Премини към съдържанието

Препоръчан отговор


Прикачих двата файла след Scan и ви моля за помощ.

Addition.txt

FRST.txt

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Здравейте...! :) Моля да опишете подробно за проблема си..! Какви симптоми наблюдавате..? Имам нужда от по подробна информация...!

 

icon1337347931.png  Сканиране с RKill

  • Отворете следния сайт и изтеглете RKill.exe и ги запазете на вашия десктоп.
  • Стартирате програмата с двоен клик върху файла и изчакайте търпеливо.
  • След приключване на проверката ще се генерира лог файл с извършените процедури.
  • Не рестартирайте компютъра след приключване на работата на  RKill, тъй като злонамерените програми (ако има такива) ще се задействат отново.
  • Прикачете лог файла в следващия си пост и преминете към следващата стъпка.

 

 

GfiJrQ9.png Malwarebytes Anti-Malware (MBAM)

Моля, изтеглете Malwarebytes Anti-Malware 2.2.0.1024 Final и я запазете на вашия десктоп.

  • Стартирайте файла mbam-setup-bc.хххх-х.х.х.хххх.exe и следвайте указанията за да инсталирате програмата.
  • След като инсталацията приключи се уверете че сте сложили отметка пред:
  • Launch Malwarebytes Anti-Malware
  • Отметката активираща пробния 14 дневен период също е маркиран по-подразбиране. Ако не желаете да тествате защитата в реално време на програмата през следващите 14 дни тогава премахнете отметката. Т.е. премахнете първата отметка:

DkgJ7Zr.png

  • Натиснете бутона Finish.
  • Отидете до табът Settings > Detection and Protection > и под категориятаDetection Options включете опцията "Scan for rootkits".
  • Отидете до табът Scan, сложете радио-бутона пред Threat Scan и след това натиснете бутона Scan Now >> . Ако е намерена актуализация тогава натиснете бутона Update Now.
  • Ще започне проверка за зловреден софтуер.
  • При някои инфекции можете да видите съобщението:
  • "Could not load DDA driver"
  • Натиснете "Yes" на това съобщение за да позволите драйвера да се зареди след рестарт.
  • Разрешете на компютъра да се рестартира и след това продължете с останалите инструкции.
  • След като проверката приключи натиснете бутона Apply Actions.
  • Изчакайте да се появи прозореца подканващ ви да рестартирате и след това натиснете бутона Yes.
  • След рестарта, когато се появи десктопа MBAM ще се зареди още веднъж.
  • Отидете то табът History > Application Logs.

65ZBqkR.jpg

  • Отворете рапорта с последната дата и час и натиснете бутона "Copy to Clipboard"
  • Сега вече поставете съдържанието на лог файла с клавишната комбинацияCtrl + V и го публикувайте в следващия си коментар.

 

 

Дневници

В следващия си отговор, моля да включите следните дневници:

  • Лог файл от RKill
  • Дневник от Malwarebytes Anti -Malware

Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Открих проблема- в системата имаше инсталиран KJ Activator- изтрих него от контрол панел и съобщението спря да се показва. Благодаря.

Сподели този отговор


Линк към този отговор
Сподели в други сайтове
преди 22 часа, milevmilev написа:

Открих проблема- в системата имаше инсталиран KJ Activator- изтрих него от контрол панел и съобщението спря да се показва. Благодаря.

Щом така мислите...! Темата се приключва...! Лек ден..!


Сподели този отговор


Линк към този отговор
Сподели в други сайтове

Регистрирайте се или влезете в профила си за да коментирате

Трябва да имате регистрация за да може да коментирате това

Регистрирайте се

Създайте нова регистрация в нашия форум. Лесно е!

Нова регистрация

Вход

Имате регистрация? Влезте от тук.

Вход

  • Разглеждащи това в момента   0 потребители

    Няма регистрирани потребители разглеждащи тази страница.

  • Горещи теми в момента

  • Подобни теми

    • от dancho730616
      Здравейте!
      След инсталиранена една игра, започна да се появява u bar и редиректване  към други сайтове.
      Сканирах с мвам, но не знам дали  са останали и други вируси.
      Прикачвам логовете
      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 21.07.2018
      Ran by Георги (administrator) on ГЕОРГИ-PC (27-07-2018 14:55:28)
      Running from C:\Users\Георги\Desktop
      Loaded Profiles: Георги (Available Profiles: Георги)
      Platform: Windows 7 Professional Service Pack 1 (X64) Language: Български (България)
      Internet Explorer Version 8 (Default browser: FF)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
      ==================== Processes (Whitelisted) =================
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
      (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
      (QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
      (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
      (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
      () C:\Windows\SysWOW64\PnkBstrA.exe
      (Palit Microsystems Ltd.) C:\Program Files (x86)\Thunder Master\THPanel.exe
      (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
      (Wargaming.net) C:\Games\World_of_Tanks\WargamingGameUpdater.exe
      (QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
      (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
      (QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe
      (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
      ==================== Registry (Whitelisted) ===========================
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
      HKLM-x32\...\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe [1460832 2018-03-13] (QIHU 360 SOFTWARE CO. LIMITED)
      HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG)
      HKU\S-1-5-21-1675032139-3229095875-1074267058-1001\...\Run: [THPanel] => C:\Program Files (x86)\Thunder Master\THPanel.exe [2030440 2017-03-30] (Palit Microsystems Ltd.)
      HKU\S-1-5-21-1675032139-3229095875-1074267058-1001\...\Run: [World of Tanks] => C:\Games\World_of_Tanks\WargamingGameUpdater.exe [3139936 2018-06-25] (Wargaming.net)
      HKU\S-1-5-21-1675032139-3229095875-1074267058-1001\...\MountPoints2: F - F:\HTC_Sync_Manager_PC.exe
      HKU\S-1-5-21-1675032139-3229095875-1074267058-1001\...\MountPoints2: {d1ac3699-803e-11e8-afad-002264b6d386} - D:\Autorun.exe
      ==================== Internet (Whitelisted) ====================
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
      Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 0.0.0.0
      Tcpip\..\Interfaces\{3BFB2928-BD47-4D2E-A295-A6E65AC8ACEF}: [DhcpNameServer] 192.168.0.1 0.0.0.0
      Internet Explorer:
      ==================
      HKU\S-1-5-21-1675032139-3229095875-1074267058-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.bg/
      HKU\S-1-5-21-1675032139-3229095875-1074267058-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
      BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll [2018-03-13] (Qihu 360 Software Co., Ltd.)
      BHO-x32: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon.dll [2017-11-27] (Qihu 360 Software Co., Ltd.)
      Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
      Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
      Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
      Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
      FireFox:
      ========
      FF DefaultProfile: 6mp9cxh7.default
      FF ProfilePath: C:\Users\Георги\AppData\Roaming\Mozilla\Firefox\Profiles\6mp9cxh7.default [2018-07-27]
      FF Homepage: Mozilla\Firefox\Profiles\6mp9cxh7.default -> www.google.bg
      FF Extension: (AdGuard рекламен блокер) - C:\Users\Георги\AppData\Roaming\Mozilla\Firefox\Profiles\6mp9cxh7.default\Extensions\adguardadblocker@adguard.com.xpi [2018-07-24]
      FF Extension: (uBlock Origin) - C:\Users\Георги\AppData\Roaming\Mozilla\Firefox\Profiles\6mp9cxh7.default\Extensions\uBlock0@raymondhill.net.xpi [2018-07-24]
      FF Extension: (WebCompat Reporter) - C:\Program Files\Mozilla Firefox\browser\features\webcompat-reporter@mozilla.org.xpi [2018-07-04] [Legacy] [not signed]
      FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_30_0_0_134.dll [2018-07-11] ()
      FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_134.dll [2018-07-11] ()
      FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2012-07-31] (Foxit Corporation)
      FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2018-03-16] (NVIDIA Corporation)
      FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2018-03-16] (NVIDIA Corporation)
      FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
      ==================== Services (Whitelisted) ====================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
      S3 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-16] (NVIDIA Corporation)
      S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [522688 2018-03-16] (NVIDIA Corporation)
      R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2018-07-24] ()
      R2 QHActiveDefense; C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe [929888 2018-03-13] (QIHU 360 SOFTWARE CO. LIMITED)
      R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
      R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
      R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
      ===================== Drivers (Whitelisted) ======================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [183416 2017-11-27] (360.cn)
      R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [86248 2018-03-13] (360.cn)
      R3 360AvFlt; C:\Windows\SysWOW64\DRIVERS\360AvFlt.sys [86248 2018-03-13] (360.cn)
      R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [330472 2018-03-13] (360.cn)
      S3 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [49088 2017-11-27] (360.cn)
      R1 360FsFlt; C:\Windows\System32\DRIVERS\360FsFlt.sys [433784 2017-11-27] (360.cn)
      R1 360netmon; C:\Windows\System32\DRIVERS\360netmon.sys [87672 2018-03-13] (360.cn)
      R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [201336 2018-03-13] (360.cn)
      R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [152688 2018-06-19] (Malwarebytes)
      R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [191208 2018-07-27] (Malwarebytes)
      R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [114920 2018-07-27] (Malwarebytes)
      R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [48360 2018-07-27] (Malwarebytes)
      R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-07-27] (Malwarebytes)
      R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [92792 2018-07-27] (Malwarebytes)
      S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [31168 2018-03-16] (NVIDIA Corporation)
      R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [59240 2018-03-16] (NVIDIA Corporation)
      R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [58816 2018-03-16] (NVIDIA Corporation)
      ==================== NetSvcs (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ==================== One Month Created files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-07-27 14:55 - 2018-07-27 14:55 - 000009431 _____ C:\Users\Георги\Desktop\FRST.txt
      2018-07-27 14:55 - 2018-07-27 14:55 - 000000000 ____D C:\FRST
      2018-07-27 14:48 - 2018-07-27 14:48 - 000142970 _____ C:\Users\Георги\Desktop\мвам.txt
      2018-07-27 14:25 - 2018-07-27 14:26 - 002412544 _____ (Farbar) C:\Users\Георги\Desktop\FRST64.exe
      2018-07-27 14:14 - 2018-07-27 14:46 - 000114920 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
      2018-07-27 14:14 - 2018-07-27 14:46 - 000092792 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
      2018-07-27 14:14 - 2018-07-27 14:46 - 000048360 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
      2018-07-27 14:14 - 2018-07-27 14:14 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
      2018-07-27 14:14 - 2018-07-27 14:14 - 000191208 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
      2018-07-27 14:14 - 2018-07-27 14:14 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
      2018-07-27 14:14 - 2018-07-27 14:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
      2018-07-27 14:14 - 2018-07-27 14:14 - 000000000 ____D C:\ProgramData\Malwarebytes
      2018-07-27 14:14 - 2018-07-27 14:14 - 000000000 ____D C:\Program Files\Malwarebytes
      2018-07-27 14:14 - 2018-06-19 14:09 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
      2018-07-27 13:58 - 2018-07-27 13:58 - 000001058 _____ C:\Users\Public\Desktop\BurnAware Free.lnk
      2018-07-27 13:58 - 2018-07-27 13:58 - 000000000 ____D C:\Users\Георги\AppData\Roaming\Burnaware
      2018-07-27 13:58 - 2018-07-27 13:58 - 000000000 ____D C:\Program Files (x86)\BurnAware Free
      2018-07-25 17:50 - 2018-07-25 17:50 - 000000000 ____D C:\Users\Георги\AppData\LocalLow\BitTorrent
      2018-07-24 10:14 - 2018-07-24 10:14 - 000000000 ____D C:\Users\Георги\AppData\Local\PunkBuster
      2018-07-24 10:11 - 2018-07-27 02:38 - 000111928 _____ C:\Windows\SysWOW64\PnkBstrB.exe
      2018-07-24 10:11 - 2018-07-24 10:11 - 000682280 _____ C:\Windows\SysWOW64\pbsvc.exe
      2018-07-24 10:11 - 2018-07-24 10:11 - 000066872 _____ C:\Windows\SysWOW64\PnkBstrA.exe
      2018-07-24 10:10 - 2018-07-24 10:10 - 000001289 _____ C:\Users\Георги\Desktop\Call of Duty - World at War - сетевая игра.lnk
      2018-07-24 10:10 - 2018-07-24 10:10 - 000001277 _____ C:\Users\Георги\Desktop\Call of Duty - World at War - одиночная игра.lnk
      2018-07-24 10:10 - 2018-07-24 10:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision
      2018-07-24 09:56 - 2018-07-24 09:56 - 000000000 ____D C:\Program Files (x86)\Activision
      2018-07-24 09:49 - 2018-07-24 09:50 - 000000000 ____D C:\Users\Георги\Downloads\CODWaW_RU_ND_Repacked
      2018-07-24 09:25 - 2018-07-24 09:25 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
      2018-07-24 09:25 - 2018-07-24 09:25 - 000000924 _____ C:\Users\Public\Desktop\Firefox.lnk
      2018-07-24 09:25 - 2018-07-24 09:25 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
      2018-07-24 09:24 - 2018-07-24 09:25 - 000000000 ____D C:\Program Files\Mozilla Firefox
      2018-07-24 09:14 - 2018-07-24 09:14 - 002555831 _____ C:\Users\Георги\Downloads\geek.zip
      2018-07-20 16:32 - 2018-07-22 15:06 - 000000000 ___SD C:\Users\Георги\AppData\LocalLow\Temp
      2018-07-20 16:29 - 2018-07-20 16:43 - 000000002 _____ C:\Users\Георги\AppData\Local\imw.ini
      2018-07-17 16:22 - 2018-07-17 16:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medal of Honor Allied Assault Breakthrough
      2018-07-17 16:12 - 2018-07-17 16:22 - 000000000 ____D C:\Program Files (x86)\Medal of Honor Allied Assault Breakthrough
      2018-07-10 11:50 - 2018-07-10 11:50 - 000001223 _____ C:\Users\Георги\Desktop\Medal Of Honor Airborne.lnk
      2018-07-10 11:50 - 2013-10-08 09:52 - 000653136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr90.dll
      2018-07-10 11:50 - 2013-10-06 22:11 - 000109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 004456904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110u.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 004421080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000875472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000535008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000168920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl110.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000092624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm110u.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000092616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm110.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000074704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110fra.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000074704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110deu.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000073680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110esn.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000072656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110ita.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000070624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110rus.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000064976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110enu.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000053712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110jpn.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000053200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110kor.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000046032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110cht.dll
      2018-07-10 11:50 - 2012-11-06 01:20 - 000046032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc110chs.dll
      2018-07-10 11:50 - 2012-05-11 01:10 - 001178112 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Windows\SysWOW64\libeay32.dll
      2018-07-10 11:50 - 2012-05-11 01:10 - 000265216 _____ (The OpenSSL Project, hxxp://www.openssl.org/) C:\Windows\SysWOW64\libssl32.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 004422992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100u.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 004397384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000773968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000421200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp100.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000138056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl100.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000081744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm100u.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000081744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcm100.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000064336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100fra.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000064336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100deu.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000063824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100esn.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000062288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100ita.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000060752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100rus.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000055120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100enu.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000043856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100jpn.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000043344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100kor.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000036176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100cht.dll
      2018-07-10 11:50 - 2011-06-11 01:58 - 000036176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc100chs.dll
      2018-07-10 11:50 - 2009-07-12 02:51 - 001053696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71u.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71deu.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71ita.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71fra.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71esp.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71enu.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71kor.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71jpn.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71cht.dll
      2018-07-10 11:50 - 2009-07-12 02:40 - 000040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71chs.dll
      2018-07-10 11:50 - 2009-07-12 02:35 - 001060864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc71.dll
      2018-07-10 11:50 - 2009-07-12 02:07 - 000090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl71.dll
      2018-07-10 11:50 - 2009-03-24 10:52 - 000659264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomct2.ocx
      2018-07-10 11:50 - 2009-03-24 10:52 - 000614992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.ocx
      2018-07-10 11:50 - 2009-03-24 10:52 - 000415552 _____ (Microsoft Corporation ) C:\Windows\SysWOW64\comct332.ocx
      2018-07-10 11:50 - 2009-03-24 10:52 - 000222528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.ocx
      2018-07-10 11:50 - 2009-03-24 10:52 - 000215880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mci32.ocx
      2018-07-10 11:50 - 2009-03-24 10:52 - 000170080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comct232.ocx
      2018-07-10 11:50 - 2009-03-24 10:52 - 000155984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
      2018-07-10 11:50 - 2007-11-15 13:27 - 000626688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr80.dll
      2018-07-10 11:50 - 2007-11-15 13:27 - 000548864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp80.dll
      2018-07-10 11:50 - 2007-08-27 15:41 - 001089440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msidcrl40.dll
      2018-07-10 11:50 - 2007-01-30 22:04 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll
      2018-07-10 11:50 - 2006-08-26 02:28 - 001017344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70u.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70ita.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70fra.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70esp.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70deu.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70enu.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70kor.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70jpn.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70cht.dll
      2018-07-10 11:50 - 2006-08-26 02:15 - 000040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70chs.dll
      2018-07-10 11:50 - 2006-08-26 02:07 - 001024000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70.dll
      2018-07-10 11:50 - 2006-08-26 01:17 - 000086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl70.dll
      2018-07-10 11:50 - 2006-04-11 02:41 - 001066176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl32.ocx
      2018-07-10 11:50 - 2005-01-20 21:25 - 000054784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvci70.dll
      2018-07-10 11:50 - 2003-06-05 13:57 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp71.dll
      2018-07-10 11:50 - 2003-02-21 04:42 - 000348160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr71.dll
      2018-07-10 11:50 - 2002-06-06 14:38 - 000139264 _____ (Creative Technology Ltd) C:\Windows\SysWOW64\eax.dll
      2018-07-10 11:50 - 2002-01-05 07:40 - 000487424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp70.dll
      2018-07-10 11:50 - 1997-07-19 16:55 - 001347344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Msvbvm50.dll
      2018-07-10 11:50 - 1994-11-18 03:00 - 000210944 _____ C:\Windows\SysWOW64\msvcrt10.dll
      2018-07-10 11:38 - 2018-07-10 11:38 - 000000000 ____D C:\Program Files (x86)\Medal Of Honor Airborne
      2018-07-10 11:27 - 2018-07-10 11:37 - 373346304 ____R C:\Users\Георги\Downloads\Medal Of Honor Airborne [CUTA].iso
      2018-07-09 16:36 - 2018-07-09 16:36 - 000000000 ____D C:\Users\Георги\AppData\LocalLow\Yandex
      2018-07-07 13:42 - 2018-07-25 16:22 - 000003852 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1530960144
      2018-07-07 13:42 - 2018-07-25 16:22 - 000000000 ____D C:\Program Files\Opera
      2018-07-07 13:42 - 2018-07-07 13:42 - 000001097 _____ C:\Users\Public\Desktop\Браузър Opera.lnk
      2018-07-07 13:42 - 2018-07-07 13:42 - 000001097 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Браузър Opera.lnk
      2018-07-07 13:40 - 2018-07-07 13:40 - 002555831 _____ C:\Users\Георги\Desktop\geek.zip
      2018-07-07 13:26 - 2016-08-10 23:52 - 000827728 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100.dll
      2018-07-06 19:18 - 2018-07-06 19:18 - 000002964 _____ C:\Windows\System32\Tasks\{928D244D-E86B-4504-9522-B520654A76CD}
      2018-07-06 19:18 - 2018-07-06 19:18 - 000002964 _____ C:\Windows\System32\Tasks\{47CED9CA-B76C-4489-967B-D72BA7D76A2C}
      2018-07-06 12:31 - 2018-07-06 12:31 - 000002964 _____ C:\Windows\System32\Tasks\{0E75E324-B782-4748-9B9A-CB2135946DFA}
      2018-07-06 10:36 - 2018-07-10 11:51 - 000000000 ____D C:\Users\Георги\Documents\EA Games
      2018-07-06 10:22 - 2018-07-06 10:22 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
      2018-07-05 14:17 - 2018-07-05 14:17 - 000001254 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk
      2018-07-05 14:15 - 2018-07-05 14:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
      2018-07-05 14:15 - 2018-07-05 14:15 - 000000000 ____D C:\Program Files (x86)\Elaborate Bytes
      2018-07-03 12:03 - 2018-07-03 12:03 - 000000000 ____D C:\Users\Георги\AppData\Roaming\Wargaming.net
      2018-07-02 16:58 - 2018-07-02 16:58 - 000000000 ____D C:\Users\Георги\AppData\Local\Activision
      2018-07-02 16:13 - 2018-07-25 18:33 - 000000000 ____D C:\Users\Георги\AppData\Roaming\BitTorrent
      2018-07-02 16:13 - 2018-07-02 16:13 - 000000873 _____ C:\Users\Георги\Desktop\BitTorrent.lnk
      2018-07-02 16:08 - 2018-07-17 15:33 - 000000000 ____D C:\D-drive-676638
      2018-07-02 16:07 - 2018-07-02 16:09 - 000001024 ____H C:\AMTAG.BIN
      2018-07-01 12:53 - 2018-07-01 12:53 - 000000000 ____D C:\Users\Георги\AppData\Roaming\HeroesAndGeneralsDesktop
      2018-07-01 12:45 - 2018-07-02 15:07 - 000000000 ____D C:\Users\Георги\AppData\LocalLow\Heroes and Generals
      2018-06-27 13:26 - 2018-06-27 13:26 - 000003522 _____ C:\Windows\System32\Tasks\RunAsStdUser_GameCenter
      2018-06-27 13:24 - 2018-06-27 13:26 - 000000000 ____D C:\Users\Георги\AppData\Roaming\Geek Uninstaller
      2018-06-27 12:41 - 2018-06-27 13:25 - 000000000 ____D C:\GamesMailRu
      2018-06-27 12:32 - 2018-06-27 12:32 - 000000000 ____D C:\Users\Георги\AppData\Roaming\360TotalSecurity
      ==================== One Month Modified files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-07-27 14:53 - 2009-07-14 07:45 - 000021104 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2018-07-27 14:53 - 2009-07-14 07:45 - 000021104 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2018-07-27 14:46 - 2018-03-22 18:19 - 000000000 ____D C:\ProgramData\NVIDIA
      2018-07-27 14:46 - 2017-12-04 17:08 - 000000000 ____D C:\Users\Георги\AppData\LocalLow\360WD
      2018-07-27 14:46 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
      2018-07-27 14:45 - 2017-12-04 16:48 - 000000000 ____D C:\Users\Георги\AppData\LocalLow\Mozilla
      2018-07-26 01:48 - 2017-12-06 00:30 - 000000000 ____D C:\Users\Георги\AppData\Local\CrashDumps
      2018-07-25 19:33 - 2017-12-04 17:40 - 000000000 ____D C:\Users\Георги\AppData\Local\ElevatedDiagnostics
      2018-07-24 10:12 - 2009-07-14 08:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
      2018-07-24 09:25 - 2017-12-04 16:48 - 000000000 ____D C:\Users\Георги\AppData\Roaming\Mozilla
      2018-07-24 09:25 - 2017-12-04 16:48 - 000000000 ____D C:\Users\Георги\AppData\Local\Mozilla
      2018-07-24 09:16 - 2017-12-04 16:42 - 000000000 ____D C:\Users\Георги
      2018-07-24 09:14 - 2018-02-27 14:23 - 000000000 __SHD C:\$360Section
      2018-07-24 09:14 - 2018-02-27 14:18 - 000000000 ____D C:\ProgramData\360Quarant
      2018-07-23 12:25 - 2009-07-14 08:08 - 000032542 _____ C:\Windows\Tasks\SCHEDLGU.TXT
      2018-07-21 14:58 - 2017-12-04 17:07 - 000000000 ____D C:\ProgramData\360safe
      2018-07-20 22:49 - 2009-07-14 08:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
      2018-07-20 22:49 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
      2018-07-11 16:05 - 2018-03-22 18:11 - 000004478 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
      2018-07-11 16:05 - 2017-12-04 16:54 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
      2018-07-11 16:05 - 2017-12-04 16:54 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
      2018-07-11 16:05 - 2017-12-04 16:54 - 000004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
      2018-07-11 16:05 - 2017-12-04 16:54 - 000000000 ____D C:\Windows\SysWOW64\Macromed
      2018-07-11 16:05 - 2017-12-04 16:54 - 000000000 ____D C:\Windows\system32\Macromed
      2018-07-11 13:48 - 2018-03-13 14:39 - 000004466 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
      2018-07-06 10:36 - 2018-03-22 18:56 - 000000000 ____D C:\Users\Георги\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
      2018-07-05 14:09 - 2017-12-04 17:14 - 000000000 ____D C:\Games
      2018-07-02 16:49 - 2018-02-27 14:17 - 000000000 ____D C:\Users\Георги\AppData\Roaming\360safe
      ==================== Files in the root of some directories =======
      2009-07-14 04:14 - 2009-07-14 04:14 - 000073216 ____N (Microsoft Corporation) C:\Program Files (x86)\Common Files\uNzGUe.exe
      2009-07-14 04:14 - 2009-07-14 04:14 - 000073216 ____N (Microsoft Corporation) C:\Users\Георги\AppData\Roaming\OayiXoOJyeY.exe
      2018-07-20 16:29 - 2018-07-20 16:43 - 000000002 _____ () C:\Users\Георги\AppData\Local\imw.ini
      Some files in TEMP:
      ====================
      2018-07-07 13:40 - 2018-07-07 13:40 - 003437504 _____ (Geek Unіnstaller) C:\Users\Георги\AppData\Local\Temp\geek64.exe
      ==================== Bamital & volsnap ======================
      (There is no automatic fix for files that do not pass verification.)
      C:\Windows\system32\winlogon.exe => File is digitally signed
      C:\Windows\system32\wininit.exe => File is digitally signed
      C:\Windows\SysWOW64\wininit.exe => File is digitally signed
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\SysWOW64\explorer.exe => File is digitally signed
      C:\Windows\system32\svchost.exe => File is digitally signed
      C:\Windows\SysWOW64\svchost.exe => File is digitally signed
      C:\Windows\system32\services.exe => File is digitally signed
      C:\Windows\system32\User32.dll => File is digitally signed
      C:\Windows\SysWOW64\User32.dll => File is digitally signed
      C:\Windows\system32\userinit.exe => File is digitally signed
      C:\Windows\SysWOW64\userinit.exe => File is digitally signed
      C:\Windows\system32\rpcss.dll => File is digitally signed
      C:\Windows\system32\dnsapi.dll => File is digitally signed
      C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
      C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
      LastRegBack: 2018-07-17 13:28
      ==================== End of FRST.txt ============================
       
       
      Addition.txt
      мвам.txt
    • от svetlana1964
      Здравейте, моля Ви за помощ понеже съм лаик в тази област. Открих зловреден софтуер, изтрих го от антивирусната програма, деинсталирах и google chrome/защото показваше, че е там вируса/ и рестартирах компютъра. След това пуснах отново да сканира и той отново се появи. Влезнах в диск C и изтрих това, което ми изписваше, че е вируса. След това вече не се появи, явно се отървах от него. Но когато инсталирах отново google chrome и пак пуснах антивирусната ми излезна друг вирус  C/Program Files/Google/Chrome/Applicatton/ Chrome. exe  Въпроса ми е ако влезна в твърдия диск C и го изтрия там ще повредя ли нещо?
    • от Янка Трифонова
      Имам един вирус, който му забарви името. Появяват се изщачащи прозорци при ползване на google chrome. Почистих комюпътра последователно със adwcleaner, htiman pro, malwarebytes... Не успява да го изчисти за съжаление
       
      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018 Ran by yanka (administrator) on DESKTOP-CPJ8TFE (30-06-2018 22:09:28) Running from C:\Users\yanka\Downloads Loaded Profiles: yanka & (Available Profiles: yanka) Platform: Windows 10 Pro Version 1803 17134.112 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Opera) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe (Performix LLC) C:\Program Files (x86)\Adguard\AdguardSvc.exe () C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe () C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe (Nitro PDF Software) C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe (Microsoft Corporation) C:\Windows\System32\printfilterpipelinesvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Desktop.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.MicrosoftOfficeHub_17.9328.1700.0_x64__8wekyb3d8bbwe\Office16\OfficeHubTaskHost.exe () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18052.10711.0_x64__8wekyb3d8bbwe\Video.UI.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Performix LLC) C:\Program Files (x86)\Adguard\Adguard.exe () C:\Program Files (x86)\BoricaAD\BISS\BISS.exe (Oracle Corporation) C:\Program Files (x86)\BoricaAD\BISS\jre1.8.0_144\bin\javaw.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe (Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe (Brother Industries, Ltd.) C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe (Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe (Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe (Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe (Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\AcWebBrowser.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\MSOSYNC.EXE (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated) HKLM\...\Run: [AdobeGCInvoker-1.0] => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [316392 2018-05-11] (Adobe Systems, Incorporated) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242904 2018-06-20] (AVAST Software) HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-06-16] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4514304 2014-08-26] (Brother Industries, Ltd.) HKLM-x32\...\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1944576 2013-03-07] (Brother Industries, Ltd.) HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [709416 2018-03-10] (Autodesk, Inc.) HKLM-x32\...\Run: [Bonus.SSR.FR12] => C:\Program Files (x86)\ABBYY FineReader 12\Bonus.ScreenshotReader.exe [1472312 2018-05-11] (ABBYY Production LLC.) HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation) HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-06302018220720016\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation) HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-06302018220720050\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation) HKU\S-1-5-21-3081403711-1452664787-965955870-1001\...\Run: [Adguard] => C:\Program Files (x86)\Adguard\Adguard.exe [5716752 2018-03-06] (Performix LLC) HKU\S-1-5-21-3081403711-1452664787-965955870-1001\...\Policies\Explorer: [] HKU\S-1-5-21-3081403711-1452664787-965955870-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssText3d.scr [217088 2018-04-12] (Microsoft Corporation) HKU\S-1-5-21-3081403711-1452664787-965955870-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-06302018220720081\...\Run: [Adguard] => C:\Program Files (x86)\Adguard\Adguard.exe [5716752 2018-03-06] (Performix LLC) HKU\S-1-5-21-3081403711-1452664787-965955870-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-06302018220720081\...\Policies\Explorer: [] HKU\S-1-5-21-3081403711-1452664787-965955870-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-06302018220720081\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\ssText3d.scr [217088 2018-04-12] (Microsoft Corporation) Startup: C:\Users\yanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\BISS.lnk [2018-04-17] ShortcutTarget: BISS.lnk -> C:\Program Files (x86)\BoricaAD\BISS\BISS.exe () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 94.26.50.7 94.26.50.8 Tcpip\..\Interfaces\{8fb52371-846f-4f09-8a26-cc1246842a61}: [DhcpNameServer] 94.26.50.7 94.26.50.8 Internet Explorer: ================== BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2015-03-31] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-03-18] (Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-03-18] (Microsoft Corporation) FireFox: ======== FF DefaultProfile: wzwpem97.default FF ProfilePath: C:\Users\yanka\AppData\Roaming\Mozilla\Firefox\Profiles\wzwpem97.default [2018-06-29] FF Extension: (Avast SafePrice) - C:\Users\yanka\AppData\Roaming\Mozilla\Firefox\Profiles\wzwpem97.default\Extensions\sp@avast.com.xpi [2018-04-12] FF Extension: (Avast Online Security) - C:\Users\yanka\AppData\Roaming\Mozilla\Firefox\Profiles\wzwpem97.default\Extensions\wrc@avast.com.xpi [2018-06-20] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-03-31] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation) FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 10\npnitromozilla.dll [2015-05-06] (Nitro PDF) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-21] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-21] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-05-11] (Adobe Systems Inc.) Chrome: ======= CHR DefaultSearchURL: Default -> hxxps://ssl.gstatic.com/docs/spreadsheets/favicon_jfk2.png CHR Profile: C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default [2018-06-30] CHR Extension: (Презентации) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-04-11] CHR Extension: (Документи) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-04-11] CHR Extension: (Google Диск) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-04-11] CHR Extension: (YouTube) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-04-11] CHR Extension: (Avast SafePrice) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2018-06-20] CHR Extension: (Таблици) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-04-11] CHR Extension: (КАСА - Google Таблици) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjagmccglmmkiaepnjekpdffjbeaehoc [2018-05-11] CHR Extension: (Google Документи офлайн) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-04-12] CHR Extension: (Avast Online Security) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-04-13] CHR Extension: (Плащания в уеб магазина на Chrome) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-11] CHR Extension: (Scrummos) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaapbceemikiebmdofdbfoflpfnnepf [2018-06-07] CHR Extension: (Gmail) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-04-11] CHR Extension: (Chrome Media Router) - C:\Users\yanka\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-11] CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1374072 2018-03-10] (Autodesk Inc.) R2 Adguard Service; C:\Program Files (x86)\Adguard\AdguardSvc.exe [129296 2018-03-06] (Performix LLC) R2 AGMService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGMService.exe [2321384 2018-05-11] (Adobe Systems, Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2128872 2018-05-11] (Adobe Systems, Incorporated) R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7780400 2018-06-20] (AVAST Software) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-06-20] (AVAST Software) S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (www.BitComet.com) R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [282112 2013-09-25] (Brother Industries, Ltd.) [File not signed] R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2017-07-26] () [File not signed] R3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-03] (Malwarebytes) R2 NitroDriverReadSpool10; C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe [324760 2015-05-06] (Nitro PDF Software) R2 NitroUpdateService; C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe [418968 2015-05-06] () R2 osrss; C:\WINDOWS\system32\osrss.dll [131288 2018-06-27] (Microsoft Corporation) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation) S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] () R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [11293936 2018-04-03] (TeamViewer GmbH) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4451616 2018-04-12] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105344 2018-04-12] (Microsoft Corporation) ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 adgnetworkwfpdrv; C:\WINDOWS\System32\drivers\adgnetworkwfpdrv.sys [81000 2017-03-27] () R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [197160 2018-06-20] (AVAST Software) R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdrivera.sys [229392 2018-06-20] (AVAST Software) R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsha.sys [201328 2018-06-20] (AVAST Software) R0 aswblog; C:\WINDOWS\System32\drivers\aswbloga.sys [346664 2018-06-20] (AVAST Software) R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniva.sys [59592 2018-06-20] (AVAST Software) S3 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [15360 2018-06-20] (AVAST Software) R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [239680 2018-06-20] (AVAST Software) S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [46976 2018-06-20] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [159640 2018-06-20] (AVAST Software) R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [111872 2018-06-20] (AVAST Software) R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [85968 2018-06-20] (AVAST Software) R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [1027728 2018-06-20] (AVAST Software) R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [463080 2018-06-20] (AVAST Software) R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [211160 2018-06-20] (AVAST Software) R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [381584 2018-06-20] (AVAST Software) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [152184 2018-04-26] (Malwarebytes) R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [190696 2018-06-29] (Malwarebytes) R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [112864 2018-06-30] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [44768 2018-06-30] (Malwarebytes) R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253664 2018-06-30] (Malwarebytes) R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [103648 2018-06-30] (Malwarebytes) R3 MTsensor; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [17280 2013-05-17] () R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-12] (Realtek ) S3 smbdirect; C:\WINDOWS\System32\DRIVERS\smbdirect.sys [152064 2018-04-12] (Microsoft Corporation) S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44616 2018-04-12] (Microsoft Corporation) S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [331680 2018-04-12] (Microsoft Corporation) S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [44032 2018-04-12] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-06-30 22:09 - 2018-06-30 22:09 - 000018683 _____ C:\Users\yanka\Downloads\FRST.txt 2018-06-30 22:09 - 2018-06-30 22:09 - 000000000 ____D C:\FRST 2018-06-30 22:08 - 2018-06-30 22:08 - 002412544 _____ (Farbar) C:\Users\yanka\Downloads\FRST64.exe 2018-06-30 21:55 - 2018-06-30 21:55 - 000000000 ___HD C:\OneDriveTemp 2018-06-29 21:10 - 2018-06-29 21:10 - 043520264 _____ (Microsoft Corporation) C:\Users\yanka\Downloads\Windows-KB890830-x64-V5.61.exe 2018-06-29 10:59 - 2018-06-29 10:59 - 000000567 _____ C:\Users\yanka\Desktop\JRT.txt 2018-06-29 10:54 - 2018-06-29 10:54 - 001790024 _____ (Malwarebytes) C:\Users\yanka\Downloads\JRT.exe 2018-06-26 13:52 - 2018-06-26 13:52 - 000287149 _____ C:\Users\yanka\Downloads\AccountStatementDocuments_NID01_180626_134436_BFA0D4AB-2985-4CEF-B3BC-DED1D1692DBC.pdf 2018-06-25 16:28 - 2018-06-25 16:28 - 000064524 _____ C:\Users\yanka\Downloads\pog_plan_PDK0320180625162424.pdf 2018-06-22 14:41 - 2018-06-22 14:41 - 000000000 _____ C:\WINDOWS\SysWOW64\last.dump 2018-06-22 14:40 - 2018-06-29 10:54 - 000000000 ____D C:\Users\yanka\AppData\LocalLow\Mozilla 2018-06-22 14:40 - 2018-06-22 14:40 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk 2018-06-22 14:40 - 2018-06-22 14:40 - 000000993 _____ C:\Users\Public\Desktop\Firefox.lnk 2018-06-22 14:40 - 2018-06-22 14:40 - 000000000 ____D C:\Users\yanka\AppData\Roaming\Mozilla 2018-06-22 14:40 - 2018-06-22 14:40 - 000000000 ____D C:\Users\yanka\AppData\Local\Mozilla 2018-06-22 14:40 - 2018-06-22 14:40 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2018-06-22 14:39 - 2018-06-22 14:40 - 000000000 ____D C:\Program Files\Mozilla Firefox 2018-06-22 14:39 - 2018-06-22 14:39 - 000313656 _____ (Mozilla) C:\Users\yanka\Downloads\Firefox Installer.exe 2018-06-22 14:38 - 2018-06-30 22:09 - 000000000 ____D C:\ProgramData\Adguard 2018-06-22 14:38 - 2018-06-30 21:34 - 000000000 ____D C:\Program Files (x86)\Adguard 2018-06-22 14:38 - 2018-06-22 14:38 - 000173328 _____ C:\Users\yanka\Downloads\adguardInstaller.exe 2018-06-22 14:38 - 2018-06-22 14:38 - 000000998 _____ C:\Users\Public\Desktop\Adguard.lnk 2018-06-22 14:38 - 2018-06-22 14:38 - 000000260 _____ C:\WINDOWS\SysWOW64\Drivers\vwifikerneldrv.sys 2018-06-22 14:38 - 2018-06-22 14:38 - 000000260 _____ C:\WINDOWS\SysWOW64\d3dx9_11.dll.tmp 2018-06-22 14:38 - 2018-06-22 14:38 - 000000260 _____ C:\ProgramData\fontcacheev1.dat 2018-06-22 14:38 - 2018-06-22 14:38 - 000000000 ____D C:\Users\yanka\AppData\Roaming\Performix LLC 2018-06-22 14:38 - 2018-06-22 14:38 - 000000000 ____D C:\Users\yanka\AppData\Local\Performix_LLC 2018-06-22 14:38 - 2018-06-22 14:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adguard 2018-06-22 14:38 - 2017-03-27 08:01 - 000081000 _____ () C:\WINDOWS\system32\Drivers\adgnetworkwfpdrv.sys 2018-06-22 14:37 - 2018-06-30 22:10 - 000103648 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys 2018-06-22 14:37 - 2018-06-30 22:06 - 000044768 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys 2018-06-22 14:37 - 2018-06-30 22:05 - 000112864 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys 2018-06-22 14:37 - 2018-06-29 10:02 - 000190696 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys 2018-06-22 14:36 - 2018-06-30 22:05 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys 2018-06-22 12:21 - 2018-06-22 12:21 - 000327839 _____ C:\Users\yanka\Downloads\Дневник за покупките-12.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000227871 _____ C:\Users\yanka\Downloads\Дневник за покупките-10.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000203267 _____ C:\Users\yanka\Downloads\Дневник за покупките-11.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000159818 _____ C:\Users\yanka\Downloads\Дневник за покупките-03.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000146997 _____ C:\Users\yanka\Downloads\Дневник за покупките-05.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000143804 _____ C:\Users\yanka\Downloads\Дневник за покупките-09.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000137572 _____ C:\Users\yanka\Downloads\Дневник за покупките-06.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000130622 _____ C:\Users\yanka\Downloads\Дневник за покупките-07.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000130494 _____ C:\Users\yanka\Downloads\Дневник за покупките-04.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000130406 _____ C:\Users\yanka\Downloads\Дневник за покупките-01.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000129562 _____ C:\Users\yanka\Downloads\Дневник за покупките-10.2016.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000124790 _____ C:\Users\yanka\Downloads\Дневник за покупките-11.2016.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000120244 _____ C:\Users\yanka\Downloads\Дневник за покупките-09.2016.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000116948 _____ C:\Users\yanka\Downloads\Дневник за покупките-12.2016.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000115595 _____ C:\Users\yanka\Downloads\Дневник за покупките-08.2017.pdf 2018-06-22 12:21 - 2018-06-22 12:21 - 000115549 _____ C:\Users\yanka\Downloads\Дневник за покупките-02.2017.pdf 2018-06-22 12:16 - 2018-06-22 12:16 - 000102400 _____ C:\Users\yanka\Downloads\Платежно вещо лице.pdf 2018-06-21 12:56 - 2018-06-21 12:56 - 000111064 _____ C:\Users\yanka\Downloads\Интертайм континентал (1).pdf 2018-06-21 10:37 - 2018-06-21 10:37 - 000000000 ____D C:\Users\yanka\AppData\Local\CrashDumps 2018-06-21 10:19 - 2018-06-21 10:19 - 000001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2018-06-21 10:19 - 2018-06-21 10:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2018-06-21 10:19 - 2018-06-21 10:19 - 000000000 ____D C:\ProgramData\Malwarebytes 2018-06-21 10:19 - 2018-06-21 10:19 - 000000000 ____D C:\Program Files\Malwarebytes 2018-06-21 10:19 - 2018-04-26 05:36 - 000152184 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys 2018-06-21 10:14 - 2018-06-21 10:14 - 000000000 ____D C:\Users\yanka\AppData\Roaming\Obsidium 2018-06-21 09:45 - 2018-06-27 03:55 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2018-06-21 09:45 - 2018-06-27 03:55 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2018-06-21 09:44 - 2018-06-21 09:49 - 000003518 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA 2018-06-21 09:44 - 2018-06-21 09:49 - 000003394 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore 2018-06-21 09:42 - 2018-06-29 09:44 - 000000000 ____D C:\Users\yanka\AppData\Local\AVAST Software 2018-06-20 17:35 - 2018-06-20 17:35 - 000378072 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe 2018-06-20 17:35 - 2018-06-20 17:35 - 000015360 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswElam.sys 2018-06-20 10:13 - 2018-06-20 10:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitComet (64-bit) 2018-06-20 09:50 - 2018-06-20 09:51 - 000000000 ____D C:\AdwCleaner 2018-06-20 09:50 - 2018-06-20 09:50 - 007372496 _____ (Malwarebytes) C:\Users\yanka\Downloads\adwcleaner_7.2.0.exe 2018-06-20 09:46 - 2018-06-20 09:46 - 000012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe 2018-06-20 09:43 - 2018-06-20 09:47 - 000000000 ____D C:\ProgramData\HitmanPro 2018-06-20 09:43 - 2018-06-20 09:43 - 011609024 _____ (SurfRight B.V.) C:\Users\yanka\Downloads\hitmanpro_x64.exe 2018-06-15 14:55 - 2018-06-15 14:55 - 000112090 _____ C:\Users\yanka\Downloads\Интертайм континентал.pdf 2018-06-15 02:35 - 2018-06-08 22:07 - 002266520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll 2018-06-15 02:35 - 2018-06-08 22:07 - 000506184 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe 2018-06-15 02:35 - 2018-06-08 22:07 - 000183712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mavinject.exe 2018-06-15 02:35 - 2018-06-08 22:07 - 000040864 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClientPS.dll 2018-06-15 02:35 - 2018-06-08 22:07 - 000019872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVTerminator.dll 2018-06-15 02:35 - 2018-06-08 22:05 - 000094112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll 2018-06-15 02:35 - 2018-06-08 22:02 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe 2018-06-15 02:35 - 2018-06-08 22:02 - 001634808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll 2018-06-15 02:35 - 2018-06-08 22:02 - 000661160 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe 2018-06-15 02:35 - 2018-06-08 22:01 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL 2018-06-15 02:35 - 2018-06-08 22:01 - 001046944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll 2018-06-15 02:35 - 2018-06-08 21:48 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll 2018-06-15 02:35 - 2018-06-08 21:47 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2018-06-15 02:35 - 2018-06-08 21:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll 2018-06-15 02:35 - 2018-06-08 21:45 - 012712448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2018-06-15 02:35 - 2018-06-08 21:45 - 004392448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll 2018-06-15 02:35 - 2018-06-08 21:45 - 001560576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe 2018-06-15 02:35 - 2018-06-08 21:45 - 000808960 _____ C:\WINDOWS\system32\MBR2GPT.EXE 2018-06-15 02:35 - 2018-06-08 21:44 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll 2018-06-15 02:35 - 2018-06-08 21:44 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll 2018-06-15 02:35 - 2018-06-08 21:44 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll 2018-06-15 02:35 - 2018-06-08 21:44 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll 2018-06-15 02:35 - 2018-06-08 21:43 - 003640832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe 2018-06-15 02:35 - 2018-06-08 21:43 - 002922496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll 2018-06-15 02:35 - 2018-06-08 21:43 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll 2018-06-15 02:35 - 2018-06-08 21:43 - 001659904 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll 2018-06-15 02:35 - 2018-06-08 21:43 - 001543680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll 2018-06-15 02:35 - 2018-06-08 21:43 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll 2018-06-15 02:35 - 2018-06-08 21:43 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll 2018-06-15 02:35 - 2018-06-08 21:42 - 003999232 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll 2018-06-15 02:35 - 2018-06-08 21:42 - 003653120 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2018-06-15 02:35 - 2018-06-08 21:42 - 002084864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl 2018-06-15 02:35 - 2018-06-08 21:42 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll 2018-06-15 02:35 - 2018-06-08 21:42 - 000800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe 2018-06-15 02:35 - 2018-06-08 21:42 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll 2018-06-15 02:35 - 2018-06-08 21:42 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe 2018-06-15 02:35 - 2018-06-08 21:42 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe 2018-06-15 02:35 - 2018-06-08 21:41 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll 2018-06-15 02:35 - 2018-06-08 21:41 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll 2018-06-15 02:35 - 2018-06-08 21:41 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll 2018-06-15 02:35 - 2018-06-08 21:41 - 000758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll 2018-06-15 02:35 - 2018-06-08 21:41 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe 2018-06-15 02:35 - 2018-06-08 21:41 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll 2018-06-15 02:35 - 2018-06-08 21:40 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll 2018-06-15 02:35 - 2018-06-08 20:07 - 000148896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mavinject.exe 2018-06-15 02:35 - 2018-06-08 20:06 - 001539488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll 2018-06-15 02:35 - 2018-06-08 20:04 - 001454024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll 2018-06-15 02:35 - 2018-06-08 19:58 - 002206544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL 2018-06-15 02:35 - 2018-06-08 19:58 - 000917408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll 2018-06-15 02:35 - 2018-06-08 19:51 - 011903488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2018-06-15 02:35 - 2018-06-08 19:50 - 001508352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdt.exe 2018-06-15 02:35 - 2018-06-08 19:48 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll 2018-06-15 02:35 - 2018-06-08 19:48 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll 2018-06-15 02:35 - 2018-06-08 19:47 - 003492864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll 2018-06-15 02:35 - 2018-06-08 19:47 - 002895872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys 2018-06-15 02:35 - 2018-06-08 19:47 - 001462784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll 2018-06-15 02:35 - 2018-06-08 19:47 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll 2018-06-15 02:35 - 2018-06-08 19:47 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll 2018-06-15 02:35 - 2018-06-08 19:47 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll 2018-06-15 02:35 - 2018-06-08 19:46 - 003444224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe 2018-06-15 02:35 - 2018-06-08 19:46 - 002016256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl 2018-06-15 02:35 - 2018-06-08 19:46 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll 2018-06-15 02:35 - 2018-06-08 19:45 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll 2018-06-15 02:35 - 2018-06-08 19:06 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe 2018-06-15 02:35 - 2018-06-08 19:05 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll 2018-06-15 02:35 - 2018-06-08 19:05 - 000944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll 2018-06-15 02:35 - 2018-06-08 17:00 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll 2018-06-15 02:35 - 2018-06-08 17:00 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll 2018-06-15 02:35 - 2018-06-08 13:38 - 005821544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll 2018-06-15 02:35 - 2018-06-08 13:37 - 002417840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll 2018-06-15 02:35 - 2018-06-08 13:35 - 001613200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll 2018-06-15 02:35 - 2018-06-08 13:35 - 000613144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll 2018-06-15 02:35 - 2018-06-08 13:34 - 001299056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll 2018-06-15 02:35 - 2018-06-08 13:34 - 000748512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll 2018-06-15 02:35 - 2018-06-08 13:31 - 007900984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll 2018-06-15 02:35 - 2018-06-08 13:31 - 003180176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll 2018-06-15 02:35 - 2018-06-08 13:31 - 000029600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys 2018-06-15 02:35 - 2018-06-08 13:30 - 000705440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys 2018-06-15 02:35 - 2018-06-08 12:34 - 001140576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi 2018-06-15 02:35 - 2018-06-08 12:34 - 000983016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe 2018-06-15 02:35 - 2018-06-08 12:33 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe 2018-06-15 02:35 - 2018-06-08 12:33 - 001034632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe 2018-06-15 02:35 - 2018-06-08 12:33 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll 2018-06-15 02:35 - 2018-06-08 12:33 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll 2018-06-15 02:35 - 2018-06-08 12:31 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe 2018-06-15 02:35 - 2018-06-08 12:31 - 001012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe 2018-06-15 02:35 - 2018-06-08 12:31 - 000226720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ucx01000.sys 2018-06-15 02:35 - 2018-06-08 12:30 - 009148320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2018-06-15 02:35 - 2018-06-08 12:30 - 003296896 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 001363632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 001063328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi 2018-06-15 02:35 - 2018-06-08 12:30 - 001017080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 000723360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 000722808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys 2018-06-15 02:35 - 2018-06-08 12:30 - 000567184 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe 2018-06-15 02:35 - 2018-06-08 12:30 - 000565152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS 2018-06-15 02:35 - 2018-06-08 12:30 - 000527264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe 2018-06-15 02:35 - 2018-06-08 12:30 - 000491328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 000194456 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys 2018-06-15 02:35 - 2018-06-08 12:30 - 000137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll 2018-06-15 02:35 - 2018-06-08 12:30 - 000134584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 007520000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 006817384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 004970360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 004403280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 003283408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 002836384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 002753048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 002590400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL 2018-06-15 02:35 - 2018-06-08 12:29 - 002570712 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 002564984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 002462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 002422688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 002371392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001946328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001921952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 001792808 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001611592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001457136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi 2018-06-15 02:35 - 2018-06-08 12:29 - 001364184 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001288816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001258288 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe 2018-06-15 02:35 - 2018-06-08 12:29 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001190152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001150416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001148808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001112608 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001097648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 001026976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 000885880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000792992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 000678840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000659096 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2018-06-15 02:35 - 2018-06-08 12:29 - 000416144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000413824 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000413088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 000375712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 000313592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000266656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000164768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys 2018-06-15 02:35 - 2018-06-08 12:29 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayUtil.dll 2018-06-15 02:35 - 2018-06-08 12:29 - 000057960 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel.appcore.dll 2018-06-15 02:35 - 2018-06-08 12:13 - 025846784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2018-06-15 02:35 - 2018-06-08 12:12 - 000861616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll 2018-06-15 02:35 - 2018-06-08 12:12 - 000786176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll 2018-06-15 02:35 - 2018-06-08 12:11 - 001461744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2018-06-15 02:35 - 2018-06-08 12:11 - 000550616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll 2018-06-15 02:35 - 2018-06-08 12:10 - 002479272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll 2018-06-15 02:35 - 2018-06-08 12:10 - 002331584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll 2018-06-15 02:35 - 2018-06-08 12:10 - 002307336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL 2018-06-15 02:35 - 2018-06-08 12:10 - 001988072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll 2018-06-15 02:35 - 2018-06-08 12:10 - 001397200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll 2018-06-15 02:35 - 2018-06-08 12:10 - 001011992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2018-06-15 02:35 - 2018-06-08 12:10 - 000880152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll 2018-06-15 02:35 - 2018-06-08 12:10 - 000457152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll 2018-06-15 02:35 - 2018-06-08 12:10 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 006569960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 006527064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 004788512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 004469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 002535552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 002486992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 002242216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001980872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001805776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001709720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001620880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001584128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001380200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001129648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001077504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 001020168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000988136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000770160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000607648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000568720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000553248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000064648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LanguageOverlayUtil.dll 2018-06-15 02:35 - 2018-06-08 12:09 - 000050208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel.appcore.dll 2018-06-15 02:35 - 2018-06-08 12:04 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll 2018-06-15 02:35 - 2018-06-08 12:03 - 022005760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2018-06-15 02:35 - 2018-06-08 12:03 - 000906752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.PhoneNumberFormatting.dll 2018-06-15 02:35 - 2018-06-08 12:03 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll 2018-06-15 02:35 - 2018-06-08 12:03 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll 2018-06-15 02:35 - 2018-06-08 12:03 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys 2018-06-15 02:35 - 2018-06-08 12:02 - 022713856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2018-06-15 02:35 - 2018-06-08 12:02 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll 2018-06-15 02:35 - 2018-06-08 12:02 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe 2018-06-15 02:35 - 2018-06-08 12:02 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe 2018-06-15 02:35 - 2018-06-08 12:01 - 004563456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2018-06-15 02:35 - 2018-06-08 12:01 - 002961408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll 2018-06-15 02:35 - 2018-06-08 12:01 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe 2018-06-15 02:35 - 2018-06-08 12:01 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll 2018-06-15 02:35 - 2018-06-08 12:01 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll 2018-06-15 02:35 - 2018-06-08 12:01 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll 2018-06-15 02:35 - 2018-06-08 12:01 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll 2018-06-15 02:35 - 2018-06-08 12:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll 2018-06-15 02:35 - 2018-06-08 12:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys 2018-06-15 02:35 - 2018-06-08 12:00 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2018-06-15 02:35 - 2018-06-08 12:00 - 004372992 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll 2018-06-15 02:35 - 2018-06-08 12:00 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll 2018-06-15 02:35 - 2018-06-08 12:00 - 001285120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll 2018-06-15 02:35 - 2018-06-08 12:00 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll 2018-06-15 02:35 - 2018-06-08 12:00 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe 2018-06-15 02:35 - 2018-06-08 12:00 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2018-06-15 02:35 - 2018-06-08 12:00 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll 2018-06-15 02:35 - 2018-06-08 12:00 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys 2018-06-15 02:35 - 2018-06-08 11:59 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 004867072 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 001767936 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 001318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 000564736 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe 2018-06-15 02:35 - 2018-06-08 11:59 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll 2018-06-15 02:35 - 2018-06-08 11:59 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 007581696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 001676800 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 000813568 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 000781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys 2018-06-15 02:35 - 2018-06-08 11:58 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll 2018-06-15 02:35 - 2018-06-08 11:58 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe 2018-06-15 02:35 - 2018-06-08 11:57 - 003348992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll 2018-06-15 02:35 - 2018-06-08 11:57 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll 2018-06-15 02:35 - 2018-06-08 11:57 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll 2018-06-15 02:35 - 2018-06-08 11:57 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll 2018-06-15 02:35 - 2018-06-08 11:57 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll 2018-06-15 02:35 - 2018-06-08 11:57 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys 2018-06-15 02:35 - 2018-06-08 11:57 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll 2018-06-15 02:35 - 2018-06-08 11:57 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll 2018-06-15 02:35 - 2018-06-08 11:57 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 005780992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 004336128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 003293696 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 002902016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 002900480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 002364928 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 001395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL 2018-06-15 02:35 - 2018-06-08 11:56 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll 2018-06-15 02:35 - 2018-06-08 11:56 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 003441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 002248192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2018-06-15 02:35 - 2018-06-08 11:55 - 002061824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 001371648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 001242112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 001171968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 001160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 001033728 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 000778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL 2018-06-15 02:35 - 2018-06-08 11:55 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll 2018-06-15 02:35 - 2018-06-08 11:55 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 002789376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 001128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000950272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000857088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL 2018-06-15 02:35 - 2018-06-08 11:54 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll 2018-06-15 02:35 - 2018-06-08 11:54 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL 2018-06-15 02:35 - 2018-06-08 11:53 - 001675264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll 2018-06-15 02:35 - 2018-06-08 11:53 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll 2018-06-15 02:35 - 2018-06-08 11:53 - 001108992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll 2018-06-15 02:35 - 2018-06-08 11:53 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll 2018-06-15 02:35 - 2018-06-08 11:53 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll 2018-06-15 02:35 - 2018-06-08 11:53 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2018-06-15 02:35 - 2018-06-08 11:53 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll 2018-06-15 02:35 - 2018-06-08 11:53 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll 2018-06-15 02:35 - 2018-06-08 10:41 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim 2018-06-15 02:35 - 2018-06-06 21:57 - 003733320 _____ C:\WINDOWS\system32\Windows.Mirage.dll 2018-06-15 02:35 - 2018-06-06 07:20 - 002841312 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll 2018-06-15 02:35 - 2018-06-02 02:24 - 000713376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll 2018-06-15 02:35 - 2018-06-02 01:54 - 001825792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll 2018-06-15 02:35 - 2018-05-25 06:24 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll 2018-06-12 17:17 - 2018-06-12 17:17 - 000118694 _____ C:\Users\yanka\Downloads\vedomost-05.2018.pdf 2018-06-12 17:17 - 2018-06-12 17:17 - 000118094 _____ C:\Users\yanka\Downloads\vedomost - 04.2018.pdf 2018-06-12 17:17 - 2018-06-12 17:17 - 000117855 _____ C:\Users\yanka\Downloads\vedomost - 01.2018.pdf 2018-06-12 17:17 - 2018-06-12 17:17 - 000117300 _____ C:\Users\yanka\Downloads\vedomost - 12.2017.pdf 2018-06-12 17:17 - 2018-06-12 17:17 - 000117219 _____ C:\Users\yanka\Downloads\vedomost-01.2017 (2).pdf 2018-06-12 16:46 - 2018-06-12 16:46 - 000126684 _____ C:\Users\yanka\Downloads\vedomost - 07.2017 (1).pdf 2018-06-12 16:46 - 2018-06-12 16:46 - 000123495 _____ C:\Users\yanka\Downloads\vedomost-08.2017 (1).pdf 2018-06-12 14:55 - 2018-06-12 14:55 - 000094834 _____ C:\Users\yanka\Downloads\фактура Смарт систем.pdf 2018-06-12 14:32 - 2018-06-12 14:32 - 003037451 _____ C:\Users\yanka\Downloads\ITC-geo-milev-vedomosti.rar 2018-06-12 14:32 - 2018-06-12 14:32 - 000000000 ____D C:\Users\yanka\Downloads\ITC-geo-milev-vedomosti 2018-06-12 14:29 - 2018-06-12 14:29 - 000119145 _____ C:\Users\yanka\Downloads\vedomost-11.2016.pdf 2018-06-12 14:29 - 2018-06-12 14:29 - 000118098 _____ C:\Users\yanka\Downloads\vedomost - 12.2016.pdf 2018-06-12 14:25 - 2018-06-12 14:25 - 000127307 _____ C:\Users\yanka\Downloads\vedomost-06.2017.pdf 2018-06-12 14:25 - 2018-06-12 14:25 - 000126524 _____ C:\Users\yanka\Downloads\vedomost-09.2017 (1).pdf 2018-06-12 14:25 - 2018-06-12 14:25 - 000124049 _____ C:\Users\yanka\Downloads\vedomost-03.2017 (1).pdf 2018-06-12 14:25 - 2018-06-12 14:25 - 000123740 _____ C:\Users\yanka\Downloads\vedomost-04.2017 (1).pdf 2018-06-12 14:25 - 2018-06-12 14:25 - 000123574 _____ C:\Users\yanka\Downloads\vedomost-01.2017 (1).pdf 2018-06-12 14:25 - 2018-06-12 14:25 - 000123528 _____ C:\Users\yanka\Downloads\vedomost-05.2017 (1).pdf 2018-06-12 14:25 - 2018-06-12 14:25 - 000123307 _____ C:\Users\yanka\Downloads\vedomost-02.2017 (1).pdf 2018-06-12 14:23 - 2018-06-12 14:23 - 000117693 _____ C:\Users\yanka\Downloads\vedomost - 06.2017.pdf 2018-06-12 14:23 - 2018-06-12 14:23 - 000117590 _____ C:\Users\yanka\Downloads\vedomost-08.2017.pdf 2018-06-12 14:23 - 2018-06-12 14:23 - 000117571 _____ C:\Users\yanka\Downloads\vedomost-05.2017.pdf 2018-06-12 14:23 - 2018-06-12 14:23 - 000117532 _____ C:\Users\yanka\Downloads\vedomost-03.2017.pdf 2018-06-12 14:23 - 2018-06-12 14:23 - 000117526 _____ C:\Users\yanka\Downloads\vedomost-09.2017.pdf 2018-06-12 14:23 - 2018-06-12 14:23 - 000117488 _____ C:\Users\yanka\Downloads\vedomost-04.2017.pdf 2018-06-12 14:23 - 2018-06-12 14:23 - 000117418 _____ C:\Users\yanka\Downloads\vedomost - 07.2017.pdf 2018-06-12 14:23 - 2018-06-12 14:23 - 000117219 _____ C:\Users\yanka\Downloads\vedomost-02.2017.pdf 2018-06-12 14:22 - 2018-06-12 14:22 - 000117219 _____ C:\Users\yanka\Downloads\vedomost-01.2017.pdf 2018-06-12 14:22 - 2018-06-12 14:22 - 000117194 _____ C:\Users\yanka\Downloads\vedomost-10.2017.pdf 2018-06-12 14:07 - 2018-06-12 14:07 - 000127143 _____ C:\Users\yanka\Downloads\vedomost-04.2018 (1).pdf 2018-06-12 11:03 - 2018-06-12 11:03 - 000007051 _____ C:\Users\yanka\Downloads\Размери паркинг система за 2 автомобила.pdf 2018-06-11 11:55 - 2018-06-11 11:55 - 000070716 _____ C:\Users\yanka\Downloads\210027991474_0242817462_20180611 (1).pdf 2018-06-11 11:53 - 2018-06-11 11:53 - 000070921 _____ C:\Users\yanka\Downloads\210035250539_0242958905_20180611.pdf 2018-06-11 11:53 - 2018-06-11 11:53 - 000070921 _____ C:\Users\yanka\Downloads\210035250539_0242958905_20180611 (1).pdf 2018-06-11 11:53 - 2018-06-11 11:53 - 000070852 _____ C:\Users\yanka\Downloads\210027957129_0242817459_20180611.pdf 2018-06-11 11:53 - 2018-06-11 11:53 - 000070852 _____ C:\Users\yanka\Downloads\210027957129_0242817459_20180611 (1).pdf 2018-06-11 11:53 - 2018-06-11 11:53 - 000070807 _____ C:\Users\yanka\Downloads\210027956931_0242817457_20180611.pdf 2018-06-11 11:53 - 2018-06-11 11:53 - 000070721 _____ C:\Users\yanka\Downloads\210027990088_0242817461_20180611.pdf 2018-06-11 11:53 - 2018-06-11 11:53 - 000070716 _____ C:\Users\yanka\Downloads\210027991474_0242817462_20180611.pdf 2018-06-11 11:53 - 2018-06-11 11:53 - 000070703 _____ C:\Users\yanka\Downloads\210027957228_0242817460_20180611.pdf 2018-06-08 18:50 - 2018-06-08 18:50 - 000126637 _____ C:\Users\yanka\Downloads\ведомост - 02,2018.pdf 2018-06-08 18:50 - 2018-06-08 18:50 - 000117857 _____ C:\Users\yanka\Downloads\ведомост - 02,2018 (1).pdf 2018-06-08 17:45 - 2018-06-08 17:45 - 000191624 _____ C:\Users\yanka\Downloads\ПРОФОРМА ФАКТУРА 3000010871 ИНТЕРТАЙМ КОНТИНЕНТАЛ АД (1).pdf 2018-06-08 15:11 - 2018-06-08 15:11 - 000040258 _____ C:\Users\yanka\Downloads\invoice-0000000103_both (1).pdf 2018-06-08 15:11 - 2018-06-08 15:11 - 000038860 _____ C:\Users\yanka\Downloads\invoice-0000000102_both.pdf 2018-06-08 13:07 - 2018-06-08 13:07 - 001887050 _____ C:\Users\yanka\Downloads\КСС, Протокол 1.pdf 2018-06-08 13:07 - 2018-06-08 13:07 - 000103078 _____ C:\Users\yanka\Downloads\F_1000000090.pdf 2018-06-08 13:01 - 2018-06-08 13:01 - 000037888 _____ C:\Users\yanka\Downloads\Oферта_29.03.18_Вълкович_Сивец (1).xls 2018-06-08 12:03 - 2018-06-08 12:03 - 000040258 _____ C:\Users\yanka\Downloads\invoice-0000000103_both.pdf 2018-06-08 11:47 - 2018-06-08 11:47 - 000054825 _____ C:\Users\yanka\Downloads\f-ra_O_0000000009.pdf 2018-06-08 11:02 - 2018-06-08 11:02 - 000190811 _____ C:\Users\yanka\Downloads\ПРОФОРМА ФАКТУРА 3000010871 ИНТЕРТАЙМ КОНТИНЕНТАЛ АД.pdf 2018-06-07 16:12 - 2018-06-07 16:12 - 001550999 _____ C:\Users\yanka\Downloads\Приемо-предавателен протокол и фактура договор за доставка (1).pdf 2018-06-06 13:13 - 2018-06-06 13:13 - 000227277 _____ C:\Users\yanka\Downloads\застраховка 3.pdf 2018-06-06 13:13 - 2018-06-06 13:13 - 000227165 _____ C:\Users\yanka\Downloads\застраховка 2.pdf 2018-06-06 13:13 - 2018-06-06 13:13 - 000227163 _____ C:\Users\yanka\Downloads\застраховка 1.pdf 2018-06-06 13:12 - 2018-06-06 13:12 - 000227001 _____ C:\Users\yanka\Downloads\застраховка.pdf 2018-06-06 13:12 - 2018-06-06 13:12 - 000052525 _____ C:\Users\yanka\Downloads\dobavak_Akt 14 UridL.PDF 2018-06-06 13:10 - 2018-06-06 13:10 - 000312116 _____ C:\Users\yanka\Downloads\Заявление за включване като страна по фирмен кредит ЮЛ.pdf 2018-06-06 13:10 - 2018-06-06 13:10 - 000223592 _____ C:\Users\yanka\Downloads\Заявление за включване като страна по фирмен кредит ФЛ.pdf 2018-06-05 11:53 - 2018-06-05 11:53 - 000066560 _____ C:\Users\yanka\Downloads\210027990088_0237832331_20180311.pdf 2018-06-05 11:38 - 2018-06-05 11:38 - 000065029 _____ C:\Users\yanka\Downloads\0366168966.pdf 2018-06-05 11:38 - 2018-06-05 11:38 - 000064959 _____ C:\Users\yanka\Downloads\0367921365.pdf 2018-06-05 11:04 - 2018-06-05 11:04 - 000013075 _____ C:\Users\yanka\Downloads\Protocol_05_18.xlsx 2018-06-04 13:52 - 2018-06-04 13:52 - 000612947 _____ C:\Users\yanka\Downloads\Отпуски май Делчо и Георги.pdf 2018-05-31 11:34 - 2018-05-31 11:34 - 003722701 _____ C:\Users\yanka\Downloads\ГФО 2017 и доклад.pdf 2018-05-31 10:13 - 2018-06-08 10:09 - 000000000 ____D C:\NAT32v2 2018-05-31 10:13 - 2018-05-31 10:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NAT32 IP Router 2018-05-31 10:10 - 2018-05-31 10:10 - 000000000 ____D C:\Program Files\Reference Assemblies 2018-05-31 10:10 - 2018-05-31 10:10 - 000000000 ____D C:\Program Files\MSBuild 2018-05-31 10:10 - 2018-05-31 10:10 - 000000000 ____D C:\Program Files (x86)\MSBuild 2018-05-31 10:09 - 2018-03-05 16:07 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2018-05-31 10:09 - 2018-03-05 16:07 - 000103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2018-05-31 10:09 - 2018-03-05 16:07 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2018-05-31 10:09 - 2018-02-14 16:21 - 001166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2018-05-31 10:09 - 2018-02-14 16:21 - 000124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2018-05-31 10:09 - 2018-02-14 16:21 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2018-05-31 10:07 - 2018-05-31 10:14 - 000000000 ____D C:\Users\yanka\AppData\Roaming\facebook-nativefier-f52d2f 2018-05-31 10:07 - 2018-05-31 10:07 - 005089366 _____ C:\Users\yanka\Downloads\nat32_2.2-Build-22270.zip 2018-05-31 10:07 - 2018-05-31 10:07 - 000004210 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1527750457 2018-05-31 10:07 - 2018-05-31 10:07 - 000001364 _____ C:\Users\yanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk 2018-05-31 10:07 - 2018-05-31 10:07 - 000000000 ____D C:\Users\yanka\AppData\Roaming\Opera Software 2018-05-31 10:07 - 2018-05-31 10:07 - 000000000 ____D C:\Users\yanka\AppData\Local\Opera Software 2018-05-31 10:07 - 2018-05-31 10:07 - 000000000 ____D C:\Program Files (x86)\Facebook ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2018-06-30 21:56 - 2018-05-16 17:35 - 000005246 _____ C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for DESKTOP-CPJ8TFE-yanka DESKTOP-CPJ8TFE 2018-06-30 21:55 - 2018-05-16 17:30 - 000000000 ____D C:\Users\yanka 2018-06-30 21:55 - 2018-04-12 02:38 - 000000000 ___HD C:\Program Files\WindowsApps 2018-06-30 21:55 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\AppReadiness 2018-06-30 21:55 - 2018-04-12 02:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2018-06-30 21:55 - 2018-04-11 19:10 - 000000000 ___RD C:\Users\yanka\OneDrive 2018-06-30 21:53 - 2018-05-16 17:28 - 000000000 ____D C:\WINDOWS\system32\SleepStudy 2018-06-30 21:39 - 2018-05-16 17:38 - 000838560 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2018-06-30 21:39 - 2018-04-12 02:36 - 000000000 ____D C:\WINDOWS\INF 2018-06-30 21:34 - 2018-05-16 17:35 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT 2018-06-30 21:34 - 2018-04-11 19:55 - 000000000 ____D C:\Program Files (x86)\TeamViewer 2018-06-29 21:10 - 2018-04-11 19:50 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe 2018-06-29 21:10 - 2018-04-11 19:50 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2018-06-29 11:00 - 2018-04-12 00:04 - 000524288 _____ C:\WINDOWS\system32\config\BBI 2018-06-28 16:43 - 2018-04-12 14:57 - 000007995 _____ C:\WINDOWS\BRRBCOM.INI 2018-06-28 12:31 - 2018-04-11 19:09 - 000000000 ____D C:\Users\yanka\AppData\Local\Packages 2018-06-27 12:10 - 2018-04-11 19:10 - 000131288 _____ (Microsoft Corporation) C:\WINDOWS\system32\osrss.dll 2018-06-22 14:59 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\LiveKernelReports 2018-06-22 14:38 - 2018-04-11 19:19 - 000000000 ____D C:\ProgramData\Package Cache 2018-06-21 17:05 - 2018-05-16 17:35 - 000003376 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3081403711-1452664787-965955870-1001 2018-06-21 17:05 - 2018-05-16 17:30 - 000002363 _____ C:\Users\yanka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2018-06-21 10:33 - 2018-04-12 12:49 - 000000000 ____D C:\Users\yanka\AppData\Roaming\BitComet 2018-06-21 09:44 - 2018-04-11 19:11 - 000000000 ____D C:\Program Files (x86)\Google 2018-06-21 09:40 - 2018-05-16 17:35 - 000004264 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update 2018-06-20 17:35 - 2018-04-12 15:50 - 001027728 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000463080 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000381584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000346664 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbloga.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000239680 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000229392 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000211160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000201328 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsha.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000197160 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000159640 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000111872 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000085968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000059592 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbuniva.sys 2018-06-20 17:35 - 2018-04-12 15:50 - 000046976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys 2018-06-20 17:35 - 2018-04-12 02:38 - 000000000 ___HD C:\WINDOWS\ELAMBKUP 2018-06-20 10:13 - 2018-04-12 12:49 - 000000853 _____ C:\Users\Public\Desktop\BitComet.lnk 2018-06-20 09:58 - 2018-04-12 14:20 - 000000000 ____D C:\Users\yanka\AppData\Local\Adobe 2018-06-15 03:11 - 2018-05-16 17:28 - 000493496 _____ C:\WINDOWS\system32\FNTCACHE.DAT 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\zu-ZA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\yo-NG 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\xh-ZA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\wo-SN 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\tn-ZA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\ti-ET 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\rw-RW 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\nso-ZA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\ig-NG 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA 2018-06-15 03:10 - 2018-04-12 12:19 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\TextInput 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\system32\oobe 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\system32\appraiser 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\ShellExperiences 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\WINDOWS\bcastdvr 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer 2018-06-15 03:10 - 2018-04-12 02:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2018-06-15 03:10 - 2018-04-12 00:04 - 000000000 ____D C:\WINDOWS\system32\Dism 2018-06-15 02:40 - 2018-04-11 19:50 - 000000000 ____D C:\WINDOWS\system32\MRT 2018-06-15 02:38 - 2018-04-12 02:30 - 000000000 ____D C:\WINDOWS\CbsTemp 2018-06-11 14:01 - 2018-04-12 14:28 - 000000000 ____D C:\Users\yanka\AppData\Local\PlaceholderTileLogoFolder 2018-06-06 02:29 - 2018-04-12 02:41 - 000835056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2018-06-06 02:29 - 2018-04-12 02:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2018-05-31 13:52 - 2018-04-17 15:06 - 000000000 ____D C:\Users\yanka\.B-Trust 2018-05-31 10:21 - 2018-05-11 11:43 - 000000000 ____D C:\Users\yanka\AppData\Local\ABBYY ==================== Files in the root of some directories ======= 2018-06-22 14:38 - 2018-06-22 14:38 - 000000260 _____ () C:\ProgramData\fontcacheev1.dat ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2018-05-16 17:28 ==================== End of FRST.txt ============================  
      Addition.txt
    • от MMM111
      Днес включих компютъра си и забелязах че снимки от десктопа ги няма. Някой бяха в кошчето другите напълно изтрити. Което ме втрещи , часът в който бяха изтрити. В момента на изтриването компютъра не е бил включен а и няма как някой от вкъщи да го включи защото има парола. След странната ситуация тръгнах да изключвам компютъра и ми се появи това съобщение : " Други хора са влезли на този компютър . Изключването на  WINDOWS може да им причини загуба на данни" 
      Някой ми влиза в компютъра? Извинявам се ако пускам темата в грешен раздел но ми трябва помощ. Какво значи това?
       
      Да добавя.
      - Изтриването е било в 6:30 сутринта а аз към 2 - 3 през нощта  приех обаждане от скайп по телефона. Възможно ли е от това обаждане този човек да се е домъкнал до личните ми данни
      - Вкъщи се използват 4 телефона които взимат интернет от едно wi fi , от компютъра. Възможно ли е заради това така да се е получило?
      Досега никога не ми се е случвало. Мисля че някой влиза. Имам нужда от отговор
    • от desperado88
      Здравейте, от няколко дена лаптопа ми започна да работи много бавно, Malwarebytes постоянно ми блокира Уебсайт, който аз не го отварям.Явно вируса кара системата автоматично да зарежда този уебсайт.След сканиране с Malwarebytes изчистих около 500 най различни вируса, сред които и Trojan.BitCoinMiner.За съжаление системата все още е инфектирана.Прилагам и снимка от Malwarebytes със блокирания уебсайт.
       
      Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14.03.2018
      Ran by Denis (administrator) on DENIS-PC (15-04-2018 13:26:58)
      Running from C:\Users\Denis\Desktop
      Loaded Profiles: Denis (Available Profiles: Denis)
      Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Английски (Съединени щати)
      Internet Explorer Version 11 (Default browser: Opera)
      Boot Mode: Normal
      Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
      ==================== Processes (Whitelisted) =================
      (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
      (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
      (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
      (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
      (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
      (SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCore64.exe
      (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
      (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaUI.exe
      (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry.exe
      (Ralink Technology, Corp.) C:\Program Files (x86)\Ralink\Common\RaRegistry64.exe
      (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
      (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
      (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
      (Intel Corporation) C:\Windows\System32\igfxEM.exe
      (Intel Corporation) C:\Windows\System32\igfxHK.exe
      (Intel Corporation) C:\Windows\System32\igfxTray.exe
      (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
      (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera_crashreporter.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Microsoft Corporation) C:\Windows\System32\wlanext.exe
      (Microsoft Corporation) C:\Windows\System32\wlanext.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Opera Software) C:\Program Files\Opera\52.0.2871.64\opera.exe
      (Microsoft Corporation) C:\Windows\System32\dllhost.exe
      (Microsoft Corporation) C:\Windows\System32\mobsync.exe
      ==================== Registry (Whitelisted) ===========================
      (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
      HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2818800 2014-09-17] (Synaptics Incorporated)
      HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-04-13] (AVAST Software)
      HKLM-x32\...\Run: [FxSound Enhancer] => C:\Program Files (x86)\DFX\dfx.exe [1663992 2017-06-25] ()
      HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
      HKU\S-1-5-21-2840518248-2148612227-1552303534-1000\...\Run: [FreeAC] => C:\Program Files (x86)\FreeAlarmClock\FreeAlarmClock.exe [3015072 2016-01-19] (Comfort Software Group)
      HKU\S-1-5-21-2840518248-2148612227-1552303534-1000\...\Run: [xACRX1n5Od.exe] => C:\Program Files\Windows Photo Viewer\ZYZV3IM54U2LXOJ32IAQ2X\xACRX1n5Od.exe 
      HKU\S-1-5-21-2840518248-2148612227-1552303534-1000\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [8887216 2018-03-22] (SUPERAntiSpyware)
      HKU\S-1-5-21-2840518248-2148612227-1552303534-1000\...\MountPoints2: {03fa777c-d793-11e7-aaf8-2c337a8d8b7c} - G:\Lenovo_Suite.exe
      HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> 
      Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk [2017-12-05]
      ShortcutTarget: Ralink Wireless Utility.lnk -> C:\Program Files (x86)\Ralink\Common\RaUI.exe (Ralink Technology, Corp.)
      GroupPolicy: Restriction - Chrome <==== ATTENTION
      ==================== Internet (Whitelisted) ====================
      (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
      Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
      Tcpip\Parameters: [DhcpNameServer] 192.168.50.1
      Tcpip\..\Interfaces\{268216B3-DCC9-4E85-BC1A-BE63B8E8A6F5}: [DhcpNameServer] 192.168.50.1
      Internet Explorer:
      ==================
      HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
      BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2018-04-01] (AVAST Software)
      BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2018-04-01] (AVAST Software)
      FireFox:
      ========
      FF DefaultProfile: du8cfbta.default
      FF ProfilePath: C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\du8cfbta.default [2018-04-15]
      FF user.js: detected! => C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\du8cfbta.default\user.js [2017-06-30]
      FF Homepage: Mozilla\Firefox\Profiles\du8cfbta.default -> hxxps://www.malwarebytes.org/restorebrowser/
      FF Extension: (Avast SafePrice) - C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\du8cfbta.default\Extensions\sp@avast.com.xpi [2018-04-04]
      FF Extension: (Avast Online Security) - C:\Users\Denis\AppData\Roaming\Mozilla\Firefox\Profiles\du8cfbta.default\Extensions\wrc@avast.com.xpi [2018-04-01]
      FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
      FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
      FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
      FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [No File]
      FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [No File]
      FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)
      Chrome: 
      =======
      CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
      CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
      Opera: 
      =======
      OPR Extension: (Adblocker for Youtube™) - C:\Users\Denis\AppData\Roaming\Opera Software\Opera Stable\Extensions\epeomjakeffkfofnidikcpbacmfliolc [2018-04-01]
      ==================== Services (Whitelisted) ====================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-01-31] (SUPERAntiSpyware.com)
      S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7603408 2018-04-13] (AVAST Software)
      R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [313640 2018-04-13] (AVAST Software)
      R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
      R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6479136 2018-03-27] (Malwarebytes)
      S3 RaMediaServer; C:\Program Files (x86)\Ralink\Common\RaMediaServer.exe [621632 2011-03-04] ()
      R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [291032 2014-08-18] (Realtek Semiconductor)
      R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [191728 2014-09-17] (Synaptics Incorporated)
      R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-08-16] (Microsoft Corporation)
      S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
      S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
      ===================== Drivers (Whitelisted) ======================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
      S3 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [196640 2018-04-13] (AVAST Software)
      S3 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [227504 2018-04-01] (AVAST Software)
      S3 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199440 2018-04-01] (AVAST Software)
      S3 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343752 2018-04-01] (AVAST Software)
      S3 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57680 2018-04-01] (AVAST Software)
      R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [227784 2018-04-13] (AVAST Software)
      S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46968 2018-04-13] (AVAST Software)
      R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [147224 2018-04-13] (AVAST Software)
      S3 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [111352 2018-04-13] (AVAST Software)
      R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84368 2018-04-13] (AVAST Software)
      S3 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1026696 2018-04-13] (AVAST Software)
      R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [460520 2018-04-13] (AVAST Software)
      S3 aswStm; C:\Windows\System32\drivers\aswStm.sys [205976 2018-04-13] (AVAST Software)
      S3 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [380528 2018-04-13] (AVAST Software)
      R1 butldsk; C:\Windows\System32\drivers\butldsk.sys [192408 2018-03-21] ()
      S3 DFX11_1; C:\Windows\System32\drivers\dfx11_1x64.sys [28008 2017-06-19] (Windows (R) Win 7 DDK provider)
      R3 DFX12; C:\Windows\System32\drivers\dfx12x64.sys [29688 2017-06-19] (Windows (R) Win 7 DDK provider)
      R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253664 2018-04-01] (Malwarebytes)
      R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [294104 2014-08-19] (Realtek Semiconductor Corp.)
      R3 RTWlanE; C:\Windows\System32\DRIVERS\rtwlane.sys [3502296 2014-08-04] (Realtek Semiconductor Corporation )
      R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
      R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
      R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [33008 2014-09-17] (Synaptics Incorporated)
      R3 TXEIx64; C:\Windows\System32\DRIVERS\TXEIx64.sys [97320 2015-05-28] (Intel Corporation)
      U3 aswbdisk; no ImagePath
      S3 VGPU; System32\drivers\rdvgkmd.sys [X]
      ==================== NetSvcs (Whitelisted) ===================
      (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

      ==================== One Month Created files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-04-15 13:26 - 2018-04-15 13:27 - 000011629 _____ C:\Users\Denis\Desktop\FRST.txt
      2018-04-14 21:08 - 2018-04-14 21:25 - 000000064 _____ C:\Users\Denis\Desktop\rufus.ini
      2018-04-14 21:06 - 2018-04-14 21:08 - 000967800 _____ (Akeo Consulting (hxxp://akeo.ie)) C:\Users\Denis\Desktop\rufus-2.18p.exe
      2018-04-13 07:28 - 2018-04-13 07:28 - 000000000 ____D C:\Windows\System32\Tasks\Avast Software
      2018-04-13 07:27 - 2018-04-13 07:26 - 000376536 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
      2018-04-12 22:49 - 2018-03-14 20:14 - 000135360 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
      2018-04-12 22:49 - 2018-03-14 20:09 - 000656384 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
      2018-04-12 22:49 - 2018-03-14 16:05 - 001993728 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
      2018-04-12 22:49 - 2018-03-14 16:05 - 001559552 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
      2018-04-12 22:49 - 2018-03-14 16:05 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
      2018-04-12 22:49 - 2018-03-14 16:05 - 000599552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
      2018-04-12 22:49 - 2018-03-14 16:05 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
      2018-04-12 22:49 - 2018-03-14 16:05 - 000414720 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
      2018-04-12 22:49 - 2018-03-14 16:05 - 000291840 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
      2018-04-12 22:49 - 2018-03-14 16:05 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
      2018-04-11 10:53 - 2018-04-11 10:53 - 000000000 ____D C:\Users\Denis\Downloads\Turkce
      2018-04-11 10:52 - 2018-04-11 11:52 - 000000000 ____D C:\Users\Denis\Downloads\Нова папка (2)
      2018-04-08 16:31 - 2018-04-15 13:26 - 000000000 ____D C:\FRST
      2018-04-08 16:28 - 2018-04-08 16:28 - 002403328 _____ (Farbar) C:\Users\Denis\Desktop\FRST64.exe
      2018-04-02 16:51 - 2018-03-09 06:39 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
      2018-04-02 16:51 - 2018-03-09 06:06 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
      2018-04-02 16:51 - 2018-03-09 06:06 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
      2018-04-02 16:51 - 2018-03-09 05:47 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
      2018-04-02 16:51 - 2018-03-09 05:43 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
      2018-04-02 16:51 - 2018-03-09 05:38 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
      2018-04-02 16:51 - 2018-03-09 05:38 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
      2018-04-02 16:51 - 2018-03-09 05:37 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
      2018-04-02 16:51 - 2018-03-09 05:34 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
      2018-04-02 16:51 - 2018-03-09 05:33 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
      2018-04-02 16:51 - 2018-03-09 05:31 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
      2018-04-02 16:51 - 2018-03-09 05:30 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
      2018-04-02 16:51 - 2018-03-09 05:29 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
      2018-04-02 16:51 - 2018-03-09 05:29 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
      2018-04-02 16:51 - 2018-03-09 05:26 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
      2018-04-02 16:51 - 2018-03-09 05:22 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
      2018-04-02 16:51 - 2018-03-09 05:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
      2018-04-02 16:51 - 2018-03-09 05:22 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
      2018-04-02 16:50 - 2018-03-28 11:31 - 005583040 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
      2018-04-02 16:50 - 2018-03-28 11:09 - 004046016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
      2018-04-02 16:50 - 2018-03-28 11:09 - 004026048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
      2018-04-02 16:50 - 2018-03-09 06:39 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
      2018-04-02 16:50 - 2018-03-09 06:39 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
      2018-04-02 16:50 - 2018-03-09 06:39 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
      2018-04-02 16:50 - 2018-03-09 06:18 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
      2018-04-02 16:50 - 2018-03-09 06:09 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 001461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 06:06 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:43 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:38 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
      2018-04-02 16:50 - 2018-03-09 05:34 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
      2018-04-02 16:50 - 2018-03-09 05:30 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
      2018-04-02 16:50 - 2018-03-09 05:22 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
      2018-04-02 16:50 - 2018-03-09 05:22 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
      2018-04-02 16:50 - 2018-03-09 05:21 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:21 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:21 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
      2018-04-02 16:50 - 2018-03-09 05:21 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
      2018-04-02 16:50 - 2018-02-19 00:34 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
      2018-04-01 14:11 - 2018-04-01 14:11 - 000000000 ____D C:\Users\Denis\AppData\Local\AVAST Software
      2018-04-01 12:40 - 2018-02-10 11:44 - 025740288 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
      2018-04-01 12:40 - 2018-02-10 10:29 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
      2018-04-01 12:40 - 2018-02-10 10:17 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
      2018-04-01 12:40 - 2018-02-10 10:17 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
      2018-04-01 12:40 - 2018-02-10 10:16 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
      2018-04-01 12:40 - 2018-02-10 10:10 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
      2018-04-01 12:40 - 2018-02-10 10:09 - 005782016 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
      2018-04-01 12:40 - 2018-02-10 10:07 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
      2018-04-01 12:40 - 2018-02-10 10:06 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
      2018-04-01 12:40 - 2018-02-10 10:06 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
      2018-04-01 12:40 - 2018-02-10 10:01 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
      2018-04-01 12:40 - 2018-02-10 09:52 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
      2018-04-01 12:40 - 2018-02-10 09:48 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
      2018-04-01 12:40 - 2018-02-10 09:33 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
      2018-04-01 12:40 - 2018-02-10 09:27 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
      2018-04-01 12:40 - 2018-02-10 09:20 - 020274176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
      2018-04-01 12:40 - 2018-02-10 08:57 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
      2018-04-01 12:40 - 2018-02-10 08:57 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
      2018-04-01 12:40 - 2018-02-10 08:56 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
      2018-04-01 12:40 - 2018-02-10 08:52 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
      2018-04-01 12:40 - 2018-02-10 08:50 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
      2018-04-01 12:40 - 2018-02-10 08:49 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
      2018-04-01 12:40 - 2018-02-10 08:49 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
      2018-04-01 12:40 - 2018-02-10 08:35 - 004498944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
      2018-04-01 12:40 - 2018-02-10 08:35 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
      2018-04-01 12:40 - 2018-02-10 08:27 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
      2018-04-01 12:40 - 2018-02-10 08:26 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
      2018-04-01 12:40 - 2018-02-10 08:14 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
      2018-04-01 12:40 - 2018-02-10 08:08 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
      2018-04-01 12:39 - 2018-02-10 22:52 - 000395928 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
      2018-04-01 12:39 - 2018-02-10 22:03 - 000347296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
      2018-04-01 12:39 - 2018-02-10 10:30 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
      2018-04-01 12:39 - 2018-02-10 10:19 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
      2018-04-01 12:39 - 2018-02-10 10:16 - 000577536 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
      2018-04-01 12:39 - 2018-02-10 10:10 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
      2018-04-01 12:39 - 2018-02-10 10:06 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
      2018-04-01 12:39 - 2018-02-10 10:06 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
      2018-04-01 12:39 - 2018-02-10 09:58 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
      2018-04-01 12:39 - 2018-02-10 09:52 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
      2018-04-01 12:39 - 2018-02-10 09:51 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
      2018-04-01 12:39 - 2018-02-10 09:49 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
      2018-04-01 12:39 - 2018-02-10 09:46 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
      2018-04-01 12:39 - 2018-02-10 09:45 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
      2018-04-01 12:39 - 2018-02-10 09:36 - 015283712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
      2018-04-01 12:39 - 2018-02-10 09:36 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
      2018-04-01 12:39 - 2018-02-10 09:34 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
      2018-04-01 12:39 - 2018-02-10 09:34 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
      2018-04-01 12:39 - 2018-02-10 09:32 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
      2018-04-01 12:39 - 2018-02-10 09:14 - 001546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
      2018-04-01 12:39 - 2018-02-10 09:08 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
      2018-04-01 12:39 - 2018-02-10 09:02 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
      2018-04-01 12:39 - 2018-02-10 08:54 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
      2018-04-01 12:39 - 2018-02-10 08:51 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
      2018-04-01 12:39 - 2018-02-10 08:49 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
      2018-04-01 12:39 - 2018-02-10 08:42 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
      2018-04-01 12:39 - 2018-02-10 08:39 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
      2018-04-01 12:39 - 2018-02-10 08:38 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
      2018-04-01 12:39 - 2018-02-10 08:38 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
      2018-04-01 12:39 - 2018-02-10 08:36 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
      2018-04-01 12:39 - 2018-02-10 08:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
      2018-04-01 12:39 - 2018-02-10 08:34 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
      2018-04-01 12:39 - 2018-02-10 08:33 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
      2018-04-01 12:39 - 2018-02-10 08:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
      2018-04-01 12:39 - 2018-02-10 08:27 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
      2018-04-01 12:39 - 2018-02-10 08:10 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
      2018-04-01 12:39 - 2018-01-12 19:44 - 001894120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
      2018-04-01 12:39 - 2018-01-12 19:27 - 004834816 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
      2018-04-01 12:39 - 2018-01-12 19:16 - 003405824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
      2018-04-01 12:39 - 2018-01-11 19:09 - 003224064 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
      2018-04-01 12:39 - 2018-01-05 19:25 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
      2018-04-01 12:39 - 2018-01-05 19:14 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
      2018-04-01 12:39 - 2018-01-01 05:21 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
      2018-04-01 12:39 - 2018-01-01 05:21 - 000948968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
      2018-04-01 12:39 - 2018-01-01 05:21 - 000288488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
      2018-04-01 12:39 - 2018-01-01 05:18 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 002066432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 001741312 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 001361408 _____ (Microsoft Corporation) C:\Windows\system32\PeerDistSvc.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 001110528 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000977408 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000863232 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
      2018-04-01 12:39 - 2018-01-01 05:18 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000705024 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
      2018-04-01 12:39 - 2018-01-01 05:18 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000439296 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000366592 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
      2018-04-01 12:39 - 2018-01-01 05:18 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
      2018-04-01 12:39 - 2018-01-01 05:04 - 000559616 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
      2018-04-01 12:39 - 2018-01-01 05:00 - 012880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
      2018-04-01 12:39 - 2018-01-01 05:00 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
      2018-04-01 12:39 - 2018-01-01 05:00 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
      2018-04-01 12:39 - 2018-01-01 05:00 - 001390080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
      2018-04-01 12:39 - 2018-01-01 05:00 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
      2018-04-01 12:39 - 2018-01-01 05:00 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
      2018-04-01 12:39 - 2018-01-01 05:00 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
      2018-04-01 12:39 - 2018-01-01 05:00 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
      2018-04-01 12:39 - 2018-01-01 05:00 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
      2018-04-01 12:39 - 2018-01-01 04:59 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
      2018-04-01 12:39 - 2018-01-01 04:50 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
      2018-04-01 12:39 - 2018-01-01 04:42 - 000460288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
      2018-04-01 12:39 - 2018-01-01 04:42 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
      2018-04-01 12:39 - 2018-01-01 04:41 - 000754176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
      2018-04-01 12:39 - 2017-12-05 20:36 - 001484288 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
      2018-04-01 12:39 - 2017-12-05 20:36 - 000218112 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
      2018-04-01 12:39 - 2017-12-05 20:08 - 001176576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
      2018-04-01 12:39 - 2017-12-05 19:04 - 000404992 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
      2018-04-01 12:38 - 2018-02-10 10:17 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
      2018-04-01 12:38 - 2018-02-10 08:57 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
      2018-04-01 12:38 - 2018-02-10 08:57 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
      2018-04-01 12:38 - 2018-01-12 19:44 - 000377064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
      2018-04-01 12:38 - 2018-01-12 19:44 - 000371432 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
      2018-04-01 12:38 - 2018-01-12 19:44 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
      2018-04-01 12:38 - 2018-01-12 19:40 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
      2018-04-01 12:38 - 2018-01-12 19:26 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
      2018-04-01 12:38 - 2018-01-12 19:16 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
      2018-04-01 12:38 - 2018-01-12 19:16 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
      2018-04-01 12:38 - 2018-01-12 19:15 - 000032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
      2018-04-01 12:38 - 2018-01-11 19:41 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
      2018-04-01 12:38 - 2018-01-11 19:22 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
      2018-04-01 12:38 - 2018-01-05 19:31 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
      2018-04-01 12:38 - 2018-01-05 19:31 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
      2018-04-01 12:38 - 2018-01-05 19:30 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
      2018-04-01 12:38 - 2018-01-05 19:30 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
      2018-04-01 12:38 - 2018-01-05 19:30 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
      2018-04-01 12:38 - 2018-01-05 19:11 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
      2018-04-01 12:38 - 2018-01-05 19:11 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
      2018-04-01 12:38 - 2018-01-05 19:11 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
      2018-04-01 12:38 - 2018-01-05 19:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
      2018-04-01 12:38 - 2018-01-05 18:50 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
      2018-04-01 12:38 - 2018-01-01 05:21 - 000213736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
      2018-04-01 12:38 - 2018-01-01 05:21 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
      2018-04-01 12:38 - 2018-01-01 05:18 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
      2018-04-01 12:38 - 2018-01-01 05:18 - 000264704 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000181760 _____ (Microsoft Corporation) C:\Windows\system32\PeerDist.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\PeerDistWSDDiscoProv.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
      2018-04-01 12:38 - 2018-01-01 05:18 - 000053760 _____ (Microsoft Corporation) C:\Windows\system32\vmicres.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000051200 _____ (Microsoft Corporation) C:\Windows\system32\PeerDistHttpTrans.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
      2018-04-01 12:38 - 2018-01-01 05:18 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
      2018-04-01 12:38 - 2018-01-01 05:18 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000304640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
      2018-04-01 12:38 - 2018-01-01 05:00 - 000139776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PeerDist.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
      2018-04-01 12:38 - 2018-01-01 05:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\traffic.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
      2018-04-01 12:38 - 2018-01-01 05:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
      2018-04-01 12:38 - 2018-01-01 04:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
      2018-04-01 12:38 - 2018-01-01 04:55 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
      2018-04-01 12:38 - 2018-01-01 04:55 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
      2018-04-01 12:38 - 2018-01-01 04:55 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
      2018-04-01 12:38 - 2018-01-01 04:55 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
      2018-04-01 12:38 - 2018-01-01 04:55 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
      2018-04-01 12:38 - 2018-01-01 04:54 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
      2018-04-01 12:38 - 2018-01-01 04:47 - 000244224 _____ (Microsoft Corporation) C:\Windows\system32\vmicsvc.exe
      2018-04-01 12:38 - 2018-01-01 04:46 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\IcCoinstall.dll
      2018-04-01 12:38 - 2018-01-01 04:46 - 000051712 _____ (Microsoft Corporation) C:\Windows\system32\vmictimeprovider.dll
      2018-04-01 12:38 - 2018-01-01 04:43 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
      2018-04-01 12:38 - 2018-01-01 04:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
      2018-04-01 12:38 - 2018-01-01 04:43 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
      2018-04-01 12:38 - 2018-01-01 04:43 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
      2018-04-01 12:38 - 2018-01-01 04:43 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapPeerProxy.dll
      2018-04-01 12:38 - 2018-01-01 04:43 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapAuthProxy.dll
      2018-04-01 12:38 - 2018-01-01 04:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
      2018-04-01 12:38 - 2018-01-01 04:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshqos.dll
      2018-04-01 12:38 - 2018-01-01 04:42 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
      2018-04-01 12:38 - 2018-01-01 04:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
      2018-04-01 12:38 - 2018-01-01 04:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
      2018-04-01 12:38 - 2017-12-05 20:36 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
      2018-04-01 12:38 - 2017-12-05 20:36 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
      2018-04-01 12:38 - 2017-12-05 20:36 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
      2018-04-01 12:38 - 2017-12-05 20:36 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
      2018-04-01 12:38 - 2017-12-05 20:36 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
      2018-04-01 12:38 - 2017-12-05 20:36 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
      2018-04-01 12:38 - 2017-12-05 20:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
      2018-04-01 12:38 - 2017-12-05 20:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
      2018-04-01 12:38 - 2017-12-05 20:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
      2018-04-01 12:38 - 2017-12-05 20:08 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
      2018-04-01 12:38 - 2017-12-05 20:08 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
      2018-04-01 12:38 - 2017-12-05 20:08 - 000135168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
      2018-04-01 12:38 - 2017-12-05 20:08 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
      2018-04-01 12:38 - 2017-12-05 18:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
      2018-04-01 12:30 - 2018-04-01 12:30 - 000000000 ____D C:\Users\Denis\AppData\Roaming\AVAST Software
      2018-04-01 12:28 - 2018-04-01 12:28 - 000001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
      2018-04-01 12:28 - 2018-04-01 12:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
      2018-04-01 12:26 - 2018-04-13 07:28 - 000003910 _____ C:\Windows\System32\Tasks\Avast Emergency Update
      2018-04-01 12:25 - 2018-04-13 07:28 - 000147224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 001026696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 000460520 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 000380528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 000227784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 000205976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 000196640 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 000111352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 000084368 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
      2018-04-01 12:25 - 2018-04-13 07:26 - 000046968 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
      2018-04-01 12:25 - 2018-04-01 12:21 - 000343752 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
      2018-04-01 12:25 - 2018-04-01 12:21 - 000227504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
      2018-04-01 12:25 - 2018-04-01 12:21 - 000199440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
      2018-04-01 12:25 - 2018-04-01 12:21 - 000057680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
      2018-04-01 12:23 - 2018-04-01 12:23 - 000000000 ____D C:\Program Files\Common Files\AVAST Software
      2018-04-01 11:45 - 2018-04-13 03:45 - 000000510 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 91abd3e0-5990-4aa4-ba5f-3e0e60b47fa2.job
      2018-04-01 11:45 - 2018-04-13 02:00 - 000000510 _____ C:\Windows\Tasks\SUPERAntiSpyware Scheduled Task 2636bd95-9cca-4d29-aa0d-132b9a2981d6.job
      2018-04-01 11:45 - 2018-04-01 11:45 - 000003584 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 2636bd95-9cca-4d29-aa0d-132b9a2981d6
      2018-04-01 11:45 - 2018-04-01 11:45 - 000003510 _____ C:\Windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 91abd3e0-5990-4aa4-ba5f-3e0e60b47fa2
      2018-04-01 11:45 - 2018-04-01 11:45 - 000001808 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Professional.lnk
      2018-04-01 11:45 - 2018-04-01 11:45 - 000000000 ____D C:\Users\Denis\AppData\Roaming\SUPERAntiSpyware.com
      2018-04-01 11:45 - 2018-04-01 11:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
      2018-04-01 11:44 - 2018-04-06 16:04 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
      2018-04-01 11:44 - 2018-04-01 11:44 - 000000000 ____D C:\ProgramData\SUPERAntiSpyware.com
      2018-04-01 11:42 - 2018-04-01 11:44 - 032580552 _____ (SUPERAntiSpyware) C:\Users\Denis\Desktop\SUPERAntiSpywarePro.exe
      2018-04-01 11:38 - 2018-04-01 11:38 - 000000000 ____D C:\Windows\system32\appmgmt
      2018-04-01 11:31 - 2018-04-01 11:31 - 000000000 ____D C:\Users\Denis\AppData\Local\Chromium
      2018-04-01 11:03 - 2018-04-01 11:03 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
      2018-04-01 11:03 - 2018-04-01 11:03 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
      2018-04-01 11:03 - 2018-04-01 11:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
      2018-04-01 11:02 - 2018-03-19 12:57 - 000076192 _____ C:\Windows\system32\Drivers\mbae64.sys
      2018-04-01 11:00 - 2018-04-01 11:00 - 000000000 ____D C:\ProgramData\Malwarebytes
      2018-04-01 11:00 - 2018-04-01 11:00 - 000000000 ____D C:\Program Files\Malwarebytes
      2018-04-01 10:58 - 2018-04-01 10:58 - 000000000 ____D C:\Program Files\5TK02URXOS
      2018-04-01 10:56 - 2018-04-01 11:34 - 000000000 ____D C:\Users\Denis\AppData\Roaming\w1ue4fa2w2e
      2018-04-01 10:55 - 2018-04-01 11:34 - 000000000 ____D C:\Users\Denis\AppData\Roaming\udvovefa0ze
      2018-04-01 10:55 - 2018-04-01 11:34 - 000000000 ____D C:\Users\Denis\AppData\Roaming\h2g3qje1ew5
      2018-04-01 10:55 - 2018-04-01 10:57 - 000000000 ____D C:\Program Files\VS2P538RN4
      2018-04-01 10:51 - 2018-04-01 10:51 - 000000290 __RSH C:\Users\Denis\ntuser.pol
      2018-04-01 10:48 - 2018-04-07 14:06 - 000000000 ____D C:\ProgramData\10b45edb-3473-4b10-b57e-0ad402f4c858
      2018-04-01 10:46 - 2018-04-01 11:34 - 000000000 ____D C:\Users\Denis\AppData\Roaming\yoasfgt1ylr
      2018-04-01 10:46 - 2018-04-01 10:46 - 000000000 ____D C:\Program Files\JC60L5XO5O
      2018-04-01 10:46 - 2018-04-01 10:46 - 000000000 ____D C:\Program Files\7JP1TF3RPR
      2018-04-01 10:45 - 2018-04-01 11:34 - 000000000 ____D C:\Users\Denis\AppData\Roaming\qzoaexvthyw
      2018-04-01 10:45 - 2018-04-01 11:34 - 000000000 ____D C:\Users\Denis\AppData\Roaming\l4vhnklvv4b
      2018-04-01 10:42 - 2018-04-01 10:42 - 000000000 ____D C:\Users\Denis\AppData\Roaming\4fypyupwbhn
      2018-04-01 10:41 - 2018-04-07 14:05 - 000000000 ____D C:\Browse
      2018-04-01 10:41 - 2018-04-01 11:33 - 000000000 ____D C:\Applications
      2018-04-01 10:41 - 2018-04-01 10:41 - 000000000 ____D C:\Winsys
      2018-04-01 10:40 - 2018-04-01 11:10 - 000000000 ____D C:\Program Files (x86)\Sikimi
      2018-04-01 10:40 - 2018-04-01 10:40 - 000000000 ____D C:\Program Files\My Program
      2018-04-01 10:38 - 2018-04-01 11:10 - 000000000 ____D C:\Users\Denis\AppData\Local\GenericTools
      2018-04-01 10:38 - 2018-04-01 10:38 - 001986226 _____ C:\Users\Denis\AppData\Local\Inis.tst
      2018-04-01 10:37 - 2018-04-01 11:04 - 000929792 _____ C:\Users\Denis\AppData\Local\sham.db
      2018-04-01 10:37 - 2018-04-01 10:37 - 000140800 _____ C:\Users\Denis\AppData\Local\installer.dat
      2018-04-01 10:36 - 2018-04-01 15:43 - 000000000 ____D C:\ProgramData\AVAST Software
      2018-04-01 10:36 - 2018-04-01 10:36 - 000000000 ____D C:\Program Files\AVAST Software
      2018-03-31 17:51 - 2018-04-11 07:29 - 000000000 ____D C:\Users\Denis\Downloads\BangBros18 - Emma Hix - Blonde Makes Juan Fuck Her Hard
      2018-03-31 17:51 - 2018-03-31 17:51 - 000000000 ____D C:\Users\Denis\Downloads\VW Golf 4 (1997+)
      2018-03-25 20:22 - 2018-03-25 20:24 - 000000000 ____D C:\Users\Denis\Desktop\gh
      2018-03-24 00:04 - 2018-03-24 00:04 - 000043872 _____ (Connectify) C:\Windows\system32\Drivers\cnnctfy3.sys
      2018-03-24 00:04 - 2018-03-24 00:04 - 000036736 _____ (Connectify) C:\Windows\system32\Drivers\cfywlan1.sys
      2018-03-24 00:01 - 2018-03-24 00:02 - 016026232 _____ (Connectify) C:\Users\Denis\Desktop\Connectify2018Installer.exe
      2018-03-21 11:38 - 2018-03-21 11:38 - 000192408 _____ C:\Windows\system32\Drivers\butldsk.sys
      ==================== One Month Modified files and folders ========
      (If an entry is included in the fixlist, the file/folder will be moved.)
      2018-04-15 13:26 - 2018-01-12 17:39 - 000000000 ____D C:\Users\Denis\AppData\Roaming\AIMP
      2018-04-15 10:43 - 2009-07-14 07:45 - 000021280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
      2018-04-15 10:43 - 2009-07-14 07:45 - 000021280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
      2018-04-15 10:35 - 2017-12-06 14:35 - 000000000 __SHD C:\Users\Denis\IntelGraphicsProfiles
      2018-04-15 10:35 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
      2018-04-14 21:31 - 2017-12-02 22:27 - 000003834 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1512242838
      2018-04-14 21:31 - 2017-12-02 22:24 - 000000000 ____D C:\Program Files\Opera
      2018-04-14 21:25 - 2017-12-02 23:41 - 000004738 __RSH C:\ProgramData\ntuser.pol
      2018-04-14 21:07 - 2009-07-14 08:13 - 000781790 _____ C:\Windows\system32\PerfStringBackup.INI
      2018-04-14 21:07 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
      2018-04-13 03:22 - 2017-12-07 12:43 - 000000000 ____D C:\Windows\system32\appraiser
      2018-04-13 03:06 - 2017-12-07 15:19 - 000000000 ____D C:\Windows\system32\MRT
      2018-04-13 03:01 - 2017-12-07 15:19 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
      2018-04-13 03:01 - 2017-12-02 20:46 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
      2018-04-11 10:53 - 2017-12-11 23:51 - 000000000 ____D C:\Users\Denis\Downloads\new
      2018-04-10 18:05 - 2018-01-21 13:58 - 000804864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
      2018-04-10 18:05 - 2018-01-21 13:58 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
      2018-04-10 18:05 - 2018-01-21 13:58 - 000004474 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
      2018-04-10 18:05 - 2018-01-21 13:58 - 000004324 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
      2018-04-10 18:05 - 2018-01-21 13:58 - 000000000 ____D C:\Windows\SysWOW64\Macromed
      2018-04-10 18:05 - 2018-01-21 13:58 - 000000000 ____D C:\Windows\system32\Macromed
      2018-04-10 18:01 - 2018-03-01 14:27 - 000000000 ___HD C:\Users\Denis\Desktop\.picasaoriginals
      2018-04-07 15:10 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\rescache
      2018-04-07 10:30 - 2017-12-28 15:27 - 000000000 ____D C:\Users\Denis\AppData\Roaming\EurekaLog
      2018-04-06 23:02 - 2017-12-02 22:26 - 000000000 ____D C:\Users\Denis\AppData\Roaming\uTorrent
      2018-04-06 18:40 - 2017-12-25 17:35 - 000000000 ____D C:\Users\Denis\AppData\LocalLow\Mozilla
      2018-04-06 18:32 - 2017-12-25 17:34 - 000000000 ____D C:\Program Files\Mozilla Firefox
      2018-04-02 16:28 - 2009-07-14 07:45 - 000268392 _____ C:\Windows\system32\FNTCACHE.DAT
      2018-04-01 16:05 - 2017-12-07 11:14 - 000774404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
      2018-04-01 11:32 - 2017-12-02 20:48 - 000001393 _____ C:\Users\Denis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
      2018-04-01 11:23 - 2017-12-28 15:53 - 000000000 ____D C:\ProgramData\Ashampoo
      2018-04-01 10:51 - 2017-12-02 20:47 - 000000000 ____D C:\Users\Denis
      2018-04-01 10:46 - 2009-07-14 06:20 - 000000000 ___HD C:\Windows\system32\GroupPolicy
      2018-04-01 10:39 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files\Windows Photo Viewer
      2018-04-01 10:38 - 2017-12-27 16:26 - 000000000 ____D C:\Program Files (x86)\Google
      ==================== Files in the root of some directories =======
      2018-04-01 10:38 - 2018-04-01 10:38 - 001986226 _____ () C:\Users\Denis\AppData\Local\Inis.tst
      2018-04-01 10:37 - 2018-04-01 10:37 - 000140800 _____ () C:\Users\Denis\AppData\Local\installer.dat
      2018-04-01 10:37 - 2018-04-01 11:04 - 000929792 _____ () C:\Users\Denis\AppData\Local\sham.db
      Some files in TEMP:
      ====================
      2017-10-24 03:51 - 2017-10-24 03:51 - 000164424 _____ (Microsoft Corporation) C:\Users\Denis\AppData\Local\Temp\atl110.dll
      2015-09-22 20:06 - 2015-09-22 20:06 - 002382216 _____ (Mooii) C:\Users\Denis\AppData\Local\Temp\GoogleSetup.exe
      2017-10-24 03:51 - 2017-10-24 03:51 - 000069632 _____ () C:\Users\Denis\AppData\Local\Temp\HwInfo.dll
      2016-10-07 06:26 - 2016-10-07 06:26 - 000270336 _____ () C:\Users\Denis\AppData\Local\Temp\NSISPromotionEx.dll
      2018-04-01 10:41 - 2018-04-01 10:52 - 048475773 _____ (My Company, Inc.                                            ) C:\Users\Denis\AppData\Local\Temp\setupsb.exe
      2017-12-03 00:07 - 2017-08-29 03:30 - 000070656 _____ () C:\Users\Denis\AppData\Local\Temp\ShellHook.dll
      ==================== Bamital & volsnap ======================
      (There is no automatic fix for files that do not pass verification.)
      C:\Windows\system32\winlogon.exe => File is digitally signed
      C:\Windows\system32\wininit.exe => File is digitally signed
      C:\Windows\SysWOW64\wininit.exe => File is digitally signed
      C:\Windows\explorer.exe => File is digitally signed
      C:\Windows\SysWOW64\explorer.exe => File is digitally signed
      C:\Windows\system32\svchost.exe => File is digitally signed
      C:\Windows\SysWOW64\svchost.exe => File is digitally signed
      C:\Windows\system32\services.exe => File is digitally signed
      C:\Windows\system32\User32.dll => File is digitally signed
      C:\Windows\SysWOW64\User32.dll => File is digitally signed
      C:\Windows\system32\userinit.exe => File is digitally signed
      C:\Windows\SysWOW64\userinit.exe => File is digitally signed
      C:\Windows\system32\rpcss.dll => File is digitally signed
      C:\Windows\system32\dnsapi.dll => File is digitally signed
      C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
      C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
      LastRegBack: 2018-04-15 11:30
      ==================== End of FRST.txt ============================

      Addition.txt
  • Дарение

×

Информация

Поставихме бисквитки на устройството ви за най-добро потребителско изживяване. Можете да промените настройките си за бисквитки, или в противен случай приемаме, че сте съгласни с нашите условия за ползване.