Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Problém s "AUEPMaster.exe" ale určitě tam nění sám .

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Alonzop
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 27 črc 2006 10:54
Bydliště: Czech Rep. - Brno
Kontaktovat uživatele:

Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#1 Příspěvek od Alonzop »

Zdravím kolegium moderatorum :worship:

Někde sem zakopl o havěť známou jako "AUEPMaster.exe" nevím co to púsobí , ale taha mi to int.přip na nějakou stránku amazon či co.
Věřím že je to pro Vás banální záležitostí. Tak jestli mohu poprosit o trochu Vašeho času s tím zatočit . Předem děkuji
Log z FRST :

Kód: Vybrat vše

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.11.2018
Ran by Alonzop (administrator) on X-COM (17-11-2018 17:05:01)
Running from C:\Users\Allonzo\Desktop
Loaded Profiles: Alonzop (Available Profiles: Alonzop)
Platform: Windows 10 Pro Version 1803 17134.345 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atiesrxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
() C:\Windows\KMS-R@1n.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\MsMpEng.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\NisSrv.exe
(AMD) C:\Windows\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atieclxx.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
() C:\Program Files (x86)\AUROZA\Monitor.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
() C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe
() C:\Program Files (x86)\Anvsoft\Syncios\androidnotifier.exe
() C:\Program Files (x86)\Anvsoft\Syncios\adb.exe
(Piriform Ltd) C:\Program Files\CCleaner\ccleaner64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amddvr.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\iDownloadManager.exe
() C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\Win32\iDownloaderConsole.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9277280 2018-09-15] (Realtek Semiconductor)
HKLM-x32\...\Run: [AUROZA EM02C Driver] => C:\Program Files (x86)\AUROZA\Monitor.exe [761856 2014-12-08] ()
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318112 2017-11-15] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3785536 2018-11-06] (Dropbox, Inc.)
HKLM-x32\...\Run: [Syncios device service] => C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe [2443384 2018-06-13] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [731240 2018-10-19] (Disc Soft Ltd)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19467544 2018-11-06] (Piriform Ltd)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {1669ae0c-807e-11e8-9d95-806e6f6e6963} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {46ad1614-e132-11e8-9e13-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {46ad162f-e132-11e8-9e13-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {54df9d64-b5fe-11e8-9dc4-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {61c59ad5-d962-11e8-9e02-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {61c59af6-d962-11e8-9e02-d43d7e9f40c1} - "H:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {65e6848a-c7fd-11e8-9de2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {65e684ca-c7fd-11e8-9de2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6b96590e-b026-11e8-9dc1-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6b965935-b026-11e8-9dc1-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6f7a13db-8f52-11e8-9da0-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6f7a13de-8f52-11e8-9da0-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {73d980a7-6ee3-11e8-9d88-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {73d980bf-6ee3-11e8-9d88-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {807c54b4-7fd9-11e8-9d94-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {8881f623-6e7b-11e8-9d86-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {9b976dd4-9dae-11e8-9dad-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {9b976e0c-9dae-11e8-9dad-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {b2c89ff0-6141-11e8-9d7d-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11a8-e773-11e8-9e21-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11c2-e773-11e8-9e21-d43d7e9f40c1} - "G:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c9cbc6a1-c0f0-11e8-9dd2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c9cbc6b0-c0f0-11e8-9dd2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {ea175277-6068-11e8-9d7c-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {ef4b1206-b878-11e8-9dc5-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-04-29]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\TP\TWCU.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{065cbf10-2caa-4b98-845d-58f844cd7367}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{15ba6f79-c3fe-4839-8ceb-9c85902f80e6}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{235b3b59-013c-4325-a9c1-dce08de51507}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{326988a7-fdcf-4ca8-aaed-31489abff3b3}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{4a471a66-ada7-469f-b245-94f49c4983f2}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{9a8ca0e5-5e36-4865-8644-400ce9f0a8bd}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{af220eb6-d63e-4c3d-994d-6b90b4308bf9}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{e654c3cc-dce8-4a0f-8348-3f7fa65109bd}: [DhcpNameServer] 10.0.0.138

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_172\bin\ssv.dll [2018-06-22] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_172\bin\jp2ssv.dll [2018-06-22] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: 840j6bnm.default
FF ProfilePath: C:\Users\Allonzo\AppData\Roaming\TomTom\HOME\Profiles\bovmmkmh.default [2016-10-26]
FF ProfilePath: C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default [2018-11-17]
FF Homepage: Mozilla\Firefox\Profiles\840j6bnm.default -> seznam.cz
FF Extension: (Messenger for WhatsApp™) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\rt42fsdty645jIidD@jetpack.xpi [2017-11-26]
FF Extension: (Download Manager (S3)) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\s3download@statusbar.xpi [2018-11-17]
FF Extension: (uBlock Origin) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\uBlock0@raymondhill.net.xpi [2018-02-02]
FF Extension: (Adblock Plus) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-12]
FF Extension: (iDM Integration Extension) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\{ed9a84e6-a04e-4d97-ad7e-b7414f2912eb}.xpi [2018-09-08]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_31_0_0_148.dll [2018-11-14] ()
FF Plugin: @java.com/DTPlugin,version=11.172.2 -> C:\Program Files\Java\jre1.8.0_172\bin\dtplugin\npDeployJava1.dll [2018-06-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.172.2 -> C:\Program Files\Java\jre1.8.0_172\bin\plugin2\npjp2.dll [2018-06-22] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_148.dll [2018-11-14] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD External Events Utility; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atiesrxx.exe [521944 2018-11-08] (AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-09-11] (Advanced Micro Devices, Inc.) [File not signed]
S2 AUEPLauncher; C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe [43008 2018-11-07] (AMD) [File not signed]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-05-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-05-27] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2018-11-06] (Dropbox, Inc.)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3729512 2018-10-19] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-08-27] (EasyAntiCheat Ltd)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-08-23] () [File not signed]
R2 KMS-R@1n; C:\Windows\KMS-R@1n.exe [26112 2017-06-06] () [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-15] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S3 sshd; C:\WINDOWS\System32\OpenSSH\sshd.exe [970240 2018-05-20] ()
S3 SshdBroker; C:\WINDOWS\System32\SshdBroker.dll [286720 2018-09-08] (Microsoft Corporation)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\NisSrv.exe [3917016 2018-10-23] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MsMpEng.exe [114208 2018-10-23] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atikmdag.sys [47840744 2018-11-08] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atikmpag.sys [604632 2018-11-08] (Advanced Micro Devices, Inc.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [42240 2013-07-31] (Advanced Micro Devices)
R2 AODDriver4.3.0; C:\Program Files\AMD\Performance Profile Client\amd64\AODDriver2.sys [60104 2015-02-19] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [107496 2018-05-28] (Advanced Micro Devices)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2018-05-27] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-01-31] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-08-02] (Disc Soft Ltd)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-31] (REALiX(tm))
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-08-23] (Huawei Technologies Co., Ltd.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1118648 2018-10-25] (Realtek )
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8228688 2018-09-27] (Realtek Semiconductor Corporation )
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2018-05-27] (Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [22016 2018-04-12] (Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46184 2018-10-23] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [328696 2018-10-23] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60408 2018-10-23] (Microsoft Corporation)
S3 MSICDSetup; \??\E:\CDriver.sys [X]
S3 SWDUMon; \SystemRoot\system32\DRIVERS\SWDUMon.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-17 17:05 - 2018-11-17 17:05 - 000017889 _____ C:\Users\Allonzo\Desktop\FRST.txt
2018-11-17 17:04 - 2018-11-17 17:05 - 000000000 ____D C:\FRST
2018-11-17 16:48 - 2018-11-17 16:48 - 002416128 _____ (Farbar) C:\Users\Allonzo\Desktop\FRST64.exe
2018-11-17 15:19 - 2018-11-17 16:19 - 000000000 ____D C:\Users\Allonzo\Desktop\bordel
2018-11-17 07:43 - 2018-11-17 07:43 - 000002215 _____ C:\Users\Public\Desktop\MTG Arena.lnk
2018-11-17 07:41 - 2018-11-17 07:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MTG Arena
2018-11-16 21:42 - 2018-11-16 21:42 - 000003160 _____ C:\WINDOWS\System32\Tasks\StartCN
2018-11-16 21:42 - 2018-11-16 21:42 - 000003074 _____ C:\WINDOWS\System32\Tasks\StartDVR
2018-11-16 21:42 - 2018-11-16 21:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2018-11-12 19:23 - 2018-11-12 19:23 - 000003176 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler
2018-11-10 18:07 - 2018-11-10 18:07 - 007592144 _____ (Malwarebytes) C:\Users\Allonzo\Downloads\adwcleaner_7.2.4.0.exe
2018-11-09 20:47 - 2018-11-16 21:41 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\AMD
2018-11-09 20:34 - 2018-11-09 20:35 - 026450000 _____ (AMD Inc.) C:\Users\Allonzo\Downloads\radeon-software-adrenalin-18.11.1-minimalsetup-181108_64bit.exe
2018-11-08 17:04 - 2018-11-08 17:04 - 001211976 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000189816 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000165520 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000029136 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2018-11-07 18:41 - 2018-11-07 18:41 - 000166728 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdihk64.dll
2018-11-07 18:41 - 2018-11-07 18:41 - 000137888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdihk32.dll
2018-11-07 06:44 - 2018-11-07 06:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-11-06 14:06 - 2018-11-06 14:06 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2018-11-06 14:06 - 2018-11-06 14:06 - 000047768 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2018-11-06 14:06 - 2018-11-06 14:06 - 000047768 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2018-11-06 14:06 - 2018-11-06 14:06 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2018-11-02 18:07 - 2018-11-02 18:07 - 000000000 ____D C:\Users\Allonzo\AppData\Local\RadeonSettings
2018-11-02 17:58 - 2018-11-02 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\##ID_STRING16##
2018-10-30 20:58 - 2018-10-30 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sudden Strike 4 [GOG.com]
2018-10-28 15:14 - 2018-10-28 15:14 - 000000000 ____D C:\Users\Public\Documents\Catch!
2018-10-28 15:13 - 2018-10-28 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2018-10-28 14:59 - 2018-10-28 14:59 - 000791712 _____ (Disc Soft Ltd.) C:\Users\Allonzo\Downloads\DTLiteInstaller.exe
2018-10-26 21:25 - 2018-10-26 21:25 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\DataWorks
2018-10-26 21:23 - 2018-10-26 21:23 - 000002940 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Alonzop)
2018-10-26 21:23 - 2018-10-26 21:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 6
2018-10-26 21:23 - 2018-10-26 21:23 - 000000000 ____D C:\Program Files (x86)\IObit
2018-10-26 21:21 - 2018-10-26 21:21 - 000275946 _____ C:\Users\Allonzo\Downloads\Phoenix.bsz
2018-10-26 21:21 - 2018-10-26 21:21 - 000242076 _____ C:\Users\Allonzo\Downloads\Sony_CDX_GT410U_v3.02_by_Rafa_Santos.bsz
2018-10-26 21:21 - 2018-10-26 21:21 - 000125686 _____ C:\Users\Allonzo\Downloads\R.A.D.I.O..bsz
2018-10-26 21:09 - 2018-10-26 21:10 - 026450000 _____ (AMD Inc.) C:\Users\Allonzo\Downloads\radeon-software-adrenalin-18.10.2-minimalsetup-181025_64bit.exe
2018-10-26 21:02 - 2018-11-08 17:04 - 001611264 _____ (AMD) C:\WINDOWS\system32\SETE916.tmp
2018-10-26 21:02 - 2018-11-08 17:04 - 001611264 _____ (AMD) C:\WINDOWS\system32\coinst_18.40.dll
2018-10-26 21:02 - 2018-10-26 21:02 - 001587616 _____ (AMD) C:\WINDOWS\system32\SETCFA1.tmp
2018-10-26 21:02 - 2018-10-26 21:02 - 000124464 _____ C:\WINDOWS\system32\kapp_ci.sbin
2018-10-26 21:02 - 2018-10-26 21:02 - 000119760 _____ C:\WINDOWS\system32\kapp_si.sbin
2018-10-26 21:02 - 2018-10-26 21:02 - 000034450 _____ C:\WINDOWS\system32\AMDKernelEvents.man
2018-10-26 21:02 - 2018-10-25 19:50 - 001587816 _____ (AMD) C:\WINDOWS\system32\SETBD7C.tmp
2018-10-26 21:02 - 2018-10-25 19:50 - 001587816 _____ (AMD) C:\WINDOWS\system32\SETA878.tmp
2018-10-25 19:50 - 2018-11-08 17:04 - 000029136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2018-10-25 19:50 - 2018-10-25 19:50 - 001192032 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\SET10CB.tmp
2018-10-25 19:50 - 2018-10-25 19:50 - 000019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SET9E4.tmp
2018-10-25 19:50 - 2018-10-25 19:50 - 000019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SET879C.tmp
2018-10-21 07:33 - 2018-11-17 08:31 - 000000000 ____D C:\ProgramData\YTD Video Downloader
2018-10-20 05:30 - 2018-10-20 05:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Northgard Ragnarok

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-17 17:04 - 2017-12-20 21:13 - 000007645 _____ C:\Users\Allonzo\AppData\Local\resmon.resmoncfg
2018-11-17 17:00 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-11-17 16:57 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF
2018-11-17 16:56 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-11-17 16:56 - 2016-04-27 07:34 - 000000000 ____D C:\WINDOWS\ShellNew
2018-11-17 16:54 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files\Common Files\system
2018-11-17 16:54 - 2015-07-10 12:04 - 000000139 _____ C:\WINDOWS\win.ini
2018-11-17 16:53 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-11-17 16:47 - 2018-05-07 17:39 - 000000000 ____D C:\Users\Allonzo\AppData\Local\PlaceholderTileLogoFolder
2018-11-17 16:47 - 2018-01-20 12:10 - 000000000 ____D C:\Users\Allonzo\AppData\Local\Packages
2018-11-17 16:46 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-11-17 16:18 - 2018-05-07 17:24 - 001689054 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-11-17 16:18 - 2018-04-12 16:51 - 000715202 _____ C:\WINDOWS\system32\perfh005.dat
2018-11-17 16:18 - 2018-04-12 16:51 - 000144496 _____ C:\WINDOWS\system32\perfc005.dat
2018-11-17 16:17 - 2016-11-19 02:44 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\Mozilla
2018-11-17 15:25 - 2018-05-07 17:31 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-11-17 15:24 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-11-17 15:24 - 2017-05-05 21:05 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-11-17 15:24 - 2017-05-05 21:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-11-17 15:24 - 2016-09-21 22:56 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2018-11-17 15:21 - 2018-05-12 20:21 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2018-11-17 15:14 - 2016-08-17 04:33 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-11-17 13:38 - 2018-05-07 17:07 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-11-17 10:29 - 2018-05-07 17:33 - 000000000 ____D C:\Users\Allonzo\AppData\Local\D3DSCache
2018-11-17 07:39 - 2018-01-27 15:42 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\MPC-HC
2018-11-17 01:51 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-11-16 21:51 - 2018-05-07 17:07 - 000410008 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-11-16 21:42 - 2016-09-21 22:56 - 000000000 ____D C:\Program Files\AMD
2018-11-16 21:41 - 2018-03-31 01:53 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-11-16 21:39 - 2017-05-17 16:00 - 000000000 ____D C:\AMD
2018-11-16 21:36 - 2016-07-31 17:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-11-16 21:36 - 2016-07-31 17:53 - 000000000 ____D C:\Program Files\Java
2018-11-15 22:54 - 2018-06-22 22:36 - 000000000 ____D C:\Users\Allonzo\Desktop\apky
2018-11-15 22:31 - 2018-05-07 17:31 - 000003362 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2823601367-1896843323-1796517690-1001
2018-11-15 22:31 - 2018-05-07 17:12 - 000002397 _____ C:\Users\Allonzo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-11-15 22:31 - 2016-07-31 08:20 - 000000000 ___RD C:\Users\Allonzo\OneDrive
2018-11-15 18:09 - 2016-08-02 04:59 - 000000000 ____D C:\Users\Allonzo\Desktop\dokumenty
2018-11-15 18:08 - 2018-02-09 15:48 - 000000000 ____D C:\Users\Allonzo\Desktop\Gamesky
2018-11-14 05:42 - 2017-03-10 19:24 - 000000000 ____D C:\Users\Allonzo\Desktop\completed
2018-11-14 01:03 - 2018-05-07 17:31 - 000004638 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-11-14 01:03 - 2018-05-07 17:31 - 000004470 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2018-11-14 01:02 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-11-14 01:02 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-11-12 19:37 - 2018-03-24 01:32 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\IObit
2018-11-12 19:24 - 2018-03-24 01:38 - 000000000 ____D C:\ProgramData\ProductData
2018-11-10 18:10 - 2016-07-31 11:27 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\IObit
2018-11-10 18:08 - 2018-01-14 10:08 - 000000000 ____D C:\AdwCleaner
2018-11-09 22:22 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-11-09 20:35 - 2018-03-31 01:49 - 000000060 _____ C:\ProgramData\SoftwareUpdateTemp.xml
2018-11-08 17:04 - 2018-04-26 23:36 - 003754160 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 003471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2018-11-08 17:04 - 2018-04-26 23:36 - 003437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2018-11-08 17:04 - 2018-04-26 23:36 - 003379720 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 001653048 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SETE2D3.tmp
2018-11-08 17:04 - 2018-04-26 23:36 - 001653048 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 001211976 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000937704 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000901288 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2018-11-08 17:04 - 2018-04-26 23:36 - 000901288 _____ C:\WINDOWS\system32\atiapfxx.blb
2018-11-08 17:04 - 2018-04-26 23:36 - 000769280 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000766720 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000585512 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000567432 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000554072 _____ C:\WINDOWS\system32\amdmiracast.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000505928 _____ C:\WINDOWS\system32\dgtrayicon.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000495632 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000490400 _____ C:\WINDOWS\system32\GameManager64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000481504 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000479016 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000445448 _____ C:\WINDOWS\system32\atieah64.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000395896 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000394272 _____ C:\WINDOWS\SysWOW64\SETE560.tmp
2018-11-08 17:04 - 2018-04-26 23:36 - 000394272 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000390160 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000361784 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000352000 _____ C:\WINDOWS\system32\clinfo.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000261080 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000229568 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000208616 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000195520 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000182656 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000180288 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000173808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000170760 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000164032 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000159928 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000154072 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000149040 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146416 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000143336 _____ C:\WINDOWS\system32\atidxx64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000138656 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000135632 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000133800 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122384 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122128 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000119016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000079752 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000056176 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000053056 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
2018-11-07 22:53 - 2018-05-07 17:31 - 000004212 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-11-07 21:42 - 2018-05-07 17:12 - 000000000 ____D C:\Users\Allonzo
2018-11-07 06:45 - 2018-05-27 05:46 - 000000000 ___RD C:\Users\Allonzo\Dropbox
2018-11-07 06:45 - 2018-05-27 05:37 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-11-06 17:59 - 2017-10-29 19:20 - 000000000 ____D C:\Program Files\CCleaner
2018-11-04 18:04 - 2017-04-23 20:04 - 000000000 ____D C:\Users\Allonzo\AppData\Local\ElevatedDiagnostics
2018-11-04 09:19 - 2018-05-12 19:04 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2018-11-04 09:18 - 2017-12-09 12:47 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2018-11-04 09:18 - 2017-06-28 17:58 - 000000000 ___HD C:\WINDOWS\msdownld.tmp
2018-11-04 09:17 - 2016-07-31 11:57 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2018-11-04 09:12 - 2018-09-14 05:54 - 000003126 _____ C:\WINDOWS\System32\Tasks\MSIAfterburner
2018-11-04 07:24 - 2016-08-02 18:04 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\DAEMON Tools Lite
2018-11-02 17:45 - 2016-07-31 10:59 - 000000000 ____D C:\Program Files\ATI
2018-10-29 18:42 - 2017-04-22 18:00 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\TP-LINK
2018-10-28 15:25 - 2016-08-06 05:10 - 000000000 ____D C:\Users\Allonzo\AppData\Local\Disc_Soft_Ltd
2018-10-28 15:14 - 2016-12-28 12:38 - 000000000 ____D C:\Program Files\DAEMON Tools Lite
2018-10-28 15:06 - 2016-08-02 18:03 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite
2018-10-27 22:31 - 2017-01-19 15:21 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\BSplayer PRO
2018-10-27 16:22 - 2016-09-21 22:57 - 000000000 ____D C:\Program Files (x86)\AMD
2018-10-27 04:35 - 2016-07-31 10:59 - 000000000 ____D C:\Program Files (x86)\ATI Technologies
2018-10-27 00:12 - 2018-08-05 08:11 - 000000000 ____D C:\Users\Allonzo\Downloads\iDM
2018-10-26 22:10 - 2018-03-31 00:41 - 000000000 ____D C:\Program Files\ATI Technologies
2018-10-26 22:10 - 2016-09-21 22:56 - 000000000 ____D C:\ProgramData\Package Cache
2018-10-26 22:10 - 2016-07-31 10:59 - 000000000 ____D C:\ProgramData\AMD
2018-10-26 21:24 - 2018-03-24 01:32 - 000000000 ____D C:\ProgramData\IObit
2018-10-26 21:02 - 2018-04-26 23:36 - 001629296 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SETA1E6.tmp
2018-10-26 20:40 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-10-25 19:50 - 2018-04-26 23:36 - 001629280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SETA255.tmp
2018-10-25 19:50 - 2018-04-26 23:36 - 001629280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SET865A.tmp
2018-10-25 19:50 - 2018-04-26 23:36 - 001629280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SET381.tmp
2018-10-25 19:50 - 2018-04-26 23:36 - 000381544 _____ C:\WINDOWS\SysWOW64\SETB31.tmp
2018-10-25 19:50 - 2018-04-26 23:36 - 000381544 _____ C:\WINDOWS\SysWOW64\SET882E.tmp
2018-10-25 18:52 - 2018-05-08 08:01 - 001118648 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2018-10-23 05:33 - 2018-02-25 02:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-10-22 19:24 - 2018-05-26 16:47 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\Syncios
2018-10-18 19:36 - 2016-07-31 10:36 - 000559880 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

==================== Files in the root of some directories =======

2017-06-04 00:06 - 2018-05-27 13:58 - 000006144 _____ () C:\Users\Allonzo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-12-20 21:13 - 2018-11-17 17:04 - 000007645 _____ () C:\Users\Allonzo\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-07 17:07

==================== End of FRST.txt ============================

Dodatek :

Kód: Vybrat vše

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15.11.2018
Ran by Alonzop (17-11-2018 17:06:26)
Running from C:\Users\Allonzo\Desktop
Windows 10 Pro Version 1803 17134.345 (X64) (2018-05-07 16:32:57)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2823601367-1896843323-1796517690-500 - Administrator - Disabled)
Alonzop (S-1-5-21-2823601367-1896843323-1796517690-1001 - Administrator - Enabled) => C:\Users\Allonzo
DefaultAccount (S-1-5-21-2823601367-1896843323-1796517690-503 - Limited - Disabled)
Guest (S-1-5-21-2823601367-1896843323-1796517690-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2823601367-1896843323-1796517690-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.148 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 18.11.1 - Advanced Micro Devices, Inc.)
AUROZA EM02C Driver (HKLM-x32\...\{2F9C99E1-A1D2-4ADB-AFA0-3A1ED9471811}) (Version:  - )
AVG PC TuneUp (HKLM-x32\...\{149D912F-03DB-4895-913E-820CB11965C0}) (Version: 16.74.1 - AVG Technologies) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Branding64 (HKLM\...\{EE2AFCE4-0238-4DE0-A140-1647021627C1}) (Version: 1.00.0001 - Advanced Micro Devices, Inc.) Hidden
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.70.1080 - AB Team, d.o.o.)
Catalyst Control Center Next Localization BR (HKLM\...\{118C2119-84B6-E32C-63E2-B56DBCF41CE5}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{3E245378-BF77-6946-C6F6-096DBE5EAB82}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{51F85784-6799-5CA3-97B2-2E5904FC3E58}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{55A4D3AB-C8DF-26B2-89A8-7E16E1E40700}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{A16E186C-58C4-3BDC-5CCE-714EFEF5F27F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{238F6F6F-2544-86CF-3AB6-2CDADAB58CF0}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{36EDC500-E4C0-371C-9865-08450415C1E9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{62098A5F-E03B-31A3-5F9C-51A7F7D25744}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{84C3F2C5-F7B2-2F08-CDF4-79EF7CC55D74}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{A0407E39-2AA4-60B3-885F-3C5347B6909E}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{C3EE628C-7394-FE2C-0C90-C05284EB528D}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{0989D0EA-AFF3-5F9A-3D25-20EE133E409B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{0E8A3B17-D603-B1B6-C205-1685EBDD23E9}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{1757AD9B-0E3C-05F9-FE43-4343BED7DA85}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{2F544F46-5F6E-97BB-3550-A0242A3C5754}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{EC688BD0-240D-AE40-55F3-234E54919AE6}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{1E7D3072-1D28-E33A-99DF-85D9F7ECD06E}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{66B06F29-EE4F-9130-D96A-754826093FEA}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{A8689A0F-5928-7300-B82B-C5E85131B7BA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{D74218A3-C503-57EF-AC9F-2220082E7ADE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{E27224E3-7913-DA1E-5B08-9BEEC8FEE3D1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{FC4086D6-E345-5F43-08BB-280FB57DAF49}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{76AAF56B-93D8-161D-809A-EC05F3B913DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{821D0A0E-F246-BE40-0D68-93883C14C410}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{95A52FC1-C728-841D-1BFC-CC793B77B0A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{BA26B70C-3D8C-2D14-4122-211FB3E6F691}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{F8EBE530-A4D5-BF51-F623-3787E6B8A878}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{063CED74-F5F0-870E-DC9C-2D78FDEDA3EE}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{42FBD43F-DE53-6D4D-5134-E3C93B45CBEF}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{5FEACE78-C338-9AED-FF05-7DE7E273C774}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{88BD74C4-23AB-4554-915C-6E1F0C81F6CD}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{A22CDEBA-6DB5-12CD-F6CE-6238C2D78363}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{13BB60AA-88F7-4B1F-2DEC-D81EEDE8B3AA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{20D46801-147B-30AD-7C5A-AC4560A79096}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{A3795528-F572-6314-C4E3-EE9DAF0FBF02}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{A48E2AB0-0866-7783-9657-E1709EB18D02}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{AC85CF50-9A55-0103-ADBF-365C37603AA4}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{C0BFC67D-E447-02C8-6046-C078DFE9EC97}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{22C39711-2747-D264-319A-1550BEEAAEC6}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{37AA6227-FF2C-95AC-87C0-45DCC0BB87DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{4853A56D-7931-A08B-5BA7-8E2D61043DF9}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{94C72EBE-2908-F0AC-62DA-D61951830F8F}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{B349892D-B015-033C-4CA8-3635E6B655D7}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{E61CEF9A-BAC3-EAEE-F735-E257D2354DF2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{1DBACFDB-5E43-7882-36BD-53526D34BD22}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{5B987681-3652-492B-6A11-E02AC0FE5959}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{B28CF677-E2C8-12CA-52BB-19B6F066D36A}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{BE8D6AB1-3049-2F0C-67FA-00C0A5D321A3}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{DA0326BB-657D-AAFC-752C-363E8FA33755}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{EB328356-1DF0-1CCE-3607-6361DD329219}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{365AEAB2-4CF3-7CBB-0DAC-E9E14B688E65}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{45907537-804A-514F-5280-5F4F12A6DCBC}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{5A083A57-10D6-D4E5-292C-F274870E73A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{8E6F5592-ED7E-9C50-74AC-BF417B1FE291}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{E42911E5-48F8-8557-ED20-D72AD1907D25}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{7ABC6D83-816E-6D48-E65D-B0CEDD294E4E}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{962364E4-08BB-347D-32E7-2B789F37BF8A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{AD28960A-6190-C991-C964-308B86EAA2E2}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B4C30EF4-B2C5-1395-B534-7B63BCB6E8E4}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{DF0D7C1C-72B6-9FFB-DF66-B3720237BB80}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{26567561-DFB2-2B63-9BA8-6A490ED37016}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{43F6D22B-E0E9-EE90-9B62-1C5FC5D15A55}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{86BFE5B4-1FCE-3C02-6373-92B1AE6431E8}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{87E6EC29-AEC5-28CB-F773-93EB6C1B8A2B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{B873A1FB-5EA0-EE5F-A861-1E38880AD08E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{0742432E-42D9-2240-4CA1-8595CCCBAA77}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{0809FEC1-EF86-51E9-8210-DC1B1BDB6745}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{CA55697D-BD74-3ED8-6B21-D7EDAD3B7D02}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{D4490E0F-8E7B-1097-B56A-7643C75F1C28}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{EC9DF9FF-9D75-4CDD-1D58-A2E887B0A42E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{ED75A775-03A7-F214-868D-497748707968}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{5FD706FF-6AD8-E372-A35A-879409982655}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{7ABACA7E-6E59-0EF9-8FA3-6B32E5F58127}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{CFC860C8-4F51-E08C-A74C-2E444ED06160}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{DAB44116-0266-C65B-B643-AC11217C3041}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{EAEAA839-44F4-22DF-D1CC-88C3B2A3D4B1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{3AF70346-52C7-0334-606F-118D1C1CB7A2}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{3E196AAF-F81C-B384-E2AB-28EE2398FE5F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{9338D693-38B7-1ED4-9B42-BFA1D5600CCB}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{A3973655-E448-4A1B-477C-988A79D132D9}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{A4E7CA0C-84EB-5E29-2F04-06C4E4790C2F}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{53AE8AC7-5213-67AF-0DC0-CED696B77643}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{59D2664C-949B-7FA7-9880-ECB993B6616A}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{6DC92550-D065-4B36-C4D3-D8D7A702A7A7}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{C971C145-258D-6650-7088-13DDB161327A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DAEFFE0C-CD05-1355-6AFC-7B3D4106A820}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{970A40CA-46AB-986C-1798-976ED0EA00FA}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{B2A83706-3F14-1532-20CD-B4EE715A8945}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{DC9DFCBF-87DA-892C-6151-99CC9EF46E3E}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{E392A425-53A7-DF90-96A0-E287A75DD3B2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{EBA09DAF-14B4-7BE7-676E-6E2FB21EDBDD}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{44ED2CDA-4197-E9E9-B328-26E1FB749116}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{4707CBFC-8ED4-463E-0FF9-DE86F4A743E9}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{4D1D5407-9B69-6422-629C-8518A26004A4}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{9AA4DD93-94BF-22EA-C9D2-7084F304A31B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{C1EFF2A2-DF4A-F6D1-B99C-1ED194AE9E78}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{D6F47BB4-700A-F612-0671-5F69EA311BB7}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{01FD9A26-3F61-9236-B360-BE5D043D82C0}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{3450566C-4561-0EE8-B1AB-D5C79CCE8D2C}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{379D900B-A785-6DB0-012E-434356A365B3}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{46EB68BE-8AAC-8C2B-7284-8DEDE6B5CD2A}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{C14A3A5B-8A86-C239-37D7-158211778C54}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{24DF617A-CD23-6E6A-126B-23630D2781CE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{366C4FB5-CF6E-258B-418D-E6D29549A278}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{64D4CCC3-63DF-252D-D29D-03491670225D}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{7A6E431B-CF43-EC3E-FD7E-0A0AAB1B25FC}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{A50C89BC-8D8E-8828-824A-7171F6D583D5}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{FCE8438C-3272-D63F-479F-670F082B294B}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{0B5633F0-C415-2F08-671E-4C9E2FAACD45}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{25D1751E-7CA2-5F6D-0125-0A16E47AF9FE}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{89A1F076-19B8-A2B1-D5A3-E8247EFAF157}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{8DF90937-B869-9F76-5D45-5A8BDA0A33B6}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{B10089DE-934F-6E0F-683A-B788F89348DF}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.36 - Piriform)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.9.0.0650 - Disc Soft Ltd)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Discord (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Discord) (Version: 0.0.301 - Discord Inc.)
Divinity: Original Sin Enhanced Edition (2.0.119.430_(hotfix)) (HKLM-x32\...\1445516929_is1) (Version: 0.1.1.310 - GOG.com)
Driver Booster 6 (HKLM-x32\...\Driver Booster_is1) (Version: 6.0.2 - IObit)
Dropbox (HKLM-x32\...\Dropbox) (Version: 61.4.95 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.141.1 - Dropbox, Inc.) Hidden
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 8.0.1.303 - )
Java 8 Update 161 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Java 8 Update 162 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180162F0}) (Version: 8.0.1620.12 - Oracle Corporation)
Java 8 Update 172 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180172F0}) (Version: 8.0.1720.11 - Oracle Corporation)
K-Lite Mega Codec Pack 14.3.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.3.0 - KLCP)
Malwarebytes verze 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\OneDriveSetup.exe) (Version: 18.192.0920.0015 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429 (HKLM-x32\...\{80586c77-db42-44bb-bfc8-7aebbb220c00}) (Version: 14.14.26429.4 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 (HKLM-x32\...\{cb7c3049-21de-415b-bd85-b65c14e547df}) (Version: 14.10.25017.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mozilla Firefox 63.0.3 (x64 cs) (HKLM\...\Mozilla Firefox 63.0.3 (x64 cs)) (Version: 63.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.2 - Mozilla)
MTG Arena (HKLM-x32\...\{A509DF1D-8265-4F4C-A866-177C0E0799D4}) (Version: 0.1.910.0 - Wizards of the Coast) Hidden
MTG Arena (HKLM-x32\...\MTG Arena 0.1.910.0) (Version: 0.1.910.0 - Wizards of the Coast)
Northgard Ragnarok (HKLM-x32\...\Northgard Ragnarok_is1) (Version:  - )
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.3 - Notepad++ Team)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Pillars of Eternity 2 Deadfire Beast of Winter (HKLM-x32\...\Pillars of Eternity 2 Deadfire Beast of Winter_is1) (Version:  - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.10.714.2016 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8485 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.9 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.9 - VS Revo Group, Ltd.)
RivaTuner Statistics Server 7.2.0 (HKLM-x32\...\RTSS) (Version: 7.2.0 - Unwinder)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.8 - Rockstar Games)
Samsung Kies (HKLM-x32\...\{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.4.17113.1 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.4.17113.1 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.)
Sid Meiers Civilization VI Rise and Fall (HKLM-x32\...\Sid Meiers Civilization VI Rise and Fall_is1) (Version:  - )
Sudden Strike 4 - Finland: Winter Storm (HKLM-x32\...\1937377674_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4 (HKLM-x32\...\2146639313_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4: Battle of Kursk (HKLM-x32\...\1938212434_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4: Road to Dunkirk (HKLM-x32\...\1589182480_is1) (Version: 1.12.28520 - GOG.com)
Syncios 6.5.0 (HKLM-x32\...\Syncios) (Version: 6.5.0 - Anvsoft)
TeamSpeak 3 Client (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\TeamSpeak 3 Client) (Version: 3.1.4.2 - TeamSpeak Systems GmbH)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 2.0.0.0 - Zenimax Online Studios)
TP-LINK TL-WN823N Driver (HKLM-x32\...\{CE194A8D-C8DF-47EB-AB04-5A54CDC1C5BD}) (Version: 1.3.1 - TP-LINK)
TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{EC5A6438-850E-4AD1-9169-DD071C8EFFEF}) (Version: 2.10.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 51.0 - Ubisoft)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0-4) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Web Companion (HKLM-x32\...\{46b8e553-65e1-4bb3-b888-f5e91c54a65e}) (Version: 4.0.1780.3335 - Lavasoft)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2017-03-08] ()
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-11-07] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2016-12-15] (VS Revo Group)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0CADBE77-2C19-4752-9BF6-7251F2952B37} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-05-27] (Dropbox, Inc.)
Task: {13E14763-C7B0-455B-9D99-6DBB495C8E62} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe [2018-11-07] (Advanced Micro Devices, Inc.)
Task: {3474EEEF-B521-466E-A075-4A1D30B5A899} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {39F6B51E-B91B-46E5-A786-2A8D5AE52E4E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {51D36D56-BC7F-4C67-A0C6-7C13BCBD7167} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_148_Plugin.exe [2018-11-14] (Adobe Systems Incorporated)
Task: {572993BF-0C1D-4A4D-BB9D-BF82384CA453} - System32\Tasks\Driver Booster SkipUAC (Alonzop) => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe [2018-10-17] (IObit)
Task: {5997F85B-42AF-458A-A0B2-04EC79860672} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2018-11-07] (Advanced Micro Devices, Inc.)
Task: {63A2E2B2-3C3F-4F53-BD65-74E110253C8A} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-11-14] (Adobe Systems Incorporated)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {663BEA23-9E12-45C9-8B54-D599258C972A} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-05-27] (Dropbox, Inc.)
Task: {6B428069-F812-4D67-9F96-9F48FF3A0D9E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-10-18] (Piriform Ltd)
Task: {8FA9C88E-06BC-412D-BA13-0FD6FF2D6072} - System32\Tasks\S-1-5-21-2823601367-1896843323-1796517690-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-04-12] (Microsoft Corporation)
Task: {9685C6F0-9309-4642-A4EC-9D1C6E9A2B6B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {A73AB5E5-6651-46FC-AED0-B22FA898490B} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {B15D6389-AFE9-42D3-A46E-98BEFD7E41B6} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\Scheduler.exe [2018-09-20] (IObit)
Task: {D6748BBC-9FF5-491D-981D-E37897A8F55C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {E2D0F99B-387E-402C-9113-001EC05D5F7F} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-10-06] (Oracle Corporation)
Task: {EEB666C1-E343-4ED0-9AEE-7B7BD1898CA6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-11-06] (Piriform Ltd)
Task: {F5483C6F-96AF-4DAB-9BDD-5DC449A1E80B} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
Task: {FDDC310D-629B-4364-9075-27AD794DC026} - System32\Tasks\klcp_update => CodecTweakTool.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-08-23 13:42 - 2018-08-23 13:42 - 000190784 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2017-06-06 16:53 - 2017-06-06 16:53 - 000026112 _____ () C:\Windows\KMS-R@1n.exe
2018-04-12 00:34 - 2018-04-12 00:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-10-14 08:47 - 2018-09-20 04:38 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-04-07 13:03 - 2014-12-08 08:56 - 000761856 _____ () C:\Program Files (x86)\AUROZA\Monitor.exe
2018-06-13 07:00 - 2018-06-13 07:00 - 002443384 _____ () C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe
2018-05-30 09:16 - 2018-05-30 09:16 - 000017024 _____ () C:\Program Files (x86)\Anvsoft\Syncios\androidnotifier.exe
2018-06-28 03:17 - 2018-06-28 03:17 - 001091896 _____ () C:\Program Files (x86)\Anvsoft\Syncios\adb.exe
2017-10-09 13:22 - 2012-12-21 19:33 - 000020288 _____ () C:\Program Files\CCleaner\branding.dll
2017-10-18 17:19 - 2017-10-18 17:19 - 000086224 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2018-06-27 22:04 - 2018-06-27 22:04 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.DLL
2018-06-27 22:04 - 2018-06-27 22:04 - 002552832 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2018-11-17 16:46 - 2018-11-17 16:46 - 000017408 _____ () C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\iDownloadManager.exe
2018-11-17 16:46 - 2018-11-17 16:46 - 020022272 _____ () C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\iDownloadManager.dll
2018-11-17 16:46 - 2018-11-17 16:46 - 000046080 _____ () C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\Win32\iDownloaderConsole.exe
2018-04-07 13:03 - 2014-09-09 14:05 - 000057344 _____ () C:\Program Files (x86)\AUROZA\lan.dll
2018-04-07 13:03 - 2013-11-01 11:57 - 000049152 _____ () C:\Program Files (x86)\AUROZA\hiddriver.dll
2018-11-07 06:43 - 2018-11-06 14:06 - 001141064 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2018-11-07 06:43 - 2018-11-06 14:06 - 002103112 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000023376 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025456 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000142312 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 001953640 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000118232 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes35.dll
2018-11-07 06:44 - 2018-11-06 14:06 - 000109024 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000083784 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000418776 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom35.dll
2018-11-07 06:44 - 2018-11-06 14:08 - 000074072 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000049128 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000026600 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000131552 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000182752 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000119272 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000401752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000028640 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000034664 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000061792 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:06 - 000023520 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000053736 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000065504 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025944 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000068968 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000032224 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000156504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000092488 _____ () C:\Program Files (x86)\Dropbox\Client\sip.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 001778000 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000518992 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000052056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 001929552 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 003821392 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000044888 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000132944 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000218456 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000205656 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000061408 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000051552 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027624 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000033632 _____ () C:\Program Files (x86)\Dropbox\Client\winreindex.compiled._winreindex.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028008 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000031600 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000486880 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000102736 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000029040 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 011144016 _____ () C:\Program Files (x86)\Dropbox\Client\nucleus_python.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000029024 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:06 - 000036312 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2018-11-07 06:43 - 2018-11-06 14:08 - 000036712 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000272208 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.advapi32.compiled._winffi_advapi32.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000433992 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2018-11-07 06:44 - 2018-11-06 14:09 - 000035680 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025920 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2018-11-07 06:43 - 2018-11-06 14:08 - 001592128 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000095592 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shcore.compiled._winffi_shcore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.gdi32.compiled._winffi_gdi32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shell32.compiled._winffi_shell32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000029544 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000530768 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000348496 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000037200 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngine.cp35-win32.pyd
2018-06-28 03:31 - 2018-06-28 03:31 - 001514496 _____ () C:\Program Files (x86)\Anvsoft\Syncios\DuiLib.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 000178688 _____ () C:\Program Files (x86)\Anvsoft\Syncios\driverMgr4Transfer_pdm.dll
2018-05-30 09:15 - 2018-05-30 09:15 - 000571392 _____ () C:\Program Files (x86)\Anvsoft\Syncios\sqlite3.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 000074752 _____ () C:\Program Files (x86)\Anvsoft\Syncios\generalFunc_pdt.dll
2018-05-30 09:12 - 2018-05-30 09:12 - 000592896 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libsscan.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 001309184 _____ () C:\Program Files (x86)\Anvsoft\Syncios\androidSyncCore_pdm.dll
2018-05-30 09:27 - 2018-05-30 09:27 - 013524469 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libheic.dll
2018-05-30 09:26 - 2018-05-30 09:26 - 001970688 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libplist.dll
2018-05-30 09:26 - 2018-05-30 09:26 - 001042432 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libandroidrecovery.dll
2018-05-30 09:15 - 2018-05-30 09:15 - 001278080 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libandroidnotifier.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 004554857 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libexiv2.dll
2018-05-30 09:12 - 2018-05-30 09:12 - 000121524 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libgcc_s_dw2-1.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 001544523 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libstdc++-6.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 001487360 _____ () C:\Program Files (x86)\Anvsoft\Syncios\exiv2.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 000066048 _____ () C:\Program Files (x86)\Anvsoft\Syncios\zlib1.dll
2018-05-30 09:16 - 2018-05-30 09:16 - 000104448 _____ () C:\Program Files (x86)\Anvsoft\Syncios\expat.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\localhost -> localhost

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-10 12:04 - 2017-06-03 07:57 - 000000033 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img13.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "Gaijin.Net Agent"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe
FirewallRules: [{E5704048-D74D-4C36-83C0-AFC2AE45C0D9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{168C4730-36FD-43E6-B9B7-83005201CA63}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [UDP Query User{93722077-3426-4264-938D-2DF7BD4BECA5}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{C280E624-8E98-4BEB-A6EB-E45683BAF9FD}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{81E1E14B-FDD7-431E-8936-021B00ECA713}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{046BB00A-96AE-49DF-8363-EEB2C8CBA86C}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{74041CFE-45F9-4A6B-8639-C37CE09197C2}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{A59A401D-D68F-42A7-937F-07FC1A9A59FD}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{2F00BEED-005C-4E96-A284-05197064E1A2}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{E8727B48-BF11-44DC-B40B-3A487ABCBE97}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{284402BC-1B04-49F8-9688-2A44ED1FB13F}D:\games\diablo iii\diablo iii.exe] => (Allow) D:\games\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{B1DACAEC-BF39-4AED-9D8B-992AE4B60AFF}D:\games\diablo iii\diablo iii.exe] => (Allow) D:\games\diablo iii\diablo iii.exe
FirewallRules: [{EEC9CB70-CECD-4E44-BFB1-1AB012AFE94F}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{56B7E9AE-46BD-4F70-BA52-C362E10C768F}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{619D4411-9A7F-4EFB-9452-E5E6B9BA8241}] => (Allow) D:\Steam\steamapps\common\Age2HD\Launcher.exe
FirewallRules: [{CBC8BC91-03DD-4A14-B879-6995D1C0BEA0}] => (Allow) D:\Steam\steamapps\common\Age2HD\Launcher.exe
FirewallRules: [TCP Query User{BDEA720E-7297-4B09-A793-67A68C270AA0}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [UDP Query User{CCC6B2D6-B100-474E-8B3A-38260721B218}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [TCP Query User{0F1755AE-AF99-43C3-B752-9F3492D0B539}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [UDP Query User{60370882-0154-433A-93FC-089CC31B18E5}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{956B4F4A-3CAE-481D-976D-38E8E89831C4}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{1FFEF323-FF74-4763-B503-227743D24F1F}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{DB64EC06-61BC-4AFC-B2CE-F40E67A6C339}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{5A6CC866-DF46-48A2-8CFA-B49857B316C9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{92776334-DD7D-4B94-AB22-521C141620C9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{EFF99DAB-AA22-43E1-95CB-FA0EAD5D8F12}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{BB8DCEA9-6A6B-429A-A747-FB04606CD4DE}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{4CD510CA-269F-4D55-B3B9-7ECF003734AD}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{2C65AE6F-AF07-4D56-A63E-385B2ABFD3F9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{23A05941-721F-4615-9B03-445ECB4ECEB6}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{7C9212D1-EC53-4A58-A2E5-2B86D76924C6}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{5D178285-D43A-4A4E-A7F7-6F3EC45C3949}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{DF2EE1A2-2D3B-4670-8CAD-BC638B2F5B24}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{FADE5BD0-73B1-4BAE-9E55-10EE70E81701}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{83E6B7A5-C6A4-45C8-9C9C-B780DE639926}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{8ACF4C21-4B5B-4CF0-B790-F84FA0B3DC8A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{94FFE1BA-67FA-4FED-94A4-DAF28FAF4691}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [UDP Query User{893CCC8F-6077-428D-8939-801974F724C1}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{3667219E-133F-4A9A-BF31-C9A426F30315}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{E2884B7B-E994-4717-BD4F-33AC914105D5}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [TCP Query User{142521BD-BC97-4665-BE8B-ACC2FDCF0EE8}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{B3C6D690-5E97-43F7-835B-AC82E52DB7DF}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{3635E671-1C76-4699-ADB9-A67586E07C19}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [UDP Query User{74E066B2-F1EF-4A18-849C-985FFD2B90AD}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [TCP Query User{156F1724-4149-4D60-9592-65B395C6783D}D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe] => (Allow) D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe
FirewallRules: [UDP Query User{4B58B240-EB49-46D0-9FE3-FD41B8DBB259}D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe] => (Allow) D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe
FirewallRules: [{BB2A3528-4C73-4E84-916E-5EE8FF60DEB7}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{292E230A-0075-493B-8662-20A6F0E558C6}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{88E39619-3461-4438-AA59-53D5CDEB8E2B}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{26AAD9CF-D94C-4791-9492-57A35C862500}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{CA7FAD52-A270-453C-994F-AE1E7A8602D9}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{18A0C796-4CFD-4F40-8A95-DDFE772DEB88}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{74A8C031-2945-4D7C-AC37-C8A3527F8B8A}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{6F6D7066-989D-46B5-846C-1FFFCEBABE0B}] => (Block) D:\Games\Pillars of Eternity 2 Deadfire Beast of Winter\PillarsOfEternityII.exe
FirewallRules: [{57DD9B1E-FB09-488B-B080-6FA6F8BE12C0}] => (Block) D:\Games\Pillars of Eternity 2 Deadfire Beast of Winter\PillarsOfEternityII.exe
FirewallRules: [{0D24A2B0-6691-4DEB-AECC-BB8BA5753292}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
FirewallRules: [{F02198EA-317E-4138-B0A8-2DC476C628BF}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
FirewallRules: [TCP Query User{81960E18-ADDE-4D93-A845-4018B92BD18D}D:\steam\steamapps\common\for honor\forhonor.exe] => (Allow) D:\steam\steamapps\common\for honor\forhonor.exe
FirewallRules: [UDP Query User{7BF1C704-A7C2-4642-A22B-C03066FF8C20}D:\steam\steamapps\common\for honor\forhonor.exe] => (Allow) D:\steam\steamapps\common\for honor\forhonor.exe
FirewallRules: [TCP Query User{DAA91239-943E-486A-90C5-0FB91D319DBB}C:\program files (x86)\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files (x86)\wizards of the coast\mtga\mtga.exe
FirewallRules: [UDP Query User{53371FEB-D07A-4091-B4D0-A32C09C183BA}C:\program files (x86)\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files (x86)\wizards of the coast\mtga\mtga.exe
FirewallRules: [{35D30BFA-4864-4A8F-AFB4-8B42AFF94B62}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe
FirewallRules: [{6B24BE88-3231-4968-BA78-20909D0CF39D}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe
FirewallRules: [{6EA189C8-3A4D-43BB-9D41-695195EADFBF}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DBDownloader.exe
FirewallRules: [{D2D67853-AC9A-449E-B972-360652398C03}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DBDownloader.exe
FirewallRules: [{60484728-3A26-4549-89F8-96991B22E8A0}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\AutoUpdate.exe
FirewallRules: [{47468509-034B-452A-9732-62B48088E5C6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\AutoUpdate.exe
FirewallRules: [{AE3135C1-282A-49B9-BBD9-127F0EE76B24}] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{89ECC069-1869-422A-8C68-95ABE5C18A7A}] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{64F8B66D-A1D1-48C7-9425-322AB5FDBB5C}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
FirewallRules: [{3B6A675D-2925-4A4C-87C2-4800FDE77F6D}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe

==================== Restore Points =========================

04-11-2018 19:29:04 Instalační služba modulů systému Windows
05-11-2018 20:39:54 Instalační služba modulů systému Windows
06-11-2018 22:40:11 Instalační služba modulů systému Windows
07-11-2018 23:44:36 Instalační služba modulů systému Windows
09-11-2018 19:38:25 Instalační služba modulů systému Windows
10-11-2018 22:11:57 Instalační služba modulů systému Windows
12-11-2018 18:02:47 Instalační služba modulů systému Windows
13-11-2018 19:26:40 Instalační služba modulů systému Windows
14-11-2018 19:46:39 Instalační služba modulů systému Windows
14-11-2018 21:46:42 Instalační služba modulů systému Windows
15-11-2018 22:32:23 Installed MTG Arena
16-11-2018 00:09:42 Instalační služba modulů systému Windows
17-11-2018 01:51:17 Instalační služba modulů systému Windows
17-11-2018 07:37:38 Installed MTG Arena
17-11-2018 16:51:53 Removed Microsoft Office Professional Plus 2013
17-11-2018 16:52:11 PROPLUSR

==================== Faulty Device Manager Devices =============

Name: Časovač událostí s vysokou přesností
Description: Časovač událostí s vysokou přesností
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardní systémová zařízení)
Service: 
Problem: : This device is disabled because the firmware of the device did not give it the required resources. (Code 29)
Resolution: Enable the device in the BIOS of the device.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/17/2018 04:51:19 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač.
.


Operace:
   Spouštění asynchronní operace

Kontext:
   Aktuální stav: DoSnapshotSet

Error: (11/17/2018 04:50:21 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
   Shromažďování dat modulu pro zápis

Kontext:
   ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
   Název modulu pro zápis: System Writer
   ID instance modulu pro zápis: {0bf0df34-99a7-4b99-95b4-4f906245d34e}

Error: (11/17/2018 04:14:28 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/17/2018 03:15:13 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/17/2018 03:14:36 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/17/2018 02:53:17 AM) (Source: Windows Search Service) (EventID: 1019) (User: )
Description: Službě Windows Search se nepodařilo zpracovat seznam zahrnutých a vyloučených umístění, a to s chybou <30, 0x80040d07, iehistory://{S-1-5-21-2823601367-1896843323-1796517690-1001}/>.

Error: (11/17/2018 12:31:02 AM) (Source: Office 2013 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0

Error: (11/16/2018 09:01:21 PM) (Source: Windows Search Service) (EventID: 1019) (User: )
Description: Službě Windows Search se nepodařilo zpracovat seznam zahrnutých a vyloučených umístění, a to s chybou <30, 0x80040d07, iehistory://{S-1-5-21-2823601367-1896843323-1796517690-1001}/>.


System errors:
=============
Error: (11/17/2018 04:19:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba AMD User Experience Program Launcher byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/17/2018 04:16:39 PM) (Source: DCOM) (EventID: 10016) (User: X-COM)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 a APPID 
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 uživateli X-COM\Alonzop (SID: S-1-5-21-2823601367-1896843323-1796517690-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy – SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/17/2018 04:16:30 PM) (Source: DCOM) (EventID: 10016) (User: X-COM)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 a APPID 
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 uživateli X-COM\Alonzop (SID: S-1-5-21-2823601367-1896843323-1796517690-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy – SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/17/2018 04:15:57 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID 
Windows.SecurityCenter.WscBrokerManager
 a APPID 
Není k dispozici
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/17/2018 04:15:57 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID 
Windows.SecurityCenter.WscBrokerManager
 a APPID 
Není k dispozici
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/17/2018 03:23:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Microsoft Passport Container neuspěla při spuštění v důsledku následující chyby: 
Přesměrování bylo ukončeno.

Error: (11/17/2018 03:17:33 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba AMD User Experience Program Launcher byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/17/2018 03:14:14 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID 
Windows.SecurityCenter.WscDataProtection
 a APPID 
Není k dispozici
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.


Windows Defender:
===================================
Date: 2018-11-12 19:22:03.201
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {98D630BD-28B6-4A73-B241-C8318C025B52}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-03 22:03:55.662
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {912E2FD6-2710-49F4-B68E-A74C6DD132E6}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-02 17:27:53.497
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {0BC3853A-3E11-4ABF-AEF4-F307F19A8725}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-30 20:04:24.361
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {EE084A95-D0F2-4AD5-A439-D60E7AF96ABD}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-27 03:50:02.505
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {FD88DD2D-0808-41A2-9AF7-6BB22311F5A3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-09 22:21:48.018
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1512.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-07 21:53:34.535
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1373.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-07 17:30:02.978
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1309.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-06 22:48:52.472
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1309.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-01 16:57:16.901
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.902.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

CodeIntegrity:
===================================

Date: 2018-10-26 23:05:58.943
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:05:57.162
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:50.601
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:49.557
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:30.519
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:29.469
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:12.384
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:11.336
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info =========================== 

Processor: AMD Athlon(tm) X4 740 Quad Core Processor 
Percentage of memory in use: 42%
Total physical RAM: 8145.84 MB
Available physical RAM: 4719.68 MB
Total Virtual: 9425.84 MB
Available Virtual: 5011.69 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:488.59 GB) (Free:37.18 GB) NTFS
Drive d: (Nový svazek) (Fixed) (Total:442.38 GB) (Free:39.16 GB) NTFS

\\?\Volume{99c499c4-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{350f029c-0000-0000-0000-102c7a000000}\ () (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 350F029C)
Partition 1: (Not Active) - (Size=488.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=450 MB) - (Type=27)
Partition 3: (Not Active) - (Size=442.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 74.5 GB) (Disk ID: 99C499C4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Alonzop
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 27 črc 2006 10:54
Bydliště: Czech Rep. - Brno
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#3 Příspěvek od Alonzop »

AD :

Kód: Vybrat vše

# -------------------------------
# Malwarebytes AdwCleaner 7.2.4.0
# -------------------------------
# Build:    09-25-2018
# Database: 2018-11-14.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    11-17-2018
# Duration: 00:00:03
# OS:       Windows 10 Pro
# Cleaned:  7
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\Users\Allonzo\AppData\Roaming\IObit\Advanced SystemCare
Deleted       C:\ProgramData\ytd video downloader

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

Deleted       C:\Windows\System32\Tasks\Driver Booster Scheduler

***** [ Registry ] *****

Deleted       HKCU\Software\Conduit
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B15D6389-AFE9-42D3-A46E-98BEFD7E41B6} 
Deleted       HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler
Deleted       HKCU\Software\{DAF8B7E5-449D-4180-8281-10E536E597F2}

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [3909 octets] - [10/11/2018 18:08:51]
AdwCleaner[C00].txt - [3466 octets] - [10/11/2018 18:10:36]
AdwCleaner[S01].txt - [1820 octets] - [11/11/2018 02:47:31]
AdwCleaner[C01].txt - [1835 octets] - [11/11/2018 03:04:59]
AdwCleaner[S02].txt - [2065 octets] - [17/11/2018 18:52:50]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C02].txt ##########

Alonzop
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 27 črc 2006 10:54
Bydliště: Czech Rep. - Brno
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#4 Příspěvek od Alonzop »

Ta Auepmaster neco posila na adresu "s3-1-w.amazonaws.com" . zase to jen procesem ukončil .

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#5 Příspěvek od Rudy »

Dejte nové logy FRST+Addition.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Alonzop
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 27 črc 2006 10:54
Bydliště: Czech Rep. - Brno
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#6 Příspěvek od Alonzop »

Kód: Vybrat vše

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.11.2018
Ran by Alonzop (administrator) on X-COM (17-11-2018 21:11:13)
Running from C:\Users\Allonzo\Desktop
Loaded Profiles: Alonzop (Available Profiles: Alonzop)
Platform: Windows 10 Pro Version 1803 17134.345 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atiesrxx.exe
(AMD) C:\Windows\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
() C:\Windows\KMS-R@1n.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\NisSrv.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
() C:\Program Files (x86)\AUROZA\Monitor.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
() C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe
() C:\Program Files (x86)\Anvsoft\Syncios\androidnotifier.exe
(Piriform Ltd) C:\Program Files\CCleaner\ccleaner64.exe
() C:\Program Files (x86)\Anvsoft\Syncios\adb.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amddvr.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
() C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\Win32\iDownloaderConsole.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(The Qt Company Ltd.) C:\Program Files\AMD\CNext\CNext\QtWebEngineProcess.exe
(The Qt Company Ltd.) C:\Program Files\AMD\CNext\CNext\QtWebEngineProcess.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9277280 2018-09-15] (Realtek Semiconductor)
HKLM-x32\...\Run: [AUROZA EM02C Driver] => C:\Program Files (x86)\AUROZA\Monitor.exe [761856 2014-12-08] ()
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318112 2017-11-15] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3785536 2018-11-06] (Dropbox, Inc.)
HKLM-x32\...\Run: [Syncios device service] => C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe [2443384 2018-06-13] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation)
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [731240 2018-10-19] (Disc Soft Ltd)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19467544 2018-11-06] (Piriform Ltd)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {1669ae0c-807e-11e8-9d95-806e6f6e6963} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {46ad1614-e132-11e8-9e13-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {46ad162f-e132-11e8-9e13-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {54df9d64-b5fe-11e8-9dc4-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {61c59ad5-d962-11e8-9e02-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {61c59af6-d962-11e8-9e02-d43d7e9f40c1} - "H:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {65e6848a-c7fd-11e8-9de2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {65e684ca-c7fd-11e8-9de2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6b96590e-b026-11e8-9dc1-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6b965935-b026-11e8-9dc1-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6f7a13db-8f52-11e8-9da0-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6f7a13de-8f52-11e8-9da0-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {73d980a7-6ee3-11e8-9d88-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {73d980bf-6ee3-11e8-9d88-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {807c54b4-7fd9-11e8-9d94-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {8881f623-6e7b-11e8-9d86-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {9b976dd4-9dae-11e8-9dad-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {9b976e0c-9dae-11e8-9dad-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {b2c89ff0-6141-11e8-9d7d-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11a8-e773-11e8-9e21-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11c2-e773-11e8-9e21-d43d7e9f40c1} - "G:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c9cbc6a1-c0f0-11e8-9dd2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c9cbc6b0-c0f0-11e8-9dd2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {ea175277-6068-11e8-9d7c-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {ef4b1206-b878-11e8-9dc5-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-04-29]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\TP\TWCU.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{065cbf10-2caa-4b98-845d-58f844cd7367}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{15ba6f79-c3fe-4839-8ceb-9c85902f80e6}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{235b3b59-013c-4325-a9c1-dce08de51507}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{326988a7-fdcf-4ca8-aaed-31489abff3b3}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{4a471a66-ada7-469f-b245-94f49c4983f2}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{9a8ca0e5-5e36-4865-8644-400ce9f0a8bd}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{af220eb6-d63e-4c3d-994d-6b90b4308bf9}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{e654c3cc-dce8-4a0f-8348-3f7fa65109bd}: [DhcpNameServer] 10.0.0.138

Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_172\bin\ssv.dll [2018-06-22] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_172\bin\jp2ssv.dll [2018-06-22] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: 840j6bnm.default
FF ProfilePath: C:\Users\Allonzo\AppData\Roaming\TomTom\HOME\Profiles\bovmmkmh.default [2016-10-26]
FF ProfilePath: C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default [2018-11-17]
FF Homepage: Mozilla\Firefox\Profiles\840j6bnm.default -> seznam.cz
FF Extension: (Messenger for WhatsApp™) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\rt42fsdty645jIidD@jetpack.xpi [2017-11-26]
FF Extension: (Download Manager (S3)) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\s3download@statusbar.xpi [2018-11-17]
FF Extension: (uBlock Origin) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\uBlock0@raymondhill.net.xpi [2018-02-02]
FF Extension: (Adblock Plus) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-12]
FF Extension: (iDM Integration Extension) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\{ed9a84e6-a04e-4d97-ad7e-b7414f2912eb}.xpi [2018-09-08]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_31_0_0_148.dll [2018-11-14] ()
FF Plugin: @java.com/DTPlugin,version=11.172.2 -> C:\Program Files\Java\jre1.8.0_172\bin\dtplugin\npDeployJava1.dll [2018-06-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.172.2 -> C:\Program Files\Java\jre1.8.0_172\bin\plugin2\npjp2.dll [2018-06-22] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_148.dll [2018-11-14] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD External Events Utility; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atiesrxx.exe [521944 2018-11-08] (AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-09-11] (Advanced Micro Devices, Inc.) [File not signed]
S2 AUEPLauncher; C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe [43008 2018-11-07] (AMD) [File not signed]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-05-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-05-27] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2018-11-06] (Dropbox, Inc.)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3729512 2018-10-19] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-08-27] (EasyAntiCheat Ltd)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-08-23] () [File not signed]
R2 KMS-R@1n; C:\Windows\KMS-R@1n.exe [26112 2017-06-06] () [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-15] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S3 sshd; C:\WINDOWS\System32\OpenSSH\sshd.exe [970240 2018-05-20] ()
S3 SshdBroker; C:\WINDOWS\System32\SshdBroker.dll [286720 2018-09-08] (Microsoft Corporation)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\NisSrv.exe [3917016 2018-10-23] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MsMpEng.exe [114208 2018-10-23] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atikmdag.sys [47840744 2018-11-08] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atikmpag.sys [604632 2018-11-08] (Advanced Micro Devices, Inc.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [42240 2013-07-31] (Advanced Micro Devices)
R2 AODDriver4.3.0; C:\Program Files\AMD\Performance Profile Client\amd64\AODDriver2.sys [60104 2015-02-19] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [107496 2018-05-28] (Advanced Micro Devices)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2018-05-27] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-01-31] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-08-02] (Disc Soft Ltd)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-31] (REALiX(tm))
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-08-23] (Huawei Technologies Co., Ltd.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1118648 2018-10-25] (Realtek )
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8228688 2018-09-27] (Realtek Semiconductor Corporation )
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2018-05-27] (Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [22016 2018-04-12] (Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46184 2018-10-23] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [328696 2018-10-23] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60408 2018-10-23] (Microsoft Corporation)
S3 MSICDSetup; \??\E:\CDriver.sys [X]
S3 SWDUMon; \SystemRoot\system32\DRIVERS\SWDUMon.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-17 19:30 - 2018-11-17 19:30 - 000000000 ____D C:\ProgramData\YTD Video Downloader
2018-11-17 18:52 - 2018-11-17 18:52 - 007592144 _____ (Malwarebytes) C:\Users\Allonzo\Downloads\adwcleaner_7.2.4.0(1).exe
2018-11-17 17:05 - 2018-11-17 21:12 - 000017465 _____ C:\Users\Allonzo\Desktop\FRST.txt
2018-11-17 17:04 - 2018-11-17 21:11 - 000000000 ____D C:\FRST
2018-11-17 16:48 - 2018-11-17 16:48 - 002416128 _____ (Farbar) C:\Users\Allonzo\Desktop\FRST64.exe
2018-11-17 15:19 - 2018-11-17 16:19 - 000000000 ____D C:\Users\Allonzo\Desktop\bordel
2018-11-17 07:43 - 2018-11-17 07:43 - 000002215 _____ C:\Users\Public\Desktop\MTG Arena.lnk
2018-11-17 07:41 - 2018-11-17 07:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MTG Arena
2018-11-16 21:42 - 2018-11-16 21:42 - 000003160 _____ C:\WINDOWS\System32\Tasks\StartCN
2018-11-16 21:42 - 2018-11-16 21:42 - 000003074 _____ C:\WINDOWS\System32\Tasks\StartDVR
2018-11-16 21:42 - 2018-11-16 21:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2018-11-10 18:07 - 2018-11-10 18:07 - 007592144 _____ (Malwarebytes) C:\Users\Allonzo\Downloads\adwcleaner_7.2.4.0.exe
2018-11-09 20:47 - 2018-11-16 21:41 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\AMD
2018-11-09 20:34 - 2018-11-09 20:35 - 026450000 _____ (AMD Inc.) C:\Users\Allonzo\Downloads\radeon-software-adrenalin-18.11.1-minimalsetup-181108_64bit.exe
2018-11-08 17:04 - 2018-11-08 17:04 - 001211976 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000189816 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000165520 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000029136 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2018-11-07 18:41 - 2018-11-07 18:41 - 000166728 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdihk64.dll
2018-11-07 18:41 - 2018-11-07 18:41 - 000137888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdihk32.dll
2018-11-07 06:44 - 2018-11-07 06:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-11-06 14:06 - 2018-11-06 14:06 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2018-11-06 14:06 - 2018-11-06 14:06 - 000047768 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2018-11-06 14:06 - 2018-11-06 14:06 - 000047768 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2018-11-06 14:06 - 2018-11-06 14:06 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2018-11-02 18:07 - 2018-11-02 18:07 - 000000000 ____D C:\Users\Allonzo\AppData\Local\RadeonSettings
2018-11-02 17:58 - 2018-11-02 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\##ID_STRING16##
2018-10-30 20:58 - 2018-10-30 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sudden Strike 4 [GOG.com]
2018-10-28 15:14 - 2018-10-28 15:14 - 000000000 ____D C:\Users\Public\Documents\Catch!
2018-10-28 15:13 - 2018-10-28 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2018-10-28 14:59 - 2018-10-28 14:59 - 000791712 _____ (Disc Soft Ltd.) C:\Users\Allonzo\Downloads\DTLiteInstaller.exe
2018-10-26 21:25 - 2018-10-26 21:25 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\DataWorks
2018-10-26 21:23 - 2018-10-26 21:23 - 000002940 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Alonzop)
2018-10-26 21:23 - 2018-10-26 21:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 6
2018-10-26 21:23 - 2018-10-26 21:23 - 000000000 ____D C:\Program Files (x86)\IObit
2018-10-26 21:21 - 2018-10-26 21:21 - 000275946 _____ C:\Users\Allonzo\Downloads\Phoenix.bsz
2018-10-26 21:21 - 2018-10-26 21:21 - 000242076 _____ C:\Users\Allonzo\Downloads\Sony_CDX_GT410U_v3.02_by_Rafa_Santos.bsz
2018-10-26 21:21 - 2018-10-26 21:21 - 000125686 _____ C:\Users\Allonzo\Downloads\R.A.D.I.O..bsz
2018-10-26 21:09 - 2018-10-26 21:10 - 026450000 _____ (AMD Inc.) C:\Users\Allonzo\Downloads\radeon-software-adrenalin-18.10.2-minimalsetup-181025_64bit.exe
2018-10-26 21:02 - 2018-11-08 17:04 - 001611264 _____ (AMD) C:\WINDOWS\system32\SETE916.tmp
2018-10-26 21:02 - 2018-11-08 17:04 - 001611264 _____ (AMD) C:\WINDOWS\system32\coinst_18.40.dll
2018-10-26 21:02 - 2018-10-26 21:02 - 001587616 _____ (AMD) C:\WINDOWS\system32\SETCFA1.tmp
2018-10-26 21:02 - 2018-10-26 21:02 - 000124464 _____ C:\WINDOWS\system32\kapp_ci.sbin
2018-10-26 21:02 - 2018-10-26 21:02 - 000119760 _____ C:\WINDOWS\system32\kapp_si.sbin
2018-10-26 21:02 - 2018-10-26 21:02 - 000034450 _____ C:\WINDOWS\system32\AMDKernelEvents.man
2018-10-26 21:02 - 2018-10-25 19:50 - 001587816 _____ (AMD) C:\WINDOWS\system32\SETBD7C.tmp
2018-10-26 21:02 - 2018-10-25 19:50 - 001587816 _____ (AMD) C:\WINDOWS\system32\SETA878.tmp
2018-10-25 19:50 - 2018-11-08 17:04 - 000029136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2018-10-25 19:50 - 2018-10-25 19:50 - 001192032 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\SET10CB.tmp
2018-10-25 19:50 - 2018-10-25 19:50 - 000019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SET9E4.tmp
2018-10-25 19:50 - 2018-10-25 19:50 - 000019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SET879C.tmp
2018-10-20 05:30 - 2018-10-20 05:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Northgard Ragnarok

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-17 21:10 - 2017-12-20 21:13 - 000007644 _____ C:\Users\Allonzo\AppData\Local\resmon.resmoncfg
2018-11-17 21:09 - 2016-11-19 02:44 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\Mozilla
2018-11-17 20:22 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-11-17 18:59 - 2018-05-07 17:24 - 001689054 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-11-17 18:59 - 2018-04-12 16:51 - 000715202 _____ C:\WINDOWS\system32\perfh005.dat
2018-11-17 18:59 - 2018-04-12 16:51 - 000144496 _____ C:\WINDOWS\system32\perfc005.dat
2018-11-17 18:59 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF
2018-11-17 18:55 - 2018-05-07 17:07 - 000398240 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-11-17 18:54 - 2018-05-07 17:31 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-11-17 18:53 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-11-17 18:53 - 2016-09-21 22:56 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2018-11-17 18:45 - 2017-05-05 21:14 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-11-17 18:40 - 2018-05-07 17:07 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-11-17 16:56 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-11-17 16:56 - 2016-04-27 07:34 - 000000000 ____D C:\WINDOWS\ShellNew
2018-11-17 16:54 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files\Common Files\system
2018-11-17 16:54 - 2015-07-10 12:04 - 000000139 _____ C:\WINDOWS\win.ini
2018-11-17 16:53 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-11-17 16:47 - 2018-05-07 17:39 - 000000000 ____D C:\Users\Allonzo\AppData\Local\PlaceholderTileLogoFolder
2018-11-17 16:47 - 2018-01-20 12:10 - 000000000 ____D C:\Users\Allonzo\AppData\Local\Packages
2018-11-17 16:46 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-11-17 15:24 - 2017-05-05 21:05 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-11-17 15:24 - 2017-05-05 21:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-11-17 15:21 - 2018-05-12 20:21 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2018-11-17 15:14 - 2016-08-17 04:33 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-11-17 10:29 - 2018-05-07 17:33 - 000000000 ____D C:\Users\Allonzo\AppData\Local\D3DSCache
2018-11-17 07:39 - 2018-01-27 15:42 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\MPC-HC
2018-11-17 01:51 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-11-16 21:42 - 2016-09-21 22:56 - 000000000 ____D C:\Program Files\AMD
2018-11-16 21:41 - 2018-03-31 01:53 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-11-16 21:39 - 2017-05-17 16:00 - 000000000 ____D C:\AMD
2018-11-16 21:36 - 2016-07-31 17:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-11-16 21:36 - 2016-07-31 17:53 - 000000000 ____D C:\Program Files\Java
2018-11-15 22:54 - 2018-06-22 22:36 - 000000000 ____D C:\Users\Allonzo\Desktop\apky
2018-11-15 22:31 - 2018-05-07 17:31 - 000003362 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2823601367-1896843323-1796517690-1001
2018-11-15 22:31 - 2018-05-07 17:12 - 000002397 _____ C:\Users\Allonzo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-11-15 22:31 - 2016-07-31 08:20 - 000000000 ___RD C:\Users\Allonzo\OneDrive
2018-11-15 18:09 - 2016-08-02 04:59 - 000000000 ____D C:\Users\Allonzo\Desktop\dokumenty
2018-11-15 18:08 - 2018-02-09 15:48 - 000000000 ____D C:\Users\Allonzo\Desktop\Gamesky
2018-11-14 05:42 - 2017-03-10 19:24 - 000000000 ____D C:\Users\Allonzo\Desktop\completed
2018-11-14 01:03 - 2018-05-07 17:31 - 000004638 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-11-14 01:03 - 2018-05-07 17:31 - 000004470 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2018-11-14 01:02 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-11-14 01:02 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-11-12 19:37 - 2018-03-24 01:32 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\IObit
2018-11-12 19:24 - 2018-03-24 01:38 - 000000000 ____D C:\ProgramData\ProductData
2018-11-10 18:10 - 2016-07-31 11:27 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\IObit
2018-11-10 18:08 - 2018-01-14 10:08 - 000000000 ____D C:\AdwCleaner
2018-11-09 22:22 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-11-09 20:35 - 2018-03-31 01:49 - 000000060 _____ C:\ProgramData\SoftwareUpdateTemp.xml
2018-11-08 17:04 - 2018-04-26 23:36 - 003754160 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 003471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2018-11-08 17:04 - 2018-04-26 23:36 - 003437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2018-11-08 17:04 - 2018-04-26 23:36 - 003379720 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 001653048 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SETE2D3.tmp
2018-11-08 17:04 - 2018-04-26 23:36 - 001653048 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 001211976 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000937704 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000901288 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2018-11-08 17:04 - 2018-04-26 23:36 - 000901288 _____ C:\WINDOWS\system32\atiapfxx.blb
2018-11-08 17:04 - 2018-04-26 23:36 - 000769280 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000766720 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000585512 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000567432 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000554072 _____ C:\WINDOWS\system32\amdmiracast.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000505928 _____ C:\WINDOWS\system32\dgtrayicon.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000495632 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000490400 _____ C:\WINDOWS\system32\GameManager64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000481504 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000479016 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000445448 _____ C:\WINDOWS\system32\atieah64.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000395896 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000394272 _____ C:\WINDOWS\SysWOW64\SETE560.tmp
2018-11-08 17:04 - 2018-04-26 23:36 - 000394272 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000390160 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000361784 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000352000 _____ C:\WINDOWS\system32\clinfo.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000261080 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000229568 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000208616 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000195520 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000182656 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000180288 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000173808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000170760 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000164032 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000159928 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000154072 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000149040 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146416 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000143336 _____ C:\WINDOWS\system32\atidxx64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000138656 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000135632 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000133800 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122384 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122128 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000119016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000079752 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000056176 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000053056 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
2018-11-07 22:53 - 2018-05-07 17:31 - 000004212 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-11-07 21:42 - 2018-05-07 17:12 - 000000000 ____D C:\Users\Allonzo
2018-11-07 06:45 - 2018-05-27 05:46 - 000000000 ___RD C:\Users\Allonzo\Dropbox
2018-11-07 06:45 - 2018-05-27 05:37 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-11-06 17:59 - 2017-10-29 19:20 - 000000000 ____D C:\Program Files\CCleaner
2018-11-04 18:04 - 2017-04-23 20:04 - 000000000 ____D C:\Users\Allonzo\AppData\Local\ElevatedDiagnostics
2018-11-04 09:19 - 2018-05-12 19:04 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2018-11-04 09:18 - 2017-12-09 12:47 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2018-11-04 09:18 - 2017-06-28 17:58 - 000000000 ___HD C:\WINDOWS\msdownld.tmp
2018-11-04 09:17 - 2016-07-31 11:57 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2018-11-04 09:12 - 2018-09-14 05:54 - 000003126 _____ C:\WINDOWS\System32\Tasks\MSIAfterburner
2018-11-04 07:24 - 2016-08-02 18:04 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\DAEMON Tools Lite
2018-11-02 17:45 - 2016-07-31 10:59 - 000000000 ____D C:\Program Files\ATI
2018-10-29 18:42 - 2017-04-22 18:00 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\TP-LINK
2018-10-28 15:25 - 2016-08-06 05:10 - 000000000 ____D C:\Users\Allonzo\AppData\Local\Disc_Soft_Ltd
2018-10-28 15:14 - 2016-12-28 12:38 - 000000000 ____D C:\Program Files\DAEMON Tools Lite
2018-10-28 15:06 - 2016-08-02 18:03 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite
2018-10-27 22:31 - 2017-01-19 15:21 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\BSplayer PRO
2018-10-27 16:22 - 2016-09-21 22:57 - 000000000 ____D C:\Program Files (x86)\AMD
2018-10-27 04:35 - 2016-07-31 10:59 - 000000000 ____D C:\Program Files (x86)\ATI Technologies
2018-10-27 00:12 - 2018-08-05 08:11 - 000000000 ____D C:\Users\Allonzo\Downloads\iDM
2018-10-26 22:10 - 2018-03-31 00:41 - 000000000 ____D C:\Program Files\ATI Technologies
2018-10-26 22:10 - 2016-09-21 22:56 - 000000000 ____D C:\ProgramData\Package Cache
2018-10-26 22:10 - 2016-07-31 10:59 - 000000000 ____D C:\ProgramData\AMD
2018-10-26 21:24 - 2018-03-24 01:32 - 000000000 ____D C:\ProgramData\IObit
2018-10-26 21:02 - 2018-04-26 23:36 - 001629296 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SETA1E6.tmp
2018-10-26 20:40 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-10-25 19:50 - 2018-04-26 23:36 - 001629280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SETA255.tmp
2018-10-25 19:50 - 2018-04-26 23:36 - 001629280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SET865A.tmp
2018-10-25 19:50 - 2018-04-26 23:36 - 001629280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SET381.tmp
2018-10-25 19:50 - 2018-04-26 23:36 - 000381544 _____ C:\WINDOWS\SysWOW64\SETB31.tmp
2018-10-25 19:50 - 2018-04-26 23:36 - 000381544 _____ C:\WINDOWS\SysWOW64\SET882E.tmp
2018-10-25 18:52 - 2018-05-08 08:01 - 001118648 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2018-10-23 05:33 - 2018-02-25 02:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-10-22 19:24 - 2018-05-26 16:47 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\Syncios
2018-10-18 19:36 - 2016-07-31 10:36 - 000559880 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe

==================== Files in the root of some directories =======

2017-06-04 00:06 - 2018-05-27 13:58 - 000006144 _____ () C:\Users\Allonzo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2017-12-20 21:13 - 2018-11-17 21:10 - 000007644 _____ () C:\Users\Allonzo\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-07 17:07

==================== End of FRST.txt ============================

Alonzop
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 27 črc 2006 10:54
Bydliště: Czech Rep. - Brno
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#7 Příspěvek od Alonzop »

addi

Kód: Vybrat vše

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15.11.2018
Ran by Alonzop (17-11-2018 21:12:49)
Running from C:\Users\Allonzo\Desktop
Windows 10 Pro Version 1803 17134.345 (X64) (2018-05-07 16:32:57)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2823601367-1896843323-1796517690-500 - Administrator - Disabled)
Alonzop (S-1-5-21-2823601367-1896843323-1796517690-1001 - Administrator - Enabled) => C:\Users\Allonzo
DefaultAccount (S-1-5-21-2823601367-1896843323-1796517690-503 - Limited - Disabled)
Guest (S-1-5-21-2823601367-1896843323-1796517690-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2823601367-1896843323-1796517690-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.148 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 18.11.1 - Advanced Micro Devices, Inc.)
AUROZA EM02C Driver (HKLM-x32\...\{2F9C99E1-A1D2-4ADB-AFA0-3A1ED9471811}) (Version:  - )
AVG PC TuneUp (HKLM-x32\...\{149D912F-03DB-4895-913E-820CB11965C0}) (Version: 16.74.1 - AVG Technologies) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Branding64 (HKLM\...\{EE2AFCE4-0238-4DE0-A140-1647021627C1}) (Version: 1.00.0001 - Advanced Micro Devices, Inc.) Hidden
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.70.1080 - AB Team, d.o.o.)
Catalyst Control Center Next Localization BR (HKLM\...\{118C2119-84B6-E32C-63E2-B56DBCF41CE5}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{3E245378-BF77-6946-C6F6-096DBE5EAB82}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{51F85784-6799-5CA3-97B2-2E5904FC3E58}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{55A4D3AB-C8DF-26B2-89A8-7E16E1E40700}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{A16E186C-58C4-3BDC-5CCE-714EFEF5F27F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{238F6F6F-2544-86CF-3AB6-2CDADAB58CF0}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{36EDC500-E4C0-371C-9865-08450415C1E9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{62098A5F-E03B-31A3-5F9C-51A7F7D25744}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{84C3F2C5-F7B2-2F08-CDF4-79EF7CC55D74}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{A0407E39-2AA4-60B3-885F-3C5347B6909E}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{C3EE628C-7394-FE2C-0C90-C05284EB528D}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{0989D0EA-AFF3-5F9A-3D25-20EE133E409B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{0E8A3B17-D603-B1B6-C205-1685EBDD23E9}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{1757AD9B-0E3C-05F9-FE43-4343BED7DA85}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{2F544F46-5F6E-97BB-3550-A0242A3C5754}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{EC688BD0-240D-AE40-55F3-234E54919AE6}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{1E7D3072-1D28-E33A-99DF-85D9F7ECD06E}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{66B06F29-EE4F-9130-D96A-754826093FEA}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{A8689A0F-5928-7300-B82B-C5E85131B7BA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{D74218A3-C503-57EF-AC9F-2220082E7ADE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{E27224E3-7913-DA1E-5B08-9BEEC8FEE3D1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{FC4086D6-E345-5F43-08BB-280FB57DAF49}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{76AAF56B-93D8-161D-809A-EC05F3B913DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{821D0A0E-F246-BE40-0D68-93883C14C410}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{95A52FC1-C728-841D-1BFC-CC793B77B0A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{BA26B70C-3D8C-2D14-4122-211FB3E6F691}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{F8EBE530-A4D5-BF51-F623-3787E6B8A878}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{063CED74-F5F0-870E-DC9C-2D78FDEDA3EE}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{42FBD43F-DE53-6D4D-5134-E3C93B45CBEF}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{5FEACE78-C338-9AED-FF05-7DE7E273C774}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{88BD74C4-23AB-4554-915C-6E1F0C81F6CD}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{A22CDEBA-6DB5-12CD-F6CE-6238C2D78363}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{13BB60AA-88F7-4B1F-2DEC-D81EEDE8B3AA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{20D46801-147B-30AD-7C5A-AC4560A79096}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{A3795528-F572-6314-C4E3-EE9DAF0FBF02}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{A48E2AB0-0866-7783-9657-E1709EB18D02}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{AC85CF50-9A55-0103-ADBF-365C37603AA4}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{C0BFC67D-E447-02C8-6046-C078DFE9EC97}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{22C39711-2747-D264-319A-1550BEEAAEC6}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{37AA6227-FF2C-95AC-87C0-45DCC0BB87DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{4853A56D-7931-A08B-5BA7-8E2D61043DF9}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{94C72EBE-2908-F0AC-62DA-D61951830F8F}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{B349892D-B015-033C-4CA8-3635E6B655D7}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{E61CEF9A-BAC3-EAEE-F735-E257D2354DF2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{1DBACFDB-5E43-7882-36BD-53526D34BD22}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{5B987681-3652-492B-6A11-E02AC0FE5959}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{B28CF677-E2C8-12CA-52BB-19B6F066D36A}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{BE8D6AB1-3049-2F0C-67FA-00C0A5D321A3}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{DA0326BB-657D-AAFC-752C-363E8FA33755}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{EB328356-1DF0-1CCE-3607-6361DD329219}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{365AEAB2-4CF3-7CBB-0DAC-E9E14B688E65}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{45907537-804A-514F-5280-5F4F12A6DCBC}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{5A083A57-10D6-D4E5-292C-F274870E73A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{8E6F5592-ED7E-9C50-74AC-BF417B1FE291}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{E42911E5-48F8-8557-ED20-D72AD1907D25}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{7ABC6D83-816E-6D48-E65D-B0CEDD294E4E}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{962364E4-08BB-347D-32E7-2B789F37BF8A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{AD28960A-6190-C991-C964-308B86EAA2E2}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B4C30EF4-B2C5-1395-B534-7B63BCB6E8E4}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{DF0D7C1C-72B6-9FFB-DF66-B3720237BB80}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{26567561-DFB2-2B63-9BA8-6A490ED37016}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{43F6D22B-E0E9-EE90-9B62-1C5FC5D15A55}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{86BFE5B4-1FCE-3C02-6373-92B1AE6431E8}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{87E6EC29-AEC5-28CB-F773-93EB6C1B8A2B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{B873A1FB-5EA0-EE5F-A861-1E38880AD08E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{0742432E-42D9-2240-4CA1-8595CCCBAA77}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{0809FEC1-EF86-51E9-8210-DC1B1BDB6745}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{CA55697D-BD74-3ED8-6B21-D7EDAD3B7D02}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{D4490E0F-8E7B-1097-B56A-7643C75F1C28}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{EC9DF9FF-9D75-4CDD-1D58-A2E887B0A42E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{ED75A775-03A7-F214-868D-497748707968}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{5FD706FF-6AD8-E372-A35A-879409982655}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{7ABACA7E-6E59-0EF9-8FA3-6B32E5F58127}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{CFC860C8-4F51-E08C-A74C-2E444ED06160}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{DAB44116-0266-C65B-B643-AC11217C3041}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{EAEAA839-44F4-22DF-D1CC-88C3B2A3D4B1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{3AF70346-52C7-0334-606F-118D1C1CB7A2}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{3E196AAF-F81C-B384-E2AB-28EE2398FE5F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{9338D693-38B7-1ED4-9B42-BFA1D5600CCB}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{A3973655-E448-4A1B-477C-988A79D132D9}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{A4E7CA0C-84EB-5E29-2F04-06C4E4790C2F}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{53AE8AC7-5213-67AF-0DC0-CED696B77643}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{59D2664C-949B-7FA7-9880-ECB993B6616A}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{6DC92550-D065-4B36-C4D3-D8D7A702A7A7}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{C971C145-258D-6650-7088-13DDB161327A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DAEFFE0C-CD05-1355-6AFC-7B3D4106A820}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{970A40CA-46AB-986C-1798-976ED0EA00FA}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{B2A83706-3F14-1532-20CD-B4EE715A8945}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{DC9DFCBF-87DA-892C-6151-99CC9EF46E3E}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{E392A425-53A7-DF90-96A0-E287A75DD3B2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{EBA09DAF-14B4-7BE7-676E-6E2FB21EDBDD}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{44ED2CDA-4197-E9E9-B328-26E1FB749116}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{4707CBFC-8ED4-463E-0FF9-DE86F4A743E9}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{4D1D5407-9B69-6422-629C-8518A26004A4}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{9AA4DD93-94BF-22EA-C9D2-7084F304A31B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{C1EFF2A2-DF4A-F6D1-B99C-1ED194AE9E78}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{D6F47BB4-700A-F612-0671-5F69EA311BB7}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{01FD9A26-3F61-9236-B360-BE5D043D82C0}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{3450566C-4561-0EE8-B1AB-D5C79CCE8D2C}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{379D900B-A785-6DB0-012E-434356A365B3}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{46EB68BE-8AAC-8C2B-7284-8DEDE6B5CD2A}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{C14A3A5B-8A86-C239-37D7-158211778C54}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{24DF617A-CD23-6E6A-126B-23630D2781CE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{366C4FB5-CF6E-258B-418D-E6D29549A278}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{64D4CCC3-63DF-252D-D29D-03491670225D}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{7A6E431B-CF43-EC3E-FD7E-0A0AAB1B25FC}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{A50C89BC-8D8E-8828-824A-7171F6D583D5}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{FCE8438C-3272-D63F-479F-670F082B294B}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{0B5633F0-C415-2F08-671E-4C9E2FAACD45}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{25D1751E-7CA2-5F6D-0125-0A16E47AF9FE}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{89A1F076-19B8-A2B1-D5A3-E8247EFAF157}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{8DF90937-B869-9F76-5D45-5A8BDA0A33B6}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{B10089DE-934F-6E0F-683A-B788F89348DF}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.36 - Piriform)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.9.0.0650 - Disc Soft Ltd)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Discord (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Discord) (Version: 0.0.301 - Discord Inc.)
Divinity: Original Sin Enhanced Edition (2.0.119.430_(hotfix)) (HKLM-x32\...\1445516929_is1) (Version: 0.1.1.310 - GOG.com)
Driver Booster 6 (HKLM-x32\...\Driver Booster_is1) (Version: 6.0.2 - IObit)
Dropbox (HKLM-x32\...\Dropbox) (Version: 61.4.95 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.141.1 - Dropbox, Inc.) Hidden
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 8.0.1.303 - )
Java 8 Update 161 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Java 8 Update 162 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180162F0}) (Version: 8.0.1620.12 - Oracle Corporation)
Java 8 Update 172 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180172F0}) (Version: 8.0.1720.11 - Oracle Corporation)
K-Lite Mega Codec Pack 14.3.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.3.0 - KLCP)
Microsoft OneDrive (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\OneDriveSetup.exe) (Version: 18.192.0920.0015 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429 (HKLM-x32\...\{80586c77-db42-44bb-bfc8-7aebbb220c00}) (Version: 14.14.26429.4 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 (HKLM-x32\...\{cb7c3049-21de-415b-bd85-b65c14e547df}) (Version: 14.10.25017.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mozilla Firefox 63.0.3 (x64 cs) (HKLM\...\Mozilla Firefox 63.0.3 (x64 cs)) (Version: 63.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.2 - Mozilla)
MTG Arena (HKLM-x32\...\{A509DF1D-8265-4F4C-A866-177C0E0799D4}) (Version: 0.1.910.0 - Wizards of the Coast) Hidden
MTG Arena (HKLM-x32\...\MTG Arena 0.1.910.0) (Version: 0.1.910.0 - Wizards of the Coast)
Northgard Ragnarok (HKLM-x32\...\Northgard Ragnarok_is1) (Version:  - )
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.3 - Notepad++ Team)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Pillars of Eternity 2 Deadfire Beast of Winter (HKLM-x32\...\Pillars of Eternity 2 Deadfire Beast of Winter_is1) (Version:  - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.10.714.2016 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8485 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.9 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.9 - VS Revo Group, Ltd.)
RivaTuner Statistics Server 7.2.0 (HKLM-x32\...\RTSS) (Version: 7.2.0 - Unwinder)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.8 - Rockstar Games)
Samsung Kies (HKLM-x32\...\{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.4.17113.1 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.4.17113.1 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.)
Sid Meiers Civilization VI Rise and Fall (HKLM-x32\...\Sid Meiers Civilization VI Rise and Fall_is1) (Version:  - )
Sudden Strike 4 - Finland: Winter Storm (HKLM-x32\...\1937377674_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4 (HKLM-x32\...\2146639313_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4: Battle of Kursk (HKLM-x32\...\1938212434_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4: Road to Dunkirk (HKLM-x32\...\1589182480_is1) (Version: 1.12.28520 - GOG.com)
Syncios 6.5.0 (HKLM-x32\...\Syncios) (Version: 6.5.0 - Anvsoft)
TeamSpeak 3 Client (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\TeamSpeak 3 Client) (Version: 3.1.4.2 - TeamSpeak Systems GmbH)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 2.0.0.0 - Zenimax Online Studios)
TP-LINK TL-WN823N Driver (HKLM-x32\...\{CE194A8D-C8DF-47EB-AB04-5A54CDC1C5BD}) (Version: 1.3.1 - TP-LINK)
TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{EC5A6438-850E-4AD1-9169-DD071C8EFFEF}) (Version: 2.10.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 51.0 - Ubisoft)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0-4) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Web Companion (HKLM-x32\...\{46b8e553-65e1-4bb3-b888-f5e91c54a65e}) (Version: 4.0.1780.3335 - Lavasoft)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2017-03-08] ()
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (Disc Soft Ltd)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-11-07] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2016-12-15] (VS Revo Group)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0CADBE77-2C19-4752-9BF6-7251F2952B37} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-05-27] (Dropbox, Inc.)
Task: {13E14763-C7B0-455B-9D99-6DBB495C8E62} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe [2018-11-07] (Advanced Micro Devices, Inc.)
Task: {3474EEEF-B521-466E-A075-4A1D30B5A899} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {39F6B51E-B91B-46E5-A786-2A8D5AE52E4E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {51D36D56-BC7F-4C67-A0C6-7C13BCBD7167} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_148_Plugin.exe [2018-11-14] (Adobe Systems Incorporated)
Task: {572993BF-0C1D-4A4D-BB9D-BF82384CA453} - System32\Tasks\Driver Booster SkipUAC (Alonzop) => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe [2018-10-17] (IObit)
Task: {5997F85B-42AF-458A-A0B2-04EC79860672} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2018-11-07] (Advanced Micro Devices, Inc.)
Task: {63A2E2B2-3C3F-4F53-BD65-74E110253C8A} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-11-14] (Adobe Systems Incorporated)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {663BEA23-9E12-45C9-8B54-D599258C972A} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-05-27] (Dropbox, Inc.)
Task: {6B428069-F812-4D67-9F96-9F48FF3A0D9E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-10-18] (Piriform Ltd)
Task: {8FA9C88E-06BC-412D-BA13-0FD6FF2D6072} - System32\Tasks\S-1-5-21-2823601367-1896843323-1796517690-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-04-12] (Microsoft Corporation)
Task: {9685C6F0-9309-4642-A4EC-9D1C6E9A2B6B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {A73AB5E5-6651-46FC-AED0-B22FA898490B} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {D6748BBC-9FF5-491D-981D-E37897A8F55C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {E2D0F99B-387E-402C-9113-001EC05D5F7F} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-10-06] (Oracle Corporation)
Task: {EEB666C1-E343-4ED0-9AEE-7B7BD1898CA6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-11-06] (Piriform Ltd)
Task: {F5483C6F-96AF-4DAB-9BDD-5DC449A1E80B} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
Task: {FDDC310D-629B-4364-9075-27AD794DC026} - System32\Tasks\klcp_update => CodecTweakTool.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-08-23 13:42 - 2018-08-23 13:42 - 000190784 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2017-06-06 16:53 - 2017-06-06 16:53 - 000026112 _____ () C:\Windows\KMS-R@1n.exe
2018-04-12 00:34 - 2018-04-12 00:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2017-03-08 03:42 - 2017-03-08 03:42 - 000230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2018-10-26 19:00 - 2018-10-26 19:00 - 035118592 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-10-26 19:00 - 2018-10-26 19:00 - 000290816 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\SharedUI.dll
2018-10-26 19:00 - 2018-10-26 19:00 - 005987328 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\EntCommon.dll
2017-09-26 16:11 - 2017-09-26 16:11 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-10-26 19:00 - 2018-10-26 19:00 - 009064448 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\EntPlat.dll
2018-06-27 22:04 - 2018-06-27 22:04 - 000014336 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.DLL
2018-06-27 22:04 - 2018-06-27 22:04 - 002552832 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2018-04-07 13:03 - 2014-12-08 08:56 - 000761856 _____ () C:\Program Files (x86)\AUROZA\Monitor.exe
2018-06-13 07:00 - 2018-06-13 07:00 - 002443384 _____ () C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe
2018-05-30 09:16 - 2018-05-30 09:16 - 000017024 _____ () C:\Program Files (x86)\Anvsoft\Syncios\androidnotifier.exe
2017-10-09 13:22 - 2012-12-21 19:33 - 000020288 _____ () C:\Program Files\CCleaner\branding.dll
2017-10-18 17:19 - 2017-10-18 17:19 - 000086224 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 001091896 _____ () C:\Program Files (x86)\Anvsoft\Syncios\adb.exe
2018-11-17 16:46 - 2018-11-17 16:46 - 000046080 _____ () C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\Win32\iDownloaderConsole.exe
2018-10-14 08:47 - 2018-09-20 04:38 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-11-15 19:55 - 2018-11-15 19:56 - 000478720 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2018-11-15 19:55 - 2018-11-15 19:56 - 066031104 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2018-11-15 19:55 - 2018-11-15 19:56 - 003715072 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2018-11-15 19:55 - 2018-11-15 19:57 - 000010752 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\RenderingPlugin.dll
2018-01-20 13:02 - 2018-01-20 13:03 - 002523136 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\UnityEngineDelegates.dll
2018-11-15 19:55 - 2018-11-15 19:57 - 000036352 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
2018-08-17 12:23 - 2018-08-17 12:23 - 002280960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\opencv_core320.dll
2018-08-17 12:23 - 2018-08-17 12:23 - 002480640 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\opencv_imgproc320.dll
2018-04-05 15:29 - 2018-04-05 15:31 - 002283008 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\TrackingDLLUWP.dll
2018-11-15 19:55 - 2018-11-15 19:57 - 014097920 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\PhotosApp.Windows.dll
2018-11-15 19:55 - 2018-11-15 19:56 - 003569152 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2018-11-15 19:55 - 2018-11-15 19:56 - 002863616 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\AppCore.Windows.dll
2018-08-30 18:41 - 2018-08-30 18:43 - 000973312 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\RuntimeConfiguration.dll
2018-07-26 15:04 - 2018-07-26 15:04 - 004584960 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-11-15 19:55 - 2018-11-15 19:57 - 000146432 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x64__8wekyb3d8bbwe\SKU.dll
2018-04-07 13:03 - 2014-09-09 14:05 - 000057344 _____ () C:\Program Files (x86)\AUROZA\lan.dll
2018-04-07 13:03 - 2013-11-01 11:57 - 000049152 _____ () C:\Program Files (x86)\AUROZA\hiddriver.dll
2018-11-07 06:43 - 2018-11-06 14:06 - 001141064 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2018-11-07 06:43 - 2018-11-06 14:06 - 002103112 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000023376 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025456 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000142312 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 001953640 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000118232 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes35.dll
2018-11-07 06:44 - 2018-11-06 14:06 - 000109024 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000083784 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000418776 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom35.dll
2018-11-07 06:44 - 2018-11-06 14:08 - 000074072 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000049128 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000026600 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000131552 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000182752 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000119272 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000401752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000028640 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000034664 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000061792 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:06 - 000023520 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000053736 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000065504 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025944 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000068968 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000032224 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000156504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000092488 _____ () C:\Program Files (x86)\Dropbox\Client\sip.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 001778000 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000518992 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000052056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 001929552 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 003821392 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000044888 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000132944 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000218456 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000205656 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000061408 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000051552 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027624 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000033632 _____ () C:\Program Files (x86)\Dropbox\Client\winreindex.compiled._winreindex.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028008 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000031600 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000486880 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000102736 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000029040 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 011144016 _____ () C:\Program Files (x86)\Dropbox\Client\nucleus_python.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000029024 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:06 - 000036312 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2018-11-07 06:43 - 2018-11-06 14:08 - 000036712 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000272208 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.advapi32.compiled._winffi_advapi32.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000433992 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2018-11-07 06:44 - 2018-11-06 14:09 - 000035680 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025920 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2018-11-07 06:43 - 2018-11-06 14:08 - 001592128 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000095592 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shcore.compiled._winffi_shcore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.gdi32.compiled._winffi_gdi32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shell32.compiled._winffi_shell32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000029544 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000530768 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000348496 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000037200 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngine.cp35-win32.pyd
2018-06-28 03:31 - 2018-06-28 03:31 - 001514496 _____ () C:\Program Files (x86)\Anvsoft\Syncios\DuiLib.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 000074752 _____ () C:\Program Files (x86)\Anvsoft\Syncios\generalFunc_pdt.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 001309184 _____ () C:\Program Files (x86)\Anvsoft\Syncios\androidSyncCore_pdm.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 000178688 _____ () C:\Program Files (x86)\Anvsoft\Syncios\driverMgr4Transfer_pdm.dll
2018-05-30 09:15 - 2018-05-30 09:15 - 000571392 _____ () C:\Program Files (x86)\Anvsoft\Syncios\sqlite3.dll
2018-05-30 09:12 - 2018-05-30 09:12 - 000592896 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libsscan.dll
2018-05-30 09:27 - 2018-05-30 09:27 - 013524469 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libheic.dll
2018-05-30 09:26 - 2018-05-30 09:26 - 001970688 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libplist.dll
2018-05-30 09:26 - 2018-05-30 09:26 - 001042432 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libandroidrecovery.dll
2018-05-30 09:15 - 2018-05-30 09:15 - 001278080 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libandroidnotifier.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 004554857 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libexiv2.dll
2018-05-30 09:12 - 2018-05-30 09:12 - 000121524 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libgcc_s_dw2-1.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 001544523 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libstdc++-6.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 001487360 _____ () C:\Program Files (x86)\Anvsoft\Syncios\exiv2.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 000066048 _____ () C:\Program Files (x86)\Anvsoft\Syncios\zlib1.dll
2018-05-30 09:16 - 2018-05-30 09:16 - 000104448 _____ () C:\Program Files (x86)\Anvsoft\Syncios\expat.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\localhost -> localhost

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-10 12:04 - 2017-06-03 07:57 - 000000033 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img13.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "Gaijin.Net Agent"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe
FirewallRules: [{E5704048-D74D-4C36-83C0-AFC2AE45C0D9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{168C4730-36FD-43E6-B9B7-83005201CA63}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [UDP Query User{93722077-3426-4264-938D-2DF7BD4BECA5}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{C280E624-8E98-4BEB-A6EB-E45683BAF9FD}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{81E1E14B-FDD7-431E-8936-021B00ECA713}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{046BB00A-96AE-49DF-8363-EEB2C8CBA86C}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{74041CFE-45F9-4A6B-8639-C37CE09197C2}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{A59A401D-D68F-42A7-937F-07FC1A9A59FD}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{2F00BEED-005C-4E96-A284-05197064E1A2}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{E8727B48-BF11-44DC-B40B-3A487ABCBE97}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{284402BC-1B04-49F8-9688-2A44ED1FB13F}D:\games\diablo iii\diablo iii.exe] => (Allow) D:\games\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{B1DACAEC-BF39-4AED-9D8B-992AE4B60AFF}D:\games\diablo iii\diablo iii.exe] => (Allow) D:\games\diablo iii\diablo iii.exe
FirewallRules: [{EEC9CB70-CECD-4E44-BFB1-1AB012AFE94F}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{56B7E9AE-46BD-4F70-BA52-C362E10C768F}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{619D4411-9A7F-4EFB-9452-E5E6B9BA8241}] => (Allow) D:\Steam\steamapps\common\Age2HD\Launcher.exe
FirewallRules: [{CBC8BC91-03DD-4A14-B879-6995D1C0BEA0}] => (Allow) D:\Steam\steamapps\common\Age2HD\Launcher.exe
FirewallRules: [TCP Query User{BDEA720E-7297-4B09-A793-67A68C270AA0}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [UDP Query User{CCC6B2D6-B100-474E-8B3A-38260721B218}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [TCP Query User{0F1755AE-AF99-43C3-B752-9F3492D0B539}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [UDP Query User{60370882-0154-433A-93FC-089CC31B18E5}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{956B4F4A-3CAE-481D-976D-38E8E89831C4}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{1FFEF323-FF74-4763-B503-227743D24F1F}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{DB64EC06-61BC-4AFC-B2CE-F40E67A6C339}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{5A6CC866-DF46-48A2-8CFA-B49857B316C9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{92776334-DD7D-4B94-AB22-521C141620C9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{EFF99DAB-AA22-43E1-95CB-FA0EAD5D8F12}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{BB8DCEA9-6A6B-429A-A747-FB04606CD4DE}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{4CD510CA-269F-4D55-B3B9-7ECF003734AD}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{2C65AE6F-AF07-4D56-A63E-385B2ABFD3F9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{23A05941-721F-4615-9B03-445ECB4ECEB6}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{7C9212D1-EC53-4A58-A2E5-2B86D76924C6}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{5D178285-D43A-4A4E-A7F7-6F3EC45C3949}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{DF2EE1A2-2D3B-4670-8CAD-BC638B2F5B24}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{FADE5BD0-73B1-4BAE-9E55-10EE70E81701}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{83E6B7A5-C6A4-45C8-9C9C-B780DE639926}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{8ACF4C21-4B5B-4CF0-B790-F84FA0B3DC8A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{94FFE1BA-67FA-4FED-94A4-DAF28FAF4691}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [UDP Query User{893CCC8F-6077-428D-8939-801974F724C1}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{3667219E-133F-4A9A-BF31-C9A426F30315}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{E2884B7B-E994-4717-BD4F-33AC914105D5}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [TCP Query User{142521BD-BC97-4665-BE8B-ACC2FDCF0EE8}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{B3C6D690-5E97-43F7-835B-AC82E52DB7DF}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{3635E671-1C76-4699-ADB9-A67586E07C19}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [UDP Query User{74E066B2-F1EF-4A18-849C-985FFD2B90AD}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [TCP Query User{156F1724-4149-4D60-9592-65B395C6783D}D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe] => (Allow) D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe
FirewallRules: [UDP Query User{4B58B240-EB49-46D0-9FE3-FD41B8DBB259}D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe] => (Allow) D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe
FirewallRules: [{BB2A3528-4C73-4E84-916E-5EE8FF60DEB7}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{292E230A-0075-493B-8662-20A6F0E558C6}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{88E39619-3461-4438-AA59-53D5CDEB8E2B}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{26AAD9CF-D94C-4791-9492-57A35C862500}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{CA7FAD52-A270-453C-994F-AE1E7A8602D9}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{18A0C796-4CFD-4F40-8A95-DDFE772DEB88}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{74A8C031-2945-4D7C-AC37-C8A3527F8B8A}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{6F6D7066-989D-46B5-846C-1FFFCEBABE0B}] => (Block) D:\Games\Pillars of Eternity 2 Deadfire Beast of Winter\PillarsOfEternityII.exe
FirewallRules: [{57DD9B1E-FB09-488B-B080-6FA6F8BE12C0}] => (Block) D:\Games\Pillars of Eternity 2 Deadfire Beast of Winter\PillarsOfEternityII.exe
FirewallRules: [{0D24A2B0-6691-4DEB-AECC-BB8BA5753292}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
FirewallRules: [{F02198EA-317E-4138-B0A8-2DC476C628BF}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
FirewallRules: [TCP Query User{81960E18-ADDE-4D93-A845-4018B92BD18D}D:\steam\steamapps\common\for honor\forhonor.exe] => (Allow) D:\steam\steamapps\common\for honor\forhonor.exe
FirewallRules: [UDP Query User{7BF1C704-A7C2-4642-A22B-C03066FF8C20}D:\steam\steamapps\common\for honor\forhonor.exe] => (Allow) D:\steam\steamapps\common\for honor\forhonor.exe
FirewallRules: [TCP Query User{DAA91239-943E-486A-90C5-0FB91D319DBB}C:\program files (x86)\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files (x86)\wizards of the coast\mtga\mtga.exe
FirewallRules: [UDP Query User{53371FEB-D07A-4091-B4D0-A32C09C183BA}C:\program files (x86)\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files (x86)\wizards of the coast\mtga\mtga.exe
FirewallRules: [{35D30BFA-4864-4A8F-AFB4-8B42AFF94B62}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe
FirewallRules: [{6B24BE88-3231-4968-BA78-20909D0CF39D}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe
FirewallRules: [{6EA189C8-3A4D-43BB-9D41-695195EADFBF}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DBDownloader.exe
FirewallRules: [{D2D67853-AC9A-449E-B972-360652398C03}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DBDownloader.exe
FirewallRules: [{60484728-3A26-4549-89F8-96991B22E8A0}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\AutoUpdate.exe
FirewallRules: [{47468509-034B-452A-9732-62B48088E5C6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\AutoUpdate.exe
FirewallRules: [{AE3135C1-282A-49B9-BBD9-127F0EE76B24}] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{89ECC069-1869-422A-8C68-95ABE5C18A7A}] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{64F8B66D-A1D1-48C7-9425-322AB5FDBB5C}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
FirewallRules: [{3B6A675D-2925-4A4C-87C2-4800FDE77F6D}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe

==================== Restore Points =========================

06-11-2018 22:40:11 Instalační služba modulů systému Windows
07-11-2018 23:44:36 Instalační služba modulů systému Windows
09-11-2018 19:38:25 Instalační služba modulů systému Windows
10-11-2018 22:11:57 Instalační služba modulů systému Windows
12-11-2018 18:02:47 Instalační služba modulů systému Windows
13-11-2018 19:26:40 Instalační služba modulů systému Windows
14-11-2018 19:46:39 Instalační služba modulů systému Windows
14-11-2018 21:46:42 Instalační služba modulů systému Windows
15-11-2018 22:32:23 Installed MTG Arena
16-11-2018 00:09:42 Instalační služba modulů systému Windows
17-11-2018 01:51:17 Instalační služba modulů systému Windows
17-11-2018 07:37:38 Installed MTG Arena
17-11-2018 16:51:53 Removed Microsoft Office Professional Plus 2013
17-11-2018 16:52:11 PROPLUSR

==================== Faulty Device Manager Devices =============

Name: Časovač událostí s vysokou přesností
Description: Časovač událostí s vysokou přesností
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardní systémová zařízení)
Service: 
Problem: : This device is disabled because the firmware of the device did not give it the required resources. (Code 29)
Resolution: Enable the device in the BIOS of the device.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/17/2018 07:00:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: iDownloaderConsole.exe, verze: 1.0.0.0, časové razítko: 0x5b9e3fc2
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17134.319, časové razítko: 0x5ea0e53d
Kód výjimky: 0xe0434352
Posun chyby: 0x001117d2
ID chybujícího procesu: 0x978
Čas spuštění chybující aplikace: 0x01d47e9f627a7dec
Cesta k chybující aplikaci: C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\Win32\iDownloaderConsole.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: 830cb434-224e-4e6d-9961-0f1fead28510
Úplný název chybujícího balíčku: 21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc
ID aplikace související s chybujícím balíčkem: App

Error: (11/17/2018 07:00:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: iDownloaderConsole.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.InvalidOperationException
   na DownloaderConsole.AppServiceManager+<AppServiceThreadProc>d__11.MoveNext()
   na System.Runtime.CompilerServices.AsyncMethodBuilderCore+<>c.<ThrowAsync>b__6_1(System.Object)
   na System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   na System.Threading.ThreadPoolWorkQueue.Dispatch()
   na System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()

Error: (11/17/2018 06:42:19 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač.
.


Operace:
   Spouštění asynchronní operace

Kontext:
   Aktuální stav: DoSnapshotSet

Error: (11/17/2018 04:51:19 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Chyba služby Stínová kopie svazků: Při volání rutiny QueryFullProcessImageNameW došlo k neočekávané chybě. hr= 0x80070006, Neplatný popisovač.
.


Operace:
   Spouštění asynchronní operace

Kontext:
   Aktuální stav: DoSnapshotSet

Error: (11/17/2018 04:50:21 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Chyba služby Stínová kopie svazků: Při dotazu na rozhraní IVssWriterCallback došlo k neočekávané chybě. hr = 0x80070005, Přístup byl odepřen.
.
To je často způsobeno nesprávným nastavením zabezpečení v modulu pro zápis nebo žadateli.


Operace:
   Shromažďování dat modulu pro zápis

Kontext:
   ID třídy modulu pro zápis: {e8132975-6f93-4464-a53e-1050253ae220}
   Název modulu pro zápis: System Writer
   ID instance modulu pro zápis: {0bf0df34-99a7-4b99-95b4-4f906245d34e}

Error: (11/17/2018 04:14:28 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/17/2018 03:15:13 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/17/2018 03:14:36 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263


System errors:
=============
Error: (11/17/2018 08:16:12 PM) (Source: DCOM) (EventID: 10016) (User: X-COM)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 a APPID 
{8BC3F05E-D86B-11D0-A075-00C04FB68820}
 uživateli X-COM\Alonzop (SID: S-1-5-21-2823601367-1896843323-1796517690-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Microsoft.Windows.ContentDeliveryManager_10.0.17134.1_neutral_neutral_cw5n1h2txyewy – SID (S-1-15-2-350187224-1905355452-1037786396-3028148496-2624191407-3283318427-1255436723). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/17/2018 07:05:48 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba AMD User Experience Program Launcher byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/17/2018 07:03:56 PM) (Source: DCOM) (EventID: 10016) (User: X-COM)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 a APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 uživateli X-COM\Alonzop (SID: S-1-5-21-2823601367-1896843323-1796517690-1001) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/17/2018 06:56:43 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID 
Windows.SecurityCenter.WscBrokerManager
 a APPID 
Není k dispozici
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/17/2018 06:53:12 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Disc Soft Lite Bus Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/17/2018 06:53:12 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba NIHardwareService byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/17/2018 06:53:12 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba SAMSUNG Mobile Connectivity Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/17/2018 06:53:11 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba HuaweiHiSuiteService64.exe byla neočekávaně ukončena. Tento stav nastal již 1krát.


Windows Defender:
===================================
Date: 2018-11-12 19:22:03.201
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {98D630BD-28B6-4A73-B241-C8318C025B52}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-03 22:03:55.662
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {912E2FD6-2710-49F4-B68E-A74C6DD132E6}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-02 17:27:53.497
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {0BC3853A-3E11-4ABF-AEF4-F307F19A8725}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-30 20:04:24.361
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {EE084A95-D0F2-4AD5-A439-D60E7AF96ABD}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-27 03:50:02.505
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {FD88DD2D-0808-41A2-9AF7-6BB22311F5A3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-09 22:21:48.018
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1512.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-07 21:53:34.535
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1373.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-07 17:30:02.978
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1309.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-06 22:48:52.472
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1309.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-01 16:57:16.901
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.902.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

CodeIntegrity:
===================================

Date: 2018-10-26 23:05:58.943
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:05:57.162
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:50.601
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:49.557
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:30.519
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:29.469
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:12.384
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:11.336
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info =========================== 

Processor: AMD Athlon(tm) X4 740 Quad Core Processor 
Percentage of memory in use: 27%
Total physical RAM: 8145.84 MB
Available physical RAM: 5943.49 MB
Total Virtual: 9425.84 MB
Available Virtual: 6144.97 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:488.59 GB) (Free:37.38 GB) NTFS
Drive d: (Nový svazek) (Fixed) (Total:442.38 GB) (Free:39.16 GB) NTFS

\\?\Volume{99c499c4-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{350f029c-0000-0000-0000-102c7a000000}\ () (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 350F029C)
Partition 1: (Not Active) - (Size=488.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=450 MB) - (Type=27)
Partition 3: (Not Active) - (Size=442.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 74.5 GB) (Disk ID: 99C499C4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#8 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {A73AB5E5-6651-46FC-AED0-B22FA898490B} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {E2D0F99B-387E-402C-9113-001EC05D5F7F} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-10-06] (Oracle Corporation)
C:\Windows\KMS-R@1n.exe
FirewallRules: [{3667219E-133F-4A9A-BF31-C9A426F30315}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{E2884B7B-E994-4717-BD4F-33AC914105D5}] => (Allow) C:\Windows\KMS-R@1n.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {1669ae0c-807e-11e8-9d95-806e6f6e6963} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {46ad1614-e132-11e8-9e13-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {46ad162f-e132-11e8-9e13-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {54df9d64-b5fe-11e8-9dc4-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {61c59ad5-d962-11e8-9e02-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {61c59af6-d962-11e8-9e02-d43d7e9f40c1} - "H:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {65e6848a-c7fd-11e8-9de2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {65e684ca-c7fd-11e8-9de2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6b96590e-b026-11e8-9dc1-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6b965935-b026-11e8-9dc1-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6f7a13db-8f52-11e8-9da0-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6f7a13de-8f52-11e8-9da0-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {73d980a7-6ee3-11e8-9d88-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {73d980bf-6ee3-11e8-9d88-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {807c54b4-7fd9-11e8-9d94-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {8881f623-6e7b-11e8-9d86-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {9b976dd4-9dae-11e8-9dad-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {9b976e0c-9dae-11e8-9dad-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {b2c89ff0-6141-11e8-9d7d-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11a8-e773-11e8-9e21-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11c2-e773-11e8-9e21-d43d7e9f40c1} - "G:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c9cbc6a1-c0f0-11e8-9dd2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c9cbc6b0-c0f0-11e8-9dd2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {ea175277-6068-11e8-9d7c-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {ef4b1206-b878-11e8-9dc5-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
C:\WINDOWS\SysWOW64\SETE560.tmp
C:\WINDOWS\msdownld.tmp
C:\WINDOWS\system32\SETA1E6.tmp
C:\WINDOWS\system32\SETA255.tmp
C:\WINDOWS\system32\SET865A.tmp
C:\WINDOWS\system32\SET381.tmp
C:\WINDOWS\SysWOW64\SETB31.tmp
C:\WINDOWS\SysWOW64\SET882E.tmp
C:\Users\Allonzo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Alonzop
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 27 črc 2006 10:54
Bydliště: Czech Rep. - Brno
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#9 Příspěvek od Alonzop »

Kód: Vybrat vše

Fix result of Farbar Recovery Scan Tool (x64) Version: 15.11.2018
Ran by Alonzop (17-11-2018 23:00:39) Run:1
Running from C:\Users\Allonzo\Desktop
Loaded Profiles: Alonzop (Available Profiles: Alonzop)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
Task: {A73AB5E5-6651-46FC-AED0-B22FA898490B} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {E2D0F99B-387E-402C-9113-001EC05D5F7F} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2018-10-06] (Oracle Corporation)
C:\Windows\KMS-R@1n.exe
FirewallRules: [{3667219E-133F-4A9A-BF31-C9A426F30315}] => (Allow) C:\Windows\KMS-R@1n.exe
FirewallRules: [{E2884B7B-E994-4717-BD4F-33AC914105D5}] => (Allow) C:\Windows\KMS-R@1n.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-10-06] (Oracle Corporation)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {1669ae0c-807e-11e8-9d95-806e6f6e6963} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {46ad1614-e132-11e8-9e13-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {46ad162f-e132-11e8-9e13-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {54df9d64-b5fe-11e8-9dc4-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {61c59ad5-d962-11e8-9e02-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {61c59af6-d962-11e8-9e02-d43d7e9f40c1} - "H:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {65e6848a-c7fd-11e8-9de2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {65e684ca-c7fd-11e8-9de2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6b96590e-b026-11e8-9dc1-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6b965935-b026-11e8-9dc1-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6f7a13db-8f52-11e8-9da0-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {6f7a13de-8f52-11e8-9da0-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {73d980a7-6ee3-11e8-9d88-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {73d980bf-6ee3-11e8-9d88-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {807c54b4-7fd9-11e8-9d94-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {8881f623-6e7b-11e8-9d86-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {9b976dd4-9dae-11e8-9dad-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {9b976e0c-9dae-11e8-9dad-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {b2c89ff0-6141-11e8-9d7d-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11a8-e773-11e8-9e21-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11c2-e773-11e8-9e21-d43d7e9f40c1} - "G:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c9cbc6a1-c0f0-11e8-9dd2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c9cbc6b0-c0f0-11e8-9dd2-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {ea175277-6068-11e8-9d7c-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {ef4b1206-b878-11e8-9dc5-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe"
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
C:\WINDOWS\SysWOW64\SETE560.tmp
C:\WINDOWS\msdownld.tmp
C:\WINDOWS\system32\SETA1E6.tmp
C:\WINDOWS\system32\SETA255.tmp
C:\WINDOWS\system32\SET865A.tmp
C:\WINDOWS\system32\SET381.tmp
C:\WINDOWS\SysWOW64\SETB31.tmp
C:\WINDOWS\SysWOW64\SET882E.tmp
C:\Users\Allonzo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A73AB5E5-6651-46FC-AED0-B22FA898490B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A73AB5E5-6651-46FC-AED0-B22FA898490B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{E2D0F99B-387E-402C-9113-001EC05D5F7F} => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E2D0F99B-387E-402C-9113-001EC05D5F7F} => removed successfully
C:\WINDOWS\System32\Tasks\Java Platform SE Auto Updater => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Java Platform SE Auto Updater => removed successfully
C:\Windows\KMS-R@1n.exe => moved successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{3667219E-133F-4A9A-BF31-C9A426F30315}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{E2884B7B-E994-4717-BD4F-33AC914105D5}" => removed successfully
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1669ae0c-807e-11e8-9d95-806e6f6e6963} => removed successfully
HKLM\Software\Classes\CLSID\{1669ae0c-807e-11e8-9d95-806e6f6e6963} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{46ad1614-e132-11e8-9e13-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{46ad1614-e132-11e8-9e13-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{46ad162f-e132-11e8-9e13-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{46ad162f-e132-11e8-9e13-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54df9d64-b5fe-11e8-9dc4-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{54df9d64-b5fe-11e8-9dc4-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{61c59ad5-d962-11e8-9e02-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{61c59ad5-d962-11e8-9e02-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{61c59af6-d962-11e8-9e02-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{61c59af6-d962-11e8-9e02-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{65e6848a-c7fd-11e8-9de2-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{65e6848a-c7fd-11e8-9de2-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{65e684ca-c7fd-11e8-9de2-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{65e684ca-c7fd-11e8-9de2-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b96590e-b026-11e8-9dc1-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{6b96590e-b026-11e8-9dc1-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6b965935-b026-11e8-9dc1-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{6b965935-b026-11e8-9dc1-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6f7a13db-8f52-11e8-9da0-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{6f7a13db-8f52-11e8-9da0-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6f7a13de-8f52-11e8-9da0-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{6f7a13de-8f52-11e8-9da0-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{73d980a7-6ee3-11e8-9d88-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{73d980a7-6ee3-11e8-9d88-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{73d980bf-6ee3-11e8-9d88-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{73d980bf-6ee3-11e8-9d88-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{807c54b4-7fd9-11e8-9d94-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{807c54b4-7fd9-11e8-9d94-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8881f623-6e7b-11e8-9d86-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{8881f623-6e7b-11e8-9d86-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b976dd4-9dae-11e8-9dad-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{9b976dd4-9dae-11e8-9dad-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9b976e0c-9dae-11e8-9dad-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{9b976e0c-9dae-11e8-9dad-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b2c89ff0-6141-11e8-9d7d-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{b2c89ff0-6141-11e8-9d7d-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c27f11a8-e773-11e8-9e21-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{c27f11a8-e773-11e8-9e21-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c27f11c2-e773-11e8-9e21-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{c27f11c2-e773-11e8-9e21-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c9cbc6a1-c0f0-11e8-9dd2-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{c9cbc6a1-c0f0-11e8-9dd2-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c9cbc6b0-c0f0-11e8-9dd2-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{c9cbc6b0-c0f0-11e8-9dd2-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea175277-6068-11e8-9d7c-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{ea175277-6068-11e8-9d7c-d43d7e9f40c1} => not found
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ef4b1206-b878-11e8-9dc5-d43d7e9f40c1} => removed successfully
HKLM\Software\Classes\CLSID\{ef4b1206-b878-11e8-9dc5-d43d7e9f40c1} => not found
HKLM\Software\\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Page_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Default_Search_URL => value restored successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Local Page => value restored successfully
C:\WINDOWS\SysWOW64\SETE560.tmp => moved successfully
C:\WINDOWS\msdownld.tmp => moved successfully
C:\WINDOWS\system32\SETA1E6.tmp => moved successfully
C:\WINDOWS\system32\SETA255.tmp => moved successfully
C:\WINDOWS\system32\SET865A.tmp => moved successfully
C:\WINDOWS\system32\SET381.tmp => moved successfully
C:\WINDOWS\SysWOW64\SETB31.tmp => moved successfully
C:\WINDOWS\SysWOW64\SET882E.tmp => moved successfully
C:\Users\Allonzo\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 47743087 B
Java, Flash, Steam htmlcache => 83380563 B
Windows/system/drivers => 199486 B
Edge => 37854 B
Chrome => 0 B
Firefox => 331498019 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 6656 B
LocalService => 0 B
NetworkService => 11896 B
NetworkService => 0 B
Allonzo => 15552157 B

RecycleBin => 236325013 B
EmptyTemp: => 690.4 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 23:03:38 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#10 Příspěvek od Rudy »

Smazáno, log by již měl být OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Alonzop
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 27 črc 2006 10:54
Bydliště: Czech Rep. - Brno
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#11 Příspěvek od Alonzop »

Bohužel i po restartech " AUEPmaster" přetrvává jeho aktivita na síti.
skusil sem jeste ADW

Kód: Vybrat vše

# -------------------------------
# Malwarebytes AdwCleaner 7.2.4.0
# -------------------------------
# Build:    09-25-2018
# Database: 2018-11-14.2 (Cloud)
# Support:  https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start:    11-18-2018
# Duration: 00:00:01
# OS:       Windows 10 Pro
# Cleaned:  3
# Failed:   0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted       C:\ProgramData\ytd video downloader

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted       HKCU\Software\Conduit
Deleted       HKCU\Software\{DAF8B7E5-449D-4180-8281-10E536E597F2}

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [3909 octets] - [10/11/2018 18:08:51]
AdwCleaner[C00].txt - [3466 octets] - [10/11/2018 18:10:36]
AdwCleaner[S01].txt - [1820 octets] - [11/11/2018 02:47:31]
AdwCleaner[C01].txt - [1835 octets] - [11/11/2018 03:04:59]
AdwCleaner[S02].txt - [2065 octets] - [17/11/2018 18:52:50]
AdwCleaner[C02].txt - [2119 octets] - [17/11/2018 18:53:15]
AdwCleaner[S03].txt - [1758 octets] - [18/11/2018 15:52:36]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C03].txt ##########

Alonzop
Návštěvník
Návštěvník
Příspěvky: 85
Registrován: 27 črc 2006 10:54
Bydliště: Czech Rep. - Brno
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#12 Příspěvek od Alonzop »

A hned RTS na cistej restart

Kód: Vybrat vše

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15.11.2018
Ran by Alonzop (administrator) on X-COM (18-11-2018 16:02:01)
Running from C:\Users\Allonzo\Desktop
Loaded Profiles: Alonzop (Available Profiles: Alonzop)
Platform: Windows 10 Pro Version 1803 17134.345 (X64) Language: Čeština (Česko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atiesrxx.exe
(AMD) C:\Windows\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atieclxx.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
(Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(DEVGURU Co., LTD.) C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\MsMpEng.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.1810.5-0\NisSrv.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Huawei) C:\Program Files (x86)\HiSuite\HiSuite.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
() C:\Program Files (x86)\AUROZA\Monitor.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe
() C:\Users\Allonzo\AppData\Local\HiSuite\userdata\hwtools\hdbtransport.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
() C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
() C:\Program Files (x86)\Anvsoft\Syncios\androidnotifier.exe
() C:\Program Files (x86)\Anvsoft\Syncios\adb.exe
(Piriform Ltd) C:\Program Files\CCleaner\ccleaner64.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amddvr.exe
(AMD) C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe
(AMD) C:\Program Files\AMD\Performance Profile Client\AUEPMaster.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\amdow.exe
(AMD) C:\Program Files\AMD\Performance Profile Client\AUEPUF.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9277280 2018-09-15] (Realtek Semiconductor)
HKLM-x32\...\Run: [AUROZA EM02C Driver] => C:\Program Files (x86)\AUROZA\Monitor.exe [761856 2014-12-08] ()
HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [318112 2017-11-15] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3785536 2018-11-06] (Dropbox, Inc.)
HKLM-x32\...\Run: [Syncios device service] => C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe [2443384 2018-06-13] ()
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [731240 2018-10-19] (Disc Soft Ltd)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [19467544 2018-11-06] (Piriform Ltd)
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11a8-e773-11e8-9e21-d43d7e9f40c1} - "F:\HiSuiteDownLoader.exe" 
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\MountPoints2: {c27f11c2-e773-11e8-9e21-d43d7e9f40c1} - "G:\HiSuiteDownLoader.exe" 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-04-29]
ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\TP\TWCU.exe ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{065cbf10-2caa-4b98-845d-58f844cd7367}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{15ba6f79-c3fe-4839-8ceb-9c85902f80e6}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{235b3b59-013c-4325-a9c1-dce08de51507}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{326988a7-fdcf-4ca8-aaed-31489abff3b3}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{4a471a66-ada7-469f-b245-94f49c4983f2}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{9a8ca0e5-5e36-4865-8644-400ce9f0a8bd}: [DhcpNameServer] 10.0.0.138
Tcpip\..\Interfaces\{af220eb6-d63e-4c3d-994d-6b90b4308bf9}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{e654c3cc-dce8-4a0f-8348-3f7fa65109bd}: [DhcpNameServer] 10.0.0.138

Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_172\bin\ssv.dll [2018-06-22] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_172\bin\jp2ssv.dll [2018-06-22] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: 840j6bnm.default
FF ProfilePath: C:\Users\Allonzo\AppData\Roaming\TomTom\HOME\Profiles\bovmmkmh.default [2016-10-26]
FF ProfilePath: C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default [2018-11-18]
FF Homepage: Mozilla\Firefox\Profiles\840j6bnm.default -> seznam.cz
FF Extension: (Messenger for WhatsApp™) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\rt42fsdty645jIidD@jetpack.xpi [2017-11-26]
FF Extension: (Download Manager (S3)) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\s3download@statusbar.xpi [2018-11-17]
FF Extension: (uBlock Origin) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\uBlock0@raymondhill.net.xpi [2018-02-02]
FF Extension: (Adblock Plus) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-12]
FF Extension: (iDM Integration Extension) - C:\Users\Allonzo\AppData\Roaming\Mozilla\Firefox\Profiles\840j6bnm.default\Extensions\{ed9a84e6-a04e-4d97-ad7e-b7414f2912eb}.xpi [2018-09-08]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_31_0_0_148.dll [2018-11-14] ()
FF Plugin: @java.com/DTPlugin,version=11.172.2 -> C:\Program Files\Java\jre1.8.0_172\bin\dtplugin\npDeployJava1.dll [2018-06-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.172.2 -> C:\Program Files\Java\jre1.8.0_172\bin\plugin2\npjp2.dll [2018-06-22] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_148.dll [2018-11-14] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD External Events Utility; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atiesrxx.exe [521944 2018-11-08] (AMD)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-09-11] (Advanced Micro Devices, Inc.) [File not signed]
R2 AUEPLauncher; C:\Program Files\AMD\Performance Profile Client\AUEPLauncher.exe [43008 2018-11-07] (AMD) [File not signed]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-05-27] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-05-27] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51024 2018-11-06] (Dropbox, Inc.)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3729512 2018-10-19] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [774272 2018-08-27] (EasyAntiCheat Ltd)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [190784 2018-08-23] () [File not signed]
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-07-15] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
S3 sshd; C:\WINDOWS\System32\OpenSSH\sshd.exe [970240 2018-05-20] ()
S3 SshdBroker; C:\WINDOWS\System32\SshdBroker.dll [286720 2018-09-08] (Microsoft Corporation)
R2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [754784 2016-07-22] (DEVGURU Co., LTD.)
R3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\NisSrv.exe [3917016 2018-10-23] (Microsoft Corporation)
R2 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MsMpEng.exe [114208 2018-10-23] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [21160 2012-09-23] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atikmdag.sys [47840744 2018-11-08] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0335517.inf_amd64_41130323c4f5b304\B335523\atikmpag.sys [604632 2018-11-08] (Advanced Micro Devices, Inc.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [42240 2013-07-31] (Advanced Micro Devices)
R2 AODDriver4.3.0; C:\Program Files\AMD\Performance Profile Client\amd64\AODDriver2.sys [60104 2015-02-19] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [107496 2018-05-28] (Advanced Micro Devices)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131984 2018-05-27] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-01-31] (Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-08-02] (Disc Soft Ltd)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2018-04-20] (Huawei Technologies Co., Ltd.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-31] (REALiX(tm))
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [116864 2018-08-23] (Huawei Technologies Co., Ltd.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1118648 2018-10-25] (Realtek )
S3 RtlWlanu; C:\WINDOWS\System32\drivers\rtwlanu.sys [8228688 2018-09-27] (Realtek Semiconductor Corporation )
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [166288 2018-05-27] (Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [22016 2018-04-12] (Microsoft Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\wd\WdBoot.sys [46184 2018-10-23] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\wd\WdFilter.sys [328696 2018-10-23] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [60408 2018-10-23] (Microsoft Corporation)
S3 MSICDSetup; \??\E:\CDriver.sys [X]
S3 SWDUMon; \SystemRoot\system32\DRIVERS\SWDUMon.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-18 16:01 - 2018-11-18 16:01 - 000001884 _____ C:\Users\Allonzo\Desktop\Nový textový dokument.txt
2018-11-18 15:50 - 2018-11-18 15:50 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2018-11-17 22:55 - 2018-11-17 22:55 - 000001104 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++.lnk
2018-11-17 22:55 - 2018-11-17 22:55 - 000000000 ____D C:\Users\Allonzo\AppData\Local\Notepad++
2018-11-17 21:12 - 2018-11-17 21:13 - 000087813 _____ C:\Users\Allonzo\Desktop\Addition.txt
2018-11-17 18:52 - 2018-11-17 18:52 - 007592144 _____ (Malwarebytes) C:\Users\Allonzo\Downloads\adwcleaner_7.2.4.0(1).exe
2018-11-17 17:05 - 2018-11-18 16:03 - 000013230 _____ C:\Users\Allonzo\Desktop\FRST.txt
2018-11-17 17:04 - 2018-11-18 16:02 - 000000000 ____D C:\FRST
2018-11-17 16:48 - 2018-11-17 16:48 - 002416128 _____ (Farbar) C:\Users\Allonzo\Desktop\FRST64.exe
2018-11-17 15:19 - 2018-11-17 16:19 - 000000000 ____D C:\Users\Allonzo\Desktop\bordel
2018-11-17 07:43 - 2018-11-17 07:43 - 000002215 _____ C:\Users\Public\Desktop\MTG Arena.lnk
2018-11-17 07:41 - 2018-11-17 07:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MTG Arena
2018-11-16 21:42 - 2018-11-16 21:42 - 000003160 _____ C:\WINDOWS\System32\Tasks\StartCN
2018-11-16 21:42 - 2018-11-16 21:42 - 000003074 _____ C:\WINDOWS\System32\Tasks\StartDVR
2018-11-16 21:42 - 2018-11-16 21:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2018-11-10 18:07 - 2018-11-10 18:07 - 007592144 _____ (Malwarebytes) C:\Users\Allonzo\Downloads\adwcleaner_7.2.4.0.exe
2018-11-09 20:47 - 2018-11-16 21:41 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\AMD
2018-11-09 20:34 - 2018-11-09 20:35 - 026450000 _____ (AMD Inc.) C:\Users\Allonzo\Downloads\radeon-software-adrenalin-18.11.1-minimalsetup-181108_64bit.exe
2018-11-08 17:04 - 2018-11-08 17:04 - 001211976 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000189816 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000165520 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2018-11-08 17:04 - 2018-11-08 17:04 - 000029136 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2018-11-07 18:41 - 2018-11-07 18:41 - 000166728 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdihk64.dll
2018-11-07 18:41 - 2018-11-07 18:41 - 000137888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdihk32.dll
2018-11-07 06:44 - 2018-11-07 06:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-11-06 14:06 - 2018-11-06 14:06 - 000051024 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2018-11-06 14:06 - 2018-11-06 14:06 - 000047768 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2018-11-06 14:06 - 2018-11-06 14:06 - 000047768 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2018-11-06 14:06 - 2018-11-06 14:06 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2018-11-02 18:07 - 2018-11-02 18:07 - 000000000 ____D C:\Users\Allonzo\AppData\Local\RadeonSettings
2018-11-02 17:58 - 2018-11-02 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\##ID_STRING16##
2018-10-30 20:58 - 2018-10-30 20:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sudden Strike 4 [GOG.com]
2018-10-28 15:14 - 2018-10-28 15:14 - 000000000 ____D C:\Users\Public\Documents\Catch!
2018-10-28 15:13 - 2018-10-28 15:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2018-10-28 14:59 - 2018-10-28 14:59 - 000791712 _____ (Disc Soft Ltd.) C:\Users\Allonzo\Downloads\DTLiteInstaller.exe
2018-10-26 21:25 - 2018-10-26 21:25 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\DataWorks
2018-10-26 21:23 - 2018-10-26 21:23 - 000002940 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Alonzop)
2018-10-26 21:23 - 2018-10-26 21:23 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 6
2018-10-26 21:23 - 2018-10-26 21:23 - 000000000 ____D C:\Program Files (x86)\IObit
2018-10-26 21:21 - 2018-10-26 21:21 - 000275946 _____ C:\Users\Allonzo\Downloads\Phoenix.bsz
2018-10-26 21:21 - 2018-10-26 21:21 - 000242076 _____ C:\Users\Allonzo\Downloads\Sony_CDX_GT410U_v3.02_by_Rafa_Santos.bsz
2018-10-26 21:21 - 2018-10-26 21:21 - 000125686 _____ C:\Users\Allonzo\Downloads\R.A.D.I.O..bsz
2018-10-26 21:09 - 2018-10-26 21:10 - 026450000 _____ (AMD Inc.) C:\Users\Allonzo\Downloads\radeon-software-adrenalin-18.10.2-minimalsetup-181025_64bit.exe
2018-10-26 21:02 - 2018-11-08 17:04 - 001611264 _____ (AMD) C:\WINDOWS\system32\SETE916.tmp
2018-10-26 21:02 - 2018-11-08 17:04 - 001611264 _____ (AMD) C:\WINDOWS\system32\coinst_18.40.dll
2018-10-26 21:02 - 2018-10-26 21:02 - 001587616 _____ (AMD) C:\WINDOWS\system32\SETCFA1.tmp
2018-10-26 21:02 - 2018-10-26 21:02 - 000124464 _____ C:\WINDOWS\system32\kapp_ci.sbin
2018-10-26 21:02 - 2018-10-26 21:02 - 000119760 _____ C:\WINDOWS\system32\kapp_si.sbin
2018-10-26 21:02 - 2018-10-26 21:02 - 000034450 _____ C:\WINDOWS\system32\AMDKernelEvents.man
2018-10-26 21:02 - 2018-10-25 19:50 - 001587816 _____ (AMD) C:\WINDOWS\system32\SETBD7C.tmp
2018-10-26 21:02 - 2018-10-25 19:50 - 001587816 _____ (AMD) C:\WINDOWS\system32\SETA878.tmp
2018-10-25 19:50 - 2018-11-08 17:04 - 000029136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2018-10-25 19:50 - 2018-10-25 19:50 - 001192032 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\SET10CB.tmp
2018-10-25 19:50 - 2018-10-25 19:50 - 000019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SET9E4.tmp
2018-10-25 19:50 - 2018-10-25 19:50 - 000019392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SET879C.tmp
2018-10-20 05:30 - 2018-10-20 05:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Northgard Ragnarok

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-11-18 16:01 - 2018-06-22 22:36 - 000000000 ____D C:\Users\Allonzo\Desktop\apky
2018-11-18 16:00 - 2018-05-07 17:24 - 001689054 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-11-18 16:00 - 2018-04-12 16:51 - 000715202 _____ C:\WINDOWS\system32\perfh005.dat
2018-11-18 16:00 - 2018-04-12 16:51 - 000144496 _____ C:\WINDOWS\system32\perfc005.dat
2018-11-18 16:00 - 2018-04-12 00:36 - 000000000 ____D C:\WINDOWS\INF
2018-11-18 16:00 - 2016-11-19 02:44 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\Mozilla
2018-11-18 15:58 - 2018-09-14 05:54 - 000003126 _____ C:\WINDOWS\System32\Tasks\MSIAfterburner
2018-11-18 15:56 - 2018-04-12 00:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-11-18 15:55 - 2018-05-07 17:31 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-11-18 15:55 - 2018-04-11 22:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-11-18 15:54 - 2016-09-21 22:56 - 000065536 _____ C:\WINDOWS\system32\spu_storage.bin
2018-11-18 15:50 - 2016-07-31 11:57 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2018-11-18 15:48 - 2018-05-07 17:07 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-11-18 15:29 - 2018-01-27 15:42 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\MPC-HC
2018-11-18 12:49 - 2017-12-20 21:13 - 000007644 _____ C:\Users\Allonzo\AppData\Local\resmon.resmoncfg
2018-11-18 11:14 - 2018-05-07 17:33 - 000000000 ____D C:\Users\Allonzo\AppData\Local\D3DSCache
2018-11-18 03:16 - 2018-04-12 00:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-11-17 22:56 - 2017-03-18 08:33 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\Notepad++
2018-11-17 18:55 - 2018-05-07 17:07 - 000398240 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-11-17 18:45 - 2017-05-05 21:14 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-11-17 16:56 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-11-17 16:56 - 2016-04-27 07:34 - 000000000 ____D C:\WINDOWS\ShellNew
2018-11-17 16:54 - 2018-04-12 00:38 - 000000000 ____D C:\Program Files\Common Files\system
2018-11-17 16:54 - 2015-07-10 12:04 - 000000139 _____ C:\WINDOWS\win.ini
2018-11-17 16:53 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-11-17 16:47 - 2018-05-07 17:39 - 000000000 ____D C:\Users\Allonzo\AppData\Local\PlaceholderTileLogoFolder
2018-11-17 16:47 - 2018-01-20 12:10 - 000000000 ____D C:\Users\Allonzo\AppData\Local\Packages
2018-11-17 16:46 - 2018-04-12 00:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-11-17 15:24 - 2017-05-05 21:05 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-11-17 15:24 - 2017-05-05 21:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-11-17 15:21 - 2018-05-12 20:21 - 000000000 ____D C:\Program Files (x86)\Hard Disk Sentinel
2018-11-17 15:14 - 2016-08-17 04:33 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-11-16 21:42 - 2016-09-21 22:56 - 000000000 ____D C:\Program Files\AMD
2018-11-16 21:41 - 2018-03-31 01:53 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-11-16 21:39 - 2017-05-17 16:00 - 000000000 ____D C:\AMD
2018-11-16 21:36 - 2016-07-31 17:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-11-16 21:36 - 2016-07-31 17:53 - 000000000 ____D C:\Program Files\Java
2018-11-15 22:31 - 2018-05-07 17:31 - 000003362 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2823601367-1896843323-1796517690-1001
2018-11-15 22:31 - 2018-05-07 17:12 - 000002397 _____ C:\Users\Allonzo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-11-15 22:31 - 2016-07-31 08:20 - 000000000 ___RD C:\Users\Allonzo\OneDrive
2018-11-15 18:09 - 2016-08-02 04:59 - 000000000 ____D C:\Users\Allonzo\Desktop\dokumenty
2018-11-15 18:08 - 2018-02-09 15:48 - 000000000 ____D C:\Users\Allonzo\Desktop\Gamesky
2018-11-14 05:42 - 2017-03-10 19:24 - 000000000 ____D C:\Users\Allonzo\Desktop\completed
2018-11-14 01:03 - 2018-05-07 17:31 - 000004638 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-11-14 01:03 - 2018-05-07 17:31 - 000004470 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2018-11-14 01:02 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-11-14 01:02 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-11-12 19:37 - 2018-03-24 01:32 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\IObit
2018-11-12 19:24 - 2018-03-24 01:38 - 000000000 ____D C:\ProgramData\ProductData
2018-11-10 18:10 - 2016-07-31 11:27 - 000000000 ____D C:\Users\Allonzo\AppData\LocalLow\IObit
2018-11-10 18:08 - 2018-01-14 10:08 - 000000000 ____D C:\AdwCleaner
2018-11-09 22:22 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-11-09 20:35 - 2018-03-31 01:49 - 000000060 _____ C:\ProgramData\SoftwareUpdateTemp.xml
2018-11-08 17:04 - 2018-04-26 23:36 - 003754160 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 003471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2018-11-08 17:04 - 2018-04-26 23:36 - 003437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2018-11-08 17:04 - 2018-04-26 23:36 - 003379720 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 001653048 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\SETE2D3.tmp
2018-11-08 17:04 - 2018-04-26 23:36 - 001653048 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 001211976 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000937704 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000901288 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2018-11-08 17:04 - 2018-04-26 23:36 - 000901288 _____ C:\WINDOWS\system32\atiapfxx.blb
2018-11-08 17:04 - 2018-04-26 23:36 - 000769280 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000766720 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000585512 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000567432 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000554072 _____ C:\WINDOWS\system32\amdmiracast.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000505928 _____ C:\WINDOWS\system32\dgtrayicon.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000495632 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000490400 _____ C:\WINDOWS\system32\GameManager64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000481504 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000479016 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000445448 _____ C:\WINDOWS\system32\atieah64.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000395896 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000394272 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000390160 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000361784 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000352000 _____ C:\WINDOWS\system32\clinfo.exe
2018-11-08 17:04 - 2018-04-26 23:36 - 000261080 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000229568 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000208616 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000195520 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000182656 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000180288 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000173808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000170760 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000164032 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000159928 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000154072 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000149040 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146416 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000146336 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000143336 _____ C:\WINDOWS\system32\atidxx64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000138656 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000135632 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000133800 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122384 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000122128 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000119016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000079752 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000056176 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
2018-11-08 17:04 - 2018-04-26 23:36 - 000053056 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
2018-11-07 22:53 - 2018-05-07 17:31 - 000004212 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-11-07 21:42 - 2018-05-07 17:12 - 000000000 ____D C:\Users\Allonzo
2018-11-07 06:45 - 2018-05-27 05:46 - 000000000 ___RD C:\Users\Allonzo\Dropbox
2018-11-07 06:45 - 2018-05-27 05:37 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-11-06 17:59 - 2017-10-29 19:20 - 000000000 ____D C:\Program Files\CCleaner
2018-11-04 18:04 - 2017-04-23 20:04 - 000000000 ____D C:\Users\Allonzo\AppData\Local\ElevatedDiagnostics
2018-11-04 09:19 - 2018-05-12 19:04 - 000000000 ____D C:\WINDOWS\SysWOW64\directx
2018-11-04 09:18 - 2017-12-09 12:47 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2018-11-04 07:24 - 2016-08-02 18:04 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\DAEMON Tools Lite
2018-11-02 17:45 - 2016-07-31 10:59 - 000000000 ____D C:\Program Files\ATI
2018-10-29 18:42 - 2017-04-22 18:00 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\TP-LINK
2018-10-28 15:25 - 2016-08-06 05:10 - 000000000 ____D C:\Users\Allonzo\AppData\Local\Disc_Soft_Ltd
2018-10-28 15:14 - 2016-12-28 12:38 - 000000000 ____D C:\Program Files\DAEMON Tools Lite
2018-10-28 15:06 - 2016-08-02 18:03 - 000000000 ____D C:\ProgramData\DAEMON Tools Lite
2018-10-27 22:31 - 2017-01-19 15:21 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\BSplayer PRO
2018-10-27 16:22 - 2016-09-21 22:57 - 000000000 ____D C:\Program Files (x86)\AMD
2018-10-27 04:35 - 2016-07-31 10:59 - 000000000 ____D C:\Program Files (x86)\ATI Technologies
2018-10-27 00:12 - 2018-08-05 08:11 - 000000000 ____D C:\Users\Allonzo\Downloads\iDM
2018-10-26 22:10 - 2018-03-31 00:41 - 000000000 ____D C:\Program Files\ATI Technologies
2018-10-26 22:10 - 2016-09-21 22:56 - 000000000 ____D C:\ProgramData\Package Cache
2018-10-26 22:10 - 2016-07-31 10:59 - 000000000 ____D C:\ProgramData\AMD
2018-10-26 21:24 - 2018-03-24 01:32 - 000000000 ____D C:\ProgramData\IObit
2018-10-26 20:40 - 2018-04-12 00:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-10-25 18:52 - 2018-05-08 08:01 - 001118648 _____ (Realtek ) C:\WINDOWS\system32\Drivers\rt640x64.sys
2018-10-23 05:33 - 2018-02-25 02:52 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-10-22 19:24 - 2018-05-26 16:47 - 000000000 ____D C:\Users\Allonzo\AppData\Roaming\Syncios

==================== Files in the root of some directories =======

2017-12-20 21:13 - 2018-11-18 12:49 - 000007644 _____ () C:\Users\Allonzo\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-07 17:07

==================== End of FRST.txt ============================

Kód: Vybrat vše

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15.11.2018
Ran by Alonzop (18-11-2018 16:04:04)
Running from C:\Users\Allonzo\Desktop
Windows 10 Pro Version 1803 17134.345 (X64) (2018-05-07 16:32:57)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2823601367-1896843323-1796517690-500 - Administrator - Disabled)
Alonzop (S-1-5-21-2823601367-1896843323-1796517690-1001 - Administrator - Enabled) => C:\Users\Allonzo
DefaultAccount (S-1-5-21-2823601367-1896843323-1796517690-503 - Limited - Disabled)
Guest (S-1-5-21-2823601367-1896843323-1796517690-501 - Limited - Disabled)
WDAGUtilityAccount (S-1-5-21-2823601367-1896843323-1796517690-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 16.02 (x64) (HKLM\...\7-Zip) (Version: 16.02 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Adobe Flash Player 31 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 31.0.0.148 - Adobe Systems Incorporated)
AMD Software (HKLM\...\AMD Catalyst Install Manager) (Version: 18.11.1 - Advanced Micro Devices, Inc.)
AUROZA EM02C Driver (HKLM-x32\...\{2F9C99E1-A1D2-4ADB-AFA0-3A1ED9471811}) (Version:  - )
AVG PC TuneUp (HKLM-x32\...\{149D912F-03DB-4895-913E-820CB11965C0}) (Version: 16.74.1 - AVG Technologies) Hidden
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Branding64 (HKLM\...\{EE2AFCE4-0238-4DE0-A140-1647021627C1}) (Version: 1.00.0001 - Advanced Micro Devices, Inc.) Hidden
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.70.1080 - AB Team, d.o.o.)
Catalyst Control Center Next Localization BR (HKLM\...\{118C2119-84B6-E32C-63E2-B56DBCF41CE5}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{3E245378-BF77-6946-C6F6-096DBE5EAB82}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{51F85784-6799-5CA3-97B2-2E5904FC3E58}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{55A4D3AB-C8DF-26B2-89A8-7E16E1E40700}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{A16E186C-58C4-3BDC-5CCE-714EFEF5F27F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization BR (HKLM\...\{E7AA1A02-575C-14C6-FBEF-4BE6D46A5B74}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{238F6F6F-2544-86CF-3AB6-2CDADAB58CF0}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{36EDC500-E4C0-371C-9865-08450415C1E9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{62098A5F-E03B-31A3-5F9C-51A7F7D25744}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{84C3F2C5-F7B2-2F08-CDF4-79EF7CC55D74}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{A0407E39-2AA4-60B3-885F-3C5347B6909E}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (HKLM\...\{C3EE628C-7394-FE2C-0C90-C05284EB528D}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{0989D0EA-AFF3-5F9A-3D25-20EE133E409B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{0E8A3B17-D603-B1B6-C205-1685EBDD23E9}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{1757AD9B-0E3C-05F9-FE43-4343BED7DA85}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{2F544F46-5F6E-97BB-3550-A0242A3C5754}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{4C2FB7FD-89FD-BA5C-585A-3811F326AD34}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (HKLM\...\{EC688BD0-240D-AE40-55F3-234E54919AE6}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{1E7D3072-1D28-E33A-99DF-85D9F7ECD06E}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{66B06F29-EE4F-9130-D96A-754826093FEA}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{A8689A0F-5928-7300-B82B-C5E85131B7BA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{D74218A3-C503-57EF-AC9F-2220082E7ADE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{E27224E3-7913-DA1E-5B08-9BEEC8FEE3D1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (HKLM\...\{FC4086D6-E345-5F43-08BB-280FB57DAF49}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{76AAF56B-93D8-161D-809A-EC05F3B913DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{821D0A0E-F246-BE40-0D68-93883C14C410}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{95A52FC1-C728-841D-1BFC-CC793B77B0A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{BA26B70C-3D8C-2D14-4122-211FB3E6F691}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{DA433FCF-90A1-19A5-65A7-FDF82DE4826D}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (HKLM\...\{F8EBE530-A4D5-BF51-F623-3787E6B8A878}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{063CED74-F5F0-870E-DC9C-2D78FDEDA3EE}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{42FBD43F-DE53-6D4D-5134-E3C93B45CBEF}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{5FEACE78-C338-9AED-FF05-7DE7E273C774}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{88BD74C4-23AB-4554-915C-6E1F0C81F6CD}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{949F125B-A6CC-5A5E-EEE7-4AC50305C1FA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (HKLM\...\{A22CDEBA-6DB5-12CD-F6CE-6238C2D78363}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{13BB60AA-88F7-4B1F-2DEC-D81EEDE8B3AA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{20D46801-147B-30AD-7C5A-AC4560A79096}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{A3795528-F572-6314-C4E3-EE9DAF0FBF02}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{A48E2AB0-0866-7783-9657-E1709EB18D02}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{AC85CF50-9A55-0103-ADBF-365C37603AA4}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (HKLM\...\{C0BFC67D-E447-02C8-6046-C078DFE9EC97}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{22C39711-2747-D264-319A-1550BEEAAEC6}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{37AA6227-FF2C-95AC-87C0-45DCC0BB87DA}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{4853A56D-7931-A08B-5BA7-8E2D61043DF9}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{94C72EBE-2908-F0AC-62DA-D61951830F8F}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{B349892D-B015-033C-4CA8-3635E6B655D7}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (HKLM\...\{E61CEF9A-BAC3-EAEE-F735-E257D2354DF2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{1DBACFDB-5E43-7882-36BD-53526D34BD22}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{5B987681-3652-492B-6A11-E02AC0FE5959}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{B28CF677-E2C8-12CA-52BB-19B6F066D36A}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{BE8D6AB1-3049-2F0C-67FA-00C0A5D321A3}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{DA0326BB-657D-AAFC-752C-363E8FA33755}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (HKLM\...\{EB328356-1DF0-1CCE-3607-6361DD329219}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{365AEAB2-4CF3-7CBB-0DAC-E9E14B688E65}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{45907537-804A-514F-5280-5F4F12A6DCBC}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{5A083A57-10D6-D4E5-292C-F274870E73A4}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{8E6F5592-ED7E-9C50-74AC-BF417B1FE291}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{E42911E5-48F8-8557-ED20-D72AD1907D25}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (HKLM\...\{EB6C44F1-0F78-FE10-BC63-90BA50AB0CE9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{7ABC6D83-816E-6D48-E65D-B0CEDD294E4E}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{962364E4-08BB-347D-32E7-2B789F37BF8A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{AD28960A-6190-C991-C964-308B86EAA2E2}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B26D75B8-FAB7-6F8B-767F-BAF975383D91}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{B4C30EF4-B2C5-1395-B534-7B63BCB6E8E4}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (HKLM\...\{DF0D7C1C-72B6-9FFB-DF66-B3720237BB80}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{26567561-DFB2-2B63-9BA8-6A490ED37016}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{43F6D22B-E0E9-EE90-9B62-1C5FC5D15A55}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{86BFE5B4-1FCE-3C02-6373-92B1AE6431E8}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{87E6EC29-AEC5-28CB-F773-93EB6C1B8A2B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{A91FC4BF-C1EC-ADCA-79D1-F4F0671F1D60}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (HKLM\...\{B873A1FB-5EA0-EE5F-A861-1E38880AD08E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{0742432E-42D9-2240-4CA1-8595CCCBAA77}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{0809FEC1-EF86-51E9-8210-DC1B1BDB6745}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{CA55697D-BD74-3ED8-6B21-D7EDAD3B7D02}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{D4490E0F-8E7B-1097-B56A-7643C75F1C28}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{EC9DF9FF-9D75-4CDD-1D58-A2E887B0A42E}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (HKLM\...\{ED75A775-03A7-F214-868D-497748707968}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{07BFBD5C-2F63-6828-1B61-B41A44113F3B}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{5FD706FF-6AD8-E372-A35A-879409982655}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{7ABACA7E-6E59-0EF9-8FA3-6B32E5F58127}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{CFC860C8-4F51-E08C-A74C-2E444ED06160}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{DAB44116-0266-C65B-B643-AC11217C3041}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (HKLM\...\{EAEAA839-44F4-22DF-D1CC-88C3B2A3D4B1}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{3AF70346-52C7-0334-606F-118D1C1CB7A2}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{3E196AAF-F81C-B384-E2AB-28EE2398FE5F}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{9338D693-38B7-1ED4-9B42-BFA1D5600CCB}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{A3973655-E448-4A1B-477C-988A79D132D9}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{A4E7CA0C-84EB-5E29-2F04-06C4E4790C2F}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (HKLM\...\{E6038D3E-5D87-8DF7-6D05-BE7532C3E73E}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{53AE8AC7-5213-67AF-0DC0-CED696B77643}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{59D2664C-949B-7FA7-9880-ECB993B6616A}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{6DC92550-D065-4B36-C4D3-D8D7A702A7A7}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{C971C145-258D-6650-7088-13DDB161327A}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DAEFFE0C-CD05-1355-6AFC-7B3D4106A820}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (HKLM\...\{DFAD9DAC-4768-C8BB-4E0E-5239605A9BEA}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{970A40CA-46AB-986C-1798-976ED0EA00FA}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{B2A83706-3F14-1532-20CD-B4EE715A8945}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{DC9DFCBF-87DA-892C-6151-99CC9EF46E3E}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{E392A425-53A7-DF90-96A0-E287A75DD3B2}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{EBA09DAF-14B4-7BE7-676E-6E2FB21EDBDD}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (HKLM\...\{FFBFBD1F-B160-A119-7C43-8584FA2E5665}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{44ED2CDA-4197-E9E9-B328-26E1FB749116}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{4707CBFC-8ED4-463E-0FF9-DE86F4A743E9}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{4D1D5407-9B69-6422-629C-8518A26004A4}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{9AA4DD93-94BF-22EA-C9D2-7084F304A31B}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{C1EFF2A2-DF4A-F6D1-B99C-1ED194AE9E78}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (HKLM\...\{D6F47BB4-700A-F612-0671-5F69EA311BB7}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{01FD9A26-3F61-9236-B360-BE5D043D82C0}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{3450566C-4561-0EE8-B1AB-D5C79CCE8D2C}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{379D900B-A785-6DB0-012E-434356A365B3}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{46EB68BE-8AAC-8C2B-7284-8DEDE6B5CD2A}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{A8379BAB-59A9-C0A3-8BCC-4852EA403692}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (HKLM\...\{C14A3A5B-8A86-C239-37D7-158211778C54}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{24DF617A-CD23-6E6A-126B-23630D2781CE}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{366C4FB5-CF6E-258B-418D-E6D29549A278}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{64D4CCC3-63DF-252D-D29D-03491670225D}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{7A6E431B-CF43-EC3E-FD7E-0A0AAB1B25FC}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{A50C89BC-8D8E-8828-824A-7171F6D583D5}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (HKLM\...\{FCE8438C-3272-D63F-479F-670F082B294B}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{0B5633F0-C415-2F08-671E-4C9E2FAACD45}) (Version: 2015.1129.2307.41591 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{25D1751E-7CA2-5F6D-0125-0A16E47AF9FE}) (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{83DDDFD8-AD42-72F9-E4F1-5456FDB304C9}) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{89A1F076-19B8-A2B1-D5A3-E8247EFAF157}) (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{8DF90937-B869-9F76-5D45-5A8BDA0A33B6}) (Version: 2017.0922.1659.28737 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (HKLM\...\{B10089DE-934F-6E0F-683A-B788F89348DF}) (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.36 - Piriform)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.9.0.0650 - Disc Soft Ltd)
Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
Discord (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\Discord) (Version: 0.0.301 - Discord Inc.)
Divinity: Original Sin Enhanced Edition (2.0.119.430_(hotfix)) (HKLM-x32\...\1445516929_is1) (Version: 0.1.1.310 - GOG.com)
Driver Booster 6 (HKLM-x32\...\Driver Booster_is1) (Version: 6.0.2 - IObit)
Dropbox (HKLM-x32\...\Dropbox) (Version: 61.4.95 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.141.1 - Dropbox, Inc.) Hidden
EVEREST Home Edition v2.20 (HKLM-x32\...\EVEREST Home Edition_is1) (Version: 2.20 - Lavalys Inc)
HiSuite (HKLM-x32\...\Hi Suite) (Version: 8.0.1.303 - )
Java 8 Update 161 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Java 8 Update 162 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180162F0}) (Version: 8.0.1620.12 - Oracle Corporation)
Java 8 Update 172 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180172F0}) (Version: 8.0.1720.11 - Oracle Corporation)
K-Lite Mega Codec Pack 14.3.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.3.0 - KLCP)
Microsoft OneDrive (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\OneDriveSetup.exe) (Version: 18.192.0920.0015 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.14.26429 (HKLM-x32\...\{80586c77-db42-44bb-bfc8-7aebbb220c00}) (Version: 14.14.26429.4 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 (HKLM-x32\...\{cb7c3049-21de-415b-bd85-b65c14e547df}) (Version: 14.10.25017.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
Mozilla Firefox 63.0.3 (x64 cs) (HKLM\...\Mozilla Firefox 63.0.3 (x64 cs)) (Version: 63.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.2 - Mozilla)
MSI Afterburner 4.5.0 (HKLM-x32\...\Afterburner) (Version: 4.5.0 - MSI Co., LTD)
MTG Arena (HKLM-x32\...\{A509DF1D-8265-4F4C-A866-177C0E0799D4}) (Version: 0.1.910.0 - Wizards of the Coast) Hidden
MTG Arena (HKLM-x32\...\MTG Arena 0.1.910.0) (Version: 0.1.910.0 - Wizards of the Coast)
Northgard Ragnarok (HKLM-x32\...\Northgard Ragnarok_is1) (Version:  - )
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.5.9 - Notepad++ Team)
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Pillars of Eternity 2 Deadfire Beast of Winter (HKLM-x32\...\Pillars of Eternity 2 Deadfire Beast of Winter_is1) (Version:  - )
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.10.714.2016 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8485 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.1.9 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.9 - VS Revo Group, Ltd.)
RivaTuner Statistics Server 7.2.0 (HKLM-x32\...\RTSS) (Version: 7.2.0 - Unwinder)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.3.8 - Rockstar Games)
Samsung Kies (HKLM-x32\...\{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.4.17113.1 - Samsung Electronics Co., Ltd.) Hidden
Samsung Kies (HKLM-x32\...\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.4.17113.1 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.61.0 - Samsung Electronics Co., Ltd.)
Sid Meiers Civilization VI Rise and Fall (HKLM-x32\...\Sid Meiers Civilization VI Rise and Fall_is1) (Version:  - )
Sudden Strike 4 - Finland: Winter Storm (HKLM-x32\...\1937377674_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4 (HKLM-x32\...\2146639313_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4: Battle of Kursk (HKLM-x32\...\1938212434_is1) (Version: 1.12.28520 - GOG.com)
Sudden Strike 4: Road to Dunkirk (HKLM-x32\...\1589182480_is1) (Version: 1.12.28520 - GOG.com)
Syncios 6.5.0 (HKLM-x32\...\Syncios) (Version: 6.5.0 - Anvsoft)
TeamSpeak 3 Client (HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\TeamSpeak 3 Client) (Version: 3.1.4.2 - TeamSpeak Systems GmbH)
The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 2.0.0.0 - Zenimax Online Studios)
TP-LINK TL-WN823N Driver (HKLM-x32\...\{CE194A8D-C8DF-47EB-AB04-5A54CDC1C5BD}) (Version: 1.3.1 - TP-LINK)
TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{EC5A6438-850E-4AD1-9169-DD071C8EFFEF}) (Version: 2.10.0.0 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 51.0 - Ubisoft)
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.1.70.0 (HKLM\...\VulkanRT1.1.70.0-4) (Version: 1.1.70.0 - LunarG, Inc.) Hidden
Web Companion (HKLM-x32\...\{46b8e553-65e1-4bb3-b888-f5e91c54a65e}) (Version: 4.0.1780.3335 - Lavasoft)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2017-03-08] ()
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (Disc Soft Ltd)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-10-19] (Disc Soft Ltd)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files\AMD\CNext\CNext\atiacm64.dll [2018-11-07] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.26.0.dll [2018-11-06] (Dropbox, Inc.)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2016-12-15] (VS Revo Group)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-14] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2016-08-14] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0CADBE77-2C19-4752-9BF6-7251F2952B37} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-05-27] (Dropbox, Inc.)
Task: {13E14763-C7B0-455B-9D99-6DBB495C8E62} - System32\Tasks\StartDVR => C:\Program Files\AMD\CNext\CNext\dvrcmd.exe [2018-11-07] (Advanced Micro Devices, Inc.)
Task: {3474EEEF-B521-466E-A075-4A1D30B5A899} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {39F6B51E-B91B-46E5-A786-2A8D5AE52E4E} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {51D36D56-BC7F-4C67-A0C6-7C13BCBD7167} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_31_0_0_148_Plugin.exe [2018-11-14] (Adobe Systems Incorporated)
Task: {572993BF-0C1D-4A4D-BB9D-BF82384CA453} - System32\Tasks\Driver Booster SkipUAC (Alonzop) => C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe [2018-10-17] (IObit)
Task: {5997F85B-42AF-458A-A0B2-04EC79860672} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2018-11-07] (Advanced Micro Devices, Inc.)
Task: {63A2E2B2-3C3F-4F53-BD65-74E110253C8A} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-11-14] (Adobe Systems Incorporated)
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {663BEA23-9E12-45C9-8B54-D599258C972A} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2018-05-27] (Dropbox, Inc.)
Task: {6B428069-F812-4D67-9F96-9F48FF3A0D9E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2017-10-18] (Piriform Ltd)
Task: {8FA9C88E-06BC-412D-BA13-0FD6FF2D6072} - System32\Tasks\S-1-5-21-2823601367-1896843323-1796517690-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-04-12] (Microsoft Corporation)
Task: {9685C6F0-9309-4642-A4EC-9D1C6E9A2B6B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {A0A3B153-44B4-4055-8A81-81F83886F622} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [2018-04-23] ()
Task: {D6748BBC-9FF5-491D-981D-E37897A8F55C} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1810.5-0\MpCmdRun.exe [2018-10-23] (Microsoft Corporation)
Task: {EEB666C1-E343-4ED0-9AEE-7B7BD1898CA6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-11-06] (Piriform Ltd)
Task: {FDDC310D-629B-4364-9075-27AD794DC026} - System32\Tasks\klcp_update => CodecTweakTool.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2018-08-23 13:42 - 2018-08-23 13:42 - 000190784 _____ () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
2018-04-12 00:34 - 2018-04-12 00:34 - 000491744 _____ () C:\Windows\System32\InputHost.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 00:34 - 2018-04-12 00:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-10-14 08:47 - 2018-09-20 04:38 - 002185728 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-10-26 19:00 - 2018-10-26 19:00 - 035118592 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-10-26 19:00 - 2018-10-26 19:00 - 000290816 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\SharedUI.dll
2018-10-26 19:00 - 2018-10-26 19:00 - 005987328 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\EntCommon.dll
2017-09-26 16:11 - 2017-09-26 16:11 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-10-26 19:00 - 2018-10-26 19:00 - 009064448 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18082.13811.0_x64__8wekyb3d8bbwe\EntPlat.dll
2018-04-07 13:03 - 2014-12-08 08:56 - 000761856 _____ () C:\Program Files (x86)\AUROZA\Monitor.exe
2018-10-04 19:55 - 2018-08-23 13:42 - 014429984 _____ () C:\Users\Allonzo\AppData\Local\HiSuite\userdata\hwtools\hdbtransport.exe
2018-06-13 07:00 - 2018-06-13 07:00 - 002443384 _____ () C:\Program Files (x86)\Anvsoft\Syncios\SynciosDeviceService.exe
2018-05-30 09:16 - 2018-05-30 09:16 - 000017024 _____ () C:\Program Files (x86)\Anvsoft\Syncios\androidnotifier.exe
2018-06-28 03:17 - 2018-06-28 03:17 - 001091896 _____ () C:\Program Files (x86)\Anvsoft\Syncios\adb.exe
2017-10-09 13:22 - 2012-12-21 19:33 - 000020288 _____ () C:\Program Files\CCleaner\branding.dll
2017-10-18 17:19 - 2017-10-18 17:19 - 000086224 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2018-03-13 03:47 - 2018-03-13 03:47 - 000912896 _____ () C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-core.dll
2015-02-19 00:13 - 2015-02-19 00:13 - 003650560 _____ () C:\Program Files\AMD\Performance Profile Client\Platform.dll
2018-03-13 03:47 - 2018-03-13 03:47 - 003109888 _____ () C:\Program Files\AMD\Performance Profile Client\aws-cpp-sdk-s3.dll
2015-02-19 00:13 - 2015-02-19 00:13 - 000817152 _____ () C:\Program Files\AMD\Performance Profile Client\Device.dll
2018-09-13 03:51 - 2018-09-13 03:51 - 000500256 _____ () C:\Program Files (x86)\HiSuite\DuiLib_ext.dll
2018-09-13 03:51 - 2018-09-13 03:51 - 000187936 _____ () C:\Program Files (x86)\HiSuite\jsondll.dll
2018-09-13 03:51 - 2018-09-13 03:51 - 000074784 _____ () C:\Program Files (x86)\HiSuite\zlibwapi.dll
2018-09-13 03:51 - 2018-09-13 03:51 - 002597920 _____ () C:\Program Files (x86)\HiSuite\CommBase.dll
2018-09-13 03:51 - 2018-09-13 03:51 - 000143904 _____ () C:\Program Files (x86)\HiSuite\MTP_DLL.DLL
2018-04-07 13:03 - 2014-09-09 14:05 - 000057344 _____ () C:\Program Files (x86)\AUROZA\lan.dll
2018-04-07 13:03 - 2013-11-01 11:57 - 000049152 _____ () C:\Program Files (x86)\AUROZA\hiddriver.dll
2018-11-07 06:43 - 2018-11-06 14:06 - 001141064 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2018-11-07 06:43 - 2018-11-06 14:06 - 002103112 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000023376 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025456 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000142312 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 001953640 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000118232 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes35.dll
2018-11-07 06:44 - 2018-11-06 14:06 - 000109024 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000083784 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000418776 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom35.dll
2018-11-07 06:44 - 2018-11-06 14:08 - 000074072 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000049128 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000026600 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000131552 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000182752 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027616 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000119272 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000401752 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000028640 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000034664 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000061792 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:06 - 000023520 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000053736 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000065504 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025944 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000068968 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000032224 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000156504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000092488 _____ () C:\Program Files (x86)\Dropbox\Client\sip.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 001778000 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000518992 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000052056 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 001929552 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 003821392 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000044888 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000132944 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000218456 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000205656 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000061408 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000051552 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000027624 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000033632 _____ () C:\Program Files (x86)\Dropbox\Client\winreindex.compiled._winreindex.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028008 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000031600 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:06 - 000486880 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000102736 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000029040 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 011144016 _____ () C:\Program Files (x86)\Dropbox\Client\nucleus_python.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000029024 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:06 - 000036312 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2018-11-07 06:43 - 2018-11-06 14:08 - 000036712 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000272208 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.advapi32.compiled._winffi_advapi32.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000433992 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2018-11-07 06:44 - 2018-11-06 14:09 - 000035680 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.cp35-win32.pyd
2018-11-07 06:43 - 2018-11-06 14:08 - 000025920 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2018-11-07 06:43 - 2018-11-06 14:08 - 001592128 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2018-11-07 06:44 - 2018-11-06 14:09 - 000095592 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shcore.compiled._winffi_shcore.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000025448 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.gdi32.compiled._winffi_gdi32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.shell32.compiled._winffi_shell32.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:09 - 000029544 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000530768 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000348496 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.cp35-win32.pyd
2018-11-07 06:44 - 2018-11-06 14:08 - 000037200 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngine.cp35-win32.pyd
2018-06-28 03:31 - 2018-06-28 03:31 - 001514496 _____ () C:\Program Files (x86)\Anvsoft\Syncios\DuiLib.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 000074752 _____ () C:\Program Files (x86)\Anvsoft\Syncios\generalFunc_pdt.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 001309184 _____ () C:\Program Files (x86)\Anvsoft\Syncios\androidSyncCore_pdm.dll
2018-06-28 03:17 - 2018-06-28 03:17 - 000178688 _____ () C:\Program Files (x86)\Anvsoft\Syncios\driverMgr4Transfer_pdm.dll
2018-05-30 09:15 - 2018-05-30 09:15 - 000571392 _____ () C:\Program Files (x86)\Anvsoft\Syncios\sqlite3.dll
2018-05-30 09:12 - 2018-05-30 09:12 - 000592896 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libsscan.dll
2018-05-30 09:27 - 2018-05-30 09:27 - 013524469 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libheic.dll
2018-05-30 09:26 - 2018-05-30 09:26 - 001970688 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libplist.dll
2018-05-30 09:26 - 2018-05-30 09:26 - 001042432 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libandroidrecovery.dll
2018-05-30 09:15 - 2018-05-30 09:15 - 001278080 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libandroidnotifier.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 004554857 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libexiv2.dll
2018-05-30 09:12 - 2018-05-30 09:12 - 000121524 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libgcc_s_dw2-1.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 001487360 _____ () C:\Program Files (x86)\Anvsoft\Syncios\exiv2.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 000066048 _____ () C:\Program Files (x86)\Anvsoft\Syncios\zlib1.dll
2018-05-30 09:16 - 2018-05-30 09:16 - 000104448 _____ () C:\Program Files (x86)\Anvsoft\Syncios\expat.dll
2018-05-30 09:30 - 2018-05-30 09:30 - 001544523 _____ () C:\Program Files (x86)\Anvsoft\Syncios\libstdc++-6.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\.DEFAULT\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\localhost -> localhost

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-10 12:04 - 2017-06-03 07:57 - 000000033 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1       localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\theme1\img13.jpg
DNS Servers: 10.0.0.138
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2823601367-1896843323-1796517690-1001\...\StartupApproved\Run: => "Gaijin.Net Agent"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [OpenSSH-Server-In-TCP] => (Allow) %SystemRoot%\system32\OpenSSH\sshd.exe
FirewallRules: [{E5704048-D74D-4C36-83C0-AFC2AE45C0D9}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{168C4730-36FD-43E6-B9B7-83005201CA63}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [UDP Query User{93722077-3426-4264-938D-2DF7BD4BECA5}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [TCP Query User{C280E624-8E98-4BEB-A6EB-E45683BAF9FD}C:\program files\mozilla firefox\firefox.exe] => (Allow) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{81E1E14B-FDD7-431E-8936-021B00ECA713}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{046BB00A-96AE-49DF-8363-EEB2C8CBA86C}] => (Allow) D:\Steam\Steam.exe
FirewallRules: [{74041CFE-45F9-4A6B-8639-C37CE09197C2}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{A59A401D-D68F-42A7-937F-07FC1A9A59FD}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{2F00BEED-005C-4E96-A284-05197064E1A2}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{E8727B48-BF11-44DC-B40B-3A487ABCBE97}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{284402BC-1B04-49F8-9688-2A44ED1FB13F}D:\games\diablo iii\diablo iii.exe] => (Allow) D:\games\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{B1DACAEC-BF39-4AED-9D8B-992AE4B60AFF}D:\games\diablo iii\diablo iii.exe] => (Allow) D:\games\diablo iii\diablo iii.exe
FirewallRules: [{EEC9CB70-CECD-4E44-BFB1-1AB012AFE94F}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{56B7E9AE-46BD-4F70-BA52-C362E10C768F}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{619D4411-9A7F-4EFB-9452-E5E6B9BA8241}] => (Allow) D:\Steam\steamapps\common\Age2HD\Launcher.exe
FirewallRules: [{CBC8BC91-03DD-4A14-B879-6995D1C0BEA0}] => (Allow) D:\Steam\steamapps\common\Age2HD\Launcher.exe
FirewallRules: [TCP Query User{BDEA720E-7297-4B09-A793-67A68C270AA0}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [UDP Query User{CCC6B2D6-B100-474E-8B3A-38260721B218}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [TCP Query User{0F1755AE-AF99-43C3-B752-9F3492D0B539}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [UDP Query User{60370882-0154-433A-93FC-089CC31B18E5}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{956B4F4A-3CAE-481D-976D-38E8E89831C4}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{1FFEF323-FF74-4763-B503-227743D24F1F}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{DB64EC06-61BC-4AFC-B2CE-F40E67A6C339}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{5A6CC866-DF46-48A2-8CFA-B49857B316C9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{92776334-DD7D-4B94-AB22-521C141620C9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{EFF99DAB-AA22-43E1-95CB-FA0EAD5D8F12}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{BB8DCEA9-6A6B-429A-A747-FB04606CD4DE}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{4CD510CA-269F-4D55-B3B9-7ECF003734AD}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{2C65AE6F-AF07-4D56-A63E-385B2ABFD3F9}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{23A05941-721F-4615-9B03-445ECB4ECEB6}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{7C9212D1-EC53-4A58-A2E5-2B86D76924C6}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{5D178285-D43A-4A4E-A7F7-6F3EC45C3949}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{DF2EE1A2-2D3B-4670-8CAD-BC638B2F5B24}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{FADE5BD0-73B1-4BAE-9E55-10EE70E81701}] => (Allow) C:\TP\RTLDHCP.exe
FirewallRules: [{83E6B7A5-C6A4-45C8-9C9C-B780DE639926}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{8ACF4C21-4B5B-4CF0-B790-F84FA0B3DC8A}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{94FFE1BA-67FA-4FED-94A4-DAF28FAF4691}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [UDP Query User{893CCC8F-6077-428D-8939-801974F724C1}D:\torr\utorrent.exe] => (Allow) D:\torr\utorrent.exe
FirewallRules: [TCP Query User{142521BD-BC97-4665-BE8B-ACC2FDCF0EE8}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{B3C6D690-5E97-43F7-835B-AC82E52DB7DF}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{3635E671-1C76-4699-ADB9-A67586E07C19}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [UDP Query User{74E066B2-F1EF-4A18-849C-985FFD2B90AD}D:\games\diablo iii\x64\diablo iii64.exe] => (Allow) D:\games\diablo iii\x64\diablo iii64.exe
FirewallRules: [TCP Query User{156F1724-4149-4D60-9592-65B395C6783D}D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe] => (Allow) D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe
FirewallRules: [UDP Query User{4B58B240-EB49-46D0-9FE3-FD41B8DBB259}D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe] => (Allow) D:\games\divinity - original sin enhanced edition\shipping\eocapp.exe
FirewallRules: [{BB2A3528-4C73-4E84-916E-5EE8FF60DEB7}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{292E230A-0075-493B-8662-20A6F0E558C6}] => (Allow) D:\Steam\steamapps\common\Magic Duels\MagicDuels.exe
FirewallRules: [{88E39619-3461-4438-AA59-53D5CDEB8E2B}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{26AAD9CF-D94C-4791-9492-57A35C862500}] => (Allow) D:\Steam\steamapps\common\EvolveGame\bin64_SteamRetail\Evolve.exe
FirewallRules: [{CA7FAD52-A270-453C-994F-AE1E7A8602D9}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{18A0C796-4CFD-4F40-8A95-DDFE772DEB88}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{74A8C031-2945-4D7C-AC37-C8A3527F8B8A}] => (Allow) C:\Program Files (x86)\Anvsoft\Syncios\pdt_syncios.exe
FirewallRules: [{6F6D7066-989D-46B5-846C-1FFFCEBABE0B}] => (Block) D:\Games\Pillars of Eternity 2 Deadfire Beast of Winter\PillarsOfEternityII.exe
FirewallRules: [{57DD9B1E-FB09-488B-B080-6FA6F8BE12C0}] => (Block) D:\Games\Pillars of Eternity 2 Deadfire Beast of Winter\PillarsOfEternityII.exe
FirewallRules: [{0D24A2B0-6691-4DEB-AECC-BB8BA5753292}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
FirewallRules: [{F02198EA-317E-4138-B0A8-2DC476C628BF}] => (Allow) D:\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
FirewallRules: [TCP Query User{81960E18-ADDE-4D93-A845-4018B92BD18D}D:\steam\steamapps\common\for honor\forhonor.exe] => (Allow) D:\steam\steamapps\common\for honor\forhonor.exe
FirewallRules: [UDP Query User{7BF1C704-A7C2-4642-A22B-C03066FF8C20}D:\steam\steamapps\common\for honor\forhonor.exe] => (Allow) D:\steam\steamapps\common\for honor\forhonor.exe
FirewallRules: [TCP Query User{DAA91239-943E-486A-90C5-0FB91D319DBB}C:\program files (x86)\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files (x86)\wizards of the coast\mtga\mtga.exe
FirewallRules: [UDP Query User{53371FEB-D07A-4091-B4D0-A32C09C183BA}C:\program files (x86)\wizards of the coast\mtga\mtga.exe] => (Allow) C:\program files (x86)\wizards of the coast\mtga\mtga.exe
FirewallRules: [{35D30BFA-4864-4A8F-AFB4-8B42AFF94B62}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe
FirewallRules: [{6B24BE88-3231-4968-BA78-20909D0CF39D}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DriverBooster.exe
FirewallRules: [{6EA189C8-3A4D-43BB-9D41-695195EADFBF}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DBDownloader.exe
FirewallRules: [{D2D67853-AC9A-449E-B972-360652398C03}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\DBDownloader.exe
FirewallRules: [{60484728-3A26-4549-89F8-96991B22E8A0}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\AutoUpdate.exe
FirewallRules: [{47468509-034B-452A-9732-62B48088E5C6}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\6.0.2\AutoUpdate.exe
FirewallRules: [{AE3135C1-282A-49B9-BBD9-127F0EE76B24}] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{89ECC069-1869-422A-8C68-95ABE5C18A7A}] => (Allow) D:\torr\utorrent.exe
FirewallRules: [{64F8B66D-A1D1-48C7-9425-322AB5FDBB5C}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
FirewallRules: [{3B6A675D-2925-4A4C-87C2-4800FDE77F6D}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe

==================== Restore Points =========================

06-11-2018 22:40:11 Instalační služba modulů systému Windows
07-11-2018 23:44:36 Instalační služba modulů systému Windows
09-11-2018 19:38:25 Instalační služba modulů systému Windows
10-11-2018 22:11:57 Instalační služba modulů systému Windows
12-11-2018 18:02:47 Instalační služba modulů systému Windows
13-11-2018 19:26:40 Instalační služba modulů systému Windows
14-11-2018 19:46:39 Instalační služba modulů systému Windows
14-11-2018 21:46:42 Instalační služba modulů systému Windows
15-11-2018 22:32:23 Installed MTG Arena
16-11-2018 00:09:42 Instalační služba modulů systému Windows
17-11-2018 01:51:17 Instalační služba modulů systému Windows
17-11-2018 07:37:38 Installed MTG Arena
17-11-2018 16:51:53 Removed Microsoft Office Professional Plus 2013
17-11-2018 16:52:11 PROPLUSR
18-11-2018 03:13:12 Instalační služba modulů systému Windows

==================== Faulty Device Manager Devices =============

Name: Časovač událostí s vysokou přesností
Description: Časovač událostí s vysokou přesností
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standardní systémová zařízení)
Service: 
Problem: : This device is disabled because the firmware of the device did not give it the required resources. (Code 29)
Resolution: Enable the device in the BIOS of the device.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/18/2018 03:24:12 PM) (Source: Windows Search Service) (EventID: 1019) (User: )
Description: Službě Windows Search se nepodařilo zpracovat seznam zahrnutých a vyloučených umístění, a to s chybou <30, 0x80040d07, iehistory://{S-1-5-21-2823601367-1896843323-1796517690-1001}/>.

Error: (11/18/2018 01:45:25 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/18/2018 01:45:02 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/18/2018 01:07:09 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/18/2018 12:44:26 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/18/2018 12:34:28 AM) (Source: Microsoft-Windows-SpellChecker) (EventID: 33) (User: X-COM)
Description: httphttp-2147467263

Error: (11/17/2018 07:00:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: iDownloaderConsole.exe, verze: 1.0.0.0, časové razítko: 0x5b9e3fc2
Název chybujícího modulu: KERNELBASE.dll, verze: 10.0.17134.319, časové razítko: 0x5ea0e53d
Kód výjimky: 0xe0434352
Posun chyby: 0x001117d2
ID chybujícího procesu: 0x978
Čas spuštění chybující aplikace: 0x01d47e9f627a7dec
Cesta k chybující aplikaci: C:\Program Files\WindowsApps\21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc\Win32\iDownloaderConsole.exe
Cesta k chybujícímu modulu: C:\WINDOWS\System32\KERNELBASE.dll
ID zprávy: 830cb434-224e-4e6d-9961-0f1fead28510
Úplný název chybujícího balíčku: 21676OptimiliaStudios.iDownload-Manager_1.1.38.0_x64__k42naep6bwmrc
ID aplikace související s chybujícím balíčkem: App

Error: (11/17/2018 07:00:21 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: iDownloaderConsole.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.InvalidOperationException
   na DownloaderConsole.AppServiceManager+<AppServiceThreadProc>d__11.MoveNext()
   na System.Runtime.CompilerServices.AsyncMethodBuilderCore+<>c.<ThrowAsync>b__6_1(System.Object)
   na System.Threading.QueueUserWorkItemCallback.WaitCallback_Context(System.Object)
   na System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   na System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
   na System.Threading.ThreadPoolWorkQueue.Dispatch()
   na System.Threading._ThreadPoolWaitCallback.PerformWaitCallback()


System errors:
=============
Error: (11/18/2018 03:57:44 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID 
Windows.SecurityCenter.WscBrokerManager
 a APPID 
Není k dispozici
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/18/2018 03:57:44 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Spuštění pro serverovou aplikaci COM s identifikátorem CLSID 
Windows.SecurityCenter.WscDataProtection
 a APPID 
Není k dispozici
 uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.

Error: (11/18/2018 03:54:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Instalační služba systému Windows byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 120000 milisekund: Restartovat službu.

Error: (11/18/2018 03:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Disc Soft Lite Bus Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/18/2018 03:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba NIHardwareService byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/18/2018 03:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba SAMSUNG Mobile Connectivity Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/18/2018 03:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba AMD FUEL Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (11/18/2018 03:54:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba HuaweiHiSuiteService64.exe byla neočekávaně ukončena. Tento stav nastal již 1krát.


Windows Defender:
===================================
Date: 2018-11-12 19:22:03.201
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {98D630BD-28B6-4A73-B241-C8318C025B52}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-03 22:03:55.662
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {912E2FD6-2710-49F4-B68E-A74C6DD132E6}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-02 17:27:53.497
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {0BC3853A-3E11-4ABF-AEF4-F307F19A8725}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-30 20:04:24.361
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {EE084A95-D0F2-4AD5-A439-D60E7AF96ABD}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-10-27 03:50:02.505
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {FD88DD2D-0808-41A2-9AF7-6BB22311F5A3}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2018-11-09 22:21:48.018
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1512.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-07 21:53:34.535
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1373.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x80240438
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-07 17:30:02.978
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1309.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-06 22:48:52.472
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.1309.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

Date: 2018-11-01 16:57:16.901
Description: 
Prohledávání Antivirová ochrana v programu Windows Defender zjistilo chybu při pokusu o aktualizaci podpisů.
Nová verze podpisu: 
Předchozí verze podpisu: 1.279.902.0
Zdroj aktualizace: Server Microsoft Update
Typ podpisu: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu: 
Předchozí verze modulu: 1.1.15400.4
Kód chyby: 0x8024402c
Popis chyby :Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře. 

CodeIntegrity:
===================================

Date: 2018-10-26 23:05:58.943
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:05:57.162
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:50.601
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:49.557
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:30.519
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:29.469
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:12.384
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2018-10-26 23:00:11.336
Description: 
Windows is unable to verify the image integrity of the file \Device\CdRom0\CDriver.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

==================== Memory info =========================== 

Processor: AMD Athlon(tm) X4 740 Quad Core Processor 
Percentage of memory in use: 26%
Total physical RAM: 8145.84 MB
Available physical RAM: 5998.05 MB
Total Virtual: 9425.84 MB
Available Virtual: 6637.66 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:488.59 GB) (Free:37.78 GB) NTFS
Drive d: (Nový svazek) (Fixed) (Total:442.38 GB) (Free:39.16 GB) NTFS

\\?\Volume{99c499c4-0000-0000-0000-100000000000}\ (Rezervováno systémem) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{350f029c-0000-0000-0000-102c7a000000}\ () (Fixed) (Total:0.44 GB) (Free:0.06 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 350F029C)
Partition 1: (Not Active) - (Size=488.6 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=450 MB) - (Type=27)
Partition 3: (Not Active) - (Size=442.4 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 74.5 GB) (Disk ID: 99C499C4)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119426
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Problém s "AUEPMaster.exe" ale určitě tam nění sám .

#13 Příspěvek od Rudy »

Log ho neukázal. Udělejte kompletní sken AVPTool: http://www.viry.cz/forum/viewtopic.php?f=29&t=58179 . Stáhněte, spusťte a nechte pracovat. Po skončení akce smažte vše, co najde.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět