Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

RSIT havěť

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Zpráva
Autor
Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

RSIT havěť

#1 Příspěvek od Max_cz »

Zdravím,

comodo na mě vyhodilo okno, že powershell.exe se snaží něco otevřít, než jsem povolil pogoogloval jsem a našel, že patří k win, tak jsem povolil a to byla chyba.
Teď na mě vyskakují v Google Chrome pop up okna, weby se mi přesměrovávají a načítají neskutečně dlouho, takže blbostí, jsem si něco stáhl. Přikládám i log

Kód: Vybrat vše

Logfile of random's system information tool 1.10 (written by random/random)
Run by Max_cz at 2016-03-16 22:40:12
Microsoft Windows 10 Home 
System drive C: has 24 GB (25%) free of 99 GB
Total RAM: 11877 MB (71% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:40:22, on 16.3.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\WINDOWS\SysWOW64\regsvr32.exe
C:\Program Files\trend micro\Max_cz.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.yahoo.com?fr=fp-comodo
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Windows.old\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "D:\PROGRAM\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{080a68b5-d193-43d3-8a14-44f4108f1b34}: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\..\{0e70f5b1-c164-4e3a-b6bf-d59cffcc0aff}: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\..\{a92265ed-e9a0-4a1f-a13a-46e690dec9ba}: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\..\{aa9323a2-dcea-480d-bfda-455aa9721669}: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\..\{edaee51b-2b61-4ac6-b136-e332744fb89b}: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CS1\Services\Tcpip\..\{080a68b5-d193-43d3-8a14-44f4108f1b34}: NameServer = 82.163.142.7 95.211.158.134
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 82.163.142.7 95.211.158.134
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O20 - AppInit_DLLs: C:\WINDOWS\SysWOW64\nvinit.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {9793E2E9-7F06-4E43-8BF7-18CA2ECBF565} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\WINDOWS\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem28.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: System Interface Foundation Service (ImControllerService) - Lenovo Group Limited - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Virtual Camera Controller (LENOVO.TVTVCAM) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\WINDOWS\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: WD Backup (WDBackup) - Western Digital Technologies, Inc. - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital Technologies, Inc. - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11669 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\WINDOWS\system32\nvvsvc.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-00ee7689-16c8-4ab3-82f8-9aa6e80e059c -SystemEventPortName:HostProcess-a70d1ab9-5e1d-4ea3-88de-6754fc3a57ba -IoCancelEventPortName:HostProcess-0f09924a-1cfa-4f6f-ba40-e376626a8bf9 -NonStateChangingEventPortName:HostProcess-ba585d9f-5110-413e-abdf-9b443e669197 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:3dad3d7c-cc15-448d-8493-2789c7de7d75 -DeviceGroupId:WpdFsGroup
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
dashost.exe {e5bd7717-68fc-4c04-8c7d7d71e133dc34}
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-b825ba27-e224-4d67-82ae-9dbb6e2102c4 -SystemEventPortName:HostProcess-bc6d41ce-1c31-41a5-bf9d-67c6243e3ca9 -IoCancelEventPortName:HostProcess-f770ee6b-ed5d-4e08-90b3-1ec2813f509c -NonStateChangingEventPortName:HostProcess-6216a0d1-e76f-4192-911b-60705b3bfddf -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:e84d895f-54d6-4111-86ce-fc1cffaf6a0d -DeviceGroupId:
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-d20be408-fca4-420e-abe0-50b15401026d -SystemEventPortName:HostProcess-bf38e838-a9c8-47c1-ac10-5d4e7044bffe -IoCancelEventPortName:HostProcess-d422ffae-9ab8-4a99-a873-34b938c32e63 -NonStateChangingEventPortName:HostProcess-386c6cdc-625d-4221-b192-2fba9552c294 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:1006d987-b5d8-4ee1-8ea0-69d2b16f9b28 -DeviceGroupId:
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe"
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
"C:\WINDOWS\system32\CxAudMsg64.exe"
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\svchost.exe -k iissvcs
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"

"C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
"C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe"
C:\PROGRA~1\LENOVO\HOTKEY\tpnumlk.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\Program Files\LENOVO\HOTKEY\tpnumlkd.exe
C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.MediaKey
sihost.exe
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe"
C:\WINDOWS\Explorer.EXE

"C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe"
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE" 
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe"
C:\WINDOWS\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Windows\System32\hkcmd.exe" 
"C:\Windows\System32\igfxpers.exe" 
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe" 
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe" 
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm106.dll,CMICtrlWnd
"C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe" 
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" 
"C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe" 
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Windows.old\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler --no-rate-limit "--database=C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=beta-m --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=50.0.2661.26 --handshake-handle=0x18c
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="6808.0.1583458179\308454866" --supports-dual-gpus=false --gpu-driver-bug-workarounds=3,11,14,23,52 --gpu-vendor-id=0x8086 --gpu-device-id=0x0106 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.4229 --ignored=" --type=renderer "
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Default/SpdyEnableDependencies/Default/StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.1.48948344\944636581"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.6.2099673582\1166846516"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.7.667703624\1592448667"
C:\WINDOWS\system32\svchost.exe -k SDRSVC
"C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe"
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
"C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.49020.0_x64__8wekyb3d8bbwe\Calculator.exe" -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca
"fontdrvhost.exe"
taskhostw.exe
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetService -RestrictPrivileges -AccessKey BCA81C99-E643-59D5-8114-588DDEF0D8BA -Reinvoke
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/*PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.279.1009346650\700571039"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="6808.291.458919103\2008057397" --ppapi-flash-args --lang=cs --device-scale-factor=1 --ignored=" --type=renderer "
taskeng.exe {09F5A7D2-59F9-4071-8069-E0738C1864C6}
"C:\Program Files\Windows Defender\MSASCui.exe" 
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/*PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.307.569924149\1009482147"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/*PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.309.542178918\278930667"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/*PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.312.1104134926\2084009282"
C:\WINDOWS\system32\regsvr32.exe /s /n /i:"/rt" "C:\PROGRA~3\238a5536\5dd424ac.dll"
 /s /n /i:"/rt" "C:\PROGRA~3\238a5536\5dd424ac.dll"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe33_ Global\UsGthrCtrlFltPipeMssGthrPipe33 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon" 
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/*PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/*PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.320.1729971900\169168094"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/*PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/*PreRead/NoPrefetchArgument/*QUIC/EnabledDelayTcpRace/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="6808.322.1546305285\889064885"

"C:\Users\Max_cz\Desktop\RSITx64.exe" 
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 968 972 980 8192 976 


======Scheduled tasks folder======

C:\WINDOWS\tasks\Bidaily Synchronize Task.job - C:\ProgramData\{88ab9569-89b0-5230-88ab-b956989b55a6}\Autopano Giga 4.0 Final 2015 Free Serial   Crack.exe
Děkuji za pomoc

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#2 Příspěvek od Max_cz »

Nakonec se Google Chrome tak zasekal, že nešel používat a jelikož potřebuji pracovat, tak jsem udělal scan pomocí Malwarebytes Anti-malware a ten zabral,

zde je z něj log

Kód: Vybrat vše

Malwarebytes Anti-Malware
www.malwarebytes.org

Datum skenování: 16.3.2016
Čas skenování: 22:46
Protokol: 
Správce: Ano

Verze: 2.2.0.1024
Databáze malwaru: v2016.03.16.06
Databáze rootkitů: v2016.03.12.01
Licence: Zkušební verze
Ochrana proti malwaru: Zapnuto
Ochrana proti škodlivým webovým stránkám: Zapnuto
Ochrana programu: Vypnuto

OS: Windows 10
CPU: x64
Souborový systém: NTFS
Uživatel: Max_cz

Typ skenu: Sken hrozeb
Výsledek: Dokončeno
Prohledaných objektů: 427462
Uplynulý čas: 33 min, 22 sek

Paměť: Zapnuto
Po spuštění: Zapnuto
Souborový systém: Zapnuto
Archivy: Zapnuto
Rootkity: Vypnuto
Heuristika: Zapnuto
PUP: Zapnuto
PUM: Zapnuto

Procesy: 0
(Nenalezeny žádné škodlivé položky)

Moduly: 0
(Nenalezeny žádné škodlivé položky)

Klíče registru: 19
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}, Do karantény, [78feb5d3cacffa3c9d33f0ab19e9f709], 
PUP.Optional.Yontoo, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}, Do karantény, [78feb5d3cacffa3c9d33f0ab19e9f709], 
PUP.Optional.Yontoo, HKU\S-1-5-21-529706889-675040250-4031740840-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{C7C5384F-D9E9-4DB1-8C72-135ECCCBC571}, Do karantény, [4b2b28608c0d66d03f94309e47bbe719], 
PUP.Optional.CloudScout, HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b, Do karantény, [2b4bec9c62374fe75ee4a19f8381b24e], 
PUP.Optional.DNSUnlocker, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E, Do karantény, [3046058385149a9cc1590b730afa32ce], 
PUP.Optional.DNSUnlocker.EncJob, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9654353D-4154-4CF3-AF81-72953CC6E614}, Smazat při restartu, [5224bdcbbedbeb4b55b0aeda44c0c43c], 
PUP.Optional.MultiPlug, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\Bidaily Synchronize Task, Smazat při restartu, [80f6860264353afc126c0a1228dc20e0], 
PUP.Optional.ClousdScout.BrwsrFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DNSLOCKINGTON, Smazat při restartu, [9ed8246468316bcba7054dd4ee15c43c], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{E1527582-8509-4011-B922-29E3FB548882}_is1, Do karantény, [88ee70181e7bcc6ac39c0386f60e5ba5], 
PUP.Optional.CloudScout, HKLM\SOFTWARE\WOW6432NODE\5da059a482fd494db3f252126fbc3d5b, Do karantény, [581e7c0c6039ed49a39ff64a61a349b7], 
PUP.Optional.SuperOptimizer, HKLM\SOFTWARE\WOW6432NODE\{6791A2F3-FC80-475C-A002-C014AF797E9C}, Do karantény, [f68080086f2acf67c4684ee0d034c937], 
PUP.Optional.DNSUnlocker, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E, Do karantény, [8beba4e4831649ed7e9ce09e15efed13], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{E1527582-8509-4011-B922-29E3FB548882}_is1, Do karantény, [62141276a9f0fd393272b3d5917317e9], 
PUP.Optional.DNSUnlocker.EncJob, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{238A5536}, Do karantény, [13630088009963d329c42564a262669a], 
PUP.Optional.SuperOptimizer, HKU\S-1-5-18\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, Do karantény, [0571fc8c4c4d3afc131432fc34d03fc1], 
PUP.Optional.SuperOptimizer, HKU\S-1-5-21-529706889-675040250-4031740840-1000\SOFTWARE\APPDATALOW\{1146AC44-2F03-4431-B4FD-889BC837521F}, Do karantény, [e98d67214356211565c2c5699a6abb45], 
Trojan.Agent.Trace, HKU\S-1-5-21-529706889-675040250-4031740840-1000\SOFTWARE\VB AND VBA PROGRAM SETTINGS\SrvID, Do karantény, [542295f3debbc76fd3b3f05f30d4758b], 
PUP.Optional.MultiPlug, HKU\S-1-5-21-529706889-675040250-4031740840-1000_Classes\TYPELIB\{157B1AA6-3E5C-404A-9118-C1D91F537040}, Do karantény, [93e3e99fc0d935019b9b79cace36b749], 
PUP.Optional.MultiPlug, HKU\S-1-5-21-529706889-675040250-4031740840-1000_Classes\INTERFACE\{3B3F3AAD-FB97-49FF-BFEE-D22869AC4326}, Do karantény, [93e3e99fc0d935019b9b79cace36b749], 

Hodnoty registru: 7
PUP.Optional.DNSUnlocker.EncJob, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9654353D-4154-4CF3-AF81-72953CC6E614}|Path, \DNSLOCKINGTON, Smazat při restartu, [5224bdcbbedbeb4b55b0aeda44c0c43c]
PUP.Optional.DNSUnlocker.EncJob, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{238a5536}|1, 1458163950, Do karantény, [13630088009963d329c42564a262669a]
Trojan.DNSChanger.DNSRst, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\INTERFACES\{080a68b5-d193-43d3-8a14-44f4108f1b34}|NameServer, 82.163.142.7 95.211.158.134, Do karantény, [90e62860bcddf442e24caad6867ea45c]
Trojan.DNSChanger.DNSRst, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\INTERFACES\{0e70f5b1-c164-4e3a-b6bf-d59cffcc0aff}|NameServer, 82.163.142.7 95.211.158.134, Do karantény, [31455137b3e67eb8200e4e32ec18fd03]
Trojan.DNSChanger.DNSRst, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\INTERFACES\{a92265ed-e9a0-4a1f-a13a-46e690dec9ba}|NameServer, 82.163.142.7 95.211.158.134, Do karantény, [7ef86e1aedac37ff5dd1f48cc242ab55]
Trojan.DNSChanger.DNSRst, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\INTERFACES\{aa9323a2-dcea-480d-bfda-455aa9721669}|NameServer, 82.163.142.7 95.211.158.134, Do karantény, [d79f17711f7a3bfb0628d6aa857f8b75]
Trojan.DNSChanger.DNSRst, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\INTERFACES\{edaee51b-2b61-4ac6-b136-e332744fb89b}|NameServer, 82.163.142.7 95.211.158.134, Do karantény, [80f67018445578be121ca3ddcf356d93]

Data registru: 1
Trojan.DNSChanger.DNSRst, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|NameServer, 82.163.142.7 95.211.158.134, Dobré: (8.8.8.8), Špatné: (82.163.142.7 95.211.158.134),Nahrazeno,[fa7c7d0bdebbf3437cf3bb61fe07a35d]

Složky: 7
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.Amonetize, C:\ProgramData\{04161cf1-512c-1}, Do karantény, [90e6b3d5c3d65dd977b25fb746bd669a], 
PUP.Optional.Amonetize, C:\ProgramData\{20a7464f-512c-0}, Do karantény, [eb8ba7e1148587af1a0f8c8af013a65a], 
PUP.Optional.Amonetize, C:\ProgramData\22657c68-1af1-1, Do karantény, [afc7058364350f272c07a3736e954ab6], 
PUP.Optional.Amonetize, C:\ProgramData\22657c68-34f3-0, Do karantény, [1660315786132c0a171c41d5bc47649c], 
PUP.Optional.Amonetize, C:\ProgramData\742196e6-1281-0, Do karantény, [fa7c8efab7e284b2b57ee333d52e19e7], 
PUP.Optional.Amonetize, C:\ProgramData\742196e6-1b43-0, Do karantény, [9bdb96f2dfbafe38201321f50bf89070], 

Soubory: 39
Adware.CloudGuard, C:\ProgramData\Comodo\Cis\Quarantine\data\{5244DD50-7492-4AFD-A85D-B6CDE3982A5D}, Do karantény, [354164246336999d5f7d7d69867b748c], 
Adware.Agent, C:\ProgramData\InstallMate\{500990F8-6696-43D4-A13F-2EB48BEAB20E}\Custom.dll, Do karantény, [beb8e5a38f0a75c13f12ebd3a85847b9], 
Adware.Agent, C:\ProgramData\InstallMate\{A4EFF264-E079-4A96-A87D-A85B7F0CD092}\Custom.dll, Do karantény, [25514840e8b160d68fc2f0cec8381fe1], 
PUP.Optional.APNToolBar, C:\ProgramData\YTD Video Downloader\ytd_installer.exe, Do karantény, [beb8a0e88712999d89d8de620df46799], 
PUP.Optional.Somoto, C:\Users\Max_cz\AppData\Local\Application Data\Bundled software uninstaller\bi_client.exe, Do karantény, [750141473c5dbd79b9b6ba8c54adc43c], 
PUP.Optional.ClousdScout.BrwsrFlsh, C:\Windows\System32\Tasks\DNSLOCKINGTON, Do karantény, [d1a573154d4cf541109aff228e75f50b], 
PUP.Optional.MultiPlug, C:\Windows\System32\Tasks\Bidaily Synchronize Task, Do karantény, [730300889afff541d49926f6c04416ea], 
PUP.Optional.MultiPlug, C:\Windows\Tasks\Bidaily Synchronize Task.job, Do karantény, [106695f31a7f54e20a6b38e41ee608f8], 
PUP.Optional.PastaLeads, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_nps.pastaleads.com_0.localstorage, Smazat při restartu, [22545f292376340205c6a29f08fc45bb], 
PUP.Optional.PastaLeads, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_nps.pastaleads.com_0.localstorage-journal, Smazat při restartu, [82f4c4c4bfdadd59646798a908fccc34], 
PUP.Optional.PastaLeads, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nps.pastaleads.com_0.localstorage, Smazat při restartu, [6115c2c65b3ed462d5f690b1fe064fb1], 
PUP.Optional.PastaLeads, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_nps.pastaleads.com_0.localstorage-journal, Smazat při restartu, [c2b464249cfdca6cd7f4c67bde26ba46], 
PUP.Optional.BestPriceNinja, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage, Smazat při restartu, [a2d4612701984bebb15e58218d774ab6], 
PUP.Optional.BestPriceNinja, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_pstatic.bestpriceninja.com_0.localstorage-journal, Smazat při restartu, [bfb7ff89158460d6719e750456aec937], 
PUP.Optional.BestPriceNinja, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage, Smazat při restartu, [2b4b0781f8a1e1553fd01d5cee16847c], 
PUP.Optional.BestPriceNinja, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.bestpriceninja.com_0.localstorage-journal, Smazat při restartu, [8beb177104953df9dd325722b3515ba5], 
PUP.Optional.eShopComp, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.eshopcomp.com_0.localstorage, Smazat při restartu, [334318706f2aed49a650126b59ab4fb1], 
PUP.Optional.eShopComp, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\http_pstatic.eshopcomp.com_0.localstorage-journal, Smazat při restartu, [7ff761277326fd399660c1bc7f85ab55], 
PUP.Optional.CrossRider, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, Smazat při restartu, [c9ade6a26b2e3501aea5770a659f2fd1], 
PUP.Optional.CrossRider, C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Local Storage\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, Smazat při restartu, [7df96622485170c66de6fa8750b4b44c], 
PUP.Optional.Amonetize.Gen, C:\ProgramData\742196e6-1281-0\BITF07D.tmp, Do karantény, [4f27385087126dc9f3d6eb9b5aaa4bb5], 
PUP.Optional.Amonetize.Gen, C:\ProgramData\742196e6-1b43-0\BITEB89.tmp, Do karantény, [75017117fb9eb0868a3ff591ca3ad729], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\config.ini, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\ConsoleApplication1.dll, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\DNSLOCKINGTON.cer, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\Info.rtf, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\License.rtf, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\LogoBlack.ico, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\LogoGreen.ico, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\LogoYellow.ico, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\Microsoft.Win32.TaskScheduler.dll, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\settings.ini, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\unins000.dat, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\unins000.exe, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.DNSUnlocker.BrwsrFlsh, C:\Program Files (x86)\DNS Unlocker\ZonaTools.XPlorerBar.dll, Do karantény, [1b5bc0c837623600dc54a5401ee4bf41], 
PUP.Optional.Amonetize, C:\ProgramData\{04161cf1-512c-1}\BITC583.tmp, Do karantény, [90e6b3d5c3d65dd977b25fb746bd669a], 
PUP.Optional.Amonetize, C:\ProgramData\{20a7464f-512c-0}\BITC5D2.tmp, Do karantény, [eb8ba7e1148587af1a0f8c8af013a65a], 
PUP.Optional.Amonetize, C:\ProgramData\22657c68-1af1-1\22657c68-1af1-1.d, Do karantény, [afc7058364350f272c07a3736e954ab6], 
PUP.Optional.Amonetize, C:\ProgramData\22657c68-34f3-0\22657c68-34f3-0.d, Do karantény, [1660315786132c0a171c41d5bc47649c], 

Fyzické sektory: 0
(Nenalezeny žádné škodlivé položky)


(end)

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#3 Příspěvek od Max_cz »

+ ještě jednou radši RSIT

Kód: Vybrat vše

Logfile of random's system information tool 1.10 (written by random/random)
Run by Max_cz at 2016-03-16 23:32:35
Microsoft Windows 10 Home 
System drive C: has 24 GB (25%) free of 99 GB
Total RAM: 11877 MB (75% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 23:32:43, on 16.3.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal

Running processes:
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files\trend micro\Max_cz.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://us.yahoo.com?fr=fp-comodo
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O4 - HKLM\..\Run: [RotateImage] C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [WD Quick View] C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Windows.old\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "D:\PROGRAM\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 8.8.8.8,8.8.8.4
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O20 - AppInit_DLLs: C:\WINDOWS\SysWOW64\nvinit.dll
O22 - SharedTaskScheduler: Virtual Storage Mount Notification - {9793E2E9-7F06-4E43-8BF7-18CA2ECBF565} - (no file)
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Genuine Software Integrity Service (AGSService) - Adobe Systems, Incorporated - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: COMODO Virtual Service Manager (cmdvirth) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\WINDOWS\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\WINDOWS\system32\CxAudMsg64.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem28.inf,%ibm.svcDesc0%;Lenovo PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\system32\ibmpmsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: System Interface Foundation Service (ImControllerService) - Lenovo Group Limited - C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Lenovo Camera Mute (LENOVO.CAMMUTE) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe
O23 - Service: Lenovo Microphone Mute (LENOVO.MICMUTE) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe
O23 - Service: Lenovo Keyboard Noise Reduction (LENOVO.TPKNRSVC) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
O23 - Service: Lenovo Virtual Camera Controller (LENOVO.TVTVCAM) - Lenovo Group Limited - C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
O23 - Service: MBAMScheduler - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\WINDOWS\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\WINDOWS\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: TeamViewer 11 (TeamViewer) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: Lenovo Hotkey Client Loader (TPHKLOAD) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe
O23 - Service: On Screen Display (TPHKSVC) - Lenovo Group Limited - C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: WD Backup (WDBackup) - Western Digital Technologies, Inc. - C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
O23 - Service: WD Drive Manager (WDDriveService) - Western Digital Technologies, Inc. - C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10951 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
winlogon.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\ibmpmsvc.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-21af688e-5cd4-4128-ab79-d1a4e4a11a6d -SystemEventPortName:HostProcess-d221a52c-9df3-4f90-bfb7-8dee887f7944 -IoCancelEventPortName:HostProcess-1eb495b1-75e7-4cf5-aa66-f18a5ac4db0d -NonStateChangingEventPortName:HostProcess-770fc51c-7c6a-4dc6-9dd8-1d021ede8507 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:79d978cc-ebd5-4823-bc8d-6d566d149dee -DeviceGroupId:
"C:\WINDOWS\system32\nvvsvc.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-f189b692-2ebd-4857-a0f6-b2c86f0317fd -SystemEventPortName:HostProcess-69637d96-99ef-40b9-ae4c-c8d385a635e8 -IoCancelEventPortName:HostProcess-c293b9fb-a794-4507-a83f-a8b759d65e3c -NonStateChangingEventPortName:HostProcess-1efcd7d8-04fa-44f6-a904-80cea60ffd0f -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:29337d77-4898-4823-809a-c5ec755a5ced -DeviceGroupId:WpdFsGroup
"C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-523c6b89-d7b3-4e9f-bf84-cccb3d98a3f1 -SystemEventPortName:HostProcess-32b4ef43-6f13-4b85-90b2-f4dac8acdfac -IoCancelEventPortName:HostProcess-362ad4c4-3edf-49e5-90f3-56e319e0f59c -NonStateChangingEventPortName:HostProcess-683b2eb7-cfb5-415a-af0c-e7de61765ff5 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:2d6c5155-05d0-46a5-83ea-76248b710ebd -DeviceGroupId:
dashost.exe {0ab29e7a-509c-4651-af4e2a249bd421eb}
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\WINDOWS\system32\CxAudMsg64.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe"
"C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe"
"C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe"
"C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe"
C:\WINDOWS\system32\svchost.exe -k iissvcs
"C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe"
C:\WINDOWS\system32\mqsvc.exe

C:\WINDOWS\system32\svchost.exe -k appmodel
C:\WINDOWS\system32\svchost.exe -k imgsvc
"C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe"
"C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe"
"C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
"C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe"
C:\PROGRA~1\LENOVO\HOTKEY\tpnumlk.exe
"C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe" /ModeAvMonitor -Embedding
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"

"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
C:\PROGRA~1\Lenovo\HOTKEY\MKRMSG.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.MediaKey
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\PROGRA~1\Lenovo\HOTKEY\TPONSCR.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.OnScreenDisplay
"C:\Program Files\COMODO\COMODO Internet Security\cistray.exe"
C:\PROGRA~1\Lenovo\HOTKEY\SHTCTKY.EXE /UEFI\\.\pipe\{C6A9690C-33AE-4a55-8B65-9498CC0A7B34}.ShortcutKey
C:\PROGRA~1\LENOVO\HOTKEY\tpnumlkd.exe
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
"C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe"
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE" 
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey 0DCA4AAE-C5EC-522F-BBFE-9B4F96732C3E -Reinvoke
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\WINDOWS\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
"C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe"
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1
"C:\Windows\System32\hkcmd.exe" 
"C:\Windows\System32\igfxpers.exe" 
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe" 
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe" 
"C:\Windows\SysWOW64\rundll32.exe" C:\Windows\Syswow64\cm106.dll,CMICtrlWnd
"C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe" 
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" 
"C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe" 
"C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe"
"C:\Program Files\COMODO\COMODO Internet Security\cis.exe" --alertsUI
"C:\Windows.old\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --flag-switches-begin --flag-switches-end
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler --no-rate-limit "--database=C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=beta-m --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=50.0.2661.37 --handshake-handle=0x184
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="7364.0.462828387\1362650396" --supports-dual-gpus=false --gpu-driver-bug-workarounds=3,11,14,23,52 --gpu-vendor-id=0x8086 --gpu-device-id=0x0106 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=9.17.10.4229 --ignored=" --type=renderer "
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model1/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledInitialReceiveWindow32KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Default/SpdyEnableDependencies/Default/StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7364.1.201664567\833383072"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model1/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledInitialReceiveWindow32KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Default/SpdyEnableDependencies/Default/StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/WebFontsIntervention/Enabled/ --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7364.9.41508708\1716119198"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model1/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledInitialReceiveWindow32KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7364.13.1453819122\470866772"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model1/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledInitialReceiveWindow32KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7364.15.261810060\1524121652"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model1/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledInitialReceiveWindow32KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7364.16.2015407926\836693170"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model1/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/PreRead/NoPrefetchArgument/*QUIC/EnabledInitialReceiveWindow32KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7364.17.90287481\273126534"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup,WebFontsIntervention<WebFontsIntervention --lang=cs --force-fieldtrials=AppBannerTriggering/Aggressive/*AsyncSetAsDefault/Disabled/AutofillProfileOrderByFrecency/Default/*AutomaticTabDiscarding/Enabled_Once_5/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ChromeSuggestions/Default/*ClientSideDetectionModel/Model1/*DataReductionProxyConfigService/Enabled/*DirectWriteFontProxy/UseDirectWriteFontProxy/*ExtensionActionRedesign/Enabled/ExtensionDeveloperModeWarning/Enabled/*ExtensionInstallVerification/Enforce/*GFE/Default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/KeywordAllowsMissingRegistryBeta/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Enabled/PluginPowerSaver/Enabled/*PreRead/NoPrefetchArgument/*QUIC/EnabledInitialReceiveWindow32KB/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SPDY/Spdy4Enabled-default/*SRTPromptFieldTrial/On/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Default/*SpdyEnableDependencies/Default/*StrictSecureCookies/Disabled/*TriggeredResetFieldTrial/On/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_11/*UMA-Uniformity-Trial-10-Percent/group_03/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/*UseDelayAgnosticAEC/DefaultEnabled/*WebFontsIntervention/Enabled/ --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=1 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="7364.20.1374193045\1891647355"

"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe" 
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe"
"C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe"
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.113_none_7689896a26389b16\TiWorker.exe -Embedding
C:\WINDOWS\system32\svchost.exe -k SDRSVC
"C:\Users\Max_cz\Desktop\RSITx64.exe" 

======Scheduled tasks folder======

C:\WINDOWS\tasks\BocaInstance.job - c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}\4501685520917765081b.exe

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#4 Příspěvek od Max_cz »

Kód: Vybrat vše

======Scheduled tasks folder======

C:\WINDOWS\tasks\BocaInstance.job - c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}\4501685520917765081b.exe  --startup=1 --single 
C:\WINDOWS\tasks\CreateExplorerShellUnelevatedTask.job - C:\WINDOWS\explorer.exe  /NOUACCHECK 
C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c 
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler 

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-18 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-18 172968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"=C:\WINDOWS\system32\igfxtray.exe [2015-09-18 183216]
"HotKeysCmds"=C:\WINDOWS\system32\hkcmd.exe [2015-09-18 411056]
"Persistence"=C:\WINDOWS\system32\igfxpers.exe [2015-09-18 453552]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-26 49056]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2014-11-25 935104]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2014-04-10 1830616]
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-08-06 1427648]
"Cm106Sound"=C:\Windows\syswow64\RunDll32.exe [2015-10-30 53760]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-11-27 508240]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-02-21 2789248]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-02-17 1903344]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CCleaner Monitoring"=C:\Windows.old\Program Files\CCleaner\CCleaner64.exe [2015-09-19 8455960]
"Zoner Photo Studio Autoupdate"=D:\PROGRAM\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2015-07-16 563416]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"RotateImage"=C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [2008-10-30 55808]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-04-13 291608]
"WD Quick View"=C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [2015-07-20 5564784]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\Windows\system32\nvinitx.dll, C:\WINDOWS\system32\nvinitx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
c:\windows\system32\igfxdev.dll [2015-06-01 451584]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\SharedTaskScheduler]
Virtual Storage Mount Notification - {9793E2E9-7F06-4E43-8BF7-18CA2ECBF565}

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"3212083974"=0x504B03047ECDE67B068374BFB5110000004000003B52047F42E5F13FFC79C52065C1BE89B50CD7B4769F60289BFBD984D14110F2D01270B16FC2706B1EDA5D73993A9F916003041E5B35D296126857F9E7251C73D3EFC09701D8D7ADC4610818404E80E342F284FC326FAFF9639EBA1E04B3742F5A9CFF01382A0C43DD64F0C5C72F17491D19AA604C54BAFD81DAB7660098606BC53B2CCFAFCC763E85AF893E2EC927770A5A8FBD749F1FADC9CAC3E32ED081F17F670C361341DCA6E6AAB22F35F8A01BF20D6F281379604DDF2B2D3AAB0475420EA35140CBD4850B5B37D2E0E582569D37AC0AEBFD63622E501F2BF5152FCF27CAACEFC4626FB241DBDA40EF0B12DD6F0AD67E93DFDC1861004081B9D72C75BB44BE9D1E27106103C35A24C81ABFA9A1F77CED3C0382BB7B0CD5005CFD4D9C12BAA0359AFBEE313FE071AFE8703BD92ABE22A0D51F3044C7410D9D6C7AA0337D9B7BBD1F3442DABD7B34DCF6888C18894965A7AC6702C9711F3905F590405B7002133BE6023C1376BB44873357A9555695625CD61A62343DC8928E685FEAE8E040D066B19FAE8E6B1F52EC94EB23382A36F982A5FE7B913C1707AA98145196E1168940B87181ECC84A3D074875B1AA306314B7D0FD77AC5602E656A4FE5F7D1276767A2614E2DE7E291B7729A58732F442E9C09842E7D8E44EB4B81D4A33BB5A0EE4A734289B6D99E87C21BF0248F522B38F8E69C3229F88BE9B8747500A03FE71AF6356476805E77DA5ACF4597917CD0632C1E257EA8EB53847066E8108E99D0FB556B2BF72BB5BED5792373C6486720619E15B5D9810F5783760949E5343C6DD4877637867BEFD768B439297D7E821CFC4BA3980F1CA2279A2E6A459470C6FF28FA2CA7236E81B6E2A1B5C349BCF4729C24388385F42302C6F8475F44F7BA90A1B7E1E10A48047D41BC1136DC51B40CFC85C09AE83F8BA3B01E359FB0241367E5168F48EFC6AF1EF1DC6B0DF6E69B29323CC1CBE73E39F3069C15AB38087A2FDB508518193F867710C6B378AF2F25A8DDCE72F0D61E19E47877F68B78B3E8AF452B22CC5BEA2AC107474689639D23E2789E4D34FD424BEDA096ED4F091B9CCF2E3D041FD6606795D3A09CD04B5ED2AF5BA71F4A01CAE89A4933FB1E08B129138CED63229F7ED9574131F0C0ECE1C5928ED9D4376DE50DDF379DBFC33DC0EB000B6098DE6F92BCE503ADFC75541BF4A6BEC97B298773EF65B60B177214313FC1508ABE30FDE7B48836D334F61047CF5BFF2093E8F380A7986AD8FFA5AC6A8EDB4392968ACAEEA2B0F2889A80D78B30648B4612E6DF2311CBF0FC50B7CAAF81E3E531A821B2A072D2FD2A9BF12170EA48EE2039A61EC4DC1671BDF2B2817786BF981D04F8CCA7771F08808CC38E04856FA22716B10F175786CD6B2E2AFF3B638F4C411E3C0851232DB04FDCBF6648EBAC7169FB7FC75C9D8AF98133F8DAA18E26BCA983977CE3B322106050FF575C707B8808C8A51DD02758ABF52B1DD5101562D5B93BB2461FFE9DCE06E52E2B27E8488DDB006F2783460F435CDF3CB6D1371A91F65497DE6E9B81D63064AF1E5AB31BE290B80A530DE6B094F5042726BF8AA46CD4652B9CB71F89CDD25CA682E6C9E25023C06FA538CA4F3DBC7738F35C0C0912C9CB16F43C8CFFB97981C0032F0C745974F620339D7CBE4C59ADEA630F92D6E6990532F427E795D4D2F6BB18FC35798B4948CAF7E2864D81ADABF22C1AB59AACD406454BAF9FFF5FFC88A35BDE96672513C1A297BA6E16BA1B7805392373FCBA9A2F3FDDA7D165B57560ADAA570693659196630B6519EE9012B76BF73FDBE807085BE5FDEB9EDC93E574396113A80ED04FCA4F572AE01EB8279A4DC9F902BD5CD206223C98DA8FC6F80EDAD25254B831B176CFCB7B83C74F63D1279EC6C69E208B3DD8B30D279ACA6238820E794D7AFED9DE063B8F9B88AC294D08E650CE9B617F6904821BFC7BE177583A90A88AA450FA2E35F6619AA39CF29632DB166D56361E17D5845C71E43B7B2EA63EADE16377FDFC5D51AB1F31CC78D9C1F31D0816C78A25A8A68BA87070B732D9F315E454DCA738C2370B5019765CAADB6B4E8226E83439487DAFBA93EA941E3B7FCB9029F846CA2D702153AC85B91BB8CB296A29662EA2617AF463DC719588CFB7A4E2E68D165ACF08EA0477376661AA1D5377931FBBFB2673C01F7573D2C8201DE8F82810FC456F633D00CA6281F8E991A75979227D2CEDF7400C9D3022CA75278518FAA2CDC4921EC58C2B1EF1D305ADD4C5DD65572F8934F5FD610B3C9DD0DBA0CABC93D46D489B7FA5E676E6A4ED2A5884D179125B9DBCE16A0D8893FCA9DB16DBDE23927CF5711A9917F5FA99DAB133665CA5648BCB61EC2B0EE013944F619E8D14B77D18B489EEBDCA6A57328B40F2C3B2562EEEBE8D67AA29C9884BE2FC81299EB03D257F1CBD26ECAB2C9BA1C843CDFE266BFFE68FE6D2A621FB08319D4D8C78EF4D32322593FB7F8D31B8B19B6CE0D6F0F23BB677643E385EA4F790CF9C6027D8635E95C3EC8AB6D45CBF86D7F2E90D4CD6604DAD3A7AEC95A9CD4621E8668B6D23559044C318528DE2358561CC518E8F2DB291705B5F28B55F0D4FFB19C0B674C84EA3944F0B3F2DAC4A4424ED634B3C93061AA252B1CF059ACE6BD182252F78B21B4416FF9317B04AE61E96EBD96519FC17C5E7612B61554D407AAFDA3799134C8AF4D3EE71354275C769E200DB6FA418CC1C7F3FACBBDEEE35A09E7922525D3CD8BF905678982FD350C19E2EFAB677CB7E465D307FA45BA289532B05BC1DB528C37A61682A555796E61ABE00771D9E9084DF6E5226405522276C7C4AD732A47FD2D0AD1312F71C87021D6E6C07CEB88F53A02EA382957A40FF9CDA815A07298BB3FB48396EE4A1E09894FED5D323267720A369652E125DF77777C75C063FE5C4A4FB18EA9501EF64D82894CE9917BC2D43F10EA1ABCDA1895CCEBA18D1DD0501F63045F0D21E3E1C815FF7B5801CF57A1CB02E4B08742721F172BC756FC4D04BCC6D1C7F1C52BEA83915AF2BF303545A55FF3E601E90AE848CC2AEFBD6880300FBD986A78DA992AD85FB75DA1DAA397DF86E9FE1DBD314AFBF27CBB03BF73D772E7F51EC3D0EB33B50000F1A632245394E0FE98B46891623E6334A4A849E0C5CC9403CC053FD5DA65453B895A0A023F9A4EC8955A41E8F951AE2204DE5FFFB571B2DD29C098B3E7577106F40D39C900E5A1A950330394C8FDDFDC48E6CCAD178B475F440373B950F2BE32CE823F39B2C7AEB524F264460557F26A82211B154B31DFF46765C478AE98E2363F21E28A763CB47BD9CFE4BDAC59B82D7F8BB04D94D65390961B359D61214612E95EEE709CB43CF5F004C54AFDFE78CF7520E3F84EF06F358531EB1D84F49D60ECAF1D4F38AE648EE978B60C6C81B8C833245D0D9F843B7C18C69FA242FD62858779119C115BF332B8DCDE8B66BA55F4175594E1AD2301AF04EC66A9BB71B20FFAD342FBE5E9689142E44C6DDA4BD5929CCF37D5C2B49BEF503B1BC229101123B21772EF939277024CEF39498C44C7FC3E6B7C01C7CDD4A247E758D3AD00D56031A5C7F8ED6DD3F944EF95CB8A98C9F129FDDFB75B2E6E4EB68CC6668AE9706623C58201CF12F027FA0532CB3DA087246E907CA3E3E6CB920FDB3196D404DBB97A667634E67580E231D92D097406F3EC39F62C356B6829FB46DDAB514A4EC7C05B40A4345ED0CC1E003C64EF5173F0771956613397CD5B1D3FAE80F856021BBE38D5B34AB0E476B91FA9A5304B6F38280429930394ACFDBBD4EBDC433E520197142BACF7B87BBDC05CB40FED6BEC2D700D940AF55112506FF365D97CF7B7E9F7A008981DA053C04F3742A6624772D3B6408936C1E3D7704B8BB2A3DF870D468979C46BD733CAA71CAE29010BE57953E149C7C10B81A2690DE5F873C3795BC04ADC4341EE5A5627AB85B70F08F32F1B361BCC834BEFBB3DEE2133EDF1761555CF48E826481D71161955E35094AD217909373981FEF5621176D54C69E4CC72262928E061600C95928D683CD7490E26A8E5AA1AB37AF0D440AC85D26F3557A02FB26BD48DEE04290E3D7B9FEBEBB59294FB0F6E06FED08145856BF52F806C83867EE6B7768DA5F7D6B5787422A3B62EDC670DF90CEB18144D37F549C234DF7E7679D7E00A52CCB77D426881C5E4B3AE86217764664777C0FE81F4AEFD1814C2F66B1F28823F5CB8E6F8F993343D2FD5F9FF88582957460D3EFAFEB5429D23573809BFB2AEB29AB44C2E1EAD93B11EAFAEE46E2888DC1CC2105C6A7999979741486E8D0FFB88D6CD7634E80800A09294EBAC8B4766DC02E2EAC4E6A8330D978C275E19D2C64C48D3162B29A71921449745F9E0BC7CF55CDEE56989ADE2BBB2791BB431833A05D59434DE364B750A2DAE8A37782428EFB41030702FC277181070503D90B230F5807684AC38E4A9C3000B71A8D6CA83F9AB864344269C559DBDFA36766787A3996E496AACB4CA56EDAB9C2BFD92BFF2414AFD0CBF5FB69E6649FAAC544AAEC33C1BE404D50703BC57ECBA53CEBF665AB7A6DE87051F6F9DC47AF14018CBF7878E03522F87B58EB82056BD4853EB3DF2ABF7D14ADD5ED7325E58EF12F4EF6BC7D158AC2CB07CD3CA032E2AA8D99BB31F4FA8DCB37415B61E71DD8E09F2F079E31797A209C65D617B108FE82F95DDD79A5B91BDB076CE8F11E8D07ED92D17B908DC9389C6CE92A48B8335E4C1E8F6EE4DDB207B15DC20E04E50FC5489E060E3BD114BB7AA16A755685A6061C308A46A3ACC746542C0228897C4B203B85B4ACAA87AA134E07CBEDA2EB4284A6CFE35EB3516C4E4739DCA0A8358BB5FD96A636BAF2B962819FE2591011B3158CD54E5972206D26D7D5B31613791B3A805D75771D70015A63F9C3D9FE9DB6561445B8C7F2D051F88C72FB3D57847D3E75EC58F3FE4F8C7F7C1721456E1AEAA943347F8D3D30D1F205AC288FC86CCF6F722A63D710583790C66D698A11BD2889869E37E641B5FAAD681252767ED8D48035F805CBE899130D0C22287E91E6377E9A06BD27E778C0E68589963748773161DFC1D214C53A8B37496D3E6702B1EF6F1FA7FA009C8ABA5D11DFA7D9D89E0C4F29DF89273AD5E8EB6C69FDB236286F86996FFE2CD493184E99A48753A80A57A6ED9B28AAAC9901BC9EFA931C9DC2E6EB1CD4C49A3CF90D76F915C8A41F22D14CC8122A767AC5051030C480DC214F2255FAA48E10A372422399DBA6BBA46A1ACB6DC72505916AE43C326EDE92ADA89898854D27D06843C7814C205F0005E2A03838271920A17C019D68AA34E751FE59762999DAAE538683933705EA529F6863B814D744E6C9FD170CAA646405DDEAE7831566CF81005B832B1B972DEFBB78058BE3657B63A3334AB61B5D465EB355C04585024E42F67725FEE76142830CED8CF98AFA05FBB9FC572E8F7155F2F963574BD49FC9EC34186BA3D48BD99EF8D2DD8C437D0EB2B147236B055B6E6A2CADCC28DC64AEAE270A9749AE7647938502067DB5FAB277880A62F064CD12688752D3B24079DE9BD985C1F16E9B5EAC46EF5D79827B69865BBF8B652A5C2161B9C718AEF0E1F19F8247F5B2247622191FD22B12D0EEA5CB4D957273585257897858F91DBA76405BEA196A7E59B488CA122F4FC4314E611193A20AB08D9CBFEA80F48D3CBDF04346DB79CD1ED4EB7DC3C8EED4CE316516C5596C7DC204A9A0CA08A4E587ECE00E75B0CEAA9F26EAE9C039A6A3F7DB0572050AA864A1E4E233F59101BA22BE52717F6CA23AA4CE2AA11518F8D512F91AFEA3CF3B22443A4A0BF2ACAC8EF572E2667C7EAC01C62C9D111061400F119FFDE950602E3074BAF80699D9A3DA96F8AFF97A407040CDEC110212A8963A5669BFAF90851C56AE1C226C1A8F630A635D1343E3E4446DB83599F913C0619B7913EEAD173075C32C301526503261CA4416FBC8BA7BEE960D98C4C244FDE30DDF5ABB3163E82ACD44A44ED24E74B3F98B29E6C481B3410BA08A39D3BF22D9B47114E04AA21A7D73B4A90F983231C0A7384B159AB760B923A548A7D0D925E76A35EF302B7859D8E40FB77B7C04A6F2CC7B08481CA35545A2D6C4D606EB1100F03C9083A5F957561920B930685C4E6FD049C30C8BEE18D8867B00BFA4F8432F05EAA5780E6DB2E4D3D767E9DBF1CE28D987DEB1C7F1AE21117B6BF6A32537C8457693C04F8802B57743A9DDD821F10098FE3EAB3934356FC8C24C0C35F92865C62F62DE06EAC6ED8884AA38351A2F5E8FB6E8D22DE672871416C2BA4E44C477EC25D04C35F549356DC20BE1CC0F44771C22366914304B08E6B5C3AEFA2D019E3E74B5D2F4724F71F47CD6548CF3FCC4DED193D9A2F57FD8CCCD94786885043F4721FFEA6277AAF2EC46B61432C3BD4881B6D9CD83983625627495D69
"301548880"=0x504B0304AF7CB8A05045F9114D070000003000003B52047F42E5F13FFC79C52065C1BE89B50CD7B476AF60289BFBD984D14110F2D01270B16FC2706B1EDA5D73993A9F916003041E5B35D296126857F9E7251C73D3EFC09701D8D7ADC4610818404E80E342F284FCC62EF128637FC2E8C4BCA51047A1E7D4571A1B18398F5F6B8E44D035A4CCC9A90C3BB2918F07633260A7770E0427505D9CD9DA45ABCE52680F80227AB6A4A6FEEC46B28564B327068008C1414A62D614AB6ADEAF538D4A6E4C4457E580BDA094361769D31091635792ADBBAC2464154AB1992C3A4D3F400B30D04F9F52954A909B6FFFDB1ED00C4B7708859BE4B769E45268B4A29FD7F85D0EB3DE7520E048F9636B469B3C05C2594F20453EE26EBA7F2E3E0074DB8B2BA76D8A4D8575BE24C65EE067ECC4921305585AE8110062C56A169070C33AE4AC318102B910A1BC96C2B479BED046D12DCD65C7B8B49231F9588A25B97EF6397A8A683D88DDD5F6E8648A7407EBDEE65A3F92DCAA580C74B698329AE3561EE66B016317963362202B9152D880D593BC760DE140BF53F283000BB3D036B78613B68311AF34D07916FE46202F896D4C0153873C1820E110BA155E3945930E95743AF650935078D9B6AB2C289260330DBC50C99E8789CA6B50B6707688798A9F81A2CEF8B40F96F8FD9E01C00774815B4DF8CA235935793FEB99D13BD3AAE3FEB2434540B740367533DC9C8E2A664A520ACFBC0A7EDA4BB5D97663F0A088CE0AB05587CA95911BD5CF90B2E4B4DFA0DEB8CE53F231BEB500C1778C0F6FC86E11D923FE1C8A798ECDA6D9628A23E81E3B3397E94B54ABA069EBE76BE1B47DFFE1A6C7F3C07159502C9552191D5BDD6CA76BF6A1B198516ABD7EA57C39C606F0E58BEC5E2C60E5D44648B3467E52DE69104130D39543048DE50A9738EDA2A12025CDAC3BFC025787979077961B958A7E1254CDA2C24A4EF29A72719CD8FF7407AF8A8D2147C2000AD3BAF6C0B40D699DBFA4230EA22EDFB5631AE4A5C58EA9CB86E5A873FF7AF22D790B354663056DFF36F8B04E17858CEAEC8EDD8EDDC4A6733DB3E33E3DD99F8769EAFA4429A2CF28C67C71C93BBBFE4D2FADA1710343B4CFB8C1376FAE0B06047757F704AEDFAA25CE0DF9E0F8CB3D6375E9C593F343A3B5FE3B0425EA947A5BB37C406B3A7C57AFFC944C008AD8D5AE59AC8B5DA282396CCEE7CF526ACE85FFD8F89EE76633E49D3662F41DF79F286E8D399ADF02A598FCA2EA3225FFC4F412E30C738E07FDCEFD08887BC8658B6AE2EC8820F4B481374042229DA9978A251D7B7497619989FA2A8652E680AF13CD32FDFFA5DF97CC3AC979B034921488C9835FDBC708F5A8B407980F4953D27FEF86B4FC331B4308A2404E064F84EED4092CE9978788CE0C46F07560A8123DF5471CDA1C34ABE85387515D27A7AC43EBAB84DEBDD29914A7DBD84876732EE9D36590CB2637B6D009C7A38EAE497D8DAFFDAA60BFC8A40D8D1753D59EC9E843511B2A1EB9907DD2E37D12C6FBCE80738A27A8BCC42ACB1150C13C6BAB2470E39819FE105531D9FF216783E956B0ECE48DA8DAD19856D2A95578A2350778AEB0A2BA7C180AD03725567A5B9C21AECAFED79CB610F92A596AA4570C4A9A25EEA1955A6695B2A3928FC8F0B58DBC93A85808DDCE0CFFCB7E4B20C78806B5174DDA44DF1699DE57D766120C93ED41F4D31C18710B6C107B846FEFE4E95A560A6BCC2CC6DAC04FC151AD1751B4278A54D0C2671F409C8575672B78B5E3EA28A4D2086452BD643D831FB68575605CCD6935EB9EB2886D197B646AB3D2A0421DB12FA59E5B48569E599B0275E399A90D90CB5CF6EAB915BA8CA139A4F6955EB0A986CBBD2C5F1EB9D22A057ADBE72916EE282BAD46CCE642A1CD18AF9BF42A6F4DC3D175A78DDED1670447A99AB7FF4D11165EBB9FC0B4B438A1D9D793B266F3356F29B7D9D882E4097A0969540127F55D8B8918245BBFCA9DC8290D14F4ECA4921B397FA4E6A16155723DD25185457064A4D13CCB64060A06348651D2E199DEB7C1DC31E7718F5A6A658DB30C807ADF416E731F1BCC5B0D59B4B81A09AECC83A332F5932463DE6DCC5DE27FF08100DF6EFB3F8CADE43C72B644994B30A485BBEFD00E23434FCF55C54D952E599FE56A408361BAF91DA4B4671F2690635BAF56169A48ABA11410361DB920FB97AFEFD94D035A161A6D8AF2F2E3124C0914883B81A5D31BEA60B6E7F8A0D2834787687BBB059877A257D21A0A3B448D291229512DEB08892C541567E0C33B6932C3D1B4C9D57DC4C76FFF23D224082BD98E4060A28F72A6D89EA7197A08CD985C2892BD87AF5DED9BDE907591BA9A5143A7A7E0D2C34322C70B74623A66B705DDC5130B80380BB12C3EC6106F3D0CB70560847BEE211512578A56FEB5DDF09E01CA45C1AC19E6C58C1D87CADBD573C0E8EDD833A51D1707CC03011FD5503CA2E34EDE0B9DDEDF94E5ACE167811CC3C66C52F9AB70DB1C8B7197BAA7F49539157D417DF2DC3773DF370573D58CC5D79106C72FB4154BC19E2EA5BC4074B28F99237B99D08C1C2AF809866962D8A81486A9D9135D70E40FFC2ACFBEB7D5C644359CBC56636F7812F4A3920C9BBFFEC497CCD5F4D7DDB1DAC1FF2A8C9D42ACFCFC80C49FAE679CD7

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Windows\SysWOW64\msiexec.exe"="C:\Windows\SysWOW64\msiexec.exe:*:Generic Host Process"
"C:\Windows\SysWOW64\svchost.exe"="C:\Windows\SysWOW64\svchost.exe:*:Generic Host Process"
"C:\Users\Max_cz\AppData\Roaming\ZQPV2L7C2K.exe"="C:\Users\Max_cz\AppData\Roaming\ZQPV2L7C2K.exe:*:Enabled:Windows Messanger"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"msacm.l3codecp"=l3codecp.acm
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.txt - open - "C:\Program Files (x86)\PSPad editor\PSPad.exe" "%1"

======List of files/folders created in the last 1 month======

2016-03-16 22:44:36 ----A---- C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys
2016-03-16 22:44:03 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2016-03-16 22:44:03 ----A---- C:\WINDOWS\system32\drivers\mbamchameleon.sys
2016-03-16 22:44:03 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2016-03-16 22:44:02 ----D---- C:\ProgramData\Malwarebytes
2016-03-16 22:44:02 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-16 22:32:35 ----D---- C:\ProgramData\238a5536
2016-03-16 16:22:00 ----D---- C:\WINDOWS\SYSWOW64\NV
2016-03-16 16:22:00 ----D---- C:\WINDOWS\system32\NV
2016-03-14 16:29:03 ----SHD---- C:\Config.Msi
2016-03-14 16:21:34 ----D---- C:\WINDOWS\LastGood
2016-03-14 16:20:45 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2016-03-14 16:20:45 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2016-03-14 16:20:45 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-14 16:20:45 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-14 16:20:45 ----A---- C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-14 16:20:45 ----A---- C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-14 16:20:45 ----A---- C:\WINDOWS\system32\drivers\nvpciflt.sys
2016-03-14 15:43:36 ----D---- C:\WINDOWS\LastGood.Tmp
2016-03-11 00:16:36 ----AD---- C:\Program Files\Speccy
2016-03-11 00:16:07 ----AD---- C:\Program Files\Defraggler
2016-03-09 20:20:33 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-03-09 20:20:32 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-03-09 20:20:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-03-09 20:20:31 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-03-09 20:20:30 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-03-09 20:20:29 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-03-09 20:20:27 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-03-09 20:20:24 ----A---- C:\WINDOWS\system32\WSService.dll
2016-03-09 20:20:24 ----A---- C:\WINDOWS\system32\wmp.dll
2016-03-09 20:20:23 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-09 20:20:19 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-03-09 20:20:17 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-03-09 20:20:15 ----A---- C:\WINDOWS\system32\windows.storage.dll
2016-03-09 20:20:12 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2016-03-09 20:20:12 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2016-03-09 20:20:10 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-03-09 20:20:05 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-03-09 20:20:05 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-09 20:20:03 ----A---- C:\WINDOWS\system32\dosvc.dll
2016-03-09 20:20:02 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-09 20:20:01 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-03-09 20:19:58 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2016-03-09 20:19:57 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-03-09 20:19:57 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-03-09 20:19:56 ----A---- C:\WINDOWS\system32\KernelBase.dll
2016-03-09 20:19:56 ----A---- C:\WINDOWS\system32\diagtrack.dll
2016-03-09 20:19:55 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2016-03-09 20:19:55 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-03-09 20:19:55 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-03-09 20:19:55 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-03-09 20:19:55 ----A---- C:\WINDOWS\system32\ContactApis.dll
2016-03-09 20:19:54 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-03-09 20:19:54 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2016-03-09 20:19:54 ----A---- C:\WINDOWS\system32\Unistore.dll
2016-03-09 20:19:54 ----A---- C:\WINDOWS\system32\ole32.dll
2016-03-09 20:19:53 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2016-03-09 20:19:53 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-03-09 20:19:53 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2016-03-09 20:19:53 ----A---- C:\WINDOWS\system32\dxgi.dll
2016-03-09 20:19:53 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-03-09 20:19:52 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2016-03-09 20:19:52 ----A---- C:\WINDOWS\system32\invagent.dll
2016-03-09 20:19:52 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2016-03-09 20:19:51 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-03-09 20:19:51 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2016-03-09 20:19:51 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2016-03-09 20:19:51 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-09 20:19:51 ----A---- C:\WINDOWS\system32\ClipSVC.dll
2016-03-09 20:19:50 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2016-03-09 20:19:50 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2016-03-09 20:19:50 ----A---- C:\WINDOWS\system32\SRH.dll
2016-03-09 20:19:50 ----A---- C:\WINDOWS\system32\mfds.dll
2016-03-09 20:19:50 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-03-09 20:19:50 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2016-03-09 20:19:49 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2016-03-09 20:19:49 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2016-03-09 20:19:49 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2016-03-09 20:19:49 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-03-09 20:19:49 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-03-09 20:19:48 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2016-03-09 20:19:48 ----A---- C:\WINDOWS\system32\wer.dll
2016-03-09 20:19:48 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-09 20:19:47 ----A---- C:\WINDOWS\SYSWOW64\PackageStateRoaming.dll
2016-03-09 20:19:47 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-03-09 20:19:47 ----A---- C:\WINDOWS\system32\dafBth.dll
2016-03-09 20:19:47 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-09 20:19:46 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2016-03-09 20:19:32 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-03-09 20:19:31 ----A---- C:\WINDOWS\SYSWOW64\sqmapi.dll
2016-03-09 20:19:31 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2016-03-09 20:19:31 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2016-03-09 20:19:31 ----A---- C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-09 20:19:30 ----A---- C:\WINDOWS\system32\ChatApis.dll
2016-03-09 20:19:30 ----A---- C:\WINDOWS\system32\EmailApis.dll
2016-03-09 20:19:29 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2016-03-09 20:19:29 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2016-03-09 20:19:29 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-09 20:19:27 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-03-09 20:19:27 ----A---- C:\WINDOWS\SYSWOW64\AppointmentActivation.dll
2016-03-09 20:19:27 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-03-09 20:19:27 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2016-03-09 20:19:26 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2016-03-09 20:19:26 ----A---- C:\WINDOWS\system32\VCardParser.dll
2016-03-09 20:19:26 ----A---- C:\WINDOWS\system32\sqmapi.dll
2016-03-09 20:19:26 ----A---- C:\WINDOWS\system32\sharemediacpl.dll
2016-03-09 20:19:26 ----A---- C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-09 20:19:23 ----A---- C:\WINDOWS\SYSWOW64\cemapi.dll
2016-03-09 20:19:23 ----A---- C:\WINDOWS\system32\domgmt.dll
2016-03-09 20:19:22 ----A---- C:\WINDOWS\SYSWOW64\fwbase.dll
2016-03-09 20:19:22 ----A---- C:\WINDOWS\system32\cemapi.dll
2016-03-09 20:19:20 ----A---- C:\WINDOWS\SYSWOW64\PhoneCallHistoryApis.dll
2016-03-09 20:19:20 ----A---- C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-09 20:19:14 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-03-09 20:19:14 ----A---- C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-09 20:19:14 ----A---- C:\WINDOWS\system32\AuthHost.exe
2016-03-09 20:19:14 ----A---- C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-09 20:19:13 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2016-03-09 20:19:13 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2016-03-09 20:19:10 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2016-03-09 20:19:10 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2016-03-09 20:19:09 ----A---- C:\WINDOWS\SYSWOW64\wermgr.exe
2016-03-09 20:19:09 ----A---- C:\WINDOWS\SYSWOW64\asycfilt.dll
2016-03-09 20:19:08 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2016-03-09 20:19:08 ----A---- C:\WINDOWS\system32\wermgr.exe
2016-03-09 20:19:07 ----A---- C:\WINDOWS\SYSWOW64\POSyncServices.dll
2016-03-09 20:19:07 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2016-03-09 20:19:07 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2016-03-09 20:19:07 ----A---- C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-09 20:19:07 ----A---- C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-09 20:19:07 ----A---- C:\WINDOWS\system32\asycfilt.dll
2016-03-09 20:19:07 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-03-09 20:19:06 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2016-03-09 20:19:00 ----A---- C:\WINDOWS\system32\AppxSip.dll
2016-03-09 20:18:58 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2016-03-09 20:18:58 ----A---- C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-09 20:18:58 ----A---- C:\WINDOWS\system32\ExSMime.dll
2016-03-09 20:18:58 ----A---- C:\WINDOWS\system32\devinv.dll
2016-03-09 20:18:57 ----A---- C:\WINDOWS\SYSWOW64\ExtrasXmlParser.dll
2016-03-09 20:18:57 ----A---- C:\WINDOWS\system32\FirewallAPI.dll
2016-03-09 20:18:57 ----A---- C:\WINDOWS\system32\dssvc.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\SYSWOW64\CallHistoryClient.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\system32\wpninprc.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\system32\wfapigp.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\system32\seclogon.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\system32\POSyncServices.dll
2016-03-09 20:18:56 ----A---- C:\WINDOWS\system32\fwbase.dll
2016-03-09 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\profext.dll
2016-03-09 20:18:55 ----A---- C:\WINDOWS\SYSWOW64\PimIndexMaintenanceClient.dll
2016-03-09 20:18:55 ----A---- C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-09 20:18:55 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-09 20:18:55 ----A---- C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-09 20:18:54 ----A---- C:\WINDOWS\SYSWOW64\UserDataPlatformHelperUtil.dll
2016-03-09 20:18:54 ----A---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2016-03-09 20:18:54 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-03-09 20:18:53 ----A---- C:\WINDOWS\SYSWOW64\UserDataLanguageUtil.dll
2016-03-09 20:18:52 ----A---- C:\WINDOWS\SYSWOW64\UserDataTypeHelperUtil.dll
2016-03-09 20:18:51 ----A---- C:\WINDOWS\system32\UserDataService.dll
2016-03-09 20:18:51 ----A---- C:\WINDOWS\system32\profext.dll
2016-03-09 20:18:51 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-03-09 20:18:51 ----A---- C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-09 20:18:51 ----A---- C:\WINDOWS\system32\configurationclient.dll
2016-03-09 20:18:50 ----A---- C:\WINDOWS\SYSWOW64\wfapigp.dll
2016-03-09 20:18:50 ----A---- C:\WINDOWS\SYSWOW64\werui.dll
2016-03-09 20:18:50 ----A---- C:\WINDOWS\SYSWOW64\fwpolicyiomgr.dll
2016-03-09 20:18:50 ----A---- C:\WINDOWS\system32\werui.dll
2016-03-09 20:18:50 ----A---- C:\WINDOWS\system32\vaultsvc.dll
2016-03-09 20:18:50 ----A---- C:\WINDOWS\system32\vaultcli.dll
2016-03-09 20:18:50 ----A---- C:\WINDOWS\system32\scapi.dll
2016-03-09 20:18:50 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-03-09 20:18:49 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-03-09 20:18:49 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-03-09 20:18:49 ----A---- C:\WINDOWS\system32\drivers\bthenum.sys
2016-03-09 20:18:49 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-03-04 20:03:55 ----AD---- C:\Program Files (x86)\HD Tune
2016-03-04 19:21:20 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-04 19:21:19 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-04 19:21:16 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-03-04 19:21:15 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-03-04 19:21:14 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-03-04 19:21:14 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-03-04 19:21:14 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-03-04 19:21:14 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-03-04 19:21:14 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-03-04 19:21:13 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-03-04 19:21:12 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-03-04 19:21:12 ----A---- C:\WINDOWS\system32\wininet.dll
2016-03-04 19:21:12 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-03-04 19:21:11 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-03-04 19:21:11 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-03-04 19:21:10 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-03-04 19:21:10 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-03-04 19:21:05 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-03-04 19:21:05 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-03-04 19:21:04 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-03-04 19:21:04 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-03-04 19:21:04 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-03-04 19:21:04 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-03-04 19:21:04 ----A---- C:\WINDOWS\system32\AudioSes.dll
2016-03-04 19:21:04 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-04 19:21:03 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-03-04 19:21:03 ----A---- C:\WINDOWS\system32\InputService.dll
2016-03-04 19:21:02 ----A---- C:\WINDOWS\system32\twinui.dll
2016-03-04 19:21:00 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-03-04 19:20:57 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-03-04 19:20:57 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2016-03-04 19:20:56 ----A---- C:\WINDOWS\system32\shell32.dll
2016-03-04 19:20:50 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-03-04 19:20:48 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-04 19:20:47 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-03-04 19:20:47 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-04 19:20:47 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-03-04 19:20:46 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-03-04 19:20:46 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-04 19:20:45 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-03-04 19:20:45 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-03-04 19:20:45 ----A---- C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-04 19:20:45 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-04 19:20:43 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-04 19:20:42 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-04 19:20:41 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-03-04 19:20:40 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2016-03-04 19:20:40 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-03-04 19:20:40 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-04 19:20:40 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-04 19:20:39 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-03-04 19:20:39 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-03-04 19:20:39 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-03-04 19:20:38 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-03-04 19:20:38 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2016-03-04 19:20:36 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-03-04 19:20:36 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-03-04 19:20:36 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-04 19:20:36 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-04 19:20:36 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-04 19:20:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-03-04 19:20:35 ----A---- C:\WINDOWS\system32\XblGameSave.dll
2016-03-04 19:20:35 ----A---- C:\WINDOWS\system32\schedsvc.dll
2016-03-04 19:20:34 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-03-04 19:20:34 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-03-04 19:20:34 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-04 19:20:33 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2016-03-04 19:20:33 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-03-04 19:20:33 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-03-04 19:20:33 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2016-03-04 19:20:32 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2016-03-04 19:20:32 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-03-04 19:20:32 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-03-04 19:20:32 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-04 19:20:31 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-03-04 19:20:31 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-04 19:20:31 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-04 19:20:31 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-04 19:20:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-03-04 19:20:30 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2016-03-04 19:20:30 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-03-04 19:20:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-03-04 19:20:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-03-04 19:20:29 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2016-03-04 19:20:28 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2016-03-04 19:20:28 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2016-03-04 19:20:28 ----A---- C:\WINDOWS\system32\SMSRouter.dll
2016-03-04 19:20:28 ----A---- C:\WINDOWS\system32\ngckeyenum.dll
2016-03-04 19:20:28 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-04 19:20:27 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2016-03-04 19:20:27 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-04 19:20:27 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2016-03-04 19:20:27 ----A---- C:\WINDOWS\system32\MDEServer.exe
2016-03-04 19:20:26 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2016-03-04 19:20:26 ----A---- C:\WINDOWS\system32\NetSetupShim.dll
2016-03-04 19:20:26 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-04 19:20:25 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-03-04 19:20:25 ----A---- C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-04 19:20:25 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-04 19:20:25 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-03-04 19:20:24 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-04 19:20:24 ----A---- C:\WINDOWS\system32\usbmon.dll
2016-03-04 19:20:24 ----A---- C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-04 19:20:24 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-03-04 19:20:24 ----A---- C:\WINDOWS\system32\SettingSync.dll
2016-03-04 19:20:24 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-04 19:20:23 ----A---- C:\WINDOWS\system32\wlansvc.dll
2016-03-04 19:20:23 ----A---- C:\WINDOWS\system32\winload.exe
2016-03-04 19:20:23 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-04 19:20:22 ----A---- C:\WINDOWS\system32\winresume.exe
2016-03-04 19:20:22 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-03-04 19:20:21 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2016-03-04 19:20:21 ----A---- C:\WINDOWS\SYSWOW64\taskschd.dll
2016-03-04 19:20:21 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-03-04 19:20:21 ----A---- C:\WINDOWS\system32\localspl.dll
2016-03-04 19:20:21 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-03-04 19:20:20 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2016-03-04 19:20:20 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2016-03-04 19:20:20 ----A---- C:\WINDOWS\system32\uDWM.dll
2016-03-04 19:20:20 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2016-03-04 19:20:20 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2016-03-04 19:20:19 ----A---- C:\WINDOWS\SYSWOW64\NetSetupShim.dll
2016-03-04 19:20:19 ----A---- C:\WINDOWS\system32\thumbcache.dll
2016-03-04 19:20:19 ----A---- C:\WINDOWS\system32\taskschd.dll
2016-03-04 19:20:19 ----A---- C:\WINDOWS\system32\msvproc.dll
2016-03-04 19:20:19 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-03-04 19:20:18 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2016-03-04 19:20:18 ----A---- C:\WINDOWS\SYSWOW64\msvproc.dll
2016-03-04 19:20:18 ----A---- C:\WINDOWS\system32\netlogon.dll
2016-03-04 19:20:18 ----A---- C:\WINDOWS\system32\drivers\rfcomm.sys
2016-03-04 19:20:18 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-03-04 19:20:17 ----A---- C:\WINDOWS\system32\wuuhext.dll
2016-03-04 19:20:17 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-04 19:20:17 ----A---- C:\WINDOWS\system32\spoolsv.exe
2016-03-04 19:20:17 ----A---- C:\WINDOWS\system32\drivers\xinputhid.sys
2016-03-04 19:20:17 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-03-04 19:20:16 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2016-03-04 19:20:16 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2016-03-04 19:20:16 ----A---- C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-04 19:20:16 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-04 19:20:16 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2016-03-04 19:20:16 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2016-03-04 19:20:15 ----A---- C:\WINDOWS\SYSWOW64\WiFiDisplay.dll
2016-03-04 19:20:15 ----A---- C:\WINDOWS\system32\SyncController.dll
2016-03-04 19:20:15 ----A---- C:\WINDOWS\system32\drivers\appid.sys
2016-03-04 19:20:15 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2016-03-04 19:20:14 ----A---- C:\WINDOWS\SYSWOW64\SyncController.dll
2016-03-04 19:20:14 ----A---- C:\WINDOWS\system32\wlanapi.dll
2016-03-04 19:20:14 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-04 19:20:14 ----A---- C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-04 19:20:13 ----A---- C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-04 19:20:12 ----A---- C:\WINDOWS\system32\wlansec.dll
2016-03-04 19:20:12 ----A---- C:\WINDOWS\system32\psmsrv.dll
2016-03-04 19:20:12 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2016-03-04 19:20:12 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2016-03-04 19:20:11 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-04 19:20:11 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2016-03-04 19:20:11 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2016-03-04 19:20:11 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-04 19:20:11 ----A---- C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-04 19:20:11 ----A---- C:\WINDOWS\system32\provpackageapidll.dll
2016-03-04 19:20:11 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-03-04 19:20:11 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2016-03-04 19:20:10 ----A---- C:\WINDOWS\SYSWOW64\TimeBrokerClient.dll
2016-03-04 19:20:10 ----A---- C:\WINDOWS\system32\wfdprov.dll
2016-03-04 19:20:10 ----A---- C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-04 19:20:10 ----A---- C:\WINDOWS\system32\srpapi.dll
2016-03-04 19:20:10 ----A---- C:\WINDOWS\system32\irmon.dll
2016-03-04 19:20:10 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2016-03-04 19:20:09 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-03-04 19:20:09 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-03-04 19:20:09 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-04 19:20:09 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-04 19:20:09 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-03-04 19:20:09 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-02-25 23:58:00 ----D---- C:\WINDOWS\system32\SleepStudy
2016-02-21 10:59:38 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.dll
2016-02-21 10:59:38 ----A---- C:\WINDOWS\system32\OpenCL.dll
2016-02-21 10:57:58 ----A---- C:\WINDOWS\system32\nvdispgenco6436191.dll
2016-02-21 10:57:58 ----A---- C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-21 10:53:59 ----D---- C:\Program Files\Western Digital
2016-02-21 04:41:38 ----SHD---- C:\Recovery
2016-02-21 04:27:32 ----ASH---- C:\hiberfil.sys
2016-02-21 04:16:27 ----D---- C:\Program Files\Common Files\SpeechEngines
2016-02-21 04:13:42 ----SD---- C:\Users\Max_cz\AppData\Roaming\Microsoft
2016-02-21 04:12:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-21 04:12:41 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2016-02-21 04:09:58 ----D---- C:\Program Files\AuthenTec
2016-02-21 04:09:49 ----D---- C:\ProgramData\NVIDIA
2016-02-21 04:09:43 ----A---- C:\WINDOWS\SYSWOW64\oemdspif.dll
2016-02-21 04:09:43 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-02-21 04:09:43 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-02-21 04:09:43 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-02-21 04:09:43 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-02-21 04:09:43 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-02-21 04:09:43 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-02-21 04:09:43 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-02-21 04:09:43 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-02-21 04:09:30 ----D---- C:\ProgramData\NVIDIA Corporation
2016-02-21 04:09:17 ----D---- C:\Program Files\NVIDIA Corporation
2016-02-21 04:09:17 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-02-21 04:08:49 ----A---- C:\WINDOWS\SYSWOW64\SASrv.exe
2016-02-21 04:08:46 ----A---- C:\WINDOWS\system32\drivers\CxSfPt.dat
2016-02-21 04:08:37 ----A---- C:\WINDOWS\system32\CxAudMsg64.exe
2016-02-21 04:08:32 ----A---- C:\WINDOWS\system32\drivers\SamSfPa.dat
2016-02-21 04:08:27 ----AD---- C:\Program Files\Dolby Digital Plus
2016-02-21 04:08:15 ----HD---- C:\Program Files\Uninstall Information
2016-02-21 04:07:53 ----D---- C:\ProgramData\Conexant
2016-02-21 04:07:46 ----D---- C:\Program Files\CONEXANT
2016-02-21 04:07:43 ----D---- C:\WINDOWS\SYSWOW64\sda
2016-02-21 04:07:03 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2016-02-21 04:06:52 ----D---- C:\Program Files\Synaptics
2016-02-21 04:04:43 ----AS---- C:\WINDOWS\bootstat.dat
2016-02-21 04:03:51 ----D---- C:\WINDOWS\Prefetch
2016-02-21 04:03:05 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2016-02-21 04:02:49 ----ASH---- C:\pagefile.sys
2016-02-21 04:01:59 ----DC---- C:\WINDOWS\Panther
2016-02-21 03:57:18 ----D---- C:\Windows.old
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOE.DLL
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOD.DLL
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\MSMPEG2ENC.DLL
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\MP3DMOD.DLL
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.proxy.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\wpncore.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\WpcMon.exe
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\srcore.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\quartz.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\MP3DMOD.DLL
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\mftranscode.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\mfps.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\mfplat.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\EncDump.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\dialserver.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\AudioEng.dll
2016-02-21 03:56:02 ----A---- C:\WINDOWS\system32\advapi32.dll
2016-02-21 03:56:01 ----A---- C:\WINDOWS\SYSWOW64\SensorsApi.dll
2016-02-21 03:56:01 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2016-02-21 03:56:01 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2016-02-21 03:56:01 ----A---- C:\WINDOWS\system32\WMSPDMOE.DLL
2016-02-21 03:56:01 ----A---- C:\WINDOWS\system32\SensorsApi.dll
2016-02-21 03:56:01 ----A---- C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-02-21 03:56:01 ----A---- C:\WINDOWS\system32\MFPlay.dll
2016-02-21 03:56:01 ----A---- C:\WINDOWS\system32\jscript.dll
2016-02-21 03:56:01 ----A---- C:\WINDOWS\system32\iernonce.dll
2016-02-21 03:56:01 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2016-02-21 03:56:01 ----A---- C:\WINDOWS\system32\evr.dll
2016-02-21 03:55:56 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2016-02-21 03:55:56 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2016-02-21 03:55:56 ----A---- C:\WINDOWS\system32\readingviewresources.dll
2016-02-21 03:55:56 ----A---- C:\WINDOWS\system32\msfeeds.dll
2016-02-21 03:55:56 ----A---- C:\WINDOWS\system32\iesetup.dll
2016-02-21 03:55:56 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\wwapi.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\wlidcli.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\usermgrcli.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\SimCfg.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\SimAuth.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\rastlsext.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\rastls.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\rasdlg.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\rasautou.exe
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\rasadhlp.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\pcaui.exe
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\OpenWith.exe
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\mtxoci.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\mssign32.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\iassam.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\CredProvDataModel.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\OpenWith.exe
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\msctf.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\lpk.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\dciman32.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2016-02-21 03:55:55 ----A---- C:\WINDOWS\system32\acmigration.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wwapi.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\Wwanpref.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wwanmm.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wwanconn.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wwancfg.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wsplib.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wshrm.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\WMSPDMOD.DLL
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wifitask.exe
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wificonnapi.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\SimCfg.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\SimAuth.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\shutdownux.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\rilproxy.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\rastlsext.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\rastls.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\rasdlg.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\rasautou.exe
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\rasauto.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\rasapi32.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\rasadhlp.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\pnidui.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\PhoneService.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\LogonController.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\ihvrilproxy.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\iassam.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\CredProvDataModel.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\system32\authui.dll
2016-02-21 03:55:52 ----A---- C:\WINDOWS\explorer.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\NmaDirect.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\MosResource.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosTrace.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosHost.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MapControls.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\MapControlStringsRes.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\BingOnlineServices.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\wups2.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\wscsvc.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\wscapi.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\wlidcli.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\wimserv.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\wimgapi.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\usermgrcli.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\uReFS.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\tetheringconfigsp.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\systemreset.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\sscoreext.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\services.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\SensorsUtilsV2.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\SensorService.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\reseteng.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\RecoveryDrive.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\qedit.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\provtool.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\provops.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\provhandlers.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\provengine.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\provdatastore.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\policymanager.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\pcaui.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\omadmclient.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\NmaDirect.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\NMAA.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\nativemap.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MusNotification.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\mtxoci.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MTFServer.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MTF.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\mssign32.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MosStorage.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MosResource.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\moshostcore.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\moshost.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\mos.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\mfpmp.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\mf.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\mapstoasttask.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MapsStore.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MapControlStringsRes.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\IcsEntitlementHost.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\hlink.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\FilterDS.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\DscCore.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\drivers\mrxdav.sys
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\drivers\http.sys
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\DDDS.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\cryptngc.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\comsvcs.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\catsrvut.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\BingOnlineServices.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\bcastdvr.proxy.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\aitstatic.exe
2016-02-21 03:55:51 ----A---- C:\WINDOWS\system32\aepic.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\ztrace_maps.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\winhttpcom.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\winhttp.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\winbio.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCoreRes.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\qedit.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\MTF.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\msorcl32.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\hlink.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\ETWCoreUIComponentsResources.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\cfgbkend.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\BackgroundTransferHost.exe
2016-02-21 03:55:47 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\ztrace_maps.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\wlidsvc.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\WinTypes.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\winhttpcom.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\winhttp.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\winbio.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\win32k.sys
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\wbiosrvc.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\user32.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\UIAutomationCoreRes.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\schannel.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\ProximityCommon.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\msftedit.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\lsasrv.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\kerberos.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\fveapibase.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\fveapi.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\facecredentialprovider.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\drivers\usbser.sys
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\drivers\BthLEEnum.sys
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\dcomp.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\d2d1.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\combase.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\cdp.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\BingMaps.dll
2016-02-21 03:55:47 ----A---- C:\WINDOWS\system32\BackgroundTransferHost.exe
2016-02-21 03:51:44 ----A---- C:\WINDOWS\SYSWOW64\NlsLexicons0009.dll
2016-02-21 03:51:44 ----A---- C:\WINDOWS\SYSWOW64\NlsData0009.dll
2016-02-21 03:51:44 ----A---- C:\WINDOWS\system32\prm0009.dll
2016-02-21 03:51:44 ----A---- C:\WINDOWS\system32\NlsLexicons0009.dll
2016-02-21 03:51:44 ----A---- C:\WINDOWS\system32\NlsData0009.dll
2016-02-21 03:51:03 ----D---- C:\WINDOWS\system32\Microsoft
2016-02-21 03:47:39 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2016-02-21 03:47:39 ----D---- C:\WINDOWS\SYSWOW64\BestPractices
2016-02-21 03:47:39 ----D---- C:\WINDOWS\system32\msmq
2016-02-21 03:47:38 ----D---- C:\WINDOWS\system32\BestPractices
2016-02-21 03:47:36 ----D---- C:\Program Files\Reference Assemblies
2016-02-21 03:47:36 ----D---- C:\Program Files\MSBuild
2016-02-21 03:47:36 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-02-21 03:47:36 ----D---- C:\Program Files (x86)\MSBuild
2016-02-21 03:47:36 ----D---- C:\inetpub
2016-02-21 03:46:47 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2016-02-21 03:46:47 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2016-02-21 03:46:47 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-02-21 03:46:41 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2016-02-21 03:46:41 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-02-21 03:46:41 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll

======List of files/folders modified in the last 1 month======

2016-03-16 23:43:36 ----D---- C:\Program Files\trend micro
2016-03-16 23:43:33 ----D---- C:\WINDOWS\Temp
2016-03-16 23:27:54 ----D---- C:\WINDOWS\System32
2016-03-16 23:27:54 ----D---- C:\WINDOWS\INF
2016-03-16 23:26:52 ----HD---- C:\ProgramData
2016-03-16 23:24:10 ----D---- C:\WINDOWS\SysWOW64
2016-03-16 23:22:49 ----RD---- C:\WINDOWS\PurchaseDialog
2016-03-16 23:22:49 ----D---- C:\WINDOWS\system32\drivers
2016-03-16 23:22:24 ----D---- C:\WINDOWS\system32\sru
2016-03-16 23:21:34 ----D---- C:\WINDOWS\system32\Tasks
2016-03-16 23:21:15 ----RD---- C:\Program Files (x86)
2016-03-16 23:21:15 ----D---- C:\WINDOWS\Tasks
2016-03-16 23:21:15 ----D---- C:\ProgramData\YTD Video Downloader
2016-03-16 22:40:17 ----D---- C:\WINDOWS\system32\drivers\etc
2016-03-16 21:30:41 ----D---- C:\WINDOWS\AppReadiness
2016-03-16 20:53:11 ----D---- C:\Users\Max_cz\AppData\Roaming\PTGui
2016-03-16 16:41:38 ----D---- C:\WINDOWS\Microsoft.NET
2016-03-15 18:18:04 ----HD---- C:\Program Files\WindowsApps
2016-03-14 20:01:50 ----D---- C:\Users\Max_cz\AppData\Roaming\vlc
2016-03-14 16:29:16 ----SHD---- C:\WINDOWS\Installer
2016-03-14 16:22:59 ----D---- C:\WINDOWS\system32\DriverStore
2016-03-14 16:21:34 ----D---- C:\Windows
2016-03-14 15:45:10 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2016-03-14 15:45:10 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2016-03-14 15:45:10 ----A---- C:\WINDOWS\system32\nvapi64.dll
2016-03-14 15:45:09 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2016-03-14 15:45:09 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2016-03-14 15:45:09 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2016-03-14 15:45:09 ----A---- C:\WINDOWS\system32\nvumdshimx.dll
2016-03-14 15:45:09 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2016-03-14 15:45:08 ----A---- C:\WINDOWS\SYSWOW64\nvumdshim.dll
2016-03-14 15:45:08 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2016-03-14 15:45:07 ----A---- C:\WINDOWS\system32\nvopencl.dll
2016-03-14 15:45:06 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2016-03-14 15:45:05 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-14 15:45:02 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2016-03-14 15:45:02 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2016-03-14 15:45:02 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2016-03-14 15:45:01 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2016-03-14 15:44:59 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2016-03-14 15:44:59 ----A---- C:\WINDOWS\system32\nvinitx.dll
2016-03-14 15:44:57 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2016-03-14 15:44:56 ----A---- C:\WINDOWS\system32\nvcuda.dll
2016-03-14 15:44:55 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2016-03-14 15:44:53 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2016-03-14 15:44:44 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2016-03-14 15:44:41 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2016-03-14 15:44:37 ----D---- C:\WINDOWS\system32\config
2016-03-11 02:25:35 ----D---- C:\WINDOWS\WinSxS
2016-03-11 00:16:36 ----RD---- C:\Program Files
2016-03-11 00:12:24 ----D---- C:\Users\Max_cz\AppData\Roaming\FileZilla
2016-03-10 23:17:49 ----RD---- C:\WINDOWS\assembly
2016-03-10 23:07:30 ----D---- C:\WINDOWS\CbsTemp
2016-03-10 21:17:52 ----D---- C:\Program Files (x86)\FileZilla FTP Client
2016-03-10 19:50:51 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-03-10 19:46:36 ----D---- C:\WINDOWS\system32\WDI
2016-03-09 23:17:23 ----D---- C:\WINDOWS\system32\migration
2016-03-09 23:17:19 ----D---- C:\WINDOWS\AppPatch
2016-03-09 23:17:19 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-03-09 23:17:18 ----D---- C:\Program Files\Windows Portable Devices
2016-03-09 23:17:18 ----D---- C:\Program Files (x86)\Windows Multimedia Platform
2016-03-09 23:17:18 ----D---- C:\Program Files (x86)\Internet Explorer
2016-03-09 23:17:17 ----D---- C:\Program Files\Windows Multimedia Platform
2016-03-09 23:17:17 ----D---- C:\Program Files\Windows Media Player
2016-03-09 23:17:16 ----D---- C:\Program Files\Internet Explorer
2016-03-09 20:44:25 ----D---- C:\WINDOWS\system32\MRT
2016-03-09 20:36:47 ----A---- C:\WINDOWS\system32\MRT.exe
2016-03-09 20:11:26 ----D---- C:\WINDOWS\system32\catroot2
2016-03-05 20:30:28 ----D---- C:\WINDOWS\rescache
2016-03-05 01:28:40 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-03-05 01:28:40 ----D---- C:\WINDOWS\SYSWOW64\Dism
2016-03-05 01:28:39 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2016-03-05 01:28:39 ----D---- C:\WINDOWS\system32\wbem
2016-03-05 01:28:39 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-03-05 01:28:39 ----D---- C:\WINDOWS\system32\Dism
2016-03-05 01:28:39 ----D---- C:\WINDOWS\system32\Boot
2016-03-05 01:28:39 ----D---- C:\WINDOWS\system32\appraiser
2016-03-05 01:28:37 ----RSD---- C:\WINDOWS\Media
2016-03-05 01:28:37 ----RSD---- C:\WINDOWS\Fonts
2016-03-05 01:28:37 ----D---- C:\WINDOWS\bcastdvr
2016-03-05 01:28:37 ----D---- C:\Program Files\Windows Journal
2016-03-04 20:03:46 ----D---- C:\Users\Max_cz\AppData\Roaming\uTorrent
2016-03-04 18:54:48 ----D---- C:\WINDOWS\Logs
2016-02-29 19:16:21 ----D---- C:\WINDOWS\system32\LogFiles
2016-02-25 23:01:51 ----D---- C:\WINDOWS\debug
2016-02-25 22:38:59 ----D---- C:\WINDOWS\appcompat
2016-02-21 11:02:02 ----RD---- C:\WINDOWS\DevicesFlow
2016-02-21 10:55:14 ----D---- C:\ProgramData\Package Cache
2016-02-21 10:53:59 ----AD---- C:\Program Files\Common Files\Western Digital
2016-02-21 10:53:58 ----D---- C:\ProgramData\Western Digital
2016-02-21 10:53:58 ----AD---- C:\Program Files (x86)\Western Digital
2016-02-21 10:44:09 ----RD---- C:\WINDOWS\PrintDialog
2016-02-21 10:44:08 ----RD---- C:\WINDOWS\MiracastView
2016-02-21 10:43:34 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-02-21 04:44:34 ----SD---- C:\ProgramData\Microsoft
2016-02-21 04:41:38 ----D---- C:\Program Files\Windows NT
2016-02-21 04:40:57 ----D---- C:\WINDOWS\SoftwareDistribution
2016-02-21 04:38:32 ----D---- C:\WINDOWS\Registration
2016-02-21 04:38:27 ----D---- C:\WINDOWS\system32\WinBioDatabase
2016-02-21 04:26:52 ----D---- C:\WINDOWS\system32\STRING
2016-02-21 04:26:52 ----D---- C:\WINDOWS\system32\pt-PT
2016-02-21 04:26:52 ----D---- C:\WINDOWS\system32\pt-BR
2016-02-21 04:26:52 ----D---- C:\WINDOWS\system32\nl-NL
2016-02-21 04:26:52 ----D---- C:\WINDOWS\system32\it-IT
2016-02-21 04:26:52 ----D---- C:\WINDOWS\system32\fr-FR
2016-02-21 04:26:52 ----D---- C:\WINDOWS\system32\es-ES
2016-02-21 04:26:52 ----D---- C:\WINDOWS\system32\en-US
2016-02-21 04:26:51 ----D---- C:\WINDOWS\system32\de-DE
2016-02-21 04:26:48 ----D---- C:\ProgramData\regid.1986-12.com.adobe
2016-02-21 04:19:23 ----D---- C:\WINDOWS\twain_32
2016-02-21 04:19:23 ----D---- C:\WINDOWS\SYSWOW64\xlive
2016-02-21 04:19:21 ----D---- C:\WINDOWS\SYSWOW64\migwiz
2016-02-21 04:19:20 ----D---- C:\WINDOWS\SYSWOW64\IME
2016-02-21 04:19:18 ----D---- C:\WINDOWS\SYSWOW64\drivers
2016-02-21 04:19:10 ----HD---- C:\WINDOWS\system32\WLANProfiles
2016-02-21 04:19:08 ----D---- C:\WINDOWS\system32\spool
2016-02-21 04:19:04 ----D---- C:\WINDOWS\system32\NDF
2016-02-21 04:19:03 ----D---- C:\WINDOWS\system32\IME
2016-02-21 04:17:21 ----HD---- C:\WINDOWS\system32\CanonIJ Uninstaller Information
2016-02-21 04:17:21 ----D---- C:\WINDOWS\system32\CatRoot
2016-02-21 04:17:16 ----D---- C:\WINDOWS\System
2016-02-21 04:17:15 ----D---- C:\WINDOWS\schemas
2016-02-21 04:17:13 ----D---- C:\WINDOWS\OCR
2016-02-21 04:17:12 ----D---- C:\WINDOWS\LiveKernelReports
2016-02-21 04:16:58 ----D---- C:\WINDOWS\ehome
2016-02-21 04:16:54 ----RD---- C:\Users
2016-02-21 04:16:53 ----D---- C:\ProgramData\USOPrivate
2016-02-21 04:16:53 ----D---- C:\ProgramData\SoftwareDistribution
2016-02-21 04:16:38 ----SHD---- C:\Program Files (x86)\Windows Sidebar
2016-02-21 04:16:38 ----D---- C:\Program Files (x86)\Windows Mail
2016-02-21 04:16:35 ----D---- C:\Program Files (x86)\Common Files
2016-02-21 04:16:32 ----SHD---- C:\Program Files\Windows Sidebar
2016-02-21 04:16:32 ----D---- C:\Program Files\Windows Mail
2016-02-21 04:16:29 ----D---- C:\Program Files\Microsoft Games
2016-02-21 04:16:27 ----D---- C:\Program Files\Common Files\System
2016-02-21 04:16:27 ----D---- C:\Program Files\Common Files\microsoft shared
2016-02-21 04:16:27 ----D---- C:\Program Files\Common Files
2016-02-21 04:15:57 ----D---- C:\WINDOWS\system32\Recovery
2016-02-21 04:15:57 ----D---- C:\WINDOWS\system32\GroupPolicy
2016-02-21 04:13:23 ----D---- C:\WINDOWS\system32\CodeIntegrity
2016-02-21 04:12:07 ----D---- C:\WINDOWS\system32\Sysprep
2016-02-21 04:09:58 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-02-21 04:09:43 ----D---- C:\WINDOWS\Help
2016-02-21 04:03:18 ----D---- C:\WINDOWS\ServiceProfiles
2016-02-21 03:56:52 ----SD---- C:\WINDOWS\system32\F12
2016-02-21 03:56:52 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-02-21 03:56:52 ----D---- C:\WINDOWS\system32\oobe
2016-02-21 03:56:52 ----D---- C:\WINDOWS\system32\cs-CZ
2016-02-21 03:56:52 ----D---- C:\WINDOWS\Provisioning
2016-02-21 03:47:39 ----D---- C:\WINDOWS\SYSWOW64\MUI
2016-02-21 03:47:39 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2016-02-21 03:47:39 ----D---- C:\WINDOWS\system32\MUI
2016-02-21 03:47:39 ----D---- C:\WINDOWS\system32\inetsrv
2016-02-21 03:47:29 ----A---- C:\WINDOWS\SYSWOW64\mqsnap.dll
2016-02-21 03:47:29 ----A---- C:\WINDOWS\SYSWOW64\mqcertui.dll
2016-02-21 03:47:28 ----A---- C:\WINDOWS\system32\wamregps.dll
2016-02-21 03:47:28 ----A---- C:\WINDOWS\system32\iisRtl.dll
2016-02-21 03:47:28 ----A---- C:\WINDOWS\system32\iisrstap.dll
2016-02-21 03:47:28 ----A---- C:\WINDOWS\system32\iisreset.exe
2016-02-21 03:47:28 ----A---- C:\WINDOWS\system32\ahadmin.dll
2016-02-21 03:47:28 ----A---- C:\WINDOWS\system32\admwprox.dll
2016-02-21 03:47:26 ----A---- C:\WINDOWS\SYSWOW64\wamregps.dll
2016-02-21 03:47:26 ----A---- C:\WINDOWS\SYSWOW64\iisRtl.dll
2016-02-21 03:47:26 ----A---- C:\WINDOWS\SYSWOW64\iisrstap.dll
2016-02-21 03:47:26 ----A---- C:\WINDOWS\SYSWOW64\iisreset.exe
2016-02-21 03:47:26 ----A---- C:\WINDOWS\SYSWOW64\ahadmin.dll
2016-02-21 03:47:26 ----A---- C:\WINDOWS\SYSWOW64\admwprox.dll
2016-02-21 03:47:25 ----A---- C:\WINDOWS\system32\mqrt.dll
2016-02-21 03:47:24 ----A---- C:\WINDOWS\SYSWOW64\mqoa.dll
2016-02-21 03:47:23 ----A---- C:\WINDOWS\system32\mqlogmgr.dll
2016-02-21 03:47:22 ----A---- C:\WINDOWS\system32\mqutil.dll
2016-02-21 03:47:19 ----A---- C:\WINDOWS\system32\mqsnap.dll
2016-02-21 03:47:19 ----A---- C:\WINDOWS\system32\mqcertui.dll
2016-02-21 03:47:17 ----A---- C:\WINDOWS\SYSWOW64\mqrt.dll
2016-02-21 03:47:17 ----A---- C:\WINDOWS\system32\mqoa.dll
2016-02-21 03:47:16 ----A---- C:\WINDOWS\system32\mqqm.dll
2016-02-21 03:47:14 ----A---- C:\WINDOWS\SYSWOW64\mqutil.dll
2016-02-21 03:47:13 ----A---- C:\WINDOWS\system32\mqsvc.exe
2016-02-21 03:47:13 ----A---- C:\WINDOWS\system32\mqbkup.exe
2016-02-21 03:30:46 ----HD---- C:\$WINDOWS.~BT
2016-02-20 11:33:03 ----D---- C:\ProgramData\Lenovo
2016-02-17 07:40:22 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2016-02-17 07:40:22 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2016-02-17 07:40:08 ----A---- C:\WINDOWS\system32\NvRtmpStreamer64.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iusb3hcs;@oem18.inf,%XHCI_svcdesc%;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\WINDOWS\System32\drivers\iusb3hcs.sys [2012-04-13 19224]
R0 nvpciflt;nvpciflt; C:\WINDOWS\system32\DRIVERS\nvpciflt.sys [2016-03-14 31376]
R1 cmderd;COMODO Internet Security Eradication Driver; C:\WINDOWS\System32\DRIVERS\cmderd.sys [2015-08-05 21720]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\system32\DRIVERS\cmdguard.sys [2015-08-05 827632]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\system32\DRIVERS\cmdhlp.sys [2015-08-05 35056]
R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 31400]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R1 inspect;COMODO Internet Security Firewall Driver; C:\WINDOWS\system32\DRIVERS\inspect.sys [2015-08-05 127232]
R1 truecrypt;truecrypt; C:\WINDOWS\System32\drivers\truecrypt.sys [2014-03-15 231376]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 5U877;@oem31.inf,%5U877.ServiceDesc%;5U877; C:\WINDOWS\system32\DRIVERS\5U877.sys [2012-03-28 216704]
R3 AMPPAL;@oem15.inf,%AMPPAL.SVCDESC%;Virtuální adaptér Intel® Centrino® Wireless Bluetooth® + High Speed; C:\WINDOWS\System32\drivers\AMPPAL.sys [2012-01-09 195584]
R3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2016-03-09 112640]
R3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-02-21 245760]
R3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2016-03-09 84992]
R3 CnxtHdAudService;@oem59.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\WINDOWS\system32\drivers\CHDRT64.sys [2015-09-21 1317096]
R3 dtsoftbus01;@oem9.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\WINDOWS\System32\drivers\dtsoftbus01.sys [2013-09-19 283064]
R3 ElbyCDFL;ElbyCDFL; C:\WINDOWS\System32\Drivers\ElbyCDFL.sys [2007-02-16 40648]
R3 IBMPMDRV;IBMPMDRV; C:\WINDOWS\system32\DRIVERS\ibmpmdrv.sys [2015-08-07 72400]
R3 ibtfltcoex;@oem25.inf,%PROVIDER_NAME%;Intel Corporation; C:\WINDOWS\system32\DRIVERS\ibtfltcoex.sys [2015-09-19 79632]
R3 igfx;igfx; C:\WINDOWS\system32\DRIVERS\igdkmd64.sys [2015-06-01 5384176]
R3 InputFilter_Hid_FlexDef2b;@oem52.inf,%HIDUASServiceDesc%;Siliten HID Devices(FlexDef2b) Driver Service; C:\WINDOWS\System32\drivers\InputFilter_FlexDef2b.sys [2015-01-22 17920]
R3 MBAMProtector;MBAMProtector; \??\C:\WINDOWS\system32\drivers\mbam.sys [2016-03-16 25816]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [2016-03-16 192216]
R3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\WINDOWS\system32\drivers\mwac.sys [2016-03-16 64216]
R3 MEIx64;@oem19.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-17 62784]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2016-02-21 175616]
R3 NETwNe64;___ Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 8 - 64 Bit; C:\WINDOWS\System32\drivers\NETwew01.sys [2015-10-30 3343872]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-03-14 11142984]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-02-17 28032]
R3 nvvad_WaveExtensible;@oem13.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2016-01-31 47760]
R3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2016-03-04 176640]
R3 RSP2STOR;@oem35.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2015-06-05 310528]
R3 rt640x64;@rt640x64.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2015-10-30 589824]
R3 SmbDrvI;SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [2015-08-21 44192]
R3 SynTP;@oem2.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-11-25 636536]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-03-09 954368]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-02-21 117248]
S3 CMUAC;USB Audio Class 1.0 and 2.0 Device Driver; C:\WINDOWS\system32\DRIVERS\CMUAC.sys [2015-09-26 661760]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-01-12 82128]
R2 AGSService;Adobe Genuine Software Integrity Service; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2016-02-19 2020056]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2015-09-08 5542472]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 CxAudMsg;@C:\WINDOWS\system32\CxAudMsg64.exe,-100; C:\WINDOWS\system32\CxAudMsg64.exe [2013-07-25 206552]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-02-21 1164672]
R2 IBMPMSVC;@oem28.inf,%ibm.svcDesc0%;Lenovo PM Service; C:\WINDOWS\system32\ibmpmsvc.exe [2015-08-07 156920]
R2 LENOVO.CAMMUTE;Lenovo Camera Mute; C:\Program Files\Lenovo\Communications Utility\CAMMUTE.exe [2014-06-20 59168]
R2 LENOVO.MICMUTE;Lenovo Microphone Mute; C:\Program Files\LENOVO\HOTKEY\MICMUTE.exe [2012-08-25 127072]
R2 LENOVO.TPKNRSVC;Lenovo Keyboard Noise Reduction; C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe [2014-06-20 72992]
R2 LENOVO.TVTVCAM;Lenovo Virtual Camera Controller; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [2014-06-20 197408]
R2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-16 1135416]
R2 MBAMScheduler;MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [2016-03-16 1513784]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2016-02-21 26624]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-02-21 1880960]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-02-19 2609024]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvvsvc.exe [2015-07-23 937800]
R2 OneSyncSvc_87a3e;Hostitel synchronizace_87a3e; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-11-25 255096]
R2 TeamViewer;TeamViewer 11; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [2016-02-04 6889232]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 TPHKLOAD;Lenovo Hotkey Client Loader; C:\Program Files\LENOVO\HOTKEY\TPHKLOAD.exe [2013-05-15 125432]
R2 TPHKSVC;On Screen Display; C:\Program Files\LENOVO\HOTKEY\TPHKSVC.exe [2012-12-05 125504]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-02-21 6474112]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S2 ImControllerService;System Interface Foundation Service; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2016-01-29 36808]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
S2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 SAService;Conexant SmartAudio service; C:\WINDOWS\system32\SAsrv.exe []
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-10-30 51376]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 cmdvirth;COMODO Virtual Service Manager; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2015-08-06 2265792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe [2015-09-18 290224]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29 144200]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_87a3e;Služba zasílání zpráv_87a3e; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2014-10-11 114288]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_87a3e;Data kontaktů_87a3e; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 PanService;PandoraService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [2013-07-08 1922600]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

altrok
Moderátor
Moderátor
Příspěvky: 7262
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: RSIT havěť

#5 Příspěvek od altrok »

Krasny den Vam preju :bye:


:arrow: Primarne resime temata bez odpovedi, takze ve Vasem pripade to vypada, ze se Vam jiz nektery z kolegu venuje a tema snadno zapadne.


:arrow: V ramci cisteni Vam budou vyprazdneny docasne adresare (vcetne Kose).


:arrow: Dejte logy FRST.txt a Addition.txt - http://forum.viry.cz/viewtopic.php?f=30&t=133101
Pozn. pri druhem a dalsim spusteni FRST je pro vytvoreni logu Addition.txt nutne tuto volbu explicitne zatrhnout pred zacatkem skenu.
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#6 Příspěvek od Max_cz »

FRST.txt 1/4

Kód: Vybrat vše

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by Max_cz (administrator) on MAX_CZ-PC (17-03-2016 19:04:10)
Running from C:\Users\Max_cz\Desktop
Loaded Profiles: Max_cz (Available Profiles: Max_cz & DefaultAppPool)
Platform: Windows 10 Home Version 1511 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Lenovo.) C:\Windows\System32\ibmpmsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\CamMute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\TPKNRSVC.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\micmute.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tphkload.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlk.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\tpnumlkd.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\mkrmsg.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\TPONSCR.exe
(Lenovo Group Limited) C:\Program Files\Lenovo\HOTKEY\shtctky.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
(Synaptics) C:\Program Files\Synaptics\SynTP\SynLenovoHelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Ricoh co.,Ltd.) C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(Piriform Ltd) C:\Windows.old\Program Files\CCleaner\CCleaner64.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(forum.viry.cz) C:\Users\Max_cz\Desktop\FRSTLauncher.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [935104 2014-11-25] (Conexant Systems, Inc.)
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1830616 2014-04-10] (Conexant Systems, Inc.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1427648 2015-08-06] (COMODO)
HKLM\...\Run: [Cm106Sound] => C:\Windows\syswow64\RunDll32.exe C:\Windows\Syswow64\cm106.dll,CMICtrlWnd
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-11-27] (Adobe Systems Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-21] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [RotateImage] => C:\Program Files (x86)\Integrated Camera Driver\X64\RCIMGDIR.exe [55808 2008-10-30] (Ricoh co.,Ltd.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-04-13] (Intel Corporation)
HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-07-20] (Western Digital Technologies, Inc.)
Winlogon\Notify\igfxcui: c:\windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [3212083974] 0x504B03047ECDE67B068374BFB5110000004000003B52047F42E5F13FFC79C52065C1BE89B50CD7B4769F60289BFBD984D14110F2D01270B16FC2706B1EDA5D73993A9F916003041E5B35D296126857F9E7251C73D3EFC09701D8D7ADC4610818404E80E342F284FC326FAFF9639EBA1E04B3742F5A9CFF01382A0C43DD64F0C5C72F17491D19AA604C54BAFD81DAB7660098606BC53B2CCFAFCC763E85AF893E2EC927770A5A8FBD749F1FADC9CAC3E32ED081F17F670C361341DCA6E6AAB22F35F8A01BF20D6F281379604DDF2B2D3AAB0475420EA35140CBD4850B5B37D2E0E582569D37AC0AEBFD63622E501F2BF5152FCF27CAACEFC4626FB241DBDA40EF0B12DD6F0AD67E93DFDC1861004081B9D72C75BB44BE9D1E27106103C35A24C81ABFA9A1F77CED3C0382BB7B0CD5005CFD4D9C12BAA0359AFBEE313FE071AFE8703BD92ABE22A0D51F3044C7410D9D6C7AA0337D9B7BBD1F3442DABD7B34DCF6888C18894965A7AC6702C9711F3905F590405B7002133BE6023C1376BB44873357A9555695625CD61A62343DC8928E685FEAE8E040D066B19FAE8E6B1F52EC94EB23382A36F982A5FE7B913C1707AA98145196E1168940B87181ECC84A3D074875B1AA306314B7D0FD77AC5602E656A4FE5F7D1276767A2614E2DE7E291B7729A58732F442E9C09842E7D8E44EB4B81D4A33BB5A0EE4A734289B6D99E87C21BF0248F522B38F8E69C3229F88BE9B8747500A03FE71AF6356476805E77DA5ACF4597917CD0632C1E257EA8EB53847066E8108E99D0FB556B2BF72BB5BED5792373C6486720619E15B5D9810F5783760949E5343C6DD4877637867BEFD768B439297D7E821CFC4BA3980F1CA2279A2E6A459470C6FF28FA2CA7236E81B6E2A1B5C349BCF4729C24388385F42302C6F8475F44F7BA90A1B7E1E10A48047D41BC1136DC51B40CFC85C09AE83F8BA3B01E359FB0241367E5168F48EFC6AF1EF1DC6B0DF6E69B29323CC1CBE73E39F3069C15AB38087A2FDB508518193F867710C6B378AF2F25A8DDCE72F0D61E19E47877F68B78B3E8AF452B22CC5BEA2AC107474689639D23E2789E4D34FD424BEDA096ED4F091B9CCF2E3D041FD6606795D3A09CD04B5ED2AF5BA71F4A01CAE89A4933FB1E08B129138CED63229F7ED9574131F0C0ECE1C5928ED9D4376DE50DDF379DBFC33DC0EB000B6098DE6F92BCE503ADFC75541BF4A6BEC97B298773EF65B60B177214313FC1508ABE30FDE7B48836D334F61047CF5BFF2093E8F380A7986AD8FFA5AC6A8EDB4392968ACAEEA2B0F2889A80D78B30648B4612E6DF2311CBF0FC50B7CAAF81E3E531A821B2A072D2FD2A9BF12170EA48EE2039A61EC4DC1671BDF2B2817786BF981D04F8CCA7771F08808CC38E04856FA22716B10F175786CD6B2E2AFF3B638F4C411E3C0851232DB04FDCBF6648EBAC7169FB7FC75C9D8AF98133F8DAA18E26BCA983977CE3B322106050FF575C707B8808C8A51DD02758ABF52B1DD5101562D5B93BB2461FFE9DCE06E52E2B27E8488DDB006F2783460F435CDF3CB6D1371A91F65497DE6E9B81D63064AF1E5AB31BE290B80A530DE6B094F5042726BF8AA46CD4652B9CB71F89CDD25CA682E6C9E25023C06FA538CA4F3DBC7738F35C0C0912C9CB16F43C8CFFB97981C0032F0C745974F620339D7CBE4C59ADEA630F92D6E6990532F427E795D4D2F6BB18FC35798B4948CAF7E2864D81ADABF22C1AB59AACD406454BAF9FFF5FFC88A35BDE96672513C1A297BA6E16BA1B7805392373FCBA9A2F3FDDA7D165B57560ADAA570693659196630B6519EE9012B76BF73FDBE807085BE5FDEB9EDC93E574396113A80ED04FCA4F572AE01EB8279A4DC9F902BD5CD206223C98DA8FC6F80EDAD25254B831B176CFCB7B83C74F63D1279EC6C69E208B3DD8B30D279ACA6238820E794D7AFED9DE063B8F9B88AC294D08E650CE9B617F6904821BFC7BE177583A90A88AA450FA2E35F6619AA39CF29632DB166D56361E17D5845C71E43B7B2EA63EADE16377FDFC5D51AB1F31CC78D9C1F31D0816C78A25A8A68BA87070B732D9F315E454DCA738C2370B5019765CAADB6B4E8226E83439487DAFBA93EA941E3B7FCB9029F846CA2D702153AC85B91BB8CB296A29662EA2617AF463DC719588CFB7A4E2E68D165ACF08EA0477376661AA1D5377931FBBFB2673C01F7573D2C8201DE8F82810FC456F633D00CA6281F8E991A75979227D2CEDF7400C9D3022CA75278518FAA2CDC4921EC58C2B1EF1D305ADD4C5DD65572F8934F5FD610B3C9DD0DBA0CABC93D46D489B7FA5E676E6A4ED2A5884D179125B9DBCE16A0D8893FCA9DB16DBDE23927CF5711A9917F5FA99DAB133665CA5648BCB61EC2B0EE013944F619E8D14B77D18B489EEBDCA6A57328B40F2C3B2562EEEBE8D67AA29C9884BE2FC81299EB03D257F1CBD26ECAB2C9BA1C843CDFE266BFFE68FE6D2A621FB08319D4D8C78EF4D32322593FB7F8D31B8B19B6CE0D6F0F23BB677643E385EA4F790CF9C6027D8635E95C3EC8AB6D45CBF86D7F2E90D4CD6604DAD3A7AEC95A9CD4621E8668B6D23559044C318528DE2358561CC518E8F2DB291705B5F28B55F0D4FFB19C0B674C84EA3944F0B3F2DAC4A4424ED634B3C93061AA252B1CF059ACE6BD182252F78B21B4416FF9317B04AE61E96EBD96519FC17C5E7612B61554D407AAFDA3799134C8AF4D3EE71354275C769E200DB6FA418CC1C7F3FACBBDEEE35A09E7922525D3CD8BF905678982FD350C19E2EFAB677CB7E465D307FA45BA289532B05BC1DB528C37A61682A555796E61ABE00771D9E9084DF6E5226405522276C7C4AD732A47FD2D0AD1AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [155280 2016-03-14] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{080a68b5-d193-43d3-8a14-44f4108f1b34}: [DhcpNameServer] 82.163.142.7
Tcpip\..\Interfaces\{0e70f5b1-c164-4e3a-b6bf-d59cffcc0aff}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{a92265ed-e9a0-4a1f-a13a-46e690dec9ba}: [DhcpNameServer] 82.163.142.7
Tcpip\..\Interfaces\{aa9323a2-dcea-480d-bfda-455aa9721669}: [DhcpNameServer] 82.163.142.7
Tcpip\..\Interfaces\{DF4077CB-3235-4844-A0E0-7096542AC60A}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{edaee51b-2b61-4ac6-b136-e332744fb89b}: [DhcpNameServer] 82.163.142.7

Internet Explorer:
==================
HKU\S-1-5-21-529706889-675040250-4031740840-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://us.yahoo.com?fr=fp-comodo
SearchScopes: HKU\S-1-5-21-529706889-675040250-4031740840-1000 -> DefaultScope {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
SearchScopes: HKU\S-1-5-21-529706889-675040250-4031740840-1000 -> {8EEAC88A-079B-4b2c-80C1-7836F79EB40A} URL = hxxp://us.search.yahoo.com/search?p={searchTerms}&fr=chr-comodo
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-18] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-18] (Oracle Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -  No File


Naposledy upravil(a) Max_cz dne 17 bře 2016 19:15, celkem upraveno 1 x.

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#7 Příspěvek od Max_cz »

FRST.txt 2/4

Kód: Vybrat vše

FireFox:
========
FF ProfilePath: C:\Users\Max_cz\AppData\Roaming\Mozilla\Firefox\Profiles\yn5izivf.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-03-01] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-03-01] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @java.com/DTPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll [2015-04-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.45.2 -> C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll [2015-04-18] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2016-01-12] ( Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-04] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
FF user.js: detected! => C:\Users\Max_cz\AppData\Roaming\Mozilla\Firefox\Profiles\yn5izivf.default\user.js [2014-11-17]
FF Extension: No Name - C:\Users\Max_cz\AppData\Roaming\Mozilla\Firefox\Profiles\yn5izivf.default\extensions\iobitascsurfingprotection@iobit.com [not found]
FF Extension: Firebug - C:\Users\Max_cz\AppData\Roaming\Mozilla\Firefox\Profiles\yn5izivf.default\Extensions\firebug@software.joehewitt.com.xpi [2014-10-20] [not signed]

Chrome: 
=======
CHR HomePage: Default -> hxxps://www.seznam.cz/
CHR StartupUrls: Default -> "hxxp://www.seznam.cz/","hxxp://www.google.cz/ig?hl=cs"
CHR Session Restore: Default -> is enabled.
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.758\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.37\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\50.0.2661.37\pdf.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll => No File
CHR Plugin: (CANON iMAGE GATEWAY Album Plugin Utility for IJ) - C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll (CANON INC.)
CHR Plugin: (AdobeAAMDetect) - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll (Adobe Systems)
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll => No File
CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
CHR Profile: C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (SEO Profesional Toolbar) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\adecfhccdknoobplgempjhbojlbpahhn [2015-03-30]
CHR Extension: (Dokumenty Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-08]
CHR Extension: (Disk Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Rozšíření pro webové stránky - WP Screenshot) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckibcdccnfeookdmbahgiakhnjcddpki [2015-02-01]
CHR Extension: (Adblock na Youtube™) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmedhionkhpnakcndndgjdbohmhepckk [2016-03-04]
CHR Extension: (Vyhledávání Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (Dokumenty Google offline) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Google Keep – poznámky a seznamy) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2016-03-15]
CHR Extension: (Přidávání a otevírání aplikací pro Ch...) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhfiojdaegegaeiefilimljmbiegiebd [2015-09-07]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-17]
CHR Extension: (Kontrola e-mailu Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-01-06]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-25]
CHR Extension: (Gmail) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Profile: C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Profile: C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Prezentace Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-01]
CHR Extension: (Dokumenty Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-01]
CHR Extension: (Disk Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-30]
CHR Extension: (Video AdBlock for Chrome) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\bknbnapaddjdnbilpmlacdkjdkjmbjhd [2015-10-30]
CHR Extension: (YouTube) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-30]
CHR Extension: (Vyhledávání Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Tabulky Google) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-03-01]
CHR Extension: (Dokumenty Google offline) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-07]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-03-01]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-07]
CHR Extension: (Gmail) - C:\Users\Max_cz\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-14]
CHR HKU\S-1-5-21-529706889-675040250-4031740840-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Max_cz\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx [2015-09-10]
CHR HKU\S-1-5-21-529706889-675040250-4031740840-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-529706889-675040250-4031740840-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2020056 2016-02-19] (Adobe Systems, Incorporated)
R2 cmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5542472 2015-09-08] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265792 2015-08-06] (COMODO)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-21] (NVIDIA Corporation)
S2 ImControllerService; C:\Program Files\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [36808 2016-01-29] (Lenovo Group Limited)
R2 LENOVO.TVTVCAM; C:\Program Files\Lenovo\Communications Utility\vcamsvc.exe [197408 2014-06-20] (Lenovo Group Limited)
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2016-03-16] (Malwarebytes)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2016-03-16] (Malwarebytes)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-21] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-21] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-19] (NVIDIA Corporation)
S4 PanService; C:\Program Files (x86)\PANDORA.TV\PanService\KMPService.exe [1922600 2013-07-08] (Pandora.TV)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [255096 2015-11-25] (Synaptics Incorporated)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2016-02-04] (TeamViewer GmbH)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-10-28] (Western Digital Technologies, Inc.)
R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [307576 2015-10-28] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [21720 2015-08-05] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [827632 2015-08-05] (COMODO)
R1 cmdHlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [35056 2015-08-05] (COMODO)
S3 CMUAC; C:\Windows\system32\DRIVERS\CMUAC.sys [661760 2015-09-26] (C-MEDIA)
R3 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2013-09-19] (Disc Soft Ltd)
R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 ElbyCDFL; C:\Windows\SysWOW64\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.)
R3 InputFilter_Hid_FlexDef2b; C:\Windows\System32\drivers\InputFilter_FlexDef2b.sys [17920 2015-01-22] (Siliten)
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [127232 2015-08-05] (COMODO)
S3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2016-03-16] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2016-03-16] (Malwarebytes Corporation)
R3 NETwNe64; C:\Windows\System32\drivers\NETwew01.sys [3343872 2015-10-30] (Intel Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2016-01-31] (NVIDIA Corporation)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44192 2015-08-21] (Synaptics Incorporated)
S3 USBMULCD; C:\Windows\system32\drivers\CM10664.sys [1310720 2015-09-26] (C-Media Electronics Inc)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)



Naposledy upravil(a) Max_cz dne 17 bře 2016 19:14, celkem upraveno 1 x.

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#8 Příspěvek od Max_cz »

FRST.txt 3/4

Kód: Vybrat vše

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-17 19:04 - 2016-03-17 19:05 - 00037520 _____ C:\Users\Max_cz\Desktop\FRST.txt
2016-03-17 19:04 - 2016-03-17 19:04 - 00000000 ____D C:\FRST
2016-03-17 19:03 - 2016-03-17 19:03 - 00112640 _____ (forum.viry.cz) C:\Users\Max_cz\Desktop\FRSTLauncher.exe
2016-03-17 18:59 - 2016-03-17 18:59 - 02374144 _____ (Farbar) C:\Users\Max_cz\Desktop\FRST64.exe
2016-03-17 00:08 - 2016-03-17 00:08 - 00127335 _____ C:\Users\Max_cz\Desktop\FAKTURA_72016.pdf
2016-03-16 22:44 - 2016-03-17 18:54 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-03-16 22:44 - 2016-03-16 22:46 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2016-03-16 22:44 - 2016-03-16 22:46 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2016-03-16 22:44 - 2016-03-16 22:46 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2016-03-16 22:44 - 2016-03-16 22:46 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-16 22:44 - 2016-03-16 22:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-16 22:44 - 2016-03-16 22:46 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-16 22:44 - 2016-03-16 22:44 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-16 22:43 - 2016-03-16 22:43 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Max_cz\Desktop\mbam-setup-2.1.4.1018.exe
2016-03-16 22:38 - 2016-03-16 22:39 - 01222144 _____ C:\Users\Max_cz\Desktop\RSITx64.exe
2016-03-16 22:32 - 2016-03-16 22:32 - 00003884 _____ C:\WINDOWS\System32\Tasks\{CD3808AF-CB98-A8A7-E796-21741D041C14}
2016-03-16 22:32 - 2016-03-16 22:32 - 00000000 ____D C:\ProgramData\238a5536
2016-03-16 16:22 - 2016-03-16 16:22 - 00000000 ____D C:\WINDOWS\SysWOW64\NV
2016-03-16 16:22 - 2016-03-16 16:22 - 00000000 ____D C:\WINDOWS\system32\NV
2016-03-14 16:32 - 2016-03-14 16:35 - 00000000 ____D C:\Users\Max_cz\Downloads\Vikings.S04E04.HDTV.XviD-FUM[ettv]
2016-03-14 16:21 - 2016-03-14 16:21 - 00000000 ____D C:\WINDOWS\LastGood
2016-03-14 16:20 - 2016-03-14 16:21 - 10547128 _____ C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-14 16:20 - 2016-03-14 16:21 - 08657936 _____ C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2016-03-14 16:20 - 2016-03-14 16:21 - 01922496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-14 16:20 - 2016-03-14 16:21 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-14 16:20 - 2016-03-14 16:21 - 00678704 _____ C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-14 16:20 - 2016-03-14 16:21 - 00571912 _____ C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2016-03-14 16:20 - 2016-03-14 15:45 - 00031376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2016-03-14 16:20 - 2016-03-08 11:27 - 00000139 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2016-03-14 16:20 - 2016-03-08 11:27 - 00000139 _____ C:\WINDOWS\system32\nv-vk64.json
2016-03-14 15:43 - 2016-03-14 15:43 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2016-03-11 00:16 - 2016-03-11 00:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2016-03-11 00:16 - 2016-03-11 00:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
2016-03-11 00:16 - 2016-03-11 00:16 - 00000000 ____D C:\Program Files\Speccy
2016-03-11 00:16 - 2016-03-11 00:16 - 00000000 ____D C:\Program Files\Defraggler
2016-03-11 00:15 - 2016-03-11 00:15 - 05111240 _____ (Piriform Ltd) C:\Users\Max_cz\Downloads\spsetup129.exe
2016-03-11 00:15 - 2016-03-11 00:15 - 04527736 _____ (Piriform Ltd) C:\Users\Max_cz\Downloads\dfsetup220.exe
2016-03-11 00:15 - 2016-03-11 00:15 - 00000000 _____ C:\Users\Max_cz\Downloads\C818.tmp
2016-03-10 22:42 - 2016-03-10 22:42 - 07122631 _____ C:\Users\Max_cz\Desktop\wordpress-4.1-cs_CZ.zip
2016-03-10 22:42 - 2015-01-18 14:57 - 00000000 ____D C:\Users\Max_cz\Desktop\wordpress
2016-03-10 21:33 - 2016-03-10 21:34 - 00000000 ____D C:\Users\Max_cz\Desktop\themes jane morris
2016-03-10 21:01 - 2016-03-10 13:02 - 98471526 _____ C:\Users\Max_cz\Desktop\01_home.psd
2016-03-10 21:00 - 2016-03-10 21:33 - 00000000 ____D C:\Users\Max_cz\Desktop\jane morris template
2016-03-10 20:57 - 2016-03-10 20:57 - 06568344 _____ (Tim Kosse) C:\Users\Max_cz\Downloads\FileZilla_3.16.0_win64-setup.exe
2016-03-10 20:03 - 2016-03-10 20:04 - 168736962 _____ C:\Users\Max_cz\Desktop\template_53917_jRBty7okCRi862kQR62Z.zip
2016-03-09 20:20 - 2016-03-09 20:20 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-03-09 20:20 - 2016-03-09 20:20 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-03-09 20:20 - 2016-03-09 20:20 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-03-09 20:20 - 2016-03-09 20:20 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2016-03-09 20:20 - 2016-03-09 20:20 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-03-09 20:19 - 2016-03-09 20:19 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-03-09 20:19 - 2016-03-09 20:19 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-03-09 20:19 - 2016-03-09 20:19 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
2016-03-09 20:19 - 2016-03-09 20:19 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
2016-03-09 20:19 - 2016-03-09 20:19 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-09 20:19 - 2016-03-09 20:19 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
2016-03-09 20:18 - 2016-03-09 20:19 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-03-09 20:18 - 2016-03-09 20:18 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2016-03-09 20:18 - 2016-03-09 20:18 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-03-09 20:18 - 2016-03-09 20:18 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
2016-03-09 20:18 - 2016-03-09 20:18 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
2016-03-04 20:03 - 2016-03-04 20:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HD Tune
2016-03-04 20:03 - 2016-03-04 20:03 - 00000000 ____D C:\Program Files (x86)\HD Tune
2016-03-04 19:21 - 2016-03-04 19:21 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2016-03-04 19:21 - 2016-03-04 19:21 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2016-03-04 19:21 - 2016-03-04 19:21 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-03-04 19:20 - 2016-03-04 19:20 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-03-04 19:20 - 2016-03-04 19:20 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2016-03-04 19:20 - 2016-03-04 19:20 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2016-03-04 19:20 - 2016-03-04 19:20 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2016-03-04 19:20 - 2016-03-04 19:20 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2016-03-04 19:20 - 2016-03-04 19:20 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rfcomm.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2016-03-04 19:20 - 2016-03-04 19:20 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
2016-03-04 19:20 - 2016-03-04 19:20 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
2016-03-04 19:20 - 2016-03-04 19:20 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
2016-02-29 19:14 - 2016-02-29 19:14 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2016-02-28 19:34 - 2016-02-28 19:34 - 00002884 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2016-02-25 23:58 - 2016-02-25 23:58 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2016-02-21 10:59 - 2016-03-14 15:44 - 00112784 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2016-02-21 10:59 - 2016-03-14 15:44 - 00105288 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2016-02-21 10:57 - 2016-02-21 10:58 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436191.dll
2016-02-21 10:57 - 2016-02-21 10:58 - 01573432 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436191.dll
2016-02-21 10:53 - 2016-02-21 10:53 - 00000000 ____D C:\Program Files\Western Digital
2016-02-21 10:50 - 2016-02-21 10:50 - 00000000 ____D C:\Users\Max_cz\AppData\Local\NVIDIA Corporation
2016-02-21 10:49 - 2016-02-21 10:49 - 00002429 _____ C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-02-21 10:49 - 2016-02-21 10:49 - 00000000 ___RD C:\Users\Max_cz\OneDrive
2016-02-21 10:45 - 2016-02-21 10:45 - 00000000 ____D C:\Users\Max_cz\AppData\Local\ActiveSync
2016-02-21 10:42 - 2016-02-21 10:42 - 00000020 ___SH C:\Users\Max_cz\ntuser.ini
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Šablony
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Poslední
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Okolní síť
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Dokumenty
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\Data aplikací
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2016-02-21 04:41 - 2016-02-21 04:41 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2016-02-21 04:35 - 2016-03-16 23:23 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-02-21 04:23 - 2016-02-21 04:23 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2016-02-21 04:23 - 2016-02-21 04:23 - 00000000 ____D C:\Users\Default\AppData\Roaming\Media Center Programs
2016-02-21 04:23 - 2016-02-21 04:23 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2016-02-21 04:23 - 2016-02-21 04:23 - 00000000 ____D C:\Users\Default\AppData\Local\Google
2016-02-21 04:23 - 2016-02-21 04:23 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Media Center Programs
2016-02-21 04:23 - 2016-02-21 04:23 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2016-02-21 04:23 - 2016-02-21 04:23 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
2016-02-21 04:16 - 2016-02-21 04:16 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2016-02-21 04:16 - 2016-02-21 04:16 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2016-02-21 04:13 - 2016-03-08 06:45 - 00000000 ____D C:\Users\Max_cz
2016-02-21 04:13 - 2016-02-29 19:14 - 00000000 ____D C:\Users\DefaultAppPool
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Šablony
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Soubory cookie
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Poslední
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Okolní tiskárny
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Okolní síť
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Nabídka Start
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Dokumenty
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Documents\Obrázky
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Documents\Hudba
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Documents\Filmy
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\Data aplikací
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\Max_cz\AppData\Local\Data aplikací
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Šablony
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Soubory cookie
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Poslední
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Okolní tiskárny
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Okolní síť
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Nabídka Start
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Dokumenty
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Obrázky
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Hudba
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Documents\Filmy
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\Data aplikací
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2016-02-21 04:13 - 2016-02-21 04:13 - 00000000 _SHDL C:\Users\DefaultAppPool\AppData\Local\Data aplikací
2016-02-21 04:12 - 2016-03-16 23:27 - 02042548 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-02-21 04:12 - 2016-02-21 04:12 - 01949904 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2016-02-21 04:10 - 2016-02-21 04:10 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_tcwbf_01_09_00.Wdf
2016-02-21 04:10 - 2016-02-21 04:10 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf
2016-02-21 04:09 - 2016-03-16 16:21 - 00000000 ____D C:\ProgramData\NVIDIA
2016-02-21 04:09 - 2016-03-15 17:23 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-02-21 04:09 - 2016-03-14 16:27 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-02-21 04:09 - 2016-02-21 04:16 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-02-21 04:09 - 2016-02-21 04:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Conexant
2016-02-21 04:09 - 2016-02-21 04:09 - 00000000 ____D C:\Program Files\AuthenTec
2016-02-21 04:09 - 2015-07-23 02:10 - 06873928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2016-02-21 04:09 - 2015-07-23 02:10 - 03493008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2016-02-21 04:09 - 2015-07-23 02:10 - 02558608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2016-02-21 04:09 - 2015-07-23 02:10 - 01059984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2016-02-21 04:09 - 2015-07-23 02:10 - 00937800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2016-02-21 04:09 - 2015-07-23 02:10 - 00579912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\oemdspif.dll
2016-02-21 04:09 - 2015-07-23 02:10 - 00385168 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2016-02-21 04:09 - 2015-07-23 02:10 - 00074896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2016-02-21 04:09 - 2015-07-23 02:10 - 00062608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2016-02-21 04:09 - 2015-07-22 05:29 - 05121613 _____ C:\WINDOWS\system32\nvcoproc.bin
2016-02-21 04:08 - 2016-02-21 04:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2016-02-21 04:08 - 2016-02-21 04:08 - 00000000 ____D C:\Program Files\Dolby Digital Plus
2016-02-21 04:08 - 2015-04-18 10:26 - 00427224 _____ (Conexant Systems, Inc.) C:\WINDOWS\SysWOW64\SASrv.exe
2016-02-21 04:08 - 2014-11-26 11:01 - 00004664 _____ C:\WINDOWS\system32\Drivers\CxSfPt.dat
2016-02-21 04:08 - 2013-07-25 14:39 - 00206552 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxAudMsg64.exe
2016-02-21 04:08 - 2012-01-12 13:16 - 00002060 _____ C:\WINDOWS\system32\Drivers\SamSfPa.dat
2016-02-21 04:07 - 2016-02-21 04:16 - 00000000 ____D C:\ProgramData\Conexant
2016-02-21 04:07 - 2016-02-21 04:08 - 00000000 ____D C:\Program Files\CONEXANT
2016-02-21 04:07 - 2016-02-21 04:07 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2016-02-21 04:07 - 2016-02-21 04:07 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01011.Wdf
2016-02-21 04:07 - 2016-02-21 04:07 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_Smb_driver_Intel_01011.Wdf
2016-02-21 04:07 - 2016-02-21 04:07 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2016-02-21 04:07 - 2016-02-21 04:07 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2016-02-21 04:07 - 2015-10-30 08:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2016-02-21 04:06 - 2016-02-21 04:06 - 00000000 ____D C:\Program Files\Synaptics
2016-02-21 04:03 - 2016-03-10 19:38 - 04976384 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-02-21 04:01 - 2016-02-21 06:00 - 00000000 ___DC C:\WINDOWS\Panther
2016-02-21 03:57 - 2016-02-21 03:57 - 00000000 ____D C:\Windows.old
2016-02-21 03:56 - 2016-02-21 03:56 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2016-02-21 03:56 - 2016-02-21 03:56 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2016-02-21 03:56 - 2016-02-21 03:56 - 02127360 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-02-21 03:56 - 2016-02-21 03:56 - 02050048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-02-21 03:56 - 2016-02-21 03:56 - 01750440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcMon.exe
2016-02-21 03:56 - 2016-02-21 03:56 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00477696 _____ (Microsoft Corporation) C:\WINDOWS\system32\srcore.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00405568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00343552 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2016-02-21 03:56 - 2016-02-21 03:56 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
2016-02-21 03:56 - 2016-02-21 03:56 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
2016-02-21 03:56 - 2016-02-21 03:56 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-02-21 03:56 - 2016-02-21 03:56 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2016-02-21 03:56 - 2016-02-21 03:56 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
2016-02-21 03:56 - 2016-02-21 03:56 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2016-02-21 03:56 - 2016-02-21 03:56 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 05503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 04502352 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 04064320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02606824 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02057216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01824264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01415200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01270072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01174008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01089880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
2016-02-21 03:55 - 2016-02-21 03:55 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00884736 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00851456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00820704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00799744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00794112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00733184 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcli.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00653312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00613888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00610816 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.UX.EapRequestHandler.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00535040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcli.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00475648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DDDS.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00440152 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00431240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00350720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00304752 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00299008 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00260608 _____ C:\WINDOWS\system32\MTFServer.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00258048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iassam.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00235008 _____ C:\WINDOWS\system32\MTF.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iassam.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00202472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimCfg.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00162816 _____ C:\WINDOWS\SysWOW64\MTF.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msorcl32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\SimAuth.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimCfg.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\FilterDS.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
2016-02-21 03:55 - 2016-02-21 03:55 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mtxoci.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winbio.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SimAuth.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
2016-02-21 03:55 - 2016-02-21 03:55 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxoci.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\hlink.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hlink.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttpcom.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winbio.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00085320 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpenWith.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00081112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpenWith.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttpcom.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00079360 _____ (Microsoft Corporation) C:\WINDOWS\system32\cfgbkend.dll

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#9 Příspěvek od Max_cz »

FRST.txt 4/4

Kód: Vybrat vše

2016-02-21 03:55 - 2016-02-21 03:55 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cfgbkend.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcaui.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pcaui.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ztrace_maps.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2016-02-21 03:55 - 2016-02-21 03:55 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ztrace_maps.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasautou.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasautou.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasadhlp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2016-02-21 03:55 - 2016-02-21 03:55 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sscoreext.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00013824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastlsext.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasadhlp.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastlsext.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2016-02-21 03:55 - 2016-02-21 03:55 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2016-02-21 03:51 - 2015-10-29 19:43 - 05739520 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2016-02-21 03:51 - 2015-10-29 19:43 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2016-02-21 03:51 - 2015-10-29 19:41 - 02629632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2016-02-21 03:51 - 2015-10-29 19:25 - 06359040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2016-02-21 03:51 - 2015-10-29 19:24 - 04847616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2016-02-21 03:50 - 2016-02-21 03:50 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\WINDOWS\system32\msmq
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\Program Files\Reference Assemblies
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\Program Files\MSBuild
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\Program Files (x86)\MSBuild
2016-02-21 03:47 - 2016-02-21 03:47 - 00000000 ____D C:\inetpub
2016-02-21 03:46 - 2015-10-23 17:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2016-02-21 03:46 - 2015-10-23 17:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-02-21 03:46 - 2015-10-23 17:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2016-02-21 03:46 - 2015-10-23 17:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-02-21 03:46 - 2015-10-23 17:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2016-02-21 03:46 - 2015-10-23 17:45 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-03-17 19:01 - 2015-10-30 08:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-17 19:01 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-03-17 18:54 - 2014-10-30 18:41 - 00000976 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-17 06:29 - 2013-07-28 20:23 - 00000000 ____D C:\Users\Max_cz\AppData\Local\Adobe
2016-03-17 06:28 - 2014-10-30 18:41 - 00000980 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-16 23:43 - 2013-12-09 19:34 - 00000000 ____D C:\Program Files\trend micro
2016-03-16 23:27 - 2015-10-30 19:31 - 00846274 _____ C:\WINDOWS\system32\perfh005.dat
2016-03-16 23:27 - 2015-10-30 19:31 - 00193772 _____ C:\WINDOWS\system32\perfc005.dat
2016-03-16 23:27 - 2015-10-30 08:21 - 00000000 ____D C:\WINDOWS\INF
2016-03-16 23:26 - 2016-01-31 15:42 - 00000270 __RSH C:\ProgramData\ntuser.pol
2016-03-16 23:24 - 2014-12-07 22:39 - 00008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat
2016-03-16 23:22 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2016-03-16 23:22 - 2015-10-30 07:28 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2016-03-16 23:21 - 2014-07-11 15:24 - 00000000 ____D C:\ProgramData\YTD Video Downloader
2016-03-16 21:30 - 2015-09-04 22:31 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-16 20:53 - 2015-08-16 08:53 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\PTGui
2016-03-14 20:01 - 2016-01-31 15:49 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\vlc
2016-03-14 16:29 - 2014-09-08 18:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2016-03-14 16:29 - 2013-08-01 19:47 - 00000000 ____D C:\Users\Max_cz\AppData\Local\CrashDumps
2016-03-14 15:45 - 2016-01-31 16:40 - 01165192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 18376584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 16160440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 16011680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 15754192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 13274904 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 11142984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2016-03-14 15:45 - 2015-07-23 04:02 - 03351864 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 02963208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 02360976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 02164040 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 01061008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 01053000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 00991152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 00983368 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 00976528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 00150832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2016-03-14 15:45 - 2015-07-23 04:02 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2016-03-14 15:44 - 2016-01-31 16:26 - 00176904 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
2016-03-14 15:44 - 2015-07-23 04:02 - 37749064 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2016-03-14 15:44 - 2015-07-23 04:02 - 30518928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2016-03-14 15:44 - 2015-07-23 04:02 - 22973584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2016-03-14 15:44 - 2015-07-23 04:02 - 14511608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2016-03-14 15:44 - 2015-07-23 04:02 - 12973680 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2016-03-14 15:44 - 2015-07-23 04:02 - 11843384 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2016-03-14 15:44 - 2015-07-23 04:02 - 00155280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
2016-03-11 00:22 - 2013-07-27 20:04 - 00000000 ____D C:\Users\Max_cz\Desktop\Práce
2016-03-11 00:12 - 2015-08-16 08:42 - 00000000 ___RD C:\Users\Max_cz\Documents\texty
2016-03-11 00:12 - 2013-08-01 20:02 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\FileZilla
2016-03-10 23:07 - 2015-10-30 08:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-03-10 21:17 - 2013-11-02 10:09 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2016-03-10 21:17 - 2013-08-01 20:01 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2016-03-10 19:50 - 2015-10-30 08:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-03-10 19:50 - 2015-10-30 08:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-09 23:17 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-09 23:17 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-09 23:17 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-09 23:17 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-09 20:44 - 2013-07-31 17:28 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-03-09 20:36 - 2013-07-28 22:06 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-03-09 20:12 - 2015-11-10 16:35 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-03-05 20:30 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\rescache
2016-03-05 19:33 - 2015-09-10 06:43 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-05 01:28 - 2015-10-30 19:35 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-05 01:28 - 2015-10-30 08:24 - 00000000 __RSD C:\WINDOWS\Media
2016-03-05 01:28 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-03-05 01:28 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2016-03-05 01:28 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-03-05 01:28 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-03-05 01:28 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2016-03-05 01:28 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2016-03-04 20:11 - 2013-09-17 21:24 - 00000000 ____D C:\Users\Max_cz\AppData\Local\ElevatedDiagnostics
2016-03-04 20:03 - 2015-01-04 21:54 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\uTorrent
2016-02-25 22:38 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\appcompat
2016-02-21 11:04 - 2015-09-19 22:35 - 00000000 ____D C:\Users\Max_cz\AppData\Local\Packages
2016-02-21 11:02 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
2016-02-21 10:55 - 2014-08-05 17:35 - 00000000 ____D C:\ProgramData\Package Cache
2016-02-21 10:53 - 2014-12-07 22:20 - 00000000 ____D C:\Program Files\Common Files\Western Digital
2016-02-21 10:53 - 2014-12-07 22:20 - 00000000 ____D C:\Program Files (x86)\Western Digital
2016-02-21 10:53 - 2014-07-11 17:47 - 00000000 ____D C:\ProgramData\Western Digital
2016-02-21 10:50 - 2016-01-31 16:29 - 00000000 ____D C:\Users\Max_cz\AppData\Local\NVIDIA
2016-02-21 10:44 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
2016-02-21 10:44 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\MiracastView
2016-02-21 10:43 - 2015-10-30 08:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2016-02-21 04:41 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Windows NT
2016-02-21 04:41 - 2015-10-30 07:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2016-02-21 04:40 - 2015-08-06 23:51 - 00027327 _____ C:\WINDOWS\diagwrn.xml
2016-02-21 04:40 - 2015-08-06 23:51 - 00026673 _____ C:\WINDOWS\diagerr.xml
2016-02-21 04:38 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2016-02-21 04:38 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Registration
2016-02-21 04:36 - 2015-09-19 22:29 - 00023020 _____ C:\WINDOWS\system32\emptyregdb.dat
2016-02-21 04:36 - 2015-06-23 22:48 - 00002954 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-02-21 04:36 - 2015-03-14 21:56 - 00002762 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-Max_cz-PC-Max_cz
2016-02-21 04:36 - 2014-11-12 21:02 - 00003358 _____ C:\WINDOWS\System32\Tasks\LaunchSignup
2016-02-21 04:36 - 2014-10-30 18:41 - 00003492 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-02-21 04:36 - 2014-10-30 18:41 - 00003268 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-02-21 04:35 - 2013-07-31 13:48 - 00002246 _____ C:\WINDOWS\System32\Tasks\Synaptics TouchPad Enhancements
2016-02-21 04:34 - 2015-10-30 08:24 - 00000000 __RHD C:\Users\Public\Libraries
2016-02-21 04:26 - 2016-01-31 19:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2016-02-21 04:26 - 2016-01-31 17:05 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Handbrake
2016-02-21 04:26 - 2016-01-31 16:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-02-21 04:26 - 2016-01-31 15:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-02-21 04:26 - 2015-12-22 13:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2016-02-21 04:26 - 2015-12-17 19:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RescuePRO Deluxe
2016-02-21 04:26 - 2015-12-13 16:54 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Total Commander
2016-02-21 04:26 - 2015-11-27 21:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.0
2016-02-21 04:26 - 2015-09-07 21:40 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aplikace Chrome
2016-02-21 04:26 - 2015-08-30 09:44 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\cURL
2016-02-21 04:26 - 2015-08-16 08:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PTGui
2016-02-21 04:26 - 2015-07-26 19:47 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kolor Autopano Giga 3.0
2016-02-21 04:26 - 2015-04-08 20:55 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitLord
2016-02-21 04:26 - 2015-03-28 19:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-02-21 04:26 - 2015-02-02 16:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Syncrosoft
2016-02-21 04:26 - 2014-11-07 17:26 - 00000000 ____D C:\WINDOWS\system32\STRING
2016-02-21 04:26 - 2014-09-21 12:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2016-02-21 04:26 - 2014-07-11 15:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader
2016-02-21 04:26 - 2013-10-29 19:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ulož.to File Manager
2016-02-21 04:26 - 2013-10-27 04:36 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
2016-02-21 04:26 - 2013-10-26 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
2016-02-21 04:26 - 2013-10-26 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Blue Ripple Sound
2016-02-21 04:26 - 2013-09-19 15:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DAEMON Tools Lite
2016-02-21 04:26 - 2013-08-21 18:42 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2016-02-21 04:26 - 2013-08-21 18:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe
2016-02-21 04:26 - 2013-08-15 20:33 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-02-21 04:26 - 2013-08-15 20:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-02-21 04:26 - 2013-08-10 08:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSPad editor
2016-02-21 04:26 - 2013-08-01 20:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QIP 2012
2016-02-21 04:26 - 2013-08-01 20:04 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\uTorrent
2016-02-21 04:26 - 2013-07-31 16:34 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The KMPlayer
2016-02-21 04:26 - 2013-07-28 22:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-02-21 04:26 - 2013-07-27 19:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProFact 3.0
2016-02-21 04:26 - 2009-07-14 06:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2016-02-21 04:23 - 2015-07-10 10:47 - 00000000 ____D C:\Users\Default.migrated
2016-02-21 04:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2016-02-21 04:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2016-02-21 04:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\spool
2016-02-21 04:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-02-21 04:19 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\IME
2016-02-21 04:19 - 2013-10-26 16:01 - 00000000 ____D C:\WINDOWS\SysWOW64\xlive
2016-02-21 04:19 - 2013-07-27 18:59 - 00000000 ___HD C:\WINDOWS\system32\WLANProfiles
2016-02-21 04:17 - 2015-10-30 19:31 - 00000000 ____D C:\WINDOWS\OCR
2016-02-21 04:17 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\System
2016-02-21 04:17 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\schemas
2016-02-21 04:17 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-02-21 04:17 - 2014-11-07 17:26 - 00000000 ___HD C:\WINDOWS\system32\CanonIJ Uninstaller Information
2016-02-21 04:16 - 2015-10-30 08:24 - 00000000 __SHD C:\Program Files\Windows Sidebar
2016-02-21 04:16 - 2015-10-30 08:24 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2016-02-21 04:16 - 2015-10-30 08:24 - 00000000 ____D C:\ProgramData\USOPrivate
2016-02-21 04:16 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\System
2016-02-21 04:16 - 2015-10-30 08:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2016-02-21 04:16 - 2014-12-07 22:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital
2016-02-21 04:16 - 2014-11-07 17:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG4200 series
2016-02-21 04:16 - 2014-02-23 14:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ashampoo
2016-02-21 04:16 - 2013-09-19 15:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SlySoft
2016-02-21 04:16 - 2013-08-29 13:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2016-02-21 04:16 - 2013-07-31 17:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
2016-02-21 04:16 - 2013-07-31 16:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PANDORATV
2016-02-21 04:16 - 2011-04-12 09:45 - 00000000 ___RD C:\Users\Public\Recorded TV
2016-02-21 04:16 - 2009-07-14 06:32 - 00000000 ____D C:\Program Files\Microsoft Games
2016-02-21 04:15 - 2015-12-22 13:55 - 00000000 ____D C:\Users\Max_cz\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2016-02-21 04:15 - 2009-07-14 04:20 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2016-02-21 04:12 - 2015-10-30 07:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2016-02-21 04:09 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Help
2016-02-21 04:03 - 2015-10-30 19:41 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2016-02-21 04:01 - 2015-10-30 08:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2016-02-21 03:56 - 2015-10-30 08:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2016-02-21 03:56 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-02-21 03:56 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\Provisioning
2016-02-21 03:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2016-02-21 03:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2016-02-21 03:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\MUI
2016-02-21 03:47 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2016-02-21 03:47 - 2015-10-30 08:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2016-02-21 03:47 - 2015-10-30 08:19 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2016-02-21 03:47 - 2015-10-30 08:19 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2016-02-21 03:47 - 2015-10-30 08:19 - 00051200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2016-02-21 03:47 - 2015-10-30 08:19 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2016-02-21 03:47 - 2015-10-30 08:19 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2016-02-21 03:47 - 2015-10-30 08:19 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2016-02-21 03:47 - 2015-10-30 08:18 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2016-02-21 03:47 - 2015-10-30 08:18 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2016-02-21 03:47 - 2015-10-30 08:18 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2016-02-21 03:47 - 2015-10-30 08:18 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2016-02-21 03:47 - 2015-10-30 08:18 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2016-02-21 03:47 - 2015-10-30 08:18 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2016-02-21 03:47 - 2015-10-30 08:18 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2016-02-21 03:47 - 2015-10-30 08:18 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2016-02-21 03:47 - 2015-10-30 08:18 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2016-02-21 03:47 - 2015-10-30 08:18 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2016-02-21 03:30 - 2015-10-30 20:11 - 00000000 ___HD C:\$WINDOWS.~BT
2016-02-20 11:33 - 2015-10-19 20:21 - 00000000 ____D C:\Users\Max_cz\AppData\Local\Lenovo
2016-02-20 11:33 - 2015-09-30 21:22 - 00000000 ____D C:\ProgramData\Lenovo
2016-02-17 07:40 - 2016-01-31 16:29 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2016-02-17 07:40 - 2016-01-31 16:29 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2016-02-17 07:40 - 2016-01-31 16:29 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2016-02-17 07:40 - 2016-01-31 16:29 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2016-02-17 07:40 - 2015-12-01 00:05 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll

==================== Files in the root of some directories =======

2015-09-19 23:09 - 2015-09-19 23:09 - 0000000 _____ () C:\Program Files\Microsoft Security Client
2013-08-21 19:09 - 2015-02-19 19:30 - 0000132 _____ () C:\Users\Max_cz\AppData\Roaming\Adobe Formát PNG CS5 – předvolby
2015-01-26 20:26 - 2015-03-10 21:38 - 0000132 _____ () C:\Users\Max_cz\AppData\Roaming\Adobe Formát PNG CS6 – předvolby
2013-08-23 19:10 - 2013-08-23 19:56 - 0002359 _____ () C:\Users\Max_cz\AppData\Roaming\screwd
2014-07-17 19:47 - 2014-07-17 19:47 - 0001480 _____ () C:\Users\Max_cz\AppData\Local\Adobe Uložit pro web 12.0 Prefs
2014-07-23 16:59 - 2014-07-23 17:07 - 0001480 _____ () C:\Users\Max_cz\AppData\Local\Adobe Uložit pro web 13.0 Prefs
2015-09-20 19:42 - 2015-09-20 19:42 - 0007597 _____ () C:\Users\Max_cz\AppData\Local\Resmon.ResmonCfg
2013-09-19 15:04 - 2013-09-19 15:15 - 0000041 ___SH () C:\ProgramData\.zreglib
2016-02-21 04:07 - 2016-02-21 04:07 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\BocaInstance.job => c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}\4501685520917765081b.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: COMODO Firewall (Disabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)

  
***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Max_cz\Desktop" je 676 MB.
 
 
***** Startup Programs *****
 
 
***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    DisableNotifications    REG_DWORD    0x0
    EnableFirewall    REG_DWORD    0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
    DisableNotifications    REG_DWORD    0x0
    EnableFirewall    REG_DWORD    0x1
    DoNotAllowExceptions    REG_DWORD    0x0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Windows\\SysWOW64\\msiexec.exe"="C:\\Windows\\SysWOW64\\msiexec.exe:*:Generic Host Process"
"C:\\Windows\\SysWOW64\\svchost.exe"="C:\\Windows\\SysWOW64\\svchost.exe:*:Generic Host Process"
"C:\\Users\\Max_cz\\AppData\\Roaming\\ZQPV2L7C2K.exe"="C:\\Users\\Max_cz\\AppData\\Roaming\\ZQPV2L7C2K.exe:*:Enabled:Windows Messanger"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
 
***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

 
==================== End Of Log ==============================

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#10 Příspěvek od Max_cz »

Addition.txt

Kód: Vybrat vše

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Max_cz (2016-03-17 19:06:08)
Running from C:\Users\Max_cz\Desktop
Windows 10 Home Version 1511 (X64) (2016-02-21 03:42:19)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-529706889-675040250-4031740840-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-529706889-675040250-4031740840-503 - Limited - Disabled)
Guest (S-1-5-21-529706889-675040250-4031740840-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-529706889-675040250-4031740840-1007 - Limited - Enabled)
Max_cz (S-1-5-21-529706889-675040250-4031740840-1000 - Administrator - Enabled) => C:\Users\Max_cz

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: COMODO Firewall (Disabled) {CA6681B7-87D1-B25B-86E8-21EB720D8B8E}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.010.20060 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Adobe Photoshop CC 2014 (HKLM-x32\...\{D7A4F897-B20A-42D0-862D-CB5F6DB7391D}) (Version: 15.2.2 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.7 64-bit (HKLM\...\{1B77B02E-17E4-4B6D-B8A1-74B29AF3D8DD}) (Version: 5.7.0 - Adobe Systems Incorporated)
Aktualizace NVIDIA 2.10.2.40 (Version: 2.10.2.40 - NVIDIA Corporation) Hidden
Ashampoo Burning Studio FREE v.1.12.0 (HKLM-x32\...\{91B33C97-91F8-FFB3-581B-BC952C901685}_is1) (Version: 1.12.0 - Ashampoo GmbH & Co. KG)
BitLord 2.4 (HKLM-x32\...\BitLord) (Version: 2.4.1-291 - House of Life)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version:  - ‪Canon Inc.‬)
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version:  - ‪Canon Inc.‬)
Canon MG4200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG4200_series) (Version: 1.02 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.0.1 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
CloneCD (HKLM-x32\...\CloneCD) (Version:  - SlySoft)
COMODO Internet Security (HKLM\...\{D6AB1F5B-FED6-49A9-9747-327BD28FB3C7}) (Version: 5.10.31649.2253 - COMODO Security Solutions Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.66.16.50 - Conexant)
cURL (HKLM\...\{2B0E3B1A-674D-4C23-8E04-E63BCD246383}) (Version: 7.43.0 - Confused by Code)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.47.1.0335 - Disc Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.20 - Piriform)
Dolby Digital Plus Advanced Audio (HKLM\...\{B0BFC63F-EA07-419E-960B-3FB2ED5DD0B2}) (Version: 7.6.5.1 - Dolby Laboratories Inc)
FileZilla Client 3.16.0 (HKU\S-1-5-21-529706889-675040250-4031740840-1000\...\FileZilla Client) (Version: 3.16.0 - Tim Kosse)
Freemake Video Converter verze 4.1.4 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.4 - Ellora Assets Corporation)
Google Drive (HKLM-x32\...\{895D0391-459F-4D45-B8DD-13F0DE70C66E}) (Version: 1.28.1549.1322 - Google, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 50.0.2661.37 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
HandBrake 0.10.2 (HKLM-x32\...\HandBrake) (Version: 0.10.2 - )
HD Tune 2.55 (HKLM-x32\...\HD Tune_is1) (Version:  - EFD Software)
Integrated Camera Driver Installer Package Ver.1.2.1.18 (HKLM-x32\...\{A78800AF-1779-4AE8-8EBE-16E1BE727C71}) (Version: 1.2.1.18 - RICOH)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.4.225 - Intel Corporation)
Java 8 Update 45 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218045F0}) (Version: 8.0.450 - Oracle Corporation)
K-Lite Mega Codec Pack 11.8.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.8.5 - KLCP)
KMP Service (HKLM-x32\...\4F6D5E84-5826-4394-9F40-3A9A19165651_is1) (Version:  - KMP) <==== ATTENTION
KMPlayer (remove only) (HKLM-x32\...\The KMPlayer) (Version: 4.0.4.6 - PandoraTV)
Kolor Autopano Giga 3.0 (HKLM\...\AutopanoGiga3.0) (Version: V3.0.8 - Kolor)
Lenovo Communications Utility (HKLM\...\{88C6A6D9-324C-46E8-BA87-563D14021442}_is1) (Version: 3.1.13.0 - Lenovo)
Lenovo Patch Utility (HKLM-x32\...\{AD32F5E9-6BDD-480A-8B7B-95571D04691C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Patch Utility 64 bit (HKLM\...\{ABE4638D-D208-4061-9F26-E3E11E3A1E0C}) (Version: 1.3.1.1 - Lenovo Group Limited)
Lenovo Power Management Driver (HKLM\...\Power Management Driver) (Version: 1.67.10.17 - Lenovo)
Lenovo System Interface Foundation (HKLM\...\{C2E5CA37-C862-4A69-AC6D-24F450A20C16}) (Version: 1.0.054.00 - Lenovo)
LibreOffice 5.0.3.2 (HKLM-x32\...\{D61E7AA0-0380-49B9-8DDD-7685E2306176}) (Version: 5.0.3.2 - The Document Foundation)
Malwarebytes Anti-Malware verze 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
Metric Collection SDK 35 (x32 Version: 1.2.0011.00 - Lenovo Group Limited) Hidden
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 33.0 - Mozilla)
NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 353.62 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.62 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
On Screen Display (HKLM\...\OnScreenDisplay) (Version: 7.12.20 - )
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Ovládací panel NVIDIA 353.62 (Version: 353.62 - NVIDIA Corporation) Hidden
ProFact 3.0 (HKLM-x32\...\ProFact 3.0_is1) (Version:  - eXmind)
PSPad editor (HKLM-x32\...\PSPad editor_is1) (Version: 4.5.7.2450 - Jan Fiala)
PTGui Pro 9.0 (HKLM-x32\...\PTGui) (Version:  - New House Internet Services B.V.)
QIP 2012 4.0.7221 (HKU\S-1-5-21-529706889-675040250-4031740840-1000\...\QIP 2012) (Version: 4.0.7221 - )
Rapture3D 2.4.8 Game (HKLM-x32\...\{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1) (Version:  - Blue Ripple Sound)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\...\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.7601.29005 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.51 - Piriform)
RescuePRO Deluxe 5.2.5.6 (HKLM-x32\...\{38D9AAB8-116B-40BB-A801-50B71DF82D24}_is1) (Version: 5.2.5.6 - LC Technology International, Inc.)
SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden
Software Intel® PROSet/Wireless WiFi (HKLM\...\{E97F409F-9E1C-42A0-B72D-765A78DF3696}) (Version: 15.01.0000.0830 - Intel Corporation)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.17.27 - Synaptics Incorporated)
Syncrosoft's License Control (HKLM-x32\...\Syncrosoft's License Control) (Version:  - SIA Syncrosoft)
TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.53254 - TeamViewer)
Texas Instruments TUSB3410 drivers. (HKLM-x32\...\InstallShield_{FA66245E-0E77-40D5-94A4-CB7AB753034F}) (Version: 6.5.9019.1 - Texas Instruments Inc.)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
TUSB3410 (x32 Version: 6.5.9019.1 - Texas Instruments Inc.) Hidden
Ulož.to File Manager verze 1.6 (HKLM-x32\...\{8190420D-F4BA-4744-8940-A466F81AF89C}_is1) (Version: 1.6 - Nodus Technologies s.r.o.)
USB Multi-Channel Audio Device (HKLM\...\C-Media CM106 Like Sound Driver) (Version:  - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WD Quick View (HKLM-x32\...\{CBB36DCC-7276-429F-9B58-4CFDC147D467}) (Version: 2.4.14.13 - Western Digital Technologies, Inc.)
WD SmartWare (HKLM\...\{D344733D-3F0C-4257-9201-6259D90B441E}) (Version: 2.4.14.13 - Western Digital Technologies, Inc.)
WD SmartWare Installer (HKLM-x32\...\{e72369b3-306a-4d10-a766-3433a65e8dc2}) (Version: 2.4.14.13 - Western Digital Technologies, Inc.)
Windows Live ID Sign-in Assistant (HKLM\...\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
YTD Video Downloader 4.8.3 (HKLM-x32\...\{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}) (Version: 4.8.3 - GreenTree Applications SRL) <==== ATTENTION
Zoner Photo Studio 17 (HKLM\...\ZonerPhotoStudio17_CZ_is1) (Version: 17.0.1.12 - ZONER software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-529706889-675040250-4031740840-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Max_cz\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\FileCoAuth.exe (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0824AE65-731C-4A7D-8915-1C7A028C82CA} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {08317534-E39E-415C-AB07-A5DA3EAD9E94} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {0ECE6CCD-95CF-44B2-A3D5-DE177F45B5D5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {0F626639-4A67-4D25-A6F5-3CEA26085189} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {13085D2C-2E25-40CD-9A00-CA6DFD76751E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {1B16B4D7-72F0-4782-B69F-AFDFBA119369} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-06] (COMODO)
Task: {20061696-2358-4525-8C5F-52700D015045} - System32\Tasks\AdobeAAMUpdater-1.0-Max_cz-PC-Max_cz => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-11-27] (Adobe Systems Incorporated)
Task: {24FB79D7-A19D-469C-BF99-D8DEB79CFFF8} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {38A0FCCB-B9E8-4686-897D-F869C4F4ECD2} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-08-06] (COMODO)
Task: {3E8FB326-2D74-4579-998C-128839CC89AD} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {47F51313-B5B1-4C49-BE4A-CAECD298A15E} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {49E36E2D-2D12-4C8B-B5D4-5E07E543098B} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {4BE127A9-10EE-4D21-A8FF-2D709E75DC6C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {4CD46EE3-AE59-4FB6-88A5-7D2FF83E8E36} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {531E674D-77E6-4711-84E5-83A65A470021} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {546A1E49-7E58-4CBA-8950-831D12EC777A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {554DCA1F-C942-4133-A81D-7C2F9196D8D9} - \{0B7A0847-7E04-0E0D-0D11-7D050E0A1179} -> No File <==== ATTENTION
Task: {58FC388E-7323-411B-8A5C-134D8845CD75} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-08-06] (COMODO)
Task: {599B3357-E6E7-4E49-9E84-37B6BD6CCCCF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {5D2CD294-C9FA-435D-B36B-34F4AF93902A} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
Task: {61CC5CA4-2B94-43F3-AD4F-56B61FDE41C5} - System32\Tasks\{CD3808AF-CB98-A8A7-E796-21741D041C14} => C:\WINDOWS\system32\regsvr32.exe [2015-10-30] (Microsoft Corporation)
Task: {67B0247E-05AB-4330-AD97-965BECCBEB0D} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {6B1A349F-4182-448B-B7B6-56351267D8C4} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {6ED6D666-EE9F-4EDC-955F-BDA79B2D9EA0} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {71502CB5-FD6A-46C7-8622-F4B9FFAFF476} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {7173DB2B-13C4-4538-8E06-E8C0B8FF8B5F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {71F9E2E0-08F2-4101-8D5B-24C464A8257A} - System32\Tasks\Synaptics TouchPad Enhancements => Program Files\Synaptics\SynTP\SynTPEnh.exe
Task: {725B4D96-8D56-4BF1-8951-985345537FE7} - System32\Tasks\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_TVSUUpdateTask => reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler  /v start /t reg_dword /d 1 /f /reg:32
Task: {7576A9E7-6815-47BE-920A-FBB62F63B59E} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {7D0EAF09-0709-4D38-B7E0-D4BF451E2971} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {7ECB275A-2E6D-42F1-9D67-5D896955F165} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {86549C45-D827-49FD-9EAB-B3DF56509EC3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {8C1EF94D-232D-4421-8CB4-865F90EC071A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {8D9F55DD-3220-4CCB-BC3C-460781E21462} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
Task: {970D8AD7-E7D4-42D3-8016-9139251C2641} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {B0F21B7A-0D0A-4A8C-A60A-1C1238C21609} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {B143A0AC-E78A-48F6-A790-12195FA84D68} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {B20329CD-715E-4B87-B10B-BDE482902090} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {B4FCF385-A3DF-424E-8104-F00284964A50} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe
Task: {B94683B9-9BA0-428B-883A-D97BD3BA242C} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {C3770B51-5E0E-423B-B7EF-4A00F008FAE6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {CD0B8E76-DBE4-45B4-BAFC-2DDA3D7D5D12} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D00D34EF-5FD2-4337-8AC5-8FF8A6DF2989} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-01-12] (Adobe Systems Incorporated)
Task: {D26B5181-46A2-4015-918F-53F79F363B83} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {DFC459CA-8DC8-439A-87D6-1E699D8FF651} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {EC834E13-F08C-47FE-B5A7-C47599926A7F} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {ED6E35AC-3D36-459C-8EF6-EBEE2FF9EE67} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {EE672CCB-DA7B-44F1-9D9F-D40C320C45C1} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {F1F7CC13-3633-450C-B60C-D2EDF81DE859} - System32\Tasks\CCleanerSkipUAC => C:\Windows.old\Program Files\CCleaner\CCleaner.exe [2015-09-19] (Piriform Ltd)
Task: {F7C63C45-6B28-442B-8D61-8D4705D2E7B6} - System32\Tasks\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance => Sc.exe control iMControllerService 128
Task: {FC88355B-3085-40B0-9BB1-2399E94AEB3E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {FDD779C8-4320-4A04-954F-D15EEB2333C5} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\BocaInstance.job => c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}\4501685520917765081b.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============


altrok
Moderátor
Moderátor
Příspěvky: 7262
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: RSIT havěť

#11 Příspěvek od altrok »

:arrow: Pred pouzitim fixlistu zkontrolujte, zda mate zapnutou funkci bodu obnoveni. Win+Pause -> Advanced System Settings -> zalozka System protection -> mate-li v PC vice disku, oznacte systemovy (C:\ ) a vyberte Configure.


:arrow: Odinstalujte starou a zranitelnou verzi javy. Pokud javu potrebujete, pak nainstalujte novou z java.com - pozor na adware pri jeji instalaci http://forum.viry.cz/viewtopic.php?p=1374438#p1374438 . Z hlediska bezpecnosti (exploity) je lepsi ji nemit. Aktualni je 8U74. Verze Javy, ktere v PC mate nainstalovane:

  • Java 8 Update 45



  • Do Poznamkoveho bloku (Start -> spustit -> notepad) zkopirujte obsah bileho pole
  • ulozte na plochu jako fixlist (Typ souboru: Textovy dokument)
  • znovu spustte FRST a kliknete na Fix
  • po restartu bude na plose ulozen fixlog, jehoz obsah vlozte do pristi odpovedi

    Kód: Vybrat vše

    Start
    CreateRestorePoint:
    CloseProcesses:
    CMD: type "C:\WINDOWS\System32\Tasks\{CD3808AF-CB98-A8A7-E796-21741D041C14}"
    File: C:\Windows\SysWOW64\msiexec.exe
    File: C:\Windows\SysWOW64\svchost.exe
    File: C:\Users\Max_cz\AppData\Roaming\screwd
    File: C:\Program Files\Microsoft Security Client
    Folder: C:\WINDOWS\SysWOW64\NV
    Folder: C:\WINDOWS\system32\NV
    Folder: C:\ProgramData\238a5536
    Folder: C:\Users\Max_cz\AppData\Local\CrashDumps
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
    CMD: ipconfig /flushdns
    FF Extension: No Name - C:\Users\Max_cz\AppData\Roaming\Mozilla\Firefox\Profiles\yn5izivf.default\extensions\iobitascsurfingprotection@iobit.com [not found]
    U3 idsvc; no ImagePath
    2016-03-16 22:38 - 2016-03-16 22:39 - 01222144 _____ C:\Users\Max_cz\Desktop\RSITx64.exe
    2016-03-16 22:32 - 2016-03-16 22:32 - 00000000 ____D C:\ProgramData\238a5536
    2016-03-16 23:43 - 2013-12-09 19:34 - 00000000 ____D C:\Program Files\trend micro
    Task: C:\WINDOWS\Tasks\BocaInstance.job => c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}\4501685520917765081b.exe <==== ATTENTION
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}
    C:\Users\Max_cz\AppData\Roaming\ZQPV2L7C2K.exe
    Task: {0ECE6CCD-95CF-44B2-A3D5-DE177F45B5D5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {13085D2C-2E25-40CD-9A00-CA6DFD76751E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {4BE127A9-10EE-4D21-A8FF-2D709E75DC6C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {4CD46EE3-AE59-4FB6-88A5-7D2FF83E8E36} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {531E674D-77E6-4711-84E5-83A65A470021} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {554DCA1F-C942-4133-A81D-7C2F9196D8D9} - \{0B7A0847-7E04-0E0D-0D11-7D050E0A1179} -> No File <==== ATTENTION
    Task: {7173DB2B-13C4-4538-8E06-E8C0B8FF8B5F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {7D0EAF09-0709-4D38-B7E0-D4BF451E2971} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {8C1EF94D-232D-4421-8CB4-865F90EC071A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    Task: {970D8AD7-E7D4-42D3-8016-9139251C2641} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {C3770B51-5E0E-423B-B7EF-4A00F008FAE6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {ED6E35AC-3D36-459C-8EF6-EBEE2FF9EE67} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    End



  • Ulozte na plochu OTM - http://oldtimer.geekstogo.com/OTM.exe
  • kliknete pravym na ikonu OTM.exe a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
  • obsah bileho pole zkopirujte do leveho okna OTM a ukoncete vsechny ostatni programy (nebo to OTM udela za Vas)
  • kliknete na MoveIt!
  • po restartu vlozte log, ktery bude v C:\_OTM\MovedFiles\mmddyyyy_hhmmss.log

    Kód: Vybrat vše

    :commands
    [EmptyTemp]
    [EmptyFlash]
    [EmptyJava]
    
    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "3212083974"=-
    "301548880"=-
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "C:\\Users\\Max_cz\\AppData\\Roaming\\ZQPV2L7C2K.exe"=-
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#12 Příspěvek od Max_cz »

fixlog.txt

Kód: Vybrat vše

Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by Max_cz (2016-03-17 21:29:39) Run:1
Running from C:\Users\Max_cz\Desktop
Loaded Profiles: Max_cz (Available Profiles: Max_cz & DefaultAppPool)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
CMD: type "C:\WINDOWS\System32\Tasks\{CD3808AF-CB98-A8A7-E796-21741D041C14}"
File: C:\Windows\SysWOW64\msiexec.exe
File: C:\Windows\SysWOW64\svchost.exe
File: C:\Users\Max_cz\AppData\Roaming\screwd
File: C:\Program Files\Microsoft Security Client
Folder: C:\WINDOWS\SysWOW64\NV
Folder: C:\WINDOWS\system32\NV
Folder: C:\ProgramData\238a5536
Folder: C:\Users\Max_cz\AppData\Local\CrashDumps
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
CMD: ipconfig /flushdns
FF Extension: No Name - C:\Users\Max_cz\AppData\Roaming\Mozilla\Firefox\Profiles\yn5izivf.default\extensions\iobitascsurfingprotection@iobit.com [not found]
U3 idsvc; no ImagePath
2016-03-16 22:38 - 2016-03-16 22:39 - 01222144 _____ C:\Users\Max_cz\Desktop\RSITx64.exe
2016-03-16 22:32 - 2016-03-16 22:32 - 00000000 ____D C:\ProgramData\238a5536
2016-03-16 23:43 - 2013-12-09 19:34 - 00000000 ____D C:\Program Files\trend micro
Task: C:\WINDOWS\Tasks\BocaInstance.job => c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}\4501685520917765081b.exe <==== ATTENTION
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}
C:\Users\Max_cz\AppData\Roaming\ZQPV2L7C2K.exe
Task: {0ECE6CCD-95CF-44B2-A3D5-DE177F45B5D5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {13085D2C-2E25-40CD-9A00-CA6DFD76751E} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {4BE127A9-10EE-4D21-A8FF-2D709E75DC6C} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {4CD46EE3-AE59-4FB6-88A5-7D2FF83E8E36} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {531E674D-77E6-4711-84E5-83A65A470021} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {554DCA1F-C942-4133-A81D-7C2F9196D8D9} - \{0B7A0847-7E04-0E0D-0D11-7D050E0A1179} -> No File <==== ATTENTION
Task: {7173DB2B-13C4-4538-8E06-E8C0B8FF8B5F} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {7D0EAF09-0709-4D38-B7E0-D4BF451E2971} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8C1EF94D-232D-4421-8CB4-865F90EC071A} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {970D8AD7-E7D4-42D3-8016-9139251C2641} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {C3770B51-5E0E-423B-B7EF-4A00F008FAE6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {ED6E35AC-3D36-459C-8EF6-EBEE2FF9EE67} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
End
*****************

Restore point was successfully created.
Processes closed successfully.

=========  type "C:\WINDOWS\System32\Tasks\{CD3808AF-CB98-A8A7-E796-21741D041C14}" =========

<?xml version="1.0" encoding="UTF-16"?>
<Task version="1.2" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
  <RegistrationInfo>
    <URI>\{CD3808AF-CB98-A8A7-E796-21741D041C14}</URI>
  </RegistrationInfo>
  <Triggers>
    <CalendarTrigger id="t4">
      <Repetition>
        <Interval>PT6H</Interval>
        <Duration>PT24H</Duration>
        <StopAtDurationEnd>false</StopAtDurationEnd>
      </Repetition>
      <StartBoundary>2016-03-16T22:37:00</StartBoundary>
      <Enabled>true</Enabled>
      <ScheduleByDay>
        <DaysInterval>1</DaysInterval>
      </ScheduleByDay>
    </CalendarTrigger>
  </Triggers>
  <Principals>
    <Principal id="Author">
      <UserId>Max_cz</UserId>
      <RunLevel>HighestAvailable</RunLevel>
      <LogonType>InteractiveToken</LogonType>
    </Principal>
  </Principals>
  <Settings>
    <MultipleInstancesPolicy>IgnoreNew</MultipleInstancesPolicy>
    <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
    <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>
    <AllowHardTerminate>true</AllowHardTerminate>
    <StartWhenAvailable>false</StartWhenAvailable>
    <RunOnlyIfNetworkAvailable>false</RunOnlyIfNetworkAvailable>
    <IdleSettings>
      <Duration>PT10M</Duration>
      <WaitTimeout>PT2H</WaitTimeout>
      <StopOnIdleEnd>true</StopOnIdleEnd>
      <RestartOnIdle>false</RestartOnIdle>
    </IdleSettings>
    <AllowStartOnDemand>true</AllowStartOnDemand>
    <Enabled>true</Enabled>
    <Hidden>true</Hidden>
    <RunOnlyIfIdle>false</RunOnlyIfIdle>
    <WakeToRun>false</WakeToRun>
    <Priority>7</Priority>
  </Settings>
  <Actions Context="Author">
    <Exec>
      <Command>C:\WINDOWS\system32\regsvr32.exe</Command>
      <Arguments>/s /n /i:"/rt" "C:\PROGRA~3\238a5536\5dd424ac.dll"</Arguments>
      <WorkingDirectory>C:\PROGRA~3\238a5536\</WorkingDirectory>
    </Exec>
  </Actions>
</Task>
========= End of CMD: =========


========================= File: C:\Windows\SysWOW64\msiexec.exe ========================

File is digitally signed
MD5: E75AC715811A89B9EA07E0F7F1EF947A
Creation and modification date: 2015-10-30 08:18 - 2015-10-30 08:18
Size: 0058368
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: msiexec
Original Name: msiexec.exe.mui
Product: Windows Installer - Unicode
Description: Windows® installer
File Version: 5.0.10586.0 (th2_release.151029-1700)
Product Version: 5.0.10586.0
Copyright: © Microsoft Corporation. Všechna práva vyhrazena.

====== End of File: ======


========================= File: C:\Windows\SysWOW64\svchost.exe ========================

File is digitally signed
MD5: 6A1212077C0559029CDFB9C39580C835
Creation and modification date: 2015-10-30 08:18 - 2015-10-30 08:18
Size: 0037256
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: svchost.exe
Original Name: svchost.exe.mui
Product: Operační systém Microsoft® Windows®
Description: Host Process for Windows Services
File Version: 10.0.10586.0 (th2_release.151029-1700)
Product Version: 10.0.10586.0
Copyright: © Microsoft Corporation. Všechna práva vyhrazena.

====== End of File: ======


========================= File: C:\Users\Max_cz\AppData\Roaming\screwd ========================

File not signed
MD5: E1D9D083CF9F567391FAED71CB45D41C
Creation and modification date: 2013-08-23 19:10 - 2013-08-23 19:56
Size: 0002359
Attributes: ----A
Company Name: 
Internal Name: 
Original Name: 
Product: 
Description: 
File Version: 
Product Version: 
Copyright: 

====== End of File: ======


========================= File: C:\Program Files\Microsoft Security Client ========================

File not signed
MD5: 
Creation and modification date: 2015-09-19 23:09 - 2015-09-19 23:09
Size: 0000000
Attributes: ----A
Company Name: 
Internal Name: 
Original Name: 
Product: 
Description: 
File Version: 
Product Version: 
Copyright: 

====== End of File: ======


========================= Folder: C:\WINDOWS\SysWOW64\NV ========================

2016-03-16 16:22 - 2016-03-14 15:45 - 0128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NV\ig4icd32.dll
2016-03-16 16:22 - 2016-03-14 15:45 - 0991152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NV\igd10umd32.dll
2016-03-16 16:22 - 2016-03-14 15:45 - 0991152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NV\igdumd32.dll

====== End of Folder: ======


========================= Folder: C:\WINDOWS\system32\NV ========================

2016-03-16 16:22 - 2016-03-14 15:45 - 0150832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NV\ig4icd64.dll
2016-03-16 16:22 - 2016-03-14 15:45 - 1165192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NV\igd10umd64.dll
2016-03-16 16:22 - 2016-03-14 15:45 - 1165192 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NV\igdumd64.dll

====== End of Folder: ======


========================= Folder: C:\ProgramData\238a5536 ========================

2016-03-16 22:32 - 2016-03-16 22:32 - 0481792 _____ () C:\ProgramData\238a5536\5dd424ac.dll

====== End of Folder: ======


========================= Folder: C:\Users\Max_cz\AppData\Local\CrashDumps ========================

2016-03-14 16:29 - 2016-03-14 16:30 - 2349806 _____ () C:\Users\Max_cz\AppData\Local\CrashDumps\nvcplui.exe.3460.dmp

====== End of Folder: ======

"HKLM\SOFTWARE\Policies\Google" => key removed successfully

=========  ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

C:\Users\Max_cz\AppData\Roaming\Mozilla\Firefox\Profiles\yn5izivf.default\extensions\iobitascsurfingprotection@iobit.com => path removed successfully
idsvc => service removed successfully
C:\Users\Max_cz\Desktop\RSITx64.exe => moved successfully
C:\ProgramData\238a5536 => moved successfully
C:\Program Files\trend micro => moved successfully
C:\WINDOWS\Tasks\BocaInstance.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => moved successfully
C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => moved successfully
"c:\programdata\{06c977a0-c47d-4b6d-06c9-977a0c47de83}" => not found.
"C:\Users\Max_cz\AppData\Roaming\ZQPV2L7C2K.exe" => not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0ECE6CCD-95CF-44B2-A3D5-DE177F45B5D5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0ECE6CCD-95CF-44B2-A3D5-DE177F45B5D5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{13085D2C-2E25-40CD-9A00-CA6DFD76751E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{13085D2C-2E25-40CD-9A00-CA6DFD76751E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4BE127A9-10EE-4D21-A8FF-2D709E75DC6C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4BE127A9-10EE-4D21-A8FF-2D709E75DC6C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4CD46EE3-AE59-4FB6-88A5-7D2FF83E8E36}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CD46EE3-AE59-4FB6-88A5-7D2FF83E8E36}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{531E674D-77E6-4711-84E5-83A65A470021}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{531E674D-77E6-4711-84E5-83A65A470021}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{554DCA1F-C942-4133-A81D-7C2F9196D8D9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{554DCA1F-C942-4133-A81D-7C2F9196D8D9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{0B7A0847-7E04-0E0D-0D11-7D050E0A1179}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7173DB2B-13C4-4538-8E06-E8C0B8FF8B5F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7173DB2B-13C4-4538-8E06-E8C0B8FF8B5F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{7D0EAF09-0709-4D38-B7E0-D4BF451E2971}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7D0EAF09-0709-4D38-B7E0-D4BF451E2971}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8C1EF94D-232D-4421-8CB4-865F90EC071A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8C1EF94D-232D-4421-8CB4-865F90EC071A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{970D8AD7-E7D4-42D3-8016-9139251C2641}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{970D8AD7-E7D4-42D3-8016-9139251C2641}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C3770B51-5E0E-423B-B7EF-4A00F008FAE6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C3770B51-5E0E-423B-B7EF-4A00F008FAE6}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{ED6E35AC-3D36-459C-8EF6-EBEE2FF9EE67}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{ED6E35AC-3D36-459C-8EF6-EBEE2FF9EE67}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully


The system needed a reboot.

==== End of Fixlog 21:29:47 ====

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#13 Příspěvek od Max_cz »

OTM.txt

Kód: Vybrat vše

All processes killed
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default.migrated
 
User: DefaultAppPool
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Max_cz
->Temp folder emptied: 891466200 bytes
->Temporary Internet Files folder emptied: 388839 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 285822653 bytes
->Flash cache emptied: 507 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 31976 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 314767251 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 1 423,00 mb
 
 
[EMPTYFLASH]
 
User: All Users
 
User: Default
->Flash cache emptied: 0 bytes
 
User: Default User
->Flash cache emptied: 0 bytes
 
User: Default.migrated
 
User: DefaultAppPool
->Flash cache emptied: 0 bytes
 
User: Max_cz
->Flash cache emptied: 0 bytes
 
User: Public
 
Total Flash Files Cleaned = 0,00 mb
 
 
[EMPTYJAVA]
 
User: All Users
 
User: Default
 
User: Default User
 
User: Default.migrated
 
User: DefaultAppPool
 
User: Max_cz
->Java cache emptied: 0 bytes
 
User: Public
 
Total Java Files Cleaned = 0,00 mb
 
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\\3212083974 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer\\301548880 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\\Users\\Max_cz\\AppData\\Roaming\\ZQPV2L7C2K.exe not found.
 
OTM by OldTimer - Version 3.1.21.0 log created on 03172016_214745

Files moved on Reboot...
File move failed. C:\Users\Max_cz\AppData\Local\Microsoft\Windows\INetCache\counters.dat scheduled to be moved on reboot.
File move failed. C:\WINDOWS\temp\adobegc.log scheduled to be moved on reboot.
C:\WINDOWS\temp\etilqs_JhxyF8R1wJZ9PsY moved successfully.

Registry entries deleted on Reboot...

altrok
Moderátor
Moderátor
Příspěvky: 7262
Registrován: 15 lis 2012 22:26
Bydliště: Znojmo

Re: RSIT havěť

#14 Příspěvek od altrok »

:arrow: Ulozte na plochu MBAR - http://www.bleepingcomputer.com/downloa ... i-rootkit/
  • spuste dvojklikem a extrahujte na plochu
  • kliknete na Next
  • aktualizujte virovou databazi klikem na Update a pokracujte na Next
  • vsechny 3 moznosti nechte zaskrtnute a zvolte Scan (potrva cca 20 minut)
  • zatrhnete vsechny nalezy a take zkontrolujte zatrzitko u Create Restore Point
  • kliknete na Cleanup a souhlaste s restartem - Yes
  • obsah logu ulozene na plose v mbar\mbar-log-2015-mm-dd (hh-mm-ss).txt vlozte do pristi odpovedi
Pokud je cokoliv nejasného, ihned se ptej.
V případě spokojenosti prosím podpořte forum.
Pro dotazy, které se nehodí na forum, je možné využít altrokzavináčforum.viry.cz
Máš-li chuť pomáhat návštěvníkům tohoto fora, přihlas se do naší školičky.

Max_cz
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 191
Registrován: 20 pro 2005 22:14
Kontaktovat uživatele:

Re: RSIT havěť

#15 Příspěvek od Max_cz »

No malware found

Odpovědět