Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu z RSIT

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Prosím o kontrolu logu z RSIT

#1 Příspěvek od Filip.R. »

Předem děkuji.

Logfile of random's system information tool 1.10 (written by random/random)
Run by Filip at 2015-08-19 14:46:46
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 13 GB (8%) free of 153 GB
Total RAM: 3198 MB (61% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:46:48, on 19.8.2015
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.17840)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Users\Filip\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Windows\System32\regsvr32.exe
C:\Program Files\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
C:\Windows\system32\taskhost.exe
C:\Users\Filip\AppData\Local\Akamai\netsession_win.exe
C:\Program Files\Steam\steam.exe
C:\Program Files\Steam\bin\steamwebhelper.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\foobar2000\foobar2000.exe
C:\Users\Filip\Downloads\RSIT.exe
C:\Program Files\trend micro\Filip.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll
O4 - HKLM\..\Run: [ASUS Update Checker] C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe
O4 - HKLM\..\Run: [Lightshot] C:\Program Files\Skillbrains\lightshot\Lightshot.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" -s
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Common Files\Java\Java Update\jusched.exe
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Filip\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
O4 - HKCU\..\Run: [Ection] regsvr32.exe C:\Users\Filip\AppData\Local\Ection\Wmidec32.dll
O4 - HKCU\..\Run: [Icsoft] C:\Windows\System32\regsvr32.exe C:\Users\Filip\AppData\Local\YSNPack\cygVdm16.dll
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [SPReview] "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"http://go.microsoft.com/fwlink/?LinkID=122915" /build:7601 (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Služba Vzdálené plochy Chrome (chromoting) - Google Inc. - C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
O23 - Service: Folder Size (FolderSize) - Brio - C:\Program Files\FolderSize\FolderSizeSvc.exe
O23 - Service: GalaxyClientService - GOG.com - C:\Program Files\GalaxyClient\GalaxyClientService.exe
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HuaweiHiSuiteService.exe - Unknown owner - C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files\Skype\Updater\Updater.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: STI Simulator - Unknown owner - C:\Windows\System32\PAStiSvc.exe

--
End of file - 6455 bytes

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\ColorWheel.job - c:\programdata\{d94dfa4b-c917-35e5-d94d-dfa4bc91e92f}\smart launcher 3 pro v3.0-beta9 apkgalaxy.com.apksmart launcher 3 pro v3.0-beta9 apkgalaxy.com.exe --startup=1 --single
C:\Windows\tasks\FolderBrusher.job - c:\programdata\{599dd0b5-075a-1f68-599d-dd0b507542d4}\4721680087125275801b.exe --startup=1 --single
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-22 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-22 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ASUS Update Checker"=C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe [2009-12-28 121472]
"Lightshot"=C:\Program Files\Skillbrains\lightshot\Lightshot.exe [2014-11-18 226560]
"StartCCC"=C:\Program Files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe [2015-03-20 748232]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2015-06-06 12205784]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2014-12-17 508800]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"=C:\Users\Filip\AppData\Local\Akamai\netsession_win.exe [2015-07-23 4691384]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner.exe [2015-07-17 6453528]
"Ection"=regsvr32.exe C:\Users\Filip\AppData\Local\Ection\Wmidec32.dll []
"Icsoft"=C:\Windows\System32\regsvr32.exe [2009-07-14 14848]
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GalaxyClient]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
C:\Users\Filip\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2015-07-28 2017848]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37Crusader]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HitmanPro37CrusaderBoot]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"ConsentPromptBehaviorUser"=3
"EnableLUA"=0
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"VIDC.LAGS"=lagarith.dll
"VIDC.FPS1"=frapsvid.dll
"wave6"=wdmaud.drv
"mixer6"=wdmaud.drv
"wave8"=wdmaud.drv
"mixer8"=wdmaud.drv
"msacm.vorbis"=vorbis.acm
"vidc.cvid"=iccvid.dll
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave7"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer7"=wdmaud.drv
"vidc.mjpg"=bdmjpeg.dll
"vidc.mpeg"=bdmpegv.dll
"msacm.bdmpeg"=bdmpega.acm

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2015-08-19 14:45:03 ----D---- C:\Program Files\trend micro
2015-08-19 14:45:02 ----D---- C:\rsit
2015-08-19 14:37:49 ----D---- C:\Users\Filip\AppData\Roaming\LizardSystems
2015-08-19 14:37:49 ----D---- C:\Program Files\LizardSystems
2015-08-19 01:23:36 ----SHD---- C:\Config.Msi
2015-08-17 14:25:01 ----A---- C:\Windows\system32\wininet.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\wextract.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\webcheck.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\vbscript.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\urlmon.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\url.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\SetIEInstalledDate.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\RegisterIEPKEYs.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\pngfilt.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\occache.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\msrating.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\msls31.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\mshtmlmedia.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\mshtmler.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\mshtmled.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\MshtmlDac.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\mshtml.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\mshta.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\msfeedssync.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\msfeedsbs.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\msfeeds.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\licmgr10.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\jsproxy.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\jsIntl.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\jscript9diag.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\jscript9.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\jscript.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\inseng.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\imgutil.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\iexpress.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ieUnatt.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ieui.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\iesysprep.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\iesetup.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\iertutil.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\iernonce.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\iepeers.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ieframe.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ieetwproxystub.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ieetwcollector.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\iedkcs32.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ieapfltr.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ieapfltr.dat
2015-08-17 14:25:01 ----A---- C:\Windows\system32\IEAdvpack.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\ie4uinit.exe
2015-08-17 14:25:01 ----A---- C:\Windows\system32\icardie.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\elshyph.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\dxtrans.dll
2015-08-17 14:25:01 ----A---- C:\Windows\system32\dxtmsft.dll
2015-08-17 10:52:15 ----D---- C:\Program Files\Recuva
2015-08-16 23:40:56 ----A---- C:\Windows\system32\drivers\hitmanpro37.sys
2015-08-16 22:36:06 ----A---- C:\TDSSKiller.3.1.0.5_16.08.2015_22.36.06_log.txt
2015-08-16 22:35:49 ----A---- C:\TDSSKiller.3.0.0.16_16.08.2015_22.35.48_log.txt
2015-08-16 21:59:02 ----D---- C:\ProgramData\NCH Software
2015-08-16 21:58:57 ----D---- C:\Program Files\NCH Software
2015-08-16 21:58:55 ----D---- C:\Users\Filip\AppData\Roaming\NCH Software
2015-08-16 20:53:35 ----D---- C:\Program Files\Lost Heaven Multiplayer
2015-08-16 20:16:17 ----D---- C:\Program Files\Cenega Czech
2015-08-16 16:00:55 ----D---- C:\Users\Filip\AppData\Roaming\VitySoft
2015-08-16 16:00:38 ----D---- C:\Program Files\FreeRapid-0.9u4
2015-08-16 14:32:21 ----D---- C:\Program Files\Rockstar Games
2015-08-15 19:42:01 ----D---- C:\Users\Filip\AppData\Roaming\GHISLER
2015-08-15 19:42:01 ----D---- C:\Program Files\totalcmd
2015-08-15 19:42:01 ----A---- C:\Windows\UC.PIF
2015-08-15 19:42:01 ----A---- C:\Windows\RAR.PIF
2015-08-15 19:42:01 ----A---- C:\Windows\PKZIP.PIF
2015-08-15 19:42:01 ----A---- C:\Windows\PKUNZIP.PIF
2015-08-15 19:42:01 ----A---- C:\Windows\LHA.PIF
2015-08-15 19:42:01 ----A---- C:\Windows\ARJ.PIF
2015-08-15 11:38:35 ----D---- C:\Users\Filip\AppData\Roaming\Atari
2015-08-15 11:23:26 ----D---- C:\Users\Filip\AppData\Roaming\Leadertech
2015-08-15 11:23:21 ----D---- C:\Program Files\Common Files\PocketSoft
2015-08-15 11:23:21 ----A---- C:\Windows\patchw32.dll
2015-08-15 11:17:30 ----D---- C:\Program Files\Atari
2015-08-13 15:31:05 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2015-08-13 15:30:51 ----D---- C:\Program Files\Malwarebytes Anti-Malware
2015-08-13 15:30:51 ----A---- C:\Windows\system32\drivers\mwac.sys
2015-08-13 15:30:51 ----A---- C:\Windows\system32\drivers\mbamchameleon.sys
2015-08-13 15:30:51 ----A---- C:\Windows\system32\drivers\mbam.sys
2015-08-13 13:59:35 ----D---- C:\Program Files\n2n Gui
2015-08-12 20:40:21 ----D---- C:\Program Files\City Car Driving
2015-08-12 19:46:01 ----D---- C:\ProgramData\6WinManPro6
2015-08-12 19:45:57 ----A---- C:\Windows\prleth.sys
2015-08-12 19:45:57 ----A---- C:\Windows\hgfs.sys
2015-08-11 17:24:13 ----D---- C:\Users\Filip\AppData\Roaming\BANDISOFT
2015-08-11 17:23:42 ----D---- C:\Program Files\Bandicam
2015-08-11 17:23:39 ----D---- C:\Program Files\BandiMPEG1
2015-08-11 16:02:17 ----A---- C:\Windows\IsUninst.exe
2015-08-02 17:40:15 ----D---- C:\Program Files\Defraggler
2015-08-02 17:37:29 ----D---- C:\Program Files\CCleaner
2015-07-26 23:29:01 ----D---- C:\Users\Filip\AppData\Roaming\SmartSteamEmu
2015-07-24 17:18:25 ----D---- C:\TRS2004 - součásti
2015-07-23 20:43:29 ----D---- C:\Users\Filip\AppData\Roaming\java
2015-07-23 20:34:18 ----D---- C:\Users\Filip\AppData\Roaming\.minecraft
2015-07-23 20:24:27 ----D---- C:\Users\Filip\AppData\Roaming\uTorrent
2015-07-23 20:23:04 ----D---- C:\Program Files\Driver Checker
2015-07-23 18:56:59 ----D---- C:\Program Files\Auran
2015-07-21 01:26:15 ----D---- C:\ProgramData\NovaTech Network
2015-07-21 01:12:27 ----D---- C:\Program Files\ATI Technologies
2015-07-20 16:55:18 ----D---- C:\Program Files\Akoff Music Composer Demo
2015-07-20 16:21:06 ----A---- C:\Windows\HideWin.exe

======List of files/folders modified in the last 1 month======

2015-08-19 14:46:46 ----D---- C:\Windows\Temp
2015-08-19 14:45:39 ----D---- C:\Users\Filip\AppData\Roaming\foobar2000
2015-08-19 14:45:03 ----RD---- C:\Program Files
2015-08-19 14:38:03 ----AD---- C:\ProgramData\Temp
2015-08-19 14:18:13 ----D---- C:\Program Files\Steam
2015-08-19 14:07:26 ----D---- C:\ProgramData\NVIDIA
2015-08-19 13:03:39 ----SHD---- C:\Windows\Installer
2015-08-19 02:16:33 ----D---- C:\Users\Filip\AppData\Roaming\Skype
2015-08-17 14:36:11 ----D---- C:\Program Files\Everything
2015-08-17 14:31:16 ----D---- C:\Windows\winsxs
2015-08-17 14:30:33 ----D---- C:\Windows\Panther
2015-08-17 14:30:18 ----D---- C:\Windows\system32\config
2015-08-17 14:29:00 ----D---- C:\Windows\system32\migration
2015-08-17 14:29:00 ----D---- C:\Windows\system32\en-US
2015-08-17 14:29:00 ----D---- C:\Windows\system32\cs-CZ
2015-08-17 14:29:00 ----D---- C:\Windows\System32
2015-08-17 14:29:00 ----D---- C:\Windows\PolicyDefinitions
2015-08-17 14:29:00 ----D---- C:\Program Files\Internet Explorer
2015-08-17 14:28:24 ----D---- C:\Windows\Logs
2015-08-17 14:24:57 ----D---- C:\Windows\system32\catroot2
2015-08-17 14:23:50 ----SHD---- C:\System Volume Information
2015-08-17 14:21:48 ----D---- C:\Windows
2015-08-17 13:15:47 ----D---- C:\Windows\Prefetch
2015-08-16 23:40:56 ----D---- C:\Windows\system32\drivers
2015-08-16 23:37:06 ----D---- C:\Program Files\Common Files\PX Storage Engine
2015-08-16 22:04:07 ----D---- C:\AdwCleaner
2015-08-16 21:59:02 ----HD---- C:\ProgramData
2015-08-16 21:59:02 ----D---- C:\Windows\system32\Tasks
2015-08-16 19:12:45 ----D---- C:\Windows\inf
2015-08-16 18:29:05 ----D---- C:\Users\Filip\AppData\Roaming\vlc
2015-08-16 13:35:53 ----D---- C:\Users\Filip\AppData\Roaming\DAEMON Tools Lite
2015-08-15 19:45:19 ----D---- C:\Program Files\Microsoft Games
2015-08-15 11:30:57 ----HD---- C:\Program Files\InstallShield Installation Information
2015-08-15 11:23:21 ----D---- C:\Program Files\Common Files
2015-08-14 20:35:01 ----D---- C:\Program Files\Common Files\Steam
2015-08-14 15:22:00 ----D---- C:\Windows\SoftwareDistribution
2015-08-13 13:49:50 ----D---- C:\Windows\rescache
2015-08-12 21:39:28 ----D---- C:\Users\Filip\AppData\Roaming\TS3Client
2015-08-12 19:43:49 ----SD---- C:\Users\Filip\AppData\Roaming\Microsoft
2015-08-12 19:14:00 ----A---- C:\Windows\system32\FlashPlayerApp.exe
2015-08-12 10:09:07 ----D---- C:\Program Files\Samsung
2015-08-11 17:21:09 ----D---- C:\Users\Filip\AppData\Roaming\Opera Software
2015-08-10 19:00:20 ----D---- C:\Program Files\Google
2015-08-10 18:58:33 ----D---- C:\Windows\Tasks
2015-08-10 16:06:21 ----D---- C:\Program Files\foobar2000
2015-08-03 18:28:35 ----D---- C:\Users\Filip\AppData\Roaming\Spotify
2015-08-03 08:38:16 ----D---- C:\Program Files\Mozilla Firefox
2015-08-02 17:29:35 ----D---- C:\Windows\system32\DriverStore
2015-07-30 21:34:31 ----RSD---- C:\Windows\Fonts
2015-07-23 09:53:02 ----D---- C:\Windows\system32\NDF
2015-07-22 22:50:43 ----D---- C:\ProgramData\Oracle
2015-07-22 22:47:29 ----A---- C:\Windows\system32\WindowsAccessBridge.dll
2015-07-22 22:46:52 ----D---- C:\Program Files\Java
2015-07-21 12:07:36 ----A---- C:\Windows\system32\PerfStringBackup.INI
2015-07-21 01:21:04 ----D---- C:\Windows\system32\directx
2015-07-21 01:20:54 ----HD---- C:\Windows\msdownld.tmp
2015-07-21 01:14:51 ----D---- C:\Windows\system32\catroot
2015-07-20 16:34:53 ----D---- C:\Windows\PixArt
2015-07-20 16:34:52 ----D---- C:\Windows\twain_32

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 AtiPcie;AMD PCI Express (3GIO) Filter; C:\Windows\system32\DRIVERS\AtiPcie.sys [2009-05-05 14392]
R0 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2013-09-27 214696]
R0 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12368]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-20 173440]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-09 243128]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO32.SYS [2015-06-06 23840]
R2 Parvdm;Parvdm; C:\Windows\system32\DRIVERS\parvdm.sys [2009-07-14 8704]
R2 SSPORT;SSPORT; \??\C:\Windows\system32\Drivers\SSPORT.sys [2011-02-08 5120]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2015-06-06 3498712]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2015-06-18 23256]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\Windows\system32\DRIVERS\ASACPI.sys [2015-06-06 13216]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2015-05-13 162624]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt86win7.sys [2015-06-06 723160]
R3 SCREAMINGBDRIVER;Screaming Bee Audio; C:\Windows\system32\drivers\ScreamingBAudio.sys [2012-07-31 34896]
R3 VCSVADHWSer;Avnex Virtual Audio Device (WDM); C:\Windows\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
R3 WFLR6654;WinFast TV2000 XP Expert (FM1216MK3); C:\Windows\system32\drivers\wfeaglxt.sys [2015-06-06 433920]
S2 CX23880;WinFast CX2388x WDM Video Capture.; C:\Windows\system32\drivers\cx88vid.sys [2005-08-11 163584]
S2 CXTUNE;Conexant 2388x Tuner; C:\Windows\system32\drivers\CX88TUNE_IBV32.sys [2006-11-02 17664]
S3 aic78xx;aic78xx; C:\Windows\system32\DRIVERS\djsvs.sys [2009-07-14 70720]
S3 amdagp;Ovladač filtru AMD portu AGP; C:\Windows\system32\drivers\amdagp.sys [2009-07-14 53312]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\b57nd60x.sys [2009-07-14 229888]
S3 eapihdrv;eapihdrv; \??\C:\Users\Filip\AppData\Local\Temp\ehdrv.sys []
S3 hamachi;Hamachi Network Interface; C:\Windows\system32\DRIVERS\hamachi.sys [2015-01-14 26176]
S3 hitmanpro37;HitmanPro 3.7 Support Driver; \??\C:\Windows\system32\drivers\hitmanpro37.sys [2015-08-16 35992]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2015-08-13 98520]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2015-06-18 51928]
S3 NisDrv;Microsoft Network Inspection System; C:\Windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
S3 PAC207;VideoCAM GE111; C:\Windows\system32\DRIVERS\pfc027.sys [2005-04-08 162176]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 14848]
S3 sisagp;Filtr SIS sběrnice AGP; C:\Windows\system32\drivers\sisagp.sys [2009-07-14 52304]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
S3 VASDeviceDrm;Virtual Audio Streaming with Drm (WDM); C:\Windows\system32\drivers\vasdDev.sys [2012-03-19 1451312]
S3 VCam_WDM;Virtual Webcam 8.0; C:\Windows\system32\DRIVERS\VCam_WDM.sys [2012-05-25 101688]
S3 viaagp;Filtr VIA sběrnice AGP; C:\Windows\system32\drivers\viaagp.sys [2009-07-14 53328]
S3 ViaC7;VIA C7 Processor Driver; C:\Windows\system32\DRIVERS\viac7.sys [2009-07-14 52736]
S3 WinUsb;Android USB Driver; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-20 35968]
S3 xhunter1;xhunter1; \??\C:\Windows\xhunter1.sys []
S4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad32v.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe [2014-12-19 81088]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-03-19 276992]
R2 FolderSize;Folder Size; C:\Program Files\FolderSize\FolderSizeSvc.exe [2013-02-13 114688]
R2 chromoting;Služba Vzdálené plochy Chrome; C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe [2015-03-08 56648]
R2 MsMpSvc;Microsoft Antimalware Service; c:\Program Files\Microsoft Security Client\MsMpEng.exe [2013-10-23 22208]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2015-05-12 671048]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-05-12 410768]
R2 STI Simulator;STI Simulator; C:\Windows\System32\PAStiSvc.exe [2005-01-14 53248]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2011-03-28 1713536]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-04-12 103608]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-10 144200]
S2 HuaweiHiSuiteService.exe;HuaweiHiSuiteService.exe; C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe -/service []
S2 MBAMService;MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
S2 SkypeUpdate;Skype Updater; C:\Program Files\Skype\Updater\Updater.exe [2015-06-03 327296]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12 269000]
S3 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe [2014-04-12 45744]
S3 GalaxyClientService;GalaxyClientService; C:\Program Files\GalaxyClient\GalaxyClientService.exe [2015-08-16 1720888]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2015-08-16 6874680]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-10 144200]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2015-08-17 102912]
S3 NisSrv;@c:\Program Files\Microsoft Security Client\MpAsDesc.dll,-243; c:\Program Files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 Steam Client Service;Steam Client Service; C:\Program Files\Common Files\Steam\SteamService.exe [2015-08-12 838336]
S4 NetMsmqActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetPipeActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]
S4 NetTcpActivator;@c:\Windows\Microsoft.NET\Framework\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe [2014-04-12 139944]

-----------------EOF-----------------

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#2 Příspěvek od Filip.R. »


Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#3 Příspěvek od Filip.R. »

No tak .dll soubor se podařilo odstranit jen jeden. Ten, který jsem testoval na těch stránkách, nešel odstranit ani v nouzové režimu (otevřen v nějakém programu). OTL běželo cca. 20min a poté vyskočila tabulka s nápisem "Out of memory", tak jsem ho vypl.

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#4 Příspěvek od Filip.R. »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-08-2015
Ran by Filip (administrator) on PC-PC (19-08-2015 18:54:01)
Running from C:\Users\Filip\Desktop
Loaded Profiles: Filip (Available Profiles: PC & Filip)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Google Inc.) C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
(Google Inc.) C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
(Brio) C:\Program Files\FolderSize\FolderSizeSvc.exe
() C:\Windows\System32\PAStiSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.28.1\GoogleCrashHandler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Skillbrains) C:\Program Files\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
(Skype Technologies S.A.) C:\Program Files\Skype\Phone\Skype.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ASUS Update Checker] => C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe [121472 2009-12-28] (ASUSTeK Computer Inc.)
HKLM\...\Run: [Lightshot] => C:\Program Files\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM\...\Run: [StartCCC] => C:\Program Files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe [748232 2015-03-20] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12205784 2015-06-06] (Realtek Semiconductor)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6453528 2015-07-17] (Piriform Ltd)
HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...409d6c4515e9\InprocServer32: [Default-shell32] C:\Users\Filip\AppData\Local\YSNPack\cygVdm16.dllATTENTION! ====> ZeroAccess?
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-12-07] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001 -> DefaultScope {FAFE46D2-0727-4C91-B1A6-0724CF25099D} URL = hxxps://www.google.com/search?q={searchTerms}&s ... utEncoding?}
SearchScopes: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001 -> {FAFE46D2-0727-4C91-B1A6-0724CF25099D} URL = hxxps://www.google.com/search?q={searchTerms}&s ... utEncoding?}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-22] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-22] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 94.74.192.252 94.74.192.244
Tcpip\..\Interfaces\{1BD708E7-1195-45E6-892F-9368F56D361F}: [DhcpNameServer] 94.74.192.252 94.74.192.244
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\o6yn3op4.default
FF Homepage: seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1215155.dll [2014-12-02] (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-22] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3936994563-2387293699-3021914305-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Filip\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-22] (Unity Technologies ApS)
FF Extension: Compat Inventory WMI provider - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\o6yn3op4.default\Extensions\{F4A9C71A-084E-C401-2625-8EB93ADC9AC7} [2015-08-12]
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]

Chrome:
=======
CHR Profile: C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-10]
CHR Extension: (Facebook Messenger, Social News) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbhigdfhmhhdieikofamakgecjalgdmd [2015-08-16]
CHR Extension: (Adblock Plus) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-08-16]
CHR Extension: (Disable Youtube™ HTML5 Player) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\enmofgaijnbjpblfljopnpdogpldapoc [2015-08-16]
CHR Extension: (YouTube™ Ex) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoeljlbdbgaeocdnnepagaibkpbdnfon [2015-08-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-10]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Filip\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-07-02]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [276992 2015-03-19] (Advanced Micro Devices, Inc.) [File not signed]
R2 chromoting; C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe [56648 2015-03-08] (Google Inc.)
R2 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [114688 2013-02-13] (Brio) [File not signed]
S3 GalaxyClientService; C:\Program Files\GalaxyClient\GalaxyClientService.exe [1720888 2015-08-16] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6874680 2015-08-16] (GOG.com)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 STI Simulator; C:\Windows\System32\PAStiSvc.exe [53248 2005-01-14] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 HuaweiHiSuiteService.exe; "C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe" -/service [X]
S2 kss; no ImagePath

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [11944 2015-06-06] (Advanced Micro Devices Inc.)
S2 CX23880; C:\Windows\System32\drivers\cx88vid.sys [163584 2005-08-11] (Leadtek Research Inc.)
S2 CXTUNE; C:\Windows\System32\drivers\CX88TUNE_IBV32.sys [17664 2006-11-02] (Conexant Systems, Inc.) [File not signed]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-09] (Disc Soft Ltd)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2015-01-14] (LogMeIn, Inc.)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [35992 2015-08-16] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-06-06] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [98520 2015-08-13] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2015-06-06] ()
S3 PAC207; C:\Windows\System32\DRIVERS\pfc027.sys [162176 2005-04-08] ()
R3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2012-07-31] (Screaming Bee LLC)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2011-02-08] (Samsung Electronics) [File not signed]
S3 VASDeviceDrm; C:\Windows\System32\drivers\vasdDev.sys [1451312 2012-03-19] (ShiningMorning Inc.)
S3 VCam_WDM; C:\Windows\System32\DRIVERS\VCam_WDM.sys [101688 2012-05-25] (e2eSoft)
R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex)
R3 WFLR6654; C:\Windows\System32\drivers\wfeaglxt.sys [433920 2015-06-06] (Leadtek Research Inc.)
S3 eapihdrv; \??\C:\Users\Filip\AppData\Local\Temp\ehdrv.sys [X]
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [102272 2015-05-07] (Huawei Technologies Co., Ltd.)
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-19 18:54 - 2015-08-19 18:54 - 00014539 _____ C:\Users\Filip\Desktop\FRST.txt
2015-08-19 18:52 - 2015-08-19 18:54 - 00000000 ____D C:\FRST
2015-08-19 18:52 - 2015-08-19 18:52 - 01677312 _____ (Farbar) C:\Users\Filip\Desktop\FRST.exe
2015-08-19 18:29 - 2015-08-19 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-19 18:27 - 2015-08-19 18:27 - 00000000 ____D C:\Users\Filip\Tracing
2015-08-19 17:04 - 2015-08-19 17:04 - 00000512 _____ C:\PhysicalMBR.bin
2015-08-19 17:00 - 2015-08-19 17:00 - 00602112 _____ (OldTimer Tools) C:\Users\Filip\Downloads\OTL.exe
2015-08-19 16:44 - 2015-08-19 16:44 - 00000275 _____ C:\Users\Filip\Downloads\figreg.rar
2015-08-19 16:44 - 2015-08-19 16:44 - 00000275 _____ C:\Users\Filip\Desktop\figreg.rar
2015-08-19 16:44 - 2015-08-19 16:44 - 00000000 ____D C:\Users\Filip\Desktop\figreg
2015-08-19 16:43 - 2015-08-19 16:44 - 00004929 _____ C:\Users\Filip\Desktop\Nový textový dokument.txt
2015-08-19 14:45 - 2015-08-19 14:46 - 00000000 ____D C:\Program Files\trend micro
2015-08-19 14:45 - 2015-08-19 14:45 - 00000000 ____D C:\rsit
2015-08-19 14:44 - 2015-08-19 14:44 - 01107968 _____ C:\Users\Filip\Downloads\RSIT.exe
2015-08-19 14:37 - 2015-08-19 14:37 - 00001185 _____ C:\Users\Filip\Desktop\Wi-Fi Scanner.lnk
2015-08-19 14:37 - 2015-08-19 14:37 - 00000000 ____D C:\Users\Filip\AppData\Roaming\LizardSystems
2015-08-19 14:37 - 2015-08-19 14:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LizardSystems
2015-08-19 14:37 - 2015-08-19 14:37 - 00000000 ____D C:\Program Files\LizardSystems
2015-08-19 14:24 - 2015-08-19 14:25 - 09559024 _____ C:\Users\Filip\Downloads\wifiscanner_setup.exe
2015-08-18 01:43 - 2015-08-18 01:43 - 00000000 _____ C:\Users\Filip\Desktop\httpsleduju.tocesta-z-mesta.txt
2015-08-17 14:25 - 2015-08-17 14:25 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-17 14:25 - 2015-08-17 14:25 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-17 14:25 - 2015-08-17 14:25 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-08-17 14:25 - 2015-08-17 14:25 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-17 14:25 - 2015-08-17 14:25 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-08-17 14:25 - 2015-08-17 14:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-17 14:21 - 2015-08-17 14:28 - 00011858 _____ C:\Windows\IE11_main.log
2015-08-17 14:21 - 2015-08-17 14:21 - 02077392 _____ (Microsoft Corporation) C:\Users\Filip\Downloads\IE11-Windows6.1.exe
2015-08-17 10:52 - 2015-08-17 10:54 - 00000000 ____D C:\Program Files\Recuva
2015-08-17 10:51 - 2015-08-17 10:51 - 04426120 _____ (Piriform Ltd) C:\Users\Filip\Downloads\rcsetup152.exe
2015-08-16 23:40 - 2015-08-16 23:40 - 00035992 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2015-08-16 23:25 - 2015-08-16 23:26 - 21220036 _____ C:\Users\Filip\Downloads\Hitman.Pro.v3.7.9.Build.242.rar
2015-08-16 23:22 - 2015-08-16 23:22 - 00000000 ____D C:\Users\Filip\Downloads\Hitman Pro 3.5.9 Build 125 (x64) incl crack
2015-08-16 22:35 - 2015-08-16 22:36 - 04383777 _____ C:\Users\Filip\Downloads\tdsskiller (1).zip
2015-08-16 22:35 - 2015-08-16 22:35 - 04101100 _____ C:\Users\Filip\Downloads\tdsskiller.zip
2015-08-16 21:59 - 2015-08-16 21:59 - 00000000 ____D C:\ProgramData\NCH Software
2015-08-16 21:58 - 2015-08-16 23:38 - 00000000 ____D C:\Program Files\NCH Software
2015-08-16 21:58 - 2015-08-16 21:58 - 00814128 _____ (NCH Software) C:\Users\Filip\Downloads\vxlsetup.exe
2015-08-16 21:58 - 2015-08-16 21:58 - 00000000 ____D C:\Users\Filip\AppData\Roaming\NCH Software
2015-08-16 21:15 - 2015-08-16 21:15 - 01243906 _____ C:\Users\Filip\Downloads\lhmp-server-rc1-updated.zip
2015-08-16 20:53 - 2015-08-16 21:17 - 00000000 ____D C:\Program Files\Lost Heaven Multiplayer
2015-08-16 20:53 - 2015-08-16 20:53 - 06391244 _____ (Lost Heaven Multiplayer ) C:\Users\Filip\Downloads\setup.exe
2015-08-16 20:53 - 2015-08-16 20:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lost Heaven Multiplayer
2015-08-16 20:16 - 2015-08-16 20:16 - 00000000 ____D C:\Program Files\Cenega Czech
2015-08-16 18:45 - 2015-08-19 16:56 - 00001008 _____ C:\Windows\setupact.log
2015-08-16 18:45 - 2015-08-16 18:45 - 00000000 _____ C:\Windows\setuperr.log
2015-08-16 16:06 - 2015-08-16 20:03 - 1828620993 _____ C:\Users\Filip\Downloads\Mafia-1-CZ-Plna-verze.rar
2015-08-16 16:00 - 2015-08-16 16:00 - 00000000 ____D C:\Users\Filip\AppData\Roaming\VitySoft
2015-08-16 16:00 - 2015-08-16 16:00 - 00000000 ____D C:\Users\Filip\.objectdb
2015-08-16 16:00 - 2015-08-16 16:00 - 00000000 ____D C:\Program Files\FreeRapid-0.9u4
2015-08-16 15:58 - 2015-08-16 16:00 - 17403694 _____ C:\Users\Filip\Downloads\FreeRapid-0.9u4.zip
2015-08-16 14:55 - 2015-08-16 14:55 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2015-08-16 14:55 - 2015-08-16 14:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2015-08-16 14:40 - 2015-08-16 14:55 - 00000000 ____D C:\Users\Filip\Documents\GTA San Andreas User Files
2015-08-16 14:32 - 2015-08-16 14:33 - 00000000 ____D C:\Program Files\Rockstar Games
2015-08-15 19:42 - 2015-08-15 19:42 - 00000000 ____D C:\Users\Filip\AppData\Roaming\GHISLER
2015-08-15 19:42 - 2015-08-15 19:42 - 00000000 ____D C:\Program Files\totalcmd
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\UC.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\RAR.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\PKZIP.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\PKUNZIP.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\LHA.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\ARJ.PIF
2015-08-15 14:58 - 2015-08-15 19:47 - 00000000 ____D C:\Users\Filip\Downloads\Zoo Tycoon Complete Collection
2015-08-15 11:38 - 2015-08-15 11:41 - 00000000 ____D C:\Users\Filip\Documents\RCT3
2015-08-15 11:38 - 2015-08-15 11:38 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Atari
2015-08-15 11:23 - 2015-08-15 11:23 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Leadertech
2015-08-15 11:23 - 2015-08-15 11:23 - 00000000 ____D C:\Program Files\Common Files\PocketSoft
2015-08-15 11:23 - 2002-02-27 18:50 - 00197120 _____ C:\Windows\patchw32.dll
2015-08-15 11:17 - 2015-08-15 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
2015-08-15 11:17 - 2015-08-15 11:17 - 00000000 ____D C:\Program Files\Atari
2015-08-15 10:04 - 2015-08-15 10:20 - 00000000 ____D C:\Users\Filip\Downloads\Rollercoaster Tycoon 3
2015-08-14 14:41 - 2015-08-19 17:16 - 00174949 _____ C:\Windows\WindowsUpdate.log
2015-08-13 15:31 - 2015-08-13 15:32 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-13 15:30 - 2015-08-13 15:30 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-08-13 15:30 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-13 15:30 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-13 15:30 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-13 13:59 - 2015-08-13 14:02 - 00000000 ____D C:\Program Files\n2n Gui
2015-08-12 20:49 - 2014-05-05 10:00 - 00000000 ____D C:\Users\Filip\Crack
2015-08-12 20:40 - 2015-08-12 20:47 - 00000000 ____D C:\Program Files\City Car Driving
2015-08-12 19:46 - 2015-08-12 19:47 - 00000000 ____D C:\ProgramData\6WinManPro6
2015-08-12 19:45 - 2015-08-12 19:45 - 00000000 _____ C:\Windows\prleth.sys
2015-08-12 19:45 - 2015-08-12 19:45 - 00000000 _____ C:\Windows\hgfs.sys
2015-08-12 19:44 - 2015-08-19 16:54 - 00000000 ____D C:\Users\Filip\AppData\Local\Ection
2015-08-12 19:44 - 2015-08-14 11:59 - 00000000 ____D C:\Users\Filip\AppData\Local\YSNPack
2015-08-12 19:44 - 2015-08-12 19:44 - 00000000 _____ C:\Users\Filip\AppData\Roaming\g78rfdsafhi
2015-08-11 17:24 - 2015-08-11 17:28 - 00000000 ____D C:\Users\Filip\Documents\Bandicam
2015-08-11 17:24 - 2015-08-11 17:24 - 00000000 ____D C:\Users\Filip\AppData\Roaming\BANDISOFT
2015-08-11 17:23 - 2015-08-11 17:23 - 00000950 _____ C:\Users\PC\Desktop\Bandicam.lnk
2015-08-11 17:23 - 2015-08-11 17:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2015-08-11 17:23 - 2015-08-11 17:23 - 00000000 ____D C:\Program Files\BandiMPEG1
2015-08-11 17:23 - 2015-08-11 17:23 - 00000000 ____D C:\Program Files\Bandicam
2015-08-11 16:02 - 1998-10-29 16:45 - 00306688 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2015-08-11 16:00 - 2015-08-16 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mafia
2015-08-10 19:07 - 2015-08-10 19:07 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2015-08-10 19:07 - 2015-08-10 19:07 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2015-08-10 19:00 - 2015-08-13 20:06 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-10 19:00 - 2015-08-10 19:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-10 18:58 - 2015-08-19 18:03 - 00000938 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-10 18:58 - 2015-08-19 16:58 - 00000934 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-10 16:31 - 2015-08-10 16:31 - 00000000 ____D C:\Users\Filip\Documents\Multisoft
2015-08-02 17:40 - 2015-08-02 17:40 - 00000000 ____D C:\Program Files\Defraggler
2015-08-02 17:37 - 2015-08-02 17:37 - 00000000 ____D C:\Program Files\CCleaner
2015-07-30 21:32 - 2015-08-02 16:38 - 00000000 _____ C:\Users\Filip\AppData\Roaming\FileOut.cns
2015-07-30 21:32 - 2015-08-02 16:38 - 00000000 _____ C:\Users\Filip\AppData\Roaming\FileIn.cns
2015-07-30 21:32 - 2015-07-30 21:32 - 00000000 _____ C:\FileOut.Cns
2015-07-30 21:32 - 2015-07-30 21:32 - 00000000 _____ C:\FileIn.Cns
2015-07-30 21:28 - 2015-08-15 19:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-07-26 23:29 - 2015-07-26 23:30 - 00000000 ____D C:\Users\Filip\AppData\Roaming\SmartSteamEmu
2015-07-24 17:18 - 2015-07-30 16:56 - 00000000 ____D C:\TRS2004 - součásti
2015-07-23 20:43 - 2015-07-23 20:43 - 00000000 ____D C:\Users\Filip\AppData\Roaming\java
2015-07-23 20:34 - 2015-08-13 14:04 - 00000000 ____D C:\Users\Filip\AppData\Roaming\.minecraft
2015-07-23 20:34 - 2015-07-23 20:34 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-07-23 20:24 - 2015-08-16 23:38 - 00000000 ____D C:\Users\Filip\AppData\Roaming\uTorrent
2015-07-23 20:23 - 2015-08-02 22:14 - 00000000 ____D C:\Program Files\Driver Checker
2015-07-23 18:57 - 2015-07-25 20:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auran
2015-07-23 18:56 - 2015-07-25 20:42 - 00000000 ____D C:\Program Files\Auran
2015-07-23 18:01 - 2015-07-23 18:52 - 1345457479 _____ C:\Users\Filip\Downloads\Trainz-Railroad-Simulator-2004-cz.rar
2015-07-22 11:01 - 2015-07-22 11:01 - 00000000 ____D C:\Users\Filip\AppData\Local\CEF
2015-07-21 01:26 - 2015-07-21 01:26 - 00000000 ____D C:\ProgramData\NovaTech Network
2015-07-21 01:12 - 2015-07-21 01:12 - 00000000 ____D C:\Program Files\ATI Technologies
2015-07-20 16:55 - 2015-08-14 12:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Akoff Music Composer Demo
2015-07-20 16:55 - 2015-07-22 22:35 - 00000000 ____D C:\Program Files\Akoff Music Composer Demo
2015-07-20 16:55 - 2015-07-20 16:55 - 00001108 _____ C:\Users\PC\Desktop\Akoff Music Composer Demo.lnk
2015-07-20 16:21 - 2015-07-20 16:21 - 00319488 _____ (Realtek Semiconductor Corp.) C:\Windows\HideWin.exe
2015-07-20 16:19 - 2015-07-20 16:19 - 00001025 _____ C:\Users\PC\Desktop\Music MasterWorks.lnk

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-19 18:41 - 2014-12-03 09:01 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Skype
2015-08-19 18:30 - 2014-12-12 20:41 - 00000000 ____D C:\ProgramData\Skype
2015-08-19 18:29 - 2014-12-03 09:01 - 00000000 ___RD C:\Program Files\Skype
2015-08-19 18:29 - 2014-12-03 09:01 - 00000000 ____D C:\Program Files\Common Files\Skype
2015-08-19 18:27 - 2014-12-01 21:17 - 00000000 ____D C:\Users\Filip
2015-08-19 18:13 - 2014-12-01 20:44 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-19 17:13 - 2009-07-14 06:34 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-19 17:13 - 2009-07-14 06:34 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-19 16:56 - 2014-12-01 21:41 - 00000000 ____D C:\ProgramData\NVIDIA
2015-08-19 16:56 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-19 16:45 - 2014-12-01 22:06 - 00000000 ____D C:\Program Files\Steam
2015-08-19 15:26 - 2015-05-31 13:27 - 00000000 ____D C:\Users\Filip\AppData\Roaming\foobar2000
2015-08-19 15:23 - 2015-07-10 15:23 - 00000354 _____ C:\Windows\Tasks\FolderBrusher.job
2015-08-19 15:23 - 2015-06-25 15:23 - 00000502 _____ C:\Windows\Tasks\ColorWheel.job
2015-08-19 14:38 - 2015-01-02 22:16 - 00000000 ____D C:\ProgramData\Temp
2015-08-19 01:23 - 2015-06-25 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-08-17 17:38 - 2015-02-15 22:19 - 00000000 ____D C:\Users\Filip\Desktop\Programy
2015-08-17 17:23 - 2014-12-14 10:50 - 00000000 ___RD C:\Users\Filip\Desktop\Filip - Plocha
2015-08-17 14:36 - 2015-06-26 17:15 - 00000000 ____D C:\Program Files\Everything
2015-08-17 14:32 - 2014-12-14 18:04 - 00000000 __SHD C:\Users\Filip\AppData\Local\EmieUserList
2015-08-17 14:32 - 2014-12-14 18:04 - 00000000 __SHD C:\Users\Filip\AppData\Local\EmieSiteList
2015-08-17 14:32 - 2014-12-14 18:04 - 00000000 __SHD C:\Users\Filip\AppData\Local\EmieBrowserModeList
2015-08-17 14:30 - 2014-11-07 09:25 - 00000000 ____D C:\Windows\Panther
2015-08-16 23:39 - 2015-01-25 17:27 - 00012234 _____ C:\Windows\system32\.crusader
2015-08-16 23:37 - 2015-01-23 00:35 - 00000000 ____D C:\Program Files\Common Files\PX Storage Engine
2015-08-16 22:04 - 2015-06-17 18:37 - 00000000 ____D C:\AdwCleaner
2015-08-16 20:24 - 2015-04-05 12:25 - 00000000 ____D C:\Users\Filip\Desktop\Hry
2015-08-16 18:46 - 2014-12-07 17:29 - 00000000 ____D C:\Users\PC\AppData\Roaming\Seznam.cz
2015-08-16 18:29 - 2014-12-03 11:04 - 00000000 ____D C:\Users\Filip\AppData\Roaming\vlc
2015-08-16 16:20 - 2014-11-27 17:30 - 00104560 _____ C:\Users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-16 16:19 - 2014-11-07 09:35 - 00001397 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-16 14:40 - 2014-12-09 00:19 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-16 13:35 - 2014-12-03 09:18 - 00000000 ____D C:\Users\Filip\AppData\Roaming\DAEMON Tools Lite
2015-08-15 19:45 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Microsoft Games
2015-08-15 11:40 - 2014-12-01 21:17 - 00000000 ____D C:\Users\Filip\AppData\Local\VirtualStore
2015-08-15 11:30 - 2014-12-04 21:52 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-08-14 20:35 - 2014-12-01 22:06 - 00000000 ____D C:\Program Files\Common Files\Steam
2015-08-14 19:42 - 2015-01-03 13:23 - 00000000 ____D C:\Users\Filip\Documents\Algodoo
2015-08-14 16:01 - 2015-06-18 16:03 - 00000000 ____D C:\Users\Filip\AppData\Local\Messenger
2015-08-14 15:28 - 2015-06-18 16:03 - 00001126 _____ C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Messenger.lnk
2015-08-13 15:29 - 2015-06-13 11:49 - 00007603 _____ C:\Users\Filip\AppData\Local\Resmon.ResmonCfg
2015-08-13 13:49 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-08-13 10:01 - 2015-05-27 14:30 - 00001397 _____ C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-12 21:39 - 2014-12-09 20:16 - 00000000 ____D C:\Users\Filip\AppData\Roaming\TS3Client
2015-08-12 21:23 - 2014-12-09 20:16 - 00000000 ____D C:\Users\Filip\AppData\Local\TeamSpeak 3 Client
2015-08-12 20:48 - 2015-05-30 16:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forward Development
2015-08-12 19:14 - 2014-12-01 20:44 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-12 19:14 - 2014-12-01 20:44 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-12 10:09 - 2014-12-09 22:28 - 00000000 ____D C:\Program Files\Samsung
2015-08-11 17:21 - 2015-05-26 18:25 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Opera Software
2015-08-11 17:21 - 2015-05-26 18:25 - 00000000 ____D C:\Users\Filip\AppData\Local\Opera Software
2015-08-10 22:53 - 2015-07-06 23:06 - 00000000 ____D C:\Users\Filip\AppData\Local\Akamai
2015-08-10 19:00 - 2014-12-01 21:18 - 00000000 ____D C:\Users\Filip\AppData\Local\Google
2015-08-10 19:00 - 2014-12-01 20:45 - 00000000 ____D C:\Program Files\Google
2015-08-10 16:06 - 2015-05-31 13:25 - 00000000 ____D C:\Program Files\foobar2000
2015-08-10 15:51 - 2015-07-10 15:55 - 00000000 ____D C:\Users\Filip\DvDrum 3
2015-08-03 18:28 - 2015-07-06 22:14 - 00000000 ____D C:\Users\Filip\AppData\Local\Spotify
2015-08-03 18:28 - 2015-07-06 22:12 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Spotify
2015-08-03 08:38 - 2015-07-06 20:21 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-07-30 21:35 - 2014-12-01 22:04 - 00104560 _____ C:\Users\Filip\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-30 21:34 - 2009-07-14 06:33 - 00361368 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-26 23:29 - 2014-12-20 15:25 - 00000000 ____D C:\Users\Filip\Documents\My Games
2015-07-23 20:24 - 2014-12-01 22:07 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2015-07-23 09:53 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2015-07-22 22:50 - 2014-12-01 22:13 - 00000000 ____D C:\ProgramData\Oracle
2015-07-22 22:47 - 2014-12-01 22:19 - 00096352 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-07-22 22:46 - 2014-12-01 22:13 - 00000000 ____D C:\Program Files\Java
2015-07-21 12:07 - 2014-11-07 14:41 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-21 01:21 - 2015-02-04 21:16 - 00000000 ____D C:\Windows\system32\directx
2015-07-21 01:20 - 2015-02-04 21:16 - 00000000 ___HD C:\Windows\msdownld.tmp
2015-07-20 16:34 - 2015-03-08 21:28 - 00000000 ____D C:\Windows\PixArt
2015-07-20 16:34 - 2009-07-14 06:52 - 00000000 ____D C:\Windows\twain_32
2015-07-20 12:45 - 2009-07-14 06:53 - 00032528 _____ C:\Windows\Tasks\SCHEDLGU.TXT

==================== Files in the root of some directories =======

2015-06-01 21:11 - 2015-06-01 21:15 - 0065617 _____ () C:\Users\Filip\AppData\Roaming\Camdata.ini
2015-06-01 21:11 - 2015-06-01 21:15 - 0000408 _____ () C:\Users\Filip\AppData\Roaming\CamLayout.ini
2015-06-01 21:11 - 2015-06-01 21:15 - 0000408 _____ () C:\Users\Filip\AppData\Roaming\CamShapes.ini
2015-06-01 21:11 - 2015-06-01 21:15 - 0004551 _____ () C:\Users\Filip\AppData\Roaming\CamStudio.cfg
2015-07-30 21:32 - 2015-08-02 16:38 - 0000000 _____ () C:\Users\Filip\AppData\Roaming\FileIn.cns
2015-07-30 21:32 - 2015-08-02 16:38 - 0000000 _____ () C:\Users\Filip\AppData\Roaming\FileOut.cns
2015-08-12 19:44 - 2015-08-12 19:44 - 0000000 _____ () C:\Users\Filip\AppData\Roaming\g78rfdsafhi
2014-12-26 22:58 - 2014-12-26 22:59 - 0000087 _____ () C:\Users\Filip\AppData\Roaming\ilovemyjob.xml
2003-04-09 05:28 - 2003-04-09 05:28 - 0233472 ____R () C:\Users\Filip\AppData\Roaming\MafiaSetup.exe
2015-06-01 21:01 - 2015-06-01 21:12 - 0000096 _____ () C:\Users\Filip\AppData\Roaming\version2.xml
2015-02-17 18:15 - 2015-02-17 18:15 - 0000000 ___SH () C:\Users\Filip\AppData\Local\LumaEmu
2015-06-13 11:49 - 2015-08-13 15:29 - 0007603 _____ () C:\Users\Filip\AppData\Local\Resmon.ResmonCfg
2015-02-12 18:55 - 2015-02-12 18:55 - 0000003 _____ () C:\Users\Filip\AppData\Local\updater.log
2015-02-12 18:55 - 2015-04-23 17:32 - 0000412 _____ () C:\Users\Filip\AppData\Local\UserProducts.xml
2014-12-04 21:56 - 2014-12-04 21:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Filip\AppData\Local\Temp\EBU8A7.exe
C:\Users\Filip\AppData\Local\Temp\Quarantine.exe
C:\Users\Filip\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Filip\AppData\Local\Temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-12 09:46

==================== End of log ============================
Přílohy
Addition.rar
(11.4 KiB) Staženo 54 x

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#5 Příspěvek od Filip.R. »

1. obsah

22:35:49.0018 0x122c TDSS rootkit removing tool 3.0.0.16 Nov 1 2013 15:53:38
22:35:53.0598 0x122c Perform update action was selected
22:35:53.0598 0x08ec Deinitialize success

2. obsah

22:36:06.0627 0x1354 TDSS rootkit removing tool 3.1.0.5 Jul 24 2015 12:29:57
22:36:08.0225 0x1354 ============================================================
22:36:08.0225 0x1354 Current date / time: 2015/08/16 22:36:08.0225
22:36:08.0225 0x1354 SystemInfo:
22:36:08.0225 0x1354
22:36:08.0225 0x1354 OS Version: 6.1.7601 ServicePack: 1.0
22:36:08.0225 0x1354 Product type: Workstation
22:36:08.0225 0x1354 ComputerName: PC-PC
22:36:08.0240 0x1354 UserName: Filip
22:36:08.0240 0x1354 Windows directory: C:\Windows
22:36:08.0240 0x1354 System windows directory: C:\Windows
22:36:08.0240 0x1354 Processor architecture: Intel x86
22:36:08.0240 0x1354 Number of processors: 1
22:36:08.0240 0x1354 Page size: 0x1000
22:36:08.0240 0x1354 Boot type: Normal boot
22:36:08.0240 0x1354 ============================================================
22:36:09.0611 0x1354 KLMD registered as C:\Windows\system32\drivers\00713623.sys
22:36:09.0946 0x1354 System UUID: {EE8A5800-D6B7-989F-4ECD-DC905B928C05}
22:36:10.0587 0x1354 Drive \Device\Harddisk1\DR1 - Size: 0x25433D6000 ( 149.05 Gb ), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:36:10.0587 0x1354 Drive \Device\Harddisk0\DR0 - Size: 0x12A1F16000 ( 74.53 Gb ), SectorSize: 0x200, Cylinders: 0x2601, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
22:36:10.0587 0x1354 ============================================================
22:36:10.0587 0x1354 \Device\Harddisk1\DR1:
22:36:10.0587 0x1354 MBR partitions:
22:36:10.0587 0x1354 \Device\Harddisk1\DR1\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x12A14BC1
22:36:10.0587 0x1354 \Device\Harddisk0\DR0:
22:36:10.0587 0x1354 MBR partitions:
22:36:10.0587 0x1354 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x2711637
22:36:10.0587 0x1354 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x27116B5, BlocksNum 0x6DF8F4B
22:36:10.0587 0x1354 ============================================================
22:36:10.0606 0x1354 C: <-> \Device\Harddisk1\DR1\Partition1
22:36:10.0637 0x1354 D: <-> \Device\Harddisk0\DR0\Partition2
22:36:10.0637 0x1354 ============================================================
22:36:10.0637 0x1354 Initialize success
22:36:10.0637 0x1354 ============================================================
22:36:11.0842 0x1338 ============================================================
22:36:11.0842 0x1338 Scan started
22:36:11.0842 0x1338 Mode: Manual;
22:36:11.0842 0x1338 ============================================================
22:36:11.0842 0x1338 KSN ping started
22:36:25.0713 0x1338 KSN ping finished: true
22:36:27.0992 0x1338 ================ Scan system memory ========================
22:36:27.0992 0x1338 System memory - ok
22:36:27.0992 0x1338 ================ Scan services =============================
22:36:28.0474 0x1338 [ 1B133875B8AA8AC48969BD3458AFE9F5, 01753BDD47F3F9BC0E0D23A069B9C56D4AE6A6B6295BC19B95AE245D25B12744 ] 1394ohci C:\Windows\system32\drivers\1394ohci.sys
22:36:28.0477 0x1338 1394ohci - ok
22:36:28.0587 0x1338 [ CEA80C80BED809AA0DA6FEBC04733349, AE69C142DC2210A4AE657C23CEA4A6E7CB32C4F4EBA039414123CAC52157509B ] ACPI C:\Windows\system32\drivers\ACPI.sys
22:36:28.0602 0x1338 ACPI - ok
22:36:28.0665 0x1338 [ 1EFBC664ABFF416D1D07DB115DCB264F, BF94D069D692140B792DBF4FD3CB0127D27C26CC5BFB6B0C28A8B6346767EE58 ] AcpiPmi C:\Windows\system32\drivers\acpipmi.sys
22:36:28.0665 0x1338 AcpiPmi - ok
22:36:28.0827 0x1338 [ FC5B75CA6A1DA31EDD4F8D53F5540B98, CDC445F2790ADFC4C5568C40D4DA8BB95CD71991665B38AEC3D84571C99C3520 ] AdobeARMservice C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
22:36:28.0827 0x1338 AdobeARMservice - ok
22:36:28.0945 0x1338 [ BBF37D81780EBB4919636CF7E5C789BE, AB866B25B0388D9F1CD79B7BDD85B2BDBF152DFFFAC91743CCC52AC00054ED6D ] AdobeFlashPlayerUpdateSvc C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
22:36:28.0960 0x1338 AdobeFlashPlayerUpdateSvc - ok
22:36:29.0023 0x1338 [ 21E785EBD7DC90A06391141AAC7892FB, A2D3D764C5E6DC0AD5AAF48485FFB8B121D2A40DC08ECF2D2CB92278A1002B25 ] adp94xx C:\Windows\system32\DRIVERS\adp94xx.sys
22:36:29.0069 0x1338 adp94xx - ok
22:36:29.0101 0x1338 [ 0C676BC278D5B59FF5ABD57BBE9123F2, 339E8A433D186BAAB6FCB44C82CC9FB6FCD63C87981449494CBEB2072CB6B7BB ] adpahci C:\Windows\system32\DRIVERS\adpahci.sys
22:36:29.0116 0x1338 adpahci - ok
22:36:29.0132 0x1338 [ 7C7B5EE4B7B822EC85321FE23A27DB33, A934AFB71D439555E6376DA9B34F82E8D39A300A4547BE9AC9311F6A3C36270C ] adpu320 C:\Windows\system32\DRIVERS\adpu320.sys
22:36:29.0147 0x1338 adpu320 - ok
22:36:29.0210 0x1338 [ 12E6A172D72AFC626727B8635DD17E39, 33B3D109C39DF6EA86AFC3C89A93657906E981D3D22FF854401BC7326990CC08 ] AeLookupSvc C:\Windows\System32\aelupsvc.dll
22:36:29.0210 0x1338 AeLookupSvc - ok
22:36:29.0272 0x1338 [ D0B388DA1D111A34366E04EB4A5DD156, 60D226F027F4025CC032CAFF73A80FAFB5FA75445654FDCF80CA8C0419C6E938 ] AFD C:\Windows\system32\drivers\afd.sys
22:36:29.0288 0x1338 AFD - ok
22:36:29.0335 0x1338 [ 507812C3054C21CEF746B6EE3D04DD6E, D7E59350AC338AD229E3D10C76E32AE16D120311B263714A9CD94AB538633B0E ] agp440 C:\Windows\system32\drivers\agp440.sys
22:36:29.0335 0x1338 agp440 - ok
22:36:29.0381 0x1338 [ 8B30250D573A8F6B4BD23195160D8707, 64EC289AFCD63D84EAFD9D81C50D0A77BCC79A1EFF32C50B2776BB0C0151757D ] aic78xx C:\Windows\system32\DRIVERS\djsvs.sys
22:36:29.0381 0x1338 aic78xx - ok
22:36:29.0428 0x1338 [ 18A54E132947CD98FEA9ACCC57F98F13, 9D39AF972785E49F0DD12C4BAEF39A79CD69F098886BF152AF1B7CCE2E902115 ] ALG C:\Windows\System32\alg.exe
22:36:29.0428 0x1338 ALG - ok
22:36:29.0475 0x1338 [ 0D40BCF52EA90FC7DF2AEAB6503DEA44, 1D1AA8F50935D976C29DE7A84708CADBBBDD936F0DD2C059E820F0D21367B3B6 ] aliide C:\Windows\system32\drivers\aliide.sys
22:36:29.0475 0x1338 aliide - ok
22:36:29.0584 0x1338 AMD FUEL Service - ok
22:36:29.0631 0x1338 [ 3C6600A0696E90A463771C7422E23AB5, 370B33DC1C25B981628A318BAE434A78A5F0A0DA93C2896DC7A3D7B87AE1A5E7 ] amdagp C:\Windows\system32\drivers\amdagp.sys
22:36:29.0631 0x1338 amdagp - ok
22:36:29.0693 0x1338 [ 7AA286C7F10916DB23734AF066EEC65D, 04A2A386C1CF6B21428EC198D5C330135B2DD030DBBC04F4581B4A5389F81AD4 ] amdide C:\Windows\system32\DRIVERS\amdide.sys
22:36:29.0693 0x1338 amdide - ok
22:36:29.0740 0x1338 [ 00DDA200D71BAC534BF56A9DB5DFD666, CA316B1FFD85BA1CF8664B3229DA1F238A5341E016059F7ED89702324CFD124B ] AmdK8 C:\Windows\system32\DRIVERS\amdk8.sys
22:36:29.0740 0x1338 AmdK8 - ok
22:36:29.0756 0x1338 [ 3CBF30F5370FDA40DD3E87DF38EA53B6, 7EACF1743367BE805357B6FD10F8F99E9B1C301FE3782D77719347B13DFA65EC ] AmdPPM C:\Windows\system32\DRIVERS\amdppm.sys
22:36:29.0756 0x1338 AmdPPM - ok
22:36:29.0823 0x1338 [ D320BF87125326F996D4904FE24300FC, F767D8C5C58D57202905D829F7AE1B1FF33937F407FDCE4C90E32A6638F27416 ] amdsata C:\Windows\system32\drivers\amdsata.sys
22:36:29.0823 0x1338 amdsata - ok
22:36:29.0875 0x1338 [ EA43AF0C423FF267355F74E7A53BDABA, 3F1335909AB0281A2FBDD7AD90E18309E091656CD32B48894B992789D8C61DB4 ] amdsbs C:\Windows\system32\DRIVERS\amdsbs.sys
22:36:29.0875 0x1338 amdsbs - ok
22:36:29.0891 0x1338 [ 46387FB17B086D16DEA267D5BE23A2F2, 8B8AC61B91F154B4EB5CC6DECB5FCCEBA8B42EFE94859947136AD06681EA8ED0 ] amdxata C:\Windows\system32\drivers\amdxata.sys
22:36:29.0891 0x1338 amdxata - ok
22:36:29.0969 0x1338 [ 81F97D8F8B3FB94A451CC6F7CF8B2965, 8DEBA4E47E1016D69740C0BB7CDD23852D86E0D42C1C1EA5A847ECB115C38CB1 ] AppID C:\Windows\system32\drivers\appid.sys
22:36:29.0969 0x1338 AppID - ok
22:36:30.0016 0x1338 [ F5090F8FA6757C58E17BAEAA86093636, 5E14CF3032DF5801240F45C59AA93962EA41AA5648A0C6458D16D9B9D95A131F ] AppIDSvc C:\Windows\System32\appidsvc.dll
22:36:30.0065 0x1338 AppIDSvc - ok
22:36:30.0118 0x1338 [ EACFDF31921F51C097629F1F3C9129B4, 24138755D823E69760579ECBD672421192457CDC9941B2BC499C2D34D83E86C3 ] Appinfo C:\Windows\System32\appinfo.dll
22:36:30.0133 0x1338 Appinfo - ok
22:36:30.0180 0x1338 [ 2932004F49677BD84DBC72EDB754FFB3, 73F84582244AC53994A2F4499A119B4A84A6BF7FD3046C29A8080C763DE540B8 ] arc C:\Windows\system32\DRIVERS\arc.sys
22:36:30.0180 0x1338 arc - ok
22:36:30.0211 0x1338 [ 5D6F36C46FD283AE1B57BD2E9FEB0BC7, F7C9C3B4F2C816F57A43B2921672858C291054220BADE291044343778216F6BA ] arcsas C:\Windows\system32\DRIVERS\arcsas.sys
22:36:30.0227 0x1338 arcsas - ok
22:36:30.0433 0x1338 [ 537B2948976F5D9B5767B74A63EBB395, 1A14F8B582E74AD15B612EDA5B707AA3CB0B2A107ED14572B4232EAA7383B634 ] aspnet_state C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
22:36:30.0436 0x1338 aspnet_state - ok
22:36:30.0487 0x1338 [ ADD2ADE1C2B285AB8378D2DAAF991481, 7965A705F37924C0EC7A934E64E89C5DF4069816E2EEA3509E0AC90F78910519 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys
22:36:30.0489 0x1338 AsyncMac - ok
22:36:30.0540 0x1338 [ 338C86357871C167A96AB976519BF59E, F28CC534523D1701B0552F5D7E18E88369C4218BDB1F69110C3E31D395884AD6 ] atapi C:\Windows\system32\drivers\atapi.sys
22:36:30.0540 0x1338 atapi - ok
22:36:30.0613 0x1338 [ B73C832088DD54B55E04FF6F9646AD8C, 52A9F9240FAFB2F50E48579F02221CC0D6872F834104F91EF63ADC6AA82A2CD0 ] AtiPcie C:\Windows\system32\DRIVERS\AtiPcie.sys
22:36:30.0615 0x1338 AtiPcie - ok
22:36:30.0699 0x1338 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll
22:36:30.0723 0x1338 AudioEndpointBuilder - ok
22:36:30.0768 0x1338 [ C1619A13B10CAC5038BF7129F57D8DE3, 9F71EA6C844650658938E68CCC1383F92D37C68E46E08461A8351491185BA791 ] Audiosrv C:\Windows\System32\Audiosrv.dll
22:36:30.0789 0x1338 Audiosrv - ok
22:36:30.0861 0x1338 [ 6E30D02AAC9CAC84F421622E3A2F6178, 229DC527C1D6C778BCA2C855A2A6F6D2C4B0F4F6DE56C886B3AAD26E3347952C ] AxInstSV C:\Windows\System32\AxInstSV.dll
22:36:30.0865 0x1338 AxInstSV - ok
22:36:30.0905 0x1338 [ 1A231ABEC60FD316EC54C66715543CEC, 09E2897BA80737997A286EA5408C03DD3CC0EBACD24CB391C2455B6D4BE7D67E ] b06bdrv C:\Windows\system32\DRIVERS\bxvbdx.sys
22:36:30.0921 0x1338 b06bdrv - ok
22:36:30.0964 0x1338 [ BD8869EB9CDE6BBE4508D869929869EE, F4363A12EBFDBB89C69FD59B22F9EE05BADA07D477A1DF2DE01F59D6EE496543 ] b57nd60x C:\Windows\system32\DRIVERS\b57nd60x.sys
22:36:30.0964 0x1338 b57nd60x - ok
22:36:31.0011 0x1338 [ EE1E9C3BB8228AE423DD38DB69128E71, ED54FD9795F3A4D32F02BED6052AD9404409A05644CDBEBFF19C662D104DA95A ] BDESVC C:\Windows\System32\bdesvc.dll
22:36:31.0011 0x1338 BDESVC - ok
22:36:31.0057 0x1338 [ 505506526A9D467307B3C393DEDAF858, 8AD6F1492E357F57CF42261497BA29122045D4FC0DCC9669AA5AC9B2A4BABFA4 ] Beep C:\Windows\system32\drivers\Beep.sys
22:36:31.0057 0x1338 Beep - ok
22:36:31.0136 0x1338 [ 1E2BAC209D184BB851E1A187D8A29136, 53933C938DA5126986FFF2918C1F522ABE93ABAB460AE32E4453161C2F7B68DF ] BFE C:\Windows\System32\bfe.dll
22:36:31.0167 0x1338 BFE - ok
22:36:31.0269 0x1338 [ E585445D5021971FAE10393F0F1C3961, 178C008A9A0A6BFDA65EB0B98C510271360AD4474F22F13594F5EB60AA4E1CF5 ] BITS C:\Windows\System32\qmgr.dll
22:36:31.0318 0x1338 BITS - ok
22:36:31.0350 0x1338 [ 2287078ED48FCFC477B05B20CF38F36F, 55BCA6174E6034A8D61CBE4126B2F1989F6052BFA624BEA9C0A0A664AEC74521 ] blbdrive C:\Windows\system32\DRIVERS\blbdrive.sys
22:36:31.0350 0x1338 blbdrive - ok
22:36:31.0396 0x1338 [ 8F2DA3028D5FCBD1A060A3DE64CD6506, E234672E9CFE1A95AD2E78E306E41E010B870221E6EBBC0E2B0BE2FA5CE0CD76 ] bowser C:\Windows\system32\DRIVERS\bowser.sys
22:36:31.0396 0x1338 bowser - ok
22:36:31.0428 0x1338 [ 9F9ACC7F7CCDE8A15C282D3F88B43309, A9131334BD9CF8FD60BA9D54AA054E2DF2BE1219FB650DF1464F2787BDEAE98F ] BrFiltLo C:\Windows\system32\DRIVERS\BrFiltLo.sys
22:36:31.0428 0x1338 BrFiltLo - ok
22:36:31.0443 0x1338 [ 56801AD62213A41F6497F96DEE83755A, 0DEB8318FB47DF6473C171C795C735E26A73FA12232876C6856549EA16F33361 ] BrFiltUp C:\Windows\system32\DRIVERS\BrFiltUp.sys
22:36:31.0443 0x1338 BrFiltUp - ok
22:36:31.0506 0x1338 [ 3DAA727B5B0A45039B0E1C9A211B8400, 903B51E75F0C503A0E255120F53BF51B047B219FEC1E15F2F1D02DDD562FC73B ] Browser C:\Windows\System32\browser.dll
22:36:31.0506 0x1338 Browser - ok
22:36:31.0537 0x1338 [ 845B8CE732E67F3B4133164868C666EA, 9309B094CD9B5EBC46295A5EB806BED472C3CEDE3B5F6F497EBDABA496A2A27F ] Brserid C:\Windows\System32\Drivers\Brserid.sys
22:36:31.0552 0x1338 Brserid - ok
22:36:31.0568 0x1338 [ 203F0B1E73ADADBBB7B7B1FABD901F6B, 782FA7B26940FE479C49C9BAA2EB582CDAAAD607013E9BCFC85E6FBBB7D49A6D ] BrSerWdm C:\Windows\System32\Drivers\BrSerWdm.sys
22:36:31.0568 0x1338 BrSerWdm - ok
22:36:31.0584 0x1338 [ BD456606156BA17E60A04E18016AE54B, DFBDC9DA6A3EA40BACFF204BC6C55C2C122B5885D2CBF6D45054DE43EE15EC4D ] BrUsbMdm C:\Windows\System32\Drivers\BrUsbMdm.sys
22:36:31.0599 0x1338 BrUsbMdm - ok
22:36:31.0615 0x1338 [ AF72ED54503F717A43268B3CC5FAEC2E, 4A638669B0C30B1BDED242A8BF2015A37749570FF4D67D190BACC8D7E0C44468 ] BrUsbSer C:\Windows\System32\Drivers\BrUsbSer.sys
22:36:31.0615 0x1338 BrUsbSer - ok
22:36:31.0646 0x1338 [ ED3DF7C56CE0084EB2034432FC56565A, B5B75E002E7BC0209582C635CCCA26DB569BDB23C33A126634E00C6434BF941B ] BTHMODEM C:\Windows\system32\DRIVERS\bthmodem.sys
22:36:31.0646 0x1338 BTHMODEM - ok
22:36:31.0708 0x1338 [ 1DF19C96EEF6C29D1C3E1A8678E07190, 1F4BB161FF3A1C5B1465BB52F3520FEDB7ACB1FAA132466F07D16DB8E394AEA5 ] bthserv C:\Windows\system32\bthserv.dll
22:36:31.0708 0x1338 bthserv - ok
22:36:31.0740 0x1338 [ 77EA11B065E0A8AB902D78145CA51E10, 160EB3BBE9E5F3CC4A02584E6F2576A812C7565B940D74838B983F1EE51FA73A ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys
22:36:31.0740 0x1338 cdfs - ok
22:36:31.0818 0x1338 [ BE167ED0FDB9C1FA1133953C18D5A6C9, E26A851CA13E7300F977E5B20FA5D25FD0E1442AB6AD5DB58BBDB2DAAD87027C ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys
22:36:31.0833 0x1338 cdrom - ok
22:36:31.0911 0x1338 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] CertPropSvc C:\Windows\System32\certprop.dll
22:36:31.0927 0x1338 CertPropSvc - ok
22:36:32.0083 0x1338 [ A2555605CD54DE880BDB6994B69DB617, D6827611C6AAA736DD5A1EC22D14A0E07BA33B59DE583DF1C3ACA00497FF6C6E ] chromoting C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
22:36:32.0098 0x1338 chromoting - ok
22:36:32.0130 0x1338 [ 3FE3FE94A34DF6FB06E6418D0F6A0060, 6B3A2A26609A75B690D4C0B3059E40822F3B3DB08943F58EC496BABDA7D0A735 ] circlass C:\Windows\system32\DRIVERS\circlass.sys
22:36:32.0130 0x1338 circlass - ok
22:36:32.0192 0x1338 [ 33A60554882FDF59CDA3E1806370BBA1, 3DE5451E1CB84AAEBD03F54BEFC670C401447B4881A8B022748B6ECF0F500F01 ] CLFS C:\Windows\system32\CLFS.sys
22:36:32.0208 0x1338 CLFS - ok
22:36:32.0293 0x1338 [ F13EC8A783E0CB0D6DC26A3CA848B7B8, 0809E3B71709F1343086EEB6C820543C1A7119E74EEF8AC1AEE1F81093ABEC66 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
22:36:32.0296 0x1338 clr_optimization_v2.0.50727_32 - ok
22:36:32.0386 0x1338 [ F5AB4D2E36625F355E81539239765107, 48E6AD65EEFD6C54F938F5753EF58377CDA77ADBB41CD8635F0040D61EFB92A4 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
22:36:32.0392 0x1338 clr_optimization_v4.0.30319_32 - ok
22:36:32.0421 0x1338 [ DEA805815E587DAD1DD2C502220B5616, 2D6A7668C95352B818F5EC59FF462894935833D34190257DA9CAC7E67FD3631C ] CmBatt C:\Windows\system32\DRIVERS\CmBatt.sys
22:36:32.0435 0x1338 CmBatt - ok
22:36:32.0457 0x1338 [ C537B1DB64D495B9B4717B4D6D9EDBF2, 400EEFE662DE117C9CC956E4CBD5E98F28F962E7447CD93E8A78FDD8CA39EB4B ] cmdide C:\Windows\system32\drivers\cmdide.sys
22:36:32.0458 0x1338 cmdide - ok
22:36:32.0520 0x1338 [ 3051724F223EA48968B19567DE2A81F4, DCC27DE1B2B35866FC6DBDE95A368E7D0D346B6C3F31D0BACA63DD39B0A8874E ] CNG C:\Windows\system32\Drivers\cng.sys
22:36:32.0536 0x1338 CNG - ok
22:36:32.0572 0x1338 [ A6023D3823C37043986713F118A89BEE, FAC239A7FA6251C7EDFFA34B4BAE3910B8BC0BD4A3574B6DB6931A8D691E207B ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys
22:36:32.0574 0x1338 Compbatt - ok
22:36:32.0601 0x1338 [ CBE8C58A8579CFE5FCCF809E6F114E89, AC083A1C649EBA18C59FCC1772D0784B10E2B8C63094E3C14388E147DBC3F6DF ] CompositeBus C:\Windows\system32\drivers\CompositeBus.sys
22:36:32.0603 0x1338 CompositeBus - ok
22:36:32.0623 0x1338 COMSysApp - ok
22:36:32.0776 0x1338 [ 2C4EBCFC84A9B44F209DFF6C6E6C61D1, 6FC323217D82EF661BA0E3F949B61B05BB5235D1A69C81D24876C2153FAECEF6 ] crcdisk C:\Windows\system32\DRIVERS\crcdisk.sys
22:36:32.0785 0x1338 crcdisk - ok
22:36:32.0899 0x1338 [ 49474B3E37969AF4B5C076F42B623AFF, BDA6B57E9B60EF1B67C74099263D33A367AAA035667239F76AB8B268FD3E8F23 ] CryptSvc C:\Windows\system32\cryptsvc.dll
22:36:32.0916 0x1338 CryptSvc - ok
22:36:33.0049 0x1338 [ FCE8506D1C61F05319E85C70638ABD21, 6FAA70CDBB5A374B49308AAF3C0E17ECFE870F8EC77C01BF4545A531F2A5C3D1 ] CX23880 C:\Windows\system32\drivers\cx88vid.sys
22:36:33.0065 0x1338 CX23880 - ok
22:36:33.0118 0x1338 [ 30EC2A93FE6D26D05BAF0635B0B1ACA5, 40738EF20A5D7E69207B5F56FEDE7D924E5AA494F66B1C1D07A8832A79A0C668 ] CXTUNE C:\Windows\system32\drivers\CX88TUNE_IBV32.sys
22:36:33.0121 0x1338 CXTUNE - ok
22:36:33.0214 0x1338 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] DcomLaunch C:\Windows\system32\rpcss.dll
22:36:33.0230 0x1338 DcomLaunch - ok
22:36:33.0286 0x1338 [ 8D6E10A2D9A5EED59562D9B82CF804E1, 888F9650F4E872BA8F4E0C27E38A6672A561042B17EBA40E306A22357965B0AD ] defragsvc C:\Windows\System32\defragsvc.dll
22:36:33.0303 0x1338 defragsvc - ok
22:36:33.0359 0x1338 [ F024449C97EC1E464AAFFDA18593DB88, 7EF1E241892E098A472BCA14C724DFF1AACCF190954AF1C4A38B6D542CC74BD2 ] DfsC C:\Windows\system32\Drivers\dfsc.sys
22:36:33.0359 0x1338 DfsC - ok
22:36:33.0390 0x1338 [ E9E01EB683C132F7FA27CD607B8A2B63, 4D9037B458C522874619143A4176BCED42472C68933E6E83D37B67242706F3C4 ] Dhcp C:\Windows\system32\dhcpcore.dll
22:36:33.0407 0x1338 Dhcp - ok
22:36:33.0438 0x1338 [ 1A050B0274BFB3890703D490F330C0DA, 79D74F4679A2EE040FAAF4D0392A9311239A10A5F8A5CCB48656C6F89B6D62FB ] discache C:\Windows\system32\drivers\discache.sys
22:36:33.0438 0x1338 discache - ok
22:36:33.0475 0x1338 [ 565003F326F99802E68CA78F2A68E9FF, ABC42B24DBA4FFC411120E09278EF26AF56CCAB463B69B4BD6C530B4A07063D2 ] Disk C:\Windows\system32\DRIVERS\disk.sys
22:36:33.0479 0x1338 Disk - ok
22:36:33.0538 0x1338 [ 33EF4861F19A0736B11314AAD9AE28D0, 4C4B84365D85758E3263B88F157D8B086B392C6F1EA5F0F3DB6BF87EF90248EC ] Dnscache C:\Windows\System32\dnsrslvr.dll
22:36:33.0543 0x1338 Dnscache - ok
22:36:33.0593 0x1338 [ 366BA8FB4B7BB7435E3B9EACB3843F67, 65B7C61ACF34F1F0149045AA9E09A3F917A927963237A385A914D0B80551DC31 ] dot3svc C:\Windows\System32\dot3svc.dll
22:36:33.0601 0x1338 dot3svc - ok
22:36:33.0656 0x1338 [ 8EC04CA86F1D68DA9E11952EB85973D6, 2E3FBC2D683D1274E8BC45EEEA87D43B77EDDCAAF0D453296D9FDA6B9D717071 ] DPS C:\Windows\system32\dps.dll
22:36:33.0672 0x1338 DPS - ok
22:36:33.0730 0x1338 [ B918E7C5F9BF77202F89E1A9539F2EB4, C589A37DE50BBEF22E2DAA9682EA43147F614AA1AF7DAAA942BA5FC192313A0B ] drmkaud C:\Windows\system32\drivers\drmkaud.sys
22:36:33.0731 0x1338 drmkaud - ok
22:36:33.0802 0x1338 [ 00C161B3D20AE0F9C7C3C0EB53AB7155, 38FE83B482FA580B292F7DFC8B372C78AECD6FF53EC41EB7BF4A2461827CDD64 ] dtsoftbus01 C:\Windows\system32\DRIVERS\dtsoftbus01.sys
22:36:33.0811 0x1338 dtsoftbus01 - ok
22:36:33.0885 0x1338 [ 3583A5A8CC2E682BFFBD4630D0FEC08B, FD0F184B358FCECAA763444B414074BEF4E871EB7527D88385519FC158435C72 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys
22:36:33.0920 0x1338 DXGKrnl - ok
22:36:34.0023 0x1338 [ 8600142FA91C1B96367D3300AD0F3F3A, 5713625E27DF11FAAFDA7AC79899A6AD813166E167088FA990EC5DE87DBE83DF ] EapHost C:\Windows\System32\eapsvc.dll
22:36:34.0046 0x1338 EapHost - ok
22:36:34.0235 0x1338 eapihdrv - ok
22:36:34.0411 0x1338 [ 024E1B5CAC09731E4D868E64DBFB4AB0, AB0826A74BBEE5B7A1B035861B665C79BC98305CFC7D82BEF420558FBD3EE994 ] ebdrv C:\Windows\system32\DRIVERS\evbdx.sys
22:36:34.0556 0x1338 ebdrv - ok
22:36:34.0602 0x1338 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] EFS C:\Windows\System32\lsass.exe
22:36:34.0602 0x1338 EFS - ok
22:36:34.0696 0x1338 [ A8C362018EFC87BEB013EE28F29C0863, 07971C681FBD391C0BA0172618AF8AD77520182207F1C57F134B34D6A113857F ] ehRecvr C:\Windows\ehome\ehRecvr.exe
22:36:34.0727 0x1338 ehRecvr - ok
22:36:34.0758 0x1338 [ D389BFF34F80CAEDE417BF9D1507996A, 12859B9925D7A4631DE61A820922F43F56ED23C2AF014CBF36322685E5CF641E ] ehSched C:\Windows\ehome\ehsched.exe
22:36:34.0758 0x1338 ehSched - ok
22:36:34.0850 0x1338 [ 0ED67910C8C326796FAA00B2BF6D9D3C, 97FAA7627A162B0AEC15545E0165D13355D535B4157604BB87F8EEB72ECD24A8 ] elxstor C:\Windows\system32\DRIVERS\elxstor.sys
22:36:34.0876 0x1338 elxstor - ok
22:36:34.0928 0x1338 [ 8FC3208352DD3912C94367A206AB3F11, 69B65C12BDADD4B730508674B1B77C5496612B4ACCC447DB9AFE49ADEA8CBF02 ] ErrDev C:\Windows\system32\drivers\errdev.sys
22:36:34.0929 0x1338 ErrDev - ok
22:36:35.0011 0x1338 [ F6916EFC29D9953D5D0DF06882AE8E16, ED41893960018D5EC2F7829B1DE4B6967D9FD074D60B11B9EB854E3E0948EC24 ] EventSystem C:\Windows\system32\es.dll
22:36:35.0033 0x1338 EventSystem - ok
22:36:35.0057 0x1338 [ 2DC9108D74081149CC8B651D3A26207F, 75CB47923A867DDAC512701CE71DFCFC340FC3A2E27F4255D0836A1FBC463176 ] exfat C:\Windows\system32\drivers\exfat.sys
22:36:35.0057 0x1338 exfat - ok
22:36:35.0088 0x1338 [ 7E0AB74553476622FB6AE36F73D97D35, 41463A255FDA1D550B3385EC7C73ABC343B1BBBE9CEE4DF9F2A8B3E7338C4947 ] fastfat C:\Windows\system32\drivers\fastfat.sys
22:36:35.0104 0x1338 fastfat - ok
22:36:35.0187 0x1338 [ 967EA5B213E9984CBE270205DF37755B, 43153E23210B03FAE16897D62D55B8742F834EDC695F8401EAB5DE307F62602D ] Fax C:\Windows\system32\fxssvc.exe
22:36:35.0211 0x1338 Fax - ok
22:36:35.0235 0x1338 [ E817A017F82DF2A1F8CFDBDA29388B29, 4CC9320A21E6FEA2D16C48D6BEA14391B695BD541A3C5FDDAEEE086A414FC837 ] fdc C:\Windows\system32\DRIVERS\fdc.sys
22:36:35.0236 0x1338 fdc - ok
22:36:35.0260 0x1338 [ F3222C893BD2F5821A0179E5C71E88FB, A85B947249DBB986358CCD4B158DD58A9301F074F3C6CCCDEF2D01F432E59D1B ] fdPHost C:\Windows\system32\fdPHost.dll
22:36:35.0260 0x1338 fdPHost - ok
22:36:35.0276 0x1338 [ 7DBE8CBFE79EFBDEB98C9FB08D3A9A5B, 0E76C29D2A974A3F2FBFCB63D066D4136B78E02F6B1F579B1865CA7A76193987 ] FDResPub C:\Windows\system32\fdrespub.dll
22:36:35.0276 0x1338 FDResPub - ok
22:36:35.0307 0x1338 [ 6CF00369C97F3CF563BE99BE983D13D8, F65F35324A2FB9DFB533B1C4D089D990CC242218FE83414329D07B786D8EFF33 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys
22:36:35.0307 0x1338 FileInfo - ok
22:36:35.0323 0x1338 [ 42C51DC94C91DA21CB9196EB64C45DB9, 388C68D12ECC8FFE3116FEAAF4DB7B80CF4A3F97E935788DD21C6ADE2369F635 ] Filetrace C:\Windows\system32\drivers\filetrace.sys
22:36:35.0323 0x1338 Filetrace - ok
22:36:35.0354 0x1338 [ 87907AA70CB3C56600F1C2FB8841579B, CA1CD82A1CD453617CE5EA431A1836997F14E3580554E8A516D9FE1E9926D979 ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys
22:36:35.0354 0x1338 flpydisk - ok
22:36:35.0385 0x1338 [ 7520EC808E0C35E0EE6F841294316653, 6EC65511B4838A7172A8F89E35C2F9DF4F0BFCE3BE12EDA790F3EB567102FF67 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys
22:36:35.0385 0x1338 FltMgr - ok
22:36:35.0497 0x1338 [ C3FE7DBDEE220251595AB81A13080B5B, 9DCFA8C0BEEBF284AB66235D2458A726168C2ACF8F77D95100EE826ED9710B11 ] FolderSize C:\Program Files\FolderSize\FolderSizeSvc.exe
22:36:35.0513 0x1338 FolderSize - ok
22:36:35.0650 0x1338 [ E12C4928B32ACE04610259647F072635, B71B9C2DF45F33C4DAC88435129B08B0BCDBBE82E8C3AD0A95F00137CC8B619F ] FontCache C:\Windows\system32\FntCache.dll
22:36:35.0695 0x1338 FontCache - ok
22:36:35.0747 0x1338 [ E56F39F6B7FDA0AC77A79B0FD3DE1A2F, DBED26852B99B362152DA9CD4F31A1883EF6F9B496F3CF3772A197BA72DB61DA ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
22:36:35.0749 0x1338 FontCache3.0.0.0 - ok
22:36:35.0770 0x1338 [ 1A16B57943853E598CFF37FE2B8CBF1D, 87609F46F3B8123552141FD70866E895220B1BBD92BC2B580CAF49201AA0197E ] FsDepends C:\Windows\system32\drivers\FsDepends.sys
22:36:35.0772 0x1338 FsDepends - ok
22:36:35.0823 0x1338 [ 7DAE5EBCC80E45D3253F4923DC424D05, 8A2C4D5591509B0B0A44583520617A9AE34F32BB6E68A012A7D7870ED24F703A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys
22:36:35.0824 0x1338 Fs_Rec - ok
22:36:35.0891 0x1338 [ E306A24D9694C724FA2491278BF50FDB, 1D246B9C28550640EACBF8CF9DC980FD75106B92832D392FEBEF0C7012353091 ] fvevol C:\Windows\system32\DRIVERS\fvevol.sys
22:36:35.0900 0x1338 fvevol - ok
22:36:35.0938 0x1338 [ 65EE0C7A58B65E74AE05637418153938, 0E1A398ADD8411AF4CCC3344D67BE1B261320C58328BD5C5855A357476FAEBEF ] gagp30kx C:\Windows\system32\DRIVERS\gagp30kx.sys
22:36:35.0941 0x1338 gagp30kx - ok
22:36:36.0124 0x1338 [ 2360D72739721F76A1CF245CDAE4EF2B, 03BB7DD3DF6FF22941F15BAA6ED4B34518C21232D616FC36EFA448D2B7357D65 ] GalaxyClientService C:\Program Files\GalaxyClient\GalaxyClientService.exe
22:36:36.0202 0x1338 GalaxyClientService - ok
22:36:36.0639 0x1338 [ A785687C7457771995289627493EF93C, 9944FD135E46E990B95B2C040BC1A0003C58437D16247E2A788F4F8BDDF5B400 ] GalaxyCommunication C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
22:36:36.0904 0x1338 GalaxyCommunication - ok
22:36:36.0982 0x1338 [ E897EAF5ED6BA41E081060C9B447A673, A428DC68516F19C6C53A8B62E4BDB2587E70FB751B9D77700B6B147D347DA157 ] gpsvc C:\Windows\System32\gpsvc.dll
22:36:36.0998 0x1338 gpsvc - ok
22:36:37.0155 0x1338 [ C6FF00DA1605982E616C03BE809FFE2D, 4D9C86B9FF2FA291DC320677D28DF00C26834409F7AD94D6C07D2233ED746B19 ] gupdate C:\Program Files\Google\Update\GoogleUpdate.exe
22:36:37.0170 0x1338 gupdate - ok
22:36:37.0233 0x1338 [ C6FF00DA1605982E616C03BE809FFE2D, 4D9C86B9FF2FA291DC320677D28DF00C26834409F7AD94D6C07D2233ED746B19 ] gupdatem C:\Program Files\Google\Update\GoogleUpdate.exe
22:36:37.0233 0x1338 gupdatem - ok
22:36:37.0298 0x1338 [ 833051C6C6C42117191935F734CFBD97, 5EB5672ABC7994A4AFF855A572158B8BE4FC6E541CFD4B9BE4FF2739A9A6AFB8 ] hamachi C:\Windows\system32\DRIVERS\hamachi.sys
22:36:37.0300 0x1338 hamachi - ok
22:36:37.0334 0x1338 [ C44E3C2BAB6837DB337DDEE7544736DB, 88A24FF7D2FECCEAFFD421B2039A0FB623DA47A6B220B80EF1E52DD26D9E222D ] hcw85cir C:\Windows\system32\drivers\hcw85cir.sys
22:36:37.0335 0x1338 hcw85cir - ok
22:36:37.0461 0x1338 [ A5EF29D5315111C80A5C1ABAD14C8972, A181DA72E946F121C3F4A19438C547B0BFD15138AB1DB5465945EC89DF1F6B0A ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys
22:36:37.0492 0x1338 HdAudAddService - ok
22:36:37.0529 0x1338 [ 9036377B8A6C15DC2EEC53E489D159B5, 1E56D2ACFE92E6DF96D755B05C63D580EED82C210F075C8623E138BEE6BCD41B ] HDAudBus C:\Windows\system32\drivers\HDAudBus.sys
22:36:37.0546 0x1338 HDAudBus - ok
22:36:37.0598 0x1338 [ 1D58A7F3E11A9731D0EAAAA8405ACC36, 7056FA18B86FBD52C4A6092D80476C02553EA053D6A0BEDB01A2FA5E152D5215 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys
22:36:37.0600 0x1338 HidBatt - ok
22:36:37.0639 0x1338 [ 89448F40E6DF260C206A193A4683BA78, 71E0FCC32AE6FF8DFF420DB0383D6A200E1EAE14BD2E32453F92CE18B31C1F3C ] HidBth C:\Windows\system32\DRIVERS\hidbth.sys
22:36:37.0643 0x1338 HidBth - ok
22:36:37.0668 0x1338 [ CF50B4CF4A4F229B9F3C08351F99CA5E, B97843620AF80FF0EC8F2C438255C0A42A756C6314FAF3DEF415DE16E14C108F ] HidIr C:\Windows\system32\DRIVERS\hidir.sys
22:36:37.0670 0x1338 HidIr - ok
22:36:37.0704 0x1338 [ 2BC6F6A1992B3A77F5F41432CA6B3B6B, 2AF3312F1C8C8923C0A29AA5DAE57CE269417E53DEA2F0CCCC8DB57029698FE1 ] hidserv C:\Windows\system32\hidserv.dll
22:36:37.0707 0x1338 hidserv - ok
22:36:37.0800 0x1338 [ 10C19F8290891AF023EAEC0832E1EB4D, E208553029488A6EE2F5216CC9FE5F93E9931A94C0D0625253BB159E30642853 ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys
22:36:37.0800 0x1338 HidUsb - ok
22:36:37.0879 0x1338 [ 6DDF381740D33DCF8EF0A62029EBDCFA, CA44C880951D629CB0A648D67925FF8EC51889055D3776FC7D4C0D64404607FB ] hitmanpro37 C:\Windows\system32\drivers\hitmanpro37.sys
22:36:37.0879 0x1338 hitmanpro37 - ok
22:36:37.0941 0x1338 [ 196B4E3F4CCCC24AF836CE58FACBB699, 7A2E1F603A073421FA0987EFB96647F1F0F2D4E0C82AA62EBC041585DA811DAF ] hkmsvc C:\Windows\system32\kmsvc.dll
22:36:37.0941 0x1338 hkmsvc - ok
22:36:38.0019 0x1338 [ 6658F4404DE03D75FE3BA09F7ABA6A30, E51D9C1580A283EB862F09B73AAE1B647DD683A53F3DD99834222F12DD15E40F ] HomeGroupListener C:\Windows\system32\ListSvc.dll
22:36:38.0050 0x1338 HomeGroupListener - ok
22:36:38.0113 0x1338 [ DBC02D918FFF1CAD628ACBE0C0EAA8E8, 02121800D9062692C102475876AE8143EBE46D855E8328B8CDCFE6A2F0D19696 ] HomeGroupProvider C:\Windows\system32\provsvc.dll
22:36:38.0128 0x1338 HomeGroupProvider - ok
22:36:38.0187 0x1338 [ 295FDC419039090EB8B49FFDBB374549, 670E8015FD374640C6570F56F7FE8DE4D8F92E7A8072F5D1B2B95D0BD699CEF7 ] HpSAMD C:\Windows\system32\drivers\HpSAMD.sys
22:36:38.0187 0x1338 HpSAMD - ok
22:36:38.0265 0x1338 [ 487569E5DA56A5A432FF8AF6D3599CF9, 7C974D8379C60B4F69A20B01876C49181B0A63AC318C4BD0A21DABFF27A15C9D ] HTTP C:\Windows\system32\drivers\HTTP.sys
22:36:38.0281 0x1338 HTTP - ok
22:36:38.0368 0x1338 HuaweiHiSuiteService.exe - ok
22:36:38.0499 0x1338 [ 6FFB351C9C9BB88E91785F4CD7396D31, 699DA017B48CD0531174ACFE1EB74F09D5B55FC62FF0C5D77EB21256BE692854 ] HWiNFO32 C:\Windows\system32\drivers\HWiNFO32.SYS
22:36:38.0503 0x1338 HWiNFO32 - ok
22:36:38.0579 0x1338 [ 0C4E035C7F105F1299258C90886C64C5, CFB4FBE7B28058E6D3E6E508CF3C1645F6AAE0AFEB4C5364835B9C42311DF0D4 ] hwpolicy C:\Windows\system32\drivers\hwpolicy.sys
22:36:38.0581 0x1338 hwpolicy - ok
22:36:38.0670 0x1338 [ F151F0BDC47F4A28B1B20A0818EA36D6, 84B24B5796D9F70A8C37773F5484A4606CC7908370CCD942627ACBEDC4952D79 ] i8042prt C:\Windows\system32\drivers\i8042prt.sys
22:36:38.0674 0x1338 i8042prt - ok
22:36:38.0738 0x1338 [ 5CD5F9A5444E6CDCB0AC89BD62D8B76E, 72870092A80C6DAE0105025B0ED8B607E98BA81E59298364A7FE4C9C56C68FF0 ] iaStorV C:\Windows\system32\drivers\iaStorV.sys
22:36:38.0749 0x1338 iaStorV - ok
22:36:38.0847 0x1338 [ 3E9213A2A050BF429E91898C90F8B4E3, D80ABE5691087661B19F01927B631CB8C5291120B814B6F863F046E0D643E9E4 ] idsvc C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
22:36:38.0894 0x1338 idsvc - ok
22:36:38.0939 0x1338 [ 4173FF5708F3236CF25195FECD742915, 0A9C0701DF6EAC6602BE342FC13C7950EF04BB5BDF7D96C2C5DABBD2A29AA55D ] iirsp C:\Windows\system32\DRIVERS\iirsp.sys
22:36:38.0942 0x1338 iirsp - ok
22:36:39.0094 0x1338 [ B9C54120F46392100478F58F374E5709, A28EE8B0988F580D5984E815FC78DF41B169260814234AA0E453375542D0957B ] IKEEXT C:\Windows\System32\ikeext.dll
22:36:39.0132 0x1338 IKEEXT - ok
22:36:39.0446 0x1338 [ 3D4799C3109D0913C6B3764FC0148CB9, F9F39DA5B5379B631F7DE6B7A9DDF408738E594F3572321BEE7BE66418FBB0F4 ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHDA.sys
22:36:39.0646 0x1338 IntcAzAudAddService - ok
22:36:39.0705 0x1338 [ A0F12F2C9BA6C72F3987CE780E77C130, 5F53DF8BE1621AA7DFB655CFD9C95E0AFA1AD3CE2E290E19D7B7FB3C6E380034 ] intelide C:\Windows\system32\drivers\intelide.sys
22:36:39.0727 0x1338 intelide - ok
22:36:40.0072 0x1338 [ 3B514D27BFC4ACCB4037BC6685F766E0, F12D7AC62F8550E6F33B28AD751D8413AB7FFEF963242D99FFA76CE8A48B027A ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys
22:36:40.0074 0x1338 intelppm - ok
22:36:40.0120 0x1338 [ ACB364B9075A45C0736E5C47BE5CAE19, 202F77C659103D2D0E787B8CB0A23BE32EA5AA2E6B3B0A0F0A8DFA906AB3C0C0 ] IPBusEnum C:\Windows\system32\ipbusenum.dll
22:36:40.0126 0x1338 IPBusEnum - ok
22:36:40.0232 0x1338 [ 709D1761D3B19A932FF0238EA6D50200, 0A9D2C3A6E91CA45540555B40CB4E2DF3EBE98C1D164C4EECEE20C86782F5823 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys
22:36:40.0378 0x1338 IpFilterDriver - ok
22:36:40.0696 0x1338 [ 58F67245D041FBE7AF88F4EAF79DF0FA, 67468D6A46FF4D87AD321BFEA42F2FC843D09AA292A119C76D4D795D06028F96 ] iphlpsvc C:\Windows\System32\iphlpsvc.dll
22:36:40.0719 0x1338 iphlpsvc - ok
22:36:40.0857 0x1338 [ 4BD7134618C1D2A27466A099062547BF, 20284ABEF4433A59E2981F4143CAEC67DC990864FE0B9E3DC70EE0B88539E964 ] IPMIDRV C:\Windows\system32\drivers\IPMIDrv.sys
22:36:40.0860 0x1338 IPMIDRV - ok
22:36:41.0053 0x1338 [ A5FA468D67ABCDAA36264E463A7BB0CD, EDB828D596E43372F97DAE1AADA46428C4C45FB80646DDC64FAD5F25C826CF63 ] IPNAT C:\Windows\system32\drivers\ipnat.sys
22:36:41.0068 0x1338 IPNAT - ok
22:36:41.0127 0x1338 [ 42996CFF20A3084A56017B7902307E9F, 688176DAB91BE569280E4822E4C5BDE755794D293591C53F8047AD59C441751D ] IRENUM C:\Windows\system32\drivers\irenum.sys
22:36:41.0128 0x1338 IRENUM - ok
22:36:41.0217 0x1338 [ 1F32BB6B38F62F7DF1A7AB7292638A35, 86522358680FBB1CEBC56B4D139290689BB0F71A3EC78CE883E4D75D0B37586F ] isapnp C:\Windows\system32\drivers\isapnp.sys
22:36:41.0222 0x1338 isapnp - ok
22:36:41.0428 0x1338 [ EB34CE31FABD4DC4343FD2AD16D2CAF9, D21C91227A15DA89ECF522345D0AB80B3B7FC24A230596DABDB8BD3B7554CE8C ] iScsiPrt C:\Windows\system32\drivers\msiscsi.sys
22:36:41.0461 0x1338 iScsiPrt - ok
22:36:41.0517 0x1338 [ ADEF52CA1AEAE82B50DF86B56413107E, A3AE1E96B04AC81665ABBD3CB267DFB3F78376DAE18FB0DBD447908DDAAA22D2 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys
22:36:41.0519 0x1338 kbdclass - ok
22:36:41.0644 0x1338 [ 9E3CED91863E6EE98C24794D05E27A71, 90CF59F20E14E4A5A793266805E82BF7AE1F0CF4C7BAB1FD2EEF3B53C5DF770F ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys
22:36:41.0653 0x1338 kbdhid - ok
22:36:41.0669 0x1338 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] KeyIso C:\Windows\system32\lsass.exe
22:36:41.0672 0x1338 KeyIso - ok
22:36:41.0722 0x1338 [ 746F89CE0C6569C589E6AC4D3DA82D41, 6D41311CBA8BB7C9C09C1757D7947539B67FE3EFF6299502176C673809BAEAD8 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys
22:36:41.0728 0x1338 KSecDD - ok
22:36:41.0898 0x1338 [ D800E1EAF33630A1636BB21E8256AA92, D07542A242E0D52B494BE63A6A141207D0A59CF66ABEBA9CE33877594BF7BA5D ] KSecPkg C:\Windows\system32\Drivers\ksecpkg.sys
22:36:41.0903 0x1338 KSecPkg - ok
22:36:42.0293 0x1338 [ 89A7B9CC98D0D80C6F31B91C0A310FCD, 4583CAEEE0D50C0C7CE955E533FDA063CDC37B69033D41EF22EF1BA242E4C747 ] KtmRm C:\Windows\system32\msdtckrm.dll
22:36:42.0324 0x1338 KtmRm - ok
22:36:42.0407 0x1338 [ D64AF876D53ECA3668BB97B51B4E70AB, D5C07C019BFEAFBEDC29AB5060356A3B07449712B21B50E03378BEF04AF180F9 ] LanmanServer C:\Windows\system32\srvsvc.dll
22:36:42.0420 0x1338 LanmanServer - ok
22:36:42.0660 0x1338 [ 58405E4F68BA8E4057C6E914F326ABA2, C3E6519A1A38F1B3597D4391E42ABFE8F1F5E86256C4B3BD876CDAD9BB68B0A6 ] LanmanWorkstation C:\Windows\System32\wkssvc.dll
22:36:42.0671 0x1338 LanmanWorkstation - ok
22:36:42.0758 0x1338 [ F7611EC07349979DA9B0AE1F18CCC7A6, 879AA7A391966F00761CA039C25EBC62F6712DD5461694911EEC673E12DE103E ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys
22:36:42.0790 0x1338 lltdio - ok
22:36:42.0838 0x1338 [ 5700673E13A2117FA3B9020C852C01E2, 6684A2905EE8C438F2A64BE47E51A54D287B08DEFB8E0AE7FC2809D845EE3C5F ] lltdsvc C:\Windows\System32\lltdsvc.dll
22:36:42.0848 0x1338 lltdsvc - ok
22:36:42.0870 0x1338 [ 55CA01BA19D0006C8F2639B6C045E08B, 4DBBDC820C514DB18CC13F8EE178F8C4E39C295C6E3C255416C235553CE7BDC1 ] lmhosts C:\Windows\System32\lmhsvc.dll
22:36:42.0977 0x1338 lmhosts - ok
22:36:43.0044 0x1338 [ EB119A53CCF2ACC000AC71B065B78FEF, 1FD60735C4945AE565C223F0B47EAF9602D8777E3D15600914C1A9D761215AF9 ] LSI_FC C:\Windows\system32\DRIVERS\lsi_fc.sys
22:36:43.0056 0x1338 LSI_FC - ok
22:36:43.0095 0x1338 [ 8ADE1C877256A22E49B75D1CC9161F9C, 3D64F233DC866537E50549A7C1A2B40A954055B22F0BDA39825B04C38C607CB7 ] LSI_SAS C:\Windows\system32\DRIVERS\lsi_sas.sys
22:36:43.0100 0x1338 LSI_SAS - ok
22:36:43.0130 0x1338 [ DC9DC3D3DAA0E276FD2EC262E38B11E9, A264990857CBC74036799E17A087130626C0A09BE19879019BAF2D761C62AECC ] LSI_SAS2 C:\Windows\system32\DRIVERS\lsi_sas2.sys
22:36:43.0133 0x1338 LSI_SAS2 - ok
22:36:43.0151 0x1338 [ 0A036C7D7CAB643A7F07135AC47E0524, 2F662D07FCB74B8D493156DB555EAA90A47E93CF14C7B30039D2FE47EB8682B8 ] LSI_SCSI C:\Windows\system32\DRIVERS\lsi_scsi.sys
22:36:43.0155 0x1338 LSI_SCSI - ok
22:36:43.0187 0x1338 [ 6703E366CC18D3B6E534F5CF7DF39CEE, 7396B9AF938284D99EC51206A7B2FA4A0DC10A493DCE6707818B03A7473782C4 ] luafv C:\Windows\system32\drivers\luafv.sys
22:36:43.0193 0x1338 luafv - ok
22:36:43.0379 0x1338 [ B4CD87E78A01562E3DA67FE1C2779204, 536AC01C53A18E7B43F02F345FC3088C189A2D01F5E060714C0534FE7ECA2356 ] MBAMProtector C:\Windows\system32\drivers\mbam.sys
22:36:43.0380 0x1338 MBAMProtector - ok
22:36:44.0274 0x1338 [ 83C982A395D00BAFF6515FB38424EA76, 0E1B66F84A483D47550347D4A9426B95A066DB5104C4284F606A16768A11DB0C ] MBAMService C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe
22:36:44.0409 0x1338 MBAMService - ok
22:36:44.0555 0x1338 [ 739164A8B8FB2F1B50A498F20AF7B21E, 8E7A387C3726A863BF251E638D072FA472B698EF6868E9A7A00EF1272F809C64 ] MBAMSwissArmy C:\Windows\system32\drivers\MBAMSwissArmy.sys
22:36:44.0561 0x1338 MBAMSwissArmy - ok
22:36:44.0642 0x1338 [ 490F0F3ED8A970E2BAA38F719242B8F7, 03F902365372639424AB654AEBF6EB2B6B73363275435ADC2D086EAA7112AC3D ] MBAMWebAccessControl C:\Windows\system32\drivers\mwac.sys
22:36:44.0646 0x1338 MBAMWebAccessControl - ok
22:36:44.0863 0x1338 [ BFB9EE8EE977EFE85D1A3105ABEF6DD1, D2A84EBF0C0B7A14AD432FD2EF43CC12300027AEA3FA4075659FB088AB62B588 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll
22:36:44.0945 0x1338 Mcx2Svc - ok
22:36:45.0059 0x1338 [ 0FFF5B045293002AB38EB1FD1FC2FB74, 49071B565FD5B2DE43EC00D8518C3BE70843F38919E82F13104B8C1FAFB20374 ] megasas C:\Windows\system32\DRIVERS\megasas.sys
22:36:45.0066 0x1338 megasas - ok
22:36:45.0097 0x1338 [ DCBAB2920C75F390CAF1D29F675D03D6, 85C3A7A010BEA5E3C6179161B295F2CB900A6A214833A5F87A4327392880E2BB ] MegaSR C:\Windows\system32\DRIVERS\MegaSR.sys
22:36:45.0106 0x1338 MegaSR - ok
22:36:45.0139 0x1338 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] MMCSS C:\Windows\system32\mmcss.dll
22:36:45.0145 0x1338 MMCSS - ok
22:36:45.0176 0x1338 [ F001861E5700EE84E2D4E52C712F4964, F4DC5AEED6F34D76CCEF360862CC47EF71097BE0813C8CE04EE5F0DB387DFFAE ] Modem C:\Windows\system32\drivers\modem.sys
22:36:45.0178 0x1338 Modem - ok
22:36:45.0306 0x1338 [ 79D10964DE86B292320E9DFE02282A23, 52714827B7EEDACA55326A4E4F6158D4942DFAA3BACDE303A2F569BF3F4FAA72 ] monitor C:\Windows\system32\DRIVERS\monitor.sys
22:36:45.0307 0x1338 monitor - ok
22:36:45.0374 0x1338 [ FB18CC1D4C2E716B6B903B0AC0CC0609, F10CCA63493782B16DE6B96B94A27078DBE68AECEF34FDF840CFF86D2C6E3C5E ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys
22:36:45.0376 0x1338 mouclass - ok
22:36:45.0534 0x1338 [ 2C388D2CD01C9042596CF3C8F3C7B24D, B2FB72272BB01AEDA4047B57C943B7E9BD8A6497854F8CC34672AAA592D0A703 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys
22:36:45.0535 0x1338 mouhid - ok
22:36:45.0680 0x1338 [ 644905A19D0F37F2233DFCE53BC4BC19, F52CB40AA0FD1EBF8CBF0F3BFB20C47142C637719840877FB93F10D085EB8C2B ] mountmgr C:\Windows\system32\drivers\mountmgr.sys
22:36:45.0686 0x1338 mountmgr - ok
22:36:46.0035 0x1338 [ E77DC03DD3C8E5A388BF9EED2A28F3D1, ED0DAA975D1EC35CE036F02596218E15CC6A054167628D12A0A5AD91B841F422 ] MpFilter C:\Windows\system32\DRIVERS\MpFilter.sys
22:36:46.0081 0x1338 MpFilter - ok
22:36:46.0252 0x1338 [ 2D699FB6E89CE0D8DA14ECC03B3EDFE0, D3D903EEA465D77345AAC9B9F02CDEADF4831212EA2DE4FCA33BEE26EBB47420 ] mpio C:\Windows\system32\drivers\mpio.sys
22:36:46.0293 0x1338 mpio - ok
22:36:46.0331 0x1338 [ AD2723A7B53DD1AACAE6AD8C0BFBF4D0, 1D6DCFA0E56C3E55B6AED819176E751502F863BA0FCF4F0B3253A81D208141A2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys
22:36:46.0334 0x1338 mpsdrv - ok
22:36:46.0445 0x1338 [ 9835584E999D25004E1EE8E5F3E3B881, 71798B0CBE9AE69F1F29B845319019C69EC7F415CBABB3B87DDE92C360675021 ] MpsSvc C:\Windows\system32\mpssvc.dll
22:36:46.0506 0x1338 MpsSvc - ok
22:36:46.0562 0x1338 [ 03F899F521D2AAED1C55008F734DF252, 4E56A51476A13F5630719018037B1F63DF9ACEA1CFE782AF04E669BD696954C5 ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys
22:36:46.0567 0x1338 MRxDAV - ok
22:36:46.0658 0x1338 [ 5D16C921E3671636C0EBA3BBAAC5FD25, 5BC107B95CAFC88F51FBB9F657B99944B20627A2B618F263093D7045E4FFD65C ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys
22:36:46.0664 0x1338 mrxsmb - ok
22:36:46.0826 0x1338 [ 6D17A4791ACA19328C685D256349FEFC, 012AA3D84EEAAF53780D06D2D11B9727DFC3441F3FAD75BC9E751FB814403668 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys
22:36:46.0893 0x1338 mrxsmb10 - ok
22:36:46.0980 0x1338 [ B81F204D146000BE76651A50670A5E9E, 78193D0F967BE9829E53F9B500342934B4B1E1F4CEFC444382959E2061BC3B17 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys
22:36:46.0980 0x1338 mrxsmb20 - ok
22:36:47.0028 0x1338 [ 012C5F4E9349E711E11E0F19A8589F0A, 208B92DFCF7AD43202660FBBC9FF5E03AEDBEE38178FF3628EB74CB6CD37C584 ] msahci C:\Windows\system32\drivers\msahci.sys
22:36:47.0028 0x1338 msahci - ok
22:36:47.0044 0x1338 [ 55055F8AD8BE27A64C831322A780A228, C2C9FD1F61302997117B1CD0835E8234405BB80084065ED05363B77868397304 ] msdsm C:\Windows\system32\drivers\msdsm.sys
22:36:47.0060 0x1338 msdsm - ok
22:36:47.0110 0x1338 [ E1BCE74A3BD9902B72599C0192A07E27, 5162EB623FE64E9DFEAC6CA2410EFA1314E62EC13207FFBFED2D61AA887603C4 ] MSDTC C:\Windows\System32\msdtc.exe
22:36:47.0110 0x1338 MSDTC - ok
22:36:47.0157 0x1338 [ DAEFB28E3AF5A76ABCC2C3078C07327F, 6EB558532400B489763BAE7203538DE5F196282A8CB46A1B31D59120FC5AFCEF ] Msfs C:\Windows\system32\drivers\Msfs.sys
22:36:47.0173 0x1338 Msfs - ok
22:36:47.0188 0x1338 [ 3E1E5767043C5AF9367F0056295E9F84, B2EDFECD3C14E4FE1BA87D9A86334043A9BD696A554EBD186DA7EAEB2EBD4F70 ] mshidkmdf C:\Windows\System32\drivers\mshidkmdf.sys
22:36:47.0188 0x1338 mshidkmdf - ok
22:36:47.0283 0x1338 [ 0A4E5757AE09FA9622E3158CC1AEF114, ED574E420E57374E328C7C526504ECA569C164287966F06019EC207CB17F2C54 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys
22:36:47.0299 0x1338 msisadrv - ok
22:36:47.0331 0x1338 [ 90F7D9E6B6F27E1A707D4A297F077828, BEFC220EAA7307849600748842ACB9254A6A91158812D9B23EFAF912C498BA7F ] MSiSCSI C:\Windows\system32\iscsiexe.dll
22:36:47.0360 0x1338 MSiSCSI - ok
22:36:47.0371 0x1338 msiserver - ok
22:36:47.0417 0x1338 [ 8C0860D6366AAFFB6C5BB9DF9448E631, 949C5A14E57F2D7385543C17C3485E7ADE36EA2016F6E0A1866571D2EDE90A77 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys
22:36:47.0418 0x1338 MSKSSRV - ok
22:36:47.0614 0x1338 [ B0F49DA36F30922F5DDC3B623B778FCE, EE025AEFA4A2095AFEABFB3A49639DA77D78068A3F5EEDA6C15D34853AFD5609 ] MsMpSvc c:\Program Files\Microsoft Security Client\MsMpEng.exe
22:36:47.0615 0x1338 MsMpSvc - ok
22:36:47.0659 0x1338 [ 3EA8B949F963562CEDBB549EAC0C11CE, 1B0B2F16A1790282504F3C548D47C3281EFB440D5D9711A1EF76D6371B768D2D ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys
22:36:47.0660 0x1338 MSPCLOCK - ok
22:36:47.0672 0x1338 [ F456E973590D663B1073E9C463B40932, 48BA6D5580EE7B6A4C06E04772FD35B51779553FC0DD6C5C30DD8B5DEEB25B11 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys
22:36:47.0673 0x1338 MSPQM - ok
22:36:47.0698 0x1338 [ 0E008FC4819D238C51D7C93E7B41E560, 141FCEBDD05874407EAEC35A9DCD3BB16F2A428F23E55487D6A5DBFCADBF10D2 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys
22:36:47.0704 0x1338 MsRPC - ok
22:36:47.0764 0x1338 [ FC6B9FF600CC585EA38B12589BD4E246, F05DB01AE1955D2468CE6B51E51998B111CA3B0BDEED090EE6B99B625CBA564A ] mssmbios C:\Windows\system32\drivers\mssmbios.sys
22:36:47.0765 0x1338 mssmbios - ok
22:36:47.0800 0x1338 [ B42C6B921F61A6E55159B8BE6CD54A36, 6BB0A7BE005B8F281E551D1B8046CE4202372BC7AE0161881C858BFAC675FE1C ] MSTEE C:\Windows\system32\drivers\MSTEE.sys
22:36:47.0804 0x1338 MSTEE - ok
22:36:47.0897 0x1338 [ 33599130F44E1F34631CEA241DE8AC84, E15B31D1AFDC8DC6D2B21D4215796A99ECC69EEDBB06CEED01AECC3C99A44C8B ] MTConfig C:\Windows\system32\DRIVERS\MTConfig.sys
22:36:47.0897 0x1338 MTConfig - ok
22:36:47.0976 0x1338 [ CBE71C122434805CB73FFB6619F60598, 332251B80AD5294188774A7A414A32DFC8C45DF348C736DB43C8E8DD8E7F08EC ] MTsensor C:\Windows\system32\DRIVERS\ASACPI.sys
22:36:47.0977 0x1338 MTsensor - ok
22:36:47.0997 0x1338 [ 159FAD02F64E6381758C990F753BCC80, E55AB01DCFA95ECAB24A2A9656E28FF9D064BA08B3D82DC8AA42F5991BA09598 ] Mup C:\Windows\system32\Drivers\mup.sys
22:36:47.0999 0x1338 Mup - ok
22:36:48.0058 0x1338 [ 61D57A5D7C6D9AFE10E77DAE6E1B445E, D252248532142E9E2332DA693BC51B795102CA938B568FF04981E98B19BFBC5C ] napagent C:\Windows\system32\qagentRT.dll
22:36:48.0073 0x1338 napagent - ok
22:36:48.0145 0x1338 [ 26384429FCD85D83746F63E798AB1480, 957C115C263A4B4DC854558B43ECE632D8E2BCCB744E23A01EBA7476BA2E7FFB ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys
22:36:48.0151 0x1338 NativeWifiP - ok
22:36:48.0306 0x1338 [ 8C9C922D71F1CD4DEF73F186416B7896, 15FF43CD90C7913F83B35F2E7986561584588E8A45196EBD965C3A355836A9C7 ] NDIS C:\Windows\system32\drivers\ndis.sys
22:36:48.0342 0x1338 NDIS - ok
22:36:48.0391 0x1338 [ 0E1787AA6C9191D3D319E8BAFE86F80C, F535022747355B2C66424BDA892D7DCB820C2EB8EE05BAE5BC6D1B1D65186278 ] NdisCap C:\Windows\system32\DRIVERS\ndiscap.sys
22:36:48.0500 0x1338 NdisCap - ok
22:36:48.0559 0x1338 [ E4A8AEC125A2E43A9E32AFEEA7C9C888, 6EA181117126FC70B3C1DD1AC73CC26D1603A2CF49E47F66623E2C9489C49B55 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys
22:36:48.0560 0x1338 NdisTapi - ok
22:36:48.0633 0x1338 [ D8A65DAFB3EB41CBB622745676FCD072, 874D3C3D247C4A309DA813DB1D2EDB0037D3C489824BD5FE95B0C20699764EF7 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys
22:36:48.0633 0x1338 Ndisuio - ok
22:36:48.0696 0x1338 [ 38FBE267E7E6983311179230FACB1017, CFD1CBCA59650795C030DB30E5795B37C11C736E14003AE1DAB081BA5C0C9B14 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys
22:36:48.0702 0x1338 NdisWan - ok
22:36:48.0773 0x1338 [ A4BDC541E69674FBFF1A8FF00BE913F2, 18CCFD063E9870B8B6958715BC0414C4D920AE63528EA1E9D7E30F7138918FFA ] NDProxy C:\Windows\system32\drivers\NDProxy.sys
22:36:48.0779 0x1338 NDProxy - ok
22:36:48.0824 0x1338 [ 80B275B1CE3B0E79909DB7B39AF74D51, 75B406B0D9D28239D4EB2A298419A5F78A58237D88C5FD688EF1DFFAFACCF796 ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys
22:36:48.0824 0x1338 NetBIOS - ok
22:36:48.0941 0x1338 [ 280122DDCF04B378EDD1AD54D71C1E54, F98B2ADE34F7E67C7C06C1D0FFB80ECBC353D044D4B4784CD952910345DC2ED0 ] NetBT C:\Windows\system32\DRIVERS\netbt.sys
22:36:48.0957 0x1338 NetBT - ok
22:36:48.0991 0x1338 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] Netlogon C:\Windows\system32\lsass.exe
22:36:48.0994 0x1338 Netlogon - ok
22:36:49.0033 0x1338 [ 7CCCFCA7510684768DA22092D1FA4DB2, BB9E4F8FABBF596D888E6D303CB54A336D9DFF95B36AEA9369D2ED787DDC4B5D ] Netman C:\Windows\System32\netman.dll
22:36:49.0049 0x1338 Netman - ok
22:36:49.0130 0x1338 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:36:49.0137 0x1338 NetMsmqActivator - ok
22:36:49.0144 0x1338 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetPipeActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:36:49.0144 0x1338 NetPipeActivator - ok
22:36:49.0208 0x1338 [ 8C338238C16777A802D6A9211EB2BA50, 0D08A47CD403EDA5E8CAD7409BBBBCDC29A9861D2DC41D42B68B22B1AA1EBDD6 ] netprofm C:\Windows\System32\netprofm.dll
22:36:49.0233 0x1338 netprofm - ok
22:36:49.0264 0x1338 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpActivator C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:36:49.0264 0x1338 NetTcpActivator - ok
22:36:49.0292 0x1338 [ E58808846B62041BFB05395E1CED6499, 5387F2CE6B494337725D2BF3EB563912E6EE33918F2872C5FE07BEDBB0F761EE ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
22:36:49.0308 0x1338 NetTcpPortSharing - ok
22:36:49.0344 0x1338 [ 1D85C4B390B0EE09C7A46B91EFB2C097, 6A8850B151E88EE371F3CC543A946302DDF9494908D684B8B0C706A42CC54348 ] nfrd960 C:\Windows\system32\DRIVERS\nfrd960.sys
22:36:49.0344 0x1338 nfrd960 - ok
22:36:49.0398 0x1338 [ 32FF06EC6D946EF791D98D6C838A3090, 319BDD491CB22D0CCCCE76A2854CF469D7AF046289F9C56CD03AE3D3CBC0275E ] NisDrv C:\Windows\system32\DRIVERS\NisDrvWFP.sys
22:36:49.0398 0x1338 NisDrv - ok
22:36:49.0480 0x1338 [ 42D33042371BFB1A7D40834590CAFD30, 53DA3618EC10293B2DF686E291A4EF6ACBBD41D116EC762D54106D201A784E87 ] NisSrv c:\Program Files\Microsoft Security Client\NisSrv.exe
22:36:49.0496 0x1338 NisSrv - ok
22:36:49.0567 0x1338 [ F115C5CD29E512F18BD7138A094B77E5, 90C2CE8B256EE9AABF674ADDE7F85E91DAF48EA368452D03C187A4AE027D4E39 ] NlaSvc C:\Windows\System32\nlasvc.dll
22:36:49.0578 0x1338 NlaSvc - ok
22:36:49.0600 0x1338 [ 1DB262A9F8C087E8153D89BEF3D2235F, A51EE5D5AD3CD76B74BEA9C66C462608BF3B50C53DAA4110A75DB10495A8C101 ] Npfs C:\Windows\system32\drivers\Npfs.sys
22:36:49.0603 0x1338 Npfs - ok
22:36:49.0633 0x1338 [ BA387E955E890C8A88306D9B8D06BF17, 3477BD9686C5777A93251C154512671AAA7533B18C536DF51F7B1D6D28E7F8A5 ] nsi C:\Windows\system32\nsisvc.dll
22:36:49.0636 0x1338 nsi - ok
22:36:49.0650 0x1338 [ E9A0A4D07E53D8FEA2BB8387A3293C58, 690CAD6C4E35ECC1172A2E1FD3933DF73158B3BF42CB21244269612A53DE4D7A ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys
22:36:49.0652 0x1338 nsiproxy - ok
22:36:49.0758 0x1338 [ C8DFF8D07755A66C7A4A738930F0FEAC, A2CC58312CE57988ABD976155BE91F558DCEC4C23481C6FBE64B361D511A36EA ] Ntfs C:\Windows\system32\drivers\Ntfs.sys
22:36:49.0810 0x1338 Ntfs - ok
22:36:49.0879 0x1338 [ F9756A98D69098DCA8945D62858A812C, 572ADBFCFDE2030B34A013AADC14DBC144EB3F34D06991E2464A3EA9605BC045 ] Null C:\Windows\system32\drivers\Null.sys
22:36:49.0881 0x1338 Null - ok
22:36:49.0965 0x1338 [ 7D6348EC738067F8E8D132DAB4789CF0, B70471CEFA1DCF9BB4223E49A94956A8E4D1F241E29FE608A79961B0ED93B458 ] NVHDA C:\Windows\system32\drivers\nvhda32v.sys
22:36:49.0980 0x1338 NVHDA - ok
22:36:50.0777 0x1338 [ 14A172C80350F7306EC5980EE7B373CF, F4DBD5E959B6C79BC6CBA4BB4F712B92CB1D6ECD9CD8E099950295866D478C84 ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys
22:36:51.0200 0x1338 nvlddmkm - ok
22:36:51.0280 0x1338 [ B3E25EE28883877076E0E1FF877D02E0, 402B6FED6FBBF645190396DC141141EF52DD059DABD01F8AC9CF01D23664070C ] nvraid C:\Windows\system32\drivers\nvraid.sys
22:36:51.0293 0x1338 nvraid - ok
22:36:51.0338 0x1338 [ 4380E59A170D88C4F1022EFF6719A8A4, 93EDB3F4CDBF53C9C1970DD29AB146E390695C568180847BA8903F5FBEABCFF2 ] nvstor C:\Windows\system32\drivers\nvstor.sys
22:36:51.0338 0x1338 nvstor - ok
22:36:51.0480 0x1338 [ 2AEB92CC818CFB31F7BF655091D59498, C4CAF4C620F80148858EA4D1A37D3C11EAEFBB3F72845D1413F71A100319FE6B ] nvsvc C:\Windows\system32\nvvsvc.exe
22:36:51.0512 0x1338 nvsvc - ok
22:36:51.0533 0x1338 nvvad_WaveExtensible - ok
22:36:51.0604 0x1338 [ 5A0983915F02BAE73267CC2A041F717D, D83461D74597BF2BE042FEFCC27FCD18BF63CB8135B0666D731D50951C3468A8 ] nv_agp C:\Windows\system32\drivers\nv_agp.sys
22:36:51.0618 0x1338 nv_agp - ok
22:36:51.0670 0x1338 [ 08A70A1F2CDDE9BB49B885CB817A66EB, 0BB98123B544124B144F3E95D77E01E973D060B8B2302503FF24ABBBE803EB63 ] ohci1394 C:\Windows\system32\drivers\ohci1394.sys
22:36:51.0675 0x1338 ohci1394 - ok
22:36:51.0758 0x1338 [ 9D10F99A6712E28F8ACD5641E3A7EA6B, 70964A0ED9011EA94044E15FA77EDD9CF535CC79ED8E03A3721FF007E69595CC ] ose C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
22:36:51.0758 0x1338 ose - ok
22:36:52.0143 0x1338 [ 358A9CCA612C68EB2F07DDAD4CE1D8D7, F342100E2E9001F11FDF93F856B50FA43F9B85D2C6B5706EC0433E77206498DA ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
22:36:52.0370 0x1338 osppsvc - ok
22:36:52.0451 0x1338 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] p2pimsvc C:\Windows\system32\pnrpsvc.dll
22:36:52.0471 0x1338 p2pimsvc - ok
22:36:52.0521 0x1338 [ 59C3DDD501E39E006DAC31BF55150D91, E02B63AB7F34CF6FF3F644AF354D10004E6F50014E03172D80BD78934EF71EF1 ] p2psvc C:\Windows\system32\p2psvc.dll
22:36:52.0565 0x1338 p2psvc - ok
22:36:52.0731 0x1338 [ 5489B567CDD6AE216519CACA7CC700E9, 2FB97D066CB2B140089CD45F64A99234FF82F516AC400C8945FB5021CB56515D ] PAC207 C:\Windows\system32\DRIVERS\pfc027.sys
22:36:52.0741 0x1338 PAC207 - ok
22:36:52.0780 0x1338 [ 2EA877ED5DD9713C5AC74E8EA7348D14, 14BA3722CE5F8FF07F2D97DCDD6558EB49C9B02E5E6FAD6D9F18D354733EFECE ] Parport C:\Windows\system32\DRIVERS\parport.sys
22:36:52.0783 0x1338 Parport - ok
22:36:52.0874 0x1338 [ 3F34A1B4C5F6475F320C275E63AFCE9B, 31295D5121C0C3F2085E0EEBA260EEE4CA003993C026E2F81986D19158036E6B ] partmgr C:\Windows\system32\drivers\partmgr.sys
22:36:52.0876 0x1338 partmgr - ok
22:36:52.0910 0x1338 [ EB0A59F29C19B86479D36B35983DAADC, AC09AFE7F13BE4079D01383BAC44091997E1AAF6512C9673A42B9E3780EB08A8 ] Parvdm C:\Windows\system32\DRIVERS\parvdm.sys
22:36:52.0913 0x1338 Parvdm - ok
22:36:52.0970 0x1338 [ 52954BE460EC6C54C0ACB2B3B126FFC6, 9F9878EC5ABC74C5A8EE8E1D940F0934F081895B07D844F42F80A638FE713F7B ] PcaSvc C:\Windows\System32\pcasvc.dll
22:36:53.0005 0x1338 PcaSvc - ok
22:36:53.0056 0x1338 [ 673E55C3498EB970088E812EA820AA8F, 1F81315664B8CBFDD569416C0ECCE4C6251F34577313A0858AB46609781303B5 ] pci C:\Windows\system32\drivers\pci.sys
22:36:53.0072 0x1338 pci - ok
22:36:53.0129 0x1338 [ AFE86F419014DB4E5593F69FFE26CE0A, CAF36E61BE7B511D3A03A65FF5A3017CEE4D2F53005B410F2D4A2AAE9FED4C00 ] pciide C:\Windows\system32\drivers\pciide.sys
22:36:53.0131 0x1338 pciide - ok
22:36:53.0163 0x1338 [ F396431B31693E71E8A80687EF523506, BC614FC21E029E2497F1CCE3131BBD295B827F2310762B47D5BBC7703D80554B ] pcmcia C:\Windows\system32\DRIVERS\pcmcia.sys
22:36:53.0163 0x1338 pcmcia - ok
22:36:53.0194 0x1338 [ 250F6B43D2B613172035C6747AEEB19F, A91F15B133F2619912CF750E6F3662E011CD0FA4B9477CE532CE3196D23307D9 ] pcw C:\Windows\system32\drivers\pcw.sys
22:36:53.0194 0x1338 pcw - ok
22:36:53.0280 0x1338 [ AEBC369F7DC72AB3F5B9BDF34FA0D43F, 2A819154AC6C23E97C583D90B4D0C112188B7AE9D8D9B3F88811BFCED124E551 ] PEAUTH C:\Windows\system32\drivers\peauth.sys
22:36:53.0313 0x1338 PEAUTH - ok
22:36:53.0737 0x1338 [ 414BBA67A3DED1D28437EB66AEB8A720, D6DF254E2615FA402044824DCD9004F579FC0DF74B90E44C99D5F0253CF8AD88 ] pla C:\Windows\system32\pla.dll
22:36:53.0824 0x1338 pla - ok
22:36:53.0888 0x1338 [ EC7BC28D207DA09E79B3E9FAF8B232CA, A42F8F69C3CD753D787A5D558659DEA2CC306C896D75B8C82549219CF654504F ] PlugPlay C:\Windows\system32\umpnpmgr.dll
22:36:53.0917 0x1338 PlugPlay - ok
22:36:53.0957 0x1338 [ 63FF8572611249931EB16BB8EED6AFC8, 9732CCBCB93A7A4BEC88812B952C20244479E9BD781240C195E57F09E619EA33 ] PNRPAutoReg C:\Windows\system32\pnrpauto.dll
22:36:53.0961 0x1338 PNRPAutoReg - ok
22:36:53.0980 0x1338 [ 82A8521DDC60710C3D3D3E7325209BEC, C4E34571EDD57C7FBB3D736B5FE8BD154624705B5C8EA2EC898F19F75B9A5942 ] PNRPsvc C:\Windows\system32\pnrpsvc.dll
22:36:54.0011 0x1338 PNRPsvc - ok
22:36:54.0090 0x1338 [ 53946B69BA0836BD95B03759530C81EC, 7F14A34635354CCA0F5342C8D9DF5A6AA1B94F6A508BD8834029E9BACF252920 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll
22:36:54.0103 0x1338 PolicyAgent - ok
22:36:54.0180 0x1338 [ F87D30E72E03D579A5199CCB3831D6EA, B09328E89954584F97908FA5946376BA990B8C650DABCBF3CA3B08719937C694 ] Power C:\Windows\system32\umpo.dll
22:36:54.0186 0x1338 Power - ok
22:36:54.0225 0x1338 [ 631E3E205AD6D86F2AED6A4A8E69F2DB, 1D3BF0CFC37D91A3A56246920B9CF1084E78A055D56E85A773417809C58C8065 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys
22:36:54.0231 0x1338 PptpMiniport - ok
22:36:54.0244 0x1338 [ 85B1E3A0C7585BC4AAE6899EC6FCF011, 1E067113C146D6842D7FB04007F363D6FB7783C6BC7C9AB6614E44075C4F86C3 ] Processor C:\Windows\system32\DRIVERS\processr.sys
22:36:54.0259 0x1338 Processor - ok
22:36:54.0339 0x1338 [ FD9692A3D31E021207D3C2A9DDDC2BE3, 5295EFAD9BD4B59996935A41825392C12A4C968D161BEEA37797F90AF8E54229 ] ProfSvc C:\Windows\system32\profsvc.dll
22:36:54.0346 0x1338 ProfSvc - ok
22:36:54.0350 0x1338 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] ProtectedStorage C:\Windows\system32\lsass.exe
22:36:54.0365 0x1338 ProtectedStorage - ok
22:36:54.0398 0x1338 [ 6270CCAE2A86DE6D146529FE55B3246A, 463209CBAF1B0E269DC8FC6FBDEE5BB7E5ADB5D3F024930BFD0B97E0A9678883 ] Psched C:\Windows\system32\DRIVERS\pacer.sys
22:36:54.0402 0x1338 Psched - ok
22:36:54.0556 0x1338 [ AB95ECF1F6659A60DDC166D8315B0751, 0ED6D3460D28978BADF31B930DBB3298A6A10EFF8883763EABA0E36A21A0E83D ] ql2300 C:\Windows\system32\DRIVERS\ql2300.sys
22:36:54.0624 0x1338 ql2300 - ok
22:36:54.0659 0x1338 [ B4DD51DD25182244B86737DC51AF2270, 7E62B04F054A6330B7F9968222523BDE8F3EE47A11D17E6C0E2D5ACDC07B9E6B ] ql40xx C:\Windows\system32\DRIVERS\ql40xx.sys
22:36:54.0664 0x1338 ql40xx - ok
22:36:54.0711 0x1338 [ 31AC809E7707EB580B2BDB760390765A, A8481FD19A0F778F5591B7676F591F664ADC68B6867E663C0F9564173F4AC909 ] QWAVE C:\Windows\system32\qwave.dll
22:36:54.0731 0x1338 QWAVE - ok
22:36:54.0746 0x1338 [ 584078CA1B95CA72DF2A27C336F9719D, 836F115C92D343463C14A9DE39648C1EFA7C7EE4720F5C692EE0F68B84830121 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys
22:36:54.0746 0x1338 QWAVEdrv - ok
22:36:54.0777 0x1338 [ 30A81B53C766D0133BB86D234E5556AB, 726C6B83B5ACAA84CAB1689B6DD6DDAE3199D61A57B5D7B5B5A0F62FCF838090 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys
22:36:54.0777 0x1338 RasAcd - ok
22:36:54.0851 0x1338 [ 57EC4AEF73660166074D8F7F31C0D4FD, C66B425EC4DB5E7FD289AE631C9B019EB16717C55E80FAE964BB22203E4AACEF ] RasAgileVpn C:\Windows\system32\DRIVERS\AgileVpn.sys
22:36:54.0873 0x1338 RasAgileVpn - ok
22:36:54.0934 0x1338 [ A60F1839849C0C00739787FD5EC03F13, B210DFA5A843CF1DA73635F168E2EA5052CBED15C664F8523CDFB34CA165D0E0 ] RasAuto C:\Windows\System32\rasauto.dll
22:36:54.0952 0x1338 RasAuto - ok
22:36:54.0987 0x1338 [ D9F91EAFEC2815365CBE6D167E4E332A, 8350457A39D141C13807E7DB5A8D4113197C4016F7744B9993391F4AEA0C4A5C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys
22:36:54.0992 0x1338 Rasl2tp - ok
22:36:55.0072 0x1338 [ CB9E04DC05EACF5B9A36CA276D475006, 4D8C0AEF1D4F84F375AD2BAF786C9F6C52316A3E655B913449E71AD7C0FCA56E ] RasMan C:\Windows\System32\rasmans.dll
22:36:55.0084 0x1338 RasMan - ok
22:36:55.0111 0x1338 [ 0FE8B15916307A6AC12BFB6A63E45507, 64119474DE7499E6E8B82E78BBD50074B3AA70B3E8329089FAE9B7F29919004E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys
22:36:55.0116 0x1338 RasPppoe - ok
22:36:55.0147 0x1338 [ 44101F495A83EA6401D886E7FD70096B, 56A0CE5C89870752B9B2AB795C1A248CA28209E049B2F20CCA0308CBE2488A0A ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys
22:36:55.0151 0x1338 RasSstp - ok
22:36:55.0231 0x1338 [ D528BC58A489409BA40334EBF96A311B, C71E9A4B101DB6C3183B9F97B9098D73D6FE1B12C05C2EB3CE8A8041BEE6BA61 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys
22:36:55.0245 0x1338 rdbss - ok
22:36:55.0273 0x1338 [ 0D8F05481CB76E70E1DA06EE9F0DA9DF, 2AFCBE3237D27AFBF095F91F1FCCA63E6890F34A9E4F00E5C34C92394CDA89FB ] rdpbus C:\Windows\system32\DRIVERS\rdpbus.sys
22:36:55.0280 0x1338 rdpbus - ok
22:36:55.0327 0x1338 [ 23DAE03F29D253AE74C44F99E515F9A1, 8FED93D10B2062F0526FE3508101F8FCF8F72DEB90AFB472EB7CBAE83A0EC430 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys
22:36:55.0328 0x1338 RDPCDD - ok
22:36:55.0368 0x1338 [ 5A53CA1598DD4156D44196D200C94B8A, 8112FE14FEC94C67B1C5BDE4171E37584F1D0098D2C557C9E4BDD3E0291E25E4 ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys
22:36:55.0369 0x1338 RDPENCDD - ok
22:36:55.0392 0x1338 [ 44B0A53CD4F27D50ED461DAE0C0B4E1F, CDA80B08E67AD034081C0C920CD66147689F1844403CBC552F65005E7C011A91 ] RDPREFMP C:\Windows\system32\drivers\rdprefmp.sys
22:36:55.0393 0x1338 RDPREFMP - ok
22:36:55.0542 0x1338 [ 65375DF758CA1872AB7EBBBA457FD5E6, 8AC7681F51277E799C22FF95FA0B833E9E260D37C0416319FF05B66FB3948005 ] RdpVideoMiniport C:\Windows\system32\drivers\rdpvideominiport.sys
22:36:55.0552 0x1338 RdpVideoMiniport - ok
22:36:55.0612 0x1338 [ CD9214A6AE17D188D17C3CF8CB9CC693, 2E16FF1F7446F0600D6519010FD05A30B94D97167C16B3E7FC396A97D8139D60 ] RDPWD C:\Windows\system32\drivers\RDPWD.sys
22:36:55.0626 0x1338 RDPWD - ok
22:36:55.0694 0x1338 [ 518395321DC96FE2C9F0E96AC743B656, 5F6A0880B4F3EE7196259EA362DA9554B0687B0236F9A8E5CF7A4A77F01F1776 ] rdyboost C:\Windows\system32\drivers\rdyboost.sys
22:36:55.0705 0x1338 rdyboost - ok
22:36:55.0736 0x1338 [ 7B5E1419717FAC363A31CC302895217A, 048B96B127CC20833948DAE53C59886D5C725ECA7A744424A01339447D2DDC32 ] RemoteAccess C:\Windows\System32\mprdim.dll
22:36:55.0746 0x1338 RemoteAccess - ok
22:36:55.0776 0x1338 [ CB9A8683F4EF2BF99E123D79950D7935, B9FA3E7E91E76D975CF40BFA37909E50F29CC13AB1399007884710651827E9AA ] RemoteRegistry C:\Windows\system32\regsvc.dll
22:36:55.0786 0x1338 RemoteRegistry - ok
22:36:55.0818 0x1338 [ 78D072F35BC45D9E4E1B61895C152234, 80C924EE1156B4E3172E83DCB9C60817E87885FB9377647E0BF90153E415B1CA ] RpcEptMapper C:\Windows\System32\RpcEpMap.dll
22:36:55.0825 0x1338 RpcEptMapper - ok
22:36:55.0842 0x1338 [ 94D36C0E44677DD26981D2BFEEF2A29D, D77A93AC60536F3706E8A0154C0C2199E888B7748C84DB7437254FF175F4DF55 ] RpcLocator C:\Windows\system32\locator.exe
22:36:55.0846 0x1338 RpcLocator - ok
22:36:55.0920 0x1338 [ 7660F01D3B38ACA1747E397D21D790AF, 04611B43705C064C2A8331F6D3F8E4530295694AE2C3E3EC3F62CFF4A5EFA88D ] RpcSs C:\Windows\system32\rpcss.dll
22:36:55.0941 0x1338 RpcSs - ok
22:36:56.0061 0x1338 [ 032B0D36AD92B582D869879F5AF5B928, 0F8F18A6A0A689957B886D9368015889091094EDA18BE532093F06A70A7CE184 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys
22:36:56.0070 0x1338 rspndr - ok
22:36:56.0135 0x1338 [ C5CF99568169D377F326B23BFF67FC6B, 1C809083280584D0C2D85EC6E2F103FB65DC2EEFF8C3F574B5B1298E86990677 ] RTL8167 C:\Windows\system32\DRIVERS\Rt86win7.sys
22:36:56.0191 0x1338 RTL8167 - ok
22:36:56.0213 0x1338 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] SamSs C:\Windows\system32\lsass.exe
22:36:56.0215 0x1338 SamSs - ok
22:36:56.0282 0x1338 [ 05D860DA1040F111503AC416CCEF2BCA, DAE2F37D09A5A42F945BC8E27E4EA2303521081783A80CEE7FEE7C5A1C2CFC5E ] sbp2port C:\Windows\system32\drivers\sbp2port.sys
22:36:56.0282 0x1338 sbp2port - ok
22:36:56.0329 0x1338 [ 8FC518FFE9519C2631D37515A68009C4, 21E10585470CF9FC3BD1977F8A426686CD2FA6BD2094B9E3594B21C7C4541D25 ] SCardSvr C:\Windows\System32\SCardSvr.dll
22:36:56.0329 0x1338 SCardSvr - ok
22:36:56.0391 0x1338 [ 0693B5EC673E34DC147E195779A4DCF6, AF1B56FBF3ADABF94CD9DBA67586B8746DE135151F6B3D1B0EE315BC1E2DB670 ] scfilter C:\Windows\system32\DRIVERS\scfilter.sys
22:36:56.0391 0x1338 scfilter - ok
22:36:56.0492 0x1338 [ A04BB13F8A72F8B6E8B4071723E4E336, E63287FF71C39CBF64C3347C455324C8437F9CF398153E269543588B65389502 ] Schedule C:\Windows\system32\schedsvc.dll
22:36:56.0575 0x1338 Schedule - ok
22:36:56.0661 0x1338 [ 319C6B309773D063541D01DF8AC6F55F, 182F392FE839499D159A30A3CD04B5D0C87219930BFB1A7456880B7DA75B9820 ] SCPolicySvc C:\Windows\System32\certprop.dll
22:36:56.0663 0x1338 SCPolicySvc - ok
22:36:56.0716 0x1338 [ A689D522EEDF89401E1DA2FE883AA7EC, 15C03644972C6CD4E2D970F3513793BEF30E2E8F18A78369CCDBD090C3F94AE0 ] SCREAMINGBDRIVER C:\Windows\system32\drivers\ScreamingBAudio.sys
22:36:56.0719 0x1338 SCREAMINGBDRIVER - ok
22:36:56.0773 0x1338 [ 08236C4BCE5EDD0A0318A438AF28E0F7, 77727F963F63C4CEC11E7AAD5FB3836179701D512CA9436C3170B9E6A4E5F888 ] SDRSVC C:\Windows\System32\SDRSVC.dll
22:36:56.0789 0x1338 SDRSVC - ok
22:36:56.0820 0x1338 [ 90A3935D05B494A5A39D37E71F09A677, F72733A69BC6E1A2BB91D7632FF3463C12563F60FDCC00A2CDD67FF20D479952 ] secdrv C:\Windows\system32\drivers\secdrv.sys
22:36:56.0820 0x1338 secdrv - ok
22:36:56.0852 0x1338 [ A59B3A4442C52060CC7A85293AA3546F, 1776D6DEE51991149265AAF39E17065E301C5FA1FF4068653DC0010B9B27185D ] seclogon C:\Windows\system32\seclogon.dll
22:36:56.0852 0x1338 seclogon - ok
22:36:56.0896 0x1338 [ DCB7FCDCC97F87360F75D77425B81737, F8289AF2C458C167038EEFE613EE5E3D6D5B3308B8784168374BC81C47891CE5 ] SENS C:\Windows\System32\sens.dll
22:36:56.0896 0x1338 SENS - ok
22:36:56.0911 0x1338 [ 50087FE1EE447009C9CC2997B90DE53F, B5E6CF1D991F87C29C5E28198E0962E31FFB499A46C3BD43FC20391693389959 ] SensrSvc C:\Windows\system32\sensrsvc.dll
22:36:56.0911 0x1338 SensrSvc - ok
22:36:56.0959 0x1338 [ 9AD8B8B515E3DF6ACD4212EF465DE2D1, E2F019BCD1446236D078D46065DD151DD068778F33BE2F1E8A0CC1EA2F954E86 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys
22:36:56.0959 0x1338 Serenum - ok
22:36:56.0990 0x1338 [ 5FB7FCEA0490D821F26F39CC5EA3D1E2, A26DB2EB9F3E2509B4EBA949DB97595CC32332D9321DF68283BFC102E66D766F ] Serial C:\Windows\system32\DRIVERS\serial.sys
22:36:56.0990 0x1338 Serial - ok
22:36:57.0006 0x1338 [ 79BFFB520327FF916A582DFEA17AA813, 7A2A9D69BE02228591186A9F4453D4B5FD98837CA422C873C48040170E8BD18C ] sermouse C:\Windows\system32\DRIVERS\sermouse.sys
22:36:57.0021 0x1338 sermouse - ok
22:36:57.0085 0x1338 [ 4AE380F39A0032EAB7DD953030B26D28, C8F5F2DD59574E966FDF3057867BB959A554BAB6FD5DC6F1427094A6BC2B2809 ] SessionEnv C:\Windows\system32\sessenv.dll
22:36:57.0100 0x1338 SessionEnv - ok
22:36:57.0149 0x1338 [ 9F976E1EB233DF46FCE808D9DEA3EB9C, 6A5C53F27F8BCA85CE206EE7D196176F67EC6FFA5D4830373A20792C149B5E75 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys
22:36:57.0150 0x1338 sffdisk - ok
22:36:57.0166 0x1338 [ 932A68EE27833CFD57C1639D375F2731, 11D6B98FBEEE2B9C7B06EF7091857BBD3B349077997D6261D66280668FD1B5C3 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys
22:36:57.0168 0x1338 sffp_mmc - ok
22:36:57.0193 0x1338 [ 6D4CCAEDC018F1CF52866BBBAA235982, AAC41F5C97B3FE5A3DC0838457EB8CC9BB71FCA16D3EDBB67D603F0A9D46C131 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys
22:36:57.0195 0x1338 sffp_sd - ok
22:36:57.0228 0x1338 [ DB96666CC8312EBC45032F30B007A547, C3AE60FC65A36E96E0D2CC6E184481D70F91A19DC3E2E17E2873DD670A592DD7 ] sfloppy C:\Windows\system32\DRIVERS\sfloppy.sys
22:36:57.0230 0x1338 sfloppy - ok
22:36:57.0267 0x1338 [ D1A079A0DE2EA524513B6930C24527A2, E2BC16DBCF38841EECD49C6FA1A9AC89C17F332F12606CA826F058E995E1B83D ] SharedAccess C:\Windows\System32\ipnathlp.dll
22:36:57.0280 0x1338 SharedAccess - ok
22:36:57.0313 0x1338 [ 414DA952A35BF5D50192E28263B40577, 9C9BAFB9880DA6CC728506A142BE124E186219610DCC3460657A3CA93C865DF1 ] ShellHWDetection C:\Windows\System32\shsvcs.dll
22:36:57.0338 0x1338 ShellHWDetection - ok
22:36:57.0364 0x1338 [ 2565CAC0DC9FE0371BDCE60832582B2E, 1A775214E86B83C2F1799F12D71077D81C89AD32734A248BA88787B7F104B79D ] sisagp C:\Windows\system32\drivers\sisagp.sys
22:36:57.0367 0x1338 sisagp - ok
22:36:57.0412 0x1338 [ A9F0486851BECB6DDA1D89D381E71055, 7E909538AB758C18AC2CCBFFEE17BA36FA6ED2E674AA70924AA87AC61375FF35 ] SiSRaid2 C:\Windows\system32\DRIVERS\SiSRaid2.sys
22:36:57.0414 0x1338 SiSRaid2 - ok
22:36:57.0438 0x1338 [ 3727097B55738E2F554972C3BE5BC1AA, 75D52A596A298C33EC79A3B0B80F25492C08A182ABC679401502DA9597687566 ] SiSRaid4 C:\Windows\system32\DRIVERS\sisraid4.sys
22:36:57.0442 0x1338 SiSRaid4 - ok
22:36:57.0583 0x1338 [ 0B70786BD1062CD4C6B58E412B9C3E55, 60ED027642FFF97BFFA55AE3EFFCCBB6D6AD8196D35E9ED06F9AF431E3C0402A ] SkypeUpdate C:\Program Files\Skype\Updater\Updater.exe
22:36:57.0604 0x1338 SkypeUpdate - ok
22:36:57.0644 0x1338 [ 3E21C083B8A01CB70BA1F09303010FCE, 803F8F91299C387110F34A49340E7136AAE91B418E2977A36285EA8F432FF197 ] Smb C:\Windows\system32\DRIVERS\smb.sys
22:36:57.0651 0x1338 Smb - ok
22:36:57.0699 0x1338 [ 6A984831644ECA1A33FFEAE4126F4F37, 753E23D2B33D47C52C05D892B052CFD96D93B97FB6E9FCB58EF1E4C4A125BF78 ] SNMPTRAP C:\Windows\System32\snmptrap.exe
22:36:57.0702 0x1338 SNMPTRAP - ok
22:36:57.0757 0x1338 [ 95CF1AE7527FB70F7816563CBC09D942, CE8BACB91A5A86CBCE82619C6C1873B4D7593B00CED3B522E41B8F7F6258CC65 ] spldr C:\Windows\system32\drivers\spldr.sys
22:36:57.0759 0x1338 spldr - ok
22:36:57.0822 0x1338 [ 9AEA093B8F9C37CF45538382CABA2475, CC63239C412067AA72318ADB8BB80BCDF2CA60DA05D814D32753C92508BC16A8 ] Spooler C:\Windows\System32\spoolsv.exe
22:36:57.0827 0x1338 Spooler - ok
22:36:58.0004 0x1338 [ CF87A1DE791347E75B98885214CED2B8, 7AF4E03D751C951A4E5FBA28200DABFE6B3BF055490163EEEEA84EBA4D0F368A ] sppsvc C:\Windows\system32\sppsvc.exe
22:36:58.0178 0x1338 sppsvc - ok
22:36:58.0256 0x1338 [ B0180B20B065D89232A78A40FE56EAA6, 4D045B23AD58A8822BE9F20119744A8D47455469D54494745CEB099951DA60FF ] sppuinotify C:\Windows\system32\sppuinotify.dll
22:36:58.0256 0x1338 sppuinotify - ok
22:36:58.0315 0x1338 [ E4C2764065D66EA1D2D3EBC28FE99C46, 043AEF06A23069DD17675955C834690A5FD8F1948A05B3969F977E823C4E25F5 ] srv C:\Windows\system32\DRIVERS\srv.sys
22:36:58.0330 0x1338 srv - ok
22:36:58.0411 0x1338 [ 03F0545BD8D4C77FA0AE1CEEDFCC71AB, 4DF31206DF8F33C2975E23C7257ED930C4EDA8BC4E246D8FDA130BB583083ED0 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys
22:36:58.0411 0x1338 srv2 - ok
22:36:58.0491 0x1338 [ BE6BD660CAA6F291AE06A718A4FA8ABC, CD38939CFBA80B882D38099194FC1EBAE15A9D27A4D941DD03C55EC745E52E59 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys
22:36:58.0496 0x1338 srvnet - ok
22:36:58.0558 0x1338 [ D887C9FD02AC9FA880F6E5027A43E118, F38BAD90EC791368C37C21090302708D2DFB83ECE9096609AD9AA667B2E5592E ] SSDPSRV C:\Windows\System32\ssdpsrv.dll
22:36:58.0594 0x1338 SSDPSRV - ok
22:36:58.0663 0x1338 [ EF3458337D7341A05169CEFC73709264, C9D0AE966CFA02F7B72586C2A6E2AFA9818C9F4856A4E9625B79BC5A886FC193 ] SSPORT C:\Windows\system32\Drivers\SSPORT.sys
22:36:58.0663 0x1338 SSPORT - ok
22:36:58.0687 0x1338 [ D318F23BE45D5E3A107469EB64815B50, D74355E6FF215AA8CE53BC9DF16AF2740F2FC2FD754939478A3608BDA8C6DDA0 ] SstpSvc C:\Windows\system32\sstpsvc.dll
22:36:58.0695 0x1338 SstpSvc - ok
22:36:58.0766 0x1338 [ 3013B9B3791A4843FADF5CEFED399B1D, 52BCA3A59F435CE57076DA64C2BD959C9A16A7F5BC1FA0D312186E5C0B82C025 ] Steam Client Service C:\Program Files\Common Files\Steam\SteamService.exe
22:36:58.0797 0x1338 Steam Client Service - ok
22:36:58.0936 0x1338 [ 33F93263136F31F4151AA460ED1944CC, 1E9E78E095D0BC6F39F070F62EC2089AA229DA9A0B8F39D18FF75DA4B3B6CD20 ] Stereo Service C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
22:36:58.0967 0x1338 Stereo Service - ok
22:36:58.0998 0x1338 [ DB32D325C192B801DF274BFD12A7E72B, F089DBA719E22BC269720A6B840B873A4AF5639745DB0C3DBC8BD2F2839A1ABA ] stexstor C:\Windows\system32\DRIVERS\stexstor.sys
22:36:58.0998 0x1338 stexstor - ok
22:36:59.0040 0x1338 [ ED78DFAD8EFCDFBC89500492C4D14645, E642BC209693D0EACDDDD2386B4FFFA4CB1C9AB4FA431796900FC730677E09D4 ] STI Simulator C:\Windows\System32\PAStiSvc.exe
22:36:59.0056 0x1338 STI Simulator - ok
22:36:59.0136 0x1338 [ E1FB3706030FB4578A0D72C2FC3689E4, A62EC9AA4514CAF2A10C0A3AEF7A36F593A7E7DA370A3F130C24E1B612E19427 ] StiSvc C:\Windows\System32\wiaservc.dll
22:36:59.0150 0x1338 StiSvc - ok
22:36:59.0212 0x1338 [ E58C78A848ADD9610A4DB6D214AF5224, 1575A90EB22A4FB066459BDA00C6CAC10198C3C8C74493721EC6D34B51F50426 ] swenum C:\Windows\system32\drivers\swenum.sys
22:36:59.0212 0x1338 swenum - ok
22:36:59.0248 0x1338 [ A28BD92DF340E57B024BA433165D34D7, 889CC7FF143C3549982128473FF927CD80CF36485A347EF399C1271C8CE12CE4 ] swprv C:\Windows\System32\swprv.dll
22:36:59.0259 0x1338 swprv - ok
22:36:59.0350 0x1338 [ 36650D618CA34C9D357DFD3D89B2C56F, 7C3774E53DCF32CB3A4B3504E32D2A651E18467FA0A6AC4C7993C696741B704B ] SysMain C:\Windows\system32\sysmain.dll
22:36:59.0398 0x1338 SysMain - ok
22:36:59.0460 0x1338 [ 763FECDC3D30C815FE72DD57936C6CD1, 1A62C7E63E426D56894F4121C75D9C60FC9A14469ADBD0D6F0B94B8DE48CDA3E ] TabletInputService C:\Windows\System32\TabSvc.dll
22:36:59.0460 0x1338 TabletInputService - ok
22:36:59.0490 0x1338 [ 613BF4820361543956909043A265C6AC, FCFF02E466D2501630B452627FB218C01E5245A0921EE3D2117E7FD63AC7E98E ] TapiSrv C:\Windows\System32\tapisrv.dll
22:36:59.0506 0x1338 TapiSrv - ok
22:36:59.0537 0x1338 [ B799D9FDB26111737F58288D8DC172D9, 409A60819A4305699E2E492A6190637FAAEBD19E745A5DB2A5D6977106C86591 ] TBS C:\Windows\System32\tbssvc.dll
22:36:59.0537 0x1338 TBS - ok
22:36:59.0650 0x1338 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] Tcpip C:\Windows\system32\drivers\tcpip.sys
22:36:59.0714 0x1338 Tcpip - ok
22:36:59.0825 0x1338 [ 5579DD18546999F5D0EC39D018726C6B, 82432BACEE75C34F21222D9CC1607223C2940947118A63DB239777A4B1442AD3 ] TCPIP6 C:\Windows\system32\DRIVERS\tcpip.sys
22:36:59.0886 0x1338 TCPIP6 - ok
22:36:59.0958 0x1338 [ 3EEBD3BD93DA46A26E89893C7AB2FF3B, 2C7204DCD2BCBC6A250FF0F6477616F327AF41FDB7CABE69E5C357361009FB4E ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys
22:36:59.0959 0x1338 tcpipreg - ok
22:37:00.0034 0x1338 [ 1CB91B2BD8F6DD367DFC2EF26FD751B2, 879E2827354BB21573AC6A7CCEB746D44214540687E6882FFCB4089546FBD954 ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys
22:37:00.0037 0x1338 TDPIPE - ok
22:37:00.0119 0x1338 [ 2C2C5AFE7EE4F620D69C23C0617651A8, E828D974C3F9D7004A030C3AD448096C736FDB4C4C1707D043E567D08C845103 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys
22:37:00.0122 0x1338 TDTCP - ok
22:37:00.0168 0x1338 [ 7FE680A3DFA421C4A8E4879AE4C5AAB0, A4C64E155AB2843823CD3586756BA7681CFDEA50812095468221503BBAD30DCD ] tdx C:\Windows\system32\DRIVERS\tdx.sys
22:37:00.0168 0x1338 tdx - ok
22:37:00.0199 0x1338 [ 04DBF4B01EA4BF25A9A3E84AFFAC9B20, 0D81B427720637882077C5024D738191F858FC734ED040697872D906351EF663 ] TermDD C:\Windows\system32\drivers\termdd.sys
22:37:00.0215 0x1338 TermDD - ok
22:37:00.0359 0x1338 [ FCFD4F50419B4BC72E80066DA10D2E54, 7C2314A57A404525F0444986332DBAE0964A3359374671598387051D7AAE72AE ] TermService C:\Windows\System32\termsrv.dll
22:37:00.0406 0x1338 TermService - ok
22:37:00.0453 0x1338 [ 42FB6AFD6B79D9FE07381609172E7CA4, B57C85091209A2FAD19ED490B8FA7FC98F12911F9C9CACE9AF1E540780CE6700 ] Themes C:\Windows\system32\themeservice.dll
22:37:00.0453 0x1338 Themes - ok
22:37:00.0479 0x1338 [ 146B6F43A673379A3C670E86D89BE5EA, C4412DCF80DE6B55466F399413271364F14BC0819C224AA161EDDC31A9775440 ] THREADORDER C:\Windows\system32\mmcss.dll
22:37:00.0479 0x1338 THREADORDER - ok
22:37:00.0510 0x1338 [ 4792C0378DB99A9BC2AE2DE6CFFF0C3A, 532A3A812578B2DFD83001DE66FC73689D79EC729409EB572E07E6D65B281712 ] TrkWks C:\Windows\System32\trkwks.dll
22:37:00.0525 0x1338 TrkWks - ok
22:37:00.0603 0x1338 [ 2C49B175AEE1D4364B91B531417FE583, 6C7995E18F84E465C376D1D5F153C15ACB66CDEA86EE5BF186677F572E7E129B ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe
22:37:00.0620 0x1338 TrustedInstaller - ok
22:37:00.0707 0x1338 [ 6C5139E4283249518F7743D7043775B3, 58684E8C90EBAC65459A97C905CDCFE3A915CFF7E8E96071DE1AC3489F85E67F ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys
22:37:00.0708 0x1338 tssecsrv - ok
22:37:00.0768 0x1338 [ C6A5FBD4977305E1FA23E02C042DB463, A6EB5E4B8051A258D40A385609E930318EAA3494C8466F48542B806FE6A7C47A ] TsUsbFlt C:\Windows\system32\drivers\tsusbflt.sys
22:37:00.0768 0x1338 TsUsbFlt - ok
22:37:00.0857 0x1338 [ B2FA25D9B17A68BB93D58B0556E8C90D, 0146931B733CAB1CD87F94C35F97E110D6ED6C55EAFF03345400A29AEDE99BDE ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys
22:37:00.0872 0x1338 tunnel - ok
22:37:00.0903 0x1338 [ 750FBCB269F4D7DD2E420C56B795DB6D, E1A95C59148FE463539C34336FD0E74B31A33B8AB2B8E34AA10349C3347471D7 ] uagp35 C:\Windows\system32\DRIVERS\uagp35.sys
22:37:00.0903 0x1338 uagp35 - ok
22:37:00.0953 0x1338 [ EE43346C7E4B5E63E54F927BABBB32FF, BAD6FC3BEE45E644D5A6A0A31428F5B2AEC72A0AA0C74EF8177B1FE23EEF3AA9 ] udfs C:\Windows\system32\DRIVERS\udfs.sys
22:37:00.0962 0x1338 udfs - ok
22:37:00.0996 0x1338 [ 8344FD4FCE927880AA1AA7681D4927E5, 1B54EFA60A221E2B9FFE59BB41C7E7D8B5AC6826F1C5577456D81371D464255A ] UI0Detect C:\Windows\system32\UI0Detect.exe
22:37:01.0012 0x1338 UI0Detect - ok
22:37:01.0049 0x1338 [ 44E8048ACE47BEFBFDC2E9BE4CBC8880, 5D96D90FDF68AE470CC92CA9DF9DA2C05A53EF455A5A109DBBF7C96F3238257C ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys
22:37:01.0065 0x1338 uliagpkx - ok
22:37:01.0158 0x1338 [ D295BED4B898F0FD999FCFA9B32B071B, D4130DB4AE76EE6DC0B8E7A4FEF5CB8B26EBD822C21021F6FA78FD29C1E211C2 ] umbus C:\Windows\system32\drivers\umbus.sys
22:37:01.0158 0x1338 umbus - ok
22:37:01.0208 0x1338 [ 7550AD0C6998BA1CB4843E920EE0FEAC, 24C001E422C3B3B920CDCF6003A3179CE464DE4284775403DD5122EF9780460D ] UmPass C:\Windows\system32\DRIVERS\umpass.sys
22:37:01.0208 0x1338 UmPass - ok
22:37:01.0271 0x1338 [ 833FBB672460EFCE8011D262175FAD33, C0C3067A305993CBF056C229771CB0593DD60C9C7AC5130FF1CA610BCA812AB5 ] upnphost C:\Windows\System32\upnphost.dll
22:37:01.0271 0x1338 upnphost - ok
22:37:01.0335 0x1338 [ 0803FBA9FE829D61AE26EC0BCC910C46, 30D00E2C7DFC630C99C1599587D4F9C272BC30D444E07C961AA05BF84587806B ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys
22:37:01.0335 0x1338 usbccgp - ok
22:37:01.0431 0x1338 [ 2352AB5F9F8F097BF9D41D5A4718A041, 25BC7828C625B9B2A5110C25B230C5828CEC18EC97ECF9EC4745E8930CBF472C ] usbcir C:\Windows\system32\drivers\usbcir.sys
22:37:01.0446 0x1338 usbcir - ok
22:37:01.0462 0x1338 [ D40855F89B69305140BBD7E9A3BA2DA6, 745DC6D770666F6B19C2B6AA89C21D1A314732E291453BFA2367F9AF86F97C3C ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys
22:37:01.0462 0x1338 usbehci - ok
22:37:01.0509 0x1338 [ EDF2DF71C4F1E13A6AC75F5224DE655A, 1764D155C6B99201774B57195349304259232A12868ECFC2069CA49443EBDC2C ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys
22:37:01.0509 0x1338 usbhub - ok
22:37:01.0536 0x1338 [ 9828C8D14CC2676421778F0DE638CF97, 479A28211FFB85190A01FAB0283B927588805D2C0CDB03F85F8F814B88E4F453 ] usbohci C:\Windows\system32\DRIVERS\usbohci.sys
22:37:01.0536 0x1338 usbohci - ok
22:37:01.0568 0x1338 [ 797D862FE0875E75C7CC4C1AD7B30252, 1BBE745E4C85F8911076F6032ACD7A35FAC048D3CB1500C64E08D8B2C70A1069 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys
22:37:01.0568 0x1338 usbprint - ok
22:37:01.0599 0x1338 [ F991AB9CC6B908DB552166768176896A, AD8E7A16B23B244B7F834622D4E38B5844193C6E31EF96F61E0E2EA16C945026 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS
22:37:01.0599 0x1338 USBSTOR - ok
22:37:01.0678 0x1338 [ 800AABFD625EEFF899F7E5496BDE37AB, 3EB7ED07760CB348FCA9A06C2B838EF79B51A83C5F70A9C9EAAEAE54480067E2 ] usbuhci C:\Windows\system32\drivers\usbuhci.sys
22:37:01.0678 0x1338 usbuhci - ok
22:37:01.0773 0x1338 [ 081E6E1C91AEC36758902A9F727CD23C, 9FDAA17A3B99067E035E5D76305427F15FFDBC5D304B2BB78AFC6463EDDE1A75 ] UxSms C:\Windows\System32\uxsms.dll
22:37:01.0773 0x1338 UxSms - ok
22:37:01.0903 0x1338 [ 1A4BEC8BBAF03C7A69F1D8B2FE03CB9D, 60FBEC25277FA661227BBB5CEA1FB75219E4F04B1D31B8D455BC004C4A2DB430 ] VASDeviceDrm C:\Windows\system32\drivers\vasdDev.sys
22:37:01.0969 0x1338 VASDeviceDrm - ok
22:37:01.0994 0x1338 [ 981CE3E3A653511799F4A862494B66A8, 414D975387A118535E39636413969A7D4C98A85E542A44B8FA515C8A20D6093F ] VaultSvc C:\Windows\system32\lsass.exe
22:37:01.0997 0x1338 VaultSvc - ok
22:37:02.0050 0x1338 [ 1EED8E78D92E81B08FC1823E63E0E447, B460A284AA8F57B3BC6F0BA86F3EAD5856D70109307CF90A1726F25B227D0715 ] VCam_WDM C:\Windows\system32\DRIVERS\VCam_WDM.sys
22:37:02.0066 0x1338 VCam_WDM - ok
22:37:02.0129 0x1338 [ B2ABAB4CA46BAD182E27763DC19C780F, D581C2EAD3CEE2FEE8A1B6B0A4088518E78DC63FF38CB3CABA3F9CDC1367D9A9 ] VCSVADHWSer C:\Windows\system32\DRIVERS\vcsvad.sys
22:37:02.0145 0x1338 VCSVADHWSer - ok
22:37:02.0176 0x1338 [ A059C4C3EDB09E07D21A8E5C0AABD3CB, BDD3729B49DF2E2FC72FFEF9D10235B481A671DE5A721B6B9A80873B7A343F07 ] vdrvroot C:\Windows\system32\drivers\vdrvroot.sys
22:37:02.0192 0x1338 vdrvroot - ok
22:37:02.0281 0x1338 [ C3CD30495687C2A2F66A65CA6FD89BE9, 582E4706C1D6A151020D14B26C7BF166F4E42BDD6E410F30EC452469270C5E9B ] vds C:\Windows\System32\vds.exe
22:37:02.0325 0x1338 vds - ok
22:37:02.0369 0x1338 [ 17C408214EA61696CEC9C66E388B14F3, 829C0416672E2B2DFABCFE641E7F281F41E8DBB3C0EF11C7784CB9BB94F87E97 ] vga C:\Windows\system32\DRIVERS\vgapnp.sys
22:37:02.0371 0x1338 vga - ok
22:37:02.0388 0x1338 [ 8E38096AD5C8570A6F1570A61E251561, 4DBA3C1397A2203548F45F006E66D99F837903F601ABBCE2304754F783CA8A39 ] VgaSave C:\Windows\System32\drivers\vga.sys
22:37:02.0390 0x1338 VgaSave - ok
22:37:02.0456 0x1338 [ 5461686CCA2FDA57B024547733AB42E3, 2721D0659AA890172FCAD4EC4D926B58ACD0EE4887DA51545DC7237420D5BF84 ] vhdmp C:\Windows\system32\drivers\vhdmp.sys
22:37:02.0462 0x1338 vhdmp - ok
22:37:02.0505 0x1338 [ C829317A37B4BEA8F39735D4B076E923, 55D1796AE750071E1E05BD7702B6C355CCFFE27B4C00E93E7044C3184732B497 ] viaagp C:\Windows\system32\drivers\viaagp.sys
22:37:02.0507 0x1338 viaagp - ok
22:37:02.0548 0x1338 [ E02F079A6AA107F06B16549C6E5C7B74, B530DCE3EE4F285B3D5F69F7148D17E016D54F04E6F93706B829A34567748788 ] ViaC7 C:\Windows\system32\DRIVERS\viac7.sys
22:37:02.0551 0x1338 ViaC7 - ok
22:37:02.0595 0x1338 [ E43574F6A56A0EE11809B48C09E4FD3C, 3687BF638E21C00E62ABFED70D728B91ADA08F7164CA898E654F31DA196589E9 ] viaide C:\Windows\system32\drivers\viaide.sys
22:37:02.0597 0x1338 viaide - ok
22:37:02.0626 0x1338 [ 4C63E00F2F4B5F86AB48A58CD990F212, 9796BD4B9CFEEEAF57C5E332A732EFC2770B21F9B35301A5D202F5FC52C1E035 ] volmgr C:\Windows\system32\drivers\volmgr.sys
22:37:02.0629 0x1338 volmgr - ok
22:37:02.0657 0x1338 [ B5BB72067DDDDBBFB04B2F89FF8C3C87, 65B9AD55F43940A5FDD88B6EC5034A7E375DF8E6F5F1AE6519A4BD6B7E992EBC ] volmgrx C:\Windows\system32\drivers\volmgrx.sys
22:37:02.0673 0x1338 volmgrx - ok
22:37:02.0704 0x1338 [ F497F67932C6FA693D7DE2780631CFE7, DAE544ED99D2CF570DA31343BD87D2F856D0D13529656D38E1BF854C77F017F6 ] volsnap C:\Windows\system32\drivers\volsnap.sys
22:37:02.0721 0x1338 volsnap - ok
22:37:02.0782 0x1338 [ A53AAF4277D17F75DAE897846A3023AF, D6E0BA2A8B7816738BD0D89446575A337E6A1799BB8CAB1EE30CC156C7BBC9DB ] voxaldriver C:\Windows\system32\DRIVERS\voxaldriverx86.sys
22:37:02.0782 0x1338 voxaldriver - ok
22:37:02.0834 0x1338 [ 9DFA0CC2F8855A04816729651175B631, 37FD9E43A2A3F125E94A315FB4CD8A1B5499A5FD74806EB2D1E5DA88C070D3A3 ] vsmraid C:\Windows\system32\DRIVERS\vsmraid.sys
22:37:02.0839 0x1338 vsmraid - ok
22:37:02.0950 0x1338 [ 209A3B1901B83AEB8527ED211CCE9E4C, 1A431F6409F8E0531F600F8F988ECECECB902DA26BBAAF1DE74A5CAC29A7CB44 ] VSS C:\Windows\system32\vssvc.exe
22:37:03.0007 0x1338 VSS - ok
22:37:03.0028 0x1338 [ 90567B1E658001E79D7C8BBD3DDE5AA6, EFC23BEEA7F54A2DC56CB523DAD1AF0358D904C5278BF08873910E2DB3F13557 ] vwifibus C:\Windows\System32\drivers\vwifibus.sys
22:37:03.0058 0x1338 vwifibus - ok
22:37:03.0089 0x1338 [ 55187FD710E27D5095D10A472C8BAF1C, AE298E2D3BA366BCBDC092C717214C181E8843FA564A6DFB07FC3238A5A68DC3 ] W32Time C:\Windows\system32\w32time.dll
22:37:03.0105 0x1338 W32Time - ok
22:37:03.0152 0x1338 [ DE3721E89C653AA281428C8A69745D90, 501C78056ED4295625D8A5412025FD2F0CA24077044D3A5800BA79DF3D946516 ] WacomPen C:\Windows\system32\DRIVERS\wacompen.sys
22:37:03.0152 0x1338 WacomPen - ok
22:37:03.0199 0x1338 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] WANARP C:\Windows\system32\DRIVERS\wanarp.sys
22:37:03.0199 0x1338 WANARP - ok
22:37:03.0215 0x1338 [ 3C3C78515F5AB448B022BDF5B8FFDD2E, 35284174A42039C3C1FF8A3C8BC187A5E067C7782FC62D19749C2CB28C4E36C7 ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys
22:37:03.0215 0x1338 Wanarpv6 - ok
22:37:03.0294 0x1338 [ 691E3285E53DCA558E1A84667F13E15A, 12EDB66EF8FC100402BEA221F354D3BD5542F6DDF715B6E7D873D6BAE7E3D329 ] wbengine C:\Windows\system32\wbengine.exe
22:37:03.0345 0x1338 wbengine - ok
22:37:03.0377 0x1338 [ 9614B5D29DC76AC3C29F6D2D3AA70E67, A2FFB92F0030B4CD771E862DA575ECCF2F3A5B4B85858C1241A0C59262C0EC88 ] WbioSrvc C:\Windows\System32\wbiosrvc.dll
22:37:03.0392 0x1338 WbioSrvc - ok
22:37:03.0441 0x1338 [ 34EEE0DFAADB4F691D6D5308A51315DC, A040A03E25A0C78B9E26F86C2DF95BCAF8E7EC90183CEB295615D3265350EBEE ] wcncsvc C:\Windows\System32\wcncsvc.dll
22:37:03.0457 0x1338 wcncsvc - ok
22:37:03.0488 0x1338 [ 5D930B6357A6D2AF4D7653BDABBF352F, 677FF2ED14EE0B0CAA710DA81556CC16D5971DAB10E7C7432D167A87CA6F0EAA ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll
22:37:03.0488 0x1338 WcsPlugInService - ok
22:37:03.0519 0x1338 [ 1112A9BADACB47B7C0BB0392E3158DFF, 1AE2AFA125973571F91E6945FE8A735F63D76EBB250A0075D98C580167FD9ED4 ] Wd C:\Windows\system32\DRIVERS\wd.sys
22:37:03.0519 0x1338 Wd - ok
22:37:03.0598 0x1338 [ 25944D2CC49E0A6C581D02A74B7D6645, AF8FFAFEC07F1A6A3D4008E609E8E1D705A8DFCC7995C766E3946887203F7BEE ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys
22:37:03.0629 0x1338 Wdf01000 - ok
22:37:03.0677 0x1338 [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiServiceHost C:\Windows\system32\wdi.dll
22:37:03.0693 0x1338 WdiServiceHost - ok
22:37:03.0708 0x1338 [ DDE994E9159497D0D5AB2CDF66D1EAD6, 49BEDECA469C47E7622542D3B9BCD31ECDDAA27838495EC5C2F1338E33FEA877 ] WdiSystemHost C:\Windows\system32\wdi.dll
22:37:03.0708 0x1338 WdiSystemHost - ok
22:37:03.0780 0x1338 [ 75E8EBD7040CE238684333F97014762A, 2CA0B267FBAEB303D1F8B639D733DC0DE17BA1276CC9096035B4F2BBBED3EF7F ] WebClient C:\Windows\System32\webclnt.dll
22:37:03.0811 0x1338 WebClient - ok
22:37:03.0858 0x1338 [ 760F0AFE937A77CFF27153206534F275, A53940BA28854486FF18F16B98A3314B36322B0B6EFB54D08B921315BEB0ADD5 ] Wecsvc C:\Windows\system32\wecsvc.dll
22:37:03.0873 0x1338 Wecsvc - ok
22:37:03.0889 0x1338 [ AC804569BB2364FB6017370258A4091B, 1856F354146A5946F3E7D0DD09726FC8A3502B0F0776FEADDF10669C81CC28E2 ] wercplsupport C:\Windows\System32\wercplsupport.dll
22:37:03.0904 0x1338 wercplsupport - ok
22:37:03.0937 0x1338 [ 08E420D873E4FD85241EE2421B02C4A4, E1E9436EB096FF7DE9A76DA6217035257EF9FC7565DDB9016DCA3859E7F1EF0F ] WerSvc C:\Windows\System32\WerSvc.dll
22:37:03.0943 0x1338 WerSvc - ok
22:37:04.0023 0x1338 [ 319828CB5E92CD4A134340871B71BC15, FB50E9CAC70774F0DA09C6445D8AC7E7AE084E46508FEEC893748CC28248BC87 ] WFLR6654 C:\Windows\system32\drivers\wfeaglxt.sys
22:37:04.0037 0x1338 WFLR6654 - ok
22:37:04.0060 0x1338 [ 8B9A943F3B53861F2BFAF6C186168F79, 88E2F79F32AFBA17CB8377A508B83A1EC2315E9F3A365F591C87FE4525AA6713 ] WfpLwf C:\Windows\system32\DRIVERS\wfplwf.sys
22:37:04.0060 0x1338 WfpLwf - ok
22:37:04.0091 0x1338 [ 5CF95B35E59E2A38023836FFF31BE64C, CEA21302B3E855EE592810D4E0DE10E47A47A393064C435463CD54598735CD8D ] WIMMount C:\Windows\system32\drivers\wimmount.sys
22:37:04.0091 0x1338 WIMMount - ok
22:37:04.0184 0x1338 [ 082CF481F659FAE0DE51AD060881EB47, BB67D2AF0BB9192D4CCF66C23D80CE5A1B38715556D94E2561DBF8F805FA30A5 ] WinDefend C:\Program Files\Windows Defender\mpsvc.dll
22:37:04.0215 0x1338 WinDefend - ok
22:37:04.0231 0x1338 WinHttpAutoProxySvc - ok
22:37:04.0277 0x1338 [ F62E510B6AD4C21EB9FE8668ED251826, FA3E5CAC3E67E49377320CFBE4646585E6B62168292768FEA81E4623F9166890 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll
22:37:04.0294 0x1338 Winmgmt - ok
22:37:04.0419 0x1338 [ 1DE9BD23AFA36150586C732D876D9B74, 32CF2C8EC18CFDA677AB72A182EB4B839DCC72BFCD6CA309BE2F434991CAE973 ] WinRM C:\Windows\system32\WsmSvc.dll
22:37:04.0485 0x1338 WinRM - ok
22:37:04.0550 0x1338 [ A67E5F9A400F3BD1BE3D80613B45F708, E170A8BD31A779403DC9C43ED6483DA8E186512D3EE700B87F6BA292E284E367 ] WinUsb C:\Windows\system32\DRIVERS\WinUsb.sys
22:37:04.0550 0x1338 WinUsb - ok
22:37:04.0612 0x1338 [ 16935C98FF639D185086A3529B1F2067, E9C6B73A572A04FCE9B1B0E6815F941B10332D9A6D55B92927C2B1275F119091 ] Wlansvc C:\Windows\System32\wlansvc.dll
22:37:04.0659 0x1338 Wlansvc - ok
22:37:04.0769 0x1338 [ FB01D4AE207B9EFDBABFC55DC95C7E31, E0EFDBBE0BAC275230C8C1A053948C21BCF20B99B92E50939E95FFB9DC87F6BA ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
22:37:04.0895 0x1338 wlidsvc - ok
22:37:04.0943 0x1338 [ 0217679B8FCA58714C3BF2726D2CA84E, 4494984B922DCF24D37BCD0E6831CEBD07D1CA49235D04E821D17ED3DF84ED2A ] WmiAcpi C:\Windows\system32\drivers\wmiacpi.sys
22:37:04.0943 0x1338 WmiAcpi - ok
22:37:04.0989 0x1338 [ 6EB6B66517B048D87DC1856DDF1F4C3F, EBB534C4829477C70062ADBB5626236B02FE563A544C53FA255E79F3CA170FE8 ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe
22:37:04.0989 0x1338 wmiApSrv - ok
22:37:05.0189 0x1338 [ 3B40D3A61AA8C21B88AE57C58AB3122E, 6C67DCB007C3CDF2EB0BBF5FD89C32CD7800C20F7166872F8C387BE262C5CD21 ] WMPNetworkSvc C:\Program Files\Windows Media Player\wmpnetwk.exe
22:37:05.0267 0x1338 WMPNetworkSvc - ok
22:37:05.0304 0x1338 [ A2F0EC770A92F2B3F9DE6D518E11409C, 6838F2148B11285E00DC449D51F8AD85AAE57694E89BA2C607B87AC1C650D845 ] WPCSvc C:\Windows\System32\wpcsvc.dll
22:37:05.0307 0x1338 WPCSvc - ok
22:37:05.0374 0x1338 [ AA53356D60AF47EACC85BC617A4F3F66, 155CB8112AA382D841C1891750FF29EF4F1BF716CD9CDF0F2243209E2CCCAC98 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll
22:37:05.0374 0x1338 WPDBusEnum - ok
22:37:05.0421 0x1338 [ 6DB3276587B853BF886B69528FDB048C, 9972FF6DF0DF6F86D1E9BCEF4C29064748B217DA196B0633C30D3D580144951C ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys
22:37:05.0421 0x1338 ws2ifsl - ok
22:37:05.0473 0x1338 [ 6F5D49EFE0E7164E03AE773A3FE25340, 15B6AFF7455538189A96F8863CC995A271E02C6FBDAC15B037D44DDA65E61339 ] wscsvc C:\Windows\System32\wscsvc.dll
22:37:05.0489 0x1338 wscsvc - ok
22:37:05.0505 0x1338 WSearch - ok
22:37:05.0688 0x1338 [ B5202CD63C502A16F6C94186089CF602, 0C4B3F92318D81B67820524D71618333539FEAD2877D8ABA5D7D82E66A9A6417 ] wuauserv C:\Windows\system32\wuaueng.dll
22:37:05.0761 0x1338 wuauserv - ok
22:37:05.0808 0x1338 [ 06E6F32C8D0A3F66D956F57B43A2E070, 9A6BD96A28294B0372F16E13D652FD603308F64B74A56E41E0C68C5E8011F943 ] WudfPf C:\Windows\system32\drivers\WudfPf.sys
22:37:05.0825 0x1338 WudfPf - ok
22:37:05.0862 0x1338 [ 867C301E8B790040AE9CF6486E8041DF, D867D6498C987944D99508B2FAD6D6B749FA1EDFE8124B0863D4A642352F0855 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys
22:37:05.0862 0x1338 WUDFRd - ok
22:37:05.0893 0x1338 [ FE47B7BC8EA320C2D9B5E5BF6E303765, 34518DBD1E9EA6E5DA62273B18613761E1D9C6B4E074A93C6D639FBAF02222EA ] wudfsvc C:\Windows\System32\WUDFSvc.dll
22:37:05.0893 0x1338 wudfsvc - ok
22:37:05.0958 0x1338 [ 7CC38741B8F68F1E0D5D79DA6123666A, F90D2DA1C9AFB506C381CD386E1430931B5F81813FEDFD720F87FBC54E7A00DA ] WwanSvc C:\Windows\System32\wwansvc.dll
22:37:05.0958 0x1338 WwanSvc - ok
22:37:05.0990 0x1338 xhunter1 - ok
22:37:06.0026 0x1338 ================ Scan global ===============================
22:37:06.0078 0x1338 [ DAB748AE0439955ED2FA22357533DDDB, 73EDD402C7479DDCE1998D0C7E99E1EC2974F64EFC33A851439CC85D09EDCDF9 ] C:\Windows\system32\basesrv.dll
22:37:06.0126 0x1338 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
22:37:06.0156 0x1338 [ 51BB04243DF6196C06E125898127E397, E1B6C83FC6E455F6806185027C5B56F8BA9ECDF1CD69E97301EC0291F0D3466E ] C:\Windows\system32\winsrv.dll
22:37:06.0185 0x1338 [ 364455805E64882844EE9ACB72522830, 906561DBBB33F744844CF27E456226044C85DF0FCFD26DE1FD11E09E2CFA6F8F ] C:\Windows\system32\sxssrv.dll
22:37:06.0247 0x1338 [ 5F1B6A9C35D3D5CA72D6D6FDEF9747D6, D7BC4ED605B32274B45328FD9914FB0E7B90D869A38F0E6F94FB1BF4E9E2B407 ] C:\Windows\system32\services.exe
22:37:06.0278 0x1338 [ Global ] - ok
22:37:06.0285 0x1338 ================ Scan MBR ==================================
22:37:06.0310 0x1338 [ 413FC2A0C716421B3158746D63736515 ] \Device\Harddisk1\DR1
22:37:06.0401 0x1338 \Device\Harddisk1\DR1 - ok
22:37:06.0413 0x1338 [ A36C5E4F47E84449FF07ED3517B43A31 ] \Device\Harddisk0\DR0
22:37:06.0920 0x1338 \Device\Harddisk0\DR0 - ok
22:37:06.0924 0x1338 ================ Scan VBR ==================================
22:37:06.0935 0x1338 [ E00F8DD5CC0086A9923705313C3EB863 ] \Device\Harddisk1\DR1\Partition1
22:37:06.0948 0x1338 \Device\Harddisk1\DR1\Partition1 - ok
22:37:06.0962 0x1338 [ 1D8AD19EDEF2B282D8DBF1E6B28643CA ] \Device\Harddisk0\DR0\Partition1
22:37:06.0962 0x1338 \Device\Harddisk0\DR0\Partition1 - ok
22:37:06.0977 0x1338 [ 6E4D5230663A9569412007D03039EF17 ] \Device\Harddisk0\DR0\Partition2
22:37:06.0977 0x1338 \Device\Harddisk0\DR0\Partition2 - ok
22:37:06.0993 0x1338 ================ Scan generic autorun ======================
22:37:07.0119 0x1338 [ F4AD88FF508A573E3EC7C8E0E4760328, A2FD2357706EB8FE7708B7874F3AA507923C2676BDA84055F5903491EDE76C82 ] C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe
22:37:07.0134 0x1338 ASUS Update Checker - ok
22:37:07.0240 0x1338 [ 53C6C41356D532FEFD8056AB2906D129, C5E54C571FA44AF7FD1974464CC5D5DD30BA0D31ED20CF6B3DBB5A49FC5F0AC7 ] C:\Program Files\Skillbrains\lightshot\Lightshot.exe
22:37:07.0244 0x1338 Lightshot - ok
22:37:07.0379 0x1338 [ 441FDEFD887CB7EBEFC6F84BD147DD56, 5E6B3374BA2391A3DDC2AA1E15BE6DBE20FCA6BF364304A35E3EDC307AC856AC ] C:\Program Files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe
22:37:07.0412 0x1338 StartCCC - ok
22:37:08.0025 0x1338 [ AF2F89E2F43D80C6878F1A177EFE9D9C, 04384F29F2F641945C90372BD0659D9378A8A0CDA7A51DBB7430BC90E06DC005 ] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
22:37:08.0502 0x1338 RTHDVCPL - ok
22:37:08.0608 0x1338 [ 9153F2335BCDB87F41559CF066223BF9, C0F89F9A63B1F49F007A971F5180128EC0AFBBBF7CFA82CA1FA44CB9DB5F8BB3 ] C:\Program Files\Common Files\Java\Java Update\jusched.exe
22:37:08.0624 0x1338 SunJavaUpdateSched - ok
22:37:08.0728 0x1338 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
22:37:08.0782 0x1338 Sidebar - ok
22:37:08.0815 0x1338 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
22:37:08.0821 0x1338 mctadmin - ok
22:37:08.0882 0x1338 [ DCCA4B04AF87E52EF9EAA2190E06CBAC, 8858CFD159BB32AE9FCCA1A79EA83C876D481A286E914071D48F42FCA5B343D8 ] C:\Program Files\Windows Sidebar\Sidebar.exe
22:37:08.0897 0x1338 Sidebar - ok
22:37:08.0928 0x1338 [ BBA1A5B86134F496B926DDAF247DB871, 636990AE49C55189B7EF69C419787440B57EC0BAD98A9C280E1028F741BB222E ] C:\Windows\System32\mctadmin.exe
22:37:08.0928 0x1338 mctadmin - ok
22:37:09.0090 0x1338 [ 177C7E1FB4793BFCC6B06D11D8032481, E929662796B17B361E4A1B5E2F004C60B9A396A46F980F7C3B1E9D9912F68870 ] C:\Users\PC\AppData\Roaming\Seznam.cz\bin\wszndesktop.exe
22:37:09.0105 0x1338 cz.seznam.software.szndesktop - ok
22:37:09.0198 0x1338 [ 919F88F5158350947FB255358CEA4907, E67E46DD7185A2B7928BDFFA7893CBF7D4BB92E4881F38E9DDB5E582D2D2D48E ] C:\Users\PC\AppData\Roaming\Seznam.cz\szninstall.exe
22:37:09.0238 0x1338 cz.seznam.software.autoupdate - ok
22:37:09.0458 0x1338 [ F73154E180105822A5F9B755BA933737, 1CD775B6CE3736A70EC5FC7A6B77A2FEDA70D59B49A66046CC20B341005501D9 ] C:\Program Files\DAEMON Tools Lite\DTLite.exe
22:37:09.0595 0x1338 DAEMON Tools Lite - ok
22:37:09.0823 0x1338 [ 71B8F5AD8CB230DD3ABA063701789CB1, A54E29953BD6D2F3303AF9514F05A1D394790B5ADB74FE833D9FA895AD61DFBF ] C:\Users\Filip\AppData\Roaming\Spotify\SpotifyWebHelper.exe
22:37:09.0886 0x1338 Spotify Web Helper - ok
22:37:10.0268 0x1338 [ 5721B5C4CBEBBD0C85AE311366783386, C2A780D6F49A0F75CF53C6A032BC9C4494D6F0FB5A0B767845AE5052179C7C40 ] C:\Users\Filip\AppData\Local\Akamai\netsession_win.exe
22:37:10.0472 0x1338 Akamai NetSession Interface - ok
22:37:10.0679 0x1338 [ 5721B5C4CBEBBD0C85AE311366783386, C2A780D6F49A0F75CF53C6A032BC9C4494D6F0FB5A0B767845AE5052179C7C40 ] C:\Users\Filip\AppData\Local\Akamai\netsession_win.exe
22:37:10.0812 0x1338 Akamai NetSession Interface - ok
22:37:11.0140 0x1338 [ 3D01BD151A423F6B7D89970E42E31E46, CA1B7619A387E94A033D3143B782DEEC30C9F9E528B52822E7CB35D1C617F349 ] C:\Program Files\CCleaner\CCleaner.exe
22:37:11.0373 0x1338 CCleaner Monitoring - ok
22:37:11.0389 0x1338 Ection - ok
22:37:11.0420 0x1338 [ 432BE6CF7311062633459EEF6B242FB5, 890C1734ED1EF6B2422A9B21D6205CF91E014ADD8A7F41AA5A294FCF60631A7B ] C:\Windows\System32\regsvr32.exe
22:37:11.0436 0x1338 Icsoft - ok
22:37:11.0576 0x1338 [ F73154E180105822A5F9B755BA933737, 1CD775B6CE3736A70EC5FC7A6B77A2FEDA70D59B49A66046CC20B341005501D9 ] C:\Program Files\DAEMON Tools Lite\DTLite.exe
22:37:11.0654 0x1338 DAEMON Tools Lite - ok
22:37:11.0710 0x1338 Waiting for KSN requests completion. In queue: 67
22:37:12.0711 0x1338 Waiting for KSN requests completion. In queue: 67
22:37:13.0720 0x1338 Waiting for KSN requests completion. In queue: 67
22:37:14.0768 0x1338 AV detected via SS2: Microsoft Security Essentials, C:\Program Files\Microsoft Security Client\msseces.exe ( 4.4.304.0 ), 0x60000 ( disabled : updated )
22:37:14.0768 0x1338 Win FW state via NFP2: enabled ( trusted )
22:37:17.0483 0x1338 ============================================================
22:37:17.0483 0x1338 Scan finished
22:37:17.0483 0x1338 ============================================================
22:37:17.0499 0x1350 Detected object count: 0
22:37:17.0499 0x1350 Actual detected object count: 0
22:37:22.0448 0x1348 Deinitialize success

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#6 Příspěvek od Filip.R. »

ComboFix 15-08-18.01 - Filip 19.08.2015 19:36:05.1.1 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1250.420.1029.18.3198.1670 [GMT 2:00]
Spuštěný z: c:\users\Filip\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {641105E6-77ED-3F35-A304-765193BCB75F}
SP: Microsoft Security Essentials *Disabled/Updated* {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Ostatní výmazy )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\17396396111821207260
c:\programdata\17396396111821207260\7c72b06002ffec186960ad5f12f4b2b5.ini
c:\programdata\17396396111821207260\cd5b15e575e1c3d06960ad5f12f4b2b5.ini
c:\windows\msdownld.tmp
.
.
((((((((((((((((((((((((( Soubory vytvořené od 2015-07-19 do 2015-08-19 )))))))))))))))))))))))))))))))
.
.
2015-08-19 17:49 . 2015-08-19 17:49 62576 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{249FBF92-0237-4F97-B75D-BEBE0FE2FCC4}\offreg.872.dll
2015-08-19 17:45 . 2015-08-19 17:49 -------- d-----w- c:\users\Filip\AppData\Local\temp
2015-08-19 17:45 . 2015-08-19 17:45 -------- d-----w- c:\users\PC\AppData\Local\temp
2015-08-19 17:45 . 2015-08-19 17:45 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-08-19 17:36 . 2015-08-19 17:36 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F313537E-1821-4F10-9C28-55B6A5E0152A}\offreg.3920.dll
2015-08-19 16:52 . 2015-08-19 16:55 -------- d-----w- C:\FRST
2015-08-19 16:27 . 2015-08-19 16:27 -------- d-----w- c:\users\Filip\Tracing
2015-08-19 15:09 . 2015-07-15 01:33 9252608 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{249FBF92-0237-4F97-B75D-BEBE0FE2FCC4}\mpengine.dll
2015-08-19 15:04 . 2015-08-19 15:04 512 ----a-w- C:\PhysicalMBR.bin
2015-08-19 12:45 . 2015-08-19 12:46 -------- d-----w- c:\program files\trend micro
2015-08-19 12:45 . 2015-08-19 12:45 -------- d-----w- C:\rsit
2015-08-19 12:37 . 2015-08-19 12:37 -------- d-----w- c:\users\Filip\AppData\Roaming\LizardSystems
2015-08-19 12:37 . 2015-08-19 12:37 -------- d-----w- c:\program files\LizardSystems
2015-08-18 12:34 . 2015-07-15 01:33 9252608 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2015-08-17 15:15 . 2015-07-21 05:25 9252608 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F313537E-1821-4F10-9C28-55B6A5E0152A}\mpengine.dll
2015-08-17 08:52 . 2015-08-17 08:54 -------- d-----w- c:\program files\Recuva
2015-08-16 21:40 . 2015-08-16 21:40 35992 ----a-w- c:\windows\system32\drivers\hitmanpro37.sys
2015-08-16 19:59 . 2015-08-16 19:59 -------- d-----w- c:\programdata\NCH Software
2015-08-16 19:58 . 2015-08-16 21:38 -------- d-----w- c:\program files\NCH Software
2015-08-16 19:58 . 2015-08-16 19:58 -------- d-----w- c:\users\Filip\AppData\Roaming\NCH Software
2015-08-16 18:53 . 2015-08-16 19:17 -------- d-----w- c:\program files\Lost Heaven Multiplayer
2015-08-16 18:16 . 2015-08-16 18:16 -------- d-----w- c:\program files\Cenega Czech
2015-08-16 14:00 . 2015-08-16 14:00 -------- d-----w- c:\users\Filip\.objectdb
2015-08-16 14:00 . 2015-08-16 14:00 -------- d-----w- c:\users\Filip\AppData\Roaming\VitySoft
2015-08-16 14:00 . 2015-08-16 14:00 -------- d-----w- c:\program files\FreeRapid-0.9u4
2015-08-16 12:32 . 2015-08-16 12:33 -------- d-----w- c:\program files\Rockstar Games
2015-08-15 17:42 . 2015-08-15 17:42 -------- d-----w- c:\users\Filip\AppData\Roaming\GHISLER
2015-08-15 17:42 . 2015-08-15 17:42 -------- d-----w- c:\program files\totalcmd
2015-08-15 17:42 . 2014-04-30 06:51 545 ----a-w- c:\windows\UC.PIF
2015-08-15 17:42 . 2014-04-30 06:51 545 ----a-w- c:\windows\RAR.PIF
2015-08-15 17:42 . 2014-04-30 06:51 545 ----a-w- c:\windows\PKZIP.PIF
2015-08-15 17:42 . 2014-04-30 06:51 545 ----a-w- c:\windows\PKUNZIP.PIF
2015-08-15 17:42 . 2014-04-30 06:51 545 ----a-w- c:\windows\LHA.PIF
2015-08-15 17:42 . 2014-04-30 06:51 545 ----a-w- c:\windows\ARJ.PIF
2015-08-15 09:38 . 2015-08-15 09:38 -------- d-----w- c:\users\Filip\AppData\Roaming\Atari
2015-08-15 09:23 . 2015-08-15 09:23 -------- d-----w- c:\users\Filip\AppData\Roaming\Leadertech
2015-08-15 09:23 . 2015-08-15 09:23 -------- d-----w- c:\program files\Common Files\PocketSoft
2015-08-15 09:23 . 2002-02-27 16:50 197120 ----a-w- c:\windows\patchw32.dll
2015-08-15 09:17 . 2015-08-15 09:17 -------- d-----w- c:\program files\Atari
2015-08-15 09:16 . 2015-08-15 09:16 282756 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\setup.dll
2015-08-15 09:16 . 2015-08-15 09:16 163972 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iGdi.dll
2015-08-15 09:16 . 2002-12-05 12:12 692224 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iKernel.dll
2015-08-15 09:16 . 2002-12-05 12:10 155648 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iuser.dll
2015-08-15 09:16 . 2002-12-02 13:22 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\DotNetInstaller.exe
2015-08-15 09:16 . 2002-12-02 11:33 57344 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\ctor.dll
2015-08-15 09:16 . 2002-12-02 11:33 237568 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\0701\Intel32\iscript.dll
2015-08-13 13:31 . 2015-08-13 13:32 98520 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2015-08-13 13:30 . 2015-08-13 13:30 -------- d-----w- c:\program files\Malwarebytes Anti-Malware
2015-08-13 13:30 . 2015-06-18 06:41 51928 ----a-w- c:\windows\system32\drivers\mwac.sys
2015-08-13 13:30 . 2015-06-18 06:41 94936 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2015-08-13 13:30 . 2015-06-18 06:41 23256 ----a-w- c:\windows\system32\drivers\mbam.sys
2015-08-13 11:59 . 2015-08-13 12:02 -------- d-----w- c:\program files\n2n Gui
2015-08-12 18:49 . 2014-05-05 08:00 -------- d-----w- c:\users\Filip\Crack
2015-08-12 18:40 . 2015-08-12 18:47 -------- d-----w- c:\program files\City Car Driving
2015-08-12 17:46 . 2015-08-12 17:47 -------- d-----w- c:\programdata\6WinManPro6
2015-08-12 17:45 . 2015-08-12 17:45 0 ----a-w- c:\windows\prleth.sys
2015-08-12 17:45 . 2015-08-12 17:45 0 ----a-w- c:\windows\hgfs.sys
2015-08-12 17:44 . 2015-08-19 14:54 -------- d-----w- c:\users\Filip\AppData\Local\Ection
2015-08-12 17:44 . 2015-08-14 09:59 -------- d-----w- c:\users\Filip\AppData\Local\YSNPack
2015-08-11 15:24 . 2015-08-11 15:24 -------- d-----w- c:\users\Filip\AppData\Roaming\BANDISOFT
2015-08-11 15:23 . 2015-08-11 15:23 -------- d-----w- c:\program files\Bandicam
2015-08-11 15:23 . 2015-08-11 15:23 -------- d-----w- c:\program files\BandiMPEG1
2015-08-11 14:02 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe
2015-08-10 17:07 . 2015-08-10 17:07 -------- d-----w- c:\users\Default\AppData\Local\Google
2015-08-02 15:40 . 2015-08-02 15:40 -------- d-----w- c:\program files\Defraggler
2015-08-02 15:37 . 2015-08-02 15:37 -------- d-----w- c:\program files\CCleaner
2015-07-26 21:29 . 2015-07-26 21:30 -------- d-----w- c:\users\Filip\AppData\Roaming\SmartSteamEmu
2015-07-24 15:18 . 2015-07-30 14:56 -------- d-----w- C:\TRS2004 - součásti
2015-07-23 18:43 . 2015-07-23 18:43 -------- d-----w- c:\users\Filip\AppData\Roaming\java
2015-07-23 18:34 . 2015-08-13 12:04 -------- d-----w- c:\users\Filip\AppData\Roaming\.minecraft
2015-07-23 18:24 . 2015-08-16 21:38 -------- d-----w- c:\users\Filip\AppData\Roaming\uTorrent
2015-07-23 18:23 . 2015-08-02 20:14 -------- d-----w- c:\program files\Driver Checker
2015-07-23 16:56 . 2015-07-25 18:42 -------- d-----w- c:\program files\Auran
2015-07-23 16:56 . 2003-11-10 16:14 729088 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iKernel.dll
2015-07-23 16:56 . 2003-11-10 16:13 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\ctor.dll
2015-07-23 16:56 . 2003-11-10 16:12 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iscript.dll
2015-07-23 16:56 . 2003-11-10 16:12 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iuser.dll
2015-07-23 16:56 . 2003-11-10 16:11 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\DotNetInstaller.exe
2015-07-23 16:56 . 2015-07-23 16:56 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\setup.dll
2015-07-23 16:56 . 2015-07-23 16:56 188548 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\01\Intel32\iGdi.dll
2015-07-22 09:01 . 2015-07-22 09:01 -------- d-----w- c:\users\Filip\AppData\Local\CEF
2015-07-20 23:26 . 2015-07-20 23:26 -------- d-----w- c:\programdata\NovaTech Network
2015-07-20 23:12 . 2015-07-20 23:12 -------- d-----w- c:\program files\ATI Technologies
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M výpis ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2015-08-12 17:14 . 2014-12-01 18:44 778440 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2015-08-12 17:14 . 2014-12-01 18:44 142536 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2015-07-22 20:47 . 2014-12-01 20:19 96352 ----a-w- c:\windows\system32\WindowsAccessBridge.dll
2015-07-20 14:21 . 2015-07-20 14:21 319488 ----a-w- c:\windows\HideWin.exe
2015-07-14 09:44 . 2014-12-21 15:30 26176 ---ha-w- c:\windows\system32\hamachi.sys
2015-06-23 11:27 . 2014-12-01 18:50 246952 ------w- c:\windows\system32\MpSigStub.exe
2015-06-06 16:08 . 2015-06-06 16:08 13216 ----a-w- c:\windows\system32\drivers\ASACPI.sys
2015-06-06 16:07 . 2015-06-06 16:07 433920 ----a-w- c:\windows\system32\drivers\wfeaglxt.sys
2015-06-06 16:04 . 2015-06-06 16:04 11944 ----a-w- c:\windows\system32\drivers\amdide.sys
2015-06-06 16:00 . 2015-06-06 16:00 100896 ----a-w- c:\windows\system32\RTNUninst32.dll
2015-06-06 16:00 . 2015-06-06 16:00 76872 ----a-w- c:\windows\system32\RtNicProp32.dll
2015-06-06 16:00 . 2015-06-06 16:00 723160 ----a-w- c:\windows\system32\drivers\Rt86win7.sys
2015-06-06 15:57 . 2015-06-06 15:57 844192 ----a-w- c:\windows\system32\tadefxapo2.dll
2015-06-06 15:57 . 2015-06-06 15:57 611496 ----a-w- c:\windows\system32\sltech32.dll
2015-06-06 15:57 . 2015-06-06 15:57 388752 ----a-w- c:\windows\system32\SRAPO.dll
2015-06-06 15:57 . 2015-06-06 15:57 329360 ----a-w- c:\windows\system32\SRCOM.dll
2015-06-06 15:57 . 2015-06-06 15:57 223912 ----a-w- c:\windows\system32\slprp32.dll
2015-06-06 15:57 . 2015-06-06 15:57 220088 ----a-w- c:\windows\system32\tossaemaxapo32.dll
2015-06-06 15:57 . 2015-06-06 15:57 1823320 ----a-w- c:\windows\system32\WavesGUILib.dll
2015-06-06 15:57 . 2015-06-06 15:57 1055888 ----a-w- c:\windows\system32\SRRPTR.dll
2015-06-06 15:57 . 2015-06-06 15:57 919600 ----a-w- c:\windows\system32\SFSS_APO.dll
2015-06-06 15:57 . 2015-06-06 15:57 865960 ----a-w- c:\windows\system32\sl3apo32.dll
2015-06-06 15:57 . 2015-06-06 15:57 695440 ----a-w- c:\windows\system32\SEHDRA32.dll
2015-06-06 15:57 . 2015-06-06 15:57 544400 ----a-w- c:\windows\system32\SECOMN32.dll
2015-06-06 15:57 . 2015-06-06 15:57 372368 ----a-w- c:\windows\system32\SEAPO32.dll
2015-06-06 15:57 . 2015-06-06 15:57 3498712 ----a-w- c:\windows\system32\drivers\RTKVHDA.sys
2015-06-06 15:57 . 2015-06-06 15:57 2637528 ----a-w- c:\windows\system32\RTSndMgr.cpl
2015-06-06 15:57 . 2015-06-06 15:57 2623192 ----a-w- c:\windows\system32\RtkPgExt.dll
2015-06-06 15:57 . 2015-06-06 15:57 2531544 ----a-w- c:\windows\system32\RltkAPO.dll
2015-06-06 15:57 . 2015-06-06 15:57 2381680 ----a-w- c:\windows\system32\RtkApoApi.dll
2015-06-06 15:57 . 2015-06-06 15:57 1702616 ----a-w- c:\windows\system32\RtkCoInstII.dll
2015-06-06 15:57 . 2015-06-06 15:57 1022120 ----a-w- c:\windows\system32\slcnt32.dll
2015-06-06 15:57 . 2015-06-06 15:57 72113152 ----a-w- c:\windows\system32\RCoRes.dat
2015-06-06 15:57 . 2015-06-06 15:57 948336 ----a-w- c:\windows\system32\MaxxSpeechAPO.dll
2015-06-06 15:57 . 2015-06-06 15:57 945456 ----a-w- c:\windows\system32\NahimicAPONSControl.dll
2015-06-06 15:57 . 2015-06-06 15:57 91920 ----a-w- c:\windows\system32\R4EEA32A.dll
2015-06-06 15:57 . 2015-06-06 15:57 852016 ----a-w- c:\windows\system32\MISS_APO.dll
2015-06-06 15:57 . 2015-06-06 15:57 818000 ----a-w- c:\windows\system32\MaxxVoiceAPO20.dll
2015-06-06 15:57 . 2015-06-06 15:57 7162128 ----a-w- c:\windows\system32\R4EEP32A.dll
2015-06-06 15:57 . 2015-06-06 15:57 62224 ----a-w- c:\windows\system32\R4EEG32A.dll
2015-06-06 15:57 . 2015-06-06 15:57 509184 ----a-w- c:\windows\system32\MaxxVolumeSDAPO.dll
2015-06-06 15:57 . 2015-06-06 15:57 4993984 ----a-w- c:\windows\system32\NAHIMICV2apo.dll
2015-06-06 15:57 . 2015-06-06 15:57 4713224 ----a-w- c:\windows\system32\NAHIMICAPOlfx.dll
2015-06-06 15:57 . 2015-06-06 15:57 352016 ----a-w- c:\windows\system32\R4EED32A.dll
2015-06-06 15:57 . 2015-06-06 15:57 13789440 ----a-w- c:\windows\system32\MaxxAudioRealtek.dll
2015-06-06 15:57 . 2015-06-06 15:57 11884288 ----a-w- c:\windows\system32\MaxxVoiceAPO30.dll
2015-06-06 15:57 . 2015-06-06 15:57 11785136 ----a-w- c:\windows\system32\MaxxVoiceAPO40.dll
2015-06-06 15:57 . 2015-06-06 15:57 106768 ----a-w- c:\windows\system32\R4EEL32A.dll
2015-06-06 15:57 . 2015-06-06 15:57 1940056 ----a-w- c:\windows\system32\MaxxAudioEQ.dll
2015-06-06 15:57 . 2015-06-06 15:57 966744 ----a-w- c:\windows\system32\MaxxAudioAPO40.dll
2015-06-06 15:57 . 2015-06-06 15:57 790272 ----a-w- c:\windows\system32\MaxxAudioAPOShell.dll
2015-06-06 15:57 . 2015-06-06 15:57 7044952 ----a-w- c:\windows\system32\DDPP32A.dll
2015-06-06 15:57 . 2015-06-06 15:57 509184 ----a-w- c:\windows\system32\MaxxAudioAPO30.dll
2015-06-06 15:57 . 2015-06-06 15:57 426944 ----a-w- c:\windows\system32\DTSU2PLFX32.dll
2015-06-06 15:57 . 2015-06-06 15:57 403392 ----a-w- c:\windows\system32\DTSU2PGFX32.dll
2015-06-06 15:57 . 2015-06-06 15:57 346048 ----a-w- c:\windows\system32\DTSU2PREC32.dll
2015-06-06 15:57 . 2015-06-06 15:57 296560 ----a-w- c:\windows\system32\ICEsoundAPO.dll
2015-06-06 15:57 . 2015-06-06 15:57 2806808 ----a-w- c:\windows\system32\FMAPO.dll
2015-06-06 15:57 . 2015-06-06 15:57 2370480 ----a-w- c:\windows\system32\MaxxAudioAPO70.dll
2015-06-06 15:57 . 2015-06-06 15:57 1175888 ----a-w- c:\windows\system32\MaxxAudioAPO50.dll
2015-06-06 15:57 . 2015-06-06 15:57 1151232 ----a-w- c:\windows\system32\MaxxAudioAPO60.dll
2015-06-06 15:57 . 2015-06-06 15:57 274264 ----a-w- c:\windows\system32\DDPO32A.dll
2015-06-06 15:57 . 2015-06-06 15:57 92584 ----a-w- c:\windows\system32\CONEQMSAPOGUILibrary.dll
2015-06-06 15:57 . 2015-06-06 15:57 87864 ----a-w- c:\windows\system32\audioLibVc.dll
2015-06-06 15:57 . 2015-06-06 15:57 519368 ----a-w- c:\windows\system32\AERTACap.dll
2015-06-06 15:57 . 2015-06-06 15:57 221528 ----a-w- c:\windows\system32\DDPA32.dll
2015-06-06 15:57 . 2015-06-06 15:57 188696 ----a-w- c:\windows\system32\AcpiServiceVnA.dll
2015-06-06 15:57 . 2015-06-06 15:57 1490264 ----a-w- c:\windows\system32\DDPD32A.dll
2015-06-06 15:57 . 2015-06-06 15:57 1476800 ----a-w- c:\windows\system32\CX32APO.dll
2015-06-06 15:50 . 2015-06-06 15:50 23840 ----a-w- c:\windows\system32\drivers\HWiNFO32.SYS
.
.
(((((((((((((((((((((((((((((((((( Spouštěcí body v registru )))))))))))))))))))))))))))))))))))))))))))))
.
.
*Poznámka* prázdné záznamy a legitimní výchozí údaje nejsou zobrazeny.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveBlacklisted]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42}]
2015-07-29 07:23 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSynced]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40}]
2015-07-29 07:23 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ GoogleDriveSyncing]
@="{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}"
[HKEY_CLASSES_ROOT\CLSID\{81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41}]
2015-07-29 07:23 576840 ----a-w- c:\program files\Google\Drive\googledrivesync32.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"="c:\program files\CCleaner\CCleaner.exe" [2015-07-17 6453528]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2014-03-04 3696912]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS Update Checker"="c:\program files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe" [2009-12-28 121472]
"Lightshot"="c:\program files\Skillbrains\lightshot\Lightshot.exe" [2014-11-18 226560]
"StartCCC"="c:\program files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe" [2015-03-19 748232]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtHDVCpl.exe" [2015-06-06 12205784]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2014-12-17 508800]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"SPReview"="c:\windows\System32\SPReview\SPReview.exe" [2014-12-07 280576]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer7"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37Crusader]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HitmanPro37CrusaderBoot]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
2014-03-04 09:19 3696912 ----a-w- c:\program files\DAEMON Tools Lite\DTLite.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Spotify Web Helper]
2015-07-28 20:43 2017848 ----a-w- c:\users\Filip\AppData\Roaming\Spotify\SpotifyWebHelper.exe
.
R2 HuaweiHiSuiteService.exe;HuaweiHiSuiteService.exe;c:\programdata\HandSetService\HuaweiHiSuiteService.exe [x]
R2 kss;Služba Kaspersky Security Scan; [x]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes Anti-Malware\mbamservice.exe [2015-06-18 1133880]
R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [2015-07-09 327296]
R3 eapihdrv;eapihdrv;c:\users\Filip\AppData\Local\Temp\ehdrv.sys [x]
R3 GalaxyClientService;GalaxyClientService;c:\program files\GalaxyClient\GalaxyClientService.exe [2015-08-16 1720888]
R3 GalaxyCommunication;GalaxyCommunication;c:\programdata\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2015-08-16 6874680]
R3 hitmanpro37;HitmanPro 3.7 Support Driver;c:\windows\system32\drivers\hitmanpro37.sys [2015-08-16 35992]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-08-17 102912]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys [2015-08-13 98520]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys [2015-06-18 51928]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2013-09-27 104768]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2013-10-23 280288]
R3 PAC207;VideoCAM GE111;c:\windows\system32\DRIVERS\pfc027.sys [2005-04-08 162176]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152]
R3 VASDeviceDrm;Virtual Audio Streaming with Drm (WDM);c:\windows\system32\drivers\vasdDev.sys [2012-03-19 1451312]
R3 VCam_WDM;Virtual Webcam 8.0;c:\windows\system32\DRIVERS\VCam_WDM.sys [2012-05-25 101688]
R3 xhunter1;xhunter1;c:\windows\xhunter1.sys [x]
R4 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM);c:\windows\system32\drivers\nvvad32v.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys [2014-12-08 243128]
S1 HWiNFO32;HWiNFO32/64 Kernel Driver;c:\windows\system32\drivers\HWiNFO32.SYS [2015-06-06 23840]
S2 AMD FUEL Service;AMD FUEL Service;c:\program files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-03-19 276992]
S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [2011-02-08 5120]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2015-05-12 410768]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2015-06-18 23256]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2015-06-06 723160]
S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2012-07-31 34896]
S3 VCSVADHWSer;Avnex Virtual Audio Device (WDM);c:\windows\system32\DRIVERS\vcsvad.sys [2008-12-26 17792]
S3 WFLR6654;WinFast TV2000 XP Expert (FM1216MK3);c:\windows\system32\drivers\wfeaglxt.sys [2015-06-06 433920]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2015-08-13 18:04 995144 ----a-w- c:\program files\Google\Chrome\Application\44.0.2403.155\Installer\chrmstp.exe
.
Obsah adresáře 'Naplánované úlohy'
.
2015-08-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-12-01 17:14]
.
2015-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2015-08-10 16:58]
.
2015-08-19 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2015-08-10 16:58]
.
.
------- Doplňkový sken -------
.
uStart Page = hxxp://www.google.com/
uDefault_Search_URL = hxxp://www.google.com
uInternet Settings,ProxyOverride = <local>
IE: E&xport to Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer = 94.74.192.252 94.74.192.244
.
- - - - NEPLATNÉ POLOŽKY ODSTRANĚNÉ Z REGISTRU - - - -
.
ShellIconOverlayIdentifiers-{CDC95B92-E27C-4745-A8C5-64A52A78855D} - (no file)
.
.
.
--------------------- ZAMKNUTÉ KLÍČE V REGISTRU ---------------------
.
[HKEY_USERS\S-1-5-21-3936994563-2387293699-3021914305-1001\Software\SecuROM\License information*]
"datasecu"=hex:ef,69,7c,65,6f,d3,87,41,ab,36,d7,72,22,71,30,d1,dc,f3,e9,6a,67,
2c,c6,b1,1f,5d,25,9c,0c,3d,7e,19,52,d5,33,d8,1c,70,25,a9,75,64,6e,a2,a8,0f,\
"rkeysecu"=hex:be,90,1d,18,32,f5,e8,0e,89,80,d7,cc,eb,c8,fa,b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Jiné spuštené procesy ------------------------
.
c:\windows\system32\nvvsvc.exe
c:\program files\Microsoft Security Client\MsMpEng.exe
c:\program files\NVIDIA Corporation\Display\nvxdsync.exe
c:\windows\system32\nvvsvc.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
c:\program files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
c:\program files\FolderSize\FolderSizeSvc.exe
c:\windows\System32\PAStiSvc.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\windows\system32\taskhost.exe
c:\windows\system32\conhost.exe
c:\windows\system32\taskhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\program files\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
c:\program files\Microsoft Security Client\MpCmdRun.exe
c:\program files\Google\Update\1.3.28.1\GoogleCrashHandler.exe
c:\windows\system32\sppsvc.exe
.
**************************************************************************
.
Celkový čas: 2015-08-19 19:54:02 - počítač byl restartován
ComboFix-quarantined-files.txt 2015-08-19 17:54
.
Před spuštěním: Volných bajtů: 13 442 883 584
Po spuštění: Volných bajtů: 13 637 509 120
.
- - End Of File - - 50A64057D6366EDCD4817D2E370C96FE
413FC2A0C716421B3158746D63736515
Přílohy
log (PCHunter).rar
(82.47 KiB) Staženo 36 x

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#7 Příspěvek od Filip.R. »

Kolik to tedy po mně chceš logů?

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#8 Příspěvek od Filip.R. »

ADWCleaner + Fixlog

Fix result of Farbar Recovery Scan Tool (x86) Version:17-08-2015
Ran by Filip (2015-08-19 20:29:14) Run:1
Running from C:\Users\Filip\Desktop
Loaded Profiles: Filip (Available Profiles: PC & Filip)
Boot Mode: Normal

==============================================

fixlist content:
*****************
Start
CloseProcesses:


HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...409d6c4515e9\InprocServer32: [Default-shell32] C:\Users\Filip\AppData\Local\YSNPack\cygVdm16.dllATTENTION! ====> ZeroAccess?
FF Plugin HKU\S-1-5-21-3936994563-2387293699-3021914305-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Filip\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-07-22] (Unity Technologies ApS)
FF Extension: Compat Inventory WMI provider - C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\o6yn3op4.default\Extensions\{F4A9C71A-084E-C401-2625-8EB93ADC9AC7} [2015-08-12]

C:\Users\Filip\AppData\Local\YSNPack
2015-08-12 19:46 - 2015-08-12 19:46 - 00065024 _____ () C:\Users\Filip\AppData\Local\YSNPack\cygVdm16.dll


CustomCLSID: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 -> C:\Users\Filip\AppData\LocalLow\Unity\WebPlayer\loader\UnityWebPluginAX.ocx (Unity Technologies ApS)
CustomCLSID: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001_Classes\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}\InprocServer32 -> C:\Users\Filip\AppData\Local\YSNPack\cygVdm16.dll ()




EmptyTemp:

End
*****************

Processes closed successfully.
HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\Software\Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} => key not found.
"HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0" => key removed successfully.
C:\Users\Filip\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll => moved successfully.
C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\o6yn3op4.default\Extensions\{F4A9C71A-084E-C401-2625-8EB93ADC9AC7} => moved successfully.
C:\Users\Filip\AppData\Local\YSNPack => moved successfully.
"C:\Users\Filip\AppData\Local\YSNPack\cygVdm16.dll" => File/Folder not found.
"HKU\S-1-5-21-3936994563-2387293699-3021914305-1001_Classes\CLSID\{444785F1-DE89-4295-863A-D46C3A781394}" => key removed successfully.
HKU\S-1-5-21-3936994563-2387293699-3021914305-1001_Classes\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9} => key not found.
EmptyTemp: => 645.8 MB temporary data Removed.


The system needed a reboot.

==== End of Fixlog 20:29:37 ====

# AdwCleaner v5.002 - Logfile created 19/08/2015 at 20:42:32
# Updated 18/08/2015 by Xplode
# Database : 2015-08-18.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x86)
# Username : Filip - PC-PC
# Running from : C:\Users\Filip\Downloads\adwcleaner_5.002.exe
# Option : Cleaning

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [SensePlus-bg.exe]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [iWebar-bg.exe]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{1F91A9A1-01BA-4C81-863D-3BA0751E1419}]
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{0f9310fb-bbd1-45eb-a7b9-68cef3c0c0e3}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{92258150-2468-4a04-aeb2-23453fc3e3ee}

***** [ Web browsers ] *****

[-] [C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider] Deleted : hxxp://www.omniboxes.com/webfavicon.ico
[-] [C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mystartsearch
[-] [C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : mystartsearch.com
[-] [C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Deleted :
[-] [C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://www.google.com/","hxxp://www.omniboxes. ... AJ93877391

*************************

:: Proxy settings cleared
:: Winsock settings cleared
:: IE policies deleted
:: Chrome policies deleted

########## EOF - C:\AdwCleaner\AdwCleaner[C7].txt - [2244 bytes] ##########

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#9 Příspěvek od Filip.R. »

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:17-08-2015
Ran by Filip (administrator) on PC-PC (20-08-2015 19:01:44)
Running from C:\Users\Filip\Desktop
Loaded Profiles: Filip (Available Profiles: PC & Filip)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Google Inc.) C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
(Google Inc.) C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
(Brio) C:\Program Files\FolderSize\FolderSizeSvc.exe
() C:\Windows\System32\PAStiSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files\Google\Update\1.3.28.1\GoogleCrashHandler.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Skillbrains) C:\Program Files\Skillbrains\lightshot\5.2.1.1\Lightshot.exe
(Valve Corporation) C:\Program Files\Steam\Steam.exe
(Valve Corporation) C:\Program Files\Steam\bin\steamwebhelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Games\Zoo Tycoon\zoo.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ASUS Update Checker] => C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe [121472 2009-12-28] (ASUSTeK Computer Inc.)
HKLM\...\Run: [Lightshot] => C:\Program Files\Skillbrains\lightshot\Lightshot.exe [226560 2014-11-18] ()
HKLM\...\Run: [StartCCC] => C:\Program Files\AMD\ATI.ACE\Core-Static\x86\CLIStart.exe [748232 2015-03-20] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12205784 2015-06-06] (Realtek Semiconductor)
HKLM\...\Run: [SunJavaUpdateSched] => C:\Program Files\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [6453528 2015-07-17] (Piriform Ltd)
HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd)
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [280576 2014-12-07] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files\Google\Drive\googledrivesync32.dll [2015-07-29] (Google)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001 -> DefaultScope {FAFE46D2-0727-4C91-B1A6-0724CF25099D} URL = hxxps://www.google.com/search?q={searchTerms}&s ... utEncoding?}
SearchScopes: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001 -> {FAFE46D2-0727-4C91-B1A6-0724CF25099D} URL = hxxps://www.google.com/search?q={searchTerms}&s ... utEncoding?}
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-22] (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-22] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 94.74.192.252 94.74.192.244
Tcpip\..\Interfaces\{1BD708E7-1195-45E6-892F-9368F56D361F}: [DhcpNameServer] 94.74.192.252 94.74.192.244

FireFox:
========
FF ProfilePath: C:\Users\Filip\AppData\Roaming\Mozilla\Firefox\Profiles\o6yn3op4.default
FF Homepage: seznam.cz
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_18_0_0_232.dll [2015-08-12] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1215155.dll [2014-12-02] (Adobe Systems, Inc.)
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-07-22] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-22] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MIF5BA~1\Office14\NPSPWRAP.DLL [2010-01-10] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-05-12] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-10] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-10] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
FF Extension: No Name - C:\Program Files\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} [not found]

Chrome:
=======
CHR Profile: C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Drive) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-10]
CHR Extension: (Facebook Messenger, Social News) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbhigdfhmhhdieikofamakgecjalgdmd [2015-08-16]
CHR Extension: (Adblock Plus) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-08-16]
CHR Extension: (Disable Youtube™ HTML5 Player) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\enmofgaijnbjpblfljopnpdogpldapoc [2015-08-16]
CHR Extension: (YouTube™ Ex) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoeljlbdbgaeocdnnepagaibkpbdnfon [2015-08-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Filip\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-10]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files\Internet Download Manager\IDMGCExt.crx <not found>
CHR HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Filip\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-07-02]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [276992 2015-03-19] (Advanced Micro Devices, Inc.) [File not signed]
R2 chromoting; C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe [56648 2015-03-08] (Google Inc.)
R2 FolderSize; C:\Program Files\FolderSize\FolderSizeSvc.exe [114688 2013-02-13] (Brio) [File not signed]
S3 GalaxyClientService; C:\Program Files\GalaxyClient\GalaxyClientService.exe [1720888 2015-08-16] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6874680 2015-08-16] (GOG.com)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22208 2013-10-23] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [280288 2013-10-23] (Microsoft Corporation)
R2 STI Simulator; C:\Windows\System32\PAStiSvc.exe [53248 2005-01-14] ()
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation)
S2 HuaweiHiSuiteService.exe; "C:\ProgramData\HandSetService\HuaweiHiSuiteService.exe" -/service [X]
S2 kss; no ImagePath

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdide; C:\Windows\System32\DRIVERS\amdide.sys [11944 2015-06-06] (Advanced Micro Devices Inc.)
S2 CX23880; C:\Windows\System32\drivers\cx88vid.sys [163584 2005-08-11] (Leadtek Research Inc.)
S2 CXTUNE; C:\Windows\System32\drivers\CX88TUNE_IBV32.sys [17664 2006-11-02] (Conexant Systems, Inc.) [File not signed]
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-09] (Disc Soft Ltd)
S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2015-01-14] (LogMeIn, Inc.)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [35992 2015-08-16] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-06-06] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-06-18] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [98520 2015-08-13] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-06-18] (Malwarebytes Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [214696 2013-09-27] (Microsoft Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [13216 2015-06-06] ()
S3 PAC207; C:\Windows\System32\DRIVERS\pfc027.sys [162176 2005-04-08] ()
R3 SCREAMINGBDRIVER; C:\Windows\System32\drivers\ScreamingBAudio.sys [34896 2012-07-31] (Screaming Bee LLC)
R2 SSPORT; C:\Windows\system32\Drivers\SSPORT.sys [5120 2011-02-08] (Samsung Electronics) [File not signed]
S3 VASDeviceDrm; C:\Windows\System32\drivers\vasdDev.sys [1451312 2012-03-19] (ShiningMorning Inc.)
S3 VCam_WDM; C:\Windows\System32\DRIVERS\VCam_WDM.sys [101688 2012-05-25] (e2eSoft)
R3 VCSVADHWSer; C:\Windows\System32\DRIVERS\vcsvad.sys [17792 2008-12-26] (Avnex)
R3 WFLR6654; C:\Windows\System32\drivers\wfeaglxt.sys [433920 2015-06-06] (Leadtek Research Inc.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Filip\AppData\Local\Temp\catchme.sys [X]
S3 eapihdrv; \??\C:\Users\Filip\AppData\Local\Temp\ehdrv.sys [X]
U5 hw_usbdev; C:\Windows\System32\Drivers\hw_usbdev.sys [102272 2015-05-07] (Huawei Technologies Co., Ltd.)
S4 nvvad_WaveExtensible; system32\drivers\nvvad32v.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-19 20:50 - 2015-08-19 20:50 - 00002323 _____ C:\Users\Filip\Desktop\AdwCleaner[C7].txt
2015-08-19 20:38 - 2015-08-19 20:38 - 01585664 _____ C:\Users\Filip\Downloads\adwcleaner_5.002.exe
2015-08-19 20:27 - 2015-08-19 20:27 - 00000661 _____ C:\Users\Filip\Downloads\fixlist.rar
2015-08-19 19:55 - 2015-08-19 19:55 - 00006361 _____ C:\ComboFix.rar
2015-08-19 19:54 - 2015-08-19 19:54 - 00024952 _____ C:\ComboFix.txt
2015-08-19 19:47 - 2015-08-19 19:47 - 00000552 _____ C:\Windows\PFRO.log
2015-08-19 19:33 - 2015-08-19 19:54 - 00000000 ____D C:\Qoobox
2015-08-19 19:33 - 2015-08-19 19:53 - 00000000 ____D C:\Windows\erdnt
2015-08-19 19:33 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2015-08-19 19:33 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2015-08-19 19:33 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-08-19 19:33 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-08-19 19:33 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-08-19 19:33 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2015-08-19 19:33 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2015-08-19 19:33 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2015-08-19 19:12 - 2015-08-19 19:13 - 00000000 ____D C:\Users\Filip\Desktop\PCHunter_free
2015-08-19 19:10 - 2015-08-19 19:11 - 06739485 _____ C:\Users\Filip\Desktop\PCHunter_free.zip
2015-08-19 19:10 - 2015-08-19 19:11 - 05635271 ____R (Swearware) C:\Users\Filip\Desktop\ComboFix.exe
2015-08-19 18:57 - 2015-08-19 18:57 - 00011669 _____ C:\Users\Filip\Desktop\Addition.rar
2015-08-19 18:55 - 2015-08-19 18:55 - 00043284 _____ C:\Users\Filip\Desktop\Addition.txt
2015-08-19 18:54 - 2015-08-20 19:02 - 00014289 _____ C:\Users\Filip\Desktop\FRST.txt
2015-08-19 18:52 - 2015-08-20 19:01 - 00000000 ____D C:\FRST
2015-08-19 18:52 - 2015-08-19 18:52 - 01677312 _____ (Farbar) C:\Users\Filip\Desktop\FRST.exe
2015-08-19 18:29 - 2015-08-19 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-19 18:27 - 2015-08-19 18:27 - 00000000 ____D C:\Users\Filip\Tracing
2015-08-19 17:04 - 2015-08-19 17:04 - 00000512 _____ C:\PhysicalMBR.bin
2015-08-19 17:00 - 2015-08-19 17:00 - 00602112 _____ (OldTimer Tools) C:\Users\Filip\Downloads\OTL.exe
2015-08-19 16:44 - 2015-08-19 16:44 - 00000275 _____ C:\Users\Filip\Downloads\figreg.rar
2015-08-19 16:44 - 2015-08-19 16:44 - 00000275 _____ C:\Users\Filip\Desktop\figreg.rar
2015-08-19 16:44 - 2015-08-19 16:44 - 00000000 ____D C:\Users\Filip\Desktop\figreg
2015-08-19 16:43 - 2015-08-19 16:44 - 00004929 _____ C:\Users\Filip\Desktop\Nový textový dokument.txt
2015-08-19 14:45 - 2015-08-19 14:46 - 00000000 ____D C:\Program Files\trend micro
2015-08-19 14:45 - 2015-08-19 14:45 - 00000000 ____D C:\rsit
2015-08-19 14:44 - 2015-08-19 14:44 - 01107968 _____ C:\Users\Filip\Downloads\RSIT.exe
2015-08-19 14:37 - 2015-08-19 14:37 - 00001185 _____ C:\Users\Filip\Desktop\Wi-Fi Scanner.lnk
2015-08-19 14:37 - 2015-08-19 14:37 - 00000000 ____D C:\Users\Filip\AppData\Roaming\LizardSystems
2015-08-19 14:37 - 2015-08-19 14:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LizardSystems
2015-08-19 14:37 - 2015-08-19 14:37 - 00000000 ____D C:\Program Files\LizardSystems
2015-08-19 14:24 - 2015-08-19 14:25 - 09559024 _____ C:\Users\Filip\Downloads\wifiscanner_setup.exe
2015-08-18 01:43 - 2015-08-18 01:43 - 00000000 _____ C:\Users\Filip\Desktop\httpsleduju.tocesta-z-mesta.txt
2015-08-17 14:25 - 2015-08-17 14:25 - 19607040 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 12829696 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 04305920 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-08-17 14:25 - 2015-08-17 14:25 - 02278912 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 02052608 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-08-17 14:25 - 2015-08-17 14:25 - 01950720 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 01309696 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 01155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00664064 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2015-08-17 14:25 - 2015-08-17 14:25 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00478208 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00342728 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-17 14:25 - 2015-08-17 14:25 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00102912 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2015-08-17 14:25 - 2015-08-17 14:25 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2015-08-17 14:25 - 2015-08-17 14:25 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-08-17 14:25 - 2015-08-17 14:25 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2015-08-17 14:21 - 2015-08-17 14:28 - 00011858 _____ C:\Windows\IE11_main.log
2015-08-17 14:21 - 2015-08-17 14:21 - 02077392 _____ (Microsoft Corporation) C:\Users\Filip\Downloads\IE11-Windows6.1.exe
2015-08-17 10:52 - 2015-08-17 10:54 - 00000000 ____D C:\Program Files\Recuva
2015-08-17 10:51 - 2015-08-17 10:51 - 04426120 _____ (Piriform Ltd) C:\Users\Filip\Downloads\rcsetup152.exe
2015-08-16 23:40 - 2015-08-16 23:40 - 00035992 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2015-08-16 23:25 - 2015-08-16 23:26 - 21220036 _____ C:\Users\Filip\Downloads\Hitman.Pro.v3.7.9.Build.242.rar
2015-08-16 23:22 - 2015-08-16 23:22 - 00000000 ____D C:\Users\Filip\Downloads\Hitman Pro 3.5.9 Build 125 (x64) incl crack
2015-08-16 22:35 - 2015-08-16 22:36 - 04383777 _____ C:\Users\Filip\Downloads\tdsskiller (1).zip
2015-08-16 22:35 - 2015-08-16 22:35 - 04101100 _____ C:\Users\Filip\Downloads\tdsskiller.zip
2015-08-16 21:59 - 2015-08-16 21:59 - 00000000 ____D C:\ProgramData\NCH Software
2015-08-16 21:58 - 2015-08-16 23:38 - 00000000 ____D C:\Program Files\NCH Software
2015-08-16 21:58 - 2015-08-16 21:58 - 00814128 _____ (NCH Software) C:\Users\Filip\Downloads\vxlsetup.exe
2015-08-16 21:58 - 2015-08-16 21:58 - 00000000 ____D C:\Users\Filip\AppData\Roaming\NCH Software
2015-08-16 21:15 - 2015-08-16 21:15 - 01243906 _____ C:\Users\Filip\Downloads\lhmp-server-rc1-updated.zip
2015-08-16 20:53 - 2015-08-16 21:17 - 00000000 ____D C:\Program Files\Lost Heaven Multiplayer
2015-08-16 20:53 - 2015-08-16 20:53 - 06391244 _____ (Lost Heaven Multiplayer ) C:\Users\Filip\Downloads\setup.exe
2015-08-16 20:53 - 2015-08-16 20:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lost Heaven Multiplayer
2015-08-16 20:16 - 2015-08-16 20:16 - 00000000 ____D C:\Program Files\Cenega Czech
2015-08-16 18:45 - 2015-08-20 16:52 - 00001344 _____ C:\Windows\setupact.log
2015-08-16 18:45 - 2015-08-16 18:45 - 00000000 _____ C:\Windows\setuperr.log
2015-08-16 16:06 - 2015-08-16 20:03 - 1828620993 _____ C:\Users\Filip\Downloads\Mafia-1-CZ-Plna-verze.rar
2015-08-16 16:00 - 2015-08-16 16:00 - 00000000 ____D C:\Users\Filip\AppData\Roaming\VitySoft
2015-08-16 16:00 - 2015-08-16 16:00 - 00000000 ____D C:\Users\Filip\.objectdb
2015-08-16 16:00 - 2015-08-16 16:00 - 00000000 ____D C:\Program Files\FreeRapid-0.9u4
2015-08-16 15:58 - 2015-08-16 16:00 - 17403694 _____ C:\Users\Filip\Downloads\FreeRapid-0.9u4.zip
2015-08-16 14:55 - 2015-08-16 14:55 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2015-08-16 14:55 - 2015-08-16 14:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
2015-08-16 14:40 - 2015-08-16 14:55 - 00000000 ____D C:\Users\Filip\Documents\GTA San Andreas User Files
2015-08-16 14:32 - 2015-08-16 14:33 - 00000000 ____D C:\Program Files\Rockstar Games
2015-08-15 19:42 - 2015-08-15 19:42 - 00000000 ____D C:\Users\Filip\AppData\Roaming\GHISLER
2015-08-15 19:42 - 2015-08-15 19:42 - 00000000 ____D C:\Program Files\totalcmd
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\UC.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\RAR.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\PKZIP.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\PKUNZIP.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\LHA.PIF
2015-08-15 19:42 - 2014-04-30 08:51 - 00000545 _____ C:\Windows\ARJ.PIF
2015-08-15 14:58 - 2015-08-15 19:47 - 00000000 ____D C:\Users\Filip\Downloads\Zoo Tycoon Complete Collection
2015-08-15 11:38 - 2015-08-15 11:41 - 00000000 ____D C:\Users\Filip\Documents\RCT3
2015-08-15 11:38 - 2015-08-15 11:38 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Atari
2015-08-15 11:23 - 2015-08-15 11:23 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Leadertech
2015-08-15 11:23 - 2015-08-15 11:23 - 00000000 ____D C:\Program Files\Common Files\PocketSoft
2015-08-15 11:23 - 2002-02-27 18:50 - 00197120 _____ C:\Windows\patchw32.dll
2015-08-15 11:17 - 2015-08-15 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
2015-08-15 11:17 - 2015-08-15 11:17 - 00000000 ____D C:\Program Files\Atari
2015-08-15 10:04 - 2015-08-15 10:20 - 00000000 ____D C:\Users\Filip\Downloads\Rollercoaster Tycoon 3
2015-08-14 14:41 - 2015-08-20 17:16 - 00194168 _____ C:\Windows\WindowsUpdate.log
2015-08-13 15:31 - 2015-08-13 15:32 - 00098520 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-13 15:30 - 2015-08-13 15:30 - 00000000 ____D C:\Program Files\Malwarebytes Anti-Malware
2015-08-13 15:30 - 2015-06-18 08:41 - 00094936 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-13 15:30 - 2015-06-18 08:41 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-13 15:30 - 2015-06-18 08:41 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-13 13:59 - 2015-08-13 14:02 - 00000000 ____D C:\Program Files\n2n Gui
2015-08-12 20:49 - 2014-05-05 10:00 - 00000000 ____D C:\Users\Filip\Crack
2015-08-12 20:40 - 2015-08-12 20:47 - 00000000 ____D C:\Program Files\City Car Driving
2015-08-12 19:46 - 2015-08-12 19:47 - 00000000 ____D C:\ProgramData\6WinManPro6
2015-08-12 19:45 - 2015-08-12 19:45 - 00000000 _____ C:\Windows\prleth.sys
2015-08-12 19:45 - 2015-08-12 19:45 - 00000000 _____ C:\Windows\hgfs.sys
2015-08-12 19:44 - 2015-08-19 16:54 - 00000000 ____D C:\Users\Filip\AppData\Local\Ection
2015-08-12 19:44 - 2015-08-12 19:44 - 00000000 _____ C:\Users\Filip\AppData\Roaming\g78rfdsafhi
2015-08-11 17:24 - 2015-08-11 17:28 - 00000000 ____D C:\Users\Filip\Documents\Bandicam
2015-08-11 17:24 - 2015-08-11 17:24 - 00000000 ____D C:\Users\Filip\AppData\Roaming\BANDISOFT
2015-08-11 17:23 - 2015-08-11 17:23 - 00000950 _____ C:\Users\PC\Desktop\Bandicam.lnk
2015-08-11 17:23 - 2015-08-11 17:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
2015-08-11 17:23 - 2015-08-11 17:23 - 00000000 ____D C:\Program Files\BandiMPEG1
2015-08-11 17:23 - 2015-08-11 17:23 - 00000000 ____D C:\Program Files\Bandicam
2015-08-11 16:02 - 1998-10-29 16:45 - 00306688 _____ (InstallShield Software Corporation) C:\Windows\IsUninst.exe
2015-08-11 16:00 - 2015-08-16 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mafia
2015-08-10 19:07 - 2015-08-10 19:07 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2015-08-10 19:07 - 2015-08-10 19:07 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2015-08-10 19:00 - 2015-08-13 20:06 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-10 19:00 - 2015-08-10 19:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-10 18:58 - 2015-08-20 18:03 - 00000938 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-10 18:58 - 2015-08-20 17:16 - 00000934 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-10 16:31 - 2015-08-10 16:31 - 00000000 ____D C:\Users\Filip\Documents\Multisoft
2015-08-02 17:40 - 2015-08-02 17:40 - 00000000 ____D C:\Program Files\Defraggler
2015-08-02 17:37 - 2015-08-02 17:37 - 00000000 ____D C:\Program Files\CCleaner
2015-07-30 21:32 - 2015-08-02 16:38 - 00000000 _____ C:\Users\Filip\AppData\Roaming\FileOut.cns
2015-07-30 21:32 - 2015-08-02 16:38 - 00000000 _____ C:\Users\Filip\AppData\Roaming\FileIn.cns
2015-07-30 21:32 - 2015-07-30 21:32 - 00000000 _____ C:\FileOut.Cns
2015-07-30 21:32 - 2015-07-30 21:32 - 00000000 _____ C:\FileIn.Cns
2015-07-30 21:28 - 2015-08-15 19:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games
2015-07-26 23:29 - 2015-07-26 23:30 - 00000000 ____D C:\Users\Filip\AppData\Roaming\SmartSteamEmu
2015-07-24 17:18 - 2015-07-30 16:56 - 00000000 ____D C:\TRS2004 - součásti
2015-07-23 20:43 - 2015-07-23 20:43 - 00000000 ____D C:\Users\Filip\AppData\Roaming\java
2015-07-23 20:34 - 2015-08-13 14:04 - 00000000 ____D C:\Users\Filip\AppData\Roaming\.minecraft
2015-07-23 20:34 - 2015-07-23 20:34 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2015-07-23 20:24 - 2015-08-16 23:38 - 00000000 ____D C:\Users\Filip\AppData\Roaming\uTorrent
2015-07-23 20:23 - 2015-08-02 22:14 - 00000000 ____D C:\Program Files\Driver Checker
2015-07-23 18:57 - 2015-07-25 20:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auran
2015-07-23 18:56 - 2015-07-25 20:42 - 00000000 ____D C:\Program Files\Auran
2015-07-23 18:01 - 2015-07-23 18:52 - 1345457479 _____ C:\Users\Filip\Downloads\Trainz-Railroad-Simulator-2004-cz.rar
2015-07-22 11:01 - 2015-07-22 11:01 - 00000000 ____D C:\Users\Filip\AppData\Local\CEF
2015-07-21 01:26 - 2015-07-21 01:26 - 00000000 ____D C:\ProgramData\NovaTech Network
2015-07-21 01:12 - 2015-07-21 01:12 - 00000000 ____D C:\Program Files\ATI Technologies

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-08-20 19:02 - 2015-05-31 13:27 - 00000000 ____D C:\Users\Filip\AppData\Roaming\foobar2000
2015-08-20 18:13 - 2014-12-01 20:44 - 00000914 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-08-20 17:45 - 2014-12-01 22:06 - 00000000 ____D C:\Program Files\Steam
2015-08-20 17:00 - 2009-07-14 06:34 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-08-20 17:00 - 2009-07-14 06:34 - 00022240 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-08-20 16:52 - 2014-12-01 21:41 - 00000000 ____D C:\ProgramData\NVIDIA
2015-08-20 16:52 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-19 20:42 - 2015-06-17 18:37 - 00000000 ____D C:\AdwCleaner
2015-08-19 20:21 - 2014-12-03 09:01 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Skype
2015-08-19 19:56 - 2014-12-14 10:50 - 00000000 ___RD C:\Users\Filip\Desktop\Filip - Plocha
2015-08-19 19:54 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Default
2015-08-19 19:54 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public
2015-08-19 19:48 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini
2015-08-19 19:42 - 2015-01-02 22:16 - 00000000 ____D C:\ProgramData\Temp
2015-08-19 18:30 - 2014-12-12 20:41 - 00000000 ____D C:\ProgramData\Skype
2015-08-19 18:29 - 2014-12-03 09:01 - 00000000 ___RD C:\Program Files\Skype
2015-08-19 18:29 - 2014-12-03 09:01 - 00000000 ____D C:\Program Files\Common Files\Skype
2015-08-19 18:27 - 2014-12-01 21:17 - 00000000 ____D C:\Users\Filip
2015-08-19 01:23 - 2015-06-25 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-08-17 17:38 - 2015-02-15 22:19 - 00000000 ____D C:\Users\Filip\Desktop\Programy
2015-08-17 14:36 - 2015-06-26 17:15 - 00000000 ____D C:\Program Files\Everything
2015-08-17 14:32 - 2014-12-14 18:04 - 00000000 __SHD C:\Users\Filip\AppData\Local\EmieUserList
2015-08-17 14:32 - 2014-12-14 18:04 - 00000000 __SHD C:\Users\Filip\AppData\Local\EmieSiteList
2015-08-17 14:32 - 2014-12-14 18:04 - 00000000 __SHD C:\Users\Filip\AppData\Local\EmieBrowserModeList
2015-08-17 14:30 - 2014-11-07 09:25 - 00000000 ____D C:\Windows\Panther
2015-08-16 23:39 - 2015-01-25 17:27 - 00012234 _____ C:\Windows\system32\.crusader
2015-08-16 23:37 - 2015-01-23 00:35 - 00000000 ____D C:\Program Files\Common Files\PX Storage Engine
2015-08-16 20:24 - 2015-04-05 12:25 - 00000000 ____D C:\Users\Filip\Desktop\Hry
2015-08-16 18:46 - 2014-12-07 17:29 - 00000000 ____D C:\Users\PC\AppData\Roaming\Seznam.cz
2015-08-16 18:29 - 2014-12-03 11:04 - 00000000 ____D C:\Users\Filip\AppData\Roaming\vlc
2015-08-16 16:20 - 2014-11-27 17:30 - 00104560 _____ C:\Users\PC\AppData\Local\GDIPFONTCACHEV1.DAT
2015-08-16 16:19 - 2014-11-07 09:35 - 00001397 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-16 14:40 - 2014-12-09 00:19 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2015-08-16 13:35 - 2014-12-03 09:18 - 00000000 ____D C:\Users\Filip\AppData\Roaming\DAEMON Tools Lite
2015-08-15 19:45 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Microsoft Games
2015-08-15 11:40 - 2014-12-01 21:17 - 00000000 ____D C:\Users\Filip\AppData\Local\VirtualStore
2015-08-15 11:30 - 2014-12-04 21:52 - 00000000 ___HD C:\Program Files\InstallShield Installation Information
2015-08-14 20:35 - 2014-12-01 22:06 - 00000000 ____D C:\Program Files\Common Files\Steam
2015-08-14 19:42 - 2015-01-03 13:23 - 00000000 ____D C:\Users\Filip\Documents\Algodoo
2015-08-14 16:01 - 2015-06-18 16:03 - 00000000 ____D C:\Users\Filip\AppData\Local\Messenger
2015-08-14 15:28 - 2015-06-18 16:03 - 00001126 _____ C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Messenger.lnk
2015-08-14 12:04 - 2015-07-20 16:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Akoff Music Composer Demo
2015-08-13 15:29 - 2015-06-13 11:49 - 00007603 _____ C:\Users\Filip\AppData\Local\Resmon.ResmonCfg
2015-08-13 13:49 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2015-08-13 10:01 - 2015-05-27 14:30 - 00001397 _____ C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-08-12 21:39 - 2014-12-09 20:16 - 00000000 ____D C:\Users\Filip\AppData\Roaming\TS3Client
2015-08-12 21:23 - 2014-12-09 20:16 - 00000000 ____D C:\Users\Filip\AppData\Local\TeamSpeak 3 Client
2015-08-12 20:48 - 2015-05-30 16:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Forward Development
2015-08-12 19:14 - 2014-12-01 20:44 - 00778440 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-08-12 19:14 - 2014-12-01 20:44 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-08-12 10:09 - 2014-12-09 22:28 - 00000000 ____D C:\Program Files\Samsung
2015-08-11 17:21 - 2015-05-26 18:25 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Opera Software
2015-08-11 17:21 - 2015-05-26 18:25 - 00000000 ____D C:\Users\Filip\AppData\Local\Opera Software
2015-08-10 22:53 - 2015-07-06 23:06 - 00000000 ____D C:\Users\Filip\AppData\Local\Akamai
2015-08-10 19:00 - 2014-12-01 21:18 - 00000000 ____D C:\Users\Filip\AppData\Local\Google
2015-08-10 19:00 - 2014-12-01 20:45 - 00000000 ____D C:\Program Files\Google
2015-08-10 16:06 - 2015-05-31 13:25 - 00000000 ____D C:\Program Files\foobar2000
2015-08-10 15:51 - 2015-07-10 15:55 - 00000000 ____D C:\Users\Filip\DvDrum 3
2015-08-03 18:28 - 2015-07-06 22:14 - 00000000 ____D C:\Users\Filip\AppData\Local\Spotify
2015-08-03 18:28 - 2015-07-06 22:12 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Spotify
2015-08-03 08:38 - 2015-07-06 20:21 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-07-30 21:35 - 2014-12-01 22:04 - 00104560 _____ C:\Users\Filip\AppData\Local\GDIPFONTCACHEV1.DAT
2015-07-30 21:34 - 2009-07-14 06:33 - 00361368 _____ C:\Windows\system32\FNTCACHE.DAT
2015-07-26 23:29 - 2014-12-20 15:25 - 00000000 ____D C:\Users\Filip\Documents\My Games
2015-07-23 20:24 - 2014-12-01 22:07 - 00000000 ____D C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2015-07-23 09:53 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\NDF
2015-07-22 22:50 - 2014-12-01 22:13 - 00000000 ____D C:\ProgramData\Oracle
2015-07-22 22:47 - 2014-12-01 22:19 - 00096352 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-07-22 22:46 - 2014-12-01 22:13 - 00000000 ____D C:\Program Files\Java
2015-07-22 22:35 - 2015-07-20 16:55 - 00000000 ____D C:\Program Files\Akoff Music Composer Demo
2015-07-21 12:07 - 2014-11-07 14:41 - 01584554 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-21 01:21 - 2015-02-04 21:16 - 00000000 ____D C:\Windows\system32\directx

==================== Files in the root of some directories =======

2015-06-01 21:11 - 2015-06-01 21:15 - 0065617 _____ () C:\Users\Filip\AppData\Roaming\Camdata.ini
2015-06-01 21:11 - 2015-06-01 21:15 - 0000408 _____ () C:\Users\Filip\AppData\Roaming\CamLayout.ini
2015-06-01 21:11 - 2015-06-01 21:15 - 0000408 _____ () C:\Users\Filip\AppData\Roaming\CamShapes.ini
2015-06-01 21:11 - 2015-06-01 21:15 - 0004551 _____ () C:\Users\Filip\AppData\Roaming\CamStudio.cfg
2015-07-30 21:32 - 2015-08-02 16:38 - 0000000 _____ () C:\Users\Filip\AppData\Roaming\FileIn.cns
2015-07-30 21:32 - 2015-08-02 16:38 - 0000000 _____ () C:\Users\Filip\AppData\Roaming\FileOut.cns
2015-08-12 19:44 - 2015-08-12 19:44 - 0000000 _____ () C:\Users\Filip\AppData\Roaming\g78rfdsafhi
2014-12-26 22:58 - 2014-12-26 22:59 - 0000087 _____ () C:\Users\Filip\AppData\Roaming\ilovemyjob.xml
2003-04-09 05:28 - 2003-04-09 05:28 - 0233472 ____R () C:\Users\Filip\AppData\Roaming\MafiaSetup.exe
2015-06-01 21:01 - 2015-06-01 21:12 - 0000096 _____ () C:\Users\Filip\AppData\Roaming\version2.xml
2015-02-17 18:15 - 2015-02-17 18:15 - 0000000 ___SH () C:\Users\Filip\AppData\Local\LumaEmu
2015-06-13 11:49 - 2015-08-13 15:29 - 0007603 _____ () C:\Users\Filip\AppData\Local\Resmon.ResmonCfg
2015-02-12 18:55 - 2015-02-12 18:55 - 0000003 _____ () C:\Users\Filip\AppData\Local\updater.log
2015-02-12 18:55 - 2015-04-23 17:32 - 0000412 _____ () C:\Users\Filip\AppData\Local\UserProducts.xml
2014-12-04 21:56 - 2014-12-04 21:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\Filip\AppData\Local\temp\Quarantine.exe
C:\Users\Filip\AppData\Local\temp\sqlite3.dll


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-08-12 09:46

==================== End of log ============================

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#10 Příspěvek od Filip.R. »

Additional scan result of Farbar Recovery Scan Tool (x86) Version:17-08-2015
Ran by Filip (2015-08-20 19:02:53)
Running from C:\Users\Filip\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3936994563-2387293699-3021914305-500 - Administrator - Disabled)
Filip (S-1-5-21-3936994563-2387293699-3021914305-1001 - Administrator - Enabled) => C:\Users\Filip
Guest (S-1-5-21-3936994563-2387293699-3021914305-501 - Limited - Disabled)
PC (S-1-5-21-3936994563-2387293699-3021914305-1000 - Administrator - Enabled) => C:\Users\PC

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Disabled - Up to date) {641105E6-77ED-3F35-A304-765193BCB75F}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Disabled - Up to date) {DF70E402-51D7-30BB-99B4-4D23E83BFDE2}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKLM\...\uTorrent) (Version: 2.2.1.25534 - emc, uTorrent.CZ)
Adobe Flash Player 18 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 18 PPAPI (HKLM\...\Adobe Flash Player PPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) - Czech (HKLM\...\{AC76BA86-7AD7-1029-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM\...\Adobe Shockwave Player) (Version: 12.1.5.155 - Adobe Systems, Inc.)
AIDA64 Extreme v5.00 (HKLM\...\AIDA64 Extreme_is1) (Version: 5.00 - FinalWire Ltd.)
Akamai NetSession Interface (HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\Akamai) (Version: - Akamai Technologies, Inc)
Algodoo v2.1.0 (HKLM\...\Algodoo_is1) (Version: - Algoryx)
AMD Catalyst Install Manager (HKLM\...\{9C4BD934-0CDB-E624-70C7-B795CFDA343B}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ASUSUpdate (HKLM\...\{587178E7-B1DF-494E-9838-FA4DD36E873C}) (Version: 7.17.17 - ASUSTeK Computer Inc.)
Audacity 2.0.6 (HKLM\...\Audacity_is1) (Version: 2.0.6 - Audacity Team)
Bandicam (HKLM\...\Bandicam) (Version: 2.3.0.834 - Bandisoft.com)
Bandisoft MPEG-1 Decoder (HKLM\...\BandiMPEG1) (Version: - Bandisoft.com)
Besiege (HKLM\...\Steam App 346010) (Version: - Spiderling Studios)
Bridge Builder (HKLM\...\Bridge Builder) (Version: - )
BS.Player FREE (HKLM\...\BSPlayerf) (Version: 2.69.1078 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 5.08 - Piriform)
City Car Driving 1.2.2 (HKLM\...\{CC457F3D-5CDE-4CE8-9685-90A4EDE81374}_is1) (Version: - Forward Development)
Counter-Strike (HKLM\...\Steam App 10) (Version: - Valve)
CPUID HWMonitor 1.27 (HKLM\...\CPUID HWMonitor_is1) (Version: - )
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.19 - Piriform)
Euro Truck Simulator 2 (HKLM\...\Steam App 227300) (Version: - SCS Software)
Everything 1.3.4.686 (x86) (HKLM\...\Everything) (Version: - )
FlatOut (HKLM\...\Steam App 6220) (Version: - Bugbear Entertainment)
Folder Size (HKLM\...\{FC8D21C8-7B29-4104-ADB0-FEE9CA1C7922}) (Version: 2.6 - Brio)
foobar2000 v1.3.8 (HKLM\...\foobar2000) (Version: 1.3.8 - Peter Pawlowski)
GOG Galaxy (HKLM\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
Google Drive (HKLM\...\{12ADFB82-D5A3-43E4-B2F4-FCD9B690315B}) (Version: 1.24.9931.5480 - Google, Inc.)
Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Chrome (HKLM\...\Google Chrome) (Version: 44.0.2403.155 - Google Inc.)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.28.1 - Google Inc.) Hidden
Chrome Remote Desktop Host (HKLM\...\{A1A724F3-F1A6-479C-AE98-208946717E2B}) (Version: 42.0.2311.39 - Google Inc.)
Java 8 Update 51 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
Jazyk popisů ovládacích prvků systému Microsoft Office 2010 – čeština (HKLM\...\{90140000-00BD-0405-0000-0000000FF1CE}) (Version: 14.0.4763.1011 - Microsoft Corporation)
K-Lite Codec Pack 11.2.0 Full (HKLM\...\KLiteCodecPack_is1) (Version: 11.2.0 - )
Lightshot-5.2.1.1 (HKLM\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.2.1.1 - Skillbrains)
Lost Heaven Multiplayer version 1.0.6 (HKLM\...\{518FE6AC-3097-4D96-88EB-D971A2AA30FF}_is1) (Version: 1.0.6 - Lost Heaven Multiplayer)
Mafia (HKLM\...\{C72D7008-266D-4DD8-BF3C-296B736127F6}) (Version: 1.02 - )
Malwarebytes Anti-Malware verze 2.1.8.1057 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5.2 (čeština) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1029) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (Italiano) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1040) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE (HKLM\...\{2C9EE786-1DDB-4C98-8FA4-B1B9B5A66B77}) (Version: 3.1.186.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Office Language Pack 2010 - Czech/èeština (HKLM\...\Office14.OMUI.cs-cz) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM\...\Office14.PROPLUS) (Version: 14.0.4734.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
Minecraft1.8.7 (HKLM\...\Minecraft1.8.7) (Version: - )
Mount & Blade: Warband (HKLM\...\Steam App 48700) (Version: - TaleWorlds Entertainment)
MSXML 4.0 SP3 Parser (HKLM\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
n2n Gui 0.41 (HKLM\...\n2n Gui_is1) (Version: - VPNHosting)
NotGTAV (HKLM\...\Steam App 369580) (Version: - Not Games LLP)
NVIDIA Ovladač 3D Vision 352.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 352.86 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA Ovladač řídící jednotky 3D Vision 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 352.86 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 352.86 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
OpenTTD 1.5.1 (HKLM\...\OpenTTD) (Version: 1.5.1 - OpenTTD)
Ovládací panel NVIDIA 352.86 (Version: 352.86 - NVIDIA Corporation) Hidden
POSTAL 2 (HKLM\...\Steam App 223470) (Version: - Running With Scissors)
Prison Architect (HKLM\...\Steam App 233450) (Version: - Introversion Software)
RCT3 Soaked (HKLM\...\{EA926717-CE5A-4CB4-AB21-9E6E9565A458}) (Version: 1.00.000 - )
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7503 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.52 - Piriform)
RollerCoaster Tycoon® 3 (HKLM\...\{907B4640-266B-4A21-92FB-CD1A86CD0F63}) (Version: 1.00.000 - )
Samsung ML-2160 Series (HKLM\...\Samsung ML-2160 Series) (Version: 1.09 (24.10.2012) - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Service Pack 2 for Microsoft Office 2010 Language Pack (KB2687449) 32-Bit Edition (HKLM\...\{90140000-0100-0405-0000-0000000FF1CE}_Office14.OMUI.cs-cz_{1FCBAAF2-0321-4986-8DAE-5F2891EC6E8E}) (Version: - Microsoft)
Skype™ 7.8 (HKLM\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Spintires (HKLM\...\Spintires_is1) (Version: - )
Spotify (HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\Spotify) (Version: 1.0.10.107.gd0dfca3a - Spotify AB)
Steam (HKLM\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamSpeak 3 Client (HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd) (Version: 8.51a - Ghisler Software GmbH)
TRS2004 (HKLM\...\{BDE1289F-4025-41A5-AD17-101DB4D82CA7}) (Version: 1.00.000 - )
Unity Web Player (HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS)
VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN)
War Thunder (HKLM\...\Steam App 236390) (Version: - Gaijin Entertainment)
Waveform (HKLM\...\Steam App 204180) (Version: - Eden Industries)
Wi-Fi Scanner version 2.0.0.20 (HKLM\...\{2A3B6859-0CA1-4B6B-9E79-EAE7B28C0E0A}_is1) (Version: 2.0.0.20 - LizardSystems)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 5.21 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
WWE RAW - Ultimate Impact (HKLM\...\WWE RAW - Ultimate Impact_is1) (Version: - )
Zoo Tycoon: Complete Collection (HKLM\...\Zoo Tycoon 1.0) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

16-08-2015 23:38:48 Checkpoint by HitmanPro
17-08-2015 14:22:50 Instalační služba modulů systému Windows
17-08-2015 14:23:44 Instalační služba modulů systému Windows
19-08-2015 17:04:09 OTL Restore Point - 19.8.2015 17:04:04

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 04:04 - 2015-08-19 19:48 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {076B3456-0852-4AC6-A87F-C0EF580AE9BF} - System32\Tasks\Opera scheduled Autoupdate 1432657543 => C:\Program Files\Opera\launcher.exe
Task: {0B17BBB5-B2C2-42DA-AD3D-3DB714456A2C} - System32\Tasks\{578AD9BC-B90B-4C82-9A0E-673A9DFFE08A} => pcalua.exe -a "C:\Program Files\DAP\DapRemove.exe" -d "C:\Program Files\DAP"
Task: {14D9266C-B6EC-48D6-B792-6BBBB62C2678} - \ShopperPro -> No File <==== ATTENTION
Task: {17AA5272-3D1E-492F-B894-51C9824C99A9} - \71d2fd3f-d552-488e-9656-9ee6c881ec26-6 -> No File <==== ATTENTION
Task: {2A4AB483-23F4-4673-8A0F-71A61504FE23} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-10] (Google Inc.)
Task: {2ACD3DE5-8665-40F9-9380-BFFDCBCCB6EC} - \71d2fd3f-d552-488e-9656-9ee6c881ec26-2 -> No File <==== ATTENTION
Task: {2DD68C7E-9C87-4A24-B379-91C1EAC8D044} - \71d2fd3f-d552-488e-9656-9ee6c881ec26-5_user -> No File <==== ATTENTION
Task: {2E307075-9F36-4F19-9159-1008CE3663C9} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated)
Task: {2FED434E-4500-4C33-8025-70D393D5EF11} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-07-17] (Piriform Ltd)
Task: {31C763BC-77A8-4712-A9C9-C6A214CA7932} - System32\Tasks\Driver Booster SkipUAC (Filip) => C:\Program Files\IObit\Driver Booster\DriverBooster.exe
Task: {348F5934-DA9F-4BA7-9516-B8B5674C188D} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {38F86AE4-157F-4372-B38A-3A755CB36FE9} - \SPBIW_UpdateTask_Time_3931353237383535352d3437415a556c2a3223346c41 -> No File <==== ATTENTION
Task: {417ADE78-CF0B-45DA-957D-682FA10E38A8} - System32\Tasks\Games\UpdateCheck_S-1-5-21-3936994563-2387293699-3021914305-1000
Task: {474D9048-5E4A-4F2C-B05F-F43B4F48C751} - System32\Tasks\{9491E8C3-592A-4E80-9316-D5A64EAFF0A2} => pcalua.exe -a C:\Users\Filip\Downloads\vcredist_x86.exe -d C:\Users\Filip\Downloads
Task: {4D299CD5-1574-4E77-B3C8-4EFD211856F9} - \0ca8f498-cd33-4cf8-bf1f-9bdc37b79e98-2 -> No File <==== ATTENTION
Task: {54465DA1-338A-438C-84E5-85F8503D7B00} - \0ca8f498-cd33-4cf8-bf1f-9bdc37b79e98-6 -> No File <==== ATTENTION
Task: {56511911-3F3B-4259-9716-E1CCE7CCE615} - \71d2fd3f-d552-488e-9656-9ee6c881ec26-7 -> No File <==== ATTENTION
Task: {589B4EAE-0378-4D4C-83D6-3A3A6862A236} - \0ca8f498-cd33-4cf8-bf1f-9bdc37b79e98-7 -> No File <==== ATTENTION
Task: {6A4A191C-70F3-47FB-A929-AA4A8959E7D7} - \71d2fd3f-d552-488e-9656-9ee6c881ec26-1 -> No File <==== ATTENTION
Task: {6BE4C861-F4D5-4F75-AEF1-1519BF6F3E35} - \0ca8f498-cd33-4cf8-bf1f-9bdc37b79e98-1 -> No File <==== ATTENTION
Task: {83CA9BDF-BE27-4064-A62B-B7520834B06D} - \71d2fd3f-d552-488e-9656-9ee6c881ec26-5 -> No File <==== ATTENTION
Task: {8AA171C6-2419-46F1-B269-109B8CD4449E} - \SPDriver -> No File <==== ATTENTION
Task: {8EC397E3-0F5B-4046-9DDE-30D3D2D36D65} - System32\Tasks\{3E035846-2508-420C-86B1-C3517BB8EA22} => C:\Program Files\City Car Driving\bin\win32\Starter.exe [2015-08-12] ()
Task: {9B0481DD-6D96-4C45-B97B-6BDF682C9738} - \0ca8f498-cd33-4cf8-bf1f-9bdc37b79e98-5_user -> No File <==== ATTENTION
Task: {AA03128D-FAF3-4A70-AD76-D6B906C1A320} - System32\Tasks\{458C8F11-24A8-43F2-BF0F-09E37CD3A4DA} => pcalua.exe -a "C:\Program Files\Steam\steamapps\common\Arma 2 Operation Arrowhead\DLCsetup\ACR\datacachepreprocessor.exe" -d "C:\Program Files\Steam\steamapps\common\Arma 2 Operation Arrowhead" -c -updater
Task: {B15448FA-2D10-4778-9778-35432BB712E1} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-12] (Adobe Systems Incorporated)
Task: {B908FD15-F414-4582-8414-EA8086F26305} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-10] (Google Inc.)
Task: {D67584A3-32E2-46F5-A964-67DD3BA8A1DF} - System32\Tasks\{B1C02DD9-161A-4CF8-BDD7-592B74D99CF1} => C:\Program Files\City Car Driving\bin\win32\Starter.exe [2015-08-12] ()
Task: {E8755DD9-AB05-4B1D-BB45-ACDC880054E7} - \0ca8f498-cd33-4cf8-bf1f-9bdc37b79e98-5 -> No File <==== ATTENTION
Task: {F2B2DDAB-FDEA-4082-98F8-0718C16876A5} - System32\Tasks\{CF17054A-7A29-40D1-B94A-5DDE0BA2B6D6} => pcalua.exe -a "C:\Users\Filip\Downloads\Return to Blockland\RTB1045full.exe" -d "C:\Users\Filip\Downloads\Return to Blockland"
Task: {F8F347C2-3EA4-405D-B276-3E9B527DC7CC} - System32\Tasks\{DDC928D7-A050-4153-913F-52932D7781C1} => C:\Program Files\City Car Driving\bin\win32\Starter.exe [2015-08-12] ()

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2014-12-01 21:40 - 2015-05-12 04:34 - 00106128 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll
2014-12-09 22:28 - 2011-04-25 13:25 - 00024064 _____ () C:\Windows\System32\ssj1mlm.dll
2015-03-08 21:29 - 2005-01-14 10:32 - 00053248 _____ () C:\Windows\System32\PAStiSvc.exe
2015-07-17 19:34 - 2015-07-17 19:34 - 00047104 _____ () C:\Program Files\CCleaner\lang\lang-1029.dll
2015-04-14 17:35 - 2015-07-03 18:12 - 00778240 _____ () C:\Program Files\Steam\SDL2.dll
2015-01-20 19:13 - 2015-07-03 18:12 - 04962816 _____ () C:\Program Files\Steam\v8.dll
2015-01-20 19:13 - 2015-07-03 18:12 - 01556992 _____ () C:\Program Files\Steam\icui18n.dll
2015-01-20 19:13 - 2015-07-03 18:12 - 01187840 _____ () C:\Program Files\Steam\icuuc.dll
2015-04-14 17:35 - 2015-08-12 20:26 - 02413248 _____ () C:\Program Files\Steam\video.dll
2014-12-01 22:12 - 2014-12-01 23:31 - 02396672 _____ () C:\Program Files\Steam\libavcodec-56.dll
2014-12-01 22:12 - 2014-12-01 23:31 - 00442880 _____ () C:\Program Files\Steam\libavutil-54.dll
2014-12-01 22:12 - 2014-12-01 23:31 - 00479744 _____ () C:\Program Files\Steam\libavformat-56.dll
2014-12-01 22:12 - 2014-12-01 23:31 - 00332800 _____ () C:\Program Files\Steam\libavresample-2.dll
2014-12-01 22:12 - 2014-12-01 23:31 - 00485888 _____ () C:\Program Files\Steam\libswscale-3.dll
2014-12-01 22:12 - 2015-08-12 20:26 - 00704192 _____ () C:\Program Files\Steam\bin\chromehtml.DLL
2015-07-22 11:00 - 2015-07-27 03:13 - 00171008 _____ () C:\Program Files\Steam\bin\openvr_api.dll
2014-12-01 22:12 - 2015-07-03 18:12 - 39553928 _____ () C:\Program Files\Steam\bin\libcef.dll
2015-08-13 20:06 - 2015-08-08 02:13 - 01405768 _____ () C:\Program Files\Google\Chrome\Application\44.0.2403.155\libglesv2.dll
2015-08-13 20:06 - 2015-08-08 02:13 - 00081224 _____ () C:\Program Files\Google\Chrome\Application\44.0.2403.155\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\Temp:088B37DC
AlternateDataStreams: C:\ProgramData\Temp:56E2E879
AlternateDataStreams: C:\ProgramData\Temp:FB6A21E3

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\...\100sexlinks.com -> 100sexlinks.com

There are 4788 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3936994563-2387293699-3021914305-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Filip\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 94.74.192.252 - 94.74.192.244
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupreg: DAEMON Tools Lite => "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorun
MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Filip\AppData\Roaming\Spotify\SpotifyWebHelper.exe"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{5A650478-ACC6-409F-A465-D5C9B5DE0CD3}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [{56C4DBF3-94DC-4D24-AC1D-94A694050C88}] => (Allow) C:\Program Files\Steam\Steam.exe
FirewallRules: [TCP Query User{A8D71375-9624-46EB-811D-B5DBD0E28F4A}C:\program files\skype\phone\skype.exe] => (Allow) C:\program files\skype\phone\skype.exe
FirewallRules: [UDP Query User{BEB85BE1-48B3-4881-8344-20A0527643A7}C:\program files\skype\phone\skype.exe] => (Allow) C:\program files\skype\phone\skype.exe
FirewallRules: [TCP Query User{BC61F41F-F807-4A02-9F09-5217A0F863B1}C:\program files\steam\steamapps\common\postal2complete\sharethepain\system\postal2mp.exe] => (Allow) C:\program files\steam\steamapps\common\postal2complete\sharethepain\system\postal2mp.exe
FirewallRules: [UDP Query User{F2CAD28D-3930-405E-AD6A-BA4A936AAA66}C:\program files\steam\steamapps\common\postal2complete\sharethepain\system\postal2mp.exe] => (Allow) C:\program files\steam\steamapps\common\postal2complete\sharethepain\system\postal2mp.exe
FirewallRules: [{9FA282A0-F81F-4D44-B51B-D3DED423DA57}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{A189F74C-DF28-4227-99A7-D07EE2D063A1}] => (Allow) LPort=2869
FirewallRules: [{2A5454B4-2714-4D29-A275-4BF2A181E11E}] => (Allow) LPort=1900
FirewallRules: [{14880805-C2DE-4EE5-8724-B20BDFD2633F}] => (Allow) C:\Program Files\Steam\steamapps\common\War Thunder\launcher.exe
FirewallRules: [{C86E3C4C-FF81-43A1-BA33-71C3D8B6ACB3}] => (Allow) C:\Program Files\Steam\steamapps\common\War Thunder\launcher.exe
FirewallRules: [TCP Query User{A94AF519-7048-4BC7-BA97-11882C06F47F}C:\program files\steam\steamapps\common\war thunder\aces.exe] => (Allow) C:\program files\steam\steamapps\common\war thunder\aces.exe
FirewallRules: [UDP Query User{526179E5-10F8-4C0C-8CD4-1B6DE0987E13}C:\program files\steam\steamapps\common\war thunder\aces.exe] => (Allow) C:\program files\steam\steamapps\common\war thunder\aces.exe
FirewallRules: [{6DCF7F1A-E61B-459C-962E-56BC8BE0D903}] => (Allow) LPort=25555
FirewallRules: [{C5AA74D3-11CF-45A1-943B-614257D8B1FE}] => (Allow) C:\Program Files\Steam\steamapps\common\POSTAL2Complete\System\Launcher.exe
FirewallRules: [{2B091D85-A54E-4786-AAF3-CCF4F68FAC24}] => (Allow) C:\Program Files\Steam\steamapps\common\POSTAL2Complete\System\Launcher.exe
FirewallRules: [{6C94E28E-6441-4CBE-AD77-12BDF92048A6}] => (Allow) C:\Program Files\Google\Chrome Remote Desktop\42.0.2311.39\remoting_host.exe
FirewallRules: [{89ABE559-ED9F-4C60-BE04-61BEEC0A1D20}] => (Allow) C:\Program Files\Steam\steamapps\common\POSTAL2Complete\System\Postal2.exe
FirewallRules: [{96D88E02-76E8-4832-A38A-11BE8E3DFF42}] => (Allow) C:\Program Files\Steam\steamapps\common\POSTAL2Complete\System\Postal2.exe
FirewallRules: [{6BD37B5C-E34E-461B-879A-0EF749C3690A}] => (Allow) C:\Program Files\Skype\Phone\Skype.exe
FirewallRules: [{2A2D6CC7-8C02-4743-AE93-1EBD291DD647}] => (Allow) C:\Users\Filip\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{C9016F09-53F4-4235-A05F-649EC8039089}] => (Allow) C:\Users\Filip\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{688B9448-E527-4FB6-91F5-6F638147433F}] => (Allow) C:\Program Files\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{5ED9C446-890D-45D9-A477-0351B0806A31}] => (Allow) C:\Program Files\Steam\steamapps\common\Besiege\Besiege.exe
FirewallRules: [{CB5BDA24-B8F4-4160-8005-B49BCEE6134A}] => (Allow) C:\Program Files\Steam\steamapps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{BE7B9124-B376-4F5C-A780-06576B8C7462}] => (Allow) C:\Program Files\Steam\steamapps\common\Prison Architect\Prison Architect.exe
FirewallRules: [{5941009D-B934-4020-84BF-40E3889D6327}] => (Allow) C:\Program Files\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{3196E103-8BB2-4F4A-9F73-694B9BB873D0}] => (Allow) C:\Program Files\Steam\steamapps\common\MountBlade Warband\mb_warband.exe
FirewallRules: [{EA49FDE7-5D04-4732-B6A8-BCA636834280}] => (Allow) C:\Program Files\Steam\steamapps\common\Waveform\Waveform.exe
FirewallRules: [{AA5A9DD7-E749-40DC-8EF4-B568CE691122}] => (Allow) C:\Program Files\Steam\steamapps\common\Waveform\Waveform.exe
FirewallRules: [{9D0D84FF-BB61-41E7-8994-3B402C856084}] => (Allow) C:\Program Files\Steam\steamapps\common\NotGTAV\NotGTAV.exe
FirewallRules: [{FDC99C14-FD68-488B-A2C7-4572CBB00DCE}] => (Allow) C:\Program Files\Steam\steamapps\common\NotGTAV\NotGTAV.exe
FirewallRules: [TCP Query User{B1864829-2EFD-4302-9F8A-94ABE6A68E73}C:\users\filip\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\filip\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{B2A61C29-F387-4D0F-AC05-03F18BF98C1F}C:\users\filip\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\filip\appdata\roaming\spotify\spotify.exe
FirewallRules: [TCP Query User{A55C0F05-D5C7-40C2-95C4-706CADE7FE3A}C:\users\filip\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\filip\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{3416192F-5FF5-422F-8DE6-8BC1E10028EE}C:\users\filip\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\filip\appdata\local\akamai\netsession_win.exe
FirewallRules: [{C329E374-2502-4DA1-B454-C1160B542ED1}] => (Allow) C:\Program Files\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{1523E020-CA84-4A6E-881C-AD0F8DE3F455}] => (Allow) C:\Program Files\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
FirewallRules: [{FB018D8D-A0F4-47EA-BDE0-78914379B066}] => (Allow) C:\Users\Filip\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{8DD6DCE8-9863-40B9-9566-26213542AA3A}] => (Allow) C:\Users\Filip\AppData\Roaming\uTorrent\utorrent.exe
FirewallRules: [{77B4C204-1D04-4113-8867-01CBC3EED11A}] => (Allow) LPort=1978
FirewallRules: [TCP Query User{3C6166E1-A661-423A-9382-FB0F02F490C0}C:\program files\city car driving\bin\win32\starter.exe] => (Allow) C:\program files\city car driving\bin\win32\starter.exe
FirewallRules: [UDP Query User{A25AFB5D-BF12-4E0C-B535-C2B430D5D941}C:\program files\city car driving\bin\win32\starter.exe] => (Allow) C:\program files\city car driving\bin\win32\starter.exe
FirewallRules: [TCP Query User{0BBFFCBB-BD87-471C-8903-0A181BBBE7E6}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [UDP Query User{A2F8BA36-6B7B-4861-B584-403054331F65}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [{83748791-88C3-4AE2-9BF7-CEF2DA7BB4EF}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{9D47EA93-5479-4A16-9AE9-65C48B5AB884}C:\program files\steam\steamapps\common\half-life\hl.exe] => (Allow) C:\program files\steam\steamapps\common\half-life\hl.exe
FirewallRules: [UDP Query User{B18EFDCA-72C6-42FF-88C9-A82E43D09A12}C:\program files\steam\steamapps\common\half-life\hl.exe] => (Allow) C:\program files\steam\steamapps\common\half-life\hl.exe

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/20/2015 05:18:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UpdateChecker.exe, verze: 1.0.9.0, časové razítko: 0x4acd3bd8
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000
ID chybujícího procesu: 0xb24
Čas spuštění chybující aplikace: 0xUpdateChecker.exe0
Cesta k chybující aplikaci: UpdateChecker.exe1
Cesta k chybujícímu modulu: UpdateChecker.exe2
ID zprávy: UpdateChecker.exe3

Error: (08/20/2015 05:03:23 PM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Chrome Remote Desktop Host -- Error 1714. The older version of Chrome Remote Desktop Host cannot be removed. Contact your technical support group. System Error 1612.

Error: (08/20/2015 12:04:11 PM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Chrome Remote Desktop Host -- Error 1714. The older version of Chrome Remote Desktop Host cannot be removed. Contact your technical support group. System Error 1612.

Error: (08/20/2015 11:58:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UpdateChecker.exe, verze: 1.0.9.0, časové razítko: 0x4acd3bd8
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000
ID chybujícího procesu: 0xbe8
Čas spuštění chybující aplikace: 0xUpdateChecker.exe0
Cesta k chybující aplikaci: UpdateChecker.exe1
Cesta k chybujícímu modulu: UpdateChecker.exe2
ID zprávy: UpdateChecker.exe3

Error: (08/20/2015 12:04:05 AM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Chrome Remote Desktop Host -- Error 1714. The older version of Chrome Remote Desktop Host cannot be removed. Contact your technical support group. System Error 1612.

Error: (08/19/2015 09:19:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UpdateChecker.exe, verze: 1.0.9.0, časové razítko: 0x4acd3bd8
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000
ID chybujícího procesu: 0xc44
Čas spuštění chybující aplikace: 0xUpdateChecker.exe0
Cesta k chybující aplikaci: UpdateChecker.exe1
Cesta k chybujícímu modulu: UpdateChecker.exe2
ID zprávy: UpdateChecker.exe3

Error: (08/19/2015 08:36:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UpdateChecker.exe, verze: 1.0.9.0, časové razítko: 0x4acd3bd8
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000
ID chybujícího procesu: 0x8b0
Čas spuštění chybující aplikace: 0xUpdateChecker.exe0
Cesta k chybující aplikaci: UpdateChecker.exe1
Cesta k chybujícímu modulu: UpdateChecker.exe2
ID zprávy: UpdateChecker.exe3

Error: (08/19/2015 07:51:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UpdateChecker.exe, verze: 1.0.9.0, časové razítko: 0x4acd3bd8
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000
ID chybujícího procesu: 0xc8c
Čas spuštění chybující aplikace: 0xUpdateChecker.exe0
Cesta k chybující aplikaci: UpdateChecker.exe1
Cesta k chybujícímu modulu: UpdateChecker.exe2
ID zprávy: UpdateChecker.exe3

Error: (08/19/2015 07:03:26 PM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Chrome Remote Desktop Host -- Error 1714. The older version of Chrome Remote Desktop Host cannot be removed. Contact your technical support group. System Error 1612.

Error: (08/19/2015 05:01:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: UpdateChecker.exe, verze: 1.0.9.0, časové razítko: 0x4acd3bd8
Název chybujícího modulu: unknown, verze: 0.0.0.0, časové razítko: 0x00000000
Kód výjimky: 0xc0000005
Posun chyby: 0x00000000
ID chybujícího procesu: 0xc94
Čas spuštění chybující aplikace: 0xUpdateChecker.exe0
Cesta k chybující aplikaci: UpdateChecker.exe1
Cesta k chybujícímu modulu: UpdateChecker.exe2
ID zprávy: UpdateChecker.exe3


System errors:
=============
Error: (08/20/2015 04:52:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Kaspersky Security Scan neuspěla při spuštění v důsledku následující chyby:
%%3

Error: (08/20/2015 04:52:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba HuaweiHiSuiteService.exe neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (08/20/2015 04:52:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Conexant 2388x Tuner neuspěla při spuštění v důsledku následující chyby:
%%1275

Error: (08/20/2015 04:52:23 PM) (Source: Application Popup) (EventID: 875) (User: )
Description: Načtení ovladače CX88TUNE_IBV32.sys je blokováno.

Error: (08/20/2015 04:52:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba WinFast CX2388x WDM Video Capture. neuspěla při spuštění v důsledku následující chyby:
%%1058

Error: (08/20/2015 11:56:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Služba Kaspersky Security Scan neuspěla při spuštění v důsledku následující chyby:
%%3

Error: (08/20/2015 11:56:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba HuaweiHiSuiteService.exe neuspěla při spuštění v důsledku následující chyby:
%%2

Error: (08/20/2015 11:56:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba Conexant 2388x Tuner neuspěla při spuštění v důsledku následující chyby:
%%1275

Error: (08/20/2015 11:56:00 AM) (Source: Application Popup) (EventID: 875) (User: )
Description: Načtení ovladače CX88TUNE_IBV32.sys je blokováno.

Error: (08/20/2015 11:56:00 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Služba WinFast CX2388x WDM Video Capture. neuspěla při spuštění v důsledku následující chyby:
%%1058


Microsoft Office:
=========================
Error: (08/20/2015 05:18:54 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: UpdateChecker.exe1.0.9.04acd3bd8unknown0.0.0.000000000c000000500000000b2401d0db5b3df233a9C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exeunknownc49062ff-474e-11e5-8436-001d602af6b8

Error: (08/20/2015 05:03:23 PM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Chrome Remote Desktop Host -- Error 1714. The older version of Chrome Remote Desktop Host cannot be removed. Contact your technical support group. System Error 1612.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (08/20/2015 12:04:11 PM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Chrome Remote Desktop Host -- Error 1714. The older version of Chrome Remote Desktop Host cannot be removed. Contact your technical support group. System Error 1612.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (08/20/2015 11:58:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: UpdateChecker.exe1.0.9.04acd3bd8unknown0.0.0.000000000c000000500000000be801d0db2e727a2c2fC:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exeunknownf99edc8e-4721-11e5-85e1-001d602af6b8

Error: (08/20/2015 12:04:05 AM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Chrome Remote Desktop Host -- Error 1714. The older version of Chrome Remote Desktop Host cannot be removed. Contact your technical support group. System Error 1612.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (08/19/2015 09:19:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: UpdateChecker.exe1.0.9.04acd3bd8unknown0.0.0.000000000c000000500000000c4401d0dab3bba6a3c7C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exeunknown427d3490-46a7-11e5-9e2b-001d602af6b8

Error: (08/19/2015 08:36:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: UpdateChecker.exe1.0.9.04acd3bd8unknown0.0.0.000000000c0000005000000008b001d0daad9da26a9bC:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exeunknown23d047be-46a1-11e5-a7b3-001d602af6b8

Error: (08/19/2015 07:51:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: UpdateChecker.exe1.0.9.04acd3bd8unknown0.0.0.000000000c000000500000000c8c01d0daa750db04b5C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exeunknownda2d8401-469a-11e5-818e-001d602af6b8

Error: (08/19/2015 07:03:26 PM) (Source: MsiInstaller) (EventID: 11714) (User: NT AUTHORITY)
Description: Product: Chrome Remote Desktop Host -- Error 1714. The older version of Chrome Remote Desktop Host cannot be removed. Contact your technical support group. System Error 1612.(NULL)(NULL)(NULL)(NULL)(NULL)

Error: (08/19/2015 05:01:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: UpdateChecker.exe1.0.9.04acd3bd8unknown0.0.0.000000000c000000500000000c9401d0da8f93f957f5C:\Program Files\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exeunknown1a949a24-4683-11e5-bbd3-001d602af6b8


==================== Memory info ===========================

Processor: AMD Athlon(tm) Processor LE-1620
Percentage of memory in use: 37%
Total physical RAM: 3198.49 MB
Available physical RAM: 2010.93 MB
Total Virtual: 6395.28 MB
Available Virtual: 5038.91 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:149.04 GB) (Free:12.98 GB) NTFS
Drive d: (Data) (Fixed) (Total:54.99 GB) (Free:4.82 GB) NTFS
Drive f: (MARINE) (CDROM) (Total:0.57 GB) (Free:0 GB) CDFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 74.5 GB) (Disk ID: BBF4BBF4)
Partition 1: (Active) - (Size=19.5 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=55 GB) - (Type=OF Extended)

========================================================
Disk: 1 (Size: 149.1 GB) (Disk ID: 504F504F)
Partition 1: (Active) - (Size=149 GB) - (Type=07 NTFS)

==================== End of log ============================

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#11 Příspěvek od Filip.R. »

Dobře, úkol splněn. Btw mám tu cestu jinak: System32/Tasks a tam hafo souborů, kde jsou v názvu uvedená pouze čísla.

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#12 Příspěvek od Filip.R. »

Já tam vůbec nemám tasky začínající na 2 nebo ten Shopper.

Filip.R.
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 19 srp 2015 13:43

Re: Prosím o kontrolu logu z RSIT

#13 Příspěvek od Filip.R. »

Ok, hotovo. Moc díky. :closed:

Zamčeno