Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Viry v PC a nechtěný One systeme Care Launcher

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Daveson
Návštěvník
Návštěvník
Příspěvky: 140
Registrován: 06 kvě 2008 12:38
Bydliště: Zlín
Kontaktovat uživatele:

Viry v PC a nechtěný One systeme Care Launcher

#1 Příspěvek od Daveson »

Logfile of random's system information tool 1.16 (written by random/random)
Run by pavilion at 2017-07-24 06:52:42
Microsoft Windows 10 Home
System drive C: has 562 GB (60%) free of 939 GB
Total RAM: 4095 MB (42% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:52:54, on 24.7.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0953)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\TeamViewer\TeamViewer.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe
C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files (x86)\4-Day Forecast\4-Day Forecast\4-Day Forecast.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\PROGRA~2\RAPTRI~1\Raptr\raptr.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
C:\PROGRA~2\RAPTRI~1\Raptr\raptr_im.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\WINDOWS\SysWOW64\ctfmon.exe
C:\Program Files\trend micro\pavilion_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: TSearch - {24744B0A-9F0D-49A6-8A90-D7EF6EAD5137} - C:\Program Files (x86)\MefarchIE\k7eRXmV6.dll (file missing)
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: YoutubeAdBlock - {C0D38E5A-7CF8-4105-8FE8-31B81443A114} - (no file)
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [4-Day Forecast] "C:\Program Files (x86)\4-Day Forecast\4-Day Forecast\4-Day Forecast.exe" /Startup
O4 - HKLM\..\Run: [Raptr] "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
O4 - HKLM\..\Run: [PlaysTV] "C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe" --startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
O4 - HKLM\..\Run: [NoterSave] "C:\Program Files (x86)\NoterSave\NoterSave.exe"
O4 - HKCU\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [iCloudDrive] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
O4 - HKCU\..\Run: [NETGEARGenie] "C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe" -mini -redirect
O4 - HKCU\..\Run: [DAEMON Tools Ultra Agent] "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'DefaultAppPool')
O4 - HKUS\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\..\RunOnce: [WAB Migrate] %ProgramFiles%\Windows Mail\wab.exe /Upgrade (User 'DefaultAppPool')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportovat do aplikace Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: TSearch - {22AFAC71-C6C3-47EA-A30E-A181F1B63411} - C:\Program Files (x86)\MefarchIE\k7eRXmV6.dll (file missing)
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra button: Zobrazit nebo skrýt HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AdobeUpdateService - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Ultra Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Ultra\DiscSoftBusServiceUltra.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Guardian - DefaultInstance (FirebirdGuardianDefaultInstance) - The Firebird Project - C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance (FirebirdServerDefaultInstance) - The Firebird Project - C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbserver.exe
O23 - Service: GoPro Device Detection Service (GoProDeviceDetectionService) - Unknown owner - C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Client Services (HPClientSvc) - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: NETGEARGenieDaemon - NETGEAR - C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:\Program Files (x86)\PDF Complete\pdfsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\SysWOW64\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: ServiceLayer - Nokia - C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
O23 - Service: TeamViewer 10 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 16119 bytes

====== Enumerating Processes ======

C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\atiesrxx.exe
C:\WINDOWS\system32\atieclxx.exe
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-5c93a75b-973d-4352-89bf-5405eaedf1c3 -SystemEventPortName:HostProcess-085c5f00-9b1b-4418-9a63-a48679896484 -IoCancelEventPortName:HostProcess-ea9a71cc-4c99-4fb7-af58-55127080157f -NonStateChangingEventPortName:HostProcess-4f50d124-927f-4647-a5e0-5a4912a3dfef -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:3dd919bf-4775-4e01-b1c8-3c23f65c0a8a -DeviceGroupId:WpdFsGroup
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServicePeerNet
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k iissvcs
C:\Windows\SysWOW64\IoctlSvc.exe
C:\WINDOWS\SysWOW64\PnkBstrA.exe
C:\WINDOWS\SysWOW64\PnkBstrB.exe
"C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe"
"C:\Program Files (x86)\PDF Complete\pdfsvc.exe" /startedbyscm:66B66708-40E2BE4D-pdfcService
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe" -s
C:\WINDOWS\SysWOW64\svchost.exe -k hpdevmgmt
"C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe"
"C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbserver.exe" -s
C:\Windows\system32\svchost.exe -k HPService
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\Explorer.EXE
"C:\Program Files (x86)\TeamViewer\TeamViewer.exe"
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\TeamViewer\tv_w32.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
"C:\Program Files (x86)\TeamViewer\tv_x64.exe" --action hooks --log C:\Program Files (x86)\TeamViewer\TeamViewer10_Logfile.log
C:\WINDOWS\system32\rundll32.EXE "C:\Program Files (x86)\YueAckU\9NYKJ9b.dll",#1
C:\WINDOWS\system32\rundll32.EXE "C:\Program Files (x86)\MederchU\lR1IRuO.dll",#1
C:\WINDOWS\system32\taskhostw.exe
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe"
"C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" /background
"C:\Program Files\Logitech\Gaming Software\LWEMon.exe" /noui
"C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
"C:\Program Files\AMD\CNext\CNext\cnext.exe" atlogon
"C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe"
"C:\Program Files\GoPro\GoPro Desktop App\GoProDesktopSystemTray.exe"
C:\WINDOWS\system32\rundll32.EXE "C:\Program Files (x86)\MederchU\lR1IRuO.dll",#1
C:\Program Files\AVAST Software\Avast\AvastUI.exe
"C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe"
C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM64.exe
"C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun
C:\Program Files\CCleaner\CCleaner64.exe
"C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe"
"C:\Program Files (x86)\4-Day Forecast\4-Day Forecast\4-Day Forecast.exe" /Startup
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe" "-launchedbyvulcan"
"C:\Program Files\DAEMON Tools Ultra\DiscSoftBusServiceUltra.exe"
"C:\PROGRA~2\RAPTRI~1\Raptr\raptr.exe" --log_to_file --from_stub --startup
C:\WINDOWS\system32\fontdrvhost.exe
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe" --type=renderer --disable-3d-apis --disable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\locales" --log-file="C:\Users\pavilion\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --log-severity=warning --user-agent="Mozilla/5.0 (Windows NT 10.0.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/537.36 CreativeCloud/3.9.0.327" --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-gpu-compositing --channel="8184.0.1397490292\491866988" /prefetch:673131151
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe" --onOSstartup=true --showwindow=false --waitForRegistration=true
"C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe"
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe"
C:\PROGRA~2\RAPTRI~1\Raptr\raptr_im.exe
"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe" "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\main.js"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe" --type=renderer --disable-3d-apis --disable-pinch --no-sandbox --enable-deferred-image-decoding --lang=en-US --lang=en-US --locales-dir-path="C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\locales" --log-file="C:\Users\pavilion\AppData\Local\Temp\CreativeCloud\ACC\CEF.log" --log-severity=warning --user-agent="Mozilla/5.0 (Windows NT 10.0.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Safari/537.36 CreativeCloud/3.9.0.327" --device-scale-factor=1 --enable-delegated-renderer --enable-impl-side-painting --num-raster-threads=1 --disable-gpu-compositing --channel="8184.1.1117556948\75719150" /prefetch:673131151
"C:\PROGRA~2\RAPTRI~1\Raptr\raptr_ep64.exe" 5248
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.13720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41275.0_x64__8wekyb3d8bbwe\HxOutlook.exe" -ServerName:microsoft.windowslive.mail.AppXfbjsbkxvprcgqg6q4c9jfr0pn3kv9x5s.mca
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41275.0_x64__8wekyb3d8bbwe\HxTsr.exe" -ServerName:Hx.IPC.Server
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17062.12911.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\system32\rundll32.EXE "C:\Program Files (x86)\YtuAskU2\zDKLNVp.dll",#1
C:\WINDOWS\system32\rundll32.EXE "C:\Program Files (x86)\YueAckU\9NYKJ9b.dll",#1
C:\WINDOWS\system32\rundll32.EXE "C:\Program Files (x86)\MadarchU2\H8XMH4s.dll",#1
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" http://www%2dsearching.com/?prd=set_epc&s=H7Lzamobl2827xn/aAU,7d968be6-2056-4a8c-80b1-2f43adb306c2,
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\pavilion\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\pavilion\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=59.0.3071.115 --initial-client-data=0x19c,0x1a0,0x8,0x198,0x1b4,0x7ffb7a6619d0,0x7ffb7a6619b8,0x7ffb7a6619e8
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=7716 --on-initialized-event-handle=624 --parent-handle=628 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1380 --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,10,20,21,24,28,43,76 --disable-gl-extensions="GL_KHR_blend_equation_advanced GL_KHR_blend_equation_advanced_coherent" --gpu-vendor-id=0x1002 --gpu-device-id=0x68f9 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=15.301.1901.0 --gpu-driver-date=2-26-2016 --service-request-channel-token=AA971307851BC34949FDC409612EBCF5 --mojo-platform-channel-handle=1460 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1380 --primordial-pipe-token=48BFF57191371D0BCA6AF37923D3CA57 --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=48BFF57191371D0BCA6AF37923D3CA57 --renderer-client-id=4 --mojo-platform-channel-handle=3112 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1380 --primordial-pipe-token=B7DDC3D3935EAC275291716D2F6DB8C9 --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=B7DDC3D3935EAC275291716D2F6DB8C9 --renderer-client-id=5 --mojo-platform-channel-handle=3152 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1380 --primordial-pipe-token=ECE7F7F6679A7801B2DEE97F431575A0 --lang=cs --extension-process --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=ECE7F7F6679A7801B2DEE97F431575A0 --renderer-client-id=6 --mojo-platform-channel-handle=3160 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1380 --primordial-pipe-token=7BB0AB86969D895064B3F93E2D644415 --lang=cs --disable-client-side-phishing-detection --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=true --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;0,16,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;1,16,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;2,16,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553;3,16,3553;4,0,3553;4,1,3553;4,2,3553;4,3,3553;4,4,3553;4,5,3553;4,6,3553;4,7,3553;4,8,3553;4,9,3553;4,10,3553;4,11,3553;4,12,3553;4,13,3553;4,14,3553;4,15,3553;4,16,3553 --service-request-channel-token=7BB0AB86969D895064B3F93E2D644415 --renderer-client-id=9 --mojo-platform-channel-handle=5908 /prefetch:1
C:\WINDOWS\SysWOW64\ctfmon.exe
c:\windows\system32\inetsrv\w3wp.exe -ap "DefaultAppPool" -v "v4.0" -l "webengine4.dll" -a \\.\pipe\iisipm14570fc7-f529-426e-a520-e48a8884bd27 -h "C:\inetpub\temp\apppools\DefaultAppPool\DefaultAppPool.config" -w "" -m 0 -t 20 -ta 0
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.1439_none_7efe016621f50bd0\TiWorker.exe -Embedding
C:\Windows\System32\smartscreen.exe -Embedding
C:\WINDOWS\system32\AUDIODG.EXE 0x514
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe13_ Global\UsGthrCtrlFltPipeMssGthrPipe13 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 636 640 648 8192 644
"C:\Users\pavilion\Downloads\RSITx64.exe"

====== Scheduled tasks folder ======

C:\WINDOWS\tasks\842DE247-2F95-42F1-A8A6-A3B7C6786533.job - rundll32 "C:\Program Files (x86)\MederchU\lR1IRuO.dll",#1
C:\WINDOWS\tasks\A0EECDFC-B485-47CA-8AE4-6DB2B0B2691F.job - rundll32 "C:\Program Files (x86)\YueAckU\9NYKJ9b.dll",#1
C:\WINDOWS\tasks\One System CarePeriod.job - C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe -scan
C:\WINDOWS\system32\tasks\5A8163FE-2D41-4CE5-AD54-7FE95B266373 - rundll32 "C:\Program Files (x86)\YtuAskU2\zDKLNVp.dll",#1
C:\WINDOWS\system32\tasks\842DE247-2F95-42F1-A8A6-A3B7C6786533 - rundll32 "C:\Program Files (x86)\MederchU\lR1IRuO.dll",#1
C:\WINDOWS\system32\tasks\842DE247-2F95-42F1-A8A6-A3B7C67865332 - rundll32 "C:\Program Files (x86)\MederchU\lR1IRuO.dll",#1
C:\WINDOWS\system32\tasks\A0EECDFC-B485-47CA-8AE4-6DB2B0B2691F - rundll32 "C:\Program Files (x86)\YueAckU\9NYKJ9b.dll",#1
C:\WINDOWS\system32\tasks\A0EECDFC-B485-47CA-8AE4-6DB2B0B2691F2 - rundll32 "C:\Program Files (x86)\YueAckU\9NYKJ9b.dll",#1
C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_137_pepper.exe -check pepperplugin
C:\WINDOWS\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\WINDOWS\system32\tasks\AF9A5517-A7AD-4299-A3C2-BD1DD4D6E61F - rundll32 "C:\Program Files (x86)\MadarchU2\H8XMH4s.dll",#1
C:\WINDOWS\system32\tasks\AMD Updater - "C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe" /AUTOUPDATEIN
C:\WINDOWS\system32\tasks\Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
C:\WINDOWS\system32\tasks\CCleanerSkipUAC - "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
C:\WINDOWS\system32\tasks\FacebookUpdateTaskUserS-1-5-21-2484980351-1062422368-565276184-1000Core - C:\Users\pavilion\AppData\Local\Facebook\Update\FacebookUpdate.exe /c /nocrashserver
C:\WINDOWS\system32\tasks\FacebookUpdateTaskUserS-1-5-21-2484980351-1062422368-565276184-1000UA - C:\Users\pavilion\AppData\Local\Facebook\Update\FacebookUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\Microsoft_Hardware_Launch_IPoint_exe - c:\Program Files\Microsoft IntelliPoint\IPoint.exe
C:\WINDOWS\system32\tasks\One System Care Run Delay - "C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe" -scan
C:\WINDOWS\system32\tasks\One System CarePeriod - C:\Program Files (x86)\OneSystemCare\OneSystemCare.exe -scan
C:\WINDOWS\system32\tasks\SafeZone scheduled Autoupdate 1470854861 - C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
C:\WINDOWS\system32\tasks\SMW_UpdateTask_Time_3530393737353137372d50552d6c455a37575a417834 - wscript.exe //B "C:\ProgramData\SearchModule\smhe.js" smu.exe /invoke /f:check_services /l:0
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{2BDB9DD1-620C-4300-BF0D-A57A12BCFCC0} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\{344EE6A1-DC3F-4CBF-8397-B880573137E9} - C:\WINDOWS\system32\pcalua.exe -a C:\Users\pavilion\Desktop\Flash_Disinfector.exe -d C:\Users\pavilion\Desktop
C:\WINDOWS\system32\tasks\{55DDD558-479D-43FA-BD81-E98832558880} - "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/ui/0/5.8.0.156/cs/a ... age=tsMain
C:\WINDOWS\system32\tasks\{5CCFCAB6-D4C7-4B1B-B593-0B15CF55C023} - C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{570C2A84-A145-4DF0-AE9D-012584DF09DC}\setup.exe"
C:\WINDOWS\system32\tasks\{6698E959-1F2C-476C-9B11-147D9EAD0B8E} - C:\Windows\system32\pcalua.exe -a E:\GameSetup.exe -d E:\
C:\WINDOWS\system32\tasks\{76CE46A0-F9AC-4645-A304-EE94605CB276} - C:\Program Files (x86)\Skype\\Phone\Skype.exe
C:\WINDOWS\system32\tasks\{89600D9A-7D44-4BF6-9119-0D75B9929979} - C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRHradekUninst.exe"
C:\WINDOWS\system32\tasks\{8B53A133-C9DF-4FB9-97D7-A20349775E50} - C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMonteklandUninst.exe"
C:\WINDOWS\system32\tasks\{931A0D46-FBD9-4030-A48E-205D0E6F2AF6} - C:\Windows\system32\pcalua.exe -a C:\Users\pavilion\Desktop\RBR\RBRTM088Inst.exe -d C:\Users\pavilion\Desktop\RBR
C:\WINDOWS\system32\tasks\{AE43101F-8BB7-4429-B059-E87B9EA71AE3} - C:\Windows\system32\pcalua.exe -a "C:\Users\pavilion\Desktop\Airprint\Windows AirPrint Installer iOS 5 for x86 x64\AirPrint_Installer.exe" -d "C:\Users\pavilion\Desktop\Airprint\Windows AirPrint Installer iOS 5 for x86 x64"
C:\WINDOWS\system32\tasks\{B0C183C7-15C7-4E01-9178-792103AED651} - C:\Windows\system32\pcalua.exe -a "C:\Users\pavilion\Desktop\Call of Duty 5\Call of duty 5 World at War - Instalace\setup.exe" -d "C:\Users\pavilion\Desktop\Call of Duty 5\Call of duty 5 World at War - Instalace"
C:\WINDOWS\system32\tasks\{B2BD4A95-A0D8-4A3C-B777-2273EFE85B83} - C:\Windows\system32\pcalua.exe -a C:\Users\pavilion\Downloads\RBRTM088Inst.exe -d C:\Users\pavilion\Downloads
C:\WINDOWS\system32\tasks\{BAA220E9-57F1-4FE4-AC84-6E27817E2418} - C:\Windows\system32\pcalua.exe -a C:\Users\pavilion\Downloads\pm_demo.exe -d C:\Users\pavilion\Downloads
C:\WINDOWS\system32\tasks\{BEB2137D-2E7E-4C01-A097-2BB90B4879DA} - C:\Windows\system32\pcalua.exe -a C:\Users\pavilion\Downloads\RBRTM087EInst.exe -d C:\Users\pavilion\Downloads
C:\WINDOWS\system32\tasks\{C688410B-7ED6-4CC9-807F-BEB0046888D0} - C:\Windows\system32\pcalua.exe -a E:\GameSetup.exe -d E:\
C:\WINDOWS\system32\tasks\{F0E81764-F5DA-4A2F-8576-7F1A21682F16} - C:\WINDOWS\system32\pcalua.exe -a "C:\Program Files (x86)\NoterSave\uninstaller.exe"
C:\WINDOWS\system32\tasks\{F1E9219C-9504-4BE7-8C00-F558063EB61A} - C:\WINDOWS\system32\pcalua.exe -a "C:\WINDOWS\system32\AZ FOTO AlbumMaker_AZ FOTO AlbumMaker_uninstaller.exe" -c uninstall
C:\WINDOWS\system32\tasks\{F580929E-59DA-40C8-9E1D-614144AD1070} - C:\WINDOWS\system32\pcalua.exe -a C:\Windows\system32\swb_uninst.exe -c "C:\Program Files\CV Curriculum vitae CREATOR\uninst.log"
C:\WINDOWS\system32\tasks\{FF2B8A4C-1CEF-4275-8E81-DA870716B30F} - C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRRallySprint11Uninst.exe"
C:\WINDOWS\system32\tasks\{FF7EFC7D-AE8B-484A-85D9-C1C0A8CBEE40} - "c:\program files (x86)\google\chrome\application\chrome.exe" http://ui.skype.com/ui/0/5.8.0.156/cs/a ... age=tsMain
C:\WINDOWS\system32\tasks\WPD\SqmUpload_S-1-5-21-2484980351-1062422368-565276184-1000 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\WINDOWS\system32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\WINDOWS\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\MusUx_UpdateInterval - %systemroot%\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe RebootDialog
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - C:\windows\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - C:\windows\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\UNP\RunCampaignManager - %windir%\System32\UNP\UNPCampaignManager.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Logon - %windir%\system32\UNP\UNPUXLauncher.exe /campaignId {91be532c-f9f1-406a-9858-43697c6f437a} /launchtype scheduled /trigger Logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\OnIdle - %windir%\system32\UNP\UNPUXLauncher.exe /campaignId {91be532c-f9f1-406a-9858-43697c6f437a} /launchtype scheduled /trigger OnIdle
C:\WINDOWS\system32\tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\OutOfIdle - %windir%\system32\UNP\UNPUXLauncher.exe /campaignId {91be532c-f9f1-406a-9858-43697c6f437a} /launchtype scheduled /trigger OutOfIdle
C:\WINDOWS\system32\tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\RunCampaignManager2 - C:\Windows\system32\UNP\UNPCampaignManager.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Time - %windir%\system32\UNP\UNPUXLauncher.exe /campaignId {91be532c-f9f1-406a-9858-43697c6f437a} /launchtype scheduled /trigger Time
C:\WINDOWS\system32\tasks\Microsoft\Windows\UNP\Campaigns\{91be532c-f9f1-406a-9858-43697c6f437a}\Unlock - %windir%\system32\UNP\UNPUXLauncher.exe /campaignId {91be532c-f9f1-406a-9858-43697c6f437a} /launchtype scheduled /trigger Unlock
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict1 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPOffendingSystem
C:\WINDOWS\system32\tasks\Microsoft\Windows\Tcpip\IpAddressConflict2 - %windir%\system32\rundll32.exe ndfapi.dll,NdfRunDllDuplicateIPDefendingSystem
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\WINDOWS\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemovalTools\MRT_HB - C:\WINDOWS\system32\MRT.exe /EHB /Q
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\Lpksetup - C:\WINDOWS\System32\lpksetup.exe -v
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\WINDOWS\System32\mcbuilder.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoActivateWindowsSearch
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService - %SystemRoot%\ehome\ehPrivJob.exe /DoConfigureInternetTimeService
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks - %SystemRoot%\ehome\ehPrivJob.exe /DoRecoveryTasks $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ehDRMInit - %SystemRoot%\ehome\ehPrivJob.exe /DRMInit
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\InstallPlayReady - %SystemRoot%\ehome\ehPrivJob.exe /InstallPlayReady $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\mcupdate - %SystemRoot%\ehome\mcupdate $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\mcupdate_scheduled - %SystemRoot%\ehome\mcupdate -crl -hms -pscn 15
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -MediaCenterRecoveryTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -ObjectStoreRecoveryTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\OCURActivate - %SystemRoot%\ehome\ehPrivJob.exe /OCURActivate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\OCURDiscovery - %SystemRoot%\ehome\ehPrivJob.exe /OCURDiscovery $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PBDADiscovery - %SystemRoot%\ehome\ehPrivJob.exe /PBDADiscovery
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 - %SystemRoot%\ehome\ehPrivJob.exe /wait:7 /PBDADiscovery
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 - %SystemRoot%\ehome\ehPrivJob.exe /wait:90 /PBDADiscovery
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PeriodicScanRetry - %windir%\ehome\MCUpdate.exe -pscn 0
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PvrRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -PvrRecoveryTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\PvrScheduleTask - %SystemRoot%\ehome\mcupdate.exe -PvrSchedule
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\RecordingRestart - %SystemRoot%\ehome\ehrec /RestartRecording
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\RegisterSearch - %SystemRoot%\ehome\ehPrivJob.exe /DoRegisterSearch $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\ReindexSearchRoot - %SystemRoot%\ehome\ehPrivJob.exe /DoReindexSearchRoot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask - %SystemRoot%\ehome\mcupdate.exe -SqlLiteRecoveryTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\StartRecording - %SystemRoot%\ehome\ehrec /StartRecording
C:\WINDOWS\system32\tasks\Microsoft\Windows\Media Center\UpdateRecordPath - %SystemRoot%\ehome\ehPrivJob.exe /DoUpdateRecordPath $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\WINDOWS\system32\tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - %windir%\system32\MDMAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\WINDOWS\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 - C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe scan upload mininterval:2880
C:\WINDOWS\system32\tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 - C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe scan upload
C:\WINDOWS\system32\tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan - c:\Program Files\Microsoft Security Client\MpCmdRun.exe Scan -ScheduleJob -RestrictPrivileges
C:\WINDOWS\system32\tasks\AVAST Software\Avast settings backup - C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe /backup /iavs
C:\WINDOWS\system32\tasks\Apple\AppleSoftwareUpdate - C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -task

=========Google Chrome=========

C:\Users\pavilion\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension agalokjhnhheienloigiaoohgmjdpned 1 Adblocker pro Youtube™ 1.0.3
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension aoojlhjjgjhndkblocmajmekmdbfdkhj 1 Torrent Search 1.5
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Vyhledávání Google 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 1 Adobe Acrobat 15.1.0.6
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension ilfoopambfaclfjmpiaijnccgcmbeigi 1 FormApps Extension 2.5.0.27
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.3
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.2
Extension pafkbggdmjlpgkdkcbjmhmfcdpncadgh 1 Google Now 1.2.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5917.424.0.7
Homepage: http://www.seznam.cz/
default_search_provider.search_url:
C:\Users\pavilion\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=


======Registry dump ======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24744B0A-9F0D-49A6-8A90-D7EF6EAD5137}]
TSearch - C:\Program Files (x86)\MefarchIE\tWCAOTC.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-07-02 210112]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-07-16 3131072]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-08-04 49440]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
HP Print Enhancer - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20 328248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24744B0A-9F0D-49A6-8A90-D7EF6EAD5137}]
TSearch - C:\Program Files (x86)\MefarchIE\k7eRXmV6.dll []

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-06-16 149704]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-04-14 462760]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C0D38E5A-7CF8-4105-8FE8-31B81443A114}]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-07-16 2106048]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-04-14 171944]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}]
HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20 509496]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-24 13885696]
"hpsysdrv"=c:\program files (x86)\hewlett-packard\HP odometer\hpsysdrv.exe [2008-11-20 62768]
"SmartMenu"=C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe [2010-09-15 611896]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]
"IntelliPoint"=c:\Program Files\Microsoft IntelliPoint\ipoint.exe [2011-08-01 2417032]
"StartCN"=C:\Program Files\AMD\CNext\CNext\cnext.exe [2016-02-26 4926664]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01 508128]
"GoPro Tray App"=C:\Program Files\GoPro\GoPro Desktop App\GoProDesktopSystemTray.exe [2017-01-27 866224]
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvLaunch.exe [2017-07-20 213832]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2017-07-14 303928]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDriveSetup"=C:\Windows\SysWOW64\OneDriveSetup.exe [2016-05-29 8886976]
"HydraVisionDesktopManager"=C:\Program Files (x86)\ATI Technologies\HydraVision\HydraDM.exe [2010-09-08 393216]
"iCloudServices"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [2017-07-14 67384]
"ApplePhotoStreams"=C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [2017-07-14 67896]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2017-06-30 9818328]
"iCloudDrive"=C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [2017-07-14 110392]
"NETGEARGenie"=C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe [2016-03-09 611584]
"DAEMON Tools Ultra Agent"=C:\Program Files\DAEMON Tools Ultra\DTAgent.exe [2016-12-12 5021888]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe /autoRun []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^pavilion^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk]
C:\PROGRA~2\OPENOF~1.ORG\program\QUICKS~1.EXE []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-07-22 150528]
"LifeCam"=C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]
"4-Day Forecast"=C:\Program Files (x86)\4-Day Forecast\4-Day Forecast\4-Day Forecast.exe [2008-11-10 1060864]
"Raptr"=C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe [2017-05-30 58584]
"PlaysTV"=C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv_launcher.exe [2016-04-05 71440]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]
"Adobe Creative Cloud"=C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2016-10-12 2383040]
"NoterSave"=C:\Program Files (x86)\NoterSave\NoterSave.exe []

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders" = credssp.dll

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"undockwithoutlogon"=1
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"HideFastUserSwitching"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"NoDrives"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
"StubPath" = %SystemRoot%\inf\unregmp2.exe /ShowWMP
[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath" = "C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave1"=wdmaud.drv
"mixer1"=wdmaud.drv
"VIDC.SP54"=SP5X_32.DLL
"VIDC.SP55"=SP5X_32.DLL
"VIDC.SP56"=SP5X_32.DLL
"VIDC.SP57"=SP5X_32.DLL
"VIDC.SP58"=SP5X_32.DLL
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.CFHD"=CFHD.dll

====== File associations ======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

====== List of files/folders created in the last 1 month ======

Daveson
Návštěvník
Návštěvník
Příspěvky: 140
Registrován: 06 kvě 2008 12:38
Bydliště: Zlín
Kontaktovat uživatele:

Re: Viry v PC a nechtěný One systeme Care Launcher

#2 Příspěvek od Daveson »

2017-07-24 06:52:42 ----D---- C:\rsit
2017-07-24 06:17:24 ----D---- C:\Users\pavilion\AppData\Roaming\Google
2017-07-24 00:44:45 ----D---- C:\ProgramData\SWCUTemp
2017-07-21 07:14:24 ----D---- C:\ProgramData\e7fe2a03-7403-0
2017-07-21 07:14:24 ----D---- C:\ProgramData\e7fe2a03-3337-1
2017-07-21 07:14:13 ----D---- C:\Users\pavilion\AppData\Roaming\One System Care
2017-07-21 07:14:13 ----D---- C:\Program Files (x86)\OneSystemCare
2017-07-21 07:13:26 ----D---- C:\ProgramData\SearchModule
2017-07-21 07:13:22 ----D---- C:\Program Files\Common Files\Noobzo
2017-07-21 07:13:20 ----A---- C:\WINDOWS\rsrcs.dll
2017-07-21 07:11:41 ----D---- C:\Users\pavilion\AppData\Roaming\RenewSoftware.com
2017-07-21 07:11:23 ----D---- C:\ProgramData\2909b477-6a51-0
2017-07-21 07:11:22 ----D---- C:\ProgramData\2909b477-71e1-1
2017-07-21 07:10:52 ----D---- C:\Program Files\KPLILVC76Q
2017-07-21 07:10:51 ----D---- C:\Program Files\A08U6NCHQN
2017-07-21 07:10:50 ----D---- C:\Users\pavilion\AppData\Roaming\5n0jzkpfay2
2017-07-21 07:10:45 ----D---- C:\Users\pavilion\AppData\Roaming\tcvm0t1kr52
2017-07-21 07:10:40 ----D---- C:\Program Files\1JCQVD2CTY
2017-07-21 07:10:39 ----D---- C:\Users\pavilion\AppData\Roaming\zvhmf101s2e
2017-07-21 07:10:37 ----D---- C:\Program Files (x86)\sbzqlkm2tol
2017-07-21 07:10:34 ----D---- C:\Program Files\1QJLAVG1XV
2017-07-21 07:08:36 ----D---- C:\Program Files\Office 2016 KMS Activator Ultimate v1.0
2017-07-20 19:05:06 ----D---- C:\Users\pavilion\AppData\Roaming\LibreELEC
2017-07-20 18:00:20 ----D---- C:\Program Files\iPod
2017-07-20 18:00:19 ----AD---- C:\Program Files\iTunes
2017-07-20 04:36:44 ----A---- C:\WINDOWS\system32\aswBoot.exe
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Sensors.dll
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.dll
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\PlayToReceiver.dll
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\Geolocation.dll
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\dialclient.dll
2017-07-12 18:26:03 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostCommon.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.BlockedShutdown.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Radios.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-07-12 18:26:02 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.InkControls.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Streaming.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Devices.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Usb.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SerialCommunication.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Picker.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Core.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-07-12 18:26:01 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2017-07-12 18:26:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.dll
2017-07-12 18:26:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.dll
2017-07-12 18:26:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Connectivity.dll
2017-07-12 18:26:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2017-07-12 18:26:00 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-07-12 18:26:00 ----A---- C:\WINDOWS\SYSWOW64\AuthBroker.dll
2017-07-12 18:26:00 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-07-12 18:25:59 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2017-07-12 18:25:59 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-07-12 18:25:58 ----A---- C:\WINDOWS\SYSWOW64\WwaApi.dll
2017-07-12 18:25:58 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2017-07-12 18:25:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Maps.dll
2017-07-12 18:25:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-07-12 18:25:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-07-12 18:25:58 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2017-07-12 18:25:58 ----A---- C:\WINDOWS\SYSWOW64\MiracastReceiver.dll
2017-07-12 18:25:58 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Import.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.XboxLive.Storage.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Perception.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.LowLevel.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Lights.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Wallet.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2017-07-12 18:25:57 ----A---- C:\WINDOWS\SYSWOW64\mbsmsapi.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\WinRtTracing.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.UserDeviceAssociation.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.SystemManagement.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.FaceAnalysis.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Gaming.Input.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Energy.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFiDirect.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.WiFi.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.HumanInterfaceDevice.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-07-12 18:25:56 ----A---- C:\WINDOWS\SYSWOW64\ErrorDetails.dll
2017-07-12 18:25:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Http.dll
2017-07-12 18:25:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2017-07-12 18:25:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Editing.dll
2017-07-12 18:25:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Globalization.dll
2017-07-12 18:25:55 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-07-12 18:25:55 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-07-12 18:25:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-07-12 18:25:54 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2017-07-12 18:25:54 ----A---- C:\WINDOWS\SYSWOW64\RTMediaFrame.dll
2017-07-12 18:25:54 ----A---- C:\WINDOWS\SYSWOW64\CryptoWinRT.dll
2017-07-12 18:25:54 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-07-12 18:25:54 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-07-12 18:25:53 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-07-12 18:25:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2017-07-12 18:25:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-07-12 18:25:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-07-12 18:25:53 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2017-07-12 18:25:53 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2017-07-12 18:25:52 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-07-12 18:25:51 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-07-12 18:25:51 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-07-12 18:25:51 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-07-12 18:25:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-07-12 18:25:50 ----A---- C:\WINDOWS\SYSWOW64\oleacc.dll
2017-07-12 18:25:50 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Web.Diagnostics.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Speech.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Ocr.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.SmartCards.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.PointOfService.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Midi.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Bluetooth.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.AllJoyn.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2017-07-12 18:25:49 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2017-07-12 18:25:48 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2017-07-12 18:25:48 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-07-12 18:25:48 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-07-12 18:25:48 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-07-12 18:25:48 ----A---- C:\WINDOWS\SYSWOW64\CPFilters.dll
2017-07-12 18:25:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-07-12 18:25:47 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-07-12 18:25:46 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2017-07-12 18:25:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-07-12 18:25:46 ----A---- C:\WINDOWS\SYSWOW64\PrintDialogs.dll
2017-07-12 18:25:46 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2017-07-12 18:25:46 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2017-07-12 18:25:46 ----A---- C:\WINDOWS\SYSWOW64\AboveLockAppHost.dll
2017-07-12 18:25:45 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-07-12 18:25:45 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-07-12 18:25:45 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-07-12 18:25:45 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-07-12 18:25:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-07-12 18:25:44 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-07-12 18:25:43 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.3D.dll
2017-07-12 18:25:43 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2017-07-12 18:25:43 ----A---- C:\WINDOWS\SYSWOW64\tsmf.dll
2017-07-12 18:25:43 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2017-07-12 18:25:43 ----A---- C:\WINDOWS\SYSWOW64\NetSetupShim.dll
2017-07-12 18:25:42 ----A---- C:\WINDOWS\SYSWOW64\odbcconf.dll
2017-07-12 18:25:42 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-07-12 18:25:42 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2017-07-12 18:25:41 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-07-12 18:25:41 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-07-12 18:25:41 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2017-07-12 18:25:40 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-07-12 18:25:40 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-07-12 18:25:39 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-07-12 18:25:39 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-07-12 18:25:39 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-07-12 18:25:37 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-07-12 18:25:33 ----A---- C:\WINDOWS\SYSWOW64\storagewmi.dll
2017-07-12 18:25:33 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2017-07-12 18:25:33 ----A---- C:\WINDOWS\SYSWOW64\mispace.dll
2017-07-12 18:25:32 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-07-12 18:25:32 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-07-12 18:25:31 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-07-12 18:25:31 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-07-12 18:25:29 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2017-07-12 18:25:29 ----A---- C:\WINDOWS\system32\drivers\stornvme.sys
2017-07-12 18:25:29 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2017-07-12 18:25:28 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2017-07-12 18:25:28 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-07-12 18:25:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2017-07-12 18:25:27 ----A---- C:\WINDOWS\SYSWOW64\OpcServices.dll
2017-07-12 18:25:26 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2017-07-12 18:25:25 ----A---- C:\WINDOWS\SYSWOW64\dsreg.dll
2017-07-12 18:25:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-07-12 18:25:24 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-07-12 18:25:24 ----A---- C:\WINDOWS\SYSWOW64\imapi2fs.dll
2017-07-12 18:25:23 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2017-07-12 18:25:22 ----A---- C:\WINDOWS\SYSWOW64\vaultcli.dll
2017-07-12 18:25:22 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2017-07-12 18:25:22 ----A---- C:\WINDOWS\SYSWOW64\credprovhost.dll
2017-07-12 18:25:21 ----A---- C:\WINDOWS\SYSWOW64\autochk.exe
2017-07-12 18:25:21 ----A---- C:\WINDOWS\SYSWOW64\autofmt.exe
2017-07-12 18:25:21 ----A---- C:\WINDOWS\SYSWOW64\autoconv.exe
2017-07-12 18:25:20 ----A---- C:\WINDOWS\SYSWOW64\untfs.dll
2017-07-12 18:25:19 ----A---- C:\WINDOWS\SYSWOW64\msinfo32.exe
2017-07-12 18:25:19 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2017-07-12 18:25:19 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-07-12 18:25:18 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2017-07-12 18:25:18 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2017-07-12 18:25:18 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-07-12 18:25:17 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-07-12 18:25:17 ----A---- C:\WINDOWS\SYSWOW64\ifsutil.dll
2017-07-12 18:25:17 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2017-07-12 18:25:17 ----A---- C:\WINDOWS\SYSWOW64\certutil.exe
2017-07-12 18:25:16 ----A---- C:\WINDOWS\SYSWOW64\Wldap32.dll
2017-07-12 18:25:16 ----A---- C:\WINDOWS\SYSWOW64\wdc.dll
2017-07-12 18:25:16 ----A---- C:\WINDOWS\SYSWOW64\uudf.dll
2017-07-12 18:25:16 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2017-07-12 18:25:16 ----A---- C:\WINDOWS\SYSWOW64\MsSpellCheckingFacility.dll
2017-07-12 18:25:16 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2017-07-12 18:25:15 ----A---- C:\WINDOWS\SYSWOW64\SHCore.dll
2017-07-12 18:25:15 ----A---- C:\WINDOWS\SYSWOW64\ntmarta.dll
2017-07-12 18:25:15 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2017-07-12 18:25:15 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2017-07-12 18:25:15 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2017-07-12 18:25:15 ----A---- C:\WINDOWS\system32\drivers\scmbus.sys
2017-07-12 18:25:14 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2017-07-12 18:25:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.Printing.dll
2017-07-12 18:25:14 ----A---- C:\WINDOWS\SYSWOW64\ufat.dll
2017-07-12 18:25:14 ----A---- C:\WINDOWS\SYSWOW64\uexfat.dll
2017-07-12 18:25:14 ----A---- C:\WINDOWS\SYSWOW64\sendmail.dll
2017-07-12 18:25:14 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2017-07-12 18:25:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2017-07-12 18:25:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.BackgroundMediaPlayback.dll
2017-07-12 18:25:13 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2017-07-12 18:25:13 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-07-12 18:25:13 ----A---- C:\WINDOWS\SYSWOW64\cnvfat.dll
2017-07-12 18:25:13 ----A---- C:\WINDOWS\SYSWOW64\azroleui.dll
2017-07-12 18:25:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.dll
2017-07-12 18:25:12 ----A---- C:\WINDOWS\SYSWOW64\ExecModelClient.dll
2017-07-12 18:25:12 ----A---- C:\WINDOWS\system32\drivers\scmdisk0101.sys
2017-07-12 18:25:11 ----A---- C:\WINDOWS\SYSWOW64\XpsDocumentTargetPrint.dll
2017-07-12 18:25:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Perception.Stub.dll
2017-07-12 18:25:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Playback.MediaPlayer.dll
2017-07-12 18:25:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2017-07-12 18:25:11 ----A---- C:\WINDOWS\SYSWOW64\StructuredQuery.dll
2017-07-12 18:25:11 ----A---- C:\WINDOWS\SYSWOW64\SmartcardCredentialProvider.dll
2017-07-12 18:25:11 ----A---- C:\WINDOWS\SYSWOW64\BioCredProv.dll
2017-07-12 18:25:10 ----A---- C:\WINDOWS\SYSWOW64\tlscsp.dll
2017-07-12 18:25:10 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2017-07-12 18:25:10 ----A---- C:\WINDOWS\SYSWOW64\ngccredprov.dll
2017-07-12 18:25:09 ----A---- C:\WINDOWS\SYSWOW64\wvc.dll
2017-07-12 18:25:09 ----A---- C:\WINDOWS\SYSWOW64\UserDeviceRegistration.Ngc.dll
2017-07-12 18:25:09 ----A---- C:\WINDOWS\SYSWOW64\uReFSv1.dll
2017-07-12 18:25:09 ----A---- C:\WINDOWS\SYSWOW64\FXSCOMEX.dll
2017-07-12 18:25:09 ----A---- C:\WINDOWS\SYSWOW64\easwrt.dll
2017-07-12 18:25:08 ----A---- C:\WINDOWS\SYSWOW64\regsvr32.exe
2017-07-12 18:25:08 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2017-07-12 18:25:08 ----A---- C:\WINDOWS\SYSWOW64\raschap.dll
2017-07-12 18:25:08 ----A---- C:\WINDOWS\SYSWOW64\onex.dll
2017-07-12 18:25:08 ----A---- C:\WINDOWS\SYSWOW64\l2gpstore.dll
2017-07-12 18:25:08 ----A---- C:\WINDOWS\SYSWOW64\fdProxy.dll
2017-07-12 18:25:08 ----A---- C:\WINDOWS\SYSWOW64\eapprovp.dll
2017-07-12 18:25:06 ----A---- C:\WINDOWS\SYSWOW64\msvcr120_clr0400.dll
2017-07-12 18:25:06 ----A---- C:\WINDOWS\SYSWOW64\msvcp120_clr0400.dll
2017-07-12 18:25:06 ----A---- C:\WINDOWS\system32\msvcr120_clr0400.dll
2017-07-12 18:25:06 ----A---- C:\WINDOWS\system32\msvcp120_clr0400.dll
2017-07-12 18:25:00 ----A---- C:\WINDOWS\system32\WinRtTracing.dll
2017-07-12 18:25:00 ----A---- C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-07-12 18:25:00 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.InkControls.dll
2017-07-12 18:25:00 ----A---- C:\WINDOWS\system32\Windows.Media.FaceAnalysis.dll
2017-07-12 18:25:00 ----A---- C:\WINDOWS\system32\Windows.Devices.Perception.dll
2017-07-12 18:25:00 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Wallet.dll
2017-07-12 18:25:00 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Core.dll
2017-07-12 18:25:00 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-07-12 18:24:59 ----A---- C:\WINDOWS\system32\Windows.Media.Ocr.dll
2017-07-12 18:24:59 ----A---- C:\WINDOWS\system32\tquery.dll
2017-07-12 18:24:57 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2017-07-12 18:24:57 ----A---- C:\WINDOWS\system32\mssrch.dll
2017-07-12 18:24:55 ----A---- C:\WINDOWS\SYSWOW64\WebcamUi.dll
2017-07-12 18:24:55 ----A---- C:\WINDOWS\system32\WwaApi.dll
2017-07-12 18:24:55 ----A---- C:\WINDOWS\system32\WebcamUi.dll
2017-07-12 18:24:54 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-07-12 18:24:54 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-07-12 18:24:54 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-07-12 18:24:54 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-07-12 18:24:54 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2017-07-12 18:24:53 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-07-12 18:24:53 ----A---- C:\WINDOWS\system32\Windows.Gaming.XboxLive.Storage.dll
2017-07-12 18:24:35 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2017-07-12 18:24:12 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2017-07-12 18:24:10 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Background.SystemEventsBroker.dll
2017-07-12 18:24:10 ----A---- C:\WINDOWS\system32\VEDataLayerHelpers.dll
2017-07-12 18:24:10 ----A---- C:\WINDOWS\system32\tileobjserver.dll
2017-07-12 18:24:10 ----A---- C:\WINDOWS\system32\tdlrecover.exe
2017-07-12 18:24:10 ----A---- C:\WINDOWS\system32\drivers\rootmdm.sys
2017-07-12 18:24:09 ----A---- C:\WINDOWS\system32\XblGameSave.dll
2017-07-12 18:24:09 ----A---- C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2017-07-12 18:24:08 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-07-12 18:24:08 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-07-12 18:24:08 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-07-12 18:24:07 ----A---- C:\WINDOWS\system32\wksprt.exe
2017-07-12 18:24:07 ----A---- C:\WINDOWS\system32\tsmf.dll
2017-07-12 18:24:07 ----A---- C:\WINDOWS\system32\NgcCtnrSvc.dll
2017-07-12 18:24:07 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-07-12 18:24:06 ----A---- C:\WINDOWS\system32\wpnapps.dll
2017-07-12 18:24:06 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-07-12 18:24:06 ----A---- C:\WINDOWS\system32\RTMediaFrame.dll
2017-07-12 18:24:06 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-07-12 18:24:06 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-07-12 18:24:05 ----A---- C:\WINDOWS\system32\SystemSettings.DeviceEncryptionHandlers.dll
2017-07-12 18:24:05 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-07-12 18:24:05 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2017-07-12 18:24:04 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-07-12 18:24:04 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2017-07-12 18:24:03 ----A---- C:\WINDOWS\system32\rdpencom.dll
2017-07-12 18:24:03 ----A---- C:\WINDOWS\system32\puiobj.dll
2017-07-12 18:24:03 ----A---- C:\WINDOWS\system32\PrintDialogs3D.dll
2017-07-12 18:24:03 ----A---- C:\WINDOWS\system32\mstsc.exe
2017-07-12 18:24:02 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-07-12 18:24:02 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2017-07-12 18:24:02 ----A---- C:\WINDOWS\system32\diagtrack.dll
2017-07-12 18:24:01 ----A---- C:\WINDOWS\system32\rdpudd.dll
2017-07-12 18:24:01 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-07-12 18:24:00 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-07-12 18:23:59 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-07-12 18:23:59 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-07-12 18:23:58 ----A---- C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-07-12 18:23:58 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-07-12 18:23:58 ----A---- C:\WINDOWS\system32\PrintDialogs.dll
2017-07-12 18:23:58 ----A---- C:\WINDOWS\system32\AboveLockAppHost.dll
2017-07-12 18:23:57 ----A---- C:\WINDOWS\system32\Windows.Media.Streaming.dll
2017-07-12 18:23:57 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2017-07-12 18:23:57 ----A---- C:\WINDOWS\system32\mos.dll
2017-07-12 18:23:56 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-07-12 18:23:56 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.dll
2017-07-12 18:23:56 ----A---- C:\WINDOWS\system32\oleaut32.dll
2017-07-12 18:23:55 ----A---- C:\WINDOWS\system32\shell32.dll
2017-07-12 18:23:52 ----A---- C:\WINDOWS\system32\Windows.Networking.ServiceDiscovery.Dnssd.dll
2017-07-12 18:23:52 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-07-12 18:23:52 ----A---- C:\WINDOWS\system32\EmailApis.dll
2017-07-12 18:23:51 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-07-12 18:23:51 ----A---- C:\WINDOWS\system32\Windows.Perception.Stub.dll
2017-07-12 18:23:51 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2017-07-12 18:23:51 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2017-07-12 18:23:51 ----A---- C:\WINDOWS\system32\mbsmsapi.dll
2017-07-12 18:23:51 ----A---- C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-07-12 18:23:51 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2017-07-12 18:23:51 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-07-12 18:23:50 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2017-07-12 18:23:49 ----A---- C:\WINDOWS\system32\wmpps.dll
2017-07-12 18:23:49 ----A---- C:\WINDOWS\system32\mfps.dll
2017-07-12 18:23:49 ----A---- C:\WINDOWS\system32\drivers\pdc.sys
2017-07-12 18:23:45 ----A---- C:\WINDOWS\system32\wdc.dll
2017-07-12 18:23:45 ----A---- C:\WINDOWS\system32\drivers\WdiWiFi.sys
2017-07-12 18:23:44 ----A---- C:\WINDOWS\system32\Windows.Media.Editing.dll
2017-07-12 18:23:44 ----A---- C:\WINDOWS\system32\pnidui.dll
2017-07-12 18:23:44 ----A---- C:\WINDOWS\system32\drivers\netio.sys
2017-07-12 18:23:43 ----A---- C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2017-07-12 18:23:41 ----A---- C:\WINDOWS\system32\wvc.dll
2017-07-12 18:23:38 ----A---- C:\WINDOWS\system32\lsass.exe
2017-07-12 18:23:37 ----A---- C:\WINDOWS\system32\tlscsp.dll
2017-07-12 18:23:30 ----A---- C:\WINDOWS\system32\rastls.dll
2017-07-12 18:23:30 ----A---- C:\WINDOWS\system32\ProvisioningHandlers.dll
2017-07-12 18:23:30 ----A---- C:\WINDOWS\system32\onex.dll
2017-07-12 18:23:30 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2017-07-12 18:23:29 ----A---- C:\WINDOWS\system32\raschap.dll
2017-07-12 18:23:29 ----A---- C:\WINDOWS\system32\l2gpstore.dll
2017-07-12 18:23:29 ----A---- C:\WINDOWS\system32\eapprovp.dll
2017-07-12 18:23:27 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2017-07-12 18:23:27 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-07-12 18:23:26 ----A---- C:\WINDOWS\SYSWOW64\mshtmled.dll
2017-07-12 18:23:26 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-07-12 18:23:24 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2017-07-12 18:23:24 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2017-07-12 18:23:24 ----A---- C:\WINDOWS\system32\DevicesFlowBroker.dll
2017-07-12 18:23:24 ----A---- C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-07-12 18:23:23 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-07-12 18:23:23 ----A---- C:\WINDOWS\system32\Windows.Energy.dll
2017-07-12 18:23:23 ----A---- C:\WINDOWS\system32\Windows.Devices.SerialCommunication.dll
2017-07-12 18:23:23 ----A---- C:\WINDOWS\system32\Windows.Devices.LowLevel.dll
2017-07-12 18:23:23 ----A---- C:\WINDOWS\system32\dialclient.dll
2017-07-12 18:23:22 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-07-12 18:23:21 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-07-12 18:23:21 ----A---- C:\WINDOWS\system32\msfeeds.dll
2017-07-12 18:23:20 ----A---- C:\WINDOWS\system32\Windows.Devices.SmartCards.dll
2017-07-12 18:23:20 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2017-07-12 18:23:20 ----A---- C:\WINDOWS\system32\PlayToReceiver.dll
2017-07-12 18:23:20 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2017-07-12 18:23:20 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2017-07-12 18:23:20 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2017-07-12 18:23:19 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-07-12 18:23:19 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-07-12 18:23:19 ----A---- C:\WINDOWS\system32\Windows.Devices.Usb.dll
2017-07-12 18:23:19 ----A---- C:\WINDOWS\system32\Windows.Devices.Picker.dll
2017-07-12 18:23:19 ----A---- C:\WINDOWS\system32\Windows.Devices.Lights.dll
2017-07-12 18:23:19 ----A---- C:\WINDOWS\system32\Windows.Devices.HumanInterfaceDevice.dll
2017-07-12 18:23:18 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-07-12 18:23:18 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-07-12 18:23:17 ----A---- C:\WINDOWS\system32\iertutil.dll
2017-07-12 18:23:16 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-07-12 18:23:15 ----A---- C:\WINDOWS\system32\Windows.Devices.PointOfService.dll
2017-07-12 18:23:15 ----A---- C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-07-12 18:23:15 ----A---- C:\WINDOWS\system32\shutdownux.dll
2017-07-12 18:23:15 ----A---- C:\WINDOWS\system32\MiracastReceiver.dll
2017-07-12 18:23:15 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-07-12 18:23:14 ----A---- C:\WINDOWS\SYSWOW64\dxtrans.dll
2017-07-12 18:23:14 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2017-07-12 18:23:14 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFiDirect.dll
2017-07-12 18:23:13 ----A---- C:\WINDOWS\system32\mshtmled.dll
2017-07-12 18:23:13 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-07-12 18:23:11 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-07-12 18:23:10 ----A---- C:\WINDOWS\SYSWOW64\iepeers.dll
2017-07-12 18:23:10 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2017-07-12 18:23:10 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-07-12 18:23:10 ----A---- C:\WINDOWS\system32\odbcconf.dll
2017-07-12 18:23:10 ----A---- C:\WINDOWS\system32\LocationFramework.dll
2017-07-12 18:23:10 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-07-12 18:23:09 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-07-12 18:23:09 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-07-12 18:23:09 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2017-07-12 18:23:08 ----A---- C:\WINDOWS\system32\wlidsvc.dll
2017-07-12 18:23:08 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-07-12 18:23:08 ----A---- C:\WINDOWS\system32\Windows.Graphics.Printing.3D.dll
2017-07-12 18:23:07 ----A---- C:\WINDOWS\system32\msv1_0.dll
2017-07-12 18:23:07 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-07-12 18:23:07 ----A---- C:\WINDOWS\system32\Geolocation.dll
2017-07-12 18:23:07 ----A---- C:\WINDOWS\system32\dxtrans.dll
2017-07-12 18:23:06 ----A---- C:\WINDOWS\system32\iepeers.dll
2017-07-12 18:23:05 ----A---- C:\WINDOWS\system32\wininet.dll
2017-07-12 18:23:05 ----A---- C:\WINDOWS\system32\vbscript.dll
2017-07-12 18:23:05 ----A---- C:\WINDOWS\system32\LogonController.dll
2017-07-12 18:23:05 ----A---- C:\WINDOWS\system32\credprovhost.dll
2017-07-12 18:23:04 ----A---- C:\WINDOWS\system32\ole32.dll
2017-07-12 18:23:04 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-07-12 18:23:04 ----A---- C:\WINDOWS\system32\msdtctm.dll
2017-07-12 18:23:03 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2017-07-12 18:23:02 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2017-07-12 18:23:02 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-07-12 18:23:02 ----A---- C:\WINDOWS\system32\d2d1.dll
2017-07-12 18:23:02 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-07-12 18:23:01 ----A---- C:\WINDOWS\system32\Windows.Web.dll
2017-07-12 18:23:01 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2017-07-12 18:23:01 ----A---- C:\WINDOWS\system32\StructuredQuery.dll
2017-07-12 18:23:00 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-07-12 18:22:59 ----A---- C:\WINDOWS\system32\Windows.Web.Http.dll
2017-07-12 18:22:59 ----A---- C:\WINDOWS\system32\Windows.Networking.dll
2017-07-12 18:22:59 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2017-07-12 18:22:59 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-07-12 18:22:59 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-07-12 18:22:58 ----A---- C:\WINDOWS\system32\WpAXHolder.dll
2017-07-12 18:22:58 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-07-12 18:22:58 ----A---- C:\WINDOWS\system32\kerberos.dll
2017-07-12 18:22:57 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-07-12 18:22:53 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-07-12 18:22:52 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2017-07-12 18:22:52 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2017-07-12 18:22:52 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-07-12 18:22:48 ----A---- C:\WINDOWS\system32\drivers\http.sys
2017-07-12 18:22:48 ----A---- C:\WINDOWS\system32\dcomp.dll
2017-07-12 18:22:47 ----A---- C:\WINDOWS\system32\msinfo32.exe
2017-07-12 18:22:46 ----A---- C:\WINDOWS\system32\ntdll.dll
2017-07-12 18:22:46 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2017-07-12 18:22:45 ----A---- C:\WINDOWS\system32\msxml3.dll
2017-07-12 18:22:45 ----A---- C:\WINDOWS\system32\hal.dll
2017-07-12 18:22:45 ----A---- C:\WINDOWS\system32\drivers\dfsc.sys
2017-07-12 18:22:45 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2017-07-12 18:22:43 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2017-07-12 18:22:43 ----A---- C:\WINDOWS\system32\drivers\mup.sys
2017-07-12 18:22:42 ----A---- C:\WINDOWS\system32\drivers\tcpipreg.sys
2017-07-12 18:22:42 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-07-12 18:22:40 ----A---- C:\WINDOWS\system32\wlidprov.dll
2017-07-12 18:22:40 ----A---- C:\WINDOWS\system32\snmptrap.exe
2017-07-12 18:22:40 ----A---- C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2017-07-12 18:22:40 ----A---- C:\WINDOWS\system32\DeviceDirectoryClient.dll
2017-07-12 18:22:39 ----A---- C:\WINDOWS\system32\Windows.Graphics.dll
2017-07-12 18:22:39 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2017-07-12 18:22:39 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2017-07-12 18:22:35 ----A---- C:\WINDOWS\system32\storagewmi.dll
2017-07-12 18:22:35 ----A---- C:\WINDOWS\system32\spaceman.exe
2017-07-12 18:22:35 ----A---- C:\WINDOWS\system32\SpaceAgent.exe
2017-07-12 18:22:35 ----A---- C:\WINDOWS\system32\mispace.dll
2017-07-12 18:22:35 ----A---- C:\WINDOWS\system32\apprepapi.dll
2017-07-12 18:22:34 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-07-12 18:22:34 ----A---- C:\WINDOWS\system32\GamePanel.exe
2017-07-12 18:22:33 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-07-12 18:22:33 ----A---- C:\WINDOWS\system32\apprepsync.dll
2017-07-12 18:22:31 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-07-12 18:22:31 ----A---- C:\WINDOWS\system32\Windows.System.UserDeviceAssociation.dll
2017-07-12 18:22:31 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-07-12 18:22:31 ----A---- C:\WINDOWS\system32\Windows.Devices.WiFi.dll
2017-07-12 18:22:31 ----A---- C:\WINDOWS\system32\Windows.Devices.Radios.dll
2017-07-12 18:22:31 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.Ngc.dll
2017-07-12 18:22:31 ----A---- C:\WINDOWS\system32\ErrorDetails.dll
2017-07-12 18:22:31 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\Windows.System.SystemManagement.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\Windows.Media.Devices.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\Windows.Gaming.Input.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\UserDeviceRegistration.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\Family.SyncEngine.dll
2017-07-12 18:22:30 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2017-07-12 18:22:29 ----A---- C:\WINDOWS\system32\winlogon.exe
2017-07-12 18:22:29 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-07-12 18:22:29 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2017-07-12 18:22:29 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-07-12 18:22:29 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-07-12 18:22:28 ----A---- C:\WINDOWS\system32\Windows.Globalization.dll
2017-07-12 18:22:28 ----A---- C:\WINDOWS\system32\NetSetupShim.dll
2017-07-12 18:22:28 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-07-12 18:22:28 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2017-07-12 18:22:27 ----A---- C:\WINDOWS\system32\Windows.Media.Import.dll
2017-07-12 18:22:27 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-07-12 18:22:27 ----A---- C:\WINDOWS\system32\Windows.Devices.AllJoyn.dll
2017-07-12 18:22:27 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2017-07-12 18:22:27 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-07-12 18:22:27 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2017-07-12 18:22:26 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-07-12 18:22:26 ----A---- C:\WINDOWS\system32\qmgr.dll
2017-07-12 18:22:26 ----A---- C:\WINDOWS\system32\msxml6.dll
2017-07-12 18:22:26 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2017-07-12 18:22:25 ----A---- C:\WINDOWS\system32\oleacc.dll
2017-07-12 18:22:25 ----A---- C:\WINDOWS\explorer.exe
2017-07-12 18:22:24 ----A---- C:\WINDOWS\system32\vaultcli.dll
2017-07-12 18:22:24 ----A---- C:\WINDOWS\system32\usermgr.dll
2017-07-12 18:22:24 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-07-12 18:22:24 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-07-12 18:22:23 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-07-12 18:22:23 ----A---- C:\WINDOWS\system32\Windows.Media.Speech.dll
2017-07-12 18:22:22 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-07-12 18:22:22 ----A---- C:\WINDOWS\system32\ShareHost.dll
2017-07-12 18:22:22 ----A---- C:\WINDOWS\system32\combase.dll
2017-07-12 18:22:21 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-07-12 18:22:21 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2017-07-12 18:22:21 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2017-07-12 18:22:20 ----A---- C:\WINDOWS\system32\twinui.dll
2017-07-12 18:22:16 ----A---- C:\WINDOWS\system32\CPFilters.dll
2017-07-12 18:22:15 ----A---- C:\WINDOWS\system32\dbgeng.dll
2017-07-12 18:22:14 ----A---- C:\WINDOWS\system32\OpcServices.dll
2017-07-12 18:22:14 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-07-12 18:22:14 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-07-12 18:22:13 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-07-12 18:22:13 ----A---- C:\WINDOWS\system32\uReFS.dll
2017-07-12 18:22:13 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-07-12 18:22:11 ----A---- C:\WINDOWS\system32\imapi2fs.dll
2017-07-12 18:22:11 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-07-12 18:22:11 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-07-12 18:22:09 ----A---- C:\WINDOWS\system32\Wldap32.dll
2017-07-12 18:22:08 ----A---- C:\WINDOWS\system32\untfs.dll
2017-07-12 18:22:08 ----A---- C:\WINDOWS\system32\autochk.exe
2017-07-12 18:22:08 ----A---- C:\WINDOWS\system32\autofmt.exe
2017-07-12 18:22:08 ----A---- C:\WINDOWS\system32\autoconv.exe
2017-07-12 18:22:07 ----A---- C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2017-07-12 18:22:07 ----A---- C:\WINDOWS\system32\MsSpellCheckingFacility.dll
2017-07-12 18:22:07 ----A---- C:\WINDOWS\system32\Family.Client.dll
2017-07-12 18:22:07 ----A---- C:\WINDOWS\system32\certutil.exe
2017-07-12 18:22:06 ----A---- C:\WINDOWS\system32\ifsutil.dll
2017-07-12 18:22:05 ----A---- C:\WINDOWS\system32\uudf.dll
2017-07-12 18:22:05 ----A---- C:\WINDOWS\system32\ScDeviceEnum.dll
2017-07-12 18:22:05 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-07-12 18:22:04 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2017-07-12 18:22:04 ----A---- C:\WINDOWS\system32\certprop.dll
2017-07-12 18:22:03 ----A---- C:\WINDOWS\system32\uexfat.dll
2017-07-12 18:22:03 ----A---- C:\WINDOWS\system32\sendmail.dll
2017-07-12 18:22:02 ----A---- C:\WINDOWS\system32\wpd_ci.dll
2017-07-12 18:22:02 ----A---- C:\WINDOWS\system32\ufat.dll
2017-07-12 18:22:02 ----A---- C:\WINDOWS\system32\KdsCli.dll
2017-07-12 18:22:02 ----A---- C:\WINDOWS\system32\cnvfat.dll
2017-07-12 18:22:01 ----A---- C:\WINDOWS\system32\uReFSv1.dll
2017-07-12 18:22:01 ----A---- C:\WINDOWS\system32\Family.Authentication.dll
2017-07-12 18:22:00 ----A---- C:\WINDOWS\system32\fdProxy.dll
2017-07-12 18:22:00 ----A---- C:\WINDOWS\system32\easwrt.dll
2017-07-12 18:22:00 ----A---- C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2017-07-12 18:21:59 ----A---- C:\WINDOWS\system32\XamlTileRender.dll
2017-07-12 18:21:59 ----A---- C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2017-07-12 18:21:59 ----A---- C:\WINDOWS\system32\ExecModelClient.dll
2017-07-12 07:20:31 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerInstaller.exe
2017-07-10 06:59:18 ----D---- C:\WINDOWS\system32\UNP
2017-07-10 06:59:18 ----AD---- C:\Program Files\UNP
2017-07-02 17:03:35 ----D---- C:\Users\pavilion\AppData\Roaming\NewspaperDirect
2017-07-01 12:04:46 ----D---- C:\Ecru
2017-07-01 12:04:12 ----HD---- C:\WINDOWS\PIF

====== List of files/folders modified in the last 1 month ======

2017-07-24 06:52:50 ----D---- C:\WINDOWS\Prefetch
2017-07-24 06:52:48 ----D---- C:\Program Files\trend micro
2017-07-24 06:50:01 ----D---- C:\WINDOWS\Temp
2017-07-24 06:48:37 ----D---- C:\WINDOWS\system32\SleepStudy
2017-07-24 06:42:53 ----RD---- C:\WINDOWS\Microsoft.NET
2017-07-24 06:09:02 ----D---- C:\WINDOWS\system32\sru
2017-07-24 01:40:25 ----D---- C:\ProgramData\PDFC
2017-07-24 00:46:00 ----D---- C:\Users\pavilion\AppData\Roaming\Raptr
2017-07-24 00:44:45 ----HD---- C:\ProgramData
2017-07-24 00:41:15 ----D---- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-07-24 00:38:28 ----D---- C:\Windows
2017-07-23 20:15:55 ----SHD---- C:\System Volume Information
2017-07-23 09:38:29 ----D---- C:\WINDOWS\AppReadiness
2017-07-23 09:38:23 ----HD---- C:\Program Files\WindowsApps
2017-07-22 21:05:30 ----D---- C:\WINDOWS\system32\config
2017-07-22 10:53:22 ----D---- C:\WINDOWS\rescache
2017-07-22 10:23:02 ----D---- C:\WINDOWS\system32\catroot2
2017-07-22 09:20:36 ----D---- C:\WINDOWS\system32\DriverStore
2017-07-22 09:20:34 ----D---- C:\WINDOWS\WinSxS
2017-07-22 08:43:02 ----RSD---- C:\WINDOWS\assembly
2017-07-22 08:35:32 ----D---- C:\WINDOWS\debug
2017-07-22 03:14:50 ----D---- C:\WINDOWS\System32
2017-07-21 18:04:19 ----D---- C:\WINDOWS\system32\Tasks
2017-07-21 16:08:39 ----SHDC---- C:\WINDOWS\Installer
2017-07-21 16:08:39 ----D---- C:\Config.Msi
2017-07-21 16:08:28 ----D---- C:\Program Files (x86)\Common Files
2017-07-21 16:05:30 ----AD---- C:\Program Files (x86)\Microsoft Office
2017-07-21 15:42:24 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-21 15:35:31 ----D---- C:\WINDOWS\INF
2017-07-21 15:35:23 ----D---- C:\WINDOWS\system32\drivers
2017-07-21 07:52:03 ----AD---- C:\Program Files (x86)
2017-07-21 07:24:38 ----D---- C:\WINDOWS\Tasks
2017-07-21 07:13:22 ----D---- C:\Program Files\Common Files
2017-07-21 07:11:07 ----AD---- C:\WINDOWS\SysWOW64
2017-07-21 07:10:56 ----HD---- C:\WINDOWS\system32\GroupPolicy
2017-07-21 07:10:52 ----RD---- C:\Program Files
2017-07-21 07:03:39 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2017-07-14 07:40:41 ----D---- C:\WINDOWS\SYSWOW64\en-US
2017-07-14 07:40:41 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-07-14 07:40:35 ----D---- C:\WINDOWS\system32\wbem
2017-07-14 07:40:35 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-07-14 07:40:35 ----D---- C:\WINDOWS\system32\oobe
2017-07-14 07:40:33 ----D---- C:\WINDOWS\system32\en-US
2017-07-14 07:40:33 ----D---- C:\WINDOWS\system32\cs-CZ
2017-07-14 07:40:33 ----D---- C:\WINDOWS\system32\appraiser
2017-07-14 07:40:30 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-07-14 07:40:30 ----D---- C:\WINDOWS\ShellExperiences
2017-07-14 07:40:30 ----D---- C:\Program Files\Windows Photo Viewer
2017-07-14 07:40:30 ----D---- C:\Program Files\Windows Mail
2017-07-14 07:40:30 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-07-13 05:48:20 ----D---- C:\WINDOWS\system32\CatRoot
2017-07-12 18:55:51 ----D---- C:\WINDOWS\CbsTemp
2017-07-12 18:37:28 ----D---- C:\WINDOWS\system32\MRT
2017-07-12 18:31:01 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-07-12 08:08:33 ----D---- C:\Program Files (x86)\McAfee
2017-07-12 08:07:45 ----D---- C:\Program Files\Common Files\McAfee
2017-07-12 07:56:16 ----A---- C:\WINDOWS\SYSWOW64\enrollmentapi.dll
2017-07-12 07:29:28 ----A---- C:\AVScanner.ini
2017-07-12 07:28:47 ----D---- C:\WINDOWS\system32\Macromed
2017-07-12 07:28:43 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-07-10 06:51:16 ----D---- C:\ProgramData\AVAST Software
2017-07-02 17:08:49 ----D---- C:\ProgramData\WildTangent
2017-07-02 17:07:59 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2017-07-02 17:02:48 ----D---- C:\Program Files (x86)\Philips
2017-07-02 17:02:44 ----D---- C:\WINDOWS\SYSWOW64\drivers
2017-07-02 17:01:32 ----AD---- C:\Program Files (x86)\HP Games
2017-07-02 16:47:12 ----AD---- C:\Program Files (x86)\OpenOffice.org 3
2017-07-02 16:46:10 ----D---- C:\Program Files (x86)\Nokia
2017-07-02 16:46:09 ----D---- C:\ProgramData\Nokia
2017-07-02 16:45:45 ----D---- C:\Users\pavilion\AppData\Roaming\Nokia Suite
2017-07-02 16:45:45 ----D---- C:\Users\pavilion\AppData\Roaming\Nokia
2017-06-30 20:26:46 ----D---- C:\ProgramData\Skype
2017-06-30 16:46:35 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

====== List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R0 amd_sata;amd_sata; C:\WINDOWS\System32\drivers\amd_sata.sys [2010-08-13 75904]
R0 amd_xata;amd_xata; C:\WINDOWS\System32\drivers\amd_xata.sys [2010-08-13 38016]
R0 amdkmafd;@oem302.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmafd.sys [2016-02-26 23240]
R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [2017-07-20 198976]
R0 aswblog;aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [2017-07-20 343288]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [2017-07-20 57728]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2017-07-10 84392]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2017-07-10 361336]
R0 AtiPcie;@oem75.inf,%ATIPCIE_svcdesc%;AMD PCI Express (3GIO) Filter; C:\WINDOWS\System32\drivers\AtiPcie64.sys [2010-03-10 16440]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-02 48992]
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [2017-07-20 320008]
R1 aswKbd;aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [2017-07-10 41800]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2017-07-10 110352]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2017-07-10 1015848]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2017-07-10 585608]
R2 AODDriver4.01;AODDriver4.01; \??\C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2017-07-20 146696]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 NPF;NetGroup Packet Filter Driver; \??\C:\WINDOWS\system32\drivers\npf.sys [2016-04-26 35344]
R3 amdiox64;@oem100.inf,%amdio.SvcDesc%;AMD IO Driver; C:\WINDOWS\System32\drivers\amdiox64.sys [2010-02-18 46136]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2016-02-26 23981568]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2016-02-26 674816]
R3 AtiHDAudioService;@oem44.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2016-01-25 111120]
R3 dc3d;@oem120.inf,%dc3d.SvcDesc%;MS Hardware Device Detection Driver (USB); C:\WINDOWS\System32\drivers\dc3d.sys [2011-08-01 52584]
R3 dtultrascsibus;@oem315.inf,%DTULTRASCSIBUS.DeviceDesc%;DAEMON Tools Ultra Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtultrascsibus.sys [2017-01-13 30264]
R3 dtultrausbbus;@oem316.inf,%DTULTRAUSBBUS.DeviceDesc%;DAEMON Tools Ultra Virtual USB Bus; C:\WINDOWS\System32\drivers\dtultrausbbus.sys [2017-01-13 47672]
R3 huawei_enumerator;huawei_enumerator; C:\WINDOWS\System32\drivers\ew_jubusenum.sys [2013-04-09 91648]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2016-09-09 175616]
R3 MSHUSBVideo;@oem43.inf,%FilterDisplayName%;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\WINDOWS\System32\Drivers\nx6000.sys [2010-12-13 36720]
R3 netr28x;@oem123.inf,%Generic.Service.DispName%;Ralink 802.11n Extensible Wireless Driver; C:\WINDOWS\system32\DRIVERS\netr28x.sys [2015-06-12 2554528]
R3 Point64;@oem72.inf,%point64.SvcDesc%;Microsoft IntelliPoint Filter Driver; C:\WINDOWS\System32\drivers\point64.sys [2011-08-01 45416]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2016-07-16 589824]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-10-05 64352]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2017-06-21 88416]
S2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2017-07-10 198768]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 aswHdsKe;aswHdsKe; \??\C:\WINDOWS\system32\drivers\aswHdsKe.sys [2016-08-27 83312]
S3 aswHwid;aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [2017-07-10 46984]
S3 dg_ssudbus;@oem8.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\WINDOWS\system32\DRIVERS\ssudbus.sys [2017-05-18 131984]
S3 dot4;@oem276.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-10-19 151968]
S3 Dot4Print;@oem289.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-10-19 27040]
S3 dot4usb;@oem276.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-10-19 49056]
S3 FlashUSB;FlashUSB; C:\WINDOWS\System32\drivers\FlashUSB.sys [2013-05-02 19968]
S3 fssfltr;fssfltr; C:\WINDOWS\system32\DRIVERS\fssfltr.sys [2012-09-12 57856]
S3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\SysWOW64\FsUsbExDisk.SYS [2013-02-05 37344]
S3 HTCAND64;HTC Device Driver; C:\WINDOWS\System32\Drivers\ANDROIDUSB.sys [2009-11-02 33736]
S3 HtcVCom32;HTC Diagnostic Port; C:\WINDOWS\system32\DRIVERS\HtcVComV64.sys [2010-03-09 121800]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-08-06 73568]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver; C:\WINDOWS\system32\drivers\LGBusEnum.sys [2009-11-24 22408]
S3 mbamchameleon;mbamchameleon; \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys [2016-08-01 91352]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfdx64.sys [2012-10-17 26112]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2017-06-21 124928]

====== List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled) ======

R2 AdobeUpdateService;AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2016-10-12 744640]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2017-05-18 2246256]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2016-02-26 249344]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; %windir%\system32\svchost.exe -k apphost;"ServiceDll" = %windir%\system32\inetsrv\apphostsvc.dll
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2017-04-03 83768]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2017-07-20 263312]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CDPUserSvc_dbcfd;CDPUserSvc_dbcfd; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2017-07-18 4412104]
R2 FirebirdGuardianDefaultInstance;Firebird Guardian - DefaultInstance; C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbguard.exe [2007-12-12 65536]
R2 GoProDeviceDetectionService;GoPro Device Detection Service; C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe [2017-01-27 37808]
R2 HPClientSvc;HP Client Services; C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-08-06 291896]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\syswow64\svchost.exe [2016-07-16 38792]
R2 HPSLPSVC;HP Network Devices Support; C:\Windows\system32\svchost.exe -k HPService;"ServiceDll" = C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2016-09-09 26112]
R2 OneSyncSvc_dbcfd;Hostitel synchronizace_dbcfd; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R2 pdfcDispatcher;PDF Document Manager; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2010-09-28 1119768]
R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [2006-12-19 81920]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\syswow64\PnkBstrA.exe [2015-09-26 75064]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\syswow64\PnkBstrB.exe [2016-12-17 214520]
R3 Disc Soft Ultra Bus Service;Disc Soft Ultra Bus Service; C:\Program Files\DAEMON Tools Ultra\DiscSoftBusServiceUltra.exe [2016-12-12 4854464]
R3 FirebirdServerDefaultInstance;Firebird Server - DefaultInstance; C:\Program Files (x86)\Firebird\Firebird_1_5\bin\fbserver.exe [2007-12-12 1531989]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\syswow64\svchost.exe [2016-07-16 38792]
R3 PimIndexMaintenanceSvc_dbcfd;Data kontaktů_dbcfd; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\RMapi.dll
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" = %SystemRoot%\System32\CDPUserSvc.dll
S2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360]
S2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360]
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-16 136360]
S2 Pml Driver HPZ12;Pml Driver HPZ12; %SystemRoot%\System32\svchost.exe -k HPZ12;"ServiceDll" = C:\WINDOWS\system32\HPZipm12.dll
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2017-06-01 317400]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920]
S3 aswbIDSAgent;aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [2017-07-20 7430992]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll" = %SystemRoot%\system32\FrameServer.dll
S3 fsssvc;Windows Live Family Safety Service; C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2014-03-31 1512640]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\hvhostsvc.dll
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2017-07-14 689976]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll" = %SystemRoot%\System32\irmon.dll
S3 MessagingService_dbcfd;Služba zasílání zpráv_dbcfd; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll" =
S3 NETGEARGenieDaemon;NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [2016-03-09 232192]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-07-18 213704]
S3 ServiceLayer;ServiceLayer; C:\Program Files (x86)\PC Connectivity Solution\ServiceLayer.exe [2013-04-18 737616]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [2011-06-20 73728]
S4 NMIndexingService;NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [2008-01-22 275752]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll" = %systemroot%\system32\Windows.SharedPC.AccountManager.dll

-----------------EOF-----------------

Daveson
Návštěvník
Návštěvník
Příspěvky: 140
Registrován: 06 kvě 2008 12:38
Bydliště: Zlín
Kontaktovat uživatele:

Re: Viry v PC a nechtěný One systeme Care Launcher

#3 Příspěvek od Daveson »

info.txt logfile of random's system information tool 1.16 2017-07-24 06:53:02

====== MBR ======

0x33C08ED0BC007CFB8EC08ED88BF4BF0006B90002FCF3A4EA60060000000000005265636F766572794D6772200040B6720000000000000000000000000000000000000000000000000000000000000D0A0000000057000000FFFFFFFFFFFFFFFF864CBDBE3006ACB40E33DBCD100AC075F5E30BFE0613065353E87000EB39B411CD16742DB410CD1680FC8575F13C0075EDEB248B166C04FA66A11C06BF5406B103F266AFFB3D00006C042BC283F82476E6B00184C0751CBBC67D668B37668B3E2C06663BF7740780C31073EEEB05BB2806EB10BBC27D807FFC00780780C31073F5EBFE66FF7704E80200FFE4C8100000B408B280CD138AC1243FFEC68AD8F6E6C0E90686CD4191F7E13956068B56068B4604731CF7F19192F6F386CDC0E10602CC418AF0B80102BB007C86261306EB1483C4100E0E52500E68007C6A016A108BF4B80042B280CD13C9C204001E50530E1FBB1B06A01704240F884704E4603CE0741A3C1D74103C2A740C3C3674083C38740484C0790666832700EB06FE07021F88075B581FEA0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000AE9DDCB700008020210007DF130C000800000020030000DF140C07FEFFFF002803000008A57200FEFFFF27FEFFFF0030A87200100E0000FEFFFF07FEFFFF0040B6720020BA0155AA

====== Uninstall list ======

[20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}\setup.exe" /z-uninstall <<Hidden
[2016/09/09 01:51:24]-->C:\Program Files (x86)\Nero\Nero 7\\nero\uninstall\UNNERO.exe /UNINSTALL <<Hidden
[2016/09/09 01:51:24]-->C:\Windows\UNNeroBackItUp.exe /UNINSTALL <<Hidden
[2016/09/09 01:51:24]-->C:\Windows\UNNeroMediaHome.exe /UNINSTALL <<Hidden
[2016/09/09 01:51:24]-->C:\Windows\UNNeroShowTime.exe /UNINSTALL <<Hidden
[2016/09/09 01:51:24]-->C:\Windows\UNNeroVision.exe /UNINSTALL <<Hidden
[2016/09/09 01:51:24]-->C:\Windows\UNRecode.exe /UNINSTALL <<Hidden
[2017/02/26 09:56:51]-->"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HDCore\Uninstaller.exe" --uninstall=1 --sapCode=COCM --productVersion=1.0 --productPlatform=win32 --productAdobeCode={COCM-1.0.4-ADBEADBEADBEADBEADBEADBEA} --productName="STI_Color_CommonSetCMYK_HD" --mode=1 <<Hidden
[2017/02/26 09:56:51]-->"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HDCore\Uninstaller.exe" --uninstall=1 --sapCode=CORE --productVersion=1.0 --productPlatform=win32 --productAdobeCode={CORE-1.0-32-ADBEADBEADBEADBEADBEADBE} --productName="STI_Color_HD" --mode=1 <<Hidden
[2017/02/26 09:56:51]-->"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HDCore\Uninstaller.exe" --uninstall=1 --sapCode=CORG --productVersion=1.0 --productPlatform=win32 --productAdobeCode={CORG-1.0.4-ADBEADBEADBEADBEADBEADBEA} --productName="STI_Color_CommonSetRGB_HD" --mode=1 <<Hidden
[2017/07/03 17:31:50]-->"C:\Program Files (x86)\HP Games\Game Explorer Categories - genres\Uninstall.exe" <<Hidden
[2017/07/03 17:31:50]-->"C:\Program Files (x86)\HP Games\Web Link - Club Penguin\Uninstall.exe" <<Hidden
[2017/07/03 17:31:50]-->"C:\Program Files (x86)\HP Games\Web Link - Dark Orbit\Uninstall.exe" <<Hidden
[2017/07/03 17:31:50]-->"C:\Program Files (x86)\HP Games\Web Link - Seafight\Uninstall.exe" <<Hidden
[2017/07/03 17:31:50]-->"C:\Program Files (x86)\HP Games\Web Link - Shaiya\Uninstall.exe" <<Hidden
[2017/07/03 17:31:50]-->"C:\Program Files (x86)\HP Games\Web Link - World of Warcraft\Uninstall.exe" <<Hidden
µTorrent [2016/09/09 01:51:25]-->C:\Users\pavilion\AppData\Roaming\uTorrent\uninstall.exe
4-Day Forecast [20120928]-->MsiExec.exe /I{B17C38D4-36B6-4941-BD24-917AA8092E84}
64 Bit HP CIO Components Installer [20110817]-->MsiExec.exe /I{FF21C3E6-97FD-474F-9518-8DCBE94C2854}
7-Zip 16.04 (x64 edition) [20161126]-->MsiExec.exe /I{23170F69-40C1-2702-1604-000001000000}
Adobe Acrobat Reader DC - Czech [20170713]-->MsiExec.exe /I{AC76BA86-7AD7-1029-7B44-AC0F074E4100}
Adobe Creative Cloud [2017/02/25 19:50:24]-->"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\Creative Cloud Uninstaller.exe"
Adobe Flash Player 26 NPAPI [2017/07/12 07:21:15]-->C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_137_Plugin.exe -maintain plugin
Adobe Flash Player 26 PPAPI [2017/07/12 07:28:50]-->C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_26_0_0_137_pepper.exe -maintain pepperplugin
Adobe Illustrator CC 2017 [2017/02/27 20:34:45]-->"C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HDCore\Uninstaller.exe" --uninstall=1 --sapCode=ILST --productVersion=21.0.0 --productPlatform=win64 --productAdobeCode={ILST-21.0.0-64-ADBEADBEADBEADBEADBEA} --productName="Illustrator CC (2017)" --mode=1
Adobe Refresh Manager [20170507]-->MsiExec.exe /I{AC76BA86-0804-1033-1959-001824225037}
AMD Accelerated Video Transcoding [20130321]-->MsiExec.exe /X{2394E621-62FE-72DF-057F-F51EB4BD2077}
AMD APP SDK Runtime [20130321]-->MsiExec.exe /I{503F672D-6C84-448A-8F8F-4BC35AC83441}
AMD Drag and Drop Transcoding [20110816]-->MsiExec.exe /X{ADED6869-D6D1-671E-9653-3782C21FA809}
AMD Install Manager [2016/10/25 15:57:27]-->"C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe" /UNINSTALL /IGNORE_UPGRADE /ON_REBOOT_MESSAGE:NO
AMD Install Manager [20161025]-->msiexec /q/x{80595353-6197-2EB6-F14C-C1F4AC093311} REBOOT=ReallySuppress
AMD Media Foundation Decoders [20130321]-->MsiExec.exe /X{A44E3BC0-77C3-3F36-2034-4F8F578B7D1B}
Apple Mobile Device Support [20170518]-->MsiExec.exe /I{0A596141-97D5-45FA-9281-98DFAF48D579}
Apple Software Update [20170401]-->MsiExec.exe /I{52D87F32-70E4-4348-8148-C0B9F35B1314}
ASUS Backtracker [20160108]-->MsiExec.exe /I{C15C060C-ED1C-49EB-83B3-F7C0FD1CD661}
aTube Catcher [2016/09/09 01:51:23]-->C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\uninstall.exe
aTube Catcher verze 3.8 [20170328]-->"C:\Program Files (x86)\DsNET Corp\aTube Catcher 2.0\unins000.exe"
Avast Free Antivirus [2017/07/24 06:29:34]-->C:\Program Files\AVAST Software\Avast\Setup\Instup.exe /control_panel
Balíček ovladače systému Windows - Nokia pccsmcfd LegacyDriver (05/31/2012 7.1.2.0) [2016/09/09 01:50:58]-->C:\PROGRA~1\DIFX\F4092D~1\dpinst.exe /u C:\Windows\system32\DRVSTORE\pccsmcfdx6_95B9C4C4739674B910F22E6D0FB93B9D8DD7E72A\pccsmcfdx64.inf
BARUM RALLY - Semetín 2009, Semetín 2010 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSemetinUninst.exe"
Bing Rewards Client Installer [20101230]-->MsiExec.exe /X{61EDBE71-5D3E-4AB7-AD95-E53FEAF68C17}
Bonjour [20160625]-->MsiExec.exe /X{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}
Catalyst Control Center - Branding [20130321]-->MsiExec.exe /I{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}
Catalyst Control Center - Branding [20161011]-->MsiExec.exe /I{11087D24-567D-7D88-69C6-D7A08B5F4C47}
CCleaner [2017/07/24 06:29:34]-->"C:\Program Files\CCleaner\uninst.exe"
CyberLink DVD Suite Deluxe [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}\setup.exe" /z-uninstall
D3DX10 [20120211]-->MsiExec.exe /X{E09C4DB7-630C-4F06-A631-8EA7239923AF}
DAEMON Tools Ultra [2017/01/13 08:13:12]-->C:\Program Files\DAEMON Tools Ultra\uninst.exe
Defraggler [2016/09/09 01:50:58]-->"C:\Program Files\Defraggler\uninst.exe"
DVD Menu Pack for HP MediaSmart Video [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}\setup.exe" /z-uninstall
DVD Menu Pack for HP MediaSmart Video [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}\setup.exe" /z-uninstall /zMS
ESET Online Scanner v3 [2016/09/09 01:51:23]-->C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineScannerUninstaller.exe
EVEREST Ultimate Edition v5.02 [2016/09/09 01:51:23]-->"C:\Program Files (x86)\Lavalys\EVEREST Ultimate Edition\unins000.exe"
Facebook Messenger 2.1.4814.0 [20130309]-->MsiExec.exe /X{7204BDEE-1A48-4D95-A964-44A9250B439E}
Facebook Video Calling 2.0.0.447 [20140113]-->MsiExec.exe /X{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}
Firebird 1.5.5 [2017/06/16 08:06:13]-->"C:\Program Files (x86)\Firebird\Firebird_1_5\unins000.exe"
Fotogalerie [20140614]-->MsiExec.exe /X{F37D360D-9308-4BB1-8515-DC6B637B9486}
Google Drive [20170330]-->MsiExec.exe /X{A1238426-ECDF-4639-BE2F-8D12A97AE23C}
Google Earth Plug-in [20160819]-->MsiExec.exe /I{57BB4801-61C8-4E74-9672-2160728A461E}
Google Chrome [20110804]-->"C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\setup.exe" --uninstall --system-level --verbose-logging
Google SketchUp 6 [20141026]-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{98736A65-3C79-49EC-B7E9-A3C77774B0E6}\setup.exe" -l0x5 -removeonly
Google SketchUp 6 [20141026]-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{B3D8B2F8-3C2C-45BC-933E-8B60E78F6684}\setup.exe" -l0x5 -removeonly
Google Update Helper [20141113]-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
Google Update Helper [20170430]-->MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
GoPro Studio [20170325]-->MsiExec.exe /X{C8312DB0-7002-4F37-95B7-836DF2227EE8}
HP Auto [20101230]-->MsiExec.exe /I{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}
HP Client Services [20101230]-->MsiExec.exe /I{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}
HP Customer Experience Enhancements [20101230]-->MsiExec.exe /X{07FA4960-B038-49EB-891B-9F95930AA544}
HP Customer Participation Program 13.0 [2016/09/09 01:50:58]-->C:\Program Files (x86)\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat -forcereboot
HP Imaging Device Functions 13.0 [2016/09/09 01:50:58]-->C:\Program Files (x86)\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
HP MediaSmart DVD [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
HP MediaSmart DVD [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{DCCAD079-F92C-44DA-B258-624FC6517A5A}\setup.exe" /z-uninstall
HP MediaSmart Music [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}\setup.exe" /z-uninstall
HP MediaSmart Music [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}\setup.exe" /z-uninstall /zMS
HP MediaSmart Photo [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}\setup.exe" /z-uninstall
HP MediaSmart Photo [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}\setup.exe" /z-uninstall
HP MediaSmart SmartMenu [20101230]-->MsiExec.exe /X{A40F60B1-F1E1-452E-96A5-FF97F9A2D102}
HP MediaSmart Video [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{D12E3E7F-1B13-4933-A915-16C7DD37A095}\setup.exe" /z-uninstall
HP MediaSmart Video [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{D12E3E7F-1B13-4933-A915-16C7DD37A095}\setup.exe" /z-uninstall
HP Photosmart All-In-One Driver Software 13.0 Rel. A [2016/09/09 01:50:59]-->C:\Program Files (x86)\HP\Digital Imaging\{17016DA1-F040-4032-BD36-34DD317BC9D5}\setup\hpzscr40.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
HP Photosmart Essential 3.5 [2016/09/09 01:50:58]-->C:\Program Files (x86)\HP\Digital Imaging\PhotosmartEssential\hpzscr01.exe -datfile hpqbud13.dat -forcereboot
HP Setup [20101230]-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{53469506-A37E-4314-A9D9-38724EC23A75}\setup.exe" -l0x9 -removeonly
HP Setup Manager [20101230]-->MsiExec.exe /I{AE856388-AFAD-4753-81DF-D96B19D0A17C}
HP Smart Web Printing 4.51 [2016/09/09 01:50:58]-->C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpzscr01.exe -datfile hpqbud15.dat
HP Solution Center 13.0 [2016/09/09 01:50:58]-->C:\Program Files (x86)\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat -forcereboot
HP Update [20101230]-->MsiExec.exe /X{DE77FE3F-A33D-499A-87AD-5FC406617B40}
HP Vision Hardware Diagnostics [20101230]-->MsiExec.exe /X{D79A02E9-6713-4335-9668-AAC7474C0C0E}
HPDiagnosticAlert [20110831]-->MsiExec.exe /I{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}
Humalamaki [20120520]-->MsiExec.exe /I{80BF3AE1-0992-4C5E-8C03-BE9A52A85205}
HydraVision [20101230]-->MsiExec.exe /X{8F9534FB-3BF3-8450-9B48-18F6EF8A6B37}
iCloud [20170720]-->MsiExec.exe /I{C510BB61-AE0B-4420-87AF-9CF646E86364}
iTunes [20170720]-->MsiExec.exe /I{02F95875-9527-49CC-B32F-970ADAEBD1EF}
Java 7 Update 55 [20130623]-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83217025FF}
Java(TM) 6 Update 24 [20111118]-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216024F0}
Java(TM) 6 Update 25 (64-bit) [20110804]-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F86416025FF}
Junk Mail filter update [20140614]-->MsiExec.exe /I{0BE9E708-5DC0-4963-9CFD-0AA519090E79}
K-Lite Codec Pack 7.2.0 (Full) [20110804]-->"C:\Program Files (x86)\K-Lite Codec Pack\unins000.exe"
LabelPrint [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" /z-uninstall
LabelPrint [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{C59C179C-668D-49A9-B6EA-0121CCFC1243}\setup.exe" /z-uninstall
LightScribe System Software [20110816]-->MsiExec.exe /X{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}
Logitech Gaming Software 5.10 [20110816]-->MsiExec.exe /X{1444D2EE-C7AD-44A8-844F-2634B49353D1}
Media Go [20140613]-->MsiExec.exe /X{F66C4A41-C3A8-4523-AB6C-BAA1DB38305C}
Media Go Network Downloader [20140613]-->MsiExec.exe /X{5562F05F-908C-4F15-9B3C-98D5FD32DCAB}
Media Go Video Playback Engine 2.4.129.12060 [20140613]-->MsiExec.exe /X{7C5AEEE1-6D7C-8922-4548-7BF9096077EC}
Microsoft .NET Framework 4.5.1 (CSY) [20140302]-->MsiExec.exe /X{50813B8C-FCBB-3C61-8039-EAAA93029066}
Microsoft .NET Framework 4.5.2 [20150514]-->MsiExec.exe /X{26784146-6E05-3FF9-9335-786C7C0FB5BE}
Microsoft Corporation [20120210]-->MsiExec.exe /I{9C5A08BF-BB99-4998-81BD-F6CC32483B34}
Microsoft Corporation [20120210]-->MsiExec.exe /I{B3BC9DB1-0B0A-48B0-B86B-EA77CAA7F800}
Microsoft DVD App Installation for Microsoft.WindowsDVDPlayer_2019.6.13291.0_neutral_~_8wekyb3d8bbwe (x64) [20151113]-->MsiExec.exe /I{25E80DAA-FD87-DCE5-202C-CC02F6673002}
Microsoft IntelliPoint 8.2 [20111024]-->MsiExec.exe /X{624C7F0A-89B2-4C49-9CAB-9D69613EC95A}
Microsoft IntelliPoint 8.2 [2016/09/09 01:50:58]-->msiexec.exe /I {624C7F0A-89B2-4C49-9CAB-9D69613EC95A}
Microsoft LifeCam [20120210]-->MsiExec.exe /X{5CE7E3F5-9803-4F32-AA89-2D8848A80109}
Microsoft Office File Validation Add-In [20160615]-->MsiExec.exe /I{90140000-2005-0000-0000-0000000FF1CE}
Microsoft Office Outlook Connector [20120211]-->MsiExec.exe /X{95140000-007A-0405-0000-0000000FF1CE}
Microsoft Office Professional Plus 2016 - cs-cz [2017/07/22 08:40:13]-->"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" scenario=install scenariosubtype=ARP sourcetype=None productstoremove=ProPlusRetail.16_cs-cz_x-none culture=cs-cz version.16=16.0
Microsoft OneDrive [2016/09/09 01:36:16]-->C:\Users\pavilion\AppData\Local\Microsoft\SkyDrive\17.0.4024.1220\OneDriveSetup.exe /uninstall
Microsoft PowerPoint Viewer [20170712]-->MsiExec.exe /X{95140000-00AF-0409-0000-0000000FF1CE}
Microsoft Security Client [20150514]-->MsiExec.exe /X{D9FCBAAE-DB72-488B-96D0-0AA3C892C0D6}
Microsoft Security Client CS-CZ Language Pack [20110816]-->MsiExec.exe /I{DC911ADF-7B60-40F2-A112-FB1EB6402D07}
Microsoft Silverlight [20170613]-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft SQL Server 2005 Compact Edition [ENU] [20120211]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
Microsoft Visual C++ 2005 Redistributable (x64) [20101230]-->MsiExec.exe /X{071c9b48-7c32-4621-a0ac-3f809523288f}
Microsoft Visual C++ 2005 Redistributable (x64) [20110816]-->MsiExec.exe /X{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}
Microsoft Visual C++ 2005 Redistributable (x64) [20110816]-->MsiExec.exe /X{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}
Microsoft Visual C++ 2005 Redistributable [20110816]-->MsiExec.exe /X{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}
Microsoft Visual C++ 2005 Redistributable [20150619]-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2005 Redistributable [20170225]-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 [20101230]-->MsiExec.exe /X{8220EEFE-38CD-377E-8595-13398D740ACE}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 [20101230]-->MsiExec.exe /X{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 [20110816]-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 [20101230]-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 [20101230]-->MsiExec.exe /X{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 [20160427]-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 [20150816]-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 [20150816]-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 [2016/09/09 01:25:56]-->"C:\ProgramData\Package Cache\{15134cb0-b767-4960-a911-f2d16ae54797}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 [2016/09/09 01:51:29]-->"C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 [2017/03/27 21:11:38]-->"C:\ProgramData\Package Cache\{22154f09-719a-4619-bb71-5b3356999fbf}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 [2017/02/25 19:43:08]-->"C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 [20160909]-->MsiExec.exe /X{AC53FC8B-EE18-3F9C-9B59-60937D0B182C}
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030 [20160113]-->MsiExec.exe /X{37B8F9C7-03FB-3253-8781-2517C99D7C00}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 [20160909]-->MsiExec.exe /X{A2CB1ACB-94A2-32BA-A15E-7D80319F7589}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030 [20160113]-->MsiExec.exe /X{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030 [20170225]-->MsiExec.exe /X{B175520C-86A2-35A7-8619-86DC379688B9}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 [20170327]-->MsiExec.exe /X{2F73A7B2-E50E-39A6-9ABC-EF89E4C62E36}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030 [20170225]-->MsiExec.exe /X{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 [2016/10/11 21:13:54]-->"C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 [2016/09/09 01:51:30]-->"C:\ProgramData\Package Cache\{ce085a78-074e-4823-8dc1-8a721b94b76d}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005 [20161011]-->MsiExec.exe /X{929FBD26-9020-399B-9A7A-751D61F0B942}
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005 [20161011]-->MsiExec.exe /X{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005 [20140613]-->MsiExec.exe /X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005 [20140613]-->MsiExec.exe /X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 [2017/02/25 19:44:09]-->"C:\ProgramData\Package Cache\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}\VC_redist.x64.exe" /uninstall
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 [2017/03/15 20:30:18]-->"C:\ProgramData\Package Cache\{e2803110-78b3-4664-a479-3611a381656a}\VC_redist.x86.exe" /uninstall
Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.23918 [20170225]-->MsiExec.exe /X{DFFEB619-5455-3697-B145-243D936DB95B}
Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.23918 [20170225]-->MsiExec.exe /X{7B50D081-E670-3B43-A460-0E2CDB5CE984}
Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.24215 [20170315]-->MsiExec.exe /X{69BCE4AC-9572-3271-A2FB-9423BDA36A43}
Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.24215 [20170315]-->MsiExec.exe /X{BBF2AC74-720C-3CB3-8291-5E34039232FA}
Microsoft_VC100_CRT_SP1_x64 [20151121]-->MsiExec.exe /I{680EDA59-9266-44B4-949E-0C24F65DFF82}
Microsoft_VC100_CRT_SP1_x86 [20151121]-->MsiExec.exe /I{E3B64CC5-C011-40C0-92BC-7316CD5E5688}
Mobiola Web Camera for S60 3.0.23 (OVI version) [20120208]-->"C:\Program Files (x86)\Mobiola Web Camera for S60\unins000.exe"
Movie Maker [20140614]-->MsiExec.exe /X{3D2CF65C-B544-4308-B996-700D3E5F6C4C}
Movie Maker [20140614]-->MsiExec.exe /X{DD67BE4B-7E62-4215-AFA3-F123A800A389}
Movie Theme Pack for HP MediaSmart Video [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{3023EBDA-BF1B-4831-B347-E5018555F26E}\setup.exe" /z-uninstall
Movie Theme Pack for HP MediaSmart Video [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{3023EBDA-BF1B-4831-B347-E5018555F26E}\setup.exe" /z-uninstall /zMS
MSVC80_x64_v2 [20151121]-->MsiExec.exe /I{4D668D4F-FAA2-4726-834C-31F4614F312E}
MSVC80_x86_v2 [20151121]-->MsiExec.exe /I{6D3245B1-8DB8-4A23-9CD2-2C90F40ABAF6}
MSVC90_x64 [20151121]-->MsiExec.exe /I{AB071C8B-873C-459F-ACA9-9EBE03C3E89B}
MSVC90_x86 [20151121]-->MsiExec.exe /I{AF111648-99A1-453E-81DD-80DBBF6DAD0D}
MSVCRT [20120211]-->MsiExec.exe /I{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}
MSVCRT_amd64 [20120211]-->MsiExec.exe /I{D0B44725-3666-492D-BEF6-587A14BD9BD9}
MSVCRT110 [20130330]-->MsiExec.exe /I{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}
MSVCRT110_amd64 [20130330]-->MsiExec.exe /I{E9FA781F-3E80-4399-825A-AD3E11C28C77}
MSXML 4.0 SP2 (KB954430) [20110816]-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688) [20110816]-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
MSXML 4.0 SP3 Parser (KB2721691) [20120711]-->MsiExec.exe /I{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}
MSXML 4.0 SP3 Parser (KB2758694) [20130305]-->MsiExec.exe /I{1D95BA90-F4F8-47EC-A882-441C99D30C1E}
MSXML 4.0 SP3 Parser (KB973685) [20111114]-->MsiExec.exe /I{859DFA95-E4A6-48CD-B88E-A3E483E89B44}
MusicStation [2016/09/09 01:51:24]-->"C:\Program Files (x86)\Hewlett-Packard\MusicStation\Uninstall.exe"
MyFreeCodec [2016/09/09 01:36:16]-->C:\Program Files (x86)\MyFree Codec\1.0b beta\uninstall.exe
Nero 7 Ultra Edition [20110816]-->MsiExec.exe /X{F90D6825-8F1F-4E3A-9E42-A9C8A9DD1029}
neroxml [20110816]-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
NETGEAR Genie [2016/09/09 01:51:24]-->C:\Program Files (x86)\NETGEAR Genie\uninstall.exe
OCR Software by I.R.I.S. 13.0 [2016/09/09 01:50:58]-->C:\Program Files (x86)\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
Office 16 Click-to-Run Extensibility Component [20170721]-->MsiExec.exe /X{90160000-008C-0000-0000-0000000FF1CE}
Office 16 Click-to-Run Extensibility Component 64-bit Registration [20170721]-->MsiExec.exe /X{90160000-00DD-0000-1000-0000000FF1CE}
Office 16 Click-to-Run Licensing Component [20170721]-->MsiExec.exe /I{90160000-008F-0000-1000-0000000FF1CE}
Office 16 Click-to-Run Localization Component [20170616]-->MsiExec.exe /X{90160000-008C-0405-0000-0000000FF1CE}
OpenAL [2017/03/25 21:39:37]-->"C:\Program Files (x86)\OpenAL\oalinst.exe" /U
PC Connectivity Solution [20151121]-->MsiExec.exe /I{6D01D1B1-17BD-4F10-BB11-F08F0C47D42B}
PDF Complete Special Edition [2016/09/09 01:51:24]-->C:\Program Files (x86)\PDF Complete\uninstall.exe
Photo Common [20140614]-->MsiExec.exe /X{15BFD731-A10E-43E9-9D18-0F682BC0480F}
Photo Gallery [20140614]-->MsiExec.exe /X{07AAB66E-4718-422D-9218-4AFB3C922A71}
PhotoNow! [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" /z-uninstall
PhotoNow! [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{D36DD326-7280-11D8-97C8-000129760CBE}\Setup.exe" /z-uninstall
PictureMover [20101230]-->MsiExec.exe /X{264FE20A-757B-492a-B0C3-4009E2997D8A}
PlayReady PC Runtime amd64 [20101230]-->MsiExec.exe /X{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}
PlaysTV [2016/09/09 01:51:24]-->"C:\Program Files (x86)\Raptr Inc\PlaysTV\uninstall.exe"
Podpora aplikací Apple (32bitová) [20170720]-->MsiExec.exe /I{D2FE6376-E549-4F63-A2C5-CA24DA035DE4}
Podpora aplikací Apple (64bitová) [20170720]-->MsiExec.exe /I{BB109E24-EE90-485B-A28B-ADDEFB40540B}
Power2Go [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
Power2Go [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\setup.exe" /z-uninstall
PowerDirector [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
PowerDirector [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{CB099890-1D5F-11D5-9EA9-0050BAE317E1}\setup.exe" /z-uninstall
Pribram 2.1 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPribramUninst.exe"
Quik [2017/06/16 08:06:13]-->"C:\ProgramData\Package Cache\{50b3f174-39f4-4599-a8dc-e66fc4e3540e}\QuikForDesktop.exe" /uninstall
Quik [20170325]-->MsiExec.exe /X{2B17EF27-5A63-4499-8410-B7D5CFF3FAB4}
Raptr [2017/06/16 07:08:51]-->"C:\Program Files (x86)\Raptr Inc\Raptr\uninstall.exe"
RBR Ai-Petri (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRAiPetriUninst.exe"
RBR Akagi Mountain (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRAkagiUninst.exe"
RBR Akagi Mountain II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRAkagi2Uninst.exe"
RBR Azov (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRAzovUninst.exe"
RBR Azov II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRAzov2Uninst.exe"
RBR Bergheim (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRBergheimUninst.exe"
RBR Bergheim 1.1(remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSieversdorfUninst.exe"
RBR Berica v1.1 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRBerica_v11_Uninst.exe"
RBR Castrezzato (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRCastrezzatoUninst.exe"
RBR Courcelles Val'd Esnoms (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRCourcellesUninst.exe"
RBR Daniel Bonara (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRDanielBonara_v1.1Uninst.exe"
RBR Fernet Branca 1.02 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRFernet_Branca_v102Uninst.exe"
RBR Foron (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRForonUninst.exe"
RBR Foron II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRForon2Uninst.exe"
RBR Foron Snow (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRForonSnowUninst.exe"
RBR Foron Snow II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRForonSnow2Uninst.exe"
RBR FSO Zeran (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRFSOZeranUninst.exe"
RBR GB Sprint Extreme v1.02 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRGBSprintExtreme_v1.02Uninst.exe"
RBR Gestel (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRGestelUninst.exe"
RBR Grand Canaria ROC 2000 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRROC2000Uninst.exe"
RBR Haugenau 1.02 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRHaugenau102Uninst.exe"
RBR Humalamaki Reversed (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRHumalamakiRUninst.exe"
RBR Hyppyjulma (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRHyppyjulmaUninst.exe"
RBR Jirkovicky 0.99 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRJirkovickyUninst.exe"
RBR Joukkovaara (remove only) [2017/05/28 11:34:14]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRJoukkovaaraUninst.exe"
RBR Junior Wheels 2 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRJuniorWeels2Uninst.exe"
RBR Junior Wheels I 1.2 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRJuniorWeels1_12Uninst.exe"
RBR Karlstad II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKarlstad2Uninst.exe"
RBR Karlstadt (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKarlstadtUninst.exe"
RBR Karowa 1.04 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKarowa_104Uninst.exe"
RBR Kolmenjarvet (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKolmenjarvet_IUninst.exe"
RBR Kolmenjarvet II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKolmenjarvet_IIUninst.exe"
RBR Kolmenjarvet tarmac (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKolmenjarvet_tarmacUninst.exe"
RBR Kolmenjarvet tarmac II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKolmenjarvet_tarmac_IIUninst.exe"
RBR Kormoran I (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKormoran1Uninst.exe"
RBR Kormoran II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKormoran2Uninst.exe"
RBR Kormoran v1.1 (remove only) [2017/05/28 11:30:59]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKormoran_v1.1Uninst.exe"
RBR Kuadonvaara (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRKuadonvaaraUninst.exe"
RBR La Rocca (remove only) [2017/01/14 12:03:52]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRLaRocca_Uninst.exe"
RBR Livadija II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRLivadija2Uninst.exe"
RBR Livadija v1.1 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRLivadijaV11Uninst.exe"
RBR Loch Ard (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRLochArdUninst.exe"
RBR Loch Ard II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRLochArd2Uninst.exe"
RBR Lyon - Gerland (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRLyonGerlandUninst.exe"
RBR Maton I (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMatonIUninst.exe"
RBR Maton II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMatonIIUninst.exe"
RBR Maton snow (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMaton_snowUninst.exe"
RBR Maton snow II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMaton_snow_IIUninst.exe"
RBR Mikolajki (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMikolajkiUninst.exe"
RBR Mlynky (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMlynkyUninst.exe"
RBR Mlynky (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMlynkyUninst.exe"
RBR Mlynky II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMlynky2Uninst.exe"
RBR Mlynky Snow (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMlynkySnowUninst.exe"
RBR Mlynky Snow II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMlynkySnowIIUninst.exe"
RBR Montekland 0.99 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMonteklandUninst.exe"
RBR Muxarello (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRMuxarelloUninst.exe"
RBR Northumbria V1.1 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRNorthumbria_v1.1_Uninst.exe"
RBR Passo Valle (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPassoValleUninst.exe"
RBR Passo Valle Reverse (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPassoValleRevUninst.exe"
RBR Peklo (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPekloUninst.exe"
RBR Peklo (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPekloUninst.exe"
RBR Peklo II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPekloIIUninst.exe"
RBR Peklo Snow (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPekloSnowUninst.exe"
RBR Peklo Snow (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPekloSnowUninst.exe"
RBR Peklo Snow II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPekloSnowIIUninst.exe"
RBR Peklo Snow_R(remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPekloSnow_RUninst.exe"
RBR Peklo_R (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPeklo_RUninst.exe"
RBR Peyregrosse Mandagout (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPeyregrosseUninst.exe"
RBR Peyregrosse Mandagout NIGHT (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPeyregrosseNightUninst.exe"
RBR Pian del Colle (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPiandelColleUninst.exe"
RBR Pikes Peak 2008 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPikesPeak2008Uninst.exe"
RBR Pribram (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPribram1Uninst.exe"
RBR Pribram 2 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPribram2Uninst.exe"
RBR Prospect Ridge 2A (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPR2AUninst.exe"
RBR PTD RallySprint 1.1 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRRallySprint11Uninst.exe"
RBR Puy du Lac (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRPuyduLacUninst.exe"
RBR Rally School Czech (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSchoolCZv1.2Uninst.exe"
RBR Rally School Czech II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSchoolCZ2Uninst.exe"
RBR Rallysprint Hondarribia 2011 (remove only) [2017/03/26 12:39:37]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRRallysprintHondarribia2011_Uninst.exe"
RBR Red Bull Hill Climb V1.1 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBR_RBHC_v11_Uninst.exe"
RBR Reversed Tracks (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRRevUninst.exe"
RBR ROC 2008 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRROC2008Uninst.exe"
RBR ROC 2008 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRROC2008Uninst.exe"
RBR RP 2009 Shakedown (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRRP2009Uninst.exe"
RBR RP 2009 Shakedown Reversed(remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRRP2009RevUninst.exe"
RBR RSI slalom gegeWRC (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRgegeWRCUninst.exe"
RBR RSI slalom Shonen (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRShonenUninst.exe"
RBR Sardian (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSardianUninst.exe"
RBR Sardian Night (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSardianNightUninst.exe"
RBR Shakedown Rally del Salento 2014 v1.1 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRShakedownRdS_v11Uninst.exe"
RBR Sherwood Forest Summer (remove only) [2017/05/28 11:26:52]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSherwoodForest_SummerUninst.exe"
RBR Sherwood Forest v1.02 (remove only) [2017/05/28 11:35:20]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSherwoodForest_v102Uninst.exe"
RBR Shomaru Pass (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRShomaruUninst.exe"
RBR Shomaru Pass II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRShomaru2Uninst.exe"
RBR School stage 2 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSch2uninst.exe"
RBR Slovakia Ring 2014 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSR2014Uninst.exe"
RBR Slovakia Ring 2014 II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSR2014_RUninst.exe"
RBR Snow France Pack (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSnowFranceUninst.exe"
RBR Sorica (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSoricaUninst.exe"
RBR Sosnova2010 (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSosnova2010Uninst.exe"
RBR Stage Humalamaki [2016/09/09 01:51:23]-->msiexec.exe /x {80BF3AE1-0992-4C5E-8C03-BE9A52A85205}
RBR Stage RP 2009 Shakedown [2016/09/09 01:51:25]-->msiexec.exe /x {B9B28AD2-32A5-4D74-8857-8C96AA45BBAD}
RBR Stage Versme [2016/09/09 01:51:25]-->msiexec.exe /x {5D0A3FB4-2B8A-4E1B-892B-35FABD761EE1}
RBR Sumburk (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSumburkUninst.exe"
RBR Sweet Lamb (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSweetLambUninst.exe"
RBR Sweet Lamb II (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSweetLamb2Uninst.exe"
RBR SWISS (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSwissUninst.exe"
RBR SWISS II (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRSwiss2Uninst.exe"
RBR Tavia (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRTaviaUninst.exe"
RBR Torre Vecchia v1.1 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRTorreVecchia_v11_Uninst.exe"
RBR Tournament plugin (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRTMuninst.exe"
RBR Travanca do Monte (remove only) [2017/03/28 22:30:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRTravancaDoMonteUninst.exe"
RBR Uchan-Su (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRUchanSuUninst.exe"
RBR Uchan-Su Winter (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRUchanSuWinUninst.exe"
RBR Undva reversed (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRUndva_reversedUninst.exe"
RBR Undva v1.2 (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRUndva_12Uninst.exe"
RBR Vieux Moulin-Perrancey (remove only) [2016/09/09 01:51:24]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRVieuxMoulinPerranceyUninst.exe"
RBR Wisla Shakedown Zamarski (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRWislaUninst.exe"
RBR Zaraso Salos Trekas - 2 laps (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRZarasoSalos2lUninst.exe"
RBR Zaraso Salos Trekas - 5 laps (remove only) [2016/09/09 01:51:25]-->"C:\Program Files (x86)\SCi Games\Richard Burns Rally\RBRZarasoSalos5lUninst.exe"
Realtek High Definition Audio Driver [2016/09/10 08:02:43]-->C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709
Recovery Manager [20101230]-->"C:\Program Files (x86)\InstallShield Installation Information\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}\setup.exe" /z-uninstall
Richard Burns Rally [2017/06/16 08:06:13]-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{92C7D009-A464-4948-A980-7A3E28CB2F49}\setup.exe" -l0x5
RP 2009 Shakedown [20121126]-->MsiExec.exe /I{B9B28AD2-32A5-4D74-8857-8C96AA45BBAD}
SafeZone Stable 3.55.2393.609 [2017/07/22 08:40:13]-->"C:\Program Files\AVAST Software\SZBrowser\Launcher.exe" /uninstall
Samsung USB Driver for Mobile Phones [2016/09/09 01:51:00]-->C:\Program Files (x86)\Samsung\USB Drivers\Uninstall.exe
Seznam Software [2016/09/09 01:36:16]-->"C:\Users\pavilion\AppData\Roaming\Seznam.cz\szninstall.exe" -X
Shop for HP Supplies [2016/09/09 01:50:58]-->C:\Program Files (x86)\HP\Digital Imaging\HPSSupply\hpzscr01.exe -datfile hpqbud16.dat
Skype Click to Call [20130722]-->MsiExec.exe /I{B6CF2967-C81E-40C0-9815-C05774FEF120}
Skype™ 7.38 [20170630]-->MsiExec.exe /X{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}
Smart Switch [20170408]-->"C:\Program Files (x86)\InstallShield Installation Information\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}\setup.exe" -runfromtemp -l0x0409 -removeonly
Smart Switch [20170408]-->MsiExec.exe /I{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}
SPCA1528 PC Driver [20111223]-->"C:\Program Files (x86)\InstallShield Installation Information\{570C2A84-A145-4DF0-AE9D-012584DF09DC}\setup.exe" -runfromtemp -l0x0009 -removeonly
TeamViewer 10 [2017/07/24 06:29:34]-->C:\Program Files (x86)\TeamViewer\uninstall.exe
Total CMA Pack 0.50 [20110816]-->C:\Program Files (x86)\Total CMA Pack\Uninstall.exe
UltraVnc [20161012]-->"C:\Program Files\uvnc bvba\UltraVNC\unins000.exe"
VDRMInstaller 1.04.9 [2016/09/09 01:51:25]-->C:\Program Files (x86)\VDRMInstaller\uninstall.exe
Versme [20120520]-->MsiExec.exe /I{5D0A3FB4-2B8A-4E1B-892B-35FABD761EE1}
VFW_Codec32 [20170325]-->MsiExec.exe /I{08AA47F1-1469-430F-9163-6F11D58E1AA0}
VFW_Codec64 [20170325]-->MsiExec.exe /I{B9AE41FE-4730-4C52-8C77-442CD6F142B6}
VLC media player [2017/07/22 08:40:13]-->C:\Program Files (x86)\VideoLAN\VLC\uninstall.exe
VLC Streamer 5.27 [20160806]-->"C:\Program Files (x86)\Hobbyist Software\VLC Streamer\unins000.exe"
Win32DiskImager version 0.9.5 [20160930]-->"C:\Program Files (x86)\ImageWriter\unins000.exe"
Winamp [2016/09/09 01:51:25]-->"C:\Program Files (x86)\Winamp\UninstWA.exe"
Windows 10 Update and Privacy Settings [20170710]-->MsiExec.exe /X{4DFCD818-036A-4229-A67D-CF17DC461D92}
Windows Live Communications Platform [20140614]-->MsiExec.exe /I{41C61308-6CFD-4D54-AB6A-7136ED08A18E}
Windows Live Essentials [20140614]-->MsiExec.exe /I{9A470EA9-FF86-4C0E-992C-572BF2B9D6FF}
Windows Live Essentials [2016/09/09 01:51:25]-->C:\Program Files (x86)\Windows Live\Installer\wlarp.exe
Windows Live Family Safety [20140614]-->MsiExec.exe /I{2BC9C2FF-E0B7-40F9-B1A5-6F80663C301B}
Windows Live Family Safety [20140614]-->MsiExec.exe /X{CB3CA48C-95CB-412B-B7AE-6F2EA8F89907}
Windows Live ID Sign-in Assistant [20130330]-->MsiExec.exe /I{CE52672C-A0E9-4450-8875-88A221D5CD50}
Windows Live Installer [20140614]-->MsiExec.exe /I{659CB81C-B54E-4DF1-B618-F35777393A54}
Windows Live Mail [20140614]-->MsiExec.exe /I{3EE8FA69-F2A5-4BDB-9E23-3ABB2421B4FA}
Windows Live Mail [20140614]-->MsiExec.exe /I{B775C26B-EAA8-4A11-ACBF-76E52DF6B805}
Windows Live Messenger [20140614]-->MsiExec.exe /X{88B9357F-0845-465F-96B9-50976FB9C6C2}
Windows Live Messenger [20140614]-->MsiExec.exe /X{E703613B-BDAB-433E-A66A-DE0263E3D35D}
Windows Live MIME IFilter [20140614]-->MsiExec.exe /I{25058321-C33E-496B-8915-6FD64D362CAF}
Windows Live Photo Common [20140614]-->MsiExec.exe /X{1D6432B4-E24D-405E-A4AB-D7E6D088CBC9}
Windows Live PIMT Platform [20140614]-->MsiExec.exe /I{B2611F8A-EFE7-4E88-875D-19F0EFAE87E4}
Windows Live SOXE [20140614]-->MsiExec.exe /I{CDC1AB00-01FF-4FC7-816A-16C67F0923C0}
Windows Live SOXE Definitions [20140614]-->MsiExec.exe /I{D1893000-EA77-493C-8DDD-E262436E959B}
Windows Live UX Platform [20140614]-->MsiExec.exe /I{00F9DB8C-65D7-4D47-AB5F-F698EE38580D}
Windows Live UX Platform Language Pack [20140614]-->MsiExec.exe /I{E100E2B5-F2EF-4955-AB7A-C3F2125A3BCD}
Windows Live Writer [20140614]-->MsiExec.exe /X{04BE4035-3C8E-4B48-BFB8-1655849C0C8B}
Windows Live Writer [20140614]-->MsiExec.exe /X{124A05DC-3C47-4EEF-85CE-56D6C1CAE62B}
Windows Live Writer [20140614]-->MsiExec.exe /X{714E162E-CD4F-4F1B-8302-7F5179409C25}
Windows Live Writer Resources [20140614]-->MsiExec.exe /X{E5807449-CA84-42F6-9CE3-A0E2BDA9E24B}
Windows Media Player Firefox Plugin [20110804]-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}
WinRAR [2016/09/09 01:51:25]-->C:\Program Files (x86)\WinRAR\uninstall.exe
XP Codec Pack [2016/09/09 01:51:26]-->C:\Program Files (x86)\XP Codec Pack\Uninstall.exe
XviD MPEG-4 Video Codec [2016/09/09 01:51:26]-->C:\WINDOWS\system32\rundll32.exe setupapi,InstallHinfSection Remove_XviD 132 C:\WINDOWS\INF\xvid.inf

====== Hosts File ======

127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 distribution.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 linkmate.space
127.0.0.1 space1.adminpressure.space
127.0.0.1 trackpressure.website
127.0.0.1 doctorlink.space
127.0.0.1 plugpackdownload.net
127.0.0.1 dscdn.pw

====== System event log ======

Computer Name: pavilion-HP
Event Code: 4
Message: Připojení filtru systému souborů wcifs (verze 10.0, ‎2016‎-‎09‎-‎15T18:42:03.000000000Z) ke svazku \Device\HarddiskVolumeShadowCopy4 se nezdařilo. Filtr vrátil nestandardní konečný stav 0xC000000D. Tento filtr nebo jeho podpůrné aplikace by měly tento stav zpracovat. Pokud tento stav přetrvává, kontaktujte prodejce.
Record Number: 18444
Source Name: Microsoft-Windows-FilterManager
Time Written: 20170724042547.746881-000
Event Type: Upozornění
User: NT AUTHORITY\SYSTEM

Computer Name: pavilion-HP
Event Code: 7022
Message: Služba Optimalizace doručení přestala během spouštění reagovat.
Record Number: 18430
Source Name: Service Control Manager
Time Written: 20170723224426.128888-000
Event Type: Chyba
User:

Computer Name: pavilion-HP
Event Code: 10016
Message: Nastavení oprávnění specifické pro aplikaci neuděluje oprávnění Místní Aktivace pro serverovou aplikaci COM s identifikátorem CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
a APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
uživateli NT AUTHORITY\SYSTEM (SID: S-1-5-18) z adresy LocalHost (pomocí LRPC) běžící v kontejneru aplikací Není k dispozici – SID (Není k dispozici). Toto oprávnění zabezpečení lze změnit pomocí nástroje správy Služba komponent.
Record Number: 18428
Source Name: Microsoft-Windows-DistributedCOM
Time Written: 20170723224100.423171-000
Event Type: Chyba
User: NT AUTHORITY\SYSTEM

Computer Name: pavilion-HP
Event Code: 7000
Message: Služba Adaptér naslouchání Net.Msmq neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Record Number: 18427
Source Name: Service Control Manager
Time Written: 20170723224056.885551-000
Event Type: Chyba
User:

Computer Name: pavilion-HP
Event Code: 7000
Message: Služba Adaptér naslouchání Net.Pipe neuspěla při spuštění v důsledku následující chyby:
Služba neodpověděla na řídicí nebo zahajovací požadavek dostatečně včas.
Record Number: 18426
Source Name: Service Control Manager
Time Written: 20170723224056.885551-000
Event Type: Chyba
User:
====== Application event log ======

Computer Name: pavilion-HP
Event Code: 0
Message:
Record Number: 38115
Source Name: HP Client Services
Time Written: 20170724045301.554557-000
Event Type: Upozornění
User:

Computer Name: pavilion-HP
Event Code: 16
Message: Při aktualizaci stavu (unknown) na SECURITY_PRODUCT_STATE_ON došlo k chybě (chyba 05000000).
Record Number: 38114
Source Name: SecurityCenter
Time Written: 20170724045026.106826-000
Event Type: Chyba
User:

Computer Name: pavilion-HP
Event Code: 16
Message: Při aktualizaci stavu (unknown) na SECURITY_PRODUCT_STATE_ON došlo k chybě (chyba 05000000).
Record Number: 38113
Source Name: SecurityCenter
Time Written: 20170724045026.105826-000
Event Type: Chyba
User:

Computer Name: pavilion-HP
Event Code: 78
Message: Generování kontextu aktivace pro c:\program files (x86)\adobe\adobe creative cloud\utils\Creative Cloud Uninstaller.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku . Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní. Konfliktní součásti: Součást 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest. Součást 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest.
Record Number: 38096
Source Name: SideBySide
Time Written: 20170724041933.716645-000
Event Type: Chyba
User:

Computer Name: pavilion-HP
Event Code: 78
Message: Generování kontextu aktivace pro c:\program files (x86)\eset\eset online scanner\ESETSmartInstaller.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku . Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní. Konfliktní součásti: Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_42151e83c686086b.manifest. Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.953_none_89c2555adb023171.manifest.
Record Number: 38095
Source Name: SideBySide
Time Written: 20170724041855.717150-000
Event Type: Chyba
User:
====== Security event log ======

Computer Name: pavilion-HP
Event Code: 4798
Message: Bylo vyhodnoceno členství uživatele v místní skupině.

Předmět:
ID zabezpečení: S-1-5-21-2484980351-1062422368-565276184-1000
Název účtu: pavilion
Doména účtu: PAVILION-HP
ID přihlášení: 0xC9E14

Uživatel:
ID zabezpečení: S-1-5-21-2484980351-1062422368-565276184-1000
Název účtu: pavilion
Doména účtu: pavilion-HP

Informace o procesu:
ID procesu: 0x6d4
Název procesu: C:\Windows\explorer.exe
Record Number: 127192
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170724044911.909795-000
Event Type: Úspěšný audit
User:

Computer Name: pavilion-HP
Event Code: 4797
Message: Došlo k pokusu o zadání dotazu na existenci prázdného hesla pro účet.

Subjekt:
ID zabezpečení: S-1-5-21-2484980351-1062422368-565276184-1000
Název účtu: pavilion
Doména účtu: PAVILION-HP
ID přihlášení: 0xC9E14

Další informace:
Pracovní stanice volajícího: PAVILION-HP
Název cílového účtu: HomeGroupUser$
Doména cílového účtu: pavilion-HP
Record Number: 127191
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170724044911.669889-000
Event Type: Úspěšný audit
User:

Computer Name: pavilion-HP
Event Code: 4797
Message: Došlo k pokusu o zadání dotazu na existenci prázdného hesla pro účet.

Subjekt:
ID zabezpečení: S-1-5-21-2484980351-1062422368-565276184-1000
Název účtu: pavilion
Doména účtu: PAVILION-HP
ID přihlášení: 0xC9E14

Další informace:
Pracovní stanice volajícího: PAVILION-HP
Název cílového účtu: Guest
Doména cílového účtu: pavilion-HP
Record Number: 127190
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170724044911.668127-000
Event Type: Úspěšný audit
User:

Computer Name: pavilion-HP
Event Code: 4797
Message: Došlo k pokusu o zadání dotazu na existenci prázdného hesla pro účet.

Subjekt:
ID zabezpečení: S-1-5-21-2484980351-1062422368-565276184-1000
Název účtu: pavilion
Doména účtu: PAVILION-HP
ID přihlášení: 0xC9E14

Další informace:
Pracovní stanice volajícího: PAVILION-HP
Název cílového účtu: DefaultAccount
Doména cílového účtu: pavilion-HP
Record Number: 127189
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170724044911.666391-000
Event Type: Úspěšný audit
User:

Computer Name: pavilion-HP
Event Code: 4797
Message: Došlo k pokusu o zadání dotazu na existenci prázdného hesla pro účet.

Subjekt:
ID zabezpečení: S-1-5-21-2484980351-1062422368-565276184-1000
Název účtu: pavilion
Doména účtu: PAVILION-HP
ID přihlášení: 0xC9E14

Další informace:
Pracovní stanice volajícího: PAVILION-HP
Název cílového účtu: Administrator
Doména cílového účtu: pavilion-HP
Record Number: 127188
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20170724044911.664212-000
Event Type: Úspěšný audit
User:
====== Environment variables ======

"ComSpec" = %SystemRoot%\system32\cmd.exe
"OS" = Windows_NT
"PATHEXT" = .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE" = AMD64
"TEMP" = %SystemRoot%\TEMP
"TMP" = %SystemRoot%\TEMP
"USERNAME" = SYSTEM
"windir" = %SystemRoot%
"NUMBER_OF_PROCESSORS" = 4
"PROCESSOR_LEVEL" = 16
"PROCESSOR_IDENTIFIER" = AMD64 Family 16 Model 5 Stepping 3, AuthenticAMD
"PROCESSOR_REVISION" = 0503
"FP_NO_HOST_CHECK" = NO
"Path" = C:\Program Files (x86)\PC Connectivity Solution\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\wbem;C:\Program Files (x86)\PC Connectivity Solution;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files (x86)\AMD APP\bin\x86;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\QuickTime\QTSystem;C:\Program Files (x86)\Windows Live\Shared;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\AMD\ATI.ACE\Core-Static;C:\Program Files (x86)\QuickTime\QTSystem\;C:\Program Files (x86)\Skype\Phone\
"FPPUILang" = en-US
"OnlineServices" = Online Services
"Platform" = HPD
"PCBRAND" = Pavilion
"OOBEUILang" = en-US
"AMDAPPSDKROOT" = C:\Program Files (x86)\AMD APP\
"asl.log" = Destination=file
"PSModulePath" = %SystemRoot%\system32\WindowsPowerShell\v1.0\Modules\

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7262
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: Viry v PC a nechtěný One systeme Care Launcher

#4 Příspěvek od altrok »

Krasny den Vam preju :bye:


:arrow: Crackovani Officu se trosku nevyplatilo. Takze ty cinknute Officy odinstalujte a pote pokracujte nasledujicimi kroky :)


:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vysypani Kose a tempu, vyprazdneni cache prohlizecu apod.).


:arrow: Ulozte na plochu AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/ (nebo http://www.bleepingcomputer.com/download/adwcleaner/ )
  • ukoncete vsechny programy
  • kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • kliknete na Scan (Skenovani), pote na Clean (Cisteni)
  • po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\AdwCleaner[Cx].txt), jehoz obsah zkopirujte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Daveson
Návštěvník
Návštěvník
Příspěvky: 140
Registrován: 06 kvě 2008 12:38
Bydliště: Zlín
Kontaktovat uživatele:

Re: Viry v PC a nechtěný One systeme Care Launcher

#5 Příspěvek od Daveson »

Jj crack se nevyplatil :) ;) :P

# AdwCleaner 7.0.0.0 - Logfile created on Mon Jul 24 16:08:04 2017
# Updated on 2017/17/07 by Malwarebytes
# Running on Windows 10 Home (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\myfree codec
Deleted: C:\Program Files (x86)\myfree codec
Deleted: C:\Program Files\Common Files\Noobzo
Deleted: C:\Users\pavilion\AppData\Local\AdvinstAnalytics
Deleted: C:\ProgramData\SearchModule
Deleted: C:\Users\All Users\SearchModule
Deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\One System Care
Deleted: C:\Users\pavilion\AppData\Roaming\One System Care
Deleted: C:/ProgramData\2909b477-6a51-0
Deleted: C:/ProgramData\2909b477-71e1-1
Deleted: C:/ProgramData\e7fe2a03-3337-1
Deleted: C:/ProgramData\e7fe2a03-7403-0


***** [ Files ] *****

Deleted: C:/Windows\\rsrcs.dll
Deleted: C:\Users\pavilion\appdata\local\installationconfiguration.xml
Deleted: C:\Users\pavilion\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet-Explorer Browser.lnk


***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

Cleaned: C:/ProgramData/Microsoft/Windows/Start Menu/Programs/Google Chrome.lnk[http://www%2dsearching.com/?prd=set_epc&s=H7Lzamobl2827xn/aAU,7d968be6-2056-4a8c-80b1-2f43adb306c2,]
Cleaned: C:/Users/pavilion/AppData/Roaming/Microsoft/Internet Explorer/Quick Launch/Google Chrome.lnk[http://www%2dsearching.com/?prd=set_epc&s=H7Lzamobl2827xn/aAU,7d968be6-2056-4a8c-80b1-2f43adb306c2,]
Cleaned: C:/Users/pavilion/AppData/Roaming/Microsoft/Internet Explorer/Quick Launch/Launch Internet-Explorer Browser.lnk[http://www%2dsearching.com/?prd=set_epc&s=H7Lzamobl2827xn/aAU,7d968be6-2056-4a8c-80b1-2f43adb306c2,]
Cleaned: C:/Users/pavilion/AppData/Roaming/Microsoft/Internet Explorer/Quick Launch/User Pinned/TaskBar/Google Chrome.lnk[http://www%2dsearching.com/?prd=set_epc&s=H7Lzamobl2827xn/aAU,7d968be6-2056-4a8c-80b1-2f43adb306c2,]
Cleaned: C:/Users/Public/Desktop/Google Chrome.lnk[http://www%2dsearching.com/?prd=set_epc&s=H7Lzamobl2827xn/aAU,7d968be6-2056-4a8c-80b1-2f43adb306c2,]


***** [ Tasks ] *****

Deleted: One System Care Run Delay
Deleted: One System CarePeriod
Deleted: SMW_UpdateTask_Time_3530393737353137372d50552d6c455a37575a417834


***** [ Registry ] *****

Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Start Page [http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ie]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Start Page [http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ie]
Deleted: [Data] - HKCU\Software\Microsoft\Internet Explorer\Main|Start Page [http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ie]
Deleted: [Key] - HKLM\SOFTWARE\Myfree Codec
Deleted: [Key] - HKU\S-1-5-21-2484980351-1062422368-565276184-1000\Software\Myfree Codec
Deleted: [Key] - HKCU\Software\Myfree Codec
Deleted: [Key] - HKU\S-1-5-21-2484980351-1062422368-565276184-1000\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Deleted: [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Searchy
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{24F5E422-6A70-4FAA-8CAD-E23D5DC1DAE6}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{DD0688A5-FC8B-4E93-A485-CBF606A56D49}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\DMunversion
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{074E4EFE-81BB-4EA4-866E-082CB0E01070}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{0CE5B352-9D9C-41E1-9551-FCCD92820217}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{167B2B5F-2757-434A-BBDA-2FDB2003F14F}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{27F69C85-64E1-43CE-98B5-3C9F22FB408E}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{2E9A60EA-5554-49C3-BC9D-D0404DBACC62}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{3E63C9BC-DD51-4E83-ABA6-B350EAD28531}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{44CFFEF4-E7E1-44BD-B1F5-29F828ADA1B8}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{B543EF05-9758-464E-9F37-4C28525B4A4C}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{BB76A90B-2B4C-4378-8506-9A2B6E16943C}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{C3AB94A4-BFD0-4BBA-A331-DE504F07D2DB}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{EF2B6317-C367-401B-83B8-80302D6588A7}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F5379B4B-24D8-432A-9A96-BE75EE5117DB}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{F7FB2BC4-6C27-4EAC-B5E2-037B71FDE101}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{FD53FE35-4368-4B71-89D6-F29F3DB29DF1}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C29CF951-7F4F-4B8D-ACA8-C4EE934C27DC}
Deleted: [Key] - HKLM\SOFTWARE\Classes\CLSID\{5C3B5DAA-0AFF-4808-90FB-0F2F2D760E36}
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\11668D9C06DD0A64689920C3E9AA8BF6
Deleted: [Key] - HKLM\SOFTWARE\Classes\Installer\Features\29A6C5CCA08C28545824AB0E9FB182EE
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5BB8B2DE8E6BEBB47BBC322B82D20DF9
Deleted: [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|NoterSave
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\smu.exe
Deleted: [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Control\Class\{0C95ABFE-4FB6-49DB-B22F-0E1F5FC4BEEC}
Deleted: [Key] - HKLM\SYSTEM\CurrentControlSet\Control\Class\{EEEFACB3-729F-4484-B66D-E7A7917BBFC1}
Deleted: [Key] - HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
Deleted: [Key] - HKU\.DEFAULT\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Deleted: [Key] - HKU\S-1-5-18\Software\AppDataLow\Software\_CrossriderRegNamePlaceHolder_
Deleted: [Key] - HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
Deleted: [Key] - HKU\S-1-5-21-2484980351-1062422368-565276184-1000\Software\System Healer
Deleted: [Key] - HKCU\Software\System Healer
Deleted: [Key] - HKLM\SOFTWARE\SearchModule
Deleted: [Key] - HKLM\SOFTWARE\EnigmaSoftwareGroup
Deleted: [Key] - HKU\S-1-5-21-2484980351-1062422368-565276184-1000\Software\MICROSOFT\wewewe
Deleted: [Key] - HKCU\Software\MICROSOFT\wewewe
Deleted: [Key] - HKU\S-1-5-21-2484980351-1062422368-565276184-1000\Software\One System Care
Deleted: [Key] - HKCU\Software\One System Care
Deleted: [Key] - HKLM\SOFTWARE\AppDataLow\SOFTWARE\Crossrider
Deleted: [Key] - HKLM\SOFTWARE\Classes\TypeLib\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}
Deleted: [Key] - HKLM\SOFTWARE\Classes\Interface\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch
Startpage deleted: http://www.seznam.cz/
Startpage deleted: http://www-searching.com/?pid=s&s=H7Lza ... prd=set_ch


*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [12313 B] - [2017/7/24 16:7:13]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########

Daveson
Návštěvník
Návštěvník
Příspěvky: 140
Registrován: 06 kvě 2008 12:38
Bydliště: Zlín
Kontaktovat uživatele:

Re: Viry v PC a nechtěný One systeme Care Launcher

#6 Příspěvek od Daveson »

Zdravím, je tam ještě něco prosím???

Uživatelský avatar
JaRon
Moderátor
Moderátor
Příspěvky: 15213
Registrován: 29 bře 2005 13:39
Bydliště: BB-SK

Re: Viry v PC a nechtěný One systeme Care Launcher

#7 Příspěvek od JaRon »

Zaskocim:
Nainstaluj nejaky free AV https://forum.viry.cz/viewforum.php?f=29
a prescanuj nim PC
FRST |ADWCleaner |MBAM |CCleaner |AVPTool

V prípade spokojnosti je možné podporiť fórum
https://platba.viry.cz/payment/

Odpovědět