Stránka 1 z 1

kontrola - podozrenie na malware

Napsal: 01 led 2018 22:22
od talbott
dobry den, prosim o kontrolu logu

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01.01.2018
Ran by uzivatel (administrator) on ZERO1 (01-01-2018 22:20:50)
Running from C:\Users\uzivatel\Desktop
Loaded Profiles: uzivatel (Available Profiles: uzivatel & Administrator)
Platform: Windows 8.1 Pro (Update) (X64) Language: Slovenčina (Slovensko)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit Reader\FoxitConnectedPDFService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel) C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
() C:\Windows\System32\igfxTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Windows\SysWOW64\UMonit64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [246120 2017-12-21] (AVAST Software)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297272 2017-12-11] (Apple Inc.)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Pixart Imaging Inc)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [63296 2014-08-20] ()
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
HKU\S-1-5-21-4176085001-3363555415-2058170901-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8619224 2016-01-15] (Piriform Ltd)
HKU\S-1-5-21-4176085001-3363555415-2058170901-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\SysWOW64\ACTUAL~1.SCR [111616 2017-06-21] ()
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
GroupPolicy: Restriction <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 213.151.222.34 192.168.0.1
Tcpip\..\Interfaces\{6B002129-8207-4D1B-BC85-7327C418E511}: [DhcpNameServer] 213.151.222.34 192.168.0.1
Tcpip\..\Interfaces\{AE1B6697-3F17-41CD-9040-9266881E316F}: [DhcpNameServer] 213.151.222.34 192.168.0.1

Internet Explorer:
==================
HKU\S-1-5-21-4176085001-3363555415-2058170901-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus13.msn.com/?pc=ASJB
HKU\S-1-5-21-4176085001-3363555415-2058170901-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-11-09] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-11-09] (AVAST Software)

FireFox:
========
FF DefaultProfile: 7coy8gqf.default
FF ProfilePath: C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\7coy8gqf.default [2018-01-01]
FF Homepage: Mozilla\Firefox\Profiles\7coy8gqf.default -> google.com
FF Extension: (Hoxx VPN Proxy) - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\7coy8gqf.default\Extensions\@hoxx-vpn.xpi [2017-12-27]
FF Extension: (Ghostery) - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\7coy8gqf.default\Extensions\firefox@ghostery.com.xpi [2017-12-28]
FF Extension: (uBlock Origin) - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\7coy8gqf.default\Extensions\uBlock0@raymondhill.net.xpi [2017-12-14]
FF Extension: (Avast Online Security) - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\7coy8gqf.default\Extensions\wrc@avast.com.xpi [2017-10-14]
FF Extension: (Google Analytics Opt-out Add-on (by Google)) - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\7coy8gqf.default\Extensions\{6d96bb5e-1175-4ebf-8ab5-5f56f1c79f65}.xpi [2017-03-31]
FF Extension: (NoScript) - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\7coy8gqf.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2017-12-30]
FF Extension: (noscriptlite) - C:\Users\uzivatel\AppData\Roaming\Mozilla\Firefox\Profiles\7coy8gqf.default\Extensions\{86d73a1c-2ec5-4b7a-b249-60cec805dc99}.xpi [2017-12-19]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_126.dll [2018-01-01] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_126.dll [2018-01-01] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-12] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-12] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-12] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2015-02-12] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2017-10-18] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2017-10-18] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2017-10-18] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [2017-10-18] (Foxit Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.56 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-09-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-09-03] (Intel Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\2480718.js [2018-01-01] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\2480718.cfg [2018-01-01] <==== ATTENTION

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-11-27] (Apple Inc.)
S4 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\AsusWSWinService.exe [71168 2014-08-20] (ASUS Cloud Corporation) [File not signed]
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7538536 2017-12-21] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [301168 2017-12-21] (AVAST Software)
R2 esifsvc; C:\Windows\SysWOW64\esif_uf.exe [1037568 2014-09-18] (Intel Corporation)
R2 FoxitReaderService; C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\FoxitConnectedPDFService.exe [1659456 2017-10-29] (Foxit Software Inc.)
R2 ibtsiva.exe; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [121288 2014-08-13] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [329104 2014-11-19] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887256 2014-05-13] (Intel(R) Corporation)
R2 IntelUSBoverIP; C:\Program Files\Intel Corporation\USB over IP\bin\UoipService.exe [394184 2014-10-15] (Intel)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-09-03] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [265936 2014-10-29] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3818704 2014-10-29] (Intel® Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [185096 2017-12-21] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2017-12-21] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2017-12-21] (AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2017-12-21] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2017-12-21] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [149344 2017-12-21] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46976 2017-12-21] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146664 2017-12-21] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110336 2017-12-21] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84384 2017-12-21] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1025176 2017-12-21] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [457400 2017-12-21] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [204456 2017-12-21] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [358672 2017-12-21] (AVAST Software)
S3 ATP; C:\Windows\System32\drivers\AsusTP.sys [69904 2014-11-21] (ASUS Corporation)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
S3 BthMtpEnum; C:\Windows\system32\DRIVERS\BthMtpEnum.sys [62976 2013-08-22] (Microsoft Corporation)
R3 dptf_cpu; C:\Windows\System32\drivers\dptf_cpu.sys [38720 2014-09-18] (Intel Corporation)
R3 dptf_pch; C:\Windows\System32\drivers\dptf_pch.sys [38208 2014-09-18] (Intel Corporation)
R3 esif_lf; C:\Windows\System32\drivers\esif_lf.sys [216360 2014-09-18] (Intel Corporation)
S3 GeneStor; C:\Windows\System32\drivers\GeneStor.sys [110824 2014-06-11] (GenesysLogic)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [219592 2014-08-13] (Intel Corporation)
R0 IntelHSWPcc; C:\Windows\System32\drivers\IntelPcc.sys [79016 2014-08-26] (Intel Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-06] ( )
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80920 2015-07-02] (McAfee, Inc.)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3482600 2014-11-06] (Intel Corporation)
S3 RTLU3E8023-W8-64; C:\Windows\system32\DRIVERS\rtu30x64w8.sys [70656 2013-06-18] (Realtek )
R3 SensorsAlsDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
R3 t_mouse.sys; C:\Windows\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] ()
R3 usb3Hub; C:\Windows\System32\drivers\usb3Hub.sys [213296 2014-10-15] (Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
U0 msahci; system32\drivers\msahci.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-01 22:20 - 2018-01-01 22:20 - 000016071 _____ C:\Users\uzivatel\Desktop\FRST.txt
2018-01-01 22:20 - 2018-01-01 22:20 - 000000000 ____D C:\Users\uzivatel\Downloads\FRST-OlderVersion
2018-01-01 21:06 - 2018-01-01 21:06 - 000000000 ____D C:\Windows\LastGood
2018-01-01 21:00 - 2018-01-01 21:00 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-12-31 17:46 - 2017-12-31 17:46 - 000429440 _____ C:\Windows\system32\FNTCACHE.DAT
2017-12-30 19:58 - 2017-12-30 19:58 - 001701376 _____ (TODO: <Company name>) C:\Windows\SysWOW64\RebootPrompt.exe
2017-12-30 19:58 - 2017-12-30 19:58 - 000000000 ____D C:\Windows\UCI
2017-12-30 19:58 - 2017-12-30 19:58 - 000000000 ____D C:\ProgramData\UIU
2017-12-30 19:55 - 2017-04-21 22:53 - 000029376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll
2017-12-30 19:55 - 2017-04-21 22:53 - 000018600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100_clr0400.dll
2017-12-30 19:55 - 2017-04-21 22:50 - 000030912 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll
2017-12-30 19:55 - 2017-04-21 22:50 - 000018592 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll
2017-12-30 19:55 - 2017-04-11 19:27 - 000987840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2017-12-30 19:55 - 2017-04-11 19:27 - 000485576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2017-12-30 19:55 - 2017-03-15 19:15 - 000993632 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2017-12-30 19:55 - 2017-03-15 19:15 - 000690008 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2017-12-29 22:04 - 2017-12-29 22:04 - 133326408 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-12-29 22:04 - 2017-11-17 16:37 - 004168704 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-12-29 22:04 - 2017-11-14 04:57 - 025731072 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-12-29 22:04 - 2017-11-14 04:30 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-12-29 22:04 - 2017-11-14 04:25 - 005925888 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-12-29 22:04 - 2017-11-14 04:20 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-12-29 22:04 - 2017-11-14 03:55 - 001033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-12-29 22:04 - 2017-11-14 03:48 - 015267328 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-12-29 22:04 - 2017-11-14 03:48 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-12-29 22:04 - 2017-11-14 03:39 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-12-29 22:04 - 2017-11-14 03:27 - 001544192 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-12-29 22:04 - 2017-11-14 03:16 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-12-29 22:04 - 2017-11-14 02:37 - 013679616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-12-29 22:04 - 2017-11-14 02:10 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-12-29 22:04 - 2017-11-14 01:32 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-12-29 22:04 - 2017-11-08 16:55 - 000032256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BasicRender.sys
2017-12-29 22:04 - 2017-11-07 22:15 - 000323584 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2017-12-29 22:04 - 2017-11-07 21:49 - 000179712 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2017-12-29 22:04 - 2017-11-07 21:46 - 000285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2017-12-29 22:04 - 2017-11-07 21:39 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-12-29 22:04 - 2017-11-07 21:29 - 001080320 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2017-12-29 22:04 - 2017-11-07 21:27 - 004509696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-12-29 22:04 - 2017-11-07 21:27 - 000151040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2017-12-29 22:04 - 2017-11-07 21:22 - 000880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-12-29 22:04 - 2017-11-07 21:18 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-12-29 22:04 - 2017-11-07 21:08 - 000713216 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2017-12-29 22:04 - 2017-11-07 21:04 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-12-29 22:04 - 2017-11-07 21:02 - 000562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2017-12-29 22:04 - 2017-11-07 21:01 - 001313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-12-29 22:04 - 2017-11-07 20:58 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-12-29 22:04 - 2017-10-18 18:14 - 000136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-12-29 22:04 - 2017-10-17 20:11 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-12-29 22:04 - 2017-10-16 19:38 - 002013016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-12-29 22:04 - 2017-10-14 14:04 - 001548624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-12-29 22:04 - 2017-10-14 09:13 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-12-29 22:04 - 2017-10-14 08:55 - 000445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-12-29 22:04 - 2017-10-14 08:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-12-29 22:04 - 2017-10-14 08:30 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-12-29 22:04 - 2017-10-14 08:30 - 000380416 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-12-29 22:04 - 2017-10-14 08:29 - 001436672 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-12-29 22:04 - 2017-10-14 08:27 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-12-29 22:04 - 2017-10-14 08:23 - 000963072 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-12-29 22:04 - 2017-10-14 08:17 - 003717632 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-12-29 22:04 - 2017-10-14 08:05 - 015431680 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2017-12-29 22:04 - 2017-10-14 07:50 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-12-29 22:04 - 2017-10-14 07:41 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-12-29 22:04 - 2017-10-14 07:25 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-12-29 22:04 - 2017-10-14 07:24 - 000331776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-12-29 22:04 - 2017-10-14 07:23 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-12-29 22:04 - 2017-10-14 07:19 - 000780800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-12-29 22:04 - 2017-10-14 07:14 - 013317632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2017-12-29 22:04 - 2017-10-10 17:39 - 001192960 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2017-12-29 22:04 - 2017-10-10 17:36 - 000124416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys
2017-12-29 22:04 - 2017-10-10 17:29 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\UXInit.dll
2017-12-29 22:04 - 2017-10-10 16:42 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UXInit.dll
2017-12-29 22:04 - 2017-10-10 16:38 - 003631616 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-12-29 22:04 - 2017-10-10 16:38 - 000425984 _____ (Microsoft Corporation) C:\Windows\system32\PCPTpm12.dll
2017-12-29 22:04 - 2017-10-10 16:11 - 002749952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-12-29 22:04 - 2017-10-10 16:08 - 000367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PCPTpm12.dll
2017-12-29 22:04 - 2017-10-10 15:58 - 000949760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2017-12-29 22:04 - 2017-10-05 08:17 - 000380248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2017-12-29 22:04 - 2017-09-15 00:52 - 000986968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-12-29 22:04 - 2017-09-14 20:30 - 007439704 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-12-29 22:04 - 2017-09-14 20:30 - 001737600 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-12-29 22:04 - 2017-09-14 20:29 - 001502000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-12-29 22:04 - 2017-09-14 02:18 - 001384216 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-12-29 22:04 - 2017-09-14 02:14 - 001124384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-12-29 22:04 - 2017-09-13 14:32 - 000445952 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2017-12-29 22:04 - 2017-09-13 14:31 - 000445952 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2017-12-29 22:04 - 2017-09-13 14:27 - 000384000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2017-12-29 22:04 - 2017-09-09 19:53 - 022361864 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-12-29 22:04 - 2017-09-09 18:55 - 019790760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-12-29 22:04 - 2017-09-09 18:38 - 000154112 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2017-12-29 22:04 - 2017-09-09 16:47 - 014466560 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-12-29 22:04 - 2017-09-09 16:21 - 012879360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-12-29 22:04 - 2017-09-09 14:13 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-12-29 22:04 - 2017-09-09 14:13 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-12-29 22:04 - 2017-09-09 04:50 - 001364552 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-12-29 22:04 - 2017-09-08 19:15 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-12-29 22:04 - 2017-09-08 18:39 - 000113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-12-29 22:04 - 2017-09-08 18:14 - 003084288 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2017-12-29 22:04 - 2017-09-08 17:57 - 001084928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-12-29 22:04 - 2017-09-08 17:50 - 002471424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2017-12-29 22:04 - 2017-09-08 04:31 - 000685440 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-12-29 22:04 - 2017-09-08 04:28 - 000507176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-12-29 22:04 - 2017-09-07 22:33 - 000686592 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-12-29 22:04 - 2017-09-07 22:33 - 000415744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-12-29 22:04 - 2017-09-07 22:32 - 000285184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-12-29 22:04 - 2017-09-07 22:32 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-12-29 22:04 - 2017-09-07 22:31 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\mgmtapi.dll
2017-12-29 22:04 - 2017-09-07 22:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-12-29 22:04 - 2017-09-07 21:32 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-12-29 22:04 - 2017-09-07 21:31 - 000145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2017-12-29 22:04 - 2017-09-07 21:29 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-12-29 22:04 - 2017-09-07 21:08 - 000656896 _____ (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2017-12-29 22:04 - 2017-09-07 20:54 - 000329216 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
2017-12-29 22:04 - 2017-09-07 20:20 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mgmtapi.dll
2017-12-29 22:04 - 2017-09-07 20:09 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-12-29 22:04 - 2017-09-07 19:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-12-29 22:04 - 2017-09-07 19:38 - 000128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-12-29 22:04 - 2017-09-07 19:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-12-29 22:04 - 2017-09-07 19:24 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dnsapi.dll
2017-12-29 22:04 - 2017-09-07 18:20 - 000513456 _____ C:\Windows\SysWOW64\locale.nls
2017-12-29 22:04 - 2017-09-07 18:20 - 000513456 _____ C:\Windows\system32\locale.nls
2017-12-29 22:04 - 2017-09-07 14:40 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-12-29 22:04 - 2017-09-07 14:40 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-12-29 22:04 - 2017-09-07 00:07 - 000158552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2017-12-29 22:04 - 2017-09-06 22:17 - 000461144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2017-12-29 22:04 - 2017-09-06 22:17 - 000443224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2017-12-29 22:04 - 2017-09-06 15:14 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\regsvc.dll
2017-12-29 22:04 - 2017-08-19 18:27 - 000237568 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2017-12-29 22:04 - 2017-08-19 17:48 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2017-12-29 22:04 - 2017-08-17 23:07 - 000537200 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-12-29 22:04 - 2017-08-17 23:07 - 000140016 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2017-12-29 22:04 - 2017-08-17 23:03 - 000450392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-12-29 22:04 - 2017-08-17 23:03 - 000136832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2017-12-29 22:04 - 2017-08-13 20:48 - 000202592 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2017-12-29 22:04 - 2017-08-13 18:52 - 000174944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2017-12-29 22:04 - 2017-08-13 18:19 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2017-12-29 22:04 - 2017-08-13 18:10 - 000277504 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2017-12-29 22:04 - 2017-08-13 17:33 - 000252416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
2017-12-29 22:04 - 2017-08-13 17:15 - 007078912 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
2017-12-29 22:04 - 2017-08-13 16:52 - 005274624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2017-12-29 22:04 - 2017-08-13 16:52 - 000486912 _____ (Microsoft Corporation) C:\Windows\system32\tpmvsc.dll
2017-12-29 22:04 - 2017-08-13 16:25 - 007797248 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-12-29 22:04 - 2017-08-13 16:18 - 005270016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-12-29 22:04 - 2017-08-11 22:19 - 000482304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scrptadm.dll
2017-12-29 22:04 - 2017-08-11 22:14 - 000566784 _____ (Microsoft Corporation) C:\Windows\system32\scrptadm.dll
2017-12-29 22:04 - 2017-08-11 21:13 - 000175616 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2017-12-29 22:04 - 2017-08-11 04:27 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2017-12-29 22:04 - 2017-08-11 04:27 - 000065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vpcivsp.sys
2017-12-29 22:04 - 2017-08-11 03:38 - 000477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll
2017-12-29 22:04 - 2017-08-11 03:16 - 000275968 _____ (Microsoft Corporation) C:\Windows\system32\authz.dll
2017-12-29 22:04 - 2017-08-11 03:08 - 001753600 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2017-12-29 22:04 - 2017-08-11 02:57 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authz.dll
2017-12-29 22:04 - 2017-08-11 02:52 - 001491456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2017-12-29 22:04 - 2017-08-11 02:49 - 000346624 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2017-12-29 22:04 - 2017-08-11 02:44 - 001095680 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-12-29 22:04 - 2017-08-11 02:43 - 000865792 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-12-29 22:04 - 2017-08-11 02:41 - 000307200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2017-12-29 22:04 - 2017-08-11 02:39 - 002779136 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2017-12-29 22:04 - 2017-08-11 02:30 - 002464256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2017-12-29 22:04 - 2017-08-06 22:20 - 000607232 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2017-12-29 22:04 - 2017-08-06 22:20 - 000542720 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll
2017-12-29 22:04 - 2017-08-06 08:13 - 000530432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2017-12-29 22:04 - 2017-08-02 03:19 - 000358912 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-12-29 22:04 - 2017-08-01 09:25 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-12-29 22:04 - 2017-07-22 19:34 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\iscsium.dll
2017-12-29 22:04 - 2017-07-22 18:32 - 000027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iscsium.dll
2017-12-29 22:04 - 2017-07-17 20:53 - 004298240 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-12-29 22:04 - 2017-07-17 00:55 - 003551744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-12-29 22:04 - 2017-07-12 21:29 - 000420440 _____ (Microsoft Corporation) C:\Windows\system32\wevtapi.dll
2017-12-29 22:04 - 2017-07-12 21:29 - 000075440 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-12-29 22:04 - 2017-07-12 21:25 - 000308872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtapi.dll
2017-12-29 22:04 - 2017-07-12 21:25 - 000066112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-12-29 22:04 - 2017-07-08 20:03 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-12-29 22:04 - 2017-07-08 19:43 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-12-29 22:04 - 2017-07-08 19:30 - 000039936 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-12-29 22:04 - 2017-07-08 04:14 - 000100184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2017-12-29 22:04 - 2016-07-08 15:17 - 000377344 _____ (Microsoft Corporation) C:\Windows\system32\mprddm.dll
2017-12-29 22:04 - 2016-07-08 15:17 - 000319488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprddm.dll
2017-12-29 22:04 - 2016-07-07 23:32 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\agilevpn.sys
2017-12-29 22:04 - 2016-07-07 23:10 - 000233472 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2017-12-29 22:04 - 2016-07-07 23:01 - 000272896 _____ (Microsoft Corporation) C:\Windows\system32\rasppp.dll
2017-12-29 22:04 - 2016-07-07 22:04 - 000173568 _____ (Microsoft Corporation) C:\Windows\system32\rasman.dll
2017-12-29 22:04 - 2016-07-07 21:44 - 000429568 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll
2017-12-29 22:04 - 2016-07-07 21:41 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll
2017-12-29 22:04 - 2016-07-07 21:29 - 000704512 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll
2017-12-29 22:04 - 2016-07-07 21:18 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll
2017-12-29 22:04 - 2016-07-07 21:11 - 000185856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasppp.dll
2017-12-29 22:04 - 2016-07-07 20:35 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasman.dll
2017-12-29 22:04 - 2016-07-07 20:14 - 000628736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll
2017-12-29 22:04 - 2016-02-05 16:11 - 000845312 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2017-12-29 22:04 - 2016-02-05 16:11 - 000422400 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2017-12-29 22:04 - 2016-02-05 16:07 - 000272384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2017-12-29 22:04 - 2016-01-09 02:38 - 000091992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2017-12-29 22:04 - 2015-10-11 07:34 - 000027992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2017-12-29 22:04 - 2015-10-10 19:41 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2017-12-29 22:04 - 2015-10-10 19:41 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2017-12-26 20:17 - 2017-12-26 20:17 - 006495733 _____ C:\Users\uzivatel\Downloads\0917.pdf
2017-12-21 18:06 - 2017-12-21 18:05 - 000365680 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-12-21 18:06 - 2017-12-21 18:05 - 000149344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2017-12-14 21:22 - 2017-12-14 21:22 - 000001761 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-12-14 21:22 - 2017-12-14 21:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-12-14 21:22 - 2017-12-14 21:22 - 000000000 ____D C:\Program Files\iTunes
2017-12-14 21:22 - 2017-12-14 21:22 - 000000000 ____D C:\Program Files\iPod
2017-12-11 22:42 - 2017-12-11 22:42 - 000002167 _____ C:\Users\Public\Desktop\Foxit Reader.lnk
2017-12-11 22:42 - 2017-12-11 22:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2017-12-10 21:18 - 2017-12-10 21:18 - 000434527 _____ C:\Users\uzivatel\Downloads\jidlo-na-prvnim-miste-readers-digest.pdf
2017-12-10 14:46 - 2017-12-10 14:47 - 000409890 _____ C:\Users\uzivatel\Downloads\Expert na koncovku - prax.pgn
2017-12-10 14:46 - 2017-12-10 14:46 - 000251156 _____ C:\Users\uzivatel\Downloads\Tvoj vítazny Plan - prax.pgn
2017-12-10 14:46 - 2017-12-10 14:46 - 000052346 _____ C:\Users\uzivatel\Downloads\Expert na koncovku - ulohy.pgn
2017-12-10 14:46 - 2017-12-10 14:46 - 000044253 _____ C:\Users\uzivatel\Downloads\1.Bonus 1.pdf
2017-12-10 14:37 - 2017-12-10 14:37 - 000504748 _____ C:\Users\uzivatel\Downloads\V40-EDITION-MY18.pdf
2017-12-06 21:42 - 2017-12-06 21:42 - 000000000 ____D C:\Windows\System32\Tasks\Avast Software
2017-12-06 21:42 - 2017-12-06 21:42 - 000000000 ____D C:\Program Files\Common Files\Avast Software

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-01 22:20 - 2017-10-03 18:38 - 002393088 _____ (Farbar) C:\Users\uzivatel\Desktop\FRST64.exe
2018-01-01 22:20 - 2017-07-25 21:18 - 000000000 ____D C:\FRST
2018-01-01 21:45 - 2015-09-30 16:16 - 000004288 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-01-01 21:45 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-01-01 21:45 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\system32\Macromed
2018-01-01 21:42 - 2017-09-24 18:14 - 000000000 ____D C:\Program Files\Mozilla Firefox
2018-01-01 21:42 - 2016-11-15 18:41 - 000000000 ____D C:\Users\uzivatel\AppData\LocalLow\Mozilla
2018-01-01 21:08 - 2014-03-18 16:25 - 000865068 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-01 21:08 - 2013-08-22 14:36 - 000000000 ____D C:\Windows\Inf
2018-01-01 21:05 - 2015-09-02 17:43 - 000000125 _____ C:\Users\uzivatel\AppData\Roaming\sp_data.sys
2018-01-01 21:00 - 2013-08-22 15:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-01-01 12:00 - 2015-09-02 17:49 - 000003480 _____ C:\Windows\System32\Tasks\ASUS Live Update1
2018-01-01 12:00 - 2015-09-02 17:49 - 000003470 _____ C:\Windows\System32\Tasks\ASUS Live Update2
2017-12-30 22:54 - 2015-09-02 17:48 - 000003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4176085001-3363555415-2058170901-1001
2017-12-30 20:20 - 2015-05-13 10:07 - 000000000 ____D C:\Program Files\CONEXANT
2017-12-30 19:57 - 2015-05-13 10:07 - 000000000 ____D C:\ProgramData\Conexant
2017-12-30 19:57 - 2013-08-22 16:20 - 000000000 ____D C:\Windows\CbsTemp
2017-12-30 13:47 - 2013-08-22 14:25 - 000262144 ___SH C:\Windows\system32\config\BBI
2017-12-29 23:27 - 2013-08-22 16:36 - 000000000 ___RD C:\Windows\ToastData
2017-12-29 23:27 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\SysWOW64\setup
2017-12-29 23:27 - 2013-08-22 16:36 - 000000000 ____D C:\Windows\system32\setup
2017-12-29 22:05 - 2015-09-05 10:54 - 000000000 ____D C:\Windows\system32\MRT
2017-12-29 22:04 - 2015-09-05 10:54 - 133326408 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-12-29 15:32 - 2015-09-02 18:09 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-12-29 10:06 - 2015-09-02 18:09 - 000000950 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-12-25 15:14 - 2017-07-27 14:23 - 000000000 ____D C:\Users\uzivatel\Documents\ChessBase
2017-12-21 18:06 - 2017-10-14 12:44 - 000003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-12-21 18:05 - 2017-11-09 22:29 - 000185096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 001025176 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000457400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000358672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000343768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000321512 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000204456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000199448 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000110336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000084384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000057696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2017-12-21 18:05 - 2017-10-14 12:44 - 000046976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-12-11 22:42 - 2017-06-21 18:59 - 000000000 ____D C:\ProgramData\Foxit Software
2017-12-04 17:23 - 2013-08-22 16:38 - 000835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-12-04 17:23 - 2013-08-22 16:38 - 000177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

==================== Files in the root of some directories =======

2015-09-02 17:43 - 2018-01-01 21:05 - 000000125 _____ () C:\Users\uzivatel\AppData\Roaming\sp_data.sys
2015-10-01 14:42 - 2015-10-01 14:42 - 000000017 _____ () C:\Users\uzivatel\AppData\Local\resmon.resmoncfg

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-12-23 10:47

==================== End of FRST.txt ============================

Re: kontrola - podozrenie na malware

Napsal: 02 led 2018 12:59
od Rudy
Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.

Re: kontrola - podozrenie na malware

Napsal: 02 led 2018 21:35
od talbott
Islo o to, ze po kliknuti na beznu stranku (napr. diskusia k nejakemu clanku) ma presmerovalo na nejake hazardne hry apod.

# AdwCleaner 7.0.6.0 - Logfile created on Tue Jan 02 20:32:50 2018
# Updated on 2017/21/12 by Malwarebytes
# Running on Windows 8.1 Pro (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

No malicious registry entries deleted.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries deleted.

*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[C0].txt - [1220 B] - [2017/7/26 19:15:13]
C:/AdwCleaner/AdwCleaner[C1].txt - [1484 B] - [2017/8/25 19:59:48]
C:/AdwCleaner/AdwCleaner[S0].txt - [1061 B] - [2017/7/26 19:11:39]
C:/AdwCleaner/AdwCleaner[S1].txt - [1346 B] - [2017/8/25 19:20:0]
C:/AdwCleaner/AdwCleaner[S2].txt - [1216 B] - [2017/8/25 20:9:35]
C:/AdwCleaner/AdwCleaner[S3].txt - [1283 B] - [2017/8/26 21:9:12]
C:/AdwCleaner/AdwCleaner[S4].txt - [1350 B] - [2018/1/2 20:32:17]


########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt ##########

Re: kontrola - podozrenie na malware

Napsal: 02 led 2018 22:08
od Rudy
Toto je OK. Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
GroupPolicy: Restriction <==== ATTENTION
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\2480718.js [2018-01-01] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\2480718.cfg [2018-01-01] <==== ATTENTION

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Re: kontrola - podozrenie na malware

Napsal: 05 led 2018 21:25
od talbott
Fix result of Farbar Recovery Scan Tool (x64) Version: 02.01.2018
Ran by uzivatel (05-01-2018 21:23:26) Run:1
Running from C:\Users\uzivatel\Desktop
Loaded Profiles: uzivatel (Available Profiles: uzivatel & Administrator)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION
GroupPolicy: Restriction <==== ATTENTION
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\2480718.js [2018-01-01] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files\mozilla firefox\2480718.cfg [2018-01-01] <==== ATTENTION

EmptyTemp:
End
*****************

HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRoot% <==== ATTENTION => restored successfully
HKLM Group Policy restriction on software: %HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ProgramFilesDir% <==== ATTENTION => restored successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\Program Files\mozilla firefox\defaults\pref\2480718.js => moved successfully
C:\Program Files\mozilla firefox\2480718.cfg => moved successfully

=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 7563016 B
Java, Flash, Steam htmlcache => 524 B
Windows/system/drivers => 764162 B
Edge => 0 B
Chrome => 0 B
Firefox => 27304021 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 138717 B
systemprofile32 => 0 B
LocalService => 3306 B
NetworkService => 0 B
uzivatel => 8505173 B
Administrator => 13884046 B

RecycleBin => 0 B
EmptyTemp: => 63.5 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 21:23:43 ====

Re: kontrola - podozrenie na malware

Napsal: 05 led 2018 21:58
od Rudy
Smazáno. Nastala nějaká změna?

Re: kontrola - podozrenie na malware

Napsal: 06 led 2018 13:34
od talbott
dakujem, zmizlo to uz po prvom kroku

co to vlastne bolo a ako sa proti tomu da branit?

Re: kontrola - podozrenie na malware

Napsal: 06 led 2018 14:14
od Rudy
Byl to tzv. únos prohlížeče. Někde jste klikl na něco, co se tvářilo přívětivě (anebo jste to musel vidět za každou cenu :D ) a stáhlo se něco, co přenastavilo prohlížeč. Před kliknutím přemýšlet nad důsledky. Antiviry toto nezachtí, protože to není virus v pravém slova smyslu.