
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Možný kelogger
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Možný kelogger
Zdravím, prosím o kontrolu logu, mám podezření na keylogger. Děkuji
Logfile of random's system information tool 1.10 (written by random/random)
Run by PC1 at 2016-01-25 16:41:39
Microsoft Windows 10 Home
System drive C: has 833 GB (89%) free of 931 GB
Total RAM: 7113 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:41:48, on 25. 1. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal
Running processes:
C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files\trend micro\PC1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [DropboxOEM] "C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe" auto
O4 - HKCU\..\Run: [OneDrive] "C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: avast! SecureLine.lnk = C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Unknown owner - C:\WINDOWS\System32\appdrvrem01.exe (file missing)
O23 - Service: @oem34.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: avast! SecureLine (SecureLine) - Unknown owner - C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11815 bytes
======Listing Processes======
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
C:\WINDOWS\system32\atiesrxx.exe
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
"C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\WINDOWS\system32\BtwRSupportService.exe
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe"
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
dashost.exe {11fff32c-2068-4765-b0faa187de4f59ca}
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\WLANExt.exe 1406228791360
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"dwm.exe"
atieclxx
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /ANDREA_BF_BYPASS
"C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe" /hideui
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobroker.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe"
"C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\AVAST Software\SecureLine\SecureLine.exe" /nogui
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe"
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
taskhostw.exe
taskeng.exe {752BB900-ADF8-4CA0-BD18-1F8E6FC62FE0}
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe134_ Global\UsGthrCtrlFltPipeMssGthrPipe134 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 632 636 404 8192 604
"C:\Users\PC1\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\PC1\AppData\Roaming\Mozilla\Firefox\Profiles\6f1nbwuz.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.286 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.286 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-01-03 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-01-23 2339032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-01-03 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-07-25 585568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-01-23 1731800]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-09-03 7636696]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-09-02 1396592]
"SimplePass"=C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [2014-03-28 3962936]
"OPBHOBroker"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [2014-03-28 415288]
"OPBHOBrokerDesktop"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [2014-03-28 415288]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-10-02 3945672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-12-26 551112]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HPMessageService"=C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [2014-09-02 507144]
"DropboxOEM"=C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2014-09-02 462160]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
avast! SecureLine.lnk - C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-01-25 16:49:39 ----A---- C:\WINDOWS\system32\drivers\appdrv01.sys
2016-01-25 16:49:39 ----A---- C:\WINDOWS\system32\appdrvrem01.exe
2016-01-25 16:41:40 ----D---- C:\Program Files\trend micro
2016-01-25 16:41:39 ----D---- C:\rsit
2016-01-25 16:00:45 ----A---- C:\WINDOWS\system32\drivers\appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946}.sys
2016-01-25 15:46:31 ----D---- C:\Program Files (x86)\Centauri
2016-01-25 14:01:30 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2016-01-24 13:22:59 ----D---- C:\Users\PC1\AppData\Roaming\AMD
2016-01-24 13:20:35 ----D---- C:\.jagex_cache_32
2016-01-16 14:09:55 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-16 14:09:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-01-16 14:09:49 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-01-16 14:09:49 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-01-16 14:09:48 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-01-16 14:09:48 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-01-16 14:09:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-01-16 14:09:46 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-01-16 14:09:43 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-01-16 14:09:42 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-01-16 14:09:42 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-01-16 14:09:41 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-01-16 14:09:41 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\mfps.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2016-01-16 14:09:38 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2016-01-16 14:09:37 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\WMSPDMOD.DLL
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\facecredentialprovider.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\evr.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOD.DLL
2016-01-16 14:09:36 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\quartz.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\invagent.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\devinv.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\advapi32.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\uReFS.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\schannel.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\PhoneService.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\mftranscode.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\SYSWOW64\MP3DMOD.DLL
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\WMSPDMOE.DLL
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\winload.exe
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\qedit.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\MP3DMOD.DLL
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\usermgrcli.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\qedit.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\usermgrcli.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\ProximityCommon.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\omadmclient.exe
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-01-16 14:09:30 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOE.DLL
2016-01-16 14:09:30 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\DscCore.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\drivers\BthLEEnum.sys
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\aitstatic.exe
2016-01-16 14:09:29 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-01-16 14:09:29 ----A---- C:\WINDOWS\system32\aepic.dll
2016-01-10 12:54:16 ----AD---- C:\Program Files (x86)\Cheat Engine 6.5
2016-01-08 23:36:50 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-01-03 16:05:08 ----AD---- C:\Program Files\Microsoft Office 15
2015-12-30 21:43:35 ----AD---- C:\Program Files\CCleaner
2015-12-30 21:31:38 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_5.dll
2015-12-30 21:31:38 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2015-12-30 21:31:37 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2015-12-30 21:31:37 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2015-12-30 21:31:36 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2015-12-30 21:31:36 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2015-12-30 21:31:33 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_42.dll
2015-12-30 21:31:33 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2015-12-30 21:31:32 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2015-12-30 21:31:32 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2015-12-30 21:31:30 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2015-12-30 21:31:30 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_3.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2015-12-30 21:31:25 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2015-12-30 21:31:25 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2015-12-30 21:31:18 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2015-12-30 21:31:18 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2015-12-30 21:31:12 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2015-12-30 21:31:12 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2015-12-30 21:31:11 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2015-12-30 21:31:11 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2015-12-30 21:31:10 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2015-12-30 21:31:10 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2015-12-30 21:31:09 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2015-12-30 21:31:09 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2015-12-30 21:31:02 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2015-12-30 21:31:02 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2015-12-30 21:31:00 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2015-12-30 21:31:00 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2015-12-30 21:30:57 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2015-12-30 21:30:57 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2015-12-30 21:30:53 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2015-12-30 21:30:53 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2015-12-30 21:30:51 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2015-12-30 21:30:51 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2015-12-30 21:30:50 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2015-12-30 21:30:50 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\system32\d3dx10.dll
2015-12-30 21:30:46 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_32.dll
2015-12-30 21:30:46 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2015-12-30 21:30:42 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2015-12-30 21:30:41 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2015-12-30 21:30:41 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2015-12-30 21:30:40 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2015-12-30 21:30:40 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2015-12-30 21:30:38 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2015-12-30 21:30:38 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2015-12-30 21:30:37 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2015-12-30 21:30:37 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2015-12-30 21:30:36 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2015-12-30 21:30:36 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2015-12-30 21:30:23 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2015-12-30 21:30:19 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2015-12-30 21:30:19 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2015-12-30 21:30:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2015-12-30 21:30:18 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2015-12-30 21:30:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2015-12-30 21:30:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2015-12-30 21:30:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2015-12-30 21:30:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2015-12-30 21:30:11 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2015-12-30 21:30:09 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2015-12-30 21:30:09 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\msvcr80.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\mss32.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2015-12-30 21:20:34 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2015-12-30 21:20:33 ----A---- C:\WINDOWS\SYSWOW64\binkw32.dll
2015-12-28 13:48:39 ----D---- C:\WINDOWS\system32\SleepStudy
2015-12-28 00:54:30 ----D---- C:\Users\PC1\AppData\Roaming\CyberLink
2015-12-26 22:41:11 ----D---- C:\ProgramData\ESET
2015-12-26 22:41:04 ----D---- C:\Program Files\ESET
2015-12-26 21:26:46 ----D---- C:\Users\PC1\AppData\Roaming\DropboxOEM
2015-12-26 15:48:44 ----D---- C:\ProgramData\USOShared
2015-12-26 15:31:30 ----D---- C:\ProgramData\Microsoft OneDrive
2015-12-26 15:21:09 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2015-12-26 15:10:50 ----ASH---- C:\hiberfil.sys
2015-12-26 15:02:32 ----SD---- C:\Users\PC1\AppData\Roaming\Microsoft
2015-12-26 15:01:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-26 15:01:41 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2015-12-26 14:58:07 ----D---- C:\Program Files\Synaptics
2015-12-26 14:58:05 ----D---- C:\WINDOWS\SYSWOW64\sda
2015-12-26 14:57:53 ----D---- C:\Program Files\Common Files\ATI Technologies
2015-12-26 14:57:28 ----D---- C:\Program Files\AMD
2015-12-26 14:56:35 ----D---- C:\WINDOWS\system32\SRSLabs
2015-12-26 14:56:31 ----D---- C:\Program Files\Realtek
2015-12-26 14:56:30 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2015-12-26 14:55:37 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2015-12-26 14:53:50 ----AS---- C:\WINDOWS\bootstat.dat
2015-12-26 14:53:12 ----D---- C:\WINDOWS\Prefetch
2015-12-26 14:52:10 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-26 14:51:05 ----SHD---- C:\Recovery
2015-12-26 14:50:57 ----DC---- C:\WINDOWS\Panther
2015-12-26 14:45:51 ----D---- C:\Windows.old
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MSMPEG2ENC.DLL
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.proxy.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\wpncore.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfds.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MDEServer.exe
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\EncDump.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\dialserver.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioSes.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioEng.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\audiodg.exe
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\readingviewresources.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\MSMPEG2ENC.DLL
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\MFPlay.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\jscript.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iesetup.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iernonce.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\wwapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\mssign32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwansvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Wwanpref.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanmm.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanconn.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwancfg.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wups2.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wsplib.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wshrm.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wininetlui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wininet.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wimserv.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wimgapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wifitask.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wificonnapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Unistore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\twinui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\StorSvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SRH.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\shutdownux.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\shell32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\services.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\rilproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provtool.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provops.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provhandlers.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provengine.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provdatastore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\policymanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\pnidui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\mssign32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\lpk.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\LogonController.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\jsproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ihvrilproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\fontsub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dciman32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\comsvcs.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\catsrvut.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\authui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\AppCapture.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\NmaDirect.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosResource.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosTrace.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosHost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MapControls.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapControlStringsRes.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\ETWCoreUIComponentsResources.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\BingOnlineServices.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32kfull.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32kbase.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\user32.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringconfigsp.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsUtilsV2.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\NmaDirect.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\NMAA.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\nativemap.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosStorage.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosResource.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\moshostcore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\moshost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mos.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mfpmp.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mf.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mapstoasttask.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsStore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsBtSvcProxy.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapControlStringsRes.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InputService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\d3d11.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\cryptngc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\BingOnlineServices.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\BingMaps.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCoreRes.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\BackgroundTransferHost.exe
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\UIAutomationCoreRes.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\fveapibase.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\fveapi.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\dcomp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\cdp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\BackgroundTransferHost.exe
2015-12-26 14:20:21 ----D---- C:\WINDOWS\system32\Microsoft
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2015-12-26 14:16:05 ----D---- C:\Program Files\Reference Assemblies
2015-12-26 14:16:05 ----D---- C:\Program Files\MSBuild
2015-12-26 14:16:05 ----D---- C:\Program Files (x86)\Reference Assemblies
2015-12-26 14:16:05 ----D---- C:\Program Files (x86)\MSBuild
2015-12-26 14:16:05 ----D---- C:\inetpub
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-12-26 14:15:07 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2015-12-26 14:15:06 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-12-26 14:15:05 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
======List of files/folders modified in the last 1 month======
2016-01-25 16:41:40 ----RD---- C:\Program Files
2016-01-25 16:40:51 ----D---- C:\WINDOWS\Temp
2016-01-25 16:04:00 ----D---- C:\WINDOWS\system32\sru
2016-01-25 16:00:45 ----D---- C:\WINDOWS\system32\drivers
2016-01-25 15:49:39 ----D---- C:\WINDOWS\System32
2016-01-25 15:49:37 ----SHD---- C:\WINDOWS\Installer
2016-01-25 15:48:37 ----SHD---- C:\System Volume Information
2016-01-25 15:47:04 ----D---- C:\WINDOWS\Logs
2016-01-25 15:46:31 ----RD---- C:\Program Files (x86)
2016-01-24 19:58:22 ----D---- C:\WINDOWS\AppReadiness
2016-01-24 16:50:34 ----D---- C:\WINDOWS\Microsoft.NET
2016-01-24 16:48:49 ----RSD---- C:\WINDOWS\assembly
2016-01-24 15:11:56 ----HD---- C:\Program Files\WindowsApps
2016-01-23 23:17:10 ----D---- C:\WINDOWS\system32\config
2016-01-23 23:06:42 ----D---- C:\WINDOWS\system32\DriverStore
2016-01-23 19:40:18 ----D---- C:\WINDOWS\SysWOW64
2016-01-23 19:21:27 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-01-23 19:09:27 ----D---- C:\WINDOWS\system32\MRT
2016-01-23 19:05:00 ----A---- C:\WINDOWS\system32\MRT.exe
2016-01-17 12:15:29 ----D---- C:\WINDOWS\INF
2016-01-16 22:12:54 ----HD---- C:\ProgramData
2016-01-16 22:09:20 ----D---- C:\Windows
2016-01-16 16:49:35 ----D---- C:\WINDOWS\WinSxS
2016-01-16 16:46:50 ----D---- C:\WINDOWS\system32\Boot
2016-01-16 16:46:49 ----D---- C:\WINDOWS\system32\appraiser
2016-01-16 16:46:49 ----D---- C:\WINDOWS\AppPatch
2016-01-16 14:51:46 ----D---- C:\Users\PC1\AppData\Roaming\vlc
2016-01-16 14:27:52 ----D---- C:\WINDOWS\CbsTemp
2016-01-16 14:01:57 ----D---- C:\WINDOWS\system32\catroot2
2016-01-10 11:48:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-01-10 00:36:40 ----D---- C:\WINDOWS\OCR
2016-01-08 16:48:17 ----D---- C:\Program Files (x86)\Common Files
2016-01-03 16:09:50 ----SD---- C:\ProgramData\Microsoft
2016-01-03 16:09:00 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-01-03 16:05:24 ----RSD---- C:\WINDOWS\Fonts
2016-01-03 02:40:25 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-01-01 02:17:22 ----D---- C:\WINDOWS\LiveKernelReports
2015-12-31 21:07:48 ----D---- C:\WINDOWS\system32\Tasks
2015-12-30 22:10:51 ----D---- C:\WINDOWS\debug
2015-12-30 22:10:44 ----D---- C:\WINDOWS\SoftwareDistribution
2015-12-29 19:29:33 ----D---- C:\WINDOWS\rescache
2015-12-29 18:08:45 ----D---- C:\WINDOWS\SYSWOW64\winrm
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\WCN
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\wbem
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2015-12-29 18:08:43 ----SD---- C:\WINDOWS\SYSWOW64\F12
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\Printing_Admin_Scripts
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\oobe
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\en-US
2015-12-29 18:08:42 ----SD---- C:\WINDOWS\SYSWOW64\DiagSvcs
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\en
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers\en-US
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers
2015-12-29 18:08:42 ----D---- C:\WINDOWS\system32\winrm
2015-12-29 18:08:39 ----D---- C:\WINDOWS\system32\WCN
2015-12-29 18:08:39 ----D---- C:\WINDOWS\system32\wbem
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\Sysprep
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\slmgr
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\sk-SK
2015-12-29 18:08:37 ----D---- C:\WINDOWS\system32\Printing_Admin_Scripts
2015-12-29 18:08:37 ----D---- C:\WINDOWS\system32\oobe
2015-12-29 18:08:36 ----SD---- C:\WINDOWS\system32\F12
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\migwiz
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\en-US
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\en
2015-12-29 18:08:35 ----SD---- C:\WINDOWS\system32\DiagSvcs
2015-12-29 18:08:35 ----RD---- C:\WINDOWS\PurchaseDialog
2015-12-29 18:08:35 ----RD---- C:\WINDOWS\MiracastView
2015-12-29 18:08:35 ----D---- C:\WINDOWS\system32\drivers\UMDF
2015-12-29 18:08:35 ----D---- C:\WINDOWS\system32\drivers\en-US
2015-12-29 18:08:35 ----D---- C:\WINDOWS\servicing
2015-12-29 18:08:35 ----D---- C:\WINDOWS\PolicyDefinitions
2015-12-29 18:08:34 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2015-12-29 18:08:34 ----RD---- C:\WINDOWS\DevicesFlow
2015-12-29 18:08:34 ----D---- C:\WINDOWS\IME
2015-12-29 18:08:34 ----D---- C:\WINDOWS\Help
2015-12-29 18:08:34 ----D---- C:\WINDOWS\en-US
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Photo Viewer
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Media Player
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Journal
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Defender
2015-12-29 18:08:34 ----D---- C:\Program Files\Internet Explorer
2015-12-29 18:08:34 ----D---- C:\Program Files\Common Files\System
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Media Player
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Defender
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Internet Explorer
2015-12-29 18:06:21 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2015-12-29 18:06:15 ----D---- C:\WINDOWS\system32\en-GB
2015-12-28 00:54:46 ----D---- C:\ProgramData\CyberLink
2015-12-27 18:29:30 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-12-27 18:29:30 ----D---- C:\WINDOWS\system32\cs-CZ
2015-12-27 18:29:27 ----A---- C:\WINDOWS\SYSWOW64\dpnet.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnsvr.exe
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnlobby.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnhupnp.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnhpast.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnathlp.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnaddr.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnet.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\SYSWOW64\dpmodemx.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnathlp.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dpwsockx.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dplayx.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2015-12-27 18:26:41 ----D---- C:\WINDOWS\system32\NDF
2015-12-27 11:06:48 ----D---- C:\WINDOWS\appcompat
2015-12-26 22:42:14 ----HD---- C:\WINDOWS\ELAMBKUP
2015-12-26 22:33:34 ----D---- C:\WINDOWS\system32\CatRoot
2015-12-26 21:35:09 ----D---- C:\WINDOWS\system32\restore
2015-12-26 21:27:08 ----D---- C:\WINDOWS\system32\WDI
2015-12-26 15:54:57 ----D---- C:\ProgramData\McAfee
2015-12-26 15:54:57 ----D---- C:\Program Files\Common Files
2015-12-26 15:48:44 ----D---- C:\ProgramData\USOPrivate
2015-12-26 15:27:58 ----RD---- C:\WINDOWS\PrintDialog
2015-12-26 15:24:10 ----D---- C:\Program Files\Windows NT
2015-12-26 15:23:54 ----D---- C:\WINDOWS\system32\WinBioDatabase
2015-12-26 15:22:11 ----D---- C:\WINDOWS\Registration
2015-12-26 15:20:32 ----D---- C:\WINDOWS\Tasks
2015-12-26 15:16:39 ----D---- C:\WINDOWS\system32\LogFiles
2015-12-26 15:16:32 ----D---- C:\WINDOWS\system32\drivers\etc
2015-12-26 15:10:07 ----AD---- C:\Program Files (x86)\ATI Technologies
2015-12-26 15:06:29 ----D---- C:\WINDOWS\SYSWOW64\zh-TW
2015-12-26 15:06:29 ----D---- C:\WINDOWS\SYSWOW64\zh-HK
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\zh-CN
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\uk-UA
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\tr-TR
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\th-TH
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sv-SE
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-RS
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sl-SI
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ru-RU
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ro-RO
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pt-PT
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pt-BR
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\nl-NL
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\nb-NO
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\lv-LV
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\lt-LT
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ko-KR
2015-12-26 15:06:25 ----D---- C:\WINDOWS\SYSWOW64\ja-JP
2015-12-26 15:06:25 ----D---- C:\WINDOWS\SYSWOW64\it-IT
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\hu-HU
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\hr-HR
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\he-IL
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\fr-FR
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\fi-FI
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\et-EE
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\es-ES
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\el-GR
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\de-DE
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\da-DK
2015-12-26 15:06:22 ----D---- C:\WINDOWS\SYSWOW64\bg-BG
2015-12-26 15:06:22 ----D---- C:\WINDOWS\SYSWOW64\ar-SA
2015-12-26 15:06:22 ----AD---- C:\WINDOWS\SYSWOW64\Adobe
2015-12-26 15:06:20 ----D---- C:\WINDOWS\system32\zh-TW
2015-12-26 15:06:19 ----D---- C:\WINDOWS\system32\zh-HK
2015-12-26 15:06:19 ----D---- C:\WINDOWS\system32\zh-CN
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\uk-UA
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\tr-TR
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\th-TH
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\sv-SE
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2015-12-26 15:06:16 ----D---- C:\WINDOWS\system32\spool
2015-12-26 15:06:15 ----D---- C:\WINDOWS\system32\sl-SI
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\ru-RU
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\ro-RO
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pt-PT
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pt-BR
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pl-PL
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\nl-NL
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\nb-NO
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\migration
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\lv-LV
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\lt-LT
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\ko-KR
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\ja-JP
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\it-IT
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\InputMethod
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\hu-HU
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\hr-HR
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\he-IL
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\fr-FR
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\fi-FI
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\et-EE
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\es-ES
2015-12-26 15:06:04 ----DC---- C:\WINDOWS\system32\DRVSTORE
2015-12-26 15:06:04 ----D---- C:\WINDOWS\system32\el-GR
2015-12-26 15:06:03 ----D---- C:\WINDOWS\system32\de-DE
2015-12-26 15:06:03 ----D---- C:\WINDOWS\system32\da-DK
2015-12-26 15:04:39 ----D---- C:\WINDOWS\system32\bg-BG
2015-12-26 15:04:39 ----D---- C:\WINDOWS\system32\ar-SA
2015-12-26 15:04:33 ----D---- C:\WINDOWS\MediaViewer
2015-12-26 15:04:28 ----D---- C:\WINDOWS\InputMethod
2015-12-26 15:04:22 ----D---- C:\WINDOWS\ADFS
2015-12-26 15:04:19 ----RD---- C:\Users
2015-12-26 15:04:14 ----D---- C:\Program Files (x86)\Windows Mail
2015-12-26 15:04:13 ----AD---- C:\Program Files (x86)\Hewlett-Packard
2015-12-26 15:04:10 ----D---- C:\Program Files\Windows Mail
2015-12-26 15:04:10 ----D---- C:\Program Files (x86)\AMD AVT
2015-12-26 15:04:09 ----D---- C:\Program Files\Common Files\microsoft shared
2015-12-26 15:03:50 ----D---- C:\WINDOWS\system32\Recovery
2015-12-26 15:02:21 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-12-26 14:52:22 ----D---- C:\WINDOWS\ServiceProfiles
2015-12-26 14:45:28 ----D---- C:\WINDOWS\SYSWOW64\migration
2015-12-26 14:45:28 ----D---- C:\WINDOWS\SYSWOW64\Dism
2015-12-26 14:45:28 ----D---- C:\WINDOWS\system32\Dism
2015-12-26 14:45:27 ----D---- C:\WINDOWS\Provisioning
2015-12-26 14:45:27 ----D---- C:\WINDOWS\bcastdvr
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\MUI
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2015-12-26 14:16:07 ----D---- C:\WINDOWS\system32\MUI
2015-12-26 14:16:07 ----D---- C:\WINDOWS\system32\inetsrv
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\wamregps.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisRtl.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisrstap.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisreset.exe
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\ahadmin.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\admwprox.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\wamregps.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisRtl.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisrstap.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisreset.exe
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\ahadmin.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\admwprox.dll
2015-12-26 14:00:54 ----HD---- C:\$WINDOWS.~BT
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amdkmpfd;@oem10.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmpfd.sys [2013-12-14 36608]
R0 amdpsp;@oem26.inf,%amdpsp.SVCDESC%;AMD PSP Service; C:\WINDOWS\system32\DRIVERS\amdpsp.sys [2015-06-23 277240]
R1 appdrv01;Application Driver (01); C:\WINDOWS\System32\Drivers\appdrv01.sys [2016-01-25 3854000]
R1 CLVirtualDrive;CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [2013-11-12 91912]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2015-11-20 263528]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2015-11-20 186784]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 epfwwfpr;epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [2015-11-20 170792]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 AmdAS4;@oem3.inf,%AmdAS4.SVCDESC%;AmdAS4 service; C:\WINDOWS\System32\drivers\AmdAS4.sys [2013-10-24 17640]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-08-01 21637664]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-08-01 682016]
R3 AtiHDAudioService;@oem29.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2015-05-28 102912]
R3 bcbtums;@oem34.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2015-10-01 208176]
R3 BCM43XX;@oem7.inf,%BCM43XX_Service_DispName%;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2014-12-22 7532760]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2015-10-30 84992]
R3 clwvd;@oem0.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\WINDOWS\system32\DRIVERS\clwvd.sys [2014-01-28 41704]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-09-03 4264536]
R3 RSP2STOR;@oem31.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2015-06-05 310528]
R3 RTL8168;@oem9.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\System32\drivers\Rt630x64.sys [2014-07-18 874712]
R3 SynTP;@oem35.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-10-02 619208]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2015-11-20 14976]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 amdkmcsp;@oem26.inf,%amdkmcsp.SVCDESC%;AMD Kernel Mode CSP Service; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [2015-06-23 101104]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2015-10-30 112640]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-01-05 245760]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-01-05 953856]
S3 btwampfl;@oem34.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2015-10-01 223024]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-26 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-10-30 175104]
S3 SmbDrv;SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [2014-09-17 32496]
S3 SmbDrvI;SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [2014-09-17 33008]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdaptiveSleepService;AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [2014-06-05 140288]
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-08-01 263200]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-06-05 344064]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 BcmBtRSupport;@oem34.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2015-10-01 2286848]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2015-12-22 2787512]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2015-11-20 2522616]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-08-01 93184]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [2014-09-02 509192]
R2 omniserv; HP SimplePass Service; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [2014-03-28 88064]
R2 OneSyncSvc_4d98815;Hostitel synchronizace_4d98815; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2014-04-14 389896]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-08-19 291032]
R2 SecureLine;avast! SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [2015-12-24 452456]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-10-02 246472]
R2 tbaseprovisioning;tbaseprovisioning; C:\WINDOWS\SysWOW64\tbaseprovisioning.exe [2015-06-23 60432]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:\WINDOWS\System32\appdrvrem01.exe [2016-01-25 551896]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-23 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-10-30 51376]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-05-13 1129760]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_4d98815;Služba zasílání zpráv_4d98815; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-01-08 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_4d98815;Data kontaktů_4d98815; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_4d98815;Úložiště uživatelských dat_4d98815; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by PC1 at 2016-01-25 16:41:39
Microsoft Windows 10 Home
System drive C: has 833 GB (89%) free of 931 GB
Total RAM: 7113 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 16:41:48, on 25. 1. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal
Running processes:
C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files\trend micro\PC1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [DropboxOEM] "C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe" auto
O4 - HKCU\..\Run: [OneDrive] "C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: avast! SecureLine.lnk = C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Unknown owner - C:\WINDOWS\System32\appdrvrem01.exe (file missing)
O23 - Service: @oem34.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: avast! SecureLine (SecureLine) - Unknown owner - C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11815 bytes
======Listing Processes======
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe"
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
C:\WINDOWS\system32\atiesrxx.exe
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k apphost
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
"C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
C:\WINDOWS\system32\BtwRSupportService.exe
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe"
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe"
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
dashost.exe {11fff32c-2068-4765-b0faa187de4f59ca}
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
C:\WINDOWS\system32\WLANExt.exe 1406228791360
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
C:\WINDOWS\System32\WinLogon.exe -SpecialSession
"dwm.exe"
atieclxx
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe"
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /ANDREA_BF_BYPASS
"C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe" /hideui
C:\WINDOWS\system32\ApplicationFrameHost.exe -Embedding
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobroker.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe"
"C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\AVAST Software\SecureLine\SecureLine.exe" /nogui
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe"
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe" -ServerName:App.AppXzst44mncqdg84v7sv6p7yznqwssy6f7f.mca
"C:\WINDOWS\ImmersiveControlPanel\SystemSettings.exe" -ServerName:microsoft.windows.immersivecontrolpanel
taskhostw.exe
taskeng.exe {752BB900-ADF8-4CA0-BD18-1F8E6FC62FE0}
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe134_ Global\UsGthrCtrlFltPipeMssGthrPipe134 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 632 636 404 8192 604
"C:\Users\PC1\Desktop\RSITx64.exe"
C:\WINDOWS\system32\wbem\wmiprvse.exe
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\PC1\AppData\Roaming\Mozilla\Firefox\Profiles\6f1nbwuz.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.286 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.286 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-01-03 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-01-23 2339032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-01-03 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-07-25 585568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-01-23 1731800]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-09-03 7636696]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-09-02 1396592]
"SimplePass"=C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [2014-03-28 3962936]
"OPBHOBroker"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [2014-03-28 415288]
"OPBHOBrokerDesktop"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [2014-03-28 415288]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-10-02 3945672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-12-26 551112]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HPMessageService"=C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [2014-09-02 507144]
"DropboxOEM"=C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2014-09-02 462160]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
avast! SecureLine.lnk - C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-01-25 16:49:39 ----A---- C:\WINDOWS\system32\drivers\appdrv01.sys
2016-01-25 16:49:39 ----A---- C:\WINDOWS\system32\appdrvrem01.exe
2016-01-25 16:41:40 ----D---- C:\Program Files\trend micro
2016-01-25 16:41:39 ----D---- C:\rsit
2016-01-25 16:00:45 ----A---- C:\WINDOWS\system32\drivers\appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946}.sys
2016-01-25 15:46:31 ----D---- C:\Program Files (x86)\Centauri
2016-01-25 14:01:30 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2016-01-24 13:22:59 ----D---- C:\Users\PC1\AppData\Roaming\AMD
2016-01-24 13:20:35 ----D---- C:\.jagex_cache_32
2016-01-16 14:09:55 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-16 14:09:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-01-16 14:09:49 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-01-16 14:09:49 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-01-16 14:09:48 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-01-16 14:09:48 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-01-16 14:09:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-01-16 14:09:46 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-01-16 14:09:43 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-01-16 14:09:42 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-01-16 14:09:42 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-01-16 14:09:41 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-01-16 14:09:41 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\mfps.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2016-01-16 14:09:38 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2016-01-16 14:09:37 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\WMSPDMOD.DLL
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\facecredentialprovider.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\evr.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOD.DLL
2016-01-16 14:09:36 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\quartz.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\invagent.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\devinv.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\advapi32.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\uReFS.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\schannel.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\PhoneService.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\mftranscode.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\SYSWOW64\MP3DMOD.DLL
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\WMSPDMOE.DLL
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\winload.exe
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\qedit.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\MP3DMOD.DLL
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\usermgrcli.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\qedit.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\usermgrcli.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\ProximityCommon.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\omadmclient.exe
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-01-16 14:09:30 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOE.DLL
2016-01-16 14:09:30 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\DscCore.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\drivers\BthLEEnum.sys
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\aitstatic.exe
2016-01-16 14:09:29 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-01-16 14:09:29 ----A---- C:\WINDOWS\system32\aepic.dll
2016-01-10 12:54:16 ----AD---- C:\Program Files (x86)\Cheat Engine 6.5
2016-01-08 23:36:50 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-01-03 16:05:08 ----AD---- C:\Program Files\Microsoft Office 15
2015-12-30 21:43:35 ----AD---- C:\Program Files\CCleaner
2015-12-30 21:31:38 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_5.dll
2015-12-30 21:31:38 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2015-12-30 21:31:37 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2015-12-30 21:31:37 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2015-12-30 21:31:36 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2015-12-30 21:31:36 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2015-12-30 21:31:33 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_42.dll
2015-12-30 21:31:33 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2015-12-30 21:31:32 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2015-12-30 21:31:32 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2015-12-30 21:31:30 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2015-12-30 21:31:30 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_3.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2015-12-30 21:31:25 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2015-12-30 21:31:25 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2015-12-30 21:31:18 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2015-12-30 21:31:18 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2015-12-30 21:31:12 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2015-12-30 21:31:12 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2015-12-30 21:31:11 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2015-12-30 21:31:11 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2015-12-30 21:31:10 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2015-12-30 21:31:10 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2015-12-30 21:31:09 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2015-12-30 21:31:09 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2015-12-30 21:31:02 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2015-12-30 21:31:02 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2015-12-30 21:31:00 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2015-12-30 21:31:00 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2015-12-30 21:30:57 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2015-12-30 21:30:57 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2015-12-30 21:30:53 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2015-12-30 21:30:53 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2015-12-30 21:30:51 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2015-12-30 21:30:51 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2015-12-30 21:30:50 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2015-12-30 21:30:50 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\system32\d3dx10.dll
2015-12-30 21:30:46 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_32.dll
2015-12-30 21:30:46 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2015-12-30 21:30:42 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2015-12-30 21:30:41 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2015-12-30 21:30:41 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2015-12-30 21:30:40 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2015-12-30 21:30:40 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2015-12-30 21:30:38 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2015-12-30 21:30:38 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2015-12-30 21:30:37 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2015-12-30 21:30:37 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2015-12-30 21:30:36 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2015-12-30 21:30:36 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2015-12-30 21:30:23 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2015-12-30 21:30:19 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2015-12-30 21:30:19 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2015-12-30 21:30:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2015-12-30 21:30:18 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2015-12-30 21:30:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2015-12-30 21:30:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2015-12-30 21:30:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2015-12-30 21:30:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2015-12-30 21:30:11 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2015-12-30 21:30:09 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2015-12-30 21:30:09 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\msvcr80.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\mss32.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2015-12-30 21:20:34 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2015-12-30 21:20:33 ----A---- C:\WINDOWS\SYSWOW64\binkw32.dll
2015-12-28 13:48:39 ----D---- C:\WINDOWS\system32\SleepStudy
2015-12-28 00:54:30 ----D---- C:\Users\PC1\AppData\Roaming\CyberLink
2015-12-26 22:41:11 ----D---- C:\ProgramData\ESET
2015-12-26 22:41:04 ----D---- C:\Program Files\ESET
2015-12-26 21:26:46 ----D---- C:\Users\PC1\AppData\Roaming\DropboxOEM
2015-12-26 15:48:44 ----D---- C:\ProgramData\USOShared
2015-12-26 15:31:30 ----D---- C:\ProgramData\Microsoft OneDrive
2015-12-26 15:21:09 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2015-12-26 15:10:50 ----ASH---- C:\hiberfil.sys
2015-12-26 15:02:32 ----SD---- C:\Users\PC1\AppData\Roaming\Microsoft
2015-12-26 15:01:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-26 15:01:41 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2015-12-26 14:58:07 ----D---- C:\Program Files\Synaptics
2015-12-26 14:58:05 ----D---- C:\WINDOWS\SYSWOW64\sda
2015-12-26 14:57:53 ----D---- C:\Program Files\Common Files\ATI Technologies
2015-12-26 14:57:28 ----D---- C:\Program Files\AMD
2015-12-26 14:56:35 ----D---- C:\WINDOWS\system32\SRSLabs
2015-12-26 14:56:31 ----D---- C:\Program Files\Realtek
2015-12-26 14:56:30 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2015-12-26 14:55:37 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2015-12-26 14:53:50 ----AS---- C:\WINDOWS\bootstat.dat
2015-12-26 14:53:12 ----D---- C:\WINDOWS\Prefetch
2015-12-26 14:52:10 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-26 14:51:05 ----SHD---- C:\Recovery
2015-12-26 14:50:57 ----DC---- C:\WINDOWS\Panther
2015-12-26 14:45:51 ----D---- C:\Windows.old
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MSMPEG2ENC.DLL
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.proxy.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\wpncore.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfds.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MDEServer.exe
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\EncDump.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\dialserver.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioSes.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioEng.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\audiodg.exe
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\readingviewresources.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\MSMPEG2ENC.DLL
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\MFPlay.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\jscript.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iesetup.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iernonce.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\wwapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\mssign32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwansvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Wwanpref.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanmm.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanconn.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwancfg.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wups2.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wsplib.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wshrm.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wininetlui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wininet.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wimserv.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wimgapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wifitask.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wificonnapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Unistore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\twinui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\StorSvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SRH.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\shutdownux.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\shell32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\services.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\rilproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provtool.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provops.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provhandlers.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provengine.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provdatastore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\policymanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\pnidui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\mssign32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\lpk.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\LogonController.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\jsproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ihvrilproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\fontsub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dciman32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\comsvcs.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\catsrvut.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\authui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\AppCapture.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\NmaDirect.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosResource.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosTrace.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosHost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MapControls.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapControlStringsRes.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\ETWCoreUIComponentsResources.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\BingOnlineServices.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32kfull.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32kbase.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\user32.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringconfigsp.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsUtilsV2.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\NmaDirect.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\NMAA.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\nativemap.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosStorage.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosResource.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\moshostcore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\moshost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mos.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mfpmp.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mf.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mapstoasttask.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsStore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsBtSvcProxy.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapControlStringsRes.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InputService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\d3d11.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\cryptngc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\BingOnlineServices.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\BingMaps.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCoreRes.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\BackgroundTransferHost.exe
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\UIAutomationCoreRes.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\fveapibase.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\fveapi.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\dcomp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\cdp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\BackgroundTransferHost.exe
2015-12-26 14:20:21 ----D---- C:\WINDOWS\system32\Microsoft
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2015-12-26 14:16:05 ----D---- C:\Program Files\Reference Assemblies
2015-12-26 14:16:05 ----D---- C:\Program Files\MSBuild
2015-12-26 14:16:05 ----D---- C:\Program Files (x86)\Reference Assemblies
2015-12-26 14:16:05 ----D---- C:\Program Files (x86)\MSBuild
2015-12-26 14:16:05 ----D---- C:\inetpub
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-12-26 14:15:07 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2015-12-26 14:15:06 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-12-26 14:15:05 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
======List of files/folders modified in the last 1 month======
2016-01-25 16:41:40 ----RD---- C:\Program Files
2016-01-25 16:40:51 ----D---- C:\WINDOWS\Temp
2016-01-25 16:04:00 ----D---- C:\WINDOWS\system32\sru
2016-01-25 16:00:45 ----D---- C:\WINDOWS\system32\drivers
2016-01-25 15:49:39 ----D---- C:\WINDOWS\System32
2016-01-25 15:49:37 ----SHD---- C:\WINDOWS\Installer
2016-01-25 15:48:37 ----SHD---- C:\System Volume Information
2016-01-25 15:47:04 ----D---- C:\WINDOWS\Logs
2016-01-25 15:46:31 ----RD---- C:\Program Files (x86)
2016-01-24 19:58:22 ----D---- C:\WINDOWS\AppReadiness
2016-01-24 16:50:34 ----D---- C:\WINDOWS\Microsoft.NET
2016-01-24 16:48:49 ----RSD---- C:\WINDOWS\assembly
2016-01-24 15:11:56 ----HD---- C:\Program Files\WindowsApps
2016-01-23 23:17:10 ----D---- C:\WINDOWS\system32\config
2016-01-23 23:06:42 ----D---- C:\WINDOWS\system32\DriverStore
2016-01-23 19:40:18 ----D---- C:\WINDOWS\SysWOW64
2016-01-23 19:21:27 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-01-23 19:09:27 ----D---- C:\WINDOWS\system32\MRT
2016-01-23 19:05:00 ----A---- C:\WINDOWS\system32\MRT.exe
2016-01-17 12:15:29 ----D---- C:\WINDOWS\INF
2016-01-16 22:12:54 ----HD---- C:\ProgramData
2016-01-16 22:09:20 ----D---- C:\Windows
2016-01-16 16:49:35 ----D---- C:\WINDOWS\WinSxS
2016-01-16 16:46:50 ----D---- C:\WINDOWS\system32\Boot
2016-01-16 16:46:49 ----D---- C:\WINDOWS\system32\appraiser
2016-01-16 16:46:49 ----D---- C:\WINDOWS\AppPatch
2016-01-16 14:51:46 ----D---- C:\Users\PC1\AppData\Roaming\vlc
2016-01-16 14:27:52 ----D---- C:\WINDOWS\CbsTemp
2016-01-16 14:01:57 ----D---- C:\WINDOWS\system32\catroot2
2016-01-10 11:48:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-01-10 00:36:40 ----D---- C:\WINDOWS\OCR
2016-01-08 16:48:17 ----D---- C:\Program Files (x86)\Common Files
2016-01-03 16:09:50 ----SD---- C:\ProgramData\Microsoft
2016-01-03 16:09:00 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-01-03 16:05:24 ----RSD---- C:\WINDOWS\Fonts
2016-01-03 02:40:25 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-01-01 02:17:22 ----D---- C:\WINDOWS\LiveKernelReports
2015-12-31 21:07:48 ----D---- C:\WINDOWS\system32\Tasks
2015-12-30 22:10:51 ----D---- C:\WINDOWS\debug
2015-12-30 22:10:44 ----D---- C:\WINDOWS\SoftwareDistribution
2015-12-29 19:29:33 ----D---- C:\WINDOWS\rescache
2015-12-29 18:08:45 ----D---- C:\WINDOWS\SYSWOW64\winrm
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\WCN
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\wbem
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2015-12-29 18:08:43 ----SD---- C:\WINDOWS\SYSWOW64\F12
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\Printing_Admin_Scripts
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\oobe
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\en-US
2015-12-29 18:08:42 ----SD---- C:\WINDOWS\SYSWOW64\DiagSvcs
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\en
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers\en-US
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers
2015-12-29 18:08:42 ----D---- C:\WINDOWS\system32\winrm
2015-12-29 18:08:39 ----D---- C:\WINDOWS\system32\WCN
2015-12-29 18:08:39 ----D---- C:\WINDOWS\system32\wbem
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\Sysprep
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\slmgr
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\sk-SK
2015-12-29 18:08:37 ----D---- C:\WINDOWS\system32\Printing_Admin_Scripts
2015-12-29 18:08:37 ----D---- C:\WINDOWS\system32\oobe
2015-12-29 18:08:36 ----SD---- C:\WINDOWS\system32\F12
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\migwiz
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\en-US
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\en
2015-12-29 18:08:35 ----SD---- C:\WINDOWS\system32\DiagSvcs
2015-12-29 18:08:35 ----RD---- C:\WINDOWS\PurchaseDialog
2015-12-29 18:08:35 ----RD---- C:\WINDOWS\MiracastView
2015-12-29 18:08:35 ----D---- C:\WINDOWS\system32\drivers\UMDF
2015-12-29 18:08:35 ----D---- C:\WINDOWS\system32\drivers\en-US
2015-12-29 18:08:35 ----D---- C:\WINDOWS\servicing
2015-12-29 18:08:35 ----D---- C:\WINDOWS\PolicyDefinitions
2015-12-29 18:08:34 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2015-12-29 18:08:34 ----RD---- C:\WINDOWS\DevicesFlow
2015-12-29 18:08:34 ----D---- C:\WINDOWS\IME
2015-12-29 18:08:34 ----D---- C:\WINDOWS\Help
2015-12-29 18:08:34 ----D---- C:\WINDOWS\en-US
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Photo Viewer
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Media Player
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Journal
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Defender
2015-12-29 18:08:34 ----D---- C:\Program Files\Internet Explorer
2015-12-29 18:08:34 ----D---- C:\Program Files\Common Files\System
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Media Player
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Defender
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Internet Explorer
2015-12-29 18:06:21 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2015-12-29 18:06:15 ----D---- C:\WINDOWS\system32\en-GB
2015-12-28 00:54:46 ----D---- C:\ProgramData\CyberLink
2015-12-27 18:29:30 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-12-27 18:29:30 ----D---- C:\WINDOWS\system32\cs-CZ
2015-12-27 18:29:27 ----A---- C:\WINDOWS\SYSWOW64\dpnet.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnsvr.exe
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnlobby.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnhupnp.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnhpast.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnathlp.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnaddr.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnet.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\SYSWOW64\dpmodemx.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnathlp.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dpwsockx.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dplayx.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2015-12-27 18:26:41 ----D---- C:\WINDOWS\system32\NDF
2015-12-27 11:06:48 ----D---- C:\WINDOWS\appcompat
2015-12-26 22:42:14 ----HD---- C:\WINDOWS\ELAMBKUP
2015-12-26 22:33:34 ----D---- C:\WINDOWS\system32\CatRoot
2015-12-26 21:35:09 ----D---- C:\WINDOWS\system32\restore
2015-12-26 21:27:08 ----D---- C:\WINDOWS\system32\WDI
2015-12-26 15:54:57 ----D---- C:\ProgramData\McAfee
2015-12-26 15:54:57 ----D---- C:\Program Files\Common Files
2015-12-26 15:48:44 ----D---- C:\ProgramData\USOPrivate
2015-12-26 15:27:58 ----RD---- C:\WINDOWS\PrintDialog
2015-12-26 15:24:10 ----D---- C:\Program Files\Windows NT
2015-12-26 15:23:54 ----D---- C:\WINDOWS\system32\WinBioDatabase
2015-12-26 15:22:11 ----D---- C:\WINDOWS\Registration
2015-12-26 15:20:32 ----D---- C:\WINDOWS\Tasks
2015-12-26 15:16:39 ----D---- C:\WINDOWS\system32\LogFiles
2015-12-26 15:16:32 ----D---- C:\WINDOWS\system32\drivers\etc
2015-12-26 15:10:07 ----AD---- C:\Program Files (x86)\ATI Technologies
2015-12-26 15:06:29 ----D---- C:\WINDOWS\SYSWOW64\zh-TW
2015-12-26 15:06:29 ----D---- C:\WINDOWS\SYSWOW64\zh-HK
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\zh-CN
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\uk-UA
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\tr-TR
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\th-TH
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sv-SE
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-RS
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sl-SI
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ru-RU
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ro-RO
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pt-PT
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pt-BR
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\nl-NL
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\nb-NO
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\lv-LV
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\lt-LT
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ko-KR
2015-12-26 15:06:25 ----D---- C:\WINDOWS\SYSWOW64\ja-JP
2015-12-26 15:06:25 ----D---- C:\WINDOWS\SYSWOW64\it-IT
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\hu-HU
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\hr-HR
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\he-IL
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\fr-FR
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\fi-FI
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\et-EE
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\es-ES
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\el-GR
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\de-DE
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\da-DK
2015-12-26 15:06:22 ----D---- C:\WINDOWS\SYSWOW64\bg-BG
2015-12-26 15:06:22 ----D---- C:\WINDOWS\SYSWOW64\ar-SA
2015-12-26 15:06:22 ----AD---- C:\WINDOWS\SYSWOW64\Adobe
2015-12-26 15:06:20 ----D---- C:\WINDOWS\system32\zh-TW
2015-12-26 15:06:19 ----D---- C:\WINDOWS\system32\zh-HK
2015-12-26 15:06:19 ----D---- C:\WINDOWS\system32\zh-CN
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\uk-UA
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\tr-TR
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\th-TH
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\sv-SE
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2015-12-26 15:06:16 ----D---- C:\WINDOWS\system32\spool
2015-12-26 15:06:15 ----D---- C:\WINDOWS\system32\sl-SI
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\ru-RU
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\ro-RO
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pt-PT
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pt-BR
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pl-PL
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\nl-NL
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\nb-NO
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\migration
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\lv-LV
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\lt-LT
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\ko-KR
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\ja-JP
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\it-IT
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\InputMethod
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\hu-HU
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\hr-HR
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\he-IL
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\fr-FR
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\fi-FI
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\et-EE
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\es-ES
2015-12-26 15:06:04 ----DC---- C:\WINDOWS\system32\DRVSTORE
2015-12-26 15:06:04 ----D---- C:\WINDOWS\system32\el-GR
2015-12-26 15:06:03 ----D---- C:\WINDOWS\system32\de-DE
2015-12-26 15:06:03 ----D---- C:\WINDOWS\system32\da-DK
2015-12-26 15:04:39 ----D---- C:\WINDOWS\system32\bg-BG
2015-12-26 15:04:39 ----D---- C:\WINDOWS\system32\ar-SA
2015-12-26 15:04:33 ----D---- C:\WINDOWS\MediaViewer
2015-12-26 15:04:28 ----D---- C:\WINDOWS\InputMethod
2015-12-26 15:04:22 ----D---- C:\WINDOWS\ADFS
2015-12-26 15:04:19 ----RD---- C:\Users
2015-12-26 15:04:14 ----D---- C:\Program Files (x86)\Windows Mail
2015-12-26 15:04:13 ----AD---- C:\Program Files (x86)\Hewlett-Packard
2015-12-26 15:04:10 ----D---- C:\Program Files\Windows Mail
2015-12-26 15:04:10 ----D---- C:\Program Files (x86)\AMD AVT
2015-12-26 15:04:09 ----D---- C:\Program Files\Common Files\microsoft shared
2015-12-26 15:03:50 ----D---- C:\WINDOWS\system32\Recovery
2015-12-26 15:02:21 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-12-26 14:52:22 ----D---- C:\WINDOWS\ServiceProfiles
2015-12-26 14:45:28 ----D---- C:\WINDOWS\SYSWOW64\migration
2015-12-26 14:45:28 ----D---- C:\WINDOWS\SYSWOW64\Dism
2015-12-26 14:45:28 ----D---- C:\WINDOWS\system32\Dism
2015-12-26 14:45:27 ----D---- C:\WINDOWS\Provisioning
2015-12-26 14:45:27 ----D---- C:\WINDOWS\bcastdvr
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\MUI
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2015-12-26 14:16:07 ----D---- C:\WINDOWS\system32\MUI
2015-12-26 14:16:07 ----D---- C:\WINDOWS\system32\inetsrv
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\wamregps.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisRtl.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisrstap.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisreset.exe
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\ahadmin.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\admwprox.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\wamregps.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisRtl.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisrstap.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisreset.exe
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\ahadmin.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\admwprox.dll
2015-12-26 14:00:54 ----HD---- C:\$WINDOWS.~BT
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amdkmpfd;@oem10.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmpfd.sys [2013-12-14 36608]
R0 amdpsp;@oem26.inf,%amdpsp.SVCDESC%;AMD PSP Service; C:\WINDOWS\system32\DRIVERS\amdpsp.sys [2015-06-23 277240]
R1 appdrv01;Application Driver (01); C:\WINDOWS\System32\Drivers\appdrv01.sys [2016-01-25 3854000]
R1 CLVirtualDrive;CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [2013-11-12 91912]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2015-11-20 263528]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2015-11-20 186784]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 epfwwfpr;epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [2015-11-20 170792]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 AmdAS4;@oem3.inf,%AmdAS4.SVCDESC%;AmdAS4 service; C:\WINDOWS\System32\drivers\AmdAS4.sys [2013-10-24 17640]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-08-01 21637664]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-08-01 682016]
R3 AtiHDAudioService;@oem29.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2015-05-28 102912]
R3 bcbtums;@oem34.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2015-10-01 208176]
R3 BCM43XX;@oem7.inf,%BCM43XX_Service_DispName%;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2014-12-22 7532760]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2015-10-30 84992]
R3 clwvd;@oem0.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\WINDOWS\system32\DRIVERS\clwvd.sys [2014-01-28 41704]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-09-03 4264536]
R3 RSP2STOR;@oem31.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2015-06-05 310528]
R3 RTL8168;@oem9.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\System32\drivers\Rt630x64.sys [2014-07-18 874712]
R3 SynTP;@oem35.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-10-02 619208]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2015-11-20 14976]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 amdkmcsp;@oem26.inf,%amdkmcsp.SVCDESC%;AMD Kernel Mode CSP Service; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [2015-06-23 101104]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2015-10-30 112640]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-01-05 245760]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-01-05 953856]
S3 btwampfl;@oem34.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2015-10-01 223024]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-26 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-10-30 175104]
S3 SmbDrv;SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [2014-09-17 32496]
S3 SmbDrvI;SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [2014-09-17 33008]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdaptiveSleepService;AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [2014-06-05 140288]
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-08-01 263200]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-06-05 344064]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 BcmBtRSupport;@oem34.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2015-10-01 2286848]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2015-12-22 2787512]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2015-11-20 2522616]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-08-01 93184]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [2014-09-02 509192]
R2 omniserv; HP SimplePass Service; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [2014-03-28 88064]
R2 OneSyncSvc_4d98815;Hostitel synchronizace_4d98815; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2014-04-14 389896]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-08-19 291032]
R2 SecureLine;avast! SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [2015-12-24 452456]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-10-02 246472]
R2 tbaseprovisioning;tbaseprovisioning; C:\WINDOWS\SysWOW64\tbaseprovisioning.exe [2015-06-23 60432]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:\WINDOWS\System32\appdrvrem01.exe [2016-01-25 551896]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-23 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-10-30 51376]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-05-13 1129760]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_4d98815;Služba zasílání zpráv_4d98815; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-01-08 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_4d98815;Data kontaktů_4d98815; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_4d98815;Úložiště uživatelských dat_4d98815; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Možný kelogger
Zdravím!
Spusťte tuto utilitu:
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Možný kelogger
Děkuji za pomáhání, zde je log
# AdwCleaner v5.030 - Logfile created 25/01/2016 at 17:21:55
# Updated 17/01/2016 by Xplode
# Database : 2016-01-25.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : PC1 - ADMIN
# Running from : C:\Users\PC1\Desktop\adwcleaner_5.030.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
***** [ Web browsers ] *****
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [652 bytes] ##########
# AdwCleaner v5.030 - Logfile created 25/01/2016 at 17:21:55
# Updated 17/01/2016 by Xplode
# Database : 2016-01-25.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : PC1 - ADMIN
# Running from : C:\Users\PC1\Desktop\adwcleaner_5.030.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLLs ] *****
***** [ Shortcuts ] *****
***** [ Scheduled tasks ] *****
***** [ Registry ] *****
***** [ Web browsers ] *****
*************************
:: "Tracing" keys removed
:: Winsock settings cleared
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [652 bytes] ##########
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Možný kelogger
Toto je OK. Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.:services
Bonjour Service
:commands
[Purity]
[Emptytemp]
[Emptyflash]
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Možný kelogger
Logfile of random's system information tool 1.10 (written by random/random)
Run by PC1 at 2016-01-25 17:51:20
Microsoft Windows 10 Home
System drive C: has 843 GB (90%) free of 931 GB
Total RAM: 7113 MB (76% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:51:25, on 25. 1. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal
Running processes:
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\PC1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [DropboxOEM] "C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe" auto
O4 - HKCU\..\Run: [OneDrive] "C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: avast! SecureLine.lnk = C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Unknown owner - C:\WINDOWS\System32\appdrvrem01.exe (file missing)
O23 - Service: @oem34.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: avast! SecureLine (SecureLine) - Unknown owner - C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11786 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe"
C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
C:\WINDOWS\system32\atiesrxx.exe
atieclxx
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe"
C:\WINDOWS\system32\BtwRSupportService.exe
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
dashost.exe {19aad1f1-9a32-497b-a4ff85d35d2e7702}
C:\WINDOWS\system32\WLANExt.exe 2149834786592
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\Explorer.EXE
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe"
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe"
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\01252016_173854.log
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /ANDREA_BF_BYPASS
"C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe" /hideui
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobroker.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobrokerdsktop.exe"
"C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\AVAST Software\SecureLine\SecureLine.exe" /nogui
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\TiWorker.exe -Embedding
wmiadap.exe /F /T /R
taskeng.exe {733866DD-8539-4E5A-A8B1-4D0F67430A41}
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="5388.0.333631711\1865577111" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 5388 "\\.\pipe\gecko-crash-server-pipe.5388" tab
"C:\Users\PC1\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\PC1\AppData\Roaming\Mozilla\Firefox\Profiles\6f1nbwuz.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.286 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.286 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-01-03 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-01-23 2339032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-01-03 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-07-25 585568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-01-23 1731800]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-09-03 7636696]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-09-02 1396592]
"SimplePass"=C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [2014-03-28 3962936]
"OPBHOBroker"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [2014-03-28 415288]
"OPBHOBrokerDesktop"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [2014-03-28 415288]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-10-02 3945672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-12-26 551112]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HPMessageService"=C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [2014-09-02 507144]
"DropboxOEM"=C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2014-09-02 462160]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
avast! SecureLine.lnk - C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-01-25 17:38:54 ----D---- C:\_OTM
2016-01-25 17:19:41 ----D---- C:\AdwCleaner
2016-01-25 16:49:39 ----A---- C:\WINDOWS\system32\drivers\appdrv01.sys
2016-01-25 16:49:39 ----A---- C:\WINDOWS\system32\appdrvrem01.exe
2016-01-25 16:41:40 ----D---- C:\Program Files\trend micro
2016-01-25 16:41:39 ----D---- C:\rsit
2016-01-25 16:00:45 ----A---- C:\WINDOWS\system32\drivers\appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946}.sys
2016-01-25 15:46:31 ----D---- C:\Program Files (x86)\Centauri
2016-01-25 14:01:30 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2016-01-24 13:22:59 ----D---- C:\Users\PC1\AppData\Roaming\AMD
2016-01-24 13:20:35 ----D---- C:\.jagex_cache_32
2016-01-16 14:09:55 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-16 14:09:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-01-16 14:09:49 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-01-16 14:09:49 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-01-16 14:09:48 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-01-16 14:09:48 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-01-16 14:09:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-01-16 14:09:46 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-01-16 14:09:43 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-01-16 14:09:42 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-01-16 14:09:42 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-01-16 14:09:41 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-01-16 14:09:41 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\mfps.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2016-01-16 14:09:38 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2016-01-16 14:09:37 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\WMSPDMOD.DLL
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\facecredentialprovider.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\evr.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOD.DLL
2016-01-16 14:09:36 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\quartz.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\invagent.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\devinv.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\advapi32.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\uReFS.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\schannel.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\PhoneService.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\mftranscode.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\SYSWOW64\MP3DMOD.DLL
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\WMSPDMOE.DLL
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\winload.exe
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\qedit.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\MP3DMOD.DLL
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\usermgrcli.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\qedit.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\usermgrcli.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\ProximityCommon.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\omadmclient.exe
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-01-16 14:09:30 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOE.DLL
2016-01-16 14:09:30 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\DscCore.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\drivers\BthLEEnum.sys
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\aitstatic.exe
2016-01-16 14:09:29 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-01-16 14:09:29 ----A---- C:\WINDOWS\system32\aepic.dll
2016-01-10 12:54:16 ----AD---- C:\Program Files (x86)\Cheat Engine 6.5
2016-01-08 23:36:50 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-01-03 16:05:08 ----AD---- C:\Program Files\Microsoft Office 15
2015-12-30 21:43:35 ----AD---- C:\Program Files\CCleaner
2015-12-30 21:31:38 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_5.dll
2015-12-30 21:31:38 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2015-12-30 21:31:37 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2015-12-30 21:31:37 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2015-12-30 21:31:36 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2015-12-30 21:31:36 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2015-12-30 21:31:33 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_42.dll
2015-12-30 21:31:33 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2015-12-30 21:31:32 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2015-12-30 21:31:32 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2015-12-30 21:31:30 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2015-12-30 21:31:30 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_3.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2015-12-30 21:31:25 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2015-12-30 21:31:25 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2015-12-30 21:31:18 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2015-12-30 21:31:18 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2015-12-30 21:31:12 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2015-12-30 21:31:12 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2015-12-30 21:31:11 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2015-12-30 21:31:11 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2015-12-30 21:31:10 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2015-12-30 21:31:10 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2015-12-30 21:31:09 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2015-12-30 21:31:09 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2015-12-30 21:31:02 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2015-12-30 21:31:02 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2015-12-30 21:31:00 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2015-12-30 21:31:00 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2015-12-30 21:30:57 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2015-12-30 21:30:57 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2015-12-30 21:30:53 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2015-12-30 21:30:53 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2015-12-30 21:30:51 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2015-12-30 21:30:51 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2015-12-30 21:30:50 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2015-12-30 21:30:50 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\system32\d3dx10.dll
2015-12-30 21:30:46 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_32.dll
2015-12-30 21:30:46 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2015-12-30 21:30:42 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2015-12-30 21:30:41 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2015-12-30 21:30:41 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2015-12-30 21:30:40 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2015-12-30 21:30:40 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2015-12-30 21:30:38 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2015-12-30 21:30:38 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2015-12-30 21:30:37 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2015-12-30 21:30:37 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2015-12-30 21:30:36 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2015-12-30 21:30:36 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2015-12-30 21:30:23 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2015-12-30 21:30:19 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2015-12-30 21:30:19 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2015-12-30 21:30:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2015-12-30 21:30:18 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2015-12-30 21:30:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2015-12-30 21:30:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2015-12-30 21:30:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2015-12-30 21:30:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2015-12-30 21:30:11 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2015-12-30 21:30:09 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2015-12-30 21:30:09 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\msvcr80.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\mss32.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2015-12-30 21:20:34 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2015-12-30 21:20:33 ----A---- C:\WINDOWS\SYSWOW64\binkw32.dll
2015-12-28 13:48:39 ----D---- C:\WINDOWS\system32\SleepStudy
2015-12-28 00:54:30 ----D---- C:\Users\PC1\AppData\Roaming\CyberLink
2015-12-26 22:41:11 ----D---- C:\ProgramData\ESET
2015-12-26 22:41:04 ----D---- C:\Program Files\ESET
2015-12-26 21:26:46 ----D---- C:\Users\PC1\AppData\Roaming\DropboxOEM
2015-12-26 15:48:44 ----D---- C:\ProgramData\USOShared
2015-12-26 15:31:30 ----D---- C:\ProgramData\Microsoft OneDrive
2015-12-26 15:21:09 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2015-12-26 15:10:50 ----ASH---- C:\hiberfil.sys
2015-12-26 15:02:32 ----SD---- C:\Users\PC1\AppData\Roaming\Microsoft
2015-12-26 15:01:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-26 15:01:41 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2015-12-26 14:58:07 ----D---- C:\Program Files\Synaptics
2015-12-26 14:58:05 ----D---- C:\WINDOWS\SYSWOW64\sda
2015-12-26 14:57:53 ----D---- C:\Program Files\Common Files\ATI Technologies
2015-12-26 14:57:28 ----D---- C:\Program Files\AMD
2015-12-26 14:56:35 ----D---- C:\WINDOWS\system32\SRSLabs
2015-12-26 14:56:31 ----D---- C:\Program Files\Realtek
2015-12-26 14:56:30 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2015-12-26 14:55:37 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2015-12-26 14:53:50 ----AS---- C:\WINDOWS\bootstat.dat
2015-12-26 14:53:12 ----D---- C:\WINDOWS\Prefetch
2015-12-26 14:52:10 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-26 14:51:05 ----SHD---- C:\Recovery
2015-12-26 14:50:57 ----DC---- C:\WINDOWS\Panther
2015-12-26 14:45:51 ----D---- C:\Windows.old
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MSMPEG2ENC.DLL
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.proxy.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\wpncore.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfds.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MDEServer.exe
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\EncDump.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\dialserver.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioSes.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioEng.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\audiodg.exe
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\readingviewresources.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\MSMPEG2ENC.DLL
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\MFPlay.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\jscript.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iesetup.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iernonce.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\wwapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\mssign32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwansvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Wwanpref.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanmm.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanconn.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwancfg.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wups2.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wsplib.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wshrm.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wininetlui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wininet.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wimserv.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wimgapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wifitask.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wificonnapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Unistore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\twinui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\StorSvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SRH.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\shutdownux.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\shell32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\services.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\rilproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provtool.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provops.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provhandlers.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provengine.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provdatastore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\policymanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\pnidui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\mssign32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\lpk.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\LogonController.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\jsproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ihvrilproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\fontsub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dciman32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\comsvcs.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\catsrvut.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\authui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\AppCapture.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\NmaDirect.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosResource.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosTrace.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosHost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MapControls.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapControlStringsRes.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\ETWCoreUIComponentsResources.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\BingOnlineServices.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32kfull.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32kbase.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\user32.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringconfigsp.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsUtilsV2.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\NmaDirect.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\NMAA.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\nativemap.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosStorage.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosResource.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\moshostcore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\moshost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mos.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mfpmp.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mf.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mapstoasttask.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsStore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsBtSvcProxy.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapControlStringsRes.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InputService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\d3d11.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\cryptngc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\BingOnlineServices.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\BingMaps.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCoreRes.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\BackgroundTransferHost.exe
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\UIAutomationCoreRes.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\fveapibase.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\fveapi.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\dcomp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\cdp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\BackgroundTransferHost.exe
2015-12-26 14:20:21 ----D---- C:\WINDOWS\system32\Microsoft
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2015-12-26 14:16:05 ----D---- C:\Program Files\Reference Assemblies
2015-12-26 14:16:05 ----D---- C:\Program Files\MSBuild
2015-12-26 14:16:05 ----D---- C:\Program Files (x86)\Reference Assemblies
2015-12-26 14:16:05 ----D---- C:\Program Files (x86)\MSBuild
2015-12-26 14:16:05 ----D---- C:\inetpub
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-12-26 14:15:07 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2015-12-26 14:15:06 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-12-26 14:15:05 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
======List of files/folders modified in the last 1 month======
2016-01-25 17:46:34 ----D---- C:\WINDOWS\Temp
2016-01-25 17:44:08 ----D---- C:\WINDOWS\system32\sru
2016-01-25 17:30:12 ----D---- C:\WINDOWS\System32
2016-01-25 17:30:11 ----D---- C:\WINDOWS\INF
2016-01-25 17:27:00 ----D---- C:\WINDOWS\AppReadiness
2016-01-25 16:41:40 ----RD---- C:\Program Files
2016-01-25 16:00:45 ----D---- C:\WINDOWS\system32\drivers
2016-01-25 15:49:37 ----SHD---- C:\WINDOWS\Installer
2016-01-25 15:48:37 ----SHD---- C:\System Volume Information
2016-01-25 15:47:04 ----D---- C:\WINDOWS\Logs
2016-01-25 15:46:31 ----RD---- C:\Program Files (x86)
2016-01-24 16:50:34 ----D---- C:\WINDOWS\Microsoft.NET
2016-01-24 16:48:49 ----RSD---- C:\WINDOWS\assembly
2016-01-24 15:11:56 ----HD---- C:\Program Files\WindowsApps
2016-01-23 23:17:10 ----D---- C:\WINDOWS\system32\config
2016-01-23 23:06:42 ----D---- C:\WINDOWS\system32\DriverStore
2016-01-23 19:40:18 ----D---- C:\WINDOWS\SysWOW64
2016-01-23 19:21:27 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-01-23 19:09:27 ----D---- C:\WINDOWS\system32\MRT
2016-01-23 19:05:00 ----A---- C:\WINDOWS\system32\MRT.exe
2016-01-16 22:12:54 ----HD---- C:\ProgramData
2016-01-16 22:09:20 ----D---- C:\Windows
2016-01-16 16:49:35 ----D---- C:\WINDOWS\WinSxS
2016-01-16 16:46:50 ----D---- C:\WINDOWS\system32\Boot
2016-01-16 16:46:49 ----D---- C:\WINDOWS\system32\appraiser
2016-01-16 16:46:49 ----D---- C:\WINDOWS\AppPatch
2016-01-16 14:51:46 ----D---- C:\Users\PC1\AppData\Roaming\vlc
2016-01-16 14:27:52 ----D---- C:\WINDOWS\CbsTemp
2016-01-16 14:01:57 ----D---- C:\WINDOWS\system32\catroot2
2016-01-10 11:48:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-01-10 00:36:40 ----D---- C:\WINDOWS\OCR
2016-01-08 16:48:17 ----D---- C:\Program Files (x86)\Common Files
2016-01-03 16:09:50 ----SD---- C:\ProgramData\Microsoft
2016-01-03 16:09:00 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-01-03 16:05:24 ----RSD---- C:\WINDOWS\Fonts
2016-01-03 02:40:25 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-01-01 02:17:22 ----D---- C:\WINDOWS\LiveKernelReports
2015-12-31 21:07:48 ----D---- C:\WINDOWS\system32\Tasks
2015-12-30 22:10:51 ----D---- C:\WINDOWS\debug
2015-12-30 22:10:44 ----D---- C:\WINDOWS\SoftwareDistribution
2015-12-29 19:29:33 ----D---- C:\WINDOWS\rescache
2015-12-29 18:08:45 ----D---- C:\WINDOWS\SYSWOW64\winrm
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\WCN
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\wbem
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2015-12-29 18:08:43 ----SD---- C:\WINDOWS\SYSWOW64\F12
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\Printing_Admin_Scripts
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\oobe
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\en-US
2015-12-29 18:08:42 ----SD---- C:\WINDOWS\SYSWOW64\DiagSvcs
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\en
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers\en-US
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers
2015-12-29 18:08:42 ----D---- C:\WINDOWS\system32\winrm
2015-12-29 18:08:39 ----D---- C:\WINDOWS\system32\WCN
2015-12-29 18:08:39 ----D---- C:\WINDOWS\system32\wbem
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\Sysprep
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\slmgr
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\sk-SK
2015-12-29 18:08:37 ----D---- C:\WINDOWS\system32\Printing_Admin_Scripts
2015-12-29 18:08:37 ----D---- C:\WINDOWS\system32\oobe
2015-12-29 18:08:36 ----SD---- C:\WINDOWS\system32\F12
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\migwiz
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\en-US
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\en
2015-12-29 18:08:35 ----SD---- C:\WINDOWS\system32\DiagSvcs
2015-12-29 18:08:35 ----RD---- C:\WINDOWS\PurchaseDialog
2015-12-29 18:08:35 ----RD---- C:\WINDOWS\MiracastView
2015-12-29 18:08:35 ----D---- C:\WINDOWS\system32\drivers\UMDF
2015-12-29 18:08:35 ----D---- C:\WINDOWS\system32\drivers\en-US
2015-12-29 18:08:35 ----D---- C:\WINDOWS\servicing
2015-12-29 18:08:35 ----D---- C:\WINDOWS\PolicyDefinitions
2015-12-29 18:08:34 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2015-12-29 18:08:34 ----RD---- C:\WINDOWS\DevicesFlow
2015-12-29 18:08:34 ----D---- C:\WINDOWS\IME
2015-12-29 18:08:34 ----D---- C:\WINDOWS\Help
2015-12-29 18:08:34 ----D---- C:\WINDOWS\en-US
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Photo Viewer
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Media Player
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Journal
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Defender
2015-12-29 18:08:34 ----D---- C:\Program Files\Internet Explorer
2015-12-29 18:08:34 ----D---- C:\Program Files\Common Files\System
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Media Player
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Defender
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Internet Explorer
2015-12-29 18:06:21 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2015-12-29 18:06:15 ----D---- C:\WINDOWS\system32\en-GB
2015-12-28 00:54:46 ----D---- C:\ProgramData\CyberLink
2015-12-27 18:29:30 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-12-27 18:29:30 ----D---- C:\WINDOWS\system32\cs-CZ
2015-12-27 18:29:27 ----A---- C:\WINDOWS\SYSWOW64\dpnet.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnsvr.exe
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnlobby.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnhupnp.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnhpast.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnathlp.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnaddr.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnet.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\SYSWOW64\dpmodemx.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnathlp.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dpwsockx.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dplayx.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2015-12-27 18:26:41 ----D---- C:\WINDOWS\system32\NDF
2015-12-27 11:06:48 ----D---- C:\WINDOWS\appcompat
2015-12-26 22:42:14 ----HD---- C:\WINDOWS\ELAMBKUP
2015-12-26 22:33:34 ----D---- C:\WINDOWS\system32\CatRoot
2015-12-26 21:35:09 ----D---- C:\WINDOWS\system32\restore
2015-12-26 21:27:08 ----D---- C:\WINDOWS\system32\WDI
2015-12-26 15:54:57 ----D---- C:\ProgramData\McAfee
2015-12-26 15:54:57 ----D---- C:\Program Files\Common Files
2015-12-26 15:48:44 ----D---- C:\ProgramData\USOPrivate
2015-12-26 15:27:58 ----RD---- C:\WINDOWS\PrintDialog
2015-12-26 15:24:10 ----D---- C:\Program Files\Windows NT
2015-12-26 15:23:54 ----D---- C:\WINDOWS\system32\WinBioDatabase
2015-12-26 15:22:11 ----D---- C:\WINDOWS\Registration
2015-12-26 15:20:32 ----D---- C:\WINDOWS\Tasks
2015-12-26 15:16:39 ----D---- C:\WINDOWS\system32\LogFiles
2015-12-26 15:16:32 ----D---- C:\WINDOWS\system32\drivers\etc
2015-12-26 15:10:07 ----AD---- C:\Program Files (x86)\ATI Technologies
2015-12-26 15:06:29 ----D---- C:\WINDOWS\SYSWOW64\zh-TW
2015-12-26 15:06:29 ----D---- C:\WINDOWS\SYSWOW64\zh-HK
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\zh-CN
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\uk-UA
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\tr-TR
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\th-TH
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sv-SE
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-RS
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sl-SI
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ru-RU
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ro-RO
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pt-PT
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pt-BR
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\nl-NL
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\nb-NO
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\lv-LV
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\lt-LT
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ko-KR
2015-12-26 15:06:25 ----D---- C:\WINDOWS\SYSWOW64\ja-JP
2015-12-26 15:06:25 ----D---- C:\WINDOWS\SYSWOW64\it-IT
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\hu-HU
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\hr-HR
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\he-IL
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\fr-FR
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\fi-FI
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\et-EE
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\es-ES
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\el-GR
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\de-DE
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\da-DK
2015-12-26 15:06:22 ----D---- C:\WINDOWS\SYSWOW64\bg-BG
2015-12-26 15:06:22 ----D---- C:\WINDOWS\SYSWOW64\ar-SA
2015-12-26 15:06:22 ----AD---- C:\WINDOWS\SYSWOW64\Adobe
2015-12-26 15:06:20 ----D---- C:\WINDOWS\system32\zh-TW
2015-12-26 15:06:19 ----D---- C:\WINDOWS\system32\zh-HK
2015-12-26 15:06:19 ----D---- C:\WINDOWS\system32\zh-CN
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\uk-UA
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\tr-TR
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\th-TH
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\sv-SE
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2015-12-26 15:06:16 ----D---- C:\WINDOWS\system32\spool
2015-12-26 15:06:15 ----D---- C:\WINDOWS\system32\sl-SI
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\ru-RU
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\ro-RO
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pt-PT
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pt-BR
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pl-PL
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\nl-NL
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\nb-NO
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\migration
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\lv-LV
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\lt-LT
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\ko-KR
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\ja-JP
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\it-IT
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\InputMethod
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\hu-HU
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\hr-HR
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\he-IL
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\fr-FR
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\fi-FI
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\et-EE
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\es-ES
2015-12-26 15:06:04 ----DC---- C:\WINDOWS\system32\DRVSTORE
2015-12-26 15:06:04 ----D---- C:\WINDOWS\system32\el-GR
2015-12-26 15:06:03 ----D---- C:\WINDOWS\system32\de-DE
2015-12-26 15:06:03 ----D---- C:\WINDOWS\system32\da-DK
2015-12-26 15:04:39 ----D---- C:\WINDOWS\system32\bg-BG
2015-12-26 15:04:39 ----D---- C:\WINDOWS\system32\ar-SA
2015-12-26 15:04:33 ----D---- C:\WINDOWS\MediaViewer
2015-12-26 15:04:28 ----D---- C:\WINDOWS\InputMethod
2015-12-26 15:04:22 ----D---- C:\WINDOWS\ADFS
2015-12-26 15:04:19 ----RD---- C:\Users
2015-12-26 15:04:14 ----D---- C:\Program Files (x86)\Windows Mail
2015-12-26 15:04:13 ----AD---- C:\Program Files (x86)\Hewlett-Packard
2015-12-26 15:04:10 ----D---- C:\Program Files\Windows Mail
2015-12-26 15:04:10 ----D---- C:\Program Files (x86)\AMD AVT
2015-12-26 15:04:09 ----D---- C:\Program Files\Common Files\microsoft shared
2015-12-26 15:03:50 ----D---- C:\WINDOWS\system32\Recovery
2015-12-26 15:02:21 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-12-26 14:52:22 ----D---- C:\WINDOWS\ServiceProfiles
2015-12-26 14:45:28 ----D---- C:\WINDOWS\SYSWOW64\migration
2015-12-26 14:45:28 ----D---- C:\WINDOWS\SYSWOW64\Dism
2015-12-26 14:45:28 ----D---- C:\WINDOWS\system32\Dism
2015-12-26 14:45:27 ----D---- C:\WINDOWS\Provisioning
2015-12-26 14:45:27 ----D---- C:\WINDOWS\bcastdvr
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\MUI
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2015-12-26 14:16:07 ----D---- C:\WINDOWS\system32\MUI
2015-12-26 14:16:07 ----D---- C:\WINDOWS\system32\inetsrv
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\wamregps.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisRtl.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisrstap.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisreset.exe
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\ahadmin.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\admwprox.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\wamregps.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisRtl.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisrstap.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisreset.exe
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\ahadmin.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\admwprox.dll
2015-12-26 14:00:54 ----HD---- C:\$WINDOWS.~BT
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amdkmpfd;@oem10.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmpfd.sys [2013-12-14 36608]
R0 amdpsp;@oem26.inf,%amdpsp.SVCDESC%;AMD PSP Service; C:\WINDOWS\system32\DRIVERS\amdpsp.sys [2015-06-23 277240]
R1 appdrv01;Application Driver (01); C:\WINDOWS\System32\Drivers\appdrv01.sys [2016-01-25 3854000]
R1 CLVirtualDrive;CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [2013-11-12 91912]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2015-11-20 263528]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2015-11-20 186784]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 epfwwfpr;epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [2015-11-20 170792]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 AmdAS4;@oem3.inf,%AmdAS4.SVCDESC%;AmdAS4 service; C:\WINDOWS\System32\drivers\AmdAS4.sys [2013-10-24 17640]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-08-01 21637664]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-08-01 682016]
R3 AtiHDAudioService;@oem29.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2015-05-28 102912]
R3 bcbtums;@oem34.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2015-10-01 208176]
R3 BCM43XX;@oem7.inf,%BCM43XX_Service_DispName%;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2014-12-22 7532760]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2015-10-30 84992]
R3 clwvd;@oem0.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\WINDOWS\system32\DRIVERS\clwvd.sys [2014-01-28 41704]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-09-03 4264536]
R3 RSP2STOR;@oem31.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2015-06-05 310528]
R3 RTL8168;@oem9.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\System32\drivers\Rt630x64.sys [2014-07-18 874712]
R3 SynTP;@oem35.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-10-02 619208]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2015-11-20 14976]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 amdkmcsp;@oem26.inf,%amdkmcsp.SVCDESC%;AMD Kernel Mode CSP Service; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [2015-06-23 101104]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2015-10-30 112640]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-01-05 245760]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-01-05 953856]
S3 btwampfl;@oem34.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2015-10-01 223024]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-26 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-10-30 175104]
S3 SmbDrv;SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [2014-09-17 32496]
S3 SmbDrvI;SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [2014-09-17 33008]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-10-30 27488]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdaptiveSleepService;AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [2014-06-05 140288]
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-08-01 263200]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-06-05 344064]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 BcmBtRSupport;@oem34.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2015-10-01 2286848]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2015-12-22 2787512]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2015-11-20 2522616]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-08-01 93184]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [2014-09-02 509192]
R2 omniserv; HP SimplePass Service; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [2014-03-28 88064]
R2 OneSyncSvc_417fe;Hostitel synchronizace_417fe; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2014-04-14 389896]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-08-19 291032]
R2 SecureLine;avast! SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [2015-12-24 452456]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-10-02 246472]
R2 tbaseprovisioning;tbaseprovisioning; C:\WINDOWS\SysWOW64\tbaseprovisioning.exe [2015-06-23 60432]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:\WINDOWS\System32\appdrvrem01.exe [2016-01-25 551896]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-23 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-10-30 51376]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-05-13 1129760]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_417fe;Služba zasílání zpráv_417fe; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-01-08 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_417fe;Data kontaktů_417fe; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_417fe;Úložiště uživatelských dat_417fe; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
-----------------EOF-----------------
Run by PC1 at 2016-01-25 17:51:20
Microsoft Windows 10 Home
System drive C: has 843 GB (90%) free of 931 GB
Total RAM: 7113 MB (76% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:51:25, on 25. 1. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0020)
Boot mode: Normal
Running processes:
C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\trend micro\PC1.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDFJS
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDFJS
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O2 - BHO: Evernote extension - {92EF2EAD-A7CE-4424-B0DB-499CF856608E} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [HPMessageService] C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe
O4 - HKLM\..\Run: [DropboxOEM] "C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe" auto
O4 - HKCU\..\Run: [OneDrive] "C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: avast! SecureLine.lnk = C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIE.dll
O9 - Extra button: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Skype for Business Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office 15\root\Office15\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\\EvernoteIERes\AddNote.html
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: AdaptiveSleepService - Unknown owner - C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Unknown owner - C:\WINDOWS\System32\appdrvrem01.exe (file missing)
O23 - Service: @oem34.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service (BcmBtRSupport) - Unknown owner - C:\WINDOWS\system32\BtwRSupportService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: HP SimplePass Service (omniserv) - Softex Inc. - C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
O23 - Service: Cyberlink RichVideo64 Service(CRVS) (RichVideo64) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo64.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: avast! SecureLine (SecureLine) - Unknown owner - C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: SynTPEnh Caller Service (SynTPEnhService) - Synaptics Incorporated - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service: tbaseprovisioning - Advanced Micro Devices, Inc. - C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 11786 bytes
======Listing Processes======
winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
"dwm.exe"
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\svchost.exe -k NetworkService
"C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe"
C:\WINDOWS\SysWOW64\tbaseprovisioning.exe
C:\WINDOWS\system32\atiesrxx.exe
atieclxx
C:\WINDOWS\system32\svchost.exe -k WbioSvcGroup
"C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /SRSPS
C:\WINDOWS\System32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe -k apphost
"C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE"
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe"
"C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe"
C:\WINDOWS\system32\BtwRSupportService.exe
"C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe" /service
"C:\Program Files\CyberLink\Shared files\RichVideo64.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe"
dashost.exe {19aad1f1-9a32-497b-a4ff85d35d2e7702}
C:\WINDOWS\system32\WLANExt.exe 2149834786592
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE"
C:\WINDOWS\Explorer.EXE
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe"
"C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe"
"C:\WINDOWS\notepad.exe" C:\_OTM\MovedFiles\01252016_173854.log
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /ANDREA_BF_BYPASS
"C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe" /hideui
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobroker.exe"
"C:\Program Files\Hewlett-Packard\SimplePass\opbhobrokerdsktop.exe"
"C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files\AVAST Software\SecureLine\SecureLine.exe" /nogui
"C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe"
"C:\Program Files\CCleaner\CCleaner.exe" /MONITOR /uac
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide
"C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe"
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\servicing\TrustedInstaller.exe
C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.10586.0_none_95e4f9a171a1ad95\TiWorker.exe -Embedding
wmiadap.exe /F /T /R
taskeng.exe {733866DD-8539-4E5A-A8B1-4D0F67430A41}
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Mozilla Firefox\firefox.exe"
"C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe" --channel="5388.0.333631711\1865577111" -greomni "C:\Program Files (x86)\Mozilla Firefox\omni.ja" -appomni "C:\Program Files (x86)\Mozilla Firefox\browser\omni.ja" -appdir "C:\Program Files (x86)\Mozilla Firefox\browser" 5388 "\\.\pipe\gecko-crash-server-pipe.5388" tab
"C:\Users\PC1\Desktop\RSITx64.exe"
======Scheduled tasks folder======
C:\WINDOWS\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
=========Mozilla firefox=========
ProfilePath - C:\Users\PC1\AppData\Roaming\Mozilla\Firefox\Profiles\6f1nbwuz.default
prefs.js - "browser.startup.homepage" - "www.seznam.cz"
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.286 Plugin
"Path"=C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_286.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.1]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.286 Plugin
"Path"=C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_286.dll
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-01-03 219304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-01-23 2339032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28 303416]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2016-01-03 153768]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92EF2EAD-A7CE-4424-B0DB-499CF856608E}]
Evernote extension - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2014-07-25 585568]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2016-01-23 1731800]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E76FD755-C1BA-4DCB-9F13-99BD91223ADE}]
HP Network Check Helper - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28 286520]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2014-09-03 7636696]
"RtHDVBg"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-09-02 1396592]
"SimplePass"=C:\Program Files\Hewlett-Packard\SimplePass\ClientCore.exe [2014-03-28 3962936]
"OPBHOBroker"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [2014-03-28 415288]
"OPBHOBrokerDesktop"=C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [2014-03-28 415288]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2015-10-02 3945672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\PC1\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-12-26 551112]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-12-08 8590760]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"HPMessageService"=C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [2014-09-02 507144]
"DropboxOEM"=C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2014-09-02 462160]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
avast! SecureLine.lnk - C:\Program Files\AVAST Software\SecureLine\SecureLine.exe
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
======List of files/folders created in the last 1 month======
2016-01-25 17:38:54 ----D---- C:\_OTM
2016-01-25 17:19:41 ----D---- C:\AdwCleaner
2016-01-25 16:49:39 ----A---- C:\WINDOWS\system32\drivers\appdrv01.sys
2016-01-25 16:49:39 ----A---- C:\WINDOWS\system32\appdrvrem01.exe
2016-01-25 16:41:40 ----D---- C:\Program Files\trend micro
2016-01-25 16:41:39 ----D---- C:\rsit
2016-01-25 16:00:45 ----A---- C:\WINDOWS\system32\drivers\appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946}.sys
2016-01-25 15:46:31 ----D---- C:\Program Files (x86)\Centauri
2016-01-25 14:01:30 ----N---- C:\WINDOWS\system32\MpSigStub.exe
2016-01-24 13:22:59 ----D---- C:\Users\PC1\AppData\Roaming\AMD
2016-01-24 13:20:35 ----D---- C:\.jagex_cache_32
2016-01-16 14:09:55 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-01-16 14:09:53 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2016-01-16 14:09:49 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2016-01-16 14:09:49 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2016-01-16 14:09:48 ----A---- C:\WINDOWS\system32\mfcore.dll
2016-01-16 14:09:48 ----A---- C:\WINDOWS\system32\edgehtml.dll
2016-01-16 14:09:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2016-01-16 14:09:46 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2016-01-16 14:09:43 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2016-01-16 14:09:42 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2016-01-16 14:09:42 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2016-01-16 14:09:41 ----A---- C:\WINDOWS\SYSWOW64\qdvd.dll
2016-01-16 14:09:41 ----A---- C:\WINDOWS\system32\Chakra.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\WWAHost.exe
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\usermgr.dll
2016-01-16 14:09:40 ----A---- C:\WINDOWS\system32\qdvd.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\WWAHost.exe
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\mfps.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\msxml6.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\mfps.dll
2016-01-16 14:09:39 ----A---- C:\WINDOWS\system32\jscript9.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\SYSWOW64\msxml6.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2016-01-16 14:09:38 ----A---- C:\WINDOWS\system32\WMADMOD.DLL
2016-01-16 14:09:38 ----A---- C:\WINDOWS\system32\generaltel.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\SYSWOW64\WMADMOD.DLL
2016-01-16 14:09:37 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\WMSPDMOD.DLL
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\facecredentialprovider.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\evr.dll
2016-01-16 14:09:37 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOD.DLL
2016-01-16 14:09:36 ----A---- C:\WINDOWS\SYSWOW64\schannel.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\quartz.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\mfsvr.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\invagent.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\gdi32.dll
2016-01-16 14:09:36 ----A---- C:\WINDOWS\system32\devinv.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\SYSWOW64\gdi32.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\SYSWOW64\evr.dll
2016-01-16 14:09:35 ----A---- C:\WINDOWS\system32\DeviceCensus.exe
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\quartz.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\SYSWOW64\advapi32.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\WMALFXGFXDSP.dll
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\winlogon.exe
2016-01-16 14:09:34 ----A---- C:\WINDOWS\system32\advapi32.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\SYSWOW64\mftranscode.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\SYSWOW64\MessagingDataModel2.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\uReFS.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\schannel.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\PhoneService.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\mftranscode.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\MessagingDataModel2.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\appraiser.dll
2016-01-16 14:09:33 ----A---- C:\WINDOWS\system32\aeinv.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\SYSWOW64\MP3DMOD.DLL
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\WMSPDMOE.DLL
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\winload.exe
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\storewuauth.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\qedit.dll
2016-01-16 14:09:32 ----A---- C:\WINDOWS\system32\MP3DMOD.DLL
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\usermgrcli.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\uReFS.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\qedit.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\SYSWOW64\ProximityCommon.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\usermgrcli.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\ProximityCommon.dll
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\omadmclient.exe
2016-01-16 14:09:31 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2016-01-16 14:09:30 ----A---- C:\WINDOWS\SYSWOW64\WMSPDMOE.DLL
2016-01-16 14:09:30 ----A---- C:\WINDOWS\SYSWOW64\UserMgrProxy.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\vbscript.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\UserMgrProxy.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\RMSRoamingSecurity.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\Chakradiag.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\DscCore.dll
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\drivers\BthLEEnum.sys
2016-01-16 14:09:30 ----A---- C:\WINDOWS\system32\aitstatic.exe
2016-01-16 14:09:29 ----A---- C:\WINDOWS\SYSWOW64\vbscript.dll
2016-01-16 14:09:29 ----A---- C:\WINDOWS\system32\aepic.dll
2016-01-10 12:54:16 ----AD---- C:\Program Files (x86)\Cheat Engine 6.5
2016-01-08 23:36:50 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-01-03 16:05:08 ----AD---- C:\Program Files\Microsoft Office 15
2015-12-30 21:43:35 ----AD---- C:\Program Files\CCleaner
2015-12-30 21:31:38 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_5.dll
2015-12-30 21:31:38 ----A---- C:\WINDOWS\system32\XAudio2_5.dll
2015-12-30 21:31:37 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_5.dll
2015-12-30 21:31:37 ----A---- C:\WINDOWS\system32\xactengine3_5.dll
2015-12-30 21:31:36 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_42.dll
2015-12-30 21:31:36 ----A---- C:\WINDOWS\system32\D3DCompiler_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\SYSWOW64\d3dx11_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\SYSWOW64\d3dcsx_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\system32\d3dx11_42.dll
2015-12-30 21:31:35 ----A---- C:\WINDOWS\system32\d3dcsx_42.dll
2015-12-30 21:31:33 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_42.dll
2015-12-30 21:31:33 ----A---- C:\WINDOWS\system32\d3dx10_42.dll
2015-12-30 21:31:32 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_42.dll
2015-12-30 21:31:32 ----A---- C:\WINDOWS\system32\D3DX9_42.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2015-12-30 21:31:31 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2015-12-30 21:31:30 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_41.dll
2015-12-30 21:31:30 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_4.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_3.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2015-12-30 21:31:29 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_4.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_6.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2015-12-30 21:31:28 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2015-12-30 21:31:27 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2015-12-30 21:31:25 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_40.dll
2015-12-30 21:31:25 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_3.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_2.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2015-12-30 21:31:24 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_3.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_5.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2015-12-30 21:31:23 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_1.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2015-12-30 21:31:21 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2015-12-30 21:31:20 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2015-12-30 21:31:18 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_39.dll
2015-12-30 21:31:18 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\XAPOFX1_0.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2015-12-30 21:31:16 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_4.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2015-12-30 21:31:14 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2015-12-30 21:31:12 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_38.dll
2015-12-30 21:31:12 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2015-12-30 21:31:11 ----A---- C:\WINDOWS\SYSWOW64\XAudio2_0.dll
2015-12-30 21:31:11 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2015-12-30 21:31:10 ----A---- C:\WINDOWS\SYSWOW64\xactengine3_0.dll
2015-12-30 21:31:10 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2015-12-30 21:31:09 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_3.dll
2015-12-30 21:31:09 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2015-12-30 21:31:08 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_10.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\SYSWOW64\D3DX9_37.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2015-12-30 21:31:06 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2015-12-30 21:31:04 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2015-12-30 21:31:02 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_36.dll
2015-12-30 21:31:02 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2015-12-30 21:31:00 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_9.dll
2015-12-30 21:31:00 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2015-12-30 21:30:59 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2015-12-30 21:30:57 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_35.dll
2015-12-30 21:30:57 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_8.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\X3DAudio1_2.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2015-12-30 21:30:56 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_34.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2015-12-30 21:30:54 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2015-12-30 21:30:53 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_7.dll
2015-12-30 21:30:53 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\SYSWOW64\d3dx10_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2015-12-30 21:30:52 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2015-12-30 21:30:51 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_33.dll
2015-12-30 21:30:51 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2015-12-30 21:30:50 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_6.dll
2015-12-30 21:30:50 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_5.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\SYSWOW64\d3dx10.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2015-12-30 21:30:48 ----A---- C:\WINDOWS\system32\d3dx10.dll
2015-12-30 21:30:46 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_32.dll
2015-12-30 21:30:46 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_4.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_1.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2015-12-30 21:30:45 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2015-12-30 21:30:42 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2015-12-30 21:30:41 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_3.dll
2015-12-30 21:30:41 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2015-12-30 21:30:40 ----A---- C:\WINDOWS\SYSWOW64\xinput1_2.dll
2015-12-30 21:30:40 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2015-12-30 21:30:38 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_2.dll
2015-12-30 21:30:38 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2015-12-30 21:30:37 ----A---- C:\WINDOWS\SYSWOW64\xinput1_1.dll
2015-12-30 21:30:37 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2015-12-30 21:30:36 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_1.dll
2015-12-30 21:30:36 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2015-12-30 21:30:23 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\SYSWOW64\xactengine2_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\SYSWOW64\x3daudio1_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2015-12-30 21:30:20 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2015-12-30 21:30:19 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_29.dll
2015-12-30 21:30:19 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2015-12-30 21:30:18 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_28.dll
2015-12-30 21:30:18 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2015-12-30 21:30:13 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_27.dll
2015-12-30 21:30:13 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2015-12-30 21:30:12 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2015-12-30 21:30:11 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_25.dll
2015-12-30 21:30:11 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2015-12-30 21:30:09 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_24.dll
2015-12-30 21:30:09 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\xinput1_3.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\msvcr80.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\mss32.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_31.dll
2015-12-30 21:20:37 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_30.dll
2015-12-30 21:20:34 ----A---- C:\WINDOWS\SYSWOW64\d3dx9_26.dll
2015-12-30 21:20:33 ----A---- C:\WINDOWS\SYSWOW64\binkw32.dll
2015-12-28 13:48:39 ----D---- C:\WINDOWS\system32\SleepStudy
2015-12-28 00:54:30 ----D---- C:\Users\PC1\AppData\Roaming\CyberLink
2015-12-26 22:41:11 ----D---- C:\ProgramData\ESET
2015-12-26 22:41:04 ----D---- C:\Program Files\ESET
2015-12-26 21:26:46 ----D---- C:\Users\PC1\AppData\Roaming\DropboxOEM
2015-12-26 15:48:44 ----D---- C:\ProgramData\USOShared
2015-12-26 15:31:30 ----D---- C:\ProgramData\Microsoft OneDrive
2015-12-26 15:21:09 ----A---- C:\WINDOWS\system32\emptyregdb.dat
2015-12-26 15:10:50 ----ASH---- C:\hiberfil.sys
2015-12-26 15:02:32 ----SD---- C:\Users\PC1\AppData\Roaming\Microsoft
2015-12-26 15:01:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-26 15:01:41 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2015-12-26 14:58:07 ----D---- C:\Program Files\Synaptics
2015-12-26 14:58:05 ----D---- C:\WINDOWS\SYSWOW64\sda
2015-12-26 14:57:53 ----D---- C:\Program Files\Common Files\ATI Technologies
2015-12-26 14:57:28 ----D---- C:\Program Files\AMD
2015-12-26 14:56:35 ----D---- C:\WINDOWS\system32\SRSLabs
2015-12-26 14:56:31 ----D---- C:\Program Files\Realtek
2015-12-26 14:56:30 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2015-12-26 14:55:37 ----A---- C:\WINDOWS\SYSWOW64\PrintConfig.dll
2015-12-26 14:53:50 ----AS---- C:\WINDOWS\bootstat.dat
2015-12-26 14:53:12 ----D---- C:\WINDOWS\Prefetch
2015-12-26 14:52:10 ----A---- C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-26 14:51:05 ----SHD---- C:\Recovery
2015-12-26 14:50:57 ----DC---- C:\WINDOWS\Panther
2015-12-26 14:45:51 ----D---- C:\Windows.old
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\WpcWebFilter.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Audio.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\PlayToDevice.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\NetSetupApi.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MSMPEG2ENC.DLL
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MSFlacDecoder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfreadwrite.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfds.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\MFCaptureEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\iertutil.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.proxy.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AudioSes.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AudioEng.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\wpncore.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\WpcWebFilter.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\Windows.Media.Audio.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupSvc.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\NetSetupApi.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MSFlacDecoder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfreadwrite.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfplat.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfds.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MFCaptureEngine.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\MDEServer.exe
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\EncDump.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\drivers\tdx.sys
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\dialserver.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\audiosrv.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioSes.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioEng.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-12-26 14:44:14 ----A---- C:\WINDOWS\system32\audiodg.exe
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\msfeeds.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\SYSWOW64\iedkcs32.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\readingviewresources.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ntdll.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\MSMPEG2ENC.DLL
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\mshtml.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\msfeeds.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\MFPlay.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\jscript.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iesetup.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iernonce.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ieframe.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\flvprophandler.dll
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\drivers\ntfs.sys
2015-12-26 14:44:13 ----A---- C:\WINDOWS\system32\drivers\afd.sys
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2015-12-26 14:44:06 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\wwapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\WWanAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\wimgapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\Unistore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\mssign32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\comsvcs.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\catsrvut.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\authui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\SYSWOW64\ActiveSyncProvider.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\XboxNetApiSvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwansvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanprotdim.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Wwanpref.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanmm.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwanconn.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wwancfg.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\WWanAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wups2.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wsplib.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wshrm.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wininetlui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wininet.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.UI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wimserv.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wimgapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wifitask.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wifinetworkmanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wificonnapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wcmsvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\wcmcsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\urlmon.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\Unistore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\twinui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\StorSvc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\StorageUsage.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SRH.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\shutdownux.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\shell32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\services.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\rilproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provtool.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provops.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provisioningcsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provhandlers.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provengine.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\provdatastore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\policymanagerprecheck.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\policymanager.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\pnidui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\PhoneProviders.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\mssign32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\mdmmigrator.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\lpk.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\LogonController.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\jsproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ihvrilproxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\iertutil.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\fontsub.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\fontdrvhost.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\drivers\wimmount.sys
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\drivers\rmcast.sys
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\dciman32.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\comsvcs.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\CellularAPI.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\catsrvut.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\authui.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\atmlib.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\atmfd.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\AppCapture.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-12-26 14:44:05 ----A---- C:\WINDOWS\system32\acmigration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\NmaDirect.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosResource.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MosHostClient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosTrace.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MosHost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\Microsoft-Windows-MapControls.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mfpmp.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\mf.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MbaeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapControlStringsRes.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\ETWCoreUIComponentsResources.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\BingOnlineServices.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\wuauclt.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32kfull.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32kbase.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\win32k.sys
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\user32.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringservice.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringconfigsp.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\tetheringclient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsUtilsV2.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorsNativeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\SensorService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\PlayToDevice.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\NmaDirect.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\NMAA.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\nativemap.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosStorage.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosResource.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\moshostcore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MosHostClient.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\moshost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mos.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mfpmp.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mf.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MBMediaManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MbaeApi.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mapsupdatetask.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\mapstoasttask.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsStore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsCSP.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsBtSvcProxy.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapControlStringsRes.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InputService.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\d3d11.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\cryptngc.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\BingOnlineServices.dll
2015-12-26 14:44:01 ----A---- C:\WINDOWS\system32\BingMaps.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\XblAuthTokenBrokerExt.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\XblAuthManagerProxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\wininetlui.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Bluetooth.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCoreRes.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\twinui.appcore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\SRHInproc.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\SRH.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\offlinelsa.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\msftedit.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\lpk.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\jsproxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\jscript.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\GdiPlus.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\fontsub.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\fontdrvhost.exe
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\deviceaccess.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\dcomp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\dciman32.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\BackgroundTransferHost.exe
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\atmlib.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\SYSWOW64\atmfd.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthManagerProxy.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\XblAuthManager.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\UIAutomationCoreRes.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\tzautoupdate.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\twinui.appcore.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\offlinelsa.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\msftedit.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\lsasrv.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\kerberos.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\fveapibase.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\fveapi.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\sdstor.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\ksecpkg.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\drivers\capimg.sys
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\deviceaccess.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\dcomp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\cdp.dll
2015-12-26 14:44:00 ----A---- C:\WINDOWS\system32\BackgroundTransferHost.exe
2015-12-26 14:20:21 ----D---- C:\WINDOWS\system32\Microsoft
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2015-12-26 14:16:05 ----D---- C:\Program Files\Reference Assemblies
2015-12-26 14:16:05 ----D---- C:\Program Files\MSBuild
2015-12-26 14:16:05 ----D---- C:\Program Files (x86)\Reference Assemblies
2015-12-26 14:16:05 ----D---- C:\Program Files (x86)\MSBuild
2015-12-26 14:16:05 ----D---- C:\inetpub
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2015-12-26 14:15:10 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-12-26 14:15:07 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2015-12-26 14:15:06 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-12-26 14:15:05 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
======List of files/folders modified in the last 1 month======
2016-01-25 17:46:34 ----D---- C:\WINDOWS\Temp
2016-01-25 17:44:08 ----D---- C:\WINDOWS\system32\sru
2016-01-25 17:30:12 ----D---- C:\WINDOWS\System32
2016-01-25 17:30:11 ----D---- C:\WINDOWS\INF
2016-01-25 17:27:00 ----D---- C:\WINDOWS\AppReadiness
2016-01-25 16:41:40 ----RD---- C:\Program Files
2016-01-25 16:00:45 ----D---- C:\WINDOWS\system32\drivers
2016-01-25 15:49:37 ----SHD---- C:\WINDOWS\Installer
2016-01-25 15:48:37 ----SHD---- C:\System Volume Information
2016-01-25 15:47:04 ----D---- C:\WINDOWS\Logs
2016-01-25 15:46:31 ----RD---- C:\Program Files (x86)
2016-01-24 16:50:34 ----D---- C:\WINDOWS\Microsoft.NET
2016-01-24 16:48:49 ----RSD---- C:\WINDOWS\assembly
2016-01-24 15:11:56 ----HD---- C:\Program Files\WindowsApps
2016-01-23 23:17:10 ----D---- C:\WINDOWS\system32\config
2016-01-23 23:06:42 ----D---- C:\WINDOWS\system32\DriverStore
2016-01-23 19:40:18 ----D---- C:\WINDOWS\SysWOW64
2016-01-23 19:21:27 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-01-23 19:09:27 ----D---- C:\WINDOWS\system32\MRT
2016-01-23 19:05:00 ----A---- C:\WINDOWS\system32\MRT.exe
2016-01-16 22:12:54 ----HD---- C:\ProgramData
2016-01-16 22:09:20 ----D---- C:\Windows
2016-01-16 16:49:35 ----D---- C:\WINDOWS\WinSxS
2016-01-16 16:46:50 ----D---- C:\WINDOWS\system32\Boot
2016-01-16 16:46:49 ----D---- C:\WINDOWS\system32\appraiser
2016-01-16 16:46:49 ----D---- C:\WINDOWS\AppPatch
2016-01-16 14:51:46 ----D---- C:\Users\PC1\AppData\Roaming\vlc
2016-01-16 14:27:52 ----D---- C:\WINDOWS\CbsTemp
2016-01-16 14:01:57 ----D---- C:\WINDOWS\system32\catroot2
2016-01-10 11:48:41 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-01-10 00:36:40 ----D---- C:\WINDOWS\OCR
2016-01-08 16:48:17 ----D---- C:\Program Files (x86)\Common Files
2016-01-03 16:09:50 ----SD---- C:\ProgramData\Microsoft
2016-01-03 16:09:00 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-01-03 16:05:24 ----RSD---- C:\WINDOWS\Fonts
2016-01-03 02:40:25 ----A---- C:\WINDOWS\SYSWOW64\FlashPlayerApp.exe
2016-01-01 02:17:22 ----D---- C:\WINDOWS\LiveKernelReports
2015-12-31 21:07:48 ----D---- C:\WINDOWS\system32\Tasks
2015-12-30 22:10:51 ----D---- C:\WINDOWS\debug
2015-12-30 22:10:44 ----D---- C:\WINDOWS\SoftwareDistribution
2015-12-29 19:29:33 ----D---- C:\WINDOWS\rescache
2015-12-29 18:08:45 ----D---- C:\WINDOWS\SYSWOW64\winrm
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\WCN
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\wbem
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2015-12-29 18:08:44 ----D---- C:\WINDOWS\SYSWOW64\sk-SK
2015-12-29 18:08:43 ----SD---- C:\WINDOWS\SYSWOW64\F12
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\Printing_Admin_Scripts
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\oobe
2015-12-29 18:08:43 ----D---- C:\WINDOWS\SYSWOW64\en-US
2015-12-29 18:08:42 ----SD---- C:\WINDOWS\SYSWOW64\DiagSvcs
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\en
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers\UMDF
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers\en-US
2015-12-29 18:08:42 ----D---- C:\WINDOWS\SYSWOW64\drivers
2015-12-29 18:08:42 ----D---- C:\WINDOWS\system32\winrm
2015-12-29 18:08:39 ----D---- C:\WINDOWS\system32\WCN
2015-12-29 18:08:39 ----D---- C:\WINDOWS\system32\wbem
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\Sysprep
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\slmgr
2015-12-29 18:08:38 ----D---- C:\WINDOWS\system32\sk-SK
2015-12-29 18:08:37 ----D---- C:\WINDOWS\system32\Printing_Admin_Scripts
2015-12-29 18:08:37 ----D---- C:\WINDOWS\system32\oobe
2015-12-29 18:08:36 ----SD---- C:\WINDOWS\system32\F12
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\migwiz
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\en-US
2015-12-29 18:08:36 ----D---- C:\WINDOWS\system32\en
2015-12-29 18:08:35 ----SD---- C:\WINDOWS\system32\DiagSvcs
2015-12-29 18:08:35 ----RD---- C:\WINDOWS\PurchaseDialog
2015-12-29 18:08:35 ----RD---- C:\WINDOWS\MiracastView
2015-12-29 18:08:35 ----D---- C:\WINDOWS\system32\drivers\UMDF
2015-12-29 18:08:35 ----D---- C:\WINDOWS\system32\drivers\en-US
2015-12-29 18:08:35 ----D---- C:\WINDOWS\servicing
2015-12-29 18:08:35 ----D---- C:\WINDOWS\PolicyDefinitions
2015-12-29 18:08:34 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2015-12-29 18:08:34 ----RD---- C:\WINDOWS\DevicesFlow
2015-12-29 18:08:34 ----D---- C:\WINDOWS\IME
2015-12-29 18:08:34 ----D---- C:\WINDOWS\Help
2015-12-29 18:08:34 ----D---- C:\WINDOWS\en-US
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Photo Viewer
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Media Player
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Journal
2015-12-29 18:08:34 ----D---- C:\Program Files\Windows Defender
2015-12-29 18:08:34 ----D---- C:\Program Files\Internet Explorer
2015-12-29 18:08:34 ----D---- C:\Program Files\Common Files\System
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Media Player
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Windows Defender
2015-12-29 18:08:34 ----D---- C:\Program Files (x86)\Internet Explorer
2015-12-29 18:06:21 ----D---- C:\WINDOWS\SYSWOW64\en-GB
2015-12-29 18:06:15 ----D---- C:\WINDOWS\system32\en-GB
2015-12-28 00:54:46 ----D---- C:\ProgramData\CyberLink
2015-12-27 18:29:30 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2015-12-27 18:29:30 ----D---- C:\WINDOWS\system32\cs-CZ
2015-12-27 18:29:27 ----A---- C:\WINDOWS\SYSWOW64\dpnet.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnsvr.exe
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnlobby.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnhupnp.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnhpast.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnathlp.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\SYSWOW64\dpnaddr.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnlobby.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnhpast.dll
2015-12-27 18:29:26 ----A---- C:\WINDOWS\system32\dpnet.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\SYSWOW64\dpmodemx.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnsvr.exe
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnhupnp.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnathlp.dll
2015-12-27 18:29:25 ----A---- C:\WINDOWS\system32\dpnaddr.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dpwsockx.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dplayx.dll
2015-12-27 18:29:24 ----A---- C:\WINDOWS\SYSWOW64\dplaysvr.exe
2015-12-27 18:26:41 ----D---- C:\WINDOWS\system32\NDF
2015-12-27 11:06:48 ----D---- C:\WINDOWS\appcompat
2015-12-26 22:42:14 ----HD---- C:\WINDOWS\ELAMBKUP
2015-12-26 22:33:34 ----D---- C:\WINDOWS\system32\CatRoot
2015-12-26 21:35:09 ----D---- C:\WINDOWS\system32\restore
2015-12-26 21:27:08 ----D---- C:\WINDOWS\system32\WDI
2015-12-26 15:54:57 ----D---- C:\ProgramData\McAfee
2015-12-26 15:54:57 ----D---- C:\Program Files\Common Files
2015-12-26 15:48:44 ----D---- C:\ProgramData\USOPrivate
2015-12-26 15:27:58 ----RD---- C:\WINDOWS\PrintDialog
2015-12-26 15:24:10 ----D---- C:\Program Files\Windows NT
2015-12-26 15:23:54 ----D---- C:\WINDOWS\system32\WinBioDatabase
2015-12-26 15:22:11 ----D---- C:\WINDOWS\Registration
2015-12-26 15:20:32 ----D---- C:\WINDOWS\Tasks
2015-12-26 15:16:39 ----D---- C:\WINDOWS\system32\LogFiles
2015-12-26 15:16:32 ----D---- C:\WINDOWS\system32\drivers\etc
2015-12-26 15:10:07 ----AD---- C:\Program Files (x86)\ATI Technologies
2015-12-26 15:06:29 ----D---- C:\WINDOWS\SYSWOW64\zh-TW
2015-12-26 15:06:29 ----D---- C:\WINDOWS\SYSWOW64\zh-HK
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\zh-CN
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\uk-UA
2015-12-26 15:06:28 ----D---- C:\WINDOWS\SYSWOW64\tr-TR
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\th-TH
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sv-SE
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sr-Latn-RS
2015-12-26 15:06:27 ----D---- C:\WINDOWS\SYSWOW64\sl-SI
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ru-RU
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ro-RO
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pt-PT
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pt-BR
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\pl-PL
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\nl-NL
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\nb-NO
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\lv-LV
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\lt-LT
2015-12-26 15:06:26 ----D---- C:\WINDOWS\SYSWOW64\ko-KR
2015-12-26 15:06:25 ----D---- C:\WINDOWS\SYSWOW64\ja-JP
2015-12-26 15:06:25 ----D---- C:\WINDOWS\SYSWOW64\it-IT
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\hu-HU
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\hr-HR
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\he-IL
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\fr-FR
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\fi-FI
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\et-EE
2015-12-26 15:06:24 ----D---- C:\WINDOWS\SYSWOW64\es-ES
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\el-GR
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\de-DE
2015-12-26 15:06:23 ----D---- C:\WINDOWS\SYSWOW64\da-DK
2015-12-26 15:06:22 ----D---- C:\WINDOWS\SYSWOW64\bg-BG
2015-12-26 15:06:22 ----D---- C:\WINDOWS\SYSWOW64\ar-SA
2015-12-26 15:06:22 ----AD---- C:\WINDOWS\SYSWOW64\Adobe
2015-12-26 15:06:20 ----D---- C:\WINDOWS\system32\zh-TW
2015-12-26 15:06:19 ----D---- C:\WINDOWS\system32\zh-HK
2015-12-26 15:06:19 ----D---- C:\WINDOWS\system32\zh-CN
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\uk-UA
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\tr-TR
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\th-TH
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\sv-SE
2015-12-26 15:06:17 ----D---- C:\WINDOWS\system32\sr-Latn-RS
2015-12-26 15:06:16 ----D---- C:\WINDOWS\system32\spool
2015-12-26 15:06:15 ----D---- C:\WINDOWS\system32\sl-SI
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\ru-RU
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\ro-RO
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pt-PT
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pt-BR
2015-12-26 15:06:14 ----D---- C:\WINDOWS\system32\pl-PL
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\nl-NL
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\nb-NO
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\migration
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\lv-LV
2015-12-26 15:06:07 ----D---- C:\WINDOWS\system32\lt-LT
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\ko-KR
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\ja-JP
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\it-IT
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\InputMethod
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\hu-HU
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\hr-HR
2015-12-26 15:06:06 ----D---- C:\WINDOWS\system32\he-IL
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\fr-FR
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\fi-FI
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\et-EE
2015-12-26 15:06:05 ----D---- C:\WINDOWS\system32\es-ES
2015-12-26 15:06:04 ----DC---- C:\WINDOWS\system32\DRVSTORE
2015-12-26 15:06:04 ----D---- C:\WINDOWS\system32\el-GR
2015-12-26 15:06:03 ----D---- C:\WINDOWS\system32\de-DE
2015-12-26 15:06:03 ----D---- C:\WINDOWS\system32\da-DK
2015-12-26 15:04:39 ----D---- C:\WINDOWS\system32\bg-BG
2015-12-26 15:04:39 ----D---- C:\WINDOWS\system32\ar-SA
2015-12-26 15:04:33 ----D---- C:\WINDOWS\MediaViewer
2015-12-26 15:04:28 ----D---- C:\WINDOWS\InputMethod
2015-12-26 15:04:22 ----D---- C:\WINDOWS\ADFS
2015-12-26 15:04:19 ----RD---- C:\Users
2015-12-26 15:04:14 ----D---- C:\Program Files (x86)\Windows Mail
2015-12-26 15:04:13 ----AD---- C:\Program Files (x86)\Hewlett-Packard
2015-12-26 15:04:10 ----D---- C:\Program Files\Windows Mail
2015-12-26 15:04:10 ----D---- C:\Program Files (x86)\AMD AVT
2015-12-26 15:04:09 ----D---- C:\Program Files\Common Files\microsoft shared
2015-12-26 15:03:50 ----D---- C:\WINDOWS\system32\Recovery
2015-12-26 15:02:21 ----D---- C:\WINDOWS\system32\CodeIntegrity
2015-12-26 14:52:22 ----D---- C:\WINDOWS\ServiceProfiles
2015-12-26 14:45:28 ----D---- C:\WINDOWS\SYSWOW64\migration
2015-12-26 14:45:28 ----D---- C:\WINDOWS\SYSWOW64\Dism
2015-12-26 14:45:28 ----D---- C:\WINDOWS\system32\Dism
2015-12-26 14:45:27 ----D---- C:\WINDOWS\Provisioning
2015-12-26 14:45:27 ----D---- C:\WINDOWS\bcastdvr
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\MUI
2015-12-26 14:16:07 ----D---- C:\WINDOWS\SYSWOW64\inetsrv
2015-12-26 14:16:07 ----D---- C:\WINDOWS\system32\MUI
2015-12-26 14:16:07 ----D---- C:\WINDOWS\system32\inetsrv
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\wamregps.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisRtl.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisrstap.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\iisreset.exe
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\ahadmin.dll
2015-12-26 14:15:57 ----A---- C:\WINDOWS\system32\admwprox.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\wamregps.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisRtl.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisrstap.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\iisreset.exe
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\ahadmin.dll
2015-12-26 14:15:55 ----A---- C:\WINDOWS\SYSWOW64\admwprox.dll
2015-12-26 14:00:54 ----HD---- C:\$WINDOWS.~BT
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 amdkmpfd;@oem10.inf,%AMDKMPFD_svcdesc%;AMD PCI Root Bus Lower Filter; C:\WINDOWS\System32\drivers\amdkmpfd.sys [2013-12-14 36608]
R0 amdpsp;@oem26.inf,%amdpsp.SVCDESC%;AMD PSP Service; C:\WINDOWS\system32\DRIVERS\amdpsp.sys [2015-06-23 277240]
R1 appdrv01;Application Driver (01); C:\WINDOWS\System32\Drivers\appdrv01.sys [2016-01-25 3854000]
R1 CLVirtualDrive;CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [2013-11-12 91912]
R1 eamonm;eamonm; C:\WINDOWS\system32\DRIVERS\eamonm.sys [2015-11-20 263528]
R1 ehdrv;ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [2015-11-20 186784]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\WINDOWS\system32\drivers\filecrypt.sys [2015-10-30 87040]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\WINDOWS\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 epfwwfpr;epfwwfpr; C:\WINDOWS\system32\DRIVERS\epfwwfpr.sys [2015-11-20 170792]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\WINDOWS\system32\drivers\mmcss.sys [2015-10-30 47616]
R2 storqosflt;@%SystemRoot%\System32\drivers\storqosflt.sys,-101; C:\WINDOWS\system32\drivers\storqosflt.sys [2015-10-30 78848]
R3 AmdAS4;@oem3.inf,%AmdAS4.SVCDESC%;AmdAS4 service; C:\WINDOWS\System32\drivers\AmdAS4.sys [2013-10-24 17640]
R3 amdkmdag;amdkmdag; C:\WINDOWS\system32\DRIVERS\atikmdag.sys [2015-08-01 21637664]
R3 amdkmdap;amdkmdap; C:\WINDOWS\system32\DRIVERS\atikmpag.sys [2015-08-01 682016]
R3 AtiHDAudioService;@oem29.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\WINDOWS\system32\drivers\AtihdWT6.sys [2015-05-28 102912]
R3 bcbtums;@oem34.inf,%BCBTUMS.SvcDesc%;Bluetooth RAM Firmware Download USB Filter; C:\WINDOWS\system32\drivers\bcbtums.sys [2015-10-01 208176]
R3 BCM43XX;@oem7.inf,%BCM43XX_Service_DispName%;Ovladač síťového adaptéru Broadcom 802.11; C:\WINDOWS\system32\DRIVERS\bcmwl63a.sys [2014-12-22 7532760]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\System32\drivers\BTHUSB.sys [2015-10-30 84992]
R3 clwvd;@oem0.inf,%clwvd.DeviceDesc%;CyberLink WebCam Virtual Driver; C:\WINDOWS\system32\DRIVERS\clwvd.sys [2014-01-28 41704]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RTKVHD64.sys [2014-09-03 4264536]
R3 RSP2STOR;@oem31.inf,%Rts5229%;Realtek PCIE CardReader Driver - P2; C:\WINDOWS\system32\DRIVERS\RtsP2Stor.sys [2015-06-05 310528]
R3 RTL8168;@oem9.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\WINDOWS\System32\drivers\Rt630x64.sys [2014-07-18 874712]
R3 SynTP;@oem35.inf,%SynTP.SvcDesc%;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2015-10-02 619208]
S0 eelam;eelam; C:\WINDOWS\system32\DRIVERS\eelam.sys [2015-11-20 14976]
S0 LSI_SAS2i;LSI_SAS2i; C:\WINDOWS\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\WINDOWS\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\WINDOWS\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\WINDOWS\System32\drivers\percsas3i.sys [2015-10-30 58720]
S0 storufs;@storufs.inf,%UfsServiceDesc%;Microsoft Universal Flash Storage (UFS) Driver; C:\WINDOWS\System32\drivers\storufs.sys [2015-10-30 34144]
S3 amdkmcsp;@oem26.inf,%amdkmcsp.SVCDESC%;AMD Kernel Mode CSP Service; C:\WINDOWS\system32\DRIVERS\amdkmcsp.sys [2015-06-23 101104]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\WINDOWS\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\WINDOWS\System32\drivers\BthEnum.sys [2015-10-30 112640]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\WINDOWS\System32\drivers\BthLEEnum.sys [2016-01-05 245760]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\WINDOWS\System32\drivers\bthpan.sys [2015-10-30 128512]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\System32\drivers\BTHport.sys [2016-01-05 953856]
S3 btwampfl;@oem34.inf,%btwampfl.ServiceName%;btwampfl; C:\WINDOWS\system32\DRIVERS\btwampfl.sys [2015-10-01 223024]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\WINDOWS\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\WINDOWS\System32\drivers\capimg.sys [2015-12-26 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\WINDOWS\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\WINDOWS\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\WINDOWS\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\WINDOWS\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\WINDOWS\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\WINDOWS\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\WINDOWS\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 ReFSv1;ReFSv1; C:\WINDOWS\system32\drivers\ReFSv1.sys [2015-10-30 930656]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\WINDOWS\System32\drivers\rfcomm.sys [2015-10-30 175104]
S3 SmbDrv;SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [2014-09-17 32496]
S3 SmbDrvI;SmbDrvI; C:\WINDOWS\System32\drivers\Smb_driver_Intel.sys [2014-09-17 33008]
S3 UcmCx0101;USB Connector Manager KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmCx.sys [2015-10-30 61952]
S3 UcmUcsi;@UcmUcsi.inf,%UcmUcsi.ServiceName%;USB Connector Manager UCSI Client; C:\WINDOWS\System32\drivers\UcmUcsi.sys [2015-10-30 46592]
S3 UdeCx;USB Device Emulation Support Library; C:\WINDOWS\system32\drivers\udecx.sys [2015-10-30 45056]
S3 Ufx01000;USB Function Class Extension; C:\WINDOWS\system32\drivers\ufx01000.sys [2015-10-30 254816]
S3 UfxChipidea;@ufxchipidea.inf,%UfxChipidea.ServiceName%;USB Chipidea Controller; C:\WINDOWS\System32\drivers\UfxChipidea.sys [2015-10-30 94048]
S3 ufxsynopsys;@ufxsynopsys.inf,%ufxsynopsys.ServiceName%;USB Synopsys Controller; C:\WINDOWS\System32\drivers\ufxsynopsys.sys [2015-10-30 131424]
S3 UrsCx01000;USB Role-Switch Support Library; C:\WINDOWS\system32\drivers\urscx01000.sys [2015-10-30 57696]
S3 UrsChipidea;@urschipidea.inf,%UrsChipidea.ServiceName%;Chipidea USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urschipidea.sys [2015-10-30 28512]
S3 UrsSynopsys;@urssynopsys.inf,%UrsSynopsys.ServiceName%;Synopsys USB Role-Switch Driver; C:\WINDOWS\System32\drivers\urssynopsys.sys [2015-10-30 27488]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AdaptiveSleepService;AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [2014-06-05 140288]
R2 AERTFilters;Andrea RT Filters Service; C:\Program Files\Realtek\Audio\HDA\AERTSr64.EXE [2009-11-18 98208]
R2 AMD External Events Utility;AMD External Events Utility; C:\WINDOWS\system32\atiesrxx.exe [2015-08-01 263200]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2014-06-05 344064]
R2 AppHostSvc;@%windir%\system32\inetsrv\iisres.dll,-30011; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 BcmBtRSupport;@oem34.inf,%BlueBcmBtRSupport.SVCNAME%;Bluetooth Driver Management Service; C:\WINDOWS\system32\BtwRSupportService.exe [2015-10-01 2286848]
R2 ClickToRunSvc;Služba Microsoft Office ClickToRun; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2015-12-22 2787512]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
R2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2015-11-20 2522616]
R2 HP Support Assistant Service;HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [2014-08-01 93184]
R2 HPWMISVC;HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [2014-09-02 509192]
R2 omniserv; HP SimplePass Service; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [2014-03-28 88064]
R2 OneSyncSvc_417fe;Hostitel synchronizace_417fe; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R2 RichVideo64;Cyberlink RichVideo64 Service(CRVS); C:\Program Files\CyberLink\Shared files\RichVideo64.exe [2014-04-14 389896]
R2 RtkAudioService;Realtek Audio Service; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2014-08-19 291032]
R2 SecureLine;avast! SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [2015-12-24 452456]
R2 SynTPEnhService;SynTPEnh Caller Service; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [2015-10-02 246472]
R2 tbaseprovisioning;tbaseprovisioning; C:\WINDOWS\SysWOW64\tbaseprovisioning.exe [2015-06-23 60432]
R2 tiledatamodelsvc;@%SystemRoot%\system32\tileobjserver.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
R3 StateRepository;@%SystemRoot%\system32\windows.staterepository.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S2 appdrvrem01;Application Driver Auto Removal Service (01); C:\WINDOWS\System32\appdrvrem01.exe [2016-01-25 551896]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-01-23 269504]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-10-30 51376]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 hpqwmiex;HP Software Framework Service; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2013-05-13 1129760]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_417fe;Služba zasílání zpráv_417fe; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-01-08 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 150600]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_417fe;Data kontaktů_417fe; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 RetailDemo;@%SystemRoot%\System32\RDXService.dll,-256; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 SensorDataService;@%SystemRoot%\system32\SensorDataService.exe,-101; C:\WINDOWS\System32\SensorDataService.exe [2015-10-30 1297408]
S3 SensorService;@%SystemRoot%\System32\sensorservice.dll,-1000; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 SmsRouter;@%SystemRoot%\System32\SmsRouterSvc.dll,-10001; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S3 TieringEngineService;@%SystemRoot%\system32\TieringEngineService.exe,-702; C:\WINDOWS\system32\TieringEngineService.exe [2015-10-30 290304]
S3 UnistoreSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-10003; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S3 UnistoreSvc_417fe;Úložiště uživatelských dat_417fe; C:\WINDOWS\System32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
S4 tzautoupdate;@%SystemRoot%\system32\tzautoupdate.dll,-200; C:\WINDOWS\system32\svchost.exe [2015-10-30 43944]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Možný kelogger
Dvouklikem na soubor C:\Program Files\trend micro\PC1.exe spusťte HijackThis. Klikněte na "Do a system scan only" a v otevřeném okně vlevo ve čtverečcích zaškrtněte:
Klikněte na >FixChecked<. Pak znovu spusťte OTM a klikněte na >CleanUp!<. OTM po sobě uklidí. Nakonec restartujte PC.R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.bing.com?pc=HPDTDFJS
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com?pc=HPDTDFJS
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Možný kelogger
Log je již OK. Co vás vede k podezření, že je v PC keylogger? Skeny žádný nenašly.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Možný kelogger
Eset občas nahlásí podezřelou komunikaci s neznámým serverem.
Re: Možný kelogger
A po posledním kroku mi přestalo fungovat tlačítko start a vůbec cokoliv na liště.
- Rudy
- Site Admin

- Příspěvky: 119673
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Možný kelogger
Desítky to po čištění někdy dělají. Zkuste obnovu systému k datu, kdy korketně fungoval.0507 píše:A po posledním kroku mi přestalo fungovat tlačítko start a vůbec cokoliv na liště.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?