Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

antivir hlásí hrozby

Patříte mezi Vzorné návštěvníky? Pak je tato sekce pro vás.

Moderátor: Moderátoři

Pravidla fóra
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
Odpovědět
Zpráva
Autor
Uživatelský avatar
Rambotnik
Vzorný návštěvník
Vzorný návštěvník
Příspěvky: 36
Registrován: 02 čer 2006 13:55

antivir hlásí hrozby

#1 Příspěvek od Rambotnik »

Zdravím, před týdnem jsem dělal čistou instalaci Win 10 a doinstaloval jen několik programů. V karanténě Windows Defenderu je několik malware a trojanů, tak se chci ujistit, že nemám něco i jinde.
Posílám log z RSIT.
Děkuji z pomoc

Logfile of random's system information tool 1.10 (written by random/random)
Run by Rambotnik at 2016-03-20 19:53:43
Microsoft Windows 10 Pro
System drive C: has 157 GB (66%) free of 238 GB
Total RAM: 8136 MB (70% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:54:27, on 20.3.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Users\Rambotnik\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Users\Rambotnik\AppData\Local\Temp\28366968\ic-0.d76cafb9508b1.exe
C:\Users\Rambotnik\AppData\Local\Temp\28366968\download\MiniThunderPlatform.exe
C:\Users\Rambotnik\AppData\Local\Temp\un.exe
C:\Windows\SysWOW64\Ctxfihlp.exe
C:\WINDOWS\SysWOW64\CTXFISPI.EXE
C:\Program Files\trend micro\Rambotnik.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.2345.com/?34838
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.2345.com/?34838
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O1 - Hosts: 64.25.35.23 updater.nclauncher.ncsoft.com
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [ic-0.d76cafb9508b1.exe -start] C:\Users\RAMBOT~1\AppData\Local\Temp\28366968\ic-0.d76cafb9508b1.exe -start
O4 - HKLM\..\Run: [ QQPCTray] "C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCTRAY.EXE" /regrun /qqrepair
O4 - HKLM\..\Run: [un] C:\Users\Rambotnik\AppData\Local\Temp\un.exe /start
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Rambotnik\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL1 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CtxfiReg] CTXFIREG.exe /FAIL1 (User 'Default user')
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://files.creative.com/Web/softwareu ... PIDPDE.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://files.creative.com/Web/softwareu ... TSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://files.creative.com/Web/softwareu ... /CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{d523dbdc-7e27-47a7-b2cd-2e0119447e93}: NameServer = 4.2.2.2,8.8.8.8
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\WINDOWS\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: ggbugreport - Unknown owner - C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: QQPCMgr RTP Service (QQPCRTP) - Unknown owner - C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCRTP.exe (file missing)
O23 - Service: QQRepairFixSVC - Unknown owner - C:\Program.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 10609 bytes

======Listing Processes======








C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
winlogon.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
"dwm.exe"
"C:\Windows\system32\nvvsvc.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe"
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalService
"C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe"
C:\WINDOWS\system32\nvvsvc.exe -session -first
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-7eec2199-1443-4981-b77e-027d390c7e35 -SystemEventPortName:HostProcess-ce1e4382-1029-4f33-b25f-abdf56600957 -IoCancelEventPortName:HostProcess-408badf0-8519-4614-8d1c-1344b837c705 -NonStateChangingEventPortName:HostProcess-c47b3e05-826e-4229-8092-463613a792ae -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:d44b0b20-b445-4496-b4fd-4a9fa21c883b -DeviceGroupId:WpdFsGroup
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\WINDOWS\System32\spoolsv.exe
dashost.exe {0778c71f-fd0f-475c-8d8be1db2cf42e24}
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\WINDOWS\system32\mqsvc.exe
C:\WINDOWS\system32\svchost.exe -k iissvcs
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel

"C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe" -NetMsmqActivator
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding

"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -profile "C:\Users\Rambotnik\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F" "http://www.yessearches.com/?ts=AHEpC38o ... &mode=scrp"
"fontdrvhost.exe"
"C:\Users\Rambotnik\AppData\Roaming\cpuminer\cpm.exe"
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Users\Rambotnik\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun

"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Users\Rambotnik\AppData\Local\Temp\28366968\ic-0.d76cafb9508b1.exe" -start
"C:\Users\Rambotnik\AppData\Local\Temp\28366968\download\MiniThunderPlatform.exe" -StartTP
"C:\Users\Rambotnik\AppData\Local\Temp\un.exe" /start
"C:\Windows\System32\Ctxfihlp.exe"
"C:\WINDOWS\SysWOW64\CTXFISPI.EXE" -Embedding
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe"
"C:\Program Files\Windows Defender\msascui.exe"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 632 636 644 8192 640

C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Users\Rambotnik\Downloads\RSITx64.exe"

======Scheduled tasks folder======

C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\Rambotnik\AppData\Roaming\Mozilla\Firefox\Profiles\CCACCBF1-7AB4-4CF5-B32D-668C686A539F

prefs.js - "browser.startup.homepage" - "www.google.com"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/npAndroidAssistant]
"Description"=QQPhoneManager Onekey-Install plug-in for Android Phones
"Path"=C:\Program Files (x86)\Common Files\Tencent\QQPhoneManager\2.0.201.3192\npQQPhoneManagerExt.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@qq.com/QQPCMgr]
"Description"=QQPCMgr Detector
"Path"=C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\npQMExtensionsMozilla.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.1.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-03-08 2789248]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-03-08 1903344]
"cpuminer"=C:\Users\Rambotnik\AppData\Roaming\cpuminer\cpm.exe [2016-02-29 1402880]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Rambotnik\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-03-17 551104]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-02-10 50599552]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-03-10 3074128]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2016-02-12 8641240]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-05-21 291648]
"ic-0.d76cafb9508b1.exe -start"=C:\Users\RAMBOT~1\AppData\Local\Temp\28366968\ic-0.d76cafb9508b1.exe [2016-03-17 2289664]
" QQPCTray"=C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCTRAY.EXE /regrun /qqrepair []
"un"=C:\Users\Rambotnik\AppData\Local\Temp\un.exe [2016-03-17 3714048]
"CTxfiHlp"=CTXFIHLP.EXE []

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\QQPCRTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\QQPCRTP]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=0
"DSCAutomationHostEnabled"=2
"EnableLUA"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=221

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"aux"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux1"=wdmaud.drv
"vidc.mjpg"=bdmjpeg64.dll
"vidc.mpeg"=bdmpegv64.dll
"msacm.bdmpeg"=bdmpega64.acm
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-03-20 19:53:43 ----D---- C:\rsit
2016-03-20 19:53:43 ----D---- C:\Program Files\trend micro
2016-03-20 19:06:50 ----D---- C:\Users\Rambotnik\AppData\Roaming\IrfanView
2016-03-20 19:06:50 ----D---- C:\Program Files\IrfanView
2016-03-18 15:38:40 ----A---- C:\WINDOWS\system32\drivers\TAOKernelEx64.sys
2016-03-18 15:33:14 ----A---- C:\WINDOWS\system32\ffnd.exe
2016-03-18 15:29:26 ----D---- C:\Users\Rambotnik\AppData\Roaming\FreeFixer
2016-03-18 15:29:21 ----D---- C:\Program Files\FreeFixer
2016-03-18 15:26:08 ----D---- C:\Program Files\CCleaner
2016-03-18 15:21:47 ----D---- C:\WINDOWS\LastGood.Tmp
2016-03-18 15:21:39 ----A---- C:\WINDOWS\SYSWOW64\INRES.DLL
2016-03-18 15:21:39 ----A---- C:\WINDOWS\system32\INRES.DLL
2016-03-18 12:29:51 ----D---- C:\WINDOWS\system32\SleepStudy
2016-03-18 12:19:04 ----A---- C:\WINDOWS\SYSWOW64\drivers\TS888x64.sys
2016-03-17 21:12:47 ----D---- C:\Users\Rambotnik\AppData\Roaming\vlc
2016-03-17 19:44:30 ----D---- C:\Program Files (x86)\VideoLAN
2016-03-17 19:43:16 ----D---- C:\Program Files (x86)\Seznam.cz
2016-03-17 19:42:33 ----D---- C:\Users\Rambotnik\AppData\Roaming\Seznam.cz
2016-03-17 19:42:16 ----D---- C:\Program Files\Common Files\Tencent
2016-03-17 19:42:15 ----A---- C:\Users\Rambotnik\AppData\Roaming\GiftBag.db
2016-03-17 19:42:13 ----D---- C:\ProgramData\TXQMPC
2016-03-17 19:42:13 ----A---- C:\WINDOWS\system32\drivers\TAOAccelerator64.sys
2016-03-17 19:42:08 ----A---- C:\WINDOWS\system32\drivers\TFsFltX64.sys
2016-03-17 19:41:47 ----D---- C:\Program Files (x86)\Tencent
2016-03-17 19:41:43 ----D---- C:\Users\Rambotnik\AppData\Roaming\Tencent
2016-03-17 19:41:41 ----D---- C:\ProgramData\Tencent
2016-03-17 19:41:32 ----D---- C:\Users\Rambotnik\AppData\Roaming\BANDISOFT
2016-03-17 19:40:34 ----D---- C:\ProgramData\Thunder Network
2016-03-17 19:40:25 ----D---- C:\Users\Rambotnik\AppData\Roaming\gplyra
2016-03-17 19:40:23 ----D---- C:\Users\Rambotnik\AppData\Roaming\cpuminer
2016-03-17 19:40:14 ----D---- C:\Program Files (x86)\WinTaske
2016-03-17 19:40:14 ----D---- C:\Program Files (x86)\Winsere
2016-03-17 19:40:10 ----D---- C:\Program Files (x86)\SearchesToYesbnd
2016-03-17 19:39:30 ----A---- C:\WINDOWS\chromebrowser.exe
2016-03-17 19:39:12 ----D---- C:\Program Files (x86)\BandiMPEG1
2016-03-17 19:39:12 ----D---- C:\Program Files (x86)\Bandicam
2016-03-17 19:34:54 ----DC---- C:\WINDOWS\Panther
2016-03-17 19:33:49 ----D---- C:\Windows.old
2016-03-17 19:33:11 ----D---- C:\WINDOWS\SYSWOW64\BestPractices
2016-03-17 19:33:11 ----D---- C:\WINDOWS\system32\msmq
2016-03-17 19:33:11 ----D---- C:\WINDOWS\system32\BestPractices
2016-03-17 19:33:11 ----D---- C:\Program Files\Reference Assemblies
2016-03-17 19:33:11 ----D---- C:\Program Files\MSBuild
2016-03-17 19:33:11 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-03-17 19:33:11 ----D---- C:\Program Files (x86)\MSBuild
2016-03-17 19:33:11 ----D---- C:\inetpub
2016-03-17 19:32:55 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2016-03-17 19:32:55 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2016-03-17 19:32:55 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2016-03-17 19:32:54 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2016-03-17 19:32:54 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2016-03-17 19:32:54 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2016-03-17 19:32:48 ----A---- C:\WINDOWS\system32\systemreset.exe
2016-03-17 19:32:48 ----A---- C:\WINDOWS\system32\reseteng.dll
2016-03-17 19:32:48 ----A---- C:\WINDOWS\system32\drivers\sdbus.sys
2016-03-17 19:32:48 ----A---- C:\WINDOWS\system32\drivers\dumpsd.sys
2016-03-17 16:36:30 ----D---- C:\Users\Rambotnik\AppData\Roaming\Awesomium
2016-03-17 13:31:43 ----D---- C:\Program Files (x86)\NCSOFT
2016-03-17 13:28:29 ----D---- C:\Program Files (x86)\NCWest
2016-03-17 12:58:28 ----A---- C:\WINDOWS\system32\drivers\EasyAntiCheat.sys
2016-03-17 12:58:23 ----A---- C:\WINDOWS\SYSWOW64\EasyAntiCheat.exe
2016-03-17 12:57:53 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_7.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_5.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_7.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_43.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_43.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\system32\XAudio2_7.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\system32\XAPOFX1_5.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\system32\xactengine3_7.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\system32\d3dcsx_43.dll
2016-03-17 12:57:53 ----A---- C:\WINDOWS\system32\D3DCompiler_43.dll
2016-03-17 12:57:52 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_6.dll
2016-03-17 12:57:52 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_4.dll
2016-03-17 12:57:52 ----A---- C:\WINDOWS\system32\XAudio2_6.dll
2016-03-17 12:57:52 ----A---- C:\WINDOWS\system32\XAPOFX1_4.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_5.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_6.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_7.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\system32\xactengine3_6.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\system32\X3DAudio1_7.dll
2016-03-17 12:57:51 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_41.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_41.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2016-03-17 12:57:50 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_3.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2016-03-17 12:57:49 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2016-03-17 12:57:48 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2016-03-17 12:57:47 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2016-03-17 12:57:46 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2016-03-17 12:57:45 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2016-03-17 12:57:44 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2016-03-17 12:57:43 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2016-03-17 12:57:42 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2016-03-17 12:57:41 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_32.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2016-03-17 12:57:40 ----A---- C:\WINDOWS\system32\d3dx10.dll
2016-03-17 12:57:39 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2016-03-17 12:57:39 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2016-03-17 12:57:39 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2016-03-17 12:57:39 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2016-03-17 12:57:39 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2016-03-17 12:57:39 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2016-03-17 12:57:39 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2016-03-17 12:57:39 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2016-03-17 12:57:37 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2016-03-17 12:57:37 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2016-03-17 12:57:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2016-03-17 12:57:37 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2016-03-17 12:57:37 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2016-03-17 12:57:37 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2016-03-17 12:57:36 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2016-03-17 12:57:36 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2016-03-17 12:57:36 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2016-03-17 12:57:36 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2016-03-17 12:57:36 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2016-03-17 12:57:36 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2016-03-17 12:57:36 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2016-03-17 12:57:36 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2016-03-17 12:57:35 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2016-03-17 12:57:35 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2016-03-17 12:57:35 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2016-03-17 12:57:35 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2016-03-17 12:18:54 ----D---- C:\Users\Rambotnik\AppData\Roaming\GHISLER
2016-03-17 12:18:54 ----D---- C:\totalcmd
2016-03-17 11:59:28 ----D---- C:\Program Files (x86)\Steam
2016-03-17 11:38:43 ----A---- C:\WINDOWS\system32\perfi005.dat
2016-03-17 11:38:43 ----A---- C:\WINDOWS\system32\perfh005.dat
2016-03-17 11:38:43 ----A---- C:\WINDOWS\system32\perfd005.dat
2016-03-17 11:38:43 ----A---- C:\WINDOWS\system32\perfc005.dat
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\drivers\cs-CZ
2016-03-17 11:38:31 ----D---- C:\WINDOWS\SYSWOW64\cs
2016-03-17 11:38:30 ----D---- C:\WINDOWS\system32\drivers\cs-CZ
2016-03-17 11:38:29 ----D---- C:\WINDOWS\system32\cs
2016-03-17 11:38:28 ----D---- C:\WINDOWS\cs-CZ
2016-03-17 11:24:44 ----D---- C:\Users\Rambotnik\AppData\Roaming\Skype
2016-03-17 11:24:40 ----RD---- C:\Program Files (x86)\Skype
2016-03-17 11:24:38 ----D---- C:\ProgramData\Skype
2016-03-17 11:21:05 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2016-03-17 11:21:05 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-03-17 11:21:05 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2016-03-17 11:21:04 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2016-03-17 11:21:04 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-17 11:21:04 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2016-03-17 11:21:04 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2016-03-17 11:21:03 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2016-03-17 11:21:03 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2016-03-17 11:21:03 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2016-03-17 11:21:03 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2016-03-17 11:21:03 ----A---- C:\WINDOWS\system32\wininet.dll
2016-03-17 11:21:03 ----A---- C:\WINDOWS\system32\urlmon.dll
2016-03-17 11:21:03 ----A---- C:\WINDOWS\system32\dwmcore.dll
2016-03-17 11:21:03 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2016-03-17 11:21:02 ----A---- C:\WINDOWS\system32\wininetlui.dll
2016-03-17 11:21:02 ----A---- C:\WINDOWS\system32\ntdll.dll
2016-03-17 11:21:02 ----A---- C:\WINDOWS\system32\ieframe.dll
2016-03-17 11:21:02 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-03-17 11:21:01 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-03-17 11:21:01 ----A---- C:\WINDOWS\system32\win32kfull.sys
2016-03-17 11:21:01 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-03-17 11:21:01 ----A---- C:\WINDOWS\system32\mshtml.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\system32\twinui.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\system32\InputService.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\system32\audiosrv.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\system32\AudioSes.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2016-03-17 11:21:00 ----A---- C:\WINDOWS\system32\audiodg.exe
2016-03-17 11:20:59 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2016-03-17 11:20:59 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2016-03-17 11:20:59 ----A---- C:\WINDOWS\system32\windows.storage.dll
2016-03-17 11:20:58 ----A---- C:\WINDOWS\system32\wmp.dll
2016-03-17 11:20:58 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2016-03-17 11:20:57 ----A---- C:\WINDOWS\system32\shell32.dll
2016-03-17 11:20:57 ----A---- C:\WINDOWS\system32\jsproxy.dll
2016-03-17 11:20:57 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-03-17 11:20:57 ----A---- C:\WINDOWS\system32\ipnathlp.dll
2016-03-17 11:20:57 ----A---- C:\WINDOWS\system32\invagent.dll
2016-03-17 11:20:57 ----A---- C:\WINDOWS\system32\devinv.dll
2016-03-17 11:20:57 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-03-17 11:20:56 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-03-17 11:20:56 ----A---- C:\WINDOWS\system32\WSService.dll
2016-03-17 11:20:55 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-03-17 11:20:55 ----A---- C:\WINDOWS\system32\mstscax.dll
2016-03-17 11:20:54 ----A---- C:\WINDOWS\SYSWOW64\wmp.dll
2016-03-17 11:20:54 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2016-03-17 11:20:54 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2016-03-17 11:20:54 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2016-03-17 11:20:54 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-03-17 11:20:53 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-03-17 11:20:53 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2016-03-17 11:20:53 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2016-03-17 11:20:52 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-03-17 11:20:52 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-03-17 11:20:52 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2016-03-17 11:20:52 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-03-17 11:20:52 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-03-17 11:20:52 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2016-03-17 11:20:52 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-03-17 11:20:52 ----A---- C:\WINDOWS\system32\CertEnroll.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\SYSWOW64\CertEnroll.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\system32\StorSvc.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\system32\SmsRouterSvc.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2016-03-17 11:20:51 ----A---- C:\WINDOWS\system32\d3d11.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2016-03-17 11:20:51 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\XblGameSave.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\UserDataService.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\schedsvc.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\dosvc.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-03-17 11:20:50 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\wwansvc.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\win32kbase.sys
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\localspl.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\KernelBase.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\iertutil.dll
2016-03-17 11:20:49 ----A---- C:\WINDOWS\system32\diagtrack.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\WMPDMC.exe
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\SYSWOW64\ContactApis.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\Unistore.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\uDWM.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\SharedStartModel.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\SettingSync.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\ole32.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\ngckeyenum.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\dxgi.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\ContactApis.dll
2016-03-17 11:20:48 ----A---- C:\WINDOWS\system32\AppointmentApis.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\taskschd.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\SettingSync.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\NetSetupShim.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\SYSWOW64\AppointmentApis.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\wlansvc.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\winresume.exe
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\winload.exe
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\Windows.Media.MediaControl.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\vaultsvc.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\SRH.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\spoolsv.exe
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\SMSRouter.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\NetSetupShim.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\netlogon.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\mfds.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\ClipSVC.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\bisrv.dll
2016-03-17 11:20:47 ----A---- C:\WINDOWS\system32\AppxPackaging.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.MediaControl.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\SyncController.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\msvproc.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\AppxPackaging.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\wuuhext.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\wlansec.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\wifiprofilessettinghandler.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\wer.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\usbmon.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\TimeBrokerServer.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\SyncController.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\QuickActionsDataModel.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\PsmServiceExtHost.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\msvproc.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\msv1_0.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\MDEServer.exe
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\dafBth.dll
2016-03-17 11:20:46 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\WiFiDisplay.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\sqmapi.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\PackageStateRoaming.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\ChatApis.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\EmailApis.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\SYSWOW64\AppointmentActivation.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\WMPDMC.exe
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\WiFiDisplay.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\werui.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\VCardParser.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\vaultcli.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\thumbcache.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\taskschd.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\sqmapi.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\sharemediacpl.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\psmsrv.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\MDMAppInstaller.exe
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\ChatApis.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\EmailApis.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\drivers\xinputhid.sys
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\drivers\bridge.sys
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\configurationclient.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\CallHistoryClient.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\AuthBroker.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\atmfd.dll
2016-03-17 11:20:45 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Scanners.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\SYSWOW64\PhoneCallHistoryApis.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\SYSWOW64\olepro32.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\SYSWOW64\fwbase.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\SYSWOW64\cemapi.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\wlanmsm.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\wlanapi.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\wermgr.exe
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\UserDataAccountApis.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\provpackageapidll.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\PimIndexMaintenance.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\PackageStateRoaming.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\drivers\appid.sys
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\domgmt.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\cemapi.dll
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\AuthHost.exe
2016-03-17 11:20:44 ----A---- C:\WINDOWS\system32\AppointmentActivation.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\werui.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\wermgr.exe
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\VCardParser.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\UserDataAccountApis.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\POSyncServices.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\ExtrasXmlParser.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\ExSMime.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\asycfilt.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\SYSWOW64\AppxSip.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\wpninprc.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\wlansvcpal.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\WiFiConfigSP.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\seclogon.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\scapi.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\POSyncServices.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\fwbase.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\FirewallAPI.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\ExSMime.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\dssvc.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\drivers\USBSTOR.SYS
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\asycfilt.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\AppxSysprep.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\AppxSip.dll
2016-03-17 11:20:43 ----A---- C:\WINDOWS\system32\accountaccessor.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\wfapigp.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\UserDataTypeHelperUtil.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\UserDataPlatformHelperUtil.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\UserDataLanguageUtil.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\TimeBrokerClient.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\profext.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\PimIndexMaintenanceClient.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\fwpolicyiomgr.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\CallHistoryClient.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\Windows.Devices.Scanners.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\wfdprov.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\wfapigp.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\UserDataLanguageUtil.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\TimeBrokerClient.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\srpapi.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\profext.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\irmon.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\fwpolicyiomgr.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\fontsub.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\ExtrasXmlParser.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\drivers\rasl2tp.sys
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\atmlib.dll
2016-03-17 11:20:42 ----A---- C:\WINDOWS\system32\AppCapture.dll
2016-03-17 11:06:41 ----D---- C:\Program Files (x86)\Kodi
2016-03-17 11:05:56 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_43.dll
2016-03-17 11:05:56 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_43.dll
2016-03-17 11:05:56 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_43.dll
2016-03-17 11:05:56 ----A---- C:\WINDOWS\system32\D3DX9_43.dll
2016-03-17 11:05:56 ----A---- C:\WINDOWS\system32\d3dx11_43.dll
2016-03-17 11:05:56 ----A---- C:\WINDOWS\system32\d3dx10_43.dll
2016-03-17 11:05:54 ----A---- C:\WINDOWS\system32\nvspcap64.dll
2016-03-17 11:05:54 ----A---- C:\WINDOWS\system32\nvspbridge64.dll
2016-03-17 11:05:54 ----A---- C:\WINDOWS\system32\NvRtmpStreamer64.dll
2016-03-17 11:05:53 ----A---- C:\WINDOWS\SYSWOW64\nvspcap.dll
2016-03-17 11:05:53 ----A---- C:\WINDOWS\SYSWOW64\nvspbridge.dll
2016-03-17 11:05:27 ----A---- C:\WINDOWS\SYSWOW64\nvStreaming.exe
2016-03-17 11:05:13 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2016-03-17 11:05:13 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2016-03-17 11:05:13 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2016-03-17 11:05:13 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2016-03-17 11:05:11 ----D---- C:\Program Files (x86)\VulkanRT
2016-03-17 11:05:05 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2016-03-17 11:05:05 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2016-03-17 11:04:41 ----D---- C:\Program Files\7-Zip
2016-03-17 11:04:18 ----A---- C:\WINDOWS\SYSWOW64\nvaudcap32v.dll
2016-03-17 11:04:18 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2016-03-17 11:04:18 ----A---- C:\WINDOWS\system32\nvaudcap64v.dll
2016-03-17 11:04:18 ----A---- C:\WINDOWS\system32\drivers\nvvad64v.sys
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvumdshim.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvoglshim32.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvinit.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvd3dum.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvumdshimx.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvopencl.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvoglshim64.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvinitx.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvdispgenco6436451.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvdispco6436451.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvd3dumx.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvcuda.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2016-03-17 11:04:17 ----A---- C:\WINDOWS\system32\nvapi64.dll
2016-03-17 10:46:36 ----A---- C:\WINDOWS\system32\prm0005.dll
2016-03-17 10:41:42 ----D---- C:\Users\Rambotnik\AppData\Roaming\Adobe
2016-03-17 10:38:29 ----SHD---- C:\Recovery
2016-03-17 10:38:29 ----SHD---- C:\ProgramData\Templates
2016-03-17 10:38:29 ----SHD---- C:\ProgramData\Start Menu
2016-03-17 10:38:29 ----SHD---- C:\ProgramData\Favorites
2016-03-17 10:38:29 ----SHD---- C:\ProgramData\Documents
2016-03-17 10:38:29 ----SHD---- C:\ProgramData\Desktop
2016-03-17 10:38:29 ----SHD---- C:\ProgramData\Application Data
2016-03-17 10:37:50 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2016-03-17 10:36:34 ----D---- C:\Program Files\Common Files\SpeechEngines
2016-03-17 10:36:24 ----SD---- C:\Users\Rambotnik\AppData\Roaming\Microsoft
2016-03-17 10:36:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2016-03-17 10:36:08 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2016-03-17 10:35:42 ----A---- C:\WINDOWS\SYSWOW64\cttele32.dll
2016-03-17 10:35:42 ----A---- C:\WINDOWS\system32\cttele64.dll
2016-03-17 10:35:31 ----D---- C:\Program Files (x86)\OpenAL
2016-03-17 10:35:31 ----A---- C:\WINDOWS\SYSWOW64\wrap_oal.dll
2016-03-17 10:35:31 ----A---- C:\WINDOWS\SYSWOW64\OpenAL32.dll
2016-03-17 10:35:31 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2016-03-17 10:35:31 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2016-03-17 10:35:30 ----D---- C:\WINDOWS\SYSWOW64\data
2016-03-17 10:35:30 ----D---- C:\WINDOWS\system32\data
2016-03-17 10:35:26 ----D---- C:\WINDOWS\Prefetch
2016-03-17 10:35:08 ----ASH---- C:\swapfile.sys
2016-03-17 09:57:58 ----HD---- C:\$WINDOWS.~BT
2016-03-17 09:01:49 ----HD---- C:\$Windows.~WS
2016-03-17 08:55:48 ----D---- C:\ESD
2016-03-16 14:51:09 ----HD---- C:\Program Files (x86)\Creative Installation Information
2016-03-16 14:51:04 ----D---- C:\Program Files\Creative
2016-03-16 14:51:03 ----D---- C:\Program Files (x86)\Creative
2016-03-16 14:51:00 ----D---- C:\ProgramData\Creative
2016-03-16 14:50:58 ----A---- C:\WINDOWS\SYSWOW64\CmdRtr.DLL
2016-03-16 14:50:58 ----A---- C:\WINDOWS\SYSWOW64\APOMngr.DLL
2016-03-16 14:50:58 ----A---- C:\WINDOWS\system32\CmdRtr64.DLL
2016-03-16 14:50:58 ----A---- C:\WINDOWS\system32\APOMgr64.DLL
2016-03-16 14:50:37 ----D---- C:\ProgramData\NVIDIA
2016-03-16 14:50:27 ----A---- C:\WINDOWS\system32\nvvsvc.exe
2016-03-16 14:50:27 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2016-03-16 14:50:27 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2016-03-16 14:50:27 ----A---- C:\WINDOWS\system32\nvshext.dll
2016-03-16 14:50:27 ----A---- C:\WINDOWS\system32\nvmctray.dll
2016-03-16 14:50:27 ----A---- C:\WINDOWS\system32\nvcpl.dll
2016-03-16 14:47:46 ----A---- C:\WINDOWS\system32\OpenCL.dll
2016-03-16 14:47:45 ----D---- C:\ProgramData\NVIDIA Corporation
2016-03-16 14:47:43 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-03-16 14:47:25 ----D---- C:\ProgramData\Package Cache
2016-03-16 14:46:21 ----D---- C:\WINDOWS\system32\MRT
2016-03-16 14:46:21 ----A---- C:\WINDOWS\system32\MRT.exe
2016-03-16 14:43:55 ----D---- C:\Program Files\NVIDIA Corporation
2016-03-16 14:41:45 ----A---- C:\WINDOWS\SYSWOW64\CSVer.dll
2016-03-16 14:37:15 ----D---- C:\WINDOWS\Intel_Chipset_V9301019_LK_XPWin7
2016-03-16 14:37:15 ----A---- C:\WINDOWS\AsTaskSched.dll
2016-03-16 14:36:46 ----A---- C:\WINDOWS\Language_trs.ini
2016-03-16 14:21:27 ----D---- C:\Users\Rambotnik\AppData\Roaming\Mozilla
2016-03-16 14:21:22 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-03-16 14:21:22 ----D---- C:\Program Files (x86)\Mozilla Firefox
2016-03-16 14:14:52 ----A---- C:\WINDOWS\system32\drivers\USB3Ver.dll
2016-03-16 14:13:13 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2016-03-16 14:11:33 ----A---- C:\WINDOWS\system32\drivers\IntelMEFWVer.dll
2016-03-16 14:11:30 ----A---- C:\WINDOWS\SYSWOW64\log.txt
2016-03-16 14:11:29 ----D---- C:\ProgramData\Intel
2016-03-16 14:11:28 ----D---- C:\Program Files\Intel
2016-03-16 14:11:18 ----D---- C:\Program Files (x86)\Intel
2016-03-16 14:11:15 ----D---- C:\Intel
2016-03-16 14:11:15 ----A---- C:\WINDOWS\system32\drivers\HECIx64.sys
2016-03-16 14:09:46 ----D---- C:\dell
2016-03-16 14:04:11 ----D---- C:\Program Files (x86)\Google
2016-03-16 14:02:48 ----A---- C:\WINDOWS\system32\RTNUninst64.dll
2016-03-16 14:02:48 ----A---- C:\WINDOWS\system32\RtNicProp64.dll
2016-03-16 14:02:48 ----A---- C:\WINDOWS\system32\drivers\Rt64win7.sys
2016-03-16 14:02:45 ----D---- C:\Program Files (x86)\Realtek
2016-03-16 14:02:44 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-03-16 13:33:06 ----D---- C:\WINDOWS\SoftwareDistribution
2016-03-16 13:31:56 ----D---- C:\Users\Rambotnik\AppData\Roaming\Identities
2016-03-16 13:31:53 ----D---- C:\Users\Rambotnik\AppData\Roaming\Media Center Programs
2016-03-16 13:28:09 ----SHD---- C:\System Volume Information
2016-03-16 13:28:09 ----ASH---- C:\pagefile.sys
2016-03-16 13:28:09 ----ASH---- C:\hiberfil.sys

======List of files/folders modified in the last 1 month======

2016-03-20 19:53:43 ----RD---- C:\Program Files
2016-03-20 19:44:07 ----D---- C:\WINDOWS\System32
2016-03-20 19:44:07 ----D---- C:\WINDOWS\INF
2016-03-20 19:40:15 ----D---- C:\WINDOWS\Temp
2016-03-20 19:38:06 ----D---- C:\WINDOWS\system32\sru
2016-03-20 18:41:50 ----D---- C:\WINDOWS\rescache
2016-03-20 18:41:36 ----D---- C:\WINDOWS\Microsoft.NET
2016-03-20 18:39:22 ----RSD---- C:\WINDOWS\assembly
2016-03-20 18:30:49 ----D---- C:\WINDOWS\Logs
2016-03-20 15:20:53 ----D---- C:\WINDOWS\system32\WDI
2016-03-20 15:19:31 ----D---- C:\WINDOWS\AppReadiness
2016-03-18 15:38:40 ----D---- C:\WINDOWS\system32\drivers
2016-03-18 15:38:27 ----D---- C:\Windows
2016-03-18 15:26:40 ----D---- C:\WINDOWS\system32\config
2016-03-18 15:26:30 ----D---- C:\WINDOWS\debug
2016-03-18 15:26:09 ----D---- C:\WINDOWS\system32\Tasks
2016-03-18 15:24:04 ----D---- C:\WINDOWS\SysWOW64
2016-03-18 15:22:40 ----D---- C:\Program Files (x86)\Common Files
2016-03-18 15:21:46 ----D---- C:\WINDOWS\system32\DriverStore
2016-03-18 15:21:29 ----D---- C:\WINDOWS\WinSxS
2016-03-18 15:20:57 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2016-03-18 15:20:57 ----D---- C:\WINDOWS\system32\cs-CZ
2016-03-18 12:31:13 ----D---- C:\WINDOWS\CbsTemp
2016-03-18 12:24:17 ----HD---- C:\Program Files\WindowsApps
2016-03-18 12:22:52 ----D---- C:\WINDOWS\appcompat
2016-03-18 12:19:04 ----D---- C:\WINDOWS\SYSWOW64\drivers
2016-03-17 19:44:30 ----RD---- C:\Program Files (x86)
2016-03-17 19:42:16 ----D---- C:\Program Files\Common Files
2016-03-17 19:42:13 ----HD---- C:\ProgramData
2016-03-17 19:42:09 ----RSD---- C:\WINDOWS\Fonts
2016-03-17 19:40:24 ----HD---- C:\WINDOWS\system32\GroupPolicy
2016-03-17 19:40:24 ----D---- C:\WINDOWS\SYSWOW64\GroupPolicy
2016-03-17 19:33:11 ----D---- C:\WINDOWS\SYSWOW64\en-US
2016-03-17 19:33:11 ----D---- C:\WINDOWS\system32\en-US
2016-03-17 19:33:09 ----A---- C:\WINDOWS\SYSWOW64\mqsnap.dll
2016-03-17 19:33:09 ----A---- C:\WINDOWS\SYSWOW64\mqcertui.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\SYSWOW64\wamregps.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\SYSWOW64\mqoa.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\SYSWOW64\iisRtl.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\SYSWOW64\iisrstap.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\SYSWOW64\iisreset.exe
2016-03-17 19:33:08 ----A---- C:\WINDOWS\SYSWOW64\ahadmin.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\SYSWOW64\admwprox.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\system32\wamregps.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\system32\mqrt.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\system32\mqlogmgr.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\system32\iisRtl.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\system32\iisrstap.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\system32\iisreset.exe
2016-03-17 19:33:08 ----A---- C:\WINDOWS\system32\ahadmin.dll
2016-03-17 19:33:08 ----A---- C:\WINDOWS\system32\admwprox.dll
2016-03-17 19:33:07 ----A---- C:\WINDOWS\system32\mqutil.dll
2016-03-17 19:33:07 ----A---- C:\WINDOWS\system32\mqsnap.dll
2016-03-17 19:33:07 ----A---- C:\WINDOWS\system32\mqcertui.dll
2016-03-17 19:33:06 ----A---- C:\WINDOWS\SYSWOW64\mqutil.dll
2016-03-17 19:33:06 ----A---- C:\WINDOWS\SYSWOW64\mqrt.dll
2016-03-17 19:33:06 ----A---- C:\WINDOWS\system32\mqsvc.exe
2016-03-17 19:33:06 ----A---- C:\WINDOWS\system32\mqqm.dll
2016-03-17 19:33:06 ----A---- C:\WINDOWS\system32\mqoa.dll
2016-03-17 19:33:06 ----A---- C:\WINDOWS\system32\mqbkup.exe
2016-03-17 16:38:47 ----D---- C:\WINDOWS\system32\LogFiles
2016-03-17 16:36:42 ----RD---- C:\Users
2016-03-17 13:31:44 ----SHD---- C:\WINDOWS\Installer
2016-03-17 11:38:32 ----SD---- C:\WINDOWS\SYSWOW64\F12
2016-03-17 11:38:32 ----SD---- C:\WINDOWS\SYSWOW64\DiagSvcs
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\winrm
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\WCN
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\wbem
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\Printing_Admin_Scripts
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\oobe
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\MUI
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\migration
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2016-03-17 11:38:32 ----D---- C:\WINDOWS\SYSWOW64\Dism
2016-03-17 11:38:31 ----SD---- C:\WINDOWS\system32\F12
2016-03-17 11:38:31 ----D---- C:\WINDOWS\SYSWOW64\Com
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\winrm
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\WCN
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\wbem
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\Sysprep
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\slmgr
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\Printing_Admin_Scripts
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\oobe
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\MUI
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\migwiz
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\migration
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\inetsrv
2016-03-17 11:38:31 ----D---- C:\WINDOWS\system32\drivers\UMDF
2016-03-17 11:38:30 ----SD---- C:\WINDOWS\system32\DiagSvcs
2016-03-17 11:38:30 ----D---- C:\WINDOWS\system32\Dism
2016-03-17 11:38:29 ----RD---- C:\WINDOWS\PurchaseDialog
2016-03-17 11:38:29 ----RD---- C:\WINDOWS\MiracastView
2016-03-17 11:38:29 ----D---- C:\WINDOWS\system32\Com
2016-03-17 11:38:29 ----D---- C:\WINDOWS\system32\Boot
2016-03-17 11:38:29 ----D---- C:\WINDOWS\servicing
2016-03-17 11:38:29 ----D---- C:\WINDOWS\PolicyDefinitions
2016-03-17 11:38:28 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2016-03-17 11:38:28 ----RD---- C:\WINDOWS\DevicesFlow
2016-03-17 11:38:28 ----D---- C:\WINDOWS\IME
2016-03-17 11:38:28 ----D---- C:\WINDOWS\Help
2016-03-17 11:38:28 ----D---- C:\WINDOWS\AppPatch
2016-03-17 11:38:28 ----D---- C:\Program Files\Windows Photo Viewer
2016-03-17 11:38:28 ----D---- C:\Program Files\Windows Media Player
2016-03-17 11:38:28 ----D---- C:\Program Files\Windows Journal
2016-03-17 11:38:28 ----D---- C:\Program Files\Windows Defender
2016-03-17 11:38:28 ----D---- C:\Program Files\Internet Explorer
2016-03-17 11:38:28 ----D---- C:\Program Files\Common Files\System
2016-03-17 11:38:28 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2016-03-17 11:38:28 ----D---- C:\Program Files (x86)\Windows Media Player
2016-03-17 11:38:28 ----D---- C:\Program Files (x86)\Windows Defender
2016-03-17 11:38:28 ----D---- C:\Program Files (x86)\Internet Explorer
2016-03-17 11:37:50 ----D---- C:\WINDOWS\system32\catroot2
2016-03-17 11:32:41 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2016-03-17 11:32:41 ----D---- C:\WINDOWS\system32\appraiser
2016-03-17 11:32:40 ----RSD---- C:\WINDOWS\Media
2016-03-17 11:32:40 ----D---- C:\WINDOWS\bcastdvr
2016-03-17 11:32:40 ----D---- C:\Program Files\Windows Portable Devices
2016-03-17 11:32:40 ----D---- C:\Program Files\Windows Multimedia Platform
2016-03-17 11:32:40 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-03-17 11:32:40 ----D---- C:\Program Files (x86)\Windows Multimedia Platform
2016-03-17 11:05:14 ----D---- C:\WINDOWS\system32\restore
2016-03-17 10:46:37 ----D---- C:\WINDOWS\OCR
2016-03-17 10:41:52 ----SD---- C:\ProgramData\Microsoft
2016-03-17 10:38:26 ----D---- C:\WINDOWS\system32\WinBioDatabase
2016-03-17 10:38:22 ----D---- C:\WINDOWS\Registration
2016-03-17 10:37:49 ----D---- C:\WINDOWS\system32\drivers\etc
2016-03-17 10:37:00 ----D---- C:\WINDOWS\Tasks
2016-03-17 10:37:00 ----D---- C:\WINDOWS\system32\CodeIntegrity
2016-03-17 10:36:41 ----D---- C:\WINDOWS\SYSWOW64\migwiz
2016-03-17 10:36:41 ----D---- C:\WINDOWS\SYSWOW64\IME
2016-03-17 10:36:40 ----D---- C:\WINDOWS\system32\NDF
2016-03-17 10:36:40 ----D---- C:\WINDOWS\system32\IME
2016-03-17 10:36:37 ----D---- C:\WINDOWS\schemas
2016-03-17 10:36:36 ----SD---- C:\WINDOWS\Downloaded Program Files
2016-03-17 10:36:36 ----D---- C:\WINDOWS\ehome
2016-03-17 10:36:35 ----SHD---- C:\Program Files\Windows Sidebar
2016-03-17 10:36:35 ----SHD---- C:\Program Files (x86)\Windows Sidebar
2016-03-17 10:36:35 ----D---- C:\Program Files\DVD Maker
2016-03-17 10:36:34 ----D---- C:\Program Files\Common Files\microsoft shared
2016-03-17 10:36:30 ----D---- C:\WINDOWS\system32\Recovery
2016-03-16 13:31:56 ----SHD---- C:\$Recycle.Bin
2016-03-16 13:28:15 ----D---- C:\WINDOWS\CSC
2016-03-08 11:27:23 ----A---- C:\WINDOWS\SYSWOW64\nvwgf2um.dll
2016-03-08 11:27:23 ----A---- C:\WINDOWS\system32\nvwgf2umx.dll
2016-03-08 11:27:23 ----A---- C:\WINDOWS\system32\nvhdagenco6420103.dll
2016-03-08 08:12:26 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R1 QMUdisk;tencent QMUdisk; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QMUdisk64.sys [2016-03-02 184536]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R2 TAOKernelDriver;Tencent Auto Optimize Platform.; \??\C:\WINDOWS\system32\Drivers\TAOKernelEx64.sys [2016-03-17 141944]
R3 CT20XUT.SYS;CT20XUT.SYS; C:\WINDOWS\System32\drivers\CT20XUT.SYS [2015-12-19 232704]
R3 ctaud2k;@oem22.inf,%CTAUD2K.SvcDesc%;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2015-12-19 703360]
R3 CTEXFIFX.SYS;CTEXFIFX.SYS; C:\WINDOWS\System32\drivers\CTEXFIFX.SYS [2015-12-19 1448192]
R3 CTHWIUT.SYS;CTHWIUT.SYS; C:\WINDOWS\System32\drivers\CTHWIUT.SYS [2015-12-19 97536]
R3 ctprxy2k;@oem22.inf,%CTPRXY2K.SvcDesc%;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2015-12-19 18176]
R3 ctsfm2k;@oem22.inf,%CTSFM2K.SvcDesc%;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\drivers\ctsfm2k.sys [2015-12-19 215296]
R3 emupia;@oem22.inf,%EMUPIA.SvcDesc%;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2015-12-19 120576]
R3 ha20x22k;@oem22.inf,%HA20X2.SvcDesc%;Creative 20X2 HAL Driver; C:\WINDOWS\system32\drivers\ha20x22k.sys [2015-12-19 1617664]
R3 MEIx64;@oem12.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2012-07-02 62784]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2016-03-17 175616]
R3 NVHDA;@oem18.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2016-03-08 205456]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\system32\DRIVERS\nvlddmkm.sys [2016-03-10 12653504]
R3 nvvad_WaveExtensible;@oem20.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2016-03-08 47760]
R3 ossrv;@oem22.inf,%OSSRV.SvcDesc%;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2015-12-19 181504]
R3 RTL8167;@oem14.inf,%rtl8167.Service.DispName%;Realtek 8167 NT Driver; C:\WINDOWS\system32\DRIVERS\Rt64win7.sys [2016-02-19 1027840]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S1 SRepairDrv;SRepairDrv; \??\C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\SRepairDrv [2016-03-18 168568]
S1 TSDefenseBt;TSDefenseBt; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TSDefenseBT64.sys []
S2 QQSysMonX64;QQSysMonX64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQSysMonX64.sys []
S2 tsnethlpx64;TsNetHlpX64.sys; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TsNetHlpX64.sys []
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2016-02-13 117248]
S3 CT20XUT;CT20XUT; C:\WINDOWS\system32\drivers\CT20XUT.SYS [2015-12-19 232704]
S3 ctac32k;@oem22.inf,%CTAC32K.SvcDesc%;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2015-12-19 582912]
S3 CTEXFIFX;CTEXFIFX; C:\WINDOWS\system32\drivers\CTEXFIFX.SYS [2015-12-19 1448192]
S3 CTHWIUT;CTHWIUT; C:\WINDOWS\system32\drivers\CTHWIUT.SYS [2015-12-19 97536]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 ha20x2k;@oem22.inf,%HA20X.SvcDesc%;Creative 20X HAL Driver; C:\WINDOWS\system32\drivers\ha20x2k.sys [2015-12-19 1572608]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 softaal;softaal; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\softaal64.sys []
S3 TAOAccelerator;Tencent TAOAccelerator driver.; \??\C:\WINDOWS\system32\Drivers\TAOAccelerator64.sys [2016-03-17 99480]
S3 TFsFlt;TFsFlt; C:\WINDOWS\system32\Drivers\TFsFltX64.sys [2016-03-17 97400]
S3 TS888x64;TS888x64; \??\C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\TS888x64.sys [2016-03-18 38520]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2010-02-12 286720]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-03-08 1164672]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-04-20 635104]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2012-07-18 165760]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2012-07-18 276864]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2016-03-17 26624]
R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-03-08 1880960]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2016-03-08 1264064]
R2 OneSyncSvc_2d2be;Sync Host_2d2be; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2016-03-08 424384]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 ggbugreport;ggbugreport; C:\Program Files (x86)\SearchesToYesbnd\bugreport.exe [2016-03-15 1592888]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-16 154440]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-10-30 135848]
S2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-03-08 2609024]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 QQPCRTP;QQPCMgr RTP Service; C:\Program Files (x86)\Tencent\QQPCMgr\11.4.17347.218\QQPCRTP.exe -r []
S2 QQRepairFixSVC;QQRepairFixSVC; C:\Program Files (x86)\Tencent\QQPCMGR\Plugins\QQRepairFixSVC []
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2015-07-09 327296]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-10-30 51376]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2016-03-18 79360]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EasyAntiCheat;EasyAntiCheat; C:\WINDOWS\syswow64\EasyAntiCheat.exe [2016-03-17 240416]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-24 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-16 154440]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2d2be;MessagingService_2d2be; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-03-04 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-03-08 6474112]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2d2be;Contact Data_2d2be; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-03-10 835152]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118244
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: antivir hlásí hrozby

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět