Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Preventivní kontrola

Nemáte v tuto chvíli žádný problém s pc a chcete se jen ujistit, že je vše v pořádku?
Vložte log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Odpovědět
Zpráva
Autor
Kllrt
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 14 říj 2009 05:49

Preventivní kontrola

#1 Příspěvek od Kllrt »

Zdravím, prosím o preventivní kontrolu logu. :)

Kód: Vybrat vše

Logfile of random's system information tool 1.10 (written by random/random)
Run by Administrator at 2016-07-29 17:26:32
Microsoft Windows 8.1 Pro 
System drive C: has 42 GB (20%) free of 214 GB
Total RAM: 8099 MB (58% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:26:35, on 29. 7. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
C:\Program Files (x86)\GlassWire\GWIdlMon.exe
C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe
C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
C:\Games\Steam\Steam.exe
C:\Users\Administrator\AppData\Local\Discord\app-0.0.293\Discord.exe
C:\Games\Steam\bin\steamwebhelper.exe
C:\Users\Administrator\AppData\Local\Discord\app-0.0.293\Discord.exe
C:\Users\Administrator\AppData\Local\Discord\app-0.0.293\Discord.exe
C:\Program Files\totalcmd\TOTALCMD.EXE
C:\Program Files (x86)\GlassWire\GlassWire.exe
C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera_crashreporter.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe
C:\Program Files\trend micro\Administrator.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = 
F2 - REG:system.ini: UserInit=userinit.exe,
O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
O2 - BHO: Skype for Business Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O2 - BHO: ExplorerBHO Class - {449D0D6E-2412-4E61-B68F-1CB625CD9E52} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: Microsoft SkyDrive Pro Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MIF5BA~1\Office15\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O2 - BHO: ClassicIEBHO Class - {EA801577-E6AD-4BD5-8F71-4BE0154331A4} - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll
O3 - Toolbar: Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll
O4 - HKLM\..\Run: [SPIRunE] Rundll32 SPIRunE.dll,RunDLLEntry
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files (x86)\Creative\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [ControlCenter4] C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe /autorun
O4 - HKLM\..\Run: [BrStsMon00] C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe /AUTORUN
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Super Charger] C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
O4 - HKLM\..\Run: [BlueStacks Agent] C:\Program Files (x86)\BlueStacks\HD-Agent.exe
O4 - HKLM\..\Run: [Fast Boot] C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe
O4 - HKLM\..\Run: [Autodesk Desktop App] "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [Steam] "C:\Games\Steam\steam.exe" -silent
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [CtrlV.cz] "C:\Users\Administrator\AppData\Local\Apps\2.0\9M24KG3P.ZYL\THM4K71T.HJ7\test..tion_0000000000000000_0001.0000_83f100c7c3913a72\TestCtrlV.exe"
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Administrator\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [CCleaner Monitoring] "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
O4 - HKCU\..\Run: [GalaxyClient] C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe /launchViaAutoStart
O4 - HKCU\..\Run: [Spotify Web Helper] "C:\Users\Administrator\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
O4 - HKCU\..\Run: [Discord] C:\Users\Administrator\AppData\Local\Discord\app-0.0.293\Discord.exe
O4 - HKCU\..\Run: [DisplayFusion] "C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\Run: [f.lux] "C:\Users\Administrator\AppData\Local\FluxSoftware\Flux\flux.exe" /noshow
O4 - HKCU\..\Run: [GlassWire] "C:\Program Files (x86)\GlassWire\glasswire.exe" -hide
O4 - HKCU\..\Run: [SpybotPostWindows10UpgradeReInstall] "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
O4 - HKUS\S-1-5-18\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Autodesk Sync] C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe (User 'Default user')
O4 - Startup: DS4Windows.lnk = D:\Program Files (x86)\DS4\DS4Windows.exe
O4 - Startup: EOS Utility.lnk = C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe
O4 - Startup: HipChat.lnk = C:\Program Files (x86)\Atlassian\HipChat\hipchat.exe
O4 - Startup: WorkDrive – zástupce.lnk = C:\Games\Steam\SteamApps\common\Arma 3 Tools\WorkDrive\WorkDrive.exe
O8 - Extra context menu item: Download all links with IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
O8 - Extra context menu item: Download with IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files\Microsoft Office 15\Root\Office15\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files\Microsoft Office 15\Root\Office15\ONBttnIE.dll/105
O8 - Extra context menu item: Stáhnout pomocí &BitSpiritu - C:\Program Files (x86)\BitSpirit\bsurl.htm
O9 - Extra button: Odeslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Od&eslat do OneNotu - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIE.dll
O9 - Extra button: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra 'Tools' menuitem: Volání kliknutím v Lyncu - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll
O9 - Extra button: (no name) - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra 'Tools' menuitem: Classic IE Settings - {56753E59-AF1D-4FBA-9E15-31557124ADA2} - C:\Program Files\Classic Shell\ClassicIE_32.exe
O9 - Extra button: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: P&ropojené poznámky aplikace OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office15\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwareupdate/ocx/15113/CTPIDPDE.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareupdate/ocx/130321/CTPID.cab
O18 - Protocol: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files (x86)\Microsoft Office\Office15\MSOSB.DLL
O18 - Filter hijack: text/xml - {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\MSOXMLMF.DLL
O20 - AppInit_DLLs: ?????????????????????
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Autodesk Desktop App Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: BattlEye Service (BEService) - Unknown owner - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: BrYNSvc - Brother Industries, Ltd. - C:\Program Files (x86)\Browny02\BrYNSvc.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\Windows\SYSTEM32\crypserv.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: DisplayFusionService - Binary Fortress Software - C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe
O23 - Service: EasyAntiCheat - EasyAntiCheat Ltd - C:\Windows\system32\EasyAntiCheat.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Evolve Service (EvoSvc) - Echobit LLC - C:\Program Files\Echobit\Evolve\EvoSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: GalaxyClientService - GOG.com - C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe
O23 - Service: GalaxyCommunication - GOG.com - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service: GlassWire Control Service (GlassWire) - SecureMix LLC - C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService1.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Smart Connect Technology Agent (ISCTAgent) - Unknown owner - C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: Logitech Gaming Registry Service (LogiRegistryService) - Logitech Inc. - C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe
O23 - Service: mental ray Satellite for Autodesk 3ds Max 2017 64-bit (mi-raysat_3dsmax2017_64) - Unknown owner - D:\Program Files\Autodesk\3ds Max 2017\raysat_3dsmax2017_64server.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_FastBoot - MSI - C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
O23 - Service: MSI_SuperCharger - MSI - C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\Windows\system32\GameMon.des.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: SAMSUNG Mobile Connectivity Service (ss_conn_service) - DEVGURU Co., LTD. - C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Thrustmaster FAST service (TmWinService) - Guillemot Corporation - C:\Program Files (x86)\Thrustmaster\TARGET\TmService.exe
O23 - Service: TunngleService - Tunngle.net GmbH - C:\Program Files (x86)\Tunngle\TnglCtrl.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: Intel(R) Extreme Tuning Utility Service (XTU3SERVICE) - Intel(R) Corporation - C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe

--
End of file - 19008 bytes

======Listing Processes======





wininit.exe


C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
winlogon.exe
C:\Windows\system32\svchost.exe -k RPCSS
"C:\Windows\system32\nvvsvc.exe"
"dwm.exe"
"C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe  -first
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
"C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe"
C:\Windows\system32\svchost.exe -k NetworkService
"C:\Program Files\AVAST Software\Avast\AvastSvc.exe"
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe" /s
taskhostex.exe 
C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
"C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe" 
"C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Windows\System32\svchost.exe -k utcsvc
dashost.exe {74378b33-f439-4801-8fb71cd6cdfa6720}
"C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe"
"C:\Program Files (x86)\GlassWire\GWCtlSrv.exe"
"C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe"
C:\Windows\Explorer.EXE
ClassicStartMenu.exe -startup
"C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe" 
"C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe"
"C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe"
"C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe"
C:\Windows\System32\svchost.exe -k HPZ12
"C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe"
"C:\Program Files (x86)\GlassWire\GWIdlMon.exe" --cookie 4471060974603 --port 26887
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\svchost.exe -k HPZ12
C:\Windows\system32\PnkBstrA.exe
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"
"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"
"C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe"
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\Thrustmaster\TARGET\TmService.exe"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe"
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files\TortoiseSVN\bin\TSVNCache.exe"
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-ae2fa152-acbc-4e8a-9a4a-d0bb3d0a267b -SystemEventPortName:HostProcess-ea79541a-2deb-4580-baad-3feca36736e9 -IoCancelEventPortName:HostProcess-a84f02d7-b399-4c7a-9177-6d353e36352f -NonStateChangingEventPortName:HostProcess-a2a923ba-55ad-4593-a457-8257053e5f86 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:eba12138-d65a-4088-ab49-6c02b60a8f17 -DeviceGroupId:WpdFsGroup
igfxEM.exe 
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-028db2b0-b12b-4ac5-8558-dffaa5acfb4b -SystemEventPortName:HostProcess-43fc960b-b5b9-4fac-921d-fa1847ea1e24 -IoCancelEventPortName:HostProcess-1d988458-be23-491c-a897-0043f61b3e95 -NonStateChangingEventPortName:HostProcess-c6fa01f7-63b5-4a88-93ec-3b8f9d7ca34e -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:64ae9df3-14bf-4645-83c1-fb417733b1f9 -DeviceGroupId:WudfDefaultDevicePool
"C:\Program Files\Logitech Gaming Software\LCore.exe" /minimized
"C:\Program Files (x86)\TeamSpeak 3 Client\ts3client_win32.exe" 

"C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe" 
"C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe" 
"C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe" 
"C:\Program Files\Logitech Gaming Software\Applets\LCDPop3.exe" 
"C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe" 
"C:\Games\Steam\Steam.exe" -silent
"C:\Users\Administrator\AppData\Local\Discord\app-0.0.293\Discord.exe" 
C:\Games\Steam\bin\steamwebhelper.exe "-cachedir=C:\Users\Administrator\AppData\Local\Steam\htmlcache" "-steampid=5860" "-buildid=1468520696" "-steamid=0" --disable-gpu-compositing --disable-gpu --process-per-tab --enable-system-flash --disable-spell-checking --enable-widevine-cdm --enable-direct-write
"C:\Users\Administrator\AppData\Local\Discord\app-0.0.293\Discord.exe" --type=gpu-process --channel="6112.0.347283826\1678750860" --mojo-application-channel-token=F3103BB66F4025B60C0B4E2112F8BF05 --no-sandbox --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,13,27,55,71 --gpu-vendor-id=0x10de --gpu-device-id=0x13c2 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.6881 --gpu-driver-date=7-10-2016 --gpu-secondary-vendor-ids=0x8086 --gpu-secondary-device-ids=0x0412 --mojo-platform-channel-handle=1272 /prefetch:2
"C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe" 
"C:\Users\Administrator\AppData\Local\Discord\app-0.0.293\Discord.exe" --type=renderer --no-sandbox --primordial-pipe-token=D9071246A5E22039CFD579010494DF73 --lang=cs --app-user-model-id=com.squirrel.Discord.Discord --node-integration=true --background-color=#282b30 --enable-blink-features=EnumerateDevices,AudioOutputDevices --hidden-page --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=5789D00B03D7C7A05ACC5A6C3854735E --mojo-application-channel-token=A9225E6E4CBA7561D7FF48DC57C7E883 --channel="6112.2.1924811928\612572113" --mojo-platform-channel-handle=2264 /prefetch:1
"C:\Program Files\totalcmd\TOTALCMD.EXE" 
"C:\Program Files (x86)\GlassWire\GlassWire.exe" -hide
"C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6064.exe" "6460" "66452" "328468" "131970" "65678" "65730" "4eefcc98-8af2-4db2-93a8-d28407ed438f" "C:\Program Files (x86)\DisplayFusion\Hooks\AppHookWIN6064_60b4e2b9-254e-4571-b21c-2d97f8bfd0e9.dll" "DisplayFusion" "Software\Binary Fortress Software\DisplayFusion" "Software\Binary Fortress Software\DisplayFusion\Session" "1" "631"
"C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe" "6460" "66452" "328468" "131970" "65678" "65730" "4eefcc98-8af2-4db2-93a8-d28407ed438f" "C:\Program Files (x86)\DisplayFusion\Hooks\AppHookWIN6032_3c64c697-fd41-409c-b501-a60fed040de8.dll" "DisplayFusion" "Software\Binary Fortress Software\DisplayFusion" "Software\Binary Fortress Software\DisplayFusion\Session" "0" "631"
"C:\Windows\System32\rundll32.exe" SPIRunE.dll,RunDLLEntry
"C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --ran-launcher
"C:\Program Files (x86)\Opera\38.0.2220.41\opera_crashreporter.exe" --ran-launcher --crash-reporter-parent-id=3532
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --enable-features=DownloadResumption --type=gpu-process --channel="3532.0.1440351448\1539984322" --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,12,13,25,54,69 --gpu-vendor-id=0x10de --gpu-device-id=0x13c2 --gpu-driver-vendor=NVIDIA --gpu-driver-version=10.18.13.6881 --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --mojo-platform-channel-handle=1424 --ignored=" --type=renderer "
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=BFD2961C83BBA95FC74C4C283FEB541F --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.2.467539753\1150070348" --mojo-platform-channel-handle=1856
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=D1A32AEBE551565A5C7E59447E2DA4C8 --lang=cs --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.3.1582943081\1126637220" --mojo-platform-channel-handle=2080
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=9365431F32349AD0C68B75A464EA16FE --lang=cs --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.4.1988061030\1122016244" --mojo-platform-channel-handle=2112
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=1058CBD8BAF72CBAF3C219647BE809E4 --lang=cs --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.5.2024093249\1049085584" --mojo-platform-channel-handle=2132
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=F6913E444949DE59331DA4A81FF6B7E7 --lang=cs --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.6.992488347\1646829197" --mojo-platform-channel-handle=2152
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=414CBA5433CC3DF3B004FC2B4E447F05 --lang=cs --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.9.294693482\1853203114" --mojo-platform-channel-handle=2240
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=7180C8AE9B76D39CCA2EE34C227902F9 --lang=cs --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.11.883487331\143483891" --mojo-platform-channel-handle=2400
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=0077BB1BEC243A34F17453928EC147E1 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.12.719758170\70935689" --mojo-platform-channel-handle=2848
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=316BF785C020EFF7211D1F351B4BF0A4 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.13.72293016\1453071807" --mojo-platform-channel-handle=3156
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=537A00097F9858C622F33E8CC7C5F3F3 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.14.621820073\1388127158" --mojo-platform-channel-handle=3104
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=8D197F424712E18631CD63BF3D121E85 --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.15.1614270288\1496705555" --mojo-platform-channel-handle=3360
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=A72489EA94FE646F1DC189E64A611E1E --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.16.2010689157\1029065796" --mojo-platform-channel-handle=3376
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=renderer --alt-high-dpi-setting=96 --system-dpi-setting=96 --disable-touch-adjustment --enable-lcd-text --enable-webgl-draft-extensions --disable-direct-write --enable-features=DownloadResumption --primordial-pipe-token=6485D203F7F88EAC385E0F8C9B67EE8A --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --disable-client-side-phishing-detection --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --channel="3532.17.339641230\1212377265" --mojo-platform-channel-handle=3396
"C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
C:\Windows\system32\svchost.exe -k WindowsMobile
"C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\XtuService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe"
"C:\Program Files (x86)\Opera\38.0.2220.41\opera.exe" --type=utility --channel="3532.21.570500340\1016496831" --lang=cs --no-sandbox --with-feature:addons-detailed-errors=on --with-feature:hi-resolution-thumbnails=on --with-feature:use-turbo2=on --with-feature:installer-experiment-test=off --with-feature:installer-ui-stats=on --with-feature:installer-hide-from-program-and-features=off --with-feature:installer-pref-default-overrides-support=on --crash-reporter-pid=3556 --mojo-platform-channel-handle=9152
"I:\scoped_dir_3532_18123\RSITx64.exe" 

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player PPAPI Notifier.job - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_22_0_0_209_pepper.exe  -check pepperplugin 
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /c 
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe  /ua /installsource scheduler 

=========Mozilla firefox=========

ProfilePath - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\mj00lcz2.default

prefs.js - "browser.startup.homepage" -  "about:home"

"wrc@avast.com"=C:\Program Files\AVAST Software\Avast\WebRep\FF
"sp@avast.com"=C:\Program Files\AVAST Software\Avast\SafePrice\FF


[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@adobe.com/ShockwavePlayer]
"Description"=Adobe Shockwave Player
"Path"=C:\Windows\SysWOW64\Adobe\Director\np32dsw_1222172.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn.me/esnsonar,version=0.70.4]
"Description"=ESN Sonar browser plugin
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@esn/esnlaunch,version=2.3.0]
"Description"=
"Path"=C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf]
"Description"=
"Path"=C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5]
"Description"=Intel IPT WebApi plugin
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater]
"Description"=This plugin updates Intel WebAPI component
"Path"=C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files (x86)\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files (x86)\Java\jre1.8.0_45\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVision]
"Description"=NVIDIA stereo images plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@nvidia.com/3DVisionStreaming]
"Description"=NVIDIA 3D Vision Streaming plugin for Mozilla browsers
"Path"=C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll


[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@adobe.com/FlashPlayer]
"Description"=Adobe® Flash® Player 20.0.0.306 Plugin
"Path"=C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/DTPlugin,version=11.45.2]
"Description"=Java™ Deployment Toolkit
"Path"=C:\Program Files\Java\jre1.8.0_45\bin\dtplugin\npDeployJava1.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@java.com/JavaPlugin,version=11.45.2]
"Description"=Oracle® Next Generation Java™ Plug-In
"Path"=C:\Program Files\Java\jre1.8.0_45\bin\plugin2\npjp2.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0]
"Description"=Ag Player Plugin
"Path"=C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.1.5]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videolan.org/vlc,version=2.2.4]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files\VideoLAN\VLC\npvlc.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-02-21 484376]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2016-03-15 228552]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20 803520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_45\bin\ssv.dll [2015-06-12 551520]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-07-24 952952]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~1\MICROS~1\Office15\GROOVEEX.DLL [2016-03-15 2348848]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-06-12 212576]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2014-04-20 483520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]
IDM integration (IDMIEHlprObj Class) - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-02-21 422424]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Skype for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2016-03-15 163016]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{449D0D6E-2412-4E61-B68F-1CB625CD9E52}]
ExplorerBHO Class - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20 683200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2015-04-28 460712]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8E5E2654-AD2D-48bf-AC2D-D17F00898D06}]
avast! Online Security - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-07-24 716632]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft SkyDrive Pro Browser Helper - C:\PROGRA~2\MIF5BA~1\Office15\GROOVEEX.DLL [2016-03-15 1741104]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2015-04-28 172968]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EA801577-E6AD-4BD5-8F71-4BE0154331A4}]
ClassicIEBHO Class - C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2014-04-20 440512]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2014-04-20 803520]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{553891B7-A0D5-4526-BE18-D3CE461D6310} - Classic Explorer Bar - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2014-04-20 683200]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Launch LCore"=C:\Program Files\Logitech Gaming Software\LCore.exe [2016-02-18 15120504]
"AdobeAAMUpdater-1.0"=C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04 446392]
"Classic Start Menu"=C:\Program Files\Classic Shell\ClassicStartMenu.exe [2014-04-20 161984]
"ISCT Tray"=C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe [2014-08-25 5860656]
"IAStorIcon"=C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe [2013-11-21 36352]
"Windows Mobile-based device management"=C:\Windows\WindowsMobile\wmdcBase.exe [2007-05-31 660360]
"Start WingMan Profiler"=C:\Program Files\Logitech\Gaming Software\LWEMon.exe [2010-06-14 190536]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Steam"=C:\Games\Steam\steam.exe [2016-07-13 2856528]
"AdobeBridge"= []
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2014-03-04 3696912]
"CtrlV.cz"=C:\Users\Administrator\AppData\Local\Apps\2.0\9M24KG3P.ZYL\THM4K71T.HJ7\test..tion_0000000000000000_0001.0000_83f100c7c3913a72\TestCtrlV.exe []
"Akamai NetSession Interface"=C:\Users\Administrator\AppData\Local\Akamai\netsession_win.exe [2014-10-29 4673432]
"CCleaner Monitoring"=C:\Program Files\CCleaner\CCleaner64.exe [2015-07-17 8418584]
"GalaxyClient"=C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [2016-06-18 3978304]
"Spotify Web Helper"=C:\Users\Administrator\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2016-06-29 1553520]
"Discord"=C:\Users\Administrator\AppData\Local\Discord\app-0.0.293\Discord.exe [2016-07-27 62385336]
"DisplayFusion"=C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [2016-01-20 8547320]
"Zoner Photo Studio Autoupdate"=C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTRAY.EXE [2015-10-21 563416]
"f.lux"=C:\Users\Administrator\AppData\Local\FluxSoftware\Flux\flux.exe [2013-10-24 1017224]
"GlassWire"=C:\Program Files (x86)\GlassWire\glasswire.exe [2016-07-03 5742032]
"SpybotPostWindows10UpgradeReInstall"=C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [2015-07-28 1011200]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SPIRunE"=Rundll32 SPIRunE.dll,RunDLLEntry []
"AvastUI.exe"=C:\Program Files\AVAST Software\Avast\AvastUI.exe [2016-07-24 8900328]
"VolPanel"=C:\Program Files (x86)\Creative\Volume Panel\VolPanlu.exe [2010-02-18 241789]
"SwitchBoard"=C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]
"AdobeCS6ServiceManager"=C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [2012-03-09 1073312]
"ControlCenter4"=C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [2012-09-06 143360]
"BrStsMon00"=C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2012-06-06 3076096]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2015-04-30 334896]
"Super Charger"=C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [2015-05-18 1027024]
"BlueStacks Agent"=C:\Program Files (x86)\BlueStacks\HD-Agent.exe []
"Fast Boot"=C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [2015-04-22 759120]
"Autodesk Desktop App"=C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [2016-07-01 721856]
"SDTray"=C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [2014-06-24 4101576]

C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
DS4Windows.lnk - D:\Program Files (x86)\DS4\DS4Windows.exe
EOS Utility.lnk - C:\Program Files (x86)\Canon\EOS Utility\EOS Utility.exe
HipChat.lnk - C:\Program Files (x86)\Atlassian\HipChat\hipchat.exe
WorkDrive – zástupce.lnk - C:\Games\Steam\SteamApps\common\Arma 3 Tools\WorkDrive\WorkDrive.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\AeroGlass\DWMGlass.dll"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PAexec]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PAexec]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0
"SoftwareSASGeneration"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
""=

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutorun"=158

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot - Search & Destroy tray access"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater"
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe"="C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux2"=wdmaud.drv
"VIDC.FPS1"=frapsv64.dll
"VIDC.LAGS"=lagarith.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux3"=wdmaud.drv
"vidc.xtor"=C:\Windows\system32\DxtoryCodec.dll
"VIDC.RTV1"=rtvcvfw64.dll
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux1"=wdmaud.drv
"wave7"=wdmaud.drv
"midi7"=wdmaud.drv
"mixer7"=wdmaud.drv
"aux4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install - 
.scr - config - 

======List of files/folders created in the last 1 month======

2016-07-29 17:26:32 ----D---- C:\Program Files\trend micro
2016-07-29 17:16:47 ----D---- C:\AdwCleaner
2016-07-29 17:12:43 ----D---- C:\rsit
2016-07-29 17:12:43 ----D---- C:\Program Files (x86)\trend micro
2016-07-29 16:45:26 ----A---- C:\Windows\SYSWOW64\NvCamera32.dll
2016-07-29 16:45:26 ----A---- C:\Windows\system32\NvCamera64.dll
2016-07-29 16:44:58 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvumdshim.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvoglshim32.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-07-29 16:42:57 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvumdshimx.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvopencl.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvoglv64.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvoglshim64.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvmcumd.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvinitx.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\NvIFR64.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvhdap64.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\NvFBC64.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvdispgenco6436881.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvdispco6436881.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvcuvid.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvcuda.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\nvcompiler.dll
2016-07-29 16:42:57 ----A---- C:\Windows\system32\drivers\nvvadarm.sys
2016-07-29 16:42:57 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-07-29 16:42:57 ----A---- C:\Windows\system32\drivers\nvhda64v.sys
2016-07-29 16:42:56 ----A---- C:\Windows\system32\nvaudcaparm.dll
2016-07-27 16:23:07 ----D---- C:\dev
2016-07-25 16:30:01 ----A---- C:\Windows\system32\sdnclean64.exe
2016-07-24 21:47:23 ----A---- C:\Windows\system32\aswBoot.exe
2016-07-24 21:47:20 ----A---- C:\Windows\avastSS.scr
2016-07-20 17:37:54 ----D---- C:\ProgramData\Gaijin
2016-07-14 16:45:41 ----A---- C:\Windows\system32\drivers\gwdrv.sys
2016-07-14 16:45:38 ----D---- C:\Program Files (x86)\GlassWire
2016-07-09 17:21:47 ----D---- C:\Users\Administrator\AppData\Roaming\KingRoot
2016-07-09 17:18:49 ----D---- C:\Program Files (x86)\One Click Root
2016-07-09 17:18:23 ----D---- C:\Users\Administrator\AppData\Roaming\One Click Root
2016-07-09 16:25:53 ----D---- C:\Windows\LastGood
2016-07-07 16:53:43 ----D---- C:\Windows\LastGood.Tmp
2016-07-06 10:45:49 ----A---- C:\Windows\BlendSettings.ini
2016-07-05 13:11:23 ----D---- C:\Program Files\Bonjour
2016-07-05 13:11:23 ----D---- C:\Program Files (x86)\Bonjour
2016-07-05 13:09:43 ----D---- C:\Users\Administrator\AppData\Roaming\Andy

======List of files/folders modified in the last 1 month======

2016-07-29 17:26:32 ----RD---- C:\Program Files
2016-07-29 17:25:27 ----RD---- C:\Windows\System32
2016-07-29 17:25:27 ----D---- C:\Windows\Inf
2016-07-29 17:25:27 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-07-29 17:23:48 ----AD---- C:\Windows\Temp
2016-07-29 17:21:42 ----D---- C:\Users\Administrator\AppData\Roaming\ClassicShell
2016-07-29 17:20:12 ----D---- C:\Program Files (x86)\MSI Afterburner
2016-07-29 17:19:26 ----D---- C:\Users\Administrator\AppData\Roaming\TS3Client
2016-07-29 17:18:46 ----D---- C:\ProgramData\NVIDIA
2016-07-29 17:12:43 ----RD---- C:\Program Files (x86)
2016-07-29 17:11:02 ----D---- C:\Windows\system32\Tasks
2016-07-29 17:06:53 ----D---- C:\Users\Administrator\AppData\Roaming\discord
2016-07-29 17:05:55 ----D---- C:\Windows\SysWOW64
2016-07-29 17:00:36 ----D---- C:\Windows\system32\DriverStore
2016-07-29 17:00:36 ----D---- C:\Windows\system32\drivers
2016-07-29 17:00:36 ----D---- C:\Program Files\NVIDIA Corporation
2016-07-29 17:00:36 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-07-29 17:00:34 ----D---- C:\ProgramData\NVIDIA Corporation
2016-07-29 17:00:00 ----D---- C:\Windows\system32\sru
2016-07-29 09:38:41 ----D---- C:\Windows\Microsoft.NET
2016-07-29 09:34:04 ----SHD---- C:\Windows\Installer
2016-07-29 09:34:04 ----HD---- C:\Config.Msi
2016-07-29 09:32:04 ----D---- C:\Program Files (x86)\Opera
2016-07-29 09:29:05 ----D---- C:\Windows\Tasks
2016-07-28 21:39:19 ----D---- C:\Windows\system32\config
2016-07-28 20:54:44 ----D---- C:\Users\Administrator\AppData\Roaming\Origin
2016-07-28 19:04:39 ----D---- C:\ProgramData\Origin
2016-07-28 19:04:34 ----D---- C:\Program Files (x86)\Origin
2016-07-28 16:34:35 ----D---- C:\Windows\system32\NDF
2016-07-27 19:19:59 ----HD---- C:\ProgramData
2016-07-27 16:19:58 ----RSD---- C:\Windows\assembly
2016-07-27 16:19:51 ----SHD---- C:\System Volume Information
2016-07-25 17:43:57 ----A---- C:\temp.txt
2016-07-25 17:15:11 ----D---- C:\ProgramData\Spybot - Search & Destroy
2016-07-25 16:42:27 ----D---- C:\Windows\system32\drivers\etc
2016-07-25 16:38:26 ----D---- C:\Program Files\Common Files\AV
2016-07-25 16:38:25 ----D---- C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-07-25 16:30:03 ----ASD---- C:\ProgramData\Microsoft
2016-07-24 21:47:47 ----D---- C:\Windows\Minidump
2016-07-24 21:47:22 ----AD---- C:\Windows
2016-07-24 10:45:04 ----D---- C:\Windows\system32\Macromed
2016-07-24 10:45:03 ----D---- C:\Windows\SYSWOW64\Macromed
2016-07-23 13:36:42 ----D---- C:\Users\Administrator\AppData\Roaming\Sync withSIX
2016-07-22 17:10:15 ----D---- C:\ProgramData\Package Cache
2016-07-21 16:57:57 ----D---- C:\Games
2016-07-19 20:45:26 ----D---- C:\Program Files\Common Files
2016-07-19 20:45:26 ----D---- C:\Program Files (x86)\Common Files
2016-07-18 22:00:15 ----D---- C:\Users\Administrator\AppData\Roaming\obs-studio
2016-07-18 20:51:28 ----D---- C:\Users\Administrator\AppData\Roaming\OBS
2016-07-18 19:34:09 ----D---- C:\Program Files (x86)\TeamSpeak 3 Client
2016-07-18 19:21:13 ----D---- C:\Users\Administrator\AppData\Roaming\DMCache
2016-07-17 19:28:08 ----D---- C:\Program Files (x86)\SmartGit
2016-07-17 17:04:23 ----D---- C:\Users\Administrator\AppData\Roaming\Skype
2016-07-16 19:14:33 ----D---- C:\ProgramData\Skype
2016-07-16 19:14:32 ----RD---- C:\Program Files (x86)\Skype
2016-07-15 20:20:39 ----D---- C:\Users\Administrator\AppData\Roaming\Spotify
2016-07-15 20:15:32 ----A---- C:\Windows\system32\nvhdagenco6420103.dll
2016-07-11 17:23:46 ----D---- C:\Users\Administrator\AppData\Roaming\DS4Windows
2016-07-11 04:13:48 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-07-11 04:13:48 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-07-11 04:13:48 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-07-11 04:13:48 ----A---- C:\Windows\system32\nvmcvadgenco64.dll
2016-07-11 04:13:48 ----A---- C:\Windows\system32\nvapi64.dll
2016-07-11 01:17:28 ----A---- C:\Windows\system32\nvsvc64.dll
2016-07-11 01:17:28 ----A---- C:\Windows\system32\nvcpl.dll
2016-07-11 01:17:27 ----A---- C:\Windows\system32\nvvsvc.exe
2016-07-11 01:17:27 ----A---- C:\Windows\system32\nvsvcr.dll
2016-07-11 01:17:27 ----A---- C:\Windows\system32\nvshext.dll
2016-07-11 01:17:27 ----A---- C:\Windows\system32\nvmctray.dll
2016-07-11 01:17:27 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-07-11 01:17:27 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-07-09 16:06:20 ----D---- C:\Program Files (x86)\Samsung
2016-07-09 16:06:18 ----D---- C:\Windows\system32\catroot
2016-07-09 16:06:17 ----D---- C:\Windows\system32\catroot2
2016-07-09 16:05:42 ----D---- C:\Program Files\SAMSUNG
2016-07-09 12:01:20 ----D---- C:\Program Files (x86)\LOOT
2016-07-09 09:30:19 ----D---- C:\Program Files (x86)\Google
2016-07-08 21:43:33 ----D---- C:\Program Files\Mozilla Firefox
2016-07-06 10:32:32 ----D---- C:\Windows\SYSWOW64\directx
2016-07-05 21:00:35 ----A---- C:\Windows\SYSWOW64\PnkBstrB.exe
2016-07-05 18:42:08 ----D---- C:\Users\Administrator\AppData\Roaming\deluge
2016-07-05 13:11:41 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 aswRvrt;avast! Revert; C:\Windows\system32\drivers\aswRvrt.sys [2016-07-24 74544]
R0 aswVmm;avast! VM Monitor; C:\Windows\system32\drivers\aswVmm.sys [2016-07-24 290088]
R0 iaStorA;iaStorA; C:\Windows\System32\drivers\iaStorA.sys [2013-11-21 632168]
R1 aswKbd;aswKbd; C:\Windows\system32\drivers\aswKbd.sys [2016-07-24 37144]
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [2016-07-24 103064]
R1 aswSnx;aswSnx; C:\Windows\system32\drivers\aswSnx.sys [2016-07-24 1070904]
R1 aswSP;aswSP; C:\Windows\system32\drivers\aswSP.sys [2016-07-24 473592]
R1 dtsoftbus01;@oem54.inf,%DTSoftBus.SVCDESC%;DAEMON Tools Virtual Bus Driver; C:\Windows\System32\drivers\dtsoftbus01.sys [2014-10-19 283064]
R1 gwdrv;GlassWire Driver; C:\Windows\system32\DRIVERS\gwdrv.sys [2015-05-29 33152]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Windows\system32\drivers\HWiNFO64A.SYS [2015-05-21 27552]
R1 nm3;@netnm3.inf,%Nm3_Desc%;Microsoft Network Monitor 3 Driver; C:\Windows\system32\DRIVERS\nm3.sys [2010-06-09 46392]
R2 aswHwid;avast! HardwareID; C:\Windows\system32\drivers\aswHwid.sys [2016-07-24 37656]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [2016-07-24 108304]
R2 aswStm;aswStm; C:\Windows\system32\drivers\aswStm.sys [2016-07-24 162904]
R2 IDMWFP;IDMWFP; C:\Windows\system32\DRIVERS\idmwfp.sys [2015-04-18 195056]
R2 iocbios2;iocbios2; \??\C:\Program Files (x86)\Intel\Intel(R) Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [2015-05-28 30224]
R2 LGCoreTemp;Logitech CPU Core Tempurature; \??\C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [2015-06-21 14184]
R3 EvolveVirtualAdapter;@oem161.inf,%EvolveVirtualAdapter.Service.DispName%;Evolve Virtual Miniport Driver; C:\Windows\system32\DRIVERS\evolve.sys [2015-07-09 21656]
R3 ICCWDT;@oem25.inf,%ICCWDT.SVCDESC%;Intel(R) Watchdog Timer Driver (Intel(R) WDT); C:\Windows\System32\drivers\ICCWDT.sys [2015-06-01 39736]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2014-06-13 3793408]
R3 ikbevent;Intel Upper keyboard Class Filter Driver; C:\Windows\system32\DRIVERS\ikbevent.sys [2014-05-27 22216]
R3 imsevent;Intel Upper Mouse Class Filter Driver; C:\Windows\system32\DRIVERS\imsevent.sys [2014-05-27 22728]
R3 INETMON;INETMON; \??\C:\Windows\System32\Drivers\INETMON.sys [2014-05-27 25800]
R3 ISCT;@oem32.inf,%ISCT.DeviceDesc%;Intel(R) Smart Connect Technology Device Driver; C:\Windows\System32\drivers\ISCTD.sys [2014-05-27 44744]
R3 iwdbus;@oem78.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2014-05-07 27032]
R3 L1C;@oem46.inf,%L1C.Service.DispName%;NDIS Miniport Driver for Qualcomm Atheros AR81xx PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C63x64.sys [2013-07-16 130248]
R3 LGBusEnum;@oem209.inf,%LGBusEnum.SVCDESC%;Logitech Gaming Virtual Bus Enumerator Driver; C:\Windows\system32\drivers\LGBusEnum.sys [2015-06-11 37408]
R3 LGJoyXlCore;@oem209.inf,%LGJoyXlCore.SVCDESC%;Logitech Translation Layer Driver (LGS); C:\Windows\system32\drivers\LGJoyXlCore.sys [2015-06-11 68384]
R3 LGVirHid;@oem210.inf,%LGVirHid.SVCDESC%;Logitech Gamepanel Virtual HID Device Driver; C:\Windows\system32\drivers\LGVirHid.sys [2015-06-11 26912]
R3 MEIx64;@oem166.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\System32\drivers\TeeDriverW8x64.sys [2015-06-12 183584]
R3 NTIOLib_1_0_3;NTIOLib_1_0_3; \??\C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [2012-10-25 13368]
R3 NTIOLib_FastBoot;NTIOLib_FastBoot; \??\C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [2012-10-26 13368]
R3 NVHDA;@oem95.inf,%NVHDA.SvcDesc%;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [2016-07-15 214592]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2016-07-11 13581880]
R3 NVVADARM;@oem90.inf,%NVVADARM.SvcDesc%;NVIDIA Miracast Audio; C:\Windows\system32\drivers\nvvadarm.sys [2016-07-11 47672]
R3 RTCore64;RTCore64; \??\C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [2015-06-02 13536]
R3 ScpVBus;@oem86.inf,%ScpVBus.SVCDESC%;Scp Virtual Bus Driver; C:\Windows\System32\drivers\ScpVBus.sys [2013-05-19 39168]
R3 SensorsSimulatorDriver;@oem60.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [2014-10-29 226304]
R3 StillCam;@sti.inf,%StillCam.SvcDesc%;Ovladač digitálního fotoaparátu pro sériový port; C:\Windows\System32\drivers\serscan.sys [2014-10-29 11776]
R3 t3;@oem15.inf,%Creative.Device5Desc.amd64%;Sound Blaster X-Fi Xtreme Audio; C:\Windows\system32\drivers\t3.sys [2012-10-12 632832]
R3 tap0901t;@oem49.inf,%DeviceDescription%;TAP-Win32 Adapter V9 (Tunngle); C:\Windows\system32\DRIVERS\tap0901t.sys [2009-09-16 31232]
R3 TmBusEn;@oem66.inf,%busenum.SVCDESC%;Thrustmaster Bus Enumerator; C:\Windows\System32\drivers\TmBusEn.sys [2011-01-26 30208]
S0 amdkmafd;@oem168.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\Windows\System32\drivers\amdkmafd.sys [2012-09-23 21160]
S0 prohlp02;StarForce Protection Helper Driver v2; C:\Windows\System32\drivers\prohlp02.sys []
S0 prosync1;StarForce Protection Synchronization Driver v1; C:\Windows\System32\drivers\prosync1.sys []
S0 sfhlp01;StarForce Protection Helper Driver; C:\Windows\System32\drivers\sfhlp01.sys []
S1 NetworkX;NetworkX; C:\Windows\syswow64\ckldrv.sys [2000-02-03 24608]
S1 prodrv06;StarForce Protection Environment Driver v6; C:\Windows\System32\drivers\prodrv06.sys []
S2 Hardlock;Hardlock; \??\C:\Windows\system32\drivers\hardlock.sys [2005-06-14 296448]
S3 athur;@oem43.inf,%ATHR.Service.DispName%;Atheros AR9271 Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2010-01-05 1847296]
S3 BRDriver64_1_3_3_E02B25FC;BRDriver64_1_3_3_E02B25FC; \??\C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys []
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Služba Bluetooth Enumerator; C:\Windows\System32\drivers\BthEnum.sys [2015-06-10 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Ovladač úspory energie technologie Bluetooth; C:\Windows\system32\DRIVERS\BthLEEnum.sys [2013-12-04 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Zařízení Bluetooth (síť PAN); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2015-06-10 1201664]
S3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2015-06-10 81920]
S3 dg_ssudbus;@oem205.inf,%ssud.Service.DeviceDesc%;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudbus.sys [2016-04-25 129152]
S3 dot4;@oem52.inf,%Dot4_Name%;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2012-10-19 151968]
S3 Dot4Print;@oem53.inf,%Dot4Print_Name%;Print Class Driver for IEEE-1284.4; C:\Windows\System32\drivers\Dot4Prt.sys [2012-10-19 27040]
S3 dot4usb;@oem52.inf,%DOT4USB_NAME%;Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2012-10-19 49056]
S3 DroidCam;@oem24.inf,%DroidCam.SvcDesc%;DroidCam Virtual Audio; C:\Windows\system32\DRIVERS\droidcam.sys [2016-01-08 33592]
S3 DroidCamVideo;@oem22.inf,%DroidCamVideo.DeviceDesc%;DroidCam Source 3; C:\Windows\system32\DRIVERS\droidcamvideo.sys [2016-01-08 230712]
S3 ggflt;@oem158.inf,%SvcFltDesc%;SOMC USB Flash Driver Filter; C:\Windows\System32\drivers\ggflt.sys [2015-06-27 16088]
S3 ggsomc;@oem158.inf,%SvcDesc%;SOMC USB Flash Driver; C:\Windows\System32\drivers\ggsomc.sys [2015-06-27 30424]
S3 intaud_WaveExtensible;@oem77.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2014-05-07 38296]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
S3 IntcDAud;@oem75.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2015-08-11 460048]
S3 LGSHidFilt;@oem88.inf,%LGSHidFilt.SvcDesc%;Logitech Gaming KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [2013-05-30 64280]
S3 LGSUsbFilt;@oem12.inf,%LGSHidUsbFilt.SvcDesc%;Logitech Gaming KMDF USB Filter Driver; C:\Windows\system32\DRIVERS\LGSUsbFilt.Sys [2013-05-30 41752]
S3 MBfilt;MBfilt; C:\Windows\system32\drivers\MBfilt64.sys []
S3 NdisImPlatformMp;@%SystemRoot%\System32\drivers\ndisimplatform.sys,-531; C:\Windows\system32\DRIVERS\NdisImPlatform.sys [2014-10-29 126464]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Zařízení Bluetooth (RFCOMM protokol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [2015-01-30 167424]
S3 sparkocam;@oem109.inf,%sparkocam.DeviceDesc%;SparkoCam Video Source; C:\Windows\system32\DRIVERS\sparkocam.sys [2015-12-21 36176]
S3 ssudmdm;@oem204.inf,%ssud.Service.Name%;SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.); C:\Windows\system32\DRIVERS\ssudmdm.sys [2016-04-25 221824]
S3 teamviewervpn;@oem160.inf,%DeviceDescription%;TeamViewer VPN Adapter; C:\Windows\system32\DRIVERS\teamviewervpn.sys [2015-05-20 35112]
S3 TmFilter;@oem66.inf,%filter.SvcDesc%;Thrustmaster HID Filter Driver; C:\Windows\System32\drivers\TmFilter.sys [2011-01-26 24576]
S4 nvvad_WaveExtensible;@oem97.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys []

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Desktop App Service; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [2016-07-01 1295376]
R2 avast! Antivirus;Avast Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2016-07-24 197128]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2011-08-30 462184]
R2 CTAudSvcService;Creative Audio Service; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [2010-12-19 286720]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 DisplayFusionService;DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [2016-01-20 4616216]
R2 GlassWire;GlassWire Control Service; C:\Program Files (x86)\GlassWire\GWCtlSrv.exe [2016-07-03 4342224]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-11-21 15720]
R2 igfxCUIService1.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2014-06-13 315352]
R2 ISCTAgent;Intel(R) Smart Connect Technology Agent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [2014-08-25 209712]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2014-04-03 154584]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2014-04-03 398296]
R2 LogiRegistryService;Logitech Gaming Registry Service; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [2015-11-20 193144]
R2 MSI_FastBoot;MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [2015-06-04 105296]
R2 MSI_SuperCharger;MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [2015-05-18 163280]
R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2016-07-11 1364536]
R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2014-10-29 38792]
R2 PnkBstrA;PnkBstrA; C:\Windows\system32\PnkBstrA.exe [2016-06-25 76152]
R2 RapiMgr;@%windir%\WindowsMobile\rapimgr.dll,-104; C:\Windows\system32\svchost.exe [2014-10-29 38792]
R2 SDScannerService;Spybot-S&D 2 Scanner Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [2014-06-24 1738168]
R2 SDUpdateService;Spybot-S&D 2 Updating Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2014-06-27 2088408]
R2 SDWSCService;Spybot-S&D 2 Security Center Service; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [2014-04-25 171928]
R2 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2016-02-27 131784]
R2 ss_conn_service;SAMSUNG Mobile Connectivity Service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [2014-12-03 743688]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service; C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [2016-07-11 424384]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
R3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2014-06-24 171480]
S2 Crypkey License;Crypkey License; crypserv.exe []
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-07-28 2189840]
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-05-23 324224]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-04-04 51376]
S3 BEService;BattlEye Service; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [2016-07-11 1392648]
S3 BrYNSvc;BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [2012-06-05 266240]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2014-10-29 38792]
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2014-06-13 279000]
S3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2014-09-23 79360]
S3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2014-09-23 79360]
S3 EasyAntiCheat;EasyAntiCheat; C:\Windows\syswow64\EasyAntiCheat.exe [2016-02-04 242448]
S3 EvoSvc;Evolve Service; C:\Program Files\Echobit\Evolve\EvoSvc.exe [2015-07-09 1583488]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2016-05-21 1591264]
S3 GalaxyClientService;GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [2016-06-18 245312]
S3 GalaxyCommunication;GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [2016-06-18 6211648]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28 144200]
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2014-01-31 887232]
S3 mi-raysat_3dsmax2017_64;mental ray Satellite for Autodesk 3ds Max 2017 64-bit; D:\Program Files\Autodesk\3ds Max 2017\raysat_3dsmax2017_64server.exe [2011-09-15 86016]
S3 npggsvc;nProtect GameGuard Service; C:\Windows\syswow64\GameMon.des [2015-05-19 3190784]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-07-28 2120712]
S3 ose64;Office 64 Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2014-01-23 178760]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-07-13 1450064]
S3 SwitchBoard;SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivní kontrola

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Kllrt
Návštěvník
Návštěvník
Příspěvky: 2
Registrován: 14 říj 2009 05:49

Re: Preventivní kontrola

#3 Příspěvek od Kllrt »

Proběhl sken a nic to nenašlo :)

Kód: Vybrat vše

# AdwCleaner v5.201 - Log vytvořen 01/08/2016 v 15:21:37
# Aktualizováno 30/06/2016 by ToolsLib
# Databáze : 2016-07-31.4 [Server]
# Operační system : Windows 10 Pro  (X64)
# Uživatelské jméno : Kllrt - KLLRT
# Spuštěno z : I:\scoped_dir_5284_25783\adwcleaner_5.201.exe
# Nastavení : Sken
# Podpora : https://toolslib.net/forum

***** [ Služby ] *****


***** [ Složky ] *****


***** [ Soubory ] *****


***** [ DLL ] *****


***** [ WMI ] *****


***** [ Zástupci ] *****


***** [ Naplánované úlohy ] *****


***** [ Registry ] *****


***** [ Prohlížeče ] *****


*************************

C:\AdwCleaner\AdwCleaner[C1].txt - [1644 bytů] - [29/07/2016 17:18:03]
C:\AdwCleaner\AdwCleaner[S1].txt - [1437 bytů] - [29/07/2016 17:16:55]
C:\AdwCleaner\AdwCleaner[S2].txt - [949 bytů] - [01/08/2016 15:17:38]
C:\AdwCleaner\AdwCleaner[S3].txt - [871 bytů] - [01/08/2016 15:21:37]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [943 bytů] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119418
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Preventivní kontrola

#4 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Users\Administrator\AppData\Local\Akamai
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\LastGood.Tmp

:reg
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0055C089-8582-441B-A0BF-17B458C2A3A8}]/64
[-HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]/64
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"=-
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=-

:services
Bonjour Service

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Před skenem vypněte antivir a po něm restartujte PC. Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Odpovědět