Stránka 1 z 1

prosim o preventivku

Napsal: 24 úno 2018 09:49
od roki
Logfile of random's system information tool 1.10 (written by random/random)
Run by lysov at 2018-02-24 09:37:28
Microsoft Windows 10 Home
System drive C: has 90 GB (72%) free of 126 GB
Total RAM: 8190 MB (74% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:37:33, on 24.2.2018
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.15063.0850)
Boot mode: Normal

Running processes:
C:\Users\lysov\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\trend micro\lysov.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL
O4 - HKLM\..\Run: [XPE] "C:\Program Files (x86)\XPE Windows 10 DPI Fix\XPEWindows10_DPI.exe" -hide:100
O4 - HKCU\..\Run: [OneDrive] "C:\Users\lysov\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~1\Office16\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - https://mapa.katasterportal.sk/kapor2/lib/mgaxctrl.cab
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7556 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
winlogon.exe
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
"fontdrvhost.exe"
"fontdrvhost.exe"
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
c:\windows\system32\svchost.exe -k netsvcs -s gpsvc
c:\windows\system32\svchost.exe -k netsvcs -s DsmSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
c:\windows\system32\svchost.exe -k localservice -s nsi
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservice -s EventSystem
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k localservice -s netprofm

C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted

c:\windows\system32\svchost.exe -k networkservice -s Dnscache
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
C:\WINDOWS\System32\svchost.exe -k utcsvc

c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS

c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\WINDOWS\system32\SearchIndexer.exe /Embedding

c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
dashost.exe {53321b7e-19f2-47c8-a9e2e6fb07b50a2f}

c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NgcSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s NgcCtnrSvc
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s upnphost
C:\WINDOWS\system32\wbem\wmiprvse.exe
sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
C:\WINDOWS\Explorer.EXE

"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
C:\Windows\System32\smartscreen.exe -Embedding
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
C:\WINDOWS\system32\AUDIODG.EXE 0x494
c:\windows\system32\svchost.exe -k netsvcs -s wlidsvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
c:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Users\lysov\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s WdiSystemHost
"dwm.exe"
c:\windows\system32\svchost.exe -k netsvcs -s DoSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
c:\windows\system32\svchost.exe -k unistacksvcgroup
taskhostw.exe
C:\WINDOWS\system32\msiexec.exe /V
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s Netman
C:\WINDOWS\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E}
C:\WINDOWS\system32\wbem\wmiprvse.exe
c:\windows\system32\svchost.exe -k localservicenonetwork -s NcdAutoSetup
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s FDResPub
C:\WINDOWS\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe -k netsvcs -s Browser
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s HomeGroupProvider
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 688 692 700 8192 696
C:\WINDOWS\System32\svchost.exe -k WerSvcGroup
"C:\Program Files\Opera\50.0.2762.67\opera.exe" --ran-launcher --started-from-shortcut
"C:\Program Files\Opera\50.0.2762.67\opera_crashreporter.exe" --ran-launcher --started-from-shortcut --crash-reporter-parent-id=2416
"C:\Program Files\Opera\50.0.2762.67\opera.exe" --type=gpu-process --field-trial-handle=1732,10011516754686127219,2410380652017663468,131072 --with-feature:installer-experiment-test=off --with-feature:installer-direct-unpacking=on --with-feature:installer-use-minimal-package=off --with-feature:installer-pref-default-overrides-support=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-support-x64-download=on --crash-reporter-pid=8400 --gpu-vendor-id=0x10de --gpu-device-id=0x0622 --gpu-driver-vendor=NVIDIA --gpu-driver-version=21.21.13.4201 --gpu-driver-date=11-14-2016 --with-feature:installer-experiment-test=off --with-feature:installer-direct-unpacking=on --with-feature:installer-use-minimal-package=off --with-feature:installer-pref-default-overrides-support=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-support-x64-download=on --crash-reporter-pid=8400 --service-request-channel-token=3FCAB93B78AC7ECE5B7264FC6993CD6A --mojo-platform-channel-handle=1764 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files\Opera\50.0.2762.67\opera.exe" --type=renderer --field-trial-handle=1732,10011516754686127219,2410380652017663468,131072 --service-pipe-token=2CE1B885B0104FBB7C765FC57C0D8162 --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --with-feature:installer-experiment-test=off --with-feature:installer-direct-unpacking=on --with-feature:installer-use-minimal-package=off --with-feature:installer-pref-default-overrides-support=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-support-x64-download=on --crash-reporter-pid=8400 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-gpu-async-worker-context --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --service-request-channel-token=2CE1B885B0104FBB7C765FC57C0D8162 --renderer-client-id=4 --mojo-platform-channel-handle=3028 /prefetch:1
"C:\Program Files\Opera\50.0.2762.67\opera.exe" --type=renderer --field-trial-handle=1732,10011516754686127219,2410380652017663468,131072 --service-pipe-token=2B6E0F46AAE99745ECF23DF0C96A7783 --lang=sk --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --with-feature:installer-experiment-test=off --with-feature:installer-direct-unpacking=on --with-feature:installer-use-minimal-package=off --with-feature:installer-pref-default-overrides-support=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-support-x64-download=on --crash-reporter-pid=8400 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --enable-gpu-async-worker-context --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;0,17,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;1,17,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;2,17,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;3,17,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553;4,17,3553;5,0,3553;5,1,3553;5,2,3553;5,3,3553;5,4,3553;5,5,3553;5,6,3553;5,7,3553;5,8,3553;5,9,3553;5,10,3553;5,11,3553;5,12,3553;5,13,3553;5,14,3553;5,15,3553;5,16,3553;5,17,3553;6,0,3553;6,1,3553;6,2,3553;6,3,3553;6,4,3553;6,5,3553;6,6,3553;6,7,3553;6,8,3553;6,9,3553;6,10,3553;6,11,3553;6,12,3553;6,13,3553;6,14,3553;6,15,3553;6,16,3553;6,17,3553 --service-request-channel-token=2B6E0F46AAE99745ECF23DF0C96A7783 --renderer-client-id=8 --mojo-platform-channel-handle=5744 /prefetch:1
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXe9cvj1thv1hmcw0cs98xm3r97tyzy2xs.mca
C:\WINDOWS\system32\svchost.exe -k netsvcs -s XblAuthManager
"C:\WINDOWS\System32\BackgroundTaskHost.exe" -ServerName:BackgroundTaskHost.WebAccountProvider
"C:\totalcmd\TOTALCMD64.EXE"
"D:\RSITx64.exe"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\PROGRA~1\MICROS~1\Office16\GROOVEEX.DLL [2015-07-31 2165976]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\PROGRA~2\MICROS~1\Office16\GROOVEEX.DLL [2015-07-31 1512152]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-03-18 629152]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\lysov\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2018-02-17 1558688]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"XPE"=C:\Program Files (x86)\XPE Windows 10 DPI Fix\XPEWindows10_DPI.exe [2015-08-21 28672]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2018-02-24 09:37:28 ----D---- C:\rsit
2018-02-24 09:37:28 ----D---- C:\Program Files\trend micro
2018-02-24 09:35:14 ----HD---- C:\OneDriveTemp
2018-02-24 09:33:35 ----D---- C:\WINDOWS\LastGood
2018-02-24 09:32:56 ----D---- C:\ProgramData\Package Cache
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\nvopencl.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\nvdispgenco6434201.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\nvdispco6434201.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\nvcuda.dll
2018-02-24 09:32:40 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2018-02-24 09:30:45 ----D---- C:\ProgramData\NVIDIA
2018-02-24 09:30:42 ----D---- C:\NVIDIA
2018-02-24 09:30:37 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2018-02-24 09:30:37 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2018-02-24 09:30:37 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2018-02-24 09:30:37 ----A---- C:\WINDOWS\system32\nvshext.dll
2018-02-24 09:30:37 ----A---- C:\WINDOWS\system32\nvcpl.dll
2018-02-24 09:30:36 ----A---- C:\WINDOWS\system32\nvmctray.dll
2018-02-24 09:30:17 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.dll
2018-02-24 09:30:17 ----A---- C:\WINDOWS\system32\OpenCL.dll
2018-02-24 09:29:54 ----D---- C:\WINDOWS\system32\drivers\wd
2018-02-24 09:27:06 ----D---- C:\Program Files\CCleaner
2018-02-21 19:30:57 ----HD---- C:\$WINDOWS.~BT
2018-02-18 14:06:08 ----D---- C:\Windows.old
2018-02-17 14:02:15 ----A---- C:\WINDOWS\system32\vss_ps.dll
2018-02-17 14:02:15 ----A---- C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2018-02-17 14:02:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2018-02-17 14:02:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2018-02-17 14:02:14 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2018-02-17 14:02:14 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2018-02-17 14:02:14 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-02-17 14:02:14 ----A---- C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2018-02-17 14:02:13 ----A---- C:\WINDOWS\SYSWOW64\webplatstorageserver.dll
2018-02-17 14:02:13 ----A---- C:\WINDOWS\SYSWOW64\OneCoreUAPCommonProxyStub.dll
2018-02-17 14:02:12 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2018-02-17 14:02:12 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2018-02-17 14:02:12 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2018-02-17 14:02:12 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2018-02-17 14:02:12 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2018-02-17 14:02:12 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-02-17 14:02:11 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2018-02-17 14:02:11 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2018-02-17 14:02:11 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2018-02-17 14:02:11 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2018-02-17 14:02:11 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2018-02-17 14:02:11 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2018-02-17 14:02:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2018-02-17 14:02:08 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2018-02-17 14:02:08 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2018-02-17 14:02:08 ----A---- C:\WINDOWS\system32\vbscript.dll
2018-02-17 14:02:07 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2018-02-17 14:02:07 ----A---- C:\WINDOWS\SYSWOW64\certutil.exe
2018-02-17 14:02:07 ----A---- C:\WINDOWS\system32\iertutil.dll
2018-02-17 14:02:07 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2018-02-17 14:02:06 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2018-02-17 14:02:06 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2018-02-17 14:02:06 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2018-02-17 14:02:06 ----A---- C:\WINDOWS\system32\urlmon.dll
2018-02-17 14:02:06 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2018-02-17 14:02:06 ----A---- C:\WINDOWS\system32\hvax64.exe
2018-02-17 14:02:06 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2018-02-17 14:02:05 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2018-02-17 14:02:04 ----A---- C:\WINDOWS\SYSWOW64\MshtmlDac.dll
2018-02-17 14:02:04 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2018-02-17 14:02:04 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2018-02-17 14:02:04 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2018-02-17 14:02:04 ----A---- C:\WINDOWS\system32\jscript9.dll
2018-02-17 14:02:04 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2018-02-17 14:02:04 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2018-02-17 14:02:03 ----A---- C:\WINDOWS\system32\webplatstorageserver.dll
2018-02-17 14:02:03 ----A---- C:\WINDOWS\system32\mfcore.dll
2018-02-17 14:02:03 ----A---- C:\WINDOWS\system32\jscript.dll
2018-02-17 14:02:03 ----A---- C:\WINDOWS\system32\iepeers.dll
2018-02-17 14:02:02 ----A---- C:\WINDOWS\system32\wininet.dll
2018-02-17 14:02:02 ----A---- C:\WINDOWS\system32\ncsi.dll
2018-02-17 14:02:02 ----A---- C:\WINDOWS\system32\IKEEXT.DLL
2018-02-17 14:02:01 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2018-02-17 14:02:01 ----A---- C:\WINDOWS\system32\certutil.exe
2018-02-17 14:02:00 ----A---- C:\WINDOWS\system32\win32kbase.sys
2018-02-17 14:02:00 ----A---- C:\WINDOWS\system32\hvix64.exe
2018-02-17 14:02:00 ----A---- C:\WINDOWS\system32\dbgeng.dll
2018-02-17 14:01:59 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2018-02-17 14:01:59 ----A---- C:\WINDOWS\system32\msfeeds.dll
2018-02-17 14:01:59 ----A---- C:\WINDOWS\system32\d2d1.dll
2018-02-17 14:01:59 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2018-02-17 14:01:58 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2018-02-17 14:01:58 ----A---- C:\WINDOWS\system32\hal.dll
2018-02-17 14:01:58 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2018-02-17 14:01:57 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2018-02-17 14:01:57 ----A---- C:\WINDOWS\system32\rdpudd.dll
2018-02-17 14:01:57 ----A---- C:\WINDOWS\system32\mshtmled.dll
2018-02-17 14:01:57 ----A---- C:\WINDOWS\system32\MshtmlDac.dll
2018-02-17 14:01:57 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2018-02-17 14:01:57 ----A---- C:\WINDOWS\system32\drivers\USBXHCI.SYS
2018-02-17 14:01:57 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2018-02-17 14:01:56 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2018-02-17 14:01:56 ----A---- C:\WINDOWS\system32\Chakra.dll
2018-02-17 14:01:56 ----A---- C:\WINDOWS\system32\edgehtml.dll
2018-02-17 14:01:56 ----A---- C:\WINDOWS\system32\dxtrans.dll
2018-02-17 14:01:55 ----A---- C:\WINDOWS\system32\ieframe.dll
2018-02-17 14:01:54 ----A---- C:\WINDOWS\system32\win32kfull.sys
2018-02-17 14:01:54 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2018-02-17 14:01:53 ----A---- C:\WINDOWS\system32\mshtml.dll
2018-02-17 14:01:51 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2018-02-17 14:01:48 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2018-02-17 14:01:47 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2018-02-17 14:01:47 ----A---- C:\WINDOWS\system32\Windows.Shell.StartLayoutPopulationEvents.dll
2018-02-17 14:01:47 ----A---- C:\WINDOWS\system32\SCardSvr.dll
2018-02-17 14:01:47 ----A---- C:\WINDOWS\system32\NotificationController.dll
2018-02-17 14:01:46 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2018-02-17 14:01:46 ----A---- C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2018-02-17 14:01:46 ----A---- C:\WINDOWS\system32\StartTileData.dll
2018-02-17 14:01:46 ----A---- C:\WINDOWS\system32\diagtrack.dll
2018-02-17 14:01:45 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2018-02-17 14:01:45 ----A---- C:\WINDOWS\system32\twinui.dll
2018-02-17 14:01:45 ----A---- C:\WINDOWS\system32\StorSvc.dll
2018-02-17 14:01:45 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2018-02-17 14:01:43 ----A---- C:\WINDOWS\system32\domgmt.dll
2018-02-17 14:01:42 ----A---- C:\WINDOWS\system32\dosvc.dll
2018-02-17 14:01:41 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2018-02-17 14:01:41 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2018-02-17 14:01:41 ----A---- C:\WINDOWS\system32\aitstatic.exe
2018-02-17 14:01:40 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2018-02-17 14:01:40 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2018-02-17 14:01:40 ----A---- C:\WINDOWS\system32\winsrv.dll
2018-02-17 14:01:40 ----A---- C:\WINDOWS\system32\odbcconf.dll
2018-02-17 14:01:40 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2018-02-17 14:01:39 ----A---- C:\WINDOWS\system32\shell32.dll
2018-02-17 14:01:39 ----A---- C:\WINDOWS\system32\ClipSVC.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\SYSWOW64\aepic.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\win32appinventorycsp.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\pcasvc.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\invagent.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\devinv.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\dcntel.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\CompatTelRunner.exe
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\aepic.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\aeinv.dll
2018-02-17 14:01:38 ----A---- C:\WINDOWS\system32\acmigration.dll
2018-02-17 14:01:37 ----A---- C:\WINDOWS\system32\wifitask.exe
2018-02-17 14:01:37 ----A---- C:\WINDOWS\system32\generaltel.dll
2018-02-17 14:01:37 ----A---- C:\WINDOWS\system32\appraiser.dll
2018-02-17 14:01:35 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2018-02-17 14:01:35 ----A---- C:\WINDOWS\system32\aadtb.dll
2018-02-17 14:01:35 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2018-02-17 14:01:34 ----A---- C:\WINDOWS\system32\winresume.exe
2018-02-17 14:01:34 ----A---- C:\WINDOWS\system32\winload.exe
2018-02-17 14:01:34 ----A---- C:\WINDOWS\system32\hvloader.exe
2018-02-17 14:01:33 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2018-02-17 14:01:33 ----A---- C:\WINDOWS\system32\ci.dll
2018-02-17 14:01:30 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2018-02-17 14:01:30 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2018-02-17 14:01:30 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2018-02-17 14:01:30 ----A---- C:\WINDOWS\system32\wer.dll
2018-02-17 14:01:30 ----A---- C:\WINDOWS\system32\propsys.dll
2018-02-17 14:01:30 ----A---- C:\WINDOWS\system32\BFE.DLL
2018-02-17 14:01:29 ----A---- C:\WINDOWS\system32\rtmpltfm.dll
2018-02-17 14:01:27 ----A---- C:\WINDOWS\SYSWOW64\rtmpltfm.dll
2018-02-17 14:01:27 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2018-02-17 14:01:26 ----A---- C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2018-02-17 14:01:26 ----A---- C:\WINDOWS\system32\provhandlers.dll
2018-02-17 14:01:26 ----A---- C:\WINDOWS\system32\provengine.dll
2018-02-17 14:01:25 ----A---- C:\WINDOWS\system32\certprop.dll
2018-02-17 14:01:24 ----A---- C:\WINDOWS\SYSWOW64\propsys.dll
2018-02-17 14:01:24 ----A---- C:\WINDOWS\system32\wmpps.dll
2018-02-17 14:01:24 ----A---- C:\WINDOWS\system32\mfps.dll
2018-02-17 14:01:23 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2018-02-17 14:01:23 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2018-02-17 14:01:23 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2018-02-17 14:01:23 ----A---- C:\WINDOWS\system32\rtmpal.dll
2018-02-17 14:01:22 ----A---- C:\WINDOWS\SYSWOW64\cldapi.dll
2018-02-17 14:01:22 ----A---- C:\WINDOWS\system32\cldapi.dll
2018-02-17 14:01:21 ----RA---- C:\WINDOWS\system32\Windows.Mirage.Internal.Capture.UX.dll
2018-02-17 14:01:21 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2018-02-17 14:01:21 ----A---- C:\WINDOWS\SYSWOW64\WinSCard.dll
2018-02-17 14:01:21 ----A---- C:\WINDOWS\SYSWOW64\rtmpal.dll
2018-02-17 14:01:21 ----A---- C:\WINDOWS\system32\WinSCard.dll
2018-02-17 14:01:21 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2018-02-17 14:01:20 ----A---- C:\WINDOWS\system32\wintrust.dll
2018-02-17 14:01:20 ----A---- C:\WINDOWS\system32\winbrand.dll
2018-02-17 14:01:20 ----A---- C:\WINDOWS\system32\vpnike.dll
2018-02-17 14:01:20 ----A---- C:\WINDOWS\system32\SEMgrSvc.dll
2018-02-17 14:01:20 ----A---- C:\WINDOWS\system32\SEMgrPS.dll
2018-02-17 14:01:20 ----A---- C:\WINDOWS\system32\ortcengine.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\SYSWOW64\wmpps.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\SYSWOW64\winbrand.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\SYSWOW64\rtmmvrortc.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\SYSWOW64\rtmcodecs.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\SYSWOW64\ortcengine.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\system32\rtmmvrortc.dll
2018-02-17 14:01:19 ----A---- C:\WINDOWS\system32\rtmcodecs.dll
2018-02-17 14:01:18 ----A---- C:\WINDOWS\SYSWOW64\wldp.dll
2018-02-17 14:01:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Cred.dll
2018-02-17 14:01:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.Phone.dll
2018-02-17 14:01:18 ----A---- C:\WINDOWS\system32\wow64cpu.dll
2018-02-17 14:01:18 ----A---- C:\WINDOWS\system32\wldp.dll
2018-02-17 14:01:18 ----A---- C:\WINDOWS\system32\Windows.UI.Cred.dll
2018-02-17 14:01:18 ----A---- C:\WINDOWS\system32\LocationFrameworkPS.dll
2018-02-17 14:01:18 ----A---- C:\WINDOWS\system32\drivers\hidparse.sys
2018-02-17 14:01:17 ----A---- C:\WINDOWS\SYSWOW64\mapistub.dll
2018-02-17 14:01:17 ----A---- C:\WINDOWS\SYSWOW64\mapi32.dll
2018-02-17 14:01:17 ----A---- C:\WINDOWS\SYSWOW64\LocationFrameworkPS.dll
2018-02-17 14:01:17 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.Phone.dll
2018-02-17 14:01:17 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2018-02-17 14:01:17 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2018-02-17 14:01:17 ----A---- C:\WINDOWS\system32\mapistub.dll
2018-02-17 14:01:17 ----A---- C:\WINDOWS\system32\mapi32.dll
2018-02-17 14:01:17 ----A---- C:\WINDOWS\system32\drivers\raspptp.sys
2018-02-17 14:01:16 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\SYSWOW64\vss_ps.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\SYSWOW64\msctfp.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\SYSWOW64\LocationFrameworkInternalPS.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\SYSWOW64\certenc.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\system32\winsku.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\system32\provdatastore.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\system32\msctfp.dll
2018-02-17 14:01:16 ----A---- C:\WINDOWS\system32\certenc.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\SYSWOW64\winsku.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\SYSWOW64\tzres.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2018-02-17 14:01:15 ----A---- C:\WINDOWS\SYSWOW64\fixmapi.exe
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\tzres.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\SCardBi.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\provops.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\NotificationControllerPS.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\fixmapi.exe
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\DbgModel.dll
2018-02-17 14:01:15 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2018-02-10 15:02:39 ----A---- C:\WINDOWS\system32\osrss.dll
2018-02-10 13:43:58 ----D---- C:\Program Files\Google
2018-01-28 14:08:35 ----D---- C:\Users\lysov\AppData\Roaming\Daum

======List of files/folders modified in the last 1 month======

2018-02-24 09:37:28 ----RD---- C:\Program Files
2018-02-24 09:37:00 ----D---- C:\WINDOWS\Temp
2018-02-24 09:35:46 ----D---- C:\WINDOWS\Prefetch
2018-02-24 09:34:24 ----D---- C:\WINDOWS\System32
2018-02-24 09:34:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2018-02-24 09:33:42 ----D---- C:\WINDOWS\SysWOW64
2018-02-24 09:33:35 ----D---- C:\WINDOWS\system32\drivers
2018-02-24 09:33:35 ----D---- C:\Windows
2018-02-24 09:33:35 ----D---- C:\Program Files\NVIDIA Corporation
2018-02-24 09:33:32 ----D---- C:\WINDOWS\system32\catroot2
2018-02-24 09:33:32 ----D---- C:\WINDOWS\system32\CatRoot
2018-02-24 09:33:32 ----D---- C:\WINDOWS\INF
2018-02-24 09:33:31 ----D---- C:\WINDOWS\system32\DriverStore
2018-02-24 09:32:58 ----SHD---- C:\WINDOWS\Installer
2018-02-24 09:32:56 ----HD---- C:\ProgramData
2018-02-24 09:31:54 ----D---- C:\WINDOWS\system32\sru
2018-02-24 09:30:29 ----D---- C:\WINDOWS\Help
2018-02-24 09:30:05 ----D---- C:\ProgramData\NVIDIA Corporation
2018-02-24 09:28:53 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2018-02-24 09:27:09 ----D---- C:\WINDOWS\system32\Tasks
2018-02-24 09:20:53 ----D---- C:\WINDOWS\system32\config
2018-02-21 19:34:53 ----D---- C:\WINDOWS\CbsTemp
2018-02-21 19:31:57 ----DC---- C:\WINDOWS\Panther
2018-02-21 19:17:06 ----D---- C:\WINDOWS\Logs
2018-02-21 18:57:38 ----D---- C:\WINDOWS\system32\LogFiles
2018-02-21 05:41:08 ----D---- C:\WINDOWS\AppReadiness
2018-02-21 05:41:07 ----HD---- C:\Program Files\WindowsApps
2018-02-18 18:53:03 ----D---- C:\WINDOWS\system32\SleepStudy
2018-02-18 14:57:41 ----D---- C:\WINDOWS\Registration
2018-02-18 14:29:23 ----D---- C:\WINDOWS\rescache
2018-02-18 14:28:20 ----RD---- C:\WINDOWS\Microsoft.NET
2018-02-18 14:25:58 ----D---- C:\WINDOWS\WinSxS
2018-02-18 14:22:53 ----RD---- C:\WINDOWS\assembly
2018-02-18 13:51:40 ----SHD---- C:\Boot
2018-02-17 15:04:20 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2018-02-17 15:04:20 ----D---- C:\WINDOWS\SYSWOW64\oobe
2018-02-17 15:04:20 ----D---- C:\WINDOWS\SYSWOW64\Dism
2018-02-17 15:04:19 ----RSD---- C:\WINDOWS\Fonts
2018-02-17 15:04:19 ----RD---- C:\WINDOWS\PrintDialog
2018-02-17 15:04:19 ----D---- C:\WINDOWS\system32\sk-SK
2018-02-17 15:04:19 ----D---- C:\WINDOWS\system32\oobe
2018-02-17 15:04:19 ----D---- C:\WINDOWS\system32\Dism
2018-02-17 15:04:19 ----D---- C:\WINDOWS\system32\Boot
2018-02-17 15:04:19 ----D---- C:\WINDOWS\system32\appraiser
2018-02-17 15:04:19 ----D---- C:\WINDOWS\ShellExperiences
2018-02-17 15:04:19 ----D---- C:\WINDOWS\Provisioning
2018-02-17 15:04:19 ----D---- C:\WINDOWS\HoloShell
2018-02-17 15:04:19 ----D---- C:\WINDOWS\AppPatch
2018-02-17 15:04:19 ----D---- C:\Program Files\Windows Photo Viewer
2018-02-17 15:04:19 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2018-02-17 14:04:45 ----D---- C:\WINDOWS\system32\MRT
2018-02-17 14:03:36 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2018-02-17 14:03:31 ----AC---- C:\WINDOWS\system32\MRT.exe
2018-02-17 13:44:36 ----D---- C:\WINDOWS\SoftwareDistribution
2018-02-10 13:51:15 ----AD---- C:\Program Files\rempl
2018-02-06 19:57:30 ----D---- C:\Program Files (x86)\Google
2018-02-06 19:53:26 ----D---- C:\WINDOWS\system32\Macromed
2018-02-06 19:53:23 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2018-02-02 21:34:52 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2018-01-26 15:07:42 ----A---- C:\WINDOWS\system32\MpSigStub.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2017-03-18 49568]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2017-03-18 54272]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2018-01-01 8192]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2017-03-18 14336]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2017-03-18 50688]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2018-01-01 79872]
R3 netr28ux;@netr28ux.inf,%Generic.Service.DispName%;RT2870 USB Extensible Wireless LAN Card Driver; C:\WINDOWS\System32\drivers\netr28ux.sys [2017-03-18 2224128]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-11-14 12905016]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2017-03-18 604160]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-03-18 123808]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-03-18 103328]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-03-18 64416]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2017-03-18 58784]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2017-03-18 61848]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2017-03-18 91040]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2017-03-18 36760]
S2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2017-03-18 12288]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-03-18 20480]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2017-03-18 17920]
S3 athr;@netathrx.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN device driver; C:\WINDOWS\System32\drivers\athwnx.sys [2017-03-18 4233728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-09-05 39424]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2017-03-18 53664]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2017-03-18 122880]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-03-18 21504]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-03-18 51104]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2018-01-01 74648]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-03-18 347032]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-03-18 2104224]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2017-03-18 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2017-03-18 81408]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-03-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-03-18 85504]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-03-18 165376]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-03-18 168448]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2017-03-18 526240]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-03-18 36864]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2018-01-01 120320]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2017-03-18 405408]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2017-03-18 51104]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-03-18 842656]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2017-03-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2017-03-18 122368]
S3 nvdimmn;@nvdimmn.inf,%nvdimmn.SvcDesc%;Microsoft NVDIMM-N device driver; C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-03-18 80896]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2017-03-18 101376]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2017-03-18 936864]
S3 SDFRd;@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector; C:\WINDOWS\System32\drivers\SDFRd.sys [2017-03-18 31128]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter; C:\WINDOWS\System32\drivers\SpatialGraphFilter.sys [2017-03-20 40352]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2017-09-05 104960]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys [2017-03-18 179200]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2017-07-28 51712]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2017-03-18 45568]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2017-03-18 263584]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2017-03-18 98712]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2017-03-18 138656]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2017-03-18 59288]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2017-03-18 29600]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2017-03-18 28064]
S3 usbser;@usbser.inf,%UsbSerial.DriverDesc%;Microsoft USB Serial Driver; C:\WINDOWS\System32\drivers\usbser.sys [2017-09-05 71680]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 CDPUserSvc_2fb28;Connected Devices Platform User Service_2fb28; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2016-11-14 932728]
R2 OneSyncSvc_2fb28;Sync Host_2fb28; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 osrss;OS Remediation System Service; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 SecurityHealthService;@%systemroot%\system32\SecurityHealthAgent.dll,-1002; C:\WINDOWS\system32\SecurityHealthService.exe [2017-09-30 336320]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 PimIndexMaintenanceSvc_2fb28;Kontaktné údaje_2fb28; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 TokenBroker;@%systemroot%\system32\tokenbroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R3 UnistoreSvc_2fb28;Ukladací priestor používateľských údajov_2fb28; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-09-15 153168]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWoW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-02-06 272384]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DevicesFlowUserSvc_2fb28;DevicesFlow_2fb28; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-03-18 86528]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2017-02-10 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-09-15 153168]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MessagingService_2fb28;MessagingService_2fb28; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-31 242864]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 SEMgrSvc;@%SystemRoot%\System32\SEMgrSvc.dll,-1001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2017-03-18 1284608]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 spectrum;@%systemroot%\system32\spectrum.exe,-101; C:\WINDOWS\system32\spectrum.exe [2018-01-01 891904]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2017-03-18 302592]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]

-----------------EOF-----------------

Dakujem :)

Re: prosim o preventivku

Napsal: 24 úno 2018 13:12
od Conder
Ahoj :)

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Scan (Skenovanie) a pockaj na dokoncenie
  • Klikni na Clean (Cistenie) a potvrd kliknutim na OK
  • AdwCleaner si vyziada restart PC, potvrd kliknutim na Restart Now (Restartovat teraz)
  • Po dokonceni a restartovani PC vyskoci log, jeho obsah sem skopiruj

Re: prosim o preventivku

Napsal: 24 úno 2018 16:26
od roki
# AdwCleaner 7.0.8.0 - Logfile created on Sat Feb 24 14:42:46 2018
# Updated on 2018/08/02 by Malwarebytes
# Running on Windows 10 Home (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0

Vyzerá čisto

*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [945 B] - [2018/2/24 14:40:37]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########

Re: prosim o preventivku

Napsal: 24 úno 2018 16:39
od Conder
:arrow: Poprosim o obidva logy z FRST podla tohto navodu (FRST.txt a Addition.txt): https://forum.viry.cz/viewtopic.php?f=13&t=152707

:arrow: V pripade, ze sa FRSTLauncher nebude dat stiahnut alebo spustit, pouzi iba samotny FRST.

:arrow: Ak sa logy nezmestia do jedneho prispevku, zabal ich do archivu RAR alebo ZIP a posli ako prilohu.

Re: prosim o preventivku

Napsal: 25 úno 2018 08:57
od roki
Logy z FRST :)

Re: prosim o preventivku

Napsal: 25 úno 2018 14:57
od Conder
:arrow: Body obnovenia mas zakazane/vypnute umyselne? Kazdopadne odporcam zapnut:
  • Stlac Win+R, napis "sysdm.cpl" (bez uvodzoviek) a stlac enter
  • Klikni na kartu Ochrana systemu a potom na Konfigurovat
  • Vyber moznost Zapnut ochranu systemu a klikni na OK
:arrow: Poznas tento subor? D:\backup.bat

:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    CMD: type "C:\Users\lysov\Desktop\LM.bat"
    CMD: type "D:\backup.bat"
    HKU\S-1-5-21-2994255237-3946984938-1703718942-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
    2018-02-25 08:48 - 2018-02-25 08:49 - 000029696 _____ C:\Users\lysov\AppData\Local\MSGBOX.EXE
    Task: {128DC5AE-C306-4F93-A6B8-C44B19609C6A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
    Task: {CF4D5C80-23E2-4FBE-BF9A-6B1139EF793A} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2017-02-19] ()
    C:\Windows\AutoKMS
    
    Hosts:
    EmptyTemp:
    End
  • Uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj
:arrow: Spusti kontrolu integrity systemovych suborov:
  • Otvor Start, napis "cmd" (bez uvodzoviek), klikni pravym tlacitkom mysi na Prikazovy riadok a klikni na Spustit ako spravca
  • Postupne skopiruj a spusti tieto 2 prikazy a stlac enter (pockaj na dokoncenie pred druhym prikazom):

    Kód: Vybrat vše

    DISM.exe /Online /Cleanup-image /Restorehealth
    sfc /scannow
  • Po dokonceni obidvoch prikazov skopiruj a spusti tento prikaz:

    Kód: Vybrat vše

    findstr /c:"[SR]" %windir%\logs\cbs\cbs.log >> "%userprofile%\desktop\sfcdetails.txt"
  • Na ploche sa vytvori subor sfcdetails.txt, jeho obsah sem skopiruj

Re: prosim o preventivku

Napsal: 25 úno 2018 16:37
od roki
D:\backup.bat - poznam to som spravil na zalohu niektorych priecinkov pomocou robocopy

Fixlog:

Kód: Vybrat vše

Fix result of Farbar Recovery Scan Tool (x64) Version: 24.02.2018
Ran by lysov (25-02-2018 15:09:54) Run:1
Running from C:\Users\lysov\Desktop
Loaded Profiles: lysov (Available Profiles: defaultuser0 & lysov)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

CMD: type "C:\Users\lysov\Desktop\LM.bat"
CMD: type "D:\backup.bat"
HKU\S-1-5-21-2994255237-3946984938-1703718942-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
2018-02-25 08:48 - 2018-02-25 08:49 - 000029696 _____ C:\Users\lysov\AppData\Local\MSGBOX.EXE
Task: {128DC5AE-C306-4F93-A6B8-C44B19609C6A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {CF4D5C80-23E2-4FBE-BF9A-6B1139EF793A} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2017-02-19] ()
C:\Windows\AutoKMS

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.

========= type "C:\Users\lysov\Desktop\LM.bat" =========

@echo off
set verzeLM=30_09_2013 (01)
cls
if not exist Addition.txt goto End

echo.Probiha kompletace logu. Prosim cekejte.
echo.
echo.Pozadovany log se za malou chvili otevre v Poznamkovem bloku a
echo.bude rovnez ulozen na Plose jako FRST.txt.


::Vypsani celeho FRST.txt do docasneho FRST2.txt 
type FRST.txt | find /i /v "End of Log">FRST2.txt


::Oddeleni FRST.txt a Addition.txt
echo.>>FRST2.txt
echo.>>FRST2.txt
echo.>>FRST2.txt
echo.===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===>>FRST2.txt
 
 
::Vypis pameti a disku
echo.>>FRST2.txt
echo.==================== Drive and Memory info ===================>>FRST2.txt
echo.>>FRST2.txt
type Addition.txt | find /i "Free:">>FRST2.txt
echo.>>FRST2.txt
type Addition.txt | find /i "Available physical RAM">>FRST2.txt
type Addition.txt | find /i "Total physical RAM">>FRST2.txt
type Addition.txt | find /i "Percentage of memory in use">>FRST2.txt


::Vypis MBR & Partition Table
echo.>>FRST2.txt
echo.==================== MBR and Partition Table ==================>>FRST2.txt
echo.>>FRST2.txt
type Addition.txt | find /i "Size">>FRST2.txt


::Vypis Naplanovanych uloh
echo.>>FRST2.txt
echo.==================== Scheduled Tasks (whitelisted) ==================>>FRST2.txt
echo.>>FRST2.txt
type Addition.txt | find /i ".job">>FRST2.txt


::Vypis ADS
echo.>>FRST2.txt
echo.==================== Alternate Data Streams (whitelisted) ==================>>FRST2.txt
echo.>>FRST2.txt
type Addition.txt | find /i "AlternateDataStreams:">>FRST2.txt


::Vypis Security Centra
echo.>>FRST2.txt
echo.==================== Security Center ==================>>FRST2.txt
echo.>>FRST2.txt
type Addition.txt | find /i "AV:">>FRST2.txt
type Addition.txt | find /i "AS:">>FRST2.txt
type Addition.txt | find /i "FW:">>FRST2.txt



:: Oddeleni casti FRST a FRSTLauncher
echo.>>FRST2.txt
echo.>>FRST2.txt
echo.>>FRST2.txt
echo.===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===>>FRST2.txt
echo.Posledni aktualizace FRSTLauncheru: %verzeFRSTL%>>FRST2.txt
echo.Posledni aktualizace Modifikacniho skriptu: %verzeLM%>>FRST2.txt


::Velikost Plochy
echo.>>FRST2.txt
echo.>>FRST2.txt  
echo.***** Velikost "Plochy" *****>>FRST2.txt
echo.>>FRST2.txt
setLocal EnableDelayedExpansion
set /a value=0
set /a sum=0
FOR /R %1 %%I IN (*) DO (
set /a value=%%~zI/1024
set /a sum=!sum!+!value!
)
set /a velikost=sum/1024
Echo Velikost slozky %tpath% je %velikost% MB.>>FRST2.txt


::Rozdelovac 32bit X 64bit OS
if %OSType%==x64 goto x64OS



::********************   32bit oS - start  ******************** 
::StartUp
echo.>>FRST2.txt 
echo.>>FRST2.txt 
echo.***** Startup Programs *****>>FRST2.txt
echo.>>FRST2.txt 
:x32Startupreg
reg query "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg">first.txt
type first.txt | find /i "\startupreg\" >nul & IF ERRORLEVEL 1 goto x32Startupfolder 
(
 type first.txt | find /i "startupreg\">first2.txt
 FOR /F "TOKENS=*" %%g IN ( first2.txt ) DO @REG query "%%g" /v command>>first3.txt 
 type first3.txt | find /i "\">first4.txt 
 FOR /F "EOL=H TOKENS=3*" %%g IN ( first4.txt ) DO @echo %%g %%h>>first5.txt 
 for /F "TOKENS=*" %%i IN ( first5.txt ) DO @if exist %%i (
 echo.>>first6.txt) ELSE (
 echo.[x]>>first6.txt))
 set f1=first5.txt
 set f2=first6.txt
 set "sep="  % tab %
 (for /f "delims=" %%a in (%f1%) do (
 setlocal enabledelayedexpansion
 set /p line=
 echo(%%a!sep!!line!
 endlocal))<%f2%>>first7.txt
 set f3=first2.txt
 set f4=first7.txt
 (for /f "delims=" %%a in (%f3%) do (
 setlocal enabledelayedexpansion
 set /p line=
 echo(%%a!
 echo !line!
 echo.
 endlocal))<%f4%>>first8.txt
 type first8.txt>>FRST2.txt

:x32Startupfolder
reg query "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder" /s >>first9.txt
type first9.txt | find /i "REG_SZ" >nul & IF ERRORLEVEL 1 goto x32msconfigservices 
(
 type first9.txt | find /i /v "reg.exe" | find /i /v "path" | find /i /v "backup" | find /i /v "location" | find /i /v "item" >>first10.txt
 type first10.txt | find /i "." >>first11.txt
 type first11.txt | find /i "command" >>first12.txt
 type first11.txt | find /i /v "command" >>first13.txt
 FOR /F "EOL=H TOKENS=3*" %%g IN ( first12.txt ) DO @echo %%g %%h>>first14.txt 
 for /F "TOKENS=*" %%i IN ( first14.txt ) DO @if exist %%i (
 echo.>>first15.txt) ELSE (
 echo.[x]>>first15.txt))
 set f5=first14.txt
 set f6=first15.txt
 set "sep="  % tab %
 (for /f "delims=" %%a in (%f5%) do (
 setlocal enabledelayedexpansion
 set /p line=
 echo(%%a!sep!!line!
 endlocal))<%f6%>>first16.txt
 set f7=first13.txt
 set f8=first16.txt
 (setlocal DisableDelayedExpansion
 for /f "delims=" %%a in (%f7%) do (
 set "f7_line=%%a"
 setlocal EnableDelayedExpansion
 set /p f8_line=
 echo(!f7_line!
 echo(!f8_line!
 echo.
 endlocal)
 endlocal)<%f8%>>first17.txt
 type first17.txt>>FRST2.txt
)

:x32msconfigservices
reg query "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services">first11.txt
type first11.txt | find /i "REG_DWORD" >nul & IF NOT ERRORLEVEL 1 (
echo.>>FRST2.txt
echo.HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services>>FRST2.txt
type first11.txt | find /i "REG_DWORD">>FRST2.txt)


::Pravidla FW
echo.>>FRST2.txt 
echo.***** Firewall rules *****>>FRST2.txt
echo.>>FRST2.txt
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile">sixth3.txt
echo.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]>>FRST2.txt
type sixth3.txt | find /i "REG_DWORD">>FRST2.txt
echo.>>FRST2.txt
reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile">sixth4.txt
echo.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]>>FRST2.txt
type sixth4.txt | find /i "REG_DWORD">>FRST2.txt
echo.>>FRST2.txt
reg export "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list" sixth5.txt >nul 2>&1
type sixth5.txt | find /i "\\" >nul & IF NOT ERRORLEVEL 1 (
type sixth5.txt | find /i /v "Windows Registry Editor Version 5.00">>FRST2.txt) ELSE (
echo.[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]>>FRST2.txt
echo.>>FRST2.txt)
reg export "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" sixth6.txt >nul 2>&1
type sixth6.txt | find /i "\\" >nul & IF NOT ERRORLEVEL 1 (
type sixth6.txt | find /i /v "Windows Registry Editor Version 5.00">>FRST2.txt) ELSE (
echo.[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]>>FRST2.txt
echo.>>FRST2.txt)
reg export "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List" sixth8.txt >nul 2>&1
echo.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]>>FRST2.txt
if exist sixth8.txt type sixth8.txt | find /i ":">>FRST2.txt
echo.>>FRST2.txt
reg export "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" sixth9.txt >nul 2>&1
echo.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]>>FRST2.txt
if exist sixth9.txt type sixth9.txt | find /i ":">>FRST2.txt


::SystemRestore
echo.>>FRST2.txt 
echo.>>FRST2.txt 
echo.***** System Restore *****>>FRST2.txt
reg export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" seventh.txt >nul 2>&1
echo.>>FRST2.txt
type seventh.txt | find /i "SystemRestore]">>FRST2.txt
type seventh.txt | find /i "DisableSR">>FRST2.txt

goto Kompletace
::********************   32bit oS - end  ********************


::********************   64bit oS - start  ********************  
:x64OS

::StartUp
echo.>>FRST2.txt 
echo.>>FRST2.txt 
echo.***** Startup Programs *****>>FRST2.txt
echo.>>FRST2.txt 
:x64Startupreg
"%windir%\sysnative\reg.exe" query "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg">first.txt
type first.txt | find /i "\startupreg\" >nul & IF ERRORLEVEL 1 goto x64Startupfolder 
(
 type first.txt | find /i "startupreg\">first2.txt
 FOR /F "TOKENS=*" %%g IN ( first2.txt ) DO "%windir%\sysnative\reg.exe" query "%%g" /v command>>first3.txt 
 type first3.txt | find /i "\">first4.txt 
 FOR /F "EOL=H TOKENS=3*" %%g IN ( first4.txt ) DO @echo %%g %%h>>first5.txt 
 for /F "TOKENS=*" %%i IN ( first5.txt ) DO @if exist %%i (
 echo.>>first6.txt) ELSE (
 echo.[x]>>first6.txt))
 set f1=first5.txt
 set f2=first6.txt
 set "sep="  % tab %
 (for /f "delims=" %%a in (%f1%) do (
 setlocal enabledelayedexpansion
 set /p line=
 echo(%%a!sep!!line!
 endlocal))<%f2%>>first7.txt
 set f3=first2.txt
 set f4=first7.txt
 (for /f "delims=" %%a in (%f3%) do (
 setlocal enabledelayedexpansion
 set /p line=
 echo(%%a!
 echo !line!
 echo.
 endlocal))<%f4%>>first8.txt
 type first8.txt>>FRST2.txt
)

:x64Startupfolder
"%windir%\sysnative\reg.exe" query "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder" /s >>first9.txt
type first9.txt | find /i "REG_SZ" >nul & IF ERRORLEVEL 1 goto x64msconfigservices 
(
 type first9.txt | find /i /v "reg.exe" | find /i /v "path" | find /i /v "backup" | find /i /v "location" | find /i /v "item" >>first10.txt
 type first10.txt | find /i "." >>first11.txt
 type first11.txt | find /i "command" >>first12.txt
 type first11.txt | find /i /v "command" >>first13.txt
 FOR /F "EOL=H TOKENS=3*" %%g IN ( first12.txt ) DO @echo %%g %%h>>first14.txt 
 for /F "TOKENS=*" %%i IN ( first14.txt ) DO @if exist %%i (
 echo.>>first15.txt) ELSE (
 echo.[x]>>first15.txt))
 set f5=first14.txt
 set f6=first15.txt
 set "sep="  % tab %
 (for /f "delims=" %%a in (%f5%) do (
 setlocal enabledelayedexpansion
 set /p line=
 echo(%%a!sep!!line!
 endlocal))<%f6%>>first16.txt
 set f7=first13.txt
 set f8=first16.txt
 (setlocal DisableDelayedExpansion
 for /f "delims=" %%a in (%f7%) do (
 set "f7_line=%%a"
 setlocal EnableDelayedExpansion
 set /p f8_line=
 echo(!f7_line!
 echo(!f8_line!
 echo.
 endlocal)
 endlocal)<%f8%>>first17.txt
 type first17.txt>>FRST2.txt
)

:x64msconfigservices
"%windir%\sysnative\reg.exe" query "HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services">first11.txt
type first11.txt | find /i "REG_DWORD" >nul & IF NOT ERRORLEVEL 1 (
echo.>>FRST2.txt
echo.HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services>>FRST2.txt
type first11.txt | find /i "REG_DWORD">>FRST2.txt)


::Pravidla FW
echo.>>FRST2.txt 
echo.***** Firewall rules *****>>FRST2.txt
echo.>>FRST2.txt
"%windir%\sysnative\reg.exe" query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile">sixth3.txt
echo.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]>>FRST2.txt
type sixth3.txt | find /i "REG_DWORD">>FRST2.txt
echo.>>FRST2.txt
"%windir%\sysnative\reg.exe" query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile">sixth4.txt
echo.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]>>FRST2.txt
type sixth4.txt | find /i "REG_DWORD">>FRST2.txt
echo.>>FRST2.txt
"%windir%\sysnative\reg.exe" export "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list" sixth5.txt >nul 2>&1
type sixth5.txt | find /i "\\" >nul & IF NOT ERRORLEVEL 1 (
type sixth5.txt | find /i /v "Windows Registry Editor Version 5.00">>FRST2.txt) ELSE (
echo.[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]>>FRST2.txt
echo.>>FRST2.txt)
"%windir%\sysnative\reg.exe" export "HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list" sixth6.txt >nul 2>&1
type sixth6.txt | find /i "\\" >nul & IF NOT ERRORLEVEL 1 (
type sixth6.txt | find /i /v "Windows Registry Editor Version 5.00">>FRST2.txt) ELSE (
echo.[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]>>FRST2.txt
echo.>>FRST2.txt)
"%windir%\sysnative\reg.exe" export "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List" sixth8.txt >nul 2>&1
echo.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]>>FRST2.txt
if exist sixth8.txt type sixth8.txt | find /i ":">>FRST2.txt
echo.>>FRST2.txt
"%windir%\sysnative\reg.exe" export "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List" sixth9.txt >nul 2>&1
echo.[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]>>FRST2.txt
if exist sixth9.txt type sixth9.txt | find /i ":">>FRST2.txt

::SystemRestore
echo.>>FRST2.txt 
echo.>>FRST2.txt 
echo.***** System Restore *****>>FRST2.txt
"%windir%\sysnative\reg.exe" export "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore" seventh.txt >nul 2>&1
echo.>>FRST2.txt
type seventh.txt | find /i "SystemRestore]">>FRST2.txt
type seventh.txt | find /i "DisableSR">>FRST2.txt
::********************   64bit oS - end  ********************


::Kompletace logu
:Kompletace
echo.>>FRST2.txt
echo.>>FRST2.txt 
echo.==================== End Of Log ==============================>>FRST2.txt
type FRST2.txt | find /i /v "\cmd.exe" | find /i /v "ping.exe" | find /i /v "00154232" | find /i /v "\LM.bat" | find /i /v "\MSGBOX.exe">>FRST3.txt
del /a /f /q FRST.txt
del /a /f /q FRST2.txt
if exist "%userprofile%\AppData\Local" (
dir "%userprofile%\AppData\Local" /B >>FRSTL.txt
type FRSTL.txt | find /i "qb">>FRSTL2.txt
for /F "TOKENS=*" %%g IN ( FRSTL2.txt ) DO @RD /s /q "%userprofile%\AppData\Local\%%g" 2>NUL
)
move /y FRST3.txt FRST.txt

::Mazani docastnych souboru\slozek
del /a /f /q "first*.txt"
del /a /f /q "sixth?.txt"
del /a /f /q "seventh.txt"
del /a /f /q "eighth?.txt"
del /a /f /q "SecurityCenter?.vbs"
del /a /f /q "SecurityCenter.txt"
del /a /f /q "FRSTL?.txt"
del /a /f /q "%userprofile%\AppData\Local\MSGBOX.exe"

::Spusteni vysledneho logu
cls
notepad FRST.txt
del %0 2>NUL
exit

::Pokud neni vytvoreny Addition.txt skoci LM.bat primo sem a ukonci se. 
:End
del %0 2>NUL
exit
========= End of CMD: =========


========= type "D:\backup.bat" =========

robocopy /e /purge c:\Users\lysov\Documents\Data\ e:\Backup\Data\
robocopy /e /purge c:\Users\lysov\Desktop\ e:\Backup\Desktop\
========= End of CMD: =========

"HKU\S-1-5-21-2994255237-3946984938-1703718942-1001\Software\Microsoft\Internet Explorer\Main\\Start Page Redirect Cache" => removed successfully
C:\Users\lysov\AppData\Local\MSGBOX.EXE => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{128DC5AE-C306-4F93-A6B8-C44B19609C6A} => could not remove key. ErrorCode1: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{128DC5AE-C306-4F93-A6B8-C44B19609C6A} => could not remove key. ErrorCode1: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => could not remove key. ErrorCode1: 0x00000001
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{CF4D5C80-23E2-4FBE-BF9A-6B1139EF793A} => could not remove key. ErrorCode1: 0x00000002
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CF4D5C80-23E2-4FBE-BF9A-6B1139EF793A} => key not found
"C:\WINDOWS\System32\Tasks\AutoKMS" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS => key not found
C:\Windows\AutoKMS => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 6053888 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12871944 B
Java, Flash, Steam htmlcache => 506 B
Windows/system/drivers => 1613682 B
Edge => 1769352 B
Chrome => 0 B
Firefox => 0 B
Opera => 466435931 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 2678 B
defaultuser0 => 0 B
lysov => 2433538 B

RecycleBin => 112748 B
EmptyTemp: => 468.5 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 25-02-2018 15:14:37)


Result of scheduled keys to remove after reboot:

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{128DC5AE-C306-4F93-A6B8-C44B19609C6A}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{128DC5AE-C306-4F93-A6B8-C44B19609C6A}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{CF4D5C80-23E2-4FBE-BF9A-6B1139EF793A}" => removed successfully

==== End of Fixlog 15:14:37 ====

sfcdetails:

2018-02-25 16:09:48, Info CSI 00000010 [SR] Verifying 100 components
2018-02-25 16:09:48, Info CSI 00000011 [SR] Beginning Verify and Repair transaction
2018-02-25 16:09:50, Info CSI 00000076 [SR] Verify complete
2018-02-25 16:09:50, Info CSI 00000077 [SR] Verifying 100 components
2018-02-25 16:09:50, Info CSI 00000078 [SR] Beginning Verify and Repair transaction
2018-02-25 16:09:52, Info CSI 000000dd [SR] Verify complete
2018-02-25 16:09:53, Info CSI 000000de [SR] Verifying 100 components
2018-02-25 16:09:53, Info CSI 000000df [SR] Beginning Verify and Repair transaction
2018-02-25 16:09:55, Info CSI 00000144 [SR] Verify complete
2018-02-25 16:09:55, Info CSI 00000145 [SR] Verifying 100 components
2018-02-25 16:09:55, Info CSI 00000146 [SR] Beginning Verify and Repair transaction
2018-02-25 16:09:58, Info CSI 000001ab [SR] Verify complete
2018-02-25 16:09:58, Info CSI 000001ac [SR] Verifying 100 components
2018-02-25 16:09:58, Info CSI 000001ad [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:00, Info CSI 00000212 [SR] Verify complete
2018-02-25 16:10:01, Info CSI 00000213 [SR] Verifying 100 components
2018-02-25 16:10:01, Info CSI 00000214 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:03, Info CSI 00000279 [SR] Verify complete
2018-02-25 16:10:03, Info CSI 0000027a [SR] Verifying 100 components
2018-02-25 16:10:03, Info CSI 0000027b [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:07, Info CSI 000002e0 [SR] Verify complete
2018-02-25 16:10:07, Info CSI 000002e1 [SR] Verifying 100 components
2018-02-25 16:10:07, Info CSI 000002e2 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:09, Info CSI 00000347 [SR] Verify complete
2018-02-25 16:10:09, Info CSI 00000348 [SR] Verifying 100 components
2018-02-25 16:10:09, Info CSI 00000349 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:11, Info CSI 000003ae [SR] Verify complete
2018-02-25 16:10:12, Info CSI 000003af [SR] Verifying 100 components
2018-02-25 16:10:12, Info CSI 000003b0 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:14, Info CSI 00000415 [SR] Verify complete
2018-02-25 16:10:14, Info CSI 00000416 [SR] Verifying 100 components
2018-02-25 16:10:14, Info CSI 00000417 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:17, Info CSI 0000047c [SR] Verify complete
2018-02-25 16:10:17, Info CSI 0000047d [SR] Verifying 100 components
2018-02-25 16:10:17, Info CSI 0000047e [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:20, Info CSI 000004e3 [SR] Verify complete
2018-02-25 16:10:20, Info CSI 000004e4 [SR] Verifying 100 components
2018-02-25 16:10:20, Info CSI 000004e5 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:24, Info CSI 0000054d [SR] Verify complete
2018-02-25 16:10:24, Info CSI 0000054e [SR] Verifying 100 components
2018-02-25 16:10:24, Info CSI 0000054f [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:27, Info CSI 000005b4 [SR] Verify complete
2018-02-25 16:10:27, Info CSI 000005b5 [SR] Verifying 100 components
2018-02-25 16:10:27, Info CSI 000005b6 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:29, Info CSI 0000061b [SR] Verify complete
2018-02-25 16:10:29, Info CSI 0000061c [SR] Verifying 100 components
2018-02-25 16:10:29, Info CSI 0000061d [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:32, Info CSI 00000682 [SR] Verify complete
2018-02-25 16:10:32, Info CSI 00000683 [SR] Verifying 100 components
2018-02-25 16:10:32, Info CSI 00000684 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:36, Info CSI 000006e9 [SR] Verify complete
2018-02-25 16:10:36, Info CSI 000006ea [SR] Verifying 100 components
2018-02-25 16:10:36, Info CSI 000006eb [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:39, Info CSI 00000750 [SR] Verify complete
2018-02-25 16:10:39, Info CSI 00000751 [SR] Verifying 100 components
2018-02-25 16:10:39, Info CSI 00000752 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:42, Info CSI 000007b7 [SR] Verify complete
2018-02-25 16:10:42, Info CSI 000007b8 [SR] Verifying 100 components
2018-02-25 16:10:42, Info CSI 000007b9 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:46, Info CSI 0000081e [SR] Verify complete
2018-02-25 16:10:46, Info CSI 0000081f [SR] Verifying 100 components
2018-02-25 16:10:46, Info CSI 00000820 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:49, Info CSI 00000885 [SR] Verify complete
2018-02-25 16:10:49, Info CSI 00000886 [SR] Verifying 100 components
2018-02-25 16:10:49, Info CSI 00000887 [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:52, Info CSI 000008ec [SR] Verify complete
2018-02-25 16:10:52, Info CSI 000008ed [SR] Verifying 100 components
2018-02-25 16:10:52, Info CSI 000008ee [SR] Beginning Verify and Repair transaction
2018-02-25 16:10:55, Info CSI 00000953 [SR] Verify complete
2018-02-25 16:10:55, Info CSI 00000954 [SR] Verifying 100 components
2018-02-25 16:10:55, Info CSI 00000955 [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:00, Info CSI 000009ba [SR] Verify complete
2018-02-25 16:11:00, Info CSI 000009bb [SR] Verifying 100 components
2018-02-25 16:11:00, Info CSI 000009bc [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:04, Info CSI 00000a22 [SR] Verify complete
2018-02-25 16:11:04, Info CSI 00000a23 [SR] Verifying 100 components
2018-02-25 16:11:04, Info CSI 00000a24 [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:07, Info CSI 00000a89 [SR] Verify complete
2018-02-25 16:11:07, Info CSI 00000a8a [SR] Verifying 100 components
2018-02-25 16:11:07, Info CSI 00000a8b [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:10, Info CSI 00000af0 [SR] Verify complete
2018-02-25 16:11:10, Info CSI 00000af1 [SR] Verifying 100 components
2018-02-25 16:11:10, Info CSI 00000af2 [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:13, Info CSI 00000b59 [SR] Verify complete
2018-02-25 16:11:13, Info CSI 00000b5a [SR] Verifying 100 components
2018-02-25 16:11:13, Info CSI 00000b5b [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:18, Info CSI 00000bcb [SR] Verify complete
2018-02-25 16:11:19, Info CSI 00000bcc [SR] Verifying 100 components
2018-02-25 16:11:19, Info CSI 00000bcd [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:22, Info CSI 00000c39 [SR] Verify complete
2018-02-25 16:11:22, Info CSI 00000c3a [SR] Verifying 100 components
2018-02-25 16:11:22, Info CSI 00000c3b [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:27, Info CSI 00000ca6 [SR] Verify complete
2018-02-25 16:11:27, Info CSI 00000ca7 [SR] Verifying 100 components
2018-02-25 16:11:27, Info CSI 00000ca8 [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:32, Info CSI 00000d1d [SR] Verify complete
2018-02-25 16:11:32, Info CSI 00000d1e [SR] Verifying 100 components
2018-02-25 16:11:32, Info CSI 00000d1f [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:37, Info CSI 00000d8a [SR] Verify complete
2018-02-25 16:11:37, Info CSI 00000d8b [SR] Verifying 100 components
2018-02-25 16:11:37, Info CSI 00000d8c [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:40, Info CSI 00000df3 [SR] Verify complete
2018-02-25 16:11:40, Info CSI 00000df4 [SR] Verifying 100 components
2018-02-25 16:11:40, Info CSI 00000df5 [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:44, Info CSI 00000e60 [SR] Verify complete
2018-02-25 16:11:44, Info CSI 00000e61 [SR] Verifying 100 components
2018-02-25 16:11:44, Info CSI 00000e62 [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:50, Info CSI 00000ec7 [SR] Verify complete
2018-02-25 16:11:50, Info CSI 00000ec8 [SR] Verifying 100 components
2018-02-25 16:11:50, Info CSI 00000ec9 [SR] Beginning Verify and Repair transaction
2018-02-25 16:11:55, Info CSI 00000f2f [SR] Verify complete
2018-02-25 16:11:55, Info CSI 00000f30 [SR] Verifying 100 components
2018-02-25 16:11:55, Info CSI 00000f31 [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:02, Info CSI 00000f9c [SR] Verify complete
2018-02-25 16:12:02, Info CSI 00000f9d [SR] Verifying 100 components
2018-02-25 16:12:02, Info CSI 00000f9e [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:11, Info CSI 00001069 [SR] Verify complete
2018-02-25 16:12:11, Info CSI 0000106a [SR] Verifying 100 components
2018-02-25 16:12:11, Info CSI 0000106b [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:19, Info CSI 0000116a [SR] Verify complete
2018-02-25 16:12:20, Info CSI 0000116b [SR] Verifying 100 components
2018-02-25 16:12:20, Info CSI 0000116c [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:25, Info CSI 000011db [SR] Verify complete
2018-02-25 16:12:25, Info CSI 000011dc [SR] Verifying 100 components
2018-02-25 16:12:25, Info CSI 000011dd [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:31, Info CSI 0000124a [SR] Verify complete
2018-02-25 16:12:31, Info CSI 0000124b [SR] Verifying 100 components
2018-02-25 16:12:31, Info CSI 0000124c [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:36, Info CSI 000012bf [SR] Verify complete
2018-02-25 16:12:36, Info CSI 000012c0 [SR] Verifying 100 components
2018-02-25 16:12:36, Info CSI 000012c1 [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:41, Info CSI 0000133a [SR] Verify complete
2018-02-25 16:12:41, Info CSI 0000133b [SR] Verifying 100 components
2018-02-25 16:12:41, Info CSI 0000133c [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:45, Info CSI 000013ac [SR] Verify complete
2018-02-25 16:12:45, Info CSI 000013ad [SR] Verifying 100 components
2018-02-25 16:12:45, Info CSI 000013ae [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:51, Info CSI 00001414 [SR] Verify complete
2018-02-25 16:12:51, Info CSI 00001415 [SR] Verifying 100 components
2018-02-25 16:12:51, Info CSI 00001416 [SR] Beginning Verify and Repair transaction
2018-02-25 16:12:57, Info CSI 0000147e [SR] Verify complete
2018-02-25 16:12:57, Info CSI 0000147f [SR] Verifying 100 components
2018-02-25 16:12:57, Info CSI 00001480 [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:01, Info CSI 000014e8 [SR] Verify complete
2018-02-25 16:13:01, Info CSI 000014e9 [SR] Verifying 100 components
2018-02-25 16:13:01, Info CSI 000014ea [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:06, Info CSI 00001559 [SR] Verify complete
2018-02-25 16:13:06, Info CSI 0000155a [SR] Verifying 100 components
2018-02-25 16:13:06, Info CSI 0000155b [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:12, Info CSI 000015dc [SR] Verify complete
2018-02-25 16:13:12, Info CSI 000015dd [SR] Verifying 100 components
2018-02-25 16:13:12, Info CSI 000015de [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:19, Info CSI 0000167a [SR] Verify complete
2018-02-25 16:13:19, Info CSI 0000167b [SR] Verifying 100 components
2018-02-25 16:13:19, Info CSI 0000167c [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:30, Info CSI 00001779 [SR] Verify complete
2018-02-25 16:13:30, Info CSI 0000177a [SR] Verifying 100 components
2018-02-25 16:13:30, Info CSI 0000177b [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:35, Info CSI 000017ed [SR] Verify complete
2018-02-25 16:13:35, Info CSI 000017ee [SR] Verifying 100 components
2018-02-25 16:13:35, Info CSI 000017ef [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:40, Info CSI 0000185b [SR] Verify complete
2018-02-25 16:13:41, Info CSI 0000185c [SR] Verifying 100 components
2018-02-25 16:13:41, Info CSI 0000185d [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:50, Info CSI 00001936 [SR] Verify complete
2018-02-25 16:13:50, Info CSI 00001937 [SR] Verifying 100 components
2018-02-25 16:13:50, Info CSI 00001938 [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:53, Info CSI 0000199d [SR] Verify complete
2018-02-25 16:13:53, Info CSI 0000199e [SR] Verifying 100 components
2018-02-25 16:13:53, Info CSI 0000199f [SR] Beginning Verify and Repair transaction
2018-02-25 16:13:56, Info CSI 00001a04 [SR] Verify complete
2018-02-25 16:13:56, Info CSI 00001a05 [SR] Verifying 100 components
2018-02-25 16:13:56, Info CSI 00001a06 [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:03, Info CSI 00001a7b [SR] Verify complete
2018-02-25 16:14:03, Info CSI 00001a7c [SR] Verifying 100 components
2018-02-25 16:14:03, Info CSI 00001a7d [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:10, Info CSI 00001af3 [SR] Verify complete
2018-02-25 16:14:10, Info CSI 00001af4 [SR] Verifying 100 components
2018-02-25 16:14:10, Info CSI 00001af5 [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:17, Info CSI 00001b6d [SR] Verify complete
2018-02-25 16:14:17, Info CSI 00001b6e [SR] Verifying 100 components
2018-02-25 16:14:17, Info CSI 00001b6f [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:21, Info CSI 00001bda [SR] Verify complete
2018-02-25 16:14:21, Info CSI 00001bdb [SR] Verifying 100 components
2018-02-25 16:14:21, Info CSI 00001bdc [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:25, Info CSI 00001c4d [SR] Verify complete
2018-02-25 16:14:26, Info CSI 00001c4e [SR] Verifying 100 components
2018-02-25 16:14:26, Info CSI 00001c4f [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:31, Info CSI 00001cc2 [SR] Verify complete
2018-02-25 16:14:31, Info CSI 00001cc3 [SR] Verifying 100 components
2018-02-25 16:14:31, Info CSI 00001cc4 [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:37, Info CSI 00001d55 [SR] Verify complete
2018-02-25 16:14:37, Info CSI 00001d56 [SR] Verifying 100 components
2018-02-25 16:14:37, Info CSI 00001d57 [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:40, Info CSI 00001dc0 [SR] Verify complete
2018-02-25 16:14:40, Info CSI 00001dc1 [SR] Verifying 100 components
2018-02-25 16:14:40, Info CSI 00001dc2 [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:44, Info CSI 00001e28 [SR] Verify complete
2018-02-25 16:14:44, Info CSI 00001e29 [SR] Verifying 100 components
2018-02-25 16:14:44, Info CSI 00001e2a [SR] Beginning Verify and Repair transaction
2018-02-25 16:14:49, Info CSI 00001e94 [SR] Verify complete
2018-02-25 16:14:49, Info CSI 00001e95 [SR] Verifying 100 components
2018-02-25 16:14:49, Info CSI 00001e96 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:02, Info CSI 00001f8a [SR] Verify complete
2018-02-25 16:15:02, Info CSI 00001f8b [SR] Verifying 100 components
2018-02-25 16:15:02, Info CSI 00001f8c [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:07, Info CSI 00001ff8 [SR] Verify complete
2018-02-25 16:15:07, Info CSI 00001ff9 [SR] Verifying 100 components
2018-02-25 16:15:07, Info CSI 00001ffa [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:11, Info CSI 00002061 [SR] Verify complete
2018-02-25 16:15:11, Info CSI 00002062 [SR] Verifying 100 components
2018-02-25 16:15:11, Info CSI 00002063 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:17, Info CSI 000020e6 [SR] Verify complete
2018-02-25 16:15:17, Info CSI 000020e7 [SR] Verifying 100 components
2018-02-25 16:15:17, Info CSI 000020e8 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:24, Info CSI 00002153 [SR] Verify complete
2018-02-25 16:15:25, Info CSI 00002154 [SR] Verifying 100 components
2018-02-25 16:15:25, Info CSI 00002155 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:29, Info CSI 000021be [SR] Verify complete
2018-02-25 16:15:29, Info CSI 000021bf [SR] Verifying 100 components
2018-02-25 16:15:29, Info CSI 000021c0 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:33, Info CSI 00002232 [SR] Verify complete
2018-02-25 16:15:33, Info CSI 00002233 [SR] Verifying 100 components
2018-02-25 16:15:33, Info CSI 00002234 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:36, Info CSI 000022a7 [SR] Verify complete
2018-02-25 16:15:36, Info CSI 000022a8 [SR] Verifying 100 components
2018-02-25 16:15:36, Info CSI 000022a9 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:41, Info CSI 00002313 [SR] Verify complete
2018-02-25 16:15:41, Info CSI 00002314 [SR] Verifying 100 components
2018-02-25 16:15:41, Info CSI 00002315 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:47, Info CSI 0000239d [SR] Verify complete
2018-02-25 16:15:47, Info CSI 0000239e [SR] Verifying 100 components
2018-02-25 16:15:47, Info CSI 0000239f [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:54, Info CSI 00002492 [SR] Verify complete
2018-02-25 16:15:54, Info CSI 00002493 [SR] Verifying 100 components
2018-02-25 16:15:54, Info CSI 00002494 [SR] Beginning Verify and Repair transaction
2018-02-25 16:15:59, Info CSI 00002508 [SR] Verify complete
2018-02-25 16:15:59, Info CSI 00002509 [SR] Verifying 100 components
2018-02-25 16:15:59, Info CSI 0000250a [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:03, Info CSI 00002573 [SR] Verify complete
2018-02-25 16:16:03, Info CSI 00002574 [SR] Verifying 100 components
2018-02-25 16:16:03, Info CSI 00002575 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:06, Info CSI 000025e0 [SR] Verify complete
2018-02-25 16:16:06, Info CSI 000025e1 [SR] Verifying 100 components
2018-02-25 16:16:06, Info CSI 000025e2 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:10, Info CSI 00002654 [SR] Verify complete
2018-02-25 16:16:11, Info CSI 00002655 [SR] Verifying 100 components
2018-02-25 16:16:11, Info CSI 00002656 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:14, Info CSI 000026bb [SR] Verify complete
2018-02-25 16:16:14, Info CSI 000026bc [SR] Verifying 100 components
2018-02-25 16:16:14, Info CSI 000026bd [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:17, Info CSI 00002728 [SR] Verify complete
2018-02-25 16:16:18, Info CSI 00002729 [SR] Verifying 100 components
2018-02-25 16:16:18, Info CSI 0000272a [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:22, Info CSI 0000279c [SR] Verify complete
2018-02-25 16:16:22, Info CSI 0000279d [SR] Verifying 100 components
2018-02-25 16:16:22, Info CSI 0000279e [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:26, Info CSI 00002814 [SR] Verify complete
2018-02-25 16:16:26, Info CSI 00002815 [SR] Verifying 100 components
2018-02-25 16:16:26, Info CSI 00002816 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:31, Info CSI 00002884 [SR] Verify complete
2018-02-25 16:16:31, Info CSI 00002885 [SR] Verifying 100 components
2018-02-25 16:16:31, Info CSI 00002886 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:40, Info CSI 00002931 [SR] Verify complete
2018-02-25 16:16:40, Info CSI 00002932 [SR] Verifying 100 components
2018-02-25 16:16:40, Info CSI 00002933 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:45, Info CSI 000029a6 [SR] Verify complete
2018-02-25 16:16:45, Info CSI 000029a7 [SR] Verifying 100 components
2018-02-25 16:16:45, Info CSI 000029a8 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:50, Info CSI 00002a13 [SR] Verify complete
2018-02-25 16:16:50, Info CSI 00002a14 [SR] Verifying 100 components
2018-02-25 16:16:50, Info CSI 00002a15 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:54, Info CSI 00002a86 [SR] Verify complete
2018-02-25 16:16:54, Info CSI 00002a87 [SR] Verifying 100 components
2018-02-25 16:16:54, Info CSI 00002a88 [SR] Beginning Verify and Repair transaction
2018-02-25 16:16:58, Info CSI 00002af3 [SR] Verify complete
2018-02-25 16:16:59, Info CSI 00002af4 [SR] Verifying 100 components
2018-02-25 16:16:59, Info CSI 00002af5 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:03, Info CSI 00002b63 [SR] Verify complete
2018-02-25 16:17:03, Info CSI 00002b64 [SR] Verifying 100 components
2018-02-25 16:17:03, Info CSI 00002b65 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:08, Info CSI 00002bcf [SR] Verify complete
2018-02-25 16:17:08, Info CSI 00002bd0 [SR] Verifying 100 components
2018-02-25 16:17:08, Info CSI 00002bd1 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:13, Info CSI 00002c3f [SR] Verify complete
2018-02-25 16:17:14, Info CSI 00002c40 [SR] Verifying 100 components
2018-02-25 16:17:14, Info CSI 00002c41 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:18, Info CSI 00002cb6 [SR] Verify complete
2018-02-25 16:17:18, Info CSI 00002cb7 [SR] Verifying 100 components
2018-02-25 16:17:18, Info CSI 00002cb8 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:22, Info CSI 00002d23 [SR] Verify complete
2018-02-25 16:17:22, Info CSI 00002d24 [SR] Verifying 100 components
2018-02-25 16:17:22, Info CSI 00002d25 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:27, Info CSI 00002d90 [SR] Verify complete
2018-02-25 16:17:27, Info CSI 00002d91 [SR] Verifying 100 components
2018-02-25 16:17:27, Info CSI 00002d92 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:31, Info CSI 00002dff [SR] Verify complete
2018-02-25 16:17:31, Info CSI 00002e00 [SR] Verifying 100 components
2018-02-25 16:17:31, Info CSI 00002e01 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:36, Info CSI 00002e69 [SR] Verify complete
2018-02-25 16:17:36, Info CSI 00002e6a [SR] Verifying 100 components
2018-02-25 16:17:36, Info CSI 00002e6b [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:40, Info CSI 00002ed0 [SR] Verify complete
2018-02-25 16:17:40, Info CSI 00002ed1 [SR] Verifying 100 components
2018-02-25 16:17:40, Info CSI 00002ed2 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:47, Info CSI 00002f40 [SR] Verify complete
2018-02-25 16:17:47, Info CSI 00002f41 [SR] Verifying 100 components
2018-02-25 16:17:47, Info CSI 00002f42 [SR] Beginning Verify and Repair transaction
2018-02-25 16:17:58, Info CSI 00002fe7 [SR] Verify complete
2018-02-25 16:17:58, Info CSI 00002fe8 [SR] Verifying 100 components
2018-02-25 16:17:58, Info CSI 00002fe9 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:02, Info CSI 0000305e [SR] Verify complete
2018-02-25 16:18:02, Info CSI 0000305f [SR] Verifying 100 components
2018-02-25 16:18:02, Info CSI 00003060 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:07, Info CSI 000030d7 [SR] Verify complete
2018-02-25 16:18:07, Info CSI 000030d8 [SR] Verifying 100 components
2018-02-25 16:18:07, Info CSI 000030d9 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:10, Info CSI 0000313e [SR] Verify complete
2018-02-25 16:18:10, Info CSI 0000313f [SR] Verifying 100 components
2018-02-25 16:18:10, Info CSI 00003140 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:14, Info CSI 000031a5 [SR] Verify complete
2018-02-25 16:18:14, Info CSI 000031a6 [SR] Verifying 100 components
2018-02-25 16:18:14, Info CSI 000031a7 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:18, Info CSI 0000320c [SR] Verify complete
2018-02-25 16:18:18, Info CSI 0000320d [SR] Verifying 100 components
2018-02-25 16:18:18, Info CSI 0000320e [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:23, Info CSI 00003274 [SR] Verify complete
2018-02-25 16:18:23, Info CSI 00003275 [SR] Verifying 100 components
2018-02-25 16:18:23, Info CSI 00003276 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:26, Info CSI 000032dc [SR] Verify complete
2018-02-25 16:18:26, Info CSI 000032dd [SR] Verifying 100 components
2018-02-25 16:18:26, Info CSI 000032de [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:30, Info CSI 00003344 [SR] Verify complete
2018-02-25 16:18:30, Info CSI 00003345 [SR] Verifying 100 components
2018-02-25 16:18:30, Info CSI 00003346 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:34, Info CSI 000033ab [SR] Verify complete
2018-02-25 16:18:34, Info CSI 000033ac [SR] Verifying 100 components
2018-02-25 16:18:34, Info CSI 000033ad [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:40, Info CSI 00003414 [SR] Verify complete
2018-02-25 16:18:40, Info CSI 00003415 [SR] Verifying 100 components
2018-02-25 16:18:40, Info CSI 00003416 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:43, Info CSI 0000347b [SR] Verify complete
2018-02-25 16:18:43, Info CSI 0000347c [SR] Verifying 100 components
2018-02-25 16:18:43, Info CSI 0000347d [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:47, Info CSI 000034e3 [SR] Verify complete
2018-02-25 16:18:47, Info CSI 000034e4 [SR] Verifying 100 components
2018-02-25 16:18:47, Info CSI 000034e5 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:50, Info CSI 0000354d [SR] Verify complete
2018-02-25 16:18:50, Info CSI 0000354e [SR] Verifying 100 components
2018-02-25 16:18:50, Info CSI 0000354f [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:53, Info CSI 000035b4 [SR] Verify complete
2018-02-25 16:18:53, Info CSI 000035b5 [SR] Verifying 100 components
2018-02-25 16:18:53, Info CSI 000035b6 [SR] Beginning Verify and Repair transaction
2018-02-25 16:18:57, Info CSI 00003621 [SR] Verify complete
2018-02-25 16:18:57, Info CSI 00003622 [SR] Verifying 100 components
2018-02-25 16:18:57, Info CSI 00003623 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:01, Info CSI 00003689 [SR] Verify complete
2018-02-25 16:19:01, Info CSI 0000368a [SR] Verifying 100 components
2018-02-25 16:19:01, Info CSI 0000368b [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:04, Info CSI 000036f0 [SR] Verify complete
2018-02-25 16:19:04, Info CSI 000036f1 [SR] Verifying 100 components
2018-02-25 16:19:04, Info CSI 000036f2 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:07, Info CSI 00003757 [SR] Verify complete
2018-02-25 16:19:07, Info CSI 00003758 [SR] Verifying 100 components
2018-02-25 16:19:07, Info CSI 00003759 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:10, Info CSI 000037be [SR] Verify complete
2018-02-25 16:19:10, Info CSI 000037bf [SR] Verifying 100 components
2018-02-25 16:19:10, Info CSI 000037c0 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:13, Info CSI 00003825 [SR] Verify complete
2018-02-25 16:19:13, Info CSI 00003826 [SR] Verifying 100 components
2018-02-25 16:19:13, Info CSI 00003827 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:23, Info CSI 00003895 [SR] Verify complete
2018-02-25 16:19:23, Info CSI 00003896 [SR] Verifying 100 components
2018-02-25 16:19:23, Info CSI 00003897 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:28, Info CSI 00003900 [SR] Verify complete
2018-02-25 16:19:28, Info CSI 00003901 [SR] Verifying 100 components
2018-02-25 16:19:28, Info CSI 00003902 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:32, Info CSI 00003969 [SR] Verify complete
2018-02-25 16:19:32, Info CSI 0000396a [SR] Verifying 100 components
2018-02-25 16:19:32, Info CSI 0000396b [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:34, Info CSI 000039d1 [SR] Verify complete
2018-02-25 16:19:35, Info CSI 000039d2 [SR] Verifying 100 components
2018-02-25 16:19:35, Info CSI 000039d3 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:38, Info CSI 00003a45 [SR] Verify complete
2018-02-25 16:19:38, Info CSI 00003a46 [SR] Verifying 100 components
2018-02-25 16:19:38, Info CSI 00003a47 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:42, Info CSI 00003ab4 [SR] Verify complete
2018-02-25 16:19:42, Info CSI 00003ab5 [SR] Verifying 100 components
2018-02-25 16:19:42, Info CSI 00003ab6 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:45, Info CSI 00003b1b [SR] Verify complete
2018-02-25 16:19:45, Info CSI 00003b1c [SR] Verifying 100 components
2018-02-25 16:19:45, Info CSI 00003b1d [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:48, Info CSI 00003b82 [SR] Verify complete
2018-02-25 16:19:48, Info CSI 00003b83 [SR] Verifying 100 components
2018-02-25 16:19:48, Info CSI 00003b84 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:51, Info CSI 00003be9 [SR] Verify complete
2018-02-25 16:19:51, Info CSI 00003bea [SR] Verifying 100 components
2018-02-25 16:19:51, Info CSI 00003beb [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:54, Info CSI 00003c50 [SR] Verify complete
2018-02-25 16:19:54, Info CSI 00003c51 [SR] Verifying 100 components
2018-02-25 16:19:54, Info CSI 00003c52 [SR] Beginning Verify and Repair transaction
2018-02-25 16:19:58, Info CSI 00003cb8 [SR] Verify complete
2018-02-25 16:19:58, Info CSI 00003cb9 [SR] Verifying 100 components
2018-02-25 16:19:58, Info CSI 00003cba [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:01, Info CSI 00003d26 [SR] Verify complete
2018-02-25 16:20:01, Info CSI 00003d27 [SR] Verifying 100 components
2018-02-25 16:20:01, Info CSI 00003d28 [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:05, Info CSI 00003d8d [SR] Verify complete
2018-02-25 16:20:05, Info CSI 00003d8e [SR] Verifying 100 components
2018-02-25 16:20:05, Info CSI 00003d8f [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:08, Info CSI 00003df6 [SR] Verify complete
2018-02-25 16:20:08, Info CSI 00003df7 [SR] Verifying 100 components
2018-02-25 16:20:08, Info CSI 00003df8 [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:12, Info CSI 00003e5d [SR] Verify complete
2018-02-25 16:20:12, Info CSI 00003e5e [SR] Verifying 100 components
2018-02-25 16:20:12, Info CSI 00003e5f [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:19, Info CSI 00003f0b [SR] Verify complete
2018-02-25 16:20:19, Info CSI 00003f0c [SR] Verifying 100 components
2018-02-25 16:20:19, Info CSI 00003f0d [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:22, Info CSI 00003f72 [SR] Verify complete
2018-02-25 16:20:22, Info CSI 00003f73 [SR] Verifying 100 components
2018-02-25 16:20:22, Info CSI 00003f74 [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:26, Info CSI 00003fdb [SR] Verify complete
2018-02-25 16:20:26, Info CSI 00003fdc [SR] Verifying 100 components
2018-02-25 16:20:26, Info CSI 00003fdd [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:30, Info CSI 0000404a [SR] Verify complete
2018-02-25 16:20:30, Info CSI 0000404b [SR] Verifying 100 components
2018-02-25 16:20:30, Info CSI 0000404c [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:34, Info CSI 000040b2 [SR] Verify complete
2018-02-25 16:20:35, Info CSI 000040b3 [SR] Verifying 100 components
2018-02-25 16:20:35, Info CSI 000040b4 [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:38, Info CSI 00004119 [SR] Verify complete
2018-02-25 16:20:38, Info CSI 0000411a [SR] Verifying 100 components
2018-02-25 16:20:38, Info CSI 0000411b [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:44, Info CSI 000041c1 [SR] Verify complete
2018-02-25 16:20:44, Info CSI 000041c2 [SR] Verifying 100 components
2018-02-25 16:20:44, Info CSI 000041c3 [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:49, Info CSI 00004240 [SR] Verify complete
2018-02-25 16:20:49, Info CSI 00004241 [SR] Verifying 100 components
2018-02-25 16:20:49, Info CSI 00004242 [SR] Beginning Verify and Repair transaction
2018-02-25 16:20:57, Info CSI 000042c5 [SR] Verify complete
2018-02-25 16:20:57, Info CSI 000042c6 [SR] Verifying 100 components
2018-02-25 16:20:57, Info CSI 000042c7 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:01, Info CSI 00004330 [SR] Verify complete
2018-02-25 16:21:01, Info CSI 00004331 [SR] Verifying 100 components
2018-02-25 16:21:01, Info CSI 00004332 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:03, Info CSI 00004397 [SR] Verify complete
2018-02-25 16:21:03, Info CSI 00004398 [SR] Verifying 100 components
2018-02-25 16:21:03, Info CSI 00004399 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:07, Info CSI 00004406 [SR] Verify complete
2018-02-25 16:21:07, Info CSI 00004407 [SR] Verifying 100 components
2018-02-25 16:21:07, Info CSI 00004408 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:13, Info CSI 00004474 [SR] Verify complete
2018-02-25 16:21:13, Info CSI 00004475 [SR] Verifying 100 components
2018-02-25 16:21:13, Info CSI 00004476 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:16, Info CSI 000044db [SR] Verify complete
2018-02-25 16:21:16, Info CSI 000044dc [SR] Verifying 100 components
2018-02-25 16:21:16, Info CSI 000044dd [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:20, Info CSI 00004542 [SR] Verify complete
2018-02-25 16:21:20, Info CSI 00004543 [SR] Verifying 100 components
2018-02-25 16:21:20, Info CSI 00004544 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:23, Info CSI 000045aa [SR] Verify complete
2018-02-25 16:21:23, Info CSI 000045ab [SR] Verifying 100 components
2018-02-25 16:21:23, Info CSI 000045ac [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:28, Info CSI 00004616 [SR] Verify complete
2018-02-25 16:21:28, Info CSI 00004617 [SR] Verifying 100 components
2018-02-25 16:21:28, Info CSI 00004618 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:35, Info CSI 000046c2 [SR] Verify complete
2018-02-25 16:21:35, Info CSI 000046c3 [SR] Verifying 100 components
2018-02-25 16:21:35, Info CSI 000046c4 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:39, Info CSI 00004729 [SR] Verify complete
2018-02-25 16:21:39, Info CSI 0000472a [SR] Verifying 100 components
2018-02-25 16:21:39, Info CSI 0000472b [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:43, Info CSI 00004796 [SR] Verify complete
2018-02-25 16:21:43, Info CSI 00004797 [SR] Verifying 100 components
2018-02-25 16:21:43, Info CSI 00004798 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:49, Info CSI 000047fe [SR] Verify complete
2018-02-25 16:21:49, Info CSI 000047ff [SR] Verifying 100 components
2018-02-25 16:21:49, Info CSI 00004800 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:52, Info CSI 00004867 [SR] Verify complete
2018-02-25 16:21:53, Info CSI 00004868 [SR] Verifying 100 components
2018-02-25 16:21:53, Info CSI 00004869 [SR] Beginning Verify and Repair transaction
2018-02-25 16:21:59, Info CSI 0000491c [SR] Verify complete
2018-02-25 16:21:59, Info CSI 0000491d [SR] Verifying 100 components
2018-02-25 16:21:59, Info CSI 0000491e [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:03, Info CSI 00004987 [SR] Verify complete
2018-02-25 16:22:03, Info CSI 00004988 [SR] Verifying 100 components
2018-02-25 16:22:03, Info CSI 00004989 [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:07, Info CSI 000049f3 [SR] Verify complete
2018-02-25 16:22:07, Info CSI 000049f4 [SR] Verifying 100 components
2018-02-25 16:22:07, Info CSI 000049f5 [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:11, Info CSI 00004a5c [SR] Verify complete
2018-02-25 16:22:11, Info CSI 00004a5d [SR] Verifying 100 components
2018-02-25 16:22:11, Info CSI 00004a5e [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:15, Info CSI 00004ac3 [SR] Verify complete
2018-02-25 16:22:15, Info CSI 00004ac4 [SR] Verifying 100 components
2018-02-25 16:22:15, Info CSI 00004ac5 [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:21, Info CSI 00004b3a [SR] Verify complete
2018-02-25 16:22:21, Info CSI 00004b3b [SR] Verifying 100 components
2018-02-25 16:22:21, Info CSI 00004b3c [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:24, Info CSI 00004ba3 [SR] Verify complete
2018-02-25 16:22:25, Info CSI 00004ba4 [SR] Verifying 100 components
2018-02-25 16:22:25, Info CSI 00004ba5 [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:28, Info CSI 00004c12 [SR] Verify complete
2018-02-25 16:22:29, Info CSI 00004c13 [SR] Verifying 100 components
2018-02-25 16:22:29, Info CSI 00004c14 [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:33, Info CSI 00004c79 [SR] Verify complete
2018-02-25 16:22:33, Info CSI 00004c7a [SR] Verifying 100 components
2018-02-25 16:22:33, Info CSI 00004c7b [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:37, Info CSI 00004cea [SR] Verify complete
2018-02-25 16:22:37, Info CSI 00004ceb [SR] Verifying 100 components
2018-02-25 16:22:37, Info CSI 00004cec [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:41, Info CSI 00004d54 [SR] Verify complete
2018-02-25 16:22:41, Info CSI 00004d55 [SR] Verifying 100 components
2018-02-25 16:22:41, Info CSI 00004d56 [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:45, Info CSI 00004dbc [SR] Verify complete
2018-02-25 16:22:45, Info CSI 00004dbd [SR] Verifying 100 components
2018-02-25 16:22:45, Info CSI 00004dbe [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:50, Info CSI 00004e26 [SR] Verify complete
2018-02-25 16:22:50, Info CSI 00004e27 [SR] Verifying 100 components
2018-02-25 16:22:50, Info CSI 00004e28 [SR] Beginning Verify and Repair transaction
2018-02-25 16:22:58, Info CSI 00004ec9 [SR] Verify complete
2018-02-25 16:22:58, Info CSI 00004eca [SR] Verifying 100 components
2018-02-25 16:22:58, Info CSI 00004ecb [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:02, Info CSI 00004f31 [SR] Verify complete
2018-02-25 16:23:02, Info CSI 00004f32 [SR] Verifying 100 components
2018-02-25 16:23:02, Info CSI 00004f33 [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:07, Info CSI 00004fbc [SR] Verify complete
2018-02-25 16:23:07, Info CSI 00004fbd [SR] Verifying 100 components
2018-02-25 16:23:07, Info CSI 00004fbe [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:11, Info CSI 00005031 [SR] Verify complete
2018-02-25 16:23:12, Info CSI 00005032 [SR] Verifying 100 components
2018-02-25 16:23:12, Info CSI 00005033 [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:17, Info CSI 0000509c [SR] Verify complete
2018-02-25 16:23:17, Info CSI 0000509d [SR] Verifying 100 components
2018-02-25 16:23:17, Info CSI 0000509e [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:21, Info CSI 0000511b [SR] Verify complete
2018-02-25 16:23:21, Info CSI 0000511c [SR] Verifying 100 components
2018-02-25 16:23:21, Info CSI 0000511d [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:24, Info CSI 0000518a [SR] Verify complete
2018-02-25 16:23:24, Info CSI 0000518b [SR] Verifying 100 components
2018-02-25 16:23:24, Info CSI 0000518c [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:28, Info CSI 000051f1 [SR] Verify complete
2018-02-25 16:23:28, Info CSI 000051f2 [SR] Verifying 100 components
2018-02-25 16:23:28, Info CSI 000051f3 [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:31, Info CSI 00005258 [SR] Verify complete
2018-02-25 16:23:31, Info CSI 00005259 [SR] Verifying 100 components
2018-02-25 16:23:31, Info CSI 0000525a [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:35, Info CSI 000052c0 [SR] Verify complete
2018-02-25 16:23:35, Info CSI 000052c1 [SR] Verifying 100 components
2018-02-25 16:23:35, Info CSI 000052c2 [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:39, Info CSI 00005327 [SR] Verify complete
2018-02-25 16:23:39, Info CSI 00005328 [SR] Verifying 100 components
2018-02-25 16:23:39, Info CSI 00005329 [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:42, Info CSI 0000538f [SR] Verify complete
2018-02-25 16:23:42, Info CSI 00005390 [SR] Verifying 100 components
2018-02-25 16:23:42, Info CSI 00005391 [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:45, Info CSI 000053f6 [SR] Verify complete
2018-02-25 16:23:46, Info CSI 000053f7 [SR] Verifying 100 components
2018-02-25 16:23:46, Info CSI 000053f8 [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:50, Info CSI 0000545e [SR] Verify complete
2018-02-25 16:23:50, Info CSI 0000545f [SR] Verifying 9 components
2018-02-25 16:23:50, Info CSI 00005460 [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:51, Info CSI 0000546b [SR] Verify complete
2018-02-25 16:23:51, Info CSI 0000546c [SR] Repairing 0 components
2018-02-25 16:23:51, Info CSI 0000546d [SR] Beginning Verify and Repair transaction
2018-02-25 16:23:51, Info CSI 0000546e [SR] Repair complete

Re: prosim o preventivku

Napsal: 25 úno 2018 18:04
od Conder
:arrow: Poprosim o novy log z FRST

Re: prosim o preventivku

Napsal: 25 úno 2018 18:37
od roki
Nový log

Re: prosim o preventivku

Napsal: 25 úno 2018 19:03
od Conder
:arrow: Vyzera to uz OK.

:arrow: Skontroluj, velkost plochy (C:\Users\lysov\Desktop). Ak je vacsia ako 300 MB, presun vsetky subory a zlozky z plochy do dokumentov a na ploche nechaj iba odkazy/zastupcov. Prilis velka velkost plochy moze sposobit spomalenie systemu.

:arrow: Ak nie su dalsie problemy, tak este upraceme po pouzitych nastrojoch: :arrow: Subor "LM.bat" na ploche mozes zmazat.

Re: prosim o preventivku

Napsal: 25 úno 2018 19:41
od roki
na ploche by toho nemalo byt vela - o tom spomalení viem ;)

Diky za pomoc a asi mozte lock :)

Re: prosim o preventivku

Napsal: 26 úno 2018 15:04
od Conder
Nie je zaco, rad som pomohol :)