Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Prosím kontrola (před reinstallem)

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Sertr
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 19 bře 2010 07:47

Prosím kontrola (před reinstallem)

#1 Příspěvek od Sertr »

Budu provádět reinstall a rád bych znal stav současného systému (a případně jestli lze bezpečně převést data)



Logfile of random's system information tool 1.10 (written by random/random)
Run by RoyalSertr at 2017-11-06 14:45:29
Microsoft Windows 10 Pro
System drive C: has 147 GB (64%) free of 228 GB
Total RAM: 8130 MB (59% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 14:45:31, on 06.11.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.15063.0608)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
D:\Programs\AI Suite III\AISuite3.exe
D:\Programs\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
D:\Programs\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
D:\Programs\Corsair\Corsair Utility Engine\CUE.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files\trend micro\RoyalSertr.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll
O2 - BHO: Microsoft Web Test Recorder 10.0 Helper - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - D:\Programs\Visual Studio 2012 Ultimate\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKLM\..\Run: [Corsair Utility Engine] "D:\Programs\Corsair\Corsair Utility Engine\CUE.exe" --autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [OneDrive] "C:\Users\RoyalSertr\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "D:\Programs\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASUS Com Service (asComSvc) - Unknown owner - C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
O23 - Service: ASUS HM Com Service (asHmComSvc) - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe
O23 - Service: AsusFanControlService - ASUSTeK Computer Inc. - C:\Program Files (x86)\ASUS\AsusFanControlService\1.03.03\AsusFanControlService.exe
O23 - Service: aswbIDSAgent - AVAST Software s.r.o. - D:\Programs\AVAST Software\Avast\x64\aswidsagenta.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - D:\Programs\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Avast Firewall Service (avast! Firewall) - AVAST Software - D:\Programs\AVAST Software\Avast\afwServ.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: DbxSvc - Unknown owner - C:\WINDOWS\system32\DbxSvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: HuaweiHiSuiteService64.exe - Unknown owner - C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
O23 - Service: Origin Client Service - Electronic Arts - D:\Programs\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - D:\Programs\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001 (Sense) - Unknown owner - C:\Program Files (x86)\Windows Defender Advanced Threat Protection\MsSense.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13251 bytes

======Listing Processes======









winlogon.exe
c:\windows\system32\svchost.exe -k dcomlaunch -s PlugPlay
"fontdrvhost.exe"
"fontdrvhost.exe"
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
c:\windows\system32\svchost.exe -k rpcss
c:\windows\system32\svchost.exe -k dcomlaunch -s LSM
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s NcbService
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s TimeBrokerSvc
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-0fd16310-2924-45bc-b7d6-025ca080ecf5 -SystemEventPortName:HostProcess-d28100d8-1ef7-41ec-8a7c-303aebc4fb1a -IoCancelEventPortName:HostProcess-c66bd1aa-ce64-4381-b6e2-5bc7cc1e0d54 -NonStateChangingEventPortName:HostProcess-23fc66e7-cca7-4c78-a94e-bcacb9bf7555 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:399e1b6c-28ad-49e4-9cde-b41d56cb709a -DeviceGroupId:WudfDefaultDevicePool
c:\windows\system32\svchost.exe -k netsvcs -s Schedule
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s hidserv
c:\windows\system32\svchost.exe -k netsvcs -s ProfSvc
c:\windows\system32\svchost.exe -k netsvcs -s UserManager
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s EventLog
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
c:\windows\system32\svchost.exe -k localservice -s nsi
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s Dhcp
c:\windows\system32\svchost.exe -k netsvcs -s Themes
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s CscService
c:\windows\system32\svchost.exe -k networkservice -s NlaSvc
c:\windows\system32\svchost.exe -k localservice -s EventSystem
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
c:\windows\system32\svchost.exe -k netsvcs -s SENS
c:\windows\system32\svchost.exe -k localservice -s netprofm
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s AudioEndpointBuilder
c:\windows\system32\svchost.exe -k localservice -s FontCache
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k appmodel -s StateRepository
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
c:\windows\system32\svchost.exe -k networkservice -s Dnscache
c:\windows\system32\svchost.exe -k netsvcs -s ShellHWDetection

c:\windows\system32\svchost.exe -k localservice -s WinHttpAutoProxySvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s lmhosts
C:\WINDOWS\System32\spoolsv.exe
c:\windows\system32\svchost.exe -k networkservice -s LanmanWorkstation

C:\WINDOWS\system32\AUDIODG.EXE 0x4c0
c:\windows\system32\svchost.exe -k netsvcs -s LanmanServer
c:\windows\system32\svchost.exe -k netsvcs -s Browser
c:\windows\system32\svchost.exe -k apphost -s AppHostSvc
c:\windows\system32\svchost.exe -k networkservice -s CryptSvc
"C:\Program Files\Intel\iCLS Client\HeciServer.exe"
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files\Bonjour\mDNSResponder.exe"
"C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe" -/service
"C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe"
"C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
"C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin"
C:\Windows\system32\IProsetMonitor.exe
"C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe"
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s DeviceAssociationService
c:\windows\system32\svchost.exe -k localservicenonetwork -s DPS
c:\windows\system32\svchost.exe -k iissvcs
C:\WINDOWS\System32\svchost.exe -k utcsvc
C:\WINDOWS\SysWOW64\PnkBstrA.exe
c:\windows\system32\svchost.exe -k netsvcs -s IKEEXT
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s PcaSvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s SysMain
C:\WINDOWS\system32\DbxSvc.exe
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service

c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s TrkWks
"C:\Program Files (x86)\ASUS\AsusFanControlService\1.03.03\AsusFanControlService.exe"
c:\windows\system32\svchost.exe -k netsvcs -s WpnService
c:\windows\system32\svchost.exe -k netsvcs -s Winmgmt
C:\WINDOWS\SysWOW64\PnkBstrB.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\windows\system32\svchost.exe -k appmodel -s tiledatamodelsvc
C:\WINDOWS\system32\mqsvc.exe
"D:\Programs\Origin\OriginWebHelperService.exe"

c:\windows\system32\svchost.exe -k localservice -s WdiServiceHost
c:\windows\system32\svchost.exe -k netsvcs -s iphlpsvc
dashost.exe {c3e179e9-29ae-42b9-bcea38957e3a7be0}
c:\windows\system32\svchost.exe -k localserviceandnoimpersonation -s SSDPSRV
c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe
"c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe" -netmsmqactivator
C:\WINDOWS\system32\wbem\wmiprvse.exe
c:\windows\system32\svchost.exe -k localservice -s CDPSvc
c:\windows\system32\svchost.exe -k localservicenetworkrestricted -s wscsvc
c:\windows\system32\svchost.exe -k networkservicenetworkrestricted -s PolicyAgent

"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
sihost.exe
c:\windows\system32\svchost.exe -k unistacksvcgroup -s CDPUserSvc
c:\windows\system32\svchost.exe -k unistacksvcgroup -s WpnUserService
c:\windows\system32\svchost.exe -k netsvcs -s TokenBroker
"C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe" /c
"D:\Programs\AI Suite III\AISuite3.exe"
"D:\Programs\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe"
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\WINDOWS\Explorer.EXE
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s WdiSystemHost
"C:/Program Files/NVIDIA Corporation/Display/nvtray.exe" -user_has_logged_in 1"
"D:\Programs\Mozilla Firefox\firefox.exe"
"D:\Programs\Mozilla Firefox\firefox.exe" -contentproc --channel="8096.0.1093146023\1726466251" -greomni "D:\Programs\Mozilla Firefox\omni.ja" -appomni "D:\Programs\Mozilla Firefox\browser\omni.ja" -appdir "D:\Programs\Mozilla Firefox\browser" 8096 "\\.\pipe\gecko-crash-server-pipe.8096" gpu
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
"D:\Programs\Mozilla Firefox\firefox.exe" -contentproc --channel="8096.13.1299666891\965790971" -childID 2 -isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|49:0|51:400|52:1|53:0|54:0|59:0|60:120|61:120|92:2|93:1|107:5000|118:0|120:0|131:10000|143:-1|148:128|149:10000|150:0|156:24|157:32768|159:0|160:0|168:5|172:1048576|173:100|174:5000|176:600|178:1|187:3|191:0|201:60000| -boolPrefs 1:0|2:0|4:0|26:1|27:1|30:0|35:1|36:0|37:0|38:0|41:1|42:1|45:0|46:0|47:0|48:0|50:0|55:1|56:1|57:0|58:1|62:1|63:1|64:0|65:1|66:1|67:0|68:1|71:0|72:0|75:1|76:1|80:1|81:1|82:1|83:0|84:0|86:0|87:0|88:1|89:0|94:1|95:0|101:0|106:0|109:1|110:1|113:1|115:1|119:0|122:1|125:1|126:1|132:0|133:0|134:1|136:0|142:0|144:1|145:0|146:1|147:0|154:0|155:0|158:1|161:0|163:1|165:1|166:0|171:0|175:1|180:0|181:0|182:0|183:1|184:0|185:0|186:1|189:0|193:0|194:0|195:1|196:1|197:0|198:1|199:1|200:1|202:0|203:0|205:0|213:1|214:1|215:0|216:0|217:0| -stringPrefs "3:7;release|135:3;1.0|152:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|153:8;moderate|188:38;{7625dc55-5d9e-4ef8-b350-eba69784cd27}|" -greomni "D:\Programs\Mozilla Firefox\omni.ja" -appomni "D:\Programs\Mozilla Firefox\browser\omni.ja" -appdir "D:\Programs\Mozilla Firefox\browser" 8096 "\\.\pipe\gecko-crash-server-pipe.8096" tab
c:\windows\system32\svchost.exe -k localservice -s LicenseManager
"D:\Programs\Mozilla Firefox\firefox.exe" -contentproc --channel="8096.20.825976864\991101885" -childID 3 -isForBrowser -intPrefs 5:50|6:-1|28:1000|33:20|34:10|43:128|44:10000|49:0|51:400|52:1|53:0|54:0|59:0|60:120|61:120|92:2|93:1|107:5000|118:0|120:0|131:10000|143:-1|148:128|149:10000|150:0|156:24|157:32768|159:0|160:0|168:5|172:1048576|173:100|174:5000|176:600|178:1|187:3|191:0|201:60000| -boolPrefs 1:0|2:0|4:0|26:1|27:1|30:0|35:1|36:0|37:0|38:0|41:1|42:1|45:0|46:0|47:0|48:0|50:0|55:1|56:1|57:0|58:1|62:1|63:1|64:0|65:1|66:1|67:0|68:1|71:0|72:0|75:1|76:1|80:1|81:1|82:1|83:0|84:0|86:0|87:0|88:1|89:0|94:1|95:0|101:0|106:0|109:1|110:1|113:1|115:1|119:0|122:1|125:1|126:1|132:0|133:0|134:1|136:0|142:0|144:1|145:0|146:1|147:0|154:0|155:0|158:1|161:0|163:1|165:1|166:0|171:0|175:1|180:0|181:0|182:0|183:1|184:0|185:0|186:1|189:0|193:0|194:0|195:1|196:1|197:0|198:1|199:1|200:1|202:0|203:0|205:0|213:1|214:1|215:0|216:0|217:0| -stringPrefs "3:7;release|135:3;1.0|152:332;  ¼½¾ǃː̷̸։֊׃״؉؊٪۔܁܂܃܄ᅟᅠ᜵           ​‎‏‐’․‧

‪‫‬‭‮ ‹›⁁⁄⁒ ⅓⅔⅕⅖⅗⅘⅙⅚⅛⅜⅝⅞⅟∕∶⎮╱⧶⧸⫻⫽⿰⿱⿲⿳⿴⿵⿶⿷⿸⿹⿺⿻ 。〔〕〳゠ㅤ㈝㈞㎮㎯㏆㏟꞉︔︕︿﹝﹞./。ᅠ�|153:8;moderate|188:38;{7625dc55-5d9e-4ef8-b350-eba69784cd27}|" -greomni "D:\Programs\Mozilla Firefox\omni.ja" -appomni "D:\Programs\Mozilla Firefox\browser\omni.ja" -appdir "D:\Programs\Mozilla Firefox\browser" 8096 "\\.\pipe\gecko-crash-server-pipe.8096" tab
c:\windows\system32\svchost.exe -k netsvcs
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\iTunes\iTunesHelper.exe"
AvastUI.exe /nogui
D:\Programs\CCleaner\CCleaner.exe /MONITOR /uac
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" -type:crashpad-handler --no-upload-gzip --no-rate-limit --database=C:\Users\RoyalSertr\AppData\Local\Dropbox\Crashpad --metrics-dir=0 --url=https://d.dropbox.com/report_crashpad_minidump --https-pin=0x23,0xf2,0xed,0xff,0x3e,0xde,0x90,0x25,0x9a,0x9e,0x30,0xf4,0xa,0xf8,0xf9,0x12,0xa5,0xe5,0xb3,0x69,0x4e,0x69,0x38,0x44,0x3,0x41,0xf6,0x6,0xe,0x1,0x4f,0xfa --https-pin=0xaf,0xf9,0x88,0x90,0x6d,0xde,0x12,0x95,0x5d,0x9b,0xeb,0xbf,0x92,0x8f,0xdc,0xc3,0x1c,0xce,0x32,0x8d,0x5b,0x93,0x84,0xf2,0x1c,0x89,0x41,0xca,0x26,0xe2,0x3,0x91 --https-pin=0x5a,0x88,0x96,0x47,0x22,0xe,0x54,0xd6,0xbd,0x8a,0x16,0x81,0x72,0x24,0x52,0xb,0xb5,0xc7,0x8e,0x58,0x98,0x4b,0xd5,0x70,0x50,0x63,0x88,0xb9,0xde,0xf,0x7,0x5f --https-pin=0xfe,0xa2,0xb7,0xd6,0x45,0xfb,0xa7,0x3d,0x75,0x3c,0x1e,0xc9,0xa7,0x87,0xc,0x40,0xe1,0xf7,0xb0,0xc5,0x61,0xe9,0x27,0xb9,0x85,0xbf,0x71,0x18,0x66,0xe3,0x6f,0x22 --https-pin=0x76,0xee,0x85,0x90,0x37,0x4c,0x71,0x54,0x37,0xbb,0xca,0x6b,0xba,0x60,0x28,0xea,0xdd,0xe2,0xdc,0x6d,0xbb,0xb8,0xc3,0xf6,0x10,0xe8,0x51,0xf1,0x1d,0x1a,0xb7,0xf5 --https-pin=0x6d,0xbf,0xae,0x0,0xd3,0x7b,0x9c,0xd7,0x3f,0x8f,0xb4,0x7d,0xe6,0x59,0x17,0xaf,0x0,0xe0,0xdd,0xdf,0x42,0xdb,0xce,0xac,0x20,0xc1,0x7c,0x2,0x75,0xee,0x20,0x95 --https-pin=0x1e,0xa3,0xc5,0xe4,0x3e,0xd6,0x6c,0x2d,0xa2,0x98,0x3a,0x42,0xa4,0xa7,0x9b,0x1e,0x90,0x67,0x86,0xce,0x9f,0x1b,0x58,0x62,0x14,0x19,0xa0,0x4,0x63,0xa8,0x7d,0x38 --https-pin=0x87,0xaf,0x34,0xd6,0x6f,0xb3,0xf2,0xfd,0xf3,0x6e,0x9,0x11,0x1e,0x9a,0xba,0x2f,0x6f,0x44,0xb2,0x7,0xf3,0x86,0x3f,0x3d,0xb,0x54,0xb2,0x50,0x23,0x90,0x9a,0xa5 --https-pin=0xbc,0xfb,0x44,0xaa,0xb9,0xad,0x2,0x10,0x15,0x70,0x6b,0x41,0x21,0xea,0x76,0x1c,0x81,0xc9,0xe8,0x89,0x67,0x59,0xf,0x6f,0x94,0xae,0x74,0x4d,0xc8,0x8b,0x78,0xfb --https-pin=0xab,0x98,0x49,0x52,0x76,0xad,0xf1,0xec,0xaf,0xf2,0x8f,0x35,0xc5,0x30,0x48,0x78,0x1e,0x5c,0x17,0x18,0xda,0xb9,0xc8,0xe6,0x7a,0x50,0x4f,0x4f,0x6a,0x51,0x32,0x8f --https-pin=0x49,0x5,0x46,0x66,0x23,0xab,0x41,0x78,0xbe,0x92,0xac,0x5c,0xbd,0x65,0x84,0xf7,0xa1,0xe1,0x7f,0x27,0x65,0x2d,0x5a,0x85,0xaf,0x89,0x50,0x4e,0xa2,0x39,0xaa,0xaa --https-pin=0x56,0x32,0xd9,0x7b,0xfa,0x77,0x5b,0xf3,0xc9,0x9d,0xde,0xa5,0x2f,0xc2,0x55,0x34,0x10,0x86,0x40,0x16,0x72,0x9c,0x52,0xdd,0x65,0x24,0xc8,0xa9,0xc3,0xb4,0x48,0x9f --https-pin=0x2a,0x8f,0x2d,0x8a,0xf0,0xeb,0x12,0x38,0x98,0xf7,0x4c,0x86,0x6a,0xc3,0xfa,0x66,0x90,0x54,0xe2,0x3c,0x17,0xbc,0x7a,0x95,0xbd,0x2,0x34,0x19,0x2d,0xc6,0x35,0xd0 --https-pin=0x32,0xb6,0x4b,0x66,0x72,0x7a,0x20,0x63,0xe4,0x6,0x6f,0x3b,0x95,0x8c,0xb0,0xaa,0xee,0x57,0x6a,0x5e,0xce,0xfd,0x95,0x33,0x99,0xbb,0x88,0x74,0x73,0x1d,0x95,0x87 --https-pin=0xf5,0x3c,0x22,0x5,0x98,0x17,0xdd,0x96,0xf4,0x0,0x65,0x16,0x39,0xd2,0xf8,0x57,0xe2,0x10,0x70,0xa5,0x9a,0xbe,0xd9,0x7,0x94,0x0,0xd9,0xf6,0x95,0x50,0x69,0x0 --https-pin=0x67,0xdc,0x4f,0x32,0xfa,0x10,0xe7,0xd0,0x1a,0x79,0xa0,0x73,0xaa,0xc,0x9e,0x2,0x12,0xec,0x2f,0xfc,0x3d,0x77,0x9e,0xa,0xa7,0xf9,0xc0,0xf0,0xe1,0xc2,0xc8,0x93 --https-pin=0x19,0x6,0xc6,0x12,0x4d,0xbb,0x43,0x85,0x78,0xd0,0xe,0x6,0x6d,0x50,0x54,0xc6,0xc3,0x7f,0xf,0xa6,0x2,0x8c,0x5,0x54,0x5e,0x9,0x94,0xed,0xda,0xec,0x86,0x29 --https-pin=0x1d,0x75,0xd0,0x83,0x1b,0x9e,0x8,0x85,0x39,0x4d,0x32,0xc7,0xa1,0xbf,0xdb,0x3d,0xbc,0x1c,0x28,0xe2,0xb0,0xe8,0x39,0x1f,0xb1,0x35,0x98,0x1d,0xbc,0x5b,0xa9,0x36 --annotation=buildno=Dropbox-win-38.4.27 --annotation=client_session_id=95ea41a8-a530-4c06-b963-b323797d3bf6 --annotation=host_int_account1_boot=15428141024 --annotation=machine_id=8c9e7390-8ad3-422a-9935-141b16c7f98c --annotation=platform=win --annotation=platform_version=10 --initial-client-data=0x1dc,0x1c8,0x1e0,0x1e4,0x1e8,0x6a5b5dc0,0x6a5b5dd0,0x6a5b5de0
"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" -type:exit-monitor -session-token:95ea41a8-a530-4c06-b963-b323797d3bf6 -target-handle:484 -target-shutdown-event:488 "-target-command-line:\"C:\Program Files (x86)\Dropbox\Client\Dropbox.exe\" /systemstartup" -method:collectupload -handler-pipe:\\.\pipe\crashpad_11452_TNHUOMZGOOCGHVIM
"C:\Program Files\iPod\bin\iPodService.exe"
"D:\Programs\Corsair\Corsair Utility Engine\CUE.exe" --autorun
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
c:\windows\system32\svchost.exe -k unistacksvcgroup
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
c:\windows\system32\svchost.exe -k netsvcs -s Appinfo
"D:\Downloads\FRST64.exe"
C:\WINDOWS\system32\vssvc.exe
C:\WINDOWS\System32\svchost.exe -k swprv
notepad "D:\Downloads\FRST.txt"
notepad "D:\Downloads\Addition.txt"
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:App.AppXe9cvj1thv1hmcw0cs98xm3r97tyzy2xs.mca

"D:\Downloads\RSITx64.exe"
C:\Windows\System32\smartscreen.exe -Embedding
taskhostw.exe -RegisterDevice -ProtectionStateChanged -FreeNetworkOnly -NoLocation
C:\WINDOWS\system32\svchost.exe -k netsvcs -s wlidsvc
c:\windows\system32\svchost.exe -k netsvcs -s lfsvc
c:\windows\system32\svchost.exe -k localsystemnetworkrestricted -s StorSvc


======Scheduled tasks folder======

C:\WINDOWS\tasks\DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
C:\WINDOWS\tasks\DropboxUpdateTaskMachineUA.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\RoyalSertr\AppData\Roaming\Mozilla\Firefox\Profiles\vzb42xmv.default-1460553524321

prefs.js - "browser.search.useDBForOrder" - true
prefs.js - "browser.startup.homepage" - "about:newtab"

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 27.0.0.183 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1229199.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.151.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.151.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@t.garena.com/garenatalk]
"Description"=Garena Talk Plugin
"Path"=D:\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 27.0.0.183 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.131.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.131.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-09-05 229064]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-04-24 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-09-05 896288]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-09-05 2351920]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-24 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2017-08-15 163536]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-27 473664]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{876d9f09-c6d6-4324-a2cc-04dd9a4de12f}]
Microsoft Web Test Recorder 10.0 Helper - D:\Programs\Visual Studio 2012 Ultimate\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26 74888]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2017-09-05 1744688]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-27 187968]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\Program Files\Windows Defender\MSASCuiL.exe [2017-03-18 629152]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2015-06-12 8484056]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2017-05-03 1893496]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2017-09-11 297784]
"AvastUI.exe"=D:\Programs\AVAST Software\Avast\AvLaunch.exe [2017-10-12 253344]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\RoyalSertr\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2017-09-22 1686736]
"CCleaner Monitoring"=D:\Programs\CCleaner\CCleaner64.exe [2017-09-20 9856176]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Autodesk Sync]
C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GalaxyClient]
[]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
D:\Programs\iTunes\iTunesHelper.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogMeIn Hamachi Ui]
D:\Programs\LogMeIn Hamachi\hamachi-2-ui.exe --auto-start []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^RoyalSertr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk]
C:\Users\ROYALS~1\AppData\Roaming\Dropbox\bin\Dropbox.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^RoyalSertr^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk]
D:\Programs\MICROS~1\Office14\ONENOTEM.EXE []

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Dropbox"=C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [2017-11-01 3567928]
"Corsair Utility Engine"=D:\Programs\Corsair\Corsair Utility Engine\CUE.exe [2017-08-04 18848976]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-09-05 587288]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DisableTaskMgr"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-11-06 14:45:29 ----D---- C:\rsit
2017-11-06 14:45:29 ----D---- C:\Program Files\trend micro
2017-11-06 14:43:09 ----D---- C:\FRST
2017-11-06 12:33:36 ----D---- C:\ProgramData\SWCUTemp
2017-11-01 12:58:30 ----A---- C:\WINDOWS\system32\drivers\dbx-stable.sys
2017-11-01 12:58:30 ----A---- C:\WINDOWS\system32\drivers\dbx-dev.sys
2017-11-01 12:58:30 ----A---- C:\WINDOWS\system32\drivers\dbx-canary.sys
2017-11-01 12:58:30 ----A---- C:\WINDOWS\system32\DbxSvc.exe
2017-10-27 15:58:08 ----A---- C:\WINDOWS\SYSWOW64\nativelog.txt
2017-10-23 11:28:33 ----A---- C:\WINDOWS\system32\drivers\aswNetSec.sys
2017-10-23 11:28:31 ----A---- C:\WINDOWS\system32\aswBoot.exe
2017-10-10 19:58:10 ----AC---- C:\WINDOWS\system32\MRT-KB890830.exe
2017-10-10 19:56:00 ----A---- C:\WINDOWS\SYSWOW64\rpchttp.dll
2017-10-10 19:56:00 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2017-10-10 19:56:00 ----A---- C:\WINDOWS\system32\tquery.dll
2017-10-10 19:55:59 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2017-10-10 19:55:59 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2017-10-10 19:55:59 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2017-10-10 19:55:59 ----A---- C:\WINDOWS\SYSWOW64\msIso.dll
2017-10-10 19:55:59 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2017-10-10 19:55:59 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-10-10 19:55:59 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.dll
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerUI.dll
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\dbgeng.dll
2017-10-10 19:55:58 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2017-10-10 19:55:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-10-10 19:55:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2017-10-10 19:55:57 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2017-10-10 19:55:57 ----A---- C:\WINDOWS\SYSWOW64\oleaut32.dll
2017-10-10 19:55:57 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2017-10-10 19:55:57 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-10-10 19:55:57 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2017-10-10 19:55:57 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-10-10 19:55:56 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-10-10 19:55:56 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-10-10 19:55:56 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2017-10-10 19:55:56 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-10-10 19:55:56 ----A---- C:\WINDOWS\SYSWOW64\twinapi.appcore.dll
2017-10-10 19:55:56 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-10-10 19:55:55 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-10-10 19:55:55 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-10-10 19:55:55 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2017-10-10 19:55:55 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-10-10 19:55:54 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-10-10 19:55:54 ----A---- C:\WINDOWS\SYSWOW64\TpmCoreProvisioning.dll
2017-10-10 19:55:54 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-10-10 19:55:54 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-10-10 19:55:54 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2017-10-10 19:55:53 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-10-10 19:55:53 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2017-10-10 19:55:53 ----A---- C:\WINDOWS\SYSWOW64\AppVEntSubsystems32.dll
2017-10-10 19:55:53 ----A---- C:\WINDOWS\system32\drivers\BasicRender.sys
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Phone.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\smartscreenps.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\scksp.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\OneCoreUAPCommonProxyStub.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\mswstr10.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\msjint40.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\msexcl40.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\Microsoft.Uev.AppAgent.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\SYSWOW64\basecsp.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\system32\SecurityHealthService.exe
2017-10-10 19:55:52 ----A---- C:\WINDOWS\system32\mssprxy.dll
2017-10-10 19:55:52 ----A---- C:\WINDOWS\system32\drivers\USBHUB3.SYS
2017-10-10 19:55:52 ----A---- C:\WINDOWS\system32\drivers\usbhub.sys
2017-10-10 19:55:51 ----RA---- C:\WINDOWS\SYSWOW64\icuuc.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\Windows.Graphics.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\usoapi.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\twinapi.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\tetheringclient.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\t2embed.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\sspicli.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\Robocopy.exe
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\resutils.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\mcbuilder.exe
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\clusapi.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2017-10-10 19:55:51 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2017-10-10 19:55:50 ----A---- C:\WINDOWS\SYSWOW64\webio.dll
2017-10-10 19:55:50 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2017-10-10 19:55:50 ----A---- C:\WINDOWS\SYSWOW64\Microsoft.Uev.Office2013CustomActions.dll
2017-10-10 19:55:50 ----A---- C:\WINDOWS\SYSWOW64\mgmtapi.dll
2017-10-10 19:55:50 ----A---- C:\WINDOWS\SYSWOW64\FirewallAPI.dll
2017-10-10 19:55:50 ----A---- C:\WINDOWS\SYSWOW64\cipher.exe
2017-10-10 19:55:50 ----A---- C:\WINDOWS\SYSWOW64\BitLockerCsp.dll
2017-10-10 19:55:49 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2017-10-10 19:55:49 ----A---- C:\WINDOWS\system32\drivers\srv.sys
2017-10-10 19:55:49 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2017-10-10 19:55:48 ----A---- C:\WINDOWS\system32\WWAHost.exe
2017-10-10 19:55:48 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2017-10-10 19:55:47 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-10-10 19:55:44 ----A---- C:\WINDOWS\system32\UserDataService.dll
2017-10-10 19:55:44 ----A---- C:\WINDOWS\system32\NgcCtnr.dll
2017-10-10 19:55:44 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-10-10 19:55:44 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2017-10-10 19:55:44 ----A---- C:\WINDOWS\system32\MusNotification.exe
2017-10-10 19:55:44 ----A---- C:\WINDOWS\system32\musdialoghandlers.dll
2017-10-10 19:55:44 ----A---- C:\WINDOWS\system32\cryptngc.dll
2017-10-10 19:55:43 ----A---- C:\WINDOWS\system32\wpdbusenum.dll
2017-10-10 19:55:43 ----A---- C:\WINDOWS\system32\Windows.Graphics.dll
2017-10-10 19:55:43 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-10-10 19:55:43 ----A---- C:\WINDOWS\system32\MusNotifyIcon.exe
2017-10-10 19:55:43 ----A---- C:\WINDOWS\system32\fveui.dll
2017-10-10 19:55:43 ----A---- C:\WINDOWS\system32\bdesvc.dll
2017-10-10 19:55:42 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-10-10 19:55:42 ----A---- C:\WINDOWS\system32\mstsc.exe
2017-10-10 19:55:42 ----A---- C:\WINDOWS\system32\manage-bde.exe
2017-10-10 19:55:42 ----A---- C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2017-10-10 19:55:41 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-10-10 19:55:41 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-10-10 19:55:40 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-10-10 19:55:40 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-10-10 19:55:40 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-10-10 19:55:39 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-10-10 19:55:39 ----A---- C:\WINDOWS\system32\lsass.exe
2017-10-10 19:55:38 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-10-10 19:55:38 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-10-10 19:55:38 ----A---- C:\WINDOWS\system32\BingMaps.dll
2017-10-10 19:55:37 ----A---- C:\WINDOWS\system32\oleaut32.dll
2017-10-10 19:55:37 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-10-10 19:55:36 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2017-10-10 19:55:36 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2017-10-10 19:55:36 ----A---- C:\WINDOWS\system32\drivers\ksecdd.sys
2017-10-10 19:55:35 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\sspisrv.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\sspicli.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\mgmtapi.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\jscript.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\fvewiz.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\fvecpl.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\FntCache.dll
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\bdechangepin.exe
2017-10-10 19:55:35 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-10-10 19:55:34 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-10-10 19:55:34 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2017-10-10 19:55:34 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-10-10 19:55:34 ----A---- C:\WINDOWS\system32\DWrite.dll
2017-10-10 19:55:34 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-10-10 19:55:33 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2017-10-10 19:55:33 ----A---- C:\WINDOWS\system32\wer.dll
2017-10-10 19:55:33 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-10-10 19:55:33 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2017-10-10 19:55:33 ----A---- C:\WINDOWS\system32\dbgeng.dll
2017-10-10 19:55:31 ----A---- C:\WINDOWS\system32\winresume.exe
2017-10-10 19:55:31 ----A---- C:\WINDOWS\system32\winload.exe
2017-10-10 19:55:31 ----A---- C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll
2017-10-10 19:55:31 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2017-10-10 19:55:31 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2017-10-10 19:55:30 ----A---- C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
2017-10-10 19:55:30 ----A---- C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
2017-10-10 19:55:30 ----A---- C:\WINDOWS\system32\eShims.dll
2017-10-10 19:55:30 ----A---- C:\WINDOWS\system32\dnsapi.dll
2017-10-10 19:55:30 ----A---- C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
2017-10-10 19:55:30 ----A---- C:\WINDOWS\system32\AgentService.exe
2017-10-10 19:55:29 ----A---- C:\WINDOWS\system32\wwansvc.dll
2017-10-10 19:55:29 ----A---- C:\WINDOWS\system32\wscsvc.dll
2017-10-10 19:55:29 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-10-10 19:55:29 ----A---- C:\WINDOWS\system32\rpchttp.dll
2017-10-10 19:55:28 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-10-10 19:55:28 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-10-10 19:55:28 ----A---- C:\WINDOWS\system32\msftedit.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\wups.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\WindowManagement.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\usocore.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\twinui.pcshell.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\TokenBrokerUI.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\StartTileData.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\msIso.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\dosvc.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\domgmt.dll
2017-10-10 19:55:27 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2017-10-10 19:55:26 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-10-10 19:55:26 ----A---- C:\WINDOWS\system32\twinui.dll
2017-10-10 19:55:26 ----A---- C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-10-10 19:55:26 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-10-10 19:55:25 ----A---- C:\WINDOWS\system32\wininet.dll
2017-10-10 19:55:25 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-10-10 19:55:25 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2017-10-10 19:55:25 ----A---- C:\WINDOWS\explorer.exe
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\wuuhosdeployment.dll
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\TpmTasks.dll
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\TileDataRepository.dll
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\smartscreenps.dll
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\smartscreen.exe
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\hvloader.exe
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-10-10 19:55:24 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\msctf.dll
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2017-10-10 19:55:23 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-10-10 19:55:22 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-10-10 19:55:22 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-10-10 19:55:22 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-10-10 19:55:22 ----A---- C:\WINDOWS\system32\user32.dll
2017-10-10 19:55:22 ----A---- C:\WINDOWS\system32\quartz.dll
2017-10-10 19:55:22 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-10-10 19:55:22 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-10-10 19:55:22 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2017-10-10 19:55:21 ----A---- C:\WINDOWS\system32\twinapi.appcore.dll
2017-10-10 19:55:21 ----A---- C:\WINDOWS\system32\shell32.dll
2017-10-10 19:55:21 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2017-10-10 19:55:21 ----A---- C:\WINDOWS\system32\msv1_0.dll
2017-10-10 19:55:21 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-10-10 19:55:20 ----A---- C:\WINDOWS\system32\UpdateAgent.dll
2017-10-10 19:55:20 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2017-10-10 19:55:20 ----A---- C:\WINDOWS\system32\RecoveryDrive.exe
2017-10-10 19:55:20 ----A---- C:\WINDOWS\system32\AppVEntSubsystems64.dll
2017-10-10 19:55:20 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\efscore.dll
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\daxexec.dll
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\AppVPublishing.dll
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\AppVOrchestration.dll
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\AppVIntegration.dll
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\AppVEntVirtualization.dll
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\AppVEntSubsystemController.dll
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\AppVClient.exe
2017-10-10 19:55:19 ----A---- C:\WINDOWS\system32\AppVCatalog.dll
2017-10-10 19:55:18 ----A---- C:\WINDOWS\system32\fveapi.dll
2017-10-10 19:55:17 ----A---- C:\WINDOWS\system32\wsp_health.dll
2017-10-10 19:55:17 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2017-10-10 19:55:17 ----A---- C:\WINDOWS\system32\scksp.dll
2017-10-10 19:55:17 ----A---- C:\WINDOWS\system32\dusmsvc.dll
2017-10-10 19:55:17 ----A---- C:\WINDOWS\system32\basecsp.dll
2017-10-10 19:55:17 ----A---- C:\WINDOWS\system32\advapi32.dll
2017-10-10 19:55:16 ----RA---- C:\WINDOWS\system32\icuuc.dll
2017-10-10 19:55:16 ----A---- C:\WINDOWS\system32\wlansec.dll
2017-10-10 19:55:16 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-10-10 19:55:16 ----A---- C:\WINDOWS\system32\resutils.dll
2017-10-10 19:55:16 ----A---- C:\WINDOWS\system32\drivers\nwifi.sys
2017-10-10 19:55:16 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-10-10 19:55:16 ----A---- C:\WINDOWS\system32\drivers\appid.sys
2017-10-10 19:55:16 ----A---- C:\WINDOWS\system32\clusapi.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\webio.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\usoapi.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\twinapi.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\TabSvc.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\t2embed.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\ServiceWorkerHost.exe
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\Robocopy.exe
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\regsvc.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\mcbuilder.exe
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\iscsiexe.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\fveapibase.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\FirewallAPI.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\efssvc.dll
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\easinvoker.exe
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\cipher.exe
2017-10-10 19:55:15 ----A---- C:\WINDOWS\system32\BitLockerCsp.dll

======List of files/folders modified in the last 1 month======

2017-11-06 14:45:29 ----RD---- C:\Program Files
2017-11-06 14:45:29 ----D---- C:\WINDOWS\Prefetch
2017-11-06 14:43:54 ----D---- C:\Windows
2017-11-06 14:41:32 ----D---- C:\WINDOWS\System32
2017-11-06 14:41:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-06 14:38:21 ----D---- C:\WINDOWS\Temp
2017-11-06 14:38:20 ----D---- C:\ProgramData\NVIDIA
2017-11-06 14:36:35 ----A---- C:\WINDOWS\PE_Rom.dll
2017-11-06 12:48:16 ----D---- C:\WINDOWS\system32\sru
2017-11-06 12:44:09 ----D---- C:\Users\RoyalSertr\AppData\Roaming\vlc
2017-11-06 12:33:55 ----RD---- C:\WINDOWS\Microsoft.NET
2017-11-06 12:33:36 ----HD---- C:\ProgramData
2017-11-05 17:46:08 ----D---- C:\WINDOWS\system32\SleepStudy
2017-11-04 17:45:47 ----SHD---- C:\System Volume Information
2017-11-03 18:09:03 ----D---- C:\Program Files (x86)\Dropbox
2017-11-03 18:09:00 ----D---- C:\WINDOWS\system32\drivers
2017-11-02 16:05:42 ----D---- C:\WINDOWS\AppReadiness
2017-11-01 14:03:26 ----HD---- C:\Program Files\WindowsApps
2017-10-31 17:20:51 ----D---- C:\WINDOWS\system32\config
2017-10-31 16:59:21 ----D---- C:\Users\RoyalSertr\AppData\Roaming\BitTorrent
2017-10-30 18:05:50 ----D---- C:\WINDOWS\WinSxS
2017-10-28 11:52:58 ----RSD---- C:\WINDOWS\assembly
2017-10-28 11:28:34 ----SHD---- C:\Config.Msi
2017-10-28 11:28:34 ----RD---- C:\Program Files (x86)
2017-10-27 16:29:54 ----D---- C:\WINDOWS\pss
2017-10-27 16:29:35 ----D---- C:\WINDOWS\system32\Tasks
2017-10-27 16:28:38 ----SHD---- C:\WINDOWS\Installer
2017-10-27 16:28:38 ----D---- C:\WINDOWS\SysWOW64
2017-10-27 16:28:10 ----D---- C:\Program Files (x86)\Google
2017-10-27 16:23:42 ----D---- C:\ProgramData\Skype
2017-10-27 16:23:41 ----D---- C:\Program Files (x86)\Common Files
2017-10-27 16:18:10 ----D---- C:\Program Files\Common Files
2017-10-27 16:16:23 ----RSD---- C:\WINDOWS\Fonts
2017-10-27 16:16:22 ----AD---- C:\ProgramData\Autodesk
2017-10-27 16:04:33 ----D---- C:\Users\RoyalSertr\AppData\Roaming\Wargaming.net
2017-10-27 16:03:11 ----D---- C:\WINDOWS\system32\DriverStore
2017-10-27 16:03:11 ----D---- C:\WINDOWS\INF
2017-10-27 16:03:08 ----D---- C:\ProgramData\Razer
2017-10-27 16:02:44 ----D---- C:\Games
2017-10-27 16:00:22 ----D---- C:\ProgramData\boost_interprocess
2017-10-27 15:54:47 ----D---- C:\Users\RoyalSertr\AppData\Roaming\Doublefine
2017-10-27 15:45:18 ----A---- C:\WINDOWS\SYSWOW64\WindowsAccessBridge-32.dll
2017-10-27 15:45:10 ----D---- C:\Program Files (x86)\Java
2017-10-26 14:22:27 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2017-10-26 14:22:27 ----D---- C:\WINDOWS\system32\Macromed
2017-10-23 12:18:01 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2017-10-23 12:16:26 ----AD---- C:\Program Files\Microsoft Office 15
2017-10-23 11:57:01 ----SD---- C:\Users\RoyalSertr\AppData\Roaming\Microsoft
2017-10-18 23:10:27 ----D---- C:\WINDOWS\system32\catroot2
2017-10-18 14:01:31 ----D---- C:\WINDOWS\CbsTemp
2017-10-13 01:21:46 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2017-10-12 11:49:57 ----A---- C:\WINDOWS\SMSS-PFRO1d9a.tmp
2017-10-12 11:49:50 ----D---- C:\ProgramData\AVAST Software
2017-10-11 13:29:42 ----D---- C:\WINDOWS\rescache
2017-10-11 11:03:21 ----SHD---- C:\Boot
2017-10-10 22:31:47 ----D---- C:\WINDOWS\SYSWOW64\wbem
2017-10-10 22:31:47 ----D---- C:\WINDOWS\SYSWOW64\en-US
2017-10-10 22:31:47 ----D---- C:\WINDOWS\system32\wbem
2017-10-10 22:31:47 ----D---- C:\WINDOWS\system32\migration
2017-10-10 22:31:47 ----D---- C:\WINDOWS\system32\en-US
2017-10-10 22:31:47 ----D---- C:\WINDOWS\system32\Boot
2017-10-10 22:31:47 ----D---- C:\WINDOWS\ShellExperiences
2017-10-10 22:31:47 ----D---- C:\WINDOWS\Provisioning
2017-10-10 22:31:47 ----D---- C:\WINDOWS\PolicyDefinitions
2017-10-10 22:31:36 ----A---- C:\WINDOWS\SYSWOW64\msclmd.dll
2017-10-10 22:31:36 ----A---- C:\WINDOWS\system32\msclmd.dll
2017-10-10 20:00:27 ----D---- C:\WINDOWS\system32\MRT
2017-10-10 19:58:13 ----D---- C:\WINDOWS\debug
2017-10-10 19:58:09 ----AC---- C:\WINDOWS\system32\MRT.exe
2017-10-08 21:04:23 ----D---- C:\Users\RoyalSertr\AppData\Roaming\Origin
2017-10-08 21:00:01 ----D---- C:\ProgramData\Origin

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 asahci64;asahci64; C:\WINDOWS\System32\drivers\asahci64.sys [2013-01-10 47512]
R0 aswbidsh;aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [2017-10-12 198976]
R0 aswblog;aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [2017-10-12 343288]
R0 aswbuniv;aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [2017-10-12 57736]
R0 aswRvrt;aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [2017-10-12 84416]
R0 aswVmm;aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [2017-10-12 363440]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2017-03-18 49568]
R1 AsIO;AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [2013-07-04 15232]
R1 AsUpIO;AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [2012-09-14 14464]
R1 aswbidsdriver;aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [2017-10-12 321032]
R1 aswNetSec;aswNetSec; C:\WINDOWS\system32\drivers\aswNetSec.sys [2017-10-23 556152]
R1 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [2017-10-12 110376]
R1 aswSnx;aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [2017-10-27 1029872]
R1 aswSP;aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [2017-10-12 587168]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2017-03-18 54272]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2017-03-18 8192]
R2 aswMonFlt;aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [2017-10-12 147776]
R2 aswStm;aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [2017-10-12 201352]
R2 atksgt;atksgt; C:\WINDOWS\system32\DRIVERS\atksgt.sys [2015-09-14 314016]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2017-03-18 14336]
R2 lirsgt;lirsgt; C:\WINDOWS\system32\DRIVERS\lirsgt.sys [2015-09-14 43680]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2017-03-18 50688]
R3 CorsairVBusDriver;@oem36.inf,%dev.SVCDESC%;Corsair Bus; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [2017-06-21 45528]
R3 CorsairVHidDriver;@oem27.inf,%dev.SVCDESC%;Corsair virtual device; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [2017-06-21 21968]
R3 e1iexpress;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\System32\drivers\e1i63x64.sys [2017-03-18 524800]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys [2012-08-21 33240]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-06-18 4496600]
R3 MEIx64;@oem57.inf,%HECI_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\HECIx64.sys [2013-03-12 64624]
R3 MQAC;@mqutil.dll,-6101; C:\WINDOWS\system32\drivers\mqac.sys [2017-07-09 177664]
R3 NVHDA;@oem21.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2017-08-03 227416]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_c0f7a2f5b2e4e6e0\nvlddmkm.sys [2017-08-03 15668664]
R3 nvvad_WaveExtensible;@oem81.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2017-05-03 48248]
R3 nvvhci;@oem45.inf,%ServiceDesc%;NVVHCI Enumerator Service; C:\WINDOWS\System32\drivers\nvvhci.sys [2017-05-03 57976]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2017-03-18 123808]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2017-03-18 103328]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2017-03-18 64416]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2017-03-18 58784]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2017-03-18 61848]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2017-03-18 91040]
S2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2017-03-18 12288]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2017-03-18 20480]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2017-03-18 17920]
S3 AppvStrm;@%systemroot%\system32\drivers\AppvStrm.sys,-101; C:\WINDOWS\system32\drivers\AppvStrm.sys [2017-03-19 127904]
S3 AppvVemgr;@%systemroot%\system32\drivers\AppvVemgr.sys,-101; C:\WINDOWS\system32\drivers\AppvVemgr.sys [2017-03-19 161696]
S3 AppvVfs;@%systemroot%\system32\drivers\AppvVfs.sys,-101; C:\WINDOWS\system32\drivers\AppvVfs.sys [2017-03-19 143776]
S3 aswHwid;aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [2017-10-12 47008]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2017-09-05 39424]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2017-03-18 53664]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2017-03-18 122880]
S3 dc1-controller;@dc1-controller.inf,%dc1-controller.SvcDesc%;Xbox Peripherals Driver; C:\WINDOWS\System32\drivers\dc1-controller.sys [2017-03-18 61440]
S3 EvolveVirtualAdapter;Evolve Virtual Miniport Driver; C:\WINDOWS\System32\drivers\evolve.sys [2016-11-19 21656]
S3 ew_usbccgpfilter;@oem68.inf,%busupper.SVCDESC%;HwHandSet_CompositeFilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [2017-04-11 18944]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2017-03-18 21504]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2015-08-06 33856]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2017-03-18 51104]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2017-03-18 74648]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2017-03-18 347032]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2017-03-18 2104224]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2017-03-18 33280]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2017-03-18 81408]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2017-03-18 70656]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2017-03-18 85504]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2017-03-18 165376]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2017-03-18 168448]
S3 iaStorA;iaStorA; C:\WINDOWS\system32\DRIVERS\iaStorA.sys [2013-07-02 667496]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2017-03-18 526240]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2017-03-18 36864]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2017-03-18 120320]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2017-03-18 405408]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2017-03-18 51104]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2017-03-18 842656]
S3 MsSecFlt;@%SystemRoot%\System32\Drivers\mssecflt.sys,-1001; C:\WINDOWS\system32\drivers\mssecflt.sys [2017-03-19 230816]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2017-03-18 108960]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2017-03-18 122368]
S3 nvdimmn;@nvdimmn.inf,%nvdimmn.SvcDesc%;Microsoft NVDIMM-N device driver; C:\WINDOWS\System32\drivers\nvdimmn.sys [2017-03-18 80896]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2017-05-03 30328]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2017-03-18 101376]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2017-03-18 936864]
S3 RzDxgk;RzDxgk; \??\C:\Windows\system32\drivers\RzDxgk.sys [2014-04-18 129472]
S3 rzendpt;@oem44.inf,%rzendpt.SvcDesc%;rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [2015-10-26 50392]
S3 rzmpos;@oem47.inf,%rzmpos.SvcDesc%;rzmpos; C:\WINDOWS\System32\drivers\rzmpos.sys [2015-10-26 47312]
S3 rzudd;@oem84.inf,%Razer.SvcDesc%;Razer Mouse Driver; C:\WINDOWS\System32\drivers\rzudd.sys [2015-10-26 201432]
S3 SDFRd;@SDFRd.inf,%SDFRd.ServiceDesc%;SDF Reflector; C:\WINDOWS\System32\drivers\SDFRd.sys [2017-03-18 31128]
S3 semav6msr64;semav6msr64; \??\C:\Windows\system32\drivers\semav6msr64.sys [2016-03-09 21984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2017-07-19 83032]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 Apple Mobile Device Service;Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2017-09-07 83768]
R2 asComSvc;ASUS Com Service; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [2013-07-04 936728]
R2 asHmComSvc;ASUS HM Com Service; C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe [2013-08-01 954648]
R2 AsusFanControlService;AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.03.03\AsusFanControlService.exe [2013-07-31 1660728]
R2 avast! Antivirus;Avast Antivirus; D:\Programs\AVAST Software\Avast\AvastSvc.exe [2017-10-12 281416]
R2 avast! Firewall;Avast Firewall Service; D:\Programs\AVAST Software\Avast\afwServ.exe [2017-10-23 330832]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2015-08-12 462096]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 CDPUserSvc_5e39d;Connected Devices Platform User Service_5e39d; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2017-09-05 3058416]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 DbxSvc;DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [2017-11-01 51016]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R2 HuaweiHiSuiteService64.exe;HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [2017-04-11 192200]
R2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [2013-02-13 731648]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [2016-02-19 272456]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2013-03-12 169432]
R2 MSMQ;@mqutil.dll,-6102; C:\WINDOWS\system32\mqsvc.exe [2017-07-09 26112]
R2 NetMsmqActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8195; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-18 136360]
R2 NetPipeActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8197; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-18 136360]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03 495224]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2017-07-18 462968]
R2 NvTelemetryContainer;NVIDIA Telemetry Container; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [2017-05-03 450168]
R2 OneSyncSvc_5e39d;Sync Host_5e39d; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
R2 Origin Web Helper Service;Origin Web Helper Service; D:\Programs\Origin\OriginWebHelperService.exe [2017-10-05 3000168]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\syswow64\PnkBstrA.exe [2016-06-18 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\syswow64\PnkBstrB.exe [2016-06-18 107832]
R2 SecurityHealthService;@%systemroot%\system32\SecurityHealthAgent.dll,-1002; C:\WINDOWS\system32\SecurityHealthService.exe [2017-09-30 336320]
R3 aswbIDSAgent;aswbIDSAgent; D:\Programs\AVAST Software\Avast\x64\aswidsagenta.exe [2017-10-12 7446024]
R3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2013-01-02 171632]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2017-09-11 673080]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
R3 PimIndexMaintenanceSvc_5e39d;Contact Data_5e39d; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 dbupdate;Dropbox Update Service (dbupdate); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-01-31 143144]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2013-03-12 366552]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S2 NetTcpActivator;@%systemroot%\Microsoft.NET\Framework64\v4.0.30319\ServiceModelInstallRC.dll,-8199; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2017-03-18 136360]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S2 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2014-09-25 5132888]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-26 272384]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2017-03-18 52920]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2017-05-16 1536520]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 dbupdatem;Dropbox Update Service (dbupdatem); C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-01-31 143144]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DevicesFlowUserSvc_5e39d;DevicesFlow_5e39d; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2017-03-18 86528]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2017-02-10 43696]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [2012-07-25 139776]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2017-09-19 8242752]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2013-02-13 820184]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 MessagingService_5e39d;MessagingService_5e39d; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-05-03 495224]
S3 Origin Client Service;Origin Client Service; D:\Programs\Origin\OriginClientService.exe [2017-10-05 2120032]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2017-10-03 159960]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2017-03-18 47664]
S3 SEMgrSvc;@%SystemRoot%\System32\SEMgrSvc.dll,-1001; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S3 Sense;@%ProgramFiles%\Windows Defender Advanced Threat Protection\MsSense.exe,-1001; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2017-03-19 3913064]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2017-03-18 1284608]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2017-03-18 47664]
S4 AppVClient;@%systemroot%\system32\AppVClient.exe,-102; C:\WINDOWS\system32\AppVClient.exe [2017-09-30 849816]

-----------------EOF-----------------

Sertr
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 19 bře 2010 07:47

Re: Prosím kontrola (před reinstallem)

#2 Příspěvek od Sertr »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2017
Ran by RoyalSertr (administrator) on ROYALWOLF (06-11-2017 14:51:46)
Running from D:\Downloads
Loaded Profiles: RoyalSertr (Available Profiles: RoyalSertr & DefaultAppPool)
Platform: Windows 10 Pro Version 1703 15063.674 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(AVAST Software) D:\Programs\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) D:\Programs\AVAST Software\Avast\afwServ.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsusFanControlService\1.03.03\AsusFanControlService.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Electronic Arts) D:\Programs\Origin\OriginWebHelperService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(AVAST Software s.r.o.) D:\Programs\AVAST Software\Avast\x64\aswidsagenta.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(ASUSTeK Computer Inc.) D:\Programs\AI Suite III\AISuite3.exe
() D:\Programs\AI Suite III\DIP4\DIPAwayMode\DipAwayMode.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Mozilla Corporation) D:\Programs\Mozilla Firefox\firefox.exe
(Mozilla Corporation) D:\Programs\Mozilla Firefox\firefox.exe
(Mozilla Corporation) D:\Programs\Mozilla Firefox\firefox.exe
(Mozilla Corporation) D:\Programs\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(AVAST Software) D:\Programs\AVAST Software\Avast\avastui.exe
(Piriform Ltd) D:\Programs\CCleaner\CCleaner64.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Corsair Components, Inc.) D:\Programs\Corsair\Corsair Utility Engine\CUE.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-09-11] (Apple Inc.)
HKLM\...\Run: [AvastUI.exe] => D:\Programs\AVAST Software\Avast\AvLaunch.exe [253344 2017-10-12] (AVAST Software)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.)
HKLM-x32\...\Run: [Corsair Utility Engine] => D:\Programs\Corsair\Corsair Utility Engine\CUE.exe [18848976 2017-08-04] (Corsair Components, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-1085299360-3705221177-4155360806-1000\...\Run: [CCleaner Monitoring] => D:\Programs\CCleaner\CCleaner64.exe [9856176 2017-09-20] (Piriform Ltd)
HKU\S-1-5-21-1085299360-3705221177-4155360806-1000\...\MountPoints2: {c1976b26-3972-11e7-8649-d850e6491680} - "F:\HiSuiteDownLoader.exe"

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 213.46.172.36 213.46.172.37 192.168.1.1
Tcpip\..\Interfaces\{281ce32b-66d0-4905-b7ff-fd5621e4f6c6}: [DhcpNameServer] 213.46.172.36 213.46.172.37 192.168.1.1

Internet Explorer:
==================
SearchScopes: HKU\S-1-5-21-1085299360-3705221177-4155360806-1000 -> DefaultScope {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1085299360-3705221177-4155360806-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1085299360-3705221177-4155360806-1000 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={616C3C03-51E4-4432-8CE9-0A3A7C74EA0B}&mid=3e7cb022813147d2b6fc0919a0adff73-e0e6c662d8a77407c305e67be39ec0474a83d014&lang=cs&ds=AVG&coid=avgtbavg&cmpid=0615piz&pr=fr&d=2015-11-22 13:30:04&v=4.2.0.886&pid=wtu&sg=&sap=dsp&q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-09-05] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-04-24] (Oracle Corporation)
BHO: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-09-05] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-09-05] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-24] (Oracle Corporation)
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2017-08-15] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-10-27] (Oracle Corporation)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> D:\Programs\Visual Studio 2012 Ultimate\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2012-07-26] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2017-09-05] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-10-27] (Oracle Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-07-18] (Microsoft Corporation)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File

FireFox:
========
FF DefaultProfile: vzb42xmv.default-1460553524321
FF ProfilePath: C:\Users\RoyalSertr\AppData\Roaming\Mozilla\Firefox\Profiles\vzb42xmv.default-1460553524321 [2017-11-06]
FF Homepage: Mozilla\Firefox\Profiles\vzb42xmv.default-1460553524321 -> about:newtab
FF Extension: (Safe Browsing Version 4 (temporary add-on)) - C:\Users\RoyalSertr\AppData\Roaming\Mozilla\Firefox\Profiles\vzb42xmv.default-1460553524321\Extensions\sbv4-gradual-rollout@mozilla.com.xpi [2017-10-06]
FF Extension: (Adblock Plus) - C:\Users\RoyalSertr\AppData\Roaming\Mozilla\Firefox\Profiles\vzb42xmv.default-1460553524321\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-07]
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\wtu-secure-search.xml [2016-02-01]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_27_0_0_183.dll [2017-10-26] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-24] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_183.dll [2017-10-26] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-10-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-10-27] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-12] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-10-13] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-07-18] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-07-18] (NVIDIA Corporation)
FF Plugin-x32: @t.garena.com/garenatalk -> D:\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-10] (Adobe Systems Inc.)
StartMenuInternet: FIREFOX.EXE - D:\Programs\Mozilla Firefox\firefox.exe

Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-09-07] (Apple Inc.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-04] ()
R2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.22\aaHMSvc.exe [954648 2013-08-01] (ASUSTeK Computer Inc.)
R2 AsusFanControlService; C:\Program Files (x86)\ASUS\AsusFanControlService\1.03.03\AsusFanControlService.exe [1660728 2013-07-31] (ASUSTeK Computer Inc.)
R3 aswbIDSAgent; D:\Programs\AVAST Software\Avast\x64\aswidsagenta.exe [7446024 2017-10-12] (AVAST Software s.r.o.)
R2 avast! Antivirus; D:\Programs\AVAST Software\Avast\AvastSvc.exe [281416 2017-10-12] (AVAST Software)
R2 avast! Firewall; D:\Programs\AVAST Software\Avast\afwServ.exe [330832 2017-10-23] (AVAST Software)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [1536520 2017-05-16] ()
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058416 2017-09-05] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-01-31] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-01-31] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.0\App Certification Kit\fussvc.exe [139776 2012-07-25] (Microsoft Corporation) [File not signed]
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [8242752 2017-09-19] (GOG.com)
R2 HuaweiHiSuiteService64.exe; C:\Program Files (x86)\HiSuite\HandSetService\HuaweiHiSuiteService64.exe [192200 2017-04-11] () [File not signed]
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-05-03] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-07-18] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-05-03] (NVIDIA Corporation)
S3 Origin Client Service; D:\Programs\Origin\OriginClientService.exe [2120032 2017-10-05] (Electronic Arts)
R2 Origin Web Helper Service; D:\Programs\Origin\OriginWebHelperService.exe [3000168 2017-10-05] (Electronic Arts)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2016-06-18] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2016-06-18] ()
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-19] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.0\Testing\Runtimes\TAEF\Wex.Services.exe [126976 2012-07-25] (Microsoft Corporation) [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 asahci64; C:\WINDOWS\System32\drivers\asahci64.sys [47512 2013-01-10] (Asmedia Technology)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [14464 2012-09-14] ()
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [321032 2017-10-12] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198976 2017-10-12] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343288 2017-10-12] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57736 2017-10-12] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [47008 2017-10-12] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [147776 2017-10-12] (AVAST Software)
R1 aswNetSec; C:\WINDOWS\system32\drivers\aswNetSec.sys [556152 2017-10-23] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110376 2017-10-12] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84416 2017-10-12] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1029872 2017-10-27] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [587168 2017-10-12] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [201352 2017-10-12] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [363440 2017-10-12] (AVAST Software)
R2 atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [314016 2015-09-14] ()
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [45528 2017-06-21] (Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21968 2017-06-21] (Corsair)
S3 EvolveVirtualAdapter; C:\WINDOWS\System32\drivers\evolve.sys [21656 2016-11-19] (Echobit, LLC)
S3 ew_usbccgpfilter; C:\WINDOWS\System32\drivers\ew_usbccgpfilter.sys [18944 2017-04-11] (Huawei Technologies Co., Ltd.)
R2 lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [43680 2015-09-14] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_c0f7a2f5b2e4e6e0\nvlddmkm.sys [15668664 2017-08-03] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-05-03] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48248 2017-05-03] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57976 2017-05-03] (NVIDIA Corporation)
S3 RzDxgk; C:\Windows\system32\drivers\RzDxgk.sys [129472 2014-04-18] (Razer, Inc.)
S3 rzendpt; C:\WINDOWS\System32\drivers\rzendpt.sys [50392 2015-10-26] (Razer Inc)
S3 rzmpos; C:\WINDOWS\System32\drivers\rzmpos.sys [47312 2015-10-26] (Razer Inc)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2016-03-09] ()
S3 VBAudioVMVAIOMME; C:\WINDOWS\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2016-12-08] (Windows (R) Win 7 DDK provider)
S3 VSPerfDrv110; D:\Programs\Visual Studio 2012 Ultimate\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
U1 aswbdisk; no ImagePath
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-06 14:45 - 2017-11-06 14:50 - 000000000 ____D C:\Program Files\trend micro
2017-11-06 14:45 - 2017-11-06 14:45 - 000000000 ____D C:\rsit
2017-11-06 14:43 - 2017-11-06 14:51 - 000000000 ____D C:\FRST
2017-11-06 12:33 - 2017-11-06 12:33 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-11-03 18:09 - 2017-11-03 18:09 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-11-01 12:58 - 2017-11-01 12:58 - 000051016 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-11-01 12:58 - 2017-11-01 12:58 - 000045672 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-11-01 12:58 - 2017-11-01 12:58 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-11-01 12:58 - 2017-11-01 12:58 - 000045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-10-27 21:28 - 2017-10-27 21:28 - 000000000 ____D C:\Users\RoyalSertr\Documents\Klei
2017-10-27 15:58 - 2017-10-27 15:58 - 000000522 _____ C:\WINDOWS\SysWOW64\nativelog.txt
2017-10-23 11:28 - 2017-10-23 11:28 - 000556152 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetSec.sys
2017-10-23 11:28 - 2017-10-23 11:28 - 000001005 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Internet Security.lnk
2017-10-23 11:28 - 2017-10-12 11:49 - 000401488 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-10-12 22:33 - 2017-10-22 16:08 - 000000000 ____D C:\WINDOWS\System32\Tasks\AVAST Software
2017-10-10 19:58 - 2017-10-10 19:58 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2017-10-10 19:56 - 2017-09-30 03:04 - 000182680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2017-10-10 19:56 - 2017-09-29 08:29 - 000157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll
2017-10-10 19:56 - 2017-09-29 08:24 - 003377664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-10-10 19:55 - 2017-09-30 06:52 - 001595152 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-10-10 19:55 - 2017-09-30 06:51 - 001458320 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-10-10 19:55 - 2017-09-30 06:51 - 001147288 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-10-10 19:55 - 2017-09-30 06:51 - 000661224 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2017-10-10 19:55 - 2017-09-30 06:50 - 001346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-10-10 19:55 - 2017-09-30 06:50 - 001068208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-10-10 19:55 - 2017-09-30 06:50 - 001024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-10-10 19:55 - 2017-09-30 06:49 - 001004136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-10-10 19:55 - 2017-09-30 06:49 - 000777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-10-10 19:55 - 2017-09-30 06:49 - 000135576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2017-10-10 19:55 - 2017-09-30 06:48 - 008319384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-10-10 19:55 - 2017-09-30 06:48 - 002399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-10-10 19:55 - 2017-09-30 06:48 - 002327448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-10-10 19:55 - 2017-09-30 06:48 - 000644696 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2017-10-10 19:55 - 2017-09-30 06:47 - 002969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-10-10 19:55 - 2017-09-30 06:47 - 001194792 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2017-10-10 19:55 - 2017-09-30 06:45 - 000511896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2017-10-10 19:55 - 2017-09-30 06:44 - 000712600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-10-10 19:55 - 2017-09-30 06:44 - 000181912 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2017-10-10 19:55 - 2017-09-30 06:43 - 007318888 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-10-10 19:55 - 2017-09-30 06:43 - 002442136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-10-10 19:55 - 2017-09-30 06:42 - 004848952 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-10-10 19:55 - 2017-09-30 06:42 - 001506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-10-10 19:55 - 2017-09-30 06:42 - 000820120 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-10-10 19:55 - 2017-09-30 06:41 - 005477600 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-10-10 19:55 - 2017-09-30 06:41 - 005304496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2017-10-10 19:55 - 2017-09-30 06:41 - 002086808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2017-10-10 19:55 - 2017-09-30 06:41 - 000961944 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-10-10 19:55 - 2017-09-30 06:41 - 000654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-10-10 19:55 - 2017-09-30 06:41 - 000651672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-10-10 19:55 - 2017-09-30 06:41 - 000259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-10-10 19:55 - 2017-09-30 06:41 - 000257432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2017-10-10 19:55 - 2017-09-30 06:41 - 000228248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-10-10 19:55 - 2017-09-30 06:40 - 000849816 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2017-10-10 19:55 - 2017-09-30 06:40 - 000724704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-10-10 19:55 - 2017-09-30 06:40 - 000701336 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVCatalog.dll
2017-10-10 19:55 - 2017-09-30 06:40 - 000642680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-10-10 19:55 - 2017-09-30 06:40 - 000558912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-10-10 19:55 - 2017-09-30 06:40 - 000408984 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-10-10 19:55 - 2017-09-30 06:40 - 000336320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2017-10-10 19:55 - 2017-09-30 06:40 - 000184728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2017-10-10 19:55 - 2017-09-30 06:40 - 000173976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbccgp.sys
2017-10-10 19:55 - 2017-09-30 06:40 - 000072944 _____ (Microsoft Corporation) C:\WINDOWS\system32\easinvoker.exe
2017-10-10 19:55 - 2017-09-30 06:39 - 021351760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-10-10 19:55 - 2017-09-30 06:39 - 001694104 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVIntegration.dll
2017-10-10 19:55 - 2017-09-30 06:39 - 000203672 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
2017-10-10 19:55 - 2017-09-30 06:38 - 007910072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-10-10 19:55 - 2017-09-30 06:38 - 002239136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2017-10-10 19:55 - 2017-09-30 06:38 - 001854872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntVirtualization.dll
2017-10-10 19:55 - 2017-09-30 06:37 - 002377112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.AppAgent.dll
2017-10-10 19:55 - 2017-09-30 06:37 - 002229144 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2017-10-10 19:55 - 2017-09-30 06:37 - 001464728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystemController.dll
2017-10-10 19:55 - 2017-09-30 06:36 - 002672024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-10-10 19:55 - 2017-09-30 06:36 - 000855960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVOrchestration.dll
2017-10-10 19:55 - 2017-09-30 06:36 - 000675224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2017-10-10 19:55 - 2017-09-30 06:36 - 000057976 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2017-10-10 19:55 - 2017-09-30 03:29 - 001408536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-10-10 19:55 - 2017-09-30 03:29 - 000804784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-10-10 19:55 - 2017-09-30 03:26 - 001333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-10-10 19:55 - 2017-09-30 03:26 - 001292872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-10-10 19:55 - 2017-09-30 03:10 - 001839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-10-10 19:55 - 2017-09-30 03:10 - 001150776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-10-10 19:55 - 2017-09-30 03:10 - 000606072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-10-10 19:55 - 2017-09-30 03:10 - 000508344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2017-10-10 19:55 - 2017-09-30 03:10 - 000480920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2017-10-10 19:55 - 2017-09-30 03:09 - 002259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-10-10 19:55 - 2017-09-30 03:09 - 000787712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2017-10-10 19:55 - 2017-09-30 03:06 - 004471368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-10-10 19:55 - 2017-09-30 03:05 - 005827744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-10-10 19:55 - 2017-09-30 03:05 - 002603744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2017-10-10 19:55 - 2017-09-30 03:05 - 001266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-10-10 19:55 - 2017-09-30 03:05 - 000750488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-10-10 19:55 - 2017-09-30 03:05 - 000559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-10-10 19:55 - 2017-09-30 03:04 - 004215184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2017-10-10 19:55 - 2017-09-30 03:04 - 000612120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-10-10 19:55 - 2017-09-30 03:04 - 000519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-10-10 19:55 - 2017-09-30 03:04 - 000438096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2017-10-10 19:55 - 2017-09-30 03:04 - 000347544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-10-10 19:55 - 2017-09-30 03:03 - 020373408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-10-10 19:55 - 2017-09-30 03:03 - 006768288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-10-10 19:55 - 2017-09-30 03:03 - 001439032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2017-10-10 19:55 - 2017-09-30 03:02 - 001624096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.AppAgent.dll
2017-10-10 19:55 - 2017-09-30 03:02 - 001517464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2017-10-10 19:55 - 2017-09-30 03:02 - 000175512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll
2017-10-10 19:55 - 2017-09-30 03:01 - 000124544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2017-10-10 19:55 - 2017-09-29 08:46 - 023678976 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-10-10 19:55 - 2017-09-29 08:45 - 002953216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-10-10 19:55 - 2017-09-29 08:44 - 000133120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\t2embed.dll
2017-10-10 19:55 - 2017-09-29 08:43 - 002199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-10-10 19:55 - 2017-09-29 08:43 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2017-10-10 19:55 - 2017-09-29 08:43 - 000060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2017-10-10 19:55 - 2017-09-29 08:42 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mgmtapi.dll
2017-10-10 19:55 - 2017-09-29 08:41 - 013844992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-10-10 19:55 - 2017-09-29 08:41 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2017-10-10 19:55 - 2017-09-29 08:40 - 006728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-10-10 19:55 - 2017-09-29 08:40 - 000371200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-10-10 19:55 - 2017-09-29 08:40 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2017-10-10 19:55 - 2017-09-29 08:39 - 020511232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-10-10 19:55 - 2017-09-29 08:39 - 011888640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-10-10 19:55 - 2017-09-29 08:39 - 000364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 005721600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 002671616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 001135616 ____R (The ICU Project) C:\WINDOWS\SysWOW64\icuuc.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 000498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Uev.Office2013CustomActions.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 000471040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webio.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 000308224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2017-10-10 19:55 - 2017-09-29 08:38 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll
2017-10-10 19:55 - 2017-09-29 08:37 - 000306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Graphics.dll
2017-10-10 19:55 - 2017-09-29 08:37 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2017-10-10 19:55 - 2017-09-29 08:36 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-10-10 19:55 - 2017-09-29 08:36 - 000590336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2017-10-10 19:55 - 2017-09-29 08:35 - 003654656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-10-10 19:55 - 2017-09-29 08:34 - 017370624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-10-10 19:55 - 2017-09-29 08:34 - 006255616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-10-10 19:55 - 2017-09-29 08:34 - 003669504 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-10-10 19:55 - 2017-09-29 08:34 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-10-10 19:55 - 2017-09-29 08:34 - 000798720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-10-10 19:55 - 2017-09-29 08:34 - 000787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-10-10 19:55 - 2017-09-29 08:34 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.dll
2017-10-10 19:55 - 2017-09-29 08:33 - 007598080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-10-10 19:55 - 2017-09-29 08:33 - 004559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-10-10 19:55 - 2017-09-29 08:33 - 001506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2017-10-10 19:55 - 2017-09-29 08:33 - 000658944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2017-10-10 19:55 - 2017-09-29 08:33 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\t2embed.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 002782720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 002340864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 002199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 001244160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Phone.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 000087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-10-10 19:55 - 2017-09-29 08:32 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll
2017-10-10 19:55 - 2017-09-29 08:32 - 000023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\mgmtapi.dll
2017-10-10 19:55 - 2017-09-29 08:31 - 003107328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2017-10-10 19:55 - 2017-09-29 08:31 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-10-10 19:55 - 2017-09-29 08:31 - 000168448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-10-10 19:55 - 2017-09-29 08:31 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2017-10-10 19:55 - 2017-09-29 08:31 - 000057344 _____ (Microsoft Corporation) C:\WINDOWS\system32\efssvc.dll
2017-10-10 19:55 - 2017-09-29 08:31 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-10-10 19:55 - 2017-09-29 08:30 - 023686144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-10-10 19:55 - 2017-09-29 08:30 - 007931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-10-10 19:55 - 2017-09-29 08:30 - 000529408 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-10-10 19:55 - 2017-09-29 08:30 - 000179200 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2017-10-10 19:55 - 2017-09-29 08:30 - 000064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-10-10 19:55 - 2017-09-29 08:30 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmTasks.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 008333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 001460736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_fs.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 001318912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsp_health.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 000724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\nwifi.sys
2017-10-10 19:55 - 2017-09-29 08:29 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 000433152 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 000304640 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 000083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2017-10-10 19:55 - 2017-09-29 08:29 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ServiceWorkerHost.exe
2017-10-10 19:55 - 2017-09-29 08:28 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2017-10-10 19:55 - 2017-09-29 08:28 - 000681472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clusapi.dll
2017-10-10 19:55 - 2017-09-29 08:28 - 000556032 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-10-10 19:55 - 2017-09-29 08:28 - 000527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-10-10 19:55 - 2017-09-29 08:28 - 000473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\resutils.dll
2017-10-10 19:55 - 2017-09-29 08:28 - 000458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2017-10-10 19:55 - 2017-09-29 08:28 - 000297984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mcbuilder.exe
2017-10-10 19:55 - 2017-09-29 08:28 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-10-10 19:55 - 2017-09-29 08:28 - 000254976 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
2017-10-10 19:55 - 2017-09-29 08:28 - 000104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Robocopy.exe
2017-10-10 19:55 - 2017-09-29 08:28 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cipher.exe
2017-10-10 19:55 - 2017-09-29 08:27 - 012803072 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-10-10 19:55 - 2017-09-29 08:27 - 001321984 ____R (The ICU Project) C:\WINDOWS\system32\icuuc.dll
2017-10-10 19:55 - 2017-09-29 08:27 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2017-10-10 19:55 - 2017-09-29 08:27 - 000565760 _____ (Microsoft Corporation) C:\WINDOWS\system32\webio.dll
2017-10-10 19:55 - 2017-09-29 08:27 - 000538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2017-10-10 19:55 - 2017-09-29 08:27 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-10-10 19:55 - 2017-09-29 08:27 - 000412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-10-10 19:55 - 2017-09-29 08:27 - 000409600 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2017-10-10 19:55 - 2017-09-29 08:27 - 000350720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Graphics.dll
2017-10-10 19:55 - 2017-09-29 08:26 - 008213504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-10-10 19:55 - 2017-09-29 08:26 - 002809344 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-10-10 19:55 - 2017-09-29 08:26 - 001468928 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-10-10 19:55 - 2017-09-29 08:26 - 001269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-10-10 19:55 - 2017-09-29 08:26 - 001197568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.CommonBridge.dll
2017-10-10 19:55 - 2017-09-29 08:26 - 001141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplySettingsTemplateCatalog.exe
2017-10-10 19:55 - 2017-09-29 08:26 - 000772096 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2017-10-10 19:55 - 2017-09-29 08:26 - 000356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2017-10-10 19:55 - 2017-09-29 08:26 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2017-10-10 19:55 - 2017-09-29 08:25 - 008199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-10-10 19:55 - 2017-09-29 08:25 - 004175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2017-10-10 19:55 - 2017-09-29 08:25 - 002760704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-10-10 19:55 - 2017-09-29 08:25 - 000586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-10-10 19:55 - 2017-09-29 08:24 - 003307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-10-10 19:55 - 2017-09-29 08:24 - 002503680 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-10-10 19:55 - 2017-09-29 08:24 - 001886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-10-10 19:55 - 2017-09-29 08:24 - 001628672 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2017-10-10 19:55 - 2017-09-29 08:24 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-10-10 19:55 - 2017-09-29 08:24 - 001201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AgentService.exe
2017-10-10 19:55 - 2017-09-29 08:24 - 000684032 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 005557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 004730368 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 003140096 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 002730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-10-10 19:55 - 2017-09-29 08:23 - 002446336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 002195968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Uev.ModernAppAgent.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 002055680 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-10-10 19:55 - 2017-09-29 08:23 - 001887744 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 001460224 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 001398784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 001052672 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 000986624 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 000972288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 000756224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 000647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-10-10 19:55 - 2017-09-29 08:23 - 000512000 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.dll
2017-10-10 19:55 - 2017-09-29 08:22 - 002829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-10-10 19:55 - 2017-09-29 08:22 - 001802240 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-10-10 19:55 - 2017-09-29 08:22 - 001438208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Phone.dll
2017-10-10 19:55 - 2017-09-29 08:22 - 000407040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-10-10 19:55 - 2017-09-29 08:21 - 003304448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2017-10-10 19:55 - 2017-09-29 08:21 - 000722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-10-10 19:55 - 2017-09-29 08:21 - 000476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-10-10 19:55 - 2017-09-29 08:21 - 000414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-10-10 19:55 - 2017-09-29 08:21 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2017-10-10 19:55 - 2017-09-29 08:21 - 000154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\regsvc.dll
2017-10-10 19:55 - 2017-09-29 08:21 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2017-10-10 19:55 - 2017-09-29 08:21 - 000124928 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2017-10-10 19:55 - 2017-09-29 08:20 - 001811456 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_health.dll
2017-10-10 19:55 - 2017-09-29 08:20 - 000804864 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2017-10-10 19:55 - 2017-09-29 08:20 - 000385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdesvc.dll
2017-10-10 19:55 - 2017-09-29 08:20 - 000286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-10-10 19:55 - 2017-09-29 08:20 - 000194560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpchttp.dll
2017-10-10 19:55 - 2017-09-29 08:20 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\system32\iscsiexe.dll
2017-10-10 19:55 - 2017-09-29 08:19 - 002088448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsp_fs.dll
2017-10-10 19:55 - 2017-09-29 08:19 - 000325120 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvecpl.dll
2017-10-10 19:55 - 2017-09-29 08:19 - 000306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveui.dll
2017-10-10 19:55 - 2017-09-29 08:19 - 000208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2017-10-10 19:55 - 2017-09-29 08:18 - 002438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-10-10 19:55 - 2017-09-29 08:18 - 001527296 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2017-10-10 19:55 - 2017-09-29 08:18 - 000893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\clusapi.dll
2017-10-10 19:55 - 2017-09-29 08:18 - 000603136 _____ (Microsoft Corporation) C:\WINDOWS\system32\resutils.dll
2017-10-10 19:55 - 2017-09-29 08:18 - 000364032 _____ (Microsoft Corporation) C:\WINDOWS\system32\bdechangepin.exe
2017-10-10 19:55 - 2017-09-29 08:18 - 000347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcbuilder.exe
2017-10-10 19:55 - 2017-09-29 08:18 - 000215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\manage-bde.exe
2017-10-10 19:55 - 2017-09-29 08:18 - 000141312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerDeviceEncryption.exe
2017-10-10 19:55 - 2017-09-29 08:18 - 000130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Robocopy.exe
2017-10-10 19:55 - 2017-09-29 08:18 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\cipher.exe
2017-10-10 19:55 - 2017-09-29 06:40 - 000804312 _____ C:\WINDOWS\SysWOW64\locale.nls
2017-10-10 19:55 - 2017-09-29 06:40 - 000804312 _____ C:\WINDOWS\system32\locale.nls
2017-10-10 19:55 - 2017-09-20 16:08 - 000640512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll
2017-10-10 19:55 - 2017-09-20 16:08 - 000345088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-10-10 19:55 - 2017-09-20 16:08 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll
2017-10-10 19:55 - 2017-09-19 00:20 - 001065104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-10-10 19:55 - 2017-09-19 00:20 - 000900376 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-10-10 19:55 - 2017-09-19 00:18 - 000965024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-10-10 19:55 - 2017-09-19 00:17 - 001395664 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-10-10 19:55 - 2017-09-19 00:17 - 001186464 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-10-10 19:55 - 2017-09-19 00:17 - 000821664 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-10-10 19:55 - 2017-09-19 00:11 - 001018272 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2017-10-10 19:55 - 2017-09-19 00:09 - 000554400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2017-10-10 19:55 - 2017-09-18 23:26 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2017-10-10 19:55 - 2017-09-18 23:25 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\eShims.dll
2017-10-10 19:55 - 2017-09-18 23:23 - 000210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2017-10-10 19:55 - 2017-09-18 23:20 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2017-10-10 19:55 - 2017-09-18 23:20 - 000049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
2017-10-10 19:55 - 2017-09-18 23:15 - 000648704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-06 14:41 - 2017-07-09 11:11 - 002244642 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-11-06 14:41 - 2014-06-09 13:22 - 000000000 _____ C:\WINDOWS\Path.idx
2017-11-06 14:38 - 2017-07-09 11:10 - 000000000 ____D C:\ProgramData\NVIDIA
2017-11-06 14:36 - 2016-11-18 22:18 - 000000000 ____D C:\Users\RoyalSertr\AppData\LocalLow\Mozilla
2017-11-06 14:36 - 2014-06-09 13:17 - 001048576 _____ C:\WINDOWS\PE_Rom.dll
2017-11-06 14:35 - 2017-07-09 11:24 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-11-06 12:48 - 2017-03-18 12:40 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2017-11-06 12:44 - 2014-03-07 22:52 - 000000000 ____D C:\Users\RoyalSertr\AppData\Roaming\vlc
2017-11-06 00:40 - 2017-07-09 11:11 - 000000000 ____D C:\Users\RoyalSertr
2017-11-05 23:58 - 2014-07-13 00:21 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Battle.net
2017-11-05 17:46 - 2017-07-09 11:10 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-11-03 18:09 - 2017-01-31 21:17 - 000000000 ____D C:\Program Files (x86)\Dropbox
2017-11-02 16:05 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-11-01 14:03 - 2017-03-18 22:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-10-31 23:58 - 2016-04-05 16:46 - 000000000 ____D C:\Users\RoyalSertr\.junique
2017-10-31 21:57 - 2014-08-29 14:14 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Arma 3
2017-10-31 16:59 - 2014-03-07 22:27 - 000000000 ____D C:\Users\RoyalSertr\AppData\Roaming\BitTorrent
2017-10-29 22:36 - 2016-05-02 20:46 - 000000000 ____D C:\Users\RoyalSertr\Documents\Overwatch
2017-10-28 11:28 - 2017-07-09 11:10 - 000471512 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-10-27 16:50 - 2013-12-12 20:10 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-10-27 16:48 - 2009-07-14 06:32 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-10-27 16:38 - 2013-11-22 12:44 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Ubisoft Game Launcher
2017-10-27 16:32 - 2016-07-26 20:02 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Packages
2017-10-27 16:29 - 2014-01-08 19:17 - 000000000 ____D C:\WINDOWS\pss
2017-10-27 16:28 - 2016-03-05 19:37 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Google
2017-10-27 16:28 - 2015-09-13 19:50 - 000000000 ____D C:\Program Files (x86)\Google
2017-10-27 16:23 - 2013-11-29 22:08 - 000000000 ____D C:\ProgramData\Skype
2017-10-27 16:18 - 2014-04-12 15:48 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Unity
2017-10-27 16:16 - 2017-04-30 13:16 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Swifty
2017-10-27 16:16 - 2016-05-09 19:48 - 000000000 ____D C:\Users\RoyalSertr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sebastian Broberg
2017-10-27 16:16 - 2014-01-21 20:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2017-10-27 16:16 - 2014-01-21 20:02 - 000000000 ____D C:\ProgramData\Autodesk
2017-10-27 16:16 - 2014-01-12 18:46 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Autodesk
2017-10-27 16:06 - 2013-11-21 23:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2017-10-27 16:05 - 2016-12-21 18:38 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Discord
2017-10-27 16:04 - 2017-04-24 12:54 - 000000000 ____D C:\Users\RoyalSertr\AppData\Roaming\Wargaming.net
2017-10-27 16:03 - 2017-07-09 11:10 - 000000000 ____D C:\ProgramData\Razer
2017-10-27 16:03 - 2017-03-18 22:01 - 000000000 ____D C:\WINDOWS\INF
2017-10-27 16:03 - 2013-11-22 16:15 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Razer
2017-10-27 16:02 - 2017-04-24 12:55 - 000000000 ____D C:\Games
2017-10-27 16:00 - 2015-07-03 16:32 - 000000000 ____D C:\ProgramData\boost_interprocess
2017-10-27 15:55 - 2015-03-14 20:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CodeBlocks
2017-10-27 15:54 - 2015-02-07 20:03 - 000000000 ____D C:\Users\RoyalSertr\AppData\Roaming\Doublefine
2017-10-27 15:45 - 2014-10-05 13:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit
2017-10-27 15:45 - 2014-02-23 14:07 - 000097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-10-27 15:45 - 2013-11-26 20:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-10-27 15:45 - 2013-11-26 20:06 - 000000000 ____D C:\Program Files (x86)\Java
2017-10-27 11:01 - 2017-09-29 17:14 - 001029872 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswsnx.sys
2017-10-26 14:22 - 2017-07-09 11:24 - 000004374 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2017-10-26 14:22 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-10-26 14:22 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-10-24 18:50 - 2014-10-06 17:39 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\ownCloud
2017-10-23 18:17 - 2017-09-30 13:59 - 000000000 ____D C:\Users\RoyalSertr\Documents\Larian Studios
2017-10-23 12:18 - 2017-03-18 22:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-10-23 12:16 - 2014-10-13 17:36 - 000000000 ____D C:\Program Files\Microsoft Office 15
2017-10-23 11:28 - 2017-09-29 17:14 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-10-23 11:28 - 2017-09-29 17:14 - 000003984 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-10-22 16:09 - 2017-01-31 21:17 - 000000936 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2017-10-22 16:09 - 2017-01-31 21:17 - 000000932 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2017-10-22 16:08 - 2017-07-09 11:24 - 000003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-10-22 16:08 - 2017-07-09 11:24 - 000003450 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2017-10-22 16:08 - 2017-07-09 11:24 - 000003398 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-22 16:08 - 2017-07-09 11:24 - 000003226 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2017-10-22 16:08 - 2017-07-09 11:24 - 000003176 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002984 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002968 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002956 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002838 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002786 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002744 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002464 _____ C:\WINDOWS\System32\Tasks\{252E3667-7EEC-4EEC-9E04-614EA4EB8BD3}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002392 _____ C:\WINDOWS\System32\Tasks\{1CEB02B7-5ABE-4548-9298-36E18E570484}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002282 _____ C:\WINDOWS\System32\Tasks\{0307D57E-9C01-4476-AF62-799AD803844A}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002226 _____ C:\WINDOWS\System32\Tasks\{7980550A-EC7B-4288-BC01-7BEB33A8451E}
2017-10-22 16:08 - 2017-07-09 11:24 - 000002210 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2017-10-22 16:08 - 2017-07-09 11:24 - 000002078 _____ C:\WINDOWS\System32\Tasks\SidebarExecute
2017-10-21 15:05 - 2014-08-29 14:14 - 000000000 ____D C:\Users\RoyalSertr\AppData\Local\Arma 3 Launcher
2017-10-20 19:05 - 2014-02-25 22:22 - 000000000 ____D C:\Users\RoyalSertr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-10-20 19:05 - 2014-02-25 22:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-10-18 14:52 - 2015-10-14 20:26 - 000000000 ____D C:\Users\RoyalSertr\.maplesoft
2017-10-18 14:01 - 2017-03-18 21:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-10-13 01:21 - 2017-03-18 22:06 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-10-13 01:21 - 2017-03-18 22:06 - 000177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-10-12 11:49 - 2017-09-29 17:14 - 000587168 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000363440 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000343288 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000321032 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000201352 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000198976 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000147776 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000061304 _____ () C:\WINDOWS\SMSS-PFRO1d9a.tmp
2017-10-12 11:49 - 2017-09-29 17:14 - 000057736 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-10-12 11:49 - 2017-09-29 17:14 - 000047008 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-10-12 11:49 - 2017-09-29 17:11 - 000000000 ____D C:\ProgramData\AVAST Software
2017-10-11 13:29 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\rescache
2017-10-11 11:06 - 2016-07-26 20:02 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-10-10 22:31 - 2017-03-18 22:03 - 000230400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2017-10-10 22:31 - 2017-03-18 22:03 - 000207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2017-10-10 22:31 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\ShellExperiences
2017-10-10 22:31 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\Provisioning
2017-10-10 22:31 - 2017-03-18 22:03 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2017-10-10 20:00 - 2013-11-25 18:00 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-10-10 19:58 - 2013-11-25 18:00 - 126925120 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-10-08 21:04 - 2014-07-28 10:03 - 000000000 ____D C:\Users\RoyalSertr\AppData\Roaming\Origin
2017-10-08 21:00 - 2014-07-28 10:03 - 000000000 ____D C:\ProgramData\Origin

==================== Files in the root of some directories =======

2014-02-07 18:09 - 2014-06-02 10:56 - 000003743 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2014-03-07 22:27 - 2014-03-07 22:29 - 000002530 _____ () C:\Users\RoyalSertr\AppData\Roaming\install-BitTorrent.txt
2014-01-08 19:00 - 2014-02-03 22:27 - 000045270 _____ () C:\Users\RoyalSertr\AppData\Roaming\room_v3.dat
2016-12-08 14:37 - 2016-12-08 14:54 - 000003978 _____ () C:\Users\RoyalSertr\AppData\Roaming\VoiceMeeterDefault.xml
2014-07-03 23:09 - 2014-07-03 23:09 - 001065984 _____ () C:\Users\RoyalSertr\AppData\Local\file__0.localstorage
2017-04-28 14:46 - 2017-04-28 14:46 - 000021241 _____ () C:\Users\RoyalSertr\AppData\Local\recently-used.xbel
2014-08-24 16:49 - 2016-06-25 15:06 - 000007606 _____ () C:\Users\RoyalSertr\AppData\Local\Resmon.ResmonCfg
2017-03-20 14:36 - 2017-03-20 14:36 - 000000130 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
2017-01-08 14:52 - 2017-02-06 11:31 - 000006776 _____ () C:\ProgramData\NvTelemetryContainer.log
2017-01-08 14:52 - 2017-02-05 22:12 - 000005110 _____ () C:\ProgramData\NvTelemetryContainer.log_backup1

Some files in TEMP:
====================
2017-09-29 17:17 - 2011-12-14 13:42 - 000014760 _____ (Autodesk, Inc.) C:\Users\RoyalSertr\AppData\Local\Temp\AcDeltree.exe
2017-09-29 17:16 - 2017-10-27 15:52 - 001977168 _____ (Flexera Software, Inc.) C:\Users\RoyalSertr\AppData\Local\Temp\FNP_ACT_InstallerCA.dll
2017-10-22 16:32 - 2017-10-22 16:32 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-2097813385808953255.dll
2017-10-22 16:29 - 2017-10-22 16:29 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-2214904088295088574.dll
2017-10-24 18:52 - 2017-10-24 18:52 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-2408872447801249601.dll
2017-10-13 18:57 - 2017-10-13 18:57 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-244412148640725114.dll
2017-10-31 21:56 - 2017-10-31 21:56 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-2896332819643197584.dll
2017-10-21 12:56 - 2017-10-21 12:56 - 000062464 _____ () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-3395672528329541579.dll
2017-10-31 17:52 - 2017-10-31 17:52 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-3507210887007475211.dll
2017-10-17 15:34 - 2017-10-17 15:34 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-4181006122595314808.dll
2017-10-15 18:46 - 2017-10-15 18:46 - 000062464 _____ () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-5068172355538032435.dll
2017-10-13 21:22 - 2017-10-13 21:22 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-5112435708768432873.dll
2017-10-16 12:43 - 2017-10-16 12:43 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-5117072650065684021.dll
2017-10-11 18:37 - 2017-10-11 18:37 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-552718589823571686.dll
2017-10-27 17:37 - 2017-10-27 17:37 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-567577519745726719.dll
2017-10-17 17:45 - 2017-10-17 17:45 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-5687461170821557077.dll
2017-10-10 18:01 - 2017-10-10 18:01 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-6181374516406685849.dll
2017-10-09 18:08 - 2017-10-09 18:08 - 000062464 _____ () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-6244432951375992671.dll
2017-10-20 17:15 - 2017-10-20 17:15 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-6324158104739889801.dll
2017-10-21 18:36 - 2017-10-21 18:36 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-6570109871033801719.dll
2017-10-24 14:53 - 2017-10-24 14:53 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-6724672315290599417.dll
2017-10-12 11:51 - 2017-10-12 11:51 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-7038543098071641347.dll
2017-10-10 15:16 - 2017-10-10 15:16 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-725752266887024674.dll
2017-10-21 15:03 - 2017-10-21 15:03 - 000062464 _____ () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-8209238966479652696.dll
2017-10-25 18:57 - 2017-10-25 18:57 - 000062464 ____N () C:\Users\RoyalSertr\AppData\Local\Temp\jshortcut-9205752568875127324.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-10-29 15:43

==================== End of FRST.txt ============================
Přílohy
Addition.zip
(20.49 KiB) Staženo 71 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118269
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím kontrola (před reinstallem)

#3 Příspěvek od Rudy »

Zdravím!
Až na několik zbytečností vypadá log čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Sertr
Návštěvník
Návštěvník
Příspěvky: 40
Registrován: 19 bře 2010 07:47

Re: Prosím kontrola (před reinstallem)

#4 Příspěvek od Sertr »

Děkuji.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118269
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Prosím kontrola (před reinstallem)

#5 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno