Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu, nejspíše nějaký RAT nebo něco takového

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Feroxik
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 22 srp 2017 13:29

Prosím o kontrolu, nejspíše nějaký RAT nebo něco takového

#1 Příspěvek od Feroxik »

Dobrý den, mám problém s nějakým spywarem, RATem, nebo něco co mi útočník dal do počítače.
Taky mám nějak podezřele moc svchost.exe procesů v správci úloh - screen: https://imgur.com/a/E0KIf
První nějaké podezření jsem měl když se mi začali měnit jména na různých účtech. Potom když se mi sám od sebe odebral mobilní autentifikátor ze Steamu, tak jsem začal trochu více zabezpečovat PC.
Tyto problémy trvají cca tři dny, včera jsem měl už trochu strach, tak jsem nainstalovat různé doporučené antimalwary, antispywary atd.
Jedinou věc co mi našel SpyEmergency tak to byl nějaký malware ve skypu appdata/roaming/skype/maxmilian04/httpfe/cookies.dat.
Pak jsem našel aplikaci RKill, která má nějak detekovat malwary, ale taky nic nenašla, jediné co se našlo tak to bylo:
"[HKLM\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware" = dword:00000001"
Potom jsem to manuálně v registrech zapnul, tak že jsem předělal číslo na nulu.
Dneska ráno jsem se ještě díval na nastavení defenderu, a byl vypnutý firewall v privátní a veřejné síti, tak jsem ho zapnul a sám od sebe se vypíná.
Když se podíváte do nastavení v defenderu, kliknete na firewall, a tam máte veřejná(nezjistitelná) síť. Když na to kliknete tak tam se mi vypíná firewall, a taky nejde zapout blokování všech příchozích připojení, jak u privatní, tak i u veřejné sítě.
Přikládám log z RSIT.



Logfile of random's system information tool 1.16 (written by random/random)
Run by Ferox at 2017-08-22 14:50:31
Microsoft Windows 10 Pro
System drive C: has 16 GB (14%) free of 114 GB
Total RAM: 12236 MB (59% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:50:34, on 22.08.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.15063.0000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files (x86)\SpyShelter Firewall\SpyShelter.exe
C:\Program Files (x86)\Steam\Steam.exe
C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\ASUS\GPU TweakII\Monitor.exe
C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyWow64.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
C:\Program Files\trend micro\Ferox_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Discord] C:\ProgramData\SquirrelMachineInstalls\Discord.exe --checkInstall
O4 - HKLM\..\Run: [zenvpn] C:\Program Files (x86)\ZenVPN OpenVPN bundle\bin\zenvpn.exe
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Ferox\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Discord] C:\Users\Ferox\AppData\Local\Discord\app-0.0.298\Discord.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Users\Ferox\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_00171127CFADF2F8E5D7DA00AA0FBFC4] "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
O4 - HKCU\..\Run: [SpyShelter] C:\Program Files (x86)\SpyShelter Firewall\SpyShelter.exe
O4 - HKCU\..\Run: [SpyEmergency] C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O20 - AppInit_DLLs: C:\PROGRA~2\KEYCRY~1\KE50FD~1.DLL
O23 - Service: Služba Acronis Scheduler2 (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Avira Phantom VPN (AviraPhantomVPN) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\Windows\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\Windows\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Spy Emergency Health Check (SpyEmrgHealth) - NETGATE Technologies s.r.o. - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe
O23 - Service: Spy Emergency Engine Service (SpyEmrgSrv) - NETGATE Technologies s.r.o. - C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: ZAM Controller Service (ZAMSvc) - Copyright 2017. - C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe

--
End of file - 10820 bytes

====== Enumerating Processes ======

c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\fontdrvhost.exe
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
C:\Windows\system32\winlogon.exe
C:\Windows\system32\fontdrvhost.exe
C:\Windows\system32\dwm.exe
c:\windows\system32\svchost.exe -k networkservice -s TermService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k localservice -s nsi
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s UmRdpService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k netsvcs -s CertPropSvc
C:\Windows\system32\atiesrxx.exe
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation
c:\windows\system32\svchost.exe -k localservice -s netprofm
c:\windows\system32\svchost.exe -k netsvcs -s SessionEnv
c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localservice -s EventSystem
C:\Windows\system32\atieclxx.exe
c:\windows\system32\svchost.exe -k localservicenonetwork -s NcdAutoSetup
C:\Windows\system32\svchost.exe -k LocalService
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s FDResPub
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s HomeGroupProvider
C:\Windows\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
C:\Windows\system32\dashost.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
C:\Windows\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\system32\sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
"C:\Program Files\ESET\ESET Security\egui.exe" /hide
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
"C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe"
c:\windows\system32\taskhostw.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe"
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
c:\windows\system32\svchost.exe -k netsvcs -s IKEEXT
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe"
"C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe"
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
"C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
"C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe"
"C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe"
C:\Windows\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
"C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe" /service
c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent
"C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe" /rep_new
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s Netman
"C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\Ferox\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Ferox\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=60.0.3112.101 --initial-client-data=0x308,0x30c,0x320,0x314,0x324,0x7fffc1b929c0,0x7fffc1b929d8,0x7fffc1b929e8
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.820.0_x64__kzf8qxf38zg5c\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=8396 --on-initialized-event-handle=984 --parent-handle=972 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,20,21,24,43,77 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x1002 --gpu-device-id=0x67b1 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=22.19.162.4 --gpu-driver-date=4-24-2017 --service-request-channel-token=8583A689E86F06D6140BD4B7305C7C78 --mojo-platform-channel-handle=1624 --ignored=" --type=renderer " /prefetch:2
C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe atlogon
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=5BEEA5438B12F390EE6293FBD0DC672B --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=5BEEA5438B12F390EE6293FBD0DC672B --renderer-client-id=4 --mojo-platform-channel-handle=3328 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=3D235CDFB7072E90871C71A99153ED23 --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=3D235CDFB7072E90871C71A99153ED23 --renderer-client-id=5 --mojo-platform-channel-handle=3388 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=8B331604E895096303158E33743A6126 --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=8B331604E895096303158E33743A6126 --renderer-client-id=6 --mojo-platform-channel-handle=3396 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=4F94E41CD9FA3E5DF701FB79FD6E56F4 --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=4F94E41CD9FA3E5DF701FB79FD6E56F4 --renderer-client-id=7 --mojo-platform-channel-handle=3404 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=213070E8757E1E59B2AF108B0F93D926 --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=213070E8757E1E59B2AF108B0F93D926 --renderer-client-id=8 --mojo-platform-channel-handle=3416 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=3908C2B6369A0ACD18B4F81EE6AC24F7 --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=3908C2B6369A0ACD18B4F81EE6AC24F7 --renderer-client-id=9 --mojo-platform-channel-handle=3424 /prefetch:1
"C:\Program Files (x86)\SpyShelter Firewall\SpyShelter.exe"
"C:\Program Files (x86)\Steam\Steam.exe"
"C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe" /minimized
"C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" "-lang=cs_CZ" "-cachedir=C:\Users\Ferox\AppData\Local\Steam\htmlcache" "-steampid=10596" "-buildid=1500335472" "-steamid=0" "-clientui=C:\Program Files (x86)\Steam\clientui" --disable-spell-checking --disable-out-of-process-pac --enable-blink-features=ResizeObserver --disable-smooth-scrolling --disable-gpu-compositing --disable-gpu --enable-direct-write "--log-file=C:\Program Files (x86)\Steam\logs\cef_log.txt"
"C:\Program Files (x86)\Common Files\Steam\SteamService.exe" /RunAsService
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\ASUS\GPU TweakII\Monitor.exe" -ByGPUTweakII -12 273
"C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe"
"C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyWow64.exe"
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
C:\Windows\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
C:\Windows\system32\ApplicationFrameHost.exe -Embedding
c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
c:\windows\system32\svchost.exe -k unistacksvcgroup
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
c:\windows\system32\svchost.exe -k netsvcs
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.35071.13510.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.1862.0_x64__8wekyb3d8bbwe\Calculator.exe" -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca
"C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --disable-smooth-scrolling --enable-blink-features=ResizeObserver --enable-pinch --service-pipe-token=CEFC4642D0DD406665E1537A4A57EFB6 --lang=en-US --lang=cs-CZ --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --disable-spell-checking --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --disable-accelerated-video-decode --disable-gpu-compositing --service-request-channel-token=CEFC4642D0DD406665E1537A4A57EFB6 --renderer-client-id=6 --mojo-platform-channel-handle=2884 /prefetch:1
C:\Windows\system32\svchost.exe -k netsvcs -s WpnService
"C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe" /WAIT
C:\Windows\helppane.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=F7EFE34FEAAEEB8B78A13B736FF392E3 --lang=cs --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=F7EFE34FEAAEEB8B78A13B736FF392E3 --renderer-client-id=98 --mojo-platform-channel-handle=8744 /prefetch:1
"C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe" --type=renderer --disable-gpu-compositing --disable-smooth-scrolling --enable-blink-features=ResizeObserver --enable-pinch --service-pipe-token=3563518849581E98C5386EC151E8979B --lang=en-US --lang=cs-CZ --log-file="C:\Program Files (x86)\Steam\logs\cef_log.txt" --product-version="Valve Steam Client" --disable-spell-checking --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --disable-accelerated-video-decode --disable-gpu-compositing --service-request-channel-token=3563518849581E98C5386EC151E8979B --renderer-client-id=8 --mojo-platform-channel-handle=2928 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=87888891D21C09252E9D3FA2D44BB58C --lang=cs --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=87888891D21C09252E9D3FA2D44BB58C --renderer-client-id=138 --mojo-platform-channel-handle=15480 /prefetch:1
C:\Windows\System32\smartscreen.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=2D3F8326A4DE2A56412263099D3CD387 --lang=cs --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=2D3F8326A4DE2A56412263099D3CD387 --renderer-client-id=156 --mojo-platform-channel-handle=19940 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1608,17604974268017209700,5148341841959326037,131072 --service-pipe-token=87F617D9C7AF2E60861D64881048CCCF --lang=cs --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=87F617D9C7AF2E60861D64881048CCCF --renderer-client-id=159 --mojo-platform-channel-handle=11776 /prefetch:1
"C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe" -ServerName:SecHealthUI.AppXep4x2tbtjws1v9qqs0rmb3hxykvkpqtn.mca
C:\Windows\system32\DllHost.exe /Processid:{7E55A26D-EF95-4A45-9F55-21E52ADF9887}
C:\Windows\system32\svchost.exe -k netsvcs -s gpsvc
"C:\Windows\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
C:\Windows\system32\AUDIODG.EXE 0x6f0
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Ferox\Downloads\RSITx64.exe"
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -s WdiSystemHost
C:\Windows\system32\wbem\wmiprvse.exe

====== Scheduled tasks folder ======

C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\AdobeAAMUpdater-1.0-DESKTOP-IFA1B0Q-Ferox - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe -mode=scheduled
C:\Windows\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\GPU Tweak II - C:\Program Files (x86)\ASUS\GPU TweakII\GPUTweakII.exe
C:\Windows\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-602109316-548196106-1611085337-1001 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\Windows\system32\tasks\SafeZone scheduled Autoupdate 1500297013 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\Windows\system32\tasks\StartCN - "C:\Program Files\AMD\CNext\CNext\cncmd.exe" startwithdelay
C:\Windows\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\Windows\system32\tasks\Microsoft\Windows\WwanSvc\NotificationTask - %SystemRoot%\System32\WiFiTask.exe wwan
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan - C:\Program Files\Windows Defender\MpCmdRun.exe Scan -ScheduleJob -ScanTrigger 55
C:\Windows\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\Windows\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Combined Scan Download Install - %systemroot%\system32\usoclient.exe ScanInstallWait
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe RebootDialog
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - %systemroot%\system32\MusNotification.exe Display
C:\Windows\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - %systemroot%\system32\MusNotification.exe ReadyToReboot
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\Subscription\EnableLicenseAcquisition - %SystemRoot%\system32\ClipRenew.exe -e
C:\Windows\system32\tasks\Microsoft\Windows\Subscription\LicenseAcquisition - %SystemRoot%\system32\ClipRenew.exe
C:\Windows\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\Windows\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Management\Provisioning\Cellular - %windir%\system32\ProvTool.exe /turn 7 /source CellStateChangeTask
C:\Windows\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5 /source LogonIdleTask
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\Windows\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\Windows\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\Windows\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe

=========Google Chrome=========

C:\Users\Ferox\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension bfllnafdpfdenppkmbllnnackcapfoad 1 Agar.io Mods 1.0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension canbadmphamemnmdfngmcabnjmjgaiki 1 Ban Checker for Steam 0.6.2
Extension cfhdojbkjhnklbpkdaibdccddilifddb 1 Adblock Plus 1.13.3
Extension cllhabecdhkflmjpoimkheipdagjobbl 1 Doplněk pro DámeJídlo 2.1.3
Extension cmeakgjggjdlcpncigglobpjbkabhmjl 1 Steam Inventory Helper 1.11.3.4
Extension dbnfnbehhjknomdbfhcobpgpphnlnikp 1 Tipli do prohlížeče 1.3.0
Extension dggomkijbihggjgcgdbnleolpleddaid 1 Slither.io Skins, Mods, Hack & Guide 1.1
Extension dhdgffkkebhmkfjojejmpbldmpobfkfo 1 Tampermonkey 4.3.6
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension eofcbnmajmjmplflapaojjnihcjkigck 0 Avast SafePrice 12.0.263
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension fidfhokmiihfkmkhgpacakihkehklhka 1 Ban Checker For Steam With History 1.2.3
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension gkojfkhlekighikafcpjkiklfbnlmeio 1 Unlimited Free VPN - Hola 1.53.628
Extension gomekmidlodglbbmalcneegieacbdmki 0 Avast Online Security 12.0.263
Extension hgmaihllcpbdicdhadfffflhopaijpif 1 Counter Strike: Global Offensive - Theme 8
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension kojolejmgolbhakghocbgjemjgbmcjig 1 SteamWizard 1.0.11
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.4
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.3
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 6017.605.1.4
Homepage: https://www.google.cz/
default_search_provider.search_url:
C:\Users\Ferox\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eofcbnmajmjmplflapaojjnihcjkigck]
"Path"=

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\gomekmidlodglbbmalcneegieacbdmki]
"Path"=


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre7\bin\ssv.dll [2017-08-09 553384]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre7\bin\jp2ssv.dll [2017-08-09 210856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2017-08-09 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2017-08-09 171944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-03-18 629152]
"Služba Acronis Scheduler2"=C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [2015-12-25 383624]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-07-29 213832]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"Malwarebytes TrayApp"=C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2017-05-09 3146704]
"ZAM"=C:\Program Files (x86)\Zemana AntiLogger\ZAM.exe [2017-06-19 15546512]
"SpywareTerminatorShield"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2017-08-22 5349120]
"SpywareTerminatorUpdater"=C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [2017-08-22 5585672]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Ferox\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-07-27 1536208]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2017-07-18 3062560]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2017-07-28 27815896]
"Discord"=C:\Users\Ferox\AppData\Local\Discord\app-0.0.298\Discord.exe [2017-08-08 57477112]
"uTorrent"=C:\Users\Ferox\AppData\Roaming\uTorrent\uTorrent.exe [2017-07-17 2146496]
"AdobeBridge"= []
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2017-07-03 4836032]
"GoogleChromeAutoLaunch_00171127CFADF2F8E5D7DA00AA0FBFC4"=C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [2017-08-11 1301848]
"SpyShelter"=C:\Program Files (x86)\SpyShelter Firewall\SpyShelter.exe [2017-07-10 3739904]
"SpyEmergency"=C:\Program Files\NETGATE\Spy Emergency\SpyEmergency.exe [2017-02-07 3295680]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Discord"=C:\ProgramData\SquirrelMachineInstalls\Discord.exe [2017-07-15 52553728]
"zenvpn"=C:\Program Files (x86)\ZenVPN OpenVPN bundle\bin\zenvpn.exe []
"Avira SystrayStartTrigger"=C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2017-08-02 97512]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-07-02 254336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~2\KEYCRY~1\KE6D28~1.DLL"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"vidc.mjpg"=bdmjpeg64.dll
"vidc.mpeg"=bdmpegv64.dll
"msacm.bdmpeg"=bdmpega64.acm
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

Feroxik
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 22 srp 2017 13:29

Re: Prosím o kontrolu, nejspíše nějaký RAT nebo něco takovéh

#2 Příspěvek od Feroxik »

Ještě zbytek z logu, nevešlo se mi to tam, protože jsem překročil limit znaků.
====== List of files/folders created in the last 1 month ======

2017-08-22 14:17:46 ----D---- C:\rsit
2017-08-22 14:17:46 ----D---- C:\Program Files\trend micro
2017-08-22 13:59:25 ----D---- C:\ProgramData\Spyware Terminator
2017-08-22 13:58:32 ----D---- C:\Program Files (x86)\Spyware Terminator
2017-08-22 03:37:56 ----D---- C:\Users\Ferox\AppData\Roaming\Spy Emergency
2017-08-22 03:37:54 ----A---- C:\Windows\system32\drivers\spyemrg_guard.sys
2017-08-22 03:37:54 ----A---- C:\Windows\system32\drivers\spyemrg_access.sys
2017-08-22 03:37:54 ----A---- C:\Windows\system32\drivers\spyemrg.sys
2017-08-22 03:37:50 ----D---- C:\ProgramData\NETGATE
2017-08-22 03:37:50 ----D---- C:\Program Files\NETGATE
2017-08-22 02:43:04 ----A---- C:\Windows\system32\drivers\zamguard64.sys
2017-08-22 02:43:04 ----A---- C:\Windows\system32\drivers\zam64.sys
2017-08-22 02:42:54 ----D---- C:\Program Files (x86)\KeyCryptSDK
2017-08-22 02:42:54 ----A---- C:\Windows\system32\drivers\KeyCrypt64.sys
2017-08-22 02:42:54 ----A---- C:\Windows\system32\drivers\1F93EEF0-2666-45F8-98-D0-FB-D9-58-19-77-B1.sys
2017-08-22 02:42:53 ----D---- C:\Program Files (x86)\Zemana AntiLogger
2017-08-22 02:41:15 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-08-22 02:40:59 ----D---- C:\Program Files (x86)\ATRKT
2017-08-22 02:28:17 ----A---- C:\Windows\SYSWOW64\SpyShelterShellExt.dll
2017-08-22 02:28:17 ----A---- C:\Windows\system32\SpyShelterShellExt.dll
2017-08-22 02:28:13 ----D---- C:\Users\Ferox\AppData\Roaming\SpyShelter
2017-08-22 02:28:13 ----D---- C:\Program Files (x86)\SpyShelter Firewall
2017-08-22 02:20:43 ----D---- C:\ProgramData\SWCUTemp
2017-08-22 02:14:46 ----D---- C:\ProgramData\ESET
2017-08-22 02:14:46 ----D---- C:\Program Files\ESET
2017-08-20 02:02:33 ----D---- C:\Windows\Microsoft Antimalware
2017-08-20 01:04:46 ----A---- C:\Windows\system32\drivers\MBAMChameleon.sys
2017-08-20 01:04:38 ----A---- C:\Windows\system32\drivers\mwac.sys
2017-08-20 01:04:38 ----A---- C:\Windows\system32\drivers\farflt.sys
2017-08-20 01:04:35 ----A---- C:\Windows\system32\drivers\mbam.sys
2017-08-20 01:04:33 ----A---- C:\Windows\system32\drivers\MBAMSwissArmy.sys
2017-08-20 01:04:19 ----A---- C:\Windows\system32\drivers\mbae64.sys
2017-08-20 01:04:12 ----D---- C:\ProgramData\Malwarebytes
2017-08-20 01:04:12 ----D---- C:\Program Files\Malwarebytes
2017-08-13 17:32:14 ----AD---- C:\Program Files (x86)\Free Auto Clicker
2017-08-11 16:37:48 ----A---- C:\Windows\SYSWOW64\VsGraphicsDesktopEngine.exe
2017-08-11 16:37:48 ----A---- C:\Windows\SYSWOW64\d3d12warp.dll
2017-08-11 16:37:48 ----A---- C:\Windows\SYSWOW64\d3d12SDKLayers.dll
2017-08-11 16:37:48 ----A---- C:\Windows\SYSWOW64\d2d1debug3.dll
2017-08-11 16:37:48 ----A---- C:\Windows\system32\VsGraphicsDesktopEngine.exe
2017-08-11 16:37:48 ----A---- C:\Windows\system32\d3d12SDKLayers.dll
2017-08-11 16:37:48 ----A---- C:\Windows\system32\d2d1debug3.dll
2017-08-11 13:34:07 ----D---- C:\ProgramData\Git
2017-08-11 13:26:31 ----AD---- C:\Program Files\Git
2017-08-11 13:24:55 ----AD---- C:\Program Files\Python36
2017-08-11 13:16:15 ----D---- C:\Program Files (x86)\IIS
2017-08-11 13:16:15 ----AD---- C:\Program Files\IIS
2017-08-11 13:15:55 ----D---- C:\Program Files (x86)\Entity Framework Tools
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\VsGraphicsRemoteEngine.exe
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\VsGraphicsProxyStub.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\VsGraphicsExperiment.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\VsGraphicsCapture.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\VSD3DWARPDebug.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\VSD3DWARP12Debug.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\perf_gputiming.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\DXToolsReporting.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\DxToolsReportGenerator.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\DXToolsOfflineAnalysis.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\DXToolsMonitor.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\DXGIDebug.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\DXCpl.exe
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\DXCaptureReplay.dll
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\DXCap.exe
2017-08-11 13:15:29 ----A---- C:\Windows\SYSWOW64\d3d11_3SDKLayers.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\VsGraphicsRemoteEngine.exe
2017-08-11 13:15:29 ----A---- C:\Windows\system32\VsGraphicsProxyStub.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\VsGraphicsExperiment.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\VsGraphicsCapture.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\VSD3DWARPDebug.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\VSD3DWARP12Debug.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\perf_gputiming.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\DXToolsReporting.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\DxToolsReportGenerator.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\DXToolsOfflineAnalysis.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\DXToolsMonitor.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\DXGIDebug.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\DXCpl.exe
2017-08-11 13:15:29 ----A---- C:\Windows\system32\DXCaptureReplay.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\DXCap.exe
2017-08-11 13:15:29 ----A---- C:\Windows\system32\d3d12warp.dll
2017-08-11 13:15:29 ----A---- C:\Windows\system32\d3d11_3SDKLayers.dll
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\3082
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\2052
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1055
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1049
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1046
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1045
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1042
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1041
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1040
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1036
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1033
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1031
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1029
2017-08-11 13:15:14 ----D---- C:\Windows\SYSWOW64\1028
2017-08-11 13:15:14 ----D---- C:\Windows\system32\3082
2017-08-11 13:15:14 ----D---- C:\Windows\system32\2052
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1055
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1049
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1046
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1045
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1042
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1041
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1040
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1036
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1033
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1031
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1029
2017-08-11 13:15:14 ----D---- C:\Windows\system32\1028
2017-08-11 13:11:47 ----D---- C:\Program Files (x86)\Windows Phone Kits
2017-08-11 13:09:41 ----AD---- C:\ProgramData\Windows App Certification Kit
2017-08-11 13:09:38 ----AD---- C:\Program Files\Application Verifier
2017-08-11 13:09:38 ----AD---- C:\Program Files (x86)\Application Verifier
2017-08-11 13:06:53 ----D---- C:\Program Files (x86)\NuGet
2017-08-11 13:04:52 ----D---- C:\Program Files\Microsoft SQL Server
2017-08-11 13:04:48 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 14.0
2017-08-11 13:04:48 ----AD---- C:\Program Files (x86)\Microsoft SQL Server
2017-08-11 13:04:43 ----D---- C:\Program Files (x86)\Microsoft Web Tools
2017-08-11 13:01:48 ----D---- C:\Program Files (x86)\Windows Kits
2017-08-11 13:01:48 ----D---- C:\Program Files (x86)\Microsoft SDKs
2017-08-11 12:56:54 ----D---- C:\Program Files (x86)\VS
2017-08-11 12:54:55 ----D---- C:\Users\Ferox\AppData\Roaming\Visual Studio Setup
2017-08-11 12:54:30 ----D---- C:\Program Files (x86)\Microsoft Visual Studio
2017-08-10 11:03:14 ----A---- C:\Windows\system32\drivers\EasyAntiCheat.sys
2017-08-10 11:03:09 ----A---- C:\Windows\SYSWOW64\EasyAntiCheat.exe
2017-08-10 10:35:37 ----A---- C:\Windows\system32\drivers\dtliteusbbus.sys
2017-08-10 10:35:34 ----D---- C:\Users\Ferox\AppData\Roaming\DAEMON Tools Lite
2017-08-10 10:35:34 ----A---- C:\Windows\system32\drivers\dtlitescsibus.sys
2017-08-10 10:35:29 ----D---- C:\Program Files\DAEMON Tools Lite
2017-08-10 10:35:03 ----D---- C:\ProgramData\DAEMON Tools Lite
2017-08-09 23:23:09 ----D---- C:\ProgramData\Steam
2017-08-09 23:18:31 ----D---- C:\Windows\SYSWOW64\XPSViewer
2017-08-09 23:18:25 ----D---- C:\Program Files (x86)\Reference Assemblies
2017-08-09 23:18:25 ----D---- C:\Program Files (x86)\MSBuild
2017-08-09 23:18:24 ----D---- C:\Program Files\Reference Assemblies
2017-08-09 23:18:24 ----D---- C:\Program Files\MSBuild
2017-08-09 23:18:21 ----A---- C:\AiOLog.txt
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\zlib1.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\wrap_oal.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\vb40032.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\ssleay32.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\openal32.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\msvcr70.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\msvcp70.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\msvci70.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\msdia100.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71u.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71kor.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71jpn.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71ita.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71cht.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71chs.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71fra.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71esp.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71enu.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71deu.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc71.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70u.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70kor.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70jpn.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70ita.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70cht.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70chs.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70fra.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70esp.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70enu.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\mfc70deu.dll
2017-08-09 23:18:19 ----A---- C:\Windows\SYSWOW64\atl71.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\msstkprp.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\msstdfmt.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\mfc70.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\libssl32.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\libpng15.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\libpng13.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\libmmd.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\libintl3.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\libiconv2.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\libeay32.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\cygwin1.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\atl70.dll
2017-08-09 23:18:18 ----A---- C:\Windows\SYSWOW64\AiORuntimes.dll
2017-08-09 23:18:17 ----A---- C:\Windows\unins000.exe
2017-08-09 23:18:17 ----A---- C:\Windows\unins000.dat
2017-08-09 23:18:17 ----A---- C:\Windows\SYSWOW64\autoitx3.dll
2017-08-09 23:18:01 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2017-08-09 23:18:01 ----A---- C:\Windows\SYSWOW64\PresentationNative_v0300.dll
2017-08-09 23:18:01 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-08-09 23:17:59 ----A---- C:\Windows\system32\TsWpfWrp.exe
2017-08-09 23:17:59 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
2017-08-09 23:17:59 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2017-08-09 23:17:42 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2017-08-09 23:17:42 ----AD---- C:\Program Files\Microsoft Silverlight
2017-08-09 23:17:36 ----AD---- C:\Windows\SYSWOW64\Adobe
2017-08-09 23:16:37 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2017-08-09 23:16:29 ----D---- C:\Windows\SYSWOW64\URTTEMP
2017-08-09 23:16:19 ----A---- C:\Windows\system32\javaws.exe
2017-08-09 23:16:17 ----A---- C:\Windows\system32\WindowsAccessBridge-64.dll
2017-08-09 23:16:17 ----A---- C:\Windows\system32\javaw.exe
2017-08-09 23:16:17 ----A---- C:\Windows\system32\java.exe
2017-08-09 23:16:15 ----D---- C:\Program Files\Java
2017-08-09 23:16:11 ----D---- C:\ProgramData\Sun
2017-08-09 23:16:10 ----A---- C:\Windows\SYSWOW64\javaws.exe
2017-08-09 23:16:09 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2017-08-09 23:16:09 ----A---- C:\Windows\SYSWOW64\javaw.exe
2017-08-09 23:16:09 ----A---- C:\Windows\SYSWOW64\java.exe
2017-08-09 23:16:06 ----D---- C:\Program Files (x86)\Java
2017-08-09 21:30:32 ----A---- C:\Windows\GPU-Z.INI
2017-08-09 21:30:02 ----N---- C:\Windows\system32\drivers\IOMap64.sys
2017-08-09 21:28:46 ----D---- C:\Program Files (x86)\ASUS
2017-08-09 21:28:34 ----D---- C:\Windows\Downloaded Installations
2017-08-09 20:49:20 ----D---- C:\Program Files (x86)\SpeedFan
2017-08-08 21:42:41 ----A---- C:\Windows\SYSWOW64\WpcWebFilter.dll
2017-08-08 21:42:41 ----A---- C:\Windows\SYSWOW64\IpNatHlpClient.dll
2017-08-08 21:42:41 ----A---- C:\Windows\SYSWOW64\InstallAgentUserBroker.exe
2017-08-08 21:42:41 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2017-08-08 21:42:41 ----A---- C:\Windows\system32\tquery.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\Windows.UI.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\rasapi32.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\policymanager.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\InstallAgent.exe
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\BingMaps.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2017-08-08 21:42:40 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2017-08-08 21:42:39 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2017-08-08 21:42:39 ----A---- C:\Windows\SYSWOW64\tquery.dll
2017-08-08 21:42:39 ----A---- C:\Windows\SYSWOW64\msIso.dll
2017-08-08 21:42:39 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2017-08-08 21:42:39 ----A---- C:\Windows\SYSWOW64\aadtb.dll
2017-08-08 21:42:38 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-08-08 21:42:38 ----A---- C:\Windows\SYSWOW64\win32kfull.sys
2017-08-08 21:42:38 ----A---- C:\Windows\SYSWOW64\MSVPXENC.dll
2017-08-08 21:42:38 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2017-08-08 21:42:38 ----A---- C:\Windows\SYSWOW64\D3DCompiler_47.dll
2017-08-08 21:42:38 ----A---- C:\Windows\SYSWOW64\d2d1.dll
2017-08-08 21:42:37 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2017-08-08 21:42:37 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2017-08-08 21:42:37 ----A---- C:\Windows\SYSWOW64\ole32.dll
2017-08-08 21:42:37 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2017-08-08 21:42:37 ----A---- C:\Windows\SYSWOW64\CoreMessaging.dll
2017-08-08 21:42:37 ----A---- C:\Windows\SYSWOW64\AzureSettingSyncProvider.dll
2017-08-08 21:42:37 ----A---- C:\Windows\SYSWOW64\ActivationManager.dll
2017-08-08 21:42:36 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2017-08-08 21:42:36 ----A---- C:\Windows\SYSWOW64\Windows.UI.Immersive.dll
2017-08-08 21:42:36 ----A---- C:\Windows\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-08-08 21:42:36 ----A---- C:\Windows\SYSWOW64\InputService.dll
2017-08-08 21:42:36 ----A---- C:\Windows\SYSWOW64\CoreUIComponents.dll
2017-08-08 21:42:35 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2017-08-08 21:42:35 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2017-08-08 21:42:35 ----A---- C:\Windows\SYSWOW64\windows.storage.dll
2017-08-08 21:42:35 ----A---- C:\Windows\SYSWOW64\twinui.dll
2017-08-08 21:42:35 ----A---- C:\Windows\SYSWOW64\shell32.dll
2017-08-08 21:42:35 ----A---- C:\Windows\SYSWOW64\comdlg32.dll
2017-08-08 21:42:33 ----A---- C:\Windows\SYSWOW64\TokenBroker.dll
2017-08-08 21:42:33 ----A---- C:\Windows\SYSWOW64\msrepl40.dll
2017-08-08 21:42:33 ----A---- C:\Windows\SYSWOW64\msrd3x40.dll
2017-08-08 21:42:33 ----A---- C:\Windows\SYSWOW64\msrd2x40.dll
2017-08-08 21:42:33 ----A---- C:\Windows\SYSWOW64\msjtes40.dll
2017-08-08 21:42:33 ----A---- C:\Windows\SYSWOW64\msjetoledb40.dll
2017-08-08 21:42:33 ----A---- C:\Windows\SYSWOW64\msjet40.dll
2017-08-08 21:42:33 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\Windows.StateRepository.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\Windows.Internal.Management.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\TpmCoreProvisioning.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\rastls.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\msxbde40.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\mstext40.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\mspbde40.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\msltus40.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\msexcl40.dll
2017-08-08 21:42:32 ----A---- C:\Windows\SYSWOW64\AppXDeploymentClient.dll
2017-08-08 21:42:32 ----A---- C:\Windows\system32\drivers\USBHUB3.SYS
2017-08-08 21:42:32 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\wer.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\TextInputFramework.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\scksp.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\PCPKsp.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\ncryptprov.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\mswstr10.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\mswdat10.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\msjter40.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\msjint40.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\DolbyDecMFT.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\dmcmnutils.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\basecsp.dll
2017-08-08 21:42:31 ----A---- C:\Windows\SYSWOW64\autochk.exe
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\werui.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\wermgr.exe
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\WerFaultSecure.exe
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\WerFault.exe
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\untfs.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\sscore.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\shlwapi.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\ReAgent.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\netlogon.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\msacm32.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\mfsensorgroup.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\GamePanel.exe
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\Faultrep.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\dxgi.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\cmintegrator.dll
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\autofmt.exe
2017-08-08 21:42:30 ----A---- C:\Windows\SYSWOW64\autoconv.exe
2017-08-08 21:42:30 ----A---- C:\Windows\system32\drivers\acpi.sys
2017-08-08 21:42:30 ----A---- C:\Windows\system32\cmintegrator.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryUpgrade.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\VCardParser.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\tokenbinding.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\spbcd.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\shsvcs.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\rastlsext.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\qasf.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\fdeploy.dll
2017-08-08 21:42:29 ----A---- C:\Windows\SYSWOW64\DWWIN.EXE
2017-08-08 21:42:29 ----A---- C:\Windows\system32\drivers\UcmUcsi.sys
2017-08-08 21:42:29 ----A---- C:\Windows\system32\drivers\bthhfenum.sys
2017-08-08 21:42:27 ----A---- C:\Windows\system32\wbiosrvc.dll
2017-08-08 21:42:25 ----A---- C:\Windows\system32\drivers\tdx.sys
2017-08-08 21:42:25 ----A---- C:\Windows\system32\drivers\tcpip.sys
2017-08-08 21:42:25 ----A---- C:\Windows\system32\diagtrack.dll
2017-08-08 21:42:22 ----A---- C:\Windows\system32\WWAHost.exe
2017-08-08 21:42:21 ----A---- C:\Windows\system32\storewuauth.dll
2017-08-08 21:42:21 ----A---- C:\Windows\system32\InstallAgentUserBroker.exe
2017-08-08 21:42:21 ----A---- C:\Windows\system32\InstallAgent.exe
2017-08-08 21:42:20 ----A---- C:\Windows\SYSWOW64\ieproxy.dll
2017-08-08 21:42:20 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2017-08-08 21:42:20 ----A---- C:\Windows\system32\VCardParser.dll
2017-08-08 21:42:20 ----A---- C:\Windows\system32\ieproxy.dll
2017-08-08 21:42:19 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2017-08-08 21:42:18 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2017-08-08 21:42:18 ----A---- C:\Windows\system32\Windows.Media.dll
2017-08-08 21:42:18 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2017-08-08 21:42:18 ----A---- C:\Windows\system32\Chakradiag.dll
2017-08-08 21:42:17 ----A---- C:\Windows\system32\MFMediaEngine.dll
2017-08-08 21:42:17 ----A---- C:\Windows\system32\KernelBase.dll
2017-08-08 21:42:17 ----A---- C:\Windows\system32\drivers\bridge.sys
2017-08-08 21:42:17 ----A---- C:\Windows\system32\BingMaps.dll
2017-08-08 21:42:16 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2017-08-08 21:42:16 ----A---- C:\Windows\system32\jscript9diag.dll
2017-08-08 21:42:16 ----A---- C:\Windows\system32\jscript9.dll
2017-08-08 21:42:16 ----A---- C:\Windows\system32\InputService.dll
2017-08-08 21:42:16 ----A---- C:\Windows\system32\edgehtml.dll
2017-08-08 21:42:15 ----A---- C:\Windows\system32\mshtml.dll
2017-08-08 21:42:15 ----A---- C:\Windows\system32\Chakra.dll
2017-08-08 21:42:13 ----A---- C:\Windows\SYSWOW64\Chakradiag.dll
2017-08-08 21:42:13 ----A---- C:\Windows\system32\wmpps.dll
2017-08-08 21:42:13 ----A---- C:\Windows\system32\TextInputFramework.dll
2017-08-08 21:42:13 ----A---- C:\Windows\system32\rastlsext.dll
2017-08-08 21:42:13 ----A---- C:\Windows\system32\psmsrv.dll
2017-08-08 21:42:13 ----A---- C:\Windows\system32\drivers\ntfs.sys
2017-08-08 21:42:12 ----A---- C:\Windows\system32\ole32.dll
2017-08-08 21:42:12 ----A---- C:\Windows\system32\drivers\clfs.sys
2017-08-08 21:42:12 ----A---- C:\Windows\system32\dbgeng.dll
2017-08-08 21:42:12 ----A---- C:\Windows\system32\D3DCompiler_47.dll
2017-08-08 21:42:12 ----A---- C:\Windows\system32\bisrv.dll
2017-08-08 21:42:12 ----A---- C:\Windows\system32\AppReadiness.dll
2017-08-08 21:42:12 ----A---- C:\Windows\system32\ActivationManager.dll
2017-08-08 21:42:11 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2017-08-08 21:42:11 ----A---- C:\Windows\system32\wudriver.dll
2017-08-08 21:42:11 ----A---- C:\Windows\system32\windows.storage.dll
2017-08-08 21:42:11 ----A---- C:\Windows\system32\ntoskrnl.exe
2017-08-08 21:42:11 ----A---- C:\Windows\system32\CoreUIComponents.dll
2017-08-08 21:42:10 ----A---- C:\Windows\system32\ieframe.dll
2017-08-08 21:42:09 ----A---- C:\Windows\system32\Windows.StateRepository.dll
2017-08-08 21:42:09 ----A---- C:\Windows\system32\browserbroker.dll
2017-08-08 21:42:09 ----A---- C:\Windows\system32\AppXDeploymentClient.dll
2017-08-08 21:42:08 ----A---- C:\Windows\SYSWOW64\bcd.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\workfolderssvc.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\Windows.StateRepositoryUpgrade.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\wermgr.exe
2017-08-08 21:42:08 ----A---- C:\Windows\system32\WerFaultSecure.exe
2017-08-08 21:42:08 ----A---- C:\Windows\system32\WerFault.exe
2017-08-08 21:42:08 ----A---- C:\Windows\system32\wer.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\services.exe
2017-08-08 21:42:08 ----A---- C:\Windows\system32\RjvMDMConfig.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\MDMAppInstaller.exe
2017-08-08 21:42:08 ----A---- C:\Windows\system32\hal.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\FlightSettings.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\Faultrep.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\dxgi.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\DolbyDecMFT.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\DmApiSetExtImplDesktop.dll
2017-08-08 21:42:08 ----A---- C:\Windows\system32\bcd.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\Windows.Shell.BlueLightReduction.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\wersvc.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\SettingsHandlers_Display.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\officecsp.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\DolbyMATEnc.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\DolbyHrtfEnc.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\AudioSes.dll
2017-08-08 21:42:07 ----A---- C:\Windows\system32\AudioEndpointBuilder.dll
2017-08-08 21:42:06 ----A---- C:\Windows\system32\GamePanel.exe
2017-08-08 21:42:06 ----A---- C:\Windows\system32\CoreMessaging.dll
2017-08-08 21:42:06 ----A---- C:\Windows\system32\AudioEng.dll
2017-08-08 21:42:05 ----A---- C:\Windows\system32\wwansvc.dll
2017-08-08 21:42:05 ----A---- C:\Windows\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2017-08-08 21:42:05 ----A---- C:\Windows\system32\dwmredir.dll
2017-08-08 21:42:05 ----A---- C:\Windows\system32\dosvc.dll
2017-08-08 21:42:05 ----A---- C:\Windows\system32\BluetoothApis.dll
2017-08-08 21:42:05 ----A---- C:\Windows\system32\audiosrv.dll
2017-08-08 21:42:04 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2017-08-08 21:42:03 ----A---- C:\Windows\system32\wuuhosdeployment.dll
2017-08-08 21:42:03 ----A---- C:\Windows\system32\AppXDeploymentExtensions.desktop.dll
2017-08-08 21:42:03 ----A---- C:\Windows\system32\aadcloudap.dll
2017-08-08 21:42:02 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2017-08-08 21:42:02 ----A---- C:\Windows\system32\Windows.UI.dll
2017-08-08 21:42:02 ----A---- C:\Windows\system32\Windows.Internal.Management.dll
2017-08-08 21:42:02 ----A---- C:\Windows\system32\SettingsHandlers_nt.dll
2017-08-08 21:42:02 ----A---- C:\Windows\system32\iertutil.dll
2017-08-08 21:42:02 ----A---- C:\Windows\system32\AzureSettingSyncProvider.dll
2017-08-08 21:42:01 ----A---- C:\Windows\system32\wuuhext.dll
2017-08-08 21:42:01 ----A---- C:\Windows\system32\TokenBroker.dll
2017-08-08 21:42:01 ----A---- C:\Windows\system32\TileDataRepository.dll
2017-08-08 21:42:01 ----A---- C:\Windows\system32\SIHClient.exe
2017-08-08 21:42:01 ----A---- C:\Windows\system32\rastls.dll
2017-08-08 21:42:01 ----A---- C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
2017-08-08 21:42:01 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2017-08-08 21:42:01 ----A---- C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2017-08-08 21:42:00 ----A---- C:\Windows\system32\Windows.UI.Immersive.dll
2017-08-08 21:42:00 ----A---- C:\Windows\system32\urlmon.dll
2017-08-08 21:42:00 ----A---- C:\Windows\system32\twinui.dll
2017-08-08 21:42:00 ----A---- C:\Windows\system32\LogonController.dll
2017-08-08 21:42:00 ----A---- C:\Windows\system32\ExplorerFrame.dll
2017-08-08 21:42:00 ----A---- C:\Windows\system32\comdlg32.dll
2017-08-08 21:41:59 ----A---- C:\Windows\system32\wuaueng.dll
2017-08-08 21:41:59 ----A---- C:\Windows\system32\wuapi.dll
2017-08-08 21:41:59 ----A---- C:\Windows\system32\winsrv.dll
2017-08-08 21:41:59 ----A---- C:\Windows\system32\rasapi32.dll
2017-08-08 21:41:59 ----A---- C:\Windows\system32\msIso.dll
2017-08-08 21:41:59 ----A---- C:\Windows\system32\FrameServer.dll
2017-08-08 21:41:59 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2017-08-08 21:41:59 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2017-08-08 21:41:58 ----A---- C:\Windows\system32\win32kfull.sys
2017-08-08 21:41:58 ----A---- C:\Windows\system32\win32kbase.sys
2017-08-08 21:41:58 ----A---- C:\Windows\system32\shell32.dll
2017-08-08 21:41:58 ----A---- C:\Windows\system32\msv1_0.dll
2017-08-08 21:41:58 ----A---- C:\Windows\system32\ClipSVC.dll
2017-08-08 21:41:57 ----A---- C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-08-08 21:41:57 ----A---- C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2017-08-08 21:41:56 ----A---- C:\Windows\system32\policymanager.dll
2017-08-08 21:41:56 ----A---- C:\Windows\system32\dmcmnutils.dll
2017-08-08 21:41:56 ----A---- C:\Windows\system32\bcdedit.exe
2017-08-08 21:41:56 ----A---- C:\Windows\system32\bcdboot.exe
2017-08-08 21:41:55 ----A---- C:\Windows\SYSWOW64\UIRibbonRes.dll
2017-08-08 21:41:55 ----A---- C:\Windows\system32\WpcWebFilter.dll
2017-08-08 21:41:55 ----A---- C:\Windows\system32\UIRibbonRes.dll
2017-08-08 21:41:55 ----A---- C:\Windows\system32\reseteng.dll
2017-08-08 21:41:55 ----A---- C:\Windows\system32\enterprisecsps.dll
2017-08-08 21:41:55 ----A---- C:\Windows\system32\efscore.dll
2017-08-08 21:41:55 ----A---- C:\Windows\system32\aadtb.dll
2017-08-08 21:41:54 ----A---- C:\Windows\system32\wininit.exe
2017-08-08 21:41:54 ----A---- C:\Windows\system32\TpmCoreProvisioning.dll
2017-08-08 21:41:54 ----A---- C:\Windows\system32\SettingsHandlers_Notifications.dll
2017-08-08 21:41:54 ----A---- C:\Windows\system32\scksp.dll
2017-08-08 21:41:54 ----A---- C:\Windows\system32\MBR2GPT.EXE
2017-08-08 21:41:54 ----A---- C:\Windows\system32\basecsp.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\XblAuthManager.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\Windows.Security.Authentication.Web.Core.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\werconcpl.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\ReAgent.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\ncryptprov.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\msacm32.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\MPSSVC.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\lpasvc.dll
2017-08-08 21:41:53 ----A---- C:\Windows\system32\autochk.exe
2017-08-08 21:41:52 ----A---- C:\Windows\system32\werui.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\wercplsupport.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\untfs.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\sscore.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\srvsvc.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\shlwapi.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\SettingsHandlers_Flights.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\profsvcext.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\policymanagerprecheck.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\PCPKsp.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\ofdeploy.exe
2017-08-08 21:41:52 ----A---- C:\Windows\system32\netlogon.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\mfsensorgroup.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\fdeploy.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\drivers\vmbkmclr.sys
2017-08-08 21:41:52 ----A---- C:\Windows\system32\drivers\vmbkmcl.sys
2017-08-08 21:41:52 ----A---- C:\Windows\system32\drivers\fvevol.sys
2017-08-08 21:41:52 ----A---- C:\Windows\system32\dmenterprisediagnostics.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\coredpus.dll
2017-08-08 21:41:52 ----A---- C:\Windows\system32\autofmt.exe
2017-08-08 21:41:52 ----A---- C:\Windows\system32\autoconv.exe
2017-08-08 21:41:51 ----A---- C:\Windows\SYSWOW64\UIRibbon.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\wsqmcons.exe
2017-08-08 21:41:51 ----A---- C:\Windows\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\UIRibbon.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\TpmTasks.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\tokenbinding.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\spbcd.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\SmsRouterSvc.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\shsvcs.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\setbcdlocale.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\RecoveryDrive.exe
2017-08-08 21:41:51 ----A---- C:\Windows\system32\qasf.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\mdmregistration.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\facecredentialprovider.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\DWWIN.EXE
2017-08-08 21:41:51 ----A---- C:\Windows\system32\dui70.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\dmenrollengine.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\dmcsps.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\DeviceEnroller.exe
2017-08-08 21:41:51 ----A---- C:\Windows\system32\configmanager2.dll
2017-08-08 21:41:51 ----A---- C:\Windows\system32\BootMenuUX.dll
2017-08-08 21:41:50 ----A---- C:\Windows\system32\IpNatHlpClient.dll
2017-08-08 00:04:44 ----AD---- C:\Program Files\7-Zip
2017-08-04 15:38:01 ----D---- C:\Users\Ferox\AppData\Roaming\.mono
2017-08-04 15:38:01 ----D---- C:\ProgramData\.mono
2017-08-04 14:03:24 ----AD---- C:\Program Files (x86)\Diablo III
2017-08-04 14:00:23 ----AD---- C:\Program Files (x86)\Hearthstone
2017-08-04 14:00:12 ----D---- C:\ProgramData\Blizzard Entertainment
2017-08-04 13:59:33 ----D---- C:\Users\Ferox\AppData\Roaming\Battle.net
2017-08-04 13:58:59 ----AD---- C:\Program Files (x86)\Blizzard App
2017-08-04 13:56:47 ----D---- C:\ProgramData\Battle.net
2017-07-31 17:34:48 ----D---- C:\Windows\SYSWOW64\directx
2017-07-29 18:25:22 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2017-07-29 18:25:00 ----D---- C:\Program Files\Adobe
2017-07-29 18:24:29 ----AD---- C:\Program Files (x86)\Adobe
2017-07-29 18:23:50 ----D---- C:\Program Files\Common Files\Adobe
2017-07-29 18:21:59 ----D---- C:\Users\Ferox\AppData\Roaming\Macromedia
2017-07-29 18:21:58 ----D---- C:\ProgramData\Adobe
2017-07-29 17:21:08 ----A---- C:\Windows\system32\aswBoot.exe
2017-07-29 02:32:29 ----D---- C:\ProgramData\DivX
2017-07-28 18:41:44 ----D---- C:\ProgramData\Avira
2017-07-28 18:41:44 ----D---- C:\Program Files (x86)\Avira
2017-07-27 16:42:03 ----D---- C:\ProgramData\ZenVPN
2017-07-25 21:36:44 ----D---- C:\Users\Ferox\AppData\Roaming\OBS
2017-07-25 21:36:33 ----D---- C:\Program Files\OBS
2017-07-25 21:36:24 ----D---- C:\Program Files (x86)\OBS
2017-07-23 22:07:16 ----D---- C:\Program Files (x86)\Bignox
2017-07-23 22:06:36 ----D---- C:\Program Files (x86)\Nox

====== List of files/folders modified in the last 1 month ======

2017-08-22 14:41:32 ----D---- C:\Windows\Temp
2017-08-22 14:24:23 ----D---- C:\Windows\Prefetch
2017-08-22 14:22:58 ----D---- C:\Users\Ferox\AppData\Roaming\Skype
2017-08-22 14:20:00 ----D---- C:\Windows\system32\sru
2017-08-22 14:17:46 ----RD---- C:\Program Files
2017-08-22 14:07:55 ----D---- C:\Windows\Logs
2017-08-22 13:59:25 ----HD---- C:\ProgramData
2017-08-22 13:58:32 ----RD---- C:\Program Files (x86)
2017-08-22 13:35:55 ----D---- C:\Windows\system32\SleepStudy
2017-08-22 13:25:39 ----D---- C:\Windows\System32
2017-08-22 13:25:39 ----A---- C:\Windows\system32\PerfStringBackup.INI
2017-08-22 13:19:59 ----D---- C:\Windows\system32\Tasks
2017-08-22 13:19:58 ----D---- C:\Program Files (x86)\Steam
2017-08-22 13:19:42 ----D---- C:\Windows\system32\drivers
2017-08-22 13:19:36 ----D---- C:\Windows
2017-08-22 12:51:09 ----D---- C:\Windows\AppReadiness
2017-08-22 12:50:54 ----D---- C:\Windows\GameBarPresenceWriter
2017-08-22 12:50:09 ----D---- C:\Users\Ferox\AppData\Roaming\uTorrent
2017-08-22 08:38:14 ----HD---- C:\Program Files\WindowsApps
2017-08-22 03:37:56 ----SD---- C:\ProgramData\Microsoft
2017-08-22 02:28:17 ----D---- C:\Windows\SysWOW64
2017-08-22 02:20:46 ----D---- C:\Windows\debug
2017-08-22 02:16:21 ----D---- C:\Windows\system32\catroot2
2017-08-22 02:15:04 ----SHD---- C:\Windows\Installer
2017-08-22 02:15:04 ----D---- C:\Windows\system32\DriverStore
2017-08-22 02:15:04 ----D---- C:\Windows\INF
2017-08-22 02:15:01 ----HD---- C:\Windows\ELAMBKUP
2017-08-22 02:12:41 ----HD---- C:\Windows\system32\GroupPolicy
2017-08-22 00:45:09 ----D---- C:\Users\Ferox\AppData\Roaming\TS3Client
2017-08-22 00:26:42 ----D---- C:\Users\Ferox\AppData\Roaming\discord
2017-08-21 13:24:09 ----RD---- C:\Windows\Microsoft.NET
2017-08-21 09:42:38 ----D---- C:\ProgramData\Package Cache
2017-08-20 20:07:39 ----D---- C:\Users\Ferox\AppData\Roaming\.minecraft
2017-08-20 04:31:15 ----D---- C:\Windows\system32\config
2017-08-19 23:06:06 ----D---- C:\Windows\Minidump
2017-08-18 01:58:43 ----N---- C:\Windows\system32\MpSigStub.exe
2017-08-13 16:03:30 ----SD---- C:\Users\Ferox\AppData\Roaming\Microsoft
2017-08-12 21:55:08 ----D---- C:\Windows\CbsTemp
2017-08-12 21:55:05 ----D---- C:\Windows\WinSxS
2017-08-12 12:26:00 ----D---- C:\Windows\rescache
2017-08-11 13:38:07 ----RSD---- C:\Windows\Fonts
2017-08-11 13:16:29 ----RSD---- C:\Windows\assembly
2017-08-11 13:15:52 ----D---- C:\Program Files (x86)\Microsoft.NET
2017-08-11 13:11:49 ----SD---- C:\Windows\system32\Microsoft
2017-08-11 13:09:43 ----D---- C:\Program Files (x86)\Common Files
2017-08-11 13:03:14 ----D---- C:\Program Files\Common Files\microsoft shared
2017-08-10 19:35:56 ----D---- C:\Users\Ferox\AppData\Roaming\REC
2017-08-10 11:08:25 ----D---- C:\Windows\system32\CatRoot
2017-08-09 23:18:31 ----D---- C:\Windows\SYSWOW64\MUI
2017-08-09 23:18:31 ----D---- C:\Windows\SYSWOW64\cs-CZ
2017-08-09 23:18:31 ----D---- C:\Windows\system32\MUI
2017-08-09 23:18:31 ----D---- C:\Windows\system32\cs-CZ
2017-08-09 23:18:18 ----D---- C:\Windows\System
2017-08-09 23:17:44 ----D---- C:\Windows\Tasks
2017-08-09 23:17:42 ----D---- C:\Windows\system32\Macromed
2017-08-09 23:17:40 ----D---- C:\Windows\SYSWOW64\Macromed
2017-08-09 23:17:04 ----D---- C:\Windows\Registration
2017-08-09 23:16:29 ----D---- C:\Program Files (x86)\Internet Explorer
2017-08-09 21:28:50 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-08-09 21:25:05 ----SHD---- C:\System Volume Information
2017-08-09 02:28:18 ----D---- C:\Windows\SYSWOW64\WinMetadata
2017-08-09 02:28:18 ----D---- C:\Windows\SYSWOW64\en-US
2017-08-09 02:28:18 ----D---- C:\Windows\system32\WinMetadata
2017-08-09 02:28:18 ----D---- C:\Windows\system32\WinBioPlugIns
2017-08-09 02:28:18 ----D---- C:\Windows\system32\oobe
2017-08-09 02:28:18 ----D---- C:\Windows\system32\en-US
2017-08-09 02:28:17 ----RD---- C:\Windows\ImmersiveControlPanel
2017-08-09 02:28:17 ----D---- C:\Windows\ShellExperiences
2017-08-09 02:28:17 ----D---- C:\Windows\AppPatch
2017-08-09 02:28:17 ----D---- C:\Program Files\Windows Photo Viewer
2017-08-09 02:28:17 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-08-09 02:28:15 ----D---- C:\Windows\system32\drivers\UMDF
2017-08-08 21:44:12 ----D---- C:\Windows\system32\MRT
2017-08-08 21:43:09 ----AC---- C:\Windows\system32\MRT.exe
2017-08-08 14:07:25 ----D---- C:\Windows\LiveKernelReports
2017-08-03 21:36:04 ----D---- C:\ProgramData\Skype
2017-08-03 17:23:53 ----D---- C:\Program Files (x86)\Rockstar Games
2017-08-03 17:23:44 ----D---- C:\Program Files\Rockstar Games
2017-07-31 17:15:09 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2017-07-30 02:43:34 ----D---- C:\Users\Ferox\AppData\Roaming\Adobe
2017-07-29 18:23:50 ----D---- C:\Program Files\Common Files

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 aswRvrt;aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [2017-07-17 84392]
R0 edevmon;edevmon; C:\Windows\system32\DRIVERS\edevmon.sys [2017-05-04 107344]
R0 fltsrv;Acronis Storage Filter Management; C:\Windows\system32\DRIVERS\fltsrv.sys [2017-07-15 160600]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\Windows\system32\drivers\iorate.sys [2017-03-18 49568]
R0 snapman;Acronis Snapshots Manager; C:\Windows\system32\DRIVERS\snapman.sys [2017-07-15 339288]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2017-07-17 585608]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2017-06-22 132824]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2017-05-04 178056]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2017-05-04 78192]
R1 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2017-05-04 101648]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\Windows\system32\drivers\mbae64.sys [2017-06-27 77376]
R1 MpKsl26ba1fc9;MpKsl26ba1fc9; \??\C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B0BC967A-B50E-4677-ACF6-DBC4467AADF9}\MpKsl26ba1fc9.sys [2017-08-22 44928]
R1 SpyEmrg;Spy Emergency Driver; C:\Windows\System32\Drivers\spyemrg.sys [2011-04-21 17240]
R1 SpyShelter;SpyShelter; \??\C:\Program Files (x86)\SpyShelter Firewall\SpyShelter.sys [2017-07-10 1877384]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2017-08-09 146704]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\Windows\System32\drivers\registry.sys [2017-03-18 14336]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2017-05-04 50752]
R2 MBAMChameleon;MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [2017-08-21 188352]
R3 amdkmdag;amdkmdag; C:\Windows\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atikmdag.sys [2017-05-16 36558208]
R3 amdkmdap;amdkmdap; C:\Windows\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atikmpag.sys [2017-05-16 528760]
R3 AtiHDAudioService;@oem5.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdWT6.sys [2016-12-12 110088]
R3 dtlitescsibus;@oem11.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2017-08-10 30264]
R3 dtliteusbbus;@oem12.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\Windows\System32\drivers\dtliteusbbus.sys [2017-08-10 47672]
R3 IOMap;IOMap; \??\C:\Windows\system32\drivers\IOMap64.sys [2017-01-11 35352]
R3 keycrypt;keycrypt; C:\Windows\system32\DRIVERS\KeyCrypt64.sys [2017-03-22 161408]
R3 MBAMFarflt;MBAMFarflt; \??\C:\Windows\system32\drivers\farflt.sys [2017-08-22 101784]
R3 MBAMProtection;MBAMProtection; \??\C:\Windows\system32\drivers\mbam.sys [2017-08-22 45472]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2017-08-22 253856]
R3 MBAMWebProtection;MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [2017-08-22 93600]
R3 phantomtap;@oem10.inf,%DeviceDescription%;Phantom TAP-Windows Adapter V9; C:\Windows\System32\drivers\phantomtap.sys [2017-07-13 45056]
R3 SpyEmrgGuard;Spy Emergency Real-Time Shield Driver; C:\Windows\System32\Drivers\spyemrg_guard.sys [2015-03-09 19768]
S0 eelam;eelam; C:\Windows\system32\DRIVERS\eelam.sys [2017-05-04 14880]
S0 megasas2i;megasas2i; C:\Windows\System32\drivers\MegaSas2i.sys [2017-03-18 64416]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\Windows\System32\drivers\scmbus.sys [2017-03-18 91040]
S2 CldFlt;Windows Cloud Files Filter Driver; C:\Windows\system32\drivers\cldflt.sys [2017-03-18 12288]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\Windows\System32\drivers\AcpiDev.sys [2017-03-18 20480]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\Windows\system32\drivers\applockerfltr.sys [2017-03-18 17920]
S3 AppvStrm;@%systemroot%\system32\drivers\AppvStrm.sys,-101; C:\Windows\system32\drivers\AppvStrm.sys [2017-03-20 127904]
S3 AppvVemgr;@%systemroot%\system32\drivers\AppvVemgr.sys,-101; C:\Windows\system32\drivers\AppvVemgr.sys [2017-03-20 161696]
S3 AppvVfs;@%systemroot%\system32\drivers\AppvVfs.sys,-101; C:\Windows\system32\drivers\AppvVfs.sys [2017-03-20 143776]
S3 aswbidsdriver;aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [2017-07-29 320008]
S3 aswbidsh;aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [2017-07-29 198976]
S3 aswblog;aswblog; C:\Windows\system32\drivers\aswbloga.sys [2017-07-29 343288]
S3 aswbuniv;aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [2017-07-29 57728]
S3 aswHwid;aswHwid; C:\Windows\system32\drivers\aswHwid.sys [2017-07-17 46984]
S3 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2017-07-17 41800]
S3 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2017-07-17 110352]
S3 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2017-08-09 1015880]
S3 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2017-07-17 198768]
S3 aswVmm;aswVmm; C:\Windows\system32\drivers\aswVmm.sys [2017-07-17 361336]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\Windows\System32\drivers\CAD.sys [2017-03-18 53664]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\Windows\system32\drivers\hvservice.sys [2017-03-18 74648]
S3 cht4iscsi;cht4iscsi; C:\Windows\System32\drivers\cht4sx64.sys [2017-03-18 347032]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\Windows\System32\drivers\cht4vx64.sys [2017-03-18 2104224]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\Windows\System32\drivers\iagpio.sys [2017-03-18 33280]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [2017-03-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\Windows\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-03-18 85504]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-03-18 168448]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\Windows\System32\drivers\IndirectKmd.sys [2017-03-18 36864]
S3 irda;IrDA; C:\Windows\system32\drivers\irda.sys [2017-03-18 120320]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\Windows\System32\drivers\mausbhost.sys [2017-03-18 405408]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\Windows\System32\drivers\mausbip.sys [2017-03-18 51104]
S3 MsSecFlt;@%SystemRoot%\System32\Drivers\mssecflt.sys,-1001; C:\Windows\system32\drivers\mssecflt.sys [2017-03-20 230816]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\Windows\system32\drivers\NetAdapterCx.sys [2017-03-18 122368]
S3 netvsc;netvsc; C:\Windows\System32\drivers\netvsc.sys [2017-04-19 118784]
S3 nvdimmn;@nvdimmn.inf,%nvdimmn.SvcDesc%;Microsoft NVDIMM-N device driver; C:\Windows\System32\drivers\nvdimmn.sys [2017-03-18 80896]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\Windows\System32\drivers\pmem.sys [2017-03-18 101376]
S3 ReFS;ReFS; C:\Windows\system32\drivers\ReFS.sys [2017-03-18 1735584]
S3 SDFRd;@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector; C:\Windows\System32\drivers\SDFRd.sys [2017-03-18 31128]
S3 SpatialGraphFilter;Holographic Spatial Graph Filter; C:\Windows\System32\drivers\SpatialGraphFilter.sys [2017-03-20 40352]
S3 SpyEmrgAccess;Spy Emergency OnAccess Driver; C:\Windows\System32\Drivers\spyemrg_access.sys [2011-04-21 24408]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AcrSch2Svc;Služba Acronis Scheduler2; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [2015-12-25 943280]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2017-05-16 551808]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-07-29 263312]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2017-08-02 389312]
R2 AviraPhantomVPN;Avira Phantom VPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [2017-07-13 322616]
R2 CDPUserSvc_380b9;CDPUserSvc_380b9; C:\Windows\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\dusmsvc.dll
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Security\ekrn.exe [2017-06-13 2625368]
R2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc); C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [2017-03-30 21312]
R2 MBAMService;Malwarebytes Service; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [2017-05-09 4470736]
R2 OneSyncSvc_380b9;OneSyncSvc_380b9; C:\Windows\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 SecurityHealthService;@%systemroot%\system32\SecurityHealthAgent.dll,-1002; C:\Windows\system32\SecurityHealthService.exe [2017-07-07 336320]
R2 SpyEmrgHealth;Spy Emergency Health Check; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencyHealth.exe [2015-03-20 379192]
R2 SpyEmrgSrv;Spy Emergency Engine Service; C:\Program Files\NETGATE\Spy Emergency\SpyEmergencySrv.exe [2015-03-20 3335008]
R3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-07-18 1608480]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" = %SystemRoot%\System32\CDPUserSvc.dll
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-06-01 317400]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-07-29 7430992]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; %SystemRoot%\system32\svchost.exe -k DevicesFlow;"ServiceDll" = %SystemRoot%\System32\DevicesFlowBroker.dll
S3 DevicesFlowUserSvc_380b9;DevicesFlowUserSvc_380b9; C:\Windows\system32\svchost.exe -k DevicesFlow;"ServiceDll" =
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2017-07-03 2291904]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2016-12-27 395024]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2017-02-10 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll" = %SystemRoot%\system32\FrameServer.dll
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\hvhostsvc.dll
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; %SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\IpxlatCfg.dll
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\irmon.dll
S3 MessagingService_380b9;MessagingService_380b9; C:\Windows\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; %SystemRoot%\system32\svchost.exe -k netsvcs;"ServiceDll" = %SystemRoot%\System32\NaturalAuth.dll
S3 PimIndexMaintenanceSvc_380b9;PimIndexMaintenanceSvc_380b9; C:\Windows\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\RMapi.dll
S3 SEMgrSvc;@%SystemRoot%\System32\SEMgrSvc.dll,-1001; %SystemRoot%\system32\svchost.exe -k LocalService;"ServiceDll" = %SystemRoot%\system32\SEMgrSvc.dll
S3 Sense;@%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2017-03-20 3913064]
S3 spectrum;@%systemroot%\system32\spectrum.exe,-101; C:\Windows\system32\spectrum.exe [2017-03-18 891904]
S4 AppVClient;@%systemroot%\system32\AppVClient.exe,-102; C:\Windows\system32\AppVClient.exe [2017-07-07 846752]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll" = %systemroot%\system32\Windows.SharedPC.AccountManager.dll

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118253
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, nejspíše nějaký RAT nebo něco takovéh

#3 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Feroxik
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 22 srp 2017 13:29

Re: Prosím o kontrolu, nejspíše nějaký RAT nebo něco takovéh

#4 Příspěvek od Feroxik »

Omlouvám se za pozdní odpověď. tady je log z AdwCleaneru.
# AdwCleaner 7.0.1.0 - Logfile created on Wed Aug 23 00:52:33 2017
# Updated on 2017/05/08 by Malwarebytes
# Database: 07-31-2017.1
# Running on Windows 10 Pro (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Adware.Heuristic, \Downloaded Installers\M928366
PUP.Adware.Heuristic, \Installer\M928366


***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Adware.Heuristic, [Key] - HKCU\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\M928366


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries.

*************************



########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118253
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, nejspíše nějaký RAT nebo něco takovéh

#5 Příspěvek od Rudy »

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Feroxik
Návštěvník
Návštěvník
Příspěvky: 4
Registrován: 22 srp 2017 13:29

Re: Prosím o kontrolu, nejspíše nějaký RAT nebo něco takovéh

#6 Příspěvek od Feroxik »

Ani jeden log se mi sem nevešel, oba jsou přiloženy v rar souboru.
Přílohy
Desktop.rar
Oba logy
(32.97 KiB) Staženo 46 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118253
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu, nejspíše nějaký RAT nebo něco takovéh

#7 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
C:\Users\Ferox\AppData\Local\Temp
ContextMenuHandlers1: [STShellMenu] -> {F32C83B9-DF1D-42AD-9741-C52909703957} => C:\Program Files (x86)\Spyware Terminator\STShell64.dll -> No File
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Users\Ferox\Downloads\sssssssssssssssssssssssssssss\rarext.dll -> No File
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Users\Ferox\Downloads\sssssssssssssssssssssssssssss\rarext32.dll -> No File
ContextMenuHandlers6: [STShellMenu] -> {F32C83B9-DF1D-42AD-9741-C52909703957} => C:\Program Files (x86)\Spyware Terminator\STShell64.dll -> No File
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Users\Ferox\Downloads\sssssssssssssssssssssssssssss\rarext.dll -> No File
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Users\Ferox\Downloads\sssssssssssssssssssssssssssss\rarext32.dll -> No File

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Podle logu máte v PC 2 funkční antiviry. Eset a Avast. Jeden si vyberte a druhý odinstalujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět