Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím o kontrolu logu, pomalý notebook, nefunkční antimalwa

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
pepaa
Návštěvník
Návštěvník
Příspěvky: 98
Registrován: 01 kvě 2007 18:51
Kontaktovat uživatele:

Prosím o kontrolu logu, pomalý notebook, nefunkční antimalwa

#1 Příspěvek od pepaa »

Dobrý den,
prosím Vás mám problem s notebookem. Načítá se velmi pomalu cokoliv. Po nejnovější aktualizaci SKYPE nefunguje, píše to něcove smyslu, že to nepracuje správně, či co, nevidím antiirus Avira a mám pocit, že je tam někde schovaný vir. Když se zapne notebook, píše to i chybovou hlášku, že se Anti-malware nemohl spojit se serverem. Skype sem teda odinstaloval a teď nevím co dál všechno a jaký postup. Přikládám log z RSIT:

Děkuji za jakoukoli pomoc.

Logfile of random's system information tool 1.16 (written by random/random)
Run by Marie at 2017-06-16 14:06:41
Microsoft Windows 10 Home
System drive C: has 357 GB (83%) free of 432 GB
Total RAM: 4040 MB (42% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:06:52, on 16.06.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\Program Files (x86)\Lenovo\Power2Go\Power2GoExpress.exe
C:\Users\Marie\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\USB Camera\VM331STI.EXE
C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files\trend micro\Marie_RSITx64 (2).exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/?gfe_rd=cr&ei=Bgu ... gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [331BigDog] "C:\Program Files (x86)\USB Camera\VM331STI.EXE"
O4 - HKLM\..\Run: [UpdateP2GShortCut] "C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
O4 - HKLM\..\Run: [YouCam Mirage] "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
O4 - HKLM\..\Run: [YouCam Tray] "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe" /s
O4 - HKLM\..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
O4 - HKLM\..\Run: [emsisoft anti-malware] "C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe" /d=60
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files (x86)\Lenovo\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [HP Deskjet 3050 J610 series (NET)] "C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN1353B53Z05HX:NW" -scfn "HP Deskjet 3050 J610 series (NET)" -AutoStart 1
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Marie\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: Sledovat výstrahy inkoustu - HP Deskjet 3050 J610 series (Síť).lnk = ?
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&eslat do aplikace OneNote - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Odeslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do aplikace OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O9 - Extra 'Tools' menuitem: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - (no file)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{8885be12-0739-421c-96b0-a3a7a8cc9b2c}: NameServer = 217.30.64.53,8.8.8.8
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - (no file)
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Emsisoft Anti-Malware 8.0 - Service (a2AntiMalware) - Emsisoft Ltd - C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)

--
End of file - 11062 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files\iPod\bin\iPodService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe" avshadowcontrol0_0000138c
C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:30
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
C:\WINDOWS\System32\dwm.exe
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\taskhostw.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\Explorer.EXE
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\System32\InstallAgentUserBroker.exe -Embedding
"C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe"
"C:\Program Files (x86)\Lenovo\Energy Management\utility.exe"
"C:\Program Files\iTunes\iTunesHelper.exe"
"C:\Windows\System32\igfxtray.exe"
"C:\Windows\System32\hkcmd.exe"
"C:\Windows\System32\igfxpers.exe"
"C:\Program Files (x86)\Lenovo\Power2Go\Power2GoExpress.exe" /Startup
"C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN1353B53Z05HX:NW" -scfn "HP Deskjet 3050 J610 series (NET)" -AutoStart 1
"C:\Users\Marie\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\WINDOWS\system32\RunDll32.exe" "C:\Program Files\HP\HP Deskjet 3050 J610 series\bin\HPStatusBL.dll",RunDLLEntry SERIALNUMBER=CN1353B53Z05HX;CONNECTION=NW;MONITOR=1;
"C:\Program Files (x86)\USB Camera\VM331STI.EXE"
"C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPNetworkCommunicatorCom.exe" -Embedding
"C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe"
"C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe"
"C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe"
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
C:\WINDOWS\System32\fontdrvhost.exe
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\CCleaner\CCleaner64.exe" /monitor
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
C:\WINDOWS\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}
C:\Windows\System32\smartscreen.exe -Embedding
C:\WINDOWS\system32\AUDIODG.EXE 0x44
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Marie\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Marie\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=58.0.3029.110 --initial-client-data=0x1a0,0x1a4,0x1a8,0x19c,0x1ac,0x7ffcf8f92968,0x7ffcf8f92980,0x7ffcf8f92990
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=1000 --on-initialized-event-handle=436 --parent-handle=432 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=772 --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,19,23,41,61,74 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x8086 --gpu-device-id=0x0106 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.4459 --gpu-driver-date=5-19-2016 --service-request-channel-token=6DEC5B2C6924A21AA014A70423DC3CB0 --mojo-platform-channel-handle=1408 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=772 --primordial-pipe-token=7BAC9E72A62C8663F0812609D380E633 --lang=cs --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=7BAC9E72A62C8663F0812609D380E633 --renderer-client-id=4 --mojo-platform-channel-handle=2588 /prefetch:1
C:\WINDOWS\system32\vssvc.exe
C:\WINDOWS\System32\svchost.exe -k swprv
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=772 --primordial-pipe-token=00E21EF5012B8EADEE6B01BCF7D9DF83 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553 --service-request-channel-token=00E21EF5012B8EADEE6B01BCF7D9DF83 --renderer-client-id=8 --mojo-platform-channel-handle=2164 /prefetch:1
C:\WINDOWS\system32\msiexec.exe /V
"C:\Users\Marie\Downloads\RSITx64 (2).exe"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 640 644 652 8192 648

====== Scheduled tasks folder ======

C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\HP Deskjet 3050 J610 series.exe - C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HP Deskjet 3050 J610 series.exe -prfn "HP Deskjet 3050 J610 series (Síť)" -showSplashScreen
C:\WINDOWS\system32\tasks\HPCustParticipation HP Deskjet 3050 J610 series - "C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\HPCustPartic.exe" /UA 9.5 /DDV 0x0805
C:\WINDOWS\system32\tasks\MirageAgent - C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task - C:\Users\Marie\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task v2 - %localappdata%\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{BC28E954-E868-4473-881B-A03E673F1DCE} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\{079E283D-8661-4B6E-A9A5-EE596CED9A58} - "c:\windows\system32\launchwinapp.exe" http://ui.skype.com/ui/0/7.23.0.105.259 ... age=tsBing
C:\WINDOWS\system32\tasks\{0F4D32CA-64AC-44EE-9DB8-92AC436CB181} - "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/ui/0/7.0.0.102/cs/a ... age=tsBing
C:\WINDOWS\system32\tasks\{265EFFD4-14CA-4DA3-8FC4-05E8C5FEBE11} - "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/ui/0/7.0.0.102/cs/a ... age=tsBing
C:\WINDOWS\system32\tasks\{7659A57F-3930-409A-AA59-7617556B31F8} - "c:\windows\system32\launchwinapp.exe" https://www.skype.com/go/downloading?so ... rror=12002
C:\WINDOWS\system32\tasks\{76B6B6ED-D882-48C9-9FEF-7F267C116780} - "c:\windows\system32\launchwinapp.exe" https://ui.skype.com/ui/0/7.29.64.102/c ... age=tsBing
C:\WINDOWS\system32\tasks\{A871A492-03E8-441E-AD29-A35F14135AA7} - "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://ui.skype.com/ui/0/6.7.0.102/cs/a ... age=tsBing
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\WINDOWS\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval - C:\WINDOWS\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe RebootDialog
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - C:\windows\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - C:\windows\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\WINDOWS\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\WINDOWS\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemovalTools\MRT_HB - C:\WINDOWS\system32\MRT.exe /EHB /Q
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\Lpksetup - C:\windows\System32\lpksetup.exe -v
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\windows\System32\mcbuilder.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\mcupdate_scheduled - %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\WINDOWS\system32\tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - %windir%\system32\MDMAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan - c:\Program Files\Microsoft Security Client\MpCmdRun.exe Scan -ScheduleJob -RestrictPrivileges
C:\WINDOWS\system32\tasks\Apple\AppleSoftwareUpdate - C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -task

=========Google Chrome=========

C:\Users\Marie\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo
Extension coobgpohoikkiipiblmjeljniedjpjpf
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension ennkphjdgehloodpbhlhldgbnhmacadg Settings 0.2
Extension flliilndjeohchalpbbcdekjklbdgfkk 1 Avira Browser Safety 2.4.2.1650
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension gomekmidlodglbbmalcneegieacbdmki 2 avast! Online Security 9.0.2018.95
Extension hcacjajhaajmpeladcjdbgghfgfamome 1 Mixcloud Downloader 1.0
Extension ilfoopambfaclfjmpiaijnccgcmbeigi 1 FormApps Extension 2.5.0.27
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5817.313.0.5
Homepage:
default_search_provider.search_url:
C:\Users\Marie\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk]
"Path"=


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={6A1806CD-94D4-4689-BA73-E35EA1EA9990}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={6A1806CD-94D4-4689-BA73-E35EA1EA9990}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}]
"URL"=http://www.google.com/search?q={searchT ... urceid=ie7

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2013-03-06 562904]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Energy Management"=C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [2011-11-11 9753024]
"EnergyUtility"=C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [2011-11-11 5908928]
"emsisoft anti-malware"=c:\program files (x86)\emsisoft anti-malware\a2guard.exe [2016-08-14 5836888]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-09-02 3952800]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2017-01-19 176440]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2017-03-09 193112]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2017-03-09 420960]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2017-03-09 463960]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Power2GoExpress"=C:\Program Files (x86)\Lenovo\Power2Go\Power2GoExpress.exe [2011-01-03 2532648]
"HP Deskjet 3050 J610 series (NET)"=C:\Program Files\HP\HP Deskjet 3050 J610 series\Bin\ScanToPCActivationApp.exe [2012-10-17 2573416]
"OneDrive"=C:\Users\Marie\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-04-15 1518808]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2017-06-13 9803992]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"331BigDog"=C:\Program Files (x86)\USB Camera\VM331STI.EXE [2015-06-12 561672]
"UpdateP2GShortCut"=C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [2010-07-26 222504]
"YouCam Mirage"=C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [2011-01-29 136488]
"YouCam Tray"=C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [2011-01-29 228448]
"VeriFaceManager"=C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [2011-11-11 329056]
"HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2013-05-30 96056]
"avgnt"=C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [2017-06-16 918008]
"Avira SystrayStartTrigger"=C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2017-04-11 61944]
"emsisoft anti-malware"=C:\Program Files (x86)\Emsisoft Anti-Malware\a2guard.exe [2016-08-14 5836888]

C:\Users\Marie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Sledovat výstrahy inkoustu - HP Deskjet 3050 J610 series (Síť).lnk - C:\WINDOWS\system32\RunDll32.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
igfxdev.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"undockwithoutlogon"=1
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

2017-06-16 07:15:07 ----A---- C:\WINDOWS\system32\drivers\avdevprot.sys
2017-05-27 16:19:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-05-27 16:18:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-05-27 16:18:58 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-05-27 16:18:57 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-05-27 16:18:56 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-05-27 16:18:55 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-05-27 16:18:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-05-27 16:18:53 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-05-27 16:18:53 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2017-05-27 16:18:53 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-05-27 16:18:52 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2017-05-27 16:18:52 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-05-27 16:18:51 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2017-05-27 16:18:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2017-05-27 16:18:50 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-05-27 16:18:50 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-05-27 16:18:49 ----A---- C:\WINDOWS\SYSWOW64\rdpcore.dll
2017-05-27 16:18:49 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2017-05-27 16:18:49 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2017-05-27 16:18:48 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-05-27 16:18:48 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-05-27 16:18:48 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-05-27 16:18:47 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-05-27 16:18:47 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-05-27 16:18:46 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-05-27 16:18:46 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-05-27 16:18:46 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-05-27 16:18:45 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2017-05-27 16:18:45 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2017-05-27 16:18:45 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2017-05-27 16:18:44 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-05-27 16:18:44 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-05-27 16:18:44 ----A---- C:\WINDOWS\SYSWOW64\crypt32.dll
2017-05-27 16:18:43 ----A---- C:\WINDOWS\SYSWOW64\wsp_sr.dll
2017-05-27 16:18:43 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2017-05-27 16:18:43 ----A---- C:\WINDOWS\SYSWOW64\TSWorkspace.dll
2017-05-27 16:18:43 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-05-27 16:18:42 ----A---- C:\WINDOWS\SYSWOW64\mprddm.dll
2017-05-27 16:18:42 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2017-05-27 16:18:41 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-05-27 16:18:41 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2017-05-27 16:18:41 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-05-27 16:18:41 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2017-05-27 16:18:41 ----A---- C:\WINDOWS\SYSWOW64\MMDevAPI.dll
2017-05-27 16:18:41 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2017-05-27 16:18:40 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-05-27 16:18:40 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2017-05-27 16:18:40 ----A---- C:\WINDOWS\SYSWOW64\OpcServices.dll
2017-05-27 16:18:40 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-05-27 16:18:40 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2017-05-27 16:18:39 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-05-27 16:18:39 ----A---- C:\WINDOWS\SYSWOW64\kernel32.dll
2017-05-27 16:18:38 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-05-27 16:18:38 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2017-05-27 16:18:38 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-05-27 16:18:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-05-27 16:18:37 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-05-27 16:18:37 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-05-27 16:18:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-05-27 16:18:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-05-27 16:18:36 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-05-27 16:18:36 ----A---- C:\WINDOWS\SYSWOW64\tsmf.dll
2017-05-27 16:18:36 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-05-27 16:18:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-05-27 16:18:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Enumeration.dll
2017-05-27 16:18:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-05-27 16:18:35 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-05-27 16:18:35 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2017-05-27 16:18:34 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-05-27 16:18:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-05-27 16:18:34 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2017-05-27 16:18:34 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-05-27 16:18:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-05-27 16:18:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2017-05-27 16:18:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-05-27 16:18:33 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-05-27 16:18:32 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-05-27 16:18:32 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostCommon.dll
2017-05-27 16:18:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-05-27 16:18:31 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-05-27 16:18:31 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-05-27 16:18:31 ----A---- C:\WINDOWS\system32\drivers\scmbus.sys
2017-05-27 16:18:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-05-27 16:18:30 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-05-27 16:18:30 ----A---- C:\WINDOWS\SYSWOW64\CPFilters.dll
2017-05-27 16:18:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-05-27 16:18:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-05-27 16:18:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-05-27 16:18:29 ----A---- C:\WINDOWS\SYSWOW64\ReAgent.dll
2017-05-27 16:18:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-05-27 16:18:28 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-05-27 16:18:28 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-05-27 16:18:28 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-05-27 16:18:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-05-27 16:18:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-05-27 16:18:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-05-27 16:18:27 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-05-27 16:18:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-05-27 16:18:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-05-27 16:18:26 ----A---- C:\WINDOWS\SYSWOW64\AppContracts.dll
2017-05-27 16:18:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-05-27 16:18:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-05-27 16:18:25 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-05-27 16:18:25 ----A---- C:\WINDOWS\SYSWOW64\input.dll
2017-05-27 16:18:25 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-05-27 16:18:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-05-27 16:18:24 ----A---- C:\WINDOWS\SYSWOW64\dlnashext.dll
2017-05-27 16:18:24 ----A---- C:\WINDOWS\SYSWOW64\adsnt.dll
2017-05-27 16:18:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-05-27 16:18:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-05-27 16:18:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-05-27 16:18:23 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-05-27 16:18:23 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-05-27 16:18:23 ----A---- C:\WINDOWS\SYSWOW64\BluetoothApis.dll
2017-05-27 16:18:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-05-27 16:18:22 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2017-05-27 16:18:22 ----A---- C:\WINDOWS\SYSWOW64\dialclient.dll
2017-05-27 16:18:21 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2017-05-27 16:18:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-05-27 16:18:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-05-27 16:18:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-05-27 16:18:20 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2017-05-27 16:18:20 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-05-27 16:18:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-05-27 16:18:19 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2017-05-27 16:18:19 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2017-05-27 16:18:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2017-05-27 16:18:18 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-05-27 16:18:18 ----A---- C:\WINDOWS\SYSWOW64\virtdisk.dll
2017-05-27 16:18:18 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-05-27 16:18:18 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-05-27 16:18:18 ----A---- C:\WINDOWS\SYSWOW64\LocationApi.dll
2017-05-27 16:18:17 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-05-27 16:18:17 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-05-27 16:18:17 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-05-27 16:18:17 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-05-27 16:18:17 ----A---- C:\WINDOWS\SYSWOW64\setupugc.exe
2017-05-27 16:18:17 ----A---- C:\WINDOWS\SYSWOW64\credprovhost.dll
2017-05-27 16:18:16 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-05-27 16:18:16 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-05-27 16:18:16 ----A---- C:\WINDOWS\SYSWOW64\dsreg.dll
2017-05-27 16:18:16 ----A---- C:\WINDOWS\SYSWOW64\DeviceFlows.DataModel.dll
2017-05-27 16:18:15 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2017-05-27 16:18:14 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-05-27 16:18:13 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-05-27 16:18:13 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-05-27 16:18:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-05-27 16:18:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-05-27 16:18:12 ----A---- C:\WINDOWS\SYSWOW64\Geolocation.dll
2017-05-27 16:18:11 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-05-27 16:18:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-05-27 16:18:11 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-05-27 16:18:11 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-05-27 16:18:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.BlockedShutdown.dll
2017-05-27 16:18:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2017-05-27 16:18:10 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-05-27 16:18:10 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2017-05-27 16:18:10 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-05-27 16:18:10 ----A---- C:\WINDOWS\SYSWOW64\AppointmentActivation.dll
2017-05-27 16:18:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Lights.dll
2017-05-27 16:18:09 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Core.dll
2017-05-27 16:18:09 ----A---- C:\WINDOWS\SYSWOW64\ReInfo.dll
2017-05-27 16:18:09 ----A---- C:\WINDOWS\SYSWOW64\imapi2.dll
2017-05-27 16:18:09 ----A---- C:\WINDOWS\SYSWOW64\CameraCaptureUI.dll
2017-05-27 16:18:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Devices.dll
2017-05-27 16:18:08 ----A---- C:\WINDOWS\SYSWOW64\Windows.Energy.dll
2017-05-27 16:18:08 ----A---- C:\WINDOWS\SYSWOW64\SensorsApi.dll
2017-05-27 16:18:08 ----A---- C:\WINDOWS\SYSWOW64\rastlsext.dll
2017-05-27 16:18:08 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-05-27 16:18:07 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-05-27 16:18:07 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-05-27 16:18:07 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-05-27 16:18:05 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2017-05-27 16:18:04 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2017-05-27 16:18:04 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-05-27 16:18:03 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-05-27 16:18:03 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-05-27 16:18:03 ----A---- C:\WINDOWS\SYSWOW64\NaturalLanguage6.dll
2017-05-27 16:18:03 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2017-05-27 16:18:03 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-05-27 16:18:03 ----A---- C:\WINDOWS\SYSWOW64\BthTelemetry.dll
2017-05-27 16:18:02 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-05-27 16:17:57 ----A---- C:\WINDOWS\system32\mssrch.dll
2017-05-27 16:17:53 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-05-27 16:17:53 ----A---- C:\WINDOWS\system32\usocore.dll
2017-05-27 16:17:52 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-05-27 16:17:52 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-05-27 16:17:52 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-05-27 16:17:46 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2017-05-27 16:17:42 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-05-27 16:17:40 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-05-27 16:17:35 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-05-27 16:17:35 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-05-27 16:17:32 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-05-27 16:17:31 ----A---- C:\WINDOWS\system32\Windows.Media.Ocr.dll
2017-05-27 16:17:31 ----A---- C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-05-27 16:17:31 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-05-27 16:17:31 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-05-27 16:17:31 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2017-05-27 16:17:30 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-05-27 16:17:30 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-05-27 16:17:30 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-05-27 16:17:28 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-05-27 16:17:25 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-05-27 16:17:23 ----A---- C:\WINDOWS\system32\shell32.dll
2017-05-27 16:17:21 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-05-27 16:17:20 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-05-27 16:17:17 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-05-27 16:17:16 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-05-27 16:17:15 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-05-27 16:17:14 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2017-05-27 16:17:14 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-05-27 16:17:13 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-05-27 16:17:13 ----A---- C:\WINDOWS\system32\wpncore.dll
2017-05-27 16:17:13 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-05-27 16:17:12 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-05-27 16:17:12 ----A---- C:\WINDOWS\system32\services.exe
2017-05-27 16:17:12 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-05-27 16:17:11 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-05-27 16:17:11 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2017-05-27 16:17:11 ----A---- C:\WINDOWS\system32\mf.dll
2017-05-27 16:17:10 ----A---- C:\WINDOWS\system32\usercpl.dll
2017-05-27 16:17:10 ----A---- C:\WINDOWS\system32\oleaut32.dll
2017-05-27 16:17:10 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-05-27 16:17:09 ----A---- C:\WINDOWS\system32\TSWorkspace.dll
2017-05-27 16:17:09 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2017-05-27 16:17:09 ----A---- C:\WINDOWS\system32\mprddm.dll
2017-05-27 16:17:09 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2017-05-27 16:17:08 ----A---- C:\WINDOWS\system32\rdpcore.dll
2017-05-27 16:17:08 ----A---- C:\WINDOWS\system32\NgcCtnrSvc.dll
2017-05-27 16:17:08 ----A---- C:\WINDOWS\system32\mstsc.exe
2017-05-27 16:17:07 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-05-27 16:17:07 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2017-05-27 16:17:07 ----A---- C:\WINDOWS\system32\smartscreen.exe
2017-05-27 16:17:06 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2017-05-27 16:17:06 ----A---- C:\WINDOWS\system32\localspl.dll
2017-05-27 16:17:06 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2017-05-27 16:17:04 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-05-27 16:17:04 ----A---- C:\WINDOWS\system32\wiaservc.dll
2017-05-27 16:17:04 ----A---- C:\WINDOWS\system32\tsmf.dll
2017-05-27 16:17:04 ----A---- C:\WINDOWS\system32\EmailApis.dll
2017-05-27 16:17:03 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-05-27 16:17:03 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2017-05-27 16:17:03 ----A---- C:\WINDOWS\system32\mfps.dll
2017-05-27 16:17:03 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-05-27 16:17:01 ----A---- C:\WINDOWS\system32\msi.dll
2017-05-27 16:17:01 ----A---- C:\WINDOWS\system32\MMDevAPI.dll
2017-05-27 16:17:00 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-05-27 16:16:59 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-05-27 16:16:59 ----A---- C:\WINDOWS\system32\rdpudd.dll
2017-05-27 16:16:59 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-05-27 16:16:59 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-05-27 16:16:58 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-05-27 16:16:58 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2017-05-27 16:16:58 ----A---- C:\WINDOWS\system32\drivers\vwifimp.sys
2017-05-27 16:16:55 ----A---- C:\WINDOWS\system32\wpnapps.dll
2017-05-27 16:16:52 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2017-05-27 16:16:44 ----A---- C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2017-05-27 16:16:44 ----A---- C:\WINDOWS\system32\SensorsApi.dll
2017-05-27 16:16:44 ----A---- C:\WINDOWS\system32\fvewiz.dll
2017-05-27 16:16:43 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-05-27 16:16:43 ----A---- C:\WINDOWS\system32\storewuauth.dll
2017-05-27 16:16:43 ----A---- C:\WINDOWS\system32\PrintWSDAHost.dll
2017-05-27 16:16:43 ----A---- C:\WINDOWS\system32\PrintDialogs3D.dll
2017-05-27 16:16:43 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2017-05-27 16:16:42 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-05-27 16:16:42 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-05-27 16:16:42 ----A---- C:\WINDOWS\system32\Unistore.dll
2017-05-27 16:16:42 ----A---- C:\WINDOWS\system32\rdpclip.exe
2017-05-27 16:16:42 ----A---- C:\WINDOWS\system32\rastls.dll
2017-05-27 16:16:42 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2017-05-27 16:16:42 ----A---- C:\WINDOWS\system32\fvecpl.dll
2017-05-27 16:16:41 ----A---- C:\WINDOWS\system32\wksprt.exe
2017-05-27 16:16:41 ----A---- C:\WINDOWS\system32\rastlsext.dll
2017-05-27 16:16:41 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2017-05-27 16:16:41 ----A---- C:\WINDOWS\system32\drivers\raspppoe.sys
2017-05-27 16:16:41 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-05-27 16:16:40 ----A---- C:\WINDOWS\system32\rdpencom.dll
2017-05-27 16:16:40 ----A---- C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-05-27 16:16:36 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-05-27 16:16:35 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-05-27 16:16:34 ----A---- C:\WINDOWS\system32\ole32.dll
2017-05-27 16:16:34 ----A---- C:\WINDOWS\system32\msdtctm.dll
2017-05-27 16:16:33 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-05-27 16:16:33 ----A---- C:\WINDOWS\system32\d2d1.dll
2017-05-27 16:16:32 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-05-27 16:16:31 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2017-05-27 16:16:31 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-05-27 16:16:27 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-05-27 16:16:26 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-05-27 16:16:24 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-05-27 16:16:22 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-05-27 16:16:21 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-05-27 16:16:19 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-05-27 16:16:17 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-05-27 16:16:16 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-05-27 16:16:15 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-05-27 16:16:14 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-05-27 16:16:13 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-05-27 16:16:13 ----A---- C:\WINDOWS\system32\Windows.Devices.Lights.dll
2017-05-27 16:16:12 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-05-27 16:16:12 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-05-27 16:16:12 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-05-27 16:16:12 ----A---- C:\WINDOWS\system32\DWrite.dll
2017-05-27 16:16:11 ----A---- C:\WINDOWS\system32\wininet.dll
2017-05-27 16:16:11 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-05-27 16:16:11 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-05-27 16:16:11 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-05-27 16:16:11 ----A---- C:\WINDOWS\system32\dwmcore.dll
2017-05-27 16:16:10 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2017-05-27 16:16:10 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-05-27 16:16:10 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2017-05-27 16:16:10 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-05-27 16:16:09 ----A---- C:\WINDOWS\system32\wlidsvc.dll
2017-05-27 16:16:09 ----A---- C:\WINDOWS\system32\LogonController.dll
2017-05-27 16:16:08 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-05-27 16:16:08 ----A---- C:\WINDOWS\system32\Windows.Devices.Printers.dll
2017-05-27 16:16:08 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-05-27 16:16:08 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-05-27 16:16:08 ----A---- C:\WINDOWS\system32\FntCache.dll
2017-05-27 16:16:07 ----A---- C:\WINDOWS\SYSWOW64\ieapfltr.dll
2017-05-27 16:16:07 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-05-27 16:16:06 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2017-05-27 16:16:06 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2017-05-27 16:16:06 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-05-27 16:16:06 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2017-05-27 16:16:05 ----A---- C:\WINDOWS\system32\rasmans.dll
2017-05-27 16:16:05 ----A---- C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-05-27 16:16:04 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2017-05-27 16:16:04 ----A---- C:\WINDOWS\system32\Windows.Devices.Enumeration.dll
2017-05-27 16:16:04 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2017-05-27 16:16:04 ----A---- C:\WINDOWS\system32\ieproxy.dll
2017-05-27 16:16:03 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2017-05-27 16:16:03 ----A---- C:\WINDOWS\system32\thumbcache.dll
2017-05-27 16:16:03 ----A---- C:\WINDOWS\system32\msfeeds.dll
2017-05-27 16:16:03 ----A---- C:\WINDOWS\system32\browserbroker.dll
2017-05-27 16:16:02 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2017-05-27 16:16:02 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-05-27 16:16:02 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2017-05-27 16:16:02 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-05-27 16:16:01 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-05-27 16:16:01 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-05-27 16:16:00 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2017-05-27 16:16:00 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2017-05-27 16:15:59 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-05-27 16:15:59 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2017-05-27 16:15:59 ----A---- C:\WINDOWS\system32\browser_broker.exe
2017-05-27 16:15:58 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2017-05-27 16:15:58 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-05-27 16:15:58 ----A---- C:\WINDOWS\system32\ConhostV2.dll
2017-05-27 16:15:57 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2017-05-27 16:15:57 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-05-27 16:15:57 ----A---- C:\WINDOWS\system32\vbscript.dll
2017-05-27 16:15:57 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2017-05-27 16:15:56 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-05-27 16:15:56 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-05-27 16:15:55 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-05-27 16:15:55 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2017-05-27 16:15:54 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-05-27 16:15:54 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2017-05-27 16:15:53 ----A---- C:\WINDOWS\system32\Geolocation.dll
2017-05-27 16:15:53 ----A---- C:\WINDOWS\system32\credprovhost.dll
2017-05-27 16:15:52 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-05-27 16:15:52 ----A---- C:\WINDOWS\system32\CameraCaptureUI.dll
2017-05-27 16:15:51 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2017-05-27 16:15:51 ----A---- C:\WINDOWS\system32\dxtrans.dll
2017-05-27 16:15:50 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2017-05-27 16:15:50 ----A---- C:\WINDOWS\system32\iepeers.dll
2017-05-27 16:15:49 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2017-05-27 16:15:49 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2017-05-27 16:15:49 ----A---- C:\WINDOWS\system32\dialclient.dll
2017-05-27 16:15:48 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-05-27 16:15:48 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2017-05-27 16:15:48 ----A---- C:\WINDOWS\system32\mshtmled.dll
2017-05-27 16:15:48 ----A---- C:\WINDOWS\system32\DevicesFlowBroker.dll
2017-05-27 16:15:46 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2017-05-27 16:15:46 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2017-05-27 16:15:46 ----A---- C:\WINDOWS\system32\catsrvps.dll
2017-05-27 16:15:45 ----A---- C:\WINDOWS\system32\shutdownux.dll
2017-05-27 16:15:44 ----A---- C:\WINDOWS\system32\Windows.Energy.dll
2017-05-27 16:15:44 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2017-05-27 16:15:44 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-05-27 16:15:44 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-05-27 16:15:43 ----A---- C:\WINDOWS\SYSWOW64\webcheck.dll
2017-05-27 16:15:43 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2017-05-27 16:15:43 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-05-27 16:15:43 ----A---- C:\WINDOWS\system32\webcheck.dll
2017-05-27 16:15:43 ----A---- C:\WINDOWS\system32\odbcconf.dll
2017-05-27 16:15:43 ----A---- C:\WINDOWS\system32\NaturalLanguage6.dll
2017-05-27 16:15:37 ----A---- C:\WINDOWS\system32\apprepsync.dll
2017-05-27 16:15:37 ----A---- C:\WINDOWS\system32\apprepapi.dll
2017-05-27 16:15:35 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-05-27 16:15:34 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2017-05-27 16:15:34 ----A---- C:\WINDOWS\system32\ShareHost.dll
2017-05-27 16:15:34 ----A---- C:\WINDOWS\system32\dlnashext.dll
2017-05-27 16:15:34 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2017-05-27 16:15:34 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-05-27 16:15:33 ----A---- C:\WINDOWS\system32\twinui.dll
2017-05-27 16:15:33 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2017-05-27 16:15:30 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-05-27 16:15:29 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-05-27 16:15:29 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-05-27 16:15:28 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-05-27 16:15:28 ----A---- C:\WINDOWS\system32\combase.dll
2017-05-27 16:15:27 ----A---- C:\WINDOWS\system32\mispace.dll
2017-05-27 16:15:27 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-05-27 16:15:26 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-05-27 16:15:26 ----A---- C:\WINDOWS\system32\storagewmi.dll
2017-05-27 16:15:26 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-05-27 16:15:25 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-05-27 16:15:25 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-05-27 16:15:25 ----A---- C:\WINDOWS\explorer.exe
2017-05-27 16:15:24 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-05-27 16:15:24 ----A---- C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-05-27 16:15:24 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-05-27 16:15:24 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2017-05-27 16:15:24 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2017-05-27 16:15:23 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-05-27 16:15:23 ----A---- C:\WINDOWS\system32\usermgr.dll
2017-05-27 16:15:22 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-05-27 16:15:22 ----A---- C:\WINDOWS\system32\OpcServices.dll
2017-05-27 16:15:22 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-05-27 16:15:21 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-05-27 16:15:21 ----A---- C:\WINDOWS\system32\crypt32.dll
2017-05-27 16:15:20 ----A---- C:\WINDOWS\system32\wsp_sr.dll
2017-05-27 16:15:20 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-05-27 16:15:19 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-05-27 16:15:18 ----A---- C:\WINDOWS\system32\WinSetupUI.dll
2017-05-27 16:15:18 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-05-27 16:15:18 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-05-27 16:15:17 ----A---- C:\WINDOWS\system32\uReFS.dll
2017-05-27 16:15:17 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-05-27 16:15:17 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2017-05-27 16:15:17 ----A---- C:\WINDOWS\system32\audiosrv.dll
2017-05-27 16:15:16 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-05-27 16:15:15 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-05-27 16:15:15 ----A---- C:\WINDOWS\system32\kernel32.dll
2017-05-27 16:15:15 ----A---- C:\WINDOWS\system32\authui.dll
2017-05-27 16:15:14 ----A---- C:\WINDOWS\system32\resutils.dll
2017-05-27 16:15:14 ----A---- C:\WINDOWS\system32\dafBth.dll
2017-05-27 16:15:14 ----A---- C:\WINDOWS\system32\bisrv.dll
2017-05-27 16:15:13 ----A---- C:\WINDOWS\system32\rpcss.dll
2017-05-27 16:15:12 ----A---- C:\WINDOWS\system32\wbengine.exe
2017-05-27 16:15:12 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2017-05-27 16:15:11 ----A---- C:\WINDOWS\system32\VSSVC.exe
2017-05-27 16:15:11 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-05-27 16:15:11 ----A---- C:\WINDOWS\system32\securekernel.exe
2017-05-27 16:15:10 ----A---- C:\WINDOWS\system32\SpaceAgent.exe
2017-05-27 16:15:09 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-05-27 16:15:09 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2017-05-27 16:15:09 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2017-05-27 16:15:08 ----A---- C:\WINDOWS\system32\spwizeng.dll
2017-05-27 16:15:08 ----A---- C:\WINDOWS\system32\input.dll
2017-05-27 16:15:08 ----A---- C:\WINDOWS\system32\drivers\fsdepends.sys
2017-05-27 16:15:07 ----A---- C:\WINDOWS\system32\wimserv.exe
2017-05-27 16:15:07 ----A---- C:\WINDOWS\system32\wimgapi.dll
2017-05-27 16:15:07 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-05-27 16:15:06 ----A---- C:\WINDOWS\system32\spaceman.exe
2017-05-27 16:15:06 ----A---- C:\WINDOWS\system32\msxml6.dll
2017-05-27 16:15:06 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-05-27 16:15:05 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-05-27 16:15:05 ----A---- C:\WINDOWS\system32\virtdisk.dll
2017-05-27 16:15:05 ----A---- C:\WINDOWS\system32\ReAgent.dll
2017-05-27 16:15:05 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-05-27 16:15:04 ----A---- C:\WINDOWS\system32\CPFilters.dll
2017-05-27 16:15:04 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-05-27 16:15:03 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2017-05-27 16:15:03 ----A---- C:\WINDOWS\system32\bthserv.dll
2017-05-27 16:15:02 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2017-05-27 16:15:02 ----A---- C:\WINDOWS\system32\cryptui.dll
2017-05-27 16:15:01 ----A---- C:\WINDOWS\system32\vds.exe
2017-05-27 16:15:01 ----A---- C:\WINDOWS\system32\BluetoothApis.dll
2017-05-27 16:15:00 ----A---- C:\WINDOWS\system32\winlogon.exe
2017-05-27 16:15:00 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-05-27 16:15:00 ----A---- C:\WINDOWS\system32\Family.Client.dll
2017-05-27 16:14:59 ----A---- C:\WINDOWS\system32\RecoveryDrive.exe
2017-05-27 16:14:58 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2017-05-27 16:14:58 ----A---- C:\WINDOWS\system32\LocationApi.dll
2017-05-27 16:14:57 ----A---- C:\WINDOWS\system32\SettingsHandlers_ClosedCaptioning.dll
2017-05-27 16:14:57 ----A---- C:\WINDOWS\system32\imapi2.dll
2017-05-27 16:14:56 ----A---- C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-05-27 16:14:56 ----A---- C:\WINDOWS\system32\oleacc.dll
2017-05-27 16:14:56 ----A---- C:\WINDOWS\system32\appidsvc.dll
2017-05-27 16:14:56 ----A---- C:\WINDOWS\system32\adsnt.dll
2017-05-27 16:14:55 ----A---- C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll
2017-05-27 16:14:55 ----A---- C:\WINDOWS\system32\Windows.Media.Devices.dll
2017-05-27 16:14:55 ----A---- C:\WINDOWS\system32\ConsentUX.dll
2017-05-27 16:14:55 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2017-05-27 16:14:54 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-05-27 16:14:54 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-05-27 16:14:54 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-05-27 16:14:54 ----A---- C:\WINDOWS\system32\BthTelemetry.dll
2017-05-27 16:14:54 ----A---- C:\WINDOWS\system32\appidcertstorecheck.exe
2017-05-27 16:14:53 ----A---- C:\WINDOWS\SYSWOW64\UIRibbonRes.dll
2017-05-27 16:14:53 ----A---- C:\WINDOWS\system32\vaultcli.dll
2017-05-27 16:14:53 ----A---- C:\WINDOWS\system32\UIRibbonRes.dll
2017-05-27 15:38:39 ----D---- C:\ProgramData\Wondershare
2017-05-27 15:38:39 ----D---- C:\Program Files (x86)\Wondershare

====== List of files/folders modified in the last 1 month ======

2017-06-16 14:06:52 ----D---- C:\WINDOWS\Prefetch
2017-06-16 14:06:50 ----SHD---- C:\WINDOWS\Installer
2017-06-16 14:06:50 ----D---- C:\WINDOWS\Temp
2017-06-16 14:06:49 ----SHD---- C:\Config.Msi
2017-06-16 14:06:49 ----D---- C:\Program Files\trend micro
2017-06-16 14:06:48 ----D---- C:\ProgramData\Microsoft Help
2017-06-16 14:06:34 ----D---- C:\WINDOWS\system32\config
2017-06-16 14:04:31 ----D---- C:\WINDOWS\WinSxS
2017-06-16 14:04:31 ----D---- C:\WINDOWS\SysWOW64
2017-06-16 14:04:25 ----D---- C:\WINDOWS\system32\catroot2
2017-06-16 14:04:20 ----D---- C:\WINDOWS\CbsTemp
2017-06-16 13:57:34 ----HD---- C:\Program Files\WindowsApps
2017-06-16 13:48:07 ----D---- C:\Windows
2017-06-16 13:47:20 ----D---- C:\WINDOWS\AppReadiness
2017-06-16 13:44:59 ----RD---- C:\Program Files (x86)\Skype
2017-06-16 13:44:59 ----D---- C:\Program Files (x86)\Common Files
2017-06-16 13:44:53 ----D---- C:\ProgramData\Skype
2017-06-16 13:37:40 ----D---- C:\ProgramData\VeriFace
2017-06-16 13:37:18 ----AD---- C:\Program Files (x86)\Emsisoft Anti-Malware
2017-06-16 13:35:28 ----D---- C:\WINDOWS\system32\sru
2017-06-16 07:25:30 ----SHD---- C:\System Volume Information
2017-06-16 07:15:57 ----D---- C:\WINDOWS\system32\drivers
2017-06-14 21:46:34 ----D---- C:\WINDOWS\system32\SleepStudy
2017-06-13 13:20:58 ----RD---- C:\WINDOWS\Microsoft.NET
2017-06-13 13:20:57 ----RD---- C:\WINDOWS\assembly
2017-06-11 20:44:29 ----D---- C:\Users\Marie\AppData\Roaming\Skype
2017-06-10 07:12:00 ----D---- C:\WINDOWS\system32\Tasks
2017-06-10 07:08:51 ----D---- C:\WINDOWS\debug
2017-06-10 06:56:59 ----D---- C:\AdwCleaner
2017-06-09 12:57:23 ----D---- C:\WINDOWS\system32\appraiser
2017-06-03 08:43:19 ----D---- C:\WINDOWS\INF
2017-06-03 08:36:03 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2017-05-30 07:03:28 ----D---- C:\WINDOWS\LiveKernelReports
2017-05-28 19:46:44 ----D---- C:\WINDOWS\System32
2017-05-28 17:20:36 ----D---- C:\WINDOWS\rescache
2017-05-27 20:33:29 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-27 20:33:19 ----HD---- C:\ProgramData
2017-05-27 20:33:17 ----RD---- C:\Program Files (x86)
2017-05-27 20:33:01 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-05-27 20:32:51 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2017-05-27 16:47:44 ----D---- C:\WINDOWS\system32\DriverStore
2017-05-27 16:43:40 ----D---- C:\WINDOWS\SYSWOW64\wbem
2017-05-27 16:43:40 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-CS
2017-05-27 16:43:40 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2017-05-27 16:43:39 ----SD---- C:\WINDOWS\SYSWOW64\F12
2017-05-27 16:43:39 ----D---- C:\WINDOWS\SYSWOW64\Dism
2017-05-27 16:43:39 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-05-27 16:43:30 ----D---- C:\WINDOWS\system32\wbem
2017-05-27 16:43:29 ----SD---- C:\WINDOWS\system32\F12
2017-05-27 16:43:29 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2017-05-27 16:43:29 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-05-27 16:43:29 ----D---- C:\WINDOWS\system32\oobe
2017-05-27 16:43:29 ----D---- C:\WINDOWS\system32\migration
2017-05-27 16:43:29 ----D---- C:\WINDOWS\system32\inetsrv
2017-05-27 16:43:28 ----D---- C:\WINDOWS\system32\cs-CZ
2017-05-27 16:43:14 ----D---- C:\WINDOWS\ShellExperiences
2017-05-27 16:43:14 ----D---- C:\WINDOWS\Provisioning
2017-05-27 16:43:14 ----D---- C:\WINDOWS\PolicyDefinitions
2017-05-27 16:43:08 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-05-27 16:43:08 ----RD---- C:\Program Files\Windows Defender
2017-05-27 16:43:08 ----D---- C:\Program Files\Windows Photo Viewer
2017-05-27 16:43:08 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-05-27 16:43:08 ----D---- C:\Program Files (x86)\Windows Defender
2017-05-24 15:52:48 ----D---- C:\WINDOWS\system32\MRT
2017-05-23 11:02:23 ----AC---- C:\WINDOWS\system32\MRT.exe

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 avdevprot;avdevprot; C:\WINDOWS\system32\DRIVERS\avdevprot.sys [2017-06-16 60920]
R0 fbfmon;fbfmon; C:\WINDOWS\system32\drivers\fbfmon.sys [2011-11-11 57952]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-02 48992]
R0 LHDmgr;LHDmgr; C:\WINDOWS\System32\DRIVERS\LhdX64.sys [2011-11-11 39008]
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2017-06-16 164824]
R1 avkmgr;avkmgr; C:\WINDOWS\system32\DRIVERS\avkmgr.sys [2017-03-02 44488]
R1 BPntDrv;BPntDrv; C:\WINDOWS\system32\drivers\BPntDrv.sys [2011-11-11 13408]
R1 epp64;epp64; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\epp64.sys [2016-08-14 138504]
R2 avgntflt;avgntflt; C:\WINDOWS\system32\DRIVERS\avgntflt.sys [2017-06-16 167504]
R2 avnetflt;avnetflt; C:\WINDOWS\system32\DRIVERS\avnetflt.sys [2017-03-02 88488]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R3 ACPIVPC;@oem15.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\WINDOWS\System32\drivers\AcpiVpc.sys [2011-11-11 29792]
R3 BCM43XX;@netbc64.inf,%BCM43XX_Service_DispName%;Broadcom 802.11 – ovladač síťového adaptéru; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2016-07-16 7585280]
R3 clwvd;@oem40.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\WINDOWS\system32\DRIVERS\clwvd.sys [2011-01-29 31088]
R3 CnxtHdAudService;@oem31.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDRT64.sys [2011-02-14 1581184]
R3 L1C;@netl1c63x64.inf,%L1C.Service.DispName%;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\WINDOWS\System32\drivers\L1C63x64.sys [2016-07-16 121344]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2016-11-03 175616]
R3 RTSUER;@oem17.inf,%RtsUER%;Realtek USB Card Reader - UER; C:\WINDOWS\system32\Drivers\RtsUer.sys [2015-12-10 402960]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2015-09-02 44192]
R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Ovladač digitálního fotoaparátu pro sériový port; C:\WINDOWS\system32\DRIVERS\serscan.sys [2016-07-16 12800]
R3 SynTP;@oem92.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-09-02 630944]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-11-03 64352]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2017-04-28 88416]
S1 A2DDA;A2 Direct Disk Access Support Driver; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\a2ddax64.sys [2013-03-28 26176]
S3 a2acc;a2acc; \??\C:\PROGRAM FILES (X86)\EMSISOFT ANTI-MALWARE\a2accx64.sys [2014-05-12 71472]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 dg_ssudbus;@oem97.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2016-09-05 131712]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-11-03 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 Netaapl;@oem51.inf,%Netaapl.Service.DispName%;Apple Mobile Device Ethernet Service; C:\WINDOWS\System32\drivers\netaapl64.sys [2014-08-16 23040]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]
S3 ssudmdm;@oem98.inf,%ssud.Service.Name%;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [2016-09-05 165504]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys [2016-07-16 108544]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [2017-06-16 490968]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [2017-06-16 490968]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; %windir%\system32\svchost.exe -k apphost;"ServiceDll" = %windir%\system32\inetsrv\apphostsvc.dll
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2016-09-22 83768]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CDPUserSvc_7544806;CDPUserSvc_7544806; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-12-21 325656]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2016-11-03 26112]
R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360]
R2 OneSyncSvc_7544806;Hostitel synchronizace_7544806; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-09-02 247968]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2017-01-19 651576]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 PimIndexMaintenanceSvc_7544806;Data kontaktů_7544806; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\RMapi.dll
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\TimeBrokerServer.dll
S2 a2AntiMalware;Emsisoft Anti-Malware 8.0 - Service; C:\Program Files (x86)\Emsisoft Anti-Malware\a2service.exe [2016-08-14 7084784]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avmailc7.exe [2017-06-16 1128432]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\AntiVir Desktop\avwebg7.exe [2017-06-16 1524216]
S2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2017-04-11 350120]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" = %SystemRoot%\System32\CDPUserSvc.dll
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll" = %SystemRoot%\system32\FrameServer.dll
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\hvhostsvc.dll
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\irmon.dll
S3 MessagingService_7544806;Služba zasílání zpráv_7544806; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S4 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll" = %systemroot%\system32\Windows.SharedPC.AccountManager.dll

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118254
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím o kontrolu logu, pomalý notebook, nefunkční antim

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět