Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

prosim o kontrolu

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
superjano
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 16 srp 2005 23:08

prosim o kontrolu

#1 Příspěvek od superjano »

Logfile of random's system information tool 1.10 (written by random/random)
Run by Milan at 2020-09-06 19:25:23
Microsoft Windows 10 Home
System drive C: has 457 GB (50%) free of 921 GB
Total RAM: 8135 MB (60% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:25:29, on 06.09.2020
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.19041.0001)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksdeui.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avpui.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe
C:\Users\Milan\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe
C:\WINDOWS\Lenovo\iMController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe
C:\WINDOWS\Lenovo\iMController\PluginHost86\Lenovo.Modern.ImController.PluginHost.CompanionApp.exe
C:\Program Files\trend micro\Milan.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://lenovo15.msn.com/?pc=LCTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://lenovo15.msn.com/?pc=LCTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.44\BHO\ie_to_edge_bho.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_241\bin\ssv.dll
O2 - BHO: ScriptInjectionPluginBrowserHelperObject - {9F904093-6E18-4536-BF5F-B03689CF00F0} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\IEExt\ie_plugin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_241\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {b60873b9-51aa-4566-b2fc-c16de2ec8bff} - (no file)
O3 - Toolbar: Kaspersky Protection Toolbar - {EF293C5A-9F37-49FD-91C4-2B867063FC54} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\IEExt\ie_plugin.dll
O4 - HKLM\..\Run: [Opera Browser Assistant] C:\Program Files (x86)\Opera\assistant\browser_assistant.exe
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Milan\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files (x86)\Microsoft Office\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Inc. - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Kaspersky Anti-Virus Service 20.0 (AVP20.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avp.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_d336473 - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\85.0.4183.83\elevation_service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @oem32.inf,%ImcSvcDisplayName%;System Interface Foundation Service (ImControllerService) - Lenovo Group Ltd. - C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Security Assist - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
O23 - Service: Intel(R) Security Assist Helper (isaHelperSvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Kaspersky Volume Shadow Copy Service Bridge 20.0 (klvssbridge64_20.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\x64\vssbridge64.exe
O23 - Service: Kaspersky Password Manager Service (kpm_launch_service) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
O23 - Service: Kaspersky Secure Connection Service 4.0 (KSDE4.0) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksde.exe
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\nvlei.inf_amd64_504ca354d84d7684\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Rockstar Game Library Service (Rockstar Service) - Rockstar Games - C:\Program Files\Rockstar Games\Launcher\RockstarService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: Skdaemon Service (Sks8821) - Unknown owner - C:\Program Files\Lenovo\Lenovo Slim USB Keyboard\Sks8821.exe
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Wondershare Driver Install Service (WsDrvInst) - Wondershare - C:\Program Files (x86)\Wondershare\Wondershare Video Converter Ultimate(CPC)\Transfer\DriverInstall.exe

--
End of file - 12038 bytes

======Listing Processes======









C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
"fontdrvhost.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-56f167f5-dcf9-4e0a-ab3c-c5e47c9e16d9 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-7335dbef-565e-4f8b-948a-ebebd4be7c46 -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-3c067ce4-39cc-4b34-9e86-f5685a881bc9 -NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-cfdbb87a-915e-4174-a7af-7ccdca77331f -LifetimeId:6d4b307d-8d68-4b09-a736-a234cc635f57 -DeviceGroupId: -HostArg:0
C:\WINDOWS\system32\svchost.exe -k RPCSS -p
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s LSM
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s hidserv
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s ProfSvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s TimeBrokerSvc
C:\WINDOWS\System32\DriverStore\FileRepository\nvlei.inf_amd64_504ca354d84d7684\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvlei.inf_amd64_504ca354d84d7684\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UserManager
C:\WINDOWS\system32\svchost.exe -k LocalService -p
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s nsi
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s Dhcp
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s Themes
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s NlaSvc
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s EventSystem
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s SENS
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s camsvc

C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s AudioEndpointBuilder
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s FontCache
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s netprofm
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s StateRepository
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Winmgmt
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s ShellHWDetection
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s DispBrokerDesktopSvc
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s LanmanWorkstation
C:\WINDOWS\System32\svchost.exe -k utcsvc -p
C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s CryptSvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p -s DPS
C:\WINDOWS\System32\svchost.exe -k NetSvcs -p -s iphlpsvc
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s SstpSvc
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"

"C:\Program Files\Lenovo\Lenovo Slim USB Keyboard\Sks8821.exe"
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt -s hpqddsvc
"C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe"
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TrkWks
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s WpnService
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s WdiServiceHost
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s LanmanServer
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s RmSvc
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s DeviceAssociationService
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Windows\SysWOW64\svchost.exe -k hpdevmgmt -s hpqcxs08
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TabletInputService
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s TokenBroker
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s CDPSvc
C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s LicenseManager
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc

C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s SSDPSRV
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Appinfo

"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksde.exe" -r
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"

C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UsoSvc
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s BthAvctpSvc
C:\WINDOWS\System32\svchost.exe -k netsvcs -p
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe"
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s DsSvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s QWAVE
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wuauserv
C:\Windows\System32\mousocoreworker.exe -Embedding

C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup -s WbioSrvc

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"fontdrvhost.exe"
"dwm.exe"
"C:\WINDOWS\System32\DriverStore\FileRepository\nvlei.inf_amd64_504ca354d84d7684\Display.NvContainer\NVDisplay.Container.exe" -f %ProgramData%\NVIDIA\DisplaySessionContainer%d.log -d C:\WINDOWS\System32\DriverStore\FileRepository\nvlei.inf_amd64_504ca354d84d7684\Display.NvContainer\plugins\Session -r -l 3 -p 30000 -cfg NVDisplay.ContainerLocalSystem\Session -c
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s lmhosts
"ctfmon.exe"
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s CDPUserSvc
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s WpnUserService
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksdeui.exe" -hidden
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avpui.exe" -hidden
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc
"C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /LENOVO_MICPKEY
"C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca
"C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20081.117.0_x64__8wekyb3d8bbwe\YourPhone.exe" -ServerName:App.AppX9yct9q388jvt4h7y0gn06smzkxcsnt8m.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\WINDOWS\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe" -ServerName:WindowsDefaultLockScreen.AppX7y4nbzq37zn4ks9k7amqjywdat7d3j2z.mca
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_tray.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\SecurityHealthSystray.exe"
"C:\Program Files\Lenovo\Lenovo Slim USB Keyboard\Skd8821.exe"
"C:\Program Files\Lenovo\Lenovo Slim USB Keyboard\Skdh8821.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Users\Milan\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe"
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe"
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --no-rate-limit --no-upload-gzip --type=crash-handler "--crashes-directory=C:\Users\Milan\AppData\Local\Temp\skype-preview Crashes" "--database=C:\Users\Milan\AppData\Local\Temp\skype-preview Crashes" "--metrics-dir=C:\Users\Milan\AppData\Local\Temp\skype-preview Crashes" --url=appcenter://generic?aid=a8902fe7-ef45-455c-8513-5e56d48e36fd&iid=1cbb288a-e798-41ae-8507-0f5d84e43c69&uid=6579ee35-2c6c-42c3-6f91-5d9a7d0da88f --initial-client-data=0x764,0x768,0x76c,0x760,0x770,0x57ec150,0x57ec160,0x57ec16c
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=gpu-process --field-trial-handle=2380,10428188499849946722,4773162293218293529,131072 --disable-features=PictureInPicture,SpareRendererForSitePerProcess --gpu-preferences=KAAAAAAAAADgAAAwAAAAAAAAYAAAAAAAEAAAAAAAAAAAAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --service-request-channel-token=16899127901123150568 --mojo-platform-channel-handle=2388 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=utility --field-trial-handle=2380,10428188499849946722,4773162293218293529,131072 --disable-features=PictureInPicture,SpareRendererForSitePerProcess --lang=cs --service-sandbox-type=network --service-request-channel-token=12969594570861408494 --mojo-platform-channel-handle=2656 /prefetch:8
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe" -CtxID "#Hewlett-Packard#HP Deskjet F4100 series#1594362434" -Startup
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe" -Embedding
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe" -Embedding
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=renderer --autoplay-policy=no-user-gesture-required --disable-background-timer-throttling --ms-disable-indexeddb-transaction-timeout --field-trial-handle=2380,10428188499849946722,4773162293218293529,131072 --disable-features=PictureInPicture,SpareRendererForSitePerProcess --lang=cs --app-user-model-id=Microsoft.Skype.SkypeDesktop --app-path="C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar" --webview-tag --no-sandbox --no-zygote --native-window-open --preload="C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\resources\app.asar\Preload.js" --disable-remote-module --background-color=#fff --node-integration-in-subframes --enable-websql --enable-spellcheck --electron-shared-settings=eyJjci5jb21wYW55IjoiRWxlY3Ryb24iLCJjci5kdW1wcyI6IiIsImNyLmVuYWJsZWQiOmZhbHNlLCJjci5wcm9kdWN0IjoiRWxlY3Ryb24iLCJjci5zZXNzaW9uIjoiIiwiY3IudXJsIjoiIiwiY3IudmVyc2lvbiI6IiJ9 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=17648702339218361340 --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3044 /prefetch:1 --skype-process-type=Main --skype-window-id=__MAIN_ROOT_VIEW_ID__
"C:\WINDOWS\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe" -ServerName:InputApp.AppX9jnwykgrccxc8by3hsrsh07r423xzvav.mca
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.63.76.0_x86__kzf8qxf38zg5c\Skype\Skype.exe" --type=utility --field-trial-handle=2380,10428188499849946722,4773162293218293529,131072 --disable-features=PictureInPicture,SpareRendererForSitePerProcess --lang=cs --service-sandbox-type=audio --service-request-channel-token=11470678029242852856 --mojo-platform-channel-handle=3532 /prefetch:8
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
-name 5c74c5ee-9d0e-4e7a-a710-fc59f3f57c9b -runas -pluginName GenericMessagingPlugin -pluginVersion 3.1.0.153
-name ca3b496f-2e07-425b-8d63-38288571d0c6 -runas -pluginName LenovoWiFiSecurityPlugin -pluginVersion 2.1.0.68
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.WindowsStore_12008.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe" -ServerName:App.AppXc75wvwned5vhz4xyxxecvgdjhdkgsdza.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.ZuneMusic_10.20032.12611.0_x64__8wekyb3d8bbwe\Music.UI.exe" -ServerName:Microsoft.ZuneMusic.AppX48dcrcgzqqdshm3kf61t0cm5e9pyd6h6.mca
"C:\Windows\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
C:\Windows\System32\oobe\UserOOBEBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.20070.10002.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding

C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost
"C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20032.16211.0_x64__8wekyb3d8bbwe\Video.UI.exe" -ServerName:Microsoft.ZuneVideo.AppX758ya5sqdjd98rx6z7g95nw6jy7bqx9y.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding

C:\Windows\System32\smartscreen.exe -Embedding
C:\WINDOWS\system32\AUDIODG.EXE 0x5c4

"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe104_ Global\UsGthrCtrlFltPipeMssGthrPipe104 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 788 792 800 8192 796 772
"C:\Users\Milan\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\nfmios0o.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 32.0.0.414 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_414.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.241.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_241\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.241.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_241\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 32.0.0.414 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_32_0_0_414.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll


C:\Users\Milan\AppData\Roaming\Mozilla\Firefox\Profiles\nfmios0o.default\extensions\
passwordmanager@avira.com

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.44\BHO\ie_to_edge_bho_64.dll [2020-08-30 500624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9F904093-6E18-4536-BF5F-B03689CF00F0}]
Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\x64\IEExt\ie_plugin.dll [2020-06-22 2960456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.44\BHO\ie_to_edge_bho.dll [2020-08-30 386960]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_241\bin\ssv.dll [2020-02-09 480320]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9F904093-6E18-4536-BF5F-B03689CF00F0}]
Kaspersky Protection - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\IEExt\ie_plugin.dll [2020-06-22 2401352]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_241\bin\jp2ssv.dll [2020-02-09 194624]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{b60873b9-51aa-4566-b2fc-c16de2ec8bff}
{EF293C5A-9F37-49FD-91C4-2B867063FC54} - Kaspersky Protection Toolbar - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\x64\IEExt\ie_plugin.dll [2020-06-22 2960456]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{b60873b9-51aa-4566-b2fc-c16de2ec8bff}
{EF293C5A-9F37-49FD-91C4-2B867063FC54} - Kaspersky Protection Toolbar - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\IEExt\ie_plugin.dll [2020-06-22 2401352]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\WINDOWS\system32\SecurityHealthSystray.exe [2019-12-07 86016]
"Skd8821"=C:\Program Files\Lenovo\Lenovo Slim USB Keyboard\Skd8821.exe [2015-12-30 2209056]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2017-07-13 18384352]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\Milan\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2020-08-17 1911152]
"CCleaner Smart Cleaning"=C:\Program Files\CCleaner\CCleaner64.exe [2019-10-14 24552064]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Opera Browser Assistant"=C:\Program Files (x86)\Opera\assistant\browser_assistant.exe [2020-09-02 3126808]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
HP Digital Imaging Monitor.lnk - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CBDHSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NgcCtnrSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NgcSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CBDHSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudAddService.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudBus.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsQuic]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NgcCtnrSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NgcSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\usbaudio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableFullTrustStartupTasks"=2
"EnableUwpStartupTasks"=2
"SupportFullTrustStartupTasks"=1
"SupportUwpStartupTasks"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"aux"=wdmaud.drv
"midi"=wdmaud.drv
"midimapper"=midimap.dll
"mixer"=wdmaud.drv
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wave"=wdmaud.drv
"wavemapper"=msacm32.drv
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"aux1"=wdmaud.drv
"midi1"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer1"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave1"=wdmaud.drv
"wave2"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"aux2"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave3"=wdmaud.drv

======File associations======

.inf - install -
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2020-09-06 19:25:24 ----D---- C:\Program Files\trend micro
2020-09-06 19:25:23 ----D---- C:\rsit
2020-08-30 10:41:45 ----D---- C:\Program Files (x86)\Mozilla Thunderbird
2020-08-21 19:32:02 ----D---- C:\mp3
2020-08-20 10:54:49 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_klbg.sys
2020-08-20 08:53:24 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_arkmon.sys
2020-08-13 17:00:14 ----A---- C:\WINDOWS\system32\fvecpl.dll
2020-08-13 17:00:13 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2020-08-13 17:00:13 ----A---- C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2020-08-13 17:00:13 ----A---- C:\WINDOWS\system32\WinBioDataModel.dll
2020-08-13 17:00:11 ----A---- C:\WINDOWS\system32\WalletService.dll
2020-08-13 17:00:02 ----A---- C:\WINDOWS\system32\cdp.dll
2020-08-13 17:00:02 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2020-08-13 16:59:52 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2020-08-13 16:59:51 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2020-08-13 16:59:50 ----A---- C:\WINDOWS\SYSWOW64\syncutil.dll
2020-08-13 16:59:50 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2020-08-13 16:59:49 ----A---- C:\WINDOWS\system32\syncutil.dll
2020-08-13 16:59:49 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2020-08-13 16:58:23 ----A---- C:\WINDOWS\SYSWOW64\WMVDECOD.DLL
2020-08-13 16:58:22 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2020-08-13 16:58:22 ----A---- C:\WINDOWS\SYSWOW64\MP4SDECD.DLL
2020-08-13 16:58:22 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2020-08-13 16:58:22 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2020-08-13 16:58:22 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2020-08-13 16:58:21 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2020-08-13 16:58:21 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2020-08-13 16:58:21 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2020-08-13 16:58:21 ----A---- C:\WINDOWS\system32\DolbyDecMFT.dll
2020-08-13 16:58:19 ----A---- C:\WINDOWS\system32\Hydrogen.dll
2020-08-13 16:58:18 ----A---- C:\WINDOWS\system32\HolographicExtensions.dll
2020-08-13 16:58:18 ----A---- C:\WINDOWS\system32\HologramWorld.dll
2020-08-13 16:58:17 ----A---- C:\WINDOWS\system32\WMVDECOD.DLL
2020-08-13 16:58:17 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2020-08-13 16:58:17 ----A---- C:\WINDOWS\system32\MSAudDecMFT.dll
2020-08-13 16:58:17 ----A---- C:\WINDOWS\system32\MP4SDECD.DLL
2020-08-13 16:58:16 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2020-08-13 16:58:16 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2020-08-13 16:58:16 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-08-13 16:58:16 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2020-08-13 16:58:15 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2020-08-13 16:58:15 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2020-08-13 16:58:15 ----A---- C:\WINDOWS\system32\mfcore.dll
2020-08-13 16:58:14 ----A---- C:\WINDOWS\system32\mf.dll
2020-08-13 16:58:09 ----A---- C:\WINDOWS\SYSWOW64\Vault.dll
2020-08-13 16:58:09 ----A---- C:\WINDOWS\SYSWOW64\mstsc.exe
2020-08-13 16:58:09 ----A---- C:\WINDOWS\SYSWOW64\AcSpecfc.dll
2020-08-13 16:58:08 ----A---- C:\WINDOWS\SYSWOW64\themecpl.dll
2020-08-13 16:58:08 ----A---- C:\WINDOWS\SYSWOW64\tapisrv.dll
2020-08-13 16:58:08 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2020-08-13 16:58:07 ----A---- C:\WINDOWS\SYSWOW64\wsp_health.dll
2020-08-13 16:58:07 ----A---- C:\WINDOWS\SYSWOW64\wsp_fs.dll
2020-08-13 16:58:07 ----A---- C:\WINDOWS\SYSWOW64\tapi32.dll
2020-08-13 16:58:07 ----A---- C:\WINDOWS\SYSWOW64\mfsensorgroup.dll
2020-08-13 16:58:07 ----A---- C:\WINDOWS\SYSWOW64\FrameServerClient.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\SyncCenter.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\powercpl.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\netcenter.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\msxbde40.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\msrd3x40.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\msjet40.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\msisip.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\msimsg.dll
2020-08-13 16:58:06 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2020-08-13 16:58:05 ----A---- C:\WINDOWS\SYSWOW64\iemigplugin.dll
2020-08-13 16:58:04 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2020-08-13 16:58:04 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2020-08-13 16:58:04 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2020-08-13 16:58:04 ----A---- C:\WINDOWS\SYSWOW64\Chakrathunk.dll
2020-08-13 16:58:04 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2020-08-13 16:58:03 ----A---- C:\WINDOWS\SYSWOW64\IndexedDbLegacy.dll
2020-08-13 16:58:03 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2020-08-13 16:58:02 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2020-08-13 16:58:02 ----A---- C:\WINDOWS\SYSWOW64\EdgeManager.dll
2020-08-13 16:58:01 ----A---- C:\WINDOWS\SYSWOW64\webplatstorageserver.dll
2020-08-13 16:58:00 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2020-08-13 16:58:00 ----A---- C:\WINDOWS\SYSWOW64\FirewallControlPanel.dll
2020-08-13 16:58:00 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2020-08-13 16:58:00 ----A---- C:\WINDOWS\SYSWOW64\Dsui.dll
2020-08-13 16:57:49 ----A---- C:\WINDOWS\SYSWOW64\sud.dll
2020-08-13 16:57:49 ----A---- C:\WINDOWS\SYSWOW64\DxpTaskSync.dll
2020-08-13 16:57:48 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2020-08-13 16:57:48 ----A---- C:\WINDOWS\SYSWOW64\upnphost.dll
2020-08-13 16:57:48 ----A---- C:\WINDOWS\SYSWOW64\upnpcont.exe
2020-08-13 16:57:48 ----A---- C:\WINDOWS\SYSWOW64\udhisapi.dll
2020-08-13 16:57:48 ----A---- C:\WINDOWS\SYSWOW64\fdSSDP.dll
2020-08-13 16:57:48 ----A---- C:\WINDOWS\SYSWOW64\BioCredProv.dll
2020-08-13 16:57:48 ----A---- C:\WINDOWS\SYSWOW64\autoplay.dll
2020-08-13 16:57:43 ----A---- C:\WINDOWS\system32\SpaceControl.dll
2020-08-13 16:57:43 ----A---- C:\WINDOWS\system32\SpaceAgent.exe
2020-08-13 16:57:43 ----A---- C:\WINDOWS\system32\sharemediacpl.dll
2020-08-13 16:57:43 ----A---- C:\WINDOWS\system32\dsregcmd.exe
2020-08-13 16:57:42 ----A---- C:\WINDOWS\system32\WorkfoldersControl.dll
2020-08-13 16:57:42 ----A---- C:\WINDOWS\system32\Windows.Mirage.dll
2020-08-13 16:57:42 ----A---- C:\WINDOWS\system32\SIHClient.exe
2020-08-13 16:57:42 ----A---- C:\WINDOWS\system32\fhcpl.dll
2020-08-13 16:57:41 ----A---- C:\WINDOWS\system32\AcSpecfc.dll
2020-08-13 16:57:41 ----A---- C:\WINDOWS\system32\acmigration.dll
2020-08-13 16:57:41 ----A---- C:\WINDOWS\system32\AcGenral.dll
2020-08-13 16:57:40 ----A---- C:\WINDOWS\system32\Vault.dll
2020-08-13 16:57:40 ----A---- C:\WINDOWS\system32\mstscax.dll
2020-08-13 16:57:40 ----A---- C:\WINDOWS\system32\mstsc.exe
2020-08-13 16:57:40 ----A---- C:\WINDOWS\system32\CPFilters.dll
2020-08-13 16:57:39 ----A---- C:\WINDOWS\system32\wsp_health.dll
2020-08-13 16:57:39 ----A---- C:\WINDOWS\system32\wsp_fs.dll
2020-08-13 16:57:39 ----A---- C:\WINDOWS\system32\themecpl.dll
2020-08-13 16:57:39 ----A---- C:\WINDOWS\system32\tapisrv.dll
2020-08-13 16:57:39 ----A---- C:\WINDOWS\system32\tapi32.dll
2020-08-13 16:57:39 ----A---- C:\WINDOWS\system32\rdpclip.exe
2020-08-13 16:57:39 ----A---- C:\WINDOWS\system32\DiagCpl.dll
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\SysResetErr.exe
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\SyncCenter.dll
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\ResetEngine.exe
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\reseteng.dll
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\RecoveryDrive.exe
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\recovery.dll
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\mfsensorgroup.dll
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\FrameServerClient.dll
2020-08-13 16:57:38 ----A---- C:\WINDOWS\system32\FrameServer.dll
2020-08-13 16:57:37 ----A---- C:\WINDOWS\system32\systemreset.exe
2020-08-13 16:57:37 ----A---- C:\WINDOWS\system32\ResetEngOnline.dll
2020-08-13 16:57:37 ----A---- C:\WINDOWS\system32\ResetEngine.dll
2020-08-13 16:57:36 ----A---- C:\WINDOWS\system32\powercpl.dll
2020-08-13 16:57:36 ----A---- C:\WINDOWS\system32\netcenter.dll
2020-08-13 16:57:36 ----A---- C:\WINDOWS\system32\msisip.dll
2020-08-13 16:57:36 ----A---- C:\WINDOWS\system32\msimsg.dll
2020-08-13 16:57:35 ----A---- C:\WINDOWS\system32\msi.dll
2020-08-13 16:57:35 ----A---- C:\WINDOWS\system32\IESettingSync.exe
2020-08-13 16:57:35 ----A---- C:\WINDOWS\system32\iemigplugin.dll
2020-08-13 16:57:34 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2020-08-13 16:57:34 ----A---- C:\WINDOWS\system32\jscript9.dll
2020-08-13 16:57:34 ----A---- C:\WINDOWS\system32\ieframe.dll
2020-08-13 16:57:33 ----A---- C:\WINDOWS\system32\IndexedDbLegacy.dll
2020-08-13 16:57:33 ----A---- C:\WINDOWS\system32\Chakrathunk.dll
2020-08-13 16:57:33 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2020-08-13 16:57:33 ----A---- C:\WINDOWS\system32\Chakra.dll
2020-08-13 16:57:31 ----A---- C:\WINDOWS\system32\mshtml.dll
2020-08-13 16:57:30 ----A---- C:\WINDOWS\system32\webplatstorageserver.dll
2020-08-13 16:57:30 ----A---- C:\WINDOWS\system32\EdgeManager.dll
2020-08-13 16:57:29 ----A---- C:\WINDOWS\system32\edgehtml.dll
2020-08-13 16:57:28 ----A---- C:\WINDOWS\system32\wiatrace.dll
2020-08-13 16:57:28 ----A---- C:\WINDOWS\system32\wiaservc.dll
2020-08-13 16:57:28 ----A---- C:\WINDOWS\system32\wiarpc.dll
2020-08-13 16:57:28 ----A---- C:\WINDOWS\system32\werconcpl.dll
2020-08-13 16:57:28 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2020-08-13 16:57:28 ----A---- C:\WINDOWS\system32\sti.dll
2020-08-13 16:57:28 ----A---- C:\WINDOWS\system32\jscript.dll
2020-08-13 16:57:28 ----A---- C:\WINDOWS\system32\FirewallControlPanel.dll
2020-08-13 16:57:27 ----A---- C:\WINDOWS\system32\sud.dll
2020-08-13 16:57:27 ----A---- C:\WINDOWS\system32\StorSvc.dll
2020-08-13 16:57:27 ----A---- C:\WINDOWS\system32\DxpTaskSync.dll
2020-08-13 16:57:27 ----A---- C:\WINDOWS\system32\DXP.dll
2020-08-13 16:57:27 ----A---- C:\WINDOWS\system32\Dsui.dll
2020-08-13 16:57:27 ----A---- C:\WINDOWS\system32\autoplay.dll
2020-08-13 16:57:09 ----A---- C:\WINDOWS\system32\wsecedit.dll
2020-08-13 16:57:09 ----A---- C:\WINDOWS\system32\MDMAppInstaller.exe
2020-08-13 16:57:09 ----A---- C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2020-08-13 16:57:08 ----A---- C:\WINDOWS\system32\edpcsp.dll
2020-08-13 16:57:08 ----A---- C:\WINDOWS\system32\computecore.dll
2020-08-13 16:57:06 ----A---- C:\WINDOWS\system32\sdshext.dll
2020-08-13 16:57:06 ----A---- C:\WINDOWS\system32\sdrsvc.dll
2020-08-13 16:57:06 ----A---- C:\WINDOWS\system32\sdclt.exe
2020-08-13 16:57:05 ----A---- C:\WINDOWS\system32\tcbloader.dll
2020-08-13 16:57:05 ----A---- C:\WINDOWS\system32\skci.dll
2020-08-13 16:57:05 ----A---- C:\WINDOWS\system32\sdengin2.dll
2020-08-13 16:57:05 ----A---- C:\WINDOWS\system32\sdcpl.dll
2020-08-13 16:57:04 ----A---- C:\WINDOWS\system32\ucrtbase_enclave.dll
2020-08-13 16:57:04 ----A---- C:\WINDOWS\system32\tcblaunch.exe
2020-08-13 16:57:04 ----A---- C:\WINDOWS\system32\securekernel.exe
2020-08-13 16:57:04 ----A---- C:\WINDOWS\system32\hvix64.exe
2020-08-13 16:57:03 ----A---- C:\WINDOWS\system32\upnphost.dll
2020-08-13 16:57:03 ----A---- C:\WINDOWS\system32\upnpcont.exe
2020-08-13 16:57:03 ----A---- C:\WINDOWS\system32\udhisapi.dll
2020-08-13 16:57:03 ----A---- C:\WINDOWS\system32\NgcIso.exe
2020-08-13 16:57:03 ----A---- C:\WINDOWS\system32\hvax64.exe
2020-08-13 16:57:03 ----A---- C:\WINDOWS\system32\fdSSDP.dll
2020-08-13 16:57:03 ----A---- C:\WINDOWS\system32\BioIso.exe
2020-08-13 16:57:02 ----A---- C:\WINDOWS\SYSWOW64\Windows.FileExplorer.Common.dll
2020-08-13 16:57:02 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2020-08-13 16:57:02 ----A---- C:\WINDOWS\SYSWOW64\OpenWith.exe
2020-08-13 16:57:01 ----A---- C:\WINDOWS\SYSWOW64\scecli.dll
2020-08-13 16:57:01 ----A---- C:\WINDOWS\SYSWOW64\rasdlg.dll
2020-08-13 16:57:01 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2020-08-13 16:57:01 ----A---- C:\WINDOWS\SYSWOW64\iprtrmgr.dll
2020-08-13 16:57:01 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2020-08-13 16:57:00 ----A---- C:\WINDOWS\SYSWOW64\rtm.dll
2020-08-13 16:57:00 ----A---- C:\WINDOWS\SYSWOW64\rasplap.dll
2020-08-13 16:57:00 ----A---- C:\WINDOWS\SYSWOW64\puiobj.dll
2020-08-13 16:57:00 ----A---- C:\WINDOWS\SYSWOW64\printui.exe
2020-08-13 16:57:00 ----A---- C:\WINDOWS\SYSWOW64\mprdim.dll
2020-08-13 16:57:00 ----A---- C:\WINDOWS\SYSWOW64\iprtprio.dll
2020-08-13 16:57:00 ----A---- C:\WINDOWS\SYSWOW64\findnetprinters.dll
2020-08-13 16:57:00 ----A---- C:\WINDOWS\SYSWOW64\DafPrintProvider.dll
2020-08-13 16:56:59 ----A---- C:\WINDOWS\SYSWOW64\XpsPrint.dll
2020-08-13 16:56:59 ----A---- C:\WINDOWS\SYSWOW64\rasgcw.dll
2020-08-13 16:56:59 ----A---- C:\WINDOWS\SYSWOW64\puiapi.dll
2020-08-13 16:56:59 ----A---- C:\WINDOWS\SYSWOW64\newdev.exe
2020-08-13 16:56:59 ----A---- C:\WINDOWS\SYSWOW64\newdev.dll
2020-08-13 16:56:59 ----A---- C:\WINDOWS\SYSWOW64\ndadmin.exe
2020-08-13 16:56:59 ----A---- C:\WINDOWS\SYSWOW64\drvsetup.dll
2020-08-13 16:56:59 ----A---- C:\WINDOWS\SYSWOW64\compstui.dll
2020-08-13 16:56:58 ----A---- C:\WINDOWS\SYSWOW64\wlidnsp.dll
2020-08-13 16:56:58 ----A---- C:\WINDOWS\SYSWOW64\wlidfdp.dll
2020-08-13 16:56:58 ----A---- C:\WINDOWS\SYSWOW64\wlidcredprov.dll
2020-08-13 16:56:58 ----A---- C:\WINDOWS\SYSWOW64\wlidcli.dll
2020-08-13 16:56:58 ----A---- C:\WINDOWS\SYSWOW64\windowslivelogin.dll
2020-08-13 16:56:58 ----A---- C:\WINDOWS\SYSWOW64\msidcrl40.dll
2020-08-13 16:56:58 ----A---- C:\WINDOWS\SYSWOW64\msauserext.dll
2020-08-13 16:56:58 ----A---- C:\WINDOWS\SYSWOW64\MicrosoftAccountTokenProvider.dll
2020-08-13 16:56:57 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2020-08-13 16:56:57 ----A---- C:\WINDOWS\SYSWOW64\instnm.exe
2020-08-13 16:56:56 ----A---- C:\WINDOWS\SYSWOW64\wow32.dll
2020-08-13 16:56:56 ----A---- C:\WINDOWS\SYSWOW64\user.exe
2020-08-13 16:56:56 ----A---- C:\WINDOWS\SYSWOW64\setup16.exe
2020-08-13 16:56:56 ----A---- C:\WINDOWS\SYSWOW64\ntvdm64.dll
2020-08-13 16:56:56 ----A---- C:\WINDOWS\SYSWOW64\msIso.dll
2020-08-13 16:56:56 ----A---- C:\WINDOWS\SYSWOW64\edgeIso.dll
2020-08-13 16:56:56 ----A---- C:\WINDOWS\SYSWOW64\acwow64.dll
2020-08-13 16:56:55 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2020-08-13 16:56:55 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2020-08-13 16:56:55 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2020-08-13 16:56:55 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2020-08-13 16:56:55 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2020-08-13 16:56:54 ----A---- C:\WINDOWS\SYSWOW64\UserAccountControlSettings.dll
2020-08-13 16:56:54 ----A---- C:\WINDOWS\SYSWOW64\hgcpl.dll
2020-08-13 16:56:54 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2020-08-13 16:56:54 ----A---- C:\WINDOWS\SYSWOW64\DMAlertListener.ProxyStub.dll
2020-08-13 16:56:54 ----A---- C:\WINDOWS\SYSWOW64\d3d9.dll
2020-08-13 16:56:54 ----A---- C:\WINDOWS\SYSWOW64\d3d8thk.dll
2020-08-13 16:56:54 ----A---- C:\WINDOWS\SYSWOW64\ActionCenterCPL.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\unenrollhook.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\omadmapi.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\mdmlocalmanagement.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\enterpriseresourcemanager.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\enrollmentapi.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2020-08-13 16:56:53 ----A---- C:\WINDOWS\SYSWOW64\dmcmnutils.dll
2020-08-13 16:56:52 ----A---- C:\WINDOWS\SYSWOW64\msimg32.dll
2020-08-13 16:56:52 ----A---- C:\WINDOWS\SYSWOW64\mf3216.dll
2020-08-13 16:56:52 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2020-08-13 16:56:52 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2020-08-13 16:56:52 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2020-08-13 16:56:52 ----A---- C:\WINDOWS\SYSWOW64\dmcfgutils.dll
2020-08-13 16:56:51 ----A---- C:\WINDOWS\SYSWOW64\wermgr.exe
2020-08-13 16:56:51 ----A---- C:\WINDOWS\SYSWOW64\weretw.dll
2020-08-13 16:56:51 ----A---- C:\WINDOWS\SYSWOW64\werdiagcontroller.dll
2020-08-13 16:56:51 ----A---- C:\WINDOWS\SYSWOW64\wer.dll
2020-08-13 16:56:51 ----A---- C:\WINDOWS\SYSWOW64\netlogon.dll
2020-08-13 16:56:51 ----A---- C:\WINDOWS\SYSWOW64\dtdump.exe
2020-08-13 16:56:51 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2020-08-13 16:56:50 ----A---- C:\WINDOWS\SYSWOW64\wldp.dll
2020-08-13 16:56:50 ----A---- C:\WINDOWS\SYSWOW64\ucrtbase.dll
2020-08-13 16:56:50 ----A---- C:\WINDOWS\SYSWOW64\mswsock.dll
2020-08-13 16:56:50 ----A---- C:\WINDOWS\SYSWOW64\msvcp_win.dll
2020-08-13 16:56:50 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2020-08-13 16:56:50 ----A---- C:\WINDOWS\SYSWOW64\dwmapi.dll
2020-08-13 16:56:50 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2020-08-13 16:56:50 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2020-08-13 16:56:49 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2020-08-13 16:56:49 ----A---- C:\WINDOWS\SYSWOW64\setupcl.dll
2020-08-13 16:56:49 ----A---- C:\WINDOWS\SYSWOW64\pcaui.dll
2020-08-13 16:56:48 ----A---- C:\WINDOWS\SYSWOW64\wups.dll
2020-08-13 16:56:48 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2020-08-13 16:56:48 ----A---- C:\WINDOWS\SYSWOW64\PCShellCommonProxyStub.dll
2020-08-13 16:56:48 ----A---- C:\WINDOWS\SYSWOW64\pcacli.dll
2020-08-13 16:56:48 ----A---- C:\WINDOWS\SYSWOW64\accessibilitycpl.dll
2020-08-13 16:56:31 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2020-08-13 16:56:31 ----A---- C:\WINDOWS\SYSWOW64\win32k.sys
2020-08-13 16:56:31 ----A---- C:\WINDOWS\SYSWOW64\mdmregistration.dll
2020-08-13 16:56:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.OnlineId.dll
2020-08-13 16:56:30 ----A---- C:\WINDOWS\SYSWOW64\win32u.dll
2020-08-13 16:56:30 ----A---- C:\WINDOWS\SYSWOW64\mskeyprotcli.dll
2020-08-13 16:56:30 ----A---- C:\WINDOWS\SYSWOW64\D3D12.dll
2020-08-13 16:56:30 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2020-08-13 16:56:29 ----A---- C:\WINDOWS\SYSWOW64\wpnapps.dll
2020-08-13 16:56:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryUpgrade.dll
2020-08-13 16:56:29 ----A---- C:\WINDOWS\SYSWOW64\StateRepository.Core.dll
2020-08-13 16:56:29 ----A---- C:\WINDOWS\SYSWOW64\OneCoreUAPCommonProxyStub.dll
2020-08-13 16:56:29 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2020-08-13 16:56:28 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2020-08-13 16:56:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryPS.dll
2020-08-13 16:56:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryCore.dll
2020-08-13 16:56:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2020-08-13 16:56:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryBroker.dll
2020-08-13 16:56:28 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2020-08-13 16:56:28 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2020-08-13 16:56:27 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2020-08-13 16:56:27 ----A---- C:\WINDOWS\SYSWOW64\TileDataRepository.dll
2020-08-13 16:56:27 ----A---- C:\WINDOWS\SYSWOW64\MbaeApiPublic.dll
2020-08-13 16:56:27 ----A---- C:\WINDOWS\SYSWOW64\MapRouter.dll
2020-08-13 16:56:27 ----A---- C:\WINDOWS\SYSWOW64\InstallService.dll
2020-08-13 16:56:26 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2020-08-13 16:56:26 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2020-08-13 16:56:26 ----A---- C:\WINDOWS\SYSWOW64\TextShaping.dll
2020-08-13 16:56:26 ----A---- C:\WINDOWS\SYSWOW64\TextInputMethodFormatter.dll
2020-08-13 16:56:26 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2020-08-13 16:56:26 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2020-08-13 16:56:26 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostUser.dll
2020-08-13 16:56:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.AccountsControl.dll
2020-08-13 16:56:25 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostCommon.dll
2020-08-13 16:56:25 ----A---- C:\WINDOWS\SYSWOW64\ActivationManager.dll
2020-08-13 16:56:24 ----A---- C:\WINDOWS\SYSWOW64\wlidprov.dll
2020-08-13 16:56:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.System.Launcher.dll
2020-08-13 16:56:24 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2020-08-13 16:56:24 ----A---- C:\WINDOWS\SYSWOW64\UiaManager.dll
2020-08-13 16:56:24 ----A---- C:\WINDOWS\SYSWOW64\GameInput.dll
2020-08-13 16:56:23 ----A---- C:\WINDOWS\SYSWOW64\Windows.Data.Pdf.dll
2020-08-13 16:56:23 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2020-08-13 16:56:23 ----A---- C:\WINDOWS\SYSWOW64\MicrosoftAccountWAMExtension.dll
2020-08-13 16:56:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.HostName.dll
2020-08-13 16:56:22 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Connectivity.dll
2020-08-13 16:56:22 ----A---- C:\WINDOWS\SYSWOW64\cdprt.dll
2020-08-13 16:56:22 ----A---- C:\WINDOWS\SYSWOW64\AppxAllUserStore.dll
2020-08-13 16:56:21 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2020-08-13 16:56:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2020-08-13 16:56:21 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-08-13 16:56:21 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2020-08-13 16:56:21 ----A---- C:\WINDOWS\SYSWOW64\mapistub.dll
2020-08-13 16:56:21 ----A---- C:\WINDOWS\SYSWOW64\mapi32.dll
2020-08-13 16:56:21 ----A---- C:\WINDOWS\SYSWOW64\fixmapi.exe
2020-08-13 16:56:20 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2020-08-13 16:56:20 ----A---- C:\WINDOWS\SYSWOW64\taskschd.dll
2020-08-13 16:56:20 ----A---- C:\WINDOWS\SYSWOW64\taskcomp.dll
2020-08-13 16:56:20 ----A---- C:\WINDOWS\SYSWOW64\systemcpl.dll
2020-08-13 16:56:20 ----A---- C:\WINDOWS\SYSWOW64\RADCUI.dll
2020-08-13 16:56:20 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2020-08-13 16:56:19 ----A---- C:\WINDOWS\SYSWOW64\wcmapi.dll
2020-08-13 16:56:19 ----A---- C:\WINDOWS\SYSWOW64\sxstrace.exe
2020-08-13 16:56:19 ----A---- C:\WINDOWS\SYSWOW64\sxs.dll
2020-08-13 16:56:19 ----A---- C:\WINDOWS\SYSWOW64\ShellCommonCommonProxyStub.dll
2020-08-13 16:56:19 ----A---- C:\WINDOWS\SYSWOW64\fontext.dll
2020-08-13 16:56:19 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2020-08-13 16:56:19 ----A---- C:\WINDOWS\SYSWOW64\control.exe
2020-08-13 16:56:18 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2020-08-13 16:56:18 ----A---- C:\WINDOWS\SYSWOW64\Wpc.dll
2020-08-13 16:56:17 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.ConversationalAgent.dll
2020-08-13 16:56:17 ----A---- C:\WINDOWS\SYSWOW64\SpatializerApo.dll
2020-08-13 16:56:17 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2020-08-13 16:56:17 ----A---- C:\WINDOWS\SYSWOW64\HrtfApo.dll
2020-08-13 16:56:17 ----A---- C:\WINDOWS\SYSWOW64\FlightSettings.dll
2020-08-13 16:56:17 ----A---- C:\WINDOWS\SYSWOW64\ContentDeliveryManager.Utilities.dll
2020-08-13 16:56:16 ----A---- C:\WINDOWS\SYSWOW64\agentactivationruntimewindows.dll
2020-08-13 16:56:16 ----A---- C:\WINDOWS\SYSWOW64\agentactivationruntime.dll
2020-08-13 16:56:16 ----A---- C:\WINDOWS\SYSWOW64\AarSvc.dll
2020-08-13 16:56:16 ----A---- C:\WINDOWS\system32\MBR2GPT.EXE
2020-08-13 16:56:10 ----A---- C:\WINDOWS\system32\ScDeviceEnum.dll
2020-08-13 16:56:10 ----A---- C:\WINDOWS\system32\SCardDlg.dll
2020-08-13 16:56:10 ----A---- C:\WINDOWS\system32\SCardBi.dll
2020-08-13 16:56:10 ----A---- C:\WINDOWS\system32\ngctasks.dll
2020-08-13 16:56:10 ----A---- C:\WINDOWS\system32\drivers\scfilter.sys
2020-08-13 16:56:10 ----A---- C:\WINDOWS\system32\certprop.dll
2020-08-13 16:55:52 ----A---- C:\WINDOWS\system32\SCardSvr.dll
2020-08-13 16:55:50 ----A---- C:\WINDOWS\system32\Windows.FileExplorer.Common.dll
2020-08-13 16:55:50 ----A---- C:\WINDOWS\system32\shell32.dll
2020-08-13 16:55:50 ----A---- C:\WINDOWS\system32\scecli.dll
2020-08-13 16:55:50 ----A---- C:\WINDOWS\system32\rasdlg.dll
2020-08-13 16:55:50 ----A---- C:\WINDOWS\system32\OpenWith.exe
2020-08-13 16:55:50 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2020-08-13 16:55:49 ----A---- C:\WINDOWS\system32\rasmans.dll
2020-08-13 16:55:49 ----A---- C:\WINDOWS\system32\rascustom.dll
2020-08-13 16:55:49 ----A---- C:\WINDOWS\system32\rasapi32.dll
2020-08-13 16:55:49 ----A---- C:\WINDOWS\system32\iprtrmgr.dll
2020-08-13 16:55:49 ----A---- C:\WINDOWS\system32\iprtprio.dll
2020-08-13 16:55:48 ----A---- C:\WINDOWS\system32\rtm.dll
2020-08-13 16:55:48 ----A---- C:\WINDOWS\system32\RMapi.dll
2020-08-13 16:55:48 ----A---- C:\WINDOWS\system32\rasplap.dll
2020-08-13 16:55:48 ----A---- C:\WINDOWS\system32\printui.exe
2020-08-13 16:55:48 ----A---- C:\WINDOWS\system32\mprdim.dll
2020-08-13 16:55:48 ----A---- C:\WINDOWS\system32\findnetprinters.dll
2020-08-13 16:55:48 ----A---- C:\WINDOWS\system32\DafPrintProvider.dll
2020-08-13 16:55:47 ----A---- C:\WINDOWS\system32\puiobj.dll
2020-08-13 16:55:47 ----A---- C:\WINDOWS\system32\puiapi.dll
2020-08-13 16:55:47 ----A---- C:\WINDOWS\system32\compstui.dll
2020-08-13 16:55:46 ----A---- C:\WINDOWS\system32\xpsservices.dll
2020-08-13 16:55:46 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2020-08-13 16:55:46 ----A---- C:\WINDOWS\system32\drvsetup.dll
2020-08-13 16:55:45 ----A---- C:\WINDOWS\system32\SystemSettings.Handlers.dll
2020-08-13 16:55:45 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2020-08-13 16:55:45 ----A---- C:\WINDOWS\system32\SettingsHandlers_Gpu.dll
2020-08-13 16:55:45 ----A---- C:\WINDOWS\system32\newdev.exe
2020-08-13 16:55:45 ----A---- C:\WINDOWS\system32\newdev.dll
2020-08-13 16:55:45 ----A---- C:\WINDOWS\system32\ndadmin.exe
2020-08-13 16:55:45 ----A---- C:\WINDOWS\system32\AboutSettingsHandlers.dll
2020-08-13 16:55:45 ----A---- C:\WINDOWS\system32\6bea57fb-8dfb-4177-9ae8-42e8b3529933_RuntimeDeviceInstall.dll
2020-08-13 16:55:44 ----A---- C:\WINDOWS\system32\npmproxy.dll
2020-08-13 16:55:44 ----A---- C:\WINDOWS\system32\nlmsprep.dll
2020-08-13 16:55:44 ----A---- C:\WINDOWS\system32\nlmproxy.dll
2020-08-13 16:55:44 ----A---- C:\WINDOWS\system32\netprofmsvc.dll
2020-08-13 16:55:44 ----A---- C:\WINDOWS\system32\netprofm.dll
2020-08-13 16:55:43 ----A---- C:\WINDOWS\system32\taskschd.dll
2020-08-13 16:55:43 ----A---- C:\WINDOWS\system32\taskcomp.dll
2020-08-13 16:55:43 ----A---- C:\WINDOWS\system32\systemcpl.dll
2020-08-13 16:55:43 ----A---- C:\WINDOWS\system32\schedsvc.dll
2020-08-13 16:55:43 ----A---- C:\WINDOWS\system32\rasgcw.dll
2020-08-13 16:55:42 ----A---- C:\WINDOWS\system32\wsqmcons.exe
2020-08-13 16:55:42 ----A---- C:\WINDOWS\system32\sxstrace.exe
2020-08-13 16:55:42 ----A---- C:\WINDOWS\system32\sxs.dll
2020-08-13 16:55:42 ----A---- C:\WINDOWS\system32\sppobjs.dll
2020-08-13 16:55:42 ----A---- C:\WINDOWS\system32\SppExtComObj.Exe
2020-08-13 16:55:41 ----A---- C:\WINDOWS\system32\sppsvc.exe
2020-08-13 16:55:41 ----A---- C:\WINDOWS\system32\sppcext.dll
2020-08-13 16:55:41 ----A---- C:\WINDOWS\system32\MaintenanceUI.dll
2020-08-13 16:55:40 ----A---- C:\WINDOWS\system32\WUDFx02000.dll
2020-08-13 16:55:39 ----A---- C:\WINDOWS\system32\wlidnsp.dll
2020-08-13 16:55:39 ----A---- C:\WINDOWS\system32\wlidfdp.dll
2020-08-13 16:55:39 ----A---- C:\WINDOWS\system32\wlidcredprov.dll
2020-08-13 16:55:39 ----A---- C:\WINDOWS\system32\wlidcli.dll
2020-08-13 16:55:39 ----A---- C:\WINDOWS\system32\LockHostingFramework.dll
2020-08-13 16:55:39 ----A---- C:\WINDOWS\system32\LockController.dll
2020-08-13 16:55:39 ----A---- C:\WINDOWS\system32\LockAppHost.exe
2020-08-13 16:55:38 ----A---- C:\WINDOWS\system32\windowslivelogin.dll
2020-08-13 16:55:38 ----A---- C:\WINDOWS\system32\msidcrl40.dll
2020-08-13 16:55:38 ----A---- C:\WINDOWS\system32\msauserext.dll
2020-08-13 16:55:38 ----A---- C:\WINDOWS\system32\lpkinstall.exe
2020-08-13 16:55:37 ----A---- C:\WINDOWS\system32\msIso.dll
2020-08-13 16:55:37 ----A---- C:\WINDOWS\system32\jsproxy.dll
2020-08-13 16:55:37 ----A---- C:\WINDOWS\system32\iertutil.dll
2020-08-13 16:55:37 ----A---- C:\WINDOWS\system32\edgeIso.dll
2020-08-13 16:55:36 ----A---- C:\WINDOWS\system32\wininet.dll
2020-08-13 16:55:36 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2020-08-13 16:55:36 ----A---- C:\WINDOWS\system32\actxprxy.dll
2020-08-13 16:55:35 ----A---- C:\WINDOWS\system32\hgcpl.dll
2020-08-13 16:55:34 ----A---- C:\WINDOWS\system32\UserAccountControlSettings.dll
2020-08-13 16:55:34 ----A---- C:\WINDOWS\system32\ActionCenterCPL.dll
2020-08-13 16:55:26 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2020-08-13 16:55:25 ----A---- C:\WINDOWS\system32\d3d9.dll
2020-08-13 16:55:25 ----A---- C:\WINDOWS\system32\d3d8thk.dll
2020-08-13 16:55:19 ----A---- C:\WINDOWS\system32\MdmDiagnostics.dll
2020-08-13 16:55:19 ----A---- C:\WINDOWS\system32\DMAlertListener.ProxyStub.dll
2020-08-13 16:55:19 ----A---- C:\WINDOWS\system32\DeviceDriverRetrievalClient.dll
2020-08-13 16:55:16 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2020-08-13 16:55:16 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2020-08-13 16:55:16 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2020-08-13 16:55:16 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2020-08-13 16:55:11 ----A---- C:\WINDOWS\system32\unenrollhook.dll
2020-08-13 16:55:11 ----A---- C:\WINDOWS\system32\omadmclient.exe
2020-08-13 16:55:11 ----A---- C:\WINDOWS\system32\omadmapi.dll
2020-08-13 16:55:11 ----A---- C:\WINDOWS\system32\mdmpostprocessevaluator.dll
2020-08-13 16:55:11 ----A---- C:\WINDOWS\system32\mdmlocalmanagement.dll
2020-08-13 16:55:11 ----A---- C:\WINDOWS\system32\enterpriseresourcemanager.dll
2020-08-13 16:55:11 ----A---- C:\WINDOWS\system32\dmenterprisediagnostics.dll
2020-08-13 16:55:10 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2020-08-13 16:54:53 ----A---- C:\WINDOWS\system32\policymanager.dll
2020-08-13 16:54:53 ----A---- C:\WINDOWS\system32\DMPushRouterCore.dll
2020-08-13 16:54:53 ----A---- C:\WINDOWS\system32\dmcsps.dll
2020-08-13 16:54:53 ----A---- C:\WINDOWS\system32\dmcmnutils.dll
2020-08-13 16:54:53 ----A---- C:\WINDOWS\system32\dmcfgutils.dll
2020-08-13 16:54:53 ----A---- C:\WINDOWS\system32\coredpus.dll
2020-08-13 16:54:52 ----A---- C:\WINDOWS\system32\LogonController.dll
2020-08-13 16:54:52 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2020-08-13 16:54:52 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2020-08-13 16:54:52 ----A---- C:\WINDOWS\system32\cryptcatsvc.dll
2020-08-13 16:54:52 ----A---- C:\WINDOWS\system32\configmanager2.dll
2020-08-13 16:54:49 ----A---- C:\WINDOWS\system32\wuuhext.dll
2020-08-13 16:54:49 ----A---- C:\WINDOWS\system32\msimg32.dll
2020-08-13 16:54:49 ----A---- C:\WINDOWS\system32\mf3216.dll
2020-08-13 16:54:48 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2020-08-13 16:54:48 ----A---- C:\WINDOWS\system32\lpk.dll
2020-08-13 16:54:48 ----A---- C:\WINDOWS\system32\fontsub.dll
2020-08-13 16:54:48 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2020-08-13 16:54:48 ----A---- C:\WINDOWS\system32\dciman32.dll
2020-08-13 16:54:47 ----A---- C:\WINDOWS\system32\netlogon.dll
2020-08-13 16:54:47 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2020-08-13 16:54:46 ----A---- C:\WINDOWS\system32\KernelBase.dll
2020-08-13 16:54:46 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2020-08-13 16:54:46 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2020-08-13 16:54:45 ----A---- C:\WINDOWS\system32\drivers\WdfLdr.sys
2020-08-13 16:54:45 ----A---- C:\WINDOWS\system32\drivers\Wdf01000.sys
2020-08-13 16:54:45 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2020-08-13 16:54:41 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2020-08-13 16:54:41 ----A---- C:\WINDOWS\system32\ntdll.dll
2020-08-13 16:54:41 ----A---- C:\WINDOWS\system32\hal.dll
2020-08-13 16:54:41 ----A---- C:\WINDOWS\system32\drivers\hwpolicy.sys
2020-08-13 16:54:40 ----A---- C:\WINDOWS\system32\wersvc.dll
2020-08-13 16:54:40 ----A---- C:\WINDOWS\system32\wermgr.exe
2020-08-13 16:54:40 ----A---- C:\WINDOWS\system32\weretw.dll
2020-08-13 16:54:40 ----A---- C:\WINDOWS\system32\werdiagcontroller.dll
2020-08-13 16:54:39 ----A---- C:\WINDOWS\system32\wer.dll
2020-08-13 16:54:39 ----A---- C:\WINDOWS\system32\utcutil.dll
2020-08-13 16:54:39 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2020-08-13 16:54:39 ----A---- C:\WINDOWS\system32\lsasrv.dll
2020-08-13 16:54:39 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2020-08-13 16:54:39 ----A---- C:\WINDOWS\system32\diagtrack.dll
2020-08-13 16:54:39 ----A---- C:\WINDOWS\system32\diagnosticdataquery.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\wldp.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\ucrtbase.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\SecurityHealthService.exe
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\SecurityHealthHost.exe
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\mswsock.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\msvcp_win.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\msv1_0.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\dnsapi.dll
2020-08-13 16:54:38 ----A---- C:\WINDOWS\system32\ci.dll
2020-08-13 16:54:37 ----A---- C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-08-13 16:54:36 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-08-13 16:54:35 ----A---- C:\WINDOWS\system32\wimserv.exe
2020-08-13 16:54:35 ----A---- C:\WINDOWS\system32\wimgapi.dll
2020-08-13 16:54:35 ----A---- C:\WINDOWS\system32\uDWM.dll
2020-08-13 16:54:35 ----A---- C:\WINDOWS\system32\setupcl.dll
2020-08-13 16:54:35 ----A---- C:\WINDOWS\system32\dwmcore.dll
2020-08-13 16:54:35 ----A---- C:\WINDOWS\system32\dwmapi.dll
2020-08-13 16:54:35 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2020-08-13 16:54:35 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2020-08-13 16:54:34 ----A---- C:\WINDOWS\system32\drivers\cldflt.sys
2020-08-13 16:54:34 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2020-08-13 16:54:33 ----A---- C:\WINDOWS\system32\winresume.exe
2020-08-13 16:54:33 ----A---- C:\WINDOWS\system32\winload.exe
2020-08-13 16:54:32 ----A---- C:\WINDOWS\system32\tier2punctuations.dll
2020-08-13 16:54:32 ----A---- C:\WINDOWS\system32\pcaui.dll
2020-08-13 16:54:32 ----A---- C:\WINDOWS\system32\pcacli.dll
2020-08-13 16:54:32 ----A---- C:\WINDOWS\system32\invagent.dll
2020-08-13 16:54:31 ----A---- C:\WINDOWS\system32\SRH.dll
2020-08-13 16:54:30 ----A---- C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-08-13 16:54:30 ----A---- C:\WINDOWS\system32\accessibilitycpl.dll
2020-08-13 16:54:16 ----A---- C:\WINDOWS\system32\QuietHours.dll
2020-08-13 16:54:15 ----A---- C:\WINDOWS\system32\CustomInstallExec.exe
2020-08-13 16:54:15 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-08-13 16:54:15 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-08-13 16:54:15 ----A---- C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-08-13 16:54:15 ----A---- C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-08-13 16:54:14 ----A---- C:\WINDOWS\system32\Facilitator.dll
2020-08-13 16:54:14 ----A---- C:\WINDOWS\system32\BootMenuUX.dll
2020-08-13 16:54:14 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-08-13 16:54:14 ----A---- C:\WINDOWS\system32\AppxAllUserStore.dll
2020-08-13 16:54:10 ----A---- C:\WINDOWS\system32\twinui.pcshell.dll
2020-08-13 16:54:10 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2020-08-13 16:54:10 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2020-08-13 16:54:10 ----A---- C:\WINDOWS\system32\SettingsHandlers_PCDisplay.dll
2020-08-13 16:54:09 ----A---- C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2020-08-13 16:54:09 ----A---- C:\WINDOWS\system32\PCShellCommonProxyStub.dll
2020-08-13 16:54:08 ----A---- C:\WINDOWS\system32\wuuhosdeployment.dll
2020-08-13 16:54:08 ----A---- C:\WINDOWS\system32\wups2.dll
2020-08-13 16:54:08 ----A---- C:\WINDOWS\system32\wuauclt.exe
2020-08-13 16:54:07 ----A---- C:\WINDOWS\system32\wups.dll
2020-08-13 16:54:07 ----A---- C:\WINDOWS\system32\wuaueng.dll
2020-08-13 16:54:07 ----A---- C:\WINDOWS\system32\wuapi.dll
2020-08-13 16:54:07 ----A---- C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-08-13 16:54:07 ----A---- C:\WINDOWS\system32\UpdateAgent.dll
2020-08-13 16:54:06 ----A---- C:\WINDOWS\system32\usosvc.dll
2020-08-13 16:54:06 ----A---- C:\WINDOWS\system32\usocoreworker.exe
2020-08-13 16:54:06 ----A---- C:\WINDOWS\system32\MoUsoCoreWorker.exe
2020-08-13 16:54:05 ----A---- C:\WINDOWS\system32\SettingsHandlers_SpeechPrivacy.dll
2020-08-13 16:54:04 ----A---- C:\WINDOWS\system32\wbiosrvc.dll
2020-08-13 16:54:04 ----A---- C:\WINDOWS\system32\RasMediaManager.dll
2020-08-13 16:54:04 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2020-08-13 16:54:04 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2020-08-13 16:54:04 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2020-08-13 16:54:04 ----A---- C:\WINDOWS\system32\BioCredProv.dll
2020-08-13 16:54:03 ----A---- C:\WINDOWS\system32\wpncore.dll
2020-08-13 16:54:03 ----A---- C:\WINDOWS\system32\win32u.dll
2020-08-13 16:54:03 ----A---- C:\WINDOWS\system32\win32kfull.sys
2020-08-13 16:54:03 ----A---- C:\WINDOWS\system32\win32k.sys
2020-08-13 16:54:02 ----A---- C:\WINDOWS\system32\wpnprv.dll
2020-08-13 16:54:02 ----A---- C:\WINDOWS\system32\wpnapps.dll
2020-08-13 16:54:02 ----A---- C:\WINDOWS\system32\sbservicetrigger.dll
2020-08-13 16:54:02 ----A---- C:\WINDOWS\system32\ncbservice.dll
2020-08-13 16:54:02 ----A---- C:\WINDOWS\system32\MPSSVC.dll
2020-08-13 16:54:02 ----A---- C:\WINDOWS\system32\kerberos.dll
2020-08-13 16:54:02 ----A---- C:\WINDOWS\system32\keepaliveprovider.dll
2020-08-13 16:54:01 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-08-13 16:54:01 ----A---- C:\WINDOWS\system32\StateRepository.Core.dll
2020-08-13 16:53:53 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-08-13 16:53:52 ----A---- C:\WINDOWS\system32\wintrust.dll
2020-08-13 16:53:52 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-08-13 16:53:52 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-08-13 16:53:52 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-08-13 16:53:52 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2020-08-13 16:53:51 ----A---- C:\WINDOWS\system32\windows.storage.dll
2020-08-13 16:53:51 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2020-08-13 16:53:50 ----A---- C:\WINDOWS\system32\WindowManagement.dll
2020-08-13 16:53:50 ----A---- C:\WINDOWS\system32\WaaSMedicCapsule.dll
2020-08-13 16:53:49 ----A---- C:\WINDOWS\system32\WaaSMedicSvc.dll
2020-08-13 16:53:49 ----A---- C:\WINDOWS\system32\WaaSMedicPS.dll
2020-08-13 16:53:49 ----A---- C:\WINDOWS\system32\WaaSMedicAgent.exe
2020-08-13 16:53:47 ----A---- C:\WINDOWS\system32\storewuauth.dll
2020-08-13 16:53:46 ----A---- C:\WINDOWS\system32\TileDataRepository.dll
2020-08-13 16:53:46 ----A---- C:\WINDOWS\system32\MbaeApiPublic.dll
2020-08-13 16:53:46 ----A---- C:\WINDOWS\system32\MapRouter.dll
2020-08-13 16:53:46 ----A---- C:\WINDOWS\system32\ISM.dll
2020-08-13 16:53:46 ----A---- C:\WINDOWS\system32\InstallService.dll
2020-08-13 16:53:45 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2020-08-13 16:53:45 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2020-08-13 16:53:45 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2020-08-13 16:53:45 ----A---- C:\WINDOWS\system32\MapsStore.dll
2020-08-13 16:53:45 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2020-08-13 16:53:44 ----A---- C:\WINDOWS\system32\win32kbase.sys
2020-08-13 16:53:44 ----A---- C:\WINDOWS\system32\TextShaping.dll
2020-08-13 16:53:44 ----A---- C:\WINDOWS\system32\TextInputMethodFormatter.dll
2020-08-13 16:53:44 ----A---- C:\WINDOWS\system32\InputService.dll
2020-08-13 16:53:44 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2020-08-13 16:53:44 ----A---- C:\WINDOWS\system32\EdgeContent.dll
2020-08-13 16:53:36 ----A---- C:\WINDOWS\system32\ngcsvc.dll
2020-08-13 16:53:36 ----A---- C:\WINDOWS\system32\ngcpopkeysrv.dll
2020-08-13 16:53:36 ----A---- C:\WINDOWS\system32\NgcCtnrSvc.dll
2020-08-13 16:53:36 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2020-08-13 16:53:36 ----A---- C:\WINDOWS\system32\cryptngc.dll
2020-08-13 16:53:35 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2020-08-13 16:53:35 ----A---- C:\WINDOWS\system32\cdd.dll
2020-08-13 16:53:34 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2020-08-13 16:53:34 ----A---- C:\WINDOWS\system32\oemlicense.dll
2020-08-13 16:53:34 ----A---- C:\WINDOWS\system32\mskeyprotcli.dll
2020-08-13 16:53:34 ----A---- C:\WINDOWS\system32\licensingdiag.exe
2020-08-13 16:53:34 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2020-08-13 16:53:34 ----A---- C:\WINDOWS\system32\drivers\ClipSp.sys
2020-08-13 16:53:34 ----A---- C:\WINDOWS\system32\D3D12.dll
2020-08-13 16:53:34 ----A---- C:\WINDOWS\system32\Clipc.dll
2020-08-13 16:53:33 ----A---- C:\WINDOWS\system32\Windows.Networking.HostName.dll
2020-08-13 16:53:33 ----A---- C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2020-08-13 16:53:33 ----A---- C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-08-13 16:53:33 ----A---- C:\WINDOWS\system32\CloudExperienceHostUser.dll
2020-08-13 16:53:32 ----A---- C:\WINDOWS\system32\Windows.AccountsControl.dll
2020-08-13 16:53:32 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-08-13 16:53:32 ----A---- C:\WINDOWS\system32\ActivationManager.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\wlidsvc.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\wlidprov.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\Windows.System.Launcher.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\UiaManager.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\thumbcache.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\MicrosoftAccountTokenProvider.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\MicrosoftAccountCloudAP.dll
2020-08-13 16:53:31 ----A---- C:\WINDOWS\system32\GameInput.dll
2020-08-13 16:53:30 ----A---- C:\WINDOWS\system32\MSAProfileNotificationHandler.dll
2020-08-13 16:53:30 ----A---- C:\WINDOWS\system32\MicrosoftAccountWAMExtension.dll
2020-08-13 16:53:30 ----A---- C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-08-13 16:53:29 ----A---- C:\WINDOWS\system32\Windows.Data.Pdf.dll
2020-08-13 16:53:29 ----A---- C:\WINDOWS\system32\cdpusersvc.dll
2020-08-13 16:53:29 ----A---- C:\WINDOWS\system32\cdpsvc.dll
2020-08-13 16:53:28 ----A---- C:\WINDOWS\system32\mapi32.dll
2020-08-13 16:53:28 ----A---- C:\WINDOWS\system32\fixmapi.exe
2020-08-13 16:53:28 ----A---- C:\WINDOWS\system32\cdprt.dll
2020-08-13 16:53:27 ----A---- C:\WINDOWS\system32\wudriver.dll
2020-08-13 16:53:27 ----A---- C:\WINDOWS\system32\windowsudk.shellcommon.dll
2020-08-13 16:53:27 ----A---- C:\WINDOWS\system32\Windows.Internal.UI.Shell.WindowTabManager.dll
2020-08-13 16:53:27 ----A---- C:\WINDOWS\system32\usercpl.dll
2020-08-13 16:53:27 ----A---- C:\WINDOWS\system32\mapistub.dll
2020-08-13 16:53:27 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2020-08-13 16:53:26 ----A---- C:\WINDOWS\system32\XamlTileRender.dll
2020-08-13 16:53:26 ----A---- C:\WINDOWS\system32\twinui.dll
2020-08-13 16:53:26 ----A---- C:\WINDOWS\system32\StartTileData.dll
2020-08-13 16:53:26 ----A---- C:\WINDOWS\system32\RADCUI.dll
2020-08-13 16:53:26 ----A---- C:\WINDOWS\system32\DataStoreCacheDumpTool.exe
2020-08-13 16:53:25 ----A---- C:\WINDOWS\system32\Windows.CloudStore.Schema.Shell.dll
2020-08-13 16:53:14 ----A---- C:\WINDOWS\system32\ShellCommonCommonProxyStub.dll
2020-08-13 16:53:13 ----A---- C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2020-08-13 16:53:13 ----A---- C:\WINDOWS\system32\pkeyhelper.dll
2020-08-13 16:53:11 ----A---- C:\WINDOWS\system32\WiredNetworkCSP.dll
2020-08-13 16:53:11 ----A---- C:\WINDOWS\system32\WiFiConfigSP.dll
2020-08-13 16:53:11 ----A---- C:\WINDOWS\system32\taskbarcpl.dll
2020-08-13 16:53:11 ----A---- C:\WINDOWS\system32\fontext.dll
2020-08-13 16:53:11 ----A---- C:\WINDOWS\system32\dafWfdProvider.dll
2020-08-13 16:53:11 ----A---- C:\WINDOWS\system32\control.exe
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\win32spl.dll
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\wifitask.exe
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\wifidatacapabilityhandler.dll
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\wcmapi.dll
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\SettingsHandlers_SIUF.dll
2020-08-13 16:53:10 ----A---- C:\WINDOWS\system32\cellulardatacapabilityhandler.dll
2020-08-13 16:53:10 ----A---- C:\WINDOWS\explorer.exe
2020-08-13 16:53:09 ----A---- C:\WINDOWS\system32\spoolsv.exe
2020-08-13 16:53:09 ----A---- C:\WINDOWS\system32\localspl.dll
2020-08-13 16:53:09 ----A---- C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-08-13 16:53:08 ----A---- C:\WINDOWS\system32\WpcProxyStubs.dll
2020-08-13 16:53:08 ----A---- C:\WINDOWS\system32\WpcMon.exe
2020-08-13 16:53:08 ----A---- C:\WINDOWS\system32\WpcApi.dll
2020-08-13 16:53:08 ----A---- C:\WINDOWS\system32\Wpc.dll
2020-08-13 16:53:08 ----A---- C:\WINDOWS\system32\ApproveChildRequest.exe
2020-08-13 16:53:07 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2020-08-13 16:53:07 ----A---- C:\WINDOWS\system32\WpcTok.exe
2020-08-13 16:53:07 ----A---- C:\WINDOWS\system32\WpcRefreshTask.dll
2020-08-13 16:53:07 ----A---- C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2020-08-13 16:53:07 ----A---- C:\WINDOWS\system32\RjvMDMConfig.dll
2020-08-13 16:53:07 ----A---- C:\WINDOWS\system32\GPCSEWrapperCsp.dll
2020-08-13 16:53:07 ----A---- C:\WINDOWS\system32\FlightSettings.dll
2020-08-13 16:53:06 ----A---- C:\WINDOWS\system32\MDMAgent.exe
2020-08-13 16:53:06 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-08-13 16:53:00 ----A---- C:\WINDOWS\system32\audioresourceregistrar.dll
2020-08-13 16:53:00 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2020-08-13 16:53:00 ----A---- C:\WINDOWS\system32\audiodg.exe
2020-08-13 16:52:59 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2020-08-13 16:52:54 ----A---- C:\WINDOWS\system32\SpatialAudioLicenseSrv.exe
2020-08-13 16:52:54 ----A---- C:\WINDOWS\system32\audiosrv.dll
2020-08-13 16:52:53 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.ConversationalAgent.dll
2020-08-13 16:52:53 ----A---- C:\WINDOWS\system32\SpatializerApo.dll
2020-08-13 16:52:53 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2020-08-13 16:52:53 ----A---- C:\WINDOWS\system32\HrtfApo.dll
2020-08-13 16:52:53 ----A---- C:\WINDOWS\system32\AudioEng.dll
2020-08-13 16:52:53 ----A---- C:\WINDOWS\system32\agentactivationruntime.dll
2020-08-13 16:52:53 ----A---- C:\WINDOWS\system32\AarSvc.dll
2020-08-13 16:52:52 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2020-08-13 16:52:52 ----A---- C:\WINDOWS\system32\agentactivationruntimewindows.dll
2020-08-13 16:52:51 ----A---- C:\WINDOWS\system32\wwansvc.dll
2020-08-13 16:52:51 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2020-08-13 16:52:51 ----A---- C:\WINDOWS\system32\lpasvc.dll
2020-08-13 16:52:51 ----A---- C:\WINDOWS\system32\fcon.dll
2020-08-13 16:52:51 ----A---- C:\WINDOWS\system32\drivers\MbbCx.sys
2020-08-13 16:52:51 ----A---- C:\WINDOWS\system32\drivers\KNetPwrDepBroker.sys
2020-08-13 16:52:48 ----A---- C:\WINDOWS\system32\drivers\Vid.sys
2020-08-13 16:52:47 ----A---- C:\WINDOWS\system32\drivers\USBXHCI.SYS
2020-08-13 16:52:47 ----A---- C:\WINDOWS\system32\drivers\hidbth.sys
2020-08-13 16:52:47 ----A---- C:\WINDOWS\system32\drivers\BTHUSB.SYS
2020-08-13 16:52:47 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2020-08-13 16:52:46 ----A---- C:\WINDOWS\system32\drivers\BthMini.SYS
2020-08-13 16:52:46 ----A---- C:\WINDOWS\system32\drivers\bthenum.sys
2020-08-13 16:52:45 ----A---- C:\WINDOWS\system32\drivers\spaceport.sys
2020-08-13 16:52:45 ----A---- C:\WINDOWS\system32\drivers\spacedump.sys
2020-08-13 16:52:45 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2020-08-13 16:52:43 ----A---- C:\WINDOWS\system32\drivers\usbvideo.sys
2020-08-13 16:52:43 ----A---- C:\WINDOWS\system32\drivers\IntelTA.sys
2020-08-13 16:52:43 ----A---- C:\WINDOWS\system32\drivers\intelpep.sys
2020-08-13 16:52:43 ----A---- C:\WINDOWS\system32\drivers\acpi.sys
2020-08-13 16:19:43 ----A---- C:\WINDOWS\SYSWOW64\poqexec.exe
2020-08-13 16:19:42 ----A---- C:\WINDOWS\system32\poqexec.exe
2020-08-13 16:19:31 ----D---- C:\WINDOWS\Panther

======List of files/folders modified in the last 1 month======

2020-09-06 19:25:24 ----RD---- C:\Program Files
2020-09-06 19:12:00 ----D---- C:\WINDOWS\system32\sru
2020-09-06 18:50:32 ----D---- C:\WINDOWS\INF
2020-09-06 18:50:32 ----D---- C:\Windows
2020-09-06 18:50:31 ----D---- C:\WINDOWS\Temp
2020-09-06 18:24:48 ----D---- C:\ProgramData\Kaspersky Lab
2020-09-06 18:20:46 ----D---- C:\WINDOWS\system32\SleepStudy
2020-09-06 15:05:10 ----D---- C:\WINDOWS\Prefetch
2020-09-05 20:24:39 ----D---- C:\ProgramData\NVIDIA
2020-09-05 20:23:40 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2020-09-05 20:09:14 ----RD---- C:\WINDOWS\Microsoft.NET
2020-09-05 18:12:08 ----SHD---- C:\System Volume Information
2020-09-05 11:46:24 ----AD---- C:\Program Files (x86)\Opera
2020-09-05 11:46:22 ----D---- C:\WINDOWS\system32\Tasks
2020-09-04 20:01:13 ----HD---- C:\Program Files\WindowsApps
2020-09-04 19:51:00 ----D---- C:\WINDOWS\AppReadiness
2020-08-30 11:11:47 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2020-08-30 11:11:46 ----RD---- C:\Program Files (x86)
2020-08-25 12:54:36 ----SHDC---- C:\WINDOWS\Installer
2020-08-22 11:19:19 ----D---- C:\WINDOWS\SysWOW64
2020-08-21 20:33:28 ----D---- C:\WINDOWS\system32\catroot2
2020-08-20 10:54:49 ----D---- C:\WINDOWS\system32\drivers
2020-08-20 10:51:18 ----D---- C:\Users\Milan\AppData\Roaming\vlc
2020-08-19 20:06:32 ----D---- C:\WINDOWS\System32
2020-08-19 20:06:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2020-08-19 19:59:27 ----D---- C:\WINDOWS\ServiceState
2020-08-19 19:59:23 ----ASH---- C:\DumpStack.log.tmp
2020-08-14 20:52:19 ----D---- C:\WINDOWS\system32\config
2020-08-14 07:43:26 ----RD---- C:\WINDOWS\assembly
2020-08-13 17:23:15 ----D---- C:\WINDOWS\WinSxS
2020-08-13 17:17:04 ----D---- C:\WINDOWS\system32\DriverStore
2020-08-13 17:16:00 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2020-08-13 17:15:37 ----D---- C:\WINDOWS\system32\drivers\UMDF
2020-08-13 17:12:39 ----D---- C:\WINDOWS\SYSWOW64\WinMetadata
2020-08-13 17:12:39 ----D---- C:\WINDOWS\SYSWOW64\setup
2020-08-13 17:12:39 ----D---- C:\WINDOWS\SYSWOW64\migwiz
2020-08-13 17:12:39 ----D---- C:\WINDOWS\SYSWOW64\migration
2020-08-13 17:12:39 ----D---- C:\WINDOWS\SYSWOW64\Dism
2020-08-13 17:12:37 ----D---- C:\WINDOWS\SystemResources
2020-08-13 17:12:33 ----D---- C:\WINDOWS\system32\WinMetadata
2020-08-13 17:12:33 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2020-08-13 17:12:33 ----D---- C:\WINDOWS\system32\wbem
2020-08-13 17:12:33 ----D---- C:\WINDOWS\system32\Sysprep
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\sk-SK
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\setup
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\PerceptionSimulation
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\oobe
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\migwiz
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\migration
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\en-US
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\Dism
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\cs-CZ
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\Boot
2020-08-13 17:12:32 ----D---- C:\WINDOWS\system32\appraiser
2020-08-13 17:12:26 ----RD---- C:\WINDOWS\PrintDialog
2020-08-13 17:12:26 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2020-08-13 17:12:26 ----D---- C:\WINDOWS\ShellExperiences
2020-08-13 17:12:26 ----D---- C:\WINDOWS\ShellComponents
2020-08-13 17:12:26 ----D---- C:\WINDOWS\Provisioning
2020-08-13 17:12:26 ----D---- C:\WINDOWS\bcastdvr
2020-08-13 17:12:26 ----D---- C:\WINDOWS\apppatch
2020-08-13 17:07:59 ----D---- C:\WINDOWS\CbsTemp
2020-08-13 17:01:01 ----D---- C:\Program Files (x86)\Common Files
2020-08-13 16:47:23 ----SD---- C:\Users\Milan\AppData\Roaming\Microsoft
2020-08-13 16:45:11 ----HD---- C:\ProgramData
2020-08-13 16:38:16 ----D---- C:\Program Files\Epic Games
2020-08-13 16:19:41 ----HD---- C:\$WinREAgent
2020-08-11 20:13:06 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2020-08-11 20:13:03 ----D---- C:\WINDOWS\system32\Macromed
2020-08-11 20:13:02 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2020-08-11 20:13:02 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerInstaller.exe

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit); C:\WINDOWS\system32\DRIVERS\cm_km.sys [2019-02-16 246912]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2019-12-07 57360]
R0 klbackupdisk;Kaspersky Lab klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [2020-05-19 79768]
R0 klupd_klif_arkmon;klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [2020-08-20 256760]
R0 klupd_klif_klbg;klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [2020-08-20 117512]
R1 afunix;afunix; C:\WINDOWS\system32\drivers\afunix.sys [2019-12-07 41984]
R1 bam;@%SystemRoot%\system32\drivers\bam.sys,-100; C:\WINDOWS\system32\drivers\bam.sys [2019-12-07 78136]
R1 CimFS;CimFS; C:\WINDOWS\system32\drivers\CimFS.sys [2019-12-07 91136]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2019-12-07 59392]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2019-12-07 8704]
R1 klbackupflt;Kaspersky Lab klbackupflt; C:\WINDOWS\system32\DRIVERS\klbackupflt.sys [2020-05-19 145504]
R1 kldisk;kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [2019-03-12 93312]
R1 klgse;Kaspersky Lab Security Extender Driver; C:\WINDOWS\system32\DRIVERS\klgse.sys [2020-06-26 643840]
R1 klhk;Kaspersky Lab service driver; C:\WINDOWS\System32\drivers\klhk.sys [2020-06-26 1277704]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2020-08-10 998808]
R1 klim6;@oem59.inf,%KLIM6_Desc%;Kaspersky Anti-Virus NDIS 6 Filter; C:\WINDOWS\system32\DRIVERS\klim6.sys [2019-03-19 58192]
R1 klpd;Kaspersky Lab format recognizer driver; C:\WINDOWS\system32\DRIVERS\klpd.sys [2019-03-13 51328]
R1 klwtp;KLwtp - WFP callout traffic inspector; C:\WINDOWS\system32\DRIVERS\klwtp.sys [2020-05-19 211048]
R1 kneps;kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [2020-08-10 233368]
R2 bindflt;@%systemroot%\system32\drivers\bindflt.sys,-100; C:\WINDOWS\system32\drivers\bindflt.sys [2020-07-09 143160]
R2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2020-08-13 491520]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2019-12-07 53248]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2017-07-13 5863904]
R3 klflt;Kaspersky Lab Kernel DLL; C:\WINDOWS\system32\DRIVERS\klflt.sys [2020-08-10 251800]
R3 klids;klids; \??\C:\ProgramData\Kaspersky Lab\AVP20.0\Bases\klids.sys [2020-09-03 240200]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [2020-05-19 79760]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2019-03-18 59512]
R3 kltap;@oem29.inf,%DeviceDescription%;Kaspersky Security Data Escort Adapter; C:\WINDOWS\System32\drivers\kltap.sys [2018-03-16 48592]
R3 klupd_klif_kimul;klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [2019-06-12 99152]
R3 klupd_klif_klark;klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [2020-04-16 309968]
R3 klupd_klif_mark;klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [2020-04-16 206880]
R3 MEIx64;@oem62.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [2016-09-23 204896]
R3 MsQuic;@%SystemRoot%\system32\drivers\msquic.sys,-1; C:\WINDOWS\system32\drivers\msquic.sys [2019-12-07 322600]
R3 NVHDA;@oem72.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2020-06-22 222112]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvlei.inf_amd64_504ca354d84d7684\nvlddmkm.sys [2020-06-23 24671128]
R3 rt640x64;@oem66.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2015-06-23 895256]
S0 bttflt;@virtdisk.inf,%service_desc%;Microsoft Hyper-V VHDPMEM BTT Filter; C:\WINDOWS\System32\drivers\bttflt.sys [2019-12-07 43832]
S0 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2019-12-07 319800]
S0 iaStorAVC;@iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller; C:\WINDOWS\System32\drivers\iaStorAVC.sys [2019-12-07 884752]
S0 ItSas35i;ItSas35i; C:\WINDOWS\System32\drivers\ItSas35i.sys [2019-12-07 172344]
S0 klelam;klelam; C:\WINDOWS\system32\DRIVERS\klelam.sys [2020-05-19 37816]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2019-12-07 124216]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2019-12-07 135992]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2019-12-07 81720]
S0 megasas35i;megasas35i; C:\WINDOWS\System32\drivers\megasas35i.sys [2019-12-07 105480]
S0 nvdimm;@nvdimm.inf,%nvdimm.SvcDesc%;Microsoft NVDIMM device driver; C:\WINDOWS\System32\drivers\nvdimm.sys [2019-12-07 168464]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2019-12-07 58680]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2019-12-07 68408]
S0 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2019-12-07 138040]
S0 Ramdisk;Windows RAM Disk Driver; C:\WINDOWS\system32\DRIVERS\ramdisk.sys [2019-12-07 42296]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2019-12-07 23040]
S3 Acx01000;@%SystemRoot%\system32\drivers\Acx01000.sys,-1000; C:\WINDOWS\system32\drivers\Acx01000.sys [2019-12-07 415232]
S3 aftap0901;@oem2.inf,%DeviceDescription%;AnchorFree TAP-Windows Adapter V9; C:\WINDOWS\System32\drivers\aftap0901.sys [2017-11-16 48624]
S3 amdgpio2;@amdgpio2.inf,%GPIO.SvcDesc%;AMD GPIO Client Driver; C:\WINDOWS\System32\drivers\amdgpio2.sys [2019-12-07 18432]
S3 amdi2c;@amdi2c.inf,%amdi2c.SVCDESC%;AMD I2C Controller Service; C:\WINDOWS\System32\drivers\amdi2c.sys [2019-12-07 45568]
S3 AndnetBus;@oem40.inf,%LGSI.Service.Desc%;LGE Mobile USB Composite Device; C:\WINDOWS\System32\drivers\lgandnetbus64.sys [2015-01-21 20992]
S3 AndNetDiag;LGE AndroidNet USB Serial Port; C:\WINDOWS\system32\DRIVERS\lgandnetdiag64.sys [2015-01-26 30720]
S3 ANDNetModem;LGE AndroidNet USB Modem; C:\WINDOWS\system32\DRIVERS\lgandnetmodem64.sys [2015-01-26 37376]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2019-12-07 18432]
S3 athur;Qualcomm Atheros AR9271 Wireless Network Adapter Service; C:\WINDOWS\System32\drivers\athuwbx.sys [2013-11-20 2702336]
S3 BthA2dp;@microsoft_bluetooth_a2dp.inf,%BthA2dp.ServiceDescription%;Microsoft Bluetooth A2dp driver; C:\WINDOWS\System32\drivers\BthA2dp.sys [2019-12-07 279040]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2020-08-13 113664]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [2019-12-07 106496]
S3 BthMini;@bth.inf,%BTHMINI.SvcDesc%;Bluetooth Radio Driver; C:\WINDOWS\System32\drivers\BTHMINI.sys [2020-08-13 45568]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\drivers\BTHport.sys [2020-08-13 1548288]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\drivers\BTHUSB.sys [2020-08-13 110592]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2019-12-07 44032]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2019-12-07 66576]
S3 dot4;@oem84.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\WINDOWS\system32\DRIVERS\Dot4.sys [2012-09-25 151968]
S3 Dot4Print;@oem42.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\drivers\Dot4Prt.sys [2012-09-25 27040]
S3 dot4usb;@oem84.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\WINDOWS\system32\DRIVERS\dot4usb.sys [2012-09-25 49056]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_53931f0ae21d6d2c\genericusbfn.sys [2019-12-07 23040]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2019-12-07 55824]
S3 hidspi;@hidspi_km.inf,%hidspi.SVCDESC%;Microsoft SPI HID Miniport Driver; C:\WINDOWS\System32\drivers\hidspi.sys [2019-12-07 66560]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2020-07-15 95032]
S3 HwNClx0101;Microsoft Hardware Notifications Class Extension Driver; C:\WINDOWS\System32\Drivers\mshwnclx.sys [2019-12-07 30208]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2019-12-07 1853752]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2019-12-07 36352]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2019-12-07 91136]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2019-12-07 79360]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2019-12-07 93184]
S3 iaLPSS2i_GPIO2_CNL;@iaLPSS2i_GPIO2_CNL.inf,%iaLPSS2i_GPIO2_CNL.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [2019-12-07 112128]
S3 iaLPSS2i_GPIO2_GLK;@iaLPSS2i_GPIO2_GLK.inf,%iaLPSS2i_GPIO2_GLK.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [2019-12-07 96256]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2019-12-07 171520]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2019-12-07 175104]
S3 iaLPSS2i_I2C_CNL;@iaLPSS2i_I2C_CNL.inf,%iaLPSS2i_I2C_CNL.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [2019-12-07 177152]
S3 iaLPSS2i_I2C_GLK;@iaLPSS2i_I2C_GLK.inf,%iaLPSS2i_I2C_GLK.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [2019-12-07 177664]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2019-12-07 558904]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2019-12-07 47104]
S3 intelpmax;@intelpmax.inf,%SvcDesc%;Intel(R) Dynamic Device Peak Power Manager Driver; C:\WINDOWS\System32\drivers\intelpmax.sys [2019-12-07 30720]
S3 IPT;IPT; C:\WINDOWS\System32\drivers\ipt.sys [2019-12-07 59704]
S3 klpnpflt;Kaspersky Lab klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [2019-03-10 45904]
S3 klupd_klif_arkmon_547B264C;klupd_klif_arkmon_547B264C; \??\C:\ProgramData\Kaspersky Lab\AVP20.0\temp\547B264CB7FBC89FD49FFF7B63AB7FA2\klupd_klif_arkmon.sys [2020-08-20 256760]
S3 klupd_klif_klark_87A8F0F5;klupd_klif_klark_87A8F0F5; \??\C:\ProgramData\Kaspersky Lab\AVP20.0\temp\87A8F0F55EBBAF48F423EC66E26B846F\klupd_klif_klark.sys [2020-08-20 309768]
S3 klupd_klif_mark_BD29CBA6;klupd_klif_mark_BD29CBA6; \??\C:\ProgramData\Kaspersky Lab\AVP20.0\temp\BD29CBA65F83A8DBEACDF710C61A653D\klupd_klif_mark.sys [2020-08-20 206888]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2019-12-07 537608]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2019-12-07 64016]
S3 MbbCx;MBB Network Adapter Class Extension; C:\WINDOWS\system32\drivers\MbbCx.sys [2020-08-13 386048]
S3 Microsoft_Bluetooth_AvrcpTransport;@microsoft_bluetooth_avrcptransport.inf,%Microsoft_Bluetooth_AvrcpTransport.ServiceDescription%;Microsoft Bluetooth Avrcp Transport Driver; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [2019-12-07 65024]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2019-12-07 1131320]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2019-12-07 146232]
S3 NDKPing;NDKPing Driver; C:\WINDOWS\system32\drivers\NDKPing.sys [2019-12-07 72720]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2019-12-07 206336]
S3 PktMon;Packet Monitor Driver; C:\WINDOWS\system32\drivers\PktMon.sys [2019-12-07 104456]
S3 PNPMEM;@memory.inf,%PNPMEM.SvcDesc%;Microsoft Memory Module Driver; C:\WINDOWS\System32\drivers\pnpmem.sys [2019-12-07 17408]
S3 portcfg;portcfg; C:\WINDOWS\System32\drivers\portcfg.sys [2019-12-07 27136]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2019-12-07 990008]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2019-12-07 213504]
S3 rhproxy;@rhproxy.inf,%rhproxy.SVCDESC%;Resource Hub proxy driver; C:\WINDOWS\System32\drivers\rhproxy.sys [2019-12-07 115712]
S3 RTSUER;@oem89.inf,%RtsUER%;Realtek USB Card Reader - UER; C:\WINDOWS\system32\Drivers\RtsUer.sys [2019-04-02 451792]
S4 hvcrash;hvcrash; C:\WINDOWS\System32\drivers\hvcrash.sys [2019-12-07 35128]
S4 klwfp;klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [2019-03-05 105600]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2020-07-08 169544]
R2 AVP20.0;Kaspersky Anti-Virus Service 20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\avp.exe [2019-03-21 357416]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
R2 CDPUserSvc_d336473;Uživatelská služba platformy připojených zařízení_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
R2 DispBrokerDesktopSvc;@%SystemRoot%\system32\dispbroker.desktop.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
R2 hpqddsvc;Služba HP CUE DeviceDiscovery; C:\WINDOWS\syswow64\svchost.exe [2019-12-07 47232]
R2 ImControllerService;@oem32.inf,%ImcSvcDisplayName%;System Interface Foundation Service; C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe [2020-07-15 81240]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2016-10-20 177440]
R2 KSDE4.0;Kaspersky Secure Connection Service 4.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 4.0\ksde.exe [2019-03-21 619752]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2016-10-20 419616]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\WINDOWS\System32\DriverStore\FileRepository\nvlei.inf_amd64_504ca354d84d7684\Display.NvContainer\NVDisplay.Container.exe [2020-06-23 883096]
R2 OneSyncSvc_d336473;Hostitel synchronizace_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2019-12-07 57368]
R3 BthAvctpSvc;@%SystemRoot%\system32\BthAvctpSvc.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
R3 camsvc;@%SystemRoot%\system32\CapabilityAccessManager.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
R3 cbdhsvc_d336473;Uživatelská služba schránky_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
R3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
R3 hpqcxs08;hpqcxs08; C:\WINDOWS\syswow64\svchost.exe [2019-12-07 47232]
R3 InstallService;@%SystemRoot%\system32\InstallService.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
R3 Intel(R) Security Assist;Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [2015-05-19 335872]
R3 kpm_launch_service;Kaspersky Password Manager Service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [2020-08-25 351480]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S2 edgeupdate;Služba Microsoft Edge Update (edgeupdate); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-06-08 224160]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-16 154440]
S2 isaHelperSvc;Intel(R) Security Assist Helper; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [2015-05-19 7680]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2019-12-07 57368]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 AarSvc;@%SystemRoot%\system32\AarSvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 AarSvc_d336473;Agent Activation Runtime_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2020-08-11 335416]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 autotimesvc;@%SystemRoot%\System32\autotimesvc.dll,-6; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 BcastDVRUserService;@%SystemRoot%\system32\BcastDVRUserService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 BcastDVRUserService_d336473;Uživatelská služba pro GameDVR a vysílání her_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 BluetoothUserService;@%SystemRoot%\system32\Microsoft.Bluetooth.UserService.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 BluetoothUserService_d336473;Služba pro podporu uživatelů Bluetooth_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 BTAGService;@%SystemRoot%\system32\BTAGService.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 CaptureService;@%SystemRoot%\system32\CaptureService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 CaptureService_d336473;CaptureService_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 cbdhsvc;@%SystemRoot%\system32\cbdhsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 ConsentUxUserSvc;@%SystemRoot%\system32\ConsentUxClient.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 ConsentUxUserSvc_d336473;ConsentUX_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 CredentialEnrollmentManagerUserSvc;@%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [2020-07-15 380632]
S3 CredentialEnrollmentManagerUserSvc_d336473;CredentialEnrollmentManagerUserSvc_d336473; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [2020-07-15 380632]
S3 DeviceAssociationBrokerSvc;@%SystemRoot%\system32\deviceaccess.dll,-107; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 DeviceAssociationBrokerSvc_d336473;DeviceAssociationBroker_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 DevicePickerUserSvc;@%SystemRoot%\system32\Windows.Devices.Picker.dll,-1006; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 DevicePickerUserSvc_d336473;DevicePicker_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 DevicesFlowUserSvc_d336473;Tok zařízení_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2020-07-15 94208]
S3 diagsvc;@%systemroot%\system32\DiagSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S3 DisplayEnhancementService;@%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1000; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 edgeupdatem;Služba Microsoft Edge Update (edgeupdatem); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-06-08 224160]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2019-11-08 46184]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files (x86)\Google\Chrome\Application\85.0.4183.83\elevation_service.exe [2020-08-23 1322992]
S3 GraphicsPerfSvc;@%SystemRoot%\system32\GraphicsPerfSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-16 154440]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2016-07-26 987432]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S3 klvssbridge64_20.0;Kaspersky Volume Shadow Copy Service Bridge 20.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Free 20.0\x64\vssbridge64.exe [2019-03-21 438928]
S3 LxpSvc;@%SystemRoot%\system32\LanguageOverlayServer.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 MessagingService_d336473;Služba zasílání zpráv_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 MicrosoftEdgeElevationService;Microsoft Edge Elevation Service; C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.44\elevation_service.exe [2020-08-30 1536912]
S3 MixedRealityOpenXRSvc;@%SystemRoot%\system32\MixedRealityRuntime.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2020-01-24 244936]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2011-07-20 440696]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 perceptionsimulation;@%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101; C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe [2020-07-09 105984]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 PimIndexMaintenanceSvc_d336473;Data kontaktů_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 PrintWorkflowUserSvc;@%SystemRoot%\system32\PrintWorkflowService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 PrintWorkflowUserSvc_d336473;PrintWorkflow_d336473; C:\WINDOWS\system32\svchost.exe [2019-12-07 57368]
S3 PushToInstall;@%SystemRoot%\system32\pushtoinstall.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2019-12-07 57368]
S3 Rockstar Service;Rockstar Game Library Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2020-06-25 1711232]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu

#2 Příspěvek od Rudy »

Zdravím!
Dejte logy FRST+Addition: https://forum.viry.cz/viewtopic.php?f=13&t=154679 . RSIT není s desítkami plně kompatibilní.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

superjano
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 16 srp 2005 23:08

Re: prosim o kontrolu

#3 Příspěvek od superjano »

posielam rar
Přílohy
FRST+ Addition.rar
(29.02 KiB) Staženo 83 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu

#4 Příspěvek od Rudy »

OK. Teď spusťte tuto utilitu:
Ulozte na plochu AdwCleaner https://malwarebytes.com/adwcleaner/ nebo http://www.bleepingcomputer.com/download/adwcleaner/

ukoncete vsechny programy
odsouhlaste licencni podmiky (EULA) klikem na Souhlasim
kliknete pravym na ikonu AdwCleaneru a vyberte Spustit jako spravce (v pripade Win XP spustte obycejne dvojklikem)
kliknete na Skenovat nyni (Scan now), pote na Cisteni a opravy (Clean and Repair)
po restartu na Vas vyskoci log (pripadne jej najdete v C:\AdwCleaner\Logs\AdwCleaner[Cxx].txt), jehoz obsah zkopirujte do pristi odpovedi
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

superjano
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 16 srp 2005 23:08

Re: prosim o kontrolu

#5 Příspěvek od superjano »

# -------------------------------
# Malwarebytes AdwCleaner 8.0.7.0
# -------------------------------
# Build: 07-22-2020
# Database: 2020-07-20.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 09-09-2020
# Duration: 00:00:04
# OS: Windows 10 Home
# Cleaned: 3
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

No malicious registry entries cleaned.

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

Deleted Preinstalled.LenovoIMController Folder C:\ProgramData\LENOVO\IMCONTROLLER
Deleted Preinstalled.LenovoIMController Folder C:\Windows\LENOVO\IMCONTROLLER
Deleted Preinstalled.LenovoIMController Folder C:\Windows\System32\Tasks\LENOVO\IMCONTROLLER


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1620 octets] - [09/09/2020 07:13:43]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu

#6 Příspěvek od Rudy »

Dejte nové logy FRST+Addition.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

superjano
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 16 srp 2005 23:08

Re: prosim o kontrolu

#7 Příspěvek od superjano »

tu su.
Přílohy
FRST+Addition.rar
(34.28 KiB) Staženo 62 x

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu

#8 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start

CloseProcesses:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
Task: {1248CDB4-4B6A-4103-8C5A-2FEC6A84F69A} - \Lenovo\ImController\TimeBasedEvents\9c4b876b-7bf3-4af0-825c-c6c992d22fd0 -> No File <==== ATTENTION
Task: {2CD215E2-CBBE-4F25-A59D-8A38A4C1D471} - \Lenovo\ImController\TimeBasedEvents\a4d10f67-31bc-4cd4-8a41-f1eed381ef90 -> No File <==== ATTENTION
Task: {33C60E24-9AB4-4E9A-8AE7-19851FE40D2D} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
Task: {432115F2-E67F-46C9-80DC-82A8D1FE4AD2} - \Lenovo\ImController\TimeBasedEvents\3993f52a-dbd9-4c41-8562-5d40f0ab9f51 -> No File <==== ATTENTION
Task: {59AD61A8-A93F-4D60-87D2-F20B0E51DD46} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {60139D6B-8130-4B59-AF16-755F22E74B98} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1660520 2020-02-27] (Avast Software s.r.o. -> Avast Software)
Task: {658D1522-3ABD-4D88-9F12-A82B7F988DBC} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {68EA13BD-A7D1-4CF6-ADD5-ACE2C3064C06} - \Lenovo\ImController\TimeBasedEvents\c53a9be7-f7d4-41d7-9461-3c65deb34013 -> No File <==== ATTENTION
Task: {773A8CEA-3AE8-4E1C-B74E-D321BA598A6A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
SearchScopes: HKU\S-1-5-21-3357283396-1472899698-1061014907-1001 -> DefaultScope {62D5142B-A90C-4616-860F-73B33E585CC0} URL =
SearchScopes: HKU\S-1-5-21-3357283396-1472899698-1061014907-1001 -> {62D5142B-A90C-4616-860F-73B33E585CC0} URL =
Toolbar: HKLM - No Name - {b60873b9-51aa-4566-b2fc-c16de2ec8bff} - No File
Toolbar: HKLM-x32 - No Name - {b60873b9-51aa-4566-b2fc-c16de2ec8bff} - No File
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2019-06-16] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2019-06-16] <==== ATTENTION
C:\DumpStack.log.tmp
C:\Users\Milan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers4: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
AlternateDataStreams: C:\Users\Milan\Downloads\CAM00341.mp4:TOC.WMV [130]
AlternateDataStreams: C:\Users\Milan\Downloads\Príšerky-s.r.o..mpg:TOC.WMV [130]
AlternateDataStreams: C:\Users\Milan\Downloads\terypo1.avi:TOC.WMV [130]

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

V PC jsou 2 funkční antiviry (ESET A Kaspersky). Jeden z nich vypněte, mohlo by docházet k sw kolizím.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

superjano
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 16 srp 2005 23:08

Re: prosim o kontrolu

#9 Příspěvek od superjano »

Ja mam iba jeden antivir nod32. Kaspersky som odinstaloval vcera.

superjano
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 16 srp 2005 23:08

Re: prosim o kontrolu

#10 Příspěvek od superjano »

Fix result of Farbar Recovery Scan Tool (x64) Version: 09-09-2020
Ran by Milan (09-09-2020 14:25:53) Run:1
Running from C:\Users\Milan\Desktop
Loaded Profiles: Milan
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CloseProcesses:
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
Task: {1248CDB4-4B6A-4103-8C5A-2FEC6A84F69A} - \Lenovo\ImController\TimeBasedEvents\9c4b876b-7bf3-4af0-825c-c6c992d22fd0 -> No File <==== ATTENTION
Task: {2CD215E2-CBBE-4F25-A59D-8A38A4C1D471} - \Lenovo\ImController\TimeBasedEvents\a4d10f67-31bc-4cd4-8a41-f1eed381ef90 -> No File <==== ATTENTION
Task: {33C60E24-9AB4-4E9A-8AE7-19851FE40D2D} - \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask -> No File <==== ATTENTION
Task: {432115F2-E67F-46C9-80DC-82A8D1FE4AD2} - \Lenovo\ImController\TimeBasedEvents\3993f52a-dbd9-4c41-8562-5d40f0ab9f51 -> No File <==== ATTENTION
Task: {59AD61A8-A93F-4D60-87D2-F20B0E51DD46} - \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance -> No File <==== ATTENTION
Task: {60139D6B-8130-4B59-AF16-755F22E74B98} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1660520 2020-02-27] (Avast Software s.r.o. -> Avast Software)
Task: {658D1522-3ABD-4D88-9F12-A82B7F988DBC} - \Lenovo\ImController\Lenovo iM Controller Monitor -> No File <==== ATTENTION
Task: {68EA13BD-A7D1-4CF6-ADD5-ACE2C3064C06} - \Lenovo\ImController\TimeBasedEvents\c53a9be7-f7d4-41d7-9461-3c65deb34013 -> No File <==== ATTENTION
Task: {773A8CEA-3AE8-4E1C-B74E-D321BA598A6A} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
SearchScopes: HKU\S-1-5-21-3357283396-1472899698-1061014907-1001 -> DefaultScope {62D5142B-A90C-4616-860F-73B33E585CC0} URL =
SearchScopes: HKU\S-1-5-21-3357283396-1472899698-1061014907-1001 -> {62D5142B-A90C-4616-860F-73B33E585CC0} URL =
Toolbar: HKLM - No Name - {b60873b9-51aa-4566-b2fc-c16de2ec8bff} - No File
Toolbar: HKLM-x32 - No Name - {b60873b9-51aa-4566-b2fc-c16de2ec8bff} - No File
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2019-06-16] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2019-06-16] <==== ATTENTION
C:\DumpStack.log.tmp
C:\Users\Milan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => -> No File
ContextMenuHandlers1: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers1: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers4: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
ContextMenuHandlers4: [SHAREit.FileContextMenuExt] -> {430BD134-576D-4E75-87CD-0F5C6221A82B} => -> No File
ContextMenuHandlers6: [BriefcaseMenu] -> {85BBD920-42A0-1069-A2E4-08002B30309D} => -> No File
ContextMenuHandlers6: [Offline Files] -> {474C98EE-CF3D-41f5-80E3-4AAB0AB04301} => -> No File
AlternateDataStreams: C:\Users\Milan\Downloads\CAM00341.mp4:TOC.WMV [130]
AlternateDataStreams: C:\Users\Milan\Downloads\Príšerky-s.r.o..mpg:TOC.WMV [130]
AlternateDataStreams: C:\Users\Milan\Downloads\terypo1.avi:TOC.WMV [130]

EmptyTemp:
End
*****************

Processes closed successfully.
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1248CDB4-4B6A-4103-8C5A-2FEC6A84F69A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1248CDB4-4B6A-4103-8C5A-2FEC6A84F69A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\9c4b876b-7bf3-4af0-825c-c6c992d22fd0" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2CD215E2-CBBE-4F25-A59D-8A38A4C1D471}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2CD215E2-CBBE-4F25-A59D-8A38A4C1D471}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\a4d10f67-31bc-4cd4-8a41-f1eed381ef90" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{33C60E24-9AB4-4E9A-8AE7-19851FE40D2D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{33C60E24-9AB4-4E9A-8AE7-19851FE40D2D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{432115F2-E67F-46C9-80DC-82A8D1FE4AD2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{432115F2-E67F-46C9-80DC-82A8D1FE4AD2}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\3993f52a-dbd9-4c41-8562-5d40f0ab9f51" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{59AD61A8-A93F-4D60-87D2-F20B0E51DD46}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{59AD61A8-A93F-4D60-87D2-F20B0E51DD46}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{60139D6B-8130-4B59-AF16-755F22E74B98}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{60139D6B-8130-4B59-AF16-755F22E74B98}" => removed successfully
C:\WINDOWS\System32\Tasks\Avast Software\Overseer => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast Software\Overseer" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{658D1522-3ABD-4D88-9F12-A82B7F988DBC}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{658D1522-3ABD-4D88-9F12-A82B7F988DBC}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\Lenovo iM Controller Monitor" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{68EA13BD-A7D1-4CF6-ADD5-ACE2C3064C06}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{68EA13BD-A7D1-4CF6-ADD5-ACE2C3064C06}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\ImController\TimeBasedEvents\c53a9be7-f7d4-41d7-9461-3c65deb34013" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{773A8CEA-3AE8-4E1C-B74E-D321BA598A6A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{773A8CEA-3AE8-4E1C-B74E-D321BA598A6A}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\UNP\RunCampaignManager" => not found
"HKU\S-1-5-21-3357283396-1472899698-1061014907-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
HKU\S-1-5-21-3357283396-1472899698-1061014907-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{62D5142B-A90C-4616-860F-73B33E585CC0} => removed successfully
"HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{b60873b9-51aa-4566-b2fc-c16de2ec8bff}" => removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{b60873b9-51aa-4566-b2fc-c16de2ec8bff}" => removed successfully
C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js => moved successfully
C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg => moved successfully
Could not move "C:\DumpStack.log.tmp" => Scheduled to move on reboot.
C:\Users\Milan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini => moved successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avg => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\ANotepad++64 => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
"HKLM\Software\Classes\CLSID\{85BBD920-42A0-1069-A2E4-08002B30309D}" => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\SHAREit.FileContextMenuExt => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\7-Zip => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\SHAREit.FileContextMenuExt => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\BriefcaseMenu => removed successfully
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\Offline Files => removed successfully
C:\Users\Milan\Downloads\CAM00341.mp4 => ":TOC.WMV" ADS removed successfully
C:\Users\Milan\Downloads\Príšerky-s.r.o..mpg => ":TOC.WMV" ADS removed successfully
C:\Users\Milan\Downloads\terypo1.avi => ":TOC.WMV" ADS removed successfully

=========== EmptyTemp: ==========

BITS transfer queue => 10510336 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 81418628 B
Java, Flash, Steam htmlcache => 370484770 B
Windows/system/drivers => 1047965 B
Edge => 128875 B
Chrome => 391092145 B
Firefox => 32366767 B
Opera => 706611 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 31336 B
NetworkService => 36520 B
Milan => 48636739 B

RecycleBin => 0 B
EmptyTemp: => 893.1 MB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 09-09-2020 14:28:58)

C:\DumpStack.log.tmp => Could not move

==== End of Fixlog 14:28:59 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu

#11 Příspěvek od Rudy »

Smazáno, log již bude OK.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

superjano
Návštěvník
Návštěvník
Příspěvky: 64
Registrován: 16 srp 2005 23:08

Re: prosim o kontrolu

#12 Příspěvek od superjano »

Dakujem.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 118275
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: prosim o kontrolu

#13 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno