01 12:08 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2018-01-05 14:03 - 2018-01-01 12:05 - 002510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-01-05 14:03 - 2018-01-01 12:05 - 001160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-01-05 14:02 - 2018-01-01 13:54 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-01-05 14:02 - 2018-01-01 13:53 - 001090984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-01-05 14:02 - 2018-01-01 13:52 - 000066712 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2018-01-05 14:02 - 2018-01-01 13:51 - 001414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-01-05 14:02 - 2018-01-01 13:51 - 001209240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-01-05 14:02 - 2018-01-01 13:51 - 000191816 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-01-05 14:02 - 2018-01-01 13:50 - 000780464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2018-01-05 14:02 - 2018-01-01 13:50 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-01-05 14:02 - 2018-01-01 13:50 - 000077208 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-01-05 14:02 - 2018-01-01 13:49 - 000599448 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-01-05 14:02 - 2018-01-01 13:49 - 000292376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2018-01-05 14:02 - 2018-01-01 13:48 - 000382360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2018-01-05 14:02 - 2018-01-01 13:47 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-01-05 14:02 - 2018-01-01 13:46 - 000898216 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-01-05 14:02 - 2018-01-01 13:46 - 000733592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-01-05 14:02 - 2018-01-01 13:43 - 001173576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-01-05 14:02 - 2018-01-01 13:43 - 000367336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2018-01-05 14:02 - 2018-01-01 13:43 - 000062872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
2018-01-05 14:02 - 2018-01-01 13:42 - 001029016 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2018-01-05 14:02 - 2018-01-01 13:42 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-01-05 14:02 - 2018-01-01 13:42 - 000109976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2018-01-05 14:02 - 2018-01-01 13:41 - 000559512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-01-05 14:02 - 2018-01-01 13:41 - 000549552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2018-01-05 14:02 - 2018-01-01 13:39 - 000677784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-01-05 14:02 - 2018-01-01 13:39 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-01-05 14:02 - 2018-01-01 13:38 - 000727448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2018-01-05 14:02 - 2018-01-01 13:38 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-01-05 14:02 - 2018-01-01 13:38 - 000103320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-01-05 14:02 - 2018-01-01 13:38 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
2018-01-05 14:02 - 2018-01-01 13:37 - 000461720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2018-01-05 14:02 - 2018-01-01 13:36 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-01-05 14:02 - 2018-01-01 13:36 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2018-01-05 14:02 - 2018-01-01 13:36 - 000113560 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2018-01-05 14:02 - 2018-01-01 13:36 - 000057752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbios.sys
2018-01-05 14:02 - 2018-01-01 13:35 - 000075160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-01-05 14:02 - 2018-01-01 13:34 - 001336344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-01-05 14:02 - 2018-01-01 13:34 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-01-05 14:02 - 2018-01-01 13:34 - 000087384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2018-01-05 14:02 - 2018-01-01 13:33 - 002773400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-01-05 14:02 - 2018-01-01 13:32 - 000617304 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2018-01-05 14:02 - 2018-01-01 13:27 - 000163736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-01-05 14:02 - 2018-01-01 13:26 - 000081304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2018-01-05 14:02 - 2018-01-01 13:21 - 001103768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-01-05 14:02 - 2018-01-01 13:21 - 000614296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2018-01-05 14:02 - 2018-01-01 13:06 - 000311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2018-01-05 14:02 - 2018-01-01 13:03 - 000777904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-01-05 14:02 - 2018-01-01 13:03 - 000650328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2018-01-05 14:02 - 2018-01-01 13:03 - 000566664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-01-05 14:02 - 2018-01-01 12:49 - 000481464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-01-05 14:02 - 2018-01-01 12:49 - 000258808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2018-01-05 14:02 - 2018-01-01 12:46 - 000289816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2018-01-05 14:02 - 2018-01-01 12:45 - 000450928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2018-01-05 14:02 - 2018-01-01 12:42 - 001003152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-01-05 14:02 - 2018-01-01 12:42 - 000386424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2018-01-05 14:02 - 2018-01-01 12:42 - 000129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-01-05 14:02 - 2018-01-01 12:42 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2018-01-05 14:02 - 2018-01-01 12:25 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2018-01-05 14:02 - 2018-01-01 12:24 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2018-01-05 14:02 - 2018-01-01 12:24 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2018-01-05 14:02 - 2018-01-01 12:24 - 000038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2018-01-05 14:02 - 2018-01-01 12:23 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2018-01-05 14:02 - 2018-01-01 12:23 - 000385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2018-01-05 14:02 - 2018-01-01 12:23 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\convertvhd.exe
2018-01-05 14:02 - 2018-01-01 12:23 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2018-01-05 14:02 - 2018-01-01 12:23 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2018-01-05 14:02 - 2018-01-01 12:23 - 000047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2018-01-05 14:02 - 2018-01-01 12:22 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2018-01-05 14:02 - 2018-01-01 12:22 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2018-01-05 14:02 - 2018-01-01 12:22 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmApplicationHealthMonitorProxy.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2018-01-05 14:02 - 2018-01-01 12:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspptp.sys
2018-01-05 14:02 - 2018-01-01 12:21 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2018-01-05 14:02 - 2018-01-01 12:21 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2018-01-05 14:02 - 2018-01-01 12:20 - 000524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2018-01-05 14:02 - 2018-01-01 12:20 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2018-01-05 14:02 - 2018-01-01 12:20 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
2018-01-05 14:02 - 2018-01-01 12:20 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshhttp.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalAuth.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2018-01-05 14:02 - 2018-01-01 12:19 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2018-01-05 14:02 - 2018-01-01 12:19 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2018-01-05 14:02 - 2018-01-01 12:19 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoert2.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2018-01-05 14:02 - 2018-01-01 12:19 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-01-05 14:02 - 2018-01-01 12:19 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2018-01-05 14:02 - 2018-01-01 12:18 - 000082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 006564864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2018-01-05 14:02 - 2018-01-01 12:17 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-01-05 14:02 - 2018-01-01 12:17 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000966656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000956928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2018-01-05 14:02 - 2018-01-01 12:16 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 002349568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2018-01-05 14:02 - 2018-01-01 12:15 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 000985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-01-05 14:02 - 2018-01-01 12:14 - 000870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-01-05 14:02 - 2018-01-01 12:13 - 002013184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-01-05 14:02 - 2018-01-01 12:13 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-01-05 14:02 - 2018-01-01 12:13 - 000897024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-01-05 14:02 - 2018-01-01 12:12 - 001573376 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2018-01-05 14:02 - 2018-01-01 12:12 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2018-01-05 14:02 - 2018-01-01 12:12 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 002082304 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-01-05 14:02 - 2018-01-01 12:11 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 001343488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-01-05 14:02 - 2018-01-01 12:11 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-01-05 14:02 - 2018-01-01 12:10 - 003126272 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-01-05 14:02 - 2018-01-01 12:10 - 002528256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-01-05 14:02 - 2018-01-01 12:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscproxystub.dll
2018-01-05 14:02 - 2018-01-01 12:09 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-01-05 14:02 - 2018-01-01 12:09 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2018-01-05 14:02 - 2018-01-01 12:08 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-01-05 14:02 - 2018-01-01 12:08 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-01-05 14:02 - 2018-01-01 12:08 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2018-01-05 14:02 - 2018-01-01 12:06 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2018-01-05 14:02 - 2018-01-01 12:05 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2018-01-03 15:08 - 2018-01-03 15:08 - 000000722 _____ C:\Users\Fedorovi\Desktop\Kleirou – zástupce.lnk
2017-12-30 07:29 - 2017-12-16 01:23 - 001990128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6438871.dll
2017-12-30 07:29 - 2017-12-16 01:23 - 001674736 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6438871.dll
2017-12-29 15:52 - 2017-12-29 15:52 - 000003834 _____ C:\WINDOWS\System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473
2017-12-29 15:19 - 2017-12-07 23:29 - 000041512 _____ C:\WINDOWS\system32\Drivers\semav6msr64.sys
2017-12-29 15:13 - 2017-12-29 15:13 - 000000000 ____D C:\Intel
2017-12-29 14:58 - 2017-12-29 14:58 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsign6eea94283bec1be9
2017-12-29 14:58 - 2017-12-29 14:58 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsign5e21e6dbbb1a28fd
2017-12-29 14:58 - 2017-12-29 14:58 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsign352e001da65cb700
2017-12-24 19:07 - 2017-12-24 19:07 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsigne875345af2dd7e16
2017-12-24 19:06 - 2017-12-24 19:06 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsignd8bcbf80b4b6cc28
2017-12-24 19:06 - 2017-12-24 19:06 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Tempzxpsignae29bdadfb484294
2017-12-23 14:41 - 2018-01-05 15:31 - 000000000 ____D C:\Users\Fedorovi\Documents\Settlers7
2017-12-23 14:41 - 2017-12-23 15:46 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Ubisoft Game Launcher
2017-12-23 14:40 - 2009-09-04 17:44 - 000517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2017-12-23 14:40 - 2009-09-04 17:44 - 000069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 005554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 005501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 002582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 002475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 001974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 001892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 000523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 000453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 000285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2017-12-23 14:40 - 2009-09-04 17:29 - 000235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
2017-12-23 14:40 - 2009-03-16 14:18 - 000521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2017-12-23 14:40 - 2009-03-16 14:18 - 000517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
2017-12-23 14:40 - 2009-03-16 14:18 - 000235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
2017-12-23 14:40 - 2009-03-16 14:18 - 000174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 005425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 004178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 002430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 001846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 000520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2017-12-23 14:40 - 2009-03-09 15:27 - 000453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
2017-12-23 14:39 - 2009-03-16 14:18 - 000024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2017-12-23 14:39 - 2009-03-16 14:18 - 000022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
2017-12-23 14:39 - 2008-10-27 10:04 - 000023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 005631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 004379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 002605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 002036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 000519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2017-12-23 14:39 - 2008-10-15 06:22 - 000452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2017-12-23 14:39 - 2008-07-31 10:41 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
2017-12-23 14:39 - 2008-07-31 10:41 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2017-12-23 14:39 - 2008-07-31 10:41 - 000072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2017-12-23 14:39 - 2008-07-31 10:41 - 000068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2017-12-23 14:39 - 2008-07-31 10:40 - 000513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2017-12-23 14:39 - 2008-07-31 10:40 - 000509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2017-12-23 14:39 - 2008-07-10 11:01 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 004992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 003851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 001942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 001493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2017-12-23 14:39 - 2008-07-10 11:00 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2017-12-23 14:39 - 2008-05-30 14:19 - 000511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2017-12-23 14:39 - 2008-05-30 14:19 - 000507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
2017-12-23 14:39 - 2008-05-30 14:18 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
2017-12-23 14:39 - 2008-05-30 14:18 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2017-12-23 14:39 - 2008-05-30 14:17 - 000068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2017-12-23 14:39 - 2008-05-30 14:17 - 000065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
2017-12-23 14:39 - 2008-05-30 14:17 - 000025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
2017-12-23 14:39 - 2008-05-30 14:16 - 000028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 004991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 003850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 001941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 001491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2017-12-23 14:39 - 2008-05-30 14:11 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
2017-12-23 14:39 - 2008-03-05 16:04 - 000489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2017-12-23 14:39 - 2008-03-05 16:03 - 000479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
2017-12-23 14:39 - 2008-03-05 16:03 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
2017-12-23 14:39 - 2008-03-05 16:03 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2017-12-23 14:39 - 2008-03-05 16:00 - 000028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2017-12-23 14:39 - 2008-03-05 16:00 - 000025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
2017-12-23 14:39 - 2008-03-05 15:56 - 004910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2017-12-23 14:39 - 2008-03-05 15:56 - 003786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
2017-12-23 14:39 - 2008-03-05 15:56 - 001860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2017-12-23 14:39 - 2008-03-05 15:56 - 001420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
2017-12-23 14:39 - 2008-02-05 23:07 - 000529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2017-12-23 14:39 - 2008-02-05 23:07 - 000462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
2017-12-23 14:39 - 2007-10-22 03:40 - 000411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2017-12-23 14:39 - 2007-10-22 03:39 - 000267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
2017-12-23 14:39 - 2007-10-22 03:37 - 000021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2017-12-23 14:39 - 2007-10-22 03:37 - 000017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
2017-12-23 14:39 - 2007-10-12 15:14 - 005081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2017-12-23 14:39 - 2007-10-12 15:14 - 003734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
2017-12-23 14:39 - 2007-10-12 15:14 - 002006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2017-12-23 14:39 - 2007-10-12 15:14 - 001374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
2017-12-23 14:39 - 2007-10-02 09:56 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2017-12-23 14:39 - 2007-10-02 09:56 - 000444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
2017-12-23 14:39 - 2007-07-20 00:57 - 000411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2017-12-23 14:39 - 2007-07-20 00:57 - 000267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 005073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 003727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 001985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 001358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2017-12-23 14:39 - 2007-07-19 18:14 - 000444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
2017-12-23 14:39 - 2007-06-20 20:49 - 000409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2017-12-23 14:39 - 2007-06-20 20:46 - 000266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 004496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 003497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 001401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 001124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2017-12-23 14:39 - 2007-05-16 16:45 - 000443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
2017-12-23 14:39 - 2007-04-04 18:55 - 000403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2017-12-23 14:39 - 2007-04-04 18:55 - 000261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
2017-12-23 14:39 - 2007-04-04 18:54 - 000107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
2017-12-23 14:39 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
2017-12-23 14:39 - 2007-03-15 16:57 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2017-12-23 14:39 - 2007-03-15 16:57 - 000443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
2017-12-23 14:39 - 2007-03-12 16:42 - 004494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2017-12-23 14:39 - 2007-03-12 16:42 - 003495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
2017-12-23 14:39 - 2007-03-12 16:42 - 001400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2017-12-23 14:39 - 2007-03-12 16:42 - 001123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
2017-12-23 14:39 - 2007-03-05 12:42 - 000017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2017-12-23 14:39 - 2007-03-05 12:42 - 000015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
2017-12-23 14:39 - 2007-01-24 15:27 - 000393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2017-12-23 14:39 - 2007-01-24 15:27 - 000255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
2017-12-23 14:39 - 2006-12-08 12:02 - 000251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
2017-12-23 14:39 - 2006-12-08 12:00 - 000390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
2017-12-23 14:39 - 2006-11-29 13:06 - 004398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2017-12-23 14:39 - 2006-11-29 13:06 - 003426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2017-12-23 14:39 - 2006-11-29 13:06 - 000469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
2017-12-23 14:39 - 2006-11-29 13:06 - 000440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
2017-12-23 14:39 - 2006-09-28 16:05 - 003977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
2017-12-23 14:39 - 2006-09-28 16:05 - 002414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
2017-12-23 14:39 - 2006-09-28 16:05 - 000237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
2017-12-23 14:39 - 2006-09-28 16:04 - 000364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
2017-12-23 14:39 - 2006-07-28 09:31 - 000083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
2017-12-23 14:39 - 2006-07-28 09:30 - 000363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
2017-12-23 14:39 - 2006-07-28 09:30 - 000236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
2017-12-23 14:39 - 2006-07-28 09:30 - 000062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
2017-12-23 14:39 - 2006-05-31 07:24 - 000230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
2017-12-23 14:39 - 2006-05-31 07:22 - 000354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
2017-12-23 14:39 - 2006-03-31 12:41 - 003927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
2017-12-23 14:39 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2017-12-23 14:39 - 2006-03-31 12:40 - 000352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
2017-12-23 14:39 - 2006-03-31 12:39 - 000229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
2017-12-23 14:39 - 2006-03-31 12:39 - 000083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
2017-12-23 14:39 - 2006-03-31 12:39 - 000062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
2017-12-23 14:39 - 2006-02-03 08:43 - 003830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
2017-12-23 14:39 - 2006-02-03 08:43 - 002332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
2017-12-23 14:39 - 2006-02-03 08:42 - 000355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
2017-12-23 14:39 - 2006-02-03 08:42 - 000230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
2017-12-23 14:39 - 2006-02-03 08:41 - 000016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
2017-12-23 14:39 - 2006-02-03 08:41 - 000014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
2017-12-23 14:39 - 2005-12-05 18:09 - 003815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
2017-12-23 14:39 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
2017-12-23 14:39 - 2005-07-22 19:59 - 003807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
2017-12-23 14:39 - 2005-07-22 19:59 - 002319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
2017-12-23 14:39 - 2005-05-26 15:34 - 003767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
2017-12-23 14:39 - 2005-05-26 15:34 - 002297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
2017-12-23 14:39 - 2005-03-18 17:19 - 003823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
2017-12-23 14:39 - 2005-03-18 17:19 - 002337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
2017-12-23 14:39 - 2005-02-05 19:45 - 003544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
2017-12-23 14:39 - 2005-02-05 19:45 - 002222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
2017-12-23 14:38 - 2017-12-23 14:38 - 000000000 ____D C:\Program Files (x86)\Ubisoft
2017-12-13 20:05 - 2017-12-13 20:05 - 000142760 _____ C:\WINDOWS\system32\Drivers\ykyusygrf.sys
2017-12-13 20:05 - 2017-12-13 20:05 - 000007712 _____ C:\WINDOWS\system32\Drivers\xiewtpbkl.sys
2017-12-13 17:21 - 2017-12-08 07:52 - 000666112 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2017-12-13 17:21 - 2017-12-08 00:34 - 001925296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-12-13 17:21 - 2017-12-08 00:34 - 001634288 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-12-13 17:21 - 2017-12-08 00:28 - 000710912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-12-13 17:21 - 2017-12-08 00:28 - 000630752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcrt.dll
2017-12-13 17:21 - 2017-12-08 00:27 - 004504456 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2017-12-13 17:21 - 2017-12-08 00:26 - 000525208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2017-12-13 17:21 - 2017-12-08 00:24 - 000705944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2017-12-13 17:21 - 2017-12-08 00:24 - 000437144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-12-13 17:21 - 2017-12-08 00:24 - 000246168 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-12-13 17:21 - 2017-12-08 00:22 - 001003104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-12-13 17:21 - 2017-12-08 00:22 - 000979352 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-12-13 17:21 - 2017-12-08 00:22 - 000137544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2017-12-13 17:21 - 2017-12-08 00:16 - 001776272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-12-13 17:21 - 2017-12-08 00:15 - 000721592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-12-13 17:21 - 2017-12-08 00:12 - 000401304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2017-12-13 17:21 - 2017-12-07 23:56 - 001528904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-12-13 17:21 - 2017-12-07 23:55 - 001490328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-12-13 17:21 - 2017-12-07 23:55 - 000097144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2017-12-13 17:21 - 2017-12-07 23:37 - 001145104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-12-13 17:21 - 2017-12-07 23:36 - 000769096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcrt.dll
2017-12-13 17:21 - 2017-12-07 23:33 - 000747416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-12-13 17:21 - 2017-12-07 23:33 - 000592280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2017-12-13 17:21 - 2017-12-07 23:31 - 001522176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-12-13 17:21 - 2017-12-07 23:12 - 000101376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscript.ocx
2017-12-13 17:21 - 2017-12-07 23:10 - 006466048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-12-13 17:21 - 2017-12-07 23:10 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2017-12-13 17:21 - 2017-12-07 23:10 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-12-13 17:21 - 2017-12-07 23:09 - 001663488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\batmeter.dll
2017-12-13 17:21 - 2017-12-07 23:09 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2017-12-13 17:21 - 2017-12-07 23:09 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscript.exe
2017-12-13 17:21 - 2017-12-07 23:09 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cscript.exe
2017-12-13 17:21 - 2017-12-07 23:09 - 000136704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gamingtcui.dll
2017-12-13 17:21 - 2017-12-07 23:08 - 000514560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2017-12-13 17:21 - 2017-12-07 23:08 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scrobj.dll
2017-12-13 17:21 - 2017-12-07 23:08 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-12-13 17:21 - 2017-12-07 23:07 - 000254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\PushToInstall.dll
2017-12-13 17:21 - 2017-12-07 23:07 - 000246272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-12-13 17:21 - 2017-12-07 23:07 - 000172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2017-12-13 17:21 - 2017-12-07 23:07 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-12-13 17:21 - 2017-12-07 23:06 - 000676352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2017-12-13 17:21 - 2017-12-07 23:06 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\gamingtcui.dll
2017-12-13 17:21 - 2017-12-07 23:06 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscript.exe
2017-12-13 17:21 - 2017-12-07 23:05 - 001670656 _____ (Microsoft Corporation) C:\WINDOWS\system32\batmeter.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000559616 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\HolographicExtensions.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000481792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcext.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000363008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\scrobj.dll
2017-12-13 17:21 - 2017-12-07 23:05 - 000164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\cscript.exe
2017-12-13 17:21 - 2017-12-07 23:05 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\slcext.dll
2017-12-13 17:21 - 2017-12-07 23:04 - 001498112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2017-12-13 17:21 - 2017-12-07 23:04 - 001321472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 001230848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 000841728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-12-13 17:21 - 2017-12-07 23:03 - 000085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\hascsp.dll
2017-12-13 17:21 - 2017-12-07 23:02 - 007545344 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-12-13 17:21 - 2017-12-07 23:02 - 002864640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mispace.dll
2017-12-13 17:21 - 2017-12-07 23:02 - 002117632 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2017-12-13 17:21 - 2017-12-07 23:02 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2017-12-13 17:21 - 2017-12-07 23:01 - 004592640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-12-13 17:21 - 2017-12-07 23:01 - 001980928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\storagewmi.dll
2017-12-13 17:21 - 2017-12-07 23:01 - 000601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2017-12-13 17:21 - 2017-12-07 23:01 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\slcext.dll
2017-12-13 17:21 - 2017-12-07 23:00 - 001509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-12-13 17:21 - 2017-12-07 22:59 - 002105856 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-12-13 17:21 - 2017-12-07 22:59 - 001666048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-12-13 17:21 - 2017-12-07 22:59 - 001058304 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-12-13 17:21 - 2017-12-07 22:58 - 003478016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mispace.dll
2017-12-13 17:21 - 2017-12-07 22:58 - 003211776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-12-13 17:21 - 2017-12-07 22:58 - 001353728 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-12-13 17:21 - 2017-12-07 22:56 - 002666496 _____ (Microsoft Corporation) C:\WINDOWS\system32\storagewmi.dll
2017-12-13 17:21 - 2017-12-07 22:56 - 001739264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-12-13 17:21 - 2017-12-07 22:54 - 001570816 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-10 13:59 - 2017-10-26 12:01 - 001872235 _____ C:\WINDOWS\system32\r6lstmp5.dat
2018-01-10 13:57 - 2017-07-04 16:37 - 000000000 ____D C:\ProgramData\NVIDIA
2018-01-10 13:56 - 2017-12-02 08:58 - 000003100 _____ C:\WINDOWS\System32\Tasks\GPU Tweak II
2018-01-10 13:56 - 2017-06-28 16:48 - 000000000 ____D C:\Users\Fedorovi\AppData\LocalLow\Mozilla
2018-01-10 13:55 - 2017-12-02 08:58 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-01-10 13:55 - 2017-09-29 09:45 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-01-10 13:51 - 2017-06-25 05:57 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Battle.net
2018-01-10 12:31 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-01-10 12:19 - 2017-07-07 11:02 - 000000000 ____D C:\Users\Fedorovi\AppData\Roaming\Seznam.cz
2018-01-10 12:17 - 2017-12-02 08:58 - 000004218 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{633CA722-7311-444B-BD0D-C122C404D2DF}
2018-01-10 12:17 - 2017-09-29 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-01-10 12:17 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-01-10 02:38 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-01-10 02:38 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-01-10 02:38 - 2017-06-28 16:54 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Adobe
2018-01-10 02:35 - 2017-12-02 08:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-01-09 17:27 - 2017-10-14 08:19 - 000000000 ____D C:\Temp
2018-01-09 17:27 - 2017-09-29 14:44 - 000000000 ____D C:\WINDOWS\INF
2018-01-09 17:27 - 2017-07-04 16:37 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-01-09 17:27 - 2017-07-04 16:37 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-01-09 17:27 - 2017-06-24 04:54 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\NVIDIA
2018-01-09 17:27 - 2017-06-24 04:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-01-09 14:11 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\rescache
2018-01-09 13:41 - 2017-07-07 19:10 - 000093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2018-01-09 13:28 - 2017-07-07 19:10 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2018-01-09 13:28 - 2017-07-07 19:10 - 000101784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2018-01-09 13:28 - 2017-07-07 19:10 - 000045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2018-01-07 12:58 - 2017-12-02 08:55 - 002156588 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-01-07 12:58 - 2017-09-30 15:31 - 000944270 _____ C:\WINDOWS\system32\perfh005.dat
2018-01-07 12:58 - 2017-09-30 15:31 - 000209976 _____ C:\WINDOWS\system32\perfc005.dat
2018-01-07 12:56 - 2017-11-29 14:07 - 000571472 _____ C:\Tiem.txt
2018-01-07 09:29 - 2017-07-07 19:10 - 000188352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2018-01-06 11:26 - 2017-06-25 05:10 - 000000000 ____D C:\Users\Fedorovi\Documents\My Games
2018-01-05 21:42 - 2017-06-30 11:45 - 000000000 ___RD C:\Users\Fedorovi\3D Objects
2018-01-05 21:42 - 2017-06-23 18:15 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-01-05 18:15 - 2017-12-02 08:41 - 000346512 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-01-05 18:15 - 2017-07-07 17:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-01-05 18:15 - 2017-07-07 17:58 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-01-05 18:13 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\Provisioning
2018-01-05 18:13 - 2017-09-29 09:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-01-05 15:32 - 2017-07-07 17:58 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2018-01-05 15:31 - 2017-06-24 04:54 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-01-05 14:06 - 2017-09-29 14:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-01-05 14:04 - 2017-09-29 14:41 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-01-05 14:04 - 2017-09-29 14:41 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-01-05 14:04 - 2017-09-29 14:41 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-01-04 02:44 - 2017-12-01 15:15 - 004580320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2018-01-04 02:44 - 2017-12-01 15:15 - 003893792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2018-01-04 02:44 - 2017-12-01 15:15 - 001682288 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2018-01-04 02:44 - 2017-12-01 15:15 - 000226760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2018-01-04 02:44 - 2017-12-01 15:15 - 000048282 _____ C:\WINDOWS\system32\nvinfo.pb
2018-01-04 01:33 - 2017-07-04 16:37 - 000001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2018-01-04 00:50 - 2017-07-04 16:37 - 005951336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2018-01-04 00:50 - 2017-07-04 16:37 - 002588232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2018-01-04 00:50 - 2017-07-04 16:37 - 001768480 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2018-01-04 00:50 - 2017-07-04 16:37 - 000631880 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2018-01-04 00:50 - 2017-07-04 16:37 - 000450352 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2018-01-04 00:50 - 2017-07-04 16:37 - 000123704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2018-01-04 00:50 - 2017-07-04 16:37 - 000081992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-12-30 06:39 - 2017-06-24 04:53 - 000000000 ____D C:\ProgramData\Package Cache
2017-12-29 15:52 - 2017-06-24 05:47 - 000000000 ____D C:\ProgramData\Intel
2017-12-29 15:19 - 2017-06-24 05:44 - 000000000 ____D C:\Program Files\Intel
2017-12-25 07:28 - 2017-06-28 17:54 - 000000000 ___RD C:\Users\Fedorovi\Creative Cloud Files
2017-12-24 20:07 - 2017-07-04 16:37 - 007928821 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-12-23 15:47 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-12-14 13:02 - 2017-12-02 08:45 - 000000000 ____D C:\Users\Fedorovi\AppData\Local\Packages
2017-12-13 18:55 - 2017-12-02 08:38 - 000000000 ____D C:\Windows.old
2017-12-13 17:24 - 2017-06-24 18:20 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-12-13 17:23 - 2017-10-11 14:16 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-12-13 17:23 - 2017-06-24 18:20 - 133326408 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-12-12 19:55 - 2017-12-02 08:58 - 000004506 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater

==================== Files in the root of some directories =======

2017-09-23 06:48 - 2017-10-18 17:06 - 000001206 _____ () C:\Users\Fedorovi\AppData\Roaming\DESKTOP-ESQS67O.MTBF.txt
2017-07-07 08:44 - 2017-07-07 08:44 - 102212096 _____ () C:\Users\Fedorovi\AppData\Roaming\Launcher.dat
2017-07-07 08:44 - 2017-07-07 08:44 - 025289369 _____ () C:\Users\Fedorovi\AppData\Roaming\m.fjk
2017-07-07 08:44 - 2017-07-07 16:19 - 000000009 _____ () C:\Users\Fedorovi\AppData\Roaming\update.dat
2017-09-23 06:50 - 2017-10-14 10:01 - 000005632 _____ () C:\Users\Fedorovi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-07-09 08:07 - 2017-07-24 15:12 - 000007606 _____ () C:\Users\Fedorovi\AppData\Local\Resmon.ResmonCfg

Some files in TEMP:
====================
2018-01-01 09:04 - 2018-01-01 09:04 - 000882176 _____ (System Process Inc.) C:\Users\Fedorovi\AppData\Local\Temp\235023546.exe
2017-12-10 07:21 - 2017-12-15 23:47 - 000759848 _____ (NVIDIA Corporation) C:\Users\Fedorovi\AppData\Local\Temp\nvSCPAPI.dll
2017-12-10 07:21 - 2017-12-15 23:47 - 000874880 _____ (NVIDIA Corporation) C:\Users\Fedorovi\AppData\Local\Temp\nvSCPAPI64.dll
2017-12-30 07:30 - 2017-12-15 23:47 - 000371000 _____ (NVIDIA Corporation) C:\Users\Fedorovi\AppData\Local\Temp\nvStInst.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-01-02 14:09

==================== End of FRST.txt ============================

Re: Adware ve Firefoxu.

Napsal: 10 led 2018 14:02
od ppetr
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.01.2018
Ran by Fedorovi (10-01-2018 13:59:51)
Running from A:\Download
Windows 10 Home Version 1709 16299.192 (X64) (2017-12-02 07:59:40)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1786104691-2426081519-2716709316-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1786104691-2426081519-2716709316-503 - Limited - Disabled)
Fedorovi (S-1-5-21-1786104691-2426081519-2716709316-1001 - Administrator - Enabled) => C:\Users\Fedorovi
Guest (S-1-5-21-1786104691-2426081519-2716709316-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-1786104691-2426081519-2716709316-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.3.0.256 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_1_1) (Version: 18.1.1 - Adobe Systems Incorporated)
Aktualizace NVIDIA 31.0.1.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.0.1.0 - NVIDIA Corporation) Hidden
ASUS GPU TweakII (HKLM-x32\...\{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.4.7.3 - ASUSTek COMPUTER INC.) Hidden
ASUS GPU TweakII (HKLM-x32\...\InstallShield_{0075AAC2-EA9F-490E-83F7-5D5F81EB2A43}) (Version: 1.4.7.3 - ASUSTek COMPUTER INC.)
ASUS Product Register Program (HKLM-x32\...\{C87D79F6-F813-4812-B7A9-CCCAAB8B1188}) (Version: 1.0.031 - ASUSTek Computer Inc.)
AURA(GRAPHICS CARD) (HKLM-x32\...\{3507F3C9-1898-430F-B080-C603373F42D0}) (Version: 0.0.4.1 - )
Blizzard App (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Canon MP210 series (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP210_series) (Version: - )
DiRT 4 (HKLM-x32\...\DiRT 4_is1) (Version: - )
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 390.65 - NVIDIA Corporation) Hidden
Dragon Age: Inquisition (HKLM-x32\...\Dragon Age: Inquisition_is1) (Version: - )
F1 2017 (HKLM-x32\...\F1 2017_is1) (Version: 1.6 - THE KNIGHT)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
HWiNFO64 Version 5.54 (HKLM\...\HWiNFO64_is1) (Version: 5.54 - Martin Malík - REALiX)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.7.0.1028 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.7.1.1015 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{e81fcd9c-17cd-4fff-b3ac-e3b258dd998c}) (Version: 10.1.1.32 - Intel(R) Corporation) Hidden
IPTInstaller (HKLM-x32\...\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Malwarebytes verze 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
Microsoft Games for Windows - LIVE (HKLM-x32\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{00C5F4F4-62F9-40D7-8000-AD8A9CD0C669}) (Version: 3.1.99.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mortal Kombat XL (HKLM-x32\...\Mortal Kombat XL_is1) (Version: - )
Mozilla Firefox 57.0.4 (x64 cs) (HKLM\...\Mozilla Firefox 57.0.4 (x64 cs)) (Version: 57.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 54.0.1 - Mozilla)
NVIDIA GeForce Experience 3.11.0.73 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.11.0.73 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 390.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 390.65 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.36.6 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.36.6 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 390.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 390.65 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
OpenAL (HKLM-x32\...\OpenAL) (Version: - )
OpenOffice 4.1.3 (HKLM-x32\...\{7308600A-5231-459C-A3E2-A637F842CACA}) (Version: 4.13.9783 - Apache Software Foundation)
Ovládací panel NVIDIA 390.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 390.65 - NVIDIA Corporation) Hidden
Pinnacle Studio 20 (HKLM\...\{4D548AFA-B83A-4C39-A474-AAE833B320AD}) (Version: 20.5.0.295 - Corel Corporation)
Pomocník při upgradu na Windows 10 (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.22175 - Microsoft Corporation)
Rapture3D 2.4.4 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version: - Blue Ripple Sound)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8158 - Realtek Semiconductor Corp.)
Resident Evil 0 HD Remaster (HKLM-x32\...\Resident Evil 0 HD Remaster_is1) (Version: - )
Resident Evil 7 Biohazard (HKLM-x32\...\{1ECBF8F3-7079-44CA-AD32-B2AECBCF636F}_is1) (Version: - Capcom)
Resident Evil HD Remaster (HKLM-x32\...\Resident Evil HD Remaster_is1) (Version: - )
Seznam Software (HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\SeznamInstall) (Version: 2.1.29 - Seznam.cz)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
Vulkan Run Time Libraries 1.0.65.0 (HKLM\...\VulkanRT1.0.65.0) (Version: 1.0.65.0 - LunarG, Inc.) Hidden
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)
XSplit Gamecaster (HKLM-x32\...\{86D10763-A1F2-45A4-814C-3BDE40458C7E}) (Version: 3.0.1705.3128 - SplitmediaLabs)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-B85706A67B3C}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ContextMenuHandlers1: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => A:\Programs\Winrar\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => A:\Programs\Winrar\rarext32.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers2: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => A:\Programs\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers4: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-01-04] (NVIDIA Corporation)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2017-09-26] ()
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => A:\Programs\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => A:\Programs\Winrar\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => A:\Programs\Winrar\rarext32.dll [2016-08-14] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {061FEF69-9F62-4CCD-ACC1-29551357F7C8} - System32\Tasks\Stenougrade Monitor Free => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Stenougrade Monitor Free\Stenougrade Monitor Free.dll",dlWLLLaTbRy <==== ATTENTION
Task: {0DEFF955-D8A5-411C-8323-7F12885A7C5A} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-ESQS67O-Fedorovi => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {1A9031FA-0C46-4D6B-AA6D-EFF095CA8D13} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-08] (Microsoft Corporation)
Task: {2B7E9968-E071-4874-A653-FFC0A2018119} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-11-16] (NVIDIA Corporation)
Task: {3DA4B8D1-55BB-41B3-954C-E8FC1E24E81C} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-11-16] (NVIDIA Corporation)
Task: {4B7D4DB5-B534-4A50-AAB4-62EFA3EA8821} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-08] (Microsoft Corporation)
Task: {4BCECE29-6189-417C-B395-5E357F9C1205} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {4C6FA581-E44D-42DD-9A2D-3F0C4B7F2AA2} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-11-16] (NVIDIA Corporation)
Task: {55A736E0-6DE0-4A20-B428-09C740ABAD46} - System32\Tasks\GPU Tweak II => C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe [2017-06-20] (TODO: <Company name>)
Task: {628926C7-536F-4144-9297-BB1855604AF2} - System32\Tasks\ASUS Live Update Task Schedule => C:\Program Files (x86)\ASUS\GPU Tweak\ASUSLiveUpdate.exe
Task: {66024546-C97F-4170-8481-F598061AADBF} - System32\Tasks\AURA => C:\Program Files (x86)\ASUS\AURA(GRAPHICS CARD)\ledcontrolservice.exe
Task: {7C58F03F-2625-4CC6-919F-6E6404A6F174} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-11-16] (NVIDIA Corporation)
Task: {99900023-089D-4C75-A5D9-6EBDB48E7B2D} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-11-16] (NVIDIA Corporation)
Task: {A8A21DE2-893F-4ED6-B194-54B02546CB8F} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-11-16] (NVIDIA Corporation)
Task: {B9707671-BE8C-4CEE-8906-BB34C856DDA7} - System32\Tasks\ASUS\ASUS Product Register Service => C:\Program Files (x86)\ASUS\APRP\aprp.exe [2015-05-18] ()
Task: {B9DF67A3-16FA-4DFC-ACBB-CA0766523EF7} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-11-16] (NVIDIA Corporation)
Task: {BCDF386E-7348-4294-8F75-2E67840741C0} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-08] (Microsoft Corporation)
Task: {C9D1E640-6852-4E86-AE13-D7398E4F13F0} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {E682C18B-1AB5-401A-B8CA-F27403224216} - System32\Tasks\Intel PTT EK Recertification => C:\Program Files\Intel\iCLS Client\IntelPTTEKRecertification.exe [2017-02-24] (Intel(R) Corporation)
Task: {F25EDFA2-30AD-413E-9BAA-F4B022334676} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.17123-0\MpCmdRun.exe [2017-12-08] (Microsoft Corporation)
Task: {FD09BCE5-82AF-4DD0-B022-DB7DE36B9BA9} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-10] (Adobe Systems Incorporated)
Task: {FE4EE9CD-A0BA-4075-8568-EFCBAAA1CDF8} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-11-16] (NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-01-09 17:27 - 2018-01-04 02:44 - 000544056 _____ () C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem\DisplayDriverAnalyzer\_DisplayDriverCrashAnalyzer64.dll
2017-09-17 13:39 - 2015-05-08 07:26 - 000936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2017-09-17 13:39 - 2014-04-24 07:29 - 001360016 _____ () C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.22\AsSysCtrlService.exe
2017-06-25 06:06 - 2017-11-16 02:41 - 001267136 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2013-10-17 14:27 - 2013-10-17 14:27 - 000166912 _____ () C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe
2017-09-26 01:52 - 2017-09-26 01:52 - 000491600 _____ () C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
2015-05-18 09:45 - 2015-05-18 09:45 - 001552544 _____ () C:\Program Files (x86)\ASUS\APRP\aprp.exe
2017-12-02 08:07 - 2017-12-02 08:07 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-12-02 08:07 - 2017-12-02 08:07 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-01-09 12:24 - 2018-01-09 12:25 - 000061952 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.11.0_x64__8wekyb3d8bbwe\WinStoreTasksWrapper.dll
2018-01-03 13:57 - 2018-01-03 14:00 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-01-03 13:57 - 2018-01-03 14:00 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-01-03 13:57 - 2018-01-03 14:00 - 024670720 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-01-03 13:57 - 2018-01-03 14:00 - 002550272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.257.0_x64__kzf8qxf38zg5c\skypert.dll
2017-07-07 11:02 - 2013-05-16 14:25 - 001062472 _____ () C:\Users\Fedorovi\AppData\Roaming\Seznam.cz\szninstall.exe
2017-09-26 01:52 - 2017-09-26 01:52 - 034879568 _____ () C:\Program Files (x86)\Adobe\Adobe Sync\Coresync\Coresync.exe
2017-09-17 13:39 - 2018-01-10 13:55 - 000035624 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2017-09-17 13:39 - 2015-05-08 07:26 - 000104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2017-02-09 09:39 - 2017-02-09 09:39 - 000065536 _____ () C:\Program Files (x86)\ASUS\GPU TweakII\Exeio.dll
2017-06-02 13:11 - 2017-06-02 13:11 - 001753600 _____ () C:\Program Files (x86)\ASUS\GPU TweakII\Vender.dll
2017-06-25 06:06 - 2017-11-16 02:41 - 001040320 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-12-03 07:00 - 2017-12-03 07:00 - 000102088 _____ () C:\Users\Fedorovi\AppData\Local\Microsoft\OneDrive\17.3.7131.1115\UpdateRingSettings.dll
2017-05-18 08:02 - 2017-05-18 08:02 - 040524400 _____ () C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\libcef.dll
2017-09-20 01:42 - 2017-09-20 01:42 - 067115616 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
2017-09-06 17:11 - 2017-09-06 17:11 - 000118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node
2017-09-06 17:11 - 2017-09-06 17:11 - 000214528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2017-09-06 17:11 - 2017-09-06 17:11 - 000117248 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node
2017-09-06 17:11 - 2017-09-06 17:11 - 000125952 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node
2017-09-20 02:04 - 2017-09-20 02:04 - 000099424 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin.dll
2017-09-06 17:11 - 2017-09-06 17:11 - 000086528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node
2017-06-05 23:23 - 2017-06-05 23:23 - 001244304 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 12:47 - 2017-07-07 11:06 - 000000865 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1 plugpackdownload.net
127.0.0.1 dscdn.pw

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\Control Panel\Desktop\\Wallpaper -> A:\Kleirou\Fotky\Plumlov 15.10.2016\IMG_0147.JPG
DNS Servers: 178.22.112.22 - 178.22.118.10
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run32: => "iSkysoft Helper Compact.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D727F91A-929C-4C7F-A4D3-F4E49ED95292}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [UDP Query User{E69A0A24-2F03-451E-B534-38F2D4DFE4EB}C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [TCP Query User{A916C501-A99A-4035-92B9-25CC1034AB0B}C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_151\bin\javaw.exe
FirewallRules: [UDP Query User{725FE6E9-E2EE-4624-A6C2-D56DB12B55F8}A:\hry\divinity - original sin 2\bin\eocapp.exe] => (Block) A:\hry\divinity - original sin 2\bin\eocapp.exe
FirewallRules: [TCP Query User{41F3604A-4B35-4DFD-8F11-2FEF90AC6A86}A:\hry\divinity - original sin 2\bin\eocapp.exe] => (Block) A:\hry\divinity - original sin 2\bin\eocapp.exe
FirewallRules: [{BAB48C81-22EF-41C3-8BEA-5463B9B73A2E}] => (Allow) A:\Programs\Pinneacle studio 20\programs\UMI.exe
FirewallRules: [{80484E34-6C1F-4F74-AEBD-FDEFB66E50C5}] => (Allow) A:\Programs\Pinneacle studio 20\programs\UMI.exe
FirewallRules: [{1FE30C2E-5EFA-411D-9CB3-89FB2A16B086}] => (Allow) A:\Programs\Pinneacle studio 20\programs\NGStudio.exe
FirewallRules: [{3D97AF65-849C-4828-BA48-E8AF021F4647}] => (Allow) A:\Programs\Pinneacle studio 20\programs\NGStudio.exe
FirewallRules: [{D3A3C064-E0FF-4BC2-A841-21BDF46C4F6D}] => (Allow) A:\Programs\Pinneacle studio 20\programs\RM.exe
FirewallRules: [{869FE1B3-44D3-4A28-8CEC-B518E67E161D}] => (Allow) A:\Programs\Pinneacle studio 20\programs\RM.exe
FirewallRules: [{2C6D1F8C-2DB9-4059-A5B6-20F255F7D53F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{8F5902F3-BCD2-4A27-B011-BE4089EC5D65}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F315BA4D-4662-4833-81D1-29FE97878C64}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{B9FDAA28-0DCE-45CD-B013-8D01D9AD9034}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [UDP Query User{C69B3D91-CAA0-4C4F-A323-E26CEA759F67}C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe
FirewallRules: [TCP Query User{21290B18-F0E9-4BB5-A07D-6312817D0F37}C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_144\bin\javaw.exe
FirewallRules: [UDP Query User{4CADEBE2-58AE-47CD-98EA-21A823A88444}A:\programs\droidjoy server\droidjoyserver.exe] => (Allow) A:\programs\droidjoy server\droidjoyserver.exe
FirewallRules: [TCP Query User{6E2DC936-E6CB-4C66-A0C1-D02279128C6E}A:\programs\droidjoy server\droidjoyserver.exe] => (Allow) A:\programs\droidjoy server\droidjoyserver.exe
FirewallRules: [UDP Query User{32AFA2AD-A844-4B2D-907C-A1F3D07EF23A}A:\games\mortal kombat xl\binaries\retail\mk10.exe] => (Allow) A:\games\mortal kombat xl\binaries\retail\mk10.exe
FirewallRules: [TCP Query User{BA026EC8-AE45-418C-A24E-75365D52A471}A:\games\mortal kombat xl\binaries\retail\mk10.exe] => (Allow) A:\games\mortal kombat xl\binaries\retail\mk10.exe
FirewallRules: [{933CF0A4-1D1F-4CE4-9A4C-E15ABC36047E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2CD46A88-B38C-46F6-9318-23EACB70327A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{56438277-D167-43AA-A48A-241BB8D93AEA}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{AAEB3D8B-7A98-417C-B0FD-5EE3D232B159}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{9B390FD1-BAF9-4963-ACBC-36B29AA183D9}] => (Allow) C:\program files (x86)\common files\tencent\qqdownload\130\tencentdl.exe
FirewallRules: [{046E8FF4-7B2E-4BE0-A075-5E0C3450B261}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [UDP Query User{BD27B043-F03E-40BA-B877-0348933962AF}A:\programs\java\launch4j-tmp\frd.exe] => (Allow) A:\programs\java\launch4j-tmp\frd.exe
FirewallRules: [TCP Query User{FBC32753-05FB-4218-854E-AE88DCF8B291}A:\programs\java\launch4j-tmp\frd.exe] => (Allow) A:\programs\java\launch4j-tmp\frd.exe
FirewallRules: [{5C397735-D8FA-4923-AC4A-5216EFF5018A}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Gamecaster\XSplit.Gamecaster.exe
FirewallRules: [{C6DF10F1-3939-4539-BE0B-B4E636CF6335}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Gamecaster\XSplit.Gamecaster.exe
FirewallRules: [{D2AC4A8D-8ECC-43F3-906A-AB6C58C45A54}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Gamecaster\XSplit.cam.exe
FirewallRules: [{146CCDFB-5663-4890-B6F7-C372951D25A3}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Gamecaster\XSplit.cam.exe
FirewallRules: [{9BEAFB41-3AAF-4EC2-818B-96A7B7DB74BD}] => (Allow) A:\Programy\Steam.exe
FirewallRules: [{BC89C12A-DCA6-411F-94BC-B389D2B4B275}] => (Allow) A:\Programy\Steam.exe
FirewallRules: [{84249E77-AEA6-4B36-A0BD-F721151C2549}] => (Allow) A:\Programy\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{F39374ED-F30F-4989-8A0C-CD5BBA65747E}] => (Allow) A:\Programy\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{A2373B1E-4DFB-4BEA-9327-04DEBB4B8E15}] => (Allow) A:\Programy\steamapps\common\Dawn of War III\RelicDoW3.exe
FirewallRules: [{0EC7343F-EF35-424A-8E9E-8A1CB29859D2}] => (Allow) A:\Programy\steamapps\common\Dawn of War III\RelicDoW3.exe
FirewallRules: [{AB099027-B4A2-45E1-BFCD-652A96A8661A}] => (Allow) A:\Programs\Steam\Steam.exe
FirewallRules: [{CE36CD76-CDED-4160-A2FA-A8351B166FE4}] => (Allow) A:\Programs\Steam\Steam.exe
FirewallRules: [{D722AA30-581B-4AC9-9739-2B94CABD0852}] => (Allow) A:\Programs\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{5C165691-47F4-4706-B19D-068967A49FB3}] => (Allow) A:\Programs\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{5349D10F-AADE-4736-94A3-1638B6F0E984}A:\programs\steam\steamapps\common\dawn of war iii\relicdow3.exe] => (Allow) A:\programs\steam\steamapps\common\dawn of war iii\relicdow3.exe
FirewallRules: [UDP Query User{3F959601-8272-46B8-93F7-3990CCC5A925}A:\programs\steam\steamapps\common\dawn of war iii\relicdow3.exe] => (Allow) A:\programs\steam\steamapps\common\dawn of war iii\relicdow3.exe
FirewallRules: [{8A2B3974-6850-4FF1-974C-196DA78FDF08}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{6B3E1C05-D906-4133-9091-965ACE27CAA8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{1752FD2E-6327-401D-9624-7D3FC3A84490}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{28416376-EBDF-4944-8D50-FF41170781AD}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{863F55BF-51E5-4F8C-995C-F6DEB809EC71}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{3B0EED9F-9324-488E-8293-12A531B9D0CB}A:\hry\hearthstone\hearthstone.exe] => (Allow) A:\hry\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{75D03BED-70BA-4DEF-8FF1-859C25B333D7}A:\hry\hearthstone\hearthstone.exe] => (Allow) A:\hry\hearthstone\hearthstone.exe
FirewallRules: [{25549846-0A96-4AC7-96D6-58085FC9A0CD}] => (Allow) A:\Hry\NFS HP\Launcher.exe
FirewallRules: [{5042168E-C96D-48FD-B140-A743C6C55E9A}] => (Allow) A:\Hry\NFS HP\Launcher.exe
FirewallRules: [{5079C31D-1147-4992-870D-EF1F2B5AFA67}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{5096EA30-FE70-4415-8CDE-71D91985C3D1}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UbisoftGameLauncher.exe
FirewallRules: [{B1AFDF11-3004-4BE1-A883-E6850C8AA9EF}] => (Allow) C:\Users\Fedorovi\AppData\Roaming\SystemProcess\SystemProcess.exe
FirewallRules: [{CAF43793-29E8-4C9B-A6DF-F9E2B70578AF}] => (Allow) C:\Users\Fedorovi\AppData\Roaming\SystemProcess\SystemProcess.exe
FirewallRules: [TCP Query User{61A0DAC0-31DC-4216-A35B-BC9338824379}A:\hry\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe] => (Block) A:\hry\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe
FirewallRules: [UDP Query User{8D14146E-A8E3-4905-8524-862D37921D2B}A:\hry\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe] => (Block) A:\hry\the vanishing of ethan carter\binaries\win64\astronautsgame-win64-shipping.exe

==================== Restore Points =========================

ATTENTION: System Restore is disabled

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/09/2018 04:49:24 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program NVStWiz.exe verze 7.17.13.8871 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 1820

Čas spuštění: 01d38961413284cb

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NVStWiz.exe

ID hlášení: d6d8eda5-924b-4291-bf81-55f4d82e38e7

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (01/09/2018 04:26:25 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program NVStWiz.exe verze 7.17.13.8871 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 1900

Čas spuštění: 01d3895e0a1b092a

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NVStWiz.exe

ID hlášení: 1de89fc8-634f-4a5d-bb2e-70b391297901

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (01/07/2018 08:29:08 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: GPUTweakII.exe, verze: 1.4.7.3, časové razítko: 0x5948d4d8
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000
ID chybujícího procesu: 0x17e4
Čas spuštění chybující aplikace: 0x01d387890e7663f4
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
Cesta k chybujícímu modulu: unknown
ID zprávy: 978c9396-109b-46a2-bfa1-6f31bb9c3b73
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (01/04/2018 01:54:05 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_InstallService, verze: 10.0.16299.15, časové razítko: 0x9c786b9a
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.16299.125, časové razítko: 0x70f70cc4
Kód výjimky: 0xc0000409
Posun chyby: 0x000000000006b70e
ID chybujícího procesu: 0x2394
Čas spuštění chybující aplikace: 0x01d3850d8e78d087
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID zprávy: c06276c2-6aa4-4a42-857d-a29b19ff881b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (01/03/2018 02:00:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: svchost.exe_InstallService, verze: 10.0.16299.15, časové razítko: 0x9c786b9a
Název chybujícího modulu: ucrtbase.dll, verze: 10.0.16299.125, časové razítko: 0x70f70cc4
Kód výjimky: 0xc0000409
Posun chyby: 0x000000000006b70e
ID chybujícího procesu: 0x1b08
Čas spuštění chybující aplikace: 0x01d384444772d93f
Cesta k chybující aplikaci: C:\WINDOWS\System32\svchost.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\ucrtbase.dll
ID zprávy: c3b19a7a-743e-45cf-8586-245d08e6541d
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (01/02/2018 02:43:51 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program Hearthstone.exe verze 10.0.0.22611 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 2128

Čas spuštění: 01d383cf5ae04a47

Čas ukončení: 9

Cesta k aplikaci: A:\Hry\Hearthstone\Hearthstone.exe

ID hlášení: 31fdf79c-c167-41a7-9ba2-64faec58f026

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (12/31/2017 02:08:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Settlers7R.exe, verze: 1.12.1396.0, časové razítko: 0x4d8744d4
Název chybujícího modulu: ntdll.dll, verze: 10.0.16299.64, časové razítko: 0xac8afc81
Kód výjimky: 0xc0000409
Posun chyby: 0x00041af0
ID chybujícího procesu: 0x73c
Čas spuštění chybující aplikace: 0x01d38235c5c846e2
Cesta k chybující aplikaci: A:\Hry\Settlers 7\Data\Base\_Dbg\Bin\Release\Settlers7R.exe
Cesta k chybujícímu modulu: C:\WINDOWS\SYSTEM32\ntdll.dll
ID zprávy: d622973e-a7c5-4b90-a96f-b505a195b161
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (12/30/2017 07:35:28 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program NVStWiz.exe verze 7.17.13.8871 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 83c

Čas spuštění: 01d38138120821de

Čas ukončení: 4294967295

Cesta k aplikaci: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\NVStWiz.exe

ID hlášení: ff7409e6-0aa8-43e5-9fe3-60f4a96d9c60

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (12/29/2017 03:19:27 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: Procedura Open pro službu BITS v knihovně DLL C:\Windows\System32\bitsperf.dll se nezdařila. Výkonnostní data pro tuto službu nebudou k dispozici. Vrácený kód stavu představují první čtyři bajty (DWORD) datové části.

Error: (12/25/2017 07:29:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: GPUTweakII.exe, verze: 1.4.7.3, časové razítko: 0x5948d4d8
Název chybujícího modulu: GPUTweakII.exe, verze: 1.4.7.3, časové razítko: 0x5948d4d8
Kód výjimky: 0xc0000005
Posun chyby: 0x000b633a
ID chybujícího procesu: 0x52a0
Čas spuštění chybující aplikace: 0x01d37d4973718130
Cesta k chybující aplikaci: C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
Cesta k chybujícímu modulu: C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
ID zprávy: 1169b032-7142-4ec1-8d6b-17307d73c99a
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (01/10/2018 01:54:53 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-ESQS67O)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA Display Container LS byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 1000 milisekund: Restartovat službu.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba AdobeUpdateService byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Intel(R) Dynamic Application Loader Host Interface Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba ASUS Com Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA Telemetry Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 1000 milisekund: Restartovat službu.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Adobe Genuine Software Integrity Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Internet Pass-Through Service byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 1000 milisekund: Restartovat službu.

Error: (01/10/2018 01:54:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba ASUS System Control Service byla neočekávaně ukončena. Tento stav nastal již 1krát.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-6700 CPU @ 3.40GHz
Percentage of memory in use: 17%
Total physical RAM: 16329.32 MB
Available physical RAM: 13506.6 MB
Total Virtual: 18761.32 MB
Available Virtual: 15682.88 MB

==================== Drives ================================

Drive a: (Místní disk) (Fixed) (Total:833.86 GB) (Free:571.06 GB) NTFS
Drive c: () (Fixed) (Total:97.1 GB) (Free:47.24 GB) NTFS
Drive i: (HTC Sync Manager) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

Re: Adware ve Firefoxu.

Napsal: 10 led 2018 14:07
od ppetr
Už po prvním scanu, FRST, se reklamy neobjevují. Zřejmě to stačilo :D .
Je to už všechno, nebo bych měl ještě něco udělat?

Děkuji za radu.

Re: Adware ve Firefoxu.

Napsal: 10 led 2018 15:09
od Rudy
Ještě dočistíme. Otevřte poznámkový blok a zkopírujte do něj:
Start
CustomCLSID: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-B85706A67B3C}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
ContextMenuHandlers1: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers2: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers4: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
Task: {061FEF69-9F62-4CCD-ACC1-29551357F7C8} - System32\Tasks\Stenougrade Monitor Free => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Stenougrade Monitor Free\Stenougrade Monitor Free.dll",dlWLLLaTbRy <==== ATTENTION
Task: {4BCECE29-6189-417C-B395-5E357F9C1205} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\MountPoints2: {5977a24a-b02b-11e7-858e-2c4d54569ba0} - "I:\HTC_Sync_Manager_PC.exe"
GroupPolicy: Restriction - Windows Defender <==== ATTENTION
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> DefaultScope {5CE25775-92B7-477d-9603-852F0B34D8B0} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... &pc=MSERT1
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> {5CE25775-92B7-477d-9603-852F0B34D8B0} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... &pc=MSERT1
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> {8ACD20D1-E475-4D00-A706-CBDA4685C337} URL =
FF Plugin HKU\S-1-5-21-1786104691-2426081519-2716709316-1001: ubisoft.com/uplaypc -> A:\Hry\Settlers 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [No File]
S1 bemszcafb.sys; C:\WINDOWS\system32\drivers\bemszcafb.sys [7712 2017-11-27] () [File not signed]
S1 bogqlyryb.sys; C:\WINDOWS\system32\drivers\bogqlyryb.sys [7712 2017-11-24] () [File not signed]
S1 cqctmvzng.sys; C:\WINDOWS\system32\drivers\cqctmvzng.sys [7712 2017-11-18] () [File not signed]
S1 ctoofsmoa.sys; C:\WINDOWS\system32\drivers\ctoofsmoa.sys [7712 2017-11-17] () [File not signed]
S1 cuuzkpsfk.sys; C:\WINDOWS\system32\drivers\cuuzkpsfk.sys [7712 2017-11-25] () [File not signed]
S1 dbprghlhs.sys; C:\WINDOWS\system32\drivers\dbprghlhs.sys [7712 2017-11-26] () [File not signed]
S1 dekyvudve.sys; C:\WINDOWS\system32\drivers\dekyvudve.sys [142760 2017-11-15] () [File not signed]
S1 devxiwfkv.sys; C:\WINDOWS\system32\drivers\devxiwfkv.sys [7712 2017-12-02] () [File not signed]
S0 dgsjfiqr.sys; C:\WINDOWS\System32\drivers\dgsjfiqr.sys [904104 2018-01-01] () [File not signed]
S1 dqwnqlplj.sys; C:\WINDOWS\system32\drivers\dqwnqlplj.sys [7712 2017-11-08] () [File not signed]
S1 dsxhokbii.sys; C:\WINDOWS\system32\drivers\dsxhokbii.sys [7712 2017-11-13] () [File not signed]
S1 dzskyxbvb.sys; C:\WINDOWS\system32\drivers\dzskyxbvb.sys [7712 2017-11-28] () [File not signed]
S1 eavkldyag.sys; C:\WINDOWS\system32\drivers\eavkldyag.sys [7712 2017-11-30] () [File not signed]
S1 ejpgbrgry.sys; C:\WINDOWS\system32\drivers\ejpgbrgry.sys [7712 2017-11-11] () [File not signed]
S1 fckodwrar.sys; C:\WINDOWS\system32\drivers\fckodwrar.sys [7712 2017-11-14] () [File not signed]
S1 fdftoylto.sys; C:\WINDOWS\system32\drivers\fdftoylto.sys [7712 2017-11-19] () [File not signed]
S1 gitutnzyg.sys; C:\WINDOWS\system32\drivers\gitutnzyg.sys [7712 2017-11-18] () [File not signed]
S1 gnadttrzp.sys; C:\WINDOWS\system32\drivers\gnadttrzp.sys [7712 2017-11-27] () [File not signed]
S1 gnqzjjlpt.sys; C:\WINDOWS\system32\drivers\gnqzjjlpt.sys [7712 2017-11-02] () [File not signed]
R3 GPUIO; C:\Program Files (x86)\ASUS\GPU TweakII\690b33e1-0462-4e84-9bea-c7552b45432a.sys [27120 2018-01-10] ()
S1 hfksobcgy.sys; C:\WINDOWS\system32\drivers\hfksobcgy.sys [7712 2017-11-04] () [File not signed]
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [27552 2017-08-06] (REALiX(tm))
S1 iajekjhzs.sys; C:\WINDOWS\system32\drivers\iajekjhzs.sys [7712 2017-11-18] () [File not signed]
S1 ikffgqzyq.sys; C:\WINDOWS\system32\drivers\ikffgqzyq.sys [7712 2017-12-01] () [File not signed]
R3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2017-05-08] (ASUSTeK Computer Inc.)
S1 jbjtpsvjp.sys; C:\WINDOWS\system32\drivers\jbjtpsvjp.sys [7712 2017-11-12] () [File not signed]
S1 jsifawipr.sys; C:\WINDOWS\system32\drivers\jsifawipr.sys [7712 2017-10-31] () [File not signed]
S1 mdyvbjunl.sys; C:\WINDOWS\system32\drivers\mdyvbjunl.sys [15424 2017-08-06] () [File not signed]
S1 mivujvbcw.sys; C:\WINDOWS\system32\drivers\mivujvbcw.sys [7712 2017-10-31] () [File not signed]
S1 mrzcjjceb.sys; C:\WINDOWS\system32\drivers\mrzcjjceb.sys [7712 2018-01-10] () [File not signed]
R1 mtunnbbvg.sys; C:\WINDOWS\system32\drivers\mtunnbbvg.sys [142760 2018-01-10] () [File not signed]
S1 namccznua.sys; C:\WINDOWS\system32\drivers\namccznua.sys [7712 2017-11-03] () [File not signed]
S1 ofierptfj.sys; C:\WINDOWS\system32\drivers\ofierptfj.sys [15424 2017-08-06] () [File not signed]
S0 pbwckpzo.sys; C:\WINDOWS\System32\drivers\pbwckpzo.sys [15440 2018-01-01] (Acer Laboratories Inc.)
S1 pfchccpjf.sys; C:\WINDOWS\system32\drivers\pfchccpjf.sys [7712 2017-11-22] () [File not signed]
S1 pgmtoudyn.sys; C:\WINDOWS\system32\drivers\pgmtoudyn.sys [7712 2017-11-05] () [File not signed]
R0 pkkjmqev.sys; C:\WINDOWS\System32\drivers\pkkjmqev.sys [904104 2018-01-01] () [File not signed]
S1 plwhmuliy.sys; C:\WINDOWS\system32\drivers\plwhmuliy.sys [7712 2017-11-02] () [File not signed]
S1 poekcoojk.sys; C:\WINDOWS\system32\drivers\poekcoojk.sys [15424 2017-07-27] () [File not signed]
S1 ppctndrks.sys; C:\WINDOWS\system32\drivers\ppctndrks.sys [7712 2017-11-09] () [File not signed]
S1 pskricapm.sys; C:\WINDOWS\system32\drivers\pskricapm.sys [7712 2017-11-18] () [File not signed]
S1 qgcftitqz.sys; C:\WINDOWS\system32\drivers\qgcftitqz.sys [15424 2017-08-06] () [File not signed]
S1 qjfajkcpq.sys; C:\WINDOWS\system32\drivers\qjfajkcpq.sys [7712 2017-11-25] () [File not signed]
S1 qkvmaioxc.sys; C:\WINDOWS\system32\drivers\qkvmaioxc.sys [7712 2017-12-01] () [File not signed]
S1 qrymmgucq.sys; C:\WINDOWS\system32\drivers\qrymmgucq.sys [7712 2017-10-31] () [File not signed]
S1 qswpbwjmv.sys; C:\WINDOWS\system32\drivers\qswpbwjmv.sys [7712 2017-11-02] () [File not signed]
S1 runcqaaii.sys; C:\WINDOWS\system32\drivers\runcqaaii.sys [7712 2017-11-29] () [File not signed]
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [41512 2017-12-07] ()
S1 tlyxkongt.sys; C:\WINDOWS\system32\drivers\tlyxkongt.sys [15424 2017-07-26] () [File not signed]
S1 ubxdpiopr.sys; C:\WINDOWS\system32\drivers\ubxdpiopr.sys [7712 2018-01-06] () [File not signed]
S1 uwtjuzxqo.sys; C:\WINDOWS\system32\drivers\uwtjuzxqo.sys [7712 2017-11-16] () [File not signed]
S1 vbziccmil.sys; C:\WINDOWS\system32\drivers\vbziccmil.sys [7712 2017-11-20] () [File not signed]
S1 vnjnxllxc.sys; C:\WINDOWS\system32\drivers\vnjnxllxc.sys [7712 2017-11-15] () [File not signed]
S1 vnwlzfuap.sys; C:\WINDOWS\system32\drivers\vnwlzfuap.sys [7712 2017-11-06] () [File not signed]
S1 vqrwxlxnu.sys; C:\WINDOWS\system32\drivers\vqrwxlxnu.sys [7712 2017-11-01] () [File not signed]
S1 vrraekqwa.sys; C:\WINDOWS\system32\drivers\vrraekqwa.sys [15424 2017-08-06] () [File not signed]
S1 vxfeoyqku.sys; C:\WINDOWS\system32\drivers\vxfeoyqku.sys [15424 2017-07-07] () [File not signed]
S1 vysgcoiqn.sys; C:\WINDOWS\system32\drivers\vysgcoiqn.sys [7712 2017-11-03] () [File not signed]
S1 wpinwbetm.sys; C:\WINDOWS\system32\drivers\wpinwbetm.sys [7712 2017-11-21] () [File not signed]
S1 xbcgiypin.sys; C:\WINDOWS\system32\drivers\xbcgiypin.sys [7712 2017-11-01] () [File not signed]
S1 xgsfbmoos.sys; C:\WINDOWS\system32\drivers\xgsfbmoos.sys [7712 2017-11-18] () [File not signed]
S1 xiewtpbkl.sys; C:\WINDOWS\system32\drivers\xiewtpbkl.sys [7712 2017-12-13] () [File not signed]
S1 yxixaooko.sys; C:\WINDOWS\system32\drivers\yxixaooko.sys [7712 2017-11-01] () [File not signed]
S1 zibaqtkwt.sys; C:\WINDOWS\system32\drivers\zibaqtkwt.sys [7712 2017-11-07] () [File not signed]
S1 zunfgmfni.sys; C:\WINDOWS\system32\drivers\zunfgmfni.sys [7712 2017-11-23] () [File not signed]
C:\WINDOWS\system32\Drivers\pkkjmqev.sys
C:\WINDOWS\system32\Drivers\dgsjfiqr.sys
C:\WINDOWS\system32\Drivers\ykyusygrf.sys
C:\WINDOWS\system32\Drivers\xiewtpbkl.sys
C:\Users\Fedorovi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\Fedorovi\AppData\Local\Temp

EmptyTemp:
ResetHosts:
End
Uložte do A:\Download jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Adware ve Firefoxu.

Napsal: 10 led 2018 15:47
od ppetr
Fix result of Farbar Recovery Scan Tool (x64) Version: 02.01.2018
Ran by Fedorovi (10-01-2018 15:42:12) Run:1
Running from A:\Download
Loaded Profiles: Fedorovi (Available Profiles: Fedorovi)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CustomCLSID: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-B85706A67B3C}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
ContextMenuHandlers1: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers2: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
ContextMenuHandlers4: [duba_64bit] -> {DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => -> No File
Task: {061FEF69-9F62-4CCD-ACC1-29551357F7C8} - System32\Tasks\Stenougrade Monitor Free => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Stenougrade Monitor Free\Stenougrade Monitor Free.dll",dlWLLLaTbRy <==== ATTENTION
Task: {4BCECE29-6189-417C-B395-5E357F9C1205} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\...\MountPoints2: {5977a24a-b02b-11e7-858e-2c4d54569ba0} - "I:\HTC_Sync_Manager_PC.exe"
GroupPolicy: Restriction - Windows Defender <==== ATTENTION
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> DefaultScope {5CE25775-92B7-477d-9603-852F0B34D8B0} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... &pc=MSERT1
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> {5CE25775-92B7-477d-9603-852F0B34D8B0} URL = hxxp://www.bing.com/search?q={searchTerms}&for ... &pc=MSERT1
SearchScopes: HKU\S-1-5-21-1786104691-2426081519-2716709316-1001 -> {8ACD20D1-E475-4D00-A706-CBDA4685C337} URL =
FF Plugin HKU\S-1-5-21-1786104691-2426081519-2716709316-1001: ubisoft.com/uplaypc -> A:\Hry\Settlers 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll [No File]
S1 bemszcafb.sys; C:\WINDOWS\system32\drivers\bemszcafb.sys [7712 2017-11-27] () [File not signed]
S1 bogqlyryb.sys; C:\WINDOWS\system32\drivers\bogqlyryb.sys [7712 2017-11-24] () [File not signed]
S1 cqctmvzng.sys; C:\WINDOWS\system32\drivers\cqctmvzng.sys [7712 2017-11-18] () [File not signed]
S1 ctoofsmoa.sys; C:\WINDOWS\system32\drivers\ctoofsmoa.sys [7712 2017-11-17] () [File not signed]
S1 cuuzkpsfk.sys; C:\WINDOWS\system32\drivers\cuuzkpsfk.sys [7712 2017-11-25] () [File not signed]
S1 dbprghlhs.sys; C:\WINDOWS\system32\drivers\dbprghlhs.sys [7712 2017-11-26] () [File not signed]
S1 dekyvudve.sys; C:\WINDOWS\system32\drivers\dekyvudve.sys [142760 2017-11-15] () [File not signed]
S1 devxiwfkv.sys; C:\WINDOWS\system32\drivers\devxiwfkv.sys [7712 2017-12-02] () [File not signed]
S0 dgsjfiqr.sys; C:\WINDOWS\System32\drivers\dgsjfiqr.sys [904104 2018-01-01] () [File not signed]
S1 dqwnqlplj.sys; C:\WINDOWS\system32\drivers\dqwnqlplj.sys [7712 2017-11-08] () [File not signed]
S1 dsxhokbii.sys; C:\WINDOWS\system32\drivers\dsxhokbii.sys [7712 2017-11-13] () [File not signed]
S1 dzskyxbvb.sys; C:\WINDOWS\system32\drivers\dzskyxbvb.sys [7712 2017-11-28] () [File not signed]
S1 eavkldyag.sys; C:\WINDOWS\system32\drivers\eavkldyag.sys [7712 2017-11-30] () [File not signed]
S1 ejpgbrgry.sys; C:\WINDOWS\system32\drivers\ejpgbrgry.sys [7712 2017-11-11] () [File not signed]
S1 fckodwrar.sys; C:\WINDOWS\system32\drivers\fckodwrar.sys [7712 2017-11-14] () [File not signed]
S1 fdftoylto.sys; C:\WINDOWS\system32\drivers\fdftoylto.sys [7712 2017-11-19] () [File not signed]
S1 gitutnzyg.sys; C:\WINDOWS\system32\drivers\gitutnzyg.sys [7712 2017-11-18] () [File not signed]
S1 gnadttrzp.sys; C:\WINDOWS\system32\drivers\gnadttrzp.sys [7712 2017-11-27] () [File not signed]
S1 gnqzjjlpt.sys; C:\WINDOWS\system32\drivers\gnqzjjlpt.sys [7712 2017-11-02] () [File not signed]
R3 GPUIO; C:\Program Files (x86)\ASUS\GPU TweakII\690b33e1-0462-4e84-9bea-c7552b45432a.sys [27120 2018-01-10] ()
S1 hfksobcgy.sys; C:\WINDOWS\system32\drivers\hfksobcgy.sys [7712 2017-11-04] () [File not signed]
R1 HWiNFO32; C:\WINDOWS\system32\drivers\HWiNFO64A.SYS [27552 2017-08-06] (REALiX(tm))
S1 iajekjhzs.sys; C:\WINDOWS\system32\drivers\iajekjhzs.sys [7712 2017-11-18] () [File not signed]
S1 ikffgqzyq.sys; C:\WINDOWS\system32\drivers\ikffgqzyq.sys [7712 2017-12-01] () [File not signed]
R3 IOMap; C:\WINDOWS\system32\drivers\IOMap64.sys [34064 2017-05-08] (ASUSTeK Computer Inc.)
S1 jbjtpsvjp.sys; C:\WINDOWS\system32\drivers\jbjtpsvjp.sys [7712 2017-11-12] () [File not signed]
S1 jsifawipr.sys; C:\WINDOWS\system32\drivers\jsifawipr.sys [7712 2017-10-31] () [File not signed]
S1 mdyvbjunl.sys; C:\WINDOWS\system32\drivers\mdyvbjunl.sys [15424 2017-08-06] () [File not signed]
S1 mivujvbcw.sys; C:\WINDOWS\system32\drivers\mivujvbcw.sys [7712 2017-10-31] () [File not signed]
S1 mrzcjjceb.sys; C:\WINDOWS\system32\drivers\mrzcjjceb.sys [7712 2018-01-10] () [File not signed]
R1 mtunnbbvg.sys; C:\WINDOWS\system32\drivers\mtunnbbvg.sys [142760 2018-01-10] () [File not signed]
S1 namccznua.sys; C:\WINDOWS\system32\drivers\namccznua.sys [7712 2017-11-03] () [File not signed]
S1 ofierptfj.sys; C:\WINDOWS\system32\drivers\ofierptfj.sys [15424 2017-08-06] () [File not signed]
S0 pbwckpzo.sys; C:\WINDOWS\System32\drivers\pbwckpzo.sys [15440 2018-01-01] (Acer Laboratories Inc.)
S1 pfchccpjf.sys; C:\WINDOWS\system32\drivers\pfchccpjf.sys [7712 2017-11-22] () [File not signed]
S1 pgmtoudyn.sys; C:\WINDOWS\system32\drivers\pgmtoudyn.sys [7712 2017-11-05] () [File not signed]
R0 pkkjmqev.sys; C:\WINDOWS\System32\drivers\pkkjmqev.sys [904104 2018-01-01] () [File not signed]
S1 plwhmuliy.sys; C:\WINDOWS\system32\drivers\plwhmuliy.sys [7712 2017-11-02] () [File not signed]
S1 poekcoojk.sys; C:\WINDOWS\system32\drivers\poekcoojk.sys [15424 2017-07-27] () [File not signed]
S1 ppctndrks.sys; C:\WINDOWS\system32\drivers\ppctndrks.sys [7712 2017-11-09] () [File not signed]
S1 pskricapm.sys; C:\WINDOWS\system32\drivers\pskricapm.sys [7712 2017-11-18] () [File not signed]
S1 qgcftitqz.sys; C:\WINDOWS\system32\drivers\qgcftitqz.sys [15424 2017-08-06] () [File not signed]
S1 qjfajkcpq.sys; C:\WINDOWS\system32\drivers\qjfajkcpq.sys [7712 2017-11-25] () [File not signed]
S1 qkvmaioxc.sys; C:\WINDOWS\system32\drivers\qkvmaioxc.sys [7712 2017-12-01] () [File not signed]
S1 qrymmgucq.sys; C:\WINDOWS\system32\drivers\qrymmgucq.sys [7712 2017-10-31] () [File not signed]
S1 qswpbwjmv.sys; C:\WINDOWS\system32\drivers\qswpbwjmv.sys [7712 2017-11-02] () [File not signed]
S1 runcqaaii.sys; C:\WINDOWS\system32\drivers\runcqaaii.sys [7712 2017-11-29] () [File not signed]
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [41512 2017-12-07] ()
S1 tlyxkongt.sys; C:\WINDOWS\system32\drivers\tlyxkongt.sys [15424 2017-07-26] () [File not signed]
S1 ubxdpiopr.sys; C:\WINDOWS\system32\drivers\ubxdpiopr.sys [7712 2018-01-06] () [File not signed]
S1 uwtjuzxqo.sys; C:\WINDOWS\system32\drivers\uwtjuzxqo.sys [7712 2017-11-16] () [File not signed]
S1 vbziccmil.sys; C:\WINDOWS\system32\drivers\vbziccmil.sys [7712 2017-11-20] () [File not signed]
S1 vnjnxllxc.sys; C:\WINDOWS\system32\drivers\vnjnxllxc.sys [7712 2017-11-15] () [File not signed]
S1 vnwlzfuap.sys; C:\WINDOWS\system32\drivers\vnwlzfuap.sys [7712 2017-11-06] () [File not signed]
S1 vqrwxlxnu.sys; C:\WINDOWS\system32\drivers\vqrwxlxnu.sys [7712 2017-11-01] () [File not signed]
S1 vrraekqwa.sys; C:\WINDOWS\system32\drivers\vrraekqwa.sys [15424 2017-08-06] () [File not signed]
S1 vxfeoyqku.sys; C:\WINDOWS\system32\drivers\vxfeoyqku.sys [15424 2017-07-07] () [File not signed]
S1 vysgcoiqn.sys; C:\WINDOWS\system32\drivers\vysgcoiqn.sys [7712 2017-11-03] () [File not signed]
S1 wpinwbetm.sys; C:\WINDOWS\system32\drivers\wpinwbetm.sys [7712 2017-11-21] () [File not signed]
S1 xbcgiypin.sys; C:\WINDOWS\system32\drivers\xbcgiypin.sys [7712 2017-11-01] () [File not signed]
S1 xgsfbmoos.sys; C:\WINDOWS\system32\drivers\xgsfbmoos.sys [7712 2017-11-18] () [File not signed]
S1 xiewtpbkl.sys; C:\WINDOWS\system32\drivers\xiewtpbkl.sys [7712 2017-12-13] () [File not signed]
S1 yxixaooko.sys; C:\WINDOWS\system32\drivers\yxixaooko.sys [7712 2017-11-01] () [File not signed]
S1 zibaqtkwt.sys; C:\WINDOWS\system32\drivers\zibaqtkwt.sys [7712 2017-11-07] () [File not signed]
S1 zunfgmfni.sys; C:\WINDOWS\system32\drivers\zunfgmfni.sys [7712 2017-11-23] () [File not signed]
C:\WINDOWS\system32\Drivers\pkkjmqev.sys
C:\WINDOWS\system32\Drivers\dgsjfiqr.sys
C:\WINDOWS\system32\Drivers\ykyusygrf.sys
C:\WINDOWS\system32\Drivers\xiewtpbkl.sys
C:\Users\Fedorovi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
C:\Users\Fedorovi\AppData\Local\Temp

EmptyTemp:
ResetHosts:
End
*****************

"HKU\S-1-5-21-1786104691-2426081519-2716709316-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-B85706A67B3C}" => removed successfully
"HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\duba_64bit" => removed successfully
HKLM\Software\Classes\CLSID\{DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => key not found
"HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\duba_64bit" => removed successfully
HKLM\Software\Classes\CLSID\{DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => key not found
"HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\duba_64bit" => removed successfully
HKLM\Software\Classes\CLSID\{DDEA5705-1BB0-4C03-AC1E-8FF9716A0D51} => key not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{061FEF69-9F62-4CCD-ACC1-29551357F7C8} => could not remove key. ErrorCode1: 0x00000002
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{061FEF69-9F62-4CCD-ACC1-29551357F7C8}" => removed successfully
C:\WINDOWS\System32\Tasks\Stenougrade Monitor Free => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Stenougrade Monitor Free" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4BCECE29-6189-417C-B395-5E357F9C1205}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BCECE29-6189-417C-B395-5E357F9C1205}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => key not found
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
"HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5977a24a-b02b-11e7-858e-2c4d54569ba0}" => removed successfully
HKLM\Software\Classes\CLSID\{5977a24a-b02b-11e7-858e-2c4d54569ba0} => key not found
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
"HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
"HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{5CE25775-92B7-477d-9603-852F0B34D8B0}" => removed successfully
HKLM\Software\Classes\CLSID\{5CE25775-92B7-477d-9603-852F0B34D8B0} => key not found
"HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8ACD20D1-E475-4D00-A706-CBDA4685C337}" => removed successfully
HKLM\Software\Classes\CLSID\{8ACD20D1-E475-4D00-A706-CBDA4685C337} => key not found
"HKU\S-1-5-21-1786104691-2426081519-2716709316-1001\Software\MozillaPlugins\ubisoft.com/uplaypc" => removed successfully
"A:\Hry\Settlers 7\Data\Base\_Dbg\Bin\Release\orbit\npuplaypc.dll" => not found
"HKLM\System\CurrentControlSet\Services\bemszcafb.sys" => removed successfully
bemszcafb.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\bogqlyryb.sys" => removed successfully
bogqlyryb.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\cqctmvzng.sys" => removed successfully
cqctmvzng.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\ctoofsmoa.sys" => removed successfully
ctoofsmoa.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\cuuzkpsfk.sys" => removed successfully
cuuzkpsfk.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\dbprghlhs.sys" => removed successfully
dbprghlhs.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\dekyvudve.sys" => removed successfully
dekyvudve.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\devxiwfkv.sys" => removed successfully
devxiwfkv.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\dgsjfiqr.sys" => removed successfully
dgsjfiqr.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\dqwnqlplj.sys" => removed successfully
dqwnqlplj.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\dsxhokbii.sys" => removed successfully
dsxhokbii.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\dzskyxbvb.sys" => removed successfully
dzskyxbvb.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\eavkldyag.sys" => removed successfully
eavkldyag.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\ejpgbrgry.sys" => removed successfully
ejpgbrgry.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\fckodwrar.sys" => removed successfully
fckodwrar.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\fdftoylto.sys" => removed successfully
fdftoylto.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\gitutnzyg.sys" => removed successfully
gitutnzyg.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\gnadttrzp.sys" => removed successfully
gnadttrzp.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\gnqzjjlpt.sys" => removed successfully
gnqzjjlpt.sys => service removed successfully
GPUIO => Unable to stop service.
"HKLM\System\CurrentControlSet\Services\GPUIO" => removed successfully
GPUIO => service removed successfully
"HKLM\System\CurrentControlSet\Services\hfksobcgy.sys" => removed successfully
hfksobcgy.sys => service removed successfully
HWiNFO32 => Unable to stop service.
"HKLM\System\CurrentControlSet\Services\HWiNFO32" => removed successfully
HWiNFO32 => service removed successfully
"HKLM\System\CurrentControlSet\Services\iajekjhzs.sys" => removed successfully
iajekjhzs.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\ikffgqzyq.sys" => removed successfully
ikffgqzyq.sys => service removed successfully
IOMap => Unable to stop service.
"HKLM\System\CurrentControlSet\Services\IOMap" => removed successfully
IOMap => service removed successfully
"HKLM\System\CurrentControlSet\Services\jbjtpsvjp.sys" => removed successfully
jbjtpsvjp.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\jsifawipr.sys" => removed successfully
jsifawipr.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\mdyvbjunl.sys" => removed successfully
mdyvbjunl.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\mivujvbcw.sys" => removed successfully
mivujvbcw.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\mrzcjjceb.sys" => removed successfully
mrzcjjceb.sys => service removed successfully
mtunnbbvg.sys => Unable to stop service.
"HKLM\System\CurrentControlSet\Services\mtunnbbvg.sys" => removed successfully
mtunnbbvg.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\namccznua.sys" => removed successfully
namccznua.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\ofierptfj.sys" => removed successfully
ofierptfj.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\pbwckpzo.sys" => removed successfully
pbwckpzo.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\pfchccpjf.sys" => removed successfully
pfchccpjf.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\pgmtoudyn.sys" => removed successfully
pgmtoudyn.sys => service removed successfully
pkkjmqev.sys => Unable to stop service.
"HKLM\System\CurrentControlSet\Services\pkkjmqev.sys" => removed successfully
pkkjmqev.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\plwhmuliy.sys" => removed successfully
plwhmuliy.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\poekcoojk.sys" => removed successfully
poekcoojk.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\ppctndrks.sys" => removed successfully
ppctndrks.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\pskricapm.sys" => removed successfully
pskricapm.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\qgcftitqz.sys" => removed successfully
qgcftitqz.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\qjfajkcpq.sys" => removed successfully
qjfajkcpq.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\qkvmaioxc.sys" => removed successfully
qkvmaioxc.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\qrymmgucq.sys" => removed successfully
qrymmgucq.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\qswpbwjmv.sys" => removed successfully
qswpbwjmv.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\runcqaaii.sys" => removed successfully
runcqaaii.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\semav6msr64" => removed successfully
semav6msr64 => service removed successfully
"HKLM\System\CurrentControlSet\Services\tlyxkongt.sys" => removed successfully
tlyxkongt.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\ubxdpiopr.sys" => removed successfully
ubxdpiopr.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\uwtjuzxqo.sys" => removed successfully
uwtjuzxqo.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\vbziccmil.sys" => removed successfully
vbziccmil.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\vnjnxllxc.sys" => removed successfully
vnjnxllxc.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\vnwlzfuap.sys" => removed successfully
vnwlzfuap.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\vqrwxlxnu.sys" => removed successfully
vqrwxlxnu.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\vrraekqwa.sys" => removed successfully
vrraekqwa.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\vxfeoyqku.sys" => removed successfully
vxfeoyqku.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\vysgcoiqn.sys" => removed successfully
vysgcoiqn.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\wpinwbetm.sys" => removed successfully
wpinwbetm.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\xbcgiypin.sys" => removed successfully
xbcgiypin.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\xgsfbmoos.sys" => removed successfully
xgsfbmoos.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\xiewtpbkl.sys" => removed successfully
xiewtpbkl.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\yxixaooko.sys" => removed successfully
yxixaooko.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\zibaqtkwt.sys" => removed successfully
zibaqtkwt.sys => service removed successfully
"HKLM\System\CurrentControlSet\Services\zunfgmfni.sys" => removed successfully
zunfgmfni.sys => service removed successfully
C:\WINDOWS\system32\Drivers\pkkjmqev.sys => moved successfully
C:\WINDOWS\system32\Drivers\dgsjfiqr.sys => moved successfully
C:\WINDOWS\system32\Drivers\ykyusygrf.sys => moved successfully
C:\WINDOWS\system32\Drivers\xiewtpbkl.sys => moved successfully
C:\Users\Fedorovi\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully

"C:\Users\Fedorovi\AppData\Local\Temp" folder move:

Could not move "C:\Users\Fedorovi\AppData\Local\Temp" => Scheduled to move on reboot.

ResetHosts: => Error: No automatic fix found for this entry.

=========== EmptyTemp: ==========

BITS transfer queue => 7364608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 133290592 B
Java, Flash, Steam htmlcache => 140814 B
Windows/system/drivers => 2790166 B
Edge => 16030820 B
Chrome => 0 B
Firefox => 394011873 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 307352 B
Fedorovi => 2239451741 B

RecycleBin => 0 B
EmptyTemp: => 2.6 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 10-01-2018 15:45:22)

C:\Users\Fedorovi\AppData\Local\Temp => moved successfully

==== End of Fixlog 15:45:23 ====

Re: Adware ve Firefoxu.

Napsal: 10 led 2018 20:40
od Rudy
Smazáno. Log je již OK.

Re: Adware ve Firefoxu.

Napsal: 11 led 2018 12:32
od ppetr
Ještě jednou, děkuji za pomoc :thumbsup:

Re: Adware ve Firefoxu.

Napsal: 11 led 2018 14:46
od Rudy
Rádo se stalo! :)