Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivka 4.10.2020

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Preventivka 4.10.2020

#1 Příspěvek od bojimso »

Zdravím,

odinstaloval jsem Avast a nainstaloval Kaspersky Total Security, tak jsem zvedav na pretentivku :happy:

RSIT LOG:

Logfile of random's system information tool 1.10 (written by random/random)
Run by David at 2020-10-04 18:25:29
Microsoft Windows 10 Home
System drive C: has 24 GB (10%) free of 228 GB
Total RAM: 16329 MB (62% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:25:34, on 04.10.2020
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.18362.0001)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksdeui.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
C:\Windows\System32\TiltWheelMouse.exe
C:\Program Files (x86)\Gyazo\GyStation.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\ProgramData\Battle.net\Agent\Agent.7205\Agent.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\plugin-nm-server-v2.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\transport_proxy.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files\trend micro\David.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.68\BHO\ie_to_edge_bho.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\David\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe
O4 - HKCU\..\Run: [Battle.net] "C:\Program Files (x86)\Battle.net\Battle.net.exe" --autostarted
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [TSMApplication] "C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Ubisoft Game Launcher] "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe" -uplay_silent
O4 - HKCU\..\Run: [kpm.exe] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe" autoStart
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: chrome.lnk = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\Program Files\Microsoft Office\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Export do &Tahiti - C:\Program Files (x86)\LightComp eDoklady Skenováni\iehelper.html
O8 - Extra context menu item: Poslat do On&eNotu - res://C:\Program Files\Microsoft Office\Office16\ONBttnIE.dll/105
O9 - Extra button: Poslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Poslat do On&eNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{7c9dc72d-d055-4562-a383-1580067a83d0}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus 21.1 (AVP21.1) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avp.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_1b173d0e - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\85.0.4183.121\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HPSmartDeviceAgentBase - Unknown owner - c:\Program Files (x86)\HP\HPSmartDeviceAgentBase\Service\HPSmartDeviceAgentBase.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\WINDOWS\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Kaspersky Volume Shadow Copy Service Bridge 21.1 (klvssbridge64_21.1) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\vssbridge64.exe
O23 - Service: Kaspersky Password Manager Service (kpm_launch_service) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
O23 - Service: Služba Kaspersky Secure Connection 5.1 (KSDE5.1) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Rockstar Game Library Service (Rockstar Service) - Rockstar Games - C:\Program Files\Rockstar Games\Launcher\RockstarService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: Adaptér výkonu rozhraní WMI (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12757 bytes

======Listing Processes======









C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
"fontdrvhost.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-c9bbe29a-ef4e-41f0-bc9d-ec59a4e0cb44 -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-4349a661-9150-47f6-90e3-e693a6dde80f -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-3bb11cbe-7100-461c-9386-ea58d2af5408 -NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-e4929c35-9d0b-4d5c-b451-29f324d9f772 -LifetimeId:ca1e7e99-8db2-40f2-87f1-c0e1146a702d -DeviceGroupId:WudfDefaultDevicePool -HostArg:0
C:\WINDOWS\system32\svchost.exe -k RPCSS -p
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s LSM
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s TimeBrokerSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s hidserv
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s ProfSvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UserManager
C:\WINDOWS\system32\svchost.exe -k LocalService -p
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s nsi
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s Dhcp
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s Themes
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s EventSystem
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s NlaSvc
C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s DispBrokerDesktopSvc

C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s SENS
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s StateRepository
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s AudioEndpointBuilder
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s FontCache
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s netprofm
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s fdPHost
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Winmgmt
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s FDResPub
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s ShellHWDetection
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s DeviceAssociationService
C:\WINDOWS\System32\spoolsv.exe
dashost.exe {15e1ce64-53b6-44da-902fca596b188327}
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup -s WbioSrvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s LanmanWorkstation
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s IKEEXT
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted -p -s PolicyAgent
C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s CryptSvc
C:\WINDOWS\System32\svchost.exe -k utcsvc -p
C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p -s DPS

C:\WINDOWS\System32\svchost.exe -k NetSvcs -p -s iphlpsvc
C:\WINDOWS\system32\IProsetMonitor.exe

"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s SstpSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s LanmanServer
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s WpnService
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s WdiServiceHost
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TrkWks
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s TapiSrv
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s SSDPSRV
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s TokenBroker
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TabletInputService
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s CDPSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s lfsvc
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s LicenseManager

C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc
C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe"

C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe" -r

C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UsoSvc

C:\WINDOWS\System32\svchost.exe -k netsvcs -p
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s BthAvctpSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wuauserv
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Appinfo
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s camsvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -s RmSvc
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s DsSvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p -s NcdAutoSetup

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"fontdrvhost.exe"
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
"C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbamtray.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s CDPUserSvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s lmhosts
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s WpnUserService
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe" /s
C:\WINDOWS\Explorer.EXE
"ctfmon.exe"
C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc
"C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksdeui.exe" -hidden
"C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20091.84.0_x64__8wekyb3d8bbwe\YourPhone.exe" -ServerName:App.AppX9yct9q388jvt4h7y0gn06smzkxcsnt8m.mca

C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe" /i
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe" /i
C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\SecurityHealthSystray.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\System32\TiltWheelMouse.exe"
"C:\Program Files (x86)\Gyazo\GyStation.exe"
"C:\Program Files (x86)\Battle.net\Battle.net.exe" --autostarted
"C:\ProgramData\Battle.net\Agent\Agent.7205\Agent.exe" --session=7611091551001092446
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Battle.net\Battle.net.exe" --type=gpu-process --field-trial-handle=3400,5861024952714410837,14644616897679839203,131072 --disable-features=HardwareMediaKeyHandling --no-sandbox --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201004T150353.748000.log" --log-severity=error --product-version="Battle.net/1.26.0.12375 (retail) Chrome/75.0.3770.100" --lang=en-US --watch-browser-pid=12040 --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201004T150353.748000.log" --service-request-channel-token=14764797108598018101 --mojo-platform-channel-handle=3424 /prefetch:2 --battle-net-helper=Battle.net.12375
"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe" -uplay_silent
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe" autoStart
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\David\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\David\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\David\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=85.0.4183.121 --initial-client-data=0xdc,0xe0,0xe4,0xb8,0xe8,0x7ffe8cab3e00,0x7ffe8cab3e10,0x7ffe8cab3e20
"C:\Program Files (x86)\Battle.net\Battle.net.exe" --type=utility --field-trial-handle=3400,5861024952714410837,14644616897679839203,131072 --disable-features=HardwareMediaKeyHandling --lang=en-US --service-sandbox-type=network --no-sandbox --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201004T150353.748000.log" --log-severity=error --product-version="Battle.net/1.26.0.12375 (retail) Chrome/75.0.3770.100" --lang=en-US --watch-browser-pid=12040 --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201004T150353.748000.log" --service-request-channel-token=5234441734018309539 --mojo-platform-channel-handle=4608 /prefetch:8 --battle-net-helper=Battle.net.12375
"C:\Program Files (x86)\Battle.net\Battle.net.exe" --type=renderer --no-sandbox --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201004T150353.748000.log" --field-trial-handle=3400,5861024952714410837,14644616897679839203,131072 --disable-features=HardwareMediaKeyHandling --lang=en-US --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201004T150353.748000.log" --log-severity=error --product-version="Battle.net/1.26.0.12375 (retail) Chrome/75.0.3770.100" --disable-spell-checking --uncaught-exception-stack-size=10 --watch-browser-pid=12040 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=14754457500553732597 --renderer-client-id=4 --mojo-platform-channel-handle=4672 /prefetch:1 --battle-net-helper=Battle.net.12375
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1548 /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --lang=cs --service-sandbox-type=network --enable-audio-service-sandbox --mojo-platform-channel-handle=1860 /prefetch:8
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=2884 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --extension-process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3192 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --extension-process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3420 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --extension-process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3452 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --extension-process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3464 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --extension-process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3480 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --extension-process --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3500 /prefetch:1
C:\WINDOWS\system32\cmd.exe /d /c "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\plugins_nms.exe" chrome-extension://ahkjpbeeocnddjkakilopmfdlnjdpcdm/ --parent-window=0 < \\.\pipe\chrome.nativeMessaging.in.44d023300cd58f45 > \\.\pipe\chrome.nativeMessaging.out.44d023300cd58f45
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\cmd.exe /d /c "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\plugin-nm-server-v2.exe" chrome-extension://dhnkblpjbkfklfloegejegedcafpliaa/ --parent-window=0 < \\.\pipe\chrome.nativeMessaging.in.746c41fc533d8a9 > \\.\pipe\chrome.nativeMessaging.out.746c41fc533d8a9
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\plugin-nm-server-v2.exe" chrome-extension://dhnkblpjbkfklfloegejegedcafpliaa/ --parent-window=0

"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\transport_proxy.exe" -Embedding
"C:/Program Files (x86)/Ubisoft/Ubisoft Game Launcher/UplayWebCore.exe" --type=renderer --no-sandbox --disable-features=TouchpadAndWheelScrollLatching --service-pipe-token=0C241FBD347CF48362081D6F1A398B7B --lang=en-US --locales-dir-path="C:/Program Files (x86)/Ubisoft/Ubisoft Game Launcher/locales/1/" --log-file="C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\debug.log" --disable-spell-checking --enable-system-flash --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=0C241FBD347CF48362081D6F1A398B7B --renderer-client-id=4 --mojo-platform-channel-handle=2668 /prefetch:1
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --lang=cs --service-sandbox-type=audio --enable-audio-service-sandbox --mojo-platform-channel-handle=6288 /prefetch:8
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2008.2.0_x64__8wekyb3d8bbwe\Calculator.exe" -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca
"C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.20090.1002.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\system32\AUDIODG.EXE 0x6f4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=61 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3360 /prefetch:1
"C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\Windows\System32\SystemSettingsBroker.exe -Embedding
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe141_ Global\UsGthrCtrlFltPipeMssGthrPipe141 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 776 780 788 8192 784
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=77 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6968 /prefetch:1
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1540,15402120024578718566,13073659515167178781,131072 --disable-gpu-compositing --lang=cs --enable-auto-reload --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=90 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=1472 /prefetch:1
C:\Windows\System32\smartscreen.exe -Embedding
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc
"C:\Users\David\Desktop\RSITx64.exe"
C:\Windows\System32\RuntimeBroker.exe -Embedding
consent.exe 10620 324 000002E94AC57A50

=========Mozilla firefox=========

ProfilePath - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\3911gjs4.default

prefs.js - "browser.startup.homepage" - "https://www.facebook.com/"

"light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com"=C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\FFExt\light_plugin_firefox\addon.xpi


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\Office16\NPSPWRAP.DLL


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=4.0.0-dev]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.68\BHO\ie_to_edge_bho_64.dll [2020-10-01 514944]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-13 2177328]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.68\BHO\ie_to_edge_bho.dll [2020-10-01 399248]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-13 1522480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\WINDOWS\system32\SecurityHealthSystray.exe [2020-02-14 84992]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-09-17 16404224]
"MouseDriver"=C:\Windows\system32\TiltWheelMouse.exe [2013-04-09 241152]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2015-06-23 36352]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2018-11-02 3942936]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\David\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2020-02-07 1573224]
"Gyazo"=C:\Program Files (x86)\Gyazo\GyStation.exe [2018-10-04 1384840]
"Battle.net"=C:\Program Files (x86)\Battle.net\Battle.net.exe [2020-09-24 1090024]
"CCleaner Smart Cleaning"=C:\Program Files\CCleaner\CCleaner64.exe [2020-09-22 30870200]
"TSMApplication"=C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe [2020-08-17 1623040]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2020-02-09 365160]
"Ubisoft Game Launcher"=C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe [2020-09-23 471360]
"kpm.exe"=C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [2020-08-24 659976]

C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CBDHSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CBDHSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudAddService.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudBus.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\usbaudio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinQuic]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableFullTrustStartupTasks"=2
"EnableUwpStartupTasks"=2
"SupportFullTrustStartupTasks"=1
"SupportUwpStartupTasks"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"aux"=wdmaud.drv
"midi"=wdmaud.drv
"midimapper"=midimap.dll
"mixer"=wdmaud.drv
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wave"=wdmaud.drv
"wavemapper"=msacm32.drv
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.FPS1"=frapsv64.dll
"VIDC.RTV1"=rtvcvfw64.dll
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2020-10-04 18:25:29 ----D---- C:\rsit
2020-10-04 18:25:29 ----D---- C:\Program Files\trend micro
2020-09-28 23:34:33 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2020-09-28 23:34:28 ----A---- C:\WINDOWS\system32\drivers\farflt.sys
2020-09-28 23:34:27 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2020-09-28 23:34:27 ----A---- C:\WINDOWS\system32\drivers\MbamChameleon.sys
2020-09-28 23:32:21 ----D---- C:\WINDOWS\LastGood
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo-1-999-0-0-0.exe
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1-999-0-0-0.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\nvofapi.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\OpenCL.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\nvofapi64.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\nvmcumd.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\nvdispgenco6445655.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\nvdispco6445655.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2020-09-28 23:31:39 ----A---- C:\WINDOWS\system32\nvcuda.dll
2020-09-22 17:16:27 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2020-09-22 17:16:25 ----A---- C:\WINDOWS\system32\drivers\MbamElam.sys
2020-09-18 03:54:38 ----D---- C:\WINDOWS\LastGood.Tmp
2020-09-18 03:53:48 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2020-09-15 20:57:01 ----D---- C:\Program Files (x86)\Mozilla Firefox
2020-09-10 00:29:04 ----A---- C:\WINDOWS\SYSWOW64\fveapibase.dll
2020-09-10 00:29:04 ----A---- C:\WINDOWS\SYSWOW64\fveapi.dll
2020-09-10 00:29:03 ----A---- C:\WINDOWS\system32\FXSUTILITY.dll
2020-09-10 00:29:03 ----A---- C:\WINDOWS\system32\fveapibase.dll
2020-09-10 00:29:03 ----A---- C:\WINDOWS\system32\fveapi.dll
2020-09-10 00:29:02 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2020-09-10 00:29:02 ----A---- C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2020-09-10 00:29:02 ----A---- C:\WINDOWS\system32\WinBioDataModel.dll
2020-09-10 00:29:02 ----A---- C:\WINDOWS\system32\WFSR.dll
2020-09-10 00:29:02 ----A---- C:\WINDOWS\system32\WFS.exe
2020-09-10 00:29:02 ----A---- C:\WINDOWS\system32\FXSCOVER.exe
2020-09-10 00:29:02 ----A---- C:\WINDOWS\system32\FXSCOMPOSERES.dll
2020-09-10 00:29:02 ----A---- C:\WINDOWS\system32\FXSCOMPOSE.dll
2020-09-10 00:29:01 ----A---- C:\WINDOWS\system32\cdp.dll
2020-09-10 00:29:01 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2020-09-10 00:28:58 ----A---- C:\WINDOWS\SYSWOW64\xpsrchvw.exe
2020-09-10 00:28:58 ----A---- C:\WINDOWS\system32\xpsrchvw.exe
2020-09-10 00:28:56 ----A---- C:\WINDOWS\SYSWOW64\WMVCORE.DLL
2020-09-10 00:28:56 ----A---- C:\WINDOWS\SYSWOW64\WMADMOE.DLL
2020-09-10 00:28:56 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2020-09-10 00:28:56 ----A---- C:\WINDOWS\SYSWOW64\DolbyDecMFT.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOE.DLL
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\mfh264enc.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\system32\HologramCompositor.dll
2020-09-10 00:28:55 ----A---- C:\WINDOWS\system32\DolbyDecMFT.dll
2020-09-10 00:28:54 ----A---- C:\WINDOWS\system32\Hydrogen.dll
2020-09-10 00:28:53 ----A---- C:\WINDOWS\system32\WMVCORE.DLL
2020-09-10 00:28:53 ----A---- C:\WINDOWS\system32\WMADMOE.DLL
2020-09-10 00:28:53 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2020-09-10 00:28:53 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2020-09-10 00:28:53 ----A---- C:\WINDOWS\system32\HologramWorld.dll
2020-09-10 00:28:52 ----A---- C:\WINDOWS\system32\WMSPDMOE.DLL
2020-09-10 00:28:52 ----A---- C:\WINDOWS\system32\MSAudDecMFT.dll
2020-09-10 00:28:52 ----A---- C:\WINDOWS\system32\mfh264enc.dll
2020-09-10 00:28:51 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-09-10 00:28:51 ----A---- C:\WINDOWS\system32\mfds.dll
2020-09-10 00:28:50 ----A---- C:\WINDOWS\system32\mfsvr.dll
2020-09-10 00:28:50 ----A---- C:\WINDOWS\system32\mfcore.dll
2020-09-10 00:28:50 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2020-09-10 00:28:49 ----A---- C:\WINDOWS\system32\mf.dll
2020-09-10 00:28:48 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecsRaw.dll
2020-09-10 00:28:48 ----A---- C:\WINDOWS\system32\WindowsCodecsRaw.dll
2020-09-10 00:28:47 ----A---- C:\WINDOWS\SYSWOW64\Windows.Mirage.Internal.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\nshwfp.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\NAPCRYPT.DLL
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\mstext40.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\msjet40.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\msimsg.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\iemigplugin.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\Chakrathunk.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\Chakradiag.dll
2020-09-10 00:28:46 ----A---- C:\WINDOWS\SYSWOW64\CPFilters.dll
2020-09-10 00:28:45 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2020-09-10 00:28:44 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2020-09-10 00:28:44 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2020-09-10 00:28:43 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2020-09-10 00:28:43 ----A---- C:\WINDOWS\SYSWOW64\upnpcont.exe
2020-09-10 00:28:43 ----A---- C:\WINDOWS\SYSWOW64\udhisapi.dll
2020-09-10 00:28:43 ----A---- C:\WINDOWS\SYSWOW64\tar.exe
2020-09-10 00:28:43 ----A---- C:\WINDOWS\SYSWOW64\fdWSD.dll
2020-09-10 00:28:43 ----A---- C:\WINDOWS\SYSWOW64\fdSSDP.dll
2020-09-10 00:28:43 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2020-09-10 00:28:43 ----A---- C:\WINDOWS\SYSWOW64\dnscmmc.dll
2020-09-10 00:28:42 ----A---- C:\WINDOWS\SYSWOW64\upnphost.dll
2020-09-10 00:28:42 ----A---- C:\WINDOWS\system32\wslapi.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\SIHClient.exe
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\pnrpsvc.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\P2P.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\nshwfp.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\nltest.exe
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\nettrace.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\NAPCRYPT.DLL
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\msimsg.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\msi.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\FileHistory.exe
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\fhuxgraphics.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\drivers\ndiscap.sys
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\DAFMCP.dll
2020-09-10 00:28:41 ----A---- C:\WINDOWS\system32\CPFilters.dll
2020-09-10 00:28:40 ----A---- C:\WINDOWS\system32\jscript9diag.dll
2020-09-10 00:28:40 ----A---- C:\WINDOWS\system32\jscript9.dll
2020-09-10 00:28:40 ----A---- C:\WINDOWS\system32\iemigplugin.dll
2020-09-10 00:28:40 ----A---- C:\WINDOWS\system32\ieframe.dll
2020-09-10 00:28:40 ----A---- C:\WINDOWS\system32\Chakrathunk.dll
2020-09-10 00:28:40 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2020-09-10 00:28:39 ----A---- C:\WINDOWS\system32\ieproxy.dll
2020-09-10 00:28:39 ----A---- C:\WINDOWS\system32\Chakra.dll
2020-09-10 00:28:38 ----A---- C:\WINDOWS\system32\wsecedit.dll
2020-09-10 00:28:38 ----A---- C:\WINDOWS\system32\tar.exe
2020-09-10 00:28:38 ----A---- C:\WINDOWS\system32\mshtml.dll
2020-09-10 00:28:38 ----A---- C:\WINDOWS\system32\fdWSD.dll
2020-09-10 00:28:38 ----A---- C:\WINDOWS\system32\dnscmmc.dll
2020-09-10 00:28:38 ----A---- C:\WINDOWS\system32\computecore.dll
2020-09-10 00:28:38 ----A---- C:\WINDOWS\system32\ClipUp.exe
2020-09-10 00:28:37 ----A---- C:\WINDOWS\system32\tcbloader.dll
2020-09-10 00:28:37 ----A---- C:\WINDOWS\system32\tcblaunch.exe
2020-09-10 00:28:37 ----A---- C:\WINDOWS\system32\securekernel.exe
2020-09-10 00:28:37 ----A---- C:\WINDOWS\system32\kdhvcom.dll
2020-09-10 00:28:37 ----A---- C:\WINDOWS\system32\hvix64.exe
2020-09-10 00:28:36 ----A---- C:\WINDOWS\system32\udhisapi.dll
2020-09-10 00:28:36 ----A---- C:\WINDOWS\system32\hvloader.dll
2020-09-10 00:28:36 ----A---- C:\WINDOWS\system32\hvax64.exe
2020-09-10 00:28:36 ----A---- C:\WINDOWS\system32\fdSSDP.dll
2020-09-10 00:28:36 ----A---- C:\WINDOWS\system32\drivers\hvservice.sys
2020-09-10 00:28:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.FileExplorer.dll
2020-09-10 00:28:35 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2020-09-10 00:28:35 ----A---- C:\WINDOWS\SYSWOW64\scecli.dll
2020-09-10 00:28:35 ----A---- C:\WINDOWS\system32\vid.dll
2020-09-10 00:28:35 ----A---- C:\WINDOWS\system32\upnphost.dll
2020-09-10 00:28:35 ----A---- C:\WINDOWS\system32\upnpcont.exe
2020-09-10 00:28:35 ----A---- C:\WINDOWS\system32\ssdpsrv.dll
2020-09-10 00:28:35 ----A---- C:\WINDOWS\system32\ssdpapi.dll
2020-09-10 00:28:35 ----A---- C:\WINDOWS\system32\SgrmEnclave_secure.dll
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\rtutils.dll
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\msxml3r.dll
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\msxml3.dll
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\msIso.dll
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\KBDKOR.DLL
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\KBDJPN.DLL
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\kbd106n.dll
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\kbd106.dll
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\kbd101.DLL
2020-09-10 00:28:32 ----A---- C:\WINDOWS\SYSWOW64\edgeIso.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\wincorlib.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\tzres.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\tdh.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\samlib.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\perfproc.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\perfos.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\perfnet.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\perfdisk.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\perfctrs.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\pdh.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\offlinesam.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\msimg32.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\mf3216.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\edpnotify.exe
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\dtdump.exe
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\dnsapi.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc6.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\dhcpcsvc.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore6.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\dhcpcore.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\ddraw.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\dbghelp.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\credprovs.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2020-09-10 00:28:31 ----A---- C:\WINDOWS\SYSWOW64\BitLockerCsp.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryUpgrade.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryPS.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryCore.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryBroker.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.Vpn.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Devices.Lights.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\win32u.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\win32k.sys
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\StateRepository.Core.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\srpapi.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\OneCoreUAPCommonProxyStub.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\msxml6r.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\daxexec.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\cmintegrator.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\AppLockerCSP.dll
2020-09-10 00:28:30 ----A---- C:\WINDOWS\SYSWOW64\appidtel.exe
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\wintrust.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.Payments.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\UserDataTimeUtil.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\tquery.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\InstallServiceTasks.dll
2020-09-10 00:28:29 ----A---- C:\WINDOWS\SYSWOW64\InstallService.dll
2020-09-10 00:28:28 ----A---- C:\WINDOWS\SYSWOW64\SearchIndexer.exe
2020-09-10 00:28:28 ----A---- C:\WINDOWS\SYSWOW64\SearchFilterHost.exe
2020-09-10 00:28:28 ----A---- C:\WINDOWS\SYSWOW64\Search.ProtocolHandler.MAPI2.dll
2020-09-10 00:28:28 ----A---- C:\WINDOWS\SYSWOW64\mssvp.dll
2020-09-10 00:28:28 ----A---- C:\WINDOWS\SYSWOW64\mssrch.dll
2020-09-10 00:28:28 ----A---- C:\WINDOWS\SYSWOW64\mssprxy.dll
2020-09-10 00:28:28 ----A---- C:\WINDOWS\SYSWOW64\mssph.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\wudriver.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Input.Inking.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\TokenBrokerCookies.exe
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\thumbcache.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\tbauth.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\SearchProtocolHost.exe
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\mssitlb.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\msscntrs.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\mapistub.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\mapi32.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\kernel32.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\fixmapi.exe
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\DWrite.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\CloudExperienceHostCommon.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\cdprt.dll
2020-09-10 00:28:25 ----A---- C:\WINDOWS\SYSWOW64\ActivationManager.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\Windows.Security.Authentication.Web.Core.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\TokenBroker.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\sspicli.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\rpcrt4.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\PCPKsp.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\InputSwitch.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\SYSWOW64\ContentDeliveryManager.Utilities.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\system32\XpsPrint.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\system32\scecli.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\system32\rtutils.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\system32\rascustom.dll
2020-09-10 00:28:24 ----A---- C:\WINDOWS\system32\drivers\wanarp.sys
2020-09-10 00:28:24 ----A---- C:\WINDOWS\system32\drivers\ndproxy.sys
2020-09-10 00:28:24 ----A---- C:\WINDOWS\system32\drivers\ndistapi.sys
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\wininet.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\tdh.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\policymanager.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\perfproc.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\perfos.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\perfnet.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\perfdisk.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\perfctrs.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\pdh.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\omadmclient.exe
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\msxml3r.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\msxml3.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\msIso.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\KBDJPN.DLL
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\kbd106n.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\kbd106.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\kbd101.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\jsproxy.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\iertutil.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\gdi32full.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\efscore.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\edpnotify.exe
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\edgeIso.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\drivers\ahcache.sys
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\dmenterprisediagnostics.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\ddraw.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\cryptcatsvc.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\credprovs.dll
2020-09-10 00:28:22 ----A---- C:\WINDOWS\system32\BitLockerCsp.dll
2020-09-10 00:28:18 ----A---- C:\WINDOWS\system32\wuuhext.dll
2020-09-10 00:28:18 ----A---- C:\WINDOWS\system32\wow64win.dll
2020-09-10 00:28:18 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-09-10 00:28:18 ----A---- C:\WINDOWS\system32\SecurityHealthService.exe
2020-09-10 00:28:18 ----A---- C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-09-10 00:28:18 ----A---- C:\WINDOWS\system32\SecurityHealthHost.exe
2020-09-10 00:28:18 ----A---- C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\msimg32.dll
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\mf3216.dll
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\lpk.dll
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\fontsub.dll
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\drivers\mup.sys
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\drivers\mrxsmb.sys
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2020-09-10 00:28:17 ----A---- C:\WINDOWS\system32\dciman32.dll
2020-09-10 00:28:15 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\sspisrv.dll
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\sspicli.dll
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\rpcrt4.dll
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\lsass.exe
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\KernelBase.dll
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\drivers\tcpip.sys
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\drivers\ndis.sys
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\drivers\msrpc.sys
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\drivers\ksecdd.sys
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\drivers\FWPKCLNT.SYS
2020-09-10 00:28:15 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\WinTypes.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\wincorlib.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\utcutil.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\tzres.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\schannel.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\samsrv.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\samlib.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\runexehelper.exe
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\profsvc.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\offlinesam.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\ntdll.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\lsasrv.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\dnsrslvr.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\dnsapi.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\diagtrack.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\dhcpcsvc6.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\dhcpcsvc.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\dhcpcore6.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\dhcpcore.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\dbghelp.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\combase.dll
2020-09-10 00:28:14 ----A---- C:\WINDOWS\system32\ci.dll
2020-09-10 00:28:13 ----A---- C:\WINDOWS\system32\wudriver.dll
2020-09-10 00:28:13 ----A---- C:\WINDOWS\system32\TabSvc.dll
2020-09-10 00:28:13 ----A---- C:\WINDOWS\system32\sppsvc.exe
2020-09-10 00:28:13 ----A---- C:\WINDOWS\system32\sppobjs.dll
2020-09-10 00:28:13 ----A---- C:\WINDOWS\system32\SppExtComObj.Exe
2020-09-10 00:28:13 ----A---- C:\WINDOWS\system32\sppcext.dll
2020-09-10 00:28:13 ----A---- C:\WINDOWS\system32\msctf.dll
2020-09-10 00:28:13 ----A---- C:\WINDOWS\system32\InputSwitch.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\tier2punctuations.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\srpapi.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\SRH.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\shell32.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\ole32.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\dwmcore.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\drivers\applockerfltr.sys
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\drivers\appid.sys
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\CloudExperienceHostBroker.exe
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\appraiser.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\AppLockerCSP.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\appidtel.exe
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\appidsvc.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\appidpolicyconverter.exe
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\appidcertstorecheck.exe
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\appidapi.dll
2020-09-10 00:28:12 ----A---- C:\WINDOWS\system32\acmigration.dll
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\win32kfull.sys
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\wevtsvc.dll
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\usosvc.dll
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\usocoreworker.exe
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\updatecsp.dll
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\twinui.pcshell.dll
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\MusNotifyIcon.exe
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\MusNotificationUx.exe
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\MusNotification.exe
2020-09-10 00:28:11 ----A---- C:\WINDOWS\system32\daxexec.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\wpnservice.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\wintrust.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\windows.storage.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.Devices.Lights.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\WindowManagement.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\win32u.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\win32k.sys
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\VPNv2CSP.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\UserDataTimeUtil.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\storewuauth.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\StateRepository.Core.dll
2020-09-10 00:28:10 ----A---- C:\WINDOWS\system32\cmintegrator.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\Windows.Payments.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\tquery.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\SearchIndexer.exe
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\SearchFilterHost.exe
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\mssvp.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\mssrch.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\mssprxy.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\mssph.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\ISM.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\InstallServiceTasks.dll
2020-09-10 00:28:09 ----A---- C:\WINDOWS\system32\InstallService.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\SearchProtocolHost.exe
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\msxml6r.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\msxml6.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\mssitlb.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\msscntrs.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\FntCache.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\EdgeContent.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\dxgi.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\DWrite.dll
2020-09-10 00:28:06 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\wuuhosdeployment.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\wups2.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\wuaueng.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\wuauclt.exe
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\wuapi.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\win32kbase.sys
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\CloudExperienceHostUser.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\cdd.dll
2020-09-10 00:28:05 ----A---- C:\WINDOWS\system32\appinfo.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\WWAHost.exe
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\TokenBrokerCookies.exe
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\TokenBroker.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\thumbcache.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\tbauth.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\smbwmiv2.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\mapistub.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\mapi32.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\kernel32.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\fixmapi.exe
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\CustomInstallExec.exe
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\cdpusersvc.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\cdpsvc.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\cdprt.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-09-10 00:28:04 ----A---- C:\WINDOWS\system32\ActivationManager.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\UtcDecoderHost.exe
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\StartTileData.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\provtool.exe
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\provops.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\provhandlers.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\provengine.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\provdiagnostics.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\provdatastore.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\PCPKsp.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\localspl.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\drivers\PEAuth.sys
2020-09-10 00:28:03 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\wwansvc.dll
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\Vid.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\storufs.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\stornvme.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\processr.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\KNetPwrDepBroker.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\intelppm.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\amdppm.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\drivers\amdk8.sys
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-09-10 00:28:02 ----A---- C:\WINDOWS\system32\audiosrv.dll
2020-09-10 00:28:01 ----A---- C:\WINDOWS\system32\drivers\BtaMPM.sys
2020-09-10 00:21:14 ----A---- C:\WINDOWS\SYSWOW64\poqexec.exe
2020-09-10 00:21:14 ----A---- C:\WINDOWS\system32\poqexec.exe
2020-09-07 00:47:25 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_klark.sys
2020-09-07 00:44:30 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_mark.sys
2020-09-07 00:44:30 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_klbg.sys
2020-09-07 00:44:30 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_kimul.sys
2020-09-07 00:44:30 ----A---- C:\WINDOWS\system32\drivers\klupd_klif_arkmon.sys
2020-09-07 00:44:17 ----A---- C:\WINDOWS\system32\klfphc.dll
2020-09-07 00:44:09 ----D---- C:\Program Files (x86)\Kaspersky Lab
2020-09-07 00:44:05 ----A---- C:\WINDOWS\system32\drivers\klif.sys
2020-09-07 00:44:05 ----A---- C:\WINDOWS\system32\drivers\klflt.sys
2020-09-07 00:41:46 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2020-09-07 00:21:19 ----A---- C:\ProgramData\ntuser.dat
2020-09-06 23:41:05 ----D---- C:\ProgramData\Kaspersky Lab
2020-09-06 22:44:38 ----D---- C:\ProgramData\Kaspersky Lab Setup Files
2020-09-05 02:04:46 ----D---- C:\Users\David\AppData\Roaming\Mael Horz

======List of files/folders modified in the last 1 month======

2020-10-04 18:25:30 ----D---- C:\WINDOWS\Prefetch
2020-10-04 18:25:29 ----D---- C:\Program Files
2020-10-04 18:16:26 ----D---- C:\WINDOWS\system32\SleepStudy
2020-10-04 18:16:26 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2020-10-04 18:05:00 ----D---- C:\WINDOWS\system32\sru
2020-10-04 17:06:26 ----D---- C:\ProgramData\NVIDIA
2020-10-04 17:04:23 ----D---- C:\WINDOWS\Temp
2020-10-04 07:59:50 ----D---- C:\WINDOWS\system32\Tasks
2020-10-04 00:04:10 ----D---- C:\Users\David\AppData\Roaming\vlc
2020-10-03 23:38:43 ----HD---- C:\Program Files\WindowsApps
2020-10-03 23:38:43 ----D---- C:\WINDOWS\AppReadiness
2020-10-03 23:12:38 ----RD---- C:\WINDOWS\Microsoft.NET
2020-10-02 13:29:38 ----D---- C:\Users\David\AppData\Roaming\qBittorrent
2020-10-01 08:44:37 ----D---- C:\WINDOWS\system32\DriverStore
2020-10-01 08:44:37 ----D---- C:\WINDOWS\INF
2020-10-01 02:05:27 ----D---- C:\WINDOWS\system32\catroot2
2020-10-01 00:26:37 ----SHD---- C:\WINDOWS\Installer
2020-10-01 00:26:36 ----D---- C:\WINDOWS\system32\Logs
2020-10-01 00:26:36 ----D---- C:\Program Files\Microsoft Update Health Tools
2020-10-01 00:26:31 ----SHD---- C:\System Volume Information
2020-10-01 00:26:15 ----D---- C:\WINDOWS\Logs
2020-10-01 00:00:00 ----D---- C:\WINDOWS\system32\LogFiles
2020-09-29 19:54:20 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2020-09-29 19:54:18 ----RD---- C:\Program Files (x86)
2020-09-29 17:40:28 ----D---- C:\WINDOWS\System32
2020-09-29 00:55:11 ----D---- C:\Program Files (x86)\MSI Afterburner
2020-09-29 00:05:53 ----AD---- C:\Users\David\AppData\Roaming\Curse Client
2020-09-28 23:40:28 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2020-09-28 23:34:33 ----D---- C:\WINDOWS\system32\drivers
2020-09-28 23:34:19 ----D---- C:\WINDOWS\SysWOW64
2020-09-28 23:32:21 ----D---- C:\Windows
2020-09-26 01:35:42 ----A---- C:\WINDOWS\system32\nvapi64.dll
2020-09-26 01:35:40 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2020-09-25 20:47:23 ----AD---- C:\World of Warcraft
2020-09-25 01:41:45 ----AD---- C:\Program Files (x86)\Battle.net
2020-09-24 22:26:54 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2020-09-24 22:26:54 ----A---- C:\WINDOWS\system32\nvcpl.dll
2020-09-24 22:26:52 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2020-09-24 22:26:52 ----A---- C:\WINDOWS\system32\nvshext.dll
2020-09-24 22:26:52 ----A---- C:\WINDOWS\system32\nvmctray.dll
2020-09-24 22:26:51 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2020-09-24 22:26:51 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2020-09-22 17:16:26 ----HD---- C:\WINDOWS\ELAMBKUP
2020-09-18 03:55:36 ----D---- C:\ProgramData\NVIDIA Corporation
2020-09-18 03:54:48 ----D---- C:\Program Files\NVIDIA Corporation
2020-09-15 00:13:44 ----A---- C:\WINDOWS\system32\nvhdagenco6420103.dll
2020-09-11 16:32:58 ----D---- C:\WINDOWS\system32\config
2020-09-10 18:14:38 ----A---- C:\WINDOWS\system32\sedplugins.dll
2020-09-10 18:14:36 ----A---- C:\WINDOWS\system32\QualityUpdateAssistant.dll
2020-09-10 01:36:01 ----D---- C:\WINDOWS\WinSxS
2020-09-10 00:36:41 ----AD---- C:\Program Files\WinRAR
2020-09-10 00:35:57 ----D---- C:\WINDOWS\SYSWOW64\migration
2020-09-10 00:35:57 ----D---- C:\WINDOWS\SYSWOW64\en-US
2020-09-10 00:35:57 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2020-09-10 00:35:57 ----D---- C:\WINDOWS\SystemResources
2020-09-10 00:35:56 ----SD---- C:\WINDOWS\system32\DiagSvcs
2020-09-10 00:35:56 ----RD---- C:\WINDOWS\PrintDialog
2020-09-10 00:35:56 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\wbem
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\ru-RU
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\ro-RO
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\pt-PT
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\pl-PL
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\oobe
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\nl-NL
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\migwiz
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\migration
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\en-US
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\el-GR
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\cs-CZ
2020-09-10 00:35:56 ----D---- C:\WINDOWS\system32\ar-SA
2020-09-10 00:35:56 ----D---- C:\WINDOWS\ShellExperiences
2020-09-10 00:35:56 ----D---- C:\WINDOWS\Provisioning
2020-09-10 00:35:56 ----D---- C:\WINDOWS\bcastdvr
2020-09-10 00:35:56 ----D---- C:\Program Files\Internet Explorer
2020-09-10 00:35:03 ----D---- C:\WINDOWS\system32\MRT
2020-09-10 00:32:07 ----AC---- C:\WINDOWS\system32\MRT.exe
2020-09-10 00:32:04 ----D---- C:\WINDOWS\CbsTemp
2020-09-10 00:28:02 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2020-09-09 02:45:10 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2020-09-09 02:45:06 ----D---- C:\WINDOWS\system32\Macromed
2020-09-09 02:45:05 ----D---- C:\WINDOWS\SYSWOW64\Macromed
2020-09-07 03:05:58 ----D---- C:\WINDOWS\AutoKMS
2020-09-07 00:46:24 ----D---- C:\WINDOWS\debug
2020-09-07 00:44:31 ----D---- C:\Program Files\Common Files\AV
2020-09-07 00:44:10 ----D---- C:\Program Files (x86)\Common Files
2020-09-07 00:40:19 ----D---- C:\ProgramData\AVAST Software
2020-09-07 00:40:18 ----D---- C:\Program Files\Common Files
2020-09-07 00:21:19 ----HD---- C:\ProgramData
2020-09-05 03:31:53 ----SD---- C:\ProgramData\Microsoft

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit); C:\WINDOWS\system32\DRIVERS\cm_km.sys [2020-06-29 248504]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2015-06-23 1455552]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2019-03-19 56632]
R0 klupd_klif_arkmon;klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [2020-09-07 256760]
R0 klupd_klif_klbg;klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [2020-09-07 117512]
R1 afunix;afunix; C:\WINDOWS\system32\drivers\afunix.sys [2020-08-12 40960]
R1 AsrAppCharger;AsrAppCharger; C:\WINDOWS\system32\DRIVERS\AsrAppCharger.sys [2011-11-07 17192]
R1 bam;@%SystemRoot%\system32\drivers\bam.sys,-100; C:\WINDOWS\system32\drivers\bam.sys [2019-03-19 70456]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\WINDOWS\system32\drivers\mbae64.sys [2020-09-22 153312]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2019-03-19 59392]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2019-03-19 8704]
R1 klbackupdisk;Kaspersky Lab klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [2020-06-29 104712]
R1 klbackupflt;Kaspersky Lab klbackupflt; C:\WINDOWS\system32\DRIVERS\klbackupflt.sys [2020-06-29 205048]
R1 kldisk;kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [2020-06-29 121088]
R1 klflt;Kaspersky Lab Kernel DLL; C:\WINDOWS\system32\DRIVERS\klflt.sys [2020-06-29 509184]
R1 klgse;Kaspersky Lab Security Extender Driver; C:\WINDOWS\system32\DRIVERS\klgse.sys [2020-06-26 643840]
R1 klhk;Kaspersky Lab service driver; C:\WINDOWS\system32\DRIVERS\klhk.sys [2020-06-26 1277704]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2020-06-29 984320]
R1 klim6;@oem51.inf,%KLIM6_Desc%;Kaspersky Anti-Virus NDIS 6 Filter; C:\WINDOWS\system32\DRIVERS\klim6.sys [2020-06-29 87808]
R1 klpd;Kaspersky Lab format recognizer driver; C:\WINDOWS\system32\DRIVERS\klpd.sys [2020-06-29 79104]
R1 klpnpflt;Kaspersky Lab klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [2020-06-29 90368]
R1 klwfp;klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [2020-06-29 133888]
R1 klwtp;KLwtp - WFP callout traffic inspector; C:\WINDOWS\system32\DRIVERS\klwtp.sys [2020-06-29 242944]
R1 kneps;kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [2020-06-29 279824]
R2 BlueStacksDrv;BlueStacks Hypervisor; \??\C:\Program Files\BlueStacks\BstkDrv_bgp.sys [2020-06-13 315976]
R2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2020-05-14 457216]
R2 MBAMChameleon;MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [2020-09-28 217592]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2019-03-19 53760]
R3 bindflt;@%systemroot%\system32\drivers\bindflt.sys,-100; C:\WINDOWS\system32\drivers\bindflt.sys [2020-02-14 117264]
R3 dtlitescsibus;@oem26.inf,%DisplayName%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2020-02-09 42256]
R3 dtliteusbbus;@oem37.inf,%DisplayName%;DAEMON Tools Lite Virtual USB Bus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [2020-02-09 59360]
R3 e1dexpress;@oem27.inf,%e1dExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver D; C:\WINDOWS\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_f6c146a8872514f7\e1d68x64.sys [2020-05-04 599928]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-09-17 4603136]
R3 klids;klids; \??\C:\ProgramData\Kaspersky Lab\AVP21.1\Bases\klids.sys [2020-09-15 240728]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [2020-06-29 106768]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2020-06-29 106752]
R3 kltap;@oem52.inf,%devicedescription%;Kaspersky Security Data Escort Adapter; C:\WINDOWS\System32\drivers\kltap.sys [2020-06-29 55592]
R3 klupd_klif_kimul;klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [2020-09-07 99152]
R3 klupd_klif_klark;klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [2020-09-07 309768]
R3 klupd_klif_mark;klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [2020-09-07 206888]
R3 MBAMFarflt;MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [2020-09-28 197280]
R3 MBAMProtection;MBAMProtection; \??\C:\WINDOWS\system32\DRIVERS\mbam.sys [2020-09-28 73880]
R3 MBAMSwissArmy;MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [2020-09-22 248968]
R3 MBAMWebProtection;MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [2020-09-28 131232]
R3 MEIx64;@oem12.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [2018-05-06 228992]
R3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvsw64e.sys [2020-06-18 57696]
R3 NVHDA;@oem54.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2020-09-15 222112]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_1b09d1209c6a0b92\nvlddmkm.sys [2020-09-26 32460528]
R3 NvModuleTracker;@oem30.inf,%ServiceName%;NvModuleTracker; C:\WINDOWS\System32\drivers\NvModuleTracker.sys [2020-03-04 50592]
R3 nvvad_WaveExtensible;@oem22.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2019-03-19 69840]
R3 nvvhci;@oem8.inf,%ServiceDesc%;NVVHCI Enumerator Service; C:\WINDOWS\System32\drivers\nvvhci.sys [2020-03-11 67456]
S0 bttflt;@virtdisk.inf,%service_desc%;Microsoft Hyper-V VHDPMEM BTT Filter; C:\WINDOWS\System32\drivers\bttflt.sys [2019-03-19 42808]
S0 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2019-03-19 319528]
S0 iaStorAVC;@iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller; C:\WINDOWS\System32\drivers\iaStorAVC.sys [2019-03-19 885048]
S0 ItSas35i;ItSas35i; C:\WINDOWS\System32\drivers\ItSas35i.sys [2019-03-19 148520]
S0 klelam;klelam; C:\WINDOWS\system32\DRIVERS\klelam.sys [2020-06-29 37496]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2019-03-19 124448]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2019-03-19 128528]
S0 MbamElam;MbamElam; C:\WINDOWS\system32\DRIVERS\MbamElam.sys [2020-09-22 19912]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2019-03-19 75280]
S0 megasas35i;megasas35i; C:\WINDOWS\System32\drivers\megasas35i.sys [2019-03-19 94736]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2019-03-19 58896]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2019-03-19 68624]
S0 Ramdisk;Windows RAM Disk Driver; C:\WINDOWS\system32\DRIVERS\ramdisk.sys [2019-03-19 41784]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2019-03-19 20992]
S3 Acx01000;@%SystemRoot%\system32\drivers\Acx01000.sys,-1000; C:\WINDOWS\system32\drivers\Acx01000.sys [2020-03-12 337920]
S3 amdgpio2;@amdgpio2.inf,%GPIO.SvcDesc%;AMD GPIO Client Driver; C:\WINDOWS\System32\drivers\amdgpio2.sys [2019-03-19 18432]
S3 amdi2c;@amdi2c.inf,%amdi2c.SVCDESC%;AMD I2C Controller Service; C:\WINDOWS\System32\drivers\amdi2c.sys [2019-03-19 37888]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2020-09-10 18432]
S3 BthA2dp;@microsoft_bluetooth_a2dp.inf,%BthA2dp.ServiceDescription%;Microsoft Bluetooth A2dp driver; C:\WINDOWS\System32\drivers\BthA2dp.sys [2020-03-12 231936]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2020-03-12 114688]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [2019-03-19 97280]
S3 BthMini;@bth.inf,%BTHMINI.SvcDesc%;Bluetooth Radio Driver; C:\WINDOWS\System32\drivers\BTHMINI.sys [2020-03-12 36864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\drivers\BTHport.sys [2020-03-12 1428992]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\drivers\BTHUSB.sys [2020-03-12 99328]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2019-03-19 43008]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2019-03-19 64312]
S3 DESerialPort;@oem48.inf,%SerialPort_SvcDesc%;DE USB Serial Port Service; C:\WINDOWS\system32\DRIVERS\DimensionSerialPort.sys [2016-11-12 24576]
S3 e1i65x64;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\System32\drivers\e1i65x64.sys [2019-03-19 553984]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_b9c53b80e63af230\genericusbfn.sys [2019-09-21 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2019-03-19 53560]
S3 hidspi;@hidspi_km.inf,%hidspi.SVCDESC%;Microsoft SPI HID Miniport Driver; C:\WINDOWS\System32\drivers\hidspi.sys [2019-10-04 64000]
S3 HPEWSFXBULK;HPEWSFXBULK; C:\WINDOWS\system32\drivers\hpfx64bulk.sys [2016-09-13 29248]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2020-09-10 84280]
S3 HwNClx0101;Microsoft Hardware Notifications Class Extension Driver; C:\WINDOWS\System32\Drivers\mshwnclx.sys [2019-03-19 28672]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2019-03-19 1866768]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2019-03-19 36352]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2019-03-19 91136]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2019-03-19 79360]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2019-03-19 93184]
S3 iaLPSS2i_GPIO2_CNL;@iaLPSS2i_GPIO2_CNL.inf,%iaLPSS2i_GPIO2_CNL.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [2019-03-19 112128]
S3 iaLPSS2i_GPIO2_GLK;@iaLPSS2i_GPIO2_GLK.inf,%iaLPSS2i_GPIO2_GLK.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [2019-03-19 96256]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2019-03-19 171520]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2019-03-19 175104]
S3 iaLPSS2i_I2C_CNL;@iaLPSS2i_I2C_CNL.inf,%iaLPSS2i_I2C_CNL.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [2019-03-19 180736]
S3 iaLPSS2i_I2C_GLK;@iaLPSS2i_I2C_GLK.inf,%iaLPSS2i_I2C_GLK.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [2019-03-19 177664]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2019-03-19 566800]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2019-03-19 46592]
S3 intelpmax;@intelpmax.inf,%SvcDesc%;Intel Power Limit Driver; C:\WINDOWS\System32\drivers\intelpmax.sys [2019-03-19 28672]
S3 IPT;IPT; C:\WINDOWS\System32\drivers\ipt.sys [2019-03-19 54584]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2019-03-19 535864]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2019-03-19 62264]
S3 MbbCx;MBB Network Adapter Class Extension; C:\WINDOWS\system32\drivers\MbbCx.sys [2019-11-15 359424]
S3 Microsoft_Bluetooth_AvrcpTransport;@microsoft_bluetooth_avrcptransport.inf,%Microsoft_Bluetooth_AvrcpTransport.ServiceDescription%;Microsoft Bluetooth Avrcp Transport Driver; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [2019-03-19 64512]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2019-03-19 1150480]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2019-03-19 153616]
S3 NDKPing;NDKPing Driver; C:\WINDOWS\system32\drivers\NDKPing.sys [2019-03-19 63488]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2019-03-19 187904]
S3 nvdimm;@nvdimm.inf,%nvdimm.SvcDesc%;Microsoft NVDIMM device driver; C:\WINDOWS\System32\drivers\nvdimm.sys [2019-03-19 158520]
S3 PktMon;Packet Monitor Driver; C:\WINDOWS\system32\drivers\PktMon.sys [2019-03-19 96056]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2019-03-19 127800]
S3 PNPMEM;@memory.inf,%PNPMEM.SvcDesc%;Microsoft Memory Module Driver; C:\WINDOWS\System32\drivers\pnpmem.sys [2019-03-19 17408]
S3 portcfg;portcfg; C:\WINDOWS\System32\drivers\portcfg.sys [2019-03-19 25600]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2019-12-14 986936]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2019-03-19 211456]
S3 rhproxy;@rhproxy.inf,%rhproxy.SVCDESC%;Resource Hub proxy driver; C:\WINDOWS\System32\drivers\rhproxy.sys [2019-03-19 113152]
S4 hvcrash;hvcrash; C:\WINDOWS\System32\drivers\hvcrash.sys [2019-03-19 32568]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVP21.1;Služba Kaspersky Anti-Virus 21.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avp.exe [2020-06-29 381968]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 CDPUserSvc_1b173d0e;Uživatelská služba platformy připojených zařízení_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 DispBrokerDesktopSvc;@%SystemRoot%\system32\dispbroker.desktop.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2015-06-23 18856]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [2020-06-23 575408]
R2 kpm_launch_service;Kaspersky Password Manager Service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [2020-09-22 351424]
R2 KSDE5.1;Služba Kaspersky Secure Connection 5.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe [2020-06-29 644312]
R2 MBAMService;Malwarebytes Service; C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe [2020-09-22 7185288]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2020-05-07 874472]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2020-09-24 884024]
R2 OneSyncSvc_1b173d0e;Hostitel synchronizace_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 BthAvctpSvc;@%SystemRoot%\system32\BthAvctpSvc.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 camsvc;@%SystemRoot%\system32\CapabilityAccessManager.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 cbdhsvc_1b173d0e;Uživatelská služba schránky_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2020-02-09 4506728]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 InstallService;@%SystemRoot%\system32\InstallService.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 PimIndexMaintenanceSvc_1b173d0e;Data kontaktů_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S2 edgeupdate;Služba Microsoft Edge Update (edgeupdate); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-06-10 224160]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-07 153752]
S2 HPSmartDeviceAgentBase;HPSmartDeviceAgentBase; c:\Program Files (x86)\HP\HPSmartDeviceAgentBase\Service\HPSmartDeviceAgentBase.exe [2017-10-25 68608]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 AarSvc;@%SystemRoot%\system32\AarSvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 AarSvc_1b173d0e;Agent Activation Runtime_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2020-09-09 335416]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 autotimesvc;@%SystemRoot%\System32\autotimesvc.dll,-6; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BcastDVRUserService;@%SystemRoot%\system32\BcastDVRUserService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BcastDVRUserService_1b173d0e;Uživatelská služba pro GameDVR a vysílání her_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BluetoothUserService;@%SystemRoot%\system32\Microsoft.Bluetooth.UserService.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BluetoothUserService_1b173d0e;Služba pro podporu uživatelů Bluetooth_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BTAGService;@%SystemRoot%\system32\BTAGService.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CaptureService;@%SystemRoot%\system32\CaptureService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CaptureService_1b173d0e;CaptureService_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 cbdhsvc;@%SystemRoot%\system32\cbdhsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 ConsentUxUserSvc;@%SystemRoot%\system32\ConsentUxClient.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 ConsentUxUserSvc_1b173d0e;ConsentUX_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CredentialEnrollmentManagerUserSvc;@%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [2020-07-16 381152]
S3 CredentialEnrollmentManagerUserSvc_1b173d0e;CredentialEnrollmentManagerUserSvc_1b173d0e; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [2020-07-16 381152]
S3 DeviceAssociationBrokerSvc;@%SystemRoot%\system32\deviceaccess.dll,-107; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DeviceAssociationBrokerSvc_1b173d0e;DeviceAssociationBroker_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicePickerUserSvc;@%SystemRoot%\system32\Windows.Devices.Picker.dll,-1006; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicePickerUserSvc_1b173d0e;DevicePicker_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicesFlowUserSvc_1b173d0e;Tok zařízení_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2020-09-10 97792]
S3 diagsvc;@%systemroot%\system32\DiagSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 DisplayEnhancementService;@%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1000; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 edgeupdatem;Služba Microsoft Edge Update (edgeupdatem); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-06-10 224160]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2019-09-21 43704]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files (x86)\Google\Chrome\Application\85.0.4183.121\elevation_service.exe [2020-09-19 1322992]
S3 GraphicsPerfSvc;@%SystemRoot%\system32\GraphicsPerfSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-07 153752]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 klvssbridge64_21.1;Kaspersky Volume Shadow Copy Service Bridge 21.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\vssbridge64.exe [2020-06-29 436168]
S3 LxpSvc;@%SystemRoot%\system32\LanguageOverlayServer.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MessagingService_1b173d0e;Služba zasílání zpráv_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MicrosoftEdgeElevationService;Microsoft Edge Elevation Service; C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.68\elevation_service.exe [2020-10-01 1537424]
S3 MixedRealityOpenXRSvc;@%SystemRoot%\system32\MixedRealityRuntime.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2020-09-15 245968]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-31 242864]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2019-09-15 2431816]
S3 perceptionsimulation;@%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101; C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe [2019-03-19 103424]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PrintWorkflowUserSvc;@%SystemRoot%\system32\PrintWorkflowService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PrintWorkflowUserSvc_1b173d0e;PrintWorkflow_1b173d0e; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PushToInstall;@%SystemRoot%\system32\pushtoinstall.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 Rockstar Service;Rockstar Game Library Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2019-11-28 474256]

-----------------EOF-----------------

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#2 Příspěvek od bojimso »

info.txt logfile of random's system information tool 1.10 2020-10-04 18:25:36

======MBR======

0x33C08ED0BC007C8EC08ED8BE007CBF0006B90002FCF3A450681C06CBFBB90400BDBE07807E00007C0B0F850E0183C510E2F1CD1888560055C6461105C6461000B441BBAA55CD135D720F81FB55AA7509F7C101007403FE46106660807E1000742666680000000066FF760868000068007C680100681000B4428A56008BF4CD139F83C4109EEB14B80102BB007C8A56008A76018A4E028A6E03CD136661731CFE4E11750C807E00800F848A00B280EB845532E48A5600CD135DEB9E813EFE7D55AA756EFF7600E88D007517FAB0D1E664E88300B0DFE660E87C00B0FFE664E87500FBB800BBCD1A6623C0753B6681FB54435041753281F90201722C666807BB00006668000200006668080000006653665366556668000000006668007C0000666168000007CD1A5A32F6EA007C0000CD18A0B707EB08A0B607EB03A0B50732E40500078BF0AC3C007409BB0700B40ECD10EBF2F4EBFD2BC9E464EB002402E0F82402C3496E76616C696420706172746974696F6E207461626C65004572726F72206C6F6164696E67206F7065726174696E672073797374656D004D697373696E67206F7065726174696E672073797374656D000000637B9A00000000000000000200EEFFFFFF01000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000055AA

======Uninstall list======

-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{E296D50E-EFEB-48F5-9CBE-5A335AE2D49F}" "1029" "0"
64 Bit HP CIO Components Installer-->MsiExec.exe /I{50229C72-539F-4E65-BEB5-F0491C5074B7}
Adobe Flash Player 32 PPAPI-->C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_433_pepper.exe -maintain pepperplugin
APP Shop v1.0.21-->"C:\Program Files (x86)\ASRock Utility\APP Shop\unins000.exe"
ASRock App Charger v1.0.6-->"C:\Program Files\ASRock Utility\AsrAppCharger\unins000.exe"
Assassin's Creed Odyssey-->"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe" uplay://uninstall/5059
Assassin's Creed Unity-->"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe" uplay://uninstall/720
Audacity 2.2.1-->"C:\Program Files (x86)\Audacity\unins000.exe"
Balíček ovladače systému Windows - Dimension Engineering USB Serial Converter (11/11/2016 1.0.3.21)-->C:\PROGRA~1\DIFX\9F8F65CFB72E33A8\dpinst64.exe /u C:\WINDOWS\System32\DriverStore\FileRepository\oemsetup.inf_amd64_3440eb0b010c4e60\oemsetup.inf
Batman - Arkham Origins-->"D:\Hry\Batman - Arkham Origins\unins000.exe"
Batman Arkham Knight v.1.0.4.5-->"D:\Hry\Batman Arkham Knight\unins000.exe"
Battle.net-->"C:\ProgramData\Battle.net\Agent\Blizzard Uninstaller.exe" --lang=enUS --uid=battle.net --displayname="Battle.net"
BlueStacks App Player-->C:\Program Files\BlueStacks\BlueStacksUninstaller.exe -tmp
BS.Player PRO-->"C:\Program Files (x86)\Webteh\BSplayerPro\uninstall.exe"
CCleaner-->"C:\Program Files\CCleaner\uninst.exe"
Counter-Strike: Global Offensive-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/730
CPUID CPU-Z 1.92-->"C:\Program Files\CPUID\CPU-Z\unins000.exe"
Curse-->MsiExec.exe /X{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}
DAEMON Tools Lite-->C:\Program Files\DAEMON Tools Lite\uninst.exe
Definition Update for Microsoft Office 2016 (KB3115407) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{3DBF9257-2612-4385-BCE3-E9D4C41CC8CB}" "1029" "0"
Defraggler-->"C:\Program Files\Defraggler\uninst.exe"
Deus Ex - Human Revolution version 1.0-->"D:\Hry\Deus Ex - Human Revolution\unins000.exe"
Diablo III-->"C:\ProgramData\Battle.net\Agent\Blizzard Uninstaller.exe" --lang=enUS --uid=diablo3_enus --displayname="Diablo III"
Epic Games Launcher Prerequisites (x64)-->MsiExec.exe /X{66C5838F-B854-4A55-89E6-A6138747A4DF}
Epic Games Launcher-->MsiExec.exe /X{C69A2919-0662-4390-9418-67C931B44C18}
Fallout 4 v.1.1.30-->"D:\Hry\Fallout 4\unins000.exe"
foobar2000 v1.3.12-->"C:\Program Files (x86)\foobar2000\uninstall.exe" _?=C:\Program Files (x86)\foobar2000
Google Chrome-->"C:\Program Files (x86)\Google\Chrome\Application\85.0.4183.121\Installer\setup.exe" --uninstall --system-level --verbose-logging
Google Update Helper-->MsiExec.exe /I{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}
Google Update Helper-->MsiExec.exe /I{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}
gpedt.msc 1.0-->"C:\WINDOWS\unins000.exe"
Grand Theft Auto V-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/271590
GTA San Andreas-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files (x86)\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x9 -removeonly
Gyazo 3.4.1.0-->"C:\Program Files (x86)\Gyazo\unins000.exe"
Hearthstone-->"C:\ProgramData\Battle.net\Agent\Blizzard Uninstaller.exe" --lang=enUS --uid=hs_beta --displayname="Hearthstone"
HPSmartDeviceAgentBase-->MsiExec.exe /I{F7270182-8AD0-420F-92A3-52438ED810A9}
Intel(R) Chipset Device Software-->MsiExec.exe /I{55398EAC-F58E-4F19-B553-BDF8B9EFD839}
Intel(R) Management Engine Components-->"C:\ProgramData\Intel\Package Cache\{1CEAC85D-2590-4760-800F-8DE5E91F3700}\Setup.exe" -uninstall
Intel(R) Management Engine Components-->MsiExec.exe /I{A4512F5C-D956-4AB0-8A07-EA7D9F8ABB2A}
Intel(R) ME UninstallLegacy-->MsiExec.exe /I{555B1C57-E71B-4775-BC1D-627EEF693F0D}
Intel(R) Network Connections 25.2.0.0-->MsiExec.exe /i{FBDEEBC8-592A-415F-AD68-086A8EEFA433} ARPREMOVE=1
Intel(R) Network Connections 25.2.0.0-->MsiExec.exe /i{FBDEEBC8-592A-415F-AD68-086A8EEFA433} ARPREMOVE=1
Intel(R) Rapid Storage Technology-->"C:\ProgramData\Intel\Package Cache\{409CB30E-E457-4008-9B1A-ED1B9EA21140}\Setup.exe" -uninstall
Intel(R) Rapid Storage Technology-->MsiExec.exe /I{205AE40D-8AD7-4F29-A430-DD2168DA562D}
Intel® Chipset Device Software-->"C:\ProgramData\Package Cache\{c7f54569-0018-439c-809a-48046a4d4ebc}\SetupChipset.exe" /uninstall
JDownloader 2-->"C:\Users\David\AppData\Local\JDownloader 2.0\Uninstall JDownloader.exe"
Kaspersky Password Manager-->MsiExec.exe /I{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611} REMOVE=ALL REINSTALLMODE=omus
Kaspersky Password Manager-->MsiExec.exe /X{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}
Kaspersky Secure Connection-->MsiExec.exe /I{8E3A90F0-23D4-4761-AEBF-409CBBA48C80}
Kaspersky Secure Connection-->MsiExec.exe /I{8E3A90F0-23D4-4761-AEBF-409CBBA48C80} REMOVE=ALL
Kaspersky Total Security-->MsiExec.exe /I{0124CD8C-8A9A-4A95-BF8C-F084040A93CE}
Kaspersky Total Security-->MsiExec.exe /I{0124CD8C-8A9A-4A95-BF8C-F084040A93CE} REMOVE=ALL
LAME v3.99.3 (for Windows)-->"C:\Program Files (x86)\Lame For Audacity\unins000.exe"
Launcher Prerequisites (x64)-->"C:\ProgramData\Package Cache\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}\LauncherPrereqSetup_x64.exe" /uninstall
League of Legends-->msiexec.exe /x {657DFCCF-B080-44B1-9AEA-61676011A1AE}
League of Legends-->MsiExec.exe /X{657DFCCF-B080-44B1-9AEA-61676011A1AE}
Logitech-kameraindstillinger-->C:\Program Files (x86)\Common Files\LogiShrd\LogiUCDpp\uninstall.exe
Malwarebytes version 4.2.1.89-->"C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbuns.exe" /Uninstall
Microsoft Access MUI (Czech) 2016-->MsiExec.exe /X{90160000-0015-0405-1000-0000000FF1CE}
Microsoft DCF MUI (Czech) 2016-->MsiExec.exe /X{90160000-0090-0405-1000-0000000FF1CE}
Microsoft Edge-->"C:\Program Files (x86)\Microsoft\Edge\Application\85.0.564.68\Installer\setup.exe" --uninstall --system-level --verbose-logging
Microsoft Excel MUI (Czech) 2016-->MsiExec.exe /X{90160000-0016-0405-1000-0000000FF1CE}
Microsoft Groove MUI (Czech) 2016-->MsiExec.exe /X{90160000-00BA-0405-1000-0000000FF1CE}
Microsoft HEVC Media Extension Installation for Microsoft.HEVCVideoExtension_1.0.2512.0_x64__8wekyb3d8bbwe (x64)-->MsiExec.exe /I{B0169E83-757B-EF66-E2F0-391944D785BC}
Microsoft InfoPath MUI (Czech) 2016-->MsiExec.exe /X{90160000-0044-0405-1000-0000000FF1CE}
Microsoft Office 32-bit Components 2016-->MsiExec.exe /X{90160000-00C1-0000-1000-0000000FF1CE}
Microsoft Office Korrekturhilfen 2016 – Deutsch-->MsiExec.exe /X{90160000-001F-0407-1000-0000000FF1CE}
Microsoft Office OSM MUI (Czech) 2016-->MsiExec.exe /X{90160000-00E1-0405-1000-0000000FF1CE}
Microsoft Office OSM UX MUI (Czech) 2016-->MsiExec.exe /X{90160000-00E2-0405-1000-0000000FF1CE}
Microsoft Office Professional Plus 2016-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
Microsoft Office Professional Plus 2016-->MsiExec.exe /X{90160000-0011-0000-1000-0000000FF1CE}
Microsoft Office Proofing (Czech) 2016-->MsiExec.exe /X{90160000-002C-0405-1000-0000000FF1CE}
Microsoft Office Proofing Tools 2016 - English-->MsiExec.exe /X{90160000-001F-0409-1000-0000000FF1CE}
Microsoft Office Shared 32-bit MUI (Czech) 2016-->MsiExec.exe /X{90160000-00C1-0405-1000-0000000FF1CE}
Microsoft Office Shared MUI (Czech) 2016-->MsiExec.exe /X{90160000-006E-0405-1000-0000000FF1CE}
Microsoft OneNote MUI (Czech) 2016-->MsiExec.exe /X{90160000-00A1-0405-1000-0000000FF1CE}
Microsoft Outlook MUI (Czech) 2016-->MsiExec.exe /X{90160000-001A-0405-1000-0000000FF1CE}
Microsoft PowerPoint MUI (Czech) 2016-->MsiExec.exe /X{90160000-0018-0405-1000-0000000FF1CE}
Microsoft Publisher MUI (Czech) 2016-->MsiExec.exe /X{90160000-0019-0405-1000-0000000FF1CE}
Microsoft Skype for Business MUI (Czech) 2016-->MsiExec.exe /X{90160000-012B-0405-1000-0000000FF1CE}
Microsoft Update Health Tools-->MsiExec.exe /X{97238E8A-4919-4A1E-965A-C6C36938F4CE}
Microsoft Visual C++ 2005 Redistributable (x64)-->MsiExec.exe /X{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{837b34e3-7c30-493c-8f6a-2b0f04e2912c}
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161-->MsiExec.exe /X{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161-->MsiExec.exe /X{9BE518E6-ECC6-35A9-88E4-87755C07200F}
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219-->MsiExec.exe /X{1D8E6291-B0D5-35EC-8441-6616F567A0F7}
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219-->MsiExec.exe /X{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030-->"C:\ProgramData\Package Cache\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030-->"C:\ProgramData\Package Cache\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030-->MsiExec.exe /X{37B8F9C7-03FB-3253-8781-2517C99D7C00}
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030-->MsiExec.exe /X{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030-->MsiExec.exe /X{B175520C-86A2-35A7-8619-86DC379688B9}
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030-->MsiExec.exe /X{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501-->"C:\ProgramData\Package Cache\{050d4fc8-5d48-4b8f-8972-47c82c46020f}\vcredist_x64.exe" /uninstall
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501-->"C:\ProgramData\Package Cache\{f65db027-aff3-4070-886a-0d87064aabb1}\vcredist_x86.exe" /uninstall
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005-->MsiExec.exe /X{929FBD26-9020-399B-9A7A-751D61F0B942}
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005-->MsiExec.exe /X{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005-->MsiExec.exe /X{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005-->MsiExec.exe /X{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821-->"C:\ProgramData\Package Cache\{6361b579-2795-4886-b2a8-53d5239b6452}\VC_redist.x64.exe" /uninstall
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821-->"C:\ProgramData\Package Cache\{5bfc1380-fd35-4b85-9715-7351535d077e}\VC_redist.x86.exe" /uninstall
Microsoft Visual C++ 2019 X64 Additional Runtime - 14.22.27821-->MsiExec.exe /I{6E2C7A8E-B17A-4637-9CE9-F0B1157CF378}
Microsoft Visual C++ 2019 X64 Minimum Runtime - 14.22.27821-->MsiExec.exe /I{0093C20C-273D-4397-B623-515CB8616CB9}
Microsoft Visual C++ 2019 X86 Additional Runtime - 14.22.27821-->MsiExec.exe /I{3BDE80F7-7EC9-448E-8160-4ADA0CDA8879}
Microsoft Visual C++ 2019 X86 Minimum Runtime - 14.22.27821-->MsiExec.exe /I{1E6FC929-567E-4D22-9206-C5B83F0A21B9}
Microsoft Word MUI (Czech) 2016-->MsiExec.exe /X{90160000-001B-0405-1000-0000000FF1CE}
Mozilla Firefox 80.0.1 (x64 cs)-->"C:\Program Files (x86)\Mozilla Firefox\uninstall\helper.exe"
Mozilla Maintenance Service-->"C:\Program Files (x86)\Mozilla Maintenance Service\uninstall.exe"
MSI Afterburner 4.6.1-->"C:\Program Files (x86)\MSI Afterburner\uninstall.exe"
Nástroje kontroly pravopisu pro Microsoft Office 2016 – čeština-->MsiExec.exe /X{90160000-001F-0405-1000-0000000FF1CE}
Nástroje korektúry balíka Microsoft Office 2016 - slovenčina-->MsiExec.exe /X{90160000-001F-041B-1000-0000000FF1CE}
NVIDIA GeForce Experience 3.20.4.14-->"C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.GFExperience
NVIDIA Ovladač HD audia 1.3.38.35-->"C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage HDAudio.Driver
NVIDIA Ovladače grafiky 456.55-->"C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.Driver
NVIDIA Systémový software PhysX 9.19.0218-->"C:\WINDOWS\SysWOW64\RunDll32.EXE" "C:\Program Files\NVIDIA Corporation\Installer2\InstallerCore\NVI2.DLL",UninstallPackage Display.PhysX
OBS Studio-->C:\Program Files (x86)\obs-studio\uninstall.exe
Open Broadcaster Software-->C:\Program Files (x86)\OBS\uninstall.exe
Ori and the Blind Forest Definitive Edition-->"D:\Hry\Ori and the Blind Forest Definitive Edition\unins000.exe"
Overwatch-->"C:\ProgramData\Battle.net\Agent\Blizzard Uninstaller.exe" --lang=enUS --uid=prometheus --displayname="Overwatch"
Overwolf-->"C:\Program Files (x86)\Overwolf\\OWUninstaller.exe" /S
Personify ChromaCam (remove only)-->C:\Program Files (x86)\Personify\ChromaCam\Uninstall Personify ChromaCam 1.1.6.7.exe
PixelHealer-->"C:\Program Files\Aurelitec\PixelHealer\uninstall.exe"
Posel smrti 1.2-->D:\Hry\PoselSmrti\unins000.exe
Print Conductor 5.4-->"C:\Program Files (x86)\Print Conductor\unins000.exe"
qBittorrent 4.2.5-->"C:\Program Files\qBittorrent\uninst.exe"
Realtek High Definition Audio Driver-->C:\Program Files\Realtek\Audio\HDA\RtlUpd64.exe -r -m -nrg2709
Resident Evil 2-->"D:\Hry\Resident Evil 2\unins000.exe"
Resident Evil 7 Biohazard-->"D:\Hry\Resident Evil 7 Biohazard\unins000.exe"
RivaTuner Statistics Server 7.2.3-->"C:\Program Files (x86)\RivaTuner Statistics Server\uninstall.exe"
Rockstar Games Launcher-->"C:\Program Files\Rockstar Games\Launcher\uninstall.exe"
Rockstar Games Social Club-->C:\Program Files\Rockstar Games\Social Club\uninstallRGSCRedistributable.exe
Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{5A84393A-E440-48A1-BB99-AD1244AC0C35}" "1029" "0"
Security Update for Microsoft Office 2016 (KB3085538) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{5A84393A-E440-48A1-BB99-AD1244AC0C35}" "1029" "0"
Security Update for Microsoft Office 2016 (KB3085635) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-006E-0405-1000-0000000FF1CE}" "{0C1232DC-F66D-4C54-B5FB-FADF7C671AF0}" "1029" "0"
Security Update for Microsoft Office 2016 (KB3115415) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{9BCB2776-3683-47A4-B0DF-586DBA0E3507}" "1029" "0"
Security Update for Microsoft Office 2016 (KB3115415) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-006E-0405-1000-0000000FF1CE}" "{9BCB2776-3683-47A4-B0DF-586DBA0E3507}" "1029" "0"
Security Update for Microsoft Office 2016 (KB3115415) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{9BCB2776-3683-47A4-B0DF-586DBA0E3507}" "1029" "0"
Security Update for Microsoft Office 2016 (KB3115415) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0405-1000-0000000FF1CE}" "{9BCB2776-3683-47A4-B0DF-586DBA0E3507}" "1029" "0"
Security Update for Microsoft OneNote 2016 (KB3115419) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{EBAFD092-D4C1-4739-8C25-F529AE42B7CF}" "1029" "0"
Security Update for Microsoft OneNote 2016 (KB3115419) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00A1-0405-1000-0000000FF1CE}" "{EBAFD092-D4C1-4739-8C25-F529AE42B7CF}" "1029" "0"
Security Update for Microsoft OneNote 2016 (KB3115419) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{EBAFD092-D4C1-4739-8C25-F529AE42B7CF}" "1029" "0"
Security Update for Microsoft Outlook 2016 (KB3115440) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{9C4F10E7-917F-453C-84C3-38A40E522473}" "1029" "0"
Security Update for Microsoft Outlook 2016 (KB3115440) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001A-0405-1000-0000000FF1CE}" "{9C4F10E7-917F-453C-84C3-38A40E522473}" "1029" "0"
Security Update for Microsoft Publisher 2016 (KB2920680) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{1409AE9B-C1F4-497A-81D9-AFF2C1A7B106}" "1029" "0"
Security Update for Microsoft Publisher 2016 (KB2920680) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0019-0405-1000-0000000FF1CE}" "{1409AE9B-C1F4-497A-81D9-AFF2C1A7B106}" "1029" "0"
Security Update for Microsoft Publisher 2016 (KB2920680) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{1409AE9B-C1F4-497A-81D9-AFF2C1A7B106}" "1029" "0"
Security Update for Microsoft Word 2016 (KB3115439) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{876D53BB-54F4-4C06-A9D7-0238722F77E9}" "1029" "0"
Security Update for Microsoft Word 2016 (KB3115439) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001A-0405-1000-0000000FF1CE}" "{876D53BB-54F4-4C06-A9D7-0238722F77E9}" "1029" "0"
Security Update for Microsoft Word 2016 (KB3115439) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001B-0405-1000-0000000FF1CE}" "{876D53BB-54F4-4C06-A9D7-0238722F77E9}" "1029" "0"
Security Update for Microsoft Word 2016 (KB3115439) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{876D53BB-54F4-4C06-A9D7-0238722F77E9}" "1029" "0"
Security Update for Microsoft Word 2016 (KB3115439) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-012B-0405-1000-0000000FF1CE}" "{876D53BB-54F4-4C06-A9D7-0238722F77E9}" "1029" "0"
Serious Sam HD The First Encounter-->"D:\Hry\Serious Sam HD The First Encounter\unins000.exe"
Someday Youll Return-->"D:\Hry\Someday Youll Return\unins000.exe"
Speccy-->"C:\Program Files\Speccy\uninst.exe"
SpeedFan (remove only)-->"C:\Program Files (x86)\SpeedFan\uninstall.exe"
Steam-->C:\Program Files (x86)\Steam\uninstall.exe
Streamlabs OBS-->"C:\Program Files\Streamlabs OBS\Uninstall Streamlabs OBS.exe" /allusers
Stronghold Crusader 2-->"D:\Hry\Stronghold Crusader 2\unins000.exe"
Stronghold Crusader HD Enhanced Edition-->"D:\Hry\Stronghold Crusader HD Enhanced Edition\unins000.exe"
Stronghold HD-->"D:\Hry\Stronghold HD\unins000.exe"
Super Seducer-->D:\Hry\Super Seducer\uninstall.exe
SUPERHOT MIND CONTROL DELETE-->"D:\Hry\SUPERHOT MIND CONTROL DELETE\unins000.exe"
SUPERHOT-->"D:\Hry\SUPERHOT\unins000.exe"
Syberia-->RunDll32 C:\PROGRA~2\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "D:\Hry\Syberia\Uninstall\Setup.exe" -l0x5
TeamSpeak 3 Client-->"C:\Program Files\TeamSpeak 3 Client\uninstall.exe"
The Walking Dead A New Frontier Episode 1-->"D:\Hry\The Walking Dead A New Frontier Episode 1\unins000.exe"
The Witcher: Enhanced Edition-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/20900
TradeSkillMaster Application version 1.0-->"C:\Program Files (x86)\TradeSkillMaster Application\unins000.exe"
Unturned-->"C:\Program Files (x86)\Steam\steam.exe" steam://uninstall/304930
Update for Microsoft Access 2016 (KB3115142) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{DD3CCB1F-8CB6-4EFD-8E11-36CE6C857DC9}" "1029" "0"
Update for Microsoft Access 2016 (KB3115142) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{DD3CCB1F-8CB6-4EFD-8E11-36CE6C857DC9}" "1029" "0"
Update for Microsoft Excel 2016 (KB3115438) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{1DD11C24-C2AD-495F-B816-3C29A702EC14}" "1029" "0"
Update for Microsoft Excel 2016 (KB3115438) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0016-0405-1000-0000000FF1CE}" "{1DD11C24-C2AD-495F-B816-3C29A702EC14}" "1029" "0"
Update for Microsoft Excel 2016 (KB3115438) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0018-0405-1000-0000000FF1CE}" "{1DD11C24-C2AD-495F-B816-3C29A702EC14}" "1029" "0"
Update for Microsoft Excel 2016 (KB3115438) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001B-0405-1000-0000000FF1CE}" "{1DD11C24-C2AD-495F-B816-3C29A702EC14}" "1029" "0"
Update for Microsoft Excel 2016 (KB3115438) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{1DD11C24-C2AD-495F-B816-3C29A702EC14}" "1029" "0"
Update for Microsoft Office 2016 (KB2910954) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{89B85BAE-5618-49A4-9C18-153202BDFC73}" "1029" "0"
Update for Microsoft Office 2016 (KB2910979) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{F556D361-9A36-47BC-94D8-9BC2C36EE333}" "1029" "0"
Update for Microsoft Office 2016 (KB2920678) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{D6AE0D54-13A7-4B0D-A862-8AEF7D4796A6}" "1029" "0"
Update for Microsoft Office 2016 (KB2920678) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{D6AE0D54-13A7-4B0D-A862-8AEF7D4796A6}" "1029" "0"
Update for Microsoft Office 2016 (KB2920684) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{4D4432EE-ECE1-42CA-8B93-0916170C8252}" "1029" "0"
Update for Microsoft Office 2016 (KB2920712) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{A73D1FF5-0819-44C7-9294-FBDD4BA2F43B}" "1029" "0"
Update for Microsoft Office 2016 (KB2920718) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001F-0405-1000-0000000FF1CE}" "{8022705C-355F-4886-A2FA-5C7C54D21B09}" "1029" "0"
Update for Microsoft Office 2016 (KB2920718) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001F-0407-1000-0000000FF1CE}" "{8022705C-355F-4886-A2FA-5C7C54D21B09}" "1029" "0"
Update for Microsoft Office 2016 (KB2920718) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001F-0409-1000-0000000FF1CE}" "{8022705C-355F-4886-A2FA-5C7C54D21B09}" "1029" "0"
Update for Microsoft Office 2016 (KB2920718) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-001F-041B-1000-0000000FF1CE}" "{8022705C-355F-4886-A2FA-5C7C54D21B09}" "1029" "0"
Update for Microsoft Office 2016 (KB2920720) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{8683D594-A08C-451F-82C3-51D6FB730A6C}" "1029" "0"
Update for Microsoft Office 2016 (KB2920724) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{AA7A282E-E962-4C45-9A74-16C49FD88FF1}" "1029" "0"
Update for Microsoft Office 2016 (KB3114369) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{B17EC43D-59DC-496B-8E86-BC46D995F0ED}" "1029" "0"
Update for Microsoft Office 2016 (KB3114708) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{E440F668-2E16-4412-A9C8-E6603EC2A1EE}" "1029" "0"
Update for Microsoft Office 2016 (KB3114709) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{B0D12818-1641-422F-9EB4-AC05243A4DD8}" "1029" "0"
Update for Microsoft Office 2016 (KB3114903) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{92281B72-2A8C-40A4-BD15-58CCDF7DEDB1}" "1029" "0"
Update for Microsoft Office 2016 (KB3115081) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{78D7B4DE-619F-4312-9707-DF354A48D110}" "1029" "0"
Update for Microsoft Office 2016 (KB3115099) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{D7B201EB-BBD8-451C-B9F0-B71EA436953E}" "1029" "0"
Update for Microsoft Office 2016 (KB3115100) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{5EA702B7-1613-4DCB-85E6-A9BD9327CE00}" "1029" "0"
Update for Microsoft Office 2016 (KB3115141) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{017D5158-921B-4578-A067-51B1824BC813}" "1029" "0"
Update for Microsoft Office 2016 (KB3115183) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{7DB2548E-8D37-4B11-825F-41687A9BF8D8}" "1029" "0"
Update for Microsoft Office 2016 (KB3115183) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{7DB2548E-8D37-4B11-825F-41687A9BF8D8}" "1029" "0"
Update for Microsoft Office 2016 (KB3115189) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{B17883DD-F38B-4015-BA9E-62C5A08EF21C}" "1029" "0"
Update for Microsoft Office 2016 (KB3115270) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{0BBBB2AE-33C8-43AF-9404-AF93405B54E7}" "1029" "0"
Update for Microsoft Office 2016 (KB3115270) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0016-0405-1000-0000000FF1CE}" "{0BBBB2AE-33C8-43AF-9404-AF93405B54E7}" "1029" "0"
Update for Microsoft Office 2016 (KB3115277) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{99595D1D-0AAF-4442-8548-9DCE466BE30B}" "1029" "0"
Update for Microsoft Office 2016 (KB3115277) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{99595D1D-0AAF-4442-8548-9DCE466BE30B}" "1029" "0"
Update for Microsoft Office 2016 (KB3115282) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{122FCF65-71FF-4EB8-B6CB-B655D184A094}" "1029" "0"
Update for Microsoft Office 2016 (KB3115282) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{122FCF65-71FF-4EB8-B6CB-B655D184A094}" "1029" "0"
Update for Microsoft Office 2016 (KB3115406) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{C1815A1B-6EA5-42E5-B2D3-2FF059D7EEAD}" "1029" "0"
Update for Microsoft Office 2016 (KB3115410) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{7592A91E-385A-41F6-9834-CC07836F13E8}" "1029" "0"
Update for Microsoft Office 2016 (KB3115410) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-006E-0405-1000-0000000FF1CE}" "{7592A91E-385A-41F6-9834-CC07836F13E8}" "1029" "0"
Update for Microsoft Office 2016 (KB3115410) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{7592A91E-385A-41F6-9834-CC07836F13E8}" "1029" "0"
Update for Microsoft Office 2016 (KB3115411) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{A4D3F38C-2511-44B3-BB16-14EC0047F208}" "1029" "0"
Update for Microsoft Office 2016 (KB3115411) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{A4D3F38C-2511-44B3-BB16-14EC0047F208}" "1029" "0"
Update for Microsoft Office 2016 (KB3115413) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{9517E83E-72A7-4CE2-840B-02963390076A}" "1029" "0"
Update for Microsoft Office 2016 (KB3115413) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{9517E83E-72A7-4CE2-840B-02963390076A}" "1029" "0"
Update for Microsoft Office 2016 (KB3115416) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{B42996AB-548D-47EF-AAAE-A00027F480E8}" "1029" "0"
Update for Microsoft Office 2016 (KB3115417) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{06BD37C1-CD5F-4954-8015-240FFD6F7B41}" "1029" "0"
Update for Microsoft Office 2016 (KB3115421) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{6C450AEC-437D-4393-8598-D8E3E930B11B}" "1029" "0"
Update for Microsoft OneDrive for Business (KB3115423) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{26BAFEBC-30B1-4A01-A087-D532502C835B}" "1029" "0"
Update for Microsoft OneDrive for Business (KB3115423) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00BA-0405-1000-0000000FF1CE}" "{26BAFEBC-30B1-4A01-A087-D532502C835B}" "1029" "0"
Update for Microsoft OneDrive for Business (KB3115423) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{26BAFEBC-30B1-4A01-A087-D532502C835B}" "1029" "0"
Update for Microsoft OneDrive for Business (KB3115423) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0405-1000-0000000FF1CE}" "{26BAFEBC-30B1-4A01-A087-D532502C835B}" "1029" "0"
Update for Microsoft PowerPoint 2016 (KB3115409) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{6F326E0E-7D40-4AC5-80F1-12AFB4770E56}" "1029" "0"
Update for Microsoft PowerPoint 2016 (KB3115409) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0018-0405-1000-0000000FF1CE}" "{6F326E0E-7D40-4AC5-80F1-12AFB4770E56}" "1029" "0"
Update for Microsoft PowerPoint 2016 (KB3115409) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{6F326E0E-7D40-4AC5-80F1-12AFB4770E56}" "1029" "0"
Update for Microsoft Project 2016 (KB3115424) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{41574851-1A3F-4545-96E9-9D6F68224E32}" "1029" "0"
Update for Microsoft Project 2016 (KB3115424) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{41574851-1A3F-4545-96E9-9D6F68224E32}" "1029" "0"
Update for Microsoft Visio 2016 (KB3115405) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{6F4725F7-1D67-478E-8FD8-757E40C06AE6}" "1029" "0"
Update for Microsoft Visio 2016 (KB3115405) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{6F4725F7-1D67-478E-8FD8-757E40C06AE6}" "1029" "0"
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-0011-0000-1000-0000000FF1CE}" "{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}" "1029" "0"
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-00C1-0000-1000-0000000FF1CE}" "{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}" "1029" "0"
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE16\Oarpmany.exe" /removereleaseinpatch "{90160000-012B-0405-1000-0000000FF1CE}" "{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}" "1029" "0"
Update for Windows 10 for x64-based Systems (KB4023057)-->MsiExec.exe /X{32DC821E-4A7D-4878-BEE8-337FA153D7F2}
Uplay-->C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uninstall.exe
VLC media player-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Voicemeeter, The Virtual Mixing Console-->C:\Program Files (x86)\VB\Voicemeeter\VoicemeeterProSetup.exe
VooPoo version 1.5.1.30-->"C:\Program Files (x86)\Gene\VooPoo\unins000.exe"
VueScan x64-->"C:\Program Files\VueScan\vuescan.exe" /remove
Warcraft III-->"C:\ProgramData\Battle.net\Agent\Blizzard Uninstaller.exe" --lang=enUS --uid=w3 --displayname="Warcraft III"
Warframe-->MsiExec.exe /X{72BD42A9-6701-42EB-B77A-2AFC0C499F5E}
Watch_Dogs-->"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe" uplay://uninstall/274
WinRAR 5.91 (64-bit)-->C:\Program Files\WinRAR\uninstall.exe
World of Warcraft Classic-->"C:\ProgramData\Battle.net\Agent\Blizzard Uninstaller.exe" --lang=enUS --uid=wow_classic --displayname="World of Warcraft Classic"
World of Warcraft-->"C:\ProgramData\Battle.net\Agent\Blizzard Uninstaller.exe" --lang=enUS --uid=wow_enus --displayname="World of Warcraft"

======System event log======

Computer Name: DESKTOP-7D2FQ0G
Event Code: 7002
Message: Oznámení o odhlášení uživatele pro program Zlepšování softwaru a služeb na základě zkušeností uživatelů
Record Number: 52137
Source Name: Microsoft-Windows-Winlogon
Time Written: 20200318062311.932037-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-7D2FQ0G
Event Code: 16
Message: Historie přístupů do podregistru \??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-3482348820-1896476200-1895645591-1002-03182020070455512-UsrClass.dat byla vymazána aktualizací 0 klíčů a vytvořením 0 upravených stránek.
Record Number: 52136
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20200318060455.863270-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-7D2FQ0G
Event Code: 16
Message: Historie přístupů do podregistru \??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-21-3482348820-1896476200-1895645591-1002-03182020070455512-ntuser.dat byla vymazána aktualizací 0 klíčů a vytvořením 0 upravených stránek.
Record Number: 52135
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20200318060455.808407-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-7D2FQ0G
Event Code: 16
Message: Historie přístupů do podregistru \??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-20-03182020070455476-ntuser.dat byla vymazána aktualizací 0 klíčů a vytvořením 0 upravených stránek.
Record Number: 52134
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20200318060455.487351-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-7D2FQ0G
Event Code: 16
Message: Historie přístupů do podregistru \??\C:\PROGRAMDATA\MALWAREBYTES\MBAMSERVICE\S-1-5-19-03182020070455444-ntuser.dat byla vymazána aktualizací 0 klíčů a vytvořením 0 upravených stránek.
Record Number: 52133
Source Name: Microsoft-Windows-Kernel-General
Time Written: 20200318060455.455014-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

=====Application event log=====

Computer Name: DESKTOP-7D2FQ0G
Event Code: 256
Message: Služba Šifrování neinicializovala databázi katalogu. Chyba: -2147418113 (0x8000ffff) : Katastrofální selhání
.
Record Number: 5
Source Name: Microsoft-Windows-CAPI2
Time Written: 20190921113231.301343-000
Event Type: Chyba
User:

Computer Name: DESKTOP-7D2FQ0G
Event Code: 1531
Message: Služba Profil uživatele byla úspěšně spuštěna.


Record Number: 4
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20190921113218.819178-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-7D2FQ0G
Event Code: 5617
Message: Subsystémy služby WMI (Windows Management Instrumentation) byly úspěšně inicializovány.
Record Number: 3
Source Name: Microsoft-Windows-WMI
Time Written: 20190921113203.185686-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-7D2FQ0G
Event Code: 5615
Message: Služba WMI (Windows Management Instrumentation) byla úspěšně spuštěna.
Record Number: 2
Source Name: Microsoft-Windows-WMI
Time Written: 20190921113202.646263-000
Event Type: Informace
User: NT AUTHORITY\SYSTEM

Computer Name: DESKTOP-7D2FQ0G
Event Code: 4625
Message: Subsystém EventSystem zabraňuje vytváření duplicitních záznamů v protokolu událostí po dobu 86400 sekund. Tuto dobu lze změnit pomocí hodnoty REG_DWORD s názvem SuppressDuplicateDuration v následujícím klíči registru: HKLM\Software\Microsoft\EventSystem\EventLog.
Record Number: 1
Source Name: Microsoft-Windows-EventSystem
Time Written: 20190921113218.816208-000
Event Type: Informace
User:

=====Security event log=====

Computer Name: DESKTOP-7D2FQ0G
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: DESKTOP-7D2FQ0G$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7

Informace o přihlášení:
Typ přihlášení: 5
Omezený režim správce: -
Virtuální účet: Ne
Token se zvýšeným oprávněním: Ano

Úroveň zosobnění: Zosobnění

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3E7
ID propojeného přihlášení: 0x0
Název účtu v síti: -
Doména účtu v síti: -
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x340
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě: -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (jenom NTLM): -
Délka klíče: 0

Tato událost je vygenerována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole předmětu označují účet v místním systému, který si vyžádal přihlášení. Obvykle se jedná o službu, například serverovou službu, nebo o místní proces, například Winlogon.exe nebo Services.exe.

Pole typu přihlášení označuje druh přihlášení, které proběhlo. Nejčastější typy jsou 2 (interaktivní) a 3 (síťové).

Pole Nové přihlášení označují účet, pro který bylo vytvořeno nové přihlášení, tj. přihlášený účet.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole úrovně zosobnění označuje rozsah, ve kterém může být proces v přihlašovací relaci zosobněn.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují pomocné služby, které se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje dílčí protokol z protokolů NTLM, který byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 1930209
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20200922171103.107978-000
Event Type: Úspěšný audit
User:

Computer Name: DESKTOP-7D2FQ0G
Event Code: 4672
Message: Novému přihlášení byla přiřazena zvláštní oprávnění.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3E7

Oprávnění: SeAssignPrimaryTokenPrivilege
SeTcbPrivilege
SeSecurityPrivilege
SeTakeOwnershipPrivilege
SeLoadDriverPrivilege
SeBackupPrivilege
SeRestorePrivilege
SeDebugPrivilege
SeAuditPrivilege
SeSystemEnvironmentPrivilege
SeImpersonatePrivilege
SeDelegateSessionUserImpersonatePrivilege
Record Number: 1930208
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20200922170234.558314-000
Event Type: Úspěšný audit
User:

Computer Name: DESKTOP-7D2FQ0G
Event Code: 4624
Message: Účet byl úspěšně přihlášen.

Předmět:
ID zabezpečení: S-1-5-18
Název účtu: DESKTOP-7D2FQ0G$
Doména účtu: WORKGROUP
ID přihlášení: 0x3E7

Informace o přihlášení:
Typ přihlášení: 5
Omezený režim správce: -
Virtuální účet: Ne
Token se zvýšeným oprávněním: Ano

Úroveň zosobnění: Zosobnění

Nové přihlášení:
ID zabezpečení: S-1-5-18
Název účtu: SYSTEM
Doména účtu: NT AUTHORITY
ID přihlášení: 0x3E7
ID propojeného přihlášení: 0x0
Název účtu v síti: -
Doména účtu v síti: -
GUID přihlášení: {00000000-0000-0000-0000-000000000000}

Informace o procesu:
ID procesu: 0x340
Název procesu: C:\Windows\System32\services.exe

Informace o síti:
Název pracovní stanice: -
Adresa zdrojové sítě: -
Zdrojový port: -

Podrobné informace o ověření:
Proces přihlášení: Advapi
Balíček ověření: Negotiate
Přenosové služby: -
Název balíčku (jenom NTLM): -
Délka klíče: 0

Tato událost je vygenerována po vytvoření relace přihlášení. Je generována v počítači, ke kterému byl získán přístup.

Pole předmětu označují účet v místním systému, který si vyžádal přihlášení. Obvykle se jedná o službu, například serverovou službu, nebo o místní proces, například Winlogon.exe nebo Services.exe.

Pole typu přihlášení označuje druh přihlášení, které proběhlo. Nejčastější typy jsou 2 (interaktivní) a 3 (síťové).

Pole Nové přihlášení označují účet, pro který bylo vytvořeno nové přihlášení, tj. přihlášený účet.

Pole Síť označují původ požadavku na vzdálené přihlášení. Název pracovní stanice není vždy k dispozici a v některých případech může být toto pole prázdné.

Pole úrovně zosobnění označuje rozsah, ve kterém může být proces v přihlašovací relaci zosobněn.

Pole s informacemi o ověření poskytují podrobné informace o tomto konkrétním požadavku na přihlášení.
- GUID přihlášení je jednoznačný identifikátor, který je možné použít ke spojení této události s událostí KDC.
- Přenosové služby označují pomocné služby, které se podílely na tomto požadavku na přihlášení.
- Název balíčku označuje dílčí protokol z protokolů NTLM, který byl použit.
- Délka klíče označuje délku generovaného klíče relace. Tato hodnota bude 0, pokud nebyl požadován žádný klíč relace.
Record Number: 1930207
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20200922170234.558308-000
Event Type: Úspěšný audit
User:

Computer Name: DESKTOP-7D2FQ0G
Event Code: 5059
Message: Operace migrace klíče

Subjekt:
ID zabezpečení: S-1-5-21-3482348820-1896476200-1895645591-1002
Název účtu: David
Doména účtu: DESKTOP-7D2FQ0G
ID přihlášení: 0x38665

Informace o procesu:
ID procesu: 11804
Čas vytvoření procesu: ‎2020‎-‎09‎-‎22T16:50:51.276912700Z

Kryptografické parametry:
Název poskytovatele: Microsoft Software Key Storage Provider
Název algoritmu: ECDSA_P256
Název klíče: TB_2_msedge.net
Typ klíče: Klíč uživatele

Další informace:
Operace: Export trvalého kryptografického klíče
Návratový kód: 0x0
Record Number: 1930206
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20200922165052.110915-000
Event Type: Úspěšný audit
User:

Computer Name: DESKTOP-7D2FQ0G
Event Code: 5061
Message: Kryptografická operace.

Předmět:
ID zabezpečení: S-1-5-21-3482348820-1896476200-1895645591-1002
Název účtu: David
Doména účtu: DESKTOP-7D2FQ0G
ID přihlášení: 0x38665

Kryptografické parametry:
Název poskytovatele: Microsoft Software Key Storage Provider
Název algoritmu: ECDSA_P256
Název klíče: TB_2_msedge.net
Typ klíče: Klíč uživatele

Kryptografická operace:
Operace: Otevřít klíč
Návratový kód: 0x0
Record Number: 1930205
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20200922165052.110667-000
Event Type: Úspěšný audit
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"DriverData"=C:\Windows\System32\Drivers\DriverData
"OS"=Windows_NT
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
"PROCESSOR_ARCHITECTURE"=AMD64
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"USERNAME"=SYSTEM
"windir"=%SystemRoot%
"Path"=C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\NVIDIA Corporation\PhysX\Common;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\WINDOWS\System32\WindowsPowerShell\v1.0\;C:\WINDOWS\System32\OpenSSH\;C:\Program Files\NVIDIA Corporation\NVIDIA NvDLISR;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;%SYSTEMROOT%\System32\OpenSSH\
"PSModulePath"=%ProgramFiles%\WindowsPowerShell\Modules;%SystemRoot%\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files\Intel\;C:\Program Files\Intel\Wired Networking\
"NUMBER_OF_PROCESSORS"=4
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=Intel64 Family 6 Model 94 Stepping 3, GenuineIntel
"PROCESSOR_REVISION"=5e03

-----------------EOF-----------------

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#3 Příspěvek od bojimso »

FRST LOG:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-10-2020
Ran by David (administrator) on DESKTOP-7D2FQ0G (04-10-2020 18:29:09)
Running from C:\Users\David\Desktop
Loaded Profiles: David
Platform: Windows 10 Home Version 1909 18363.1082 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.exe <4>
(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.7205\Agent.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <15>
(Intel Corporation - Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation - Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksdeui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avpui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\plugins_nms.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\transport_proxy.exe
(Kaspersky Lab JSC -> Kaspersky Lab AO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\plugin-nm-server-v2.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2008.2.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
(ND_Apps -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Nota Inc. -> Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16404224 2015-09-17] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation - Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942936 2018-11-02] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [1384840 2018-10-04] (Nota Inc. -> Nota Inc.)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [Battle.net] => C:\Program Files (x86)\Battle.net\Battle.net.exe [1090024 2020-09-24] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [30870200 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [TSMApplication] => C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe [1623040 2020-08-17] () [File not signed]
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [365160 2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [Ubisoft Game Launcher] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe [471360 2020-09-23] (Ubisoft Entertainment Sweden AB -> Ubisoft)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [659976 2020-08-24] (Kaspersky Lab -> AO Kaspersky Lab)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\MountPoints2: {2f792c64-4b05-11ea-ab35-d05099ae28e2} - "E:\setup.exe"
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\MountPoints2: {99340521-9073-11ea-ab51-d05099ae28e2} - "F:\setup.exe"
HKLM\...\Windows x64\Print Processors\hpcpp190: C:\Windows\System32\spool\prtprocs\x64\hpcpp190.dll [651176 2016-08-26] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp196: C:\Windows\System32\spool\prtprocs\x64\hpcpp196.dll [758000 2017-02-14] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp215: C:\Windows\System32\spool\prtprocs\x64\hpcpp215.dll [770232 2018-03-04] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp220: C:\Windows\System32\spool\prtprocs\x64\hpcpp220.dll [772280 2018-08-20] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp230: C:\Windows\System32\spool\prtprocs\x64\hpcpp230.dll [797832 2019-05-24] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\Windows\system32\HPMPW082.DLL [127624 2019-05-24] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HPMLM190: C:\Windows\system32\hpmlm190.dll [310968 2018-08-20] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HPMLM225: C:\Windows\system32\hpmlm225.dll [315528 2019-05-24] (HP Inc. -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\85.0.4183.121\Installer\chrmstp.exe [2020-09-23] (Google LLC -> Google LLC)
Startup: C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\chrome.lnk [2018-09-27]
ShortcutTarget: chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0C9BA02D-C39F-4C25-8CB3-FFAA5F64BEB1} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1D44E45C-F9EE-4ECE-90F1-7189A0084E5A} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3292984 2020-06-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3906E0B8-DDDB-4B33-BFC5-F96E879E4D20} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {40FE9DE1-5C5B-42D5-9679-6D13C2740EA9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [25492152 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {430FEE59-1EE2-4DCE-A592-ABAC966AB81B} - System32\Tasks\Opera scheduled Autoupdate 1593648143 => C:\Users\David\AppData\Local\Programs\Opera\launcher.exe
Task: {4B515F5D-9B31-4DAD-ACFE-E132DDB5DAE8} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [752136 2020-09-28] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {4B5CFAC6-2DD7-4CAD-B746-784FEAC2AB2D} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [647656 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {506690E8-DEF1-4C8C-9D73-A16FC880A186} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
Task: {66A26C5D-66A1-4D78-BACB-C084A30CA59E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {6EB8F908-0B98-49D7-A217-69D5C56EBB99} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-09-09] (Adobe Inc. -> Adobe)
Task: {7652206C-2203-4482-954C-355BC828E30D} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [660688 2020-09-15] (Mozilla Corporation -> Mozilla Foundation)
Task: {90ACD96A-3CAD-4FEB-9905-3D55610C20E8} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9511A6F5-077F-4226-8E8A-A5D8D8C2693F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {952FF45B-D9C8-4257-8405-056578353803} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2018-10-04] (Nota Inc. -> Nota Inc.)
Task: {A1DA0E07-9DBA-4B46-B188-939BCC9BEEF6} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [781808 2019-04-21] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {A5B5260C-77E7-4D9C-8B1F-EA765912E378} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A651D882-FF47-458A-A8A3-699C8A1EC3F1} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A759CB3C-5883-47B3-A04F-A8F5F7D93DC5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {AAD9007D-86CF-4D71-8C84-F8DC236703DF} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_433_pepper.exe [1497656 2020-09-09] (Adobe Inc. -> Adobe)
Task: {B6494C7C-46FF-4944-94A3-1209C263C877} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2018-10-04] (Nota Inc. -> Nota Inc.)
Task: {C2ABD97E-15AB-4077-BF0B-1F73CC68256D} - System32\Tasks\Opera scheduled assistant Autoupdate 1593648148 => C:\Users\David\AppData\Local\Programs\Opera\launcher.exe
Task: {CBE51F93-5848-4293-8E76-337D9F0733E6} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D3936408-0C8F-4EEA-BD6E-385B1F471175} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E2D294D6-E4D9-4AC0-98DB-381910868B51} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F10A0FAB-3E61-40F4-BB5B-A9E623F7C0E9} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2431816 2019-09-15] (Overwolf Ltd -> Overwolf LTD)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 93.89.159.2 1.1.1.1
Tcpip\..\Interfaces\{7c9dc72d-d055-4562-a383-1580067a83d0}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{fab8b2ab-1c3a-43d1-9408-9e478ed961cb}: [DhcpNameServer] 93.89.159.2 1.1.1.1

Edge:
======
Edge DefaultProfile: Default
Edge Profile: C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default [2020-09-19]
Edge Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2020-09-09]
Edge HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]

FireFox:
========
FF DefaultProfile: 3911gjs4.default
FF ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\3911gjs4.default [2020-09-29]
FF Homepage: Mozilla\Firefox\Profiles\3911gjs4.default -> hxxps://www.facebook.com/
FF Notifications: Mozilla\Firefox\Profiles\3911gjs4.default -> hxxps://www.facebook.com
FF Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\3911gjs4.default\Extensions\light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com.xpi [2020-09-15]
FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\FFExt\light_plugin_firefox\addon.xpi => not found
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=4.0.0-dev -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-12-10] (VideoLAN) [File not signed]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2020-09-15] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2020-09-15] <==== ATTENTION

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Default [2020-10-04]
CHR DownloadDir: C:\Users\David\Desktop
CHR Notifications: Default -> hxxps://www.misthub.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://facebook.com/
CHR StartupUrls: Default -> "hxxp://facebook.com/"
CHR Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2020-09-07]
CHR Extension: (BetterTTV) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2020-09-30]
CHR Extension: (uBlock Origin) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-08-21]
CHR Extension: (Kaspersky Password Manager) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhnkblpjbkfklfloegejegedcafpliaa [2020-09-07]
CHR Extension: (Darkness - Beautiful Dark Themes) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\imilbobhamcfahccagbncamhpnbkaenm [2019-05-24]
CHR Extension: (Twitch Now) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk [2020-06-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Global Twitch Emotes) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgniedifoejifjkndekolimjeclnokkb [2020-06-15]
CHR Extension: (Chrome Media Router) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-09-02]
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-07-22]
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\System Profile [2018-11-28]
CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/ahkjpbeeocnddjkakilopmfdlnjdpcdm

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-09-09] (Adobe Inc. -> Adobe)
R2 AVP21.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avp.exe [381968 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4506728 2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
S2 HPSmartDeviceAgentBase; c:\Program Files (x86)\HP\HPSmartDeviceAgentBase\Service\HPSmartDeviceAgentBase.exe [68608 2017-10-25] () [File not signed]
S3 klvssbridge64_21.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\vssbridge64.exe [436168 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [351424 2020-09-22] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 KSDE5.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe [644312 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe [7185288 2020-09-22] (Malwarebytes Inc -> Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2019-02-01] (HP Inc.) [File not signed]
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2431816 2019-09-15] (Overwolf Ltd -> Overwolf LTD)
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2019-02-01] (HP Inc.) [File not signed]
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [474256 2019-11-28] (Rockstar Games, Inc. -> Rockstar Games)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsrAppCharger; C:\WINDOWS\system32\DRIVERS\AsrAppCharger.sys [17192 2011-11-07] (ASROCK Incorporation -> Windows (R) Win 7 DDK provider)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-06-13] (Bluestack Systems, Inc -> Bluestack System Inc.)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [248504 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
S3 DESerialPort; C:\WINDOWS\system32\DRIVERS\DimensionSerialPort.sys [24576 2016-11-12] (Dimension Engineering LLC -> )
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-09-22] (Malwarebytes Corporation -> Malwarebytes)
S3 HPEWSFXBULK; C:\WINDOWS\system32\drivers\hpfx64bulk.sys [29248 2016-09-13] (Hewlett-Packard Company -> Hewlett Packard)
R1 klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [104712 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [205048 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [121088 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [37496 2020-06-29] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R1 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [509184 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [643840 2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\system32\DRIVERS\klhk.sys [1277704 2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP21.1\Bases\klids.sys [240728 2020-09-15] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [984320 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [87808 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [106768 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [106752 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [79104 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [90368 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [55592 2020-06-29] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [256760 2020-09-07] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [309768 2020-09-07] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [117512 2020-09-07] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [206888 2020-09-07] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [133888 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [242944 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [279824 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [217592 2020-09-28] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-09-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [197280 2020-09-28] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73880 2020-09-28] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-09-22] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [131232 2020-09-28] (Malwarebytes Inc -> Malwarebytes)
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 VBAudioVMAUXVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmauxvaio64_win10.sys [71920 2020-08-05] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2020-08-05] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-04 18:29 - 2020-10-04 18:29 - 000027505 _____ C:\Users\David\Desktop\FRST.txt
2020-10-04 18:25 - 2020-10-04 18:29 - 000000000 ____D C:\FRST
2020-10-04 18:25 - 2020-10-04 18:25 - 000000000 ____D C:\rsit
2020-10-04 18:25 - 2020-10-04 18:25 - 000000000 ____D C:\Program Files\trend micro
2020-10-04 18:24 - 2020-10-04 18:25 - 002299392 _____ (Farbar) C:\Users\David\Desktop\FRST64.exe
2020-10-04 18:24 - 2020-10-04 18:24 - 001222144 _____ C:\Users\David\Desktop\RSITx64.exe
2020-09-29 19:54 - 2020-09-29 19:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-09-28 23:34 - 2020-09-28 23:34 - 000217592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-09-28 23:34 - 2020-09-28 23:34 - 000197280 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-09-28 23:34 - 2020-09-28 23:34 - 000131232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-09-28 23:34 - 2020-09-28 23:34 - 000073880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-09-28 23:32 - 2020-09-28 23:32 - 000000000 ____D C:\WINDOWS\LastGood
2020-09-28 23:31 - 2020-09-26 01:41 - 001769688 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-09-28 23:31 - 2020-09-26 01:41 - 001769688 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-09-28 23:31 - 2020-09-26 01:41 - 001370328 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-09-28 23:31 - 2020-09-26 01:41 - 001370328 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-09-28 23:31 - 2020-09-26 01:41 - 001054944 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-09-28 23:31 - 2020-09-26 01:41 - 001054944 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-09-28 23:31 - 2020-09-26 01:41 - 000917728 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-09-28 23:31 - 2020-09-26 01:41 - 000917728 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-09-28 23:31 - 2020-09-26 01:41 - 000455408 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-09-28 23:31 - 2020-09-26 01:41 - 000349936 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 002097560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 001585048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 001506200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 001160600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 000815856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 000811248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 000674200 _____ C:\WINDOWS\system32\nvofapi64.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 000670104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 000656792 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 000555928 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2020-09-28 23:31 - 2020-09-26 01:40 - 000540912 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2020-09-28 23:31 - 2020-09-26 01:39 - 007705320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2020-09-28 23:31 - 2020-09-26 01:39 - 006859152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2020-09-28 23:31 - 2020-09-26 01:39 - 004174736 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2020-09-28 23:31 - 2020-09-26 01:39 - 002509200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2020-09-28 23:31 - 2020-09-26 01:39 - 001733008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6445655.dll
2020-09-28 23:31 - 2020-09-26 01:39 - 001482984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6445655.dll
2020-09-27 09:37 - 2020-09-27 09:37 - 000143740 _____ C:\Users\David\Desktop\passy.jpeg
2020-09-27 03:06 - 2020-09-27 03:06 - 000536374 _____ C:\Users\David\Desktop\leni.jpeg
2020-09-25 02:43 - 2020-09-26 03:27 - 000000918 _____ C:\Users\David\Desktop\Serious Sam HD The First Encounter.lnk
2020-09-25 02:43 - 2020-09-25 02:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam HD The First Encounter
2020-09-22 17:16 - 2020-09-22 17:16 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-09-22 17:16 - 2020-09-22 17:15 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-09-18 03:54 - 2020-09-18 03:55 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2020-09-18 03:53 - 2020-09-15 00:13 - 000038816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2020-09-15 20:57 - 2020-09-29 20:07 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-09-14 20:26 - 2020-09-14 20:26 - 000000910 _____ C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2020-09-10 00:29 - 2020-09-10 00:29 - 005503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 004309504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000928768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe
2020-09-10 00:29 - 2020-09-10 00:29 - 000724480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000709632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFSR.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000522752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMPOSE.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000338944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOVER.exe
2020-09-10 00:29 - 2020-09-10 00:29 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSUTILITY.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2020-09-10 00:29 - 2020-09-10 00:29 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMPOSERES.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 032928920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 031598936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 025444864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 022642176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 019852288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 018032128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 009926456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 007910152 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007845080 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007761408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007582768 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007284736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007271232 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006526448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006304256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006233080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006170624 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006069360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005907456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005848848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005767744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005284328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005041152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005003832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004859904 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004605952 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 004538368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004470272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004048384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004005888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003822592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003805696 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003740456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003727872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 003714048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003581240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 003547136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003525608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003501568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003371176 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 003265024 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003136000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 002870784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002799104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 002774088 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002772616 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002711552 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 002697536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 002585032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002576896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002565120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002494752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002483712 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002454904 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002422384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 002315472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002306048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002291712 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002260824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002259680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002230240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002138264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 002090280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002060288 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001999968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001957552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001942016 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001930752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001918464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001784832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001767424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001751040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001750016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001746232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001743680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001704960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001698816 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001672544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001670144 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001664696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001653792 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001522176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001521664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001512960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001499136 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001491160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001485824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001480520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 001459200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001421392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001399216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001397560 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001393960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001369088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001326592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001307464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001274128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001272160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001260752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001247744 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 001246208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001218424 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001182208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001170960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001151808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001141048 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001138688 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001124864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001108384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001099600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001098720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001077048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001054160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001039872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 001012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001009200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001008952 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000981320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000978232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000944680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000932256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000894032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000893104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000892728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000867328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000858928 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000844088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000823752 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000822784 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000783496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000777216 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000775480 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000768504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000748384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000744240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000738072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000716304 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000682752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000675032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000671560 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000667312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000666288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000661832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000632320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000628400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000600064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000593480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfh264enc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfh264enc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000572208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000564480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000555320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000553664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000544336 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000537608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000528896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000510792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-09-10 00:28 - 2020-09-10 00:28 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000466352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000460192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000420168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000404480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000400696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000375096 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000372536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000363128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000356160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000299072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000294728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000285056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smbwmiv2.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000273208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstext40.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFMCP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000260408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000254776 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000250680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\FileHistory.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpsrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000224072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000224064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000213824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000208712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000205640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000201544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000200008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000165184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWSD.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000146640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000146248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000142152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnscmmc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWSD.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnscmmc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptcatsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000108856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdSSDP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000104248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000093496 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000090944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000090936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vid.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000089344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdSSDP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000079576 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhuxgraphics.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000076800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000066872 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtutils.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000063296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000059392 _____ C:\WINDOWS\system32\runexehelper.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000059192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000057888 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiscap.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtutils.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tar.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NAPCRYPT.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edpnotify.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfctrs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000047008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfproc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NAPCRYPT.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tar.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfctrs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfdisk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfos.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfproc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfdisk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wslapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfos.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmintegrator.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidtel.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdiagnostics.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fixmapi.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidtel.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\applockerfltr.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fixmapi.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDJPN.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDKOR.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106n.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd101.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106n.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd101.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3r.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3r.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-09-10 00:21 - 2020-08-15 07:25 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-09-10 00:21 - 2020-08-15 07:15 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2020-09-07 01:28 - 2020-09-07 01:28 - 000000000 ____D C:\Users\David\Documents\Kaspersky Password Manager
2020-09-07 01:27 - 2020-09-07 01:27 - 000000000 ____D C:\Users\David\AppData\Local\Kaspersky Lab
2020-09-07 00:47 - 2020-09-07 00:47 - 000309768 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2020-09-07 00:45 - 2020-09-07 00:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Password Manager
2020-09-07 00:44 - 2020-09-07 00:45 - 000000000 ____D C:\Program Files (x86)\Kaspersky Lab
2020-09-07 00:44 - 2020-09-07 00:44 - 000256760 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2020-09-07 00:44 - 2020-09-07 00:44 - 000206888 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2020-09-07 00:44 - 2020-09-07 00:44 - 000117512 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2020-09-07 00:44 - 2020-09-07 00:44 - 000099152 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2020-09-07 00:44 - 2020-09-07 00:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2020-09-07 00:44 - 2020-09-07 00:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2020-09-07 00:44 - 2020-06-29 20:14 - 000984320 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2020-09-07 00:44 - 2020-06-29 20:14 - 000509184 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2020-09-07 00:44 - 2020-06-29 20:14 - 000110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2020-09-07 00:41 - 2020-09-07 00:40 - 000744808 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2020-09-06 23:42 - 2020-09-06 23:42 - 000000000 ____D C:\Users\Default\AppData\Local\Kaspersky Lab
2020-09-06 23:42 - 2020-09-06 23:42 - 000000000 ____D C:\Users\Default User\AppData\Local\Kaspersky Lab
2020-09-06 23:41 - 2020-09-07 00:45 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2020-09-06 23:41 - 2020-09-07 00:44 - 000003240 _____ C:\WINDOWS\system32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2020-09-06 22:44 - 2020-09-07 00:44 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2020-09-05 02:04 - 2020-09-05 02:04 - 000000000 ____D C:\Users\David\AppData\Roaming\Mael Horz
2020-09-05 01:51 - 2020-09-05 01:51 - 000000000 ____D C:\Users\David\Documents\My Cheat Tables

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-04 18:30 - 2016-10-15 02:40 - 000000000 ____D C:\Users\David\AppData\Local\Battle.net
2020-10-04 18:16 - 2019-09-21 13:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-10-04 18:16 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-10-04 17:06 - 2017-08-17 09:21 - 000000000 ____D C:\ProgramData\NVIDIA
2020-10-04 17:04 - 2020-06-10 12:31 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-10-04 17:04 - 2020-06-10 12:31 - 000003460 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-04 17:04 - 2016-10-24 21:54 - 000000000 ____D C:\Users\David\AppData\Local\Ubisoft Game Launcher
2020-10-04 07:59 - 2019-09-21 13:41 - 000003142 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner
2020-10-04 07:57 - 2019-11-22 10:41 - 000095666 _____ C:\Users\David\Desktop\trollings.txt
2020-10-04 00:04 - 2017-12-11 07:31 - 000000000 ____D C:\Users\David\AppData\Roaming\vlc
2020-10-03 23:38 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-10-03 23:38 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-10-03 03:43 - 2020-06-10 12:31 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-10-02 13:29 - 2020-08-15 09:49 - 000000000 ____D C:\Users\David\AppData\Roaming\qBittorrent
2020-10-02 00:10 - 2017-11-18 22:32 - 000000000 ____D C:\Users\David\AppData\Local\Packages
2020-10-01 08:44 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF
2020-10-01 00:26 - 2020-08-20 23:58 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2020-09-30 01:16 - 2019-09-21 13:41 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-09-29 20:38 - 2018-03-15 11:00 - 000000000 ____D C:\Users\David\AppData\LocalLow\Mozilla
2020-09-29 19:54 - 2016-10-25 00:27 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-09-29 19:54 - 2016-10-25 00:27 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-09-29 16:15 - 2019-12-05 05:00 - 000003946 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper
2020-09-29 00:55 - 2017-07-12 22:01 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2020-09-29 00:05 - 2017-03-31 01:14 - 000000000 ____D C:\Users\David\AppData\Roaming\Curse Client
2020-09-28 23:40 - 2019-09-21 13:42 - 001695456 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-09-28 23:40 - 2019-03-19 13:55 - 000716944 _____ C:\WINDOWS\system32\perfh005.dat
2020-09-28 23:40 - 2019-03-19 13:55 - 000145024 _____ C:\WINDOWS\system32\perfc005.dat
2020-09-28 23:34 - 2019-09-21 13:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-09-28 23:34 - 2019-03-19 06:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-09-28 12:12 - 2019-03-19 06:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-09-27 23:17 - 2020-07-09 19:16 - 000000000 ____D C:\Users\David\Desktop\Vaníček hlášky
2020-09-26 01:35 - 2020-07-17 05:08 - 005964496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2020-09-26 01:35 - 2019-09-11 15:25 - 006992184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2020-09-25 20:47 - 2016-12-26 15:43 - 000000000 ____D C:\World of Warcraft
2020-09-25 01:41 - 2016-10-15 02:35 - 000000000 ____D C:\Program Files (x86)\Battle.net
2020-09-25 00:55 - 2019-09-11 15:25 - 000058630 _____ C:\WINDOWS\system32\nvinfo.pb
2020-09-24 22:26 - 2017-08-17 09:21 - 005510456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2020-09-24 22:26 - 2017-08-17 09:21 - 002635752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2020-09-24 22:26 - 2017-08-17 09:21 - 001759032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2020-09-24 22:26 - 2017-08-17 09:21 - 000990520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2020-09-24 22:26 - 2017-08-17 09:21 - 000195560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2020-09-24 22:26 - 2017-08-17 09:21 - 000122344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2020-09-24 22:26 - 2017-08-17 09:21 - 000083256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2020-09-23 02:35 - 2020-08-27 23:50 - 000000000 ____D C:\Users\David\Documents\Stronghold Crusader
2020-09-23 00:27 - 2016-10-07 13:13 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-09-22 17:16 - 2020-07-02 02:15 - 000002087 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-09-22 17:16 - 2019-03-19 06:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-09-22 17:15 - 2020-02-17 12:26 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-09-18 11:49 - 2019-09-21 13:34 - 000000000 ____D C:\Users\David
2020-09-18 03:55 - 2017-08-17 09:21 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2020-09-18 03:54 - 2017-08-17 09:20 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2020-09-16 20:51 - 2020-08-27 21:42 - 000675839 _____ C:\Users\David\Desktop\Životopis David Bejbl.pdf
2020-09-16 08:44 - 2017-08-17 09:21 - 009302127 _____ C:\WINDOWS\system32\nvcoproc.bin
2020-09-15 00:13 - 2019-09-11 15:25 - 001682368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2020-09-15 00:13 - 2019-09-11 15:25 - 000222112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2020-09-11 05:14 - 2019-06-08 15:30 - 000000000 ____D C:\Users\David\Desktop\Likeš, Kraken a Vágus memes
2020-09-10 18:14 - 2020-08-20 23:58 - 000905528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2020-09-10 18:14 - 2020-08-20 23:58 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
2020-09-10 00:37 - 2017-11-18 22:39 - 000000000 ___RD C:\Users\David\3D Objects
2020-09-10 00:37 - 2016-04-27 08:39 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-09-10 00:36 - 2019-09-21 13:31 - 000436632 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-09-10 00:36 - 2016-10-14 19:53 - 000000000 ____D C:\Program Files\WinRAR
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\Provisioning
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-09-10 00:35 - 2016-10-14 23:11 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-09-10 00:32 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-09-10 00:32 - 2016-10-14 23:11 - 129170736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-09-10 00:28 - 2019-09-21 13:34 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2020-09-09 03:35 - 2016-10-20 22:47 - 000000000 ____D C:\Users\David\AppData\Local\Personify
2020-09-09 02:45 - 2019-09-21 13:41 - 000004624 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player PPAPI Notifier
2020-09-09 02:45 - 2019-09-21 13:41 - 000004464 _____ C:\WINDOWS\system32\Tasks\Adobe Flash Player Updater
2020-09-09 02:45 - 2019-03-19 06:56 - 000842296 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2020-09-09 02:45 - 2019-03-19 06:56 - 000175160 _____ (Adobe) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2020-09-09 02:45 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2020-09-09 02:45 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\Macromed
2020-09-07 18:49 - 2016-10-14 19:53 - 000000000 ____D C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2020-09-07 18:49 - 2016-10-14 19:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2020-09-07 03:05 - 2016-10-16 20:12 - 000000000 ____D C:\WINDOWS\AutoKMS
2020-09-07 01:15 - 2019-09-21 13:41 - 000002220 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-09-07 00:44 - 2017-01-27 19:57 - 000000000 ____D C:\Program Files\Common Files\AV
2020-09-07 00:40 - 2016-10-14 19:43 - 000000000 ____D C:\ProgramData\AVAST Software
2020-09-07 00:39 - 2019-09-21 13:41 - 000000000 ____D C:\WINDOWS\system32\Tasks\AVAST Software
2020-09-07 00:27 - 2017-09-18 22:03 - 000000000 ____D C:\Users\David\AppData\Local\AVAST Software
2020-09-07 00:21 - 2015-10-30 08:28 - 000000000 ____D C:\Users\Default.migrated
2020-09-06 22:14 - 2020-07-02 02:02 - 000003858 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1593648148
2020-09-06 22:14 - 2020-07-02 02:02 - 000003604 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1593648143
2020-09-06 22:14 - 2019-09-21 13:41 - 000003398 _____ C:\WINDOWS\system32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000003196 _____ C:\WINDOWS\system32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000003152 _____ C:\WINDOWS\system32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000002984 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000002948 _____ C:\WINDOWS\system32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000002914 _____ C:\WINDOWS\system32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-06 22:14 - 2019-09-21 13:41 - 000002744 _____ C:\WINDOWS\system32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2020-09-05 02:52 - 2020-06-13 17:33 - 000000000 ____D C:\Users\David\Desktop\H O N K
2020-09-05 02:05 - 2016-10-15 02:52 - 000000000 ____D C:\Users\David\AppData\Local\CrashDumps

==================== Files in the root of some directories ========

2017-08-02 23:57 - 2018-04-05 16:53 - 000000006 _____ () C:\Users\David\AppData\Roaming\.nfe_lock
2020-08-10 04:39 - 2020-08-10 04:39 - 000034786 _____ () C:\Users\David\AppData\Roaming\VoiceMeeterBananaDefault.xml
2020-08-19 11:17 - 2020-08-19 11:28 - 000004596 _____ () C:\Users\David\AppData\Roaming\VoiceMeeterDefault.xml
2020-06-15 20:30 - 2020-06-21 13:21 - 000004608 _____ () C:\Users\David\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#4 Příspěvek od bojimso »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-10-2020
Ran by David (04-10-2020 18:30:15)
Running from C:\Users\David\Desktop
Windows 10 Home Version 1909 18363.1082 (X64) (2019-09-21 11:41:31)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3482348820-1896476200-1895645591-500 - Administrator - Disabled)
David (S-1-5-21-3482348820-1896476200-1895645591-1002 - Administrator - Enabled) => C:\Users\David
DefaultAccount (S-1-5-21-3482348820-1896476200-1895645591-503 - Limited - Disabled)
Guest (S-1-5-21-3482348820-1896476200-1895645591-501 - Limited - Disabled)
Mamka (S-1-5-21-3482348820-1896476200-1895645591-1004 - Limited - Enabled) => C:\Users\bejja
WDAGUtilityAccount (S-1-5-21-3482348820-1896476200-1895645591-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (HKLM\...\{50229C72-539F-4E65-BEB5-F0491C5074B7}) (Version: 22.2.1 - HP Inc.) Hidden
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.433 - Adobe)
Aktualizace NVIDIA 38.0.5.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 38.0.5.0 - NVIDIA Corporation) Hidden
APP Shop v1.0.21 (HKLM-x32\...\{90242E9B-BC60-46E3-8EE7-8E953F702280}_is1) (Version: 1.0.21 - ASRock Inc.)
ASRock App Charger v1.0.6 (HKLM\...\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft)
Audacity 2.2.1 (HKLM-x32\...\Audacity_is1) (Version: 2.2.1 - Audacity Team)
Balíček ovladače systému Windows - Dimension Engineering USB Serial Converter (11/11/2016 1.0.3.21) (HKLM\...\377DE9679F7155ADE94AA4BCBF4CA02472B49707) (Version: 11/11/2016 1.0.3.21 - Dimension Engineering)
Batman - Arkham Origins (HKLM-x32\...\Batman - Arkham Origins_is1) (Version: - )
Batman Arkham Knight v.1.0.4.5 (HKLM-x32\...\Batman Arkham Knight_is1) (Version: - )
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BlueStacks App Player (HKLM\...\BlueStacks) (Version: 4.215.0.1019 - BlueStack Systems, Inc.)
Browser (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Overwolf_jgbnfkaeklillfmfafgkodhlcnfdgkmjmjngaaof) (Version: 1.0.0.0 - Overwolf app)
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.75.1088 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 5.72 - Piriform)
CPUID CPU-Z 1.92 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.92 - CPUID, Inc.)
Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
Curse Client (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse)
Čeština do hry The Evil Within včetně 3 DLC v1.1 (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Čeština do hry The Evil Within včetně 3 DLC v1.1) (Version: - )
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.12.0.1114 - Disc Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform)
Deus Ex - Human Revolution version 1.0 (HKLM-x32\...\{1146E8F3-4057-4F46-B39C-D18AB4BB1523}_is1) (Version: 1.0 - Square Enix)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Discord (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Discord) (Version: 0.0.306 - Discord Inc.)
ECigStats (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\ECigStats) (Version: - Evolv)
Epic Games Launcher (HKLM-x32\...\{C69A2919-0662-4390-9418-67C931B44C18}) (Version: 1.1.236.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
EScribe Suite (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\EScribe) (Version: - Evolv)
Fallout 4 v.1.1.30 (HKLM-x32\...\Fallout 4_is1) (Version: - )
foobar2000 v1.3.12 (HKLM-x32\...\foobar2000) (Version: 1.3.12 - Peter Pawlowski)
Game Summary (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Overwolf_nafihghfcpikebhfhdhljejkcifgbdahdhngepfb) (Version: 215.9.49 - Overwolf app)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 85.0.4183.121 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.24.15 - Google Inc.) Hidden
gpedt.msc 1.0 (HKLM-x32\...\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version: - Richard)
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
Gyazo 3.4.1.0 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)
HearthArena Companion (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Overwolf_eldaohcjmecjpkpdhhoiolhhaeapcldppbdgbnbc) (Version: 1.5.0.2 - Overwolf app)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Hearthstone Deck Tracker (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\HearthstoneDeckTracker) (Version: 1.6.9 - HearthSim)
HPSmartDeviceAgentBase (HKLM-x32\...\{F7270182-8AD0-420F-92A3-52438ED810A9}) (Version: 1.1.0.0 - HP Inc)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation)
Intel(R) Network Connections 25.2.0.0 (HKLM\...\PROSetDX) (Version: 25.2.0.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{8E3A90F0-23D4-4761-AEBF-409CBBA48C80}) (Version: 21.1.15.500 - Kaspersky) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{8E3A90F0-23D4-4761-AEBF-409CBBA48C80}) (Version: 21.1.15.500 - Kaspersky)
Kaspersky Total Security (HKLM-x32\...\{0124CD8C-8A9A-4A95-BF8C-F084040A93CE}) (Version: 21.1.15.500 - Kaspersky) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{0124CD8C-8A9A-4A95-BF8C-F084040A93CE}) (Version: 21.1.15.500 - Kaspersky)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKLM-x32\...\{657DFCCF-B080-44B1-9AEA-61676011A1AE}) (Version: 4.1.2 - Riot Games) Hidden
League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
League of Legends (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Riot Game league_of_legends.live) (Version: - Riot Games, Inc)
Logitech-kameraindstillinger (HKLM-x32\...\LogiUCDPP) (Version: 1.1.87.0 - Logitech Europe S.A.)
Malwarebytes version 4.2.1.89 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.1.89 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 85.0.564.68 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.135.37 - )
Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\OneDriveSetup.exe) (Version: 19.232.1124.0005 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{97238E8A-4919-4A1E-965A-C6C36938F4CE}) (Version: 2.68.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821 (HKLM-x32\...\{6361b579-2795-4886-b2a8-53d5239b6452}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Mozilla Firefox 80.0.1 (x64 cs) (HKLM\...\Mozilla Firefox 80.0.1 (x64 cs)) (Version: 80.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.7.2 - Mozilla)
MSI Afterburner 4.6.1 (HKLM-x32\...\Afterburner) (Version: 4.6.1 - MSI Co., LTD)
Nástroje kontroly pravopisu pro Microsoft Office 2016 – čeština (HKLM\...\{90160000-001F-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2016 - slovenčina (HKLM\...\{90160000-001F-041B-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.27 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.20.4.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.4.14 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.38.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.35 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 456.55 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 456.55 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
NvModuleTracker (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvModuleTracker.Driver) (Version: 6.14.24033.38719 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 20.0.1 - OBS Project)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
Ori and the Blind Forest Definitive Edition (HKLM-x32\...\Ori and the Blind Forest Definitive Edition_is1) (Version: - )
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.135.0.24 - Overwolf Ltd.)
Ovládací panel NVIDIA 456.55 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 456.55 - NVIDIA Corporation) Hidden
Personify ChromaCam (remove only) (HKLM-x32\...\Personify ChromaCam) (Version: 1.1.6.7 - Personify, Inc.)
PixelHealer (HKLM\...\PixelHealer) (Version: 1.5.0.30 - Aurelitec)
Posel smrti 1.2 (HKLM-x32\...\Posel smrti_is1) (Version: - Future Games s.r.o.)
Print Conductor 5.4 (HKLM-x32\...\Print Conductor_is1) (Version: 5.4 - fCoder SIA)
qBittorrent 4.2.5 (HKLM-x32\...\qBittorrent) (Version: 4.2.5 - The qBittorrent project)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7614 - Realtek Semiconductor Corp.)
Resident Evil 2 (HKLM-x32\...\Resident Evil 2_is1) (Version: - )
Resident Evil 7 Biohazard (HKLM-x32\...\{1ECBF8F3-7079-44CA-AD32-B2AECBCF636F}_is1) (Version: - Capcom)
RivaTuner Statistics Server 7.2.3 (HKLM-x32\...\RTSS) (Version: 7.2.3 - Unwinder)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.16.196 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.4.3 - Rockstar Games)
Serious Sam HD The First Encounter (HKLM-x32\...\Serious Sam HD The First Encounter_is1) (Version: - )
Someday Youll Return (HKLM-x32\...\Someday Youll Return_is1) (Version: - )
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Streamlabs OBS (HKLM\...\029c4619-0385-5543-9426-46f9987161d9) (Version: 0.21.2 - General Workings, Inc.)
Stronghold Crusader 2 (HKLM-x32\...\1433852499_is1) (Version: 2.5.0.10 - GOG.com)
Stronghold Crusader HD Enhanced Edition (HKLM-x32\...\Stronghold Crusader HD Enhanced Edition_is1) (Version: - )
Stronghold HD (HKLM-x32\...\GOGPACKSTRONGHOLDHD_is1) (Version: 2.0.0.3 - GOG.com)
Super Seducer (HKLM\...\SKIDROW - Super Seducer) (Version: - SKIDROW)
SUPERHOT (HKLM-x32\...\1456141688_is1) (Version: 2.0.0.4 - GOG.com)
SUPERHOT MIND CONTROL DELETE (HKLM-x32\...\SUPERHOT MIND CONTROL DELETE_is1) (Version: - )
Syberia (HKLM-x32\...\{E34E9B33-46EC-4252-A52F-DDA3978CC0AF}) (Version: - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
The Walking Dead A New Frontier Episode 1 (HKLM-x32\...\The Walking Dead A New Frontier Episode 1_is1) (Version: - )
TradeSkillMaster Application version 1.0 (HKLM-x32\...\{c44da794-b956-4d50-8733-346d56ae63c7}_is1) (Version: 1.0 - TradeSkillMaster)
Twitch (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 8.0.0 - Twitch Interactive, Inc.)
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition (HKLM\...\{90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}) (Version: - Microsoft)
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition (HKLM\...\{90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}) (Version: - Microsoft)
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition (HKLM\...\{90160000-012B-0405-1000-0000000FF1CE}_Office16.PROPLUS_{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}) (Version: - Microsoft)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 4.9 - Ubisoft)
VLC media player (HKLM\...\VLC media player) (Version: 4.0.0-dev - VideoLAN)
Voicemeeter, The Virtual Mixing Console (HKLM-x32\...\VB:Voicemeeter {17359A74-1236-5467}) (Version: - VB-Audio Software)
VooPoo version 1.5.1.30 (HKLM-x32\...\{63EEAD1F-3FC8-40F5-A415-E4BE098004C0}_is1) (Version: 1.5.1.30 - KunShan XW-TEC)
VueScan x64 (HKLM\...\VueScan x64) (Version: 9.7.13 - Hamrick Software)
Warcraft III (HKLM-x32\...\Warcraft III) (Version: - Blizzard Entertainment)
Warframe (HKLM-x32\...\{72BD42A9-6701-42EB-B77A-2AFC0C499F5E}) (Version: 1.0.0 - Digital Extremes)
Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
World of Warcraft Classic (HKLM-x32\...\World of Warcraft Classic) (Version: - Blizzard Entertainment)

Packages:
=========
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.178.200.0_x86__kgqvnymyfvs32 [2020-10-02] (king.com)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-03-09] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_115.1.152.0_x64__v10z8vjag6ke6 [2020-05-29] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8101.0_x64__8wekyb3d8bbwe [2020-08-20] (Microsoft Studios) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-09] (Twitter Inc.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3482348820-1896476200-1895645591-1002_Classes\CLSID\{9a338598-86a1-4119-8b66-9d52715b6a76}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Windows -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers1: [Kaspersky Anti-Virus 21.1] -> {091EC05A-4A09-4108-8D41-F7B1078DAA9E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\shellex.dll [2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers2: [Kaspersky Anti-Virus 21.1] -> {091EC05A-4A09-4108-8D41-F7B1078DAA9E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\shellex.dll [2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbshlext.dll [2020-02-17] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [Kaspersky Anti-Virus 21.1] -> {091EC05A-4A09-4108-8D41-F7B1078DAA9E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\shellex.dll [2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-09-24] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [Kaspersky Anti-Virus 21.1] -> {091EC05A-4A09-4108-8D41-F7B1078DAA9E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\shellex.dll [2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbshlext.dll [2020-02-17] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-25] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\system32\frapsv64.dll [105984 2015-09-05] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2015-09-05] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2020-09-24 21:42 - 2020-09-24 21:43 - 096130560 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\libcef.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000117760 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\libEGL.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 004342784 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\libGLESv2.dll
2019-04-21 10:33 - 2019-04-21 10:33 - 000232448 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTCore.dll
2019-04-21 10:32 - 2019-04-21 10:32 - 000057344 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTFC.dll
2019-04-21 10:33 - 2019-04-21 10:33 - 000649216 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
2019-04-21 10:32 - 2019-04-21 10:32 - 000074240 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
2019-04-21 10:33 - 2019-04-21 10:33 - 000367104 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTUI.dll
2019-09-09 16:29 - 2019-09-09 16:29 - 000057344 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll
2019-09-09 16:30 - 2019-09-09 16:30 - 000074240 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll
2019-09-09 16:30 - 2019-09-09 16:30 - 000368640 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll
2014-11-10 11:12 - 2019-04-17 22:39 - 085372416 _____ () [File not signed] C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\libcef.dll
2019-04-17 22:39 - 2019-04-17 22:39 - 000043520 _____ () [File not signed] C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\libUbiCustomEvent.dll
2015-06-23 16:00 - 2015-06-23 16:00 - 000285696 _____ (Intel Corporation) [File not signed] [File is in use] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\PsiData.dll
2015-06-23 16:00 - 2015-06-23 16:00 - 000562688 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\ISDI2.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000188928 _____ (Mercer Road Corp) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\ortp.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 004362752 _____ (Mercer Road Corp) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\vivoxsdk.dll
2020-09-24 21:42 - 2020-09-24 21:42 - 000760832 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\chrome_elf.dll
2017-11-06 19:21 - 2019-04-17 22:39 - 000518144 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\chrome_elf.dll
2020-09-24 21:42 - 2020-09-24 21:42 - 000047104 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\audio\qtaudio_windows.dll
2020-09-24 21:42 - 2020-09-24 21:42 - 000026112 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\imageformats\qgif.dll
2020-09-24 21:42 - 2020-09-24 21:42 - 000027136 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\imageformats\qico.dll
2020-09-24 21:42 - 2020-09-24 21:42 - 000243712 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\imageformats\qjpeg.dll
2020-09-24 21:42 - 2020-09-24 21:42 - 000223744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\imageformats\qmng.dll
2020-09-24 21:42 - 2020-09-24 21:42 - 000020992 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\imageformats\qsvg.dll
2020-09-24 21:42 - 2020-09-24 21:42 - 000332288 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\imageformats\qtiff.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 001140224 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\platforms\qwindows.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000041984 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtQml\Models.2\modelsplugin.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtQuick.2\qtquick2plugin.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000084480 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000267776 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtQuick\Controls\qtquickcontrolsplugin.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000071680 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtQuick\Layouts\qquicklayoutsplugin.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000211456 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\qml\QtQuick\Window.2\windowplugin.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 004943360 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Core.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 005022208 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Gui.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000626176 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Multimedia.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000877056 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Network.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 002908672 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Qml.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 003078656 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Quick.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000096256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5QuickControls2.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000681472 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5QuickTemplates2.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000259072 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Svg.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 004718080 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Widgets.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000439296 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5WinExtras.dll
2020-09-24 21:43 - 2020-09-24 21:43 - 000159232 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12375\Qt5Xml.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-13] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-13] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-30 09:24 - 2020-07-22 17:24 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\David\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\wp3662821-assassin-wallpapers.jpg
DNS Servers: 93.89.159.2 - 1.1.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{EA613B87-0798-4766-A039-C81BCAB8DFFE}C:\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [TCP Query User{037281B6-55E4-4E6B-A41A-47FB34BA2F4D}C:\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{3AF034F5-FB2A-4042-9468-5CA7E033B4E7}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{05F735C0-7169-4805-A4E0-4555305419CD}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{2FFC3A6B-0473-4092-ABE1-5D39FD53A17E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{F2405F33-0AF3-431E-9652-1707CA01F1D4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{A1F83455-609A-47AF-9B5A-D69FC68CF4A9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Millie\Millie.exe () [File not signed]
FirewallRules: [{6C593DAD-8395-4F11-A590-F76DDDC9FE92}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Millie\Millie.exe () [File not signed]
FirewallRules: [UDP Query User{302C507C-4DA4-49AB-B64A-8352BC41950E}C:\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\world of warcraft\_retail_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [TCP Query User{06AC170C-54F5-41D1-B2B9-6B5A0A08E0E1}C:\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\world of warcraft\_retail_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{10D5C4D9-2E6B-4B67-A476-5281B56C5955}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{502EF961-5B71-4A32-969F-BA5D52140A00}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [UDP Query User{7EC9CC81-508D-4D45-8E81-DB52CCF2436E}C:\program files\microsoft office\office16\winword.exe] => (Allow) C:\program files\microsoft office\office16\winword.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{98050A6F-1373-48CC-83FA-4BBE97A3F9B5}C:\program files\microsoft office\office16\winword.exe] => (Allow) C:\program files\microsoft office\office16\winword.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3741751F-5BEE-45CB-837A-59E83B005968}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{F9B04128-D8B4-493D-B96B-5A6BAD2795ED}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [UDP Query User{7DA08C82-AB8E-46FE-83A4-6CCF7A8EAA24}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe => No File
FirewallRules: [TCP Query User{0329B052-4C9E-40FD-AD0B-127686849CB4}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe => No File
FirewallRules: [{32FF5D5F-AE6F-4F4E-9C6A-A44362281CD3}] => (Allow) C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{30431157-60F2-404A-B781-4FC5A1FE4407}] => (Allow) C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [TCP Query User{AFC1F7F7-ED3C-4777-85B5-65678200DA35}C:\users\david\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\david\appdata\roaming\utorrent\utorrent.exe => No File
FirewallRules: [UDP Query User{747FE15F-A487-4A02-A70A-A9E98014E198}C:\users\david\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\david\appdata\roaming\utorrent\utorrent.exe => No File
FirewallRules: [TCP Query User{11522C14-B13A-4060-A2EB-03E1287F5182}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{4894D9CD-74EE-4F4D-B682-799DCF973BD9}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{28C2D19F-C193-4A94-97AD-664B24F1C348}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{72CA7C7D-10FB-4D96-B4E3-9AC3B9BB9EDB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{68FBEF50-D0C9-4B70-A3DA-FA8AB9F5C96E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [UDP Query User{C03AB2BE-B25F-4357-9117-35F841408DDF}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [{2D1F0F24-59F0-49DC-9CBA-9166ED79341E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{215B305F-3793-4710-866F-AAAFC4D5A75D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{9526E725-5332-4491-900A-A5B3E00C15F8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{95745F81-0967-4BC0-A61E-3A3E1F4555A8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{0AFE615F-ABD8-45F3-9AE8-F7117FC64CDC}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe (Plays.tv, Inc -> Copyright (c) 2018 Plays.tv, LLC)
FirewallRules: [{DE2DE3B5-8173-4FAC-896C-9FAC3AE29D46}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe (Plays.tv, Inc -> Copyright (c) 2018 Plays.tv, LLC)
FirewallRules: [{42216372-4873-4D06-8A71-3F90277E2E73}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{E09D3792-7521-4348-A40C-8F04F7EBBEC1}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{950A489C-6DC1-4369-A3DC-3DFAE6527798}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{60D42B90-ECC4-40D2-A604-71943C273C20}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{9587D4F0-7BDE-42AA-8234-5B4948E5084A}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\System\witcher.exe (CD Projekt Red) [File not signed]
FirewallRules: [{320922C1-99B3-4866-95D5-6D0C8792482C}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\System\witcher.exe (CD Projekt Red) [File not signed]
FirewallRules: [{52E113A4-D189-4112-826B-9019169D0858}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\System\djinni!.exe (CD Projekt RED Sp. z o.o. -> CD Projekt Red)
FirewallRules: [{B8A860D9-E58B-40DD-B63F-07CE2BEC9BA5}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\System\djinni!.exe (CD Projekt RED Sp. z o.o. -> CD Projekt Red)
FirewallRules: [{6F3AD882-084D-4F82-88D9-937FCC53BB4C}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe () [File not signed]
FirewallRules: [{42B2AA49-B47A-4C28-9490-87830D930524}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe () [File not signed]
FirewallRules: [TCP Query User{1A5E115A-10A8-458D-B3A0-0D08C151128D}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [UDP Query User{A33F85DC-8C02-40B1-99C9-2E2A9F5F0587}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{ED2F8AD3-A6E8-4A1C-BE03-77568C5A9C31}] => (Allow) C:\Program Files\VueScan\vuescan.exe (Hamrick Software) [File not signed]
FirewallRules: [{24DF0275-31DF-480F-95AD-E9A62D964EA7}] => (Allow) C:\Program Files\VueScan\vuescan.exe (Hamrick Software) [File not signed]
FirewallRules: [{5A06E980-6786-4094-BB82-A017F5B88366}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{402159DD-49FA-48BE-83F6-0781AE48CA75}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{BD235299-EF0E-4922-B1EC-FC5A352AB385}] => (Allow) D:\Hry\Assassins Creed Odyssey\ACOdyssey_plus.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{55507DCB-965C-4C75-9957-E8B41A17E22D}] => (Allow) D:\Hry\Assassins Creed Odyssey\ACOdyssey_plus.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{C41E8E36-C825-4F32-A6E8-C2CEFE79A756}] => (Allow) C:\Users\David\AppData\Local\Programs\Opera\69.0.3686.36\opera.exe => No File
FirewallRules: [{6AC5F6E1-A6EE-44B6-9E94-4043E98FCE9E}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
FirewallRules: [{F7C9A6A1-7EB0-467B-B0BB-558FD3575E8F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{B8342AAF-69AB-4EA6-9BA0-29F4957FE7C2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{BE24539C-7D43-4978-87E1-9FEC0CA6F023}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{95E3E803-D9F6-4CDB-98CF-CB0C36EBCB92}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{F46D583F-BFFD-4328-A985-6E194B84E4B6}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [UDP Query User{40136A8F-97F3-4C74-85D5-E12E64BD19AF}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{4AF092A6-463B-479D-8EB4-0047C4E628FD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F788FE0A-8BA7-42BE-897F-83FBC2EC8A96}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7D71C875-EC8F-4B1F-B0C0-444D7EA81450}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5F6D0D58-5EDE-40FB-8DF2-8AFB62F19755}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5FCBDB4A-3D2F-43C5-944E-6993BBA5AB63}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [{430F349B-7A08-451C-A276-3229EECA9E38}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [TCP Query User{A672DB78-0AE2-42A8-BF8E-6992EE5E8DFF}D:\hry\stronghold crusader 2\bin\win32_galaxy_release\crusader2.exe] => (Allow) D:\hry\stronghold crusader 2\bin\win32_galaxy_release\crusader2.exe () [File not signed]
FirewallRules: [UDP Query User{A4C65F8B-C1E2-460E-8148-ABBC0B0FE3CE}D:\hry\stronghold crusader 2\bin\win32_galaxy_release\crusader2.exe] => (Allow) D:\hry\stronghold crusader 2\bin\win32_galaxy_release\crusader2.exe () [File not signed]
FirewallRules: [TCP Query User{78008688-4859-47D1-9319-C36BC9F43F7D}D:\hry\stronghold hd\stronghold.exe] => (Allow) D:\hry\stronghold hd\stronghold.exe (Firefly Studios Limited -> )
FirewallRules: [UDP Query User{2EEC134B-69FD-408B-B1D8-C8D8A5671C0F}D:\hry\stronghold hd\stronghold.exe] => (Allow) D:\hry\stronghold hd\stronghold.exe (Firefly Studios Limited -> )
FirewallRules: [{4A3CA91E-CF6B-4CEF-A9B4-A2F15B2A5196}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

==================== Restore Points =========================

10-09-2020 00:31:10 Windows Update
18-09-2020 13:21:13 Naplánovaný kontrolní bod
26-09-2020 00:15:05 Naplánovaný kontrolní bod
01-10-2020 00:26:20 Windows Update

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (10/04/2020 05:03:34 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/03/2020 11:02:02 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/03/2020 05:15:03 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/03/2020 03:41:36 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/02/2020 01:18:29 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program ACOdyssey.exe verze 0.0.0.0 přestal spolupracovat s Windows a byl ukončen. Pokud chcete zjistit, jestli je k dispozici více informací o tomto problému, vyhledejte historii problému na ovládacím panelu Zabezpečení a údržba.

ID procesu: 2564

Čas spuštění: 01d6989f725349aa

Čas ukončení: 4294967295

Cesta k aplikaci: D:\Hry\Assassins Creed Odyssey\ACOdyssey.exe

ID hlášení: 2d142e6b-acb4-40f3-9139-0394d86b3301

Úplný název balíčku s chybou:

ID aplikace relativní podle balíčku s chybou:

Typ zablokování: Top level window is idle

Error: (10/02/2020 07:39:47 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/02/2020 06:02:27 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/01/2020 11:32:45 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.


System errors:
=============
Error: (09/28/2020 11:34:14 PM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI5

Error: (09/28/2020 11:32:24 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (09/28/2020 11:32:24 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba NVIDIA LocalSystem Container byla ukončena s následující chybou:
Obecný spustitelný příkaz vrátil výsledek označující selhání.

Error: (09/22/2020 05:17:35 PM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI5

Error: (09/18/2020 03:57:05 AM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI5

Error: (09/18/2020 03:54:43 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba NVIDIA LocalSystem Container byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 6000 milisekund: Restartovat službu.

Error: (09/18/2020 03:54:43 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: Služba NVIDIA LocalSystem Container byla ukončena s následující chybou:
Obecný spustitelný příkaz vrátil výsledek označující selhání.

Error: (09/18/2020 03:17:50 AM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI5


CodeIntegrity:
===================================

Date: 2020-10-03 23:02:26.928
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 23:02:26.825
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 23:02:26.673
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 23:02:26.544
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 23:02:26.401
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 03:41:59.411
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 03:41:59.310
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-03 03:41:59.216
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

==================== Memory info ===========================

BIOS: American Megatrends Inc. P2.80 01/26/2016
Motherboard: ASRock Z170 Extreme4
Processor: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
Percentage of memory in use: 41%
Total physical RAM: 16329.27 MB
Available physical RAM: 9634 MB
Total Virtual: 32713.27 MB
Available Virtual: 23666.53 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.18 GB) (Free:22.34 GB) NTFS
Drive d: () (Fixed) (Total:931.5 GB) (Free:297.47 GB) NTFS

\\?\Volume{153a7e41-9717-4114-b409-806cd10646b5}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{a57f3c44-5d42-4e0e-a549-233e2a1c34ff}\ () (Fixed) (Total:0.84 GB) (Free:0.41 GB) NTFS
\\?\Volume{138a95a2-35ad-430f-91a6-0617b595d599}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 223.6 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Preventivka 4.10.2020

#5 Příspěvek od Conder »

Ahoj :)

:arrow: Su s PC nejake problemy?

:arrow: Stiahni AdwCleaner: https://toolslib.net/downloads/finish/1/
  • Uloz na plochu a ukonci vsetky programy
  • Spusti AdwCleaner ako spravca
  • Odsuhlas licencne podmienky
  • Klikni na Spustit skenovani a pockaj na dokoncenie
  • V pripade nalezov nechaj vsetky nalezy oznacene a klikni na Karantena (ak nie su ziadne nalezy, tak na Spustit zakladni opravu)
  • V pripade, ze sa detekuje aj "predinstalovany software", tieto programy mozes, ale nemusis zmazat (toto nie su skodlive programy, ale iba zbytocnosti)
  • Potvrd vyzvu, pockaj na dokoncenie a potvrd restartovanie PC
  • Po restartovani PC sa otvori AdwCleaner, klikni na Zobrazit soubor protokolu
  • Otvori sa log, jeho obsah skopiruj a vloz do dalsej odpovede
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#6 Příspěvek od bojimso »

Zdravím, PC je OK. :|

Našlo a smazalo to pouze jeden PUP.

# -------------------------------
# Malwarebytes AdwCleaner 8.0.7.0
# -------------------------------
# Build: 07-22-2020
# Database: 2020-09-29.1 (Cloud)
# Support: https://www.malwarebytes.com/support
#
# -------------------------------
# Mode: Clean
# -------------------------------
# Start: 10-07-2020
# Duration: 00:00:00
# OS: Windows 10 Home
# Cleaned: 1
# Failed: 0


***** [ Services ] *****

No malicious services cleaned.

***** [ Folders ] *****

No malicious folders cleaned.

***** [ Files ] *****

No malicious files cleaned.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks cleaned.

***** [ Registry ] *****

Deleted HKLM\Software\Wow6432Node\FutureGames

***** [ Chromium (and derivatives) ] *****

No malicious Chromium entries cleaned.

***** [ Chromium URLs ] *****

No malicious Chromium URLs cleaned.

***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries cleaned.

***** [ Firefox URLs ] *****

No malicious Firefox URLs cleaned.

***** [ Hosts File Entries ] *****

No malicious hosts file entries cleaned.

***** [ Preinstalled Software ] *****

No Preinstalled Software cleaned.


*************************

[+] Delete Tracing Keys
[+] Reset Winsock

*************************

AdwCleaner[S00].txt - [1439 octets] - [07/10/2020 06:23:51]

########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Preventivka 4.10.2020

#7 Příspěvek od Conder »

OK, poprosim o obidva nove logy z FRST a este docistime zbytocnosti.
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#8 Příspěvek od bojimso »

Logfile of random's system information tool 1.10 (written by random/random)
Run by David at 2020-10-10 13:52:30
Microsoft Windows 10 Home
System drive C: has 26 GB (11%) free of 228 GB
Total RAM: 16329 MB (66% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 13:52:33, on 10.10.2020
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.18362.0001)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksdeui.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
C:\Windows\System32\TiltWheelMouse.exe
C:\Program Files (x86)\Gyazo\GyStation.exe
C:\ProgramData\Battle.net\Agent\Agent.7212\Agent.exe
C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\plugin-nm-server-v2.exe
C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\transport_proxy.exe
C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe
C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Program Files (x86)\Battle.net\Battle.net.exe
C:\Program Files\trend micro\David.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\BHO\ie_to_edge_bho.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL
O4 - HKCU\..\Run: [OneDrive] "C:\Users\David\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Gyazo] C:\Program Files (x86)\Gyazo\GyStation.exe
O4 - HKCU\..\Run: [Battle.net] "C:\Program Files (x86)\Battle.net\Battle.net.exe" --autostarted
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [TSMApplication] "C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Ubisoft Game Launcher] "C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe" -uplay_silent
O4 - HKCU\..\Run: [kpm.exe] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe" autoStart
O4 - HKCU\..\Run: [QMxNetworkSync] C:\Program Files\Common Files\MAGIX Services\QMxNetworkSync\QMxNetworkSync.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Startup: chrome.lnk = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
O8 - Extra context menu item: E&xportovat do Microsoft Excelu - res://C:\Program Files\Microsoft Office\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Export do &Tahiti - C:\Program Files (x86)\LightComp eDoklady Skenováni\iehelper.html
O8 - Extra context menu item: Poslat do On&eNotu - res://C:\Program Files\Microsoft Office\Office16\ONBttnIE.dll/105
O9 - Extra button: Poslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Poslat do On&eNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIE.dll
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{7c9dc72d-d055-4562-a383-1580067a83d0}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE16\MSOXMLMF.DLL
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe - C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: Služba Kaspersky Anti-Virus 21.1 (AVP21.1) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avp.exe
O23 - Service: @%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100 (CredentialEnrollmentManagerUserSvc) - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: CredentialEnrollmentManagerUserSvc_3d657cb - Unknown owner - C:\WINDOWS\system32\CredentialEnrollmentManager.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe
O23 - Service: Google Chrome Elevation Service (GoogleChromeElevationService) - Google LLC - C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.75\elevation_service.exe
O23 - Service: Služba Aktualizace Google (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Aktualizace Google (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HPSmartDeviceAgentBase - Unknown owner - c:\Program Files (x86)\HP\HPSmartDeviceAgentBase\Service\HPSmartDeviceAgentBase.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\WINDOWS\system32\IProsetMonitor.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Kaspersky Volume Shadow Copy Service Bridge 21.1 (klvssbridge64_21.1) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\vssbridge64.exe
O23 - Service: Kaspersky Password Manager Service (kpm_launch_service) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
O23 - Service: Služba Kaspersky Secure Connection 5.1 (KSDE5.1) - AO Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe
O23 - Service: Malwarebytes Service (MBAMService) - Malwarebytes - C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: Overwolf Updater Windows SCM (OverwolfUpdater) - Overwolf LTD - C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe
O23 - Service: @%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101 (perceptionsimulation) - Unknown owner - C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe (file missing)
O23 - Service: Rockstar Game Library Service (Rockstar Service) - Rockstar Games - C:\Program Files\Rockstar Games\Launcher\RockstarService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\SecurityHealthAgent.dll,-1002 (SecurityHealthService) - Unknown owner - C:\WINDOWS\system32\SecurityHealthService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\System32\SgrmBroker.exe,-100 (SgrmBroker) - Unknown owner - C:\WINDOWS\system32\SgrmBroker.exe (file missing)
O23 - Service: @firewallapi.dll,-50323 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spectrum.exe,-101 (spectrum) - Unknown owner - C:\WINDOWS\system32\spectrum.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: Adaptér výkonu rozhraní WMI (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 13268 bytes

======Listing Processes======









C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s PlugPlay
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p
"fontdrvhost.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-b9a8e8bf-f7d3-48dd-9337-dbf28d62dbbc -SystemEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-dd339862-2601-4951-807a-d072455e478c -IoCancelEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-5fe88c56-66fd-42e9-a598-bb92a11573b4 -NonStateChangingEventPortName:\UMDFCommunicationPorts\WUDF\HostProcess-e700f4b7-f1ac-4c81-ac8e-6525b80a51f0 -LifetimeId:26de14cf-e255-4910-b249-37556c59594a -DeviceGroupId:WudfDefaultDevicePool -HostArg:0
C:\WINDOWS\system32\svchost.exe -k RPCSS -p
C:\WINDOWS\system32\svchost.exe -k DcomLaunch -p -s LSM
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s NcbService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s TimeBrokerSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s hidserv
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s ProfSvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork -p
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s EventLog
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UserManager
C:\WINDOWS\system32\svchost.exe -k LocalService -p
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s nsi
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s Dhcp
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s SysMain
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s EventSystem
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s Themes
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s DispBrokerDesktopSvc
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s NlaSvc
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s StateRepository
C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache

C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s SENS
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s AudioEndpointBuilder
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s FontCache
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s netprofm
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s WinHttpAutoProxySvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Winmgmt
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s fdPHost
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s FDResPub
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s DeviceAssociationService
dashost.exe {97d5dc00-3af9-4356-ace2b5a729448dfc}
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p
C:\WINDOWS\System32\svchost.exe -k netsvcs -p -s ShellHWDetection
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup -s WbioSrvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetworkFirewall -p
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s LanmanWorkstation
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s IKEEXT
C:\WINDOWS\system32\svchost.exe -k NetworkServiceNetworkRestricted -p -s PolicyAgent
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s CryptSvc

C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p -s DPS
C:\WINDOWS\System32\svchost.exe -k utcsvc -p
C:\WINDOWS\System32\svchost.exe -k NetSvcs -p -s iphlpsvc
C:\WINDOWS\system32\IProsetMonitor.exe
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe"

C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s LanmanServer
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s SstpSvc
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TrkWks
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s WpnService
C:\WINDOWS\System32\svchost.exe -k NetworkService -p -s TapiSrv
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation -p -s SSDPSRV
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s WdiServiceHost
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s TokenBroker
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s TabletInputService
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s CDPSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wuauserv
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s lfsvc
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\System32\svchost.exe -k LocalService -p -s LicenseManager
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UsoSvc
C:\WINDOWS\System32\svchost.exe -k netsvcs -p

C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s PcaSvc
C:\WINDOWS\system32\svchost.exe -k LocalService -p -s BthAvctpSvc
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Appinfo
"C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe"

"C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe" /DisableUI
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe" -r


C:\WINDOWS\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\WINDOWS\system32\svchost.exe -k appmodel -p -s camsvc
C:\WINDOWS\System32\svchost.exe -k LocalServiceNoNetwork -p -s NcdAutoSetup
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s DsSvc

C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"fontdrvhost.exe"
"dwm.exe"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -f "C:\ProgramData\NVIDIA\DisplaySessionContainer%d.log" -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\Session" -r -l 3 -p 30000 -c
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -c
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s lmhosts
sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s CDPUserSvc
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup -s WpnUserService
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe" /s
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe -k ClipboardSvcGroup -p -s cbdhsvc
"C:\WINDOWS\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe" -ServerName:App.AppXywbrabmsek0gm3tkwpr5kwzbs55tkqay.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"ctfmon.exe"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksdeui.exe" -hidden

C:\WINDOWS\system32\SettingSyncHost.exe -Embedding
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20092.108.0_x64__8wekyb3d8bbwe\YourPhone.exe" -ServerName:App.AppX9yct9q388jvt4h7y0gn06smzkxcsnt8m.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe"
"C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe" /i
"C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe" /i
C:\WINDOWS\System32\svchost.exe -k UnistackSvcGroup
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\System32\SecurityHealthSystray.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Windows\System32\TiltWheelMouse.exe"
"C:\Program Files (x86)\Gyazo\GyStation.exe"
"C:\ProgramData\Battle.net\Agent\Agent.7212\Agent.exe" --session=7624333732783465081
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe"
"C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe" -uplay_silent
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe" autoStart
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\David\AppData\Local\Google\Chrome\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\David\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\David\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=86.0.4240.75 --initial-client-data=0xcc,0xd0,0xd4,0x68,0xd8,0x7ff8c8ba6e00,0x7ff8c8ba6e10,0x7ff8c8ba6e20
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --gpu-preferences=MAAAAAAAAADgAAAwAAAAAAAAAAAAAAAAAABgAAAAAAAQAAAAAAAAAAAAAAAAAAAAKAAAAAQAAAAgAAAAAAAAACgAAAAAAAAAMAAAAAAAAAA4AAAAAAAAABAAAAAAAAAAAAAAAAUAAAAQAAAAAAAAAAAAAAAGAAAAEAAAAAAAAAABAAAABQAAABAAAAAAAAAAAQAAAAYAAAA= --use-gl=swiftshader-webgl --mojo-platform-channel-handle=1740 /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --lang=cs --service-sandbox-type=network --mojo-platform-channel-handle=1788 /prefetch:8
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=4 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3352 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3520 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3376 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3468 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3552 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=9 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=3580 /prefetch:1
C:\WINDOWS\system32\cmd.exe /d /c "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\plugins_nms.exe" chrome-extension://ahkjpbeeocnddjkakilopmfdlnjdpcdm/ --parent-window=0 < \\.\pipe\chrome.nativeMessaging.in.5085edd2191ec743 > \\.\pipe\chrome.nativeMessaging.out.5085edd2191ec743
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\cmd.exe /d /c "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\plugin-nm-server-v2.exe" chrome-extension://dhnkblpjbkfklfloegejegedcafpliaa/ --parent-window=0 < \\.\pipe\chrome.nativeMessaging.in.246a4bc111c9246f > \\.\pipe\chrome.nativeMessaging.out.246a4bc111c9246f
\??\C:\WINDOWS\system32\conhost.exe 0x4

"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\plugin-nm-server-v2.exe" chrome-extension://dhnkblpjbkfklfloegejegedcafpliaa/ --parent-window=0
"C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\transport_proxy.exe" -Embedding
"C:/Program Files (x86)/Ubisoft/Ubisoft Game Launcher/UplayWebCore.exe" --type=renderer --no-sandbox --disable-features=TouchpadAndWheelScrollLatching --service-pipe-token=944254756A1B99F3099641399FEC4426 --lang=en-US --locales-dir-path="C:/Program Files (x86)/Ubisoft/Ubisoft Game Launcher/locales/1/" --log-file="C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\debug.log" --disable-spell-checking --enable-system-flash --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=944254756A1B99F3099641399FEC4426 --renderer-client-id=4 --mojo-platform-channel-handle=2652 /prefetch:1
C:\WINDOWS\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=audio.mojom.AudioService --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --lang=cs --service-sandbox-type=audio --mojo-platform-channel-handle=5968 /prefetch:8
"C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe"
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2008.2.0_x64__8wekyb3d8bbwe\Calculator.exe" -ServerName:App.AppXsm3pg4n7er43kdh1qp4e79f1j7am68r8.mca
"C:\WINDOWS\SystemApps\InputApp_cw5n1h2txyewy\WindowsInternal.ComposableShell.Experiences.TextInput.InputApp.exe" -ServerName:App.AppXagta193n5rpf7mheremt3yyfa1g555vc.mca
C:\WINDOWS\system32\DllHost.exe /Processid:{973D20D7-562D-44B9-B70B-5A0F49CCDF3F}
"C:\Program Files (x86)\Battle.net\Battle.net.exe" --updatepid=6236
"C:\Program Files (x86)\Battle.net\Battle.net.exe" --type=gpu-process --field-trial-handle=2988,12076702705469603598,360772478312596828,131072 --disable-features=HardwareMediaKeyHandling --no-sandbox --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201010T053837.732706.log" --log-severity=error --product-version="Battle.net/1.27.1.12428 (retail) Chrome/75.0.3770.100" --lang=en-US --watch-browser-pid=3124 --gpu-preferences=KAAAAAAAAADgAAAgAQAAAAAAAAAAAGAAAAAAAAAAAAAIAAAAAAAAACgAAAAEAAAAIAAAAAAAAAAoAAAAAAAAADAAAAAAAAAAOAAAAAAAAAAQAAAAAAAAAAAAAAAFAAAAEAAAAAAAAAAAAAAABgAAABAAAAAAAAAAAQAAAAUAAAAQAAAAAAAAAAEAAAAGAAAA --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201010T053837.732706.log" --service-request-channel-token=13921381359681458015 --mojo-platform-channel-handle=3016 /prefetch:2 --battle-net-helper=Battle.net.12428
"C:\Program Files (x86)\Battle.net\Battle.net.exe" --type=utility --field-trial-handle=2988,12076702705469603598,360772478312596828,131072 --disable-features=HardwareMediaKeyHandling --lang=en-US --service-sandbox-type=network --no-sandbox --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201010T053837.732706.log" --log-severity=error --product-version="Battle.net/1.27.1.12428 (retail) Chrome/75.0.3770.100" --lang=en-US --watch-browser-pid=3124 --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201010T053837.732706.log" --service-request-channel-token=13082895497357262119 --mojo-platform-channel-handle=4008 /prefetch:8 --battle-net-helper=Battle.net.12428
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s XblAuthManager
"C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbamtray.exe"
"C:\Program Files (x86)\Battle.net\Battle.net.exe" --type=renderer --no-sandbox --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201010T053837.732706.log" --field-trial-handle=2988,12076702705469603598,360772478312596828,131072 --disable-features=HardwareMediaKeyHandling --lang=en-US --log-file="C:\Users\David\AppData\Local\Battle.net\Logs\libcef-20201010T053837.732706.log" --log-severity=error --product-version="Battle.net/1.27.1.12428 (retail) Chrome/75.0.3770.100" --disable-spell-checking --uncaught-exception-stack-size=10 --watch-browser-pid=3124 --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --service-request-channel-token=15476280958291638516 --renderer-client-id=8 --mojo-platform-channel-handle=3068 /prefetch:1 --battle-net-helper=Battle.net.12428
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=261 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=8876 /prefetch:1
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.20090.1002.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\WINDOWS\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s WdiSystemHost

C:\WINDOWS\system32\AUDIODG.EXE 0x778
C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted -p -s NgcSvc
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted -p -s NgcCtnrSvc
C:\Windows\System32\smartscreen.exe -Embedding
"C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=420 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6136 /prefetch:1
"C:\Users\David\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --field-trial-handle=1728,12598682937376955446,1066974143441517097,131072 --disable-gpu-compositing --lang=cs --extension-process --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=421 --no-v8-untrusted-code-mitigations --mojo-platform-channel-handle=6180 /prefetch:1

======Scheduled tasks folder======

C:\WINDOWS\tasks\Connect.job - C:\Program Files (x86)\MAGIX\Connect\connect.exe

=========Mozilla firefox=========

ProfilePath - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\3911gjs4.default

prefs.js - "browser.startup.homepage" - "https://www.facebook.com/"

"light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com"=C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\FFExt\light_plugin_firefox\addon.xpi


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\Office16\NPSPWRAP.DLL


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=4.0.0-dev]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\BHO\ie_to_edge_bho_64.dll [2020-10-08 519056]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-13 2177328]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD49718-1D00-4B19-AF5F-070AF6D5D54C}]
IEToEdge BHO - C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\BHO\ie_to_edge_bho.dll [2020-10-08 403856]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-13 1522480]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SecurityHealth"=C:\WINDOWS\system32\SecurityHealthSystray.exe [2020-02-14 84992]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-09-17 16404224]
"MouseDriver"=C:\Windows\system32\TiltWheelMouse.exe [2013-04-09 241152]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2015-06-23 36352]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2018-11-02 3942936]
"OODefragTray"=C:\Program Files\OO Software\Defrag\oodtray.exe []

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\David\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2020-02-07 1573224]
"Gyazo"=C:\Program Files (x86)\Gyazo\GyStation.exe [2018-10-04 1384840]
"Battle.net"=C:\Program Files (x86)\Battle.net\Battle.net.exe [2020-10-10 1090024]
"CCleaner Smart Cleaning"=C:\Program Files\CCleaner\CCleaner64.exe [2020-09-22 30870200]
"TSMApplication"=C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe [2020-08-17 1623040]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2020-02-09 365160]
"Ubisoft Game Launcher"=C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe [2020-10-06 471360]
"kpm.exe"=C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [2020-08-24 659976]
"QMxNetworkSync"=C:\Program Files\Common Files\MAGIX Services\QMxNetworkSync\QMxNetworkSync.exe [2018-07-05 414976]

C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
chrome.lnk - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AudioSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CBDHSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudAddService.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HdAudBus.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\usbaudio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioEndpointBuilder]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AudioSrv]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CBDHSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudAddService.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HdAudBus.Sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MBAMService]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\NetSetupSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SerCx2.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\usbaudio.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WinQuic]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{4D36E96C-E325-11CE-BFC1-08002BE10318}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"EnableFullTrustStartupTasks"=2
"EnableUwpStartupTasks"=2
"SupportFullTrustStartupTasks"=1
"SupportUwpStartupTasks"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"aux"=wdmaud.drv
"midi"=wdmaud.drv
"midimapper"=midimap.dll
"mixer"=wdmaud.drv
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wave"=wdmaud.drv
"wavemapper"=msacm32.drv
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.FPS1"=frapsv64.dll
"VIDC.RTV1"=rtvcvfw64.dll
"MSVideo8"=VfWWDM32.dll

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2020-10-08 17:34:44 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2020-10-08 17:34:37 ----A---- C:\WINDOWS\system32\drivers\mwac.sys
2020-10-08 17:34:37 ----A---- C:\WINDOWS\system32\drivers\farflt.sys
2020-10-08 17:34:36 ----A---- C:\WINDOWS\system32\drivers\MbamChameleon.sys
2020-10-08 04:22:17 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo-1-999-0-0-0.exe
2020-10-08 04:22:17 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2020-10-08 04:22:17 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1-999-0-0-0.dll
2020-10-08 04:22:17 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2020-10-08 04:22:17 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.dll
2020-10-08 04:22:17 ----A---- C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-10-08 04:22:17 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2020-10-08 04:22:17 ----A---- C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-10-08 04:22:17 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2020-10-08 04:22:17 ----A---- C:\WINDOWS\system32\OpenCL.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\SYSWOW64\nvofapi.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\nvofapi64.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\nvmcumd.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\nvdispgenco6445671.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\nvdispco6445671.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2020-10-08 04:22:16 ----A---- C:\WINDOWS\system32\nvcuda.dll
2020-10-07 11:10:43 ----D---- C:\ProgramData\simplitec
2020-10-07 11:10:42 ----D---- C:\Program Files (x86)\MAGIX
2020-10-07 11:10:28 ----D---- C:\Program Files\Common Files\MAGIX Services
2020-10-07 11:10:18 ----D---- C:\ProgramData\MAGIX
2020-10-07 11:10:14 ----D---- C:\Program Files (x86)\MSXML 4.0
2020-10-07 06:23:17 ----D---- C:\AdwCleaner
2020-10-04 18:25:49 ----D---- C:\FRST
2020-10-04 18:25:29 ----D---- C:\rsit
2020-10-04 18:25:29 ----D---- C:\Program Files\trend micro
2020-09-28 23:32:21 ----D---- C:\WINDOWS\LastGood
2020-09-22 17:16:27 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2020-09-22 17:16:25 ----A---- C:\WINDOWS\system32\drivers\MbamElam.sys
2020-09-18 03:54:38 ----D---- C:\WINDOWS\LastGood.Tmp
2020-09-18 03:53:48 ----A---- C:\WINDOWS\system32\nvhdap64.dll
2020-09-15 20:57:01 ----D---- C:\Program Files (x86)\Mozilla Firefox

======List of files/folders modified in the last 1 month======

2020-10-10 13:51:55 ----D---- C:\Users\David\AppData\Roaming\qBittorrent
2020-10-10 13:49:04 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2020-10-10 13:47:02 ----D---- C:\WINDOWS\Prefetch
2020-10-10 13:10:00 ----D---- C:\WINDOWS\system32\sru
2020-10-10 12:35:17 ----D---- C:\WINDOWS\system32\SleepStudy
2020-10-10 12:25:58 ----D---- C:\ProgramData\NVIDIA
2020-10-10 10:09:44 ----D---- C:\WINDOWS\Temp
2020-10-10 10:09:43 ----D---- C:\WINDOWS\system32\drivers
2020-10-10 07:38:38 ----AD---- C:\Program Files (x86)\Battle.net
2020-10-10 07:36:09 ----D---- C:\Users\David\AppData\Roaming\vlc
2020-10-09 19:27:06 ----D---- C:\WINDOWS\system32\Tasks
2020-10-09 17:55:27 ----D---- C:\WINDOWS\system32\DriverStore
2020-10-09 17:55:27 ----D---- C:\WINDOWS\System32
2020-10-09 17:55:27 ----D---- C:\WINDOWS\INF
2020-10-09 17:55:18 ----RD---- C:\WINDOWS\Microsoft.NET
2020-10-09 01:37:45 ----HD---- C:\Program Files\WindowsApps
2020-10-09 01:37:45 ----D---- C:\WINDOWS\AppReadiness
2020-10-09 01:36:42 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2020-10-09 01:31:09 ----D---- C:\WINDOWS\system32\LogFiles
2020-10-08 17:34:37 ----D---- C:\WINDOWS\system32\catroot2
2020-10-08 17:34:34 ----SHD---- C:\System Volume Information
2020-10-08 17:34:30 ----D---- C:\WINDOWS\SysWOW64
2020-10-08 14:26:30 ----D---- C:\WINDOWS\Logs
2020-10-08 00:49:41 ----D---- C:\Program Files (x86)\MSI Afterburner
2020-10-07 14:06:57 ----D---- C:\WINDOWS\system32\config
2020-10-07 11:17:26 ----AD---- C:\World of Warcraft
2020-10-07 11:17:16 ----HD---- C:\ProgramData
2020-10-07 11:17:16 ----HD---- C:\$AV_ASW
2020-10-07 11:17:16 ----D---- C:\PerfLogs
2020-10-07 11:17:16 ----D---- C:\Logs
2020-10-07 11:13:12 ----SHD---- C:\WINDOWS\Installer
2020-10-07 11:11:01 ----D---- C:\WINDOWS\WinSxS
2020-10-07 11:10:43 ----D---- C:\WINDOWS\Tasks
2020-10-07 11:10:42 ----RD---- C:\Program Files (x86)
2020-10-07 11:10:28 ----D---- C:\Program Files\Common Files
2020-10-07 11:10:17 ----D---- C:\Program Files (x86)\Common Files
2020-10-07 06:26:26 ----D---- C:\Program Files (x86)\RivaTuner Statistics Server
2020-10-07 06:25:54 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2020-10-07 00:47:08 ----AD---- C:\Users\David\AppData\Roaming\Curse Client
2020-10-04 18:25:29 ----D---- C:\Program Files
2020-10-02 02:49:16 ----A---- C:\WINDOWS\system32\nvapi64.dll
2020-10-02 02:49:10 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll
2020-10-01 07:19:21 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2020-10-01 07:19:21 ----A---- C:\WINDOWS\system32\nvcpl.dll
2020-10-01 07:19:17 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2020-10-01 07:19:17 ----A---- C:\WINDOWS\system32\nvshext.dll
2020-10-01 07:19:17 ----A---- C:\WINDOWS\system32\nvmctray.dll
2020-10-01 07:19:17 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2020-10-01 07:19:17 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2020-10-01 00:26:36 ----D---- C:\WINDOWS\system32\Logs
2020-10-01 00:26:36 ----D---- C:\Program Files\Microsoft Update Health Tools
2020-09-28 23:32:21 ----D---- C:\Windows
2020-09-22 17:16:26 ----HD---- C:\WINDOWS\ELAMBKUP
2020-09-18 03:55:36 ----D---- C:\ProgramData\NVIDIA Corporation
2020-09-18 03:54:48 ----D---- C:\Program Files\NVIDIA Corporation
2020-09-15 00:13:44 ----A---- C:\WINDOWS\system32\nvhdagenco6420103.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 cm_km;AO Kaspersky Lab Cryptographic Module x64 (56 bit); C:\WINDOWS\system32\DRIVERS\cm_km.sys [2020-06-29 248504]
R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2015-06-23 1455552]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-101; C:\WINDOWS\system32\drivers\iorate.sys [2019-03-19 56632]
R0 klupd_klif_arkmon;klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [2020-09-07 256760]
R0 klupd_klif_klbg;klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [2020-09-07 117512]
R1 afunix;afunix; C:\WINDOWS\system32\drivers\afunix.sys [2020-08-12 40960]
R1 AsrAppCharger;AsrAppCharger; C:\WINDOWS\system32\DRIVERS\AsrAppCharger.sys [2011-11-07 17192]
R1 bam;@%SystemRoot%\system32\drivers\bam.sys,-100; C:\WINDOWS\system32\drivers\bam.sys [2019-03-19 70456]
R1 ESProtectionDriver;Malwarebytes Anti-Exploit; \??\C:\WINDOWS\system32\drivers\mbae64.sys [2020-09-22 153312]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2019-03-19 59392]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2019-03-19 8704]
R1 klbackupdisk;Kaspersky Lab klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [2020-06-29 104712]
R1 klbackupflt;Kaspersky Lab klbackupflt; C:\WINDOWS\system32\DRIVERS\klbackupflt.sys [2020-06-29 205048]
R1 kldisk;kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [2020-06-29 121088]
R1 klflt;Kaspersky Lab Kernel DLL; C:\WINDOWS\system32\DRIVERS\klflt.sys [2020-06-29 509184]
R1 klgse;Kaspersky Lab Security Extender Driver; C:\WINDOWS\system32\DRIVERS\klgse.sys [2020-06-26 643840]
R1 klhk;Kaspersky Lab service driver; C:\WINDOWS\system32\DRIVERS\klhk.sys [2020-06-26 1277704]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2020-06-29 984320]
R1 klim6;@oem51.inf,%KLIM6_Desc%;Kaspersky Anti-Virus NDIS 6 Filter; C:\WINDOWS\system32\DRIVERS\klim6.sys [2020-06-29 87808]
R1 klpd;Kaspersky Lab format recognizer driver; C:\WINDOWS\system32\DRIVERS\klpd.sys [2020-06-29 79104]
R1 klpnpflt;Kaspersky Lab klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [2020-06-29 90368]
R1 klwfp;klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [2020-06-29 133888]
R1 klwtp;KLwtp - WFP callout traffic inspector; C:\WINDOWS\system32\DRIVERS\klwtp.sys [2020-06-29 242944]
R1 kneps;kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [2020-06-29 279824]
R2 BlueStacksDrv;BlueStacks Hypervisor; \??\C:\Program Files\BlueStacks\BstkDrv_bgp.sys [2020-06-13 315976]
R2 CldFlt;Windows Cloud Files Filter Driver; C:\WINDOWS\system32\drivers\cldflt.sys [2020-05-14 457216]
R2 MBAMChameleon;MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [2020-10-10 217592]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2019-03-19 53760]
R3 bindflt;@%systemroot%\system32\drivers\bindflt.sys,-100; C:\WINDOWS\system32\drivers\bindflt.sys [2020-02-14 117264]
R3 dtlitescsibus;@oem26.inf,%DisplayName%;DAEMON Tools Lite Virtual SCSI Bus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [2020-02-09 42256]
R3 dtliteusbbus;@oem37.inf,%DisplayName%;DAEMON Tools Lite Virtual USB Bus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [2020-02-09 59360]
R3 e1dexpress;@oem27.inf,%e1dExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver D; C:\WINDOWS\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_f6c146a8872514f7\e1d68x64.sys [2020-05-04 599928]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2015-09-17 4603136]
R3 klids;klids; \??\C:\ProgramData\Kaspersky Lab\AVP21.1\Bases\klids.sys [2020-09-15 240728]
R3 klkbdflt;Kaspersky Lab KLKBDFLT; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [2020-06-29 106768]
R3 klmouflt;Kaspersky Lab KLMOUFLT; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [2020-06-29 106752]
R3 kltap;@oem52.inf,%devicedescription%;Kaspersky Security Data Escort Adapter; C:\WINDOWS\System32\drivers\kltap.sys [2020-06-29 55592]
R3 klupd_klif_kimul;klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [2020-09-07 99152]
R3 klupd_klif_klark;klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [2020-09-07 309768]
R3 klupd_klif_mark;klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [2020-09-07 206888]
R3 MBAMFarflt;MBAMFarflt; C:\WINDOWS\system32\DRIVERS\farflt.sys [2020-10-10 197280]
R3 MBAMProtection;MBAMProtection; \??\C:\WINDOWS\system32\DRIVERS\mbam.sys [2020-10-10 73880]
R3 MBAMSwissArmy;MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [2020-10-10 248968]
R3 MBAMWebProtection;MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [2020-10-10 131232]
R3 MEIx64;@oem12.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\WINDOWS\System32\drivers\TeeDriverW8x64.sys [2018-05-06 228992]
R3 NAL;Nal Service ; \??\C:\WINDOWS\system32\Drivers\iqvsw64e.sys [2020-06-18 57696]
R3 NVHDA;@oem54.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\WINDOWS\system32\drivers\nvhda64v.sys [2020-09-15 222112]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvmdi.inf_amd64_1c5894d897494457\nvlddmkm.sys [2020-10-02 32479640]
R3 NvModuleTracker;@oem30.inf,%ServiceName%;NvModuleTracker; C:\WINDOWS\System32\drivers\NvModuleTracker.sys [2020-03-04 50592]
R3 nvvad_WaveExtensible;@oem22.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2019-03-19 69840]
R3 nvvhci;@oem8.inf,%ServiceDesc%;NVVHCI Enumerator Service; C:\WINDOWS\System32\drivers\nvvhci.sys [2020-03-11 67456]
S0 bttflt;@virtdisk.inf,%service_desc%;Microsoft Hyper-V VHDPMEM BTT Filter; C:\WINDOWS\System32\drivers\bttflt.sys [2019-03-19 42808]
S0 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2019-03-19 319528]
S0 iaStorAVC;@iastorav.inf,%iaStorAVC.DeviceDesc%;Intel Chipset SATA RAID Controller; C:\WINDOWS\System32\drivers\iaStorAVC.sys [2019-03-19 885048]
S0 ItSas35i;ItSas35i; C:\WINDOWS\System32\drivers\ItSas35i.sys [2019-03-19 148520]
S0 klelam;klelam; C:\WINDOWS\system32\DRIVERS\klelam.sys [2020-06-29 37496]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2019-03-19 124448]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2019-03-19 128528]
S0 MbamElam;MbamElam; C:\WINDOWS\system32\DRIVERS\MbamElam.sys [2020-09-22 19912]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2019-03-19 75280]
S0 megasas35i;megasas35i; C:\WINDOWS\System32\drivers\megasas35i.sys [2019-03-19 94736]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2019-03-19 58896]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2019-03-19 68624]
S0 Ramdisk;Windows RAM Disk Driver; C:\WINDOWS\system32\DRIVERS\ramdisk.sys [2019-03-19 41784]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2019-03-19 20992]
S3 Acx01000;@%SystemRoot%\system32\drivers\Acx01000.sys,-1000; C:\WINDOWS\system32\drivers\Acx01000.sys [2020-03-12 337920]
S3 amdgpio2;@amdgpio2.inf,%GPIO.SvcDesc%;AMD GPIO Client Driver; C:\WINDOWS\System32\drivers\amdgpio2.sys [2019-03-19 18432]
S3 amdi2c;@amdi2c.inf,%amdi2c.SVCDESC%;AMD I2C Controller Service; C:\WINDOWS\System32\drivers\amdi2c.sys [2019-03-19 37888]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2020-09-10 18432]
S3 BthA2dp;@microsoft_bluetooth_a2dp.inf,%BthA2dp.ServiceDescription%;Microsoft Bluetooth A2dp driver; C:\WINDOWS\System32\drivers\BthA2dp.sys [2020-03-12 231936]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\WINDOWS\System32\drivers\BthEnum.sys [2020-03-12 114688]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.Legacy.LEEnumerator.sys [2019-03-19 97280]
S3 BthMini;@bth.inf,%BTHMINI.SvcDesc%;Bluetooth Radio Driver; C:\WINDOWS\System32\drivers\BTHMINI.sys [2020-03-12 36864]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\WINDOWS\System32\drivers\BTHport.sys [2020-03-12 1428992]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\WINDOWS\System32\drivers\BTHUSB.sys [2020-03-12 99328]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2019-03-19 43008]
S3 CAD;@ChargeArbitration.inf,%CAD_DevDesc%;Charge Arbitration Driver; C:\WINDOWS\System32\drivers\CAD.sys [2019-03-19 64312]
S3 DESerialPort;@oem48.inf,%SerialPort_SvcDesc%;DE USB Serial Port Service; C:\WINDOWS\system32\DRIVERS\DimensionSerialPort.sys [2016-11-12 24576]
S3 e1i65x64;@net1ic64.inf,%e1iExpress.Service.DispName%;Intel(R) PRO/1000 PCI Express Network Connection Driver I; C:\WINDOWS\System32\drivers\e1i65x64.sys [2019-03-19 553984]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\DriverStore\FileRepository\genericusbfn.inf_amd64_b9c53b80e63af230\genericusbfn.sys [2019-09-21 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2019-03-19 53560]
S3 hidspi;@hidspi_km.inf,%hidspi.SVCDESC%;Microsoft SPI HID Miniport Driver; C:\WINDOWS\System32\drivers\hidspi.sys [2019-10-04 64000]
S3 HPEWSFXBULK;HPEWSFXBULK; C:\WINDOWS\system32\drivers\hpfx64bulk.sys [2016-09-13 29248]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2020-09-10 84280]
S3 HwNClx0101;Microsoft Hardware Notifications Class Extension Driver; C:\WINDOWS\System32\Drivers\mshwnclx.sys [2019-03-19 28672]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2019-03-19 1866768]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2019-03-19 36352]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2019-03-19 91136]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2019-03-19 79360]
S3 iaLPSS2i_GPIO2_BXT_P;@iaLPSS2i_GPIO2_BXT_P.inf,%iaLPSS2i_GPIO2_BXT_P.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_BXT_P.sys [2019-03-19 93184]
S3 iaLPSS2i_GPIO2_CNL;@iaLPSS2i_GPIO2_CNL.inf,%iaLPSS2i_GPIO2_CNL.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_CNL.sys [2019-03-19 112128]
S3 iaLPSS2i_GPIO2_GLK;@iaLPSS2i_GPIO2_GLK.inf,%iaLPSS2i_GPIO2_GLK.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2_GLK.sys [2019-03-19 96256]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2019-03-19 171520]
S3 iaLPSS2i_I2C_BXT_P;@iaLPSS2i_I2C_BXT_P.inf,%iaLPSS2i_I2C_BXT_P.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_BXT_P.sys [2019-03-19 175104]
S3 iaLPSS2i_I2C_CNL;@iaLPSS2i_I2C_CNL.inf,%iaLPSS2i_I2C_CNL.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_CNL.sys [2019-03-19 180736]
S3 iaLPSS2i_I2C_GLK;@iaLPSS2i_I2C_GLK.inf,%iaLPSS2i_I2C_GLK.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C_GLK.sys [2019-03-19 177664]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2019-03-19 566800]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2019-03-19 46592]
S3 intelpmax;@intelpmax.inf,%SvcDesc%;Intel Power Limit Driver; C:\WINDOWS\System32\drivers\intelpmax.sys [2019-03-19 28672]
S3 IPT;IPT; C:\WINDOWS\System32\drivers\ipt.sys [2019-03-19 54584]
S3 mausbhost;@mausbhost.inf,%MAUSBHost.ServiceName%;MA-USB Host Controller Driver; C:\WINDOWS\System32\drivers\mausbhost.sys [2019-03-19 535864]
S3 mausbip;@mausbhost.inf,%MAUSBIP.ServiceName%;MA-USB IP Filter Driver; C:\WINDOWS\System32\drivers\mausbip.sys [2019-03-19 62264]
S3 MbbCx;MBB Network Adapter Class Extension; C:\WINDOWS\system32\drivers\MbbCx.sys [2019-11-15 359424]
S3 Microsoft_Bluetooth_AvrcpTransport;@microsoft_bluetooth_avrcptransport.inf,%Microsoft_Bluetooth_AvrcpTransport.ServiceDescription%;Microsoft Bluetooth Avrcp Transport Driver; C:\WINDOWS\System32\drivers\Microsoft.Bluetooth.AvrcpTransport.sys [2019-03-19 64512]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2019-03-19 1150480]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2019-03-19 153616]
S3 NDKPing;NDKPing Driver; C:\WINDOWS\system32\drivers\NDKPing.sys [2019-03-19 63488]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2019-03-19 187904]
S3 nvdimm;@nvdimm.inf,%nvdimm.SvcDesc%;Microsoft NVDIMM device driver; C:\WINDOWS\System32\drivers\nvdimm.sys [2019-03-19 158520]
S3 PktMon;Packet Monitor Driver; C:\WINDOWS\system32\drivers\PktMon.sys [2019-03-19 96056]
S3 pmem;@pmem.inf,%pmem.SvcDesc%;Microsoft persistent memory disk driver; C:\WINDOWS\System32\drivers\pmem.sys [2019-03-19 127800]
S3 PNPMEM;@memory.inf,%PNPMEM.SvcDesc%;Microsoft Memory Module Driver; C:\WINDOWS\System32\drivers\pnpmem.sys [2019-03-19 17408]
S3 portcfg;portcfg; C:\WINDOWS\System32\drivers\portcfg.sys [2019-03-19 25600]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2019-12-14 986936]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2019-03-19 211456]
S3 rhproxy;@rhproxy.inf,%rhproxy.SVCDESC%;Resource Hub proxy driver; C:\WINDOWS\System32\drivers\rhproxy.sys [2019-03-19 113152]
S4 hvcrash;hvcrash; C:\WINDOWS\System32\drivers\hvcrash.sys [2019-03-19 32568]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AVP21.1;Služba Kaspersky Anti-Virus 21.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avp.exe [2020-06-29 381968]
R2 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 CDPUserSvc_3d657cb;Uživatelská služba platformy připojených zařízení_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 DispBrokerDesktopSvc;@%SystemRoot%\system32\dispbroker.desktop.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 DusmSvc;@%SystemRoot%\System32\dusmsvc.dll,-1; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R2 Fabs;FABS - Helping agent for MAGIX media database; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [2012-01-23 1858048]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2015-06-23 18856]
R2 Intel(R) PROSet Monitoring Service;Intel(R) PROSet Monitoring Service; C:\WINDOWS\system32\IProsetMonitor.exe [2020-06-23 575408]
R2 kpm_launch_service;Kaspersky Password Manager Service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [2020-09-22 351424]
R2 KSDE5.1;Služba Kaspersky Secure Connection 5.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe [2020-06-29 644312]
R2 MBAMService;Malwarebytes Service; C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe [2020-09-22 7185288]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2020-05-07 874472]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2020-10-01 885224]
R2 OneSyncSvc_3d657cb;Hostitel synchronizace_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 BthAvctpSvc;@%SystemRoot%\system32\BthAvctpSvc.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 camsvc;@%SystemRoot%\system32\CapabilityAccessManager.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 cbdhsvc_3d657cb;Uživatelská služba schránky_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2020-02-09 4506728]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 InstallService;@%SystemRoot%\system32\InstallService.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
R3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
R3 PimIndexMaintenanceSvc_3d657cb;Data kontaktů_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S2 edgeupdate;Služba Microsoft Edge Update (edgeupdate); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-06-10 224160]
S2 gupdate;Služba Aktualizace Google (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-07 153752]
S2 HPSmartDeviceAgentBase;HPSmartDeviceAgentBase; c:\Program Files (x86)\HP\HPSmartDeviceAgentBase\Service\HPSmartDeviceAgentBase.exe [2017-10-25 68608]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 AarSvc;@%SystemRoot%\system32\AarSvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 AarSvc_3d657cb;Agent Activation Runtime_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2020-09-09 335416]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 autotimesvc;@%SystemRoot%\System32\autotimesvc.dll,-6; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BcastDVRUserService;@%SystemRoot%\system32\BcastDVRUserService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BcastDVRUserService_3d657cb;Uživatelská služba pro GameDVR a vysílání her_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BluetoothUserService;@%SystemRoot%\system32\Microsoft.Bluetooth.UserService.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BluetoothUserService_3d657cb;Služba pro podporu uživatelů Bluetooth_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 BTAGService;@%SystemRoot%\system32\BTAGService.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CaptureService;@%SystemRoot%\system32\CaptureService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CaptureService_3d657cb;CaptureService_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 cbdhsvc;@%SystemRoot%\system32\cbdhsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 ConsentUxUserSvc;@%SystemRoot%\system32\ConsentUxClient.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 ConsentUxUserSvc_3d657cb;ConsentUX_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 CredentialEnrollmentManagerUserSvc;@%SystemRoot%\system32\CredentialEnrollmentManager.exe,-100; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [2020-07-16 381152]
S3 CredentialEnrollmentManagerUserSvc_3d657cb;CredentialEnrollmentManagerUserSvc_3d657cb; C:\WINDOWS\system32\CredentialEnrollmentManager.exe [2020-07-16 381152]
S3 DeviceAssociationBrokerSvc;@%SystemRoot%\system32\deviceaccess.dll,-107; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DeviceAssociationBrokerSvc_3d657cb;DeviceAssociationBroker_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicePickerUserSvc;@%SystemRoot%\system32\Windows.Devices.Picker.dll,-1006; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicePickerUserSvc_3d657cb;DevicePicker_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicesFlowUserSvc;@%SystemRoot%\system32\DevicesFlowBroker.dll,-103; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevicesFlowUserSvc_3d657cb;Tok zařízení_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2020-09-10 97792]
S3 diagsvc;@%systemroot%\system32\DiagSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 DisplayEnhancementService;@%SystemRoot%\System32\Microsoft.Graphics.Display.DisplayEnhancementService.dll,-1000; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 edgeupdatem;Služba Microsoft Edge Update (edgeupdatem); C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe [2020-06-10 224160]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-201; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2011-04-26 2702848]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2019-09-21 43704]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 GoogleChromeElevationService;Google Chrome Elevation Service; C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.75\elevation_service.exe [2020-10-05 1406448]
S3 GraphicsPerfSvc;@%SystemRoot%\system32\GraphicsPerfSvc.dll,-100; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 gupdatem;Služba Aktualizace Google (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-10-07 153752]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 IpxlatCfgSvc;@%Systemroot%\system32\ipxlatcfg.dll,-500; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 klvssbridge64_21.1;Kaspersky Volume Shadow Copy Service Bridge 21.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\vssbridge64.exe [2020-06-29 436168]
S3 LxpSvc;@%SystemRoot%\system32\LanguageOverlayServer.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MessagingService_3d657cb;Služba zasílání zpráv_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MicrosoftEdgeElevationService;Microsoft Edge Elevation Service; C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\elevation_service.exe [2020-10-08 1535376]
S3 MixedRealityOpenXRSvc;@%SystemRoot%\system32\MixedRealityRuntime.dll,-101; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2020-09-15 245968]
S3 NaturalAuthentication;@%systemroot%\system32\NaturalAuth.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2015-07-31 242864]
S3 OverwolfUpdater;Overwolf Updater Windows SCM; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2019-09-15 2431816]
S3 perceptionsimulation;@%systemroot%\system32\PerceptionSimulation\PerceptionSimulationService.exe,-101; C:\WINDOWS\system32\PerceptionSimulation\PerceptionSimulationService.exe [2019-03-19 103424]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PrintWorkflowUserSvc;@%SystemRoot%\system32\PrintWorkflowService.dll,-100; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PrintWorkflowUserSvc_3d657cb;PrintWorkflow_3d657cb; C:\WINDOWS\system32\svchost.exe [2019-03-19 53744]
S3 PushToInstall;@%SystemRoot%\system32\pushtoinstall.dll,-200; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; C:\WINDOWS\System32\svchost.exe [2019-03-19 53744]
S3 Rockstar Service;Rockstar Game Library Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [2019-11-28 474256]

-----------------EOF-----------------

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#9 Příspěvek od bojimso »

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04-10-2020
Ran by David (administrator) on DESKTOP-7D2FQ0G (10-10-2020 13:53:35)
Running from C:\Users\David\Desktop
Loaded Profiles: David
Platform: Windows 10 Home Version 1909 18363.1082 (X64) Language: Čeština (Česko)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe
(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
(Alexey Nicolaychuk -> ) C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(AVB Disc Soft, SIA -> Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DTShellHlp.exe
(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.exe <4>
(Blizzard Entertainment, Inc. -> Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.7212\Agent.exe
(Google Inc -> Google Inc.) C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe <16>
(Intel Corporation - Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation - Rapid Storage Technology -> Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksdeui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avp.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avpui.exe
(Kaspersky Lab -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\plugins_nms.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe
(Kaspersky Lab JSC -> AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\transport_proxy.exe
(Kaspersky Lab JSC -> Kaspersky Lab AO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\plugin-nm-server-v2.exe
(MAGIX AG) [File not signed] C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes Inc -> Malwarebytes) C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.2008.2.0_x64__8wekyb3d8bbwe\Calculator.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\cmd.exe <2>
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc) C:\Windows\System32\TiltWheelMouse.exe
(MICRO-STAR INTERNATIONAL CO., LTD. -> ) C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
(ND_Apps -> Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Nota Inc. -> Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe <2>
(NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe <2>
(Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\upc.exe
(Ubisoft Entertainment Sweden AB -> Ubisoft) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\UplayWebCore.exe

==================== Registry (Whitelisted) ===================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16404224 2015-09-17] (Realtek Semiconductor Corp -> Realtek Semiconductor)
HKLM\...\Run: [MouseDriver] => C:\Windows\system32\TiltWheelMouse.exe [241152 2013-04-09] (Microsoft Windows Hardware Compatibility Publisher -> Pixart Imaging Inc)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation - Rapid Storage Technology -> Intel Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\System32\LogiLDA.dll [3942936 2018-11-02] (Logitech -> Logitech, Inc.)
HKLM\...\Run: [OODefragTray] => C:\Program Files\OO Software\Defrag\oodtray.exe
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [1384840 2018-10-04] (Nota Inc. -> Nota Inc.)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [Battle.net] => C:\Program Files (x86)\Battle.net\Battle.net.exe [1090024 2020-10-10] (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [30870200 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [TSMApplication] => C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe [1623040 2020-08-17] () [File not signed]
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [365160 2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [Ubisoft Game Launcher] => C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\Uplay.exe [471360 2020-10-06] (Ubisoft Entertainment Sweden AB -> Ubisoft)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [kpm.exe] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm.exe [659976 2020-08-24] (Kaspersky Lab -> AO Kaspersky Lab)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Run: [QMxNetworkSync] => C:\Program Files\Common Files\MAGIX Services\QMxNetworkSync\QMxNetworkSync.exe [414976 2018-07-05] (MAGIX Software GmbH -> MAGIX)
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\MountPoints2: {2f792c64-4b05-11ea-ab35-d05099ae28e2} - "E:\setup.exe"
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\MountPoints2: {99340521-9073-11ea-ab51-d05099ae28e2} - "F:\setup.exe"
HKLM\...\Windows x64\Print Processors\hpcpp190: C:\Windows\System32\spool\prtprocs\x64\hpcpp190.dll [651176 2016-08-26] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp196: C:\Windows\System32\spool\prtprocs\x64\hpcpp196.dll [758000 2017-02-14] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp215: C:\Windows\System32\spool\prtprocs\x64\hpcpp215.dll [770232 2018-03-04] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp220: C:\Windows\System32\spool\prtprocs\x64\hpcpp220.dll [772280 2018-08-20] (HP Inc. -> HP Inc.)
HKLM\...\Windows x64\Print Processors\hpcpp230: C:\Windows\System32\spool\prtprocs\x64\hpcpp230.dll [797832 2019-05-24] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HP Universal Print Monitor: C:\Windows\system32\HPMPW082.DLL [127624 2019-05-24] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HPMLM190: C:\Windows\system32\hpmlm190.dll [310968 2018-08-20] (HP Inc. -> HP Inc.)
HKLM\...\Print\Monitors\HPMLM225: C:\Windows\system32\hpmlm225.dll [315528 2019-05-24] (HP Inc. -> HP Inc.)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\86.0.4240.75\Installer\chrmstp.exe [2020-10-07] (Google LLC -> Google LLC)
Startup: C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\chrome.lnk [2018-09-27]
ShortcutTarget: chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION

==================== Scheduled Tasks (Whitelisted) ============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0C9BA02D-C39F-4C25-8CB3-FFAA5F64BEB1} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {1D44E45C-F9EE-4ECE-90F1-7189A0084E5A} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3292984 2020-06-25] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {3906E0B8-DDDB-4B33-BFC5-F96E879E4D20} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office16\OLicenseHeartbeat.exe [316632 2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
Task: {40FE9DE1-5C5B-42D5-9679-6D13C2740EA9} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [25492152 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {430FEE59-1EE2-4DCE-A592-ABAC966AB81B} - System32\Tasks\Opera scheduled Autoupdate 1593648143 => C:\Users\David\AppData\Local\Programs\Opera\launcher.exe
Task: {4B515F5D-9B31-4DAD-ACFE-E132DDB5DAE8} - System32\Tasks\BlueStacksHelper => C:\ProgramData\BlueStacks\Client\Helper\BlueStacksHelper.exe [752136 2020-10-08] (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
Task: {4B5CFAC6-2DD7-4CAD-B746-784FEAC2AB2D} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [647656 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {506690E8-DEF1-4C8C-9D73-A16FC880A186} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [791232 2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
Task: {66A26C5D-66A1-4D78-BACB-C084A30CA59E} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-09-22] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {6EB8F908-0B98-49D7-A217-69D5C56EBB99} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-09-09] (Adobe Inc. -> Adobe)
Task: {7652206C-2203-4482-954C-355BC828E30D} - System32\Tasks\Mozilla\Firefox Default Browser Agent E7CF176E110C211B => C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe [660688 2020-09-15] (Mozilla Corporation -> Mozilla Foundation)
Task: {90ACD96A-3CAD-4FEB-9905-3D55610C20E8} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {9511A6F5-077F-4226-8E8A-A5D8D8C2693F} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [907240 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {952FF45B-D9C8-4257-8405-056578353803} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2018-10-04] (Nota Inc. -> Nota Inc.)
Task: {9B967109-11E3-40F9-8BAF-4E092812CD25} - System32\Tasks\Connect => C:\Program Files (x86)\MAGIX\Connect\connect.exe [324680 2017-05-10] (MAGIX Software GmbH -> MAGIX Software GmbH)
Task: {A5B5260C-77E7-4D9C-8B1F-EA765912E378} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A651D882-FF47-458A-A8A3-699C8A1EC3F1} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {A759CB3C-5883-47B3-A04F-A8F5F7D93DC5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {AAD9007D-86CF-4D71-8C84-F8DC236703DF} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_433_pepper.exe [1497656 2020-09-09] (Adobe Inc. -> Adobe)
Task: {B6494C7C-46FF-4944-94A3-1209C263C877} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2018-10-04] (Nota Inc. -> Nota Inc.)
Task: {B7273D46-8111-4D96-8B76-B2F2F6682273} - System32\Tasks\MSIAfterburner => C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe [781808 2019-04-21] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
Task: {C2ABD97E-15AB-4077-BF0B-1F73CC68256D} - System32\Tasks\Opera scheduled assistant Autoupdate 1593648148 => C:\Users\David\AppData\Local\Programs\Opera\launcher.exe
Task: {CBE51F93-5848-4293-8E76-337D9F0733E6} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [874472 2020-05-07] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {D3936408-0C8F-4EEA-BD6E-385B1F471175} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {E2D294D6-E4D9-4AC0-98DB-381910868B51} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1126888 2020-06-23] (NVIDIA Corporation -> NVIDIA Corporation)
Task: {F10A0FAB-3E61-40F4-BB5B-A9E623F7C0E9} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2431816 2019-09-15] (Overwolf Ltd -> Overwolf LTD)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Connect.job => C:\Program Files (x86)\MAGIX\Connect\connect.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 93.89.159.2 1.1.1.1
Tcpip\..\Interfaces\{7c9dc72d-d055-4562-a383-1580067a83d0}: [NameServer] 8.8.8.8,8.8.4.4
Tcpip\..\Interfaces\{fab8b2ab-1c3a-43d1-9408-9e478ed961cb}: [DhcpNameServer] 93.89.159.2 1.1.1.1

Edge:
======
Edge DefaultProfile: Default
Edge Profile: C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default [2020-09-19]
Edge Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Local\Microsoft\Edge\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2020-09-09]
Edge HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\SOFTWARE\Microsoft\Edge\Extensions\...\Edge\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm]

FireFox:
========
FF DefaultProfile: 3911gjs4.default
FF ProfilePath: C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\3911gjs4.default [2020-09-29]
FF Homepage: Mozilla\Firefox\Profiles\3911gjs4.default -> hxxps://www.facebook.com/
FF Notifications: Mozilla\Firefox\Profiles\3911gjs4.default -> hxxps://www.facebook.com
FF Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Roaming\Mozilla\Firefox\Profiles\3911gjs4.default\Extensions\light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com.xpi [2020-09-15]
FF HKLM\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\FFExt\light_plugin_firefox\addon.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [light_plugin_7571494CE0B94E11BB762B659A4AD71F@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\FFExt\light_plugin_firefox\addon.xpi => not found
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=4.0.0-dev -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-12-10] (VideoLAN) [File not signed]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\Office16\NPSPWRAP.DLL [2015-07-31] (Microsoft Corporation -> Microsoft Corporation)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\kl_prefs_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.js [2020-09-15] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\kl_config_62fbb8f7_c917_4cf7_957a_aad2b8fa768c.cfg [2020-09-15] <==== ATTENTION

Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Default [2020-10-10]
CHR DownloadDir: C:\Users\David\Desktop
CHR Notifications: Default -> hxxps://www.misthub.com; hxxps://www.youtube.com
CHR HomePage: Default -> hxxp://facebook.com/
CHR StartupUrls: Default -> "hxxp://facebook.com/"
CHR Extension: (Ochrana Kaspersky) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahkjpbeeocnddjkakilopmfdlnjdpcdm [2020-09-07]
CHR Extension: (BetterTTV) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2020-10-06]
CHR Extension: (uBlock Origin) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2020-10-08]
CHR Extension: (Kaspersky Password Manager) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhnkblpjbkfklfloegejegedcafpliaa [2020-10-09]
CHR Extension: (Darkness - Beautiful Dark Themes) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\imilbobhamcfahccagbncamhpnbkaenm [2019-05-24]
CHR Extension: (Twitch Now) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk [2020-06-30]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-03]
CHR Extension: (Global Twitch Emotes) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgniedifoejifjkndekolimjeclnokkb [2020-06-15]
CHR Extension: (Chrome Media Router) - C:\Users\David\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-10-07]
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\Guest Profile [2020-07-22]
CHR Profile: C:\Users\David\AppData\Local\Google\Chrome\User Data\System Profile [2018-11-28]
CHR HKLM\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/ahkjpbeeocnddjkakilopmfdlnjdpcdm
CHR HKLM-x32\...\Chrome\Extension: [ahkjpbeeocnddjkakilopmfdlnjdpcdm] - hxxps://chrome.google.com/webstore/detail/ahkjpbeeocnddjkakilopmfdlnjdpcdm

==================== Services (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 AdobeFlashPlayerUpdateSvc; C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-09-09] (Adobe Inc. -> Adobe)
R2 AVP21.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\avp.exe [381968 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [4506728 2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]
S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]
S2 HPSmartDeviceAgentBase; c:\Program Files (x86)\HP\HPSmartDeviceAgentBase\Service\HPSmartDeviceAgentBase.exe [68608 2017-10-25] () [File not signed]
S3 klvssbridge64_21.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\vssbridge64.exe [436168 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R2 kpm_launch_service; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 9.0.2\kpm_service.exe [351424 2020-09-22] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R2 KSDE5.1; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe [644312 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes\Anti-Malware\MBAMService.exe [7185288 2020-09-22] (Malwarebytes Inc -> Malwarebytes)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2019-02-01] (HP Inc.) [File not signed]
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2431816 2019-09-15] (Overwolf Ltd -> Overwolf LTD)
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2019-02-01] (HP Inc.) [File not signed]
S3 Rockstar Service; C:\Program Files\Rockstar Games\Launcher\RockstarService.exe [474256 2019-11-28] (Rockstar Games, Inc. -> Rockstar Games)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [4098056 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [113992 2019-03-19] (Microsoft Corporation -> Microsoft Corporation)

===================== Drivers (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 AsrAppCharger; C:\WINDOWS\system32\DRIVERS\AsrAppCharger.sys [17192 2011-11-07] (ASROCK Incorporation -> Windows (R) Win 7 DDK provider)
R2 BlueStacksDrv; C:\Program Files\BlueStacks\BstkDrv_bgp.sys [315976 2020-06-13] (Bluestack Systems, Inc -> Bluestack System Inc.)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [248504 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
S3 DESerialPort; C:\WINDOWS\system32\DRIVERS\DimensionSerialPort.sys [24576 2016-11-12] (Dimension Engineering LLC -> )
R3 dtlitescsibus; C:\WINDOWS\System32\drivers\dtlitescsibus.sys [42256 2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R3 dtliteusbbus; C:\WINDOWS\System32\drivers\dtliteusbbus.sys [59360 2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [153312 2020-09-22] (Malwarebytes Corporation -> Malwarebytes)
S3 HPEWSFXBULK; C:\WINDOWS\system32\drivers\hpfx64bulk.sys [29248 2016-09-13] (Hewlett-Packard Company -> Hewlett Packard)
R1 klbackupdisk; C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys [104712 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [205048 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [121088 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [37496 2020-06-29] (Microsoft Windows Early Launch Anti-malware Publisher -> AO Kaspersky Lab)
R1 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [509184 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klgse; C:\WINDOWS\System32\DRIVERS\klgse.sys [643840 2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klhk; C:\WINDOWS\system32\DRIVERS\klhk.sys [1277704 2020-06-26] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klids; C:\ProgramData\Kaspersky Lab\AVP21.1\Bases\klids.sys [240728 2020-09-15] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [984320 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klim6; C:\WINDOWS\system32\DRIVERS\klim6.sys [87808 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [106768 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [106752 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [79104 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klpnpflt; C:\WINDOWS\system32\DRIVERS\klpnpflt.sys [90368 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R3 kltap; C:\WINDOWS\System32\drivers\kltap.sys [55592 2020-06-29] (AnchorFree Inc -> The OpenVPN Project)
R0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [256760 2020-09-07] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_kimul; C:\WINDOWS\System32\Drivers\klupd_klif_kimul.sys [99152 2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
R3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [309768 2020-09-07] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [117512 2020-09-07] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [206888 2020-09-07] (Kaspersky Lab JSC -> AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [133888 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [242944 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [279824 2020-06-29] (Kaspersky Lab -> AO Kaspersky Lab)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [217592 2020-10-10] (Malwarebytes Inc -> Malwarebytes)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [19912 2020-09-22] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [197280 2020-10-10] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [73880 2020-10-10] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [248968 2020-10-10] (Malwarebytes Inc -> Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\DRIVERS\mwac.sys [131232 2020-10-10] (Malwarebytes Inc -> Malwarebytes)
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2017-08-27] (MICRO-STAR INTERNATIONAL CO., LTD. -> )
R2 speedfan; C:\WINDOWS\SysWOW64\speedfan.sys [28664 2012-12-29] (SOKNO S.R.L. -> Almico Software)
S3 t_mouse.sys; C:\WINDOWS\system32\DRIVERS\t_mouse.sys [6144 2013-04-09] (Microsoft Windows Hardware Compatibility Publisher -> )
R3 VBAudioVMAUXVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmauxvaio64_win10.sys [71920 2020-08-05] (Vincent Burel -> Windows (R) Win 7 DDK provider)
R3 VBAudioVMVAIOMME; C:\WINDOWS\System32\drivers\vbaudio_vmvaio64_win10.sys [71712 2020-08-05] (Vincent Burel -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [46472 2019-03-19] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [333784 2019-03-19] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [62432 2019-03-19] (Microsoft Windows -> Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ===================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-08 17:34 - 2020-10-10 10:09 - 000217592 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2020-10-08 17:34 - 2020-10-10 10:09 - 000197280 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2020-10-08 17:34 - 2020-10-10 10:09 - 000131232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2020-10-08 17:34 - 2020-10-10 10:09 - 000073880 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2020-10-08 04:22 - 2020-10-02 02:54 - 001769688 _____ C:\WINDOWS\system32\vulkaninfo-1-999-0-0-0.exe
2020-10-08 04:22 - 2020-10-02 02:54 - 001769688 _____ C:\WINDOWS\system32\vulkaninfo.exe
2020-10-08 04:22 - 2020-10-02 02:54 - 001370328 _____ C:\WINDOWS\SysWOW64\vulkaninfo-1-999-0-0-0.exe
2020-10-08 04:22 - 2020-10-02 02:54 - 001370328 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2020-10-08 04:22 - 2020-10-02 02:54 - 001054936 _____ C:\WINDOWS\system32\vulkan-1-999-0-0-0.dll
2020-10-08 04:22 - 2020-10-02 02:54 - 001054936 _____ C:\WINDOWS\system32\vulkan-1.dll
2020-10-08 04:22 - 2020-10-02 02:54 - 000917728 _____ C:\WINDOWS\SysWOW64\vulkan-1-999-0-0-0.dll
2020-10-08 04:22 - 2020-10-02 02:54 - 000917728 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2020-10-08 04:22 - 2020-10-02 02:54 - 000455408 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2020-10-08 04:22 - 2020-10-02 02:54 - 000351128 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2020-10-08 04:22 - 2020-10-02 02:52 - 001507224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2020-10-08 04:22 - 2020-10-02 02:52 - 001161112 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2020-10-08 04:22 - 2020-10-02 02:52 - 000816368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmcumd.dll
2020-10-08 04:22 - 2020-10-02 02:52 - 000673520 _____ C:\WINDOWS\system32\nvofapi64.dll
2020-10-08 04:22 - 2020-10-02 02:52 - 000670616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2020-10-08 04:22 - 2020-10-02 02:52 - 000555248 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2020-10-08 04:22 - 2020-10-02 02:52 - 000543128 _____ C:\WINDOWS\SysWOW64\nvofapi.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 007707544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 006860184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 004174064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 002508528 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 002098072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 001731824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6445671.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 001585560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 001482992 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6445671.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 000813464 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2020-10-08 04:22 - 2020-10-02 02:51 - 000657304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2020-10-08 02:06 - 2020-10-10 11:15 - 000000000 ____D C:\Users\David\AppData\LocalLow\IGDump
2020-10-07 11:15 - 2020-10-07 11:15 - 000000000 ____D C:\Users\David\AppData\Local\QMxNetworkSync
2020-10-07 11:11 - 2020-10-07 11:11 - 000001327 _____ C:\Users\Public\Desktop\MAGIX Photo Manager Deluxe.lnk
2020-10-07 11:11 - 2020-10-07 11:11 - 000000000 ____D C:\Users\Public\Documents\MAGIX
2020-10-07 11:11 - 2020-10-07 11:11 - 000000000 ____D C:\Users\David\AppData\Local\Xara
2020-10-07 11:10 - 2020-10-08 17:34 - 000000376 _____ C:\WINDOWS\Tasks\Connect.job
2020-10-07 11:10 - 2020-10-07 11:15 - 000000000 ____D C:\ProgramData\MAGIX
2020-10-07 11:10 - 2020-10-07 11:12 - 000000000 ____D C:\Program Files\Common Files\MAGIX Services
2020-10-07 11:10 - 2020-10-07 11:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAGIX
2020-10-07 11:10 - 2020-10-07 11:11 - 000000000 ____D C:\Program Files (x86)\MAGIX
2020-10-07 11:10 - 2020-10-07 11:10 - 000002804 _____ C:\WINDOWS\system32\Tasks\Connect
2020-10-07 11:10 - 2020-10-07 11:10 - 000000000 ___RD C:\Users\David\Documents\MAGIX
2020-10-07 11:10 - 2020-10-07 11:10 - 000000000 ____D C:\ProgramData\simplitec
2020-10-07 11:10 - 2020-10-07 11:10 - 000000000 ____D C:\Program Files (x86)\MSXML 4.0
2020-10-07 06:23 - 2020-10-07 11:17 - 000000000 ____D C:\AdwCleaner
2020-10-07 06:23 - 2020-10-07 06:23 - 008414384 _____ (Malwarebytes) C:\Users\David\Desktop\adwcleaner_8.0.7.exe
2020-10-05 08:29 - 2020-10-05 13:02 - 000000000 ____D C:\Users\David\Desktop\Terezka96
2020-10-04 18:30 - 2020-10-04 18:31 - 000058294 _____ C:\Users\David\Desktop\Addition.txt
2020-10-04 18:29 - 2020-10-10 13:54 - 000028561 _____ C:\Users\David\Desktop\FRST.txt
2020-10-04 18:25 - 2020-10-10 13:53 - 000000000 ____D C:\FRST
2020-10-04 18:25 - 2020-10-10 13:52 - 000000000 ____D C:\Program Files\trend micro
2020-10-04 18:25 - 2020-10-07 11:17 - 000000000 ____D C:\rsit
2020-10-04 18:24 - 2020-10-04 18:25 - 002299392 _____ (Farbar) C:\Users\David\Desktop\FRST64.exe
2020-10-04 18:24 - 2020-10-04 18:24 - 001222144 _____ C:\Users\David\Desktop\RSITx64.exe
2020-09-29 19:54 - 2020-09-29 19:54 - 000000000 ____D C:\WINDOWS\system32\Tasks\Mozilla
2020-09-28 23:32 - 2020-09-28 23:32 - 000000000 ____D C:\WINDOWS\LastGood
2020-09-27 09:37 - 2020-09-27 09:37 - 000143740 _____ C:\Users\David\Desktop\passy.jpeg
2020-09-27 03:06 - 2020-09-27 03:06 - 000536374 _____ C:\Users\David\Desktop\leni.jpeg
2020-09-25 02:43 - 2020-09-26 03:27 - 000000918 _____ C:\Users\David\Desktop\Serious Sam HD The First Encounter.lnk
2020-09-25 02:43 - 2020-09-25 02:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serious Sam HD The First Encounter
2020-09-22 17:16 - 2020-10-10 10:09 - 000248968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2020-09-22 17:16 - 2020-09-22 17:15 - 000019912 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamElam.sys
2020-09-18 03:54 - 2020-09-18 03:55 - 000000000 ____D C:\WINDOWS\LastGood.Tmp
2020-09-18 03:53 - 2020-09-15 00:13 - 000038816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2020-09-15 20:57 - 2020-10-07 06:25 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-09-14 20:26 - 2020-09-14 20:26 - 000000910 _____ C:\Users\David\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2020-09-10 00:29 - 2020-09-10 00:29 - 005503488 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 004309504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000941568 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000928768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFS.exe
2020-09-10 00:29 - 2020-09-10 00:29 - 000724480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapi.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000709632 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFSR.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000522752 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000415232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMPOSE.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000408576 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000338944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fveapibase.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOVER.exe
2020-09-10 00:29 - 2020-09-10 00:29 - 000181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSUTILITY.dll
2020-09-10 00:29 - 2020-09-10 00:29 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2020-09-10 00:29 - 2020-09-10 00:29 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\system32\FXSCOMPOSERES.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 032928920 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 031598936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 025444864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 022642176 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 019852288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 019812864 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramWorld.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 018032128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 009926456 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 007910152 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007845080 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007761408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007604584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007582768 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007284736 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 007271232 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006526448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006304256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006233080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006170624 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 006069360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005907456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005848848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005767744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005284328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005041152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 005003832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004859904 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004605952 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004565248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 004538368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004470272 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 004129416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004048384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 004005888 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003822592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003805696 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003740456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneCoreUAPCommonProxyStub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003727872 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 003714048 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003581240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 003547136 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003525608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003501568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003371176 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003365376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 003265024 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003136000 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 003084800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002986808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 002870784 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002799104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 002774088 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002772616 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002711552 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 002697536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 002585032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002576896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002565120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002494752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002483712 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002454904 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002422384 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 002315472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002306048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002291712 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002260824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002259680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002230240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002138264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 002090280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002073600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 002060288 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdprt.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001999968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001957552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001942016 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001930752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001918464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001885184 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001784832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001767424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001751040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001750016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001746232 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001743680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001726264 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001704960 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001698816 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001688064 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001672544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001670144 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001664696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001653792 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001610240 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001522176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001521664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001512960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdprt.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001499136 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001491160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001486848 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocoreworker.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001485824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001480520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 001459200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001421392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001399216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001397560 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001393960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001369088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001326592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001307464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContentDeliveryManager.Utilities.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001274128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryPS.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001272160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001260752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001247744 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 001246208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001218424 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001182720 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001182208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001170960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001151808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001149712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001141048 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001138688 _____ (Microsoft Corporation) C:\WINDOWS\system32\nettrace.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001124864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001108384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001099600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001098720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001092096 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001077048 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 001054160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001039872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 001012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001009200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 001008952 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000981320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000978232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PCPKsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000944680 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000932256 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000894032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000893104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000892728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000882688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000874296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000867328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000858928 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000851968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000844088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Language.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000841216 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000823752 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000822784 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000817152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\PEAuth.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000783496 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000777216 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000775768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000775480 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000768504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000748384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000744240 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000738072 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000722072 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000716304 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000705536 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000701440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000682752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOE.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000675840 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000675032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000671560 _____ (Microsoft Corporation) C:\WINDOWS\system32\computecore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000670720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000667312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PCPKsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000666288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000661832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000632320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000628400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000621568 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000609280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000600064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000593480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfh264enc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000578048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ddraw.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000574976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfh264enc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000572208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000564480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StateRepository.Core.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000561464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000555320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Vid.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000553664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000553472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000550400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000544336 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\usosvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000537608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000533504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000530432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\nltest.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000528896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ddraw.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000525824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000516608 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000510792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64win.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000506880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000499200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.FileExplorer.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000492032 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000477496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2020-09-10 00:28 - 2020-09-10 00:28 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000466352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000462848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000460192 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000457216 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnphost.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000457016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000435200 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\MicrosoftAccountExtension.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000422008 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000420168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Lights.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000410624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000404480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000400696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000392704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Search.ProtocolHandler.MAPI2.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000379904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000375096 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000372536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000368128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000363128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000356160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthAgent.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000332800 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnphost.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000328192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000324608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000324408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000315904 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenterprisediagnostics.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000308736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000307712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000299520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000299072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000294728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000294400 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcore6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000292864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Lights.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000285056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000283136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000279552 _____ (Microsoft Corporation) C:\WINDOWS\system32\smbwmiv2.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\pdh.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\scecli.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000273208 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstext40.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000272384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DAFMCP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000265216 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000260408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcore6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateDeploymentProvider.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnservice.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000254776 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000250680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000249856 _____ (Microsoft Corporation) C:\WINDOWS\system32\FileHistory.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000245248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pdh.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000244736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFilterHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000240128 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpsrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000233472 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000224768 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000224072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelppm.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000224064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000219136 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000214016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scecli.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000213824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000211968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFilterHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000211256 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcbloader.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000209216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000208712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\processr.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000205640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000201544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdppm.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000200704 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000200008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\amdk8.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000197632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Win32CompatibilityAppraiserCSP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000179712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000179512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000170496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000165184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000163840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BitLockerCsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidpolicyconverter.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000152064 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWSD.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapistub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapi32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000146640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000146248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000142152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000139776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakrathunk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000136192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnscmmc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000132408 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000131896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mup.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcDecoderHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000128512 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssitlb.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWSD.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000127064 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32u.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000124416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnscmmc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptcatsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\samlib.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatecsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapistub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000120832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mapi32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000113152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssitlb.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000108856 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdSSDP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000108032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000105472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakrathunk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000104248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000099328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000093496 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000092672 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000090944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryBroker.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000090936 _____ (Microsoft Corporation) C:\WINDOWS\system32\vid.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000089344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32u.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdSSDP.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000084992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\samlib.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000084280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvservice.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dtdump.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000079576 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhuxgraphics.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\CustomInstallExec.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000076800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000070144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\udhisapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\dhcpcsvc6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000066872 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ssdpapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000065024 _____ (Microsoft Corporation) C:\WINDOWS\system32\rtutils.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iemigplugin.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000063296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthHost.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf3216.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssprxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\msscntrs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000059392 _____ C:\WINDOWS\system32\runexehelper.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000059192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storufs.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\udhisapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dhcpcsvc6.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000057888 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndiscap.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000053760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rtutils.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\tar.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000050688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NAPCRYPT.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edpnotify.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000047104 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfctrs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000047008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf3216.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msscntrs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\cmintegrator.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfproc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000044032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NAPCRYPT.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000043520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tar.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfctrs.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfdisk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\upnpcont.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfos.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfproc.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfdisk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wslapi.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfos.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BtaMPM.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\upnpcont.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryCore.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\FaxPrinterInstaller.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\KNetPwrDepBroker.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cmintegrator.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspisrv.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\perfnet.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimsg.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimsg.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidtel.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perfnet.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdiagnostics.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000021504 _____ (Microsoft Corporation) C:\WINDOWS\system32\fixmapi.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000021304 _____ (Microsoft Corporation) C:\WINDOWS\system32\kdhvcom.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidtel.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidcertstorecheck.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\applockerfltr.sys
2020-09-10 00:28 - 2020-09-10 00:28 - 000016384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fixmapi.exe
2020-09-10 00:28 - 2020-09-10 00:28 - 000015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\KBDJPN.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000013824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDJPN.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000013312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KBDKOR.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000008704 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\msimg32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd106n.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000008192 _____ (Microsoft Corporation) C:\WINDOWS\system32\kbd101.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106n.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd106.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000007680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kbd101.DLL
2020-09-10 00:28 - 2020-09-10 00:28 - 000007168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msimg32.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6r.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3r.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tier2punctuations.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6r.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3r.dll
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth9.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth8.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth7.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth6.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth5.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth4.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth3.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth2.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth12.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth11.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth10.bin
2020-09-10 00:28 - 2020-09-10 00:28 - 000000315 _____ C:\WINDOWS\system32\DrtmAuth1.bin
2020-09-10 00:21 - 2020-08-15 07:25 - 000492544 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2020-09-10 00:21 - 2020-08-15 07:15 - 000390656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe

==================== One month (modified) ==================

(If an entry is included in the fixlist, the file/folder will be moved.)

2020-10-10 13:51 - 2020-08-15 09:49 - 000000000 ____D C:\Users\David\AppData\Roaming\qBittorrent
2020-10-10 13:50 - 2016-10-15 02:40 - 000000000 ____D C:\Users\David\AppData\Local\Battle.net
2020-10-10 13:49 - 2019-03-19 06:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-10-10 12:35 - 2019-09-21 13:31 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-10-10 12:25 - 2017-08-17 09:21 - 000000000 ____D C:\ProgramData\NVIDIA
2020-10-10 07:38 - 2016-10-15 02:35 - 000000000 ____D C:\Program Files (x86)\Battle.net
2020-10-10 07:36 - 2017-12-11 07:31 - 000000000 ____D C:\Users\David\AppData\Roaming\vlc
2020-10-10 07:05 - 2020-06-10 12:31 - 000002436 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Edge.lnk
2020-10-10 07:04 - 2020-06-10 12:31 - 000003584 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
2020-10-10 07:04 - 2020-06-10 12:31 - 000003460 _____ C:\WINDOWS\system32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
2020-10-10 07:04 - 2016-10-24 21:54 - 000000000 ____D C:\Users\David\AppData\Local\Ubisoft Game Launcher
2020-10-09 19:27 - 2019-09-21 13:41 - 000003142 _____ C:\WINDOWS\system32\Tasks\MSIAfterburner
2020-10-09 17:55 - 2019-03-19 06:50 - 000000000 ____D C:\WINDOWS\INF
2020-10-09 10:40 - 2019-12-05 05:00 - 000003946 _____ C:\WINDOWS\system32\Tasks\BlueStacksHelper
2020-10-09 01:37 - 2019-03-19 06:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-10-09 01:37 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-10-09 01:36 - 2019-09-21 13:42 - 001695456 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-10-09 01:36 - 2019-03-19 13:55 - 000716944 _____ C:\WINDOWS\system32\perfh005.dat
2020-10-09 01:36 - 2019-03-19 13:55 - 000145024 _____ C:\WINDOWS\system32\perfc005.dat
2020-10-08 17:34 - 2019-09-21 13:41 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-10-08 17:34 - 2019-03-19 06:37 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2020-10-08 00:49 - 2017-07-12 22:01 - 000000000 ____D C:\Program Files (x86)\MSI Afterburner
2020-10-07 12:15 - 2019-03-19 06:37 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2020-10-07 11:17 - 2020-05-14 22:08 - 000000000 ____D C:\PerfLogs
2020-10-07 11:17 - 2017-07-21 14:24 - 000000000 ___HD C:\$AV_ASW
2020-10-07 11:17 - 2016-12-26 15:43 - 000000000 ____D C:\World of Warcraft
2020-10-07 06:26 - 2017-07-12 22:11 - 000000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server
2020-10-07 06:25 - 2016-10-25 00:27 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2020-10-07 05:29 - 2016-10-07 13:13 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-10-07 00:47 - 2017-03-31 01:14 - 000000000 ____D C:\Users\David\AppData\Roaming\Curse Client
2020-10-06 22:45 - 2016-10-20 22:47 - 000000000 ____D C:\Users\David\AppData\Local\Personify
2020-10-05 23:51 - 2019-11-22 10:41 - 000095802 _____ C:\Users\David\Desktop\trollings.txt
2020-10-05 04:30 - 2017-11-18 22:32 - 000000000 ____D C:\Users\David\AppData\Local\Packages
2020-10-02 02:49 - 2020-07-17 05:08 - 005972824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2020-10-02 02:49 - 2019-09-11 15:25 - 007001536 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2020-10-01 09:17 - 2019-09-11 15:25 - 000058620 _____ C:\WINDOWS\system32\nvinfo.pb
2020-10-01 07:19 - 2017-08-17 09:21 - 005510968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2020-10-01 07:19 - 2017-08-17 09:21 - 002635064 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2020-10-01 07:19 - 2017-08-17 09:21 - 001759032 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2020-10-01 07:19 - 2017-08-17 09:21 - 000992232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2020-10-01 07:19 - 2017-08-17 09:21 - 000195560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2020-10-01 07:19 - 2017-08-17 09:21 - 000122344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2020-10-01 07:19 - 2017-08-17 09:21 - 000083256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2020-10-01 00:26 - 2020-08-20 23:58 - 000000000 ____D C:\Program Files\Microsoft Update Health Tools
2020-09-30 12:06 - 2017-08-17 09:21 - 009339287 _____ C:\WINDOWS\system32\nvcoproc.bin
2020-09-30 01:16 - 2019-09-21 13:41 - 000003936 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-09-29 20:38 - 2018-03-15 11:00 - 000000000 ____D C:\Users\David\AppData\LocalLow\Mozilla
2020-09-29 19:54 - 2016-10-25 00:27 - 000001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-09-27 23:17 - 2020-07-09 19:16 - 000000000 ____D C:\Users\David\Desktop\Vaníček hlášky
2020-09-23 02:35 - 2020-08-27 23:50 - 000000000 ____D C:\Users\David\Documents\Stronghold Crusader
2020-09-22 17:16 - 2020-07-02 02:15 - 000002087 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes.lnk
2020-09-22 17:16 - 2019-03-19 06:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-09-22 17:15 - 2020-02-17 12:26 - 000153312 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2020-09-18 11:49 - 2019-09-21 13:34 - 000000000 ____D C:\Users\David
2020-09-18 03:55 - 2017-08-17 09:21 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2020-09-18 03:54 - 2017-08-17 09:20 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2020-09-16 20:51 - 2020-08-27 21:42 - 000675839 _____ C:\Users\David\Desktop\Životopis David Bejbl.pdf
2020-09-15 00:13 - 2019-09-11 15:25 - 001682368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2020-09-15 00:13 - 2019-09-11 15:25 - 000222112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2020-09-11 05:14 - 2019-06-08 15:30 - 000000000 ____D C:\Users\David\Desktop\Likeš, Kraken a Vágus memes
2020-09-10 18:14 - 2020-08-20 23:58 - 000905528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sedplugins.dll
2020-09-10 18:14 - 2020-08-20 23:58 - 000436536 _____ (Microsoft Corporation) C:\WINDOWS\system32\QualityUpdateAssistant.dll
2020-09-10 00:37 - 2017-11-18 22:39 - 000000000 ___RD C:\Users\David\3D Objects
2020-09-10 00:37 - 2016-04-27 08:39 - 000000000 __RHD C:\Users\Public\AccountPictures
2020-09-10 00:36 - 2019-09-21 13:31 - 000436632 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-09-10 00:36 - 2016-10-14 19:53 - 000000000 ____D C:\Program Files\WinRAR
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\PrintDialog
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\SystemResources
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\oobe
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\system32\migwiz
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\ShellExperiences
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\Provisioning
2020-09-10 00:35 - 2019-03-19 06:52 - 000000000 ____D C:\WINDOWS\bcastdvr
2020-09-10 00:35 - 2016-10-14 23:11 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-09-10 00:32 - 2019-03-19 06:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-09-10 00:32 - 2016-10-14 23:11 - 129170736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-09-10 00:28 - 2019-09-21 13:34 - 002876416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll

==================== Files in the root of some directories ========

2017-08-02 23:57 - 2018-04-05 16:53 - 000000006 _____ () C:\Users\David\AppData\Roaming\.nfe_lock
2020-08-10 04:39 - 2020-08-10 04:39 - 000034786 _____ () C:\Users\David\AppData\Roaming\VoiceMeeterBananaDefault.xml
2020-08-19 11:17 - 2020-08-19 11:28 - 000004596 _____ () C:\Users\David\AppData\Roaming\VoiceMeeterDefault.xml
2020-06-15 20:30 - 2020-06-21 13:21 - 000004608 _____ () C:\Users\David\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini

==================== SigCheck ============================

(There is no automatic fix for files that do not pass verification.)

==================== End of FRST.txt ========================

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#10 Příspěvek od bojimso »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-10-2020
Ran by David (10-10-2020 13:55:31)
Running from C:\Users\David\Desktop
Windows 10 Home Version 1909 18363.1082 (X64) (2019-09-21 11:41:31)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3482348820-1896476200-1895645591-500 - Administrator - Disabled)
David (S-1-5-21-3482348820-1896476200-1895645591-1002 - Administrator - Enabled) => C:\Users\David
DefaultAccount (S-1-5-21-3482348820-1896476200-1895645591-503 - Limited - Disabled)
Guest (S-1-5-21-3482348820-1896476200-1895645591-501 - Limited - Disabled)
Mamka (S-1-5-21-3482348820-1896476200-1895645591-1004 - Limited - Enabled) => C:\Users\bejja
WDAGUtilityAccount (S-1-5-21-3482348820-1896476200-1895645591-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: Kaspersky Total Security (Enabled - Up to date) {0AB30972-4BAC-7BEE-CBCA-B8F9E68797D8}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}
FW: Kaspersky Total Security (Enabled) {32888857-01C3-7AB6-E095-11CC1854D0A3}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (HKLM\...\{50229C72-539F-4E65-BEB5-F0491C5074B7}) (Version: 22.2.1 - HP Inc.) Hidden
Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.433 - Adobe)
Aktualizace NVIDIA 38.0.5.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 38.0.5.0 - NVIDIA Corporation) Hidden
APP Shop v1.0.21 (HKLM-x32\...\{90242E9B-BC60-46E3-8EE7-8E953F702280}_is1) (Version: 1.0.21 - ASRock Inc.)
ASRock App Charger v1.0.6 (HKLM\...\ASRock App Charger_is1) (Version: 1.0.6 - ASRock Inc.)
Assassin's Creed Odyssey (HKLM-x32\...\Uplay Install 5059) (Version: - Ubisoft)
Assassin's Creed Unity (HKLM-x32\...\Uplay Install 720) (Version: - Ubisoft)
Audacity 2.2.1 (HKLM-x32\...\Audacity_is1) (Version: 2.2.1 - Audacity Team)
Balíček ovladače systému Windows - Dimension Engineering USB Serial Converter (11/11/2016 1.0.3.21) (HKLM\...\377DE9679F7155ADE94AA4BCBF4CA02472B49707) (Version: 11/11/2016 1.0.3.21 - Dimension Engineering)
Batman - Arkham Origins (HKLM-x32\...\Batman - Arkham Origins_is1) (Version: - )
Batman Arkham Knight v.1.0.4.5 (HKLM-x32\...\Batman Arkham Knight_is1) (Version: - )
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
BlueStacks App Player (HKLM\...\BlueStacks) (Version: 4.215.0.1019 - BlueStack Systems, Inc.)
Browser (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Overwolf_jgbnfkaeklillfmfafgkodhlcnfdgkmjmjngaaof) (Version: 1.0.0.0 - Overwolf app)
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.75.1088 - AB Team, d.o.o.)
CCleaner (HKLM\...\CCleaner) (Version: 5.72 - Piriform)
Connect (HKLM-x32\...\MAGIX_connector_is1) (Version: 2.5.1.84 - MAGIX Software GmbH)
CPUID CPU-Z 1.92 (HKLM\...\CPUID CPU-Z_is1) (Version: 1.92 - CPUID, Inc.)
Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
Curse Client (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse)
Čeština do hry The Evil Within včetně 3 DLC v1.1 (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Čeština do hry The Evil Within včetně 3 DLC v1.1) (Version: - )
DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.12.0.1114 - Disc Soft Ltd)
Defraggler (HKLM\...\Defraggler) (Version: 2.22 - Piriform)
Deus Ex - Human Revolution version 1.0 (HKLM-x32\...\{1146E8F3-4057-4F46-B39C-D18AB4BB1523}_is1) (Version: 1.0 - Square Enix)
Diablo III (HKLM-x32\...\Diablo III) (Version: - Blizzard Entertainment)
Discord (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Discord) (Version: 0.0.306 - Discord Inc.)
ECigStats (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\ECigStats) (Version: - Evolv)
Epic Games Launcher (HKLM-x32\...\{C69A2919-0662-4390-9418-67C931B44C18}) (Version: 1.1.236.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
EScribe Suite (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\EScribe) (Version: - Evolv)
Fallout 4 v.1.1.30 (HKLM-x32\...\Fallout 4_is1) (Version: - )
Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)
foobar2000 v1.3.12 (HKLM-x32\...\foobar2000) (Version: 1.3.12 - Peter Pawlowski)
Game Summary (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Overwolf_nafihghfcpikebhfhdhljejkcifgbdahdhngepfb) (Version: 215.9.49 - Overwolf app)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 86.0.4240.75 - Google LLC)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.24.15 - Google Inc.) Hidden
gpedt.msc 1.0 (HKLM-x32\...\{10B9C608-BF7C-4CCF-A658-C01D969DCA21}_is1) (Version: - Richard)
GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
Gyazo 3.4.1.0 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)
HearthArena Companion (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Overwolf_eldaohcjmecjpkpdhhoiolhhaeapcldppbdgbnbc) (Version: 1.5.0.2 - Overwolf app)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Hearthstone Deck Tracker (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\HearthstoneDeckTracker) (Version: 1.6.9 - HearthSim)
HPSmartDeviceAgentBase (HKLM-x32\...\{F7270182-8AD0-420F-92A3-52438ED810A9}) (Version: 1.1.0.0 - HP Inc)
Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1162 - Intel Corporation)
Intel(R) Network Connections 25.2.0.0 (HKLM\...\PROSetDX) (Version: 25.2.0.0 - Intel)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel® Chipset Device Software (HKLM-x32\...\{c7f54569-0018-439c-809a-48046a4d4ebc}) (Version: 10.1.1.9 - Intel(R) Corporation) Hidden
JDownloader 2 (HKLM\...\jdownloader2) (Version: 2.0 - AppWork GmbH)
Kaspersky Password Manager (HKLM-x32\...\{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab) Hidden
Kaspersky Password Manager (HKLM-x32\...\InstallWIX_{B2F7333E-6C8D-4994-AAC4-FEC8EBBF9611}) (Version: 9.0.2.767 - Kaspersky Lab)
Kaspersky Secure Connection (HKLM-x32\...\{8E3A90F0-23D4-4761-AEBF-409CBBA48C80}) (Version: 21.1.15.500 - Kaspersky) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{8E3A90F0-23D4-4761-AEBF-409CBBA48C80}) (Version: 21.1.15.500 - Kaspersky)
Kaspersky Total Security (HKLM-x32\...\{0124CD8C-8A9A-4A95-BF8C-F084040A93CE}) (Version: 21.1.15.500 - Kaspersky) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{0124CD8C-8A9A-4A95-BF8C-F084040A93CE}) (Version: 21.1.15.500 - Kaspersky)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
League of Legends (HKLM-x32\...\{657DFCCF-B080-44B1-9AEA-61676011A1AE}) (Version: 4.1.2 - Riot Games) Hidden
League of Legends (HKLM-x32\...\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
League of Legends (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\Riot Game league_of_legends.live) (Version: - Riot Games, Inc)
Logitech-kameraindstillinger (HKLM-x32\...\LogiUCDPP) (Version: 1.1.87.0 - Logitech Europe S.A.)
MAGIX Cloud Import (HKLM\...\{54542D3F-4809-4F2E-ADA4-3B60281888C4}) (Version: 0.1.0.3 - MAGIX Software GmbH) Hidden
MAGIX Cloud Import (HKLM\...\MX.{54542D3F-4809-4F2E-ADA4-3B60281888C4}) (Version: 0.1.0.3 - MAGIX Software GmbH)
MAGIX Connect (HKLM\...\{03202DE9-DBCA-4D7C-A00B-470474575B1F}) (Version: 1.0.0.3 - MAGIX Software GmbH) Hidden
MAGIX Connect (HKLM\...\MX.{03202DE9-DBCA-4D7C-A00B-470474575B1F}) (Version: 1.0.0.3 - MAGIX Software GmbH)
MAGIX Photo Manager Deluxe (HKLM\...\{43922F0B-E668-47C8-846D-8AB17A59F8CE}) (Version: 13.1.1.4 - MAGIX Software GmbH) Hidden
MAGIX Photo Manager Deluxe (HKLM-x32\...\MX.{43922F0B-E668-47C8-846D-8AB17A59F8CE}) (Version: 13.1.1.4 - MAGIX Software GmbH)
MAGIX Slideshow Maker 2 (HKLM\...\{ADB6CF23-87C3-493D-A12D-DCE526E0418C}) (Version: 2.0.1.9 - MAGIX Software GmbH) Hidden
MAGIX Slideshow Maker 2 (HKLM-x32\...\MX.{ADB6CF23-87C3-493D-A12D-DCE526E0418C}) (Version: 2.0.1.9 - MAGIX Software GmbH)
MAGIX Speed burnR (HKLM\...\{4860F54D-7F49-4408-9F5E-FF6905DAE811}) (Version: 7.0.1.27 - MAGIX Software GmbH) Hidden
MAGIX Speed burnR (HKLM-x32\...\MX.{4860F54D-7F49-4408-9F5E-FF6905DAE811}) (Version: 7.0.1.27 - MAGIX Software GmbH)
Malwarebytes version 4.2.1.89 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 4.2.1.89 - Malwarebytes)
Microsoft Edge (HKLM-x32\...\Microsoft Edge) (Version: 86.0.622.38 - Microsoft Corporation)
Microsoft Edge Update (HKLM-x32\...\Microsoft Edge Update) (Version: 1.3.135.41 - )
Microsoft Office Professional Plus 2016 (HKLM\...\Office16.PROPLUS) (Version: 16.0.4266.1001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\OneDriveSetup.exe) (Version: 19.232.1124.0005 - Microsoft Corporation)
Microsoft Update Health Tools (HKLM\...\{97238E8A-4919-4A1E-965A-C6C36938F4CE}) (Version: 2.68.0.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x64) - 14.22.27821 (HKLM-x32\...\{6361b579-2795-4886-b2a8-53d5239b6452}) (Version: 14.22.27821.0 - Microsoft Corporation)
Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.22.27821 (HKLM-x32\...\{5bfc1380-fd35-4b85-9715-7351535d077e}) (Version: 14.22.27821.0 - Microsoft Corporation)
Mozilla Firefox 80.0.1 (x64 cs) (HKLM\...\Mozilla Firefox 80.0.1 (x64 cs)) (Version: 80.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 60.7.2 - Mozilla)
MSI Afterburner 4.6.1 (HKLM-x32\...\Afterburner) (Version: 4.6.1 - MSI Co., LTD)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
Nástroje kontroly pravopisu pro Microsoft Office 2016 – čeština (HKLM\...\{90160000-001F-0405-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
Nástroje korektúry balíka Microsoft Office 2016 - slovenčina (HKLM\...\{90160000-001F-041B-1000-0000000FF1CE}) (Version: 16.0.4266.1001 - Microsoft Corporation) Hidden
NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.27 - NVIDIA Corporation) Hidden
NVIDIA GeForce Experience 3.20.4.14 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.4.14 - NVIDIA Corporation)
NVIDIA Ovladač HD audia 1.3.38.35 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.35 - NVIDIA Corporation)
NVIDIA Ovladače grafiky 456.71 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 456.71 - NVIDIA Corporation)
NVIDIA Systémový software PhysX 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
NvModuleTracker (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvModuleTracker.Driver) (Version: 6.14.24033.38719 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 20.0.1 - OBS Project)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version: - )
Ori and the Blind Forest Definitive Edition (HKLM-x32\...\Ori and the Blind Forest Definitive Edition_is1) (Version: - )
Overwatch (HKLM-x32\...\Overwatch) (Version: - Blizzard Entertainment)
Overwolf (HKLM-x32\...\Overwolf) (Version: 0.135.0.24 - Overwolf Ltd.)
Ovládací panel NVIDIA 456.71 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel) (Version: 456.71 - NVIDIA Corporation) Hidden
Personify ChromaCam (remove only) (HKLM-x32\...\Personify ChromaCam) (Version: 1.1.6.7 - Personify, Inc.)
Photo Manager Deluxe Update (HKLM\...\{3E029B44-7B06-44D0-A627-E5E45F7CFEC0}) (Version: 13.1.1.12 - MAGIX Software GmbH) Hidden
PixelHealer (HKLM\...\PixelHealer) (Version: 1.5.0.30 - Aurelitec)
Posel smrti 1.2 (HKLM-x32\...\Posel smrti_is1) (Version: - Future Games s.r.o.)
Print Conductor 5.4 (HKLM-x32\...\Print Conductor_is1) (Version: 5.4 - fCoder SIA)
qBittorrent 4.2.5 (HKLM-x32\...\qBittorrent) (Version: 4.2.5 - The qBittorrent project)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7614 - Realtek Semiconductor Corp.)
Resident Evil 2 (HKLM-x32\...\Resident Evil 2_is1) (Version: - )
Resident Evil 7 Biohazard (HKLM-x32\...\{1ECBF8F3-7079-44CA-AD32-B2AECBCF636F}_is1) (Version: - Capcom)
RivaTuner Statistics Server 7.2.3 (HKLM-x32\...\RTSS) (Version: 7.2.3 - Unwinder)
Rockstar Games Launcher (HKLM-x32\...\Rockstar Games Launcher) (Version: 1.0.16.196 - Rockstar Games)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 2.0.4.3 - Rockstar Games)
Serious Sam HD The First Encounter (HKLM-x32\...\Serious Sam HD The First Encounter_is1) (Version: - )
Someday Youll Return (HKLM-x32\...\Someday Youll Return_is1) (Version: - )
Speccy (HKLM\...\Speccy) (Version: 1.32 - Piriform)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Streamlabs OBS (HKLM\...\029c4619-0385-5543-9426-46f9987161d9) (Version: 0.21.2 - General Workings, Inc.)
Stronghold Crusader 2 (HKLM-x32\...\1433852499_is1) (Version: 2.5.0.10 - GOG.com)
Stronghold Crusader HD Enhanced Edition (HKLM-x32\...\Stronghold Crusader HD Enhanced Edition_is1) (Version: - )
Stronghold HD (HKLM-x32\...\GOGPACKSTRONGHOLDHD_is1) (Version: 2.0.0.3 - GOG.com)
Super Seducer (HKLM\...\SKIDROW - Super Seducer) (Version: - SKIDROW)
SUPERHOT (HKLM-x32\...\1456141688_is1) (Version: 2.0.0.4 - GOG.com)
SUPERHOT MIND CONTROL DELETE (HKLM-x32\...\SUPERHOT MIND CONTROL DELETE_is1) (Version: - )
Syberia (HKLM-x32\...\{E34E9B33-46EC-4252-A52F-DDA3978CC0AF}) (Version: - )
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
The Walking Dead A New Frontier Episode 1 (HKLM-x32\...\The Walking Dead A New Frontier Episode 1_is1) (Version: - )
TradeSkillMaster Application version 1.0 (HKLM-x32\...\{c44da794-b956-4d50-8733-346d56ae63c7}_is1) (Version: 1.0 - TradeSkillMaster)
Twitch (HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 8.0.0 - Twitch Interactive, Inc.)
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition (HKLM\...\{90160000-0011-0000-1000-0000000FF1CE}_Office16.PROPLUS_{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}) (Version: - Microsoft)
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition (HKLM\...\{90160000-00C1-0000-1000-0000000FF1CE}_Office16.PROPLUS_{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}) (Version: - Microsoft)
Update for Skype for Business 2016 (KB3115268) 64-Bit Edition (HKLM\...\{90160000-012B-0405-1000-0000000FF1CE}_Office16.PROPLUS_{5D633E34-0FA8-4C3F-8A16-D1A6C33C7015}) (Version: - Microsoft)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{32DC821E-4A7D-4878-BEE8-337FA153D7F2}) (Version: 2.63.0.0 - Microsoft Corporation) Hidden
Uplay (HKLM-x32\...\Uplay) (Version: 4.9 - Ubisoft)
VLC media player (HKLM\...\VLC media player) (Version: 4.0.0-dev - VideoLAN)
Voicemeeter, The Virtual Mixing Console (HKLM-x32\...\VB:Voicemeeter {17359A74-1236-5467}) (Version: - VB-Audio Software)
VooPoo version 1.5.1.30 (HKLM-x32\...\{63EEAD1F-3FC8-40F5-A415-E4BE098004C0}_is1) (Version: 1.5.1.30 - KunShan XW-TEC)
VueScan x64 (HKLM\...\VueScan x64) (Version: 9.7.13 - Hamrick Software)
Warcraft III (HKLM-x32\...\Warcraft III) (Version: - Blizzard Entertainment)
Warframe (HKLM-x32\...\{72BD42A9-6701-42EB-B77A-2AFC0C499F5E}) (Version: 1.0.0 - Digital Extremes)
Watch_Dogs (HKLM-x32\...\Uplay Install 274) (Version: - Ubisoft)
WinRAR 5.91 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.91.0 - win.rar GmbH)
World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
World of Warcraft Classic (HKLM-x32\...\World of Warcraft Classic) (Version: - Blizzard Entertainment)

Packages:
=========
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.178.200.0_x86__kgqvnymyfvs32 [2020-10-02] (king.com)
Doplněk multimediálního modulu pro aplikaci Fotografie -> C:\Program Files\WindowsApps\Microsoft.Photos.MediaEngineDLC_1.0.0.0_x64__8wekyb3d8bbwe [2020-03-09] (Microsoft Corporation)
HP Smart -> C:\Program Files\WindowsApps\AD2F1837.HPPrinterControl_120.1.741.0_x64__v10z8vjag6ke6 [2020-10-09] (HP Inc.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-01-20] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.7.8101.0_x64__8wekyb3d8bbwe [2020-08-20] (Microsoft Studios) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2018-09-09] (Twitter Inc.)

==================== Custom CLSID (Whitelisted): ==============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3482348820-1896476200-1895645591-1002_Classes\CLSID\{9a338598-86a1-4119-8b66-9d52715b6a76}\InprocServer32 -> C:\Windows\system32\dfshim.dll (Microsoft Windows -> Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers1: [Kaspersky Anti-Virus 21.1] -> {091EC05A-4A09-4108-8D41-F7B1078DAA9E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\shellex.dll [2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [DaemonShellExtDriveLite] -> {C06369D6-E77D-4626-9656-1256312BD576} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers2: [Kaspersky Anti-Virus 21.1] -> {091EC05A-4A09-4108-8D41-F7B1078DAA9E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\shellex.dll [2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers3: [DaemonShellExtImageLite] -> {1D1B5D7B-0FC9-452E-902C-12BACD4FBC20} => C:\Program Files\DAEMON Tools Lite\dtshl64.dll [2020-02-09] (AVB Disc Soft, SIA -> Disc Soft Ltd)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbshlext.dll [2020-02-17] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers4: [Kaspersky Anti-Virus 21.1] -> {091EC05A-4A09-4108-8D41-F7B1078DAA9E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\shellex.dll [2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2020-10-01] (NVIDIA Corporation -> NVIDIA Corporation)
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2018-05-02] (Piriform Ltd -> Piriform Ltd)
ContextMenuHandlers6: [Kaspersky Anti-Virus 21.1] -> {091EC05A-4A09-4108-8D41-F7B1078DAA9E} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\shellex.dll [2020-09-07] (Kaspersky Lab -> AO Kaspersky Lab)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes\Anti-Malware\mbshlext.dll [2020-02-17] (Malwarebytes Corporation -> Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2020-08-25] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2020-08-25] (win.rar GmbH -> Alexander Roshal)

==================== Codecs (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\system32\frapsv64.dll [105984 2015-09-05] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\system32\rtvcvfw64.dll [246272 2012-09-28] () [File not signed]
HKLM\...\Drivers32: [VIDC.FPS1] => C:\Windows\SysWOW64\frapsvid.dll [94208 2015-09-05] (Beepa P/L) [File not signed]
HKLM\...\Drivers32: [VIDC.RTV1] => C:\Windows\SysWOW64\rtvcvfw32.dll [247296 2012-09-28] () [File not signed]

==================== Shortcuts & WMI ========================

==================== Loaded Modules (Whitelisted) =============

2020-10-10 07:04 - 2020-10-10 07:05 - 096130560 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\libcef.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000117760 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\libEGL.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 004342784 _____ () [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\libGLESv2.dll
2019-04-21 10:33 - 2019-04-21 10:33 - 000232448 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTCore.dll
2019-04-21 10:32 - 2019-04-21 10:32 - 000057344 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTFC.dll
2019-04-21 10:33 - 2019-04-21 10:33 - 000649216 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTHAL.dll
2019-04-21 10:32 - 2019-04-21 10:32 - 000074240 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTMUI.dll
2019-04-21 10:33 - 2019-04-21 10:33 - 000367104 _____ () [File not signed] C:\Program Files (x86)\MSI Afterburner\RTUI.dll
2019-09-09 16:29 - 2019-09-09 16:29 - 000057344 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTFC.dll
2019-09-09 16:30 - 2019-09-09 16:30 - 000074240 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTMUI.dll
2019-09-09 16:30 - 2019-09-09 16:30 - 000368640 _____ () [File not signed] C:\Program Files (x86)\RivaTuner Statistics Server\RTUI.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000053760 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\_bz2.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 000084992 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\_ctypes.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 000783360 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\_hashlib.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 000137216 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\_lzma.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 000047104 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\_socket.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 000039424 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\psutil._psutil_windows.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 001861120 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\PyQt5.QtCore.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 002002944 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\PyQt5.QtGui.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 004101120 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\PyQt5.QtWidgets.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 000009728 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\select.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 000075264 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\sip.pyd
2020-08-17 18:44 - 2020-08-17 18:44 - 000758784 _____ () [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\unicodedata.pyd
2014-11-10 11:12 - 2019-04-17 22:39 - 085372416 _____ () [File not signed] C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\libcef.dll
2019-04-17 22:39 - 2019-04-17 22:39 - 000043520 _____ () [File not signed] C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\libUbiCustomEvent.dll
2015-06-23 16:00 - 2015-06-23 16:00 - 000285696 _____ (Intel Corporation) [File not signed] [File is in use] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\PsiData.dll
2015-06-23 16:00 - 2015-06-23 16:00 - 000562688 _____ (Intel Corporation) [File not signed] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\ISDI2.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 002741248 _____ (Python Software Foundation) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\python34.dll
2020-10-10 07:04 - 2020-10-10 07:04 - 000760832 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\chrome_elf.dll
2017-11-06 19:21 - 2019-04-17 22:39 - 000518144 _____ (The Chromium Authors) [File not signed] C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\chrome_elf.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000848896 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\icudt53.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 001580032 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\icuin53.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 001079296 _____ (The ICU Project) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\icuuc53.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000036352 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qdds.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000022016 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qgif.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000029184 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qicns.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000022016 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qico.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000381952 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qjp2.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000206848 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qjpeg.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000218624 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qmng.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000016384 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qtga.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000308736 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qtiff.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000015360 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qwbmp.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000287232 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\imageformats\qwebp.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 000991744 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\platforms\qwindows.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 004182528 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\Qt5Core.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 004877312 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\Qt5Gui.dll
2020-08-17 18:44 - 2020-08-17 18:44 - 004490752 _____ (The Qt Company Ltd) [File not signed] C:\Program Files (x86)\TradeSkillMaster Application\app\Qt5Widgets.dll
2020-10-10 07:04 - 2020-10-10 07:04 - 000047104 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\audio\qtaudio_windows.dll
2020-10-10 07:04 - 2020-10-10 07:04 - 000026112 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\imageformats\qgif.dll
2020-10-10 07:04 - 2020-10-10 07:04 - 000027136 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\imageformats\qico.dll
2020-10-10 07:04 - 2020-10-10 07:04 - 000243712 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\imageformats\qjpeg.dll
2020-10-10 07:04 - 2020-10-10 07:04 - 000223744 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\imageformats\qmng.dll
2020-10-10 07:04 - 2020-10-10 07:04 - 000020992 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\imageformats\qsvg.dll
2020-10-10 07:04 - 2020-10-10 07:04 - 000332288 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\imageformats\qtiff.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 001140224 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\platforms\qwindows.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000041984 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtGraphicalEffects\private\qtgraphicaleffectsprivate.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtGraphicalEffects\qtgraphicaleffectsplugin.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtQml\Models.2\modelsplugin.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtQuick.2\qtquick2plugin.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000084480 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtQuick\Controls.2\qtquickcontrols2plugin.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000267776 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtQuick\Controls\qtquickcontrolsplugin.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000071680 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtQuick\Layouts\qquicklayoutsplugin.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000211456 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtQuick\Templates.2\qtquicktemplates2plugin.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\qml\QtQuick\Window.2\windowplugin.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 004943360 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Core.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 005022208 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Gui.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000626176 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Multimedia.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000877056 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Network.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 002908672 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Qml.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 003078656 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Quick.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000096256 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5QuickControls2.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000681472 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5QuickTemplates2.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000259072 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Svg.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 004718080 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Widgets.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000439296 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5WinExtras.dll
2020-10-10 07:05 - 2020-10-10 07:05 - 000159232 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files (x86)\Battle.net\Battle.net.12428\Qt5Xml.dll

==================== Alternate Data Streams (Whitelisted) ========

==================== Safe Mode (Whitelisted) ==================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) =================

==================== Internet Explorer (Whitelisted) ==========

BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-13] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-13] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {3459B272-CC19-4448-86C9-DDC3B4B2FAD3} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\Office16\MSOSB.DLL [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\Office16\MSOSB.DLL [2016-07-12] (Microsoft Corporation -> Microsoft Corporation)

==================== Hosts content: =========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-30 09:24 - 2020-07-22 17:24 - 000000027 _____ C:\WINDOWS\system32\drivers\etc\hosts
127.0.0.1 localhost

==================== Other Areas ===========================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\David\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\wp3662821-assassin-wallpapers.jpg
DNS Servers: 93.89.159.2 - 1.1.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(If an entry is included in the fixlist, it will be removed.)

HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\StartupApproved\Run: => "CCleaner Smart Cleaning"

==================== FirewallRules (Whitelisted) ================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [UDP Query User{EA613B87-0798-4766-A039-C81BCAB8DFFE}C:\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [TCP Query User{037281B6-55E4-4E6B-A41A-47FB34BA2F4D}C:\world of warcraft\_classic_\utils\wowvoiceproxy.exe] => (Allow) C:\world of warcraft\_classic_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{3AF034F5-FB2A-4042-9468-5CA7E033B4E7}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{05F735C0-7169-4805-A4E0-4555305419CD}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe (Valve -> )
FirewallRules: [{2FFC3A6B-0473-4092-ABE1-5D39FD53A17E}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{F2405F33-0AF3-431E-9652-1707CA01F1D4}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
FirewallRules: [{A1F83455-609A-47AF-9B5A-D69FC68CF4A9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Millie\Millie.exe () [File not signed]
FirewallRules: [{6C593DAD-8395-4F11-A590-F76DDDC9FE92}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Millie\Millie.exe () [File not signed]
FirewallRules: [UDP Query User{302C507C-4DA4-49AB-B64A-8352BC41950E}C:\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\world of warcraft\_retail_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [TCP Query User{06AC170C-54F5-41D1-B2B9-6B5A0A08E0E1}C:\world of warcraft\_retail_\utils\wowvoiceproxy.exe] => (Allow) C:\world of warcraft\_retail_\utils\wowvoiceproxy.exe (Blizzard Entertainment, Inc. -> Blizzard Entertainment)
FirewallRules: [{10D5C4D9-2E6B-4B67-A476-5281B56C5955}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{502EF961-5B71-4A32-969F-BA5D52140A00}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [UDP Query User{7EC9CC81-508D-4D45-8E81-DB52CCF2436E}C:\program files\microsoft office\office16\winword.exe] => (Allow) C:\program files\microsoft office\office16\winword.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [TCP Query User{98050A6F-1373-48CC-83FA-4BBE97A3F9B5}C:\program files\microsoft office\office16\winword.exe] => (Allow) C:\program files\microsoft office\office16\winword.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{3741751F-5BEE-45CB-837A-59E83B005968}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{F9B04128-D8B4-493D-B96B-5A6BAD2795ED}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [UDP Query User{7DA08C82-AB8E-46FE-83A4-6CCF7A8EAA24}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe => No File
FirewallRules: [TCP Query User{0329B052-4C9E-40FD-AD0B-127686849CB4}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe => No File
FirewallRules: [{32FF5D5F-AE6F-4F4E-9C6A-A44362281CD3}] => (Allow) C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{30431157-60F2-404A-B781-4FC5A1FE4407}] => (Allow) C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [TCP Query User{AFC1F7F7-ED3C-4777-85B5-65678200DA35}C:\users\david\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\david\appdata\roaming\utorrent\utorrent.exe => No File
FirewallRules: [UDP Query User{747FE15F-A487-4A02-A70A-A9E98014E198}C:\users\david\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\david\appdata\roaming\utorrent\utorrent.exe => No File
FirewallRules: [TCP Query User{11522C14-B13A-4060-A2EB-03E1287F5182}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{4894D9CD-74EE-4F4D-B682-799DCF973BD9}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{28C2D19F-C193-4A94-97AD-664B24F1C348}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [{72CA7C7D-10FB-4D96-B4E3-9AC3B9BB9EDB}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
FirewallRules: [TCP Query User{68FBEF50-D0C9-4B70-A3DA-FA8AB9F5C96E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [UDP Query User{C03AB2BE-B25F-4357-9117-35F841408DDF}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [{2D1F0F24-59F0-49DC-9CBA-9166ED79341E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{215B305F-3793-4710-866F-AAAFC4D5A75D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [TCP Query User{9526E725-5332-4491-900A-A5B3E00C15F8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [UDP Query User{95745F81-0967-4BC0-A61E-3A3E1F4555A8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{0AFE615F-ABD8-45F3-9AE8-F7117FC64CDC}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe (Plays.tv, Inc -> Copyright (c) 2018 Plays.tv, LLC)
FirewallRules: [{DE2DE3B5-8173-4FAC-896C-9FAC3AE29D46}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe (Plays.tv, Inc -> Copyright (c) 2018 Plays.tv, LLC)
FirewallRules: [{42216372-4873-4D06-8A71-3F90277E2E73}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{E09D3792-7521-4348-A40C-8F04F7EBBEC1}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\PlayGTAV.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [TCP Query User{950A489C-6DC1-4369-A3DC-3DFAE6527798}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [UDP Query User{60D42B90-ECC4-40D2-A604-71943C273C20}D:\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) D:\steam\steamapps\common\grand theft auto v\gta5.exe (Rockstar Games, Inc. -> Rockstar Games)
FirewallRules: [{9587D4F0-7BDE-42AA-8234-5B4948E5084A}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\System\witcher.exe (CD Projekt Red) [File not signed]
FirewallRules: [{320922C1-99B3-4866-95D5-6D0C8792482C}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\System\witcher.exe (CD Projekt Red) [File not signed]
FirewallRules: [{52E113A4-D189-4112-826B-9019169D0858}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\System\djinni!.exe (CD Projekt RED Sp. z o.o. -> CD Projekt Red)
FirewallRules: [{B8A860D9-E58B-40DD-B63F-07CE2BEC9BA5}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\System\djinni!.exe (CD Projekt RED Sp. z o.o. -> CD Projekt Red)
FirewallRules: [{6F3AD882-084D-4F82-88D9-937FCC53BB4C}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe () [File not signed]
FirewallRules: [{42B2AA49-B47A-4C28-9490-87830D930524}] => (Allow) D:\Steam\steamapps\common\The Witcher Enhanced Edition\Digital Comic\DigitalComic.exe () [File not signed]
FirewallRules: [TCP Query User{1A5E115A-10A8-458D-B3A0-0D08C151128D}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [UDP Query User{A33F85DC-8C02-40B1-99C9-2E2A9F5F0587}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{ED2F8AD3-A6E8-4A1C-BE03-77568C5A9C31}] => (Allow) C:\Program Files\VueScan\vuescan.exe (Hamrick Software) [File not signed]
FirewallRules: [{24DF0275-31DF-480F-95AD-E9A62D964EA7}] => (Allow) C:\Program Files\VueScan\vuescan.exe (Hamrick Software) [File not signed]
FirewallRules: [{5A06E980-6786-4094-BB82-A017F5B88366}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{402159DD-49FA-48BE-83F6-0781AE48CA75}] => (Allow) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe (AVB Disc Soft, SIA -> Disc Soft Ltd)
FirewallRules: [{BD235299-EF0E-4922-B1EC-FC5A352AB385}] => (Allow) D:\Hry\Assassins Creed Odyssey\ACOdyssey_plus.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{55507DCB-965C-4C75-9957-E8B41A17E22D}] => (Allow) D:\Hry\Assassins Creed Odyssey\ACOdyssey_plus.exe (UBISOFT ENTERTAINMENT INC. -> )
FirewallRules: [{C41E8E36-C825-4F32-A6E8-C2CEFE79A756}] => (Allow) C:\Users\David\AppData\Local\Programs\Opera\69.0.3686.36\opera.exe => No File
FirewallRules: [{6AC5F6E1-A6EE-44B6-9E94-4043E98FCE9E}] => (Allow) C:\Program Files\BlueStacks\HD-Player.exe (BlueStack Systems, Inc. -> BlueStack Systems, Inc.)
FirewallRules: [{F7C9A6A1-7EB0-467B-B0BB-558FD3575E8F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{B8342AAF-69AB-4EA6-9BA0-29F4957FE7C2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{BE24539C-7D43-4978-87E1-9FEC0CA6F023}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [{95E3E803-D9F6-4CDB-98CF-CB0C36EBCB92}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
FirewallRules: [TCP Query User{F46D583F-BFFD-4328-A985-6E194B84E4B6}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [UDP Query User{40136A8F-97F3-4C74-85D5-E12E64BD19AF}D:\hearthstone\hearthstone.exe] => (Allow) D:\hearthstone\hearthstone.exe (Blizzard Entertainment, Inc. -> )
FirewallRules: [{4AF092A6-463B-479D-8EB4-0047C4E628FD}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{F788FE0A-8BA7-42BE-897F-83FBC2EC8A96}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{7D71C875-EC8F-4B1F-B0C0-444D7EA81450}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5F6D0D58-5EDE-40FB-8DF2-8AFB62F19755}] => (Allow) C:\Program Files\WindowsApps\Microsoft.SkypeApp_15.61.100.0_x86__kzf8qxf38zg5c\Skype\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
FirewallRules: [{5FCBDB4A-3D2F-43C5-944E-6993BBA5AB63}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [{430F349B-7A08-451C-A276-3229EECA9E38}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe () [File not signed]
FirewallRules: [TCP Query User{A672DB78-0AE2-42A8-BF8E-6992EE5E8DFF}D:\hry\stronghold crusader 2\bin\win32_galaxy_release\crusader2.exe] => (Allow) D:\hry\stronghold crusader 2\bin\win32_galaxy_release\crusader2.exe () [File not signed]
FirewallRules: [UDP Query User{A4C65F8B-C1E2-460E-8148-ABBC0B0FE3CE}D:\hry\stronghold crusader 2\bin\win32_galaxy_release\crusader2.exe] => (Allow) D:\hry\stronghold crusader 2\bin\win32_galaxy_release\crusader2.exe () [File not signed]
FirewallRules: [TCP Query User{78008688-4859-47D1-9319-C36BC9F43F7D}D:\hry\stronghold hd\stronghold.exe] => (Allow) D:\hry\stronghold hd\stronghold.exe (Firefly Studios Limited -> )
FirewallRules: [UDP Query User{2EEC134B-69FD-408B-B1D8-C8D8A5671C0F}D:\hry\stronghold hd\stronghold.exe] => (Allow) D:\hry\stronghold hd\stronghold.exe (Firefly Studios Limited -> )
FirewallRules: [{77D388DB-4758-434B-9931-7252FD41B5FB}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{5C5DE207-C294-4941-B2F4-6A5A978A60D8}] => (Allow) C:\Program Files\Common Files\MAGIX Services\QMxNetworkSync\QMxNetworkSync.exe (MAGIX Software GmbH -> MAGIX)
FirewallRules: [{18C0C0E0-6BFD-42F3-A2C5-561A6A8EB569}] => (Allow) C:\Program Files\Common Files\MAGIX Services\MxCloudSync\MxCloudSync.exe (MAGIX Software GmbH -> Magix)

==================== Restore Points =========================

18-09-2020 13:21:13 Naplánovaný kontrolní bod
26-09-2020 00:15:05 Naplánovaný kontrolní bod
01-10-2020 00:26:20 Windows Update

==================== Faulty Device Manager Devices ============


==================== Event log errors: ========================

Application errors:
==================
Error: (10/10/2020 07:03:55 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/09/2020 02:01:07 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/09/2020 10:37:23 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/09/2020 01:37:21 AM) (Source: Microsoft-Windows-AppModel-State) (EventID: 12) (User: DESKTOP-7D2FQ0G)
Description: Microsoft.YourPhone_8wekyb3d8bbwe-2147023878

Error: (10/09/2020 01:31:11 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/08/2020 05:34:43 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/08/2020 11:32:49 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.

Error: (10/07/2020 09:55:38 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Generování kontextu aktivace pro C:\Program Files (x86)\Audacity\audacity.exe se nezdařilo. Chyba v souboru manifestu nebo zásad na řádku .
Verze součásti požadovaná aplikací je v konfliktu s jinou verzí součásti, která je již aktivní.
Konfliktní součásti:
Součást 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_9e8193e1e45b25c1.manifest.
Součást 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.18362.1082_none_e62ecab8f8d74ec7.manifest.


System errors:
=============
Error: (10/09/2020 01:28:53 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7D2FQ0G)
Description: Server {2593F8B9-4EAF-457C-B68A-50F6B8EA6B54} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/09/2020 01:31:02 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Uživatelská služba platformy připojených zařízení_59fb8 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 3000 milisekund: Restartovat službu.

Error: (10/08/2020 05:34:53 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7D2FQ0G)
Description: Server Microsoft.YourPhone_1.20091.84.0_x64__8wekyb3d8bbwe!App.AppXvctmff39365zg14pgmystcwtys462fpa.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/08/2020 05:34:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7D2FQ0G)
Description: Server Microsoft.People_10.1909.10841.0_x64__8wekyb3d8bbwe!x4c7a3b7dy2188y46d4ya362y19ac5a5805e5x.AppXk8n013897y2z89d7v08qtryawtj0p3jg.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/08/2020 05:34:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7D2FQ0G)
Description: Server Microsoft.XboxApp_48.69.18001.0_x64__8wekyb3d8bbwe!Microsoft.XboxApp.AppX079r1k3wxyr7e04r85h2kh1sretge9f7.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/08/2020 05:34:51 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7D2FQ0G)
Description: Server {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/08/2020 05:34:50 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-7D2FQ0G)
Description: Server Microsoft.Windows.Cortana_1.13.0.18362_neutral_neutral_cw5n1h2txyewy!CortanaUI.AppXd4tad4d57t4wtdbnnmb8v2xtzym8c1n8.mca se v daném časovém limitu neregistroval u služby DCOM.

Error: (10/08/2020 05:34:27 PM) (Source: Application Popup) (EventID: 56) (User: )
Description: ACPI5


Windows Defender:
===================================
Date: 2020-10-09 01:32:53.891
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.325.409.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.17500.4
Kód chyby: 0x80070645
Popis chyby: Tato akce je platná pouze u produktů, které jsou momentálně nainstalovány.

Date: 2020-10-09 01:32:53.891
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.325.409.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antispywarový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.17500.4
Kód chyby: 0x80070645
Popis chyby: Tato akce je platná pouze u produktů, které jsou momentálně nainstalovány.

Date: 2020-10-09 01:32:53.890
Description:
Antivirová ochrana v programu Windows Defender narazil na chybu při pokusu o aktualizaci bezpečnostních informací.
Nová verze bezpečnostních informací:
Předchozí verze bezpečnostních informací: 1.325.409.0
Zdroj aktualizace: Centrum společnosti Microsoft pro ochranu před škodlivým softwarem
Typ bezpečnostních informací: Antivirový program
Typ aktualizace: Úplné
Uživatel: NT AUTHORITY\NETWORK SERVICE
Aktuální verze modulu:
Předchozí verze modulu: 1.1.17500.4
Kód chyby: 0x80070645
Popis chyby: Tato akce je platná pouze u produktů, které jsou momentálně nainstalovány.

CodeIntegrity:
===================================

Date: 2020-10-10 07:04:19.004
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-10 07:04:18.991
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-10 07:04:18.979
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-10 07:04:18.966
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-10 07:04:18.936
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-09 11:35:03.427
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-09 11:35:03.416
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

Date: 2020-10-09 11:35:03.402
Description:
Code Integrity determined that a process (\Device\HarddiskVolume6\Windows\System32\SIHClient.exe) attempted to load \Device\HarddiskVolume6\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 21.1\x64\antimalware_provider.dll that did not meet the Windows signing level requirements.

==================== Memory info ===========================

BIOS: American Megatrends Inc. P2.80 01/26/2016
Motherboard: ASRock Z170 Extreme4
Processor: Intel(R) Core(TM) i5-6600K CPU @ 3.50GHz
Percentage of memory in use: 40%
Total physical RAM: 16329.27 MB
Available physical RAM: 9668.35 MB
Total Virtual: 32713.27 MB
Available Virtual: 23316.92 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.18 GB) (Free:24.58 GB) NTFS
Drive d: () (Fixed) (Total:931.5 GB) (Free:242.49 GB) NTFS

\\?\Volume{153a7e41-9717-4114-b409-806cd10646b5}\ (Obnovení) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{a57f3c44-5d42-4e0e-a549-233e2a1c34ff}\ () (Fixed) (Total:0.84 GB) (Free:0.41 GB) NTFS
\\?\Volume{138a95a2-35ad-430f-91a6-0617b595d599}\ () (Fixed) (Total:0.09 GB) (Free:0.07 GB) FAT32

==================== MBR & Partition Table ====================

==========================================================
Disk: 0 (Protective MBR) (Size: 931.5 GB) (Disk ID: 00000000)

Partition: GPT.

==========================================================
Disk: 1 (Protective MBR) (Size: 223.6 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt =======================

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Preventivka 4.10.2020

#11 Příspěvek od Conder »

:arrow: Otvor poznamkovy blok (Win+R -> notepad -> enter)
  • Skopiruj nasledujuci text a vloz ho do poznamkoveho bloku:

    Kód: Vybrat vše

    Start
    CloseProcesses:
    CreateRestorePoint:
    
    PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
    File: C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe
    File: C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
    ExportKey: HKLM\SOFTWARE\Policies\Mozilla\Firefox
    ExportKey: HKLM\SOFTWARE\Policies\Google
    
    HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\MountPoints2: {2f792c64-4b05-11ea-ab35-d05099ae28e2} - "E:\setup.exe" 
    HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\MountPoints2: {99340521-9073-11ea-ab51-d05099ae28e2} - "F:\setup.exe" 
    Task: {430FEE59-1EE2-4DCE-A592-ABAC966AB81B} - System32\Tasks\Opera scheduled Autoupdate 1593648143 => C:\Users\David\AppData\Local\Programs\Opera\launcher.exe
    Task: {A759CB3C-5883-47B3-A04F-A8F5F7D93DC5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
    Task: {C2ABD97E-15AB-4077-BF0B-1F73CC68256D} - System32\Tasks\Opera scheduled assistant Autoupdate 1593648148 => C:\Users\David\AppData\Local\Programs\Opera\launcher.exe
    AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
    AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
    FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
    FirewallRules: [UDP Query User{7DA08C82-AB8E-46FE-83A4-6CCF7A8EAA24}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe => No File
    FirewallRules: [TCP Query User{0329B052-4C9E-40FD-AD0B-127686849CB4}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe => No File
    FirewallRules: [{32FF5D5F-AE6F-4F4E-9C6A-A44362281CD3}] => (Allow) C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe => No File
    FirewallRules: [{30431157-60F2-404A-B781-4FC5A1FE4407}] => (Allow) C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe => No File
    FirewallRules: [TCP Query User{AFC1F7F7-ED3C-4777-85B5-65678200DA35}C:\users\david\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\david\appdata\roaming\utorrent\utorrent.exe => No File
    FirewallRules: [UDP Query User{747FE15F-A487-4A02-A70A-A9E98014E198}C:\users\david\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\david\appdata\roaming\utorrent\utorrent.exe => No File
    FirewallRules: [TCP Query User{68FBEF50-D0C9-4B70-A3DA-FA8AB9F5C96E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
    FirewallRules: [UDP Query User{C03AB2BE-B25F-4357-9117-35F841408DDF}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
    FirewallRules: [{C41E8E36-C825-4F32-A6E8-C2CEFE79A756}] => (Allow) C:\Users\David\AppData\Local\Programs\Opera\69.0.3686.36\opera.exe => No File
    
    Hosts:
    EmptyTemp:
    End
  • Uloz na plochu s nazvom fixlist.txt
  • Spusti znovu FRST a klikni na Fix
  • Po dokonceni si FRST vyziada restart PC, potvrd kliknutim na OK
  • Po restartovani PC bude na ploche subor Fixlog.txt, jeho obsah sem skopiruj
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#12 Příspěvek od bojimso »

Hotovo, zde je LOG

Fix result of Farbar Recovery Scan Tool (x64) Version: 10-10-2020
Ran by David (11-10-2020 11:44:18) Run:1
Running from C:\Users\David\Desktop
Loaded Profiles: David
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:

PowerShell: Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum
File: C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe
File: C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
ExportKey: HKLM\SOFTWARE\Policies\Mozilla\Firefox
ExportKey: HKLM\SOFTWARE\Policies\Google

HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\MountPoints2: {2f792c64-4b05-11ea-ab35-d05099ae28e2} - "E:\setup.exe"
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\...\MountPoints2: {99340521-9073-11ea-ab51-d05099ae28e2} - "F:\setup.exe"
Task: {430FEE59-1EE2-4DCE-A592-ABAC966AB81B} - System32\Tasks\Opera scheduled Autoupdate 1593648143 => C:\Users\David\AppData\Local\Programs\Opera\launcher.exe
Task: {A759CB3C-5883-47B3-A04F-A8F5F7D93DC5} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {C2ABD97E-15AB-4077-BF0B-1F73CC68256D} - System32\Tasks\Opera scheduled assistant Autoupdate 1593648148 => C:\Users\David\AppData\Local\Programs\Opera\launcher.exe
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
FirewallRules: [UDP Query User{7DA08C82-AB8E-46FE-83A4-6CCF7A8EAA24}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe => No File
FirewallRules: [TCP Query User{0329B052-4C9E-40FD-AD0B-127686849CB4}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe] => (Allow) C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe => No File
FirewallRules: [{32FF5D5F-AE6F-4F4E-9C6A-A44362281CD3}] => (Allow) C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{30431157-60F2-404A-B781-4FC5A1FE4407}] => (Allow) C:\Users\David\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [TCP Query User{AFC1F7F7-ED3C-4777-85B5-65678200DA35}C:\users\david\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\david\appdata\roaming\utorrent\utorrent.exe => No File
FirewallRules: [UDP Query User{747FE15F-A487-4A02-A70A-A9E98014E198}C:\users\david\appdata\roaming\utorrent\utorrent.exe] => (Block) C:\users\david\appdata\roaming\utorrent\utorrent.exe => No File
FirewallRules: [TCP Query User{68FBEF50-D0C9-4B70-A3DA-FA8AB9F5C96E}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [UDP Query User{C03AB2BE-B25F-4357-9117-35F841408DDF}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe => No File
FirewallRules: [{C41E8E36-C825-4F32-A6E8-C2CEFE79A756}] => (Allow) C:\Users\David\AppData\Local\Programs\Opera\69.0.3686.36\opera.exe => No File

Hosts:
EmptyTemp:
End
*****************

Processes closed successfully.
Restore point was successfully created.

========= Get-ChildItem -Path "$ENV:USERPROFILE\Desktop" -Recurse -Force | Measure-Object -Property Length -Sum =========



Count : 1614
Average :
Sum : 914392523
Maximum :
Minimum :
Property : Length




========= End of Powershell: =========


========================= File: C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe ========================

C:\Program Files (x86)\TradeSkillMaster Application\app\TSMApplication.exe
File not signed
MD5: 72C4380EE0D19B7B76196B488E2DFD39
Creation and modification date: 2020-10-11 08:23 - 2020-10-11 08:23
Size: 001623040
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:
VirusTotal: https://www.virustotal.com/gui/file/066 ... 1600943192

====== End of File: ======


========================= File: C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe ========================

C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe
File not signed
MD5: 8FDA65209157144C3E28809D75A47526
Creation and modification date: 2012-01-23 18:19 - 2012-01-23 18:19
Size: 001858048
Attributes: ----A
Company Name: MAGIX AG
Internal Name: FABS.EXE
Original Name: FABS.EXE
Product: FABS - file change and backup server
Description: Verzeichnisüberwachung und Hilfsaufgaben für die Medienbibliothek
File Version: 2.1.32.0
Product Version: 2.1.32.0
Copyright: Copyright (C) 2005 MAGIX AG, All rights reserved.
VirusTotal: https://www.virustotal.com/gui/file/687 ... 1601462854

====== End of File: ======

================== ExportKey: ===================

[HKLM\SOFTWARE\Policies\Mozilla\Firefox]
[HKLM\SOFTWARE\Policies\Mozilla\Firefox\Certificates]

=== End of ExportKey ===
================== ExportKey: ===================

[HKLM\SOFTWARE\Policies\Google]
[HKLM\SOFTWARE\Policies\Google\Chrome]

=== End of ExportKey ===
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f792c64-4b05-11ea-ab35-d05099ae28e2} => removed successfully
HKU\S-1-5-21-3482348820-1896476200-1895645591-1002\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{99340521-9073-11ea-ab51-d05099ae28e2} => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{430FEE59-1EE2-4DCE-A592-ABAC966AB81B}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{430FEE59-1EE2-4DCE-A592-ABAC966AB81B}" => removed successfully
C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1593648143 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled Autoupdate 1593648143" => removed successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{A759CB3C-5883-47B3-A04F-A8F5F7D93DC5} => removed successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A759CB3C-5883-47B3-A04F-A8F5F7D93DC5} => removed successfully
C:\WINDOWS\System32\Tasks\AVAST Software\Avast settings backup => moved successfully
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AVAST Software\Avast settings backup => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C2ABD97E-15AB-4077-BF0B-1F73CC68256D}" => removed successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2ABD97E-15AB-4077-BF0B-1F73CC68256D}" => removed successfully
C:\WINDOWS\System32\Tasks\Opera scheduled assistant Autoupdate 1593648148 => moved successfully
"HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Opera scheduled assistant Autoupdate 1593648148" => removed successfully
"AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}" => removed successfully
"AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}" => removed successfully
"FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}" => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00avast => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{7DA08C82-AB8E-46FE-83A4-6CCF7A8EAA24}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{0329B052-4C9E-40FD-AD0B-127686849CB4}C:\users\david\appdata\roaming\utorrent\updates\3.5.3_44494.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{32FF5D5F-AE6F-4F4E-9C6A-A44362281CD3}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{30431157-60F2-404A-B781-4FC5A1FE4407}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{AFC1F7F7-ED3C-4777-85B5-65678200DA35}C:\users\david\appdata\roaming\utorrent\utorrent.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{747FE15F-A487-4A02-A70A-A9E98014E198}C:\users\david\appdata\roaming\utorrent\utorrent.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{68FBEF50-D0C9-4B70-A3DA-FA8AB9F5C96E}C:\program files (x86)\skype\phone\skype.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{C03AB2BE-B25F-4357-9117-35F841408DDF}C:\program files (x86)\skype\phone\skype.exe" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C41E8E36-C825-4F32-A6E8-C2CEFE79A756}" => removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.

=========== EmptyTemp: ==========

BITS transfer queue => 10772480 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 1305070065 B
Java, Flash, Steam htmlcache => 22344438 B
Windows/system/drivers => 87948 B
Edge => 0 B
Chrome => 577221808 B
Firefox => 884786182 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 233894 B
NetworkService => 275250 B
David => 30838977 B
bejja => 30838977 B

RecycleBin => 78399346 B
EmptyTemp: => 2.7 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 11:45:31 ====

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Preventivka 4.10.2020

#13 Příspěvek od Conder »

Odporucam este upratat po Avaste, kedze si ho odinstaloval, ale nieco z neho este zostalo v PC. Stiahni a spusti Avast Clear na precistenie po Avast antiviruse podla tohto navodu: https://www.avast.com/cs-cz/uninstall-utility
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

bojimso
2. Stupeň Varování
Příspěvky: 282
Registrován: 08 bře 2007 14:56

Re: Preventivka 4.10.2020

#14 Příspěvek od bojimso »

Provedeno v nouzovem rezimu.

Pozustatky souboru po FRST a RSITU mohu manualne smazat nebo je na to take nejaka utilita? :|

Conder
VIP
VIP
Příspěvky: 4399
Registrován: 30 pro 2013 22:29
Bydliště: Bratislava

Re: Preventivka 4.10.2020

#15 Příspěvek od Conder »

:arrow: Po pouzitych nastrojoch (FRST, RSIT...) mozeme upratat cez DelFix:
Absolvent skoly pre novacikov :)
E-mail: conder (zavinac) forum.viry.cz

Ak nieco nie je jasne, pytaj sa. Odporucam mat vzdy zalohovat dolezite data (dokumenty, fotky a ine).

Fixlisty a ine scripty su pisane len pre konkretny PC. Nepouzivajte ich na inych zariadeniach, inak hrozi poskodenie systemu alebo strata dat.
Ak mate podobny problem ako iny uzivatel, prosim, zalozte si vlastnu temu.

V pripade spokojnosti je mozne podporit forum. Dakujeme!

Zamčeno