Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Vírusov sa nedá zbaviť ani po formátovaní disku a reinstallu

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zpráva
Autor
sixdee
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 01 lis 2014 21:36

Vírusov sa nedá zbaviť ani po formátovaní disku a reinstallu

#1 Příspěvek od sixdee »

Ospravedlňujem sa, že som rovno nespravil nový topic. tak postnem to tu ešte raz.



Pred mesiacom som poslal notebook MSI GE 70 do servisu (alza) pretože sa sám prenastavoval čas (myslel som, že odišla iba bios batéria) no oni vymenili celú dosku takže muselo odísť niečo iné..
Keď mi došiel ntb domov, tak šiel úplne čudne, spomalene, samé errory vyskakovali, nefungovalo na nom takmer nič. (Ani len Eset nebol pojazdný!). Tak som zobral original dvd s windows 7 64 bit, a samozrejme som sformátoval disk a tak nainštaloval čistý windows, po nainštalovaní a zadaní oficiall kľúču som iba tak preventívne chcel nainštalovať ESET, no nechelo mi ho nainštalovať, tak som nainštaloval HitmanPro, spravil som kontrolu a vyhodil asi 160 vírusov priamo vo windowse.

Prosím Vás o pomoc, naozaj už neviem čo s tým.

ďakujem!! :)


RSIT log:
Logfile of random's system information tool 1.10 (written by random/random)
Run by Matej at 2014-11-01 22:01:08
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 425 GB (90%) free of 473 GB
Total RAM: 8112 MB (76% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:01:11, on 1. 11. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.18595)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Matej.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Killer Network Manager.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_LiveUpdate_Service - Micro-Star International - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Atheros Killer Service V2 - Qualcomm Atheros - C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7712 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 24761536
\??\C:\Windows\system32\conhost.exe "1422866512-64651104216178250891438234946830306739905256447555766594-621450535
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
"C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\UI0Detect.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss c7686988-03f0-4d81-8e0b-2d6c5bd239f3 1
\??\C:\Windows\system32\conhost.exe "-724479887776734235788864379-14432154971084512900-199390479212080172-1061876848
C:\Windows\System32\vds.exe
C:\Windows\system32\vssvc.exe
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Windows\system32\svchost.exe -k bthsvcs
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "186392921146488305232188787-1855716741381907385-1603410389257800381-1837642081
"taskhost.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
igfxEM.exe
igfxHK.exe
igfxTray.exe
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe" -minimize
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2996.0.1985502545\993127765" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,16 --gpu-vendor-id=0x8086 --gpu-device-id=0x0416 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3650 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group16 pct:1g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="2996.2.905184564\248321298" /prefetch:673131151
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group16 pct:1g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderFromOmnibox/OmniboxPrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_10/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="2996.4.2000765469\1987408187" /prefetch:673131151

C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Matej\Downloads\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2014-10-26 674816]
"AutoKMS"=C:\Windows\AutoKMS.exe [2014-10-26 615936]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-10-27 1008128]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-10-04 2462536]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-10-04 2800296]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-06-30 13672664]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-04-25 2889072]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-10-01 22065760]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2014-09-18 3476432]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2014-06-27 292848]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Killer Network Manager.lnk - C:\Windows\Installer\{4692B750-DE88-4DCF-9163-745AF5604B24}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"HideSCAHealth"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-01 22:01:08 ----D---- C:\rsit
2014-11-01 22:01:08 ----D---- C:\Program Files\trend micro
2014-11-01 21:01:14 ----D---- C:\Program Files\HitmanPro
2014-11-01 21:00:48 ----D---- C:\ProgramData\HitmanPro
2014-11-01 20:59:35 ----D---- C:\ProgramData\APN
2014-11-01 20:59:03 ----D---- C:\Users\Matej\AppData\Roaming\uTorrent
2014-11-01 20:44:18 ----D---- C:\Program Files\Elantech
2014-11-01 20:44:14 ----A---- C:\Windows\system32\drivers\ETD.sys
2014-10-27 20:29:30 ----D---- C:\Math Studio
2014-10-27 17:44:30 ----D---- C:\Users\Matej\AppData\Roaming\Skype
2014-10-27 17:44:27 ----RD---- C:\Program Files (x86)\Skype
2014-10-27 17:44:24 ----D---- C:\ProgramData\Skype
2014-10-26 21:50:49 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-10-26 19:58:37 ----A---- C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2014-10-26 19:53:47 ----D---- C:\ProgramData\ESET
2014-10-26 19:53:47 ----D---- C:\Program Files\ESET
2014-10-26 19:52:22 ----A---- C:\Windows\SYSWOW64\OpenCL.DLL
2014-10-26 19:52:22 ----A---- C:\Windows\system32\OpenCL.DLL
2014-10-26 19:51:09 ----A---- C:\Windows\system32\MetroIntelGenericUIFramework.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\IntelOpenCL32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\IntelCpHeciSvc.exe
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\Intel_OpenCL_ICD32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\iglhsip32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\iglhcp32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igfxcmrt32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igfxcmjit32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igfx11cmrt32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igdusc32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\IntelOpenCL64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\Intel_OpenCL_ICD64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\iglhsip64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\iglhcp64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxTray.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxOSP.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxLHMLibv2_0.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxLHMLib.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxLHM.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxHK.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxext.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxexps.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxEMLibv2_0.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxEMLib.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxEM.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDTCM.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDILibv2_0.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDILib.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDI.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDHLibv2_0.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDHLib.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDH.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxCUIServicePS.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxCUIService.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxCoIn_v3650.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxcmrt64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxcmjit64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfx11cmrt64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igdusc64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\SYSWOW64\igdumdim32.dll
2014-10-26 19:51:07 ----A---- C:\Windows\SYSWOW64\igdrcl32.dll
2014-10-26 19:51:07 ----A---- C:\Windows\SYSWOW64\igdmd32.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\igdumdim64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\igdrcl64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\igdmd64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\igdfcl64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\drivers\igdkmd64.sys
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igdfcl32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igdde32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igdbcl32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igdail32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igd11dxva32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igd10iumd32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igdde64.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igdbcl64.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igdail64.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igd11dxva64.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igd10iumd64.dll
2014-10-26 19:51:05 ----A---- C:\Windows\SYSWOW64\ig75icd32.dll
2014-10-26 19:51:05 ----A---- C:\Windows\system32\ig75icd64.dll
2014-10-26 19:51:05 ----A---- C:\Windows\system32\IccLibDll_x64.dll
2014-10-26 19:51:05 ----A---- C:\Windows\system32\Gfxv4_0.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\Gfxv2_0.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\GfxUIEx.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\drivers\IntcDAud.sys
2014-10-26 19:51:05 ----A---- C:\Windows\system32\DPTopologyAppv2_0.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\DPTopologyApp.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\difx64.exe
2014-10-26 19:50:43 ----D---- C:\Program Files (x86)\Intel
2014-10-26 19:50:43 ----A---- C:\Windows\system32\drivers\USB3Ver.dll
2014-10-26 19:50:12 ----D---- C:\Intel
2014-10-26 19:50:11 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
2014-10-26 19:50:11 ----A---- C:\Windows\system32\drivers\iusb3xhc.sys
2014-10-26 19:50:11 ----A---- C:\Windows\system32\drivers\iusb3hub.sys
2014-10-26 19:50:11 ----A---- C:\Windows\system32\drivers\iusb3hcs.sys
2014-10-26 19:40:03 ----D---- C:\Windows\SYSWOW64\RTCOM
2014-10-26 19:40:03 ----D---- C:\Program Files\Realtek
2014-10-26 19:39:50 ----A---- C:\Windows\system32\WavesGUILib64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\SRSWOW64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\SRSTSX64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\SRSTSH64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\SRSHP64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\RtPgEx64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\RtkCfg64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2014-10-26 19:39:49 ----A---- C:\Windows\SYSWOW64\MBAPO232.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RtkApi64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTEEP64A.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTEEL64A.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTEEG64A.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTEED64A.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RtDataProc64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTCOM64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RP3DHT64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RP3DAA64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RltkAPO64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RCoInstII64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\MBWrp64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\MBAPO264.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2014-10-26 19:39:49 ----A---- C:\Windows\system32\drivers\MBfilt64.sys
2014-10-26 19:39:48 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\FMAPO64.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\AERTAR64.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\AERTAC64.dll
2014-10-26 19:39:47 ----D---- C:\Program Files (x86)\Realtek
2014-10-26 19:39:42 ----HD---- C:\Program Files (x86)\Temp
2014-10-26 19:39:42 ----A---- C:\Windows\RtlExUpd.dll
2014-10-26 19:39:20 ----D---- C:\Program Files\Intel
2014-10-26 19:39:07 ----D---- C:\ProgramData\Package Cache
2014-10-26 19:37:45 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-10-26 19:37:45 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2014-10-26 19:37:45 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-10-26 19:37:45 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-10-26 19:37:44 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2014-10-26 19:37:44 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-10-26 19:37:24 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-10-26 19:37:24 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-10-26 19:37:24 ----A---- C:\Windows\system32\nvspcap64.dll
2014-10-26 19:37:24 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-10-26 19:33:38 ----SD---- C:\Windows\system32\CompatTel
2014-10-26 19:33:35 ----D---- C:\Windows\SYSWOW64\Wat
2014-10-26 19:33:35 ----D---- C:\Windows\system32\Wat
2014-10-26 19:23:06 ----D---- C:\Users\Matej\AppData\Roaming\Macromedia
2014-10-26 19:23:04 ----D---- C:\ProgramData\Adobe
2014-10-26 19:22:58 ----D---- C:\Users\Matej\AppData\Roaming\Adobe
2014-10-26 19:22:54 ----A---- C:\Windows\system32\browserchoice.exe
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFx.dll
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFSvc.dll
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFPlatform.dll
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFHost.exe
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2014-10-26 19:11:45 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2014-10-26 19:11:45 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2014-10-26 19:05:38 ----A---- C:\Windows\SYSWOW64\wmi.dll
2014-10-26 19:05:38 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-10-26 19:05:38 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-10-26 19:05:38 ----A---- C:\Windows\system32\wmi.dll
2014-10-26 19:05:38 ----A---- C:\Windows\system32\wintrust.dll
2014-10-26 19:05:38 ----A---- C:\Windows\system32\imagehlp.dll
2014-10-26 19:05:38 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2014-10-26 19:02:38 ----A---- C:\Windows\acpimof.dll
2014-10-26 19:02:34 ----D---- C:\Program Files (x86)\MSI
2014-10-26 19:02:34 ----D---- C:\MSILU
2014-10-26 18:59:46 ----D---- C:\ProgramData\Qualcomm
2014-10-26 18:59:26 ----D---- C:\Program Files\Qualcomm Atheros
2014-10-26 18:58:59 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-10-26 18:56:57 ----D---- C:\ProgramData\NVIDIA Corporation
2014-10-26 18:56:54 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-10-26 18:56:53 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2014-10-26 18:56:53 ----A---- C:\Windows\system32\nvaudcap64v.dll
2014-10-26 18:56:53 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2014-10-26 18:56:46 ----D---- C:\Program Files\NVIDIA Corporation
2014-10-26 18:54:25 ----D---- C:\ProgramData\Downloaded Installations
2014-10-26 18:53:11 ----A---- C:\Windows\AutoKMS.ini
2014-10-26 18:53:11 ----A---- C:\Windows\AutoKMS.exe
2014-10-26 18:49:49 ----D---- C:\Program Files\Common Files\DESIGNER
2014-10-26 18:49:29 ----D---- C:\Program Files\Microsoft Synchronization Services
2014-10-26 18:49:17 ----D---- C:\Windows\PCHEALTH
2014-10-26 18:49:17 ----D---- C:\Program Files\Microsoft Sync Framework
2014-10-26 18:49:17 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2014-10-26 18:49:17 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-10-26 18:47:35 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2014-10-26 18:46:42 ----D---- C:\Program Files\Microsoft Analysis Services
2014-10-26 18:46:42 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2014-10-26 18:46:00 ----D---- C:\Program Files (x86)\Microsoft Office
2014-10-26 18:45:59 ----D---- C:\Program Files\Microsoft Office
2014-10-26 18:45:58 ----D---- C:\ProgramData\Microsoft Help
2014-10-26 18:45:35 ----RHD---- C:\MSOCache
2014-10-26 18:42:14 ----D---- C:\Users\Matej\AppData\Roaming\WinRAR
2014-10-26 18:41:33 ----D---- C:\Program Files\WinRAR
2014-10-26 18:39:36 ----D---- C:\Program Files (x86)\Google
2014-10-26 18:35:22 ----D---- C:\Windows\system32\MRT
2014-10-26 18:35:20 ----A---- C:\Windows\system32\MRT.exe
2014-10-26 18:33:58 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-10-26 18:33:58 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-10-26 18:33:58 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-10-26 18:33:58 ----A---- C:\Windows\system32\infocardapi.dll
2014-10-26 18:33:58 ----A---- C:\Windows\system32\icardres.dll
2014-10-26 18:33:58 ----A---- C:\Windows\system32\icardagt.exe
2014-10-26 18:33:52 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-10-26 18:33:52 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\urlmon.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\url.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\mshta.exe
2014-10-26 18:33:06 ----A---- C:\Windows\system32\msfeedssync.exe
2014-10-26 18:33:06 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\jsproxy.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\iertutil.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\url.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\wininet.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\msfeeds.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\ieUnatt.exe
2014-10-26 18:33:05 ----A---- C:\Windows\system32\ieui.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\dxtrans.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\dxtmsft.dll
2014-10-26 18:33:04 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-10-26 18:33:04 ----A---- C:\Windows\system32\ieframe.dll
2014-10-26 18:33:03 ----A---- C:\Windows\system32\mshtmled.dll
2014-10-26 18:33:03 ----A---- C:\Windows\system32\mshtml.dll
2014-10-26 18:32:50 ----A---- C:\Windows\system32\generaltel.dll
2014-10-26 18:32:50 ----A---- C:\Windows\system32\aepdu.dll
2014-10-26 18:32:50 ----A---- C:\Windows\system32\aeinv.dll
2014-10-26 18:32:43 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-10-26 18:32:43 ----A---- C:\Windows\system32\lsasrv.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\winsta.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\winsta.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\winlogon.exe
2014-10-26 18:32:42 ----A---- C:\Windows\system32\wdigest.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\TSpkg.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\tsgqec.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\termsrv.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\schannel.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\rdrmemptylst.exe
2014-10-26 18:32:42 ----A---- C:\Windows\system32\rdpwsx.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\ncrypt.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\msv1_0.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\mstscax.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\mstsc.exe
2014-10-26 18:32:42 ----A---- C:\Windows\system32\kerberos.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-10-26 18:32:42 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-10-26 18:32:42 ----A---- C:\Windows\system32\credssp.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\aaclient.dll
2014-10-26 18:32:35 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-10-26 18:32:35 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-10-26 18:32:35 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-10-26 18:32:34 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-10-26 18:32:34 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-10-26 18:32:34 ----A---- C:\Windows\system32\objsel.dll
2014-10-26 18:32:34 ----A---- C:\Windows\system32\KernelBase.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\wincredprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\smss.exe
2014-10-26 18:32:33 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\dimsroam.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\csrsrv.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\cngprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\capiprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\apisetschema.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\adprovider.dll
2014-10-26 18:32:31 ----A---- C:\Windows\SYSWOW64\tdh.dll
2014-10-26 18:32:31 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-10-26 18:32:31 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2014-10-26 18:32:31 ----A---- C:\Windows\system32\tdh.dll
2014-10-26 18:32:31 ----A---- C:\Windows\system32\ntdll.dll
2014-10-26 18:32:31 ----A---- C:\Windows\system32\advapi32.dll
2014-10-26 18:32:20 ----A---- C:\Windows\system32\Wdfres.dll
2014-10-26 18:32:20 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2014-10-26 18:32:20 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2014-10-26 18:32:12 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-10-26 18:32:12 ----A---- C:\Windows\SYSWOW64\gameux.dll
2014-10-26 18:32:12 ----A---- C:\Windows\system32\Wpc.dll
2014-10-26 18:32:12 ----A---- C:\Windows\system32\gameux.dll
2014-10-26 18:32:09 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-10-26 18:32:09 ----A---- C:\Windows\system32\shdocvw.dll
2014-10-26 18:32:07 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2014-10-26 18:32:07 ----A---- C:\Windows\system32\mswsock.dll
2014-10-26 18:32:07 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-10-26 18:32:07 ----A---- C:\Windows\system32\drivers\netio.sys
2014-10-26 18:32:07 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-10-26 18:32:06 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2014-10-26 18:32:06 ----A---- C:\Windows\system32\poqexec.exe
2014-10-26 18:32:05 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-10-26 18:32:05 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-10-26 18:32:05 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-10-26 18:32:05 ----A---- C:\Windows\system32\msihnd.dll
2014-10-26 18:32:05 ----A---- C:\Windows\system32\msi.dll
2014-10-26 18:32:05 ----A---- C:\Windows\system32\consent.exe
2014-10-26 18:32:05 ----A---- C:\Windows\system32\authui.dll
2014-10-26 18:32:05 ----A---- C:\Windows\system32\appinfo.dll
2014-10-26 18:32:02 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-10-26 18:32:02 ----A---- C:\Windows\system32\shell32.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\user.exe
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-10-26 18:32:00 ----A---- C:\Windows\system32\wow64win.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\wow64cpu.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\wow64.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\winsrv.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\ntvdm64.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\kernel32.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\conhost.exe
2014-10-26 18:31:34 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-10-26 18:31:34 ----A---- C:\Windows\system32\win32spl.dll
2014-10-26 18:31:33 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2014-10-26 18:31:33 ----A---- C:\Windows\SYSWOW64\netevent.dll
2014-10-26 18:31:33 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2014-10-26 18:31:33 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\nlasvc.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\nlaapi.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\netevent.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\netcorehc.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\ncsi.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2014-10-26 18:31:29 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2014-10-26 18:31:29 ----A---- C:\Windows\system32\rdpcore.dll
2014-10-26 18:31:29 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2014-10-26 18:31:28 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2014-10-26 18:31:28 ----A---- C:\Windows\system32\iologmsg.dll
2014-10-26 18:31:28 ----A---- C:\Windows\system32\drivers\storport.sys
2014-10-26 18:31:28 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-10-26 18:31:28 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-10-26 18:31:23 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-10-26 18:31:23 ----A---- C:\Windows\system32\WebClnt.dll
2014-10-26 18:31:22 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2014-10-26 18:31:22 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2014-10-26 18:31:22 ----A---- C:\Windows\system32\davclnt.dll
2014-10-26 18:31:19 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2014-10-26 18:31:19 ----A---- C:\Windows\system32\cryptdlg.dll
2014-10-26 18:31:13 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2014-10-26 18:31:13 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2014-10-26 18:31:13 ----A---- C:\Windows\SYSWOW64\devobj.dll
2014-10-26 18:31:13 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2014-10-26 18:31:13 ----A---- C:\Windows\system32\umpnpmgr.dll
2014-10-26 18:31:13 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-10-26 18:31:13 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-10-26 18:31:13 ----A---- C:\Windows\system32\drivers\srv.sys
2014-10-26 18:31:12 ----A---- C:\Windows\system32\OxpsConverter.exe
2014-10-26 18:31:12 ----A---- C:\Windows\system32\drivers\afd.sys
2014-10-26 18:31:07 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2014-10-26 18:31:07 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2014-10-26 18:31:07 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-10-26 18:31:07 ----A---- C:\Windows\system32\drivers\hidclass.sys
2014-10-26 18:31:07 ----A---- C:\Windows\system32\dnsrslvr.dll
2014-10-26 18:31:07 ----A---- C:\Windows\system32\dnscacheugc.exe
2014-10-26 18:31:07 ----A---- C:\Windows\system32\dnsapi.dll
2014-10-26 18:31:06 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-10-26 18:31:06 ----A---- C:\Windows\system32\tzres.dll
2014-10-26 18:31:05 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-10-26 18:31:05 ----A---- C:\Windows\SYSWOW64\jscript.dll
2014-10-26 18:31:05 ----A---- C:\Windows\system32\vbscript.dll
2014-10-26 18:31:05 ----A---- C:\Windows\system32\jscript.dll
2014-10-26 18:31:03 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-10-26 18:31:03 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-10-26 18:31:03 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2014-10-26 18:31:03 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-10-26 18:31:03 ----A---- C:\Windows\system32\qdvd.dll
2014-10-26 18:31:03 ----A---- C:\Windows\system32\psisdecd.dll
2014-10-26 18:31:02 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-10-26 18:31:02 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-10-26 18:31:02 ----A---- C:\Windows\system32\cdd.dll
2014-10-26 18:30:58 ----A---- C:\Windows\SYSWOW64\rastls.dll
2014-10-26 18:30:58 ----A---- C:\Windows\system32\rastls.dll
2014-10-26 18:30:57 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-10-26 18:30:57 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-10-26 18:30:55 ----A---- C:\Windows\system32\drivers\partmgr.sys
2014-10-26 18:30:54 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2014-10-26 18:30:54 ----A---- C:\Windows\system32\drivers\usbcir.sys
2014-10-26 18:30:51 ----A---- C:\Windows\system32\winresume.exe
2014-10-26 18:30:51 ----A---- C:\Windows\system32\winload.exe
2014-10-26 18:30:51 ----A---- C:\Windows\system32\kdusb.dll
2014-10-26 18:30:51 ----A---- C:\Windows\system32\kdcom.dll
2014-10-26 18:30:51 ----A---- C:\Windows\system32\kd1394.dll
2014-10-26 18:30:48 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2014-10-26 18:30:48 ----A---- C:\Windows\SYSWOW64\browcli.dll
2014-10-26 18:30:48 ----A---- C:\Windows\system32\netapi32.dll
2014-10-26 18:30:48 ----A---- C:\Windows\system32\browser.dll
2014-10-26 18:30:48 ----A---- C:\Windows\system32\browcli.dll
2014-10-26 18:30:47 ----A---- C:\Windows\SYSWOW64\synceng.dll
2014-10-26 18:30:47 ----A---- C:\Windows\system32\synceng.dll
2014-10-26 18:30:47 ----A---- C:\Windows\system32\profsvc.dll
2014-10-26 18:30:46 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2014-10-26 18:30:46 ----A---- C:\Windows\system32\taskhost.exe
2014-10-26 18:30:46 ----A---- C:\Windows\system32\dpnet.dll
2014-10-26 18:30:45 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-10-26 18:30:38 ----A---- C:\Windows\system32\drivers\fvevol.sys
2014-10-26 18:30:37 ----A---- C:\Windows\SYSWOW64\srclient.dll
2014-10-26 18:30:37 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2014-10-26 18:30:37 ----A---- C:\Windows\system32\srcore.dll
2014-10-26 18:30:37 ----A---- C:\Windows\system32\prevhost.exe
2014-10-26 18:30:37 ----A---- C:\Windows\system32\FXSCOVER.exe
2014-10-26 18:30:36 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2014-10-26 18:30:36 ----A---- C:\Windows\system32\inetcomm.dll
2014-10-26 18:30:29 ----A---- C:\Windows\system32\sspisrv.dll
2014-10-26 18:30:29 ----A---- C:\Windows\system32\sspicli.dll
2014-10-26 18:30:29 ----A---- C:\Windows\system32\secur32.dll
2014-10-26 18:30:29 ----A---- C:\Windows\system32\lsass.exe
2014-10-26 18:30:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-10-26 18:30:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-10-26 18:30:29 ----A---- C:\Windows\system32\drivers\cng.sys
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-10-26 18:30:27 ----A---- C:\Windows\system32\cryptsvc.dll
2014-10-26 18:30:27 ----A---- C:\Windows\system32\cryptnet.dll
2014-10-26 18:30:27 ----A---- C:\Windows\system32\crypt32.dll
2014-10-26 18:30:27 ----A---- C:\Windows\system32\certutil.exe
2014-10-26 18:30:27 ----A---- C:\Windows\system32\certenc.dll
2014-10-26 18:30:23 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2014-10-26 18:30:23 ----A---- C:\Windows\system32\msvcrt.dll
2014-10-26 18:30:23 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-10-26 18:21:50 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2014-10-26 18:21:49 ----A---- C:\Windows\system32\cdosys.dll
2014-10-26 18:21:20 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-10-26 18:21:20 ----A---- C:\Windows\system32\rpcrt4.dll
2014-10-26 18:21:06 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-10-26 18:21:06 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2014-10-26 18:21:06 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2014-10-26 18:21:06 ----A---- C:\Windows\system32\drivers\bowser.sys
2014-10-26 18:20:47 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-10-26 18:20:47 ----A---- C:\Windows\system32\win32k.sys
2014-10-26 18:20:47 ----A---- C:\Windows\system32\gdi32.dll
2014-10-26 18:20:46 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2014-10-26 18:20:46 ----A---- C:\Windows\system32\EncDec.dll
2014-10-26 18:20:45 ----A---- C:\Windows\system32\scavengeui.dll
2014-10-26 18:20:44 ----A---- C:\Windows\system32\DWrite.dll
2014-10-26 18:20:43 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-10-26 18:20:43 ----A---- C:\Windows\system32\localspl.dll
2014-10-26 18:20:43 ----A---- C:\Windows\system32\FntCache.dll
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-10-26 18:20:42 ----A---- C:\Windows\system32\wscript.exe
2014-10-26 18:20:42 ----A---- C:\Windows\system32\scrrun.dll
2014-10-26 18:20:42 ----A---- C:\Windows\system32\oleaut32.dll
2014-10-26 18:20:42 ----A---- C:\Windows\system32\oleacc.dll
2014-10-26 18:20:42 ----A---- C:\Windows\system32\cscript.exe
2014-10-26 18:20:41 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-10-26 18:20:41 ----A---- C:\Windows\system32\packager.dll
2014-10-26 18:20:40 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-10-26 18:20:40 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-10-26 18:20:40 ----A---- C:\Windows\system32\nshwfp.dll
2014-10-26 18:20:40 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-10-26 18:20:40 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-10-26 18:12:56 ----A---- C:\Windows\system32\wups2.dll
2014-10-26 18:12:56 ----A---- C:\Windows\system32\wucltux.dll
2014-10-26 18:12:56 ----A---- C:\Windows\system32\wuaueng.dll
2014-10-26 18:12:56 ----A---- C:\Windows\system32\wuauclt.exe
2014-10-26 18:12:52 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-10-26 18:12:52 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-10-26 18:12:52 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-10-26 18:12:52 ----A---- C:\Windows\system32\wups.dll
2014-10-26 18:12:52 ----A---- C:\Windows\system32\wudriver.dll
2014-10-26 18:12:52 ----A---- C:\Windows\system32\wuapi.dll
2014-10-26 18:12:42 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-10-26 18:12:42 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-10-26 18:12:42 ----A---- C:\Windows\system32\wuwebv.dll
2014-10-26 18:12:42 ----A---- C:\Windows\system32\wuapp.exe
2014-10-26 18:07:39 ----D---- C:\Program Files (x86)\Cisco
2014-10-26 18:07:35 ----SHD---- C:\Windows\Installer
2014-10-26 18:07:18 ----A---- C:\Windows\system32\drivers\rtwlane.sys
2014-10-26 18:07:13 ----A---- C:\Windows\system32\Rtlihvs.dll
2014-10-26 18:07:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-26 18:07:03 ----D---- C:\Program Files (x86)\REALTEK PCIE Wireless LAN Driver
2014-10-26 18:07:03 ----A---- C:\Windows\SYSWOW64\ISSRemoveSP.exe
2014-10-26 18:07:03 ----A---- C:\Windows\SwUSB.exe
2014-10-26 18:07:03 ----A---- C:\Windows\runSW.exe
2014-10-26 16:42:54 ----D---- C:\Users\Matej\AppData\Roaming\Identities
2014-10-26 16:42:42 ----SD---- C:\Users\Matej\AppData\Roaming\Microsoft
2014-10-26 16:42:42 ----D---- C:\Users\Matej\AppData\Roaming\Media Center Programs
2014-10-26 16:42:36 ----SHD---- C:\Recovery
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Šablony
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Plocha
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Oblíbené položky
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Nabídka Start
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Dokumenty
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Data aplikací
2014-10-26 16:42:33 ----D---- C:\Windows\SoftwareDistribution
2014-10-26 16:36:35 ----D---- C:\Windows\Prefetch
2014-10-26 16:36:04 ----SHD---- C:\System Volume Information
2014-10-26 16:36:04 ----ASH---- C:\pagefile.sys
2014-10-26 16:36:04 ----ASH---- C:\hiberfil.sys
2014-10-26 16:35:46 ----D---- C:\Windows\Panther
2014-10-10 08:59:12 ----A---- C:\Windows\system32\drivers\EpfwLWF.sys

======List of files/folders modified in the last 1 month======

2014-11-01 22:01:08 ----RD---- C:\Program Files
2014-11-01 21:53:19 ----D---- C:\Windows\System32
2014-11-01 21:53:19 ----D---- C:\Windows\inf
2014-11-01 21:53:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-01 21:48:13 ----D---- C:\Windows\system32\drivers
2014-11-01 21:47:44 ----D---- C:\Windows\Temp
2014-11-01 21:47:06 ----D---- C:\Windows\Registration
2014-11-01 21:19:27 ----A---- C:\Windows\system32\SearchIndexer.exe
2014-11-01 21:00:48 ----HD---- C:\ProgramData
2014-11-01 20:44:25 ----D---- C:\Windows
2014-11-01 20:44:21 ----D---- C:\Windows\system32\catroot2
2014-11-01 20:44:21 ----D---- C:\Windows\system32\catroot
2014-11-01 20:44:16 ----D---- C:\Windows\system32\DriverStore
2014-11-01 20:40:12 ----A---- C:\Windows\system32\sppsvc.exe
2014-10-31 15:47:54 ----D---- C:\Program Files (x86)\Windows Mail
2014-10-31 13:06:34 ----D---- C:\Windows\system32\config
2014-10-31 12:13:35 ----D---- C:\Program Files\Windows Mail
2014-10-29 13:42:03 ----D---- C:\Windows\rescache
2014-10-29 13:41:41 ----D---- C:\Windows\Logs
2014-10-28 18:09:31 ----D---- C:\Windows\system32\wdi
2014-10-27 21:23:50 ----D---- C:\Windows\system32\drivers\UMDF
2014-10-27 21:15:04 ----D---- C:\Windows\Microsoft.NET
2014-10-27 20:29:50 ----D---- C:\Windows\system32\Tasks
2014-10-27 19:59:13 ----RSD---- C:\Windows\assembly
2014-10-27 17:44:27 ----RD---- C:\Program Files (x86)
2014-10-27 17:44:27 ----D---- C:\Program Files (x86)\Common Files
2014-10-27 17:43:47 ----D---- C:\Windows\system32\LogFiles
2014-10-27 17:37:05 ----A---- C:\Windows\system32\fsquirt.exe
2014-10-27 17:36:28 ----D---- C:\Program Files (x86)\Windows Sidebar
2014-10-27 17:36:12 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2014-10-27 17:36:09 ----D---- C:\Program Files (x86)\Windows Media Player
2014-10-27 17:35:03 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-27 17:28:45 ----D---- C:\Program Files\Internet Explorer
2014-10-26 19:54:21 ----D---- C:\Windows\winsxs
2014-10-26 19:53:55 ----D---- C:\Windows\SysWOW64
2014-10-26 19:42:54 ----A---- C:\Windows\system32\VSSVC.exe
2014-10-26 19:37:34 ----A---- C:\Windows\system32\msiexec.exe
2014-10-26 19:35:30 ----D---- C:\Program Files\Windows Media Player
2014-10-26 19:33:38 ----D---- C:\Windows\SYSWOW64\migration
2014-10-26 19:33:38 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-10-26 19:33:38 ----D---- C:\Windows\system32\wbem
2014-10-26 19:33:38 ----D---- C:\Windows\system32\migration
2014-10-26 19:33:38 ----D---- C:\Windows\system32\cs-CZ
2014-10-26 19:33:30 ----D---- C:\Windows\ehome
2014-10-26 19:33:29 ----D---- C:\Windows\AppPatch
2014-10-26 19:33:24 ----D---- C:\Windows\system32\Boot
2014-10-26 19:33:23 ----RSD---- C:\Windows\Fonts
2014-10-26 19:29:45 ----D---- C:\Program Files\Windows Sidebar
2014-10-26 19:29:28 ----D---- C:\Program Files\Windows Photo Viewer
2014-10-26 19:29:15 ----D---- C:\Program Files\Windows Journal
2014-10-26 19:29:13 ----D---- C:\Program Files\Windows Defender
2014-10-26 19:26:59 ----D---- C:\Program Files\DVD Maker
2014-10-26 19:25:30 ----A---- C:\Windows\system32\wbengine.exe
2014-10-26 19:25:29 ----A---- C:\Windows\system32\vds.exe
2014-10-26 19:25:28 ----A---- C:\Windows\system32\UI0Detect.exe
2014-10-26 19:25:27 ----A---- C:\Windows\system32\snmptrap.exe
2014-10-26 19:25:24 ----A---- C:\Windows\system32\msdtc.exe
2014-10-26 19:25:20 ----A---- C:\Windows\system32\FXSSVC.exe
2014-10-26 19:25:18 ----A---- C:\Windows\SYSWOW64\dllhost.exe
2014-10-26 19:25:18 ----A---- C:\Windows\system32\dllhost.exe
2014-10-26 19:25:15 ----A---- C:\Windows\SYSWOW64\svchost.exe
2014-10-26 19:25:15 ----A---- C:\Windows\system32\alg.exe
2014-10-26 18:56:07 ----D---- C:\Windows\SYSWOW64\en-US
2014-10-26 18:56:07 ----D---- C:\Windows\system32\en-US
2014-10-26 18:49:49 ----D---- C:\Windows\ShellNew
2014-10-26 18:49:49 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-10-26 18:49:49 ----D---- C:\Program Files\Common Files
2014-10-26 18:49:23 ----D---- C:\Program Files (x86)\MSBuild
2014-10-26 18:49:17 ----SD---- C:\ProgramData\Microsoft
2014-10-26 18:47:04 ----D---- C:\Program Files\Common Files\System
2014-10-26 18:47:04 ----A---- C:\Windows\win.ini
2014-10-26 18:39:39 ----D---- C:\Windows\Tasks
2014-10-26 18:35:21 ----D---- C:\Windows\debug
2014-10-26 18:06:53 ----D---- C:\Windows\system32\restore
2014-10-26 16:49:43 ----D---- C:\Windows\system32\CodeIntegrity
2014-10-26 16:42:51 ----SHD---- C:\$Recycle.Bin
2014-10-26 16:42:42 ----RD---- C:\Users
2014-10-26 16:42:36 ----D---- C:\Program Files\Windows NT
2014-10-26 16:38:52 ----D---- C:\Windows\system32\sysprep

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2014-06-27 20464]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 BfLwf;Qualcomm Atheros Bandwidth Control; C:\Windows\system32\DRIVERS\bflwfx64.sys [2014-04-10 82096]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-21 80384]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2013-04-25 365936]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-06-24 4746344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-07-15 4012632]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2014-06-27 383472]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2014-06-27 795120]
R3 Ke2200;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\e22w7x64.sys [2014-03-27 129200]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-01-11 64624]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [2010-10-22 14136]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-10-04 19272]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\Windows\system32\DRIVERS\rtwlane.sys [2014-10-26 1514568]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-21 552448]
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-06-24 451576]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-10-04 1148744]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-06-24 324568]
R2 MSI_LiveUpdate_Service;MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2014-09-18 1723856]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-10-04 1795912]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-10-04 19439944]
R2 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-10-26 736256]
R2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [2014-04-17 344576]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-10-26 692736]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-10-26 703488]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S2 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-10-26 1816576]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-10-26 607232]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-10-26 839168]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2014-10-26 52020736]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2014-10-26 5487104]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-26 672768]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-26 672768]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#2 Příspěvek od Rudy »

Zdravím!
Spusťte nejprve tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

sixdee
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 01 lis 2014 21:36

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#3 Příspěvek od sixdee »

# AdwCleaner v3.311 - Report created 01/11/2014 at 22:42:26
# Updated 30/09/2014 by Xplode
# Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
# Username : Matej - MATEJ-PC
# Running from : C:\Users\Matej\Desktop\adwcleaner_3.311.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****


***** [ Scheduled Tasks ] *****


***** [ Shortcuts ] *****


***** [ Registry ] *****


***** [ Browsers ] *****

-\\ Internet Explorer v8.0.7601.18595


-\\ Google Chrome v38.0.2125.111

[ File : C:\Users\Matej\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [930 octets] - [01/11/2014 22:36:30]
AdwCleaner[R1].txt - [923 octets] - [01/11/2014 22:38:29]
AdwCleaner[R2].txt - [1039 octets] - [01/11/2014 22:41:41]
AdwCleaner[S0].txt - [994 octets] - [01/11/2014 22:37:02]
AdwCleaner[S1].txt - [983 octets] - [01/11/2014 22:39:10]
AdwCleaner[S2].txt - [962 octets] - [01/11/2014 22:42:26]

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1021 octets] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#4 Příspěvek od Rudy »

Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\AutoKMS.ini
C:\Windows\AutoKMS.exe

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"AutoKMS"=-

:services
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

sixdee
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 01 lis 2014 21:36

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#5 Příspěvek od sixdee »

Nový RSIT log:

Logfile of random's system information tool 1.10 (written by random/random)
Run by Matej at 2014-11-02 11:32:44
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 425 GB (90%) free of 473 GB
Total RAM: 8112 MB (77% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 11:32:46, on 2. 11. 2014
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v8.00 (8.00.7601.18595)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Matej.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Killer Network Manager.lnk = ?
O8 - Extra context menu item: E&xportovať do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Od&oslať do programu OneNote - res://C:\PROGRA~1\MICROS~2\Office14\ONBttnIE.dll/105
O9 - Extra button: Odoslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&oslať do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Prepojené poznámky programu OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_LiveUpdate_Service - Micro-Star International - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Qualcomm Atheros Killer Service V2 - Qualcomm Atheros - C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 7773 bytes

======Listing Processes======



\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs

C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 22158160
\??\C:\Windows\system32\conhost.exe "-19362111972072267904-1103831491969172530-1154195136-707978492-2137814236-143129746
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
C:\Windows\system32\msiexec.exe /V
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe"
"C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
"C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe"
"C:\Program Files (x86)\Skype\Updater\Updater.exe"
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\UI0Detect.exe
C:\Windows\System32\vds.exe
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" nss c7686988-03f0-4d81-8e0b-2d6c5bd239f3 1
\??\C:\Windows\system32\conhost.exe "54326515-1263421417431583811478291511468374772-218512681976198838-1235039966
C:\Windows\system32\vssvc.exe
"C:\Windows\system32\wbengine.exe"
C:\Windows\system32\wbem\WmiApSrv.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"taskhost.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe" serviceapp
\??\C:\Windows\system32\conhost.exe "-4765843082076384065604267519-1248930859-1782688741-851269556-1322767176-355816952
C:\Windows\system32\svchost.exe -k bthsvcs
taskeng.exe {263FDB68-14CD-4516-8047-6388909C23F4}
"C:\Windows\system32\Dwm.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\Explorer.EXE
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\system32\wbem\wmiprvse.exe
igfxEM.exe
igfxHK.exe
igfxTray.exe
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe" -minimize
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe1_ Global\UsGthrCtrlFltPipeMssGthrPipe1 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="4988.0.924651183\480484962" --disable-d3d11 --supports-dual-gpus=false --gpu-driver-bug-workarounds=1,6,16 --gpu-vendor-id=0x8086 --gpu-device-id=0x0416 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=10.18.10.3650 --ignored=" --type=renderer " /prefetch:822062411
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group16 pct:1g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --extension-process --enable-webrtc-hw-h264-encoding --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="4988.2.197440391\1389780851" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group16 pct:1g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="4988.3.1195996946\1405497800" /prefetch:673131151
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --lang=sk --force-fieldtrials="AutoReloadExperiment/Enabled/AutoReloadVisibleOnlyExperiment/Enabled/BrowserBlacklist/Enabled/DomRel-Enable/disable/EmbeddedSearch/Group16 pct:1g stable:pp2 prefetch_results:1 reuse_instant_search_base_page:1/ExtensionInstallVerification/Enforce/OmniboxBundledExperimentV1/Preperiod_A4_StableBookmarksIndexURLs/PasswordGeneration/Disabled/Prerender/PrerenderEnabled/PrerenderLocalPredictorSpec/LocalPredictor=Disabled/QUIC/Disabled/RapporRollout/Enabled/SDCH/EnabledAll/SafeBrowsingIncidentReportingService/Default/SettingsEnforcement/enforce_always_with_extensions_and_dse/ShowAppLauncherPromo/ShowPromoUntilDismissed/Test0PercentDefault/group_01/UMA-Dynamic-Binary-Uniformity-Trial/default/UMA-Dynamic-Uniformity-Trial/Group6/UMA-New-Install-Uniformity-Trial/Control/UMA-Population-Restrict/normal/UMA-Session-Randomized-Uniformity-Trial-5-Percent/group_02/UMA-Uniformity-Trial-1-Percent/group_83/UMA-Uniformity-Trial-10-Percent/default/UMA-Uniformity-Trial-100-Percent/group_01/UMA-Uniformity-Trial-20-Percent/group_04/UMA-Uniformity-Trial-5-Percent/group_19/UMA-Uniformity-Trial-50-Percent/group_01/VoiceTrigger/Install/" --renderer-print-preview --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --device-scale-factor=1 --enable-delegated-renderer --channel="4988.4.693456712\919091482" /prefetch:673131151
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Matej\Desktop\RSITx64.exe"

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files\Microsoft Office\Office14\BCSSync.exe [2014-10-26 674816]
"AutoKMS"=C:\Windows\AutoKMS.exe []
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-10-27 1008128]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2014-10-04 2462536]
"ShadowPlay"=C:\Windows\system32\nvspcap64.dll [2014-10-04 2800296]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-06-30 13672664]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2013-04-25 2889072]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-10-01 22065760]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2014-09-18 3476432]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2014-06-27 292848]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Killer Network Manager.lnk - C:\Windows\Installer\{4692B750-DE88-4DCF-9163-745AF5604B24}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\hitmanpro37.sys]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1
"ForceActiveDesktopOn"=0
"HideSCAHealth"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"MSVideo8"=VfWWDM32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2014-11-02 11:31:01 ----D---- C:\_OTM
2014-11-01 22:42:01 ----A---- C:\Windows\SYSWOW64\sqlite3.dll
2014-11-01 22:36:27 ----D---- C:\AdwCleaner
2014-11-01 22:01:08 ----D---- C:\rsit
2014-11-01 22:01:08 ----D---- C:\Program Files\trend micro
2014-11-01 21:01:14 ----D---- C:\Program Files\HitmanPro
2014-11-01 21:00:48 ----D---- C:\ProgramData\HitmanPro
2014-11-01 20:59:03 ----D---- C:\Users\Matej\AppData\Roaming\uTorrent
2014-11-01 20:44:18 ----D---- C:\Program Files\Elantech
2014-11-01 20:44:14 ----A---- C:\Windows\system32\drivers\ETD.sys
2014-10-27 20:29:30 ----D---- C:\Math Studio
2014-10-27 17:44:30 ----D---- C:\Users\Matej\AppData\Roaming\Skype
2014-10-27 17:44:27 ----RD---- C:\Program Files (x86)\Skype
2014-10-27 17:44:24 ----D---- C:\ProgramData\Skype
2014-10-26 21:50:49 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2014-10-26 19:58:37 ----A---- C:\Windows\system32\{F33C3B9B-72AF-418A-B3FD-560646F7CDA2}.bat
2014-10-26 19:53:47 ----D---- C:\ProgramData\ESET
2014-10-26 19:53:47 ----D---- C:\Program Files\ESET
2014-10-26 19:52:22 ----A---- C:\Windows\SYSWOW64\OpenCL.DLL
2014-10-26 19:52:22 ----A---- C:\Windows\system32\OpenCL.DLL
2014-10-26 19:51:09 ----A---- C:\Windows\system32\MetroIntelGenericUIFramework.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\IntelOpenCL32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\IntelCpHeciSvc.exe
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\Intel_OpenCL_ICD32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\iglhsip32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\iglhcp32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igfxexps32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igfxcmrt32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igfxcmjit32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igfx11cmrt32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\SYSWOW64\igdusc32.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\IntelOpenCL64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\Intel_OpenCL_ICD64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\iglhsip64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\iglhcp64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxTray.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxOSP.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxLHMLibv2_0.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxLHMLib.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxLHM.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxHK.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxext.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxexps.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxEMLibv2_0.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxEMLib.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxEM.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDTCM.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDILibv2_0.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDILib.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDI.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDHLibv2_0.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDHLib.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxDH.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxCUIServicePS.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxCUIService.exe
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxCoIn_v3650.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxcmrt64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfxcmjit64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igfx11cmrt64.dll
2014-10-26 19:51:08 ----A---- C:\Windows\system32\igdusc64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\SYSWOW64\igdumdim32.dll
2014-10-26 19:51:07 ----A---- C:\Windows\SYSWOW64\igdrcl32.dll
2014-10-26 19:51:07 ----A---- C:\Windows\SYSWOW64\igdmd32.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\igdumdim64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\igdrcl64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\igdmd64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\igdfcl64.dll
2014-10-26 19:51:07 ----A---- C:\Windows\system32\drivers\igdkmd64.sys
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igdfcl32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igdde32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igdbcl32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igdail32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igd11dxva32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\SYSWOW64\igd10iumd32.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igdde64.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igdbcl64.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igdail64.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igd11dxva64.dll
2014-10-26 19:51:06 ----A---- C:\Windows\system32\igd10iumd64.dll
2014-10-26 19:51:05 ----A---- C:\Windows\SYSWOW64\ig75icd32.dll
2014-10-26 19:51:05 ----A---- C:\Windows\system32\ig75icd64.dll
2014-10-26 19:51:05 ----A---- C:\Windows\system32\IccLibDll_x64.dll
2014-10-26 19:51:05 ----A---- C:\Windows\system32\Gfxv4_0.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\Gfxv2_0.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\GfxUIEx.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\drivers\IntcDAud.sys
2014-10-26 19:51:05 ----A---- C:\Windows\system32\DPTopologyAppv2_0.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\DPTopologyApp.exe
2014-10-26 19:51:05 ----A---- C:\Windows\system32\difx64.exe
2014-10-26 19:50:43 ----D---- C:\Program Files (x86)\Intel
2014-10-26 19:50:43 ----A---- C:\Windows\system32\drivers\USB3Ver.dll
2014-10-26 19:50:12 ----D---- C:\Intel
2014-10-26 19:50:11 ----A---- C:\Windows\system32\WdfCoInstaller01009.dll
2014-10-26 19:50:11 ----A---- C:\Windows\system32\drivers\iusb3xhc.sys
2014-10-26 19:50:11 ----A---- C:\Windows\system32\drivers\iusb3hub.sys
2014-10-26 19:50:11 ----A---- C:\Windows\system32\drivers\iusb3hcs.sys
2014-10-26 19:40:03 ----D---- C:\Windows\SYSWOW64\RTCOM
2014-10-26 19:40:03 ----D---- C:\Program Files\Realtek
2014-10-26 19:39:50 ----A---- C:\Windows\system32\WavesGUILib64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\SRSWOW64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\SRSTSX64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\SRSTSH64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\SRSHP64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\RtPgEx64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\RtkCfg64.dll
2014-10-26 19:39:50 ----A---- C:\Windows\system32\drivers\RTKVHD64.sys
2014-10-26 19:39:49 ----A---- C:\Windows\SYSWOW64\MBAPO232.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RtkApi64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTEEP64A.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTEEL64A.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTEEG64A.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTEED64A.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RtDataProc64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RTCOM64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RP3DHT64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RP3DAA64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RltkAPO64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\RCoInstII64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\MBWrp64.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\MBAPO264.dll
2014-10-26 19:39:49 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2014-10-26 19:39:49 ----A---- C:\Windows\system32\drivers\MBfilt64.sys
2014-10-26 19:39:48 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\FMAPO64.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\AERTAR64.dll
2014-10-26 19:39:48 ----A---- C:\Windows\system32\AERTAC64.dll
2014-10-26 19:39:47 ----D---- C:\Program Files (x86)\Realtek
2014-10-26 19:39:42 ----HD---- C:\Program Files (x86)\Temp
2014-10-26 19:39:42 ----A---- C:\Windows\RtlExUpd.dll
2014-10-26 19:39:20 ----D---- C:\Program Files\Intel
2014-10-26 19:39:07 ----D---- C:\ProgramData\Package Cache
2014-10-26 19:37:45 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2014-10-26 19:37:45 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2014-10-26 19:37:45 ----A---- C:\Windows\system32\d3dx11_43.dll
2014-10-26 19:37:45 ----A---- C:\Windows\system32\d3dx10_43.dll
2014-10-26 19:37:44 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2014-10-26 19:37:44 ----A---- C:\Windows\system32\D3DX9_43.dll
2014-10-26 19:37:24 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2014-10-26 19:37:24 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2014-10-26 19:37:24 ----A---- C:\Windows\system32\nvspcap64.dll
2014-10-26 19:37:24 ----A---- C:\Windows\system32\nvspbridge64.dll
2014-10-26 19:33:38 ----SD---- C:\Windows\system32\CompatTel
2014-10-26 19:33:35 ----D---- C:\Windows\SYSWOW64\Wat
2014-10-26 19:33:35 ----D---- C:\Windows\system32\Wat
2014-10-26 19:23:06 ----D---- C:\Users\Matej\AppData\Roaming\Macromedia
2014-10-26 19:23:04 ----D---- C:\ProgramData\Adobe
2014-10-26 19:22:58 ----D---- C:\Users\Matej\AppData\Roaming\Adobe
2014-10-26 19:22:54 ----A---- C:\Windows\system32\browserchoice.exe
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFx.dll
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFSvc.dll
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFPlatform.dll
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFHost.exe
2014-10-26 19:11:45 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
2014-10-26 19:11:45 ----A---- C:\Windows\system32\drivers\WUDFRd.sys
2014-10-26 19:11:45 ----A---- C:\Windows\system32\drivers\WUDFPf.sys
2014-10-26 19:05:38 ----A---- C:\Windows\SYSWOW64\wmi.dll
2014-10-26 19:05:38 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2014-10-26 19:05:38 ----A---- C:\Windows\SYSWOW64\imagehlp.dll
2014-10-26 19:05:38 ----A---- C:\Windows\system32\wmi.dll
2014-10-26 19:05:38 ----A---- C:\Windows\system32\wintrust.dll
2014-10-26 19:05:38 ----A---- C:\Windows\system32\imagehlp.dll
2014-10-26 19:05:38 ----A---- C:\Windows\system32\drivers\fs_rec.sys
2014-10-26 19:02:38 ----A---- C:\Windows\acpimof.dll
2014-10-26 19:02:34 ----D---- C:\Program Files (x86)\MSI
2014-10-26 19:02:34 ----D---- C:\MSILU
2014-10-26 18:59:46 ----D---- C:\ProgramData\Qualcomm
2014-10-26 18:59:26 ----D---- C:\Program Files\Qualcomm Atheros
2014-10-26 18:58:59 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2014-10-26 18:56:57 ----D---- C:\ProgramData\NVIDIA Corporation
2014-10-26 18:56:54 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2014-10-26 18:56:53 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2014-10-26 18:56:53 ----A---- C:\Windows\system32\nvaudcap64v.dll
2014-10-26 18:56:53 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2014-10-26 18:56:46 ----D---- C:\Program Files\NVIDIA Corporation
2014-10-26 18:54:25 ----D---- C:\ProgramData\Downloaded Installations
2014-10-26 18:49:49 ----D---- C:\Program Files\Common Files\DESIGNER
2014-10-26 18:49:29 ----D---- C:\Program Files\Microsoft Synchronization Services
2014-10-26 18:49:17 ----D---- C:\Windows\PCHEALTH
2014-10-26 18:49:17 ----D---- C:\Program Files\Microsoft Sync Framework
2014-10-26 18:49:17 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2014-10-26 18:49:17 ----D---- C:\Program Files (x86)\Microsoft.NET
2014-10-26 18:47:35 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2014-10-26 18:46:42 ----D---- C:\Program Files\Microsoft Analysis Services
2014-10-26 18:46:42 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2014-10-26 18:46:00 ----D---- C:\Program Files (x86)\Microsoft Office
2014-10-26 18:45:59 ----D---- C:\Program Files\Microsoft Office
2014-10-26 18:45:58 ----D---- C:\ProgramData\Microsoft Help
2014-10-26 18:45:35 ----RHD---- C:\MSOCache
2014-10-26 18:42:14 ----D---- C:\Users\Matej\AppData\Roaming\WinRAR
2014-10-26 18:41:33 ----D---- C:\Program Files\WinRAR
2014-10-26 18:39:36 ----D---- C:\Program Files (x86)\Google
2014-10-26 18:35:22 ----D---- C:\Windows\system32\MRT
2014-10-26 18:35:20 ----A---- C:\Windows\system32\MRT.exe
2014-10-26 18:33:58 ----A---- C:\Windows\SYSWOW64\infocardapi.dll
2014-10-26 18:33:58 ----A---- C:\Windows\SYSWOW64\icardres.dll
2014-10-26 18:33:58 ----A---- C:\Windows\SYSWOW64\icardagt.exe
2014-10-26 18:33:58 ----A---- C:\Windows\system32\infocardapi.dll
2014-10-26 18:33:58 ----A---- C:\Windows\system32\icardres.dll
2014-10-26 18:33:58 ----A---- C:\Windows\system32\icardagt.exe
2014-10-26 18:33:52 ----A---- C:\Windows\SYSWOW64\TsWpfWrp.exe
2014-10-26 18:33:52 ----A---- C:\Windows\system32\TsWpfWrp.exe
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\wininet.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\mshta.exe
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\msfeedssync.exe
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\msfeedsbs.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2014-10-26 18:33:06 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\urlmon.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\url.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\mshta.exe
2014-10-26 18:33:06 ----A---- C:\Windows\system32\msfeedssync.exe
2014-10-26 18:33:06 ----A---- C:\Windows\system32\msfeedsbs.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\jsproxy.dll
2014-10-26 18:33:06 ----A---- C:\Windows\system32\iertutil.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\url.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\ieui.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2014-10-26 18:33:05 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\wininet.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\msfeeds.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\ieUnatt.exe
2014-10-26 18:33:05 ----A---- C:\Windows\system32\ieui.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\dxtrans.dll
2014-10-26 18:33:05 ----A---- C:\Windows\system32\dxtmsft.dll
2014-10-26 18:33:04 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2014-10-26 18:33:04 ----A---- C:\Windows\system32\ieframe.dll
2014-10-26 18:33:03 ----A---- C:\Windows\system32\mshtmled.dll
2014-10-26 18:33:03 ----A---- C:\Windows\system32\mshtml.dll
2014-10-26 18:32:50 ----A---- C:\Windows\system32\generaltel.dll
2014-10-26 18:32:50 ----A---- C:\Windows\system32\aepdu.dll
2014-10-26 18:32:50 ----A---- C:\Windows\system32\aeinv.dll
2014-10-26 18:32:43 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2014-10-26 18:32:43 ----A---- C:\Windows\system32\lsasrv.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\winsta.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\schannel.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\secur32.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\credssp.dll
2014-10-26 18:32:42 ----A---- C:\Windows\SYSWOW64\aaclient.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\winsta.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\winlogon.exe
2014-10-26 18:32:42 ----A---- C:\Windows\system32\wdigest.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\TSpkg.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\tsgqec.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\termsrv.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\schannel.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\rdrmemptylst.exe
2014-10-26 18:32:42 ----A---- C:\Windows\system32\rdpwsx.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\rdpcorekmts.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\ncrypt.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\msv1_0.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\mstscax.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\mstsc.exe
2014-10-26 18:32:42 ----A---- C:\Windows\system32\kerberos.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2014-10-26 18:32:42 ----A---- C:\Windows\system32\drivers\rdpwd.sys
2014-10-26 18:32:42 ----A---- C:\Windows\system32\credssp.dll
2014-10-26 18:32:42 ----A---- C:\Windows\system32\aaclient.dll
2014-10-26 18:32:35 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2014-10-26 18:32:35 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2014-10-26 18:32:35 ----A---- C:\Windows\system32\ntoskrnl.exe
2014-10-26 18:32:34 ----A---- C:\Windows\SYSWOW64\objsel.dll
2014-10-26 18:32:34 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2014-10-26 18:32:34 ----A---- C:\Windows\system32\objsel.dll
2014-10-26 18:32:34 ----A---- C:\Windows\system32\KernelBase.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\wincredprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\dpapiprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\dimsroam.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\cngprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\capiprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2014-10-26 18:32:33 ----A---- C:\Windows\SYSWOW64\adprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\wincredprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\smss.exe
2014-10-26 18:32:33 ----A---- C:\Windows\system32\dpapiprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\dimsroam.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\csrsrv.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\cngprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\capiprovider.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\apisetschema.dll
2014-10-26 18:32:33 ----A---- C:\Windows\system32\adprovider.dll
2014-10-26 18:32:31 ----A---- C:\Windows\SYSWOW64\tdh.dll
2014-10-26 18:32:31 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2014-10-26 18:32:31 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2014-10-26 18:32:31 ----A---- C:\Windows\system32\tdh.dll
2014-10-26 18:32:31 ----A---- C:\Windows\system32\ntdll.dll
2014-10-26 18:32:31 ----A---- C:\Windows\system32\advapi32.dll
2014-10-26 18:32:20 ----A---- C:\Windows\system32\Wdfres.dll
2014-10-26 18:32:20 ----A---- C:\Windows\system32\drivers\WdfLdr.sys
2014-10-26 18:32:20 ----A---- C:\Windows\system32\drivers\Wdf01000.sys
2014-10-26 18:32:12 ----A---- C:\Windows\SYSWOW64\Wpc.dll
2014-10-26 18:32:12 ----A---- C:\Windows\SYSWOW64\gameux.dll
2014-10-26 18:32:12 ----A---- C:\Windows\system32\Wpc.dll
2014-10-26 18:32:12 ----A---- C:\Windows\system32\gameux.dll
2014-10-26 18:32:09 ----A---- C:\Windows\SYSWOW64\shdocvw.dll
2014-10-26 18:32:09 ----A---- C:\Windows\system32\shdocvw.dll
2014-10-26 18:32:07 ----A---- C:\Windows\SYSWOW64\mswsock.dll
2014-10-26 18:32:07 ----A---- C:\Windows\system32\mswsock.dll
2014-10-26 18:32:07 ----A---- C:\Windows\system32\drivers\tcpip.sys
2014-10-26 18:32:07 ----A---- C:\Windows\system32\drivers\netio.sys
2014-10-26 18:32:07 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
2014-10-26 18:32:06 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2014-10-26 18:32:06 ----A---- C:\Windows\system32\poqexec.exe
2014-10-26 18:32:05 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2014-10-26 18:32:05 ----A---- C:\Windows\SYSWOW64\msi.dll
2014-10-26 18:32:05 ----A---- C:\Windows\SYSWOW64\authui.dll
2014-10-26 18:32:05 ----A---- C:\Windows\system32\msihnd.dll
2014-10-26 18:32:05 ----A---- C:\Windows\system32\msi.dll
2014-10-26 18:32:05 ----A---- C:\Windows\system32\consent.exe
2014-10-26 18:32:05 ----A---- C:\Windows\system32\authui.dll
2014-10-26 18:32:05 ----A---- C:\Windows\system32\appinfo.dll
2014-10-26 18:32:02 ----A---- C:\Windows\SYSWOW64\shell32.dll
2014-10-26 18:32:02 ----A---- C:\Windows\system32\shell32.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2014-10-26 18:32:00 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\wow32.dll
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\user.exe
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\setup16.exe
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2014-10-26 18:32:00 ----A---- C:\Windows\SYSWOW64\instnm.exe
2014-10-26 18:32:00 ----A---- C:\Windows\system32\wow64win.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\wow64cpu.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\wow64.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\winsrv.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\ntvdm64.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\kernel32.dll
2014-10-26 18:32:00 ----A---- C:\Windows\system32\conhost.exe
2014-10-26 18:31:34 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2014-10-26 18:31:34 ----A---- C:\Windows\system32\win32spl.dll
2014-10-26 18:31:33 ----A---- C:\Windows\SYSWOW64\nlaapi.dll
2014-10-26 18:31:33 ----A---- C:\Windows\SYSWOW64\netevent.dll
2014-10-26 18:31:33 ----A---- C:\Windows\SYSWOW64\netcorehc.dll
2014-10-26 18:31:33 ----A---- C:\Windows\SYSWOW64\ncsi.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\nlasvc.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\nlaapi.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\netevent.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\netcorehc.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\ncsi.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\iphlpsvc.dll
2014-10-26 18:31:33 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2014-10-26 18:31:29 ----A---- C:\Windows\SYSWOW64\rdpcore.dll
2014-10-26 18:31:29 ----A---- C:\Windows\system32\rdpcore.dll
2014-10-26 18:31:29 ----A---- C:\Windows\system32\drivers\tdtcp.sys
2014-10-26 18:31:28 ----A---- C:\Windows\SYSWOW64\iologmsg.dll
2014-10-26 18:31:28 ----A---- C:\Windows\system32\iologmsg.dll
2014-10-26 18:31:28 ----A---- C:\Windows\system32\drivers\storport.sys
2014-10-26 18:31:28 ----A---- C:\Windows\system32\drivers\msiscsi.sys
2014-10-26 18:31:28 ----A---- C:\Windows\system32\drivers\Diskdump.sys
2014-10-26 18:31:23 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2014-10-26 18:31:23 ----A---- C:\Windows\system32\WebClnt.dll
2014-10-26 18:31:22 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2014-10-26 18:31:22 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2014-10-26 18:31:22 ----A---- C:\Windows\system32\davclnt.dll
2014-10-26 18:31:19 ----A---- C:\Windows\SYSWOW64\cryptdlg.dll
2014-10-26 18:31:19 ----A---- C:\Windows\system32\cryptdlg.dll
2014-10-26 18:31:13 ----A---- C:\Windows\SYSWOW64\drvinst.exe
2014-10-26 18:31:13 ----A---- C:\Windows\SYSWOW64\devrtl.dll
2014-10-26 18:31:13 ----A---- C:\Windows\SYSWOW64\devobj.dll
2014-10-26 18:31:13 ----A---- C:\Windows\SYSWOW64\cfgmgr32.dll
2014-10-26 18:31:13 ----A---- C:\Windows\system32\umpnpmgr.dll
2014-10-26 18:31:13 ----A---- C:\Windows\system32\drivers\srvnet.sys
2014-10-26 18:31:13 ----A---- C:\Windows\system32\drivers\srv2.sys
2014-10-26 18:31:13 ----A---- C:\Windows\system32\drivers\srv.sys
2014-10-26 18:31:12 ----A---- C:\Windows\system32\OxpsConverter.exe
2014-10-26 18:31:12 ----A---- C:\Windows\system32\drivers\afd.sys
2014-10-26 18:31:07 ----A---- C:\Windows\SYSWOW64\dnscacheugc.exe
2014-10-26 18:31:07 ----A---- C:\Windows\SYSWOW64\dnsapi.dll
2014-10-26 18:31:07 ----A---- C:\Windows\system32\drivers\hidparse.sys
2014-10-26 18:31:07 ----A---- C:\Windows\system32\drivers\hidclass.sys
2014-10-26 18:31:07 ----A---- C:\Windows\system32\dnsrslvr.dll
2014-10-26 18:31:07 ----A---- C:\Windows\system32\dnscacheugc.exe
2014-10-26 18:31:07 ----A---- C:\Windows\system32\dnsapi.dll
2014-10-26 18:31:06 ----A---- C:\Windows\SYSWOW64\tzres.dll
2014-10-26 18:31:06 ----A---- C:\Windows\system32\tzres.dll
2014-10-26 18:31:05 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2014-10-26 18:31:05 ----A---- C:\Windows\SYSWOW64\jscript.dll
2014-10-26 18:31:05 ----A---- C:\Windows\system32\vbscript.dll
2014-10-26 18:31:05 ----A---- C:\Windows\system32\jscript.dll
2014-10-26 18:31:03 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2014-10-26 18:31:03 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2014-10-26 18:31:03 ----A---- C:\Windows\SYSWOW64\psisdecd.dll
2014-10-26 18:31:03 ----A---- C:\Windows\system32\WMVDECOD.DLL
2014-10-26 18:31:03 ----A---- C:\Windows\system32\qdvd.dll
2014-10-26 18:31:03 ----A---- C:\Windows\system32\psisdecd.dll
2014-10-26 18:31:02 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2014-10-26 18:31:02 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2014-10-26 18:31:02 ----A---- C:\Windows\system32\cdd.dll
2014-10-26 18:30:58 ----A---- C:\Windows\SYSWOW64\rastls.dll
2014-10-26 18:30:58 ----A---- C:\Windows\system32\rastls.dll
2014-10-26 18:30:57 ----A---- C:\Windows\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2014-10-26 18:30:57 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2014-10-26 18:30:55 ----A---- C:\Windows\system32\drivers\partmgr.sys
2014-10-26 18:30:54 ----A---- C:\Windows\system32\drivers\usbvideo.sys
2014-10-26 18:30:54 ----A---- C:\Windows\system32\drivers\usbcir.sys
2014-10-26 18:30:51 ----A---- C:\Windows\system32\winresume.exe
2014-10-26 18:30:51 ----A---- C:\Windows\system32\winload.exe
2014-10-26 18:30:51 ----A---- C:\Windows\system32\kdusb.dll
2014-10-26 18:30:51 ----A---- C:\Windows\system32\kdcom.dll
2014-10-26 18:30:51 ----A---- C:\Windows\system32\kd1394.dll
2014-10-26 18:30:48 ----A---- C:\Windows\SYSWOW64\netapi32.dll
2014-10-26 18:30:48 ----A---- C:\Windows\SYSWOW64\browcli.dll
2014-10-26 18:30:48 ----A---- C:\Windows\system32\netapi32.dll
2014-10-26 18:30:48 ----A---- C:\Windows\system32\browser.dll
2014-10-26 18:30:48 ----A---- C:\Windows\system32\browcli.dll
2014-10-26 18:30:47 ----A---- C:\Windows\SYSWOW64\synceng.dll
2014-10-26 18:30:47 ----A---- C:\Windows\system32\synceng.dll
2014-10-26 18:30:47 ----A---- C:\Windows\system32\profsvc.dll
2014-10-26 18:30:46 ----A---- C:\Windows\SYSWOW64\dpnet.dll
2014-10-26 18:30:46 ----A---- C:\Windows\system32\taskhost.exe
2014-10-26 18:30:46 ----A---- C:\Windows\system32\dpnet.dll
2014-10-26 18:30:45 ----A---- C:\Windows\system32\drivers\usb8023.sys
2014-10-26 18:30:38 ----A---- C:\Windows\system32\drivers\fvevol.sys
2014-10-26 18:30:37 ----A---- C:\Windows\SYSWOW64\srclient.dll
2014-10-26 18:30:37 ----A---- C:\Windows\SYSWOW64\prevhost.exe
2014-10-26 18:30:37 ----A---- C:\Windows\system32\srcore.dll
2014-10-26 18:30:37 ----A---- C:\Windows\system32\prevhost.exe
2014-10-26 18:30:37 ----A---- C:\Windows\system32\FXSCOVER.exe
2014-10-26 18:30:36 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2014-10-26 18:30:36 ----A---- C:\Windows\system32\inetcomm.dll
2014-10-26 18:30:29 ----A---- C:\Windows\system32\sspisrv.dll
2014-10-26 18:30:29 ----A---- C:\Windows\system32\sspicli.dll
2014-10-26 18:30:29 ----A---- C:\Windows\system32\secur32.dll
2014-10-26 18:30:29 ----A---- C:\Windows\system32\lsass.exe
2014-10-26 18:30:29 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2014-10-26 18:30:29 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2014-10-26 18:30:29 ----A---- C:\Windows\system32\drivers\cng.sys
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\certutil.exe
2014-10-26 18:30:27 ----A---- C:\Windows\SYSWOW64\certenc.dll
2014-10-26 18:30:27 ----A---- C:\Windows\system32\cryptsvc.dll
2014-10-26 18:30:27 ----A---- C:\Windows\system32\cryptnet.dll
2014-10-26 18:30:27 ----A---- C:\Windows\system32\crypt32.dll
2014-10-26 18:30:27 ----A---- C:\Windows\system32\certutil.exe
2014-10-26 18:30:27 ----A---- C:\Windows\system32\certenc.dll
2014-10-26 18:30:23 ----A---- C:\Windows\SYSWOW64\msvcrt.dll
2014-10-26 18:30:23 ----A---- C:\Windows\system32\msvcrt.dll
2014-10-26 18:30:23 ----A---- C:\Windows\system32\drivers\ntfs.sys
2014-10-26 18:21:50 ----A---- C:\Windows\SYSWOW64\cdosys.dll
2014-10-26 18:21:49 ----A---- C:\Windows\system32\cdosys.dll
2014-10-26 18:21:20 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2014-10-26 18:21:20 ----A---- C:\Windows\system32\rpcrt4.dll
2014-10-26 18:21:06 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2014-10-26 18:21:06 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2014-10-26 18:21:06 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2014-10-26 18:21:06 ----A---- C:\Windows\system32\drivers\bowser.sys
2014-10-26 18:20:47 ----A---- C:\Windows\SYSWOW64\gdi32.dll
2014-10-26 18:20:47 ----A---- C:\Windows\system32\win32k.sys
2014-10-26 18:20:47 ----A---- C:\Windows\system32\gdi32.dll
2014-10-26 18:20:46 ----A---- C:\Windows\SYSWOW64\EncDec.dll
2014-10-26 18:20:46 ----A---- C:\Windows\system32\EncDec.dll
2014-10-26 18:20:45 ----A---- C:\Windows\system32\scavengeui.dll
2014-10-26 18:20:44 ----A---- C:\Windows\system32\DWrite.dll
2014-10-26 18:20:43 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2014-10-26 18:20:43 ----A---- C:\Windows\system32\localspl.dll
2014-10-26 18:20:43 ----A---- C:\Windows\system32\FntCache.dll
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\wscript.exe
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\scrrun.dll
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\oleacc.dll
2014-10-26 18:20:42 ----A---- C:\Windows\SYSWOW64\cscript.exe
2014-10-26 18:20:42 ----A---- C:\Windows\system32\wscript.exe
2014-10-26 18:20:42 ----A---- C:\Windows\system32\scrrun.dll
2014-10-26 18:20:42 ----A---- C:\Windows\system32\oleaut32.dll
2014-10-26 18:20:42 ----A---- C:\Windows\system32\oleacc.dll
2014-10-26 18:20:42 ----A---- C:\Windows\system32\cscript.exe
2014-10-26 18:20:41 ----A---- C:\Windows\SYSWOW64\packager.dll
2014-10-26 18:20:41 ----A---- C:\Windows\system32\packager.dll
2014-10-26 18:20:40 ----A---- C:\Windows\SYSWOW64\nshwfp.dll
2014-10-26 18:20:40 ----A---- C:\Windows\SYSWOW64\FWPUCLNT.DLL
2014-10-26 18:20:40 ----A---- C:\Windows\system32\nshwfp.dll
2014-10-26 18:20:40 ----A---- C:\Windows\system32\IKEEXT.DLL
2014-10-26 18:20:40 ----A---- C:\Windows\system32\FWPUCLNT.DLL
2014-10-26 18:12:56 ----A---- C:\Windows\system32\wups2.dll
2014-10-26 18:12:56 ----A---- C:\Windows\system32\wucltux.dll
2014-10-26 18:12:56 ----A---- C:\Windows\system32\wuaueng.dll
2014-10-26 18:12:56 ----A---- C:\Windows\system32\wuauclt.exe
2014-10-26 18:12:52 ----A---- C:\Windows\SYSWOW64\wups.dll
2014-10-26 18:12:52 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2014-10-26 18:12:52 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2014-10-26 18:12:52 ----A---- C:\Windows\system32\wups.dll
2014-10-26 18:12:52 ----A---- C:\Windows\system32\wudriver.dll
2014-10-26 18:12:52 ----A---- C:\Windows\system32\wuapi.dll
2014-10-26 18:12:42 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2014-10-26 18:12:42 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2014-10-26 18:12:42 ----A---- C:\Windows\system32\wuwebv.dll
2014-10-26 18:12:42 ----A---- C:\Windows\system32\wuapp.exe
2014-10-26 18:07:39 ----D---- C:\Program Files (x86)\Cisco
2014-10-26 18:07:35 ----SHD---- C:\Windows\Installer
2014-10-26 18:07:18 ----A---- C:\Windows\system32\drivers\rtwlane.sys
2014-10-26 18:07:13 ----A---- C:\Windows\system32\Rtlihvs.dll
2014-10-26 18:07:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2014-10-26 18:07:03 ----D---- C:\Program Files (x86)\REALTEK PCIE Wireless LAN Driver
2014-10-26 18:07:03 ----A---- C:\Windows\SYSWOW64\ISSRemoveSP.exe
2014-10-26 18:07:03 ----A---- C:\Windows\SwUSB.exe
2014-10-26 18:07:03 ----A---- C:\Windows\runSW.exe
2014-10-26 16:42:54 ----D---- C:\Users\Matej\AppData\Roaming\Identities
2014-10-26 16:42:42 ----SD---- C:\Users\Matej\AppData\Roaming\Microsoft
2014-10-26 16:42:42 ----D---- C:\Users\Matej\AppData\Roaming\Media Center Programs
2014-10-26 16:42:36 ----SHD---- C:\Recovery
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Šablony
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Plocha
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Oblíbené položky
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Nabídka Start
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Dokumenty
2014-10-26 16:42:36 ----SHD---- C:\ProgramData\Data aplikací
2014-10-26 16:42:33 ----D---- C:\Windows\SoftwareDistribution
2014-10-26 16:36:35 ----D---- C:\Windows\Prefetch
2014-10-26 16:36:04 ----SHD---- C:\System Volume Information
2014-10-26 16:36:04 ----ASH---- C:\pagefile.sys
2014-10-26 16:36:04 ----ASH---- C:\hiberfil.sys
2014-10-26 16:35:46 ----D---- C:\Windows\Panther
2014-10-10 08:59:12 ----A---- C:\Windows\system32\drivers\EpfwLWF.sys

======List of files/folders modified in the last 1 month======

2014-11-02 11:31:39 ----D---- C:\Windows\Registration
2014-11-02 11:31:02 ----D---- C:\Windows\Tasks
2014-11-02 11:31:02 ----D---- C:\Windows
2014-11-01 22:49:19 ----D---- C:\Windows\System32
2014-11-01 22:49:19 ----D---- C:\Windows\inf
2014-11-01 22:49:19 ----A---- C:\Windows\system32\PerfStringBackup.INI
2014-11-01 22:42:01 ----D---- C:\Windows\SysWOW64
2014-11-01 22:37:02 ----HD---- C:\ProgramData
2014-11-01 22:01:08 ----RD---- C:\Program Files
2014-11-01 21:48:13 ----D---- C:\Windows\system32\drivers
2014-11-01 21:47:44 ----D---- C:\Windows\Temp
2014-11-01 21:19:27 ----A---- C:\Windows\system32\SearchIndexer.exe
2014-11-01 20:44:21 ----D---- C:\Windows\system32\catroot2
2014-11-01 20:44:21 ----D---- C:\Windows\system32\catroot
2014-11-01 20:44:16 ----D---- C:\Windows\system32\DriverStore
2014-11-01 20:40:12 ----A---- C:\Windows\system32\sppsvc.exe
2014-10-31 15:47:54 ----D---- C:\Program Files (x86)\Windows Mail
2014-10-31 13:06:34 ----D---- C:\Windows\system32\config
2014-10-31 12:13:35 ----D---- C:\Program Files\Windows Mail
2014-10-29 13:42:03 ----D---- C:\Windows\rescache
2014-10-29 13:41:41 ----D---- C:\Windows\Logs
2014-10-28 18:09:31 ----D---- C:\Windows\system32\wdi
2014-10-27 21:23:50 ----D---- C:\Windows\system32\drivers\UMDF
2014-10-27 21:15:04 ----D---- C:\Windows\Microsoft.NET
2014-10-27 20:29:50 ----D---- C:\Windows\system32\Tasks
2014-10-27 19:59:13 ----RSD---- C:\Windows\assembly
2014-10-27 17:44:27 ----RD---- C:\Program Files (x86)
2014-10-27 17:44:27 ----D---- C:\Program Files (x86)\Common Files
2014-10-27 17:43:47 ----D---- C:\Windows\system32\LogFiles
2014-10-27 17:37:05 ----A---- C:\Windows\system32\fsquirt.exe
2014-10-27 17:36:28 ----D---- C:\Program Files (x86)\Windows Sidebar
2014-10-27 17:36:12 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2014-10-27 17:36:09 ----D---- C:\Program Files (x86)\Windows Media Player
2014-10-27 17:35:03 ----D---- C:\Program Files (x86)\Internet Explorer
2014-10-27 17:28:45 ----D---- C:\Program Files\Internet Explorer
2014-10-26 19:54:21 ----D---- C:\Windows\winsxs
2014-10-26 19:42:54 ----A---- C:\Windows\system32\VSSVC.exe
2014-10-26 19:37:34 ----A---- C:\Windows\system32\msiexec.exe
2014-10-26 19:35:30 ----D---- C:\Program Files\Windows Media Player
2014-10-26 19:33:38 ----D---- C:\Windows\SYSWOW64\migration
2014-10-26 19:33:38 ----D---- C:\Windows\SYSWOW64\cs-CZ
2014-10-26 19:33:38 ----D---- C:\Windows\system32\wbem
2014-10-26 19:33:38 ----D---- C:\Windows\system32\migration
2014-10-26 19:33:38 ----D---- C:\Windows\system32\cs-CZ
2014-10-26 19:33:30 ----D---- C:\Windows\ehome
2014-10-26 19:33:29 ----D---- C:\Windows\AppPatch
2014-10-26 19:33:24 ----D---- C:\Windows\system32\Boot
2014-10-26 19:33:23 ----RSD---- C:\Windows\Fonts
2014-10-26 19:29:45 ----D---- C:\Program Files\Windows Sidebar
2014-10-26 19:29:28 ----D---- C:\Program Files\Windows Photo Viewer
2014-10-26 19:29:15 ----D---- C:\Program Files\Windows Journal
2014-10-26 19:29:13 ----D---- C:\Program Files\Windows Defender
2014-10-26 19:26:59 ----D---- C:\Program Files\DVD Maker
2014-10-26 19:25:30 ----A---- C:\Windows\system32\wbengine.exe
2014-10-26 19:25:29 ----A---- C:\Windows\system32\vds.exe
2014-10-26 19:25:28 ----A---- C:\Windows\system32\UI0Detect.exe
2014-10-26 19:25:27 ----A---- C:\Windows\system32\snmptrap.exe
2014-10-26 19:25:24 ----A---- C:\Windows\system32\msdtc.exe
2014-10-26 19:25:20 ----A---- C:\Windows\system32\FXSSVC.exe
2014-10-26 19:25:18 ----A---- C:\Windows\SYSWOW64\dllhost.exe
2014-10-26 19:25:18 ----A---- C:\Windows\system32\dllhost.exe
2014-10-26 19:25:15 ----A---- C:\Windows\SYSWOW64\svchost.exe
2014-10-26 19:25:15 ----A---- C:\Windows\system32\alg.exe
2014-10-26 18:56:07 ----D---- C:\Windows\SYSWOW64\en-US
2014-10-26 18:56:07 ----D---- C:\Windows\system32\en-US
2014-10-26 18:49:49 ----D---- C:\Windows\ShellNew
2014-10-26 18:49:49 ----D---- C:\Program Files\Common Files\Microsoft Shared
2014-10-26 18:49:49 ----D---- C:\Program Files\Common Files
2014-10-26 18:49:23 ----D---- C:\Program Files (x86)\MSBuild
2014-10-26 18:49:17 ----SD---- C:\ProgramData\Microsoft
2014-10-26 18:47:04 ----D---- C:\Program Files\Common Files\System
2014-10-26 18:47:04 ----A---- C:\Windows\win.ini
2014-10-26 18:35:21 ----D---- C:\Windows\debug
2014-10-26 18:06:53 ----D---- C:\Windows\system32\restore
2014-10-26 16:49:43 ----D---- C:\Windows\system32\CodeIntegrity
2014-10-26 16:42:51 ----SHD---- C:\$Recycle.Bin
2014-10-26 16:42:42 ----RD---- C:\Users
2014-10-26 16:42:36 ----D---- C:\Program Files\Windows NT
2014-10-26 16:38:52 ----D---- C:\Windows\system32\sysprep

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2014-06-27 20464]
R0 nvpciflt;nvpciflt; C:\Windows\system32\DRIVERS\nvpciflt.sys [2013-09-05 30496]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 BfLwf;Qualcomm Atheros Bandwidth Control; C:\Windows\system32\DRIVERS\bflwfx64.sys [2014-04-10 82096]
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R3 BthEnum;Služba Bluetooth Enumerator; C:\Windows\system32\DRIVERS\BthEnum.sys [2009-07-14 41984]
R3 BthPan;Zařízení Bluetooth (síť PAN); C:\Windows\system32\DRIVERS\bthpan.sys [2009-07-14 118784]
R3 BTHUSB;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2010-11-21 80384]
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2013-04-25 365936]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-06-24 4746344]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2014-07-15 4012632]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2014-06-27 383472]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2014-06-27 795120]
R3 Ke2200;NDIS Miniport Driver for Killer e2201/e2202 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\e22w7x64.sys [2014-03-27 129200]
R3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys [2009-11-18 32344]
R3 MEIx64;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\HECIx64.sys [2013-01-11 64624]
R3 NTIOLib_1_0_4;NTIOLib_1_0_4; \??\C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [2010-10-22 14136]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2014-10-04 19272]
R3 nvvad_WaveExtensible;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2014-09-04 38048]
R3 RFCOMM;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2009-07-14 158720]
R3 RTWlanE;Realtek Wireless LAN 802.11n PCI-E Network Adapter; C:\Windows\system32\DRIVERS\rtwlane.sys [2014-10-26 1514568]
S3 BTHPORT;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2010-11-21 552448]
S3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2014-06-24 451576]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2014-10-04 1148744]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-06-24 324568]
R2 MSI_LiveUpdate_Service;MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2014-09-18 1723856]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2014-10-04 1795912]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [2014-10-04 19439944]
R2 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-10-26 736256]
R2 Qualcomm Atheros Killer Service V2;Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [2014-04-17 344576]
R2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2014-04-03 315008]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2014-10-26 692736]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2014-10-26 703488]
S2 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2014-10-26 1816576]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2014-10-26 607232]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-10-26 839168]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files\Microsoft Office\Office14\GROOVE.EXE [2014-10-26 52020736]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2014-10-26 5487104]
S4 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-26 672768]
S4 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-10-26 672768]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2010-03-18 124240]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#6 Příspěvek od Rudy »

Smazáno, log je již OK. Znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

sixdee
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 01 lis 2014 21:36

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#7 Příspěvek od sixdee »

Nepomohlo, HitmanPro stále detekuje vírusy a aktualizácie a Eset stále nejde inštalovať., aj ked som iba ja správca systému :/

Obrázek

A problémy s aktiváciou sú taktiež stále, pritom pri zadaní kódu hodí tabuľku úspešne aktivovaný windows, ale po reštartovaní systému to opäť naskočí, že nemám originál.
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#8 Příspěvek od Rudy »

Ten log z Hitmana mi přijde docela jako blábol. Já tohle nepoužívám. Máte pravou kopii windows?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

sixdee
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 01 lis 2014 21:36

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#9 Příspěvek od sixdee »

áno mám pravý windows, nálepka nalepená na spodnej strane notebooku. Pre Windows 7 64bit Home premium, a taký som aj nainštaloval.. :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#10 Příspěvek od Rudy »

Namátkou otestujte soubory, nalezené Hitmanem online na www.virustotal.com . Pak dejte info.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

sixdee
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 01 lis 2014 21:36

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#11 Příspěvek od sixdee »

Aký prvý mi Hitman našiel tak som to hodil na virus total a výsledok:

SHA256: a1bf7602d8497a27dce1672046e07c4ad4ef250eafd185353f78aef103061cb0
Názov súboru: wmpnetwk.exe
Pomer detekcie: 31 / 54
Dátum analýzy: 2014-11-02 12:39:07 UTC ( pred 0 minút )
Obrázek

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#12 Příspěvek od Rudy »

Tak tenhle ano, to bych vám řekl i bez Hitmana. Myslím ale ty na obrázku výše.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

sixdee
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 01 lis 2014 21:36

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#13 Příspěvek od sixdee »

Ale veď tamto sú celé priečinky, nemám to ako dať do virustotalu.

Update:
Zistil som, že Hitman pri kontrole všetko posiela na kontrolu do virustotal.com

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119548
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#14 Příspěvek od Rudy »

Je tam napsán exáč, který najdete v tom adresáři.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

sixdee
Návštěvník
Návštěvník
Příspěvky: 20
Registrován: 01 lis 2014 21:36

Re: Vírusov sa nedá zbaviť ani po formátovaní disku a reinst

#15 Příspěvek od sixdee »

Skúsil som to a hlási aj virustotal že je tam vírus, nainštaloval som drivery na zvukovku a MSI update 6 SW od MSI a hned tam naskočil vírus, všetko čo nainštalujem tak v tom vznikne vírus.. Už naozaj neviem čo s tým :(

Odpovědět