Премини към съдържанието

Филтри за търсене

Показани резултати за тагове 'приключен'.

  • Търсене по таг

    Въведете тагове разделени със запетая
  • Търсене по автор

Търсене в


Форуми

  • Софтуер
    • Нови Програми
    • Търсене на Програми
    • Програми - Проблеми и Дискусии
    • Драйвери - Търсене, Проблеми, Линкове
    • Операционни системи
    • Сигурност и антивирусна защита
    • Игри
  • Хардуер
    • Общи хардуерни въпроси
    • Преносими компютри
    • Дънни платки
    • Запаметяващи устройства и памети
    • Монитори, Аудио и Видеокарти
    • Периферия
    • Овърклок и PC модинг
    • Нови конфигурации и части, въпроси, препоръки и мнения
  • Мобилни телефони, GSM, Мобилни приложения, Комуникации
    • Мобилни телефони - Въпроси, Проблеми, Софтуер
    • Съвети при избор на телефон
    • Мобилни Приложения (Apps)
    • Мобилни оператори, Мрежи, Промоции, Абонаменти, Услуги
    • Други теми относно мобилни телефони
  • Уеб дизайн, Графичен дизайн, Програмиране
    • Програмиране
    • Графичен Дизайн и Визуални изкуства
    • CMS, Форумни и Торент системи
    • Хостинг, Домейни, Уеб сървъри
    • SEO, Уеб оптимизация и стандарти
  • Битова Техника
    • Аудиотехника
    • Телевизори, Видео и Фото техника, Видео наблюдение
    • Климатици - проблеми, съвети, въпроси
    • Бойлери, Печки, Отопление
    • Друга битова техника
  • Интернет, Локални Мрежи и GPS Навигации
    • Интернет, WiFi, xDSL и Локална Мрежа
    • Биткойн и Криптовалути
    • Онлайн бизнес, AdSense, Affilate програми
    • Рутери, Модеми, Суичове
    • Facebook - проблеми, въпроси, вируси
    • Skype, VoIP - Интернет телефония
    • GPS, Навигационни системи - Въпроси, Карти, Проблеми
  • Изкуство
    • Музика
    • Кино и Телевизия
    • Поезия и Лично творчество
    • Изкуство - Изящно, Приложно и Сценично
    • Фотография и Фотографска техника
    • Литература, Книги (e-books, video trainings, tutorials & etc.)
  • Други
    • Статии и ревюта
    • Образование и обща култура
    • Религия, Мистика, Езотерика
    • История
    • Философия
    • Психология и Психотерапия
    • Новини от България и Света
    • Българите по света
    • Политика
    • Право и Юридически консултации
    • Здраве и Mедицина
    • Банки, Застраховане, Финанси, Кредити
    • Тийн Зона (Teen Zone)
    • Купувам / Продавам
    • Всичко останало
  • Хоби, Развлечение и Свободно време
  • За kaldata.com
  • Теми
  • Photoshop майнаци Теми
  • python3 data types
  • какви са ви любимите игри?? Темиигри за вас
  • супрески игри и рекорди Темиигри за вас

Блогове

Няма резултати

Няма резултати

Категории

  • Компютри
    • Компютърни конфигурации
    • Компютърни компоненти
    • Периферни устройства
    • Дънни платки
    • Мултимедия
    • Компютърни игри и софтуер
    • Администриране и интернет услуги
    • Компютърни аксесоари
    • Лаптопи и таблети
    • Видеокарти
    • Монитори
    • Процесори
    • Хард дискове и Памети
    • Други
  • Електроника
    • Телефони, GSM апарати
    • Аудио
    • Битова електроника
    • GPS и навигационни системи
    • Фотоапарати и обективи
    • TV и Видео
    • Други
  • Имоти
    • Гарсониери
    • Къщи и вили
    • Търговски площи
    • Гаражи
    • Апартаменти
    • Терени
    • Офиси
    • Други имоти в продажба
  • Авто-мото
    • Автомобили
    • Велосипеди
    • Лодки
    • Резервни части
    • Авто аксесоари
    • Мотоциклети
    • Скутери и ATV
    • Камиони и Автобуси
    • Авто сервизи и Rent-a-Car
    • Други
  • Работа
    • Работа в страната
    • Работа в чужбина
    • Стажове
    • Работа от вкъщи
    • Непълно работно време
  • Услуги
  • Строителство
  • Туризъм
  • Курсове и обучение
  • Домашни любимци
  • Други
  • супрески игри и рекорди Обяви
  • супрески игри и рекорди Обяви

Категории

  • Домашни любимци и Животни
  • Игри
  • Инциденти и Екстремни
  • Коли и превозни средства
  • Музика
    • Българска музика
    • Джаз
    • Електронна
    • Метъл и Рок
    • Народна и Фолклор
    • Поп и Диско
    • Поп-фолк
    • Рап и хип-хоп
    • Ритъм енд блус и соул
    • Друга
  • Новини и политика
  • Реклами
  • Смях и Развлечение
  • Спорт
  • Технологии, Компютри, Хардуер
  • ТВ Предавания и Шоу Програми
  • Хора и блогове
  • Филми и анимация
  • Други
  • Old School Hip-Hop and Electroo 80" Видео клипчета

Календари

  • Събития
  • Изложения
  • Семинари
  • Парти
  • Празници в България

Групи продукти

  • Банер Реклами

Categories

  • Articles

Търсене в...

Търси резултати които съдържат...


Дата

  • Начало

    Край


Последно обновяване

  • Начало

    Край


Филтриране по брой...

Регистрация

  • Начало

    Край


Група


Skype


Facebook


Google+


Twitter


ICQ


Yahoo


Интернет сайт


Град


Интереси

Открити 321 резултата

  1. Здравейте, Получих спам имейл в АБВ пощата ми, който ме изнудваше за 1100 лв в биткойн валута срещу изтриване на потенциален мой клип с нецензурно съдържание. Порчетох, че е измама, но все пак има риск за троянки кон в системата. Изпълних инструкциите от темата, но не мога да ги разчета, затова ги прикачвам тук Благодаря предварително! FRST.txt Addition.txt
  2. здравейте моля и в тази тема специалистите за помощ,проблемът е следният последно си спомням че имах няколко имейла от които единият отворих и на следващият ден при включване на компютъра таск менаджера показва 100% и непрекъснат сигнал след което се изключва сам, с много мъки успях да инсталирам Kaspersky и в момента е по добре,но все още ми товари много без да има основание предимно при гледане на клип в ютуб,качвам ви резултата от сканирането
  3. Това е темата която ме насочи тук, с подробна информация, какво да правя сега?
  4. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-03-2020 Ran by NightRider (administrator) on OUTPOST (01-04-2020 15:19:27) Running from C:\Users\NightRider\Desktop Loaded Profiles: NightRider (Available Profiles: NightRider) Platform: Windows 10 Pro Version 1909 18363.753 (X64) Language: Български (България) Default browser: FF Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avp.exe (Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avpui.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Windows Firewall Control\wfc.exe (Malwarebytes Inc -> Malwarebytes) C:\Program Files\Malwarebytes\Windows Firewall Control\wfcs.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_12003.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\CredentialEnrollmentManager.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation -> NVIDIA Corporation) C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\NVDisplay.Container.exe (Valve -> Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation) E:\Games\Steam\steam.exe (VoodooSoft, LLC -> VoodooSoft, LLC ) C:\Program Files\VoodooShield\VoodooShield.exe (VoodooSoft, LLC -> VoodooSoft, LLC ) C:\Program Files\VoodooShield\VoodooShieldService.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Malwarebytes Windows Firewall Control] => C:\Program Files\Malwarebytes\Windows Firewall Control\wfc.exe [647856 2020-01-05] (Malwarebytes Inc -> Malwarebytes) HKU\S-1-5-21-1903147458-2263829336-249963103-1001\...\Run: [Steam] => E:\Games\Steam\steam.exe [3370272 2020-03-27] (Valve -> Valve Corporation) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {221E7CE6-5148-42C5-A220-9EF6F74E9A63} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [739624 2018-04-23] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) Task: {B4A41E61-B4EE-4894-B34F-69ED2CD1A78C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18233016 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd) Task: {B9473F12-BF68-46A8-ABB2-FCE28B5FCEC6} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) Task: {DAE116B0-629E-4A4B-B509-24E39DF374CC} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-02-28] (Piriform Software Ltd -> Piriform Software Ltd) Task: {E2964865-E1B7-4E2C-B492-BC9EB0C98BEE} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [1724928 2020-01-21] () [File not signed] (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 217.10.251.114 Tcpip\..\Interfaces\{9706d7e1-ab22-4a95-8faa-594f0f5e1d81}: [NameServer] 1.1.1.1,1.0.0.1 Tcpip\..\Interfaces\{9706d7e1-ab22-4a95-8faa-594f0f5e1d81}: [DhcpNameServer] 217.10.251.114 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = Edge: ====== DownloadDir: C:\Users\NightRider\Downloads FireFox: ======== FF DefaultProfile: 84toqkl3.default FF ProfilePath: C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\84toqkl3.default [2020-01-17] FF ProfilePath: C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release [2020-04-01] FF Homepage: Mozilla\Firefox\Profiles\ujtk5yth.default-release -> about:blank FF Extension: (HTTPS Навсякъде) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\[email protected] [2020-03-28] FF Extension: (Privacy Badger) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\[email protected] [2020-02-20] FF Extension: (Kaspersky Protection) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\[email protected] [2020-02-15] FF Extension: (uBlock Origin) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\[email protected] [2020-03-10] FF Extension: (Black Pixel Firefox) - C:\Users\NightRider\AppData\Roaming\Mozilla\Firefox\Profiles\ujtk5yth.default-release\Extensions\{46f60d87-d458-4083-b2a6-d8165d1c296c}.xpi [2020-01-03] FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2020-01-03] <==== ATTENTION (Points to *.cfg file) FF ExtraCheck: C:\Program Files\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2020-01-03] <==== ATTENTION Chrome: ======= CHR HKLM\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk CHR HKLM-x32\...\Chrome\Extension: [elhpdacimkjpccooodognopfhbdgnpbk] - hxxps://chrome.google.com/webstore/detail/elhpdacimkjpccooodognopfhbdgnpbk ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avp.exe [357416 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [8402648 2020-01-04] (BattlEye Innovations e.K. -> ) S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [805488 2020-01-04] (EasyAntiCheat Oy -> EasyAntiCheat Ltd) S3 klvssbridge64_20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\x64\vssbridge64.exe [438928 2019-03-21] (Kaspersky Lab -> AO Kaspersky Lab) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6933272 2020-02-28] (Malwarebytes Inc -> Malwarebytes) S3 mracsvc; C:\Windows\System32\mracsvc.exe [18997912 2020-01-05] (Mail.Ru LLC -> LLC Mail.Ru) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [5930136 2020-03-27] (Microsoft Windows Publisher -> Microsoft Corporation) R2 VoodooShieldService; C:\Program Files\VoodooShield\VoodooShieldService.exe [147968 2020-01-10] (VoodooSoft, LLC -> VoodooSoft, LLC ) S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-27] (Microsoft Windows Publisher -> Microsoft Corporation) R2 wfcs; C:\Program Files\Malwarebytes\Windows Firewall Control\wfcs.exe [124592 2020-01-05] (Malwarebytes Inc -> Malwarebytes) S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-27] (Microsoft Windows Publisher -> Microsoft Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f %ProgramData%\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 BEDaisy; C:\Program Files (x86)\Common Files\BattlEye\BEDaisy.sys [2836840 2020-01-05] (BattlEye Innovations e.K. -> ) R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [246912 2019-02-16] (Kaspersky Lab -> AO Kaspersky Lab) R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [79768 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab) R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [145504 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab) R1 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [93312 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab) S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [37816 2019-01-24] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab) R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [251512 2019-11-01] (Kaspersky Lab -> AO Kaspersky Lab) R1 klgse; C:\Windows\System32\DRIVERS\klgse.sys [586496 2020-01-27] (Kaspersky Lab -> AO Kaspersky Lab) R1 klhk; C:\Windows\system32\DRIVERS\klhk.sys [1163216 2020-01-24] (Kaspersky Lab -> AO Kaspersky Lab) R3 klids; C:\ProgramData\Kaspersky Lab\AVP20.0\Bases\klids.sys [203328 2020-03-19] (Kaspersky Lab -> AO Kaspersky Lab) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [998296 2020-02-12] (Kaspersky Lab -> AO Kaspersky Lab) R1 klim6; C:\Windows\system32\DRIVERS\klim6.sys [58192 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab) R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [79184 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab) R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [59512 2019-03-18] (Kaspersky Lab -> AO Kaspersky Lab) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [51328 2019-03-13] (Kaspersky Lab -> AO Kaspersky Lab) S3 klpnpflt; C:\Windows\system32\DRIVERS\klpnpflt.sys [45904 2019-03-10] (Kaspersky Lab -> AO Kaspersky Lab) R0 klupd_klif_arkmon; C:\Windows\System32\Drivers\klupd_klif_arkmon.sys [251256 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_kimul; C:\Windows\System32\Drivers\klupd_klif_kimul.sys [99152 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_klark; C:\Windows\System32\Drivers\klupd_klif_klark.sys [306248 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R0 klupd_klif_klbg; C:\Windows\System32\Drivers\klupd_klif_klbg.sys [119744 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R3 klupd_klif_mark; C:\Windows\System32\Drivers\klupd_klif_mark.sys [204520 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) S4 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [105600 2019-03-05] (Kaspersky Lab -> AO Kaspersky Lab) R1 klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [211048 2020-01-03] (Kaspersky Lab -> AO Kaspersky Lab) R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [232272 2019-03-19] (Kaspersky Lab -> AO Kaspersky Lab) S0 MbamElam; C:\Windows\System32\DRIVERS\MbamElam.sys [20936 2020-02-28] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes) S3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [248968 2020-03-31] (Malwarebytes Inc -> Malwarebytes) S3 mracdrv; C:\Windows\System32\drivers\mracdrv.sys [18234792 2020-01-05] (Mail.Ru LLC -> LLC Mail.Ru) R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_d223212c0a2275b5\nvlddmkm.sys [23251968 2019-12-28] (NVIDIA Corporation -> NVIDIA Corporation) R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> ) R3 RTL8023x64; C:\Windows\System32\drivers\Rtnic64.sys [51712 2019-03-19] (Microsoft Windows -> Realtek Semiconductor Corporation ) R3 VSScanner; C:\Windows\System32\DRIVERS\vsscanner.sys [29752 2018-06-25] (Microsoft Windows Hardware Compatibility Publisher -> VoodooSoft, LLC) S3 WdBoot; C:\Windows\system32\drivers\wd\WdBoot.sys [45960 2020-03-27] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\wd\WdFilter.sys [391392 2020-03-27] (Microsoft Windows -> Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-27] (Microsoft Windows -> Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-04-01 15:19 - 2020-04-01 15:20 - 000015114 _____ C:\Users\NightRider\Desktop\FRST.txt 2020-04-01 15:18 - 2020-04-01 15:19 - 000000000 ____D C:\FRST 2020-04-01 15:18 - 2020-04-01 15:18 - 002280448 _____ (Farbar) C:\Users\NightRider\Desktop\FRST64.exe 2020-04-01 02:55 - 2020-04-01 02:55 - 000000641 _____ C:\Users\NightRider\Desktop\JRT.txt 2020-04-01 02:50 - 2020-04-01 02:50 - 000000000 ____D C:\AdwCleaner 2020-04-01 02:49 - 2020-04-01 02:49 - 008199856 _____ (Malwarebytes) C:\Users\NightRider\Desktop\AdwCleaner.exe 2020-04-01 02:48 - 2020-04-01 02:48 - 001790024 _____ (Malwarebytes) C:\Users\NightRider\Desktop\JRT.exe 2020-03-31 04:09 - 2020-03-31 04:09 - 000248968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2020-03-31 04:09 - 2020-03-31 04:09 - 000214496 ____N (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys 2020-03-31 04:04 - 2020-03-31 04:04 - 000000000 ___HD C:\Windows\system32\GroupPolicy 2020-03-31 02:42 - 2020-03-31 02:42 - 025444352 _____ (Microsoft Corporation) C:\Windows\system32\Hydrogen.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 009930760 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 007604584 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 006522320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 005040640 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 004563416 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 004538880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 004129416 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 002494744 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 001610240 _____ (Microsoft Corporation) C:\Windows\system32\HologramCompositor.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 001397560 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 001077048 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 000982840 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000783480 _____ (Microsoft Corporation) C:\Windows\system32\tcblaunch.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 000772096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2020-03-31 02:42 - 2020-03-31 02:42 - 000768736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Mirage.Internal.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000561464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2020-03-31 02:42 - 2020-03-31 02:42 - 000530432 _____ (Microsoft Corporation) C:\Windows\system32\sppcext.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000420360 _____ (Microsoft Corporation) C:\Windows\system32\MSAudDecMFT.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000211256 _____ (Microsoft Corporation) C:\Windows\system32\tcbloader.dll 2020-03-31 02:42 - 2020-03-31 02:42 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\pacjsworker.exe 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth9.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth8.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth7.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth6.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth5.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth4.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth3.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth2.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth12.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth11.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth10.bin 2020-03-31 02:42 - 2020-03-31 02:42 - 000000315 _____ C:\Windows\system32\DrtmAuth1.bin 2020-03-27 02:57 - 2020-03-27 02:57 - 022636544 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 019813376 _____ (Microsoft Corporation) C:\Windows\system32\HologramWorld.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 018027008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 014818816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 008013824 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 007017472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 003799552 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 003753472 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 003742544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneCoreUAPCommonProxyStub.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 002986808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 002800128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 002768440 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 002369576 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.AppAgent.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 002188600 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 002087168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001835008 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001659408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.AppAgent.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001587712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001545216 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 001495864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001477112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001386296 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001368576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wpc.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001368576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Input.Inking.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001264640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 001245184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBroker.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001081856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Vpn.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 001055376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000993280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSWorkspace.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000980832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000923136 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000912896 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000892416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000865280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000865280 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000785920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000744960 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.Office2013CustomActions.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000729600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FlightSettings.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BTAGService.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000673704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000647680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000632832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000628408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000618296 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000555008 _____ (Microsoft Corporation) C:\Windows\system32\appwiz.cpl 2020-03-27 02:57 - 2020-03-27 02:57 - 000538160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000529408 _____ (Microsoft Corporation) C:\Windows\system32\nltest.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000514560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000507152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskschd.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000497152 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000491008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppcext.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000487784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000477496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS 2020-03-27 02:57 - 2020-03-27 02:57 - 000456504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000456192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appwiz.cpl 2020-03-27 02:57 - 2020-03-27 02:57 - 000452096 _____ (Microsoft Corporation) C:\Windows\system32\rdpclip.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000415760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aepic.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000410112 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000406480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Enumeration.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\es.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000330240 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000321536 _____ (Microsoft Corporation) C:\Windows\system32\wbadmin.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000277864 _____ (Microsoft Corporation) C:\Windows\system32\LsaIso.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000234496 _____ (Microsoft Corporation) C:\Windows\system32\iasrad.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000227840 _____ (Microsoft Corporation) C:\Windows\system32\IndexedDbLegacy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000203264 _____ (Microsoft Corporation) C:\Windows\system32\LanguageComponentsInstaller.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000190048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\logoncli.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasrad.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000185952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\deviceaccess.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000179200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.XamlHost.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000178192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000175616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IndexedDbLegacy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000163840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000147696 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.XamlHost.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000123952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KerbClientShared.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000118272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slc.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000101888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sppc.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000093712 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000090624 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000089536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32u.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000087040 _____ (Microsoft Corporation) C:\Windows\system32\iasacct.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000084280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hvservice.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Custom.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000066624 _____ (Microsoft Corporation) C:\Windows\system32\iumcrypt.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iasacct.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000050544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudNotifications.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\iaspolcy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tbauth.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\Microsoft.Uev.Office2010CustomActions.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000040448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iaspolcy.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Microsoft.Uev.Office2010CustomActions.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000033080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hwpolicy.sys 2020-03-27 02:57 - 2020-03-27 02:57 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\ias.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cmintegrator.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000029184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TokenBrokerCookies.exe 2020-03-27 02:57 - 2020-03-27 02:57 - 000023552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ias.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000021520 _____ (Microsoft Corporation) C:\Windows\system32\kdhvcom.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\slcext.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000015872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Custom.ps.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000010752 _____ (Microsoft Corporation) C:\Windows\system32\DMAlertListener.ProxyStub.dll 2020-03-27 02:57 - 2020-03-27 02:57 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DMAlertListener.ProxyStub.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 017790464 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 007849216 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 006168064 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 003977216 _____ (Microsoft Corporation) C:\Windows\system32\tellib.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 003728384 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 003708928 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 003586872 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 003547648 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 003109376 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 002871608 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 002143232 _____ (Microsoft Corporation) C:\Windows\system32\WpcDesktopMonSvc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 002126144 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 002114560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.CloudStore.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001960448 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001945600 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001942528 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001918976 _____ (Microsoft Corporation) C:\Windows\system32\wevtsvc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001783296 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Input.Inking.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001762816 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001757096 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2020-03-27 02:56 - 2020-03-27 02:56 - 001726264 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001719808 _____ (Microsoft Corporation) C:\Windows\system32\Wpc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001512832 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 001497600 _____ (Microsoft Corporation) C:\Windows\system32\TokenBroker.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001480192 _____ (Microsoft Corporation) C:\Windows\system32\usocoreworker.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 001427456 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Vpn.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001413704 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001378528 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001300280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 001263856 _____ (Microsoft Corporation) C:\Windows\system32\WpcMon.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 001261808 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001257472 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001243648 _____ (Microsoft Corporation) C:\Windows\system32\TSWorkspace.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001180672 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001136128 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001127424 _____ (Microsoft Corporation) C:\Windows\system32\WpcRefreshTask.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001083904 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001071616 _____ (Microsoft Corporation) C:\Windows\system32\BTAGService.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 001011200 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000974336 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000924672 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000915192 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000893952 _____ (Microsoft Corporation) C:\Windows\system32\FlightSettings.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000879616 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Service.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000874512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000840704 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Language.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000811320 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000759272 _____ (Microsoft Corporation) C:\Windows\system32\taskschd.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000747320 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000735744 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000722072 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000684560 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000654912 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000638480 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000637240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000604984 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000589384 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000550400 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000524264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Enumeration.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000516096 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000515600 _____ (Microsoft Corporation) C:\Windows\system32\dcntel.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000513576 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000498688 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000469504 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000465208 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000459688 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000441144 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000437560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000416016 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\es.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000374784 _____ (Microsoft Corporation) C:\Windows\system32\ncbservice.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\WpcApi.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000324408 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000323584 _____ (Microsoft Corporation) C:\Windows\system32\sppcommdlg.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000297272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000278016 _____ (Microsoft Corporation) C:\Windows\system32\WpcTok.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000265216 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000259776 _____ (Microsoft Corporation) C:\Windows\system32\logoncli.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000259072 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000256000 _____ (Microsoft Corporation) C:\Windows\system32\UpdateDeploymentProvider.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000251704 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000251392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winnat.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000241152 _____ (Microsoft Corporation) C:\Windows\system32\policymanagerprecheck.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000231912 _____ (Microsoft Corporation) C:\Windows\system32\deviceaccess.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000200192 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000197632 _____ (Microsoft Corporation) C:\Windows\system32\Win32CompatibilityAppraiserCSP.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000193848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000169472 _____ (Microsoft Corporation) C:\Windows\system32\SpatialAudioLicenseSrv.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000164368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000152408 _____ (Microsoft Corporation) C:\Windows\system32\KerbClientShared.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000151352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\scmbus.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000142544 _____ (Microsoft Corporation) C:\Windows\system32\LicensingUI.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000140800 _____ (Microsoft Corporation) C:\Windows\system32\slc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000136192 _____ (Microsoft Corporation) C:\Windows\system32\sppc.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000127064 _____ (Microsoft Corporation) C:\Windows\system32\win32u.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000122368 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000115120 _____ (Microsoft Corporation) C:\Windows\system32\phoneactivate.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000108032 _____ (Microsoft Corporation) C:\Windows\system32\wwanprotdim.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000102216 _____ (Microsoft Corporation) C:\Windows\system32\changepk.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000096768 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Custom.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000089912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000088352 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\autopilot.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000071480 _____ (Microsoft Corporation) C:\Windows\system32\win32appinventorycsp.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.EnrollmentStatusTracking.ConfigProvider.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\keepaliveprovider.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\tbauth.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\CloudNotifications.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000059192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storufs.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000057856 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000057344 _____ (Microsoft Corporation) C:\Windows\system32\audioresourceregistrar.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000051200 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000047208 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000045568 _____ (Microsoft Corporation) C:\Windows\system32\cmintegrator.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.Common.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\UpgradeResultsUI.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\WpcProxyStubs.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\TokenBrokerCookies.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000036152 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCensus.exe 2020-03-27 02:56 - 2020-03-27 02:56 - 000031744 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\KNetPwrDepBroker.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\flpydisk.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000023552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Custom.ps.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\slcext.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\sbservicetrigger.dll 2020-03-27 02:56 - 2020-03-27 02:56 - 000018944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sfloppy.sys 2020-03-27 02:56 - 2020-03-27 02:56 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll 2020-03-27 02:07 - 2020-04-01 15:06 - 000000384 _____ C:\Users\NightRider\Desktop\А1 - Пряк път.lnk 2020-03-26 19:57 - 2020-03-26 19:57 - 000000000 ____D C:\Users\NightRider\AppData\Local\OneDrive 2020-03-13 02:24 - 2020-03-13 02:24 - 000021718 _____ C:\Users\NightRider\Desktop\stp_01x07_2020_e-tle(subsunacs.net).rar 2020-03-13 01:26 - 2020-02-28 03:44 - 000231936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthA2dp.sys 2020-03-10 22:06 - 2020-03-10 22:06 - 019850240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 011607552 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 009711616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 007755776 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 005911040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 005764664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 004855808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 004580352 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 003860832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtmpltfm.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 003819520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 003488768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 002956688 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 002224952 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 002072664 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 002031104 _____ C:\Windows\system32\rdpnano.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001867816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001835128 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001770552 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001555904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001490640 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001417976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001284096 _____ (Microsoft Corporation) C:\Windows\system32\werconcpl.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001282944 _____ (Microsoft Corporation) C:\Windows\system32\mfreadwrite.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001214976 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001108040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001098720 _____ (Microsoft Corporation) C:\Windows\system32\DolbyDecMFT.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 001088000 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000980320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtmpal.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DolbyDecMFT.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000915296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtmcodecs.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000883712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000757632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfreadwrite.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000739328 _____ (Microsoft Corporation) C:\Windows\system32\cscsvc.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000732000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ortcengine.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000705536 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000669496 _____ (Microsoft Corporation) C:\Windows\system32\computecore.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000668672 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000562176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000532480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000525312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000510768 _____ (Microsoft Corporation) C:\Windows\system32\systemreset.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000455168 _____ (Microsoft Corporation) C:\Windows\system32\upnphost.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000444416 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacDecoder.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000380416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacDecoder.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000328192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnphost.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000287744 _____ (Microsoft Corporation) C:\Windows\system32\MSFlacEncoder.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSFlacEncoder.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scecli.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000183808 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngOnline.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000155136 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000148992 _____ (Microsoft Corporation) C:\Windows\system32\MDMAppInstaller.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000139776 _____ (Microsoft Corporation) C:\Windows\system32\Chakrathunk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\wercplsupport.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000105472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakrathunk.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000078848 _____ (Microsoft Corporation) C:\Windows\system32\ProvSysprep.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000068096 _____ (Microsoft Corporation) C:\Windows\system32\udhisapi.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\udhisapi.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000055376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtmmvrortc.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000042296 _____ (Microsoft Corporation) C:\Windows\system32\SysResetErr.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\upnpcont.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\upnpcont.exe 2020-03-10 22:06 - 2020-03-10 22:06 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll 2020-03-10 22:06 - 2020-03-10 22:06 - 000019768 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 007905784 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 007263992 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 006084344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 004898144 _____ (Microsoft Corporation) C:\Windows\system32\rtmpltfm.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 003263488 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 002870272 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 002715648 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2020-03-10 22:05 - 2020-03-10 22:05 - 002698040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2020-03-10 22:05 - 2020-03-10 22:05 - 002561536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 002305536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 002289152 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001999952 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001764336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001751040 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001697792 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001665416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001664896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001657120 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001647072 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001581056 _____ (Microsoft Corporation) C:\Windows\system32\qmgr.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001484600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001458688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001354080 _____ (Microsoft Corporation) C:\Windows\system32\rtmpal.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001153024 _____ (Microsoft Corporation) C:\Windows\system32\windowsperformancerecordercontrol.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001149712 _____ (Microsoft Corporation) C:\Windows\system32\ApplyTrustOffline.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 001097728 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001091936 _____ (Microsoft Corporation) C:\Windows\system32\rtmcodecs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 001032544 _____ (Microsoft Corporation) C:\Windows\system32\ortcengine.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000898048 _____ (Microsoft Corporation) C:\Windows\system32\MdmDiagnostics.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000895488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000877232 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000868864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windowsperformancerecordercontrol.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000851968 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000734720 _____ (Microsoft Corporation) C:\Windows\system32\lpksetup.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000680448 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000680184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000670720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000636848 _____ (Microsoft Corporation) C:\Windows\system32\sxs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000613888 _____ (Microsoft Corporation) C:\Windows\system32\netprofmsvc.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000595968 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000578560 _____ (Microsoft Corporation) C:\Windows\system32\SppExtComObj.Exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000551824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000535552 _____ (Microsoft Corporation) C:\Windows\system32\usosvc.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000401408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000392192 _____ (Microsoft Corporation) C:\Windows\system32\Search.ProtocolHandler.MAPI2.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000379904 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000368128 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000336384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000329216 _____ (Microsoft Corporation) C:\Windows\system32\DiagnosticLogCSP.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000299520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000294400 _____ (Microsoft Corporation) C:\Windows\system32\provops.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000283136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Search.ProtocolHandler.MAPI2.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000277504 _____ (Microsoft Corporation) C:\Windows\system32\scecli.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000271872 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\netman.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000248064 _____ (Microsoft Corporation) C:\Windows\system32\weretw.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000233472 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000232960 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000226816 _____ (Microsoft Corporation) C:\Windows\system32\netprofm.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000221200 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000211968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000206336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys 2020-03-10 22:05 - 2020-03-10 22:05 - 000204800 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000201728 _____ (Microsoft Corporation) C:\Windows\system32\AppXApplicabilityBlob.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000199480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000193592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\weretw.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000165504 _____ (Microsoft Corporation) C:\Windows\system32\dmcmnutils.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000160768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000147456 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000146712 _____ (Microsoft Corporation) C:\Windows\system32\profext.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\provpackageapidll.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000138752 _____ (Microsoft Corporation) C:\Windows\system32\DeviceMetadataRetrievalClient.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000131896 _____ (Microsoft Corporation) C:\Windows\system32\DTUHandler.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000130112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmcmnutils.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000120560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\profext.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000114176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\agilevpn.sys 2020-03-10 22:05 - 2020-03-10 22:05 - 000113152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000112128 _____ (Microsoft Corporation) C:\Windows\system32\AxInstSv.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\NFCProvisioningPlugin.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\provdatastore.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000089088 _____ (Microsoft Corporation) C:\Windows\system32\BarcodeProvisioningPlugin.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\provtool.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\enterpriseresourcemanager.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\CustomInstallExec.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000071680 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\RemovableMediaProvisioningPlugin.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000066048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\enterpriseresourcemanager.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\mf3216.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\AxInstUI.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000056672 _____ (Microsoft Corporation) C:\Windows\system32\rtmmvrortc.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000046080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000045568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf3216.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\npmproxy.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\sxstrace.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Management.Provisioning.ProxyStub.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sxstrace.exe 2020-03-10 22:05 - 2020-03-10 22:05 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\nlmproxy.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\nlmsprep.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\MUILanguageCleanup.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\LangCleanupSysprepAction.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\lpksetupproxyserv.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000008192 _____ (Microsoft Corporation) C:\Windows\system32\msimg32.dll 2020-03-10 22:05 - 2020-03-10 22:05 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimg32.dll 2020-03-10 21:56 - 2020-02-11 07:48 - 000390656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2020-03-10 21:56 - 2020-02-11 07:37 - 000492544 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-04-01 15:19 - 2020-01-04 22:52 - 000000000 ____D C:\ProgramData\VoodooShield 2020-04-01 15:19 - 2020-01-03 23:18 - 000000000 ____D C:\ProgramData\Kaspersky Lab 2020-04-01 15:18 - 2019-03-19 07:50 - 000000000 ____D C:\Windows\INF 2020-04-01 15:11 - 2020-01-03 23:07 - 000000000 ____D C:\Users\NightRider\AppData\LocalLow\Mozilla 2020-04-01 15:02 - 2019-03-19 07:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2020-04-01 14:58 - 2020-01-03 22:32 - 000049064 _____ C:\Windows\system32\perfh002.dat 2020-04-01 14:58 - 2020-01-03 22:32 - 000012206 _____ C:\Windows\system32\perfc002.dat 2020-04-01 14:58 - 2020-01-03 20:16 - 000885446 _____ C:\Windows\system32\PerfStringBackup.INI 2020-04-01 14:52 - 2020-01-03 20:04 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-04-01 14:51 - 2020-01-03 23:07 - 000003136 _____ C:\Windows\system32\Tasks\MSIAfterburner 2020-04-01 14:51 - 2020-01-03 21:37 - 000017322 _____ C:\ProgramData\NVDisplay.ContainerLocalSystem.log_backup1 2020-04-01 14:51 - 2020-01-03 21:37 - 000017260 _____ C:\ProgramData\NVDisplayContainerWatchdog.log_backup1 2020-04-01 14:51 - 2020-01-03 21:37 - 000012206 _____ C:\ProgramData\DisplaySessionContainer1.log_backup1 2020-04-01 14:51 - 2019-03-19 07:37 - 000524288 _____ C:\Windows\system32\config\BBI 2020-04-01 14:50 - 2020-01-03 20:03 - 000000000 ____D C:\Windows\system32\SleepStudy 2020-04-01 11:34 - 2020-01-03 21:37 - 000001209 _____ C:\ProgramData\NvcDispCorePlugin.log_backup1 2020-04-01 08:18 - 2020-01-03 23:23 - 000004210 _____ C:\Windows\system32\Tasks\CCleaner Update 2020-04-01 03:44 - 2019-03-19 07:52 - 000000000 ___HD C:\Program Files\WindowsApps 2020-04-01 03:44 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\AppReadiness 2020-04-01 03:26 - 2020-01-03 21:21 - 000000000 ____D C:\Users\NightRider\AppData\Local\D3DSCache 2020-03-31 03:18 - 2020-01-03 21:17 - 000000000 ____D C:\Users\NightRider\AppData\Local\Packages 2020-03-31 03:12 - 2020-01-03 23:05 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner 2020-03-31 03:09 - 2019-03-19 07:37 - 000000000 ____D C:\Windows\CbsTemp 2020-03-31 02:45 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\ShellExperiences 2020-03-31 02:45 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\bcastdvr 2020-03-31 02:44 - 2020-01-03 21:15 - 000000000 ____D C:\Users\NightRider 2020-03-31 02:20 - 2020-01-04 03:56 - 000011069 _____ C:\ProgramData\DisplaySessionContainer2.log_backup1 2020-03-27 03:10 - 2020-01-03 20:03 - 000257824 _____ C:\Windows\system32\FNTCACHE.DAT 2020-03-27 03:08 - 2019-03-19 14:49 - 000000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2020-03-27 03:08 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\SystemResources 2020-03-27 03:08 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\system32\PerceptionSimulation 2020-03-27 03:08 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\Provisioning 2020-03-27 03:08 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\PolicyDefinitions 2020-03-27 02:42 - 2020-01-03 20:04 - 000000000 ____D C:\Windows\system32\Drivers\wd 2020-03-27 01:57 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\system32\NDF 2020-03-27 01:41 - 2019-03-19 07:37 - 000032768 _____ C:\Windows\system32\config\ELAM 2020-03-27 01:12 - 2020-01-04 00:34 - 000000000 ____D C:\Users\NightRider\AppData\Roaming\uTorrent 2020-03-22 04:51 - 2020-01-03 21:20 - 000003372 _____ C:\Windows\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1903147458-2263829336-249963103-1001 2020-03-22 04:51 - 2020-01-03 21:20 - 000000000 ___RD C:\Users\NightRider\OneDrive 2020-03-22 04:51 - 2020-01-03 21:15 - 000002406 _____ C:\Users\NightRider\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2020-03-15 00:17 - 2020-02-12 00:56 - 000000000 ____D C:\Users\NightRider\AppData\Local\ElevatedDiagnostics 2020-03-13 02:38 - 2020-01-04 00:38 - 000000000 ____D C:\Users\NightRider\AppData\LocalLow\uTorrent 2020-03-13 02:24 - 2020-01-04 00:38 - 000000000 ____D C:\Users\NightRider\AppData\Local\BitTorrentHelper 2020-03-12 02:54 - 2020-01-05 23:15 - 000012201 _____ C:\ProgramData\DisplaySessionContainer3.log_backup1 2020-03-10 22:15 - 2020-01-03 21:17 - 000000000 __RHD C:\Users\Public\AccountPictures 2020-03-10 22:15 - 2020-01-03 21:17 - 000000000 ___RD C:\Users\NightRider\AppData\3D Objects 2020-03-10 22:14 - 2020-02-19 23:08 - 000000000 ____D C:\Program Files\Mozilla Firefox 2020-03-10 22:14 - 2020-01-03 23:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2020-03-10 22:13 - 2019-03-19 07:52 - 000000000 ___SD C:\Windows\system32\DiagSvcs 2020-03-10 22:13 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\SysWOW64\Dism 2020-03-10 22:13 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\system32\SystemResetPlatform 2020-03-10 22:13 - 2019-03-19 07:52 - 000000000 ____D C:\Windows\system32\Dism 2020-03-10 22:13 - 2019-03-19 07:37 - 000000000 ____D C:\Windows\servicing 2020-03-10 22:12 - 2020-01-03 22:19 - 000000000 ____D C:\Windows\system32\MRT 2020-03-10 22:09 - 2020-01-03 22:19 - 121542864 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2020-03-09 17:47 - 2020-01-03 23:23 - 000000000 ____D C:\Program Files\CCleaner 2020-03-09 16:32 - 2020-02-23 19:48 - 000000000 ____D C:\ProgramData\boost_interprocess ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) ==================== End of FRST.txt ======================== Addition.txt
  5. Постоянно работи на 1-2% процесора на процес "system" в task manager. Също през няколко секунди се появява и процеса "registry" и от време на време се появява и "Service Host: Windows Event Log". Това нормално ли е? От какво е? Вирус ли е? Или се е повредила системата и трябва да я преинсталирам? Използвам Windows 10 Pro 64 bit 1909. Благодаря. Прикачам нужните файлове. Addition.txt FRST.txt
  6. Здравейте, Когато стартирам Google.com ми изписва, че връзката е поверителна и. NET::ERR_CERT_AUTHORITY_INVALID. Като това е във всички браузъри които имам - Chrome, Firefox, Explorer. Освен това се случва същото и когато влизам през телефона с Wi-Fi. Като съм с мобилен няма проблем. Дали цялата мрежа не е заразена? Наистина не знам, не разбирам от такива неща много. Освен това отваряйки различни сайтове ми дава, че са заразени с Other:Malware-gen[TrJ] и реално не ми отваря сайтовете. Имам аваст, който само го фиксва вируса. Сканирането ми дава, че имам заразени файлове на лаптопа в размер на 3 Gb. За да ги премахне ми иска да платя. Какво да направя в случая и как да отстраня вируса? Ще се радвам да ми помогнете, благодаря Ви предварително.
  7. Здравейте,открих наличието на софтуер за дистанционен достъп до компютъра си ,след като видях курсора на мишката да се движи по екрана.Не знам дали има промяна в работата на компютъра,поне не съм забелязал.Прилагам файловете при сканиране с FRST FRST.txt Addition.txt
  8. Здравейте изпратиха ме тук в този раздел да потърся помощ от вас с вирусите в компютъра ми .... Става въпрос че виждам по монитора си и на всякаде нещо като матрица Немога да прикачя файловете от scan-a на програмата FRST защото има лимит и те го надвишават
  9. Здравейте на всички, Въпросът ми е по - скоро опознаваъелен отколкото от тип проблем. Run-нах един exe файл който не ми даде никакъв output, като не забелязвам промяна и в работата на системата дори. Прекарах файлът през вирустотал като почти всички (с изключение на Cylane и JiangMin които аз не намирам за достоверни) изкараха че файлът е чист. Бихте ли могли да ми кажете дали този софтуер би могъл да причини някакви вреди на системата (или на потребителя като keylogging и други) Качвам линк към файла в докс: Линк П. С. Файлът е свален от репо от гитхъб. Нека който желае да пише, ще му пратя линк към репото. Благодаря предварително!
  10. Здравейте, понеже нещо товареше системата при броузване - мишката и станицата забива, прескача и т.н. реших да пусна една проверка с Malwarebytes но при инсталиране връща грешка след няколко рестарта и опити - прикаченият файл . Свалена е от оригиналният сайт, включително и през препратката от важната тема тук. Често имам над 15-20 таба отворени постоянно, до сега не е имало такъв проблем със забиване - курсора не движи после го показва направо на новата позиция понеже го мърдам постоянно докато прескочи. От известно време, машината изпиуква неясно защо 2-5 пъти дневно, което май се появи след като махнах батерията - единият елемент е подут значително - може би двоен размер в средата, и един има леко подут. Махнах батерията "от страх" да не стане нещо но тъй като явно не ми се занимава конкретно да вземам батерия сега и отново я монтирах поне да не изключва при спиране на ток или друго. Също така не можах да открия темата за разлини програми които пазят от копачи. В няколко теми бяха писали, че има отделна тема за това но така и не я открих, а исках да пусна поне проверка защото свалих някои игри от зеленчука.org Прикачам логовете от сканирането съгласно правилата на раздела с надежда да са "чисти" Addition.txt FRST.txt
  11. Здравейте , нямам оплаквания просто искам да направя профилактична проверка Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-02-2020 Ran by ВЕСКО (administrator) on PAPA (Hewlett-Packard HP EliteBook 6930p) (02-03-2020 14:47:25) Running from C:\Users\ВЕСКО\Downloads Loaded Profiles: ВЕСКО (Available Profiles: ВЕСКО) Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States) Default browser: Chrome Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avago Technologies U.S. Inc. -> LSI Corporation) C:\Program Files\LSI SoftModem\agr64svc.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler.exe (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.442\GoogleCrashHandler64.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (PLARIUM GLOBAL LTD. -> ) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\TrayPP.exe (PLARIUM GLOBAL LTD. -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe (PLARIUM GLOBAL LTD. -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe (PLARIUM GLOBAL LTD. -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe (PLARIUM GLOBAL LTD. -> Plarium) C:\Users\ВЕСКО\AppData\Local\Plarium\PlariumPlay\PlariumPlay.exe (SafeIP) [File not signed] C:\Program Files (x86)\SafeIP\SafeIPS.exe ==================== Registry (Whitelisted) =================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2096424 2010-05-27] (Synaptics Incorporated -> Synaptics Incorporated) HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe" HKLM-x32\...\Run: [QlbCtrl.exe] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [287800 2009-11-11] (Hewlett-Packard Company -> Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [226728 2019-07-21] (Kilonova LLC -> ) HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-14] (Piriform Software Ltd -> Piriform Ltd) HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.122\Installer\chrmstp.exe [2020-02-24] (Google LLC -> Google LLC) ==================== Scheduled Tasks (Whitelisted) ============ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {265168EC-659E-486F-A588-95AEB76ABA97} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-02-12] (Adobe Inc. -> Adobe) Task: {55DBABF8-7CBC-45AD-AA41-0CDE6FC314AF} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-14] (Piriform Software Ltd -> Piriform Software Ltd) Task: {5CB506C8-E8D6-4C56-AF40-B3D478C337CE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-14] (Piriform Software Ltd -> Piriform Ltd) Task: {6B9E0AD0-AB0C-4380-A4C4-DCAD81DBD548} - System32\Tasks\update-S-1-5-21-2076816696-1300689269-2899885506-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>) Task: {87935F6A-A2F4-4866-A907-C7CD2C7A0A21} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [414872 2017-04-12] (OOO Lightshot -> TODO: <Company name>) Task: {A843C120-2505-4293-BDFD-A29A24C02977} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-10] (Google Inc -> Google LLC) Task: {ACA797F2-DFAE-40E9-A1A1-F0FF47044B6A} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_330_pepper.exe [1453624 2020-02-12] (Adobe Inc. -> Adobe) Task: {BC7D6B7B-03DE-4E5D-A1B5-62B9B694C8C6} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [154920 2019-08-10] (Google Inc -> Google LLC) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\update-S-1-5-21-2076816696-1300689269-2899885506-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe Task: C:\Windows\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog9 01 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9 02 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9 03 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9 04 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9 16 C:\Windows\SysWOW64\SafeIPs.dll [384000 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 01 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 02 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 03 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 04 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Winsock: Catalog9-x64 16 C:\Windows\system32\SafeIPs64.dll [547328 2015-08-03] (SafeIP) [File not signed] Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{A7FF16DF-7DC1-437C-8A22-C8C6BDC82A48}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://securesearch.org/homepage?hp=2&pId=BT171101&iDate=2020-02-16 08:34:09&bName= SearchScopes: HKU\S-1-5-21-2076816696-1300689269-2899885506-1001 -> {993F5746-4C15-42BC-99C1-064A1764271B} URL = hxxps://securesearch.org?q={searchTerms} Chrome: ======= CHR Profile: C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default [2020-03-02] CHR Notifications: Default -> hxxps://realniistorii.com CHR HomePage: Default -> hxxp://google.bg/ CHR StartupUrls: Default -> "hxxps://www.google.bg/" CHR Extension: (Презентации) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2019-08-10] CHR Extension: (Документи) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2019-08-10] CHR Extension: (Google Диск) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2019-08-10] CHR Extension: (YouTube) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2019-08-10] CHR Extension: (Adblock Plus — безплатен блокер на реклами) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-02-19] CHR Extension: (Таблици) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2019-08-10] CHR Extension: (Google Документи офлайн) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-01-09] CHR Extension: (Lightshot (скрииншот инструмент)) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbniclmhobmnbdlbpiphghaielnnpgdp [2020-01-27] CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04] CHR Extension: (Gmail) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-08-10] CHR Extension: (Chrome Media Router) - C:\Users\ВЕСКО\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-02-20] ==================== Services (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AgereModemAudio; C:\Program Files\LSI SoftModem\agr64svc.exe [42096 2015-08-04] (Avago Technologies U.S. Inc. -> LSI Corporation) S3 GameforgeClientService; C:\Program Files (x86)\GameforgeClient\gfservice.exe [529568 2020-02-12] (Gameforge 4D GmbH -> ) S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [6960640 2020-01-11] (Malwarebytes Inc -> Malwarebytes) R3 SafeIPS; C:\Program Files (x86)\SafeIP\SafeIPs.exe [4606976 2015-08-03] (SafeIP) [File not signed] R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2019-08-11] (Microsoft Corporation -> Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2019-08-11] (Microsoft Corporation -> Microsoft Corporation) ===================== Drivers (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 AgereSoftModem; C:\Windows\system32\DRIVERS\agrsm64.sys [1230104 2015-08-04] (Microsoft Windows Hardware Compatibility Publisher -> LSI Corporation) S3 bcmfn2; C:\Windows\System32\drivers\bcmfn2.sys [17624 2013-08-13] (Broadcom Corporation -> Windows (R) Win 7 DDK provider) R3 HBtnKey; C:\Windows\system32\DRIVERS\cpqbttn.sys [19000 2010-02-24] (Hewlett-Packard Company -> Hewlett-Packard Company) R3 HpqKbFiltr; C:\Windows\System32\drivers\HpqKbFiltr.sys [18432 2009-04-29] (Microsoft Windows Hardware Compatibility Publisher -> Hewlett-Packard Development Company, L.P.) R3 RICOH SmartCard Reader; C:\Windows\system32\DRIVERS\rismcx64.sys [79488 2006-10-03] (Microsoft Windows Hardware Compatibility Publisher -> RICOH Company, Ltd.) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2019-08-11] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2019-08-11] (Microsoft Windows -> Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2019-08-11] (Microsoft Windows -> Microsoft Corporation) R0 WofAdk; C:\Windows\System32\drivers\wofadk.sys [221376 2019-08-11] (Microsoft Corporation -> Microsoft Corporation) S1 amsdk; \??\C:\Windows\system32\drivers\amsdk.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One month (created) =================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-03-02 14:47 - 2020-03-02 14:48 - 000011911 _____ C:\Users\ВЕСКО\Downloads\FRST.txt 2020-03-02 14:47 - 2020-03-02 14:48 - 000000000 ____D C:\FRST 2020-03-02 14:37 - 2020-03-02 14:38 - 002279424 _____ (Farbar) C:\Users\ВЕСКО\Downloads\FRST64.exe 2020-02-22 06:34 - 2020-02-22 06:35 - 000000000 ____D C:\Program Files\CCleaner 2020-02-22 06:34 - 2020-02-22 06:34 - 000003870 _____ C:\Windows\system32\Tasks\CCleaner Update 2020-02-22 06:34 - 2020-02-22 06:34 - 000002800 _____ C:\Windows\system32\Tasks\CCleanerSkipUAC 2020-02-22 06:34 - 2020-02-22 06:34 - 000000834 _____ C:\Users\Public\Desktop\CCleaner.lnk 2020-02-22 06:34 - 2020-02-22 06:34 - 000000834 _____ C:\ProgramData\Desktop\CCleaner.lnk 2020-02-22 06:34 - 2020-02-22 06:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2020-02-22 06:33 - 2020-02-22 06:34 - 024581800 _____ (Piriform Software Ltd) C:\Users\ВЕСКО\Downloads\cctrialsetup.exe 2020-02-21 04:37 - 2020-02-21 04:56 - 000002456 _____ C:\Windows\SysWOW64\SafeIPSOff.ini 2020-02-21 04:37 - 2020-02-21 04:56 - 000002456 _____ C:\Windows\system32\SafeIPSOff.ini 2020-02-21 04:28 - 2020-02-21 04:28 - 000000995 _____ C:\Users\ВЕСКО\Desktop\SafeIP.lnk 2020-02-21 04:28 - 2020-02-21 04:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SafeIP 2020-02-21 04:28 - 2020-02-21 04:28 - 000000000 ____D C:\Program Files (x86)\SafeIP 2020-02-21 04:28 - 2015-08-03 08:53 - 000384000 _____ (SafeIP) C:\Windows\SysWOW64\SafeIPs.dll 2020-02-16 12:58 - 2020-02-16 12:58 - 000000000 ____D C:\Users\ВЕСКО\Downloads\Collection 2020-02-16 12:47 - 2020-02-16 12:47 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\WinRAR 2020-02-16 12:47 - 2020-02-16 12:47 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2020-02-16 12:47 - 2020-02-16 12:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2020-02-16 12:47 - 2020-02-16 12:47 - 000000000 ____D C:\Program Files\WinRAR 2020-02-16 12:46 - 2020-02-16 12:46 - 003205888 _____ (Alexander Roshal) C:\Users\ВЕСКО\Downloads\winrar-x64-580.exe 2020-02-16 12:37 - 2020-02-16 12:37 - 000000000 ____D C:\Users\Public\Documents\Steam 2020-02-16 12:37 - 2020-02-16 12:37 - 000000000 ____D C:\ProgramData\Documents\Steam 2020-02-16 12:33 - 2020-02-16 12:33 - 000016499 _____ C:\Users\ВЕСКО\Downloads\Collection.torrent 2020-02-16 12:21 - 2020-02-16 12:33 - 000000000 ____D C:\Windows\SysWOW64\directx 2020-02-16 12:21 - 2020-02-16 12:21 - 000000000 ___HD C:\Windows\msdownld.tmp 2020-02-16 11:45 - 2020-02-16 11:45 - 000000000 ____D C:\Users\ВЕСКО\Documents\Lightshot 2020-02-16 11:43 - 2020-03-02 12:45 - 000000398 _____ C:\Windows\Tasks\update-sys.job 2020-02-16 11:43 - 2020-03-02 11:07 - 000000398 _____ C:\Windows\Tasks\update-S-1-5-21-2076816696-1300689269-2899885506-1001.job 2020-02-16 11:43 - 2020-02-16 11:43 - 000003268 _____ C:\Windows\system32\Tasks\update-sys 2020-02-16 11:43 - 2020-02-16 11:43 - 000003246 _____ C:\Windows\system32\Tasks\update-S-1-5-21-2076816696-1300689269-2899885506-1001 2020-02-16 11:43 - 2020-02-16 11:43 - 000000424 _____ C:\Users\ВЕСКО\AppData\Local\UserProducts.xml 2020-02-16 11:43 - 2020-02-16 11:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot 2020-02-16 11:43 - 2020-02-16 11:43 - 000000000 ____D C:\Program Files (x86)\Skillbrains 2020-02-16 11:41 - 2020-02-16 11:41 - 002784344 _____ (Skillbrains ) C:\Users\ВЕСКО\Downloads\setup-lightshot.exe 2020-02-16 11:00 - 2020-02-16 14:38 - 000000000 ____D C:\Games 2020-02-16 10:32 - 2020-02-22 06:37 - 000000000 ____D C:\Users\ВЕСКО\AppData\Roaming\BitTorrent 2020-02-16 10:32 - 2020-02-16 10:32 - 000000913 _____ C:\Users\ВЕСКО\Desktop\BitTorrent.lnk 2020-02-16 10:32 - 2020-02-16 10:32 - 000000893 _____ C:\Users\ВЕСКО\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk 2020-02-16 10:30 - 2020-02-16 10:31 - 005077120 _____ (BitTorrent Inc.) C:\Users\ВЕСКО\Downloads\BitTorrent.exe 2020-02-16 10:29 - 2020-02-16 10:30 - 000018355 _____ C:\Users\ВЕСКО\Downloads\Euro Truck Simulator 2 v1.36.2.2s.torrent 2020-02-16 09:56 - 2020-02-16 10:13 - 2092624032 _____ C:\Users\ВЕСКО\Downloads\EuroTruckSimulator2_1_28_1_3_patch.exe 2020-02-14 17:23 - 2020-02-14 17:24 - 001018988 _____ C:\Users\ВЕСКО\Downloads\QTranslate.6.7.4.exe 2020-02-09 11:43 - 2020-02-09 11:43 - 001031213 _____ C:\Users\ВЕСКО\Downloads\05.02.2020_Списък_на_подлежащите_на_запечатване_търговски_обекти_и_тяхното_местонахождение.pdf 2020-02-09 07:55 - 2020-02-09 07:55 - 003045838 _____ C:\Users\ВЕСКО\Downloads\1dad5ad69c6d5c9593aff6de7ce2ae91.mp4 2020-02-09 07:55 - 2020-02-09 07:55 - 002747301 _____ C:\Users\ВЕСКО\Downloads\b073f119aaf0f65be906afc679159766.mp4 2020-02-09 07:54 - 2020-02-09 07:55 - 003781947 _____ C:\Users\ВЕСКО\Downloads\a4e3ac7ac21e72da14d0550abe14d173.mp4 2020-02-07 19:31 - 2020-02-07 19:31 - 000000000 ____D C:\Users\ВЕСКО\AppData\Local\ElevatedDiagnostics ==================== One month (modified) ================== (If an entry is included in the fixlist, the file/folder will be moved.) 2020-03-02 14:45 - 2019-08-10 22:00 - 000003598 _____ C:\Windows\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2076816696-1300689269-2899885506-1001 2020-03-02 14:39 - 2019-12-01 14:43 - 000000037 _____ C:\Users\Public\Desktop\Gameforge Client.url 2020-03-02 14:39 - 2019-12-01 14:43 - 000000037 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Gameforge Client.url 2020-03-02 14:39 - 2019-12-01 14:43 - 000000037 _____ C:\ProgramData\Desktop\Gameforge Client.url 2020-03-02 14:39 - 2019-12-01 14:43 - 000000000 ____D C:\Program Files (x86)\GameforgeClient 2020-03-02 08:40 - 2019-08-10 22:08 - 000003910 _____ C:\Windows\system32\Tasks\User_Feed_Synchronization-{54DC4300-FD57-426E-B02E-B8CE96343A01} 2020-02-28 12:39 - 2019-08-10 22:03 - 000000000 ___DO C:\Users\ВЕСКО\SkyDrive 2020-02-28 12:38 - 2013-08-22 16:45 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2020-02-28 12:37 - 2013-08-22 15:25 - 000262144 ___SH C:\Windows\system32\config\BBI 2020-02-28 01:00 - 2013-08-22 15:36 - 000000000 ____D C:\Windows\Inf 2020-02-25 18:01 - 2020-01-04 20:07 - 000000065 _____ C:\Users\ВЕСКО\Downloads\uopilot.ini 2020-02-24 21:44 - 2019-08-10 22:13 - 000002244 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2020-02-24 21:44 - 2019-08-10 22:13 - 000002203 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2020-02-24 21:44 - 2019-08-10 22:13 - 000002203 _____ C:\ProgramData\Desktop\Google Chrome.lnk 2020-02-22 06:37 - 2019-10-10 03:14 - 000000000 ____D C:\Windows\Minidump 2020-02-22 06:37 - 2019-08-11 08:47 - 000000000 ____D C:\Windows\Panther 2020-02-16 12:33 - 2013-08-22 17:36 - 000000000 ____D C:\Program Files\Common Files\microsoft shared 2020-02-14 17:24 - 2020-01-15 20:02 - 000001047 _____ C:\Users\ВЕСКО\Desktop\QTranslate.lnk 2020-02-12 04:05 - 2019-10-13 11:30 - 000004424 _____ C:\Windows\system32\Tasks\Adobe Flash Player PPAPI Notifier 2020-02-12 04:05 - 2019-10-13 11:30 - 000004282 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater 2020-02-12 04:04 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2020-02-12 04:04 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\Macromed 2020-02-05 02:36 - 2019-08-10 22:11 - 000003434 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA 2020-02-05 02:36 - 2019-08-10 22:11 - 000003306 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore 2020-02-01 06:12 - 2013-08-22 17:36 - 000000000 ____D C:\Windows\system32\NDF 2020-02-01 03:03 - 2019-08-12 01:06 - 000000000 ____D C:\Users\ВЕСКО\AppData\LocalLow\Unity ==================== Files in the root of some directories ======== 2019-10-27 11:08 - 2019-10-27 11:08 - 000137168 _____ (Mozilla Foundation) C:\ProgramData\mozglue.dll 2019-10-27 11:08 - 2019-10-27 11:08 - 000440120 _____ (Microsoft Corporation) C:\ProgramData\msvcp140.dll 2019-10-27 11:08 - 2019-10-27 11:08 - 001246160 _____ (Mozilla Foundation) C:\ProgramData\nss3.dll 2019-10-27 11:08 - 2019-10-27 11:08 - 000083784 _____ (Microsoft Corporation) C:\ProgramData\vcruntime140.dll 2019-10-13 11:25 - 2019-10-13 11:24 - 051823104 _____ () C:\Program Files\Macromedia Captivate.msi 2019-08-11 00:00 - 2019-08-11 00:00 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\AtStart.txt 2019-10-27 11:08 - 2019-10-27 11:08 - 000000556 _____ () C:\Users\ВЕСКО\AppData\Local\bowsakkdestx.txt 2019-08-11 00:00 - 2019-08-11 00:00 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\DSwitch.txt 2019-08-10 22:45 - 2019-12-12 16:42 - 000039733 _____ () C:\Users\ВЕСКО\AppData\Local\PlariumPlay.log 2019-08-11 00:00 - 2019-08-11 00:00 - 000000000 _____ () C:\Users\ВЕСКО\AppData\Local\QSwitch.txt 2020-02-16 11:43 - 2020-02-16 11:43 - 000000003 _____ () C:\Users\ВЕСКО\AppData\Local\updater.log 2020-02-16 11:43 - 2020-02-16 11:43 - 000000424 _____ () C:\Users\ВЕСКО\AppData\Local\UserProducts.xml ==================== SigCheck ============================ (There is no automatic fix for files that do not pass verification.) LastRegBack: 2020-02-28 01:00 ==================== End of FRST.txt ======================== Additional scan result of Farbar Recovery Scan Tool (x64) Version: 26-02-2020 Ran by ВЕСКО (02-03-2020 14:49:23) Running from C:\Users\ВЕСКО\Downloads Windows 8.1 Pro (Update) (X64) (2019-08-10 19:55:10) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2076816696-1300689269-2899885506-500 - Administrator - Disabled) Guest (S-1-5-21-2076816696-1300689269-2899885506-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2076816696-1300689269-2899885506-1003 - Limited - Enabled) ВЕСКО (S-1-5-21-2076816696-1300689269-2899885506-1001 - Administrator - Enabled) => C:\Users\ВЕСКО ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.330 - Adobe) BitTorrent (HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\BitTorrent) (Version: 7.10.5.45496 - BitTorrent Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.63 - Piriform) Gameforge Client (HKLM-x32\...\{d3b2a0c1-f0d0-4888-ae0b-1c5e1febdafb}_is1) (Version: 2.0.51.124 - Gameforge) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.122 - Google LLC) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.441 - Google LLC) Hidden HP Quick Launch Buttons (HKLM-x32\...\{34D2AB40-150D-475D-AE32-BD23FB5EE355}) (Version: 6.50.14.1 - Hewlett-Packard Company) Lightshot-5.5.0.4 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.5.0.4 - Skillbrains) LINE (HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\LINE) (Version: 5.22.0.2111 - LINE Corporation) LSI HDA Modem (HKLM\...\LSI Soft Modem) (Version: 2.2.100 - LSI Corporation) Malwarebytes version 4.0.4.49 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.0.4.49 - Malwarebytes) Metin2 ru-RU (HKLM-x32\...\{fab180a3-cd65-4b7e-bd0e-2ef77fd0c258.ru-RU}) (Version: - Gameforge) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.24.28127 (HKLM-x32\...\{282975d8-55fe-4991-bbbb-06a72581ce58}) (Version: 14.24.28127.4 - Microsoft Corporation) Plarium Play (HKLM-x32\...\{4EE55C89-1180-4702-86C0-0E999BF691FD}) (Version: 5.1.0 - Plarium) Hidden Plarium Play (HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\{1077884f-6e6c-4848-8a7c-9dec58d99637}) (Version: 5.1.0 - Plarium) QLBCASL (HKLM-x32\...\{F1D7AC58-554A-4A58-B784-B61558B1449A}) (Version: 6.40.17.2 - Hewlett-Packard) Hidden QTranslate 6.7.4 (HKLM-x32\...\QTranslate) (Version: 6.7.4 - QuestSoft) SafeIP (HKLM-x32\...\SAFEIP_is1) (Version: - SafeIP) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.17.4 - Synaptics Incorporated) WinRAR 5.80 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.80.0 - win.rar GmbH) Packages: ========= Frameworkuapbase -> C:\Program Files\WindowsApps\48682KiddoTest.Frameworkuapbase_1.0.0.2_neutral__81ffpr532s7pc [2019-08-11] (KiddoTest) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.0_2.0.1410.19000_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.0_2.0.1410.19000_x86__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.1_2.0.1410.19000_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Kinect for Windows Framework -> C:\Program Files\WindowsApps\Microsoft.WindowsPreview.Kinect.8.1_2.0.1410.19000_x86__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Microsoft PlayReady -> C:\Program Files\WindowsApps\Microsoft.Internal.Media.PlayReadyClient_2.3.1678.1_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Microsoft PlayReady -> C:\Program Files\WindowsApps\Microsoft.Internal.Media.PlayReadyClient_2.3.1678.1_x86__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) Microsoft Visual C++ Runtime Package -> C:\Program Files\WindowsApps\Microsoft.VCLibs.120.00.Preview.Internal_12.0.20222.2_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions Internal) Microsoft Visual C++ Runtime Package -> C:\Program Files\WindowsApps\Microsoft.VCLibs.120.00.Preview.Internal_12.0.20222.2_x86__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions Internal) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.2.0.Preview.Internal_1.0.9385.3_neutral__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.2.0.Preview_1.0.9431.0_neutral__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions) Microsoft Windows Library for JavaScript -> C:\Program Files\WindowsApps\Microsoft.WinJS.Preview.1_1.0.9345.0_neutral__8wekyb3d8bbwe [2019-08-11] (Microsoft Platform Extensions) MSN Време -> C:\Program Files\WindowsApps\Microsoft.BingWeather_3.0.4.322_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] MSN Кулинария -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] MSN Пътуване -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] mxtest2 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.mxtest2_2.0.0.0_neutral__x35ns48czryn0 [2019-08-11] (m1df_mmengesha) Test_Framework_BP_052015 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkBP052015_1.0.0.9_neutral__x35ns48czryn0 [2019-08-11] (m1df_mmengesha) Test_Framework_win81appxneutral_061115 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkwin81appxneutral06_4.0.0.7_neutral__x35ns48czryn0 [2019-08-11] (M1DF_Mmengesha) Test_FrameworkBackpublish_050515 -> C:\Program Files\WindowsApps\24712m1dfmmengesha.TestFrameworkBackpublish050515_1.0.0.0_neutral__x35ns48czryn0 [2019-08-11] (m1df_mmengesha) Test_FrameworkProd_062215_01 -> C:\Program Files\WindowsApps\50856m1dfLL.TestFrameworkProd06221501_1.0.0.10_neutral__nwcxtg9ehxpvt [2019-08-11] (m1df_lucyll) TESTFRAMEWORKABO2 -> C:\Program Files\WindowsApps\40538vasetest101.TESTFRAMEWORKABO2_12.0.21005.1_x64__ssm1v0s3df7zc [2019-08-11] (vasetest101) Видео -> C:\Program Files\WindowsApps\Microsoft.ZuneVideo_2.2.802.0_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] Игри -> C:\Program Files\WindowsApps\Microsoft.XboxLIVEGames_2.0.139.0_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] Музика -> C:\Program Files\WindowsApps\Microsoft.ZuneMusic_2.2.800.0_x64__8wekyb3d8bbwe [2019-08-11] (Microsoft Corporation) [MS Ad] ==================== Custom CLSID (Whitelisted): ============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-11] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2020-01-11] (Malwarebytes Corporation -> Malwarebytes) ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal) ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-12-05] (win.rar GmbH -> Alexander Roshal) ==================== Codecs (Whitelisted) ==================== ==================== Shortcuts & WMI ======================== ==================== Loaded Modules (Whitelisted) ============= 2019-08-15 04:28 - 2015-08-03 08:54 - 000547328 _____ (SafeIP) [File not signed] C:\Windows\system32\SafeIPs64.dll ==================== Alternate Data Streams (Whitelisted) ======== ==================== Safe Mode (Whitelisted) ================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\amsdk.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SafeIPS => ""="service" ==================== Association (Whitelisted) ================= ==================== Internet Explorer trusted/restricted ========== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\...\webcompanion.com -> hxxp://webcompanion.com ==================== Hosts content: ========================= (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2013-08-22 15:25 - 2019-12-06 18:21 - 000000822 _____ C:\Windows\system32\drivers\etc\hosts ==================== Other Areas =========================== (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2076816696-1300689269-2899885506-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ВЕСКО\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img0.jpg DNS Servers: 192.168.0.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == (If an entry is included in the fixlist, it will be removed.) HKLM\...\StartupApproved\Run: => "WindowsDefender" HKLM\...\StartupApproved\Run: => "SynTPEnh" HKLM\...\StartupApproved\Run32: => "QlbCtrl.exe" ==================== FirewallRules (Whitelisted) ================ (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{90A6F7DD-E504-4409-ABEC-C48BCE0F48C2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) FirewallRules: [TCP Query User{75128495-E63B-4C18-86A2-FA3306C63C36}E:\lfs\lfs.exe] => (Allow) E:\lfs\lfs.exe () [File not signed] FirewallRules: [UDP Query User{C5906F14-8730-4E59-AB30-06C67E9BC2EB}E:\lfs\lfs.exe] => (Allow) E:\lfs\lfs.exe () [File not signed] FirewallRules: [{1BED8524-52DB-4260-8BBE-A881BD9D3E34}] => (Allow) C:\Users\ВЕСКО\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{AA496B3E-2F6F-4807-965E-F158476BB027}] => (Allow) C:\Users\ВЕСКО\AppData\Roaming\BitTorrent\BitTorrent.exe (BitTorrent Inc -> BitTorrent Inc.) FirewallRules: [{A809C2BA-1C3A-4ECC-A381-6678FB2DAD54}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC) ==================== Restore Points ========================= 21-12-2019 21:54:55 Scheduled Checkpoint 20-01-2020 02:26:46 Scheduled Checkpoint 27-01-2020 03:35:29 Scheduled Checkpoint ==================== Faulty Device Manager Devices ============ Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Fingerprint Sensor Description: Fingerprint Sensor Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Base System Device Description: Base System Device Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ======================== Application errors: ================== Error: (03/02/2020 06:15:56 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PAPA) Description: Activation of app winstore_cw5n1h2txyewy!Windows.Store failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information. Error: (03/02/2020 06:15:56 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program WWAHost.exe version 6.3.9600.17031 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: d24 Start Time: 01d5f0493947cd5c Termination Time: 4294967295 Application Path: C:\Windows\System32\WWAHost.exe Report Id: 810a4bbc-5c3c-11ea-828f-002713343a56 Faulting package full name: winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy Faulting package-relative application ID: Windows.Store Error: (03/02/2020 06:15:51 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: PAPA) Description: App winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy+Windows.Store did not launch within its allotted time. Error: (02/28/2020 12:39:52 PM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (02/27/2020 04:18:13 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: skydrive.exe, version: 6.3.9600.17484, time stamp: 0x545d76bd Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0x00000000 Fault offset: 0x0000000000000000 Faulting process id: 0x1114 Faulting application start time: 0x01d5ed78bd3cd471 Faulting application path: C:\Windows\System32\skydrive.exe Faulting module path: unknown Report Id: fccfc0d4-596b-11ea-828e-002713343a56 Faulting package full name: Faulting package-relative application ID: Error: (02/26/2020 04:20:02 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: skydrive.exe, version: 6.3.9600.17484, time stamp: 0x545d76bd Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000 Exception code: 0x00000000 Fault offset: 0x0000000000000000 Faulting process id: 0x1614 Faulting application start time: 0x01d5ecafd3283424 Faulting application path: C:\Windows\System32\skydrive.exe Faulting module path: unknown Report Id: 134ef253-58a3-11ea-828e-002713343a56 Faulting package full name: Faulting package-relative application ID: Error: (02/26/2020 04:58:58 AM) (Source: Perflib) (EventID: 1008) (User: ) Description: The Open Procedure for service "WmiApRpl" in DLL "C:\Windows\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code. Error: (02/26/2020 04:58:51 AM) (Source: Perflib) (EventID: 1023) (User: ) Description: Windows cannot load the extensible counter DLL rdyboost. The first four bytes (DWORD) of the Data section contains the Windows error code. System errors: ============= Error: (02/27/2020 04:27:58 PM) (Source: DCOM) (EventID: 10005) (User: NT AUTHORITY) Description: DCOM got error "1053" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69} Error: (02/27/2020 04:27:57 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Услуга на Google Актуализация (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. Error: (02/27/2020 04:27:57 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: A timeout was reached (30000 milliseconds) while waiting for the Услуга на Google Актуализация (gupdate) service to connect. Error: (02/27/2020 04:18:47 PM) (Source: DCOM) (EventID: 10010) (User: PAPA) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Error: (02/26/2020 04:21:21 PM) (Source: DCOM) (EventID: 10010) (User: PAPA) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Error: (02/25/2020 04:19:39 PM) (Source: DCOM) (EventID: 10010) (User: PAPA) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Error: (02/21/2020 04:23:25 PM) (Source: Service Control Manager) (EventID: 7032) (User: ) Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Peer Name Resolution Protocol service, but this action failed with the following error: An instance of the service is already running. Error: (02/21/2020 04:21:26 PM) (Source: DCOM) (EventID: 10010) (User: PAPA) Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout. Windows Defender: =================================== Date: 2020-03-02 14:49:21.815 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:BAT/AutoKms.S!MTB&threatid=2147743496&enterprise=0 Name: HackTool:BAT/AutoKms.S!MTB ID: 2147743496 Severity: High Category: Tool Path: file:_C:\Users\ВЕСКО\Documents\windows8.cmd Detection Origin: Local machine Detection Type: Concrete Detection Source: Real-Time Protection Process Name: C:\Users\ВЕСКО\Downloads\FRST64.exe Signature Version: AV: 1.311.394.0, AS: 1.311.394.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16800.2, NIS: 2.1.14600.4 Date: 2020-02-24 16:49:50.613 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Vigram.A&threatid=232718&enterprise=0 Name: Program:Win32/Vigram.A ID: 232718 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\ВЕСКО\Downloads\SafeIP.exe Detection Origin: Local machine Detection Type: FastPath Detection Source: System Process Name: Unknown Signature Version: AV: 1.309.1602.0, AS: 1.309.1602.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16700.3, NIS: 2.1.14600.4 Date: 2020-02-21 04:27:22.929 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Vigram.A&threatid=232718&enterprise=0 Name: Program:Win32/Vigram.A ID: 232718 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\ВЕСКО\Downloads\SafeIP (1).exe;file:_C:\Users\ВЕСКО\Downloads\SafeIP.exe;webfile:_C:\Users\ВЕСКО\Downloads\SafeIP (1).exe|https://www.freesafeip.com/SafeIP.exe|chrome.exe;webfile:_C:\Users\ВЕСКО\Downloads\SafeIP.exe|https://www.freesafeip.com/SafeIP.exe|chrome.exe Detection Origin: Internet Detection Type: FastPath Detection Source: Downloads and attachments Process Name: Unknown Signature Version: AV: 1.309.1348.0, AS: 1.309.1348.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16700.3, NIS: 2.1.14600.4 Date: 2020-02-21 04:27:20.517 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Vigram.A&threatid=232718&enterprise=0 Name: Program:Win32/Vigram.A ID: 232718 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\ВЕСКО\Downloads\SafeIP.exe;webfile:_C:\Users\ВЕСКО\Downloads\SafeIP.exe|https://www.freesafeip.com/SafeIP.exe|chrome.exe Detection Origin: Internet Detection Type: FastPath Detection Source: Downloads and attachments Process Name: Unknown Signature Version: AV: 1.309.1348.0, AS: 1.309.1348.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16700.3, NIS: 2.1.14600.4 Date: 2020-02-21 04:24:18.037 Description: Windows Defender has detected malware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=Program:Win32/Vigram.A&threatid=232718&enterprise=0 Name: Program:Win32/Vigram.A ID: 232718 Severity: Severe Category: Potentially Unwanted Software Path: file:_C:\Users\ВЕСКО\Downloads\SafeIP.exe;webfile:_C:\Users\ВЕСКО\Downloads\SafeIP.exe|https://www.freesafeip.com/SafeIP.exe|chrome.exe Detection Origin: Internet Detection Type: FastPath Detection Source: Downloads and attachments Process Name: Unknown Signature Version: AV: 1.309.1348.0, AS: 1.309.1348.0, NIS: 119.0.0.0 Engine Version: AM: 1.1.16700.3, NIS: 2.1.14600.4 Date: 2020-03-02 12:48:53.550 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.311.300.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16800.2 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Date: 2020-02-29 12:48:53.098 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.311.96.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16800.2 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Date: 2020-02-27 16:25:58.491 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.311.51.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16800.2 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Date: 2020-02-26 02:54:12.140 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.309.1602.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16700.3 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. Date: 2020-02-24 16:32:59.871 Description: Windows Defender has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.309.1475.0 Update Source: Microsoft Update Server Signature Type: AntiVirus Update Type: Full Current Engine Version: Previous Engine Version: 1.1.16700.3 Error code: 0x80070422 Error description: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. CodeIntegrity: =================================== Date: 2020-03-02 14:42:10.317 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2020-03-02 14:42:09.709 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-12-01 14:45:58.203 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-12-01 14:45:57.468 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-10-27 11:05:31.653 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-10-27 11:05:30.955 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-10-15 17:13:52.723 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2019-10-15 17:13:51.566 Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\SafeIPs64.dll that did not meet the Custom 3 / Antimalware signing level requirements. ==================== Memory info =========================== BIOS: Hewlett-Packard 68PCU Ver. F.20 12/08/2011 Motherboard: Hewlett-Packard 30DB Processor: Intel(R) Core(TM)2 Duo CPU P8600 @ 2.40GHz Percentage of memory in use: 57% Total physical RAM: 3000.26 MB Available physical RAM: 1289.71 MB Total Virtual: 7000.26 MB Available Virtual: 5244.19 MB ==================== Drives ================================ Drive 😄 () (Fixed) (Total:365.12 GB) (Free:324.76 GB) NTFS Drive e: () (Fixed) (Total:100.1 GB) (Free:80.41 GB) NTFS \\?\Volume{bce0ecb4-bba7-11e9-8250-806e6f6e6963}\ (Резервирана за системата) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS \\?\Volume{bce0ecb7-bba7-11e9-8250-806e6f6e6963}\ () (Fixed) (Total:0.44 GB) (Free:0.16 GB) NTFS ==================== MBR & Partition Table ==================== ========================================================== Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 0FD73A73) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=100.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=365.1 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt =======================
  12. Здравейте. От няколко дни след като си рестартирам компа ми се появява cmd команда и автоматично и ми пуска хрома и отваря този сайт - dinoraptzor.org. С уин 10 съм, но нямам malwarebytes, а уж май би трябвало да имам? Сканирах с друга програма, но не успя да го намери и да го отстрани. Някакви съвети?
  13. Здравейте! Сложих флашка на компютър с Уиндоус 8, написа ми , че е открит злонамерен вирус и всичко от флашката изчезна. може ли да възстановя файловете?
  14. Здравейте, от месец се опитавм да се оправя с един кмопютър. Излизат долу вдясно едни прозорци. Сканирал съм със следните туулчета Hitman Pro - trial Malwarebytes Premium - trial adwcleaner ZHPCleaner Дотук не успях да ги премахна. Гледам и спирам разширенията в google chrome, но пак не става.
  15. Здравейте, след отварянето на файл във формат .doc получен по вайбър, се оказа, че е вирус, който антивирусната засече, но не съм сигурен дали успя да изчисти. Иначе системата си е напълно стабилна. Addition.txt FRST.txt
  16. Здравейте! Накратко - Бях инфектиран от зловреден софтуер с името DJVU ransomware. Вече е напълно премахнат, след пълно дефрагментиране на двата диска C, D и инсталация на нов Windows 10. Всички лични снимки са криптирани с формат. RIGH. Някакви решения как мога да оправя файловете си? Около 20GB снимки имам, качени в OneDrive с името тип на файла. RIGH ЗА РЕШЕНИЕ НА ПРОБЛЕМА ЩЕ СЕ ЗАПЛАТИ СЪОТВЕТНА СУМА ЛИЧНО ОТ МЕН.
  17. Delete на темата. Ще преинсталирам, че занимавката около чистенето ми изяде няколко пъти повече време отколкото ще ми изяде чиста преинсталация. Може да триете темата.
  18. Компютърът ми стана обект на хакерско нападение. Имах няколко заредени раздела в Хром и внезапно само за единия от тях (отворен по-рано) връзката падна. Не успях да изчета какво точно съобщение ми изписа тъй като по инерция дадох презареждане но помня че извършителят се беше подписал с подигравателен ник (от който ми стана ясно че следи последната ми активност в нета). Отделно вчера още отваряхме моя флашка на чужд компютър и ми казаха, че имала вируси – нямаше възможност да попитам какви точно. Миналата седмица същата флашка същият компютър я прие без проблем, така че вероятно става дума за нещо ново. Касперският ми не е успял да го спре, нито поне да засече нещо, за флашката при сканиране също не откриваше нищо. Има ли начин да науча за какъв вид атака става въпрос и как лицето е успяло да проникне? Как да сканирам и изчистя системата и как да я опазя за в бъдеще от подобни поразии?
  19. Здравейте колеги от HJT Teams. Както става ясно от заглавието компютъра е заразен с крипто вирус Cerber. Целта е ако може заразата да се изчисти. Вируса е поразил всички doc и jpg файлове на дял Д, но на дял С нищо не е криптирано. На дял С има ценна информация, която ако може е хубаво да се спаси. Ето и прикачените файлове, за да се направи проверката. FRST.txt Addition.txt
  20. Здравейте! Получихме файл по имейл изпратен все едно от нашата поща. За съжаление го отворихме и вследствие на това всички файлове от компютъра (word, pdf, gpeg) се изгубиха. Заглавията на отделните файлове се промениха с цифри. Изпращам информацията от FRST и Addition файловете. Моля за съвет! Благодаря предварително! Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 Ran by MitrevG (administrator) on MITREVG-PC (25-03-2016 14:39:10) Running from C:\Users\MitrevG\Desktop\Файлове от пощата Loaded Profiles: MitrevG (Available Profiles: MitrevG) Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Английски (Съединени щати) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (IObit) C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (charismathics GmbH) C:\Windows\System32\cmEvtSrv64.exe (ABBYY) C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe (IObit) C:\Program Files (x86)\IObit\Smart Defrag 3\SmartDefrag.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (CANON INC.) C:\Windows\System32\spool\drivers\x64\3\CNAP2LAK.EXE (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (CANON INC.) C:\Windows\System32\spool\drivers\x64\3\CNAP2RPK.EXE (CANON INC.) C:\Windows\System32\spool\drivers\x64\3\CNABFSWK.EXE (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFTips.exe (IObit) C:\Program Files (x86)\IObit Uninstaller\UninstallMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12503184 2012-06-11] (Realtek Semiconductor) HKLM\...\Run: [MSC] => C:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation) HKLM\...\Run: [CNAP2 Launcher] => C:\Windows\system32\spool\DRIVERS\x64\3\CNAP2LAK.EXE [226784 2010-10-15] (CANON INC.) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-12-22] (Oracle Corporation) HKLM-x32\...\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5361440 2016-02-26] (IObit) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-866752721-1448422713-3629417032-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50593408 2016-02-10] (Skype Technologies S.A.) HKU\S-1-5-21-866752721-1448422713-3629417032-1000\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-866752721-1448422713-3629417032-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 HKU\S-1-5-18\...\Run: [Advanced SystemCare 8] => C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCTray.exe [2428704 2015-01-20] (IObit) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{E21A947D-200B-4AAF-B490-3C5EB46F8B1C}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\ssv.dll [2016-01-28] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\jp2ssv.dll [2016-01-28] (Oracle Corporation) DPF: HKLM-x32 {97EA2A5E-A821-48A1-B0F9-DEDB5E0E62A2} hxxps://inetdec.nra.bg/cabs/SignCOM.cab DPF: HKLM-x32 {A996E48C-D3DC-4244-89F7-AFA33EC60679} hxxps://e-fibank.bg/EBank/CAPICOM/capicom.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\SKYPE4~1.DLL [2014-05-02] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\MitrevG\AppData\Roaming\Mozilla\Firefox\Profiles\d4w5d9oa.default FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\dtplugin\npDeployJava1.dll [2016-01-28] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.71.2 -> C:\Program Files (x86)\Java\jre1.8.0_71\bin\plugin2\npjp2.dll [2016-01-28] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.) FF user.js: detected! => C:\Users\MitrevG\AppData\Roaming\Mozilla\Firefox\Profiles\d4w5d9oa.default\user.js [2016-03-25] Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x86\widevinecdmadapter.dll (Google Inc.) CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\49.0.2623.108\PepperFlash\pepflashplayer.dll () CHR Profile: C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\Profile 1 CHR Extension: (Google Документи) - C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04] CHR Extension: (Google Диск) - C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (YouTube) - C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24] CHR Extension: (Google Търсене) - C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (Google Документи офлайн) - C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16] CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-24] CHR Extension: (Gmail) - C:\Users\MitrevG\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-30] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Professional.11.0; C:\Program Files (x86)\ABBYY FineReader 11\NetworkLicenseServer.exe [819976 2011-08-18] (ABBYY) R2 AdvancedSystemCareService8; C:\Program Files (x86)\IObit\Advanced SystemCare 8\ASCService.exe [815392 2014-11-04] (IObit) R2 cmevtsrv; C:\Windows\system32\cmEvtSrv64.exe [80416 2011-11-09] (charismathics GmbH) R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [955168 2016-02-26] (IObit) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-07-05] (Intel Corporation) S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2909472 2015-07-31] (IObit) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes) R2 MsMpSvc; C:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation) R3 NisSrv; C:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 A38CCID; C:\Windows\System32\DRIVERS\a38ccid.sys [62592 2014-02-04] (Advanced Card Systems Ltd.) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R3 FileMonitor; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys [22208 2015-12-22] (IObit) R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [26528 2014-12-22] (REALiX(tm)) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-03-25] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation) R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation) R3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2015-03-25] (IObit.com) R0 SmartDefragDriver; C:\Windows\System32\Drivers\SmartDefragDriver.sys [21184 2014-06-04] (IObit) S3 usbohci; C:\Windows\system32\drivers\usbohci.sys [25600 2012-07-27] (Microsoft Corporation) [File not signed] S3 usbuhci; C:\Windows\system32\drivers\usbuhci.sys [30720 2012-07-27] (Microsoft Corporation) [File not signed] S3 gdrv; \??\C:\Windows\gdrv.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-25 14:38 - 2016-03-25 14:39 - 00000000 ____D C:\FRST 2016-03-25 14:26 - 2016-03-25 14:28 - 00000000 ____D C:\AdwCleaner 2016-03-25 13:50 - 2016-03-25 14:30 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-03-25 13:50 - 2016-03-25 13:50 - 00000000 ____D C:\Windows\system32\Drivers\etc\BACKUP 2016-03-25 13:49 - 2016-03-25 13:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware 2016-03-25 13:49 - 2016-03-25 13:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware 2016-03-25 13:49 - 2016-03-25 13:49 - 00001112 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2016-03-25 13:49 - 2016-03-25 13:49 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-03-25 13:49 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2016-03-25 13:49 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-03-25 13:49 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2016-03-24 16:17 - 2016-03-24 16:17 - 03400516 _____ C:\Users\MitrevG\537957F6B0F4BB23BACCE37B3B1B14DE.locky 2016-03-24 16:17 - 2016-03-24 16:17 - 00001154 _____ C:\Users\MitrevG\_HELP_instructions.txt 2016-03-24 16:14 - 2016-03-24 16:14 - 01608867 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB234ADA9E07CA162A66.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00772014 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB23C438080B36CE2E2A.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00415473 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB23C8E8B9EAD8A0B5C1.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00258263 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB23F33700F59C067FF0.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00212721 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB23A58D215DEA008CAF.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00210146 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB230D1A31F711B48EF6.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00146356 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB23C7B610B48BC57EDF.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00080254 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB2398E32101DE1F7F17.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00033546 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB235DF16D04C097F348.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00032278 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB23F48CF210B0ABFF34.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00030408 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB23F635A87F045EEE18.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00028777 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB238C47436AD4362393.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00027129 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB237AEDC7B609054AB9.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00026624 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB231B63E9BDBC14FA1E.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00019569 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB23F42CCB8620740B65.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00019235 _____ C:\Users\MitrevG\Documents\537957F6B0F4BB2365CE64CDB24BF592.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00016265 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB2325D91E79BB1ED80E.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00014996 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB23D788C76A5E24D07F.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00010820 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB23094B1B53DF2947B5.locky 2016-03-24 16:14 - 2016-03-24 16:14 - 00001154 _____ C:\Users\MitrevG\Documents\_HELP_instructions.txt 2016-03-24 16:14 - 2016-03-24 16:14 - 00000998 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB23918DE6D90E58A324.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00063812 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB2300BBCDABEB1D23FB.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00058692 ____N C:\Users\MitrevG\Desktop\537957F6B0F4BB23738318E5BD4D4782.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00041203 _____ C:\Users\MitrevG\Downloads\537957F6B0F4BB23CF2DB3E3010E883D.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00032562 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB237AAD6626EB720FD1.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00014545 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB238E6B7145540BCBFF.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00014304 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB231AB37968E52F7F2E.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00013802 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB23606C45430E0CBB64.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00011115 _____ C:\Users\MitrevG\Desktop\537957F6B0F4BB2337B07F00287E3E84.locky 2016-03-24 16:13 - 2016-03-24 16:13 - 00001154 _____ C:\Users\MitrevG\Downloads\_HELP_instructions.txt 2016-03-24 16:13 - 2016-03-24 16:13 - 00001154 _____ C:\Users\MitrevG\Desktop\_HELP_instructions.txt 2016-03-21 13:39 - 2016-03-21 13:39 - 00002829 _____ C:\Windows\diagerr.xml 2016-03-21 13:39 - 2016-03-21 13:39 - 00001908 _____ C:\Windows\diagwrn.xml 2016-03-16 08:34 - 2016-03-16 08:34 - 00000000 ____H C:\asc_rdflag 2016-03-11 08:21 - 2016-03-11 08:21 - 00001183 _____ C:\Users\Public\Desktop\IObit Malware Fighter.lnk 2016-03-11 08:21 - 2016-03-11 08:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter 2016-03-09 08:40 - 2016-02-12 20:52 - 03169792 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2016-03-09 08:40 - 2016-02-12 20:52 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2016-03-09 08:40 - 2016-02-12 20:52 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2016-03-09 08:40 - 2016-02-12 20:44 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2016-03-09 08:40 - 2016-02-12 20:39 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2016-03-09 08:40 - 2016-02-12 20:22 - 02610688 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2016-03-09 08:40 - 2016-02-12 20:19 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2016-03-09 08:40 - 2016-02-12 20:18 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2016-03-09 08:40 - 2016-02-12 20:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2016-03-09 08:40 - 2016-02-12 20:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2016-03-09 08:40 - 2016-02-12 20:18 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2016-03-09 08:40 - 2016-02-12 20:18 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2016-03-09 08:40 - 2016-02-12 20:06 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2016-03-09 08:40 - 2016-02-12 20:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2016-03-09 08:40 - 2016-02-12 20:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2016-03-09 08:40 - 2016-02-12 20:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2016-03-09 08:40 - 2016-02-09 08:53 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-03-09 08:40 - 2016-02-09 08:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-03-09 08:40 - 2016-02-08 23:05 - 20352512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-03-09 08:40 - 2016-02-08 22:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-03-09 08:40 - 2016-02-08 22:39 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-03-09 08:40 - 2016-02-08 22:39 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-03-09 08:40 - 2016-02-08 22:38 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-03-09 08:40 - 2016-02-08 22:38 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-03-09 08:40 - 2016-02-08 22:37 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-03-09 08:40 - 2016-02-08 22:34 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-03-09 08:40 - 2016-02-08 22:32 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-03-09 08:40 - 2016-02-08 22:31 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-03-09 08:40 - 2016-02-08 22:30 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-03-09 08:40 - 2016-02-08 22:28 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-03-09 08:40 - 2016-02-08 22:28 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-03-09 08:40 - 2016-02-08 22:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-03-09 08:40 - 2016-02-08 22:20 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-03-09 08:40 - 2016-02-08 22:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-03-09 08:40 - 2016-02-08 22:15 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2016-03-09 08:40 - 2016-02-08 22:13 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-03-09 08:40 - 2016-02-08 22:12 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-03-09 08:40 - 2016-02-08 22:11 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-03-09 08:40 - 2016-02-08 22:10 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-03-09 08:40 - 2016-02-08 22:10 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-03-09 08:40 - 2016-02-08 22:03 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-03-09 08:40 - 2016-02-08 22:02 - 13012480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-03-09 08:40 - 2016-02-08 22:02 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-03-09 08:40 - 2016-02-08 22:01 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-03-09 08:40 - 2016-02-08 22:01 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-03-09 08:40 - 2016-02-08 21:43 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-03-09 08:40 - 2016-02-08 21:39 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-03-09 08:40 - 2016-02-08 21:38 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-03-09 08:40 - 2016-02-08 20:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-03-09 08:40 - 2016-02-08 20:41 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-03-09 08:40 - 2016-02-08 20:27 - 02887680 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-03-09 08:40 - 2016-02-08 20:27 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-03-09 08:40 - 2016-02-08 20:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-03-09 08:40 - 2016-02-08 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-03-09 08:40 - 2016-02-08 20:26 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-03-09 08:40 - 2016-02-08 20:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-03-09 08:40 - 2016-02-08 20:19 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-03-09 08:40 - 2016-02-08 20:18 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-03-09 08:40 - 2016-02-08 20:16 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-03-09 08:40 - 2016-02-08 20:15 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-03-09 08:40 - 2016-02-08 20:14 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-03-09 08:40 - 2016-02-08 20:14 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-03-09 08:40 - 2016-02-08 20:13 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-03-09 08:40 - 2016-02-08 20:13 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-03-09 08:40 - 2016-02-08 20:06 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-03-09 08:40 - 2016-02-08 20:03 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-03-09 08:40 - 2016-02-08 19:55 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-03-09 08:40 - 2016-02-08 19:54 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2016-03-09 08:40 - 2016-02-08 19:52 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-03-09 08:40 - 2016-02-08 19:51 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-03-09 08:40 - 2016-02-08 19:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-03-09 08:40 - 2016-02-08 19:47 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-03-09 08:40 - 2016-02-08 19:37 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-03-09 08:40 - 2016-02-08 19:35 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-03-09 08:40 - 2016-02-08 19:34 - 00798720 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-03-09 08:40 - 2016-02-08 19:33 - 14613504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-03-09 08:40 - 2016-02-08 19:33 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-03-09 08:40 - 2016-02-08 19:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-03-09 08:40 - 2016-02-08 19:19 - 02597376 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-03-09 08:40 - 2016-02-08 19:07 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-03-09 08:40 - 2016-02-08 18:55 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-03-09 08:40 - 2016-02-04 19:52 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-03-09 08:40 - 2016-02-03 20:58 - 00862208 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2016-03-09 08:40 - 2016-02-03 20:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2016-03-09 08:40 - 2016-02-03 20:49 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2016-03-09 08:40 - 2016-02-03 20:43 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2016-03-09 08:40 - 2016-02-03 20:07 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2016-03-09 08:40 - 2016-01-11 21:11 - 01684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2016-03-09 08:40 - 2015-11-19 16:07 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2016-03-09 08:40 - 2015-11-19 16:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2016-03-09 08:39 - 2016-02-19 21:02 - 00038336 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-03-09 08:39 - 2016-02-19 20:54 - 01168896 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-03-09 08:39 - 2016-02-19 16:07 - 01373184 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-03-09 08:39 - 2016-02-11 20:56 - 05572032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-03-09 08:39 - 2016-02-11 20:56 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-03-09 08:39 - 2016-02-11 20:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-03-09 08:39 - 2016-02-11 20:52 - 01733592 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-03-09 08:39 - 2016-02-11 20:49 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-03-09 08:39 - 2016-02-11 20:49 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-03-09 08:39 - 2016-02-11 20:49 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-03-09 08:39 - 2016-02-11 20:49 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-03-09 08:39 - 2016-02-11 20:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-03-09 08:39 - 2016-02-11 20:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-03-09 08:39 - 2016-02-11 20:49 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-03-09 08:39 - 2016-02-11 20:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-03-09 08:39 - 2016-02-11 20:48 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-03-09 08:39 - 2016-02-11 20:48 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-03-09 08:39 - 2016-02-11 20:48 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-03-09 08:39 - 2016-02-11 20:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-03-09 08:39 - 2016-02-11 20:48 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-03-09 08:39 - 2016-02-11 20:47 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-03-09 08:39 - 2016-02-11 20:45 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-03-09 08:39 - 2016-02-11 20:45 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-03-09 08:39 - 2016-02-11 20:45 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-03-09 08:39 - 2016-02-11 20:45 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-03-09 08:39 - 2016-02-11 20:44 - 03994560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-03-09 08:39 - 2016-02-11 20:44 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-03-09 08:39 - 2016-02-11 20:44 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-03-09 08:39 - 2016-02-11 20:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-03-09 08:39 - 2016-02-11 20:44 - 00730112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-03-09 08:39 - 2016-02-11 20:44 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-03-09 08:39 - 2016-02-11 20:42 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-03-09 08:39 - 2016-02-11 20:42 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-03-09 08:39 - 2016-02-11 20:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 01314328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-03-09 08:39 - 2016-02-11 20:38 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-03-09 08:39 - 2016-02-11 20:38 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-03-09 08:39 - 2016-02-11 20:38 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-03-09 08:39 - 2016-02-11 20:38 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-03-09 08:39 - 2016-02-11 20:38 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-03-09 08:39 - 2016-02-11 20:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-03-09 08:39 - 2016-02-11 20:37 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-03-09 08:39 - 2016-02-11 20:37 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-03-09 08:39 - 2016-02-11 20:37 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-03-09 08:39 - 2016-02-11 20:35 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-03-09 08:39 - 2016-02-11 20:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-03-09 08:39 - 2016-02-11 20:35 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-03-09 08:39 - 2016-02-11 20:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-03-09 08:39 - 2016-02-11 20:33 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-03-09 08:39 - 2016-02-11 20:31 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 19:48 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-03-09 08:39 - 2016-02-11 19:43 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-03-09 08:39 - 2016-02-11 19:41 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-03-09 08:39 - 2016-02-11 19:40 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-03-09 08:39 - 2016-02-11 19:34 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-03-09 08:39 - 2016-02-11 19:34 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-03-09 08:39 - 2016-02-11 19:33 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-03-09 08:39 - 2016-02-11 19:32 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-03-09 08:39 - 2016-02-11 19:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-03-09 08:39 - 2016-02-11 19:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-03-09 08:39 - 2016-02-11 19:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-03-09 08:39 - 2016-02-11 19:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-03-09 08:39 - 2016-02-11 19:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-03-09 08:39 - 2016-02-11 19:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-03-09 08:39 - 2016-02-11 19:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 19:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 19:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 19:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-03-09 08:39 - 2016-02-11 16:07 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-03-09 08:39 - 2016-02-09 11:57 - 14634496 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2016-03-09 08:39 - 2016-02-09 11:57 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2016-03-09 08:39 - 2016-02-09 11:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2016-03-09 08:39 - 2016-02-09 11:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2016-03-09 08:39 - 2016-02-09 11:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll 2016-03-09 08:39 - 2016-02-09 11:54 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2016-03-09 08:39 - 2016-02-09 11:51 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2016-03-09 08:39 - 2016-02-09 11:51 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2016-03-09 08:39 - 2016-02-09 11:13 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2016-03-09 08:39 - 2016-02-09 11:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2016-03-09 08:39 - 2016-02-09 11:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2016-03-09 08:39 - 2016-02-08 22:05 - 25816576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-03-09 08:39 - 2016-02-05 20:54 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2016-03-09 08:39 - 2016-02-05 20:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2016-03-09 08:39 - 2016-02-05 20:53 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2016-03-09 08:39 - 2016-02-05 20:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2016-03-09 08:39 - 2016-02-05 20:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2016-03-09 08:39 - 2016-02-05 20:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2016-03-09 08:39 - 2016-02-05 20:42 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2016-03-09 08:39 - 2016-02-05 19:48 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2016-03-09 08:39 - 2016-02-05 19:43 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2016-03-09 08:39 - 2016-02-05 19:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2016-03-09 08:39 - 2016-02-05 16:07 - 00696832 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-03-09 08:39 - 2016-02-05 16:07 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-03-09 08:39 - 2016-02-05 16:07 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-03-09 08:39 - 2016-02-05 03:19 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2016-03-09 08:39 - 2016-02-04 20:41 - 00296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-25 14:39 - 2014-04-25 12:55 - 00000000 ____D C:\Users\MitrevG\Desktop\Файлове от пощата 2016-03-25 14:37 - 2009-07-14 06:45 - 00026768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-03-25 14:37 - 2009-07-14 06:45 - 00026768 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-03-25 14:33 - 2009-07-14 07:13 - 00786622 _____ C:\Windows\system32\PerfStringBackup.INI 2016-03-25 14:33 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-03-25 14:30 - 2015-02-26 08:50 - 00002860 _____ C:\Windows\System32\Tasks\Driver Booster SkipUAC (SYSTEM) 2016-03-25 14:29 - 2014-07-01 16:12 - 00000994 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-03-25 14:29 - 2014-05-12 13:11 - 00000000 ____D C:\Users\MitrevG\AppData\Roaming\Skype 2016-03-25 14:29 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-03-25 14:11 - 2014-07-01 16:12 - 00000998 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-03-25 14:00 - 2014-03-28 15:57 - 00000000 ____D C:\Users\MitrevG\AppData\Roaming\uTorrent 2016-03-25 09:13 - 2014-07-01 16:13 - 00002203 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-03-25 09:13 - 2014-07-01 16:13 - 00002191 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-03-24 16:50 - 2014-03-28 16:10 - 00000000 ____D C:\ProgramData\ProductData 2016-03-24 16:48 - 2015-03-31 10:36 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2016-03-24 16:48 - 2015-03-31 10:36 - 00000000 ___SD C:\Windows\system32\GWX 2016-03-24 16:17 - 2016-02-09 12:10 - 00000000 ____D C:\Users\MitrevG\Desktop\Нова папка 2016-03-24 16:17 - 2015-11-11 14:44 - 00000000 ____D C:\Users\MitrevG\Desktop\Папка Данко 2016-03-24 16:17 - 2015-06-08 09:58 - 00000000 ____D C:\Users\MitrevG\Desktop\Снимки Тони 2016-03-24 16:17 - 2014-03-20 14:35 - 00000000 ____D C:\Users\MitrevG 2016-03-24 16:14 - 2016-02-16 16:39 - 00000000 ____D C:\Users\MitrevG\Desktop\НТН 2011 заличаване 2016-03-24 16:14 - 2016-02-13 16:21 - 00000000 ___HD C:\$WINDOWS.~BT 2016-03-24 16:14 - 2016-01-14 13:29 - 00000000 ____D C:\Users\MitrevG\Desktop\Сашо-търг.обект 2016-03-24 16:14 - 2016-01-08 13:20 - 00000000 ____D C:\Users\MitrevG\Desktop\ДОК. СУХА РЕКА 2016-03-24 16:14 - 2015-11-24 13:12 - 00000000 ____D C:\Users\MitrevG\Desktop\оферти 2016-03-24 16:14 - 2015-11-24 13:07 - 00000000 ____D C:\Users\MitrevG\Desktop\Документи на имоти 2016-03-24 16:14 - 2015-11-17 10:27 - 00000000 ____D C:\Users\MitrevG\Desktop\Документи Суха река за сделка - сградата 2016-03-24 16:14 - 2015-11-12 12:07 - 00000000 ____D C:\Users\MitrevG\Desktop\А 34 - фонтаните 2016-03-24 16:14 - 2014-04-17 10:24 - 00000000 ____D C:\Users\MitrevG\Desktop\Almani 2016-03-21 14:41 - 2011-04-12 10:28 - 00000000 ___RD C:\Users\Public\Recorded TV 2016-03-21 13:41 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2016-03-21 13:38 - 2014-03-21 00:20 - 00000000 ____D C:\Windows\Panther 2016-03-21 09:25 - 2014-03-20 15:14 - 00000000 ____D C:\Users\MitrevG\AppData\Local\ElevatedDiagnostics 2016-03-16 08:34 - 2014-03-31 07:45 - 91451392 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak 2016-03-16 08:34 - 2014-03-31 07:45 - 44679168 _____ C:\Windows\system32\config\COMPONENTS.iodefrag.bak 2016-03-16 08:34 - 2014-03-31 07:45 - 00282624 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak 2016-03-16 08:34 - 2014-03-31 07:45 - 00061440 _____ C:\Windows\system32\config\SAM.iodefrag.bak 2016-03-16 08:34 - 2014-03-31 07:45 - 00028672 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak 2016-03-11 08:22 - 2014-03-28 16:09 - 00000000 ____D C:\Users\MitrevG\AppData\Roaming\IObit 2016-03-11 08:21 - 2014-03-28 16:10 - 00000000 ____D C:\Users\MitrevG\AppData\LocalLow\IObit 2016-03-11 08:21 - 2014-03-28 16:10 - 00000000 ____D C:\ProgramData\IObit 2016-03-11 08:21 - 2014-03-28 16:10 - 00000000 ____D C:\Program Files (x86)\IObit 2016-03-10 10:54 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2016-03-10 08:40 - 2009-07-14 06:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-03-10 08:39 - 2009-07-14 06:45 - 00409520 _____ C:\Windows\system32\FNTCACHE.DAT 2016-03-09 16:49 - 2014-03-20 18:07 - 00000000 ____D C:\Windows\system32\MRT 2016-03-09 16:46 - 2014-12-11 07:57 - 00000000 ____D C:\Windows\system32\appraiser 2016-03-09 16:46 - 2014-03-20 18:07 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-03-09 08:12 - 2014-05-12 13:11 - 00000000 ____D C:\ProgramData\Skype 2016-02-24 17:38 - 2014-03-20 15:26 - 00002121 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk 2016-02-24 17:38 - 2014-03-20 15:26 - 00001945 _____ C:\Windows\epplauncher.mif 2016-02-24 17:37 - 2014-03-20 15:26 - 00000000 ____D C:\Program Files\Microsoft Security Client 2016-02-24 17:37 - 2014-03-20 15:26 - 00000000 ____D C:\Program Files (x86)\Microsoft Security Client ==================== Files in the root of some directories ======= 2014-03-28 16:00 - 2011-08-18 23:07 - 0283136 _____ () C:\Program Files (x86)\1026.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0351232 _____ () C:\Program Files (x86)\1028.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0172032 _____ () C:\Program Files (x86)\1029.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0148992 _____ () C:\Program Files (x86)\1030.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0165376 _____ () C:\Program Files (x86)\1031.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0320512 _____ () C:\Program Files (x86)\1032.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0003584 _____ () C:\Program Files (x86)\1033.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0161280 _____ () C:\Program Files (x86)\1034.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0165376 _____ () C:\Program Files (x86)\1036.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0177664 _____ () C:\Program Files (x86)\1038.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0159232 _____ () C:\Program Files (x86)\1040.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0082944 _____ () C:\Program Files (x86)\1041.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 1124352 _____ () C:\Program Files (x86)\1042.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0154112 _____ () C:\Program Files (x86)\1043.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0173056 _____ () C:\Program Files (x86)\1045.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0155136 _____ () C:\Program Files (x86)\1046.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0289280 _____ () C:\Program Files (x86)\1049.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0175104 _____ () C:\Program Files (x86)\1051.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0146432 _____ () C:\Program Files (x86)\1053.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0171520 _____ () C:\Program Files (x86)\1055.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0239616 _____ () C:\Program Files (x86)\1058.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0103936 _____ () C:\Program Files (x86)\1061.mst 2014-03-28 16:00 - 2011-08-18 23:07 - 0351232 _____ () C:\Program Files (x86)\2052.mst 2014-03-28 16:00 - 2011-08-18 23:20 - 8025600 _____ () C:\Program Files (x86)\ABBYY FineReader 11.msi 2014-03-28 16:00 - 2011-08-18 22:57 - 1136904 _____ (ABBYY) C:\Program Files (x86)\AutoRun.exe 2014-03-28 16:00 - 2011-05-17 20:16 - 0000093 _____ () C:\Program Files (x86)\AutoRun.inf 2014-03-28 16:00 - 2011-08-18 23:07 - 84303222 _____ () C:\Program Files (x86)\Bin.cab 2014-03-28 16:00 - 2011-08-18 23:06 - 32332722 _____ () C:\Program Files (x86)\DictLang.cab 2014-03-28 16:00 - 2009-07-07 18:12 - 1822520 _____ (Microsoft Corporation) C:\Program Files (x86)\instmsiw.exe 2014-03-28 16:00 - 2011-07-21 14:55 - 0000563 _____ () C:\Program Files (x86)\setup.ini 2014-03-28 16:00 - 2009-07-07 18:12 - 0245408 _____ (Microsoft Corporation) C:\Program Files (x86)\unicows.dll 2014-03-28 15:58 - 2014-03-28 15:58 - 1043536 _____ (BitTorrent Inc.) C:\Program Files (x86)\uTorrent.exe 2014-06-19 07:16 - 2014-06-19 07:16 - 0000024 _____ () C:\Users\MitrevG\AppData\Roaming\temp.ini Some files in TEMP: ==================== C:\Users\MitrevG\AppData\Local\Temp\pkcs11wrapper5669190542113875118.dll C:\Users\MitrevG\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-03-21 12:19 ==================== End of FRST.txt ============================ Addition.txt
  21. Здравейте, компютъра забива, когато сърфирам в интернет и като влизам в дота2 ми зарежда бавно и ми изписва грешка ( дота2 не отгвоаря т.е.not responding) след няколко минути се оправя. Специално за дотата като свалих за първи път играта (преди няколко месеца) имах същия проблем, но след време се оправи, като цяло и при стартиране на комютъра зарежда бавно. Ако може да помогнете, ОС: Windows 7 Ultimate. Благодаря.
  22. Здравейте. С много бавен комп съм в момента, тъй като стария ми остана без дъно. Нямам антивирусна, а правя едни презентации и се налага да тегля един куп снимки и други файлове. Имам съмнение за вирус и си инсталирах FRST.exe. Направих каквото е необходимо и сега пускам резултатите тук FRST.txt Addition.txt
  23. Вчера седнах пред компютъра и когато се опитах да отворя ОЛХ ми се отвори съвсем друга интернет страница. Работя с Мозила но имам и Гугъл хром и от него се опитвах със същия ефект. В мозилата имах отметка в лентата на отметките и през нея и през търсачката и в хрома винаги отваря същата страница- ето снимка http://prikachi.com/images/298/8485298J.jpg Забелязах че и с мобиле.бг е станало същото, нито от отметките нито през търсачката мога да вляза. Преинсталирах браузърите - пак същото. Явно сме лепнали нещо някъде. Моля за помощ и благодаря предварително защото и преди съм ползвал помоща на екипа Ви! Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:26-11-2015 Ran by Administrator (administrator) on COMPUTEK-1DC5C0 (26-11-2015 23:32:37) Running from C:\Documents and Settings\Administrator\My Documents\Изтегляния Loaded Profiles: Administrator (Available Profiles: Administrator) Platform: Microsoft Windows XP Professional Service Pack 3 (X86) Language: English (United States) Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Google Inc.) C:\Program Files\Google\Update\1.3.28.17\GoogleCrashHandler.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Analog Devices, Inc.) C:\Program Files\Analog Devices\Core\smax4pnp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe (Microsoft Corporation) C:\WINDOWS\system32\rundll32.exe () C:\Program Files\Mtel NetAgent\MtelNetAgent_Launcher.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner.exe () C:\WINDOWS\Datecs\Flex2K.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Computer, Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Teruten) C:\WINDOWS\system32\FsUsbExService.Exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc32.exe () C:\WINDOWS\system32\PnkBstrA.exe () C:\Program Files\Mtel NetAgent\MtelNetAgent_Service.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [782520 2015-11-17] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [SoundMAXPnP] => C:\Program Files\Analog Devices\Core\smax4pnp.exe [868352 2007-03-16] (Analog Devices, Inc.) HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-09-12] (Adobe Systems Incorporated) HKLM\...\Run: [TAG_MtelNetAgent_Launcher.exe] => C:\Program Files\Mtel NetAgent\MtelNetAgent_Launcher.exe [952888 2014-04-14] () HKLM\...\Run: [Avira SystrayStartTrigger] => C:\Program Files\Avira\Launcher\Avira.SystrayStartTrigger.exe [66320 2015-10-14] (Avira Operations GmbH & Co. KG) HKU\S-1-5-19\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\S-1-5-20\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N HKU\S-1-5-21-515967899-1979792683-842925246-500\...\Run: [DAEMON Tools Lite] => C:\Program Files\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-515967899-1979792683-842925246-500\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner.exe [5282584 2014-11-21] (Piriform Ltd) HKU\S-1-5-21-515967899-1979792683-842925246-500\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1 HKU\S-1-5-21-515967899-1979792683-842925246-500\...\MountPoints2: G - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-21-515967899-1979792683-842925246-500\...\MountPoints2: {3050ba0c-fe47-11e4-adcf-001d9204ec90} - G:\.\Autorun.exe AUTORUN=1 HKU\S-1-5-18\...\RunOnce: [_nltide_3] => rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Adobe Gamma.lnk [2014-12-18] ShortcutTarget: Adobe Gamma.lnk -> C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.) Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FlexType 2K.lnk [2012-11-17] ShortcutTarget: FlexType 2K.lnk -> C:\WINDOWS\Datecs\Flex2K.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [94208 2006-02-28] (Apple Computer, Inc.) Winsock: Catalog9 01 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-15] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 02 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-15] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 03 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-15] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 04 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-15] (Avira Operations GmbH & Co. KG) Winsock: Catalog9 13 C:\Program Files\Avira\AntiVir Desktop\avsda.dll [507984 2014-05-15] (Avira Operations GmbH & Co. KG) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{6562F65F-DD0F-4E59-B6C3-64283866C0C0}: [DhcpNameServer] 192.168.1.1 192.168.1.1 Internet Explorer: ================== HKU\S-1-5-21-515967899-1979792683-842925246-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/?pc=SKY2&ocid=SKY2DHP&osmkt=en-us SearchScopes: HKU\S-1-5-21-515967899-1979792683-842925246-500 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-515967899-1979792683-842925246-500 -> {793940E2-D8CE-4707-9D01-B3EFF05F249F} URL = hxxp://www.bing.com/search?FORM=SKY2DF&PC=SKY2&q={searchTerms}&src=IE-SearchBox Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qe4temke.default-1447773881339 FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google) FF Plugin: @microsoft.com/WPF,version=3.5 -> C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.28.17\npGoogleUpdate3.dll [2015-11-26] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.28.17\npGoogleUpdate3.dll [2015-11-26] (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-09-12] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-09-12] (Adobe Systems Inc.) FF Extension: ABV Notifier - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qe4temke.default-1447773881339\extensions\[email protected] [2015-11-24] FF Extension: Adblock Plus - C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\qe4temke.default-1447773881339\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-11-26] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-04-14] [not signed] FF HKLM\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\Documents and Settings\All Users\Application Data\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext => not found Chrome: ======= CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-515967899-1979792683-842925246-500\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 6to4; C:\WINDOWS\System32\6to4svc.dll [100864 2010-09-16] (Microsoft Corporation) S3 Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-12-18] (Adobe Systems) [File not signed] S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [916968 2015-11-17] (Avira Operations GmbH & Co. KG) R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [461672 2015-11-17] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [461672 2015-11-17] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [1210512 2015-11-17] (Avira Operations GmbH & Co. KG) R2 Avira.ServiceHost; C:\Program Files\Avira\Launcher\Avira.ServiceHost.exe [243968 2015-10-14] (Avira Operations GmbH & Co. KG) R2 Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [229376 2006-02-28] (Apple Computer, Inc.) [File not signed] S3 FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2014-12-18] (Macrovision Europe Ltd.) [File not signed] R2 FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [233472 2013-05-22] (Teruten) [File not signed] R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation) R2 PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [75136 2014-10-30] () R2 TAG_Service; C:\Program Files\Mtel NetAgent\MtelNetAgent_Service.exe [350776 2014-04-14] () ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 avgntflt; C:\WINDOWS\System32\DRIVERS\avgntflt.sys [108448 2015-11-17] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [136728 2015-11-17] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\WINDOWS\System32\DRIVERS\avkmgr.sys [37896 2015-05-23] (Avira Operations GmbH & Co. KG) S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-13] (Microsoft Corporation) R1 dtsoftbus01; C:\WINDOWS\System32\DRIVERS\dtsoftbus01.sys [243128 2014-12-02] (Disc Soft Ltd) R3 FsUsbExDisk; C:\WINDOWS\system32\FsUsbExDisk.SYS [37344 2013-05-22] () [File not signed] S3 hwusb_cdcacm; C:\WINDOWS\System32\DRIVERS\ew_cdcacm.sys [108032 2013-12-10] (Huawei Technologies Co., Ltd.) S3 hwusb_cdcecm; C:\WINDOWS\System32\DRIVERS\ew_cdcecm.sys [117504 2013-12-10] (Huawei Technologies Co., Ltd.) S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-13] (Microsoft Corporation) U3 PROCMON23; C:\WINDOWS\System32\Drivers\PROCMON23.SYS [65048 2013-11-19] (Sysinternals - www.sysinternals.com) R3 SenFiltService; C:\WINDOWS\System32\drivers\Senfilt.sys [8704 2005-03-17] (Analog Devices, Inc.) R1 ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [31848 2015-06-16] (Avira Operations GmbH & Co. KG) R1 Tcpip6; C:\WINDOWS\System32\DRIVERS\tcpip6.sys [226880 2010-09-16] (Microsoft Corporation) S3 VM30xx86; C:\WINDOWS\System32\Drivers\vm30xx86.sys [1294336 2007-03-20] (Vimicro Corporation) U5 ewusbnet; C:\Windows\System32\Drivers\ewusbnet.sys [249728 2013-11-30] (Huawei Technologies Co., Ltd.) S4 InCDFs; system32\drivers\InCDFs.sys [X] S4 IntelIde; no ImagePath U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] U1 WS2IFSL; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-11-26 23:26 - 2015-11-26 23:32 - 00000000 ____D C:\FRST 2015-11-26 23:16 - 2015-11-26 23:16 - 00000730 _____ C:\Documents and Settings\All Users\Start Menu\Programs\Mozilla Firefox.lnk 2015-11-26 23:16 - 2015-11-26 23:16 - 00000724 _____ C:\Documents and Settings\All Users\Desktop\Mozilla Firefox.lnk 2015-11-26 23:16 - 2015-11-26 23:16 - 00000000 ____D C:\WINDOWS\LastGood 2015-11-26 16:54 - 2015-11-26 16:54 - 06251688 _____ C:\Documents and Settings\Administrator\Desktop\куверт.psd 2015-11-24 20:21 - 2015-11-26 23:16 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-11-02 12:28 - 2015-11-02 12:28 - 00000383 _____ C:\ftconfig.ini ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-11-26 23:32 - 2012-10-18 16:02 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Temp 2015-11-26 23:26 - 2015-05-14 23:33 - 00000000 ____D C:\Documents and Settings\Administrator\My Documents\Изтегляния 2015-11-26 23:26 - 2012-10-18 18:42 - 00000000 ____D C:\WINDOWS 2015-11-26 23:23 - 2012-10-18 18:42 - 00000000 ___HD C:\WINDOWS\inf 2015-11-26 23:19 - 2013-02-19 19:37 - 00022530 _____ C:\WINDOWS\system32\nvAppTimestamps 2015-11-26 23:16 - 2013-04-19 18:52 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-11-26 23:16 - 2013-02-09 15:06 - 00000000 ____D C:\Program Files\Google 2015-11-26 23:16 - 2012-10-18 18:48 - 00592240 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-11-26 23:16 - 2012-10-18 16:32 - 00000000 ____D C:\Documents and Settings\Administrator\Local Settings\Application Data\Google 2015-11-26 23:11 - 2014-12-27 13:40 - 00000316 _____ C:\WINDOWS\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-515967899-1979792683-842925246-500.job 2015-11-26 23:11 - 2014-12-27 13:40 - 00000294 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-515967899-1979792683-842925246-500.job 2015-11-26 23:11 - 2013-02-09 15:06 - 00000996 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-11-26 23:11 - 2012-10-18 16:02 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-11-26 23:10 - 2012-10-18 16:02 - 00032528 _____ C:\WINDOWS\SchedLgU.Txt 2015-11-26 23:10 - 2012-10-18 16:02 - 00000278 ___SH C:\Documents and Settings\Administrator\ntuser.ini 2015-11-26 23:10 - 2012-10-18 16:02 - 00000000 ____D C:\Documents and Settings\Administrator 2015-11-26 23:06 - 2012-12-01 23:25 - 00000000 ____D C:\Program Files\Real 2015-11-26 23:06 - 2012-12-01 23:25 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\Real 2015-11-26 23:06 - 2012-12-01 23:24 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Real 2015-11-26 23:04 - 2013-02-09 15:06 - 00001000 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-11-26 23:04 - 2012-11-15 17:06 - 00000000 ____D C:\Program Files\Adobe Media Player 2015-11-26 23:04 - 2012-11-15 16:34 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Adobe 2015-11-26 21:55 - 2012-11-15 18:37 - 01834496 ___SH C:\Documents and Settings\Administrator\Desktop\Thumbs.db 2015-11-26 15:14 - 2014-12-27 13:40 - 00000302 _____ C:\WINDOWS\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-515967899-1979792683-842925246-500.job 2015-11-26 15:13 - 2008-04-14 12:00 - 00002206 _____ C:\WINDOWS\system32\wpa.dbl 2015-11-25 01:07 - 2012-11-08 00:28 - 01025410 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-515967899-1979792683-842925246-500-0.dat 2015-11-25 01:07 - 2012-11-08 00:28 - 00260322 _____ C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat 2015-11-18 18:41 - 2014-11-14 13:08 - 00000000 ____D C:\Documents and Settings\All Users\Application Data\Package Cache 2015-11-17 17:45 - 2014-12-27 13:40 - 00000324 _____ C:\WINDOWS\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-515967899-1979792683-842925246-500.job 2015-11-17 17:34 - 2012-10-18 16:36 - 00000000 ____D C:\Documents and Settings\All Users\Start Menu\Programs\Avira 2015-11-17 17:31 - 2012-10-18 16:35 - 00136728 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys 2015-11-17 17:31 - 2012-10-18 16:35 - 00108448 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys 2015-11-16 22:34 - 2015-04-09 20:37 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\vlc 2015-11-16 22:18 - 2013-02-09 18:28 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\AIMP3 2015-11-16 22:18 - 2012-10-18 16:34 - 00000000 ____D C:\Documents and Settings\Administrator\Application Data\uTorrent 2015-11-02 22:09 - 2012-10-18 16:02 - 00000000 ___RD C:\Documents and Settings\Administrator\My Documents 2015-11-02 21:59 - 2012-11-03 16:38 - 00000116 _____ C:\WINDOWS\NeroDigital.ini ==================== Files in the root of some directories ======= 2014-10-30 13:38 - 2014-10-30 13:38 - 0138056 _____ () C:\Documents and Settings\Administrator\Application Data\PnkBstrK.sys 2012-11-01 21:48 - 2015-06-30 20:52 - 0065024 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-11-05 17:11 - 2012-11-05 17:11 - 0000090 _____ () C:\Documents and Settings\Administrator\Local Settings\Application Data\FASTWiz.log Some files in TEMP: ==================== C:\Documents and Settings\Administrator\Local Settings\Temp\avgnt.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed ==================== End of FRST.txt ============================ Addition.txt
  24. Здравейте, След Reset на лаптопа се оказа, че без да е включван в мрежата, без да е инсталирано нещо на компютъра въобще и дори без да е включван, батерията се изтощи от 100% на 59% след като се включи САМ !!! преди няколко дни. От тогава всеки ден след изключването на лаптопа през нощта изразходва 3-4% от батерията, при положение, че няма инсталирани програми. За съжаление не ми дава възможност да копирам съдържанието на FRST.txt файла, както и да опитвам. Озадачих се, че на D drivе има 160 МВ заети с нещо, затова прикачам снимки. Благодаря предварително! Addition.txt FRST.txt Съдържанието на FRST.txt го качвам в 11 jpegs чрез prt sc, защото по никакъв друг начин не мога да го копирам! Още 3 jpgs
×
×
  • Добави ново...