Stránka 1 z 2

Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 12:58
od spd
Prosím o pomoc s odstraněním ransomwaru. Podle dostupných informací nelze zatím soubory napadené tímto ransomewarem dešifrovat (nebo to jde??). Lze alespoň zabránit šíření a zbavit se ho ?? Díky moc !

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-10-2019
Ran by Jára (administrator) on DESKTOP-41PK4RC (Gigabyte Technology Co., Ltd. B250M-D3H) (20-10-2019 13:50:32)
Running from D:\Downloads
Loaded Profiles: Jára (Available Profiles: defaultuser0 & Jára)
Platform: Windows 10 Home Version 1903 18362.418 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Systems Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
(Akamai Technologies, Inc. -> Akamai Technologies, Inc.) C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc. -> Akamai Technologies, Inc.) C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Autodesk, Inc -> Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe
(Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(Firebit OU -> Rainmeter) C:\Program Files\Rainmeter\Rainmeter.exe
(G.K.Enterprise) [File not signed] C:\ProgramData\taskhost.exe
(Ghisler Software GmbH -> Ghisler Software GmbH) C:\totalcmd\TOTALCMD64.EXE
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel(R) Network Platform Group -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Jára\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1001.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19092.399.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeCP.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\MicrosoftEdgeSH.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
(Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Samsung Electronics Co., Ltd. -> Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.85.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.85.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9037832 2016-10-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320568 2016-09-20] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [301880 2018-11-15] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk, Inc -> Autodesk Inc.)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155131\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132216916\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155206\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217117\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [729704 2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe [4586456 2018-04-17] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3211040 2019-10-02] (Valve -> Valve Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3115792 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [148776 2007-07-04] (Nero AG -> Nero AG)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Fliqlo.scr [679936 2019-01-13] (ScreenTime Media) [File not signed]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [729704 2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Run: [Akamai NetSession Interface] => C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe [4586456 2018-04-17] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3211040 2019-10-02] (Valve -> Valve Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3115792 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [148776 2007-07-04] (Nero AG -> Nero AG)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Policies\Explorer: []
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Fliqlo.scr [679936 2019-01-13] (ScreenTime Media) [File not signed]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [729704 2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Run: [Akamai NetSession Interface] => C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe [4586456 2018-04-17] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3211040 2019-10-02] (Valve -> Valve Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3115792 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [148776 2007-07-04] (Nero AG -> Nero AG)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Policies\Explorer: []
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Fliqlo.scr [679936 2019-01-13] (ScreenTime Media) [File not signed]
HKU\S-1-5-18\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.120\Installer\chrmstp.exe [2019-10-16] (Google LLC -> Google LLC)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT-FILES.txt [2019-10-20] () [File not signed]
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT-FILES.txt [2019-10-20] () [File not signed]
Startup: C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe.ini.lnk [2019-10-20]
ShortcutTarget: Adobe.ini.lnk -> C:\ProgramData\Adobe.js () [File not signed]
Startup: C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT-FILES.txt [2019-10-20] () [File not signed]
Startup: C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2019-01-06]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Firebit OU -> Rainmeter)
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01719E40-9736-43B0-AAFA-049AE151F044} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-09] (Google Inc -> Google Inc.)
Task: {1C679054-3617-4E40-B2FF-98F35B6C25E7} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [982568 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2E585DCB-C7E5-45D7-90A9-C8F7B3FC7807} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {3C0D5580-4D8E-414B-B6E0-1C852B5C5C3C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3FE3A18A-C661-43AB-80B2-2A939DCB2D0E} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [764456 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {46BA238E-7A56-410A-8405-75421E5D2BE1} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [856616 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {57A8576F-99CC-45CA-A2FB-EDF55BA3AEAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-09] (Google Inc -> Google Inc.)
Task: {5F6A125B-E1E9-4321-9219-E82A92AA3963} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [927272 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {604A86D9-2564-4A49-9F5F-FF3960C7D54D} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [647720 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {66F70C81-7AEE-48C2-9906-BA83B12EA8A8} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3297832 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8253FA6C-44DD-4439-9FC6-EC607FC4E344} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [927272 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8370E573-BF6E-4644-9C64-67A767CDA919} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
Task: {B7A4AB13-2CEF-4524-B3C4-90E2FB46725C} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [927272 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B88FC8D9-9B43-4E02-B7FC-C6F8A393D980} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [856616 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BA9B36C1-1883-4631-80FF-25633223F225} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3933576 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
Task: {BB94C5B0-DBC2-4FB1-A40D-B5371648E31E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [13594584 2018-06-24] (Piriform Ltd -> Piriform Ltd)
Task: {C16C15F6-65E8-47B5-B5F4-BC7E25E9F31E} - System32\Tasks\klcp_update => CodecTweakTool.exe
Task: {C81A91DB-F55F-4FB1-A392-05814F57F6C3} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [1146048 2018-05-28] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co. Ltd.)
Task: {CF71B687-E5F7-4DD9-BD9E-A2D644131FB7} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-41PK4RC-Jára => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {D7FC1A64-A007-4A2A-9DB6-D53429219612} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [764456 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EB75CAE2-7719-4C7C-8FC9-9226DA379B5E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {FE7D350D-0393-4546-9D31-531F777C33F5} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [927272 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c87d4fa6-45ad-42b4-8a8e-c5a1caf63c62}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{cd19de96-a514-4b49-974a-742b7e1a1e45}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll [2018-08-09] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-08-09] (Oracle America, Inc. -> Oracle Corporation)

FireFox:
========
FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-08-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-08-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-08-21] (NVIDIA Corporation -> NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-08-21] (NVIDIA Corporation -> NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.301\npGoogleUpdate3.dll [2019-10-13] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.301\npGoogleUpdate3.dll [2019-10-13] (Google Inc -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-11] (Adobe Inc. -> Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.seznam.cz/ ... 1069300077"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default [2019-10-20]
CHR DownloadDir: D:\Downloads
CHR Extension: (Prezentace) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-08-09]
CHR Extension: (Dokumenty) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-08-09]
CHR Extension: (Disk Google) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-25]
CHR Extension: (YouTube) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-08-09]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2018-08-09]
CHR Extension: (Hudba Google Play) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2019-03-09]
CHR Extension: (Tabulky) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-08-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]
CHR Extension: (Hover Zoom) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl [2019-10-16]
CHR Extension: (Picasa) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2018-08-09]
CHR Extension: (Gmail) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-30]
CHR Extension: (Chrome Media Router) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-27]
CHR Profile: C:\Users\Jára\AppData\Local\Google\Chrome\User Data\System Profile [2019-04-26]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk, Inc -> Autodesk Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [85304 2018-10-16] (Apple Inc. -> Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6085360 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
S2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc -> Autodesk, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3606632 2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [267560 2007-07-04] (Nero AG -> Nero AG)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [764456 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [764456 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2348336 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3228976 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2018-08-13] (Even Balance, Inc. -> )
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\NisSrv.exe [3004048 2019-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MsMpEng.exe [103384 2019-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37616 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [204824 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [274456 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [209552 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [65120 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
S0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2019-10-20] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [276952 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42736 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [171520 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110320 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
S0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83792 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848432 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460448 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [236024 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316528 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-08-09] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-08-09] (Disc Soft Ltd -> Disc Soft Ltd)
S3 gdrv; C:\Windows\gdrv.sys [26192 2018-08-09] (Giga-Byte Technology -> Windows (R) Server 2003 DDK provider)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-10-20] (Malwarebytes Corporation -> Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_f5be1f8d25335236\nvlddmkm.sys [17212744 2018-08-22] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30656 2018-07-12] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69544 2018-06-08] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [65792 2018-08-21] (NVIDIA Corporation -> NVIDIA Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46688 2019-10-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [350136 2019-10-05] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54200 2019-10-05] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-10-20 13:32 - 2019-10-20 13:51 - 000000000 ____D C:\FRST
2019-10-20 13:20 - 2019-10-20 13:20 - 066367928 _____ (Malwarebytes ) C:\Users\Jára\Desktop\mb3-setup-37469.37469-3.8.3.2965-1.0.627-1.0.12633.exe
2019-10-20 13:20 - 2019-10-20 13:20 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-10-20 13:20 - 2019-10-20 13:20 - 000001918 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\Users\Jára\AppData\Local\mbamtray
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\Users\Jára\AppData\Local\mbam
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\Program Files\Malwarebytes
2019-10-20 13:20 - 2019-08-27 05:50 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-10-20 13:20 - 2019-06-26 13:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-10-20 12:41 - 2019-10-20 12:41 - 000002166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2019-10-20 12:41 - 2019-10-20 12:41 - 000002154 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2019-10-20 12:41 - 2019-10-20 12:41 - 000000000 ____D C:\Users\Jára\AppData\Roaming\AVAST Software
2019-10-20 12:40 - 2019-10-20 12:40 - 000848432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000460448 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000355720 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2019-10-20 12:40 - 2019-10-20 12:40 - 000316528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000276952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000274456 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000236024 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000209552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000204824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000171520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000110320 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000083792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000065120 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000042736 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000037616 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000016304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000003990 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2019-10-20 12:40 - 2019-10-20 12:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2019-10-20 12:40 - 2019-10-20 12:40 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
2019-10-20 12:39 - 2019-10-20 12:40 - 000000000 ____D C:\ProgramData\AVAST Software
2019-10-20 12:39 - 2019-10-20 12:39 - 000000000 ____D C:\Program Files\AVAST Software
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Public\Downloads\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Public\Documents\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Public\Desktop\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Public\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Jára\Downloads\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Jára\Documents\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\Desktop\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\AppData\Roaming\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\AppData\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\Downloads\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\Documents\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\Desktop\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\AppData\Roaming\Microsoft\Windows\Start Menu\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\AppData\Roaming\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\AppData\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\Downloads\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\Documents\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\Desktop\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\AppData\Roaming\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\AppData\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\Downloads\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\Documents\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\Desktop\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\AppData\Roaming\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\AppData\DECRYPT-FILES.txt
2019-10-20 12:04 - 2019-10-20 12:04 - 001519616 _____ (G.K.Enterprise) C:\ProgramData\taskhost.exe
2019-10-20 12:04 - 2019-10-20 12:04 - 000009524 _____ C:\Users\DECRYPT-FILES.txt
2019-10-20 12:04 - 2019-10-20 12:04 - 000009524 _____ C:\DECRYPT-FILES.txt
2019-10-20 12:04 - 2019-10-20 12:04 - 000000265 _____ C:\ProgramData\0x29A.db
2019-10-19 21:06 - 2019-10-20 12:06 - 000000000 ____D C:\Users\Jára\Desktop\Chase & Status - RTRN II JUNGLE (2019) [MP3.CBR.320] [Move-MAG]
2019-10-19 21:05 - 2019-10-20 12:07 - 032715846 _____ C:\Users\Jára\Desktop\Kemal & Rob Data - Star Trails (Synergy Bootleg).wav.vewGg8
2019-10-19 21:05 - 2019-10-20 12:06 - 013987502 _____ C:\Users\Jára\Desktop\01 No More.mp3.AStcNA9
2019-10-19 21:05 - 2019-10-20 12:06 - 012313641 _____ C:\Users\Jára\Desktop\02 If You.mp3.M4OLQ
2019-10-19 21:04 - 2019-10-20 12:07 - 012098214 _____ C:\Users\Jára\Desktop\M.mp3.lBLk
2019-10-19 21:03 - 2019-10-20 12:07 - 010704997 _____ C:\Users\Jára\Desktop\Phibes - M-Beat Feat General Levy (Phibes Remix).mp3.inIz
2019-10-19 20:58 - 2019-10-20 12:07 - 010878016 _____ C:\Users\Jára\Desktop\Phibes - Breathe.mp3.uskm
2019-10-19 20:57 - 2019-10-20 12:07 - 012331205 _____ C:\Users\Jára\Desktop\Phibes - Hustlin.mp3.oxtrA
2019-10-19 20:56 - 2019-10-20 12:07 - 010869657 _____ C:\Users\Jára\Desktop\Phibes - Super Sharp Shooter.mp3.pKxQF
2019-10-19 20:55 - 2019-10-20 12:07 - 010155740 _____ C:\Users\Jára\Desktop\Phibes - Clint Eastwood (Body Drop Vip).mp3.cRCVe
2019-10-19 20:54 - 2019-10-20 12:07 - 010112071 _____ C:\Users\Jára\Desktop\Phibes - Bitches Roll.mp3.bmkel3e
2019-10-19 20:50 - 2019-10-20 12:07 - 046577516 _____ C:\Users\Jára\Desktop\Showmelove.wav.b6r6r
2019-10-19 20:50 - 2019-10-20 12:07 - 010740946 _____ C:\Users\Jára\Desktop\Phibes - Count it Off.mp3.zOge
2019-10-19 20:48 - 2019-10-20 12:07 - 011119213 _____ C:\Users\Jára\Desktop\Phibes - Funk Soul Brother 2017 M.mp3.bgkOpW
2019-10-18 17:09 - 2019-10-20 12:06 - 000342871 _____ C:\Users\Jára\Desktop\1.jpg.M4OLQ
2019-10-16 18:38 - 2019-10-16 18:38 - 000000861 _____ C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 9 Suite.lnk
2019-10-16 17:54 - 2019-10-16 17:54 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 022628352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 019811840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 018019840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 017787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 009928504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 008010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 007600664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 007195648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 007015936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 006517640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 006232064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 005915648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 005041664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 004562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 004129616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 004012544 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 003771392 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 003701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 002861568 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002762504 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2019-10-16 17:54 - 2019-10-16 17:54 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2019-10-16 17:54 - 2019-10-16 17:54 - 002723328 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 002703360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002494440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002456064 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002448712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002422592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2019-10-16 17:54 - 2019-10-16 17:54 - 002314648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002284032 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002236144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002138472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2019-10-16 17:54 - 2019-10-16 17:54 - 002114048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002095104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002000168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001952360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001847808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001830200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001730560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001687040 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001664928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001656392 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001563648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001562424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001439744 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001394488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001283072 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001273392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001217904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001152016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001084432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000904208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000890472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000880088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000856576 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2019-10-16 17:54 - 2019-10-16 17:54 - 000844800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000829536 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000818688 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000774672 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000758584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mousocoreworker.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000679880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000598024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000537600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000516408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000515896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000466416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000462136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000452408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000412152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000404392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000380216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000225080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-10-16 17:54 - 2019-10-16 17:54 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000220472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000202040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-10-16 17:54 - 2019-10-16 17:54 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000165832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000150328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000039304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NtlmShared.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000037176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000033048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NtlmShared.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2019-10-16 17:54 - 2019-10-16 17:54 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2019-10-16 17:40 - 2019-10-16 18:38 - 000000000 ____D C:\ProgramData\Ableton
2019-10-16 17:33 - 2019-08-26 18:37 - 000002298 _____ C:\ProgramData\Adobe.js
2019-10-16 17:27 - 2019-10-20 12:07 - 000000000 ____D C:\Users\Jára\Documents\Max 8
2019-10-16 17:27 - 2019-10-20 12:06 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Cycling '74
2019-10-16 17:27 - 2019-10-16 17:27 - 000000000 ____D C:\ProgramData\Max 8
2019-10-16 17:26 - 2019-10-16 17:26 - 000000000 ____D C:\Users\Jára\AppData\Local\Ableton
2019-10-09 17:40 - 2019-09-20 06:36 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2019-10-09 17:40 - 2019-09-20 06:14 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 007848192 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 006425600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 006227624 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 006164480 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 006084048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 005865272 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizimg.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 005764872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 005105152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 004612520 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 004046336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003964056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 003742032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003727360 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 003553280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003386880 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003184128 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003105280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002821120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002799616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 002772032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002590208 _____ C:\WINDOWS\system32\dwmscene.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002552120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002258856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002160640 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002132280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002120704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002120272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002069504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001957008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001913296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001857024 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001845408 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001788728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-10-05 11:26 - 2019-10-05 11:26 - 001692160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001664376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001616784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001616608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdrecordcpu.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001607680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001543168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 001510752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001505320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001383856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-10-05 11:26 - 2019-10-05 11:26 - 001334064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdrecordcpu.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001297936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001263616 _____ (Microsoft Corporation) C:\WINDOWS\system32\opengl32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001261800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001244944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001182240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 001178816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001154656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001150240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputHost.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001091584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001054872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001047968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001029432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 001023128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000944664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000939008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000931840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000904704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\opengl32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000833312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000792296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputHost.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000759488 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000732176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000656960 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000639400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000612864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000599040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000551952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiagn.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourceMapper.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000541480 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000539648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000501232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-10-05 11:26 - 2019-10-05 11:26 - 000487576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiagn.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000450360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000449888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000442704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-10-05 11:26 - 2019-10-05 11:26 - 000417280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000398728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000387832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000383984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000379840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000375720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiag.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000342896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdwriter.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000334936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiag.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000293344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgmgr32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\directxdatabaseupdater.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000285256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000283688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdwriter.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000278080 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ManageCI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glu32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgmgr32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000223032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgiadaptercache.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlib.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000176152 _____ (Microsoft Corporation) C:\WINDOWS\system32\imm32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glu32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000159112 _____ (Microsoft Corporation) C:\WINDOWS\system32\devobj.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000143808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imm32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000140496 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prntvpt.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000137864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devobj.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ForceSync.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000125232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000119840 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000116904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000110080 _____ C:\WINDOWS\system32\ResBParser.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000105272 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000100664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000092624 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostw.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvvmtransport.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000079376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uaspstor.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000073024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000066832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvvmtransport.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidspi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\devrtl.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devrtl.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnppolicy.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000053248 _____ C:\WINDOWS\system32\Drivers\UsbPmApi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000052752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmstorfl.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000047616 _____ C:\WINDOWS\system32\UsbPmApi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000043536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storvsc.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32_DeviceGuard.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000021544 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000020944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000016696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizres.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000011576 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlibres.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-09-29 20:36 - 2019-10-20 12:07 - 000041993 _____ C:\Users\Jára\Desktop\Výstřižek.JPG.fCpNe4
2019-09-28 20:06 - 2019-09-28 20:06 - 000000000 ____D C:\ProgramData\PACE Anti-Piracy

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-10-20 13:23 - 2019-09-11 21:18 - 000436109 _____ C:\Users\Jára\Desktop\report_tdsskiller.txt
2019-10-20 13:20 - 2019-03-19 06:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-10-20 12:35 - 2018-08-11 11:17 - 000000000 ____D C:\Users\Jára\AppData\Roaming\MPC-HC
2019-10-20 12:25 - 2018-08-09 17:41 - 000000000 ____D C:\ProgramData\NVIDIA
2019-10-20 12:24 - 2018-08-09 18:42 - 000000000 ____D C:\Users\Jára\AppData\Roaming\GHISLER
2019-10-20 12:07 - 2019-09-05 09:03 - 000000000 ____D C:\Users\Jára\Desktop\dana fotky
2019-10-20 12:07 - 2019-07-21 13:49 - 000000284 ___SH C:\Users\Jára\ntuser.ini.wMlS9eB
2019-10-20 12:07 - 2019-07-21 13:45 - 000000000 ____D C:\Users\Jára
2019-10-20 12:07 - 2019-05-19 11:55 - 000000000 ____D C:\Users\Jára\Documents\My Games
2019-10-20 12:07 - 2019-05-08 16:26 - 000000426 ____H C:\Users\Jára\Desktop\~$ SP 20182019.doc.Qg1rvte
2019-10-20 12:07 - 2019-04-26 18:15 - 015822951 _____ C:\Users\Jára\Documents\HLZ - Abracatabla.mp3.GzDbpe
2019-10-20 12:07 - 2019-04-26 18:15 - 014952526 _____ C:\Users\Jára\Documents\HLZ - Clusters.mp3.ELsq3h
2019-10-20 12:07 - 2019-04-26 18:15 - 014537650 _____ C:\Users\Jára\Documents\Hybris - Crumbled (DLR's 3rd time- around Rmx).mp3.V6jGR
2019-10-20 12:07 - 2019-04-26 18:15 - 014115374 _____ C:\Users\Jára\Documents\HLZ -Vectors.mp3.EIKYX
2019-10-20 12:07 - 2019-04-26 18:15 - 014075837 _____ C:\Users\Jára\Documents\HLZ - Kronos.mp3.Wp6iJ
2019-10-20 12:07 - 2019-04-26 18:15 - 013644592 _____ C:\Users\Jára\Documents\Black Barrel - Don't Stop.mp3.H23h2n
2019-10-20 12:07 - 2019-04-26 18:15 - 013269275 _____ C:\Users\Jára\Documents\HLZ - Funk O'Clock.mp3.WVGj
2019-10-20 12:07 - 2019-04-26 18:15 - 012857568 _____ C:\Users\Jára\Documents\Monty - Tribes.mp3.nYoeSJC
2019-10-20 12:07 - 2019-04-26 18:15 - 012700749 _____ C:\Users\Jára\Documents\Monty - Ectoplasm.mp3.SpMV
2019-10-20 12:07 - 2019-04-26 18:15 - 012687927 _____ C:\Users\Jára\Documents\Monty - Temptation.mp3.AAP5387
2019-10-20 12:07 - 2019-04-26 18:15 - 011912334 _____ C:\Users\Jára\Documents\Monty - Decisions.mp3.YUXU7E
2019-10-20 12:07 - 2019-04-26 18:15 - 011816021 _____ C:\Users\Jára\Documents\Monty - Spatia.mp3.PfzeNew
2019-10-20 12:07 - 2019-04-26 18:15 - 011714614 _____ C:\Users\Jára\Documents\Kiril - This!.mp3.ZrfG9Yb
2019-10-20 12:07 - 2019-04-26 18:15 - 011670770 _____ C:\Users\Jára\Documents\Signal & Cruk - Illusion.mp3.WDvth9Z
2019-10-20 12:07 - 2019-04-26 18:15 - 011161089 _____ C:\Users\Jára\Documents\Cruk - See It Our Way.mp3.np3D
2019-10-20 12:07 - 2019-04-26 18:15 - 010973631 _____ C:\Users\Jára\Documents\Data 3 - Komparen.mp3.WRHXV
2019-10-20 12:07 - 2019-04-26 18:15 - 008202946 _____ C:\Users\Jára\Documents\Xtrah - A New Perspective.mp3.GtPzPpM
2019-10-20 12:07 - 2019-04-26 18:15 - 000032343 _____ C:\Users\Jára\Documents\2_heavy rollers.nml.DKIlHVo
2019-10-20 12:07 - 2019-04-19 20:24 - 000000000 ____D C:\Users\Jára\Documents\Assassin's Creed Unity
2019-10-20 12:07 - 2019-03-25 19:30 - 000000000 ____D C:\Users\Jára\Documents\Audacity
2019-10-20 12:07 - 2019-03-19 06:52 - 000000000 __RHD C:\Users\Public\Libraries
2019-10-20 12:07 - 2019-02-02 21:14 - 000000000 ____D C:\Users\Jára\Documents\BioWare
2019-10-20 12:07 - 2019-01-06 18:14 - 000000000 ____D C:\Users\Jára\Documents\Rainmeter
2019-10-20 12:07 - 2019-01-05 00:59 - 000000000 ____D C:\Users\Public\Documents\NI Resources
2019-10-20 12:07 - 2019-01-05 00:54 - 000000000 ____D C:\Users\Public\Documents\Native Instruments
2019-10-20 12:07 - 2018-12-27 15:40 - 000000000 ____D C:\Users\Public\Documents\Steam
2019-10-20 12:07 - 2018-10-27 14:18 - 000000000 ____D C:\Users\Jára\Documents\Ableton
2019-10-20 12:07 - 2018-10-14 19:07 - 000011939 _____ C:\Users\Jára\Documents\krkonose.docx.P5zU
2019-10-20 12:07 - 2018-09-06 21:01 - 000000000 ____D C:\Users\Jára\Documents\Battlefield V Open Beta
2019-10-20 12:07 - 2018-09-02 10:39 - 000000000 ____D C:\Users\Jára\Documents\Native Instruments
2019-10-20 12:07 - 2018-09-02 10:31 - 000000000 ____D C:\Users\Jára\Lokale Einstellungen
2019-10-20 12:07 - 2018-08-19 19:56 - 000000000 ____D C:\Users\Jára\Documents\ALTERNATIVA
2019-10-20 12:07 - 2018-08-18 08:45 - 000000000 ____D C:\Users\Jára\Downloads\Ulozto
2019-10-20 12:07 - 2018-08-14 05:19 - 000000000 ____D C:\Users\Jára\Documents\Battlefield 1
2019-10-20 12:07 - 2018-08-11 16:08 - 000000000 ____D C:\Users\Jára\Documents\Autodesk Application Manager
2019-10-20 12:07 - 2018-08-11 16:07 - 000000000 ____D C:\Users\Public\Documents\Autodesk
2019-10-20 12:07 - 2018-08-11 16:07 - 000000000 ____D C:\Users\Jára\Documents\Inventor Server SDK ACAD 2016
2019-10-20 12:07 - 2018-08-11 15:53 - 002378438 _____ C:\Users\Jára\Downloads\Mista_na_prenocovani.zip.T6Hd
2019-10-20 12:07 - 2018-08-11 15:02 - 000064776 _____ C:\Users\Jára\Downloads\jarča.doc.T6Hd
2019-10-20 12:07 - 2018-08-10 20:40 - 000000000 ___HD C:\Users\Jára\MicrosoftEdgeBackups
2019-10-20 12:07 - 2018-08-10 18:34 - 000038664 _____ C:\Users\Jára\Downloads\CV-J_Zázvorka new aj.doc.T6Hd
2019-10-20 12:07 - 2018-08-10 17:41 - 000000000 ____D C:\Users\Jára\Documents\Adobe
2019-10-20 12:07 - 2018-08-09 18:49 - 000000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2019-10-20 12:07 - 2018-08-09 18:49 - 000000000 ____D C:\Users\Public\Documents\Catch!
2019-10-20 12:07 - 2018-08-09 17:44 - 000000000 ____D C:\Users\Jára\Intel
2019-10-20 12:07 - 2018-08-09 17:31 - 000000000 ___RD C:\Users\Jára\OneDrive
2019-10-20 12:07 - 2018-08-09 17:30 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-10-20 12:06 - 2019-08-26 18:37 - 000002562 _____ C:\Users\Jára\AppData\Roaming\ML.js.RZ5IAvD
2019-10-20 12:06 - 2019-07-21 13:45 - 000000000 ____D C:\Users\defaultuser0
2019-10-20 12:06 - 2019-05-19 11:55 - 000000000 ____D C:\Users\Jára\AppData\Roaming\A Plague Tale Innocence
2019-10-20 12:06 - 2019-04-19 19:14 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2019-10-20 12:06 - 2019-03-25 19:20 - 000000000 ____D C:\Users\Jára\AppData\Roaming\audacity
2019-10-20 12:06 - 2019-03-09 19:04 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome
2019-10-20 12:06 - 2019-03-04 19:33 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Ahead
2019-10-20 12:06 - 2019-02-21 21:50 - 000000396 _____ C:\Users\Jára\AppData\Roaming\Adobe PNG Format CS6 Prefs.IrRq
2019-10-20 12:06 - 2019-02-02 13:30 - 000000000 ____D C:\Users\Jára\AppData\Roaming\TeamViewer
2019-10-20 12:06 - 2019-01-31 22:52 - 000000396 _____ C:\Users\Jára\AppData\Roaming\Adobe IllExport Filter CS6 Prefs.IrRq
2019-10-20 12:06 - 2019-01-22 19:20 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Apple Computer
2019-10-20 12:06 - 2019-01-06 18:14 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Rainmeter
2019-10-20 12:06 - 2019-01-05 00:44 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Native Instruments
2019-10-20 12:06 - 2018-12-27 15:19 - 000000000 ____D C:\RIDE 3
2019-10-20 12:06 - 2018-12-25 16:22 - 000000000 ____D C:\Users\Jára\AppData\Roaming\VitySoft
2019-10-20 12:06 - 2018-12-25 16:22 - 000000000 ____D C:\Users\Jára\.objectdb
2019-10-20 12:06 - 2018-11-08 21:20 - 000000396 _____ C:\Users\Jára\AppData\Roaming\Adobe GIF Format CS6 Prefs.IrRq
2019-10-20 12:06 - 2018-10-27 15:49 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2019-10-20 12:06 - 2018-10-27 14:14 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Ableton
2019-10-20 12:06 - 2018-09-20 21:31 - 000000000 ____D C:\Users\Jára\AppData\Roaming\freac
2019-10-20 12:06 - 2018-09-20 20:56 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3Gain
2019-10-20 12:06 - 2018-08-19 19:12 - 000000000 ____D C:\Users\Jára\AppData\Roaming\ScummVM
2019-10-20 12:06 - 2018-08-18 08:45 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Ulozto File Manager
2019-10-20 12:06 - 2018-08-15 21:49 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2019-10-20 12:06 - 2018-08-15 21:48 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2019-10-20 12:06 - 2018-08-12 19:37 - 000000000 ____D C:\Users\Jára\.QtWebEngineProcess
2019-10-20 12:06 - 2018-08-12 19:37 - 000000000 ____D C:\Users\Jára\.Origin
2019-10-20 12:06 - 2018-08-12 19:34 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Origin
2019-10-20 12:06 - 2018-08-11 16:08 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk
2019-10-20 12:06 - 2018-08-11 16:00 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Autodesk
2019-10-20 12:06 - 2018-08-10 20:40 - 000000000 ___RD C:\Users\Jára\3D Objects
2019-10-20 12:06 - 2018-08-09 21:50 - 000000000 ____D C:\Users\Jára\AppData\Roaming\HD Tune Pro
2019-10-20 12:06 - 2018-08-09 21:30 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Winamp
2019-10-20 12:06 - 2018-08-09 20:55 - 000000000 ____D C:\Users\Jára\AppData\Roaming\NVIDIA
2019-10-20 12:06 - 2018-08-09 20:15 - 000000000 ____D C:\Users\Jára\ansel
2019-10-20 12:06 - 2018-08-09 20:13 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Macromedia
2019-10-20 12:06 - 2018-08-09 18:48 - 000000000 ____D C:\Users\Jára\AppData\Roaming\DAEMON Tools Lite
2019-10-20 12:06 - 2018-08-09 18:42 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2019-10-20 12:06 - 2018-08-09 18:42 - 000000000 ____D C:\totalcmd
2019-10-20 12:06 - 2018-08-09 18:38 - 000000000 ____D C:\Users\Jára\AppData\Local\Adobe
2019-10-20 12:06 - 2018-08-09 18:32 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Sun
2019-10-20 12:06 - 2018-08-09 17:49 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Intel Corporation
2019-10-20 12:06 - 2018-08-09 17:34 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Google
2019-10-20 12:06 - 2018-08-09 17:30 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Adobe
2019-10-20 12:04 - 2019-08-17 22:38 - 000000000 ____D C:\Anthm
2019-10-20 12:04 - 2019-03-19 06:52 - 000000000 ____D C:\PerfLogs
2019-10-20 12:04 - 2019-01-13 10:55 - 000000000 ____D C:\Fliqlo 1.3.3
2019-10-20 12:04 - 2018-08-11 16:05 - 000498501 _____ C:\DSC_4047.JPG.Rx9tDI
2019-10-20 12:04 - 2018-08-11 15:59 - 000000000 ____D C:\Autodesk
2019-10-20 12:04 - 2018-08-09 18:50 - 000000000 __RHD C:\MSOCache
2019-10-20 12:04 - 2016-07-16 14:58 - 000000265 ___SH C:\BOOTNXT.V2kMl1
2019-10-20 12:02 - 2018-08-13 22:04 - 000000000 ____D C:\Program Files (x86)\Steam
2019-10-20 12:02 - 2018-08-12 19:33 - 000000000 ____D C:\ProgramData\Origin
2019-10-19 22:42 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-10-19 22:41 - 2019-07-21 13:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-10-19 22:26 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-10-19 22:26 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-10-19 18:46 - 2018-08-09 18:39 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-10-16 18:36 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF
2019-10-16 18:34 - 2019-07-21 17:56 - 001693846 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-10-16 18:34 - 2019-03-19 13:55 - 000716776 _____ C:\WINDOWS\system32\perfh005.dat
2019-10-16 18:34 - 2019-03-19 13:55 - 000144856 _____ C:\WINDOWS\system32\perfc005.dat
2019-10-16 18:34 - 2018-10-27 14:14 - 000000270 __RSH C:\ProgramData\ntuser.pol
2019-10-16 18:28 - 2019-07-21 13:49 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-10-16 18:28 - 2019-07-21 13:41 - 005543648 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SystemResources
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-10-16 18:28 - 2019-03-19 06:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-10-16 18:26 - 2019-07-21 13:49 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2019-10-16 17:56 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-10-16 17:54 - 2016-07-16 14:58 - 000410822 __RSH C:\bootmgr
2019-10-16 17:38 - 2019-07-20 15:09 - 000000000 ___DC C:\WINDOWS\Panther
2019-10-16 17:38 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-10-16 14:50 - 2018-08-09 17:33 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-10-16 14:44 - 2018-08-12 19:33 - 000000000 ____D C:\Program Files (x86)\Origin
2019-10-13 17:29 - 2019-07-21 13:49 - 000003474 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2019-10-13 17:29 - 2019-07-21 13:49 - 000003350 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2019-10-13 17:29 - 2018-08-09 17:33 - 000000000 ____D C:\Program Files (x86)\Google
2019-10-11 20:24 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2019-10-11 20:24 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2019-10-11 20:24 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-10-11 20:24 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-10-11 20:24 - 2018-08-10 18:16 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-10-09 17:40 - 2018-08-10 18:16 - 127230528 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-10-06 15:57 - 2018-10-29 22:33 - 000001456 _____ C:\Users\Jára\AppData\Local\Adobe Save for Web 13.0 Prefs
2019-10-05 11:28 - 2018-08-10 18:17 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-10-04 15:42 - 2018-08-09 17:30 - 000000000 ____D C:\Users\Jára\AppData\Local\Packages
2019-10-02 20:39 - 2019-07-21 13:49 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2198491196-3933858514-99382068-1001
2019-10-02 20:39 - 2019-07-21 13:45 - 000002364 _____ C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-09-28 20:04 - 2018-08-09 21:15 - 000000000 ____D C:\Program Files\Adobe
2019-09-28 20:04 - 2018-08-09 21:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
2019-09-28 20:04 - 2018-08-09 21:14 - 000000000 ____D C:\Program Files\Common Files\Adobe

==================== Files in the root of some directories ================

2019-10-16 17:33 - 2019-08-26 18:37 - 000002298 _____ () C:\ProgramData\Adobe.js
2019-10-20 12:04 - 2019-10-20 12:04 - 001519616 _____ (G.K.Enterprise) C:\ProgramData\taskhost.exe
2019-05-26 20:23 - 2019-05-26 20:23 - 091905672 _____ (Ableton) C:\Users\Jára\AppData\Roaming\Ableton Live 10 Suite.exe
2018-05-26 19:01 - 2018-05-26 19:01 - 001299362 _____ () C:\Users\Jára\AppData\Roaming\Ableton_KeyGen.exe
2018-11-08 21:20 - 2019-10-20 12:06 - 000000396 _____ () C:\Users\Jára\AppData\Roaming\Adobe GIF Format CS6 Prefs.IrRq
2019-01-31 22:52 - 2019-10-20 12:06 - 000000396 _____ () C:\Users\Jára\AppData\Roaming\Adobe IllExport Filter CS6 Prefs.IrRq
2019-02-21 21:50 - 2019-10-20 12:06 - 000000396 _____ () C:\Users\Jára\AppData\Roaming\Adobe PNG Format CS6 Prefs.IrRq
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ () C:\Users\Jára\AppData\Roaming\DECRYPT-FILES.txt
2019-08-26 18:37 - 2019-10-20 12:06 - 000002562 _____ () C:\Users\Jára\AppData\Roaming\ML.js.RZ5IAvD
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ () C:\Users\Jára\AppData\Roaming\Microsoft\DECRYPT-FILES.txt
2018-10-29 22:33 - 2019-10-06 15:57 - 000001456 _____ () C:\Users\Jára\AppData\Local\Adobe Save for Web 13.0 Prefs

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 12:58
od spd
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-10-2019
Ran by Jára (20-10-2019 13:54:28)
Running from D:\Downloads
Windows 10 Home Version 1903 18362.418 (X64) (2019-07-21 11:49:43)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2198491196-3933858514-99382068-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2198491196-3933858514-99382068-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-2198491196-3933858514-99382068-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-2198491196-3933858514-99382068-501 - Limited - Disabled)
Jára (S-1-5-21-2198491196-3933858514-99382068-1001 - Administrator - Enabled) => C:\Users\Jára
WDAGUtilityAccount (S-1-5-21-2198491196-3933858514-99382068-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 18.05 (x64) (HKLM\...\7-Zip) (Version: 18.05 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (HKLM\...\{5783F2D7-F004-0000-5102-0060B0CE6BBA}) (Version: 7.8.41.0 - Autodesk) Hidden
ACAD Private (HKLM\...\{5783F2D7-F001-0000-3102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.021.20048 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.7.1 64-bit (HKLM\...\{BC86B82C-8C0E-4408-9AC1-6B0F2D636963}) (Version: 5.7.1 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Akamai) (Version: - Akamai Technologies, Inc)
Akamai NetSession Interface (HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\Akamai) (Version: - Akamai Technologies, Inc)
Akamai NetSession Interface (HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\Akamai) (Version: - Akamai Technologies, Inc)
Aktualizace NVIDIA 31.2.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.2.0.0 - NVIDIA Corporation) Hidden
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_HOMESTUDENTR_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_HOMESTUDENTR_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_HOMESTUDENTR_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Apple Mobile Device Support (HKLM\...\{5FA8C4BE-8C74-4B9C-9B49-EBF759230189}) (Version: 12.1.0.25 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft)
Audacity 2.3.1 (HKLM-x32\...\Audacity_is1) (Version: 2.3.1 - Audacity Team)
AutoCAD 2016 – Čeština (Czech) (HKLM\...\{5783F2D7-F001-0405-2102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 (HKLM\...\{5783F2D7-F001-0000-0102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack – Čeština (Czech) (HKLM\...\{5783F2D7-F001-0405-1102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD 2016 – Čeština (Czech) (HKLM\...\AutoCAD 2016 – Čeština (Czech)) (Version: 20.1.49.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM\...\{A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 19.8.2393 - AVAST Software)
Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.57.44284 - Electronic Arts)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.44 - Piriform)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.8.0.0466 - Disc Soft Ltd)
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 399.07 - NVIDIA Corporation) Hidden
Fliqlo Screen Saver (HKLM-x32\...\Fliqlo) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 77.0.3865.120 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.301 - Google LLC) Hidden
HD Tune Pro 5.50 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software)
Import souborů SketchUp 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) Network Connections 21.1.29.0 (HKLM\...\PROSetDX) (Version: 21.1.29.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.2.0.1020 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden
iTunes (HKLM\...\{288617D6-B455-4C00-8BFE-46B023202CF1}) (Version: 12.9.2.6 - Apple Inc.)
Java 8 Update 181 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
K-Lite Codec Pack 14.3.6 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.3.6 - KLCP)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
Malwarebytes verze 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\OneDriveSetup.exe) (Version: 19.152.0927.0012 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\...\OneDriveSetup.exe) (Version: 19.152.0927.0012 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\...\OneDriveSetup.exe) (Version: 19.152.0927.0012 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
MSI Afterburner 4.5.0 (HKLM-x32\...\Afterburner) (Version: 4.5.0 - MSI Co., LTD)
Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: 2.4.0.445 - Native Instruments)
Native Instruments Native Access (HKLM-x32\...\Native Instruments Native Access) (Version: 1.12.0.120 - Native Instruments)
Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: 2.5.2.1549 - Native Instruments)
Native Instruments Traktor Audio 10 Driver (HKLM-x32\...\Native Instruments Traktor Audio 10 Driver) (Version: - Native Instruments)
Native Instruments Traktor Audio 2 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Audio 2 MK2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Audio 6 Driver (HKLM-x32\...\Native Instruments Traktor Audio 6 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol D2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol D2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol F1 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol F1 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol S2 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S2 MK2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol S4 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S4 MK2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol S5 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S5 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol S8 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S8 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol X1 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol X1 MK2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol Z1 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol Z1 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol Z2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol Z2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Pro 3 (HKLM-x32\...\Native Instruments Traktor Pro 3) (Version: 3.2.0.60 - Native Instruments)
Nero 7 Essentials (HKLM-x32\...\{3BDEE284-1516-40E8-B784-00FEBE1B1029}) (Version: 7.02.9769 - Nero AG)
NVIDIA GeForce Experience 3.14.1.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.14.1.48 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 399.07 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 399.07 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 399.07 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 399.07 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 10.5.50.31938 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 399.07 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 399.07 - NVIDIA Corporation) Hidden
PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Podpora aplikací Apple (32bitová) (HKLM-x32\...\{80B42CAA-28C0-4FBD-A46E-D61F45E2F9FC}) (Version: 7.2 - Apple Inc.)
Podpora aplikací Apple (64bitová) (HKLM\...\{466D00D0-E7DE-47C2-8FE5-54A8009F5850}) (Version: 7.2 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.2 r3111 - Rainmeter)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7960 - Realtek Semiconductor Corp.)
RIDE 3 (HKLM-x32\...\RIDE 3_is1) (Version: - )
RivaTuner Statistics Server 7.1.0 (HKLM-x32\...\RTSS) (Version: 7.1.0 - Unwinder)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.2.1.1780 - Samsung Electronics)
Speciální aplikace Autodesk 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.20 - Ghisler Software GmbH)
Ulož.to FileManager verze 2.71 (HKLM-x32\...\{7DE5EA5D-C933-4549-9A44-5BC671F23BBF}_is1) (Version: 2.71 - Uloz.to cloud a.s.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 85.1 - Ubisoft)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.2.0_x64__tf1gferkr813w [2019-05-28] (Autodesk Inc.)
Avee Player -> C:\Program Files\WindowsApps\11314DaawAww.AveePlayer_0.8.25.0_x64__3mhsykt1m20fj [2019-06-30] (Daaw Aww) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-03] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-03] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-12] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.10022.0_x64__8wekyb3d8bbwe [2019-10-09] (Microsoft Studios) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-12] (Microsoft Corporation) [MS Ad]
Pošta a Kalendář -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe [2019-09-25] (Microsoft Corporation) [MS Ad]
WiFi Analyzer -> C:\Program Files\WindowsApps\19965MattHafner.WifiAnalyzer_2.4.1.0_x64__gs5k5vmxr2ste [2019-01-28] (Matt Hafner)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\cs-CZ\acadficn.dll (Autodesk Development Sarl -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\cs-CZ\acadficn.dll (Autodesk Development Sarl -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\cs-CZ\acadficn.dll (Autodesk Development Sarl -> Autodesk, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc -> Autodesk, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2015-02-06] (Autodesk, Inc -> Autodesk)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-08-21] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)

==================== Codecs (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Hudba Google Play.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=fahmaaghhglfmonjliepjlchgpgfmobi

==================== Loaded Modules (Whitelisted) ==============

2018-08-12 19:35 - 2018-08-12 19:35 - 000266240 _____ () [File not signed] C:\Program Files (x86)\Origin\imageformats\qmng.dll
2018-08-12 19:36 - 2019-10-16 14:44 - 000015360 _____ () [File not signed] C:\Program Files (x86)\Origin\libEGL.DLL
2018-08-12 19:36 - 2019-10-16 14:44 - 003090944 _____ () [File not signed] C:\Program Files (x86)\Origin\libGLESv2.dll
2019-10-16 17:21 - 2019-10-16 17:21 - 004577280 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DiscSoft.NET.Common\748526c8af5cbbb2a41b3a507dc50d2b\DiscSoft.NET.Common.ni.dll
2019-10-16 17:22 - 2019-10-16 17:22 - 003113984 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DotNetCommon\73c67d70ca118cf8cd4d422c3e078538\DotNetCommon.ni.dll
2018-08-09 20:19 - 2018-04-30 14:00 - 000075776 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2016-08-24 16:54 - 2016-08-24 16:54 - 000352256 _____ (Intel(R) Corporation) [File not signed] C:\Windows\system32\NCS2Setp.dll
2003-03-19 08:14 - 2003-03-19 08:14 - 000499712 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Ahead\Lib\MSVCP71.dll
2003-02-21 16:42 - 2003-02-21 16:42 - 000348160 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Ahead\Lib\MSVCR71.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000002560 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Origin\icudt58.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 001252864 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Origin\icuuc58.dll
2011-09-30 00:19 - 2019-10-16 14:44 - 001277440 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2011-09-30 00:19 - 2019-10-16 14:44 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000030208 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qgif.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000032768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qico.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000256512 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qjpeg.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000026112 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qtga.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000305152 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qtiff.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000025600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qwbmp.dll
2018-08-12 19:35 - 2019-10-16 14:44 - 000278016 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\mediaservice\dsengine.dll
2018-08-12 19:35 - 2019-10-16 14:44 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000709120 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Multimedia.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000207360 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Positioning.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000310272 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5PrintSupport.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 003513344 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Qml.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 003390976 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Quick.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000068096 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5QuickWidgets.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000045568 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5TextToSpeech.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 054071296 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineCore.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000211456 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineWidgets.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000116224 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebChannel.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Jára\AppData\Local\Temp:p3vyxxFKbHMUTlBeESOOs6v0LSl [2324]
AlternateDataStreams: C:\Users\Jára\AppData\Local\Temp:zIvvyMRqgrVZibULbcQllH [1874]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-2198491196-3933858514-99382068-1001\Software\Classes\.scr: AutoCADScriptFile =>

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 13:47 - 2018-08-09 21:16 - 000001028 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155154\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132216956\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155184\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217091\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2198491196-3933858514-99382068-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155206\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2198491196-3933858514-99382068-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217117\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jára\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132155240\Control Panel\Desktop\\Wallpaper -> C:\Users\Jára\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019132217165\Control Panel\Desktop\\Wallpaper -> C:\Users\Jára\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Prompt)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{00FFEB82-B36E-4896-B6F1-6D6BFD410751}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed Unity\ACU.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{E05A0731-091A-4577-8A47-40013E13C2B1}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed Unity\ACU.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{53F55780-A40F-42FB-9CB8-F9BF3F3A2822}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{9F178EDD-A60C-4BFC-BE62-2F305BEFBA17}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{C900961E-EEEB-4883-BFEB-74615503C6E3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{E9DC7EBA-F611-4C3C-BF24-96A8523CE0D0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{219C649D-3B9E-445F-9A96-130F8106F9C7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{FD70FFC2-B31D-4BE9-A660-616CC8F87BC7}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [UDP Query User{46057512-9977-4A76-A89B-50AC7932D001}C:\program files (x86)\java\jre1.8.0_181\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_181\bin\javaw.exe
FirewallRules: [TCP Query User{97FE3F12-73C8-453D-9C82-A534AE2DBFDA}C:\program files (x86)\java\jre1.8.0_181\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_181\bin\javaw.exe
FirewallRules: [UDP Query User{5A9AD9D2-0150-469C-B6B4-901833E2BA42}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe (Ghisler Software GmbH -> Ghisler Software GmbH)
FirewallRules: [TCP Query User{655E7A26-F5C7-4C1D-8D86-B0B1C406052D}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe (Ghisler Software GmbH -> Ghisler Software GmbH)
FirewallRules: [{B642819E-6B15-462F-B7FC-340566A8433C}] => (Allow) D:\Games\Battlefield 1\bf1.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{E3DBF10C-CD65-40DD-8751-399B8FE3C22D}] => (Allow) D:\Games\Battlefield 1\bf1.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{C782D87E-0976-4B94-94CE-8FF1A74E77C6}] => (Allow) D:\Games\Battlefield 1\bf1Trial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{FF570B08-0D4F-42C5-A240-0638D5A137A5}] => (Allow) D:\Games\Battlefield 1\bf1Trial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{5B95A06F-9954-45AD-91D5-53496E9FC0BF}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{0F38C613-1657-43DC-B4FF-7B61636BE387}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{7B42067D-2FE7-4660-91D1-2D6113F7AEC1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{8EDA95C4-D85F-4CFF-819F-4A3DFCF54DE5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{5DD984D4-14CF-4A5F-9265-8BB4132F3283}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{D4554F65-1108-4103-B1D0-8963FA3B93A7}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{BDCC96C5-1F6F-425E-A045-1C5149F1C8C2}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{06F3DFC4-0A5A-4C66-81CE-749BCE731DB9}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{EAC339DC-9E20-41C9-9A8A-260CE07BF8A0}] => (Allow) LPort=50248
FirewallRules: [{EF37EF61-FDF0-43CC-9DD6-F9C122F3E5E4}] => (Allow) LPort=5000
FirewallRules: [{81DE9916-8271-49B8-964D-103301F15091}] => (Allow) LPort=52713
FirewallRules: [UDP Query User{0382C8D4-A6CE-4F9C-8433-D2F5E1FB00BD}C:\users\jára\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jára\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [TCP Query User{0FCB6E4F-F755-4007-A909-16211AEA07C7}C:\users\jára\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jára\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [{A8A3BEE0-EA57-42BB-A61B-91CE1CB4288D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{AD51AFCD-3944-4B20-BBF6-E332BD23C80A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{EA75AE62-CF3B-4798-975D-6DE1BDC0B996}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{49290636-537F-4855-BA72-2DBA0C17A17D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{2AA899C5-916D-4579-9674-3E2A93ECFB80}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{215435AD-7556-48B2-A4FC-510A00C1F210}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{940E7A06-9E8C-4971-94CD-A42DE5B1447C}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{C7416877-BD85-44F5-AC7C-9D23C8E4C7A0}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{D1B35F12-A113-4CF5-8359-42361778C9A8}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{6A2FA1CE-277B-4338-A574-5D9960DB62FD}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{82B4524F-CC78-4030-9957-CAEA2C761C25}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{49364918-FA0E-477C-BD35-DC50155C2BB8}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

05-10-2019 11:21:06 Windows Update
09-10-2019 17:39:57 Windows Update
14-10-2019 20:49:21 Windows Update
16-10-2019 17:10:38 Installed Ableton Live 10 Suite
20-10-2019 13:51:37 Removed Ableton Live 9 Suite

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/20/2019 01:59:20 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (7716,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 01:29:17 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5352,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 01:06:41 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1868,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 12:46:25 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (12704,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 12:12:30 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (14696,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/19/2019 10:31:49 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (11760,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/19/2019 09:40:21 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (14548,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/19/2019 09:25:48 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (15108,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).


System errors:
=============
Error: (10/16/2019 08:44:11 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-41PK4RC)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/16/2019 06:28:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Autodesk Content Service neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/16/2019 06:28:38 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Autodesk Content Service bylo dosaženo časového limitu (45000 ms).

Error: (10/16/2019 06:27:49 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-41PK4RC)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/16/2019 06:27:49 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-41PK4RC)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/16/2019 06:27:49 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-41PK4RC)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/16/2019 06:27:49 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-41PK4RC)
Description: Server {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/16/2019 05:38:42 PM) (Source: DCOM) (EventID: 10000) (User: DESKTOP-41PK4RC)
Description: Nelze spustit server DCOM: {0358B920-0AC7-461F-98F4-58E32CD89148}. Došlo k chybě:
2147942767
při provádění příkazu:
C:\WINDOWS\system32\DllHost.exe /Processid:{3EB3C877-1F16-487C-9050-104DBCD66683}


Windows Defender:
===================================
Date: 2019-10-19 21:21:46.492
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {93F28B6A-B02D-48AC-8BF5-B7E579159295}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-10-19 18:42:54.710
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Program:Win32/Unwaders.A!ml
ID: 242872
Závažnost: Vážné
Kategorie: Potenciálně nežádoucí software
Cesta: amsi:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Původ detekce: Neznámý
Typ detekce: FastPath
Zdroj detekce: AMSI
Uživatel: DESKTOP-41PK4RC\Jára
Název procesu: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Verze bezpečnostních informací: AV: 1.305.51.0, AS: 1.305.51.0, NIS: 1.305.51.0
Verze modulu: AM: 1.1.16500.1, NIS: 1.1.16500.1

Date: 2019-10-18 17:41:28.251
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {D958AD70-D015-4DB9-97EB-A1AF71046704}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-10-18 16:07:41.282
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Fuery.B!cl
ID: 2147718514
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: amsi:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Původ detekce: Neznámý
Typ detekce: FastPath
Zdroj detekce: AMSI
Uživatel: DESKTOP-41PK4RC\Jára
Název procesu: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Verze bezpečnostních informací: AV: 1.303.1818.0, AS: 1.303.1818.0, NIS: 1.303.1818.0
Verze modulu: AM: 1.1.16400.2, NIS: 1.1.16400.2

Date: 2019-10-16 19:52:18.248
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Wacatac.B!ml
ID: 2147735505
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\Jára\AppData\Roaming\test_2.exe
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Ochrana v reálném čase
Uživatel: DESKTOP-41PK4RC\Jára
Název procesu: C:\Windows\SysWOW64\cmd.exe
Verze bezpečnostních informací: AV: 1.303.1818.0, AS: 1.303.1818.0, NIS: 1.303.1818.0
Verze modulu: AM: 1.1.16400.2, NIS: 1.1.16400.2

Date: 2019-10-11 11:44:30.158
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.1283.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80240016
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2019-09-12 15:43:25.975
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.301.783.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16300.1
Kód chyby: 0x80240016
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

CodeIntegrity:
===================================

Date: 2019-10-20 13:28:09.876
Description:
Windows blocked file \Device\HarddiskVolume2\Windows\System32\scrobj.dll which has been disallowed for protected processes.

Date: 2019-10-20 12:42:11.536
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-10-20 12:42:11.528
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-10-20 12:42:11.516
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-10-20 12:42:11.507
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-10-20 12:42:11.487
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-10-20 12:40:36.553
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.1909.6-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2019-10-20 12:40:36.536
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\ProgramData\Microsoft\Windows Defender\Platform\4.18.1909.6-0\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

==================== Memory info ===========================

BIOS: American Megatrends Inc. F9 04/10/2018
Motherboard: Gigabyte Technology Co., Ltd. B250M-D3H-CF
Processor: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
Percentage of memory in use: 44%
Total physical RAM: 16344.07 MB
Available physical RAM: 9106.55 MB
Total Virtual: 18776.07 MB
Available Virtual: 9281.9 MB

==================== Drives ================================

Drive c: (SYSTEM) (Fixed) (Total:209.07 GB) (Free:65.56 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DATA01) (Fixed) (Total:465.76 GB) (Free:38.2 GB) NTFS
Drive j: (SPD) (Removable) (Total:14.62 GB) (Free:13.37 GB) FAT32

\\?\Volume{8bbafdf9-0000-0000-0000-604434000000}\ () (Fixed) (Total:0.53 GB) (Free:0.08 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 232.9 GB) (Disk ID: 8BBAFDF9)
Partition 1: (Active) - (Size=209.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=539 MB) - (Type=27)

========================================================
Disk: 2 (Size: 14.6 GB) (Disk ID: 9B46E07D)
Partition 1: (Not Active) - (Size=14.6 GB) - (Type=0C)

==================== End of Addition.txt ============================

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 14:11
od Rudy
Zdravím!
PC vám vyčistit můžeme, ale soubory nedešifrujeme. K tomu je třeba přímý přístup do PC a ten nemáme právně ošetřen. Pokud mají kolegové k dispozici dešfrovací klíč, obraťte se sem: https://neslape.cz/?utm_campaign=neslap ... ium=banner .

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 14:51
od spd
S tím počítám. Jde mi jen o to ransomware zastavit a smazat. Přijde mi že šifruje víc a víc souborů.

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 16:00
od Rudy
OK. Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 16:58
od spd
# -------------------------------
# Malwarebytes AdwCleaner 7.4.1.0
# -------------------------------
# Build: 09-04-2019
# Database: 2019-10-17.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 10-20-2019
# Duration: 00:00:01
# OS: Windows 10 Home
# Cleaned: 11
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

Deleted Hover Zoom
Deleted noajmlkipclmeolfcnflkjhijkigpfjh
Deleted pelmeidfhdlhlbjimpabfcbnnojbboma

***** [ Chromium URLs ] *****

Deleted http://istart.webssearches.com/?type=hp ... 1069300077
Deleted http://istart.webssearches.com/?type=hp ... 1069300077
Deleted http://www.delta-homes.com/?type=hp&ts= ... 1069300077
Deleted http://www.delta-homes.com/?type=hp&ts= ... 1069300077
Deleted http://www.delta-homes.com/?type=hp&ts= ... 1069300077
Deleted http://www.delta-homes.com/?type=hp&ts= ... 1069300077
Deleted http://www.delta-homes.com/?type=hp&ts= ... 1069300077
Deleted http://www.delta-homes.com/?type=hp&ts= ... 1069300077

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner_Debug.log - [20712 octets] - [20/10/2019 17:53:33]
AdwCleaner[S00].txt - [2745 octets] - [20/10/2019 17:56:53]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 17:49
od Rudy
Dejte nové logy FRST+Addition.

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 18:11
od spd
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-10-2019
Ran by Jára (administrator) on DESKTOP-41PK4RC (Gigabyte Technology Co., Ltd. B250M-D3H) (20-10-2019 19:04:16)
Running from D:\Downloads
Loaded Profiles: Jára (Available Profiles: defaultuser0 & Jára)
Platform: Windows 10 Home Version 1903 18362.418 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Inc. -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Akamai Technologies, Inc. -> Akamai Technologies, Inc.) C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc. -> Akamai Technologies, Inc.) C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Autodesk, Inc -> Autodesk Inc.) C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe
(Autodesk, Inc -> Autodesk Inc.) C:\Users\Jára\AppData\Local\Autodesk\.AdskAppManager\R1\AdAppMgr.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTAgent.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe
(Electronic Arts, Inc. -> ) C:\Program Files (x86)\Origin\QtWebEngineProcess.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe
(Electronic Arts, Inc. -> Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Even Balance, Inc. -> ) C:\Windows\SysWOW64\PnkBstrA.exe
(Intel(R) Network Platform Group -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel(R) Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Users\Jára\AppData\Local\Microsoft\OneDrive\OneDrive.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11910.1001.5.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19092.399.0_x64__8wekyb3d8bbwe\YourPhone.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Native Instruments GmbH -> Native Instruments GmbH) C:\Program Files\Common Files\Native Instruments\Hardware\NIHardwareService.exe
(Nero AG -> Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Realtek Semiconductor Corp. -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Samsung Electronics Co., Ltd. -> Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Shenzhen Yi Xing Investment Co., Ltd. -> Iskysoft) C:\Program Files (x86)\iSkysoft\IAF\2.4.3.241\IsAppClient.exe
(Shenzhen Yi Xing Investment Co., Ltd. -> Iskysoft) C:\Program Files (x86)\iSkysoft\IAF\2.4.3.241\IsAppService.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.85.0_x64__kzf8qxf38zg5c\SkypeApp.exe
(Skype) C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.53.85.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9037832 2016-10-21] (Realtek Semiconductor Corp. -> Realtek Semiconductor)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320568 2016-09-20] (Intel(R) Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [301880 2018-11-15] (Apple Inc. -> Apple Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [268680 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
HKLM-x32\...\Run: [ADSKAppManager] => C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgr.exe [529480 2016-02-24] (Autodesk, Inc -> Autodesk Inc.)
HKU\S-1-5-18-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412551\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412631\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518656 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [729704 2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [Akamai NetSession Interface] => C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe [4586456 2018-04-17] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3211040 2019-10-02] (Valve -> Valve Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3115792 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [148776 2007-07-04] (Nero AG -> Nero AG)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Fliqlo.scr [679936 2019-01-13] (ScreenTime Media) [File not signed]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [729704 2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [Akamai NetSession Interface] => C:\Users\Jára\AppData\Local\Akamai\netsession_win.exe [4586456 2018-04-17] (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3211040 2019-10-02] (Valve -> Valve Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [EADM] => C:\Program Files (x86)\Origin\Origin.exe [3115792 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [148776 2007-07-04] (Nero AG -> Nero AG)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Policies\Explorer: []
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Fliqlo.scr [679936 2019-01-13] (ScreenTime Media) [File not signed]
HKU\S-1-5-18\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18385368 2018-06-24] (Piriform Ltd -> Piriform Ltd)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\77.0.3865.120\Installer\chrmstp.exe [2019-10-16] (Google LLC -> Google LLC)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT-FILES.txt [2019-10-20] () [File not signed]
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT-FILES.txt [2019-10-20] () [File not signed]
Startup: C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DECRYPT-FILES.txt [2019-10-20] () [File not signed]
Startup: C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk [2019-01-06]
ShortcutTarget: Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (Firebit OU -> Rainmeter)
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {01719E40-9736-43B0-AAFA-049AE151F044} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-09] (Google Inc -> Google Inc.)
Task: {1C679054-3617-4E40-B2FF-98F35B6C25E7} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [982568 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {2E585DCB-C7E5-45D7-90A9-C8F7B3FC7807} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1240656 2019-09-10] (Adobe Inc. -> Adobe Systems)
Task: {3C0D5580-4D8E-414B-B6E0-1C852B5C5C3C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [619416 2019-02-04] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {3FE3A18A-C661-43AB-80B2-2A939DCB2D0E} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [764456 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {46BA238E-7A56-410A-8405-75421E5D2BE1} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [856616 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {57A8576F-99CC-45CA-A2FB-EDF55BA3AEAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-09] (Google Inc -> Google Inc.)
Task: {5F6A125B-E1E9-4321-9219-E82A92AA3963} - System32\Tasks\NvTmRepCR3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [927272 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {604A86D9-2564-4A49-9F5F-FF3960C7D54D} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [647720 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {66F70C81-7AEE-48C2-9906-BA83B12EA8A8} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3297832 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8253FA6C-44DD-4439-9FC6-EC607FC4E344} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [927272 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {8370E573-BF6E-4644-9C64-67A767CDA919} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1873288 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
Task: {B7A4AB13-2CEF-4524-B3C4-90E2FB46725C} - System32\Tasks\NvTmRepCR1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [927272 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {B88FC8D9-9B43-4E02-B7FC-C6F8A393D980} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [856616 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {BA9B36C1-1883-4631-80FF-25633223F225} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3933576 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
Task: {BB94C5B0-DBC2-4FB1-A40D-B5371648E31E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [13594584 2018-06-24] (Piriform Ltd -> Piriform Ltd)
Task: {C16C15F6-65E8-47B5-B5F4-BC7E25E9F31E} - System32\Tasks\klcp_update => CodecTweakTool.exe
Task: {C81A91DB-F55F-4FB1-A392-05814F57F6C3} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [1146048 2018-05-28] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co. Ltd.)
Task: {CF71B687-E5F7-4DD9-BD9E-A2D644131FB7} - System32\Tasks\AdobeAAMUpdater-1.0-DESKTOP-41PK4RC-Jára => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated -> Adobe Systems Incorporated)
Task: {D7FC1A64-A007-4A2A-9DB6-D53429219612} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [764456 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {EB75CAE2-7719-4C7C-8FC9-9226DA379B5E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616320 2018-01-08] (Apple Inc. -> Apple Inc.)
Task: {FE7D350D-0393-4546-9D31-531F777C33F5} - System32\Tasks\NvTmRepCR2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [927272 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{c87d4fa6-45ad-42b4-8a8e-c5a1caf63c62}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{cd19de96-a514-4b49-974a-742b7e1a1e45}: [DhcpNameServer] 192.168.0.1

Internet Explorer:
==================
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\ssv.dll [2018-08-09] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\jp2ssv.dll [2018-08-09] (Oracle America, Inc. -> Oracle Corporation)

FireFox:
========
FF Plugin-x32: @java.com/DTPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\dtplugin\npDeployJava1.dll [2018-08-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.181.2 -> C:\Program Files (x86)\Java\jre1.8.0_181\bin\plugin2\npjp2.dll [2018-08-09] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-08-21] (NVIDIA Corporation -> NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-08-21] (NVIDIA Corporation -> NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.35.301\npGoogleUpdate3.dll [2019-10-13] (Google Inc -> Google LLC)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.35.301\npGoogleUpdate3.dll [2019-10-13] (Google Inc -> Google LLC)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2019-10-11] (Adobe Inc. -> Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.seznam.cz/ ... oogle.com/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default [2019-10-20]
CHR DownloadDir: D:\Downloads
CHR Extension: (Prezentace) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-08-09]
CHR Extension: (Dokumenty) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-08-09]
CHR Extension: (Disk Google) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-10-25]
CHR Extension: (YouTube) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-08-09]
CHR Extension: (Photo Zoom for Facebook) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\elioihkkcdgakfbahdoddophfngopipi [2018-08-09]
CHR Extension: (Hudba Google Play) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2019-03-09]
CHR Extension: (Tabulky) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-08-09]
CHR Extension: (Dokumenty Google offline) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-09]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]
CHR Extension: (Hover Zoom) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl [2019-10-20]
CHR Extension: (Picasa) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\onlgmecjpnejhfeofkgbfgnmdlipdejb [2018-08-09]
CHR Extension: (Gmail) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-30]
CHR Extension: (Chrome Media Router) - C:\Users\Jára\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2019-09-27]
CHR Profile: C:\Users\Jára\AppData\Local\Google\Chrome\User Data\System Profile [2019-04-26]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Common Files\Autodesk Shared\AppManager\R1\AdAppMgrSvc.exe [1145928 2016-02-24] (Autodesk, Inc -> Autodesk Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [85304 2018-10-16] (Apple Inc. -> Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6085360 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
S2 Autodesk Content Service; C:\Program Files\Autodesk\Content Service\Connect.Service.ContentService.exe [31160 2015-02-05] (Autodesk, Inc -> Autodesk, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [996880 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [3606632 2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 IsAppService; C:\Program Files (x86)\Iskysoft\IAF\2.4.3.241\IsAppService.exe [495240 2018-07-26] (Shenzhen Yi Xing Investment Co., Ltd. -> Iskysoft)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S4 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [267560 2007-07-04] (Nero AG -> Nero AG)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [764456 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [764456 2018-07-19] (NVIDIA Corporation -> NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2348336 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3228976 2019-10-16] (Electronic Arts, Inc. -> Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [76152 2018-08-13] (Even Balance, Inc. -> )
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Test Signing Certificate -> Adobe Systems Incorporated) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\NisSrv.exe [3004048 2019-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1909.6-0\MsMpEng.exe [103384 2019-10-05] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AppleKmdfFilter; C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys [20640 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
S3 AppleLowerFilter; C:\WINDOWS\System32\drivers\AppleLowerFilter.sys [35560 2018-05-10] (WDKTestCert build,131474841775766162 -> Apple Inc.)
R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37616 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [204824 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [274456 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [209552 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [65120 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2019-10-20] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [276952 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42736 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [171520 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110320 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [83792 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848432 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [460448 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [236024 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316528 2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2018-08-09] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2018-08-09] (Disc Soft Ltd -> Disc Soft Ltd)
S3 gdrv; C:\Windows\gdrv.sys [26192 2018-08-09] (Giga-Byte Technology -> Windows (R) Server 2003 DDK provider)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [275232 2019-10-20] (Malwarebytes Corporation -> Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_f5be1f8d25335236\nvlddmkm.sys [17212744 2018-08-22] (NVIDIA Corporation -> NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30656 2018-07-12] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [69544 2018-06-08] (NVIDIA Corporation -> NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [65792 2018-08-21] (NVIDIA Corporation -> NVIDIA Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46688 2019-10-05] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [350136 2019-10-05] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54200 2019-10-05] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-10-20 18:58 - 2019-10-20 18:58 - 000000000 ____D C:\Users\Jára\Desktop\Recovered data 10-20 18_58_36
2019-10-20 18:58 - 2019-10-20 18:58 - 000000000 ____D C:\Users\Jára\Desktop\Recovered data 10-20 18_58_17
2019-10-20 18:55 - 2019-10-20 18:55 - 000000000 ____D C:\Users\Jára\Desktop\Recovered data 10-20 18_55_55
2019-10-20 18:54 - 2019-10-20 18:54 - 000000000 ____D C:\Users\Jára\Desktop\Nová složka
2019-10-20 18:53 - 2019-10-20 18:53 - 000000000 ____D C:\ProgramData\SystemAcCrux
2019-10-20 18:52 - 2019-10-20 18:52 - 043264592 _____ (EaseUS ) C:\Users\Jára\Desktop\DRW_freeRSS_easeus.exe
2019-10-20 18:52 - 2019-10-20 18:52 - 000001080 _____ C:\Users\Public\Desktop\EaseUS Data Recovery Wizard.lnk
2019-10-20 18:52 - 2019-10-20 18:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EaseUS Data Recovery Wizard
2019-10-20 18:51 - 2019-10-20 18:51 - 035106894 _____ C:\Users\Jára\Desktop\EaseUS Data Recovery Wizard 11.8.0.rar
2019-10-20 18:51 - 2019-09-22 13:27 - 001545472 _____ C:\Users\Jára\Desktop\DRW_Free_RSS_Installer_20190922.153.exe
2019-10-20 18:51 - 2019-09-22 12:47 - 000219497 _____ C:\Users\Jára\Desktop\EaseUSDataRecoveryWizard1180CZ.zip
2019-10-20 18:51 - 2019-09-22 12:44 - 032692536 _____ (EaseUS ) C:\Users\Jára\Desktop\drw_free.exe
2019-10-20 18:47 - 2019-10-20 18:47 - 000000000 ____D C:\Program Files\EaseUS
2019-10-20 18:46 - 2019-10-20 18:46 - 000000000 ____D C:\Users\Jára\Desktop\EaseUS Data Recovery Wizard v9.8.0 (Professional, Technician, AdvancedPE)
2019-10-20 18:32 - 2019-10-20 18:32 - 000000000 ____D C:\Users\Jára\AppData\Roaming\www.shadowexplorer.com
2019-10-20 18:31 - 2019-10-20 18:31 - 000000000 ____D C:\Users\Jára\Desktop\ShadowExplorerPortable-0.9
2019-10-20 18:27 - 2019-10-20 18:27 - 000000000 ____D C:\ProgramData\Wondershare
2019-10-20 18:25 - 2019-10-20 18:25 - 000001387 _____ C:\Users\Public\Desktop\iSkysoft Data Recovery.lnk
2019-10-20 18:25 - 2019-10-20 18:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSkysoft
2019-10-20 18:25 - 2019-10-20 18:25 - 000000000 ____D C:\ProgramData\iSkysoft
2019-10-20 18:25 - 2019-10-20 18:25 - 000000000 ____D C:\Program Files (x86)\iSkysoft
2019-10-20 18:25 - 2017-09-27 17:29 - 000000232 _____ C:\WINDOWS\SysWOW64\dllhost.exe.config
2019-10-20 18:24 - 2019-10-20 18:26 - 000000000 ____D C:\Users\Public\Documents\iSkysoft
2019-10-20 18:00 - 2019-10-20 18:00 - 000275232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2019-10-20 17:53 - 2019-10-20 17:59 - 000000000 ____D C:\AdwCleaner
2019-10-20 17:53 - 2019-10-20 17:53 - 007622344 _____ (Malwarebytes) C:\Users\Jára\Desktop\AdwCleaner.exe
2019-10-20 17:49 - 2019-10-20 18:01 - 000000000 ____D C:\Users\Jára\AppData\Local\CrashDumps
2019-10-20 17:48 - 2019-10-20 17:48 - 000000020 ___SH C:\Users\Jára\ntuser.ini
2019-10-20 14:07 - 2019-10-20 14:07 - 000000000 ___HD C:\$AV_ASW
2019-10-20 13:32 - 2019-10-20 19:05 - 000000000 ____D C:\FRST
2019-10-20 13:20 - 2019-10-20 13:20 - 066367928 _____ (Malwarebytes ) C:\Users\Jára\Desktop\mb3-setup-37469.37469-3.8.3.2965-1.0.627-1.0.12633.exe
2019-10-20 13:20 - 2019-10-20 13:20 - 000001918 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\Users\Jára\AppData\Local\mbamtray
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\Users\Jára\AppData\Local\mbam
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\ProgramData\Malwarebytes
2019-10-20 13:20 - 2019-10-20 13:20 - 000000000 ____D C:\Program Files\Malwarebytes
2019-10-20 13:20 - 2019-08-27 05:50 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2019-10-20 13:20 - 2019-06-26 13:00 - 000020936 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2019-10-20 12:41 - 2019-10-20 12:41 - 000002166 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2019-10-20 12:41 - 2019-10-20 12:41 - 000002154 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2019-10-20 12:41 - 2019-10-20 12:41 - 000000000 ____D C:\Users\Jára\AppData\Roaming\AVAST Software
2019-10-20 12:40 - 2019-10-20 12:40 - 000848432 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000460448 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000355720 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2019-10-20 12:40 - 2019-10-20 12:40 - 000316528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000276952 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000274456 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000236024 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000209552 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000204824 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000171520 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000110320 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000083792 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000065120 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000042736 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000037616 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000016304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys
2019-10-20 12:40 - 2019-10-20 12:40 - 000003990 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2019-10-20 12:40 - 2019-10-20 12:40 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2019-10-20 12:40 - 2019-10-20 12:40 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
2019-10-20 12:39 - 2019-10-20 12:40 - 000000000 ____D C:\ProgramData\AVAST Software
2019-10-20 12:39 - 2019-10-20 12:39 - 000000000 ____D C:\Program Files\AVAST Software
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Public\Downloads\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Public\Documents\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Public\Desktop\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Public\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Jára\Downloads\DECRYPT-FILES.txt
2019-10-20 12:07 - 2019-10-20 12:07 - 000009524 _____ C:\Users\Jára\Documents\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\Desktop\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\AppData\Roaming\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Jára\AppData\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\Downloads\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\Documents\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\Desktop\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\AppData\Roaming\Microsoft\Windows\Start Menu\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\AppData\Roaming\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\defaultuser0\AppData\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\Downloads\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\Documents\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\Desktop\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\AppData\Roaming\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default\AppData\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\Downloads\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\Documents\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\Desktop\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\AppData\Roaming\DECRYPT-FILES.txt
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ C:\Users\Default User\AppData\DECRYPT-FILES.txt
2019-10-20 12:04 - 2019-10-20 12:04 - 000009524 _____ C:\Users\DECRYPT-FILES.txt
2019-10-20 12:04 - 2019-10-20 12:04 - 000009524 _____ C:\DECRYPT-FILES.txt
2019-10-20 12:04 - 2019-10-20 12:04 - 000000265 _____ C:\ProgramData\0x29A.db
2019-10-19 21:06 - 2019-10-20 12:06 - 000000000 ____D C:\Users\Jára\Desktop\Chase & Status - RTRN II JUNGLE (2019) [MP3.CBR.320] [Move-MAG]
2019-10-19 21:05 - 2019-10-20 12:07 - 032715846 _____ C:\Users\Jára\Desktop\Kemal & Rob Data - Star Trails (Synergy Bootleg).wav.vewGg8
2019-10-19 21:05 - 2019-10-20 12:06 - 013987502 _____ C:\Users\Jára\Desktop\01 No More.mp3.AStcNA9
2019-10-19 21:05 - 2019-10-20 12:06 - 012313641 _____ C:\Users\Jára\Desktop\02 If You.mp3.M4OLQ
2019-10-19 21:04 - 2019-10-20 12:07 - 012098214 _____ C:\Users\Jára\Desktop\M.mp3.lBLk
2019-10-19 21:03 - 2019-10-20 12:07 - 010704997 _____ C:\Users\Jára\Desktop\Phibes - M-Beat Feat General Levy (Phibes Remix).mp3.inIz
2019-10-19 20:58 - 2019-10-20 12:07 - 010878016 _____ C:\Users\Jára\Desktop\Phibes - Breathe.mp3.uskm
2019-10-19 20:57 - 2019-10-20 12:07 - 012331205 _____ C:\Users\Jára\Desktop\Phibes - Hustlin.mp3.oxtrA
2019-10-19 20:56 - 2019-10-20 12:07 - 010869657 _____ C:\Users\Jára\Desktop\Phibes - Super Sharp Shooter.mp3.pKxQF
2019-10-19 20:55 - 2019-10-20 12:07 - 010155740 _____ C:\Users\Jára\Desktop\Phibes - Clint Eastwood (Body Drop Vip).mp3.cRCVe
2019-10-19 20:54 - 2019-10-20 12:07 - 010112071 _____ C:\Users\Jára\Desktop\Phibes - Bitches Roll.mp3.bmkel3e
2019-10-19 20:50 - 2019-10-20 12:07 - 046577516 _____ C:\Users\Jára\Desktop\Showmelove.wav.b6r6r
2019-10-19 20:50 - 2019-10-20 12:07 - 010740946 _____ C:\Users\Jára\Desktop\Phibes - Count it Off.mp3.zOge
2019-10-19 20:48 - 2019-10-20 12:07 - 011119213 _____ C:\Users\Jára\Desktop\Phibes - Funk Soul Brother 2017 M.mp3.bgkOpW
2019-10-18 17:09 - 2019-10-20 12:06 - 000342871 _____ C:\Users\Jára\Desktop\1.jpg.M4OLQ
2019-10-16 17:54 - 2019-10-16 17:54 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 025443840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 022628352 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 019849216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 019811840 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 018019840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 017787392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 014816256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 009928504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 008010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 007754240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 007600664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 007195648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 007015936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 006517640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 006232064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 005915648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 005041664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 004562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 004129616 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 004012544 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 003771392 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 003701760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 003525592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 002861568 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsservices.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002762504 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2019-10-16 17:54 - 2019-10-16 17:54 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2019-10-16 17:54 - 2019-10-16 17:54 - 002723328 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 002703360 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002494440 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002456064 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002448712 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002422592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2019-10-16 17:54 - 2019-10-16 17:54 - 002314648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002284032 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002236144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002138472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2019-10-16 17:54 - 2019-10-16 17:54 - 002114048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002095104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002081976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 002000168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001952360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001847808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsservices.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001830200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001748480 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001743672 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001730560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001721144 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001687040 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001664928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001656392 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001610752 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001563648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001562424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001439744 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001394488 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001283072 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001273392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001217904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001152016 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001098712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001084432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001072952 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 001066496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000904208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000890472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000880088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000856576 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2019-10-16 17:54 - 2019-10-16 17:54 - 000844800 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000842752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000829536 _____ (Microsoft Corporation) C:\WINDOWS\system32\BioIso.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000818688 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000774672 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000758584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000717312 _____ (Microsoft Corporation) C:\WINDOWS\system32\mousocoreworker.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000701952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.FileExplorer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000690176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000679880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000598024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000596992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000537600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000531968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000520192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000516408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000515896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000487424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000466416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000462136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000456504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000452408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000412152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000404392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000380216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicSvc.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000300184 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicCapsule.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000247856 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000225080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2019-10-16 17:54 - 2019-10-16 17:54 - 000224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000220472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000202040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000186880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2019-10-16 17:54 - 2019-10-16 17:54 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000165832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000150328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000117048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bindflt.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000090624 _____ (Microsoft Corporation) C:\WINDOWS\system32\tsgqec.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicAgent.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2019-10-16 17:54 - 2019-10-16 17:54 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tsgqec.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000039304 _____ (Microsoft Corporation) C:\WINDOWS\system32\NtlmShared.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000037176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2019-10-16 17:54 - 2019-10-16 17:54 - 000033048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NtlmShared.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WaaSMedicPS.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000017920 _____ (Microsoft Corporation) C:\WINDOWS\system32\bindflt.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2019-10-16 17:54 - 2019-10-16 17:54 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2019-10-16 17:54 - 2019-10-16 17:54 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2019-10-16 17:27 - 2019-10-20 12:07 - 000000000 ____D C:\Users\Jára\Documents\Max 8
2019-10-16 17:27 - 2019-10-20 12:06 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Cycling '74
2019-10-16 17:27 - 2019-10-16 17:27 - 000000000 ____D C:\ProgramData\Max 8
2019-10-16 17:26 - 2019-10-16 17:26 - 000000000 ____D C:\Users\Jára\AppData\Local\Ableton
2019-10-09 17:40 - 2019-09-20 06:36 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2019-10-09 17:40 - 2019-09-20 06:14 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 007905000 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 007848192 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 006425600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 006227624 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 006164480 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 006084048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 005865272 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizimg.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 005764872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 005105152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 004612520 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 004481536 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 004046336 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003964056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 003742032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003727360 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 003590968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 003553280 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003386880 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003184128 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 003105280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002821120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002799616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 002772032 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002590208 _____ C:\WINDOWS\system32\dwmscene.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002552120 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002466304 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002258856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002160640 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002132280 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002120704 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002120272 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 002069504 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001957008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001942528 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001940952 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001913296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001857024 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001845408 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001819136 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001788728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001757096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2019-10-05 11:26 - 2019-10-05 11:26 - 001692160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001664376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001616784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001616608 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdrecordcpu.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001607680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001543168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001512320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 001510752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001505320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 001473488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001413704 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001383856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001372160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2019-10-05 11:26 - 2019-10-05 11:26 - 001334064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdrecordcpu.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001297936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001263616 _____ (Microsoft Corporation) C:\WINDOWS\system32\opengl32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001261800 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001244944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001182240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 001178816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001154656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001150240 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputHost.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001091584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001080320 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001054872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001047968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001036800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001029432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ClipSp.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 001023128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 001009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000984376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000975872 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000944664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000939008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000931840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000904704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\opengl32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000893952 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000875008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000839680 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9on12.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000833312 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000802816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000792296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputHost.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000772656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000759488 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.Search.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000742912 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000732176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000674072 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000673080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000656960 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11on12.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000639400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp_win.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000629248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.Search.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000617784 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000612864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000606208 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000599040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000598016 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000589384 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000568336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000558592 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000551952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000546816 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiagn.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000541696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResourceMapper.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000541480 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000539648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9on12.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000510464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000507704 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizeng.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000507152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000501232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp_win.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000500736 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2019-10-05 11:26 - 2019-10-05 11:26 - 000487576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SessEnv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000463272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiagn.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000450360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11on12.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000449888 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000442704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ws2_32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000421376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2019-10-05 11:26 - 2019-10-05 11:26 - 000417280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SessEnv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000415808 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000398728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000387832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000383984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000379840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ws2_32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000375720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxdiag.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000363624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000359424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\MbbCx.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000346624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\secproc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000342896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ttdwriter.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000334936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\VAN.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ComposableShellProxyStub.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000315392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxdiag.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000293344 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgmgr32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\directxdatabaseupdater.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000285256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000284160 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000283688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ttdwriter.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000278080 _____ (Microsoft Corporation) C:\WINDOWS\system32\LsaIso.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_CapabilityAccess.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ManageCI.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\glu32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Gpu.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000236520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgmgr32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000223032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgiadaptercache.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000208184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000201016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000176440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlib.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000176152 _____ (Microsoft Corporation) C:\WINDOWS\system32\imm32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\sud.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000173568 _____ (Microsoft Corporation) C:\WINDOWS\system32\drvinst.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000169472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\glu32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000159112 _____ (Microsoft Corporation) C:\WINDOWS\system32\devobj.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000158208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ComposableShellProxyStub.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000155648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_AppExecutionAlias.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000152408 _____ (Microsoft Corporation) C:\WINDOWS\system32\KerbClientShared.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000151552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_BackgroundApps.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SpatialAudioLicenseSrv.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000143808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imm32.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000140496 _____ (Microsoft Corporation) C:\WINDOWS\system32\userenv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sud.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000139264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\prntvpt.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000137864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devobj.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000132608 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_ForceSync.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000132096 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000125232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KerbClientShared.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplicationControlCSP.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000119840 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000116904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\userenv.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\EaseOfAccessDialog.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000110080 _____ C:\WINDOWS\system32\ResBParser.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000107008 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShellExtFramework.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000105272 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000100664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\sethc.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000094208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000093712 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000092624 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskhostw.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EaseOfAccessDialog.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000089544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000088352 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000084496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdvvmtransport.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000079376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uaspstor.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sethc.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000073024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwm.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000066832 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdvvmtransport.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnrollCtrl.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidspi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AssignedAccessRuntime.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\devrtl.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\audioresourceregistrar.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devrtl.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnppolicy.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\BdeUISrv.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000053248 _____ C:\WINDOWS\system32\Drivers\UsbPmApi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000052752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmstorfl.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnrollCtrl.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000047616 _____ C:\WINDOWS\system32\UsbPmApi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AssignedAccessRuntime.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000047000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000043536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storvsc.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enrollmentapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2019-10-05 11:26 - 2019-10-05 11:26 - 000027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32_DeviceGuard.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CSystemEventsBrokerClient.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000021544 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000020944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmsgapi.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000016696 _____ (Microsoft Corporation) C:\WINDOWS\system32\spwizres.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d8thk.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d8thk.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2019-10-05 11:26 - 2019-10-05 11:26 - 000011576 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxlibres.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2019-10-05 11:26 - 2019-10-05 11:26 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2019-09-29 20:36 - 2019-10-20 12:07 - 000041993 _____ C:\Users\Jára\Desktop\Výstřižek.JPG.fCpNe4
2019-09-28 20:06 - 2019-09-28 20:06 - 000000000 ____D C:\ProgramData\PACE Anti-Piracy

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-10-20 18:46 - 2018-08-13 22:04 - 000000000 ____D C:\Program Files (x86)\Steam
2019-10-20 18:29 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2019-10-20 18:07 - 2019-07-21 17:56 - 001693846 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2019-10-20 18:07 - 2019-03-19 13:55 - 000716776 _____ C:\WINDOWS\system32\perfh005.dat
2019-10-20 18:07 - 2019-03-19 13:55 - 000144856 _____ C:\WINDOWS\system32\perfc005.dat
2019-10-20 18:07 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF
2019-10-20 18:02 - 2018-08-09 17:41 - 000000000 ____D C:\ProgramData\NVIDIA
2019-10-20 18:01 - 2018-08-12 19:33 - 000000000 ____D C:\ProgramData\Origin
2019-10-20 18:00 - 2019-07-21 13:49 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2019-10-20 18:00 - 2019-03-19 06:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2019-10-20 17:59 - 2019-07-21 13:45 - 000000000 ____D C:\Users\defaultuser0
2019-10-20 17:50 - 2018-08-12 19:34 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Origin
2019-10-20 17:49 - 2019-01-06 18:14 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Rainmeter
2019-10-20 17:49 - 2018-08-11 16:00 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Autodesk
2019-10-20 17:48 - 2019-07-21 13:45 - 000000000 ____D C:\Users\Jára
2019-10-20 13:23 - 2019-09-11 21:18 - 000436109 _____ C:\Users\Jára\Desktop\report_tdsskiller.txt
2019-10-20 13:20 - 2019-03-19 06:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2019-10-20 12:35 - 2018-08-11 11:17 - 000000000 ____D C:\Users\Jára\AppData\Roaming\MPC-HC
2019-10-20 12:24 - 2018-08-09 18:42 - 000000000 ____D C:\Users\Jára\AppData\Roaming\GHISLER
2019-10-20 12:07 - 2019-09-05 09:03 - 000000000 ____D C:\Users\Jára\Desktop\dana fotky
2019-10-20 12:07 - 2019-07-21 13:49 - 000000284 ___SH C:\Users\Jára\ntuser.ini.wMlS9eB
2019-10-20 12:07 - 2019-05-19 11:55 - 000000000 ____D C:\Users\Jára\Documents\My Games
2019-10-20 12:07 - 2019-05-08 16:26 - 000000426 ____H C:\Users\Jára\Desktop\~$ SP 20182019.doc.Qg1rvte
2019-10-20 12:07 - 2019-04-26 18:15 - 015822951 _____ C:\Users\Jára\Documents\HLZ - Abracatabla.mp3.GzDbpe
2019-10-20 12:07 - 2019-04-26 18:15 - 014952526 _____ C:\Users\Jára\Documents\HLZ - Clusters.mp3.ELsq3h
2019-10-20 12:07 - 2019-04-26 18:15 - 014537650 _____ C:\Users\Jára\Documents\Hybris - Crumbled (DLR's 3rd time- around Rmx).mp3.V6jGR
2019-10-20 12:07 - 2019-04-26 18:15 - 014115374 _____ C:\Users\Jára\Documents\HLZ -Vectors.mp3.EIKYX
2019-10-20 12:07 - 2019-04-26 18:15 - 014075837 _____ C:\Users\Jára\Documents\HLZ - Kronos.mp3.Wp6iJ
2019-10-20 12:07 - 2019-04-26 18:15 - 013644592 _____ C:\Users\Jára\Documents\Black Barrel - Don't Stop.mp3.H23h2n
2019-10-20 12:07 - 2019-04-26 18:15 - 013269275 _____ C:\Users\Jára\Documents\HLZ - Funk O'Clock.mp3.WVGj
2019-10-20 12:07 - 2019-04-26 18:15 - 012857568 _____ C:\Users\Jára\Documents\Monty - Tribes.mp3.nYoeSJC
2019-10-20 12:07 - 2019-04-26 18:15 - 012700749 _____ C:\Users\Jára\Documents\Monty - Ectoplasm.mp3.SpMV
2019-10-20 12:07 - 2019-04-26 18:15 - 012687927 _____ C:\Users\Jára\Documents\Monty - Temptation.mp3.AAP5387
2019-10-20 12:07 - 2019-04-26 18:15 - 011912334 _____ C:\Users\Jára\Documents\Monty - Decisions.mp3.YUXU7E
2019-10-20 12:07 - 2019-04-26 18:15 - 011816021 _____ C:\Users\Jára\Documents\Monty - Spatia.mp3.PfzeNew
2019-10-20 12:07 - 2019-04-26 18:15 - 011714614 _____ C:\Users\Jára\Documents\Kiril - This!.mp3.ZrfG9Yb
2019-10-20 12:07 - 2019-04-26 18:15 - 011670770 _____ C:\Users\Jára\Documents\Signal & Cruk - Illusion.mp3.WDvth9Z
2019-10-20 12:07 - 2019-04-26 18:15 - 011161089 _____ C:\Users\Jára\Documents\Cruk - See It Our Way.mp3.np3D
2019-10-20 12:07 - 2019-04-26 18:15 - 010973631 _____ C:\Users\Jára\Documents\Data 3 - Komparen.mp3.WRHXV
2019-10-20 12:07 - 2019-04-26 18:15 - 008202946 _____ C:\Users\Jára\Documents\Xtrah - A New Perspective.mp3.GtPzPpM
2019-10-20 12:07 - 2019-04-26 18:15 - 000032343 _____ C:\Users\Jára\Documents\2_heavy rollers.nml.DKIlHVo
2019-10-20 12:07 - 2019-04-19 20:24 - 000000000 ____D C:\Users\Jára\Documents\Assassin's Creed Unity
2019-10-20 12:07 - 2019-03-25 19:30 - 000000000 ____D C:\Users\Jára\Documents\Audacity
2019-10-20 12:07 - 2019-03-19 06:52 - 000000000 __RHD C:\Users\Public\Libraries
2019-10-20 12:07 - 2019-02-02 21:14 - 000000000 ____D C:\Users\Jára\Documents\BioWare
2019-10-20 12:07 - 2019-01-06 18:14 - 000000000 ____D C:\Users\Jára\Documents\Rainmeter
2019-10-20 12:07 - 2019-01-05 00:59 - 000000000 ____D C:\Users\Public\Documents\NI Resources
2019-10-20 12:07 - 2019-01-05 00:54 - 000000000 ____D C:\Users\Public\Documents\Native Instruments
2019-10-20 12:07 - 2018-12-27 15:40 - 000000000 ____D C:\Users\Public\Documents\Steam
2019-10-20 12:07 - 2018-10-27 14:18 - 000000000 ____D C:\Users\Jára\Documents\Ableton
2019-10-20 12:07 - 2018-10-14 19:07 - 000011939 _____ C:\Users\Jára\Documents\krkonose.docx.P5zU
2019-10-20 12:07 - 2018-09-06 21:01 - 000000000 ____D C:\Users\Jára\Documents\Battlefield V Open Beta
2019-10-20 12:07 - 2018-09-02 10:39 - 000000000 ____D C:\Users\Jára\Documents\Native Instruments
2019-10-20 12:07 - 2018-09-02 10:31 - 000000000 ____D C:\Users\Jára\Lokale Einstellungen
2019-10-20 12:07 - 2018-08-19 19:56 - 000000000 ____D C:\Users\Jára\Documents\ALTERNATIVA
2019-10-20 12:07 - 2018-08-18 08:45 - 000000000 ____D C:\Users\Jára\Downloads\Ulozto
2019-10-20 12:07 - 2018-08-14 05:19 - 000000000 ____D C:\Users\Jára\Documents\Battlefield 1
2019-10-20 12:07 - 2018-08-11 16:08 - 000000000 ____D C:\Users\Jára\Documents\Autodesk Application Manager
2019-10-20 12:07 - 2018-08-11 16:07 - 000000000 ____D C:\Users\Public\Documents\Autodesk
2019-10-20 12:07 - 2018-08-11 16:07 - 000000000 ____D C:\Users\Jára\Documents\Inventor Server SDK ACAD 2016
2019-10-20 12:07 - 2018-08-11 15:53 - 002378438 _____ C:\Users\Jára\Downloads\Mista_na_prenocovani.zip.T6Hd
2019-10-20 12:07 - 2018-08-11 15:02 - 000064776 _____ C:\Users\Jára\Downloads\jarča.doc.T6Hd
2019-10-20 12:07 - 2018-08-10 20:40 - 000000000 ___HD C:\Users\Jára\MicrosoftEdgeBackups
2019-10-20 12:07 - 2018-08-10 18:34 - 000038664 _____ C:\Users\Jára\Downloads\CV-J_Zázvorka new aj.doc.T6Hd
2019-10-20 12:07 - 2018-08-10 17:41 - 000000000 ____D C:\Users\Jára\Documents\Adobe
2019-10-20 12:07 - 2018-08-09 18:49 - 000000000 ____D C:\Users\Public\Documents\Daemon Tools Images
2019-10-20 12:07 - 2018-08-09 18:49 - 000000000 ____D C:\Users\Public\Documents\Catch!
2019-10-20 12:07 - 2018-08-09 17:44 - 000000000 ____D C:\Users\Jára\Intel
2019-10-20 12:07 - 2018-08-09 17:31 - 000000000 ___RD C:\Users\Jára\OneDrive
2019-10-20 12:07 - 2018-08-09 17:30 - 000000000 __RHD C:\Users\Public\AccountPictures
2019-10-20 12:06 - 2019-08-26 18:37 - 000002562 _____ C:\Users\Jára\AppData\Roaming\ML.js.RZ5IAvD
2019-10-20 12:06 - 2019-05-19 11:55 - 000000000 ____D C:\Users\Jára\AppData\Roaming\A Plague Tale Innocence
2019-10-20 12:06 - 2019-04-19 19:14 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
2019-10-20 12:06 - 2019-03-25 19:20 - 000000000 ____D C:\Users\Jára\AppData\Roaming\audacity
2019-10-20 12:06 - 2019-03-09 19:04 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome
2019-10-20 12:06 - 2019-03-04 19:33 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Ahead
2019-10-20 12:06 - 2019-02-21 21:50 - 000000396 _____ C:\Users\Jára\AppData\Roaming\Adobe PNG Format CS6 Prefs.IrRq
2019-10-20 12:06 - 2019-02-02 13:30 - 000000000 ____D C:\Users\Jára\AppData\Roaming\TeamViewer
2019-10-20 12:06 - 2019-01-31 22:52 - 000000396 _____ C:\Users\Jára\AppData\Roaming\Adobe IllExport Filter CS6 Prefs.IrRq
2019-10-20 12:06 - 2019-01-22 19:20 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Apple Computer
2019-10-20 12:06 - 2019-01-05 00:44 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Native Instruments
2019-10-20 12:06 - 2018-12-27 15:19 - 000000000 ____D C:\RIDE 3
2019-10-20 12:06 - 2018-12-25 16:22 - 000000000 ____D C:\Users\Jára\AppData\Roaming\VitySoft
2019-10-20 12:06 - 2018-12-25 16:22 - 000000000 ____D C:\Users\Jára\.objectdb
2019-10-20 12:06 - 2018-11-08 21:20 - 000000396 _____ C:\Users\Jára\AppData\Roaming\Adobe GIF Format CS6 Prefs.IrRq
2019-10-20 12:06 - 2018-10-27 15:49 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2019-10-20 12:06 - 2018-10-27 14:14 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Ableton
2019-10-20 12:06 - 2018-09-20 21:31 - 000000000 ____D C:\Users\Jára\AppData\Roaming\freac
2019-10-20 12:06 - 2018-09-20 20:56 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3Gain
2019-10-20 12:06 - 2018-08-19 19:12 - 000000000 ____D C:\Users\Jára\AppData\Roaming\ScummVM
2019-10-20 12:06 - 2018-08-18 08:45 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Ulozto File Manager
2019-10-20 12:06 - 2018-08-15 21:49 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server
2019-10-20 12:06 - 2018-08-15 21:48 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner
2019-10-20 12:06 - 2018-08-12 19:37 - 000000000 ____D C:\Users\Jára\.QtWebEngineProcess
2019-10-20 12:06 - 2018-08-12 19:37 - 000000000 ____D C:\Users\Jára\.Origin
2019-10-20 12:06 - 2018-08-11 16:08 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Autodesk
2019-10-20 12:06 - 2018-08-10 20:40 - 000000000 ___RD C:\Users\Jára\3D Objects
2019-10-20 12:06 - 2018-08-09 21:50 - 000000000 ____D C:\Users\Jára\AppData\Roaming\HD Tune Pro
2019-10-20 12:06 - 2018-08-09 21:30 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Winamp
2019-10-20 12:06 - 2018-08-09 20:55 - 000000000 ____D C:\Users\Jára\AppData\Roaming\NVIDIA
2019-10-20 12:06 - 2018-08-09 20:15 - 000000000 ____D C:\Users\Jára\ansel
2019-10-20 12:06 - 2018-08-09 20:13 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Macromedia
2019-10-20 12:06 - 2018-08-09 18:48 - 000000000 ____D C:\Users\Jára\AppData\Roaming\DAEMON Tools Lite
2019-10-20 12:06 - 2018-08-09 18:42 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2019-10-20 12:06 - 2018-08-09 18:42 - 000000000 ____D C:\totalcmd
2019-10-20 12:06 - 2018-08-09 18:38 - 000000000 ____D C:\Users\Jára\AppData\Local\Adobe
2019-10-20 12:06 - 2018-08-09 18:32 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Sun
2019-10-20 12:06 - 2018-08-09 17:49 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Intel Corporation
2019-10-20 12:06 - 2018-08-09 17:34 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Google
2019-10-20 12:06 - 2018-08-09 17:30 - 000000000 ____D C:\Users\Jára\AppData\Roaming\Adobe
2019-10-20 12:04 - 2019-08-17 22:38 - 000000000 ____D C:\Anthm
2019-10-20 12:04 - 2019-03-19 06:52 - 000000000 ____D C:\PerfLogs
2019-10-20 12:04 - 2019-01-13 10:55 - 000000000 ____D C:\Fliqlo 1.3.3
2019-10-20 12:04 - 2018-08-11 16:05 - 000498501 _____ C:\DSC_4047.JPG.Rx9tDI
2019-10-20 12:04 - 2018-08-11 15:59 - 000000000 ____D C:\Autodesk
2019-10-20 12:04 - 2018-08-09 18:50 - 000000000 __RHD C:\MSOCache
2019-10-20 12:04 - 2016-07-16 14:58 - 000000265 ___SH C:\BOOTNXT.V2kMl1
2019-10-19 22:41 - 2019-07-21 13:41 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2019-10-19 22:26 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps
2019-10-19 22:26 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2019-10-19 18:46 - 2018-08-09 18:39 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-10-16 18:34 - 2018-10-27 14:14 - 000000270 __RSH C:\ProgramData\ntuser.pol
2019-10-16 18:28 - 2019-07-21 13:41 - 005543648 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SystemResources
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2019-10-16 18:28 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2019-10-16 18:26 - 2019-07-21 13:49 - 000004562 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2019-10-16 17:56 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2019-10-16 17:54 - 2016-07-16 14:58 - 000410822 __RSH C:\bootmgr
2019-10-16 17:38 - 2019-07-20 15:09 - 000000000 ___DC C:\WINDOWS\Panther
2019-10-16 17:38 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2019-10-16 14:50 - 2018-08-09 17:33 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2019-10-16 14:44 - 2018-08-12 19:33 - 000000000 ____D C:\Program Files (x86)\Origin
2019-10-13 17:29 - 2019-07-21 13:49 - 000003474 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2019-10-13 17:29 - 2019-07-21 13:49 - 000003350 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2019-10-13 17:29 - 2018-08-09 17:33 - 000000000 ____D C:\Program Files (x86)\Google
2019-10-11 20:24 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2019-10-11 20:24 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2019-10-11 20:24 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2019-10-11 20:24 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2019-10-11 20:24 - 2018-08-10 18:16 - 000000000 ____D C:\WINDOWS\system32\MRT
2019-10-09 17:40 - 2018-08-10 18:16 - 127230528 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2019-10-06 15:57 - 2018-10-29 22:33 - 000001456 _____ C:\Users\Jára\AppData\Local\Adobe Save for Web 13.0 Prefs
2019-10-05 11:28 - 2018-08-10 18:17 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2019-10-04 15:42 - 2018-08-09 17:30 - 000000000 ____D C:\Users\Jára\AppData\Local\Packages
2019-10-02 20:39 - 2019-07-21 13:49 - 000003374 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2198491196-3933858514-99382068-1001
2019-10-02 20:39 - 2019-07-21 13:45 - 000002364 _____ C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2019-09-28 20:04 - 2018-08-09 21:15 - 000000000 ____D C:\Program Files\Adobe
2019-09-28 20:04 - 2018-08-09 21:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
2019-09-28 20:04 - 2018-08-09 21:14 - 000000000 ____D C:\Program Files\Common Files\Adobe

==================== Files in the root of some directories ================

2019-05-26 20:23 - 2019-05-26 20:23 - 091905672 _____ (Ableton) C:\Users\Jára\AppData\Roaming\Ableton Live 10 Suite.exe
2018-05-26 19:01 - 2018-05-26 19:01 - 001299362 _____ () C:\Users\Jára\AppData\Roaming\Ableton_KeyGen.exe
2018-11-08 21:20 - 2019-10-20 12:06 - 000000396 _____ () C:\Users\Jára\AppData\Roaming\Adobe GIF Format CS6 Prefs.IrRq
2019-01-31 22:52 - 2019-10-20 12:06 - 000000396 _____ () C:\Users\Jára\AppData\Roaming\Adobe IllExport Filter CS6 Prefs.IrRq
2019-02-21 21:50 - 2019-10-20 12:06 - 000000396 _____ () C:\Users\Jára\AppData\Roaming\Adobe PNG Format CS6 Prefs.IrRq
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ () C:\Users\Jára\AppData\Roaming\DECRYPT-FILES.txt
2019-08-26 18:37 - 2019-10-20 12:06 - 000002562 _____ () C:\Users\Jára\AppData\Roaming\ML.js.RZ5IAvD
2019-10-20 12:06 - 2019-10-20 12:06 - 000009524 _____ () C:\Users\Jára\AppData\Roaming\Microsoft\DECRYPT-FILES.txt
2018-10-29 22:33 - 2019-10-06 15:57 - 000001456 _____ () C:\Users\Jára\AppData\Local\Adobe Save for Web 13.0 Prefs

==================== SigCheck ===============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ============================

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 18:11
od spd
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-10-2019
Ran by Jára (20-10-2019 19:09:13)
Running from D:\Downloads
Windows 10 Home Version 1903 18362.418 (X64) (2019-07-21 11:49:43)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2198491196-3933858514-99382068-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2198491196-3933858514-99382068-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-2198491196-3933858514-99382068-1000 - Limited - Disabled) => C:\Users\defaultuser0
Guest (S-1-5-21-2198491196-3933858514-99382068-501 - Limited - Disabled)
Jára (S-1-5-21-2198491196-3933858514-99382068-1001 - Administrator - Enabled) => C:\Users\Jára
WDAGUtilityAccount (S-1-5-21-2198491196-3933858514-99382068-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 18.05 (x64) (HKLM\...\7-Zip) (Version: 18.05 - Igor Pavlov)
ACA & MEP 2016 Object Enabler (HKLM\...\{5783F2D7-F004-0000-5102-0060B0CE6BBA}) (Version: 7.8.41.0 - Autodesk) Hidden
ACAD Private (HKLM\...\{5783F2D7-F001-0000-3102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 19.021.20048 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\...\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.7.1 64-bit (HKLM\...\{BC86B82C-8C0E-4408-9AC1-6B0F2D636963}) (Version: 5.7.1 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Akamai) (Version: - Akamai Technologies, Inc)
Akamai NetSession Interface (HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Akamai) (Version: - Akamai Technologies, Inc)
Aktualizace NVIDIA 31.2.0.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 31.2.0.0 - NVIDIA Corporation) Hidden
Aktualizace produktu Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0405-0000-0000000FF1CE}_HOMESTUDENTR_{0A1FAC46-B899-421D-B1A2-470896DC45DB}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0405-0000-0000000FF1CE}_HOMESTUDENTR_{5260BB53-C1F7-4A3B-9AEB-3EC9B37FF194}) (Version: - Microsoft)
Aktualizace produktu Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0405-0000-0000000FF1CE}_HOMESTUDENTR_{E68DD413-B834-4923-8181-0A03B7555187}) (Version: - Microsoft)
Apple Mobile Device Support (HKLM\...\{5FA8C4BE-8C74-4B9C-9B49-EBF759230189}) (Version: 12.1.0.25 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.14 - Michael Tippach)
Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft)
Audacity 2.3.1 (HKLM-x32\...\Audacity_is1) (Version: 2.3.1 - Audacity Team)
AutoCAD 2016 – Čeština (Czech) (HKLM\...\{5783F2D7-F001-0405-2102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 (HKLM\...\{5783F2D7-F001-0000-0102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
AutoCAD 2016 Language Pack – Čeština (Czech) (HKLM\...\{5783F2D7-F001-0405-1102-0060B0CE6BBA}) (Version: 20.1.49.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2016 (HKLM-x32\...\{94AD53E7-493B-4291-8714-7A3B761D2783}) (Version: 6.3.0.15 - Autodesk)
Autodesk App Manager 2016 (HKLM-x32\...\{4ECF9E00-2978-46AF-BD80-455EFEAB7A93}) (Version: 2.0.0 - Autodesk)
Autodesk Application Manager (HKLM-x32\...\Autodesk Application Manager) (Version: 5.0.142.14 - Autodesk)
Autodesk AutoCAD 2016 – Čeština (Czech) (HKLM\...\AutoCAD 2016 – Čeština (Czech)) (Version: 20.1.49.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.4 (HKLM-x32\...\{4E20873D-BC20-495C-AFD9-B18877B7F9BB}) (Version: 1.2.4.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2016 Add-in 64 bit (HKLM\...\{4BEE127E-95C4-434D-ABAC-65155192BB24}) (Version: 4.35.1742 - Autodesk)
Autodesk Content Service (HKLM\...\{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service (HKLM\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM\...\{A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2016 (HKLM-x32\...\{29A7D6EC-63C2-42FD-8143-5812ABD2923F}) (Version: 6.3.0.15 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2016 (HKLM-x32\...\{6B4CFC6E-ECB0-47FE-95D3-65C680ED0687}) (Version: 6.3.0.15 - Autodesk)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 19.8.2393 - AVAST Software)
Battlefield™ 1 (HKLM-x32\...\{335B50BC-6130-4BAF-9A6A-F1561270587B}) (Version: 1.0.57.44284 - Electronic Arts)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.44 - Piriform)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.8.0.0466 - Disc Soft Ltd)
DisplayDriverAnalyzer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 399.07 - NVIDIA Corporation) Hidden
EaseUS Data Recovery Wizard (HKLM\...\EaseUS Data Recovery Wizard_is1) (Version: - EaseUS)
EaseUS Data Recovery Wizard 11.8.0 - Odinstalovat Češtinu (HKLM-x32\...\EaseUS Data Recovery Wizard 11.8.0) (Version: 11.8.0 - Cehos)
Fliqlo Screen Saver (HKLM-x32\...\Fliqlo) (Version: - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 77.0.3865.120 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.301 - Google LLC) Hidden
HD Tune Pro 5.50 (HKLM-x32\...\HD Tune Pro_is1) (Version: - EFD Software)
Import souborů SketchUp 2016 (HKLM-x32\...\{C769FB7C-1F55-4B31-9A2A-21CEC50F4F92}) (Version: 2.0.0 - Autodesk)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.6.0.1030 - Intel Corporation)
Intel(R) Network Connections 21.1.29.0 (HKLM\...\PROSetDX) (Version: 21.1.29.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 15.2.0.1020 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{bb0592a7-5772-4736-9d55-2402740085db}) (Version: 10.1.1.38 - Intel(R) Corporation) Hidden
iSkysoft Data Recovery(Build 5.0.0.9) (HKLM-x32\...\{656DB838-DB63-4acd-82E3-BB363ED99116}_is1) (Version: 5.0.0.9 - iSkysoft Software Co.,Ltd.)
iTunes (HKLM\...\{288617D6-B455-4C00-8BFE-46B023202CF1}) (Version: 12.9.2.6 - Apple Inc.)
Java 8 Update 181 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
K-Lite Codec Pack 14.3.6 Standard (HKLM-x32\...\KLiteCodecPack_is1) (Version: 14.3.6 - KLCP)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
Malwarebytes verze 3.8.3.2965 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\OneDriveSetup.exe) (Version: 19.152.0927.0012 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\OneDriveSetup.exe) (Version: 19.152.0927.0012 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
MSI Afterburner 4.5.0 (HKLM-x32\...\Afterburner) (Version: 4.5.0 - MSI Co., LTD)
Native Instruments Controller Editor (HKLM-x32\...\Native Instruments Controller Editor) (Version: 2.4.0.445 - Native Instruments)
Native Instruments Native Access (HKLM-x32\...\Native Instruments Native Access) (Version: 1.12.0.120 - Native Instruments)
Native Instruments Service Center (HKLM-x32\...\Native Instruments Service Center) (Version: 2.5.2.1549 - Native Instruments)
Native Instruments Traktor Audio 10 Driver (HKLM-x32\...\Native Instruments Traktor Audio 10 Driver) (Version: - Native Instruments)
Native Instruments Traktor Audio 2 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Audio 2 MK2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Audio 6 Driver (HKLM-x32\...\Native Instruments Traktor Audio 6 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol D2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol D2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol F1 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol F1 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol S2 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S2 MK2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol S4 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S4 MK2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol S5 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S5 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol S8 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol S8 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol X1 MK2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol X1 MK2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol Z1 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol Z1 Driver) (Version: - Native Instruments)
Native Instruments Traktor Kontrol Z2 Driver (HKLM-x32\...\Native Instruments Traktor Kontrol Z2 Driver) (Version: - Native Instruments)
Native Instruments Traktor Pro 3 (HKLM-x32\...\Native Instruments Traktor Pro 3) (Version: 3.2.0.60 - Native Instruments)
Nero 7 Essentials (HKLM-x32\...\{3BDEE284-1516-40E8-B784-00FEBE1B1029}) (Version: 7.02.9769 - Nero AG)
NVIDIA GeForce Experience 3.14.1.48 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.14.1.48 - NVIDIA Corporation)
NVIDIA Ovladač 3D Vision 399.07 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 399.07 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 390.41 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 390.41 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 399.07 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 399.07 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.17.0524 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.17.0524 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 10.5.50.31938 - Electronic Arts, Inc.)
Ovládací panel NVIDIA 399.07 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 399.07 - NVIDIA Corporation) Hidden
PDF Settings CS6 (HKLM-x32\...\{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Podpora aplikací Apple (32bitová) (HKLM-x32\...\{80B42CAA-28C0-4FBD-A46E-D61F45E2F9FC}) (Version: 7.2 - Apple Inc.)
Podpora aplikací Apple (64bitová) (HKLM\...\{466D00D0-E7DE-47C2-8FE5-54A8009F5850}) (Version: 7.2 - Apple Inc.)
Rainmeter (HKLM-x32\...\Rainmeter) (Version: 4.2 r3111 - Rainmeter)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7960 - Realtek Semiconductor Corp.)
RIDE 3 (HKLM-x32\...\RIDE 3_is1) (Version: - )
RivaTuner Statistics Server 7.1.0 (HKLM-x32\...\RTSS) (Version: 7.1.0 - Unwinder)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.2.1.1780 - Samsung Electronics)
Speciální aplikace Autodesk 2016 (HKLM-x32\...\{D42F37CD-9AF9-4435-A474-B387C5BB6B47}) (Version: 2.0.0 - Autodesk)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 9.20 - Ghisler Software GmbH)
Ulož.to FileManager verze 2.71 (HKLM-x32\...\{7DE5EA5D-C933-4549-9A44-5BC671F23BBF}_is1) (Version: 2.71 - Uloz.to cloud a.s.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
UpdateAssistant (HKLM\...\{52C1DD03-104E-4AC6-9DC6-21D585721ED1}) (Version: 1.19.0.0 - Microsoft Corporation) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 85.1 - Ubisoft)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.0.2.0_x64__tf1gferkr813w [2019-05-28] (Autodesk Inc.)
Avee Player -> C:\Program Files\WindowsApps\11314DaawAww.AveePlayer_0.8.25.0_x64__3mhsykt1m20fj [2019-06-30] (Daaw Aww) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-02-03] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-02-03] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-12] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.4.10022.0_x64__8wekyb3d8bbwe [2019-10-09] (Microsoft Studios) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.32.12463.0_x64__8wekyb3d8bbwe [2019-09-12] (Microsoft Corporation) [MS Ad]
Pošta a Kalendář -> C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_16005.12026.20218.0_x64__8wekyb3d8bbwe [2019-09-25] (Microsoft Corporation) [MS Ad]
WiFi Analyzer -> C:\Program Files\WindowsApps\19965MattHafner.WifiAnalyzer_2.4.1.0_x64__gs5k5vmxr2ste [2019-01-28] (Matt Hafner)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\cs-CZ\acadficn.dll (Autodesk Development Sarl -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001_Classes\CLSID\{5370C727-1451-4700-A960-77630950AF6D}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2016\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2198491196-3933858514-99382068-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2016\cs-CZ\acadficn.dll (Autodesk Development Sarl -> Autodesk, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll [2015-02-06] (Autodesk, Inc -> Autodesk, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2015-02-06] (Autodesk, Inc -> Autodesk)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\DTShl64.dll [2018-06-20] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2018-08-21] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2018-04-30] (Igor Pavlov) [File not signed]
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2019-10-20] (AVAST Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2019-06-26] (Malwarebytes Corporation -> Malwarebytes)

==================== Codecs (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\Jára\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Hudba Google Play.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=fahmaaghhglfmonjliepjlchgpgfmobi

==================== Loaded Modules (Whitelisted) ==============

2019-10-20 18:25 - 2018-07-26 18:46 - 001087488 _____ () [File not signed] C:\Program Files (x86)\Iskysoft\IAF\2.4.3.241\usExpex.dll
2018-08-12 19:35 - 2018-08-12 19:35 - 000266240 _____ () [File not signed] C:\Program Files (x86)\Origin\imageformats\qmng.dll
2018-08-12 19:36 - 2019-10-16 14:44 - 000015360 _____ () [File not signed] C:\Program Files (x86)\Origin\libEGL.DLL
2018-08-12 19:36 - 2019-10-16 14:44 - 003090944 _____ () [File not signed] C:\Program Files (x86)\Origin\libGLESv2.dll
2019-10-16 17:21 - 2019-10-16 17:21 - 004577280 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DiscSoft.NET.Common\748526c8af5cbbb2a41b3a507dc50d2b\DiscSoft.NET.Common.ni.dll
2019-10-16 17:22 - 2019-10-16 17:22 - 003113984 _____ () [File not signed] C:\WINDOWS\assembly\NativeImages_v4.0.30319_64\DotNetCommon\73c67d70ca118cf8cd4d422c3e078538\DotNetCommon.ni.dll
2018-08-09 20:19 - 2018-04-30 14:00 - 000075776 _____ (Igor Pavlov) [File not signed] C:\Program Files\7-Zip\7-zip.dll
2003-03-19 08:14 - 2003-03-19 08:14 - 000499712 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Ahead\Lib\MSVCP71.dll
2003-02-21 16:42 - 2003-02-21 16:42 - 000348160 _____ (Microsoft Corporation) [File not signed] C:\Program Files (x86)\Common Files\Ahead\Lib\MSVCR71.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000002560 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Origin\icudt58.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 001252864 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Origin\icuuc58.dll
2011-09-30 00:19 - 2019-10-16 14:44 - 001277440 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\LIBEAY32.dll
2011-09-30 00:19 - 2019-10-16 14:44 - 000279040 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files (x86)\Origin\ssleay32.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000030208 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qgif.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000032768 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qico.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000256512 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qjpeg.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000026112 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qtga.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000305152 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qtiff.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000025600 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\imageformats\qwbmp.dll
2018-08-12 19:35 - 2019-10-16 14:44 - 001611264 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\platforms\qwindows.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 005487104 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Core.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 005841920 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Gui.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000709120 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Multimedia.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 001179136 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Network.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000207360 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Positioning.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000310272 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5PrintSupport.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 003513344 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Qml.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 003390976 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Quick.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000068096 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5QuickWidgets.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000045568 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5TextToSpeech.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 054071296 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineCore.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000211456 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebEngineWidgets.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000116224 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebChannel.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000146432 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5WebSockets.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 005089792 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Widgets.dll
2019-10-16 14:44 - 2019-10-16 14:44 - 000184832 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\Origin\Qt5Xml.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Jára\AppData\Local\Temp:p3vyxxFKbHMUTlBeESOOs6v0LSl [2324]
AlternateDataStreams: C:\Users\Jára\AppData\Local\Temp:zIvvyMRqgrVZibULbcQllH [1874]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-2198491196-3933858514-99382068-1001\Software\Classes\.scr: AutoCADScriptFile =>

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2016-07-16 13:47 - 2018-08-09 21:16 - 000001028 _____ C:\WINDOWS\system32\drivers\etc\hosts

127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412587\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412608\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2198491196-3933858514-99382068-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412631\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jára\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\Control Panel\Desktop\\Wallpaper -> C:\Users\Jára\AppData\Roaming\Microsoft\Windows Photo Viewer\Tapeta programu Windows Prohlížeč fotografií.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Prompt)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{00FFEB82-B36E-4896-B6F1-6D6BFD410751}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed Unity\ACU.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{E05A0731-091A-4577-8A47-40013E13C2B1}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed Unity\ACU.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{53F55780-A40F-42FB-9CB8-F9BF3F3A2822}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{9F178EDD-A60C-4BFC-BE62-2F305BEFBA17}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{C900961E-EEEB-4883-BFEB-74615503C6E3}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{E9DC7EBA-F611-4C3C-BF24-96A8523CE0D0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{219C649D-3B9E-445F-9A96-130F8106F9C7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [{FD70FFC2-B31D-4BE9-A660-616CC8F87BC7}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
FirewallRules: [UDP Query User{46057512-9977-4A76-A89B-50AC7932D001}C:\program files (x86)\java\jre1.8.0_181\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_181\bin\javaw.exe
FirewallRules: [TCP Query User{97FE3F12-73C8-453D-9C82-A534AE2DBFDA}C:\program files (x86)\java\jre1.8.0_181\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_181\bin\javaw.exe
FirewallRules: [UDP Query User{5A9AD9D2-0150-469C-B6B4-901833E2BA42}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe (Ghisler Software GmbH -> Ghisler Software GmbH)
FirewallRules: [TCP Query User{655E7A26-F5C7-4C1D-8D86-B0B1C406052D}C:\totalcmd\totalcmd64.exe] => (Allow) C:\totalcmd\totalcmd64.exe (Ghisler Software GmbH -> Ghisler Software GmbH)
FirewallRules: [{B642819E-6B15-462F-B7FC-340566A8433C}] => (Allow) D:\Games\Battlefield 1\bf1.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{E3DBF10C-CD65-40DD-8751-399B8FE3C22D}] => (Allow) D:\Games\Battlefield 1\bf1.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{C782D87E-0976-4B94-94CE-8FF1A74E77C6}] => (Allow) D:\Games\Battlefield 1\bf1Trial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{FF570B08-0D4F-42C5-A240-0638D5A137A5}] => (Allow) D:\Games\Battlefield 1\bf1Trial.exe (Electronic Arts, Inc. -> EA Digital Illusions CE AB)
FirewallRules: [{5B95A06F-9954-45AD-91D5-53496E9FC0BF}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{0F38C613-1657-43DC-B4FF-7B61636BE387}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{7B42067D-2FE7-4660-91D1-2D6113F7AEC1}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{8EDA95C4-D85F-4CFF-819F-4A3DFCF54DE5}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{5DD984D4-14CF-4A5F-9265-8BB4132F3283}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{D4554F65-1108-4103-B1D0-8963FA3B93A7}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe (Even Balance, Inc. -> )
FirewallRules: [{BDCC96C5-1F6F-425E-A045-1C5149F1C8C2}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{06F3DFC4-0A5A-4C66-81CE-749BCE731DB9}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe (Even Balance, Inc. -> )
FirewallRules: [{EAC339DC-9E20-41C9-9A8A-260CE07BF8A0}] => (Allow) LPort=50248
FirewallRules: [{EF37EF61-FDF0-43CC-9DD6-F9C122F3E5E4}] => (Allow) LPort=5000
FirewallRules: [{81DE9916-8271-49B8-964D-103301F15091}] => (Allow) LPort=52713
FirewallRules: [UDP Query User{0382C8D4-A6CE-4F9C-8433-D2F5E1FB00BD}C:\users\jára\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jára\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [TCP Query User{0FCB6E4F-F755-4007-A909-16211AEA07C7}C:\users\jára\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jára\appdata\local\akamai\netsession_win.exe (Akamai Technologies, Inc. -> Akamai Technologies, Inc.)
FirewallRules: [{A8A3BEE0-EA57-42BB-A61B-91CE1CB4288D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{AD51AFCD-3944-4B20-BBF6-E332BD23C80A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{EA75AE62-CF3B-4798-975D-6DE1BDC0B996}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{49290636-537F-4855-BA72-2DBA0C17A17D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{2AA899C5-916D-4579-9674-3E2A93ECFB80}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{215435AD-7556-48B2-A4FC-510A00C1F210}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{940E7A06-9E8C-4971-94CD-A42DE5B1447C}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{C7416877-BD85-44F5-AC7C-9D23C8E4C7A0}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{D1B35F12-A113-4CF5-8359-42361778C9A8}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{6A2FA1CE-277B-4338-A574-5D9960DB62FD}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{82B4524F-CC78-4030-9957-CAEA2C761C25}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe (Nullsoft Inc. -> Nullsoft, Inc.)
FirewallRules: [{49364918-FA0E-477C-BD35-DC50155C2BB8}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

05-10-2019 11:21:06 Windows Update
09-10-2019 17:39:57 Windows Update
14-10-2019 20:49:21 Windows Update
16-10-2019 17:10:38 Installed Ableton Live 10 Suite
20-10-2019 13:51:37 Removed Ableton Live 9 Suite

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/20/2019 06:59:35 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (14760,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 06:47:54 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (11708,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 06:33:32 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (13512,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 06:23:11 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (13376,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 06:13:16 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (14932,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 06:07:58 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5808,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (10/20/2019 06:01:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Rainmeter.exe, verze: 4.2.0.3111, časové razítko: 0x5b41f002
Název chybujícího modulu: Rainmeter.dll, verze: 4.2.0.3111, časové razítko: 0x5b41efff
Kód výjimky: 0xc0000005
Posun chyby: 0x000000000005a416
ID chybujícího procesu: 0x29b4
Čas spuštění chybující aplikace: 0x01d5875f9adaf069
Cesta k chybující aplikaci: C:\Program Files\Rainmeter\Rainmeter.exe
Cesta k chybujícímu modulu: C:\Program Files\Rainmeter\Rainmeter.dll
ID zprávy: 57aac51c-f13b-4f55-a0f3-191f9f2a49ae
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (10/20/2019 06:00:01 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Aplikace: DTAgent.exe
Verze Framework: v4.0.30319
Popis: Proces byl ukončen z důvodu neošetřené výjimky.
Informace o výjimce: System.Runtime.InteropServices.COMException
na DiscSoftBusServiceLib.IDSFileTransferManager.get_IsBusy()
na DTAgent.App.TrayBaseApp.Application_SessionEnding(System.Object, System.Windows.SessionEndingCancelEventArgs)
na System.Windows.Application.OnSessionEnding(System.Windows.SessionEndingCancelEventArgs)
na System.Windows.Application.WmQueryEndSession(IntPtr, IntPtr ByRef)
na System.Windows.Application.AppFilterMessage(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
na MS.Win32.HwndWrapper.WndProc(IntPtr, Int32, IntPtr, IntPtr, Boolean ByRef)
na MS.Win32.HwndSubclass.DispatcherCallbackOperation(System.Object)
na System.Windows.Threading.ExceptionWrapper.InternalRealCall(System.Delegate, System.Object, Int32)
na System.Windows.Threading.ExceptionWrapper.TryCatchWhen(System.Object, System.Delegate, System.Object, Int32, System.Delegate)
na System.Windows.Threading.Dispatcher.LegacyInvokeImpl(System.Windows.Threading.DispatcherPriority, System.TimeSpan, System.Delegate, System.Object, Int32)
na MS.Win32.HwndSubclass.SubclassWndProc(IntPtr, Int32, IntPtr, IntPtr)


System errors:
=============
Error: (10/20/2019 06:00:49 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Autodesk Content Service neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (10/20/2019 06:00:49 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Autodesk Content Service bylo dosaženo časového limitu (45000 ms).

Error: (10/20/2019 06:00:21 PM) (Source: Service Control Manager) (EventID: 7043) (User: )
Description: Služba Malwarebytes Service se po přijetí pokynu pro vypnutí neukončila správně.

Error: (10/20/2019 05:59:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Origin Web Helper Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/20/2019 05:59:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Origin Client Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/20/2019 05:59:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Disc Soft Lite Bus Service byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/20/2019 05:59:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba NIHardwareService byla neočekávaně ukončena. Tento stav nastal již 1krát.

Error: (10/20/2019 05:59:54 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Služba Autodesk Application Manager Service byla neočekávaně ukončena. Tento stav nastal již 1krát.


Windows Defender:
===================================
Date: 2019-10-19 21:21:46.492
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {93F28B6A-B02D-48AC-8BF5-B7E579159295}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-10-19 18:42:54.710
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Program:Win32/Unwaders.A!ml
ID: 242872
Závažnost: Vážné
Kategorie: Potenciálně nežádoucí software
Cesta: amsi:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Původ detekce: Neznámý
Typ detekce: FastPath
Zdroj detekce: AMSI
Uživatel: DESKTOP-41PK4RC\Jára
Název procesu: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Verze bezpečnostních informací: AV: 1.305.51.0, AS: 1.305.51.0, NIS: 1.305.51.0
Verze modulu: AM: 1.1.16500.1, NIS: 1.1.16500.1

Date: 2019-10-18 17:41:28.251
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {D958AD70-D015-4DB9-97EB-A1AF71046704}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-10-18 16:07:41.282
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Fuery.B!cl
ID: 2147718514
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: amsi:_C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Původ detekce: Neznámý
Typ detekce: FastPath
Zdroj detekce: AMSI
Uživatel: DESKTOP-41PK4RC\Jára
Název procesu: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Verze bezpečnostních informací: AV: 1.303.1818.0, AS: 1.303.1818.0, NIS: 1.303.1818.0
Verze modulu: AM: 1.1.16400.2, NIS: 1.1.16400.2

Date: 2019-10-16 19:52:18.248
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: Trojan:Win32/Wacatac.B!ml
ID: 2147735505
Závažnost: Vážné
Kategorie: Trojský kůň
Cesta: file:_C:\Users\Jára\AppData\Roaming\test_2.exe
Původ detekce: Místní počítač
Typ detekce: FastPath
Zdroj detekce: Ochrana v reálném čase
Uživatel: DESKTOP-41PK4RC\Jára
Název procesu: C:\Windows\SysWOW64\cmd.exe
Verze bezpečnostních informací: AV: 1.303.1818.0, AS: 1.303.1818.0, NIS: 1.303.1818.0
Verze modulu: AM: 1.1.16400.2, NIS: 1.1.16400.2

Date: 2019-10-11 11:44:30.158
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.303.1283.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16400.2
Kód chyby: 0x80240016
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2019-09-12 15:43:25.975
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.301.783.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16300.1
Kód chyby: 0x80240016
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

CodeIntegrity:
===================================

Date: 2019-10-20 18:02:58.009
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-10-20 18:02:58.001
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-10-20 18:02:57.979
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Windows signing level requirements.

Date: 2019-10-20 18:01:55.874
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2019-10-20 18:01:55.862
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2019-10-20 18:01:55.851
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2019-10-20 18:01:55.837
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

Date: 2019-10-20 18:01:55.823
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswAMSI.dll that did not meet the Microsoft signing level requirements.

==================== Memory info ===========================

BIOS: American Megatrends Inc. F9 04/10/2018
Motherboard: Gigabyte Technology Co., Ltd. B250M-D3H-CF
Processor: Intel(R) Core(TM) i5-7500 CPU @ 3.40GHz
Percentage of memory in use: 43%
Total physical RAM: 16344.07 MB
Available physical RAM: 9187.68 MB
Total Virtual: 18776.07 MB
Available Virtual: 9813.42 MB

==================== Drives ================================

Drive c: (SYSTEM) (Fixed) (Total:209.07 GB) (Free:64.11 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DATA01) (Fixed) (Total:465.76 GB) (Free:38.11 GB) NTFS
Drive i: (EaseUS Data Recovery Wizard 11.8) (CDROM) (Total:0.03 GB) (Free:0 GB) UDF
Drive j: (EaseUS Data Recovery Wizard 11.8) (CDROM) (Total:0.03 GB) (Free:0 GB) UDF

\\?\Volume{8bbafdf9-0000-0000-0000-604434000000}\ () (Fixed) (Total:0.53 GB) (Free:0.08 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Protective MBR) (Size: 465.8 GB) (Disk ID: 00000000)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 232.9 GB) (Disk ID: 8BBAFDF9)
Partition 1: (Active) - (Size=209.1 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=539 MB) - (Type=27)

==================== End of Addition.txt ============================

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 18:56
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
AlternateDataStreams: C:\Users\Jára\AppData\Local\Temp:p3vyxxFKbHMUTlBeESOOs6v0LSl [2324]
AlternateDataStreams: C:\Users\Jára\AppData\Local\Temp:zIvvyMRqgrVZibULbcQllH [1874]
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
C:\Users\Jára\AppData\Roaming\test_2.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Policies\Explorer: []
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {01719E40-9736-43B0-AAFA-049AE151F044} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-09] (Google Inc -> Google Inc.)
Task: {57A8576F-99CC-45CA-A2FB-EDF55BA3AEAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-09] (Google Inc -> Google Inc.)
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore

EmptyTemp:
End
Uložte do D:\Downloads jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 19:04
od spd
Fix result of Farbar Recovery Scan Tool (x64) Version: 20-10-2019
Ran by Jára (20-10-2019 20:02:50) Run:1
Running from D:\Downloads
Loaded Profiles: Jára (Available Profiles: defaultuser0 & Jára)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
AlternateDataStreams: C:\Users\Jára\AppData\Local\Temp:p3vyxxFKbHMUTlBeESOOs6v0LSl [2324]
AlternateDataStreams: C:\Users\Jára\AppData\Local\Temp:zIvvyMRqgrVZibULbcQllH [1874]
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
C:\Users\Jára\AppData\Roaming\test_2.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-07-07] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001\...\Policies\Explorer: []
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Policies\Explorer: []
GroupPolicy: Restriction ? <==== ATTENTION
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {01719E40-9736-43B0-AAFA-049AE151F044} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-09] (Google Inc -> Google Inc.)
Task: {57A8576F-99CC-45CA-A2FB-EDF55BA3AEAE} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153168 2018-08-09] (Google Inc -> Google Inc.)
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore

EmptyTemp:
End
*****************

Processes closed successfully.
C:\Users\Jára\AppData\Local\Temp => ":p3vyxxFKbHMUTlBeESOOs6v0LSl" ADS removed successfully
C:\Users\Jára\AppData\Local\Temp => ":zIvvyMRqgrVZibULbcQllH" ADS removed successfully
C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe => moved successfully
"C:\Users\Jára\AppData\Roaming\test_2.exe" => not found
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
"HKU\S-1-5-21-2198491196-3933858514-99382068-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge" => removed successfully
"HKU\S-1-5-21-2198491196-3933858514-99382068-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\" => removed successfully
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Run: [AdobeBridge] => [X] => Error ({ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}): No automatic fix found for this entry.
HKU\S-1-5-21-2198491196-3933858514-99382068-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-10202019180412669\...\Policies\Explorer: [] => Error ({ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}): No automatic fix found for this entry.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{01719E40-9736-43B0-AAFA-049AE151F044}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{01719E40-9736-43B0-AAFA-049AE151F044}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{57A8576F-99CC-45CA-A2FB-EDF55BA3AEAE}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{57A8576F-99CC-45CA-A2FB-EDF55BA3AEAE}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found

=========== EmptyTemp: ==========

BITS transfer queue => 9199616 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 28688175 B
Java, Flash, Steam htmlcache => 204108526 B
Windows/system/drivers => 4221466 B
Edge => 4204932 B
Chrome => 585859714 B
Firefox => 0 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 19048 B
Users => 19048 B
ProgramData => 19048 B
Public => 19048 B
systemprofile => 19048 B
systemprofile32 => 19048 B
LocalService => 27040 B
NetworkService => 35724 B
defaultuser0 => 54772 B
Jára => 26227962 B

RecycleBin => 202521277 B
EmptyTemp: => 1015.9 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:03:25 ====

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 19:53
od Rudy
Smazáno. Po stránce malware a zbytečností je již log OK.

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 20:04
od spd
Dobrá. Díky moc! Je tedy jistota, že další soubory už nebudou šifrovány a ransomware se nebude dál šířit?

Re: Prosím o pomoc - ransomeware

Napsal: 20 říj 2019 20:52
od Rudy
spd píše:Dobrá. Díky moc! Je tedy jistota, že další soubory už nebudou šifrovány a ransomware se nebude dál šířit?
Měla by být. :)

Re: Prosím o pomoc - ransomeware

Napsal: 26 říj 2019 21:04
od spd
Díky. Posílám příspěvek !