Stránka 1 z 1

Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 15:54
od Gárf
Dobrý den,
mám problém s vypadáváním VPN a celkovým zpomalením PC. děkuji za pomoc


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-03-2020
Ran by Vojta (23-03-2020 15:25:25)
Running from C:\Users\Vojta\Desktop
Windows 10 Home Version 1903 18362.720 (X64) (2019-08-20 21:21:11)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3645671178-350016163-1338499739-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3645671178-350016163-1338499739-503 - Limited - Disabled)
Guest (S-1-5-21-3645671178-350016163-1338499739-501 - Limited - Disabled)
Vojta (S-1-5-21-3645671178-350016163-1338499739-1001 - Administrator - Enabled) => C:\Users\Vojta
WDAGUtilityAccount (S-1-5-21-3645671178-350016163-1338499739-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.344 - Adobe)
Adobe Reader XI (11.0.23) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.23 - Adobe Systems Incorporated)
Aide PDF to DWG Converter 11.0 (HKLM-x32\...\Aide PDF to DWG Converter_is1) (Version: - Aide CAD Systems Incorporated.)
ArchiCAD 19 CZE (HKLM\...\001FFF2FFF19FF00FF1101F01F02F000-R1) (Version: 19.0 - GRAPHISOFT)
ARCHICAD 20 CZE (HKLM\...\001FFF2FFF20FF00FF1101F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
AutoCAD 2015 – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0000-0102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
AutoCAD 2015 – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0405-2102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
AutoCAD 2015 Language Pack – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0405-1102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
Autodesk 360 (HKLM\...\{556966D9-F7F6-421B-9707-D07901604DDF}) (Version: 5.1.1.1001 - Autodesk)
Autodesk App Manager (HKLM-x32\...\{C8125548-F2D5-4059-823F-1F3C5BBD9F19}) (Version: 1.2.0 - Autodesk)
Autodesk AutoCAD 2015 – Čeština (Czech) (HKLM\...\AutoCAD 2015 – Čeština (Czech)) (Version: 20.0.51.0 - Autodesk)
Autodesk AutoCAD Civil 3D 2015 64 Bit Object Enabler on AutoCAD 2015 – Ceština (Czech) - Czech (HKLM\...\{6904F91C-1317-4D36-B12E-6D5A723CEB5D}) (Version: 524.0 - Autodesk, Inc.)
Autodesk AutoCAD Civil 3D 2015 64 Bit Object Enabler on Autodesk 360 - Language Neutral (HKLM\...\{3E06D9B0-11B4-46D2-8246-8DC2B8A51EBD}) (Version: 524.0 - Autodesk, Inc.)
Autodesk AutoCAD Performance Feedback Tool Version 1.2.2 (HKLM-x32\...\{85735431-6CD3-4B16-BEC8-95332034E53B}) (Version: 1.2.2.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit (HKLM\...\{9D589081-AFC2-4932-9071-AC585AC1EA83}) (Version: 3.32.3004 - Autodesk)
Autodesk Content Service (HKLM-x32\...\{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service (HKLM-x32\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM-x32\...\{A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2015 (HKLM-x32\...\{427F733F-4D6C-45BC-9324-EB743104C321}) (Version: 5.2.9.100 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2015 (HKLM-x32\...\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}) (Version: 5.2.9.100 - Autodesk)
Autodesk ReCap (HKLM\...\{31ABA3F2-0000-1033-0102-111D43815377}) (Version: 1.3.1.39 - Autodesk) Hidden
Autodesk ReCap (HKLM\...\Autodesk ReCap) (Version: 1.3.1.39 - Autodesk)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 20.1.2397 - AVAST Software)
Balík TT 2010 (HKLM-x32\...\{91CA3F48-5DAD-4147-AECE-C7219C4B2562}) (Version: 2010.0.0.0 - Svoboda Software (svoboda.zbynek@quick.cz, mobile +420 606 227 420))
BitComet 1.54 (HKLM-x32\...\BitComet_x64) (Version: 1.54 - CometNetwork)
Callida euroCALC 3 - Klient (HKLM-x32\...\euroCALC 3 - Klient_is1) (Version: euroCALC 3 - Klient - )
CCleaner (HKLM\...\CCleaner) (Version: 5.62 - Piriform)
CCleaner Browser (HKLM-x32\...\CCleaner Browser) (Version: 80.0.3625.135 - Autoři prohlížeče CCleaner Browser)
CCleaner Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.5.21.0 - Piriform Software) Hidden
CodeMeter Runtime Kit v5.22a (HKLM\...\{8D299F2C-A3C8-49A5-A726-E885AB397243}) (Version: 5.22.1508.501 - WIBU-SYSTEMS AG)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.3.0.0154 - Disc Soft Ltd)
DAEMON Tools Pro (HKLM\...\DAEMON Tools Pro) (Version: 6.1.0.0484 - Disc Soft Ltd)
DGN to DWG Converter (HKLM-x32\...\{A02F2188-4962-4E1A-BB0D-5982774361D7}) (Version: - )
DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0002 - Microsoft Corporation)
ecOffer (HKLM-x32\...\ecOffer_is1) (Version: ecOffer - Callida, s.r.o.)
euroCALC Remote Standard (HKLM-x32\...\euroCALC Remote Standard_is1) (Version: euroCALC Remote Standard - Callida, s.r.o.)
Evernote v. 6.5.4 (HKLM-x32\...\{D47E7D82-0D98-11E7-A6D6-005056951CAD}) (Version: 6.5.4.4720 - Evernote Corp.)
FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production)
FormApps Signing Extension (HKLM-x32\...\{ACA43D91-8B42-4D42-8C8B-A893BD6AA40D}) (Version: 2.8.2.28 - Software602 a.s.)
FreeFileSync 7.7 (HKLM-x32\...\FreeFileSync_is1) (Version: 7.7 - www.FreeFileSync.org)
Google Drive (HKLM-x32\...\{A8DC81F2-D365-4248-892A-FA3B5951F731}) (Version: 2.34.9392.7803 - Google, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.149 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
GRAPHISOFT BIMx Desktop Viewer (HKLM-x32\...\103FFFFFFF20FF00FF2801F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version: - )
Import souborů SketchUp (HKLM-x32\...\{C403E867-FCF1-432B-BCC1-8FFD40A10A6E}) (Version: 1.2.0 - Autodesk)
Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{AA67D612-0BE5-44D6-9A91-592958F754A1}) (Version: 13.0.198 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4624 - Intel Corporation)
Java 8 Update 161 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Java 8 Update 172 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180172F0}) (Version: 8.0.1720.11 - Oracle Corporation)
Java 8 Update 181 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
Java 8 Update 201 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180201F0}) (Version: 8.0.2010.9 - Oracle Corporation)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - )
Kompaktní jednotky DUPLEX - návrhový program (HKLM-x32\...\Atrea.Application_400) (Version: 8.97.450 - ATREA s.r.o.)
KROS 4 (HKLM-x32\...\{30044428-C20A-3933-8C01-205EFF81E627}) (Version: 161.100 - ÚRS Praha)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 6.3.9600.11105 - Realtek Semiconductor Corp.)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.1702.1 - McAfee, LLC)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.84 - McAfee, LLC.)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Project Language Pack 2013 - Czech/čeština (HKLM\...\Office15.PMUI.cs-cz) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Project Professional 2013 (HKLM\...\Office15.PRJPRO) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.1.0 - Mozilla)
Mozilla Thunderbird 68.1.0 (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 68.1.0 (x86 cs)) (Version: 68.1.0 - Mozilla)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (HKLM\...\{90150000-001F-0405-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (HKLM\...\{90150000-001F-041B-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
NEPrůzvučnost 2010 (HKLM-x32\...\{3C74992F-CA2C-4C49-A592-D19670356D46}) (Version: 2010.0.0.0 - Svoboda Software (svoboda.zbynek@quick.cz, mobile (+420) 606 227 420))
NVIDIA Ovladač 3D Vision 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.54 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation)
Opera Stable 67.0.3575.79 (HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Opera 67.0.3575.79) (Version: 67.0.3575.79 - Opera Software)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Ovládací panel NVIDIA 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 376.54 - NVIDIA Corporation) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.2.1 - pdfforge)
Počítačová aplikace Autodesk (HKLM-x32\...\Autodesk Desktop App) (Version: 6.2.0.174 - Autodesk)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7525 - Realtek Semiconductor Corp.)
RTS Stavitel+ 2014 (HKLM-x32\...\RTS Stavitel+_is1) (Version: - )
RTS Stavitel+ 2015 (HKLM-x32\...\RTS Stavitel +_is1) (Version: 2015 - RTS, a.s.)
Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
SketchUp 2016 (HKLM\...\{D87EE6DC-32BA-4219-AC75-0A6FD54ED058}) (Version: 16.0.19912 - Trimble Navigation Limited)
Speciální aplikace Autodesk (HKLM-x32\...\{EDDEE94B-214D-4B07-9727-A3E46F3E379A}) (Version: 1.2.0 - Autodesk)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.5 - Synaptics Incorporated)
Synology Assistant (remove only) (HKLM-x32\...\Synology Assistant) (Version: - )
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.3.8497 - TeamViewer)
TomTom MyDrive Connect 4.1.4.3089 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.4.3089 - TomTom)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 8.51 - Ghisler Software GmbH)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.5.0.0 - Elaborate Bytes)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
WinZip 24.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24125}) (Version: 24.0.13650 - Corel Corporation)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-11-26] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_110.1.671.0_x64__v10z8vjag6ke6 [2020-02-06] (HP Inc.)
KONICA MINOLTA Print Experience -> C:\Program Files\WindowsApps\KONICAMINOLTAINC.KONICAMINOLTAPrintExperience_1.3.0.13_neutral__s63fsn2sety0r [2019-10-07] (KONICA MINOLTA INC)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2001.12.0_x64__k1h2ywk1493x8 [2020-02-28] (LENOVO INC.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-08-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-25] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-25] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20583.0_x64__8wekyb3d8bbwe [2020-03-06] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-02-28] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.34.20074.0_x64__8wekyb3d8bbwe [2020-01-15] (Microsoft Corporation) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20503.0_x64__8wekyb3d8bbwe [2020-03-06] (Microsoft Corporation) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0 [2020-03-11] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3645671178-350016163-1338499739-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2015\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3645671178-350016163-1338499739-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2015\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3645671178-350016163-1338499739-1001_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll (Corel Corporation -> )
CustomCLSID: HKU\S-1-5-21-3645671178-350016163-1338499739-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2015\cs-CZ\acadficn.dll (Autodesk Development Sarl -> Autodesk, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-26] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2014-02-07] (Autodesk, Inc -> Autodesk, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2014-02-07] (Autodesk, Inc -> Autodesk)
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => -> No File
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [DaemonShellExtImage] -> {40966797-8FFE-46C8-9EF8-7003F33CCF0F} => C:\Program Files\DAEMON Tools Pro\DTShl64.dll [2015-02-27] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-04-23] (Google Inc -> Google)
ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2019-10-14] (Corel Corporation -> WinZip Computing)
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => -> No File
ContextMenuHandlers2: [DaemonShellExtDrive] -> {A5415364-784A-41A5-B47A-D452909CA8FF} => C:\Program Files\DAEMON Tools Pro\DTShl64.dll [2015-02-27] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => -> No File
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-04-23] (Google Inc -> Google)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2019-10-14] (Corel Corporation -> WinZip Computing)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-04-23] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2016-12-29] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2019-10-14] (Corel Corporation -> WinZip Computing)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Správa mých zařízení _ SledovaniTV.cz.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=momnkjpcafmkehhcmabppfanllhfnani
ShortcutWithArgument: C:\Users\Vojta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\facebook.lnk -> C:\Users\Vojta\AppData\Local\Programs\Opera\launcher.exe (Opera Software) -> www.facebook.com

==================== Loaded Modules (Whitelisted) =============

2016-09-14 20:29 - 2014-09-03 01:29 - 000950272 _____ () [File not signed] C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\ffmpegsumo.dll
2016-09-14 20:29 - 2014-09-03 01:29 - 000134144 _____ () [File not signed] C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libegl.dll
2016-09-14 20:29 - 2014-09-03 01:29 - 000912384 _____ () [File not signed] C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libglesv2.dll
2013-12-14 02:46 - 2013-12-14 02:46 - 000873984 _____ () [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\acwebbrowser\ffmpegsumo.dll
2014-01-14 19:03 - 2014-01-14 19:03 - 038602752 _____ () [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\acwebbrowser\libcef.dll
2013-12-14 02:46 - 2013-12-14 02:46 - 000102912 _____ () [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\acwebbrowser\libegl.dll
2013-12-14 02:46 - 2013-12-14 02:46 - 000880640 _____ () [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\acwebbrowser\libglesv2.dll
2017-11-01 15:27 - 2017-11-01 15:27 - 013125731 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\AcroForm.api
2017-11-01 15:27 - 2017-11-01 15:27 - 008278627 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\Annots.api
2017-11-01 15:27 - 2017-11-01 15:27 - 001484387 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\DigSig.api
2017-11-01 15:27 - 2017-11-01 15:27 - 001758819 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\EScript.api
2017-11-01 15:27 - 2017-11-01 15:27 - 000110179 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\IA32.api
2017-11-01 15:27 - 2017-11-01 15:27 - 007368291 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\PPKLite.api
2017-11-01 15:27 - 2017-11-01 15:27 - 000174179 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\Updater.api
2017-11-01 15:27 - 2017-11-01 15:27 - 000305763 _____ (Adobe Systems Incorporated) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\plug_ins\weblink.api
2014-02-07 10:57 - 2014-02-07 10:57 - 008677888 _____ (Autodesk) [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\acadbtn.xmx
2019-08-20 21:47 - 2016-12-29 13:29 - 000747464 _____ (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed] C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPI.dll
2019-08-20 21:48 - 2016-12-29 13:29 - 000339072 _____ (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed] C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem\_nvstapisvr64.dll
2012-09-23 19:43 - 2012-09-23 19:43 - 000227328 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\ccme_asym.dll
2012-09-23 19:43 - 2012-09-23 19:43 - 000379904 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\ccme_base.dll
2012-09-23 19:43 - 2012-09-23 19:43 - 000208384 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\ccme_base_non_fips.dll
2012-09-23 19:43 - 2012-09-23 19:43 - 000564736 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\ccme_ecc.dll
2012-09-23 19:43 - 2012-09-23 19:43 - 000471552 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\ccme_ecdrbg.dll
2012-09-23 19:43 - 2012-09-23 19:43 - 000291328 _____ (RSA - The Security Division of EMC) [File not signed] C:\Program Files (x86)\Adobe\Reader 11.0\Reader\cryptocme.dll
2016-09-14 20:29 - 2014-09-03 01:29 - 009994752 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\icudt.dll
2013-05-01 01:48 - 2013-05-01 01:48 - 009956864 _____ (The ICU Project) [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\acwebbrowser\icudt.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-3645671178-350016163-1338499739-1001\Software\Classes\.scr: AutoCADScriptFile =>

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-30 23:42 - 2020-03-12 09:16 - 000000875 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.1 mssplus.mcafee.com

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%INTEL_DEV_REDIST%redist\intel64\compiler;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.1.1 - 172.16.4.210
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\StartupFolder: => "CodeMeter Control Center.lnk"
HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run32: => "Autodesk Desktop App"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\StartupApproved\StartupFolder: => "EvernoteClipper.lnk"
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{689CD1DE-7042-43C8-B51C-A607610668E2}] => (Allow) C:\Program Files\BitComet\BitComet.exe (Xing Wang -> www.BitComet.com)
FirewallRules: [{8313A12B-058C-4882-BC30-1521CA35E788}] => (Allow) C:\Program Files\BitComet\BitComet.exe (Xing Wang -> www.BitComet.com)
FirewallRules: [{07BA7D2E-D784-48A2-91C2-8D957F098EFE}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{39C29D5D-F875-460C-9ACA-53AA327F60C5}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [UDP Query User{AD46EB3E-B964-4C6C-A4E7-B26D7C1FC479}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe (Synology Inc. -> ) [File not signed]
FirewallRules: [TCP Query User{F09B8A28-235F-4B57-A2B0-7109DFFE2951}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe (Synology Inc. -> ) [File not signed]
FirewallRules: [{C83CA4E2-0F70-4C6E-A95A-7BB35432BDD9}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2DD715EE-F9BE-49A1-8FDF-61530F749AB6}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F33D1CF1-7418-4C23-94C7-E1D4599D9F24}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D8DC1BBB-D74F-4EEB-AF5E-F0CE48A3A3F1}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1758A5E9-A978-4434-98D4-4414D0C43876}] => (Allow) LPort=50248
FirewallRules: [{0BF6F038-587E-46AA-A855-208E81601560}] => (Block) C:\Program Files\GRAPHISOFT\ArchiCAD 19\ArchiCAD.exe (Graphisoft SE) [File not signed]
FirewallRules: [{DA2F6EB7-C82C-494F-BE72-5DE895AF5ABA}] => (Block) C:\Program Files\GRAPHISOFT\ArchiCAD 19\CineRender\CineRender 64bit.exe (MAXON Computer GmbH -> MAXON Computer GmbH)
FirewallRules: [{45E8DAC6-6A2E-42D4-9ADF-309739AA386C}] => (Allow) C:\Program Files\GRAPHISOFT\ArchiCAD 19\BIMxUploader.exe (Graphisoft SE) [File not signed]
FirewallRules: [{FBEE6400-C43C-4621-A5D7-493F5B055C8F}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{12A5D606-068D-4F94-9F91-64D9631DD431}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{AE3F35E8-4954-4F79-8DCC-F6E452E861C0}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{B0465E15-4B2D-4766-8525-08970DF31B6D}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{31B1EE8D-14A1-4CE4-95F7-0BE956FD45AE}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{7C4FC2BB-DA8D-44DA-8A19-A7C71B557285}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\ARCHICAD.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [{19CC1750-7115-44CE-AD9E-291AB819516C}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\CineRender\CineRender 64bit.exe No File
FirewallRules: [{88A06735-E9AA-4F42-966D-054241D121D8}] => (Allow) C:\Program Files\GRAPHISOFT\ARCHICAD 20\BIMxUploader.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [{E20ACD71-C8C5-4737-914F-B82FFBC766D8}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\OverwatchServer.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [{049EDAB6-A483-401F-9495-A8931997D279}] => (Allow) LPort=1688
FirewallRules: [{0CF73C32-CBCC-48CB-8885-3CC945F73E4A}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{7138C67D-C383-4798-9E62-EE08456F6B7E}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{C889BC95-C0F8-45AE-972F-5AAA2F76AF34}] => (Allow) C:\Users\Vojta\AppData\Local\Programs\Opera\67.0.3575.53\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{001749B2-A64D-46AE-B8E5-D7B9B88F4822}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A4795BF0-60C1-4CA5-8471-2FA4017E06D2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{F39E0E94-1F5B-4D0E-BEB4-263B2A99FC3F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{331009AE-CC67-4B41-82D3-5ACA13142092}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3ADCA317-D43D-48E9-8BD8-8F718E21F576}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{7540E6B1-26A4-4902-B0C1-804BFA8AAC7B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{8C5243D5-E340-404B-8709-570A4A83A067}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3EA69065-17E6-4226-8B5B-24E0F15E6CE7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FA5AAB0E-7B09-4525-86C4-DED65EF45760}] => (Allow) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe (Piriform Software Ltd -> Piriform Software)
FirewallRules: [{0058CE96-C3C6-4550-A8FF-F90EAB05F5AE}] => (Allow) C:\Users\Vojta\AppData\Local\Programs\Opera\67.0.3575.79\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{2BB29225-1F63-4089-A423-8B7B5DE27591}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{CDD37F5B-3BA9-4F87-8738-E99D406935D5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{8C57C63D-9F4E-4FF5-8378-E85062DD465E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{C36948B4-07C8-4E74-B6D6-85F1DEB8A8EC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{97E1A0EC-B0D6-4AEB-9599-89A71B186EA9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe] => Enabled:CodeMeter Runtime Server
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe] => Enabled:CodeMeter Runtime Server

==================== Restore Points =========================

09-03-2020 12:03:23 Naplánovaný kontrolní bod
13-03-2020 19:25:57 Windows Update
23-03-2020 11:25:19 Windows Update

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (03/23/2020 02:38:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: rtl140.bpl, verze: 14.0.3593.25826, časové razítko: 0x4aef9662
Kód výjimky: 0xc000041d
Posun chyby: 0x0007bd74
ID chybujícího procesu: 0x414
Čas spuštění chybující aplikace: 0x01d6010911e82eab
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\rtl140.bpl
ID zprávy: 6035c757-234c-4f02-90b3-f1d255ef7ea2
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 02:38:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: rtl140.bpl, verze: 14.0.3593.25826, časové razítko: 0x4aef9662
Kód výjimky: 0xc0000005
Posun chyby: 0x0007bd74
ID chybujícího procesu: 0x414
Čas spuštění chybující aplikace: 0x01d6010911e82eab
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\rtl140.bpl
ID zprávy: f97f75b6-0a42-4910-8885-1013921f9288
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 01:39:09 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1244,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (03/23/2020 12:47:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Kód výjimky: 0xc000041d
Posun chyby: 0x003de99f
ID chybujícího procesu: 0x19dc
Čas spuštění chybující aplikace: 0x01d601002b0efab9
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
ID zprávy: 1686a2ea-04bd-4f31-80aa-27f3ac6e213b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 12:47:48 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Kód výjimky: 0xc0000005
Posun chyby: 0x003de99f
ID chybujícího procesu: 0x19dc
Čas spuštění chybující aplikace: 0x01d601002b0efab9
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
ID zprávy: 19ce9881-2aa5-462f-a3bf-5a8d407f7972
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 11:49:57 AM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (5992,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (03/23/2020 11:43:25 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Kód výjimky: 0xc000041d
Posun chyby: 0x003de99f
ID chybujícího procesu: 0x2e58
Čas spuštění chybující aplikace: 0x01d600ff543d7412
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
ID zprávy: b4160838-64aa-4c31-8fe6-587c47d1102d
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 11:43:18 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Kód výjimky: 0xc0000005
Posun chyby: 0x003de99f
ID chybujícího procesu: 0x2e58
Čas spuštění chybující aplikace: 0x01d600ff543d7412
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
ID zprávy: d29971f9-08ce-431a-acdd-1acf5d1a3a43
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (03/23/2020 11:36:42 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Zprostředkovatel monitorování Ochrany System Guard v režimu runtime přestala během spouštění reagovat.

Error: (03/23/2020 11:35:48 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T39I587)
Description: Server {E60687F7-01A1-40AA-86AC-DB1CBF673334} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/23/2020 11:34:41 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Správce stažených map přestala během spouštění reagovat.

Error: (03/23/2020 11:33:48 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Server {E60687F7-01A1-40AA-86AC-DB1CBF673334} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/23/2020 11:30:11 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Autodesk Content Service neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (03/23/2020 11:30:10 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Autodesk Content Service bylo dosaženo časového limitu (45000 ms).

Error: (03/23/2020 11:04:13 AM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-T39I587)
Description: Server {E60687F7-01A1-40AA-86AC-DB1CBF673334} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/23/2020 11:03:16 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Správce stažených map přestala během spouštění reagovat.


Windows Defender:
===================================
Date: 2019-11-08 12:51:26.516
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {D0D033B4-4A2E-4E06-8EE6-418CAF8613A6}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-11-08 12:33:28.979
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {229A3732-9892-4B97-AC97-AEF69B794245}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-11-08 12:10:04.406
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {C1A0F3D7-7614-4089-9F7C-6BD01E35F383}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-11-08 10:47:55.092
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {761BED30-7386-44E1-B20D-8A0D96D87281}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-08-23 14:18:44.387
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win64/AutoKMS
ID: 2147723334
Závažnost: Vysoké
Kategorie: Nástroj
Cesta: file:_C:\WINDOWS\SECOH-QAD.dll; file:_C:\WINDOWS\SECOH-QAD.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.299.2640.0, AS: 1.299.2640.0, NIS: 1.299.2640.0
Verze modulu: AM: 1.1.16200.1, NIS: 1.1.16200.1

Date: 2019-08-21 07:39:57.364
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.299.2464.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16200.1
Kód chyby: 0x80240016
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2019-08-21 02:28:23.201
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Windows Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x80004005
Popis chyby: Nespecifikovaná chyba
Důvod: Ovladač filtru přeskočil prohledávání položek a je v režimu průchodu. Příčinou může být nízký stav prostředků.

CodeIntegrity:
===================================

Date: 2020-03-23 15:27:57.695
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 15:27:57.690
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\snxhk.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 15:27:53.381
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 15:27:53.345
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\snxhk.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 15:19:07.810
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 15:19:07.804
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\snxhk.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 15:19:07.441
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 15:19:07.437
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\snxhk.dll that did not meet the Microsoft signing level requirements.

==================== Memory info ===========================

BIOS: LENOVO 9ECN36WW(V2.00) 01/12/2015
Motherboard: LENOVO Lenovo Y50-70
Processor: Intel(R) Core(TM) i5-4210H CPU @ 2.90GHz
Percentage of memory in use: 65%
Total physical RAM: 8104.27 MB
Available physical RAM: 2834.1 MB
Total Virtual: 14760.27 MB
Available Virtual: 8419.55 MB

==================== Drives ================================

Drive c: (hadr) (Fixed) (Total:888.87 GB) (Free:618.43 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.17 GB) NTFS

\\?\Volume{568a16f3-ea5a-447b-801a-468914285d17}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.68 GB) NTFS
\\?\Volume{f60f5ad0-965e-4d9e-82f0-2b32cdea9b29}\ (PBR_DRV) (Fixed) (Total:15.31 GB) (Free:5.32 GB) NTFS
\\?\Volume{137847a9-9d22-4a7c-bf00-927c47d41465}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B8499F7E)

Partition: GPT.

==================== End of Addition.txt =======================

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 15:55
od Gárf
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-03-2020
Ran by Vojta (administrator) on DESKTOP-T39I587 (LENOVO 20378) (23-03-2020 15:22:07)
Running from C:\Users\Vojta\Desktop
Loaded Profiles: Vojta (Available Profiles: Vojta)
Platform: Windows 10 Home Version 1903 18362.720 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Adobe Systems, Incorporated -> Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Autodesk) [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\AcWebBrowser\AcWebBrowser.exe
(Autodesk) [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\AcWebBrowser\AcWebBrowser.exe
(Autodesk) [File not signed] C:\Program Files\Autodesk\AutoCAD 2015\AcWebBrowser\AcWebBrowser.exe
(Autodesk, Inc -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Autodesk, Inc -> Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Autodesk, Inc -> Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Autodesk, Inc -> Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Autodesk, Inc -> Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
(Autodesk, Inc -> Autodesk, Inc.) C:\Program Files\Autodesk\AutoCAD 2015\acad.exe
(Autodesk, Inc -> Autodesk, Inc.) C:\Program Files\Common Files\Autodesk Shared\WSCommCntr4\lib\WSCommCntr4.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Corel Corporation -> Corel Corporation) C:\Program Files\WinZip\WZUpdateNotifier.exe
(Corel Corporation -> WinZip Computing) C:\Program Files\WinZip\WzPreloader.exe
(Corel Corporation -> WinZip Computing, S.L.) C:\Program Files\WinZip\FAHWindow64.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
(Flexera Software LLC -> Flexera Software LLC) C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
(Fortemedia Inc. -> ) C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company -> HP) C:\Windows\System32\HPSIsvc.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee Security Scan\3.11.1702\SSScheduler.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.19081.28230.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20022.11011.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msinfo32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Opera Software AS -> Opera Software) C:\Users\Vojta\AppData\Local\Programs\Opera\assistant\browser_assistant.exe
(Opera Software AS -> Opera Software) C:\Users\Vojta\AppData\Local\Programs\Opera\assistant\browser_assistant.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Oracle America, Inc. -> Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Piriform Software Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\1.5.21.0\CCleanerBrowserCrashHandler.exe
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\1.5.21.0\CCleanerBrowserCrashHandler64.exe
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synology Inc. -> ) [File not signed] C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-04] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3947704 2015-10-20] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [277664 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2019-10-14] (Corel Corporation -> Corel Corporation)
HKLM\...\Run: [WinZip FAH] => C:\Program Files\WinZip\FAHConsole.exe [436704 2019-10-14] (Corel Corporation -> WinZip Computing, S.L.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [721856 2016-07-01] (Autodesk, Inc -> Autodesk, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-16] (Piriform Software Ltd -> Piriform Ltd)
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Run: [Opera Browser Assistant] => C:\Users\Vojta\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3024408 2020-03-19] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Policies\Explorer: []
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.149\Installer\chrmstp.exe [2020-03-20] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{052EB454-9F19-CB42-7875-807F79F311C4}] -> C:\Program Files (x86)\CCleaner Browser\Application\80.0.3625.135\Installer\chrmstp.exe [2020-03-11] (Piriform Software Ltd -> Piriform Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk [2017-02-28]
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2020-03-12]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.1702\SSScheduler.exe (McAfee, LLC -> McAfee, LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2020-03-09]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (Corel Corporation -> WinZip Computing)
Startup: C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2017-08-14]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {042306D0-6FCA-41D1-89E0-CBC3757F6959} - System32\Tasks\CCleaner Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [1887992 2020-03-09] (Piriform Software Ltd -> Piriform Software)
Task: {06B033D5-4B7E-4C32-83C7-8C9134A2284A} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-03-11] (Adobe Inc. -> Adobe)
Task: {1383CEF3-5DF0-45A4-8F7A-21DF8B8F8187} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-16] (Piriform Software Ltd -> Piriform Ltd)
Task: {227A5FF4-4AFE-4950-9C37-51535CC7FB5F} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1626328 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {309EBAEB-C57D-4C7F-9173-43E3BC4E1F7B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {39FCD610-61EB-4DA7-B1F9-07A3B550462A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {4DA2167E-2774-4F23-AEA0-430FCED7DE15} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
Task: {4EFF5277-3A84-42A4-B203-549FFA33A1DF} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe
Task: {4FF18C40-ACFD-45FC-9DF5-E4C4314B8E84} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1660520 2020-02-28] (Avast Software s.r.o. -> Avast Software)
Task: {533D0C99-D69A-4077-B910-B6FE60C3E2E2} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3894664 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
Task: {63FD0209-96FA-4A3B-8986-EC364D2B60D7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_344_pepper.exe [1453624 2020-03-11] (Adobe Inc. -> Adobe)
Task: {6DB50304-A7BD-409F-9472-2C0FD5DB68AF} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2019-10-14] (Corel Corporation -> Corel Corporation)
Task: {7647976C-CE86-4037-83FD-175C47D3E9EB} - System32\Tasks\Opera scheduled Autoupdate 1546713095 => C:\Users\Vojta\AppData\Local\Programs\Opera\launcher.exe [1538584 2020-03-12] (Opera Software AS -> Opera Software)
Task: {79A8EF2B-6C26-40AD-BE83-305561F0C08D} - System32\Tasks\Opera scheduled assistant Autoupdate 1547232680 => C:\Users\Vojta\AppData\Local\Programs\Opera\launcher.exe [1538584 2020-03-12] (Opera Software AS -> Opera Software)
Task: {90BE6455-3CA8-4CCA-AA7D-0BED9D475B6D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {915110EC-4928-4AF1-B9D7-F2F35FC85A31} - System32\Tasks\CCleanerUpdateTaskMachineUA => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [209128 2019-10-10] (Piriform Software Ltd -> Piriform Software)
Task: {A930928B-667A-4F4C-8AC1-E4FE8EE5B94A} - System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-T39I587-Vojta DESKTOP-T39I587 => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [470720 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {AF8241B0-081F-425C-B8D5-188FA5A1591C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.)
Task: {BBD9432B-C58B-4832-8C87-2E2581A72FFB} - System32\Tasks\CCleanerUpdateTaskMachineCore => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [209128 2019-10-10] (Piriform Software Ltd -> Piriform Software)
Task: {C737768F-0735-46E8-B8BD-1A9D5F8ADC2A} - System32\Tasks\CCleaner Browser Heartbeat Task (Logon) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [1887992 2020-03-09] (Piriform Software Ltd -> Piriform Software)
Task: {CABC7ADE-DFC5-48D7-BEB3-A1354BA608BE} - System32\Tasks\ASC Task (One-Time) => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCPromote.exe
Task: {D33787A4-3F46-428B-A798-FC2CF49AFD9E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.)
Task: {D3C8764C-6E77-4E2D-8D1F-02A29AB662B1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {F0CD7647-A826-493E-B8DE-DF733C8878ED} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2019-10-14] (Corel Corporation -> Corel Corporation)
Task: {FC98907A-DF9D-45FE-A6E7-B792A80682CE} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-16] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {FE63379A-2AB0-47EB-AA19-53AAFFE091CA} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2019-10-14] (Corel Corporation -> Corel Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\..\Interfaces\{63E80E85-4CB2-46F2-9897-275B5F83B42A}: [NameServer] 172.16.4.210 195.250.128.34
Tcpip\..\Interfaces\{a519632e-1960-48f9-be54-77c9a5168884}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f8baf662-7d77-4173-bef7-184156f0e486}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2020-03-10] (McAfee, LLC -> McAfee, LLC)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-06-03] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2017-03-20] (EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-03-10] (McAfee, LLC -> McAfee, LLC)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-06-03] (Oracle America, Inc. -> Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-03-10] [UpdateUrl:hxxps://www.siteadvisor.com/waffinstall/update.json]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-06-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-06-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-29] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-29] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default [2020-03-23]
CHR Notifications: Default -> hxxps://cz.pinterest.com; hxxps://cze.patkardevelopers.com; hxxps://postovnezdarma.cz; hxxps://www.akcniletaky.com; hxxps://www.lgshop.cz; hxxps://www.paradyz.com
CHR Extension: (Prezentace) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-19]
CHR Extension: (Dokumenty) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-19]
CHR Extension: (Disk Google) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-20]
CHR Extension: (Vyhledávání Google) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Tabulky) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-19]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-02-12]
CHR Extension: (Dokumenty Google offline) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-14]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-03-18]
CHR Extension: (FormApps Extension) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2017-06-15]
CHR Extension: (Správa mých zařízení | SledovaniTV.cz) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\momnkjpcafmkehhcmabppfanllhfnani [2017-07-13]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Gmail) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-07]
CHR Extension: (Chrome Media Router) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-03-20]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1295376 2016-07-01] (Autodesk, Inc -> Autodesk Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6046624 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc -> Autodesk, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [413472 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57536 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (Shanghai Comet Network Technology -> www.BitComet.com)
S2 ccleaner; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [209128 2019-10-10] (Piriform Software Ltd -> Piriform Software)
S3 CCleanerBrowserElevationService; C:\Program Files (x86)\CCleaner Browser\Application\80.0.3625.135\elevation_service.exe [973760 2020-03-09] (Piriform Software Ltd -> Piriform Software)
S3 ccleanerm; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [209128 2019-10-10] (Piriform Software Ltd -> Piriform Software)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1443520 2016-04-04] (Disc Soft Ltd -> Disc Soft Ltd)
R3 Disc Soft Pro Bus Service; C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe [1267984 2015-02-27] (Disc Soft Ltd -> Disc Soft Ltd)
R2 HPSIService; C:\WINDOWS\system32\HPSIsvc.exe [126856 2012-11-08] (Hewlett-Packard Company -> HP)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373752 2017-04-23] (Intel(R) pGFX -> Intel Corporation)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit Information Technology -> IObit)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [907224 2020-03-10] (McAfee, LLC -> McAfee, LLC)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.1702\McCHSvc.exe [407088 2020-03-02] (McAfee, LLC -> McAfee, LLC)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13206544 2020-03-09] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248840 2016-03-18] (Synology Inc. -> ) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2020-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2020-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37864 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [205576 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [271120 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [206608 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [64272 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2020-02-26] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [279360 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42976 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [175400 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110560 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84056 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848672 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [458584 2020-03-11] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [235184 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316256 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R3 busenum; C:\WINDOWS\System32\drivers\busenum.sys [57824 2012-08-03] (Synology Inc. -> Windows (R) Win 7 DDK provider)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-04-06] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-04-06] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtproscsibus; C:\WINDOWS\System32\drivers\dtproscsibus.sys [30352 2016-04-25] (Disc Soft Ltd -> Disc Soft Ltd)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [19968 2012-11-08] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvltwu.inf_amd64_dc8ffafad3ea7ddd\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation -> NVIDIA Corporation)
R3 ROCKEYNT; C:\WINDOWS\system32\DRIVERS\Rockey4.sys [36904 2016-05-06] (Feitian Technologies Co., Ltd. -> Feitian Technologies Co., Ltd.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek Semiconductor Corp -> Realtek )
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [761600 2015-06-15] (Realtek Semiconductor Corp -> Realsil Semiconductor Corporation)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-10-20] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2020-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2020-01-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2020-01-10] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-03-23 15:22 - 2020-03-23 15:24 - 000034087 _____ C:\Users\Vojta\Desktop\FRST.txt
2020-03-23 15:20 - 2020-03-23 15:23 - 000000000 ____D C:\FRST
2020-03-23 15:18 - 2020-03-23 15:18 - 002279936 _____ (Farbar) C:\Users\Vojta\Desktop\FRST64.exe
2020-03-23 11:30 - 2020-03-23 11:36 - 000000004 ____H C:\ProgramData\cm-lock
2020-03-23 07:42 - 2020-03-23 07:42 - 000344178 _____ C:\Users\Vojta\Downloads\D12_VÝKAZ_CHVOJNO_DPS_200319.pdf
2020-03-21 12:28 - 2020-03-21 12:28 - 000353747 _____ C:\Users\Vojta\Desktop\Výpověď smlouvy AXA.pdf
2020-03-21 09:30 - 2020-03-21 09:30 - 002384037 _____ C:\Users\Vojta\Downloads\HROMOSVOD.dwg
2020-03-19 11:44 - 2020-02-26 07:35 - 000368056 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2020-03-19 10:48 - 2020-03-19 10:48 - 000000062 _____ C:\Users\Vojta\Desktop\CHVOJNO_18_03_2020_DPS - kopie.pln.lck
2020-03-19 10:36 - 2020-03-18 13:35 - 172422864 _____ C:\Users\Vojta\Desktop\CHVOJNO_18_03_2020_DPS - kopie.pln
2020-03-19 07:38 - 2020-03-18 21:07 - 002501526 _____ C:\Users\Vojta\Desktop\xxx.bak
2020-03-19 07:13 - 2020-03-19 07:13 - 000099612 _____ C:\Users\Vojta\Downloads\31949894 (1).pdf
2020-03-18 16:16 - 2020-03-19 07:39 - 001342214 _____ C:\Users\Vojta\Desktop\2NP VZT 6.3.2020.dwg
2020-03-18 16:05 - 2020-03-19 07:38 - 002566981 _____ C:\Users\Vojta\Desktop\1NP VZT 6.3.2020.dwg
2020-03-18 11:38 - 2020-03-23 15:01 - 000000000 ____D C:\Users\Vojta\AppData\Local\TeamViewer
2020-03-18 11:37 - 2020-03-23 11:30 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-03-18 11:37 - 2020-03-18 11:37 - 000001116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer.lnk
2020-03-18 11:37 - 2020-03-18 11:37 - 000001104 _____ C:\Users\Public\Desktop\TeamViewer.lnk
2020-03-18 11:27 - 2020-03-18 11:28 - 026985448 _____ (TeamViewer Germany GmbH) C:\Users\Vojta\Downloads\TeamViewer_Setup.exe
2020-03-18 10:50 - 2020-03-18 10:50 - 008542758 _____ C:\Users\Vojta\Downloads\Ceník+obnovitelných+zdrojů_08_2019.pdf
2020-03-18 10:26 - 2020-03-18 10:26 - 000241857 _____ C:\Users\Vojta\Downloads\Vitoclima_200-S (3).pdf
2020-03-18 10:25 - 2020-03-18 10:25 - 000201319 _____ C:\Users\Vojta\Downloads\LTU Vitoclima 200-S_CZ.pdf
2020-03-18 10:25 - 2020-03-18 10:25 - 000201319 _____ C:\Users\Vojta\Downloads\LTU Vitoclima 200-S_CZ (1).pdf
2020-03-18 10:11 - 2020-03-18 10:11 - 000241857 _____ C:\Users\Vojta\Downloads\Vitoclima_200-S.pdf
2020-03-18 07:51 - 2020-03-18 12:35 - 000046080 _____ C:\Users\Vojta\Desktop\D.1.4.4. VZT - ROZPOČET.xls
2020-03-17 09:37 - 2020-03-17 09:37 - 000093643 _____ C:\Users\Vojta\Downloads\Bilanční výpis 2019.pdf
2020-03-17 09:27 - 2020-03-17 09:27 - 000296760 _____ C:\Users\Vojta\Desktop\Žádost o koupi palivové dřevo Novák.pdf
2020-03-16 16:58 - 2020-03-16 16:58 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (8).pdf
2020-03-16 16:22 - 2020-03-16 16:22 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st.pdf
2020-03-13 19:51 - 2020-03-13 19:51 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-03-13 19:51 - 2020-03-13 19:51 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 006520776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 004563416 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-03-13 19:51 - 2020-03-13 19:51 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 001398584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-03-13 19:51 - 2020-03-13 19:51 - 001077048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-03-13 19:51 - 2020-03-13 19:51 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2020-03-13 19:51 - 2020-03-13 19:51 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-03-13 15:08 - 2020-03-13 15:08 - 000099612 _____ C:\Users\Vojta\Downloads\31949894.pdf
2020-03-13 14:23 - 2020-03-13 14:23 - 000117364 _____ C:\Users\Vojta\Downloads\fbldfsl (3).pdf
2020-03-13 14:22 - 2020-03-13 14:22 - 000117364 _____ C:\Users\Vojta\Downloads\fbldfsl (2).pdf
2020-03-12 09:16 - 2020-03-12 09:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2020-03-12 09:15 - 2020-03-12 10:17 - 000000000 ____D C:\ProgramData\McAfee Security Scan
2020-03-11 23:38 - 2020-03-11 23:38 - 011607552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2020-03-11 23:38 - 2020-03-11 23:38 - 009711616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 022635008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 019812352 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 018027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 007755776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 007259648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 006285312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 005911040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 004855808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 004580352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 004348408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 004129648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 003819520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 003488768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 003243296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002956688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-03-11 23:37 - 2020-03-11 23:37 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-03-11 23:37 - 2020-03-11 23:37 - 002494744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002315680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002224952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002180408 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002072664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002031104 _____ C:\WINDOWS\system32\rdpnano.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001867816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001835128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001770552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001555904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001490640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001417976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001282944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001273856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001108040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001098720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001080832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000757632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbc32.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000604160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbc32.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2020-03-11 23:37 - 2020-03-11 23:37 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacEncoder.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacEncoder.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-03-11 23:37 - 2020-03-11 23:37 - 000097080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000042296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2020-03-11 23:37 - 2020-03-11 23:37 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-03-11 23:37 - 2020-03-11 23:37 - 000032056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2020-03-11 23:37 - 2020-03-11 23:37 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000019768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2020-03-11 23:36 - 2020-03-11 23:37 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 006084344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 005112832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 003971808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002875904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 002740736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002584008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002561536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002307584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002305536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002259872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002021888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001985104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001684992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001665416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001484600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001284096 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001283600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2020-03-11 23:36 - 2020-03-11 23:36 - 001264128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001260544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001218632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 001190912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001088000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001054376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001031680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001007672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000935040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000776488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000769552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000668296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000627216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000613888 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000551824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000526848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000478792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2020-03-11 23:36 - 2020-03-11 23:36 - 000403456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcomapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000213984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeHelper.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUpdateAgent.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnpclean.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000136328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\omadmapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\NdisImPlatform.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000133944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000130112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000120560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000102760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000089568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000068408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceReactivation.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enterpriseresourcemanager.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmRes.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000042336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afunix.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmtask.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxstrace.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Drivers\afunix.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msauserext.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtprio.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchTM.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtprio.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-03-11 23:35 - 2020-03-11 23:35 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 006436352 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 004048896 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 003799552 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 003552768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 003371720 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 002773568 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 002768440 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 002698040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 002087376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001999952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001972536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001757304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-03-11 23:35 - 2020-03-11 23:35 - 001743888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001513040 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 001396152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001394168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-03-11 23:35 - 2020-03-11 23:35 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001260480 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001182448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 001153024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001071184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000983896 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000929144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000921088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000898048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000877232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000796904 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000741392 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000734720 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetup.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000661816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000636848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxs.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000605896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000489984 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-03-11 23:35 - 2020-03-11 23:35 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\slui.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000320312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000260920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000248064 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000234984 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000221200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000165504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000164776 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceMetadataRetrievalClient.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\profapi.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000120048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000107832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000098104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000089616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterpriseresourcemanager.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000063288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxstrace.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msauserext.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\MUILanguageCleanup.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\LangCleanupSysprepAction.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchTM.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetupproxyserv.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 007905784 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 004622280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 004471296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 004140544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 003728896 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 003708928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 003587896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 003260928 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 003143168 _____ (Microsoft Corporation) C:\WINDOWS\system32\directml.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002870272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002808832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002715648 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 002522112 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002474496 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002453504 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002289152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002157056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001823232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001764336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001762304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001751040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001657120 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001609216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001581056 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001481216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 001428992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 001180160 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000945384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000908504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000833616 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000802304 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000649728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000642216 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000637240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000540672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2020-03-11 23:34 - 2020-03-11 23:34 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000531768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2020-03-11 23:34 - 2020-03-11 23:34 - 000522384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000459688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000429880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Acx01000.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000250896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringMgr.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000224056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000222520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ataport.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000208696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000201744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000201528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000199992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000183608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000180232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000174392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000146712 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000141840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000128312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Taskbar.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2020-03-11 23:34 - 2020-03-11 23:34 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\monitor.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000067112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000066336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlrmdr.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmRes.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000056632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pciidex.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAProfileNotificationHandler.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000048256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbs.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2020-03-11 23:34 - 2020-03-11 23:34 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000030008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\atapi.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000029712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tbs.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wci.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000019984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelide.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpnotify.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000016912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pciide.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUserRes.dll
2020-03-11 23:33 - 2020-03-11 23:33 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthA2dp.sys
2020-03-11 23:05 - 2020-03-11 23:06 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-03-11 23:05 - 2020-03-11 23:06 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-03-11 18:52 - 2020-03-11 18:53 - 000117364 _____ C:\Users\Vojta\Downloads\fbldfsl (1).pdf
2020-03-11 18:41 - 2020-03-11 18:41 - 000117364 _____ C:\Users\Vojta\Downloads\fbldfsl.pdf
2020-03-11 11:37 - 2020-03-11 11:37 - 000540672 _____ C:\Users\Vojta\Downloads\Vetraci_mrizka_pro_instalaci_do_kruhoveho_p.rfa
2020-03-10 16:07 - 2020-03-10 16:07 - 012586088 _____ C:\Users\Vojta\Downloads\isover_vario_7-2017.pdf
2020-03-10 14:19 - 2020-03-10 14:20 - 171774448 _____ C:\Users\Vojta\Desktop\CHVOJNO_10_03_2020_DPS.pln
2020-03-09 14:38 - 2020-03-09 14:38 - 000911809 _____ C:\Users\Vojta\Downloads\om.zip
2020-03-09 13:42 - 2020-03-09 13:42 - 000911809 _____ C:\Users\Vojta\Downloads\ISOLIN-ACAD.zip
2020-03-09 13:42 - 2020-03-09 13:42 - 000000000 ____D C:\Users\Vojta\Downloads\ISOLIN-ACAD
2020-03-09 13:40 - 2020-03-09 13:40 - 000001621 _____ C:\Users\Vojta\Downloads\JS.LIN
2020-03-09 10:03 - 2020-03-09 10:03 - 000111267 _____ C:\Users\Vojta\Downloads\KL_8x75_160_OC.dwg
2020-03-09 08:40 - 2020-03-21 14:03 - 000002696 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 2
2020-03-09 08:40 - 2020-03-21 14:03 - 000002694 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 3
2020-03-09 08:40 - 2020-03-21 14:03 - 000002694 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 1
2020-03-09 08:39 - 2020-03-09 08:55 - 000000000 ____D C:\Users\Vojta\AppData\Local\WinZip
2020-03-09 08:39 - 2020-03-09 08:40 - 000000000 ____D C:\ProgramData\WinZip
2020-03-09 08:39 - 2020-03-09 08:39 - 000002091 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip.lnk
2020-03-09 08:39 - 2020-03-09 08:39 - 000001991 _____ C:\Users\Public\Desktop\WinZip.lnk
2020-03-09 08:39 - 2020-03-09 08:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2020-03-09 08:39 - 2020-03-09 08:39 - 000000000 ____D C:\Program Files\WinZip
2020-03-09 08:38 - 2020-03-09 08:38 - 000959304 _____ (WinZip Computing) C:\Users\Vojta\Downloads\winzip24-lan.exe
2020-03-09 08:38 - 2020-03-09 08:38 - 000000000 ____D C:\ProgramData\UniqueId
2020-03-06 15:29 - 2020-03-06 15:29 - 001291364 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q350-tr- (2).pdf
2020-03-06 15:27 - 2020-03-06 15:27 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (7).pdf
2020-03-06 15:27 - 2020-03-06 15:27 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (6).pdf
2020-03-06 14:54 - 2020-03-06 14:54 - 000249620 _____ C:\Users\Vojta\Downloads\SPIRO.pdf
2020-03-06 14:51 - 2020-03-06 14:51 - 000218732 _____ C:\Users\Vojta\Downloads\M001.DWG
2020-03-06 14:48 - 2020-03-06 14:48 - 001011499 _____ C:\Users\Vojta\Downloads\OVAL.dwg
2020-03-06 14:45 - 2020-03-06 14:45 - 000730266 _____ C:\Users\Vojta\Downloads\Dynamic_Blocks.dwg
2020-03-06 10:27 - 2020-03-06 10:21 - 003138903 _____ C:\Users\Vojta\Desktop\1.NP VZT DPS.bak
2020-03-06 08:04 - 2020-03-20 07:19 - 000002080 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2020-03-05 14:11 - 2020-03-05 14:11 - 000241857 _____ C:\Users\Vojta\Downloads\Vitoclima_200-S (2).pdf
2020-03-05 14:11 - 2020-03-05 14:11 - 000241857 _____ C:\Users\Vojta\Downloads\Vitoclima_200-S (1).pdf
2020-03-03 15:26 - 2020-03-03 15:26 - 002209020 _____ C:\Users\Vojta\Downloads\as-gw-aqualoop-cz-prospekt.pdf
2020-03-03 10:42 - 2020-03-03 10:42 - 000069349 _____ C:\Users\Vojta\Downloads\ND-12_ ND12Z.pdf
2020-03-03 10:41 - 2020-03-03 10:41 - 000593840 _____ C:\Users\Vojta\Downloads\Technologický postup montáže nádrží J32-105, ND, 1.7.2019.pdf
2020-03-03 10:40 - 2020-03-03 10:40 - 000119050 _____ C:\Users\Vojta\Downloads\B00238-1 - Vysoké Chvojno (Pardubice), RAB Stavby, s.r.o., 2x ND12.pdf
2020-03-02 17:02 - 2020-03-12 09:16 - 000002022 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2020-03-02 14:58 - 2020-03-02 14:58 - 004415871 _____ C:\Users\Vojta\Downloads\Sika and Tricosal_CZ_web.pdf
2020-02-28 10:33 - 2020-02-28 10:33 - 000525032 _____ C:\Users\Vojta\Downloads\D. 2.01 PŮDORYS STROPU.pdf
2020-02-28 09:25 - 2020-02-28 09:25 - 000647412 _____ C:\Users\Vojta\Downloads\C. 03 KOORDINAČNÍ SITUAČNÍ VÝKRES.pdf
2020-02-27 14:45 - 2020-02-27 14:45 - 001499935 _____ C:\Users\Vojta\Downloads\CN_Martínková_Martina.pdf
2020-02-27 10:56 - 2020-02-27 10:56 - 000638137 _____ C:\Users\Vojta\Downloads\duplex_r5_cz_2016_06.pdf
2020-02-26 15:40 - 2020-02-26 15:40 - 000099924 _____ C:\Users\Vojta\Downloads\Faktura_2080542.pdf
2020-02-26 13:09 - 2020-02-26 13:09 - 000742836 _____ C:\Users\Vojta\Downloads\PBŘ - Požárně bezpečnostní řešení (1).pdf
2020-02-26 13:05 - 2020-02-26 13:05 - 000742836 _____ C:\Users\Vojta\Downloads\PBŘ - Požárně bezpečnostní řešení.pdf
2020-02-26 07:35 - 2020-02-26 07:35 - 000235184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2020-02-26 07:35 - 2020-02-26 07:35 - 000175400 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2020-02-25 15:35 - 2020-02-25 15:35 - 001463998 _____ C:\Users\Vojta\Downloads\asset-katalog-idealni-instalace-s-comfoair-q-pro-instalatery (2).pdf
2020-02-25 15:35 - 2020-02-25 15:35 - 001463998 _____ C:\Users\Vojta\Downloads\asset-katalog-idealni-instalace-s-comfoair-q-pro-instalatery (1).pdf
2020-02-25 15:35 - 2020-02-25 15:35 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (5).pdf
2020-02-25 15:35 - 2020-02-25 15:35 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (4).pdf
2020-02-25 15:35 - 2020-02-25 15:35 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (3).pdf
2020-02-25 15:31 - 2020-02-25 15:31 - 001442595 _____ C:\Users\Vojta\Downloads\asset-katalog-chytre-domy-s-comfoair-q-pro-projektanty.pdf

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-03-23 15:12 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-03-23 14:38 - 2016-01-31 20:27 - 000000000 ____D C:\Users\Vojta\AppData\Local\CrashDumps
2020-03-23 12:32 - 2019-08-20 21:39 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-03-23 11:49 - 2019-08-20 22:20 - 000005246 _____ C:\WINDOWS\system32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-T39I587-Vojta DESKTOP-T39I587
2020-03-23 11:37 - 2020-01-06 07:52 - 000000000 ____D C:\Users\Vojta\Downloads\opera autoupdate
2020-03-23 11:31 - 2017-09-20 18:17 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-03-23 11:31 - 2015-10-20 17:41 - 000000000 __SHD C:\Users\Vojta\IntelGraphicsProfiles
2020-03-23 11:30 - 2019-08-20 22:20 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-03-23 11:30 - 2016-08-05 07:14 - 000000000 ____D C:\ProgramData\NVIDIA
2020-03-23 11:29 - 2019-03-19 05:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-03-23 11:27 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-03-23 09:09 - 2016-08-19 13:03 - 000000000 ____D C:\Users\Vojta\Graphisoft
2020-03-23 09:07 - 2017-12-20 21:30 - 000000000 ____D C:\Users\Vojta\AppData\Local\Packages
2020-03-23 07:38 - 2019-08-20 22:20 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3645671178-350016163-1338499739-1001
2020-03-23 07:37 - 2019-09-06 12:11 - 000002410 _____ C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-23 07:37 - 2015-10-20 17:44 - 000000000 ___RD C:\Users\Vojta\OneDrive
2020-03-21 19:01 - 2019-12-03 21:08 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2020-03-21 14:49 - 2019-08-20 22:20 - 000003474 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-21 14:49 - 2019-08-20 22:20 - 000003350 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-21 14:03 - 2019-12-03 21:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2020-03-21 14:03 - 2019-10-10 14:13 - 000003104 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Hourly)
2020-03-21 14:03 - 2019-10-10 14:13 - 000002622 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Logon)
2020-03-21 14:03 - 2019-10-10 14:11 - 000003452 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineUA
2020-03-21 14:03 - 2019-10-10 14:11 - 000003228 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineCore
2020-03-21 14:03 - 2019-10-09 08:26 - 000003856 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1547232680
2020-03-21 14:03 - 2019-09-24 07:01 - 000003786 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-03-21 14:03 - 2019-09-24 07:01 - 000003488 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2020-03-21 14:03 - 2019-08-20 22:20 - 000003602 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1546713095
2020-03-21 14:03 - 2019-08-20 22:20 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-21 14:03 - 2019-08-20 22:20 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-03-21 14:03 - 2019-08-20 22:20 - 000002736 _____ C:\WINDOWS\system32\Tasks\AutoKMS
2020-03-21 14:03 - 2019-08-20 22:20 - 000002558 _____ C:\WINDOWS\system32\Tasks\ASC Task (One-Time)
2020-03-21 14:03 - 2019-08-20 22:20 - 000002548 _____ C:\WINDOWS\system32\Tasks\AutoPico Daily Restart
2020-03-21 14:03 - 2019-08-20 22:20 - 000002162 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-03-20 17:57 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-03-20 17:57 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-03-20 07:19 - 2019-12-03 21:11 - 000002092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2020-03-20 07:02 - 2015-10-20 17:45 - 000002305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-03-19 11:44 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-03-19 07:04 - 2015-11-05 17:36 - 000000000 ____D C:\ProgramData\ProductData
2020-03-18 12:38 - 2019-12-03 20:26 - 000537776 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-03-18 11:37 - 2016-04-25 16:04 - 000000000 ____D C:\Users\Vojta\AppData\Roaming\TeamViewer
2020-03-18 09:09 - 2019-01-05 19:31 - 000001448 _____ C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2020-03-18 07:55 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2020-03-14 01:29 - 2019-08-20 22:05 - 001693640 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-03-14 01:29 - 2019-03-19 12:55 - 000718198 _____ C:\WINDOWS\system32\perfh005.dat
2020-03-14 01:29 - 2019-03-19 12:55 - 000145242 _____ C:\WINDOWS\system32\perfc005.dat
2020-03-14 01:16 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-03-14 01:16 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-03-13 12:47 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2020-03-12 09:16 - 2019-09-24 07:35 - 000000000 ____D C:\Program Files\McAfee Security Scan
2020-03-12 01:03 - 2017-12-20 21:51 - 000000000 ___RD C:\Users\Vojta\3D Objects
2020-03-12 01:03 - 2015-09-10 06:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\setup
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Windows Defender
2020-03-12 00:55 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\servicing
2020-03-11 23:58 - 2015-10-20 19:44 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-03-11 23:47 - 2015-10-20 19:44 - 121542864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-03-11 23:05 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-03-11 23:04 - 2019-12-11 08:21 - 008491064 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2020-03-11 23:04 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-03-11 19:18 - 2019-10-10 14:13 - 000002391 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner Browser.lnk
2020-03-11 19:18 - 2019-10-10 14:11 - 000000000 ____D C:\Program Files (x86)\CCleaner Browser
2020-03-11 12:02 - 2019-12-03 21:08 - 000458584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2020-03-06 10:44 - 2015-10-28 21:13 - 000000000 ____D C:\Fakturace
2020-02-26 07:35 - 2019-12-03 21:08 - 000848672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000316256 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000279360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000271120 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000206608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000205576 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000110560 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000084056 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000064272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000042976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000037864 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000016304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys

==================== Files in the root of some directories ========

2017-07-14 12:13 - 2020-01-13 21:27 - 000007610 _____ () C:\Users\Vojta\AppData\Local\Resmon.ResmonCfg
2017-11-25 12:08 - 2017-11-25 12:08 - 000000000 _____ () C:\Users\Vojta\AppData\Local\{C4850B69-86DD-405A-AAE3-64C9C9823ACB}

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 16:02
od Rudy
Zdravím!
Spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 18:50
od Gárf
# -------------------------------
# Malwarebytes AdwCleaner 8.0.3.0
# -------------------------------
# Build: 03-03-2020
# Database: 2020-03-13.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 03-23-2020
# Duration: 00:00:08
# OS: Windows 10 Home
# Cleaned: 21
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

Deleted C:\Program Files (x86)\Common Files\IObit\Advanced SystemCare
Deleted C:\ProgramData\IObit\Advanced SystemCare
Deleted C:\Users\Public\Documents\Downloaded Installers
Deleted C:\Users\Vojta\AppData\Local\slimware utilities inc
Deleted C:\Users\Vojta\AppData\Roaming\IObit\Advanced SystemCare
Deleted C:\Users\Vojta\AppData\Roaming\IObit\Advanced SystemCare V7
Deleted C:\Users\Vojta\AppData\Roaming\RPEng
Deleted C:\Users\Vojta\AppData\Roaming\Solvusoft

***** [ Files ] *****

Deleted C:\Windows\System32\roboot64.exe

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKCU\Software\csastats
Deleted HKLM\SOFTWARE\CLASSES\DIRECTORY\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted HKLM\SOFTWARE\CLASSES\DRIVE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted HKLM\SOFTWARE\CLASSES\LNKFILE\SHELLEX\CONTEXTMENUHANDLERS\Advanced SystemCare
Deleted HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\Advanced SystemCare
Deleted HKLM\Software\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}
Deleted HKLM\Software\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}
Deleted HKLM\Software\Wow6432Node\IOBIT\ASC
Deleted HKLM\Software\Wow6432Node\IObit\Advanced SystemCare
Deleted HKLM\Software\Wow6432Node\IObit\RealTimeProtector
Deleted HKLM\Software\Wow6432Node\\Classes\Interface\{BA935377-E17C-4475-B1BF-DE3110613A99}
Deleted HKLM\Software\Wow6432Node\\Classes\TypeLib\{60AD0991-ECD4-49DC-B170-8B7E7C60F51B}

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [3210 octets] - [23/03/2020 18:36:26]
AdwCleaner[S01].txt - [3271 octets] - [23/03/2020 18:39:23]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C01].txt ##########

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 18:59
od Rudy
Dejte nové logy FRST+Addition.

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 19:10
od Gárf
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 22-03-2020
Ran by Vojta (administrator) on DESKTOP-T39I587 (LENOVO 20378) (23-03-2020 19:08:43)
Running from C:\Users\Vojta\Desktop
Loaded Profiles: Vojta (Available Profiles: Vojta)
Platform: Windows 10 Home Version 1909 18363.720 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Adobe Inc. -> Adobe Systems) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
(Autodesk, Inc -> Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(Broadcom Corporation -> Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
(Corel Corporation -> WinZip Computing) C:\Program Files\WinZip\WzPreloader.exe
(Corel Corporation -> WinZip Computing, S.L.) C:\Program Files\WinZip\FAHWindow64.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe
(Disc Soft Ltd -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DTShellHlp.exe
(Elaborate Bytes AG -> Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Fortemedia Inc. -> ) C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Company -> HP) C:\Windows\System32\HPSIsvc.exe
(Intel(R) pGFX -> ) C:\Windows\System32\igfxTray.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel(R) pGFX -> Intel Corporation) C:\Windows\System32\igfxHK.exe
(IObit Information Technology -> IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\browserhost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\servicehost.exe
(McAfee, LLC -> McAfee, LLC) C:\Program Files\McAfee\WebAdvisor\uihost.exe
(Microsoft Corporation -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Opera Software AS -> Opera Software) C:\Users\Vojta\AppData\Local\Programs\Opera\assistant\browser_assistant.exe
(Opera Software AS -> Opera Software) C:\Users\Vojta\AppData\Local\Programs\Opera\assistant\browser_assistant.exe
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\1.5.21.0\CCleanerBrowserCrashHandler.exe
(Piriform Software Ltd -> Piriform Software) C:\Program Files (x86)\CCleaner Browser\Update\1.5.21.0\CCleanerBrowserCrashHandler64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated -> Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Synology Inc. -> ) [File not signed] C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe
(TeamViewer Germany GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-04] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-04] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942864 2016-10-13] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3947704 2015-10-20] (Synaptics Incorporated -> Synaptics Incorporated)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [277664 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
HKLM\...\Run: [WinZip UN] => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2019-10-14] (Corel Corporation -> Corel Corporation)
HKLM\...\Run: [WinZip FAH] => C:\Program Files\WinZip\FAHConsole.exe [436704 2019-10-14] (Corel Corporation -> WinZip Computing, S.L.)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG -> Elaborate Bytes AG)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [721856 2016-07-01] (Autodesk, Inc -> Autodesk, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-16] (Piriform Software Ltd -> Piriform Ltd)
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Run: [Opera Browser Assistant] => C:\Users\Vojta\AppData\Local\Programs\Opera\assistant\browser_assistant.exe [3024408 2020-03-19] (Opera Software AS -> Opera Software)
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Policies\Explorer: []
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.149\Installer\chrmstp.exe [2020-03-20] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{052EB454-9F19-CB42-7875-807F79F311C4}] -> C:\Program Files (x86)\CCleaner Browser\Application\80.0.3625.135\Installer\chrmstp.exe [2020-03-11] (Piriform Software Ltd -> Piriform Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodeMeter Control Center.lnk [2017-02-28]
ShortcutTarget: CodeMeter Control Center.lnk -> C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2020-03-12]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.1702\SSScheduler.exe (McAfee, LLC -> McAfee, LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2020-03-09]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (Corel Corporation -> WinZip Computing)
Startup: C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2017-08-14]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {042306D0-6FCA-41D1-89E0-CBC3757F6959} - System32\Tasks\CCleaner Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [1887992 2020-03-09] (Piriform Software Ltd -> Piriform Software)
Task: {06B033D5-4B7E-4C32-83C7-8C9134A2284A} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-03-11] (Adobe Inc. -> Adobe)
Task: {1383CEF3-5DF0-45A4-8F7A-21DF8B8F8187} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-16] (Piriform Software Ltd -> Piriform Ltd)
Task: {227A5FF4-4AFE-4950-9C37-51535CC7FB5F} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [1626328 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {309EBAEB-C57D-4C7F-9173-43E3BC4E1F7B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {39FCD610-61EB-4DA7-B1F9-07A3B550462A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {4DA2167E-2774-4F23-AEA0-430FCED7DE15} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
Task: {4EFF5277-3A84-42A4-B203-549FFA33A1DF} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe
Task: {4FF18C40-ACFD-45FC-9DF5-E4C4314B8E84} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [1660520 2020-02-28] (Avast Software s.r.o. -> Avast Software)
Task: {533D0C99-D69A-4077-B910-B6FE60C3E2E2} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3894664 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
Task: {63FD0209-96FA-4A3B-8986-EC364D2B60D7} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_344_pepper.exe [1453624 2020-03-11] (Adobe Inc. -> Adobe)
Task: {6DB50304-A7BD-409F-9472-2C0FD5DB68AF} - System32\Tasks\WinZip Update Notifier 2 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2019-10-14] (Corel Corporation -> Corel Corporation)
Task: {7647976C-CE86-4037-83FD-175C47D3E9EB} - System32\Tasks\Opera scheduled Autoupdate 1546713095 => C:\Users\Vojta\AppData\Local\Programs\Opera\launcher.exe [1538584 2020-03-12] (Opera Software AS -> Opera Software)
Task: {79A8EF2B-6C26-40AD-BE83-305561F0C08D} - System32\Tasks\Opera scheduled assistant Autoupdate 1547232680 => C:\Users\Vojta\AppData\Local\Programs\Opera\launcher.exe [1538584 2020-03-12] (Opera Software AS -> Opera Software)
Task: {90BE6455-3CA8-4CCA-AA7D-0BED9D475B6D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [376496 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {915110EC-4928-4AF1-B9D7-F2F35FC85A31} - System32\Tasks\CCleanerUpdateTaskMachineUA => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [209128 2019-10-10] (Piriform Software Ltd -> Piriform Software)
Task: {A930928B-667A-4F4C-8AC1-E4FE8EE5B94A} - System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-T39I587-Vojta DESKTOP-T39I587 => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [470720 2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
Task: {AF8241B0-081F-425C-B8D5-188FA5A1591C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.)
Task: {BBD9432B-C58B-4832-8C87-2E2581A72FFB} - System32\Tasks\CCleanerUpdateTaskMachineCore => C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [209128 2019-10-10] (Piriform Software Ltd -> Piriform Software)
Task: {C737768F-0735-46E8-B8BD-1A9D5F8ADC2A} - System32\Tasks\CCleaner Browser Heartbeat Task (Logon) => C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe [1887992 2020-03-09] (Piriform Software Ltd -> Piriform Software)
Task: {CABC7ADE-DFC5-48D7-BEB3-A1354BA608BE} - System32\Tasks\ASC Task (One-Time) => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCPromote.exe
Task: {D33787A4-3F46-428B-A798-FC2CF49AFD9E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.)
Task: {D3C8764C-6E77-4E2D-8D1F-02A29AB662B1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1242704 2020-02-25] (Adobe Inc. -> Adobe Systems)
Task: {F0CD7647-A826-493E-B8DE-DF733C8878ED} - System32\Tasks\WinZip Update Notifier 3 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2019-10-14] (Corel Corporation -> Corel Corporation)
Task: {FC98907A-DF9D-45FE-A6E7-B792A80682CE} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-16] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {FE63379A-2AB0-47EB-AA19-53AAFFE091CA} - System32\Tasks\WinZip Update Notifier 1 => C:\Program Files\WinZip\WZUpdateNotifier.exe [2814096 2019-10-14] (Corel Corporation -> Corel Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\..\Interfaces\{a519632e-1960-48f9-be54-77c9a5168884}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f8baf662-7d77-4173-bef7-184156f0e486}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\x64\IEPlugin.dll [2020-03-10] (McAfee, LLC -> McAfee, LLC)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\ssv.dll [2019-06-03] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2017-03-20] (EVERNOTE CORPORATION -> Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> C:\Program Files\McAfee\WebAdvisor\win32\IEPlugin.dll [2020-03-10] (McAfee, LLC -> McAfee, LLC)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\jp2ssv.dll [2019-06-03] (Oracle America, Inc. -> Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)

FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi [2020-03-10] [UpdateUrl:hxxps://www.siteadvisor.com/waffinstall/update.json]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files\McAfee\WebAdvisor\e10ssaffplg.xpi
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\dtplugin\npDeployJava1.dll [2019-06-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.201.2 -> C:\Program Files (x86)\Java\jre1.8.0_201\bin\plugin2\npjp2.dll [2019-06-03] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-29] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-29] (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems, Incorporated -> Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default [2020-03-23]
CHR Notifications: Default -> hxxps://cz.pinterest.com; hxxps://cze.patkardevelopers.com; hxxps://postovnezdarma.cz; hxxps://www.akcniletaky.com; hxxps://www.lgshop.cz; hxxps://www.paradyz.com
CHR Extension: (Prezentace) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-19]
CHR Extension: (Dokumenty) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-19]
CHR Extension: (Disk Google) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (YouTube) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-20]
CHR Extension: (Vyhledávání Google) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Tabulky) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-19]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2020-02-12]
CHR Extension: (Dokumenty Google offline) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-14]
CHR Extension: (AdBlock — best ad blocker) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2020-03-18]
CHR Extension: (FormApps Extension) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilfoopambfaclfjmpiaijnccgcmbeigi [2017-06-15]
CHR Extension: (Správa mých zařízení | SledovaniTV.cz) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\momnkjpcafmkehhcmabppfanllhfnani [2017-07-13]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-07]
CHR Extension: (Gmail) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-05-07]
CHR Extension: (Chrome Media Router) - C:\Users\Vojta\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-03-20]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho]

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1295376 2016-07-01] (Autodesk, Inc -> Autodesk Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6046624 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
S2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [31192 2014-02-07] (Autodesk, Inc -> Autodesk, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [413472 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57536 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (Shanghai Comet Network Technology -> www.BitComet.com)
S2 ccleaner; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [209128 2019-10-10] (Piriform Software Ltd -> Piriform Software)
S3 CCleanerBrowserElevationService; C:\Program Files (x86)\CCleaner Browser\Application\80.0.3625.135\elevation_service.exe [973760 2020-03-09] (Piriform Software Ltd -> Piriform Software)
S3 ccleanerm; C:\Program Files (x86)\CCleaner Browser\Update\CCleanerBrowserUpdate.exe [209128 2019-10-10] (Piriform Software Ltd -> Piriform Software)
S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusService.exe [1443520 2016-04-04] (Disc Soft Ltd -> Disc Soft Ltd)
R3 Disc Soft Pro Bus Service; C:\Program Files\DAEMON Tools Pro\DiscSoftBusService.exe [1267984 2015-02-27] (Disc Soft Ltd -> Disc Soft Ltd)
R2 HPSIService; C:\WINDOWS\system32\HPSIsvc.exe [126856 2012-11-08] (Hewlett-Packard Company -> HP)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373752 2017-04-23] (Intel(R) pGFX -> Intel Corporation)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2945312 2016-01-14] (IObit Information Technology -> IObit)
R2 McAfee WebAdvisor; C:\Program Files\McAfee\WebAdvisor\ServiceHost.exe [907224 2020-03-10] (McAfee, LLC -> McAfee, LLC)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.1702\McCHSvc.exe [407088 2020-03-02] (McAfee, LLC -> McAfee, LLC)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13206544 2020-03-09] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
R2 UsbClientService; C:\Program Files (x86)\Synology\Assistant\UsbClientService.exe [248840 2016-03-18] (Synology Inc. -> ) [File not signed]
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\NisSrv.exe [3206472 2020-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.1911.3-0\MsMpEng.exe [103376 2020-01-10] (Microsoft Windows Publisher -> Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 aswArDisk; C:\WINDOWS\System32\drivers\aswArDisk.sys [37864 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [205576 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [271120 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [206608 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [64272 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2020-02-26] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [279360 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42976 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [175400 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110560 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84056 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848672 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [458584 2020-03-11] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [235184 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316256 2020-02-26] (Avast Software s.r.o. -> AVAST Software)
R3 busenum; C:\WINDOWS\System32\drivers\busenum.sys [57824 2012-08-03] (Synology Inc. -> Windows (R) Win 7 DDK provider)
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [30264 2016-04-06] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [47672 2016-04-06] (Disc Soft Ltd -> Disc Soft Ltd)
R3 dtproscsibus; C:\WINDOWS\System32\drivers\dtproscsibus.sys [30352 2016-04-25] (Disc Soft Ltd -> Disc Soft Ltd)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [19968 2012-11-08] (Microsoft Windows Hardware Compatibility Publisher -> Marvell Semiconductor, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvltwu.inf_amd64_dc8ffafad3ea7ddd\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation -> NVIDIA Corporation)
R3 ROCKEYNT; C:\WINDOWS\system32\DRIVERS\Rockey4.sys [36904 2016-05-06] (Feitian Technologies Co., Ltd. -> Feitian Technologies Co., Ltd.)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-07-22] (Realtek Semiconductor Corp -> Realtek )
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [761600 2015-06-15] (Realtek Semiconductor Corp -> Realsil Semiconductor Corporation)
R3 rtsuvc; C:\WINDOWS\system32\DRIVERS\rtsuvc.sys [3068160 2015-06-16] (Realtek Semiconductor Corp -> Realtek Semiconductor Corp.)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-10-20] (Synaptics Incorporated -> Synaptics Incorporated)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45664 2020-01-10] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [355760 2020-01-10] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [54192 2020-01-10] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-03-23 18:45 - 2020-03-23 18:51 - 000000004 ____H C:\ProgramData\cm-lock
2020-03-23 18:30 - 2020-03-23 18:39 - 000000000 ____D C:\AdwCleaner
2020-03-23 18:25 - 2020-03-23 18:25 - 008199856 _____ (Malwarebytes) C:\Users\Vojta\Desktop\adwcleaner_8.0.3.exe
2020-03-23 15:25 - 2020-03-23 19:07 - 000061726 _____ C:\Users\Vojta\Desktop\Addition.txt
2020-03-23 15:22 - 2020-03-23 19:09 - 000030596 _____ C:\Users\Vojta\Desktop\FRST.txt
2020-03-23 15:20 - 2020-03-23 19:09 - 000000000 ____D C:\FRST
2020-03-23 15:18 - 2020-03-23 15:18 - 002279936 _____ (Farbar) C:\Users\Vojta\Desktop\FRST64.exe
2020-03-23 07:42 - 2020-03-23 07:42 - 000344178 _____ C:\Users\Vojta\Downloads\D12_VÝKAZ_CHVOJNO_DPS_200319.pdf
2020-03-21 12:28 - 2020-03-21 12:28 - 000353747 _____ C:\Users\Vojta\Desktop\Výpověď smlouvy AXA.pdf
2020-03-21 09:30 - 2020-03-21 09:30 - 002384037 _____ C:\Users\Vojta\Downloads\HROMOSVOD.dwg
2020-03-19 11:44 - 2020-02-26 07:35 - 000368056 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2020-03-19 10:48 - 2020-03-19 10:48 - 000000062 _____ C:\Users\Vojta\Desktop\CHVOJNO_18_03_2020_DPS - kopie.pln.lck
2020-03-19 10:36 - 2020-03-18 13:35 - 172422864 _____ C:\Users\Vojta\Desktop\CHVOJNO_18_03_2020_DPS - kopie.pln
2020-03-19 07:38 - 2020-03-18 21:07 - 002501526 _____ C:\Users\Vojta\Desktop\xxx.bak
2020-03-19 07:13 - 2020-03-19 07:13 - 000099612 _____ C:\Users\Vojta\Downloads\31949894 (1).pdf
2020-03-18 16:16 - 2020-03-19 07:39 - 001342214 _____ C:\Users\Vojta\Desktop\2NP VZT 6.3.2020.dwg
2020-03-18 16:05 - 2020-03-19 07:38 - 002566981 _____ C:\Users\Vojta\Desktop\1NP VZT 6.3.2020.dwg
2020-03-18 11:38 - 2020-03-23 15:01 - 000000000 ____D C:\Users\Vojta\AppData\Local\TeamViewer
2020-03-18 11:37 - 2020-03-23 18:45 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-03-18 11:37 - 2020-03-18 11:37 - 000001116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer.lnk
2020-03-18 11:37 - 2020-03-18 11:37 - 000001104 _____ C:\Users\Public\Desktop\TeamViewer.lnk
2020-03-18 11:27 - 2020-03-18 11:28 - 026985448 _____ (TeamViewer Germany GmbH) C:\Users\Vojta\Downloads\TeamViewer_Setup.exe
2020-03-18 10:50 - 2020-03-18 10:50 - 008542758 _____ C:\Users\Vojta\Downloads\Ceník+obnovitelných+zdrojů_08_2019.pdf
2020-03-18 10:26 - 2020-03-18 10:26 - 000241857 _____ C:\Users\Vojta\Downloads\Vitoclima_200-S (3).pdf
2020-03-18 10:25 - 2020-03-18 10:25 - 000201319 _____ C:\Users\Vojta\Downloads\LTU Vitoclima 200-S_CZ.pdf
2020-03-18 10:25 - 2020-03-18 10:25 - 000201319 _____ C:\Users\Vojta\Downloads\LTU Vitoclima 200-S_CZ (1).pdf
2020-03-18 10:11 - 2020-03-18 10:11 - 000241857 _____ C:\Users\Vojta\Downloads\Vitoclima_200-S.pdf
2020-03-18 07:51 - 2020-03-18 12:35 - 000046080 _____ C:\Users\Vojta\Desktop\D.1.4.4. VZT - ROZPOČET.xls
2020-03-17 09:37 - 2020-03-17 09:37 - 000093643 _____ C:\Users\Vojta\Downloads\Bilanční výpis 2019.pdf
2020-03-17 09:27 - 2020-03-17 09:27 - 000296760 _____ C:\Users\Vojta\Desktop\Žádost o koupi palivové dřevo Novák.pdf
2020-03-16 16:58 - 2020-03-16 16:58 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (8).pdf
2020-03-16 16:22 - 2020-03-16 16:22 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st.pdf
2020-03-13 19:51 - 2020-03-13 19:51 - 025444352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 009930552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-03-13 19:51 - 2020-03-13 19:51 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 006520776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 004563416 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-03-13 19:51 - 2020-03-13 19:51 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 001398584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-03-13 19:51 - 2020-03-13 19:51 - 001077048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-03-13 19:51 - 2020-03-13 19:51 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2020-03-13 19:51 - 2020-03-13 19:51 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-03-13 19:51 - 2020-03-13 19:51 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-03-13 15:08 - 2020-03-13 15:08 - 000099612 _____ C:\Users\Vojta\Downloads\31949894.pdf
2020-03-13 14:23 - 2020-03-13 14:23 - 000117364 _____ C:\Users\Vojta\Downloads\fbldfsl (3).pdf
2020-03-13 14:22 - 2020-03-13 14:22 - 000117364 _____ C:\Users\Vojta\Downloads\fbldfsl (2).pdf
2020-03-12 09:16 - 2020-03-12 09:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2020-03-12 09:15 - 2020-03-12 10:17 - 000000000 ____D C:\ProgramData\McAfee Security Scan
2020-03-11 23:38 - 2020-03-11 23:38 - 011607552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2020-03-11 23:38 - 2020-03-11 23:38 - 009711616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 022635008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 019850240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 019812352 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 018027008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 007755776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 007259648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 006285312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 005911040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 004855808 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 004580352 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 004348408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 004129648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 003819520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 003488768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 003243296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002956688 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2020-03-11 23:37 - 2020-03-11 23:37 - 002755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2020-03-11 23:37 - 2020-03-11 23:37 - 002494744 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002315680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002224952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002180408 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002072664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 002031104 _____ C:\WINDOWS\system32\rdpnano.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001867816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001835128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001770552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001555904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001540096 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001490640 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001417976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001319936 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001282944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001273856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001214976 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001108040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001098720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001080832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001012792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 001000960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000883712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000843776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkfoldersControl.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000757632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000710144 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbc32.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000604160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbc32.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000510768 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2020-03-11 23:37 - 2020-03-11 23:37 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000380416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacEncoder.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacEncoder.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000227840 _____ (Microsoft Corporation) C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFoldersShell.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngOnline.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IndexedDbLegacy.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WorkFolders.exe
2020-03-11 23:37 - 2020-03-11 23:37 - 000097080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000042296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SysResetErr.exe
2020-03-11 23:37 - 2020-03-11 23:37 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-03-11 23:37 - 2020-03-11 23:37 - 000032056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdpvideominiport.sys
2020-03-11 23:37 - 2020-03-11 23:37 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-03-11 23:37 - 2020-03-11 23:37 - 000019768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.exe
2020-03-11 23:36 - 2020-03-11 23:37 - 025900544 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 006084344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 005764664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 005112832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 004538880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 003971808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 003860832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpltfm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002875904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002800640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 002740736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directml.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002584008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002561536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002307584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002305536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002259872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 002021888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001985104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001684992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001665416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001664896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001484600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001458688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001413632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001412096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001284096 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001283600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2020-03-11 23:36 - 2020-03-11 23:36 - 001264128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001260544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpsharercom.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001218632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 001190912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Graphics.Display.DisplayEnhancementService.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001088000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001054376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001031680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 001007672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000980320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmpal.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000935040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Taskmgr.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000915296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmcodecs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000895488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000892696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windowsperformancerecordercontrol.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000783480 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000776488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000769552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.OnlineId.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000732000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ortcengine.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000691712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000680184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000669496 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000668296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000654336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000627216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000613888 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofmsvc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000595968 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000592896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000562688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtrmgr.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000551824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000532480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000526848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidprov.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000518656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000516096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtrmgr.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000500224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mprdim.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000478792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2020-03-11 23:36 - 2020-03-11 23:36 - 000403456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mprdim.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000382976 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000358912 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000327680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000287232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sppcomapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000279040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000251392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000235520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmWmiPl.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000226816 _____ (Microsoft Corporation) C:\WINDOWS\system32\netprofm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000213984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeManagerObj.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000210744 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000206336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiswan.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000199480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000193592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\weretw.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditionUpgradeHelper.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000166400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MicrosoftAccountTokenProvider.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceUpdateAgent.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000143872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAuto.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnpclean.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000136328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\omadmapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000135168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\NdisImPlatform.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000133944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000130112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000123904 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000120560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000114176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000107520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GraphicsCapture.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000105832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000102760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000089568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000087552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3api.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dot3msm.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000068408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceReactivation.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManMigrationPlugin.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000066048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\enterpriseresourcemanager.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmRes.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000055376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtmmvrortc.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmapi.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\npmproxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000042336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbs.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afunix.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000038912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmtask.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmprovhost.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sxstrace.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Drivers\afunix.sys
2020-03-11 23:36 - 2020-03-11 23:36 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmproxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmAgent.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msauserext.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlmsprep.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsmplpxy.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\iprtprio.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchTM.exe
2020-03-11 23:36 - 2020-03-11 23:36 - 000009216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iprtprio.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DMAlertListener.ProxyStub.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCertResources.dll
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-03-11 23:36 - 2020-03-11 23:36 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-03-11 23:35 - 2020-03-11 23:35 - 007263992 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 006436352 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 005040640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 004898144 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpltfm.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 004048896 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 003799552 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 003552768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 003371720 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 002773568 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 002768440 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 002698040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 002087376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001999952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001972536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001835008 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001757304 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2020-03-11 23:35 - 2020-03-11 23:35 - 001743888 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001697792 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001647072 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001513040 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 001482040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 001396152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001394168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001366128 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2020-03-11 23:35 - 2020-03-11 23:35 - 001354080 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmpal.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001260480 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001182448 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 001153024 _____ (Microsoft Corporation) C:\WINDOWS\system32\windowsperformancerecordercontrol.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001091936 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmcodecs.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 001071184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Taskmgr.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 001032544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ortcengine.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\refsutil.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000983896 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000929144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000921088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000898048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MdmDiagnostics.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000877232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000796904 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000765440 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000741392 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000734720 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetup.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000661816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000636848 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxs.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000605896 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000489984 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-03-11 23:35 - 2020-03-11 23:35 - 000460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\slui.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000443904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000353960 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DiagnosticLogCSP.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000320312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000309248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000260920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000248064 _____ (Microsoft Corporation) C:\WINDOWS\system32\weretw.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000234984 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000221200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageComponentsInstaller.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000165504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000164776 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceMetadataRetrievalClient.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\profapi.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000120048 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000112128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstSv.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000107832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000098104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2020-03-11 23:35 - 2020-03-11 23:35 - 000089616 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterpriseresourcemanager.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000063288 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AxInstUI.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000056672 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtmmvrortc.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000044544 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\sxstrace.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msauserext.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\system32\MUILanguageCleanup.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\LangCleanupSysprepAction.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000012288 _____ (Microsoft Corporation) C:\WINDOWS\system32\pacjsworker.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchTM.exe
2020-03-11 23:35 - 2020-03-11 23:35 - 000010752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpksetupproxyserv.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-03-11 23:35 - 2020-03-11 23:35 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 007905784 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 006168064 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 004622280 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 004471296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 004140544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 003728896 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 003708928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 003587896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 003263488 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 003260928 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 003143168 _____ (Microsoft Corporation) C:\WINDOWS\system32\directml.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002870272 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002808832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002715648 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 002522112 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002474496 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002453504 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002289152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 002157056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001823232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001764336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001762304 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001751040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001657120 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001609216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001581056 _____ (Microsoft Corporation) C:\WINDOWS\system32\qmgr.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001481216 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpsharercom.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001480192 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 001428992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 001180160 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001083904 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001057792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 001027000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000945384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000914944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000908504 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Service.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000833616 _____ (Microsoft Corporation) C:\WINDOWS\system32\pkeyhelper.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000802304 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000782848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000749568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000649728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidprov.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000642216 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000637240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.UXRes.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000540672 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2020-03-11 23:34 - 2020-03-11 23:34 - 000535552 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000531768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2020-03-11 23:34 - 2020-03-11 23:34 - 000522384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000459688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000448000 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000441144 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000429880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volsnap.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000355000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000338432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000337920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Acx01000.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceDirectoryClient.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmWmiPl.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000282112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3svc.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000262656 _____ (Microsoft Corporation) C:\WINDOWS\system32\netman.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000259584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000250896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\system32\vdsbas.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TetheringMgr.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000224056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000222520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ataport.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000208696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000201744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000201528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000199992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000183608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000180232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAuto.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000174392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000151568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000146712 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\GraphicsCapture.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000141840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000141824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\DTUHandler.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000128312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Taskbar.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000103936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3msm.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2020-03-11 23:34 - 2020-03-11 23:34 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\dot3api.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManMigrationPlugin.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilot.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\monitor.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000067112 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsManagementServiceWinRt.ProxyStub.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000066336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlrmdr.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmRes.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000056632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pciidex.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000054784 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAProfileNotificationHandler.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000048256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbs.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmprovhost.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiredNetworkCSP.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthMini.SYS
2020-03-11 23:34 - 2020-03-11 23:34 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmAgent.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000030008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\atapi.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000029712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tbs.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000028936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmbuspipe.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\autopilotdiag.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000024064 _____ (Microsoft Corporation) C:\WINDOWS\system32\wci.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000019984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelide.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mpnotify.exe
2020-03-11 23:34 - 2020-03-11 23:34 - 000016912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pciide.sys
2020-03-11 23:34 - 2020-03-11 23:34 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsmplpxy.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000003584 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCertResources.dll
2020-03-11 23:34 - 2020-03-11 23:34 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUserRes.dll
2020-03-11 23:33 - 2020-03-11 23:33 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthA2dp.sys
2020-03-11 23:05 - 2020-03-11 23:06 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-03-11 23:05 - 2020-03-11 23:06 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-03-11 18:52 - 2020-03-11 18:53 - 000117364 _____ C:\Users\Vojta\Downloads\fbldfsl (1).pdf
2020-03-11 18:41 - 2020-03-11 18:41 - 000117364 _____ C:\Users\Vojta\Downloads\fbldfsl.pdf
2020-03-11 11:37 - 2020-03-11 11:37 - 000540672 _____ C:\Users\Vojta\Downloads\Vetraci_mrizka_pro_instalaci_do_kruhoveho_p.rfa
2020-03-10 16:07 - 2020-03-10 16:07 - 012586088 _____ C:\Users\Vojta\Downloads\isover_vario_7-2017.pdf
2020-03-10 14:19 - 2020-03-10 14:20 - 171774448 _____ C:\Users\Vojta\Desktop\CHVOJNO_10_03_2020_DPS.pln
2020-03-09 14:38 - 2020-03-09 14:38 - 000911809 _____ C:\Users\Vojta\Downloads\om.zip
2020-03-09 13:42 - 2020-03-09 13:42 - 000911809 _____ C:\Users\Vojta\Downloads\ISOLIN-ACAD.zip
2020-03-09 13:42 - 2020-03-09 13:42 - 000000000 ____D C:\Users\Vojta\Downloads\ISOLIN-ACAD
2020-03-09 13:40 - 2020-03-09 13:40 - 000001621 _____ C:\Users\Vojta\Downloads\JS.LIN
2020-03-09 10:03 - 2020-03-09 10:03 - 000111267 _____ C:\Users\Vojta\Downloads\KL_8x75_160_OC.dwg
2020-03-09 08:40 - 2020-03-21 14:03 - 000002696 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 2
2020-03-09 08:40 - 2020-03-21 14:03 - 000002694 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 3
2020-03-09 08:40 - 2020-03-21 14:03 - 000002694 _____ C:\WINDOWS\system32\Tasks\WinZip Update Notifier 1
2020-03-09 08:39 - 2020-03-09 08:55 - 000000000 ____D C:\Users\Vojta\AppData\Local\WinZip
2020-03-09 08:39 - 2020-03-09 08:40 - 000000000 ____D C:\ProgramData\WinZip
2020-03-09 08:39 - 2020-03-09 08:39 - 000002091 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip.lnk
2020-03-09 08:39 - 2020-03-09 08:39 - 000001991 _____ C:\Users\Public\Desktop\WinZip.lnk
2020-03-09 08:39 - 2020-03-09 08:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip
2020-03-09 08:39 - 2020-03-09 08:39 - 000000000 ____D C:\Program Files\WinZip
2020-03-09 08:38 - 2020-03-09 08:38 - 000959304 _____ (WinZip Computing) C:\Users\Vojta\Downloads\winzip24-lan.exe
2020-03-09 08:38 - 2020-03-09 08:38 - 000000000 ____D C:\ProgramData\UniqueId
2020-03-06 15:29 - 2020-03-06 15:29 - 001291364 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q350-tr- (2).pdf
2020-03-06 15:27 - 2020-03-06 15:27 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (7).pdf
2020-03-06 15:27 - 2020-03-06 15:27 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (6).pdf
2020-03-06 14:54 - 2020-03-06 14:54 - 000249620 _____ C:\Users\Vojta\Downloads\SPIRO.pdf
2020-03-06 14:51 - 2020-03-06 14:51 - 000218732 _____ C:\Users\Vojta\Downloads\M001.DWG
2020-03-06 14:48 - 2020-03-06 14:48 - 001011499 _____ C:\Users\Vojta\Downloads\OVAL.dwg
2020-03-06 14:45 - 2020-03-06 14:45 - 000730266 _____ C:\Users\Vojta\Downloads\Dynamic_Blocks.dwg
2020-03-06 10:27 - 2020-03-06 10:21 - 003138903 _____ C:\Users\Vojta\Desktop\1.NP VZT DPS.bak
2020-03-06 08:04 - 2020-03-20 07:19 - 000002080 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2020-03-05 14:11 - 2020-03-05 14:11 - 000241857 _____ C:\Users\Vojta\Downloads\Vitoclima_200-S (2).pdf
2020-03-05 14:11 - 2020-03-05 14:11 - 000241857 _____ C:\Users\Vojta\Downloads\Vitoclima_200-S (1).pdf
2020-03-03 15:26 - 2020-03-03 15:26 - 002209020 _____ C:\Users\Vojta\Downloads\as-gw-aqualoop-cz-prospekt.pdf
2020-03-03 10:42 - 2020-03-03 10:42 - 000069349 _____ C:\Users\Vojta\Downloads\ND-12_ ND12Z.pdf
2020-03-03 10:41 - 2020-03-03 10:41 - 000593840 _____ C:\Users\Vojta\Downloads\Technologický postup montáže nádrží J32-105, ND, 1.7.2019.pdf
2020-03-03 10:40 - 2020-03-03 10:40 - 000119050 _____ C:\Users\Vojta\Downloads\B00238-1 - Vysoké Chvojno (Pardubice), RAB Stavby, s.r.o., 2x ND12.pdf
2020-03-02 17:02 - 2020-03-12 09:16 - 000002022 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2020-03-02 14:58 - 2020-03-02 14:58 - 004415871 _____ C:\Users\Vojta\Downloads\Sika and Tricosal_CZ_web.pdf
2020-02-28 10:33 - 2020-02-28 10:33 - 000525032 _____ C:\Users\Vojta\Downloads\D. 2.01 PŮDORYS STROPU.pdf
2020-02-28 09:25 - 2020-02-28 09:25 - 000647412 _____ C:\Users\Vojta\Downloads\C. 03 KOORDINAČNÍ SITUAČNÍ VÝKRES.pdf
2020-02-27 14:45 - 2020-02-27 14:45 - 001499935 _____ C:\Users\Vojta\Downloads\CN_Martínková_Martina.pdf
2020-02-27 10:56 - 2020-02-27 10:56 - 000638137 _____ C:\Users\Vojta\Downloads\duplex_r5_cz_2016_06.pdf
2020-02-26 15:40 - 2020-02-26 15:40 - 000099924 _____ C:\Users\Vojta\Downloads\Faktura_2080542.pdf
2020-02-26 13:09 - 2020-02-26 13:09 - 000742836 _____ C:\Users\Vojta\Downloads\PBŘ - Požárně bezpečnostní řešení (1).pdf
2020-02-26 13:05 - 2020-02-26 13:05 - 000742836 _____ C:\Users\Vojta\Downloads\PBŘ - Požárně bezpečnostní řešení.pdf
2020-02-26 07:35 - 2020-02-26 07:35 - 000235184 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2020-02-26 07:35 - 2020-02-26 07:35 - 000175400 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2020-02-25 15:35 - 2020-02-25 15:35 - 001463998 _____ C:\Users\Vojta\Downloads\asset-katalog-idealni-instalace-s-comfoair-q-pro-instalatery (2).pdf
2020-02-25 15:35 - 2020-02-25 15:35 - 001463998 _____ C:\Users\Vojta\Downloads\asset-katalog-idealni-instalace-s-comfoair-q-pro-instalatery (1).pdf
2020-02-25 15:35 - 2020-02-25 15:35 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (5).pdf
2020-02-25 15:35 - 2020-02-25 15:35 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (4).pdf
2020-02-25 15:35 - 2020-02-25 15:35 - 001220405 _____ C:\Users\Vojta\Downloads\asset-technicka-specifikace-zehnder-comfoair-q600-st (3).pdf
2020-02-25 15:31 - 2020-02-25 15:31 - 001442595 _____ C:\Users\Vojta\Downloads\asset-katalog-chytre-domy-s-comfoair-q-pro-projektanty.pdf

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-03-23 19:08 - 2016-01-31 20:27 - 000000000 ____D C:\Users\Vojta\AppData\Local\CrashDumps
2020-03-23 19:04 - 2019-08-20 22:20 - 000005246 _____ C:\WINDOWS\system32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-T39I587-Vojta DESKTOP-T39I587
2020-03-23 18:52 - 2020-01-06 07:52 - 000000000 ____D C:\Users\Vojta\Downloads\opera autoupdate
2020-03-23 18:52 - 2019-10-10 14:13 - 000002391 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner Browser.lnk
2020-03-23 18:52 - 2015-10-20 17:45 - 000002305 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-03-23 18:48 - 2019-03-19 05:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-03-23 18:46 - 2017-09-20 18:17 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2020-03-23 18:46 - 2015-10-20 17:41 - 000000000 __SHD C:\Users\Vojta\IntelGraphicsProfiles
2020-03-23 18:45 - 2019-08-20 22:20 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-03-23 18:45 - 2016-08-05 07:14 - 000000000 ____D C:\ProgramData\NVIDIA
2020-03-23 18:43 - 2019-03-19 05:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-03-23 18:39 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-03-23 18:39 - 2015-11-05 17:36 - 000000000 ____D C:\ProgramData\IObit
2020-03-23 18:39 - 2015-11-05 17:35 - 000000000 ____D C:\Users\Vojta\AppData\Roaming\IObit
2020-03-23 18:22 - 2019-08-20 21:39 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-03-23 09:09 - 2016-08-19 13:03 - 000000000 ____D C:\Users\Vojta\Graphisoft
2020-03-23 09:07 - 2017-12-20 21:30 - 000000000 ____D C:\Users\Vojta\AppData\Local\Packages
2020-03-23 07:38 - 2019-08-20 22:20 - 000003378 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3645671178-350016163-1338499739-1001
2020-03-23 07:37 - 2019-09-06 12:11 - 000002410 _____ C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-23 07:37 - 2015-10-20 17:44 - 000000000 ___RD C:\Users\Vojta\OneDrive
2020-03-21 19:01 - 2019-12-03 21:08 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2020-03-21 14:49 - 2019-08-20 22:20 - 000003474 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-21 14:49 - 2019-08-20 22:20 - 000003350 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-21 14:03 - 2019-12-03 21:09 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2020-03-21 14:03 - 2019-10-10 14:13 - 000003104 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Hourly)
2020-03-21 14:03 - 2019-10-10 14:13 - 000002622 _____ C:\WINDOWS\system32\Tasks\CCleaner Browser Heartbeat Task (Logon)
2020-03-21 14:03 - 2019-10-10 14:11 - 000003452 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineUA
2020-03-21 14:03 - 2019-10-10 14:11 - 000003228 _____ C:\WINDOWS\system32\Tasks\CCleanerUpdateTaskMachineCore
2020-03-21 14:03 - 2019-10-09 08:26 - 000003856 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1547232680
2020-03-21 14:03 - 2019-09-24 07:01 - 000003786 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-03-21 14:03 - 2019-09-24 07:01 - 000003488 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2020-03-21 14:03 - 2019-08-20 22:20 - 000003602 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1546713095
2020-03-21 14:03 - 2019-08-20 22:20 - 000003482 _____ C:\WINDOWS\system32\Tasks\Adobe Acrobat Update Task
2020-03-21 14:03 - 2019-08-20 22:20 - 000003194 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-03-21 14:03 - 2019-08-20 22:20 - 000002736 _____ C:\WINDOWS\system32\Tasks\AutoKMS
2020-03-21 14:03 - 2019-08-20 22:20 - 000002558 _____ C:\WINDOWS\system32\Tasks\ASC Task (One-Time)
2020-03-21 14:03 - 2019-08-20 22:20 - 000002548 _____ C:\WINDOWS\system32\Tasks\AutoPico Daily Restart
2020-03-21 14:03 - 2019-08-20 22:20 - 000002162 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-03-20 17:57 - 2019-03-19 05:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-03-20 17:57 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-03-20 07:19 - 2019-12-03 21:11 - 000002092 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2020-03-19 11:44 - 2019-03-19 05:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-03-19 07:04 - 2015-11-05 17:36 - 000000000 ____D C:\ProgramData\ProductData
2020-03-18 12:38 - 2019-12-03 20:26 - 000537776 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-03-18 11:37 - 2016-04-25 16:04 - 000000000 ____D C:\Users\Vojta\AppData\Roaming\TeamViewer
2020-03-18 09:09 - 2019-01-05 19:31 - 000001448 _____ C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Prohlížeč Opera.lnk
2020-03-18 07:55 - 2019-03-19 05:50 - 000000000 ____D C:\WINDOWS\INF
2020-03-14 01:29 - 2019-08-20 22:05 - 001693640 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-03-14 01:29 - 2019-03-19 12:55 - 000718198 _____ C:\WINDOWS\system32\perfh005.dat
2020-03-14 01:29 - 2019-03-19 12:55 - 000145242 _____ C:\WINDOWS\system32\perfc005.dat
2020-03-14 01:16 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-03-14 01:16 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-03-13 12:47 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2020-03-12 09:16 - 2019-09-24 07:35 - 000000000 ____D C:\Program Files\McAfee Security Scan
2020-03-12 01:03 - 2017-12-20 21:51 - 000000000 ___RD C:\Users\Vojta\3D Objects
2020-03-12 01:03 - 2015-09-10 06:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\setup
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Dism
2020-03-12 00:55 - 2019-03-19 05:52 - 000000000 ____D C:\Program Files\Windows Defender
2020-03-12 00:55 - 2019-03-19 05:37 - 000000000 ____D C:\WINDOWS\servicing
2020-03-11 23:58 - 2015-10-20 19:44 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-03-11 23:47 - 2015-10-20 19:44 - 121542864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-03-11 23:05 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-03-11 23:04 - 2019-12-11 08:21 - 008491064 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2020-03-11 23:04 - 2019-03-19 05:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-03-11 19:18 - 2019-10-10 14:11 - 000000000 ____D C:\Program Files (x86)\CCleaner Browser
2020-03-11 12:02 - 2019-12-03 21:08 - 000458584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2020-03-06 10:44 - 2015-10-28 21:13 - 000000000 ____D C:\Fakturace
2020-02-26 07:35 - 2019-12-03 21:08 - 000848672 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000316256 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000279360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000271120 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriver.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000206608 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsh.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000205576 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000110560 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000084056 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000064272 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniv.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000042976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000037864 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArDisk.sys
2020-02-26 07:35 - 2019-12-03 21:08 - 000016304 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys

==================== Files in the root of some directories ========

2017-07-14 12:13 - 2020-01-13 21:27 - 000007610 _____ () C:\Users\Vojta\AppData\Local\Resmon.ResmonCfg
2017-11-25 12:08 - 2017-11-25 12:08 - 000000000 _____ () C:\Users\Vojta\AppData\Local\{C4850B69-86DD-405A-AAE3-64C9C9823ACB}

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 19:11
od Gárf
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-03-2020
Ran by Vojta (23-03-2020 19:10:09)
Running from C:\Users\Vojta\Desktop
Windows 10 Home Version 1909 18363.720 (X64) (2019-08-20 21:21:11)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3645671178-350016163-1338499739-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3645671178-350016163-1338499739-503 - Limited - Disabled)
Guest (S-1-5-21-3645671178-350016163-1338499739-501 - Limited - Disabled)
Vojta (S-1-5-21-3645671178-350016163-1338499739-1001 - Administrator - Enabled) => C:\Users\Vojta
WDAGUtilityAccount (S-1-5-21-3645671178-350016163-1338499739-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.344 - Adobe)
Adobe Reader XI (11.0.23) - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.23 - Adobe Systems Incorporated)
Aide PDF to DWG Converter 11.0 (HKLM-x32\...\Aide PDF to DWG Converter_is1) (Version: - Aide CAD Systems Incorporated.)
ArchiCAD 19 CZE (HKLM\...\001FFF2FFF19FF00FF1101F01F02F000-R1) (Version: 19.0 - GRAPHISOFT)
ARCHICAD 20 CZE (HKLM\...\001FFF2FFF20FF00FF1101F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
AutoCAD 2015 – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0000-0102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
AutoCAD 2015 – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0405-2102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
AutoCAD 2015 Language Pack – Čeština (Czech) (HKLM\...\{5783F2D7-E001-0405-1102-0060B0CE6BBA}) (Version: 20.0.51.0 - Autodesk) Hidden
Autodesk 360 (HKLM\...\{556966D9-F7F6-421B-9707-D07901604DDF}) (Version: 5.1.1.1001 - Autodesk)
Autodesk App Manager (HKLM-x32\...\{C8125548-F2D5-4059-823F-1F3C5BBD9F19}) (Version: 1.2.0 - Autodesk)
Autodesk AutoCAD 2015 – Čeština (Czech) (HKLM\...\AutoCAD 2015 – Čeština (Czech)) (Version: 20.0.51.0 - Autodesk)
Autodesk AutoCAD Civil 3D 2015 64 Bit Object Enabler on AutoCAD 2015 – Ceština (Czech) - Czech (HKLM\...\{6904F91C-1317-4D36-B12E-6D5A723CEB5D}) (Version: 524.0 - Autodesk, Inc.)
Autodesk AutoCAD Civil 3D 2015 64 Bit Object Enabler on Autodesk 360 - Language Neutral (HKLM\...\{3E06D9B0-11B4-46D2-8246-8DC2B8A51EBD}) (Version: 524.0 - Autodesk, Inc.)
Autodesk AutoCAD Performance Feedback Tool Version 1.2.2 (HKLM-x32\...\{85735431-6CD3-4B16-BEC8-95332034E53B}) (Version: 1.2.2.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2015 Add-in 64 bit (HKLM\...\{9D589081-AFC2-4932-9071-AC585AC1EA83}) (Version: 3.32.3004 - Autodesk)
Autodesk Content Service (HKLM-x32\...\{A37CDB58-AAE8-0000-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Content Service (HKLM-x32\...\Autodesk Content Service) (Version: 3.2.0.0 - Autodesk)
Autodesk Content Service Language Pack (HKLM-x32\...\{A37CDB58-AAE8-0001-8C13-E0F7BACB0D5F}) (Version: 3.2.0.0 - Autodesk) Hidden
Autodesk Material Library 2015 (HKLM-x32\...\{427F733F-4D6C-45BC-9324-EB743104C321}) (Version: 5.2.9.100 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2015 (HKLM-x32\...\{ABE2F70B-8D94-44E9-AA04-F0DB35063D62}) (Version: 5.2.9.100 - Autodesk)
Autodesk ReCap (HKLM\...\{31ABA3F2-0000-1033-0102-111D43815377}) (Version: 1.3.1.39 - Autodesk) Hidden
Autodesk ReCap (HKLM\...\Autodesk ReCap) (Version: 1.3.1.39 - Autodesk)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 20.1.2397 - AVAST Software)
Balík TT 2010 (HKLM-x32\...\{91CA3F48-5DAD-4147-AECE-C7219C4B2562}) (Version: 2010.0.0.0 - Svoboda Software (svoboda.zbynek@quick.cz, mobile +420 606 227 420))
BitComet 1.54 (HKLM-x32\...\BitComet_x64) (Version: 1.54 - CometNetwork)
Callida euroCALC 3 - Klient (HKLM-x32\...\euroCALC 3 - Klient_is1) (Version: euroCALC 3 - Klient - )
CCleaner (HKLM\...\CCleaner) (Version: 5.62 - Piriform)
CCleaner Browser (HKLM-x32\...\CCleaner Browser) (Version: 80.0.3625.135 - Autoři prohlížeče CCleaner Browser)
CCleaner Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.5.21.0 - Piriform Software) Hidden
CodeMeter Runtime Kit v5.22a (HKLM\...\{8D299F2C-A3C8-49A5-A726-E885AB397243}) (Version: 5.22.1508.501 - WIBU-SYSTEMS AG)
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.3.0.0154 - Disc Soft Ltd)
DAEMON Tools Pro (HKLM\...\DAEMON Tools Pro) (Version: 6.1.0.0484 - Disc Soft Ltd)
DGN to DWG Converter (HKLM-x32\...\{A02F2188-4962-4E1A-BB0D-5982774361D7}) (Version: - )
DHTML Editing Component (HKLM-x32\...\{2EA870FA-585F-4187-903D-CB9FFD21E2E0}) (Version: 6.02.0002 - Microsoft Corporation)
ecOffer (HKLM-x32\...\ecOffer_is1) (Version: ecOffer - Callida, s.r.o.)
euroCALC Remote Standard (HKLM-x32\...\euroCALC Remote Standard_is1) (Version: euroCALC Remote Standard - Callida, s.r.o.)
Evernote v. 6.5.4 (HKLM-x32\...\{D47E7D82-0D98-11E7-A6D6-005056951CAD}) (Version: 6.5.4.4720 - Evernote Corp.)
FARO LS 1.1.406.58 (HKLM-x32\...\{951B0F30-9F1A-4BF6-B3DA-99EB0E917B1C}) (Version: 4.6.58.2 - FARO Scanner Production)
FormApps Signing Extension (HKLM-x32\...\{ACA43D91-8B42-4D42-8C8B-A893BD6AA40D}) (Version: 2.8.2.28 - Software602 a.s.)
FreeFileSync 7.7 (HKLM-x32\...\FreeFileSync_is1) (Version: 7.7 - www.FreeFileSync.org)
Google Drive (HKLM-x32\...\{A8DC81F2-D365-4248-892A-FA3B5951F731}) (Version: 2.34.9392.7803 - Google, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.149 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
GRAPHISOFT BIMx Desktop Viewer (HKLM-x32\...\103FFFFFFF20FF00FF2801F01F02F000-R1) (Version: 20.0 - GRAPHISOFT)
HP LaserJet Professional M1130-M1210 MFP Series (HKLM\...\HP LaserJet Professional M1130-M1210 MFP Series) (Version: - )
Import souborů SketchUp (HKLM-x32\...\{C403E867-FCF1-432B-BCC1-8FFD40A10A6E}) (Version: 1.2.0 - Autodesk)
Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{AA67D612-0BE5-44D6-9A91-592958F754A1}) (Version: 13.0.198 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4624 - Intel Corporation)
Java 8 Update 161 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Java 8 Update 172 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180172F0}) (Version: 8.0.1720.11 - Oracle Corporation)
Java 8 Update 181 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180181F0}) (Version: 8.0.1810.13 - Oracle Corporation)
Java 8 Update 201 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180201F0}) (Version: 8.0.2010.9 - Oracle Corporation)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - )
Kompaktní jednotky DUPLEX - návrhový program (HKLM-x32\...\Atrea.Application_400) (Version: 8.97.450 - ATREA s.r.o.)
KROS 4 (HKLM-x32\...\{30044428-C20A-3933-8C01-205EFF81E627}) (Version: 161.100 - ÚRS Praha)
Lenovo EasyCamera (HKLM-x32\...\{E399A5B3-ED53-4DEA-AF04-8011E1EB1EAC}) (Version: 6.3.9600.11105 - Realtek Semiconductor Corp.)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.1702.1 - McAfee, LLC)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.1.1.84 - McAfee, LLC.)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Project Language Pack 2013 - Czech/čeština (HKLM\...\Office15.PMUI.cs-cz) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Project Professional 2013 (HKLM\...\Office15.PRJPRO) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 68.1.0 - Mozilla)
Mozilla Thunderbird 68.1.0 (x86 cs) (HKLM-x32\...\Mozilla Thunderbird 68.1.0 (x86 cs)) (Version: 68.1.0 - Mozilla)
Nástroje kontroly pravopisu pro Microsoft Office 2013 – čeština (HKLM\...\{90150000-001F-0405-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2013 - slovenčina (HKLM\...\{90150000-001F-041B-1000-0000000FF1CE}) (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
NEPrůzvučnost 2010 (HKLM-x32\...\{3C74992F-CA2C-4C49-A592-D19670356D46}) (Version: 2010.0.0.0 - Svoboda Software (svoboda.zbynek@quick.cz, mobile (+420) 606 227 420))
NVIDIA Ovladač 3D Vision 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.54 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.54 - NVIDIA Corporation)
Opera Stable 67.0.3575.79 (HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Opera 67.0.3575.79) (Version: 67.0.3575.79 - Opera Software)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Ovládací panel NVIDIA 376.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 376.54 - NVIDIA Corporation) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.2.1 - pdfforge)
Počítačová aplikace Autodesk (HKLM-x32\...\Autodesk Desktop App) (Version: 6.2.0.174 - Autodesk)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7525 - Realtek Semiconductor Corp.)
RTS Stavitel+ 2014 (HKLM-x32\...\RTS Stavitel+_is1) (Version: - )
RTS Stavitel+ 2015 (HKLM-x32\...\RTS Stavitel +_is1) (Version: 2015 - RTS, a.s.)
Scan To (HKLM\...\{E8A34AC8-0137-4515-A94B-0A0946DDC251}) (Version: 2.0.1 - HP)
SketchUp 2016 (HKLM\...\{D87EE6DC-32BA-4219-AC75-0A6FD54ED058}) (Version: 16.0.19912 - Trimble Navigation Limited)
Speciální aplikace Autodesk (HKLM-x32\...\{EDDEE94B-214D-4B07-9727-A3E46F3E379A}) (Version: 1.2.0 - Autodesk)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.5 - Synaptics Incorporated)
Synology Assistant (remove only) (HKLM-x32\...\Synology Assistant) (Version: - )
TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.3.8497 - TeamViewer)
TomTom MyDrive Connect 4.1.4.3089 (HKLM-x32\...\MyDriveConnect) (Version: 4.1.4.3089 - TomTom)
Total Commander (Remove or Repair) (HKLM-x32\...\Totalcmd) (Version: 8.51 - Ghisler Software GmbH)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{16AD6161-2E47-4BF1-AA77-0946EFE93E08}) (Version: 2.61.0.0 - Microsoft Corporation)
VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.5.0.0 - Elaborate Bytes)
Visual Studio C++ 10.0 Runtime (HKLM-x32\...\{4412F224-3849-4461-A3E9-DEEF8D252790}) (Version: 10.0.0 - TomTom International B.V.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 3.0.8 - VideoLAN)
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
WinZip 24.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24125}) (Version: 24.0.13650 - Corel Corporation)

Packages:
=========
Autodesk SketchBook -> C:\Program Files\WindowsApps\89006A2E.AutodeskSketchBook_5.1.0.0_x64__tf1gferkr813w [2019-11-06] (Autodesk Inc.)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2019-11-26] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_110.1.671.0_x64__v10z8vjag6ke6 [2020-02-06] (HP Inc.)
KONICA MINOLTA Print Experience -> C:\Program Files\WindowsApps\KONICAMINOLTAINC.KONICAMINOLTAPrintExperience_1.3.0.13_neutral__s63fsn2sety0r [2019-10-07] (KONICA MINOLTA INC)
Lenovo Vantage -> C:\Program Files\WindowsApps\E046963F.LenovoCompanion_10.2001.12.0_x64__k1h2ywk1493x8 [2020-02-28] (LENOVO INC.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1808.3.0_x64__8wekyb3d8bbwe [2019-08-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-25] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-25] (Microsoft Corporation) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20583.0_x64__8wekyb3d8bbwe [2020-03-06] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-02-28] (Microsoft Studios) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.34.20074.0_x64__8wekyb3d8bbwe [2020-01-15] (Microsoft Corporation) [MS Ad]
MSN Počasí -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20503.0_x64__8wekyb3d8bbwe [2020-03-06] (Microsoft Corporation) [MS Ad]
Spotify Music -> C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0 [2020-03-11] (Spotify AB) [Startup Task]

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3645671178-350016163-1338499739-1001_Classes\CLSID\{0B628DE4-07AD-4284-81CA-5B439F67C5E6}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2015\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3645671178-350016163-1338499739-1001_Classes\CLSID\{149DD748-EA85-45A6-93C5-AC50D0260C98}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2015\acad.exe (Autodesk, Inc -> Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-3645671178-350016163-1338499739-1001_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.WinZipExpressForOffice.dll (Corel Corporation -> )
CustomCLSID: HKU\S-1-5-21-3645671178-350016163-1338499739-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2015\cs-CZ\acadficn.dll (Autodesk Development Sarl -> Autodesk, Inc.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2018-04-23] (Google Inc -> Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-26] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2014-02-07] (Autodesk, Inc -> Autodesk, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2014-02-07] (Autodesk, Inc -> Autodesk)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [DaemonShellExtImage] -> {40966797-8FFE-46C8-9EF8-7003F33CCF0F} => C:\Program Files\DAEMON Tools Pro\DTShl64.dll [2015-02-27] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-04-23] (Google Inc -> Google)
ContextMenuHandlers1: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2019-10-14] (Corel Corporation -> WinZip Computing)
ContextMenuHandlers2: [DaemonShellExtDrive] -> {A5415364-784A-41A5-B47A-D452909CA8FF} => C:\Program Files\DAEMON Tools Pro\DTShl64.dll [2015-02-27] (Disc Soft Ltd -> Disc Soft Ltd)
ContextMenuHandlers2: [VirtualCloneDrive] -> {B7056B8E-4F99-44f8-8CBD-282390FE5428} => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\ElbyVCDShell.dll [2009-12-14] (Elaborate Bytes AG -> Elaborate Bytes AG)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2018-04-23] (Google Inc -> Google)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2019-10-14] (Corel Corporation -> WinZip Computing)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2017-04-23] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2016-12-29] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-26] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2019-10-14] (Corel Corporation -> WinZip Computing)

==================== Codecs (Whitelisted) ====================

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

ShortcutWithArgument: C:\Users\Vojta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome\Správa mých zařízení _ SledovaniTV.cz.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory=Default --app-id=momnkjpcafmkehhcmabppfanllhfnani
ShortcutWithArgument: C:\Users\Vojta\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\facebook.lnk -> C:\Users\Vojta\AppData\Local\Programs\Opera\launcher.exe (Opera Software) -> www.facebook.com

==================== Loaded Modules (Whitelisted) =============

2019-08-20 21:48 - 2016-12-29 13:29 - 000339072 _____ (NVIDIA Corporation PE Sign v2016 -> NVIDIA Corporation) [File not signed] C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem\_nvstapisvr64.dll

==================== Alternate Data Streams (Whitelisted) ========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]

==================== Safe Mode (Whitelisted) ==================

==================== Association (Whitelisted) =================

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-3645671178-350016163-1338499739-1001\Software\Classes\.scr: AutoCADScriptFile =>

==================== Internet Explorer trusted/restricted ==========

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-07-30 23:42 - 2020-03-12 09:16 - 000000875 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.1 mssplus.mcafee.com

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;%INTEL_DEV_REDIST%redist\intel64\compiler;C:\ProgramData\Oracle\Java\javapath;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Vojta\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img13.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKLM\...\StartupApproved\StartupFolder: => "CodeMeter Control Center.lnk"
HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\...\StartupApproved\Run32: => "Autodesk Desktop App"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\StartupApproved\StartupFolder: => "EvernoteClipper.lnk"
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{689CD1DE-7042-43C8-B51C-A607610668E2}] => (Allow) C:\Program Files\BitComet\BitComet.exe (Xing Wang -> www.BitComet.com)
FirewallRules: [{8313A12B-058C-4882-BC30-1521CA35E788}] => (Allow) C:\Program Files\BitComet\BitComet.exe (Xing Wang -> www.BitComet.com)
FirewallRules: [{07BA7D2E-D784-48A2-91C2-8D957F098EFE}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{39C29D5D-F875-460C-9ACA-53AA327F60C5}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [UDP Query User{AD46EB3E-B964-4C6C-A4E7-B26D7C1FC479}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe (Synology Inc. -> ) [File not signed]
FirewallRules: [TCP Query User{F09B8A28-235F-4B57-A2B0-7109DFFE2951}C:\program files (x86)\synology\assistant\dsassistant.exe] => (Allow) C:\program files (x86)\synology\assistant\dsassistant.exe (Synology Inc. -> ) [File not signed]
FirewallRules: [{C83CA4E2-0F70-4C6E-A95A-7BB35432BDD9}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{2DD715EE-F9BE-49A1-8FDF-61530F749AB6}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{F33D1CF1-7418-4C23-94C7-E1D4599D9F24}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{D8DC1BBB-D74F-4EEB-AF5E-F0CE48A3A3F1}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{1758A5E9-A978-4434-98D4-4414D0C43876}] => (Allow) LPort=50248
FirewallRules: [{0BF6F038-587E-46AA-A855-208E81601560}] => (Block) C:\Program Files\GRAPHISOFT\ArchiCAD 19\ArchiCAD.exe (Graphisoft SE) [File not signed]
FirewallRules: [{DA2F6EB7-C82C-494F-BE72-5DE895AF5ABA}] => (Block) C:\Program Files\GRAPHISOFT\ArchiCAD 19\CineRender\CineRender 64bit.exe (MAXON Computer GmbH -> MAXON Computer GmbH)
FirewallRules: [{45E8DAC6-6A2E-42D4-9ADF-309739AA386C}] => (Allow) C:\Program Files\GRAPHISOFT\ArchiCAD 19\BIMxUploader.exe (Graphisoft SE) [File not signed]
FirewallRules: [{FBEE6400-C43C-4621-A5D7-493F5B055C8F}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{12A5D606-068D-4F94-9F91-64D9631DD431}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{AE3F35E8-4954-4F79-8DCC-F6E452E861C0}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{B0465E15-4B2D-4766-8525-08970DF31B6D}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{31B1EE8D-14A1-4CE4-95F7-0BE956FD45AE}] => (Allow) C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG -> WIBU-SYSTEMS AG)
FirewallRules: [{7C4FC2BB-DA8D-44DA-8A19-A7C71B557285}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\ARCHICAD.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [{19CC1750-7115-44CE-AD9E-291AB819516C}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\CineRender\CineRender 64bit.exe No File
FirewallRules: [{88A06735-E9AA-4F42-966D-054241D121D8}] => (Allow) C:\Program Files\GRAPHISOFT\ARCHICAD 20\BIMxUploader.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [{E20ACD71-C8C5-4737-914F-B82FFBC766D8}] => (Block) C:\Program Files\GRAPHISOFT\ARCHICAD 20\OverwatchServer.exe (GRAPHISOFT SE) [File not signed]
FirewallRules: [{049EDAB6-A483-401F-9495-A8931997D279}] => (Allow) LPort=1688
FirewallRules: [{0CF73C32-CBCC-48CB-8885-3CC945F73E4A}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{7138C67D-C383-4798-9E62-EE08456F6B7E}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{C889BC95-C0F8-45AE-972F-5AAA2F76AF34}] => (Allow) C:\Users\Vojta\AppData\Local\Programs\Opera\67.0.3575.53\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{001749B2-A64D-46AE-B8E5-D7B9B88F4822}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{A4795BF0-60C1-4CA5-8471-2FA4017E06D2}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{F39E0E94-1F5B-4D0E-BEB4-263B2A99FC3F}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{331009AE-CC67-4B41-82D3-5ACA13142092}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3ADCA317-D43D-48E9-8BD8-8F718E21F576}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{7540E6B1-26A4-4902-B0C1-804BFA8AAC7B}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{8C5243D5-E340-404B-8709-570A4A83A067}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{3EA69065-17E6-4226-8B5B-24E0F15E6CE7}] => (Allow) C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.128.721.0_x86__zpdnekdrzrea0\Spotify.exe (Spotify AB -> Spotify Ltd)
FirewallRules: [{FA5AAB0E-7B09-4525-86C4-DED65EF45760}] => (Allow) C:\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe (Piriform Software Ltd -> Piriform Software)
FirewallRules: [{0058CE96-C3C6-4550-A8FF-F90EAB05F5AE}] => (Allow) C:\Users\Vojta\AppData\Local\Programs\Opera\67.0.3575.79\opera.exe (Opera Software AS -> Opera Software)
FirewallRules: [{2BB29225-1F63-4089-A423-8B7B5DE27591}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{CDD37F5B-3BA9-4F87-8738-E99D406935D5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{8C57C63D-9F4E-4FF5-8378-E85062DD465E}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{C36948B4-07C8-4E74-B6D6-85F1DEB8A8EC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{97E1A0EC-B0D6-4AEB-9599-89A71B186EA9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe] => Enabled:CodeMeter Runtime Server
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe] => Enabled:CodeMeter Runtime Server

==================== Restore Points =========================

09-03-2020 12:03:23 Naplánovaný kontrolní bod
13-03-2020 19:25:57 Windows Update
23-03-2020 11:25:19 Windows Update

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (03/23/2020 07:08:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Kód výjimky: 0xc000041d
Posun chyby: 0x0008efc4
ID chybujícího procesu: 0x32f8
Čas spuštění chybující aplikace: 0x01d6013cc5863ca6
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
ID zprávy: ccd3c492-b64d-4c87-a224-c947ba283a7f
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 07:08:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Kód výjimky: 0xc0000005
Posun chyby: 0x0008efc4
ID chybujícího procesu: 0x32f8
Čas spuštění chybující aplikace: 0x01d6013cc5863ca6
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
ID zprávy: 6584f0cf-f966-42df-ab79-586ca005f57a
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 07:06:41 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (2916,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (03/23/2020 03:46:58 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (15264,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (03/23/2020 02:38:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: rtl140.bpl, verze: 14.0.3593.25826, časové razítko: 0x4aef9662
Kód výjimky: 0xc000041d
Posun chyby: 0x0007bd74
ID chybujícího procesu: 0x414
Čas spuštění chybující aplikace: 0x01d6010911e82eab
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\rtl140.bpl
ID zprávy: 6035c757-234c-4f02-90b3-f1d255ef7ea2
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 02:38:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: rtl140.bpl, verze: 14.0.3593.25826, časové razítko: 0x4aef9662
Kód výjimky: 0xc0000005
Posun chyby: 0x0007bd74
ID chybujícího procesu: 0x414
Čas spuštění chybující aplikace: 0x01d6010911e82eab
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\rtl140.bpl
ID zprávy: f97f75b6-0a42-4910-8885-1013921f9288
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:

Error: (03/23/2020 01:39:09 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1244,R,98) TILEREPOSITORYS-1-5-18: Při otevírání souboru protokolu C:\WINDOWS\system32\config\systemprofile\AppData\Local\TileDataLayer\Database\EDB.log došlo k chybě -1023 (0xfffffc01).

Error: (03/23/2020 12:47:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Název chybujícího modulu: ecWin.exe, verze: 3.6.2.1715, časové razítko: 0x5c475e92
Kód výjimky: 0xc000041d
Posun chyby: 0x003de99f
ID chybujícího procesu: 0x19dc
Čas spuštění chybující aplikace: 0x01d601002b0efab9
Cesta k chybující aplikaci: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
Cesta k chybujícímu modulu: C:\Users\Vojta\AppData\Local\Callida\euroCALC_NET\30\Client\Bin\ecWin.exe
ID zprávy: 1686a2ea-04bd-4f31-80aa-27f3ac6e213b
Úplný název chybujícího balíčku:
ID aplikace související s chybujícím balíčkem:


System errors:
=============
Error: (03/23/2020 06:51:57 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Zprostředkovatel monitorování Ochrany System Guard v režimu runtime přestala během spouštění reagovat.

Error: (03/23/2020 06:50:27 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: Server {E60687F7-01A1-40AA-86AC-DB1CBF673334} se v daném časovém limitu neregistroval u služby DCOM.

Error: (03/23/2020 06:49:53 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: Služba Správce stažených map přestala během spouštění reagovat.

Error: (03/23/2020 06:45:25 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Autodesk Content Service neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (03/23/2020 06:45:25 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Autodesk Content Service bylo dosaženo časového limitu (45000 ms).

Error: (03/23/2020 06:43:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Autodesk Content Service neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.

Error: (03/23/2020 06:43:54 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Při čekání na připojení služby Autodesk Content Service bylo dosaženo časového limitu (45000 ms).

Error: (03/23/2020 06:41:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Autodesk Content Service neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.


Windows Defender:
===================================
Date: 2019-11-08 12:51:26.516
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {D0D033B4-4A2E-4E06-8EE6-418CAF8613A6}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-11-08 12:33:28.979
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {229A3732-9892-4B97-AC97-AEF69B794245}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-11-08 12:10:04.406
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {C1A0F3D7-7614-4089-9F7C-6BD01E35F383}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-11-08 10:47:55.092
Description:
Prohledávání Antivirová ochrana v programu Windows Defender bylo zastaveno před dokončením.
ID prohledávání: {761BED30-7386-44E1-B20D-8A0D96D87281}
Typ prohledávání: Antimalwarový program
Parametry prohledávání: Rychlé prohledávání
Uživatel: NT AUTHORITY\SYSTEM

Date: 2019-08-23 14:18:44.387
Description:
Antivirová ochrana v programu Windows Defender zjistil malware nebo jiný potenciálně nežádoucí software.
Další informace:
https://go.microsoft.com/fwlink/?linkid ... terprise=0
Název: HackTool:Win64/AutoKMS
ID: 2147723334
Závažnost: Vysoké
Kategorie: Nástroj
Cesta: file:_C:\WINDOWS\SECOH-QAD.dll; file:_C:\WINDOWS\SECOH-QAD.exe
Původ detekce: Místní počítač
Typ detekce: Konkrétní
Zdroj detekce: Systém
Uživatel: NT AUTHORITY\SYSTEM
Název procesu: Unknown
Verze bezpečnostních informací: AV: 1.299.2640.0, AS: 1.299.2640.0, NIS: 1.299.2640.0
Verze modulu: AM: 1.1.16200.1, NIS: 1.1.16200.1

Date: 2019-08-21 07:39:57.364
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.299.2464.0
Zdroj aktualizace: Server Microsoft Update
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\SYSTEM
Aktuální verze modulu:
Předchozí verze modulu: 1.1.16200.1
Kód chyby: 0x80240016
Popis chyby: Při zjišťování aktualizací došlo k neočekávaným potížím. Informace o instalaci nebo řešení potíží s aktualizacemi naleznete v nápovědě a podpoře.

Date: 2019-08-21 02:28:23.201
Description:
Funkce Ochrana v reálném čase u prohledávání Antivirová ochrana v programu Windows Defender zjistila chybu a došlo k jejímu selhání.
Funkce: Při přístupu
Kód chyby: 0x80004005
Popis chyby: Nespecifikovaná chyba
Důvod: Ovladač filtru přeskočil prohledávání položek a je v režimu průchodu. Příčinou může být nízký stav prostředků.

CodeIntegrity:
===================================

Date: 2020-03-23 19:01:35.525
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 19:01:35.488
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 19:01:35.449
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 19:01:35.389
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 19:01:35.339
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 19:01:35.283
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 19:01:35.270
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\CCleaner Browser\Application\CCleanerBrowser.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.

Date: 2020-03-23 19:01:08.518
Description:
Code Integrity determined that a process (\Device\HarddiskVolume5\Program Files (x86)\Google\Chrome\Application\chrome.exe) attempted to load \Device\HarddiskVolume5\Program Files\AVAST Software\Avast\aswhook.dll that did not meet the Microsoft signing level requirements.

==================== Memory info ===========================

BIOS: LENOVO 9ECN36WW(V2.00) 01/12/2015
Motherboard: LENOVO Lenovo Y50-70
Processor: Intel(R) Core(TM) i5-4210H CPU @ 2.90GHz
Percentage of memory in use: 54%
Total physical RAM: 8104.27 MB
Available physical RAM: 3680.43 MB
Total Virtual: 14760.27 MB
Available Virtual: 10182.84 MB

==================== Drives ================================

Drive c: (hadr) (Fixed) (Total:888.87 GB) (Free:618.81 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.17 GB) NTFS

\\?\Volume{568a16f3-ea5a-447b-801a-468914285d17}\ (WINRE_DRV) (Fixed) (Total:0.98 GB) (Free:0.68 GB) NTFS
\\?\Volume{f60f5ad0-965e-4d9e-82f0-2b32cdea9b29}\ (PBR_DRV) (Fixed) (Total:15.31 GB) (Free:5.32 GB) NTFS
\\?\Volume{137847a9-9d22-4a7c-bf00-927c47d41465}\ (SYSTEM_DRV) (Fixed) (Total:0.25 GB) (Free:0.22 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B8499F7E)

Partition: GPT.

==================== End of Addition.txt =======================

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 19:58
od Rudy
Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
FirewallRules: [{0CF73C32-CBCC-48CB-8885-3CC945F73E4A}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{7138C67D-C383-4798-9E62-EE08456F6B7E}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
C:\Program Files\KMSpico
C:\WINDOWS\SECOH-QAD.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Policies\Explorer: []
C:\Program Files\McAfee Security Scan
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2020-03-12]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.1702\SSScheduler.exe (McAfee, LLC -> McAfee, LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {39FCD610-61EB-4DA7-B1F9-07A3B550462A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {4DA2167E-2774-4F23-AEA0-430FCED7DE15} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
Task: {4EFF5277-3A84-42A4-B203-549FFA33A1DF} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe
Task: {AF8241B0-081F-425C-B8D5-188FA5A1591C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.)
Task: {D33787A4-3F46-428B-A798-FC2CF49AFD9E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.)
C:\ProgramData\McAfee Security Scan
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\Tasks\AutoKMS
C:\Users\Vojta\AppData\Local\{C4850B69-86DD-405A-AAE3-64C9C9823ACB}


EmptyTemp:
Hosts:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 20:14
od Gárf
Fix result of Farbar Recovery Scan Tool (x64) Version: 22-03-2020
Ran by Vojta (23-03-2020 20:04:09) Run:1
Running from C:\Users\Vojta\Desktop
Loaded Profiles: Vojta (Available Profiles: Vojta)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`26hfm [0]
AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0]
FirewallRules: [{0CF73C32-CBCC-48CB-8885-3CC945F73E4A}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
FirewallRules: [{7138C67D-C383-4798-9E62-EE08456F6B7E}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe No File
C:\Program Files\KMSpico
C:\WINDOWS\SECOH-QAD.exe
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-3645671178-350016163-1338499739-1001\...\Policies\Explorer: []
C:\Program Files\McAfee Security Scan
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2020-03-12]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.1702\SSScheduler.exe (McAfee, LLC -> McAfee, LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
Task: {39FCD610-61EB-4DA7-B1F9-07A3B550462A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {4DA2167E-2774-4F23-AEA0-430FCED7DE15} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe
Task: {4EFF5277-3A84-42A4-B203-549FFA33A1DF} - System32\Tasks\AutoKMS => C:\WINDOWS\AutoKMS\AutoKMS.exe
Task: {AF8241B0-081F-425C-B8D5-188FA5A1591C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.)
Task: {D33787A4-3F46-428B-A798-FC2CF49AFD9E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-10-20] (Google Inc -> Google Inc.)
C:\ProgramData\McAfee Security Scan
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
C:\WINDOWS\system32\Tasks\AutoKMS
C:\Users\Vojta\AppData\Local\{C4850B69-86DD-405A-AAE3-64C9C9823ACB}


EmptyTemp:
Hosts:
End

*****************

Processes closed successfully.
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => removed successfully
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`26hfm" ADS removed successfully
C:\ProgramData\Reprise => ":wupeogjxldtlfudivq`qsp`27hfm" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0CF73C32-CBCC-48CB-8885-3CC945F73E4A}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7138C67D-C383-4798-9E62-EE08456F6B7E}" => removed successfully
C:\Program Files\KMSpico => moved successfully
"C:\WINDOWS\SECOH-QAD.exe" => not found
"HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched" => removed successfully
"HKU\S-1-5-21-3645671178-350016163-1338499739-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\" => removed successfully
C:\Program Files\McAfee Security Scan => moved successfully
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk => moved successfully
"C:\Program Files\McAfee Security Scan\3.11.1702\SSScheduler.exe" => not found
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{39FCD610-61EB-4DA7-B1F9-07A3B550462A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{39FCD610-61EB-4DA7-B1F9-07A3B550462A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4DA2167E-2774-4F23-AEA0-430FCED7DE15}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4DA2167E-2774-4F23-AEA0-430FCED7DE15}" => removed successfully
C:\WINDOWS\System32\Tasks\AutoPico Daily Restart => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoPico Daily Restart" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{4EFF5277-3A84-42A4-B203-549FFA33A1DF}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4EFF5277-3A84-42A4-B203-549FFA33A1DF}" => removed successfully
C:\WINDOWS\System32\Tasks\AutoKMS => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AutoKMS" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AF8241B0-081F-425C-B8D5-188FA5A1591C}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AF8241B0-081F-425C-B8D5-188FA5A1591C}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineCore" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D33787A4-3F46-428B-A798-FC2CF49AFD9E}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D33787A4-3F46-428B-A798-FC2CF49AFD9E}" => removed successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\GoogleUpdateTaskMachineUA" => removed successfully
C:\ProgramData\McAfee Security Scan => moved successfully
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA" => not found
"C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore" => not found
"C:\WINDOWS\system32\Tasks\AutoKMS" => not found
C:\Users\Vojta\AppData\Local\{C4850B69-86DD-405A-AAE3-64C9C9823ACB} => moved successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 12083200 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 23288225 B
Java, Flash, Steam htmlcache => 1110 B
Windows/system/drivers => 162895934 B
Edge => 56320 B
Chrome => 71028654 B
Firefox => 0 B
Opera => 141879 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 17482 B
NetworkService => 17482 B
Vojta => 41261689 B

RecycleBin => 0 B
EmptyTemp: => 296.4 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:04:57 ====

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 20:16
od Gárf
následně proveden restart

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 20:57
od Rudy
Smazáno. Nastala nějaká změna?

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 21:14
od Gárf
PC je pocitově rychlejší, stabilitu VPN ověřím zítra během pracovního procesu - ozvu se. Každopádně moc děkuji

Re: Vypadávající VPN, zpomalení PC

Napsal: 23 bře 2020 22:03
od Rudy
OK. Zatím nemáte zač! :)

Re: Vypadávající VPN, zpomalení PC

Napsal: 24 bře 2020 16:36
od Gárf
Nestabilní VPN byla z důvodu přetížené sítě poskytovatele. Celkově vzato PC šlape o dost lépe. Ještě jednou moc děkuji :)

Re: Vypadávající VPN, zpomalení PC

Napsal: 24 bře 2020 16:51
od Rudy
Gárf píše:Nestabilní VPN byla z důvodu přetížené sítě poskytovatele. Celkově vzato PC šlape o dost lépe. Ještě jednou moc děkuji :)
I to by bylo možné. Rádo se stalo! :)