Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pomalý PC, neustále vytěžuje Antimalware

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
stsam
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 14 lis 2006 15:48

Pomalý PC, neustále vytěžuje Antimalware

#1 Příspěvek od stsam »

Dobrý den, poslední dobou mi dělá, že proces Antimalware Service Executable mi disk zatíží na 100% a počítač se stává nepoužitelným. Proces ukončit nejde, tak prosím o pomoc, radu. Děkuji za Váš čas i um.

Přikládám log z RSIT

omalLogfile of random's system information tool 1.10 (written by random/random)
Run by stsam at 2016-08-13 07:34:49
Microsoft Windows 10 Pro
System drive C: has 81 GB (36%) free of 228 GB
Total RAM: 8136 MB (65% free)

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:38:57, on 13.08.2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10586.0545)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
C:\Windows\SysWOW64\muachost.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
C:\Program Files (x86)\MuralPix\MpAgent.exe
C:\Program Files (x86)\MSI\Live Update\Live Update.exe
C:\Windows\SysWOW64\mshta.exe
C:\Windows\SysWOW64\cmd.exe
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
C:\Users\stsam\AppData\Local\Temp\is-HPTL7.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp
C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
C:\Users\stsam\AppData\Local\Temp\is-K1MF6.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\stsam.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.cz/?gfe_rd=cr&ei=Vic ... gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Logitech SetPoint - {AF949550-9094-4807-95EC-D1C317803333} - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [MuralPixAgent] C:\Program Files (x86)\MuralPix\MpAgent.exe /r
O4 - HKLM\..\Run: [CanonQuickMenu] C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
O4 - HKLM\..\Run: [DriverPack Notifier] C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe --run startup
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Live Update] C:\Program Files (x86)\MSI\Live Update\Live Update.exe /REMINDER
O4 - HKCU\..\Run: [OneDrive] "C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [VideoViewer] C:\Program Files (x86)\VideoViewer\VideoViewer.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://help.eset.com (HKLM)
O15 - ESC Trusted Zone: http://help.eset.com (HKLM)
O16 - DPF: {53049A9A-1122-4673-B8D4-12F545AE3285} (CV781Object Object) - http://192.168.2.167:88/AVC_AX_764.cab
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: GamingApp_Service - Micro-Star Int'l Co., Ltd. - C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
O23 - Service: GamingHotkey_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: MSI_ActiveX_Service - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
O23 - Service: MSI Live Update Service (MSI_LiveUpdate_Service) - Micro-Star INT'L CO., LTD. - C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Protexis Licensing V2 x64 (PSI_SVC_2_x64) - arvato digital services llc - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\Windows\System32\SensorDataService.exe (file missing)
O23 - Service: Service KMSELDI - @ByELDI - C:\Program Files\KMSpico\Service_KMS.exe
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\Windows\system32\TieringEngineService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 12644 bytes

======Listing Processes======







C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork

C:\Windows\system32\atiesrxx.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
"C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe"
"C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe" /launchService
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE"
C:\Windows\system32\svchost.exe -k appmodel
C:\Windows\system32\svchost.exe -k imgsvc
"C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe"
"c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe"
"C:\Program Files\KMSpico\Service_KMS.exe"
C:\Windows\system32\locator.exe
"C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe"
"C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe"

C:\Windows\system32\wbem\WmiApSrv.exe
dashost.exe {f29b50ff-5e19-49a5-b96293e28b726f7e}
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe -Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted

C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\Windows Defender\MpCmdRun.exe" SpyNetServiceDss -RestrictPrivileges -AccessKey F3E936E2-7DA4-282B-59F6-8DF65DF92D48 -Reinvoke

C:\Windows\System32\WinLogon.exe -SpecialSession
"dwm.exe"
atieclxx
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide
sihost.exe
taskhostw.exe {222A245B-E637-4AE9-A93F-A59CA119A75E}
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe"
C:\Windows\SysWOW64\muachost.exe
"C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe"
"C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe" scan upload
C:\Windows\Explorer.EXE
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\system32\SettingSyncHost.exe -Embedding
"C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s
"C:\Program Files\Logitech\SetPointP\SetPoint.exe" /launchGaming
KHALMNPR.EXE /API
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
"C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
"C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files (x86)\MuralPix\MpAgent.exe" /r
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM" PriorityLow
"C:\Program Files (x86)\MSI\Live Update\Live Update.exe" /REMINDER
"C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe" 0
"C:\Windows\System32\mshta.exe" "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\bin\Tools\run.hta" "--relaunch" "true" "--run" "startup"
"C:\Windows\System32\cmd.exe" /C powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content 'C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.cmd.txt' -Wait | Invoke-Expression" > "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.stdout.log" 2> "C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.stderr.log"
\??\C:\Windows\system32\conhost.exe 0x4
powershell -NonInteractive -NoLogo -NoProfile -ExecutionPolicy Bypass "Get-Content 'C:\Users\stsam\AppData\Roaming\DriverPack Notifier\temp\ps.irspp88r.117dq.cmd.txt' -Wait | Invoke-Expression"
C:\Windows\System32\svchost.exe -k UnistackSvcGroup

C:\Windows\System32\InstallAgent.exe -Embedding
C:\Windows\system32\compattelrunner.exe
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe" -ServerName:SkypeHost.ServerServer
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"fontdrvhost.exe"
"C:\Windows\System32\Taskmgr.exe" /3
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=52.0.2743.116 --handshake-handle=0x1a8
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="8124.0.1249233551\2077789560" --mojo-application-channel-token=4C9C3347F88DE3ED5A5AC6AF44178535 --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=4,13,27,55 --gpu-vendor-id=0x1002 --gpu-device-id=0x67df --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=16.300.0.0 --gpu-driver-date=6-28-2016 --mojo-platform-channel-handle=1252 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=8C85144625CBBC6A43D4F0A8D662C520 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=4A11360B9A616B99C86859AD85EA7E26 --mojo-application-channel-token=E3D21900503249DB050C3E550396B40B --channel="8124.1.851544708\271718450" --mojo-platform-channel-handle=2300 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=4043DA56AE328F5B28158319D606BB99 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=73A91C7171BBCB6CB79AE829E7EE9460 --mojo-application-channel-token=A4E8F60DA7BE25D142220E90ABE5C406 --channel="8124.2.999908557\476529172" --mojo-platform-channel-handle=2360 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=02C7F62EE586097A824BD762B08488CF --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=C88306070C12463BC522BC6A2C16621D --mojo-application-channel-token=F54653761001648A97BD6F2B3A004717 --channel="8124.4.109337816\1038838931" --mojo-platform-channel-handle=2852 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=4E77192C7A2A60640E84DF815352B0EE --lang=cs --extension-process --enable-webrtc-hw-h264-encoding --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=2D8F7758716730A90FB6D9114D19C24B --mojo-application-channel-token=551E7BEBBC7DECC3E002809E339B90CD --channel="8124.5.1904356563\358751761" --mojo-platform-channel-handle=2856 /prefetch:1
"C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe"
"C:\Users\stsam\AppData\Local\Temp\is-HPTL7.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp" /SL5="$308CE,66054411,148480,C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe"
"C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe" /SPAWNWND=$308C6 /NOTIFYWND=$308CE
"C:\Users\stsam\AppData\Local\Temp\is-K1MF6.tmp\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp" /SL5="$208E0,66054411,148480,C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe" /SPAWNWND=$308C6 /NOTIFYWND=$308CE
C:\Windows\system32\DeviceCensus.exe -cv:T3yKlP98OEOWJnjQ.4

"C:\Users\stsam\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=017128FA7225A853CC443198E9F4B795 --lang=cs --instant-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=468FC8E89E058427F50926EB3E166896 --mojo-application-channel-token=5D58BFDF807FB820C5AC8D33644D7E1C --channel="8124.8.1453647312\1240125929" --mojo-platform-channel-handle=4968 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,*PreconnectMore<PreconnectMore,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/Aggressive/AutofillProfileOrderByFrecency/Enabled/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Disabled/*ClientSideDetectionModel/Model0/DirectWriteFontProxy/UseDirectWriteFontProxy/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/*EnableMediaRouter/Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/NewSuggestType_A4_Stable_R1/OutOfProcessPac/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Disable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/Default/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/*ResourcePriorities/Control25PermanentB/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/*SchedulerExpensiveTaskBlocking/Enabled/SyncHttpContentCompression/Enabled/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_10/*UMA-Uniformity-Trial-10-Percent/group_07/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_01/*UMA-Uniformity-Trial-5-Percent/group_10/*UMA-Uniformity-Trial-50-Percent/group_01/*UMA_CheckStates/NoChecks/ --primordial-pipe-token=8D5F062C0B7B3EB2CB0ADFEDED3AF79B --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=60BB871A0CAC383459120B55396F8573 --mojo-application-channel-token=6388244A2EC53327F63A75D5995B5E92 --channel="8124.10.794626780\683474137" --mojo-platform-channel-handle=2336 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=ppapi --channel="8124.11.1238816108\1743907658" --ppapi-flash-args --lang=cs --device-scale-factor=1 --mojo-platform-channel-handle=4864 --ignored=" --type=renderer " /prefetch:3

======Scheduled tasks folder======

C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler

=========Mozilla firefox=========

ProfilePath - C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@canon.com/EPPEX]
"Description"=Canon My Image Garden
"Path"=C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/Lync,version=15.0]
"Description"=Microsoft Lync Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@microsoft.com/SharePoint,version=14.0]
"Description"=Microsoft SharePoint Plug-in for Firefox
"Path"=C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9]
"Description"=Google Update
"Path"=C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\@videolan.org/vlc,version=2.2.3]
"Description"=VLC Multimedia Plugin
"Path"=C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\MozillaPlugins\Adobe Reader]
"Description"=Handles PDFs in-place in Firefox
"Path"=C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll


======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-30 213192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 209504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26 435320]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-30 2101040]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-30 154832]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3785D0AD-BFFF-47F6-BF5B-A587C162FED9}]
Canon Easy-WebPrint EX BHO - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23 176736]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF949550-9094-4807-95EC-D1C317803333}]
Logitech SetPoint - C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26 366200]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-30 1523504]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 6141528]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\Toolbar]
{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - Canon Easy-WebPrint EX - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23 4445272]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDVCPL"=C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [2016-07-18 8842496]
"EvtMgr6"=C:\Program Files\Logitech\SetPointP\SetPoint.exe [2015-08-26 3113592]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-07-08 6638472]
"Logitech Download Assistant"=C:\Windows\System32\LogiLDA.dll [2012-09-20 3933496]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"OneDrive"=C:\Users\stsam\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2016-05-18 554184]
"Skype"=C:\Program Files (x86)\Skype\Phone\Skype.exe [2016-06-29 26424960]
"VideoViewer"=C:\Program Files (x86)\VideoViewer\VideoViewer.exe [2015-07-03 286720]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"MuralPixAgent"=C:\Program Files (x86)\MuralPix\MpAgent.exe [2006-12-30 102400]
"CanonQuickMenu"=C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [2016-03-11 1314432]
"DriverPack Notifier"=C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe [2015-12-18 258560]
"StartCCC"=C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [2015-08-04 767176]
"Live Update"=C:\Program Files (x86)\MSI\Live Update\Live Update.exe [2016-07-19 11340752]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LBTWlgn]
c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll [2015-07-02 65992]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\iai2c.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Ahcache.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CoreMessagingRegistrar]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SpbCx.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\StateRepository]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\TileDataModelSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\uefi.sys]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UserManager]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{F2E7DD72-6468-4E36-B6F1-6488F42C1B52}]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"DSCAutomationHostEnabled"=2
"PromptOnSecureDesktop"=0

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=lvcod64.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"MSVideo8"=VfWWDM32.dll
"MSVideo"=vfwwdm32.dll
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"aux2"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv
"aux4"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"aux3"=wdmaud.drv
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"wave5"=wdmaud.drv
"midi5"=wdmaud.drv
"mixer5"=wdmaud.drv
"aux5"=wdmaud.drv
"wave6"=wdmaud.drv
"midi6"=wdmaud.drv
"mixer6"=wdmaud.drv
"aux6"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2016-08-13 07:34:49 ----D---- C:\rsit
2016-08-13 07:34:49 ----D---- C:\Program Files\trend micro
2016-08-13 06:58:07 ----HD---- C:\OneDriveTemp
2016-08-12 17:51:22 ----D---- C:\Windows\SYSWOW64\LiveUpdate
2016-08-12 17:51:22 ----A---- C:\Windows\SYSWOW64\ReleaseNote.txt
2016-08-12 15:57:58 ----D---- C:\Program Files\MSI Kombustor 3
2016-08-12 15:57:53 ----A---- C:\Windows\acpimof.dll
2016-08-12 15:57:41 ----D---- C:\Intel
2016-08-12 15:57:24 ----SHD---- C:\Config.Msi
2016-08-12 15:57:09 ----A---- C:\Windows\SYSWOW64\muachost.exe
2016-08-12 15:57:05 ----A---- C:\Windows\system32\FintekIcon1.dll
2016-08-12 15:57:05 ----A---- C:\Windows\system32\drivers\I2cHkBurn.sys
2016-08-12 15:56:54 ----D---- C:\Program Files (x86)\MSI
2016-08-12 15:56:54 ----D---- C:\MSI
2016-08-12 15:56:39 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-08-12 15:56:38 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-08-12 15:56:38 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-08-12 15:56:38 ----A---- C:\Windows\system32\vulkan-1.dll
2016-08-12 15:56:35 ----D---- C:\Program Files (x86)\VulkanRT
2016-08-12 15:55:47 ----A---- C:\Windows\SYSWOW64\amdocl12cl.dll
2016-08-12 15:55:47 ----A---- C:\Windows\system32\coinst_16.30.dll
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_vi_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_FJ_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_el_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\ativvaxy_cz_nd.dat
2016-08-12 15:55:47 ----A---- C:\Windows\system32\amdocl12cl64.dll
2016-08-12 15:55:45 ----A---- C:\Windows\SYSWOW64\amdoclvp9lib32.dll
2016-08-12 15:55:45 ----A---- C:\Windows\system32\amdoclvp9lib64.dll
2016-08-12 15:55:44 ----A---- C:\Windows\system32\ativvaxy_cik.dat
2016-08-12 15:55:44 ----A---- C:\Windows\system32\ativce03.dat
2016-08-12 15:55:43 ----A---- C:\Windows\SYSWOW64\amdmcl32.dll
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativvaxy_vi.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativvaxy_FJ.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\ativce02.dat
2016-08-12 15:55:43 ----A---- C:\Windows\system32\amdocl64.dll
2016-08-12 15:55:43 ----A---- C:\Windows\system32\amdmcl64.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\amfrt32.dll
2016-08-12 15:55:42 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\OpenCL.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\clinfo.exe
2016-08-12 15:55:42 ----A---- C:\Windows\system32\ativvaxy_stn_nd.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\ativvaxy_cik_nd.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amfrt64.dll
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde34b.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde34a.dat
2016-08-12 15:55:42 ----A---- C:\Windows\system32\amde31a.dat
2016-08-12 15:52:10 ----D---- C:\Windows\LastGood.Tmp
2016-08-10 18:55:38 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryClient.dll
2016-08-10 18:55:38 ----A---- C:\Windows\SYSWOW64\Windows.StateRepositoryBroker.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\rdpudd.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-08-10 18:55:38 ----A---- C:\Windows\system32\MusNotificationUx.exe
2016-08-10 18:55:38 ----A---- C:\Windows\system32\MusNotification.exe
2016-08-10 18:55:37 ----A---- C:\Windows\SYSWOW64\Windows.StateRepository.dll
2016-08-10 18:55:37 ----A---- C:\Windows\system32\SettingSyncHost.exe
2016-08-10 18:55:37 ----A---- C:\Windows\system32\rdpcorets.dll
2016-08-10 18:55:36 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-08-10 18:55:36 ----A---- C:\Windows\system32\WWAHost.exe
2016-08-10 18:55:35 ----A---- C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\wldp.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\NetSetupEngine.dll
2016-08-10 18:55:34 ----A---- C:\Windows\SYSWOW64\NetSetupApi.dll
2016-08-10 18:55:34 ----A---- C:\Windows\system32\wmp.dll
2016-08-10 18:55:33 ----A---- C:\Windows\SYSWOW64\dbgeng.dll
2016-08-10 18:55:33 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-08-10 18:55:33 ----A---- C:\Windows\system32\dbgeng.dll
2016-08-10 18:55:32 ----A---- C:\Windows\system32\drivers\cng.sys
2016-08-10 18:55:31 ----A---- C:\Windows\system32\wevtutil.exe
2016-08-10 18:55:31 ----A---- C:\Windows\system32\lsasrv.dll
2016-08-10 18:55:30 ----A---- C:\Windows\SYSWOW64\SensorsNativeApi.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\NetSetupApi.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\musdialoghandlers.dll
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgmms2.sys
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgmms1.sys
2016-08-10 18:55:29 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2016-08-10 18:55:28 ----A---- C:\Windows\system32\win32kbase.sys
2016-08-10 18:55:28 ----A---- C:\Windows\system32\NetSetupEngine.dll
2016-08-10 18:55:28 ----A---- C:\Windows\system32\cdd.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\usocore.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\NetSetupSvc.dll
2016-08-10 18:55:27 ----A---- C:\Windows\system32\ActiveSyncProvider.dll
2016-08-10 18:55:26 ----A---- C:\Windows\system32\win32kfull.sys
2016-08-10 18:55:25 ----A---- C:\Windows\system32\TpmTasks.dll
2016-08-10 18:55:24 ----A---- C:\Windows\system32\Windows.UI.Xaml.dll
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\WWAHost.exe
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-08-10 18:55:23 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-08-10 18:55:22 ----A---- C:\Windows\system32\mstscax.dll
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\VEEventDispatcher.dll
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\tdlrecover.exe
2016-08-10 18:55:21 ----A---- C:\Windows\SYSWOW64\LogonController.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\wwansvc.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\WUDFPlatform.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\winsrv.dll
2016-08-10 18:55:20 ----A---- C:\Windows\system32\RecoveryDrive.exe
2016-08-10 18:55:19 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-08-10 18:55:19 ----A---- C:\Windows\system32\GdiPlus.dll
2016-08-10 18:55:19 ----A---- C:\Windows\system32\drivers\pdc.sys
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\wshbth.dll
2016-08-10 18:55:18 ----A---- C:\Windows\SYSWOW64\BluetoothApis.dll
2016-08-10 18:55:17 ----A---- C:\Windows\SYSWOW64\Windows.UI.Xaml.dll
2016-08-10 18:55:17 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-08-10 18:55:17 ----A---- C:\Windows\system32\sppwinob.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wuaueng.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wuauclt.exe
2016-08-10 18:55:16 ----A---- C:\Windows\system32\wininet.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\urlmon.dll
2016-08-10 18:55:16 ----A---- C:\Windows\system32\sppobjs.dll
2016-08-10 18:55:15 ----A---- C:\Windows\SYSWOW64\wevtutil.exe
2016-08-10 18:55:15 ----A---- C:\Windows\system32\iertutil.dll
2016-08-10 18:55:15 ----A---- C:\Windows\system32\drivers\storport.sys
2016-08-10 18:55:15 ----A---- C:\Windows\system32\drivers\pci.sys
2016-08-10 18:55:14 ----A---- C:\Windows\system32\wuapi.dll
2016-08-10 18:55:14 ----A---- C:\Windows\system32\wshbth.dll
2016-08-10 18:55:14 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-08-10 18:55:14 ----A---- C:\Windows\system32\BluetoothApis.dll
2016-08-10 18:55:12 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepositoryBroker.dll
2016-08-10 18:55:11 ----A---- C:\Windows\system32\Windows.StateRepository.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\Windows.UI.Logon.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-08-10 18:55:10 ----A---- C:\Windows\system32\AppXDeploymentServer.dll
2016-08-10 18:55:10 ----A---- C:\Windows\system32\AppXDeploymentExtensions.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\VEEventDispatcher.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\tileobjserver.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\appraiser.dll
2016-08-10 18:55:09 ----A---- C:\Windows\system32\acmigration.dll
2016-08-10 18:55:08 ----A---- C:\Windows\system32\wldp.dll
2016-08-10 18:55:08 ----A---- C:\Windows\system32\tdlrecover.exe
2016-08-10 18:55:08 ----A---- C:\Windows\system32\LockAppHost.exe
2016-08-10 18:55:08 ----A---- C:\Windows\system32\IdCtrls.dll
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\OneDriveSettingSyncProvider.dll
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\LockAppHost.exe
2016-08-10 18:55:07 ----A---- C:\Windows\SYSWOW64\GdiPlus.dll
2016-08-10 18:55:07 ----A---- C:\Windows\system32\VEDataLayerHelpers.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\Windows.UI.Logon.dll
2016-08-10 18:55:06 ----A---- C:\Windows\SYSWOW64\SettingSyncHost.exe
2016-08-10 18:55:05 ----A---- C:\Windows\SYSWOW64\edgehtml.dll
2016-08-10 18:55:05 ----A---- C:\Windows\SYSWOW64\ActiveSyncProvider.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\Windows.Data.Pdf.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-08-10 18:55:04 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-08-10 18:55:03 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-08-10 18:55:03 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-08-10 18:55:02 ----A---- C:\Windows\SYSWOW64\IdCtrls.dll
2016-08-10 18:55:02 ----A---- C:\Windows\SYSWOW64\Chakra.dll
2016-08-10 18:55:02 ----A---- C:\Windows\system32\msfeeds.dll
2016-08-10 18:55:01 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-08-10 18:55:01 ----A---- C:\Windows\system32\jscript9.dll
2016-08-10 18:54:59 ----A---- C:\Windows\system32\Chakra.dll
2016-08-10 18:54:58 ----A---- C:\Windows\system32\ieframe.dll
2016-08-10 18:54:58 ----A---- C:\Windows\system32\Chakradiag.dll
2016-08-10 18:54:57 ----A---- C:\Windows\system32\edgehtml.dll
2016-08-10 18:54:56 ----A---- C:\Windows\system32\wuuhext.dll
2016-08-10 18:54:56 ----A---- C:\Windows\system32\mshtml.dll
2016-08-10 18:54:55 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-08-10 18:54:55 ----A---- C:\Windows\system32\LogonController.dll
2016-08-10 18:54:55 ----A---- C:\Windows\system32\ieapfltr.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\shell32.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\ole32.dll
2016-08-10 18:54:54 ----A---- C:\Windows\system32\MusUpdateHandlers.dll
2016-08-10 18:54:50 ----A---- C:\Windows\SYSWOW64\SensorsApi.dll
2016-08-10 18:54:50 ----A---- C:\Windows\system32\SensorsApi.dll
2016-08-10 18:54:49 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\SensorsNativeApi.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\SensorService.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\kerberos.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\iedkcs32.dll
2016-08-10 18:54:49 ----A---- C:\Windows\system32\drivers\rdbss.sys
2016-08-10 18:54:49 ----A---- C:\Windows\system32\bthserv.dll
2016-08-10 18:54:48 ----A---- C:\Windows\system32\ie4uinit.exe
2016-08-01 08:34:43 ----HD---- C:\ProgramData\CanonIJScan
2016-07-29 14:55:44 ----D---- C:\Users\stsam\AppData\Roaming\Mozilla
2016-07-29 14:26:06 ----D---- C:\ProgramData\ATI
2016-07-29 14:23:37 ----D---- C:\Users\stsam\AppData\Roaming\library_dir
2016-07-29 14:23:33 ----D---- C:\Program Files (x86)\Raptr Inc
2016-07-29 14:11:28 ----D---- C:\Users\stsam\AppData\Roaming\DRPNPS
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\Vb40032.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvcrt10.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvcr70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MSVCP70.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvci70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msvbvm50.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MSSTKPRP.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\msstdfmt.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71u.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71KOR.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71JPN.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ITA.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71CHT.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71CHS.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71FRA.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ESP.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71ENU.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\MFC71DEU.DLL
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70u.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70kor.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70jpn.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70ita.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70cht.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70chs.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70fra.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70esp.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70enu.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70deu.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\mfc70.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\atl71.dll
2016-07-29 14:08:06 ----A---- C:\Windows\SYSWOW64\atl70.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\tossaemaxapo64.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\tossaeapo64.dll
2016-07-29 14:07:29 ----A---- C:\Windows\system32\toseaeapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE3.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE2.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\YamahaAE.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\WavesGUILib64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tosasfapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tosade.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tepeqapo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tbb_waves.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tadefxapo264.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\tadefxapo.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\SRSWOW64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\sltech64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\slprp64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\slcnt64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\sl3apo64.dll
2016-07-29 14:07:28 ----A---- C:\Windows\system32\audioLibVc.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SRCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SFCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\SECOMN32.DLL
2016-07-29 14:07:27 ----A---- C:\Windows\SYSWOW64\RltkAPO.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSTSX64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSTSH64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRSHP64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRRPTR64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRCOM.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SRAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFSS_APO.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFNHK64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SFAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SEHDRA64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SECOMN64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\SEAPO64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtPgEx64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtlCPAPI64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEP64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEL64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEEG64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTEED64A.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RtDataProc64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RTCOM64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RP3DHT64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RP3DAA64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\RCoInstII64.dll
2016-07-29 14:07:27 ----A---- C:\Windows\system32\drivers\RTAIODAT.DAT
2016-07-29 14:07:26 ----A---- C:\Windows\system32\RCoRes64.dat
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEP64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEL64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEG64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EED64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\R4EEA64A.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\NAHIMICV3apo.dll
2016-07-29 14:07:26 ----A---- C:\Windows\system32\NahimicAPONSControl.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\NAHIMICV2apo.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\NAHIMICAPOlfx.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO4064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO3064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxVoiceAPO2064.dll
2016-07-29 14:07:25 ----A---- C:\Windows\system32\MaxxSpeechAPO64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRenderAVX64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRender64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioRealtek64.dll
2016-07-29 14:07:24 ----A---- C:\Windows\system32\MaxxAudioEQ64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MISS_APO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioCapture64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPOShell64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO7064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO6064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO5064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO4064.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO30.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\MaxxAudioAPO20.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\KAAPORT64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\IntelSstCApoPropPage.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\IntelSSTAPO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\ICEsoundAPO64.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMUI.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMLimiter.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMHVS.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMEQ_Voice.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMEQ.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMClariFi.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HMAPO.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HiFiDAX2API.dll
2016-07-29 14:07:23 ----A---- C:\Windows\system32\HarmanAudioInterface.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\FMAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSVoiceClarityDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PREC64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PLFX64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSU2PGFX64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSSymmetryDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSS2SpeakerDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSNeoPCDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSLimiterDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSLFXAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGFXAPONS64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGFXAPO64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSGainCompensatorDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSBoostDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DTSBassEnhancementDLL64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOv211.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOv201.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DolbyDAX2APOProp.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPP64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPP64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPO64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPO64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPD64AF3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPD64A.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPA64F3.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\DDPA64.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CX64APO.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\CAF64APO2.dll
2016-07-29 14:07:22 ----A---- C:\Windows\system32\Caf64api.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AERTAR64.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AERTAC64.dll
2016-07-29 14:07:21 ----A---- C:\Windows\system32\AcpiServiceVnA64.dll
2016-07-29 14:06:56 ----D---- C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-29 14:06:55 ----AD---- C:\Program Files (x86)\Mozilla Firefox
2016-07-29 14:06:46 ----D---- C:\Users\stsam\AppData\Roaming\Opera Software
2016-07-29 14:06:40 ----AD---- C:\Program Files (x86)\Opera
2016-07-29 14:06:28 ----AD---- C:\Users\stsam\AppData\Roaming\DriverPack Notifier
2016-07-29 14:06:27 ----D---- C:\Program Files (x86)\DriverPack Notifier
2016-07-29 14:06:27 ----AD---- C:\Program Files (x86)\WinRAR
2016-07-29 14:06:03 ----D---- C:\Users\stsam\AppData\Roaming\DRPSu
2016-07-27 12:39:36 ----AD---- C:\Program Files (x86)\AMD
2016-07-27 12:19:20 ----D---- C:\Program Files (x86)\Geeks3D
2016-07-27 12:18:34 ----D---- C:\Users\stsam\AppData\Roaming\AMD
2016-07-16 17:57:06 ----ASH---- C:\pagefile.sys
2016-07-15 22:20:36 ----D---- C:\Font
2016-07-14 18:26:03 ----ASH---- C:\swapfile.sys

======List of files/folders modified in the last 1 month======

2016-08-13 07:38:50 ----D---- C:\Windows\Temp
2016-08-13 07:34:49 ----RD---- C:\Program Files
2016-08-13 07:34:49 ----D---- C:\Windows\Prefetch
2016-08-13 07:26:09 ----D---- C:\Users\stsam\AppData\Roaming\Skype
2016-08-13 07:00:59 ----HD---- C:\Program Files\WindowsApps
2016-08-13 07:00:58 ----D---- C:\Windows\AppReadiness
2016-08-13 06:57:38 ----D---- C:\Windows\system32\sru
2016-08-12 21:27:32 ----D---- C:\Program Files (x86)\VideoViewer
2016-08-12 19:02:42 ----D---- C:\Windows\System32
2016-08-12 19:02:42 ----D---- C:\Windows\INF
2016-08-12 19:02:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-08-12 18:29:45 ----AD---- C:\Windows\SysWOW64
2016-08-12 18:07:26 ----D---- C:\Windows\Microsoft.NET
2016-08-12 15:58:50 ----D---- C:\Windows
2016-08-12 15:58:29 ----D---- C:\Windows\system32\CatRoot
2016-08-12 15:57:39 ----D---- C:\Windows\system32\drivers
2016-08-12 15:57:38 ----D---- C:\Windows\system32\Tasks
2016-08-12 15:57:38 ----D---- C:\Windows\system32\DriverStore
2016-08-12 15:57:37 ----D---- C:\ProgramData\Package Cache
2016-08-12 15:57:36 ----SHD---- C:\Windows\Installer
2016-08-12 15:57:24 ----SHD---- C:\System Volume Information
2016-08-12 15:56:54 ----RD---- C:\Program Files (x86)
2016-08-12 15:56:18 ----AD---- C:\Program Files\AMD
2016-08-12 07:02:23 ----D---- C:\ProgramData\CanonIJPLM
2016-08-11 20:36:13 ----D---- C:\Windows\system32\config
2016-08-11 19:09:47 ----D---- C:\Windows\WinSxS
2016-08-11 19:09:21 ----D---- C:\Windows\system32\catroot2
2016-08-11 19:07:41 ----D---- C:\Windows\rescache
2016-08-10 22:32:24 ----RD---- C:\Windows\ImmersiveControlPanel
2016-08-10 22:32:24 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-08-10 22:32:24 ----D---- C:\Windows\system32\en-US
2016-08-10 22:32:24 ----D---- C:\Windows\system32\cs-CZ
2016-08-10 22:32:24 ----D---- C:\Windows\system32\appraiser
2016-08-10 22:32:23 ----D---- C:\Program Files\Windows Journal
2016-08-10 22:32:23 ----D---- C:\Program Files\Internet Explorer
2016-08-10 22:32:23 ----D---- C:\Program Files (x86)\Internet Explorer
2016-08-10 21:04:27 ----D---- C:\Windows\system32\SecureBootUpdates
2016-08-10 21:04:27 ----D---- C:\Windows\CbsTemp
2016-08-10 21:04:25 ----D---- C:\Windows\system32\MRT
2016-08-10 21:00:14 ----AC---- C:\Windows\system32\MRT.exe
2016-08-06 17:19:10 ----D---- C:\Windows\Minidump
2016-08-05 11:00:11 ----D---- C:\AMD
2016-08-05 09:06:47 ----AD---- C:\Program Files (x86)\DVDFab 9
2016-08-05 07:47:16 ----D---- C:\Users\stsam\AppData\Roaming\vlc
2016-08-04 14:31:45 ----D---- C:\Windows\system32\NDF
2016-08-01 08:34:43 ----HD---- C:\ProgramData
2016-07-30 12:42:22 ----AD---- C:\ProgramData\regid.1991-06.com.microsoft
2016-07-30 12:42:11 ----D---- C:\Program Files (x86)\Common Files
2016-07-30 12:41:35 ----AD---- C:\Program Files (x86)\Microsoft Office
2016-07-29 14:22:59 ----D---- C:\ProgramData\AMD
2016-07-29 14:08:47 ----D---- C:\Windows\system32\wbem
2016-07-29 14:08:06 ----AD---- C:\Windows\System
2016-07-29 14:07:56 ----D---- C:\Windows\system32\DAX2
2016-07-29 14:07:46 ----D---- C:\Windows\SYSWOW64\RTCOM
2016-07-29 09:11:18 ----D---- C:\Windows\Tasks
2016-07-29 08:25:52 ----RSD---- C:\Windows\assembly
2016-07-29 08:25:52 ----D---- C:\Windows\SYSWOW64\directx
2016-07-29 08:25:31 ----D---- C:\Games
2016-07-27 21:25:34 ----N---- C:\Windows\system32\MpSigStub.exe
2016-07-27 11:55:26 ----SHD---- C:\$Recycle.Bin
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkCoLDR64.dll
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkCfg64.dll
2016-07-18 11:56:34 ----A---- C:\Windows\system32\RtkApi64.dll
2016-07-18 11:56:32 ----A---- C:\Windows\system32\RltkAPO64.dll
2016-07-15 10:09:34 ----SD---- C:\Users\stsam\AppData\Roaming\Microsoft
2016-07-15 10:09:34 ----SD---- C:\ProgramData\Microsoft
2016-07-15 09:05:07 ----D---- C:\ProgramData\Skype
2016-07-15 09:05:05 ----RD---- C:\Program Files (x86)\Skype
2016-07-14 14:45:00 ----D---- C:\Users\stsam\AppData\Roaming\Seznam.cz
2016-07-14 14:44:56 ----D---- C:\Program Files (x86)\Seznam.cz

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2016-08-03 84640]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2016-08-03 263296]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2016-08-03 197288]
R1 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2016-08-03 208552]
R1 EpfwLWF;@oem24.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-08-03 61608]
R1 FileCrypt;@%systemroot%\system32\drivers\filecrypt.sys,-100; C:\Windows\system32\drivers\filecrypt.sys [2016-04-23 87552]
R1 GpuEnergyDrv;@%SystemRoot%\system32\drivers\gpuenergydrv.sys,-100; C:\Windows\System32\drivers\gpuenergydrv.sys [2015-10-30 8192]
R2 AODDriver4.3;AODDriver4.3; \??\C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [2014-02-11 59616]
R2 ekbdflt;ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [2016-08-03 153248]
R2 MMCSS;@%systemroot%\system32\drivers\mmcss.sys,-100; C:\Windows\system32\drivers\mmcss.sys [2015-10-30 47616]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2016-06-29 26689024]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2016-06-29 500736]
R3 AtiHDAudioService;@oem13.inf,%ATIHdAudioDriver.SvcDesc%;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdWT6.sys [2016-04-26 110096]
R3 I2cHkBurn;I2cHkBurn; C:\Windows\system32\drivers\I2cHkBurn.sys [2015-07-27 41760]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2016-07-18 5193736]
R3 LEqdUsb;@oem29.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF USB Filter; C:\Windows\system32\DRIVERS\LEqdUsb.Sys [2015-06-18 87696]
R3 LHidEqd;@oem30.inf,%FltDisplayName%;Logitech SetPoint Unifying KMDF HID Filter; C:\Windows\system32\DRIVERS\LHidEqd.Sys [2015-06-18 23184]
R3 LHidFilt;@oem35.inf,%LHidFilt.SvcDesc%;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2015-06-18 86672]
R3 LMouFilt;@oem35.inf,%LMouFilt.SvcDesc%;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2015-06-18 69264]
S0 amdkmafd;@oem3.inf,%AMDKMAFD_svcdesc%;AMD Audio Bus Lower Filter; C:\Windows\System32\drivers\amdkmafd.sys [2015-07-28 40720]
S0 eelam;eelam; C:\Windows\system32\DRIVERS\eelam.sys [2016-08-03 15488]
S0 LSI_SAS2i;LSI_SAS2i; C:\Windows\System32\drivers\lsi_sas2i.sys [2015-10-30 104800]
S0 LSI_SAS3i;LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [2015-10-30 99168]
S0 percsas2i;percsas2i; C:\Windows\System32\drivers\percsas2i.sys [2015-10-30 58208]
S0 percsas3i;percsas3i; C:\Windows\System32\drivers\percsas3i.sys [2015-10-30 58720]
S3 athur;@oem25.inf,%ATHR.Service.DispName%;Atheros AR9271 Wireless Network Adapter Service; C:\Windows\System32\drivers\athurx.sys [2010-01-05 1847296]
S3 bcmfn;@bcmfn.inf,%bcmfn.SVCDESC%;bcmfn Service; C:\Windows\System32\drivers\bcmfn.sys [2015-10-30 9728]
S3 buttonconverter;@buttonconverter.inf,%btnconv.SvcDesc%;Service for Portable Device Control devices; C:\Windows\System32\drivers\buttonconverter.sys [2015-10-30 37376]
S3 CapImg;@capimg.inf,%CapImgHid_Service%;HID driver for CapImg touch screen; C:\Windows\System32\drivers\capimg.sys [2016-02-13 117248]
S3 genericusbfn;@genericusbfn.inf,%genericusbfn.ServiceName%;Generic USB Function Class; C:\Windows\System32\drivers\genericusbfn.sys [2015-10-30 20992]
S3 hidinterrupt;@hidinterrupt.inf,%HID_Interrupt.SvcDesc%;Common Driver for HID Buttons implemented with interrupts; C:\Windows\System32\drivers\hidinterrupt.sys [2015-10-30 50016]
S3 HWiNFO32;HWiNFO32/64 Kernel Driver; \??\C:\Users\stsam\AppData\Local\Temp\HWiNFO64A.SYS [2016-07-26 27552]
S3 iai2c;@iai2c.inf,%iai2c.SVCDESC%;Intel(R) Serial IO I2C Host Controller; C:\Windows\System32\drivers\iai2c.sys [2015-10-30 81408]
S3 iaLPSS2i_I2C;@iaLPSS2i_I2C_SKL.inf,%iaLPSS2i_I2C.SVCDESC%;Intel(R) Serial IO I2C Driver v2; C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [2015-10-30 165888]
S3 ibbus;@mlx4_bus.inf,%Ibbus.ServiceDesc%;Mellanox InfiniBand Bus/AL (Filter Driver); C:\Windows\System32\drivers\ibbus.sys [2015-10-30 424800]
S3 IoQos;@%SystemRoot%\system32\drivers\ioqos.sys,-100; C:\Windows\system32\drivers\ioqos.sys [2015-10-30 26624]
S3 LVRS64;@oem16.inf,%lvrs.SrvDesc%;Logitech RightSound Filter Driver; C:\Windows\system32\DRIVERS\lvrs64.sys [2012-10-26 351520]
S3 LVUVC64;@oem15.inf,%PID_0825_DD%(UVC);Logitech HD Webcam C270(UVC); C:\Windows\system32\DRIVERS\lvuvc64.sys [2012-10-26 4758176]
S3 mlx4_bus;@mlx4_bus.inf,%MLX4BUS.ServiceDesc%;Mellanox ConnectX Bus Enumerator; C:\Windows\System32\drivers\mlx4_bus.sys [2015-10-30 705376]
S3 MSICDSetup;MSICDSetup; \??\W:\CDriver64.sys [2009-08-12 28984]
S3 ndfltr;@mlx4_bus.inf,%ndfltr.ServiceDesc%;NetworkDirect Service; C:\Windows\System32\drivers\ndfltr.sys [2015-10-30 76128]
S3 NTIOLib_1_0_C;NTIOLib_1_0_C; \??\W:\NTIOLib_X64.sys [2011-06-29 11888]

stsam
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 14 lis 2006 15:48

Re: Pomalý PC, neustále vytěžuje Antimalware

#2 Příspěvek od stsam »

Zbytek logu:

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdobeARMservice;Adobe Acrobat Update Service; C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2016-06-25 82128]
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2016-06-29 269824]
R2 AMD FUEL Service;AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [2015-08-04 344064]
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-07-25 2950856]
R2 CoreMessagingRegistrar;@%SystemRoot%\system32\coremessaging.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R2 DiagTrack;@%SystemRoot%\system32\diagtrack.dll,-3001; C:\Windows\System32\svchost.exe [2015-10-30 43944]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2016-08-03 2780160]
R2 GamingApp_Service;GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [2016-05-19 39888]
R2 GamingHotkey_Service;GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2016-05-16 2019792]
R2 IJPLMSVC;Canon Inkjet Printer/Scanner/Fax Extended Survey Program; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [2013-06-28 84616]
R2 MSI_ActiveX_Service;MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [2016-06-01 54200]
R2 MSI_LiveUpdate_Service;MSI Live Update Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2016-07-19 2227152]
R2 OneSyncSvc_123f272;Hostitel synchronizace_123f272; C:\Windows\system32\svchost.exe [2015-10-30 43944]
R3 LicenseManager;@%SystemRoot%\system32\licensemanagersvc.dll,-200; C:\Windows\System32\svchost.exe [2015-10-30 43944]
R3 PimIndexMaintenanceSvc_123f272;Data kontaktů_123f272; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 DoSvc;@%systemroot%\system32\dosvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-16 154440]
S2 MapsBroker;@%SystemRoot%\System32\moshost.dll,-100; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc;@%SystemRoot%\system32\APHostRes.dll,-10002; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_115d2ac;Hostitel synchronizace_115d2ac; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_13ee79d;Hostitel synchronizace_13ee79d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_13eea554;Hostitel synchronizace_13eea554; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_14aa3f5;Hostitel synchronizace_14aa3f5; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_161c72;Hostitel synchronizace_161c72; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_1e00770;Hostitel synchronizace_1e00770; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_1ebcc87;Hostitel synchronizace_1ebcc87; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_20cd149;Hostitel synchronizace_20cd149; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_234b5e9;Hostitel synchronizace_234b5e9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_24ac328;Hostitel synchronizace_24ac328; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_25752c;Hostitel synchronizace_25752c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_26bf420;Hostitel synchronizace_26bf420; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_29c2d73;Hostitel synchronizace_29c2d73; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_2ead2fb;Hostitel synchronizace_2ead2fb; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_3009ab1;Hostitel synchronizace_3009ab1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_310187d;Hostitel synchronizace_310187d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_34006;Hostitel synchronizace_34006; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_34787;Hostitel synchronizace_34787; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_359dc;Hostitel synchronizace_359dc; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_36511;Hostitel synchronizace_36511; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_3ea52;Hostitel synchronizace_3ea52; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_3ebe8d8;Hostitel synchronizace_3ebe8d8; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_4005483;Hostitel synchronizace_4005483; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_41c45;Hostitel synchronizace_41c45; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_42c69;Hostitel synchronizace_42c69; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_448b2;Hostitel synchronizace_448b2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_44e51;Hostitel synchronizace_44e51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_44fa2;Hostitel synchronizace_44fa2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_45331;Hostitel synchronizace_45331; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_466e4;Hostitel synchronizace_466e4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_47585;Hostitel synchronizace_47585; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_477a7;Hostitel synchronizace_477a7; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_47a94;Hostitel synchronizace_47a94; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_47dee;Hostitel synchronizace_47dee; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_47eba;Hostitel synchronizace_47eba; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_48013;Hostitel synchronizace_48013; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_48e5e;Hostitel synchronizace_48e5e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_4950e;Hostitel synchronizace_4950e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_4afe2;Hostitel synchronizace_4afe2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_5252c;Hostitel synchronizace_5252c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_54a7d76;Hostitel synchronizace_54a7d76; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_55a65;Hostitel synchronizace_55a65; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_57785;Hostitel synchronizace_57785; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_5abca;Hostitel synchronizace_5abca; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_5f7e05;Hostitel synchronizace_5f7e05; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_60d4422;Hostitel synchronizace_60d4422; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_696a4;Hostitel synchronizace_696a4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_6acd0;Hostitel synchronizace_6acd0; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_6d7dad;Hostitel synchronizace_6d7dad; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_771b7;Hostitel synchronizace_771b7; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_77b8d;Hostitel synchronizace_77b8d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_7bac8a9;Hostitel synchronizace_7bac8a9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_851b4;Hostitel synchronizace_851b4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_88263;Hostitel synchronizace_88263; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_89b9a51;Hostitel synchronizace_89b9a51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_a513f1;Hostitel synchronizace_a513f1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_b2397b;Hostitel synchronizace_b2397b; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_b35df3;Hostitel synchronizace_b35df3; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_bb1c9e;Hostitel synchronizace_bb1c9e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_c9e84c;Hostitel synchronizace_c9e84c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S2 OneSyncSvc_fe8085;Hostitel synchronizace_fe8085; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 AJRouter;@%SystemRoot%\system32\AJRouter.dll,-2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 ClipSVC;@%SystemRoot%\system32\ClipSVC.dll,-103; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 DcpSvc;@%SystemRoot%\system32\dcpsvc.dll,-3001; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 DevQueryBroker;@%SystemRoot%\system32\DevQueryBroker.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 diagnosticshub.standardcollector.service;@%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [2015-10-30 31744]
S3 DmEnrollmentSvc;@%systemroot%\system32\Windows.Internal.Management.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 dmwappushservice;@%SystemRoot%\system32\dmwappushsvc.dll,-200; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 DsSvc;@%SystemRoot%\system32\dssvc.dll,-10003; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 embeddedmode;@%SystemRoot%\system32\embeddedmodesvc.dll,-200; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 EntAppSvc;@EnterpriseAppMgmtSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2015-10-23 43696]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-16 154440]
S3 icssvc;@%SystemRoot%\System32\tetheringservice.dll,-4097; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 LBTServ;Logitech Bluetooth Service; C:\Program Files\Common Files\LogiShrd\Bluetooth\lbtserv.exe [2015-07-02 356808]
S3 MessagingService;@%SystemRoot%\system32\MessagingService.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_115d2ac;Služba zasílání zpráv_115d2ac; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_123f272;Služba zasílání zpráv_123f272; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_13ee79d;Služba zasílání zpráv_13ee79d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_13eea554;Služba zasílání zpráv_13eea554; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_14aa3f5;Služba zasílání zpráv_14aa3f5; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_161c72;Služba zasílání zpráv_161c72; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_1e00770;Služba zasílání zpráv_1e00770; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_1ebcc87;Služba zasílání zpráv_1ebcc87; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_20cd149;Služba zasílání zpráv_20cd149; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_234b5e9;Služba zasílání zpráv_234b5e9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_24ac328;Služba zasílání zpráv_24ac328; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_25752c;Služba zasílání zpráv_25752c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_26bf420;Služba zasílání zpráv_26bf420; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_29c2d73;Služba zasílání zpráv_29c2d73; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_2ead2fb;Služba zasílání zpráv_2ead2fb; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_3009ab1;Služba zasílání zpráv_3009ab1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_310187d;Služba zasílání zpráv_310187d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_34006;Služba zasílání zpráv_34006; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_34787;Služba zasílání zpráv_34787; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_359dc;Služba zasílání zpráv_359dc; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_36511;Služba zasílání zpráv_36511; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_3ea52;Služba zasílání zpráv_3ea52; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_3ebe8d8;Služba zasílání zpráv_3ebe8d8; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_4005483;Služba zasílání zpráv_4005483; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_41c45;Služba zasílání zpráv_41c45; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_42c69;Služba zasílání zpráv_42c69; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_448b2;Služba zasílání zpráv_448b2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_44e51;Služba zasílání zpráv_44e51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_44fa2;Služba zasílání zpráv_44fa2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_45331;Služba zasílání zpráv_45331; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_466e4;Služba zasílání zpráv_466e4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_47585;Služba zasílání zpráv_47585; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_47a94;Služba zasílání zpráv_47a94; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_47dee;Služba zasílání zpráv_47dee; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_47eba;Služba zasílání zpráv_47eba; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_48013;Služba zasílání zpráv_48013; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_48e5e;Služba zasílání zpráv_48e5e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_4950e;Služba zasílání zpráv_4950e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_4afe2;Služba zasílání zpráv_4afe2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_5252c;Služba zasílání zpráv_5252c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_54a7d76;Služba zasílání zpráv_54a7d76; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_55a65;Služba zasílání zpráv_55a65; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_57785;Služba zasílání zpráv_57785; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_5abca;Služba zasílání zpráv_5abca; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_5f7e05;Služba zasílání zpráv_5f7e05; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_60d4422;Služba zasílání zpráv_60d4422; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_696a4;Služba zasílání zpráv_696a4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_6acd0;Služba zasílání zpráv_6acd0; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_6d7dad;Služba zasílání zpráv_6d7dad; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_771b7;Služba zasílání zpráv_771b7; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_77b8d;Služba zasílání zpráv_77b8d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_7bac8a9;Služba zasílání zpráv_7bac8a9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_851b4;Služba zasílání zpráv_851b4; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_88263;Služba zasílání zpráv_88263; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_89b9a51;Služba zasílání zpráv_89b9a51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_a513f1;Služba zasílání zpráv_a513f1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_b2397b;Služba zasílání zpráv_b2397b; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_b35df3;Služba zasílání zpráv_b35df3; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_bb1c9e;Služba zasílání zpráv_bb1c9e; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_c9e84c;Služba zasílání zpráv_c9e84c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MessagingService_fe8085;Služba zasílání zpráv_fe8085; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 MozillaMaintenance;Mozilla Maintenance Service; C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2016-06-03 146888]
S3 NetSetupSvc;@%SystemRoot%\system32\NetSetupSvc.dll,-3; C:\Windows\System32\svchost.exe [2015-10-30 43944]
S3 NgcCtnrSvc;@%SystemRoot%\System32\NgcCtnrSvc.dll,-1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 NgcSvc;@%SystemRoot%\System32\ngcsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2016-07-23 200240]
S3 PhoneSvc;@%SystemRoot%\system32\PhoneserviceRes.dll,-10000; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc;@%SystemRoot%\system32\UserDataAccessRes.dll,-15001; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_115d2ac;Data kontaktů_115d2ac; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_13ee79d;Data kontaktů_13ee79d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_13eea554;Data kontaktů_13eea554; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_14aa3f5;Data kontaktů_14aa3f5; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_161c72;Data kontaktů_161c72; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_1e00770;Data kontaktů_1e00770; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_1ebcc87;Data kontaktů_1ebcc87; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_20cd149;Data kontaktů_20cd149; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_234b5e9;Data kontaktů_234b5e9; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_24ac328;Data kontaktů_24ac328; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_25752c;Data kontaktů_25752c; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_26bf420;Data kontaktů_26bf420; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_29c2d73;Data kontaktů_29c2d73; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_2ead2fb;Data kontaktů_2ead2fb; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_3009ab1;Data kontaktů_3009ab1; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_310187d;Data kontaktů_310187d; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_34006;Data kontaktů_34006; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_34787;Data kontaktů_34787; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_359dc;Data kontaktů_359dc; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_36511;Data kontaktů_36511; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_3ea52;Data kontaktů_3ea52; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_3ebe8d8;Data kontaktů_3ebe8d8; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_4005483;Data kontaktů_4005483; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_41c45;Data kontaktů_41c45; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_42c69;Data kontaktů_42c69; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_448b2;Data kontaktů_448b2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_44e51;Data kontaktů_44e51; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_44fa2;Data kontaktů_44fa2; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S3 PimIndexMaintenanceSvc_45331;Data kontaktů_45331; C:\Windows\system32\svchost.exe [2015-10-30 43944]
S4 CDPSvc;@%SystemRoot%\system32\cdpsvc.dll,-100; C:\Windows\system32\svchost.exe [2015-10-30 43944]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý PC, neustále vytěžuje Antimalware

#3 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner http://general-changelog-team.fr/fr/dow ... adwcleaner
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan< a pak na >Clean<.
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

stsam
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 14 lis 2006 15:48

Re: Pomalý PC, neustále vytěžuje Antimalware

#4 Příspěvek od stsam »

# AdwCleaner v6.000 - *Logfile created 13/08/2016 *at 19:43:31
# *Updated on 12/08/2016 by ToolsLib
# *Database : 2016-08-13.2 [*Server]
# *Operating System : Windows 10 Pro (X64)
# *Username : stsam - STSAM
# *Running from : C:\Users\stsam\Desktop\adwcleaner_6.000.exe
# *Mode: Clean
# *Support : https://toolslib.net/forum



***** [ *Services ] *****



***** [ *Folders ] *****

[-] *Folder deleted: C:\Users\stsam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoViewer
[-] *Folder deleted: C:\Program Files (x86)\VideoViewer
[#] *Folder deleted on reboot: C:\Users\stsam\AppData\Local\temp
[-] *Folder deleted: C:\Users\stsam\AppData\LocalLow\temp
[#] *Folder deleted on reboot: C:\Windows\temp


***** [ *Files ] *****

[-] *File deleted: C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default\extensions\vb@yandex.ru.xpi
[-] *File deleted: C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default\extensions\yasearch@yandex.ru.xpi
[-] *File deleted: C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage
[-] *File deleted: C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_nafaimnnclfjfedmmabolbppcngeolgf_0.localstorage-journal


***** [ DLL ] *****



***** [ WMI ] *****



***** [ *Shortcuts ] *****



***** [ *Scheduled Tasks ] *****



***** [ *Registry ] *****

[-] *Key deleted: HKLM\SOFTWARE\Classes\CLSID\{0BF85F37-ECD3-462C-8F41-902FD170F42E}
[#] *Key deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID\{0BF85F37-ECD3-462C-8F41-902FD170F42E}
[#] *Key deleted on reboot: HKLM\SOFTWARE\Classes\WebCommObj.ExtCommObj.WebCommObj.ExtCommObj
[#] *Key deleted on reboot: HKLM\SOFTWARE\Classes\WebCommObj.ExtCommObj.WebCommObj.ExtCommObj.1
[#] *Key deleted on reboot: {C81DCEEB-4F70-497A-B8B5-E16727825B43}


***** [ *Browsers ] *****

[-] [mysearchdial.com] [Search Provider] *Deleted: mysearchdial.com
[-] [omiga-plus] [Search Provider] *Deleted: omiga-plus
[-] [babylon.com] [Search Provider] *Deleted: babylon.com
[-] [zapmeta.cz] [Search Provider] *Deleted: zapmeta.cz
[-] [teamspeak.en.softonic.com] [Search Provider] *Deleted: teamspeak.en.softonic.com
[-] [search.ask.com] [Search Provider] *Deleted: search.ask.com
[-] [trovi.search] [Search Provider] *Deleted: trovi.search
[-] [mysearch.avg.com] [Search Provider] *Deleted: mysearch.avg.com
[-] [isearch.omiga-plus.com] [Search Provider] *Deleted: isearch.omiga-plus.com
[-] [C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default] [extension] *Deleted: afpabppcibfahafilhkbbgfnlncppdnc
[-] [C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default] [extension] *Deleted: pelmeidfhdlhlbjimpabfcbnnojbboma


*************************

:: *"Tracing" keys deleted
:: *Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [2987 *Bytes] - [13/08/2016 19:43:31]
C:\AdwCleaner\AdwCleaner[S0].txt - [3550 *Bytes] - [13/08/2016 19:34:22]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3135 *Bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý PC, neustále vytěžuje Antimalware

#5 Příspěvek od Rudy »

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

stsam
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 14 lis 2006 15:48

Re: Pomalý PC, neustále vytěžuje Antimalware

#6 Příspěvek od stsam »

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2016 01
Ran by stsam (2016-08-13 20:30:40)
Running from C:\Users\stsam\Desktop
Windows 10 Pro Version 1511 (X64) (2016-04-16 10:14:17)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-331433692-3961677159-1017512419-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-331433692-3961677159-1017512419-503 - Limited - Disabled)
Guest (S-1-5-21-331433692-3961677159-1017512419-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-331433692-3961677159-1017512419-1005 - Limited - Enabled)
stsam (S-1-5-21-331433692-3961677159-1017512419-1001 - Administrator - Enabled) => C:\Users\stsam
wctxjybu (S-1-5-21-331433692-3961677159-1017512419-1003 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 9.0.395.2 (Disabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personální firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 20.2.1 - HP Inc.) Hidden
Adobe Acrobat Reader DC - Czech (HKLM-x32\...\{AC76BA86-7AD7-1029-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
AMD Install Manager (HKLM\...\AMD Catalyst Install Manager) (Version: 9.0.000.4 - Advanced Micro Devices, Inc.)
Aslain's WoT Modpack verze 9.15.1.1.00 (HKLM-x32\...\Aslains_WoT_Modpack_Installer_is1) (Version: 9.15.1.1.00 - Aslain)
Aslain's XVM WoT Modpack verze 9.15.34 (HKLM-x32\...\ZRwTINhSZfduKONYrSCTiCiGPggQZdcLRvoAVxyCOXXpkHeC~1DC3968F_is1) (Version: 9.15.34 - Aslain)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.6.0.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
Canon MG5600 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5600_series) (Version: 1.01 - Canon Inc.)
Canon MG5600 series On-screen Manual (HKLM-x32\...\Canon MG5600 series On-screen Manual) (Version: 7.7.1 - Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.5.0 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.5.0 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.7.0 - Canon Inc.)
Catalyst Control Center Next Localization BR (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CS (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DA (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization DE (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization EL (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization ES (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FI (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization FR (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization HU (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHS (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization CHT (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization IT (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization JA (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization KO (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NL (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization NO (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization PL (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization RU (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization SV (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TH (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
Catalyst Control Center Next Localization TR (Version: 2016.0708.1511.25486 - Advanced Micro Devices, Inc.) Hidden
CDRoller version 9.30 (HKLM-x32\...\CDRoller_is1) (Version: 9.30 - Digital Atlantic Corp.)
Corel Graphics - Windows Shell Extension (HKLM\...\_{EBDC2D0D-1E26-4EF2-BB48-C7E18F7800C6}) (Version: 16.0.0.707 - Corel Corporation)
Corel Graphics - Windows Shell Extension (Version: 16.0.707 - Corel Corporation) Hidden
Corel Graphics - Windows Shell Extension 32 Bit (Version: 16.0.707 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Capture (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Common (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Connect (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Custom Data (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - CZ (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Draw (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Filters (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - FontNav (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - IPM (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - PHOTO-PAINT (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Redist (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Setup Files (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VBA (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VideoBrowser (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - VSTA (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 - Writing Tools (x64) (Version: 16.0 - Corel Corporation) Hidden
CorelDRAW Graphics Suite X6 (64-Bit) (HKLM\...\_{BDBFAC49-8877-472F-876B-75ADB7DBC955}) (Version: 16.0.0.707 - Corel Corporation)
CorelDRAW Graphics Suite X6 (x64) (Version: 16.0 - Corel Corporation) Hidden
DriverPack Notifier (HKLM-x32\...\DriverPack Notifier) (Version: 2.1.2 - DriverPack Solution)
DVDFab 9.2.1.5 (28/09/2015) (HKLM-x32\...\DVDFab 9_is1) (Version: - Fengtao Software Inc.)
ESET Smart Security (HKLM\...\{5F04A9BE-7E95-4133-B23C-6BCAA3222C21}) (Version: 9.0.374.1 - ESET, spol. s r.o.)
FinePrint (HKLM\...\FinePrint) (Version: 8.16 - FinePrint Software, LLC)
Geeks3D FurMark 1.17.0.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version: - Geeks3D)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
IPScan (HKLM-x32\...\IPScan) (Version: 1.0.2.8 - Avtech)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version: - )
Light Image Resizer 4.7.7.0 (HKLM-x32\...\{EBE030DD-D404-4D92-85E9-8C3624820808}_is1) (Version: 4.7.7.0 - ObviousIdea)
Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech)
Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech)
Microsoft Office Professional Plus 2016 - cs-cz (HKLM\...\ProPlusRetail - cs-cz) (Version: 16.0.7070.2033 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 CSY (HKLM\...\{F0E39311-E741-4374-963A-8E899DC2C7B6}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 - ENU (HKLM-x32\...\{AA4A4B2C-0465-3CF8-BA76-27A027D8ACAB}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications 2.0 Runtime (HKLM-x32\...\{299C0434-4F4E-341F-A916-4E07AEB35E79}) (Version: 9.0.30729 - Microsoft Corporation)
Mozilla Firefox 47.0 (x86 ru) (HKLM-x32\...\Mozilla Firefox 47.0 (x86 ru)) (Version: 47.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0 - Mozilla)
MSI Gaming APP (HKLM-x32\...\{E0229316-E73B-484B-B9E0-45098AB38D8C}}_is1) (Version: 6.0.0.13 - MSI)
MSI Kombustor 3.5.0 (HKLM\...\{9598DA62-2AE8-426D-9C86-BEA96AC6721E}_is1) (Version: - MSI Co., LTD)
MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.1.021 - MSI)
MuralPix 1.07 (HKLM-x32\...\MuralPix) (Version: - )
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7030.1021 - Microsoft Corporation) Hidden
Rajče průvodce verze 1.59.54.269 (HKLM-x32\...\rajce.net_is1) (Version: - rajce.net)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7878 - Realtek Semiconductor Corp.)
Registrace uživatele zařízení Canon MG5600 series (HKLM-x32\...\Registrace uživatele zařízení Canon MG5600 series) (Version: - ‭Canon Inc.)
Skype™ 7.25 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.25.106 - Skype Technologies S.A.)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
Total Commander 64-bit (Remove or Repair) (HKLM\...\Totalcmd64) (Version: 8.52a - Ghisler Software GmbH)
Video Viewer (HKLM-x32\...\Video Viewer) (Version: 0.2.1.4 - AVTECH Corporation, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.3 - VideoLAN)
Vulkan Run Time Libraries 1.0.17.0 (HKLM\...\VulkanRT1.0.17.0) (Version: 1.0.17.0 - LunarG, Inc.)
WinRAR 5.30 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
World of Tanks (HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812eu}_is1) (Version: - Wargaming.net)
Záruky (HKLM\...\Zaruky) (Version: 4.1.9 - pyramidak)
Záruky (HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\Zaruky) (Version: 4.1.8 - pyramidak)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-331433692-3961677159-1017512419-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\stsam\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {07A59BAB-F48C-4A6F-A92F-EF23C62D8310} - System32\Tasks\{F85AB10B-D146-4EC6-904C-8CC654092F00} => pcalua.exe -a "C:\Users\stsam\Desktop\avech kamera\AVTECH_vyhledavac_IP_V1028\IPScan_1028_Setup.exe" -d "C:\Users\stsam\Desktop\avech kamera\AVTECH_vyhledavac_IP_V1028"
Task: {0F111AC4-EAF8-4AF4-BA7F-CB37349AB8C9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-16] (Google Inc.)
Task: {118F2575-CCBF-487F-B061-19F874E67D87} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-07-30] (Microsoft Corporation)
Task: {30683A32-0157-4CF8-8723-7563C32ACE40} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2015-12-02] (@ByELDI)
Task: {5B11343B-B0F1-495B-A162-B251DD60CDFC} - System32\Tasks\MSISW_Host => C:\Windows\SysWOW64\muachost.exe [2015-08-18] (MSI)
Task: {5E930ED9-2D3A-4CDF-857A-37D074573BB4} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-25] (Microsoft Corporation)
Task: {7D3F1AA2-8E79-44F5-AC0E-4CC4C4300498} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-07-25] (Microsoft Corporation)
Task: {A8227952-4DE2-4ABB-B604-59207270FEB3} - System32\Tasks\MSIOSDx86_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe [2016-06-30] (Micro-Star INT'L CO., LTD.)
Task: {AA589AED-2F49-4F17-B906-A67101F5B12B} - System32\Tasks\AMD Updater => C:\Program Files\AMD\CIM\\Bin64\InstallManagerApp.exe [2016-06-28] (Advanced Micro Devices, Inc.)
Task: {C19272AA-B3F0-4023-8CB6-729109D3F281} - System32\Tasks\pyramidak Zaruky => C:\Program Files\Zaruky\Zaruky.exe [2016-05-18] (pyramidak)
Task: {C2B3B54F-7909-4418-8BF8-AB696DFAA05E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-16] (Google Inc.)
Task: {CE5CDED6-4409-470B-A464-85F9B10D264F} - System32\Tasks\DriverPack Notifier => C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe [2015-12-18] ()
Task: {DE2BB7EB-9733-419D-A051-45921FBC4307} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {E9BB552A-1734-4CA5-A03C-17C2316BE372} - System32\Tasks\MSIOSDx64_Host => C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe [2016-06-30] (Micro-Star INT'L CO., LTD.)
Task: {F83EBB2E-58A1-46A2-A6D7-6290FA830EA6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2016-07-30] (Microsoft Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-10-30 09:18 - 2015-10-30 09:18 - 00185856 _____ () C:\Windows\SYSTEM32\ism32k.dll
2016-06-14 08:19 - 2013-06-28 15:28 - 00084616 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2015-08-04 00:25 - 2015-08-04 00:25 - 00214528 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 00817152 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Device.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 03650560 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Platform.dll
2016-07-12 21:45 - 2016-07-01 06:48 - 02656408 _____ () C:\Windows\system32\CoreUIComponents.dll
2016-08-12 15:57 - 2016-06-14 16:35 - 00187392 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\D3D11FontDraw.dll
2016-07-12 21:45 - 2016-07-01 06:48 - 02656408 _____ () C:\Windows\System32\CoreUIComponents.dll
2016-05-18 16:33 - 2016-05-18 16:33 - 00959168 _____ () C:\Users\stsam\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-04-19 06:35 - 2016-04-19 06:35 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-02-13 14:53 - 2016-02-13 14:53 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-12 21:46 - 2016-07-01 05:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-07-12 21:45 - 2016-07-01 05:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-07-12 21:45 - 2016-07-01 05:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-07-12 21:45 - 2016-07-01 05:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-07-12 21:45 - 2016-07-01 05:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-06-25 17:34 - 2015-06-25 17:34 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick.2\qtquick2plugin.dll
2015-06-25 17:37 - 2015-06-25 17:37 - 00739840 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-06-25 17:35 - 2015-06-25 17:35 - 00014336 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Window.2\windowplugin.dll
2015-06-25 17:38 - 2015-06-25 17:38 - 00071168 _____ () C:\Program Files\AMD\CNext\CNext\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-06-25 16:53 - 2015-06-25 16:53 - 00011776 _____ () C:\Program Files\AMD\CNext\CNext\libEGL.dll
2015-06-25 16:51 - 2015-06-25 16:51 - 02013696 _____ () C:\Program Files\AMD\CNext\CNext\libGLESv2.dll
2015-08-04 00:25 - 2015-08-04 00:25 - 00102400 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2016-08-12 17:51 - 2005-07-18 13:43 - 00160256 _____ () C:\Program Files (x86)\MSI\Live Update\unrar.dll
2016-08-12 15:57 - 2016-06-14 16:35 - 00163328 _____ () C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\D3D11FontDraw.dll
2016-04-19 06:35 - 2016-04-19 06:35 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-19 06:35 - 2016-04-19 06:35 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-05-18 16:33 - 2016-05-18 16:33 - 00679624 _____ () C:\Users\stsam\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2016-08-11 19:32 - 2016-07-13 16:33 - 00043520 _____ () C:\Games\World_of_Tanks\voip.dll
2016-07-29 08:32 - 2016-07-13 16:33 - 00140288 _____ () C:\Games\World_of_Tanks\ILU.dll
2016-07-29 08:32 - 2016-07-13 16:33 - 01529344 _____ () C:\Games\World_of_Tanks\ResIL.dll
2016-07-29 08:32 - 2016-07-13 16:33 - 00323568 _____ () C:\Games\World_of_Tanks\ortp.dll
2016-08-09 10:50 - 2016-08-03 02:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-09 10:42 - 2016-08-03 02:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-10-30 09:24 - 2015-10-30 09:21 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-331433692-3961677159-1017512419-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\stsam\AppData\Roaming\MuralPix\MuralPix_wallpaper.bmp
DNS Servers: 192.168.20.2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\Run32: => "CanonQuickMenu"
HKLM\...\StartupApproved\Run32: => "seznam-listicka-distribuce"
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\StartupApproved\Run: => "cz.seznam.software.autoupdate"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{CE100C6B-AC97-4D96-B551-FBDECCD55E89}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{829DB21C-E6EC-4D3E-8C2A-5DB1DEDC7C8C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [TCP Query User{C7DB543E-D68C-4217-8014-F566B836B666}F:\ovladace\sdi_x64_r439.exe] => (Allow) F:\ovladace\sdi_x64_r439.exe
FirewallRules: [UDP Query User{BA7FA420-0752-4F95-ADB3-75DB81A051CF}F:\ovladace\sdi_x64_r439.exe] => (Allow) F:\ovladace\sdi_x64_r439.exe
FirewallRules: [{D6A3EFFD-2816-4953-A59B-20251668A39A}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{31B9C348-12F9-48F2-92A5-7136E080058A}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{28295459-CF83-44DD-8EAB-A248EEFEA2BC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{0BC5B39B-75E4-4212-A834-0AF33A964FC8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{47F6AE9B-FAAC-4026-B727-28D5D182EF6E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{88C0BF9F-EA14-408D-A9EE-755CEA1D6F87}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2F5ACDD7-B156-4223-B349-46980FD9F68D}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{8F9AA44A-DCAD-47C2-8290-331D698E3D2C}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{66EDB261-4A3D-4E89-8D5A-BC1D8D33EA2E}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{7FC689E6-E301-4F2A-AEA9-60332B8A806C}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{BC25588C-DCD9-4621-8544-6283E6ACC82C}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{FD9FC909-B186-456C-98F2-B9B2BE5177FF}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{20FC2BE8-A097-4D42-AD4A-2802E6123FB5}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9D873294-6509-4A21-B240-2D50E015D386}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe
FirewallRules: [{3DB24814-17BE-45D2-A71B-B25C25DADFCC}] => (Allow) C:\Games\World_of_Tanks\WoTLauncher.exe
FirewallRules: [{142F0368-46FE-4F21-8883-D959448CCB72}] => (Allow) C:\Games\World_of_Tanks\worldoftanks.exe
FirewallRules: [{628B31A1-B4BA-448D-8196-BE98DCE86164}] => (Allow) C:\Games\World_of_Tanks\worldoftanks.exe
FirewallRules: [{8966535F-497E-4F1A-A6BB-D3D4FAE1C817}] => (Allow) LPort=26789

==================== Restore Points =========================

06-08-2016 16:49:43 Naplánovaný kontrolní bod
10-08-2016 20:58:34 Windows Update
12-08-2016 15:57:12 Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (08/13/2016 06:57:18 AM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error

Error: (08/12/2016 10:12:35 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error

Error: (08/12/2016 07:08:17 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Program IPScan_1028_Setup.exe verze 1.0.2.6 přestal spolupracovat se systémem Windows a byl ukončen. Chcete-li zjistit, zda je k dispozici více informací o tomto problému, vyhledejte historii problému v ovládacím panelu Zabezpečení a údržba.

ID procesu: 231c

Čas spuštění: 01d1f4bbfb27f86d

Čas ukončení: 6

Cesta k aplikaci: C:\Users\stsam\Desktop\avech kamera\AVTECH_vyhledavac_IP_V1028\IPScan_1028_Setup.exe

ID hlášení: 58042c7a-60af-11e6-bdf8-08606e757678

Úplný název balíčku s chybou:

ID aplikace související s balíčkem s chybou:

Error: (08/12/2016 06:15:22 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error

Error: (08/12/2016 05:49:55 PM) (Source: ATIeRecord) (EventID: 16387) (User: )
Description: ATI EEU Service event error

Error: (08/12/2016 03:57:49 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"1 se nezdařilo. Chyba v souboru manifestu nebo zásady UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"2 na řádku UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definice je UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (08/12/2016 03:57:15 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Služba Šifrování selhala při volání OnIdentity() v objektu System Writer.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Protokol Microsoft LLDP (Link-Layer Discovery Protocol).

System Error:
Přístup byl odepřen.
.

Error: (08/12/2016 03:56:50 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"1 se nezdařilo. Chyba v souboru manifestu nebo zásady UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"2 na řádku UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definice je UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (08/12/2016 07:16:48 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Generování kontextu aktivace pro UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"1 se nezdařilo. Chyba v souboru manifestu nebo zásady UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"2 na řádku UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0"3.
Identita komponenty nalezená v manifestu nesouhlasí s identitou požadované komponenty.
Odkaz je UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definice je UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Podrobnější diagnostické údaje získáte pomocí programu sxstrace.exe.

Error: (08/12/2016 07:16:42 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Název chybující aplikace: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp, verze: 51.1052.0.0, časové razítko: 0x57051f89
Název chybujícího modulu: isslideshow.dll_unloaded, verze: 1.0.2.0, časové razítko: 0x2a425e19
Kód výjimky: 0xc000041d
Posun chyby: 0x00023e38
ID chybujícího procesu: 0x173c
Čas spuštění chybující aplikace: 0xAslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp0
Cesta k chybující aplikaci: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp1
Cesta k chybujícímu modulu: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp2
ID zprávy: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp3
Úplný název chybujícího balíčku: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp4
ID aplikace související s chybujícím balíčkem: Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.tmp5


System errors:
=============
Error: (08/13/2016 07:54:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Přístup k uživatelským datům_4482e byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:54:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Úložiště uživatelských dat_4482e byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:54:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Data kontaktů_4482e byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:54:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_4482e byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:45:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Přístup k uživatelským datům_123f272 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:45:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Úložiště uživatelských dat_123f272 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:45:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Data kontaktů_123f272 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:45:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Hostitel synchronizace_123f272 byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 10000 milisekund: Restartovat službu.

Error: (08/13/2016 07:36:36 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: Správce služeb se pokusil o opravnou akci (Restartovat službu) po nečekaném ukončení služby Windows Search, ale tato akce selhala kvůli následující chybě:
%%1056 = Instance této služby je již spuštěna.

Error: (08/13/2016 07:36:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Služba Windows Search byla nečekaně ukončena. Stalo se to 1 krát. Následující opravná akce bude spuštěna za 30000 milisekund: Restartovat službu.


CodeIntegrity:
===================================
Date: 2016-08-13 19:55:05.417
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:55:05.411
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:55:05.404
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\Drivers\eelam\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:55:05.397
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\Drivers\eelam\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:45:57.467
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:45:57.460
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:45:57.454
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\Drivers\eelam\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-13 19:45:57.447
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\ESET\ESET Smart Security\Drivers\eelam\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-12 18:57:49.961
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2016-08-12 18:57:49.955
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\eelam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info ===========================

Processor: AMD A10-5800K APU with Radeon(tm) HD Graphics
Percentage of memory in use: 51%
Total physical RAM: 8136.32 MB
Available physical RAM: 3919.59 MB
Total Virtual: 9416.32 MB
Available Virtual: 3025.49 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:223.08 GB) (Free:112.57 GB) NTFS
Drive w: (G71-VAT1029) (CDROM) (Total:1.22 GB) (Free:0 GB) CDFS
Drive z: (Zaloha) (Fixed) (Total:1863.01 GB) (Free:497.74 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: F4D3C445)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223.1 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 77A3847A)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý PC, neustále vytěžuje Antimalware

#7 Příspěvek od Rudy »

Potřebuji vidět i log FRST. Toto je pouze Additional.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

stsam
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 14 lis 2006 15:48

Re: Pomalý PC, neustále vytěžuje Antimalware

#8 Příspěvek od stsam »

sorry

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-08-2016 01
Ran by stsam (administrator) on STSAM (13-08-2016 20:29:48)
Running from C:\Users\stsam\Desktop
Loaded Profiles: stsam (Available Profiles: stsam)
Platform: Windows 10 Pro Version 1511 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe
(Micro-Star Int'l Co., Ltd.) C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe
(Microsoft Corporation) C:\Windows\System32\Locator.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(MSI) C:\Windows\SysWOW64\muachost.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x86\MsiGamingOSD_x86.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Gaming APP\OSD\x64\MsiGamingOSD_x64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Common Files\logishrd\KHAL3\KHALMNPR.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
(Learsy) C:\Program Files (x86)\MuralPix\MpAgent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\Live Update.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Wargaming.net) C:\Games\World_of_Tanks\WorldOfTanks.exe
(forum.viry.cz) C:\Users\stsam\Desktop\FRSTLauncher.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8842496 2016-07-18] (Realtek Semiconductor)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [6638472 2016-07-08] (Advanced Micro Devices, Inc.)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [MuralPixAgent] => C:\Program Files (x86)\MuralPix\MpAgent.exe [102400 2006-12-30] (Learsy)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1314432 2016-03-11] (CANON INC.)
HKLM-x32\...\Run: [DriverPack Notifier] => C:\Program Files (x86)\DriverPack Notifier\DriverPackNotifier.exe [258560 2015-12-18] ()
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [11340752 2016-07-19] (Micro-Star INT'L CO., LTD.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [26424960 2016-06-29] (Skype Technologies S.A.)
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\Run: [VideoViewer] => C:\Program Files (x86)\VideoViewer\VideoViewer.exe [286720 2015-07-03] (AVTECH)
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\MountPoints2: {65edbeaf-03bb-11e6-bd67-806e6f6e6963} - "W:\DVDSetup.exe"

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.20.2
Tcpip\..\Interfaces\{de929600-8316-411b-8b4e-c174d279e6f3}: [DhcpNameServer] 192.168.20.2

Internet Explorer:
==================
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.cz/?gfe_rd=cr&ei=VicpVImlGYu ... gws_rd=ssl
SearchScopes: HKU\S-1-5-21-331433692-3961677159-1017512419-1001 -> {636E8C50-C2F5-4A1D-B55F-DE92B134CBC0} URL = hxxp://tv.seznam.cz/hledej?w={searchTerms}&sourceid=QuickSearch_12454
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-07-30] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-07-30] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-07-30] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2015-02-23] (CANON INC.)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-07-30] (Microsoft Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2015-02-23] (CANON INC.)
DPF: HKLM-x32 {53049A9A-1122-4673-B8D4-12F545AE3285} hxxp://192.168.2.167:88/AVC_AX_764.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-30] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-30] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-30] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-07-30] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2015-10-29] (CANON INC.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-07-30] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-07-30] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-04-26] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default\extensions\vb@yandex.ru.xpi [not found]
FF Extension: No Name - C:\Users\stsam\AppData\Roaming\Mozilla\Firefox\Profiles\rr5p9yq7.default\extensions\yasearch@yandex.ru.xpi [not found]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-04-22] [not signed]

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.cz/
CHR StartupUrls: Default -> "hxxp://www.google.cz/","hxxp://wiki.wargaming. ... AMX_50_120"
CHR Profile: C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Prezentace Google) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-04-16]
CHR Extension: (Dokumenty Google) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-04-16]
CHR Extension: (Disk Google) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-04-16]
CHR Extension: (Seznam Lištička - Email) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgjpfhpjcgdppjbgnpnjllokbmcdllig [2016-07-13]
CHR Extension: (Seznam Lištička - Slovník) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blmojkbhnkkphngknkmgccmlenfaelkd [2016-07-13]
CHR Extension: (YouTube) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-04-16]
CHR Extension: (Tabulky Google) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-04-16]
CHR Extension: (Dokumenty Google offline) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-18]
CHR Extension: (Sudoku) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\jknjmdhcdfnhedcghbjbklllbliheppm [2016-04-16]
CHR Extension: (Platby Internetového obchodu Chrome) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-16]
CHR Extension: (Seznam Lištička - Rychlá volba) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\olfeabkoenfaoljndfecamgilllcpiak [2016-08-12]
CHR Extension: (Gmail) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-16]
CHR Extension: (Chrome Media Router) - C:\Users\stsam\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-09]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-04] (Advanced Micro Devices, Inc.) [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2950856 2016-07-25] (Microsoft Corporation)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2780160 2016-08-03] (ESET)
R2 GamingApp_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingApp_Service.exe [39888 2016-05-19] (Micro-Star Int'l Co., Ltd.)
R2 GamingHotkey_Service; C:\Program Files (x86)\MSI\Gaming APP\GamingHotkey_Service.exe [2019792 2016-05-16] (Micro-Star INT'L CO., LTD.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
R2 MSI_ActiveX_Service; C:\Program Files (x86)\MSI\MSI OC Kit\ActiveX_Service\MSI_ActiveX_Service.exe [54200 2016-06-01] (Micro-Star INT'L CO., LTD.)
R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [2227152 2016-07-19] (Micro-Star INT'L CO., LTD.)
R2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2015-10-30] (HP Inc.) [File not signed]
S3 ose; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [200240 2016-07-23] (Microsoft Corporation) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2015-10-30] (HP Inc.) [File not signed]
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [336824 2010-11-30] (arvato digital services llc)
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [743616 2015-12-02] (@ByELDI) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2016-07-01] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [40720 2015-07-28] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [110096 2016-04-26] (Advanced Micro Devices)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [263296 2016-08-03] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15488 2016-08-03] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [197288 2016-08-03] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [153248 2016-08-03] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [208552 2016-08-03] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [61608 2016-08-03] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [84640 2016-08-03] (ESET)
S3 HWiNFO32; C:\Users\stsam\AppData\Local\Temp\HWiNFO64A.SYS [27552 2016-07-26] (REALiX(tm))
R3 I2cHkBurn; C:\Windows\system32\drivers\I2cHkBurn.sys [41760 2015-07-27] (FINTEK Corp.)
S3 MSICDSetup; W:\CDriver64.sys [28984 2009-08-12] (Your Corporation)
S3 NTIOLib_1_0_C; W:\NTIOLib_X64.sys [11888 2011-06-29] (MSI) [File not signed]
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [936192 2016-04-01] (Realtek )
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-13 20:29 - 2016-08-13 20:30 - 00017536 _____ C:\Users\stsam\Desktop\FRST.txt
2016-08-13 20:29 - 2016-08-13 20:29 - 00000000 ____D C:\FRST
2016-08-13 20:28 - 2016-08-13 20:28 - 02393600 _____ (Farbar) C:\Users\stsam\Desktop\FRST64.exe
2016-08-13 20:25 - 2016-08-13 20:25 - 00112640 _____ (forum.viry.cz) C:\Users\stsam\Downloads\FRSTLauncher.exe
2016-08-13 20:21 - 2016-08-13 20:21 - 00112640 _____ (forum.viry.cz) C:\Users\stsam\Downloads\FRSTLauncher (1).exe
2016-08-13 20:21 - 2016-08-13 20:21 - 00112640 _____ (forum.viry.cz) C:\Users\stsam\Desktop\FRSTLauncher.exe
2016-08-13 19:56 - 2016-08-13 19:56 - 00000000 ___HD C:\OneDriveTemp
2016-08-13 19:54 - 2016-08-13 19:54 - 00001112 _____ C:\Users\stsam\Desktop\VideoViewer.lnk
2016-08-13 19:54 - 2016-08-13 19:54 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VideoViewer
2016-08-13 19:53 - 2016-08-13 19:59 - 00000000 ____D C:\Program Files (x86)\VideoViewer
2016-08-13 19:33 - 2016-08-13 19:43 - 00000000 ____D C:\AdwCleaner
2016-08-13 19:30 - 2016-08-13 19:30 - 03784256 _____ C:\Users\stsam\Desktop\adwcleaner_6.000.exe
2016-08-13 07:34 - 2016-08-13 07:39 - 00000000 ____D C:\rsit
2016-08-13 07:34 - 2016-08-13 07:38 - 00000000 ____D C:\Program Files\trend micro
2016-08-13 07:33 - 2016-08-13 07:34 - 01222144 _____ C:\Users\stsam\Desktop\RSITx64.exe
2016-08-12 17:51 - 2016-08-12 17:51 - 00002032 _____ C:\Users\Public\Desktop\MSI Live Update 6.lnk
2016-08-12 17:51 - 2016-08-03 14:27 - 00000000 ____D C:\Windows\SysWOW64\LiveUpdate
2016-08-12 17:51 - 2016-07-19 19:27 - 00012669 _____ C:\Windows\SysWOW64\ReleaseNote.txt
2016-08-12 15:58 - 2016-08-12 15:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Kombustor 3
2016-08-12 15:57 - 2016-08-12 17:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2016-08-12 15:57 - 2016-08-12 15:58 - 00000000 ____D C:\Program Files\MSI Kombustor 3
2016-08-12 15:57 - 2016-08-12 15:57 - 00003132 _____ C:\Windows\System32\Tasks\MSIOSDx86_Host
2016-08-12 15:57 - 2016-08-12 15:57 - 00003132 _____ C:\Windows\System32\Tasks\MSIOSDx64_Host
2016-08-12 15:57 - 2016-08-12 15:57 - 00003058 _____ C:\Windows\System32\Tasks\MSISW_Host
2016-08-12 15:57 - 2016-08-12 15:57 - 00001194 _____ C:\Users\Public\Desktop\MSI Gaming APP.lnk
2016-08-12 15:57 - 2016-08-12 15:57 - 00000000 ____D C:\Intel
2016-08-12 15:57 - 2015-08-18 09:51 - 01692840 _____ (MSI) C:\Windows\SysWOW64\muachost.exe
2016-08-12 15:57 - 2015-07-27 01:37 - 00041760 _____ (FINTEK Corp.) C:\Windows\system32\Drivers\I2cHkBurn.sys
2016-08-12 15:57 - 2015-07-27 01:37 - 00031520 _____ (TODO: <公司名稱>) C:\Windows\system32\FintekIcon1.dll
2016-08-12 15:57 - 2014-04-30 16:23 - 00011248 _____ (Windows (R) Win 7 DDK provider) C:\Windows\acpimof.dll
2016-08-12 15:56 - 2016-08-13 19:54 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2016-08-12 15:56 - 2016-08-12 20:51 - 00000000 ____D C:\MSI
2016-08-12 15:56 - 2016-08-12 17:51 - 00000000 ____D C:\Program Files (x86)\MSI
2016-08-12 15:56 - 2016-08-12 15:56 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2016-08-12 15:56 - 2016-06-23 20:22 - 00264992 _____ C:\Windows\SysWOW64\vulkan-1.dll
2016-08-12 15:56 - 2016-06-23 20:21 - 00257824 _____ C:\Windows\system32\vulkan-1.dll
2016-08-12 15:56 - 2016-06-23 20:21 - 00110880 _____ C:\Windows\SysWOW64\vulkaninfo.exe
2016-08-12 15:56 - 2016-06-23 20:20 - 00125216 _____ C:\Windows\system32\vulkaninfo.exe
2016-08-12 15:55 - 2016-06-29 03:50 - 02129920 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\amfrt64.dll
2016-08-12 15:55 - 2016-06-29 03:50 - 01820160 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\amfrt32.dll
2016-08-12 15:55 - 2016-06-29 03:49 - 48797696 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2016-08-12 15:55 - 2016-06-29 03:49 - 00252928 _____ C:\Windows\system32\clinfo.exe
2016-08-12 15:55 - 2016-06-29 03:48 - 38248960 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2016-08-12 15:55 - 2016-06-29 03:47 - 00096256 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2016-08-12 15:55 - 2016-06-29 03:47 - 00087040 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2016-08-12 15:55 - 2016-06-29 03:46 - 27471872 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll
2016-08-12 15:55 - 2016-06-29 03:46 - 21623808 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll
2016-08-12 15:55 - 2016-06-29 03:26 - 00865792 _____ (AMD) C:\Windows\system32\coinst_16.30.dll
2016-08-12 15:55 - 2016-06-29 03:26 - 00728832 _____ C:\Windows\SysWOW64\atiapfxx.blb
2016-08-12 15:55 - 2016-06-29 03:26 - 00728832 _____ C:\Windows\system32\atiapfxx.blb
2016-08-12 15:55 - 2016-06-29 03:24 - 02359296 _____ C:\Windows\system32\amdoclvp9lib64.dll
2016-08-12 15:55 - 2016-06-29 03:24 - 02269184 _____ C:\Windows\SysWOW64\amdoclvp9lib32.dll
2016-08-12 15:55 - 2016-06-22 23:46 - 00117296 _____ C:\Windows\system32\kapp_ci.sbin
2016-08-12 15:55 - 2016-06-19 20:58 - 00112336 _____ C:\Windows\system32\kapp_si.sbin
2016-08-12 15:55 - 2016-06-17 20:50 - 00270912 _____ C:\Windows\system32\ativvaxy_stn_nd.dat
2016-08-12 15:55 - 2016-06-17 20:45 - 00368672 _____ C:\Windows\system32\ativvaxy_el_nd.dat
2016-08-12 15:55 - 2016-06-16 20:09 - 00260720 _____ C:\Windows\system32\ativvaxy_FJ_nd.dat
2016-08-12 15:55 - 2016-06-06 22:51 - 00260980 _____ C:\Windows\system32\ativvaxy_FJ.dat
2016-08-12 15:55 - 2016-06-06 22:47 - 00266816 _____ C:\Windows\system32\ativvaxy_cz_nd.dat
2016-08-12 15:55 - 2016-05-24 05:29 - 00016827 _____ C:\Windows\system32\AMDKernelEvents.man
2016-08-12 15:55 - 2016-05-17 23:05 - 00322736 _____ C:\Windows\system32\ativvaxy_vi_nd.dat
2016-08-12 15:55 - 2016-05-17 22:25 - 00234032 _____ C:\Windows\system32\ativvaxy_cik_nd.dat
2016-08-12 15:55 - 2016-04-21 16:45 - 00166624 _____ C:\Windows\system32\amde34b.dat
2016-08-12 15:55 - 2016-04-21 16:45 - 00166624 _____ C:\Windows\system32\amde34a.dat
2016-08-12 15:55 - 2016-04-21 16:44 - 00177280 _____ C:\Windows\system32\ativce03.dat
2016-08-12 15:55 - 2016-04-21 16:44 - 00175584 _____ C:\Windows\system32\amde31a.dat
2016-08-12 15:55 - 2016-04-21 16:41 - 00100816 _____ C:\Windows\system32\ativce02.dat
2016-08-12 15:55 - 2016-04-13 21:58 - 00234292 _____ C:\Windows\system32\ativvaxy_cik.dat
2016-08-12 15:55 - 2016-03-30 00:09 - 00322996 _____ C:\Windows\system32\ativvaxy_vi.dat
2016-08-12 15:55 - 2016-02-11 20:11 - 00149008 _____ C:\Windows\system32\samu_krnl_ci.sbin
2016-08-12 15:55 - 2015-11-30 16:54 - 00066560 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmcl64.dll
2016-08-12 15:55 - 2015-11-30 16:54 - 00050176 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmcl32.dll
2016-08-12 15:52 - 2016-08-12 15:56 - 00000000 ____D C:\Windows\LastGood.Tmp
2016-08-11 20:56 - 2016-08-11 20:59 - 67195169 _____ (Aslain ) C:\Users\stsam\Desktop\Aslains_WoT_Modpack_Installer_v.9.15.1.1.00.exe
2016-08-10 18:55 - 2016-08-03 13:14 - 01505984 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-08-10 18:55 - 2016-08-03 13:14 - 00092352 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-08-10 18:55 - 2016-08-03 13:14 - 00050368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-08-10 18:55 - 2016-08-03 12:36 - 07469408 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-08-10 18:55 - 2016-08-03 12:36 - 00099680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2016-08-10 18:55 - 2016-08-03 12:36 - 00037744 _____ (Microsoft Corporation) C:\Windows\system32\wldp.dll
2016-08-10 18:55 - 2016-08-03 12:30 - 00026408 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2016-08-10 18:55 - 2016-08-03 12:23 - 00693600 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupEngine.dll
2016-08-10 18:55 - 2016-08-03 12:23 - 00115040 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupApi.dll
2016-08-10 18:55 - 2016-08-03 12:22 - 00808288 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2016-08-10 18:55 - 2016-08-03 12:22 - 00465248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2016-08-10 18:55 - 2016-08-03 12:22 - 00331616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2016-08-10 18:55 - 2016-08-03 12:21 - 03675512 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-08-10 18:55 - 2016-08-03 12:21 - 00566112 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2016-08-10 18:55 - 2016-08-03 12:21 - 00303216 _____ (Microsoft Corporation) C:\Windows\system32\LockAppHost.exe
2016-08-10 18:55 - 2016-08-03 12:20 - 01540224 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2016-08-10 18:55 - 2016-08-03 12:20 - 00692136 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll
2016-08-10 18:55 - 2016-08-03 12:19 - 00604928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2016-08-10 18:55 - 2016-08-03 12:19 - 00161632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-08-10 18:55 - 2016-08-03 12:13 - 01988448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2016-08-10 18:55 - 2016-08-03 12:13 - 00576864 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2016-08-10 18:55 - 2016-08-03 12:13 - 00393056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2016-08-10 18:55 - 2016-08-03 11:51 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\tdlrecover.exe
2016-08-10 18:55 - 2016-08-03 11:51 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2016-08-10 18:55 - 2016-08-03 11:44 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2016-08-10 18:55 - 2016-08-03 11:44 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\wshbth.dll
2016-08-10 18:55 - 2016-08-03 11:44 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll
2016-08-10 18:55 - 2016-08-03 11:43 - 16985088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2016-08-10 18:55 - 2016-08-03 11:41 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll
2016-08-10 18:55 - 2016-08-03 11:41 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker.dll
2016-08-10 18:55 - 2016-08-03 11:40 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\VEDataLayerHelpers.dll
2016-08-10 18:55 - 2016-08-03 11:40 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2016-08-10 18:55 - 2016-08-03 11:40 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\TpmTasks.dll
2016-08-10 18:55 - 2016-08-03 11:39 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2016-08-10 18:55 - 2016-08-03 11:39 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\BluetoothApis.dll
2016-08-10 18:55 - 2016-08-03 11:38 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2016-08-10 18:55 - 2016-08-03 11:37 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\IdCtrls.dll
2016-08-10 18:55 - 2016-08-03 11:36 - 00211456 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupSvc.dll
2016-08-10 18:55 - 2016-08-03 11:36 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-08-10 18:55 - 2016-08-03 11:35 - 00200192 _____ (Microsoft Corporation) C:\Windows\system32\WUDFPlatform.dll
2016-08-10 18:55 - 2016-08-03 11:33 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\VEEventDispatcher.dll
2016-08-10 18:55 - 2016-08-03 11:31 - 00506880 _____ (Microsoft Corporation) C:\Windows\system32\tileobjserver.dll
2016-08-10 18:55 - 2016-08-03 11:31 - 00247296 _____ (Microsoft Corporation) C:\Windows\system32\wevtutil.exe
2016-08-10 18:55 - 2016-08-03 11:30 - 00515072 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2016-08-10 18:55 - 2016-08-03 11:29 - 14252544 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-08-10 18:55 - 2016-08-03 11:29 - 02127360 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-08-10 18:55 - 2016-08-03 11:29 - 01500160 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2016-08-10 18:55 - 2016-08-03 11:29 - 01387520 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2016-08-10 18:55 - 2016-08-03 11:29 - 00784384 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-08-10 18:55 - 2016-08-03 11:28 - 01213440 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2016-08-10 18:55 - 2016-08-03 11:28 - 00848896 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2016-08-10 18:55 - 2016-08-03 11:27 - 07536640 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2016-08-10 18:55 - 2016-08-03 11:27 - 01717760 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2016-08-10 18:55 - 2016-08-03 11:18 - 06974464 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2016-08-10 18:55 - 2016-08-03 11:18 - 02067968 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2016-08-10 18:55 - 2016-08-03 11:18 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-08-10 18:55 - 2016-08-03 11:17 - 02175488 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2016-08-10 18:55 - 2016-08-03 11:16 - 05123072 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll
2016-08-10 18:55 - 2016-08-03 11:16 - 03589120 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2016-08-10 18:55 - 2016-08-03 11:16 - 02635776 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2016-08-10 18:55 - 2016-08-03 11:16 - 01732096 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-08-10 18:55 - 2016-08-03 11:14 - 04895232 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-08-10 18:55 - 2016-08-03 11:14 - 01997824 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2016-08-10 18:55 - 2016-08-03 11:13 - 03025920 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-08-10 18:55 - 2016-08-03 11:13 - 02280960 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2016-08-10 18:55 - 2016-08-03 11:12 - 02746368 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll
2016-08-10 18:55 - 2016-08-03 11:11 - 04171264 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2016-08-10 18:55 - 2016-08-03 07:52 - 00034088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wldp.dll
2016-08-10 18:55 - 2016-08-03 07:34 - 00501592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupEngine.dll
2016-08-10 18:55 - 2016-08-03 07:34 - 00084832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupApi.dll
2016-08-10 18:55 - 2016-08-03 07:33 - 00051128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsNativeApi.dll
2016-08-10 18:55 - 2016-08-03 07:31 - 02921368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-08-10 18:55 - 2016-08-03 07:31 - 00957608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2016-08-10 18:55 - 2016-08-03 07:31 - 00703840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2016-08-10 18:55 - 2016-08-03 07:30 - 21123320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-08-10 18:55 - 2016-08-03 07:30 - 00465760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2016-08-10 18:55 - 2016-08-03 07:30 - 00255168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppHost.exe
2016-08-10 18:55 - 2016-08-03 06:57 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdlrecover.exe
2016-08-10 18:55 - 2016-08-03 06:48 - 00051712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshbth.dll
2016-08-10 18:55 - 2016-08-03 06:47 - 13018112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2016-08-10 18:55 - 2016-08-03 06:44 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll
2016-08-10 18:55 - 2016-08-03 06:44 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryBroker.dll
2016-08-10 18:55 - 2016-08-03 06:42 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BluetoothApis.dll
2016-08-10 18:55 - 2016-08-03 06:40 - 00092160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IdCtrls.dll
2016-08-10 18:55 - 2016-08-03 06:39 - 19351040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-08-10 18:55 - 2016-08-03 06:37 - 00219136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEEventDispatcher.dll
2016-08-10 18:55 - 2016-08-03 06:35 - 00178688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wevtutil.exe
2016-08-10 18:55 - 2016-08-03 06:34 - 00792064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-08-10 18:55 - 2016-08-03 06:34 - 00400896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll
2016-08-10 18:55 - 2016-08-03 06:33 - 18677760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2016-08-10 18:55 - 2016-08-03 06:33 - 02050048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-08-10 18:55 - 2016-08-03 06:33 - 00687616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-08-10 18:55 - 2016-08-03 06:32 - 12585984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-08-10 18:55 - 2016-08-03 06:32 - 01467392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2016-08-10 18:55 - 2016-08-03 06:32 - 00434688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2016-08-10 18:55 - 2016-08-03 06:31 - 06743040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2016-08-10 18:55 - 2016-08-03 06:31 - 00705536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2016-08-10 18:55 - 2016-08-03 06:29 - 12133376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-08-10 18:55 - 2016-08-03 06:28 - 03663360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-08-10 18:55 - 2016-08-03 06:25 - 05323776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2016-08-10 18:55 - 2016-08-03 06:25 - 04078080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll
2016-08-10 18:55 - 2016-08-03 06:23 - 05660672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2016-08-10 18:55 - 2016-08-03 06:23 - 01799680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2016-08-10 18:55 - 2016-08-03 06:22 - 02501120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-08-10 18:55 - 2016-08-03 06:22 - 01502208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-08-10 18:55 - 2016-08-03 06:21 - 01708032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActiveSyncProvider.dll
2016-08-10 18:55 - 2016-08-03 06:19 - 02180096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll
2016-08-10 18:54 - 2016-08-03 12:22 - 01322760 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2016-08-10 18:54 - 2016-08-03 12:22 - 00058408 _____ (Microsoft Corporation) C:\Windows\system32\SensorsNativeApi.dll
2016-08-10 18:54 - 2016-08-03 12:21 - 22561256 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-08-10 18:54 - 2016-08-03 12:11 - 00422744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2016-08-10 18:54 - 2016-08-03 11:46 - 22384128 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2016-08-10 18:54 - 2016-08-03 11:40 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\bthserv.dll
2016-08-10 18:54 - 2016-08-03 11:38 - 00412160 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2016-08-10 18:54 - 2016-08-03 11:36 - 00221696 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-08-10 18:54 - 2016-08-03 11:35 - 00764928 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2016-08-10 18:54 - 2016-08-03 11:34 - 00383488 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-08-10 18:54 - 2016-08-03 11:33 - 00339968 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2016-08-10 18:54 - 2016-08-03 11:31 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2016-08-10 18:54 - 2016-08-03 11:30 - 24613888 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-08-10 18:54 - 2016-08-03 11:30 - 00970752 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-08-10 18:54 - 2016-08-03 11:28 - 00529920 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2016-08-10 18:54 - 2016-08-03 11:27 - 01752576 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-08-10 18:54 - 2016-08-03 11:27 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2016-08-10 18:54 - 2016-08-03 11:20 - 13390336 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-08-10 18:54 - 2016-08-03 11:15 - 07833088 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2016-08-10 18:54 - 2016-08-03 06:37 - 00335872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-08-10 18:54 - 2016-08-03 06:35 - 00286208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2016-08-10 18:54 - 2016-08-03 06:32 - 01526272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-08-09 22:13 - 2016-08-09 22:13 - 00003448 _____ C:\Windows\System32\Tasks\{F85AB10B-D146-4EC6-904C-8CC654092F00}
2016-08-06 17:19 - 2016-08-06 17:19 - 00226252 _____ C:\Windows\Minidump\080616-8812-01.dmp
2016-08-01 08:34 - 2016-08-01 08:34 - 00000000 ___HD C:\ProgramData\CanonIJScan
2016-07-30 12:41 - 2016-07-30 12:41 - 00190116 _____ C:\Windows\Minidump\073016-9343-01.dmp
2016-07-29 14:55 - 2016-07-29 14:56 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Mozilla
2016-07-29 14:55 - 2016-07-29 14:55 - 00000000 ____D C:\Users\stsam\AppData\Local\Mozilla
2016-07-29 14:26 - 2016-07-29 14:26 - 00000000 ____D C:\ProgramData\ATI
2016-07-29 14:23 - 2016-07-29 14:23 - 00000000 ____D C:\Users\stsam\AppData\Roaming\library_dir
2016-07-29 14:23 - 2016-07-29 14:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2016-07-29 14:23 - 2016-07-29 14:23 - 00000000 ____D C:\Program Files (x86)\Raptr Inc
2016-07-29 14:11 - 2016-07-29 14:11 - 00000000 ____D C:\Users\stsam\AppData\Roaming\DRPNPS
2016-07-29 14:08 - 2014-09-10 18:14 - 00163480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 01070232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomctl.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00660120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomct2.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00617896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00444328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MShflxgd.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00416408 _____ (Microsoft Corporation ) C:\Windows\SysWOW64\comct332.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00279192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatgrd.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00259736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msflxgrd.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00253080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdatlst.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00222360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tabctl32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00219288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\richtx32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00218776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00212112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mci32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00179352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmask32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00170920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comct232.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00131728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinet.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00130712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msstdfmt.dll
2016-07-29 14:08 - 2013-11-25 15:27 - 00127640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswinsck.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00119960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscomm32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00108696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTKPRP.DLL
2016-07-29 14:08 - 2013-11-25 15:27 - 00104088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\picclp32.ocx
2016-07-29 14:08 - 2013-11-25 15:27 - 00084624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysinfo.ocx
2016-07-29 14:08 - 2011-01-12 21:36 - 01054208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71u.dll
2016-07-29 14:08 - 2011-01-12 21:25 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71DEU.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71ITA.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71FRA.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71ESP.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71ENU.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71KOR.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71JPN.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71CHT.DLL
2016-07-29 14:08 - 2011-01-12 21:25 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFC71CHS.DLL
2016-07-29 14:08 - 2011-01-12 20:53 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl71.dll
2016-07-29 14:08 - 2008-04-15 14:00 - 01355776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvbvm50.dll
2016-07-29 14:08 - 2007-01-30 18:04 - 00339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr70.dll
2016-07-29 14:08 - 2006-08-25 22:28 - 01017344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70u.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70ita.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70fra.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70esp.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70deu.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00057344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70enu.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70kor.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00049152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70jpn.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70cht.dll
2016-07-29 14:08 - 2006-08-25 22:15 - 00040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70chs.dll
2016-07-29 14:08 - 2006-08-25 22:07 - 01024000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfc70.dll
2016-07-29 14:08 - 2006-08-25 21:17 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\atl70.dll
2016-07-29 14:08 - 2006-04-10 22:41 - 01066176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSCOMCTL32.OCX
2016-07-29 14:08 - 2005-01-20 17:25 - 00054784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvci70.dll
2016-07-29 14:08 - 2002-01-05 03:40 - 00487424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVCP70.DLL
2016-07-29 14:08 - 1996-01-12 02:00 - 00935632 _____ (Microsoft Corporation) C:\Windows\system\Vb40016.dll
2016-07-29 14:08 - 1996-01-12 02:00 - 00722192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Vb40032.dll
2016-07-29 14:08 - 1994-11-17 23:00 - 00210944 _____ C:\Windows\SysWOW64\msvcrt10.dll
2016-07-29 14:08 - 1993-05-11 19:00 - 00398416 _____ (Microsoft Corporation) C:\Windows\system\Vbrun300.dll
2016-07-29 14:08 - 1992-10-21 00:00 - 00356992 _____ (Microsoft Corporation) C:\Windows\system\vbrun200.dll
2016-07-29 14:08 - 1991-05-10 01:00 - 00271264 _____ C:\Windows\system\vbrun100.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 72520720 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat
2016-07-29 14:07 - 2016-07-18 11:56 - 24404664 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRenderAVX64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 24314816 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRender64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 17370496 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioCapture64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 15202040 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 14057256 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 13122584 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO3064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 12988352 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO4064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 10512456 _____ (Intel Corporation) C:\Windows\system32\IntelSSTAPO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 07172920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 07096192 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 06566325 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2016-07-29 14:07 - 2016-07-18 11:56 - 06358552 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV3apo.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 06264640 _____ (Dolby Laboratories) C:\Windows\system32\DDPP64AF3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 05793528 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 05593624 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 05339560 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 03299832 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE2.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 03282544 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 03199744 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02895104 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2016-07-29 14:07 - 2016-07-18 11:56 - 02825112 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO7064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02732600 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RltkAPO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02706872 _____ (DTS, Inc.) C:\Windows\system32\sltech64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02437760 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02203752 _____ (DTS, Inc.) C:\Windows\system32\slcnt64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02190992 _____ (Yamaha Corporation) C:\Windows\system32\YamahaAE.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02110592 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02071296 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 02050176 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01965816 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01959608 _____ (Dolby Laboratories) C:\Windows\system32\DDPD64AF3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01780624 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01608128 _____ (Conexant Systems Inc.) C:\Windows\system32\CX64APO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01591064 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01508936 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01435152 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01422936 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO6064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01382240 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01360528 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01336624 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tossaeapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01334384 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01213664 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01186824 _____ (Intel Corporation) C:\Windows\system32\IntelSstCApoPropPage.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01166168 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01061120 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01041744 _____ (DTS, Inc.) C:\Windows\system32\sl3apo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 01003864 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00999864 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO2064.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00965032 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00962136 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tosasfapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00931624 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00927424 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00923752 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00873472 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00743968 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00727440 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00716112 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00708320 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00689888 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00678192 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00677672 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00618192 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00589080 _____ (Sound Research, Corp.) C:\Windows\SysWOW64\SECOMN32.DLL
2016-07-29 14:07 - 2016-07-18 11:56 - 00582096 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\tossaemaxapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00574760 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00570096 _____ (Intel Corporation) C:\Windows\system32\tbb_waves.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00532384 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00514528 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00504312 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00500560 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00472312 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00467168 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00450128 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00447728 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00447184 _____ (Toshiba Client Solutions Co., Ltd.) C:\Windows\system32\toseaeapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00445408 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00441272 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00437168 _____ (Conexant Systems, Inc.) C:\Windows\system32\CAF64APO2.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00428232 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00416512 _____ (Harman) C:\Windows\system32\HMUI.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00387320 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00381416 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00371456 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00366128 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\HMAPO.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00362064 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64AF3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00360352 _____ (Harman) C:\Windows\system32\HMClariFi.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00343712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00341152 _____ (Synopsys, Inc.) C:\Windows\SysWOW64\SRCOM.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00341152 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00330568 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00327456 _____ (Dolby Laboratories) C:\Windows\system32\DDPO64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00310424 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64F3.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00272720 _____ (Dolby Laboratories) C:\Windows\system32\DDPA64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00258864 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00253904 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00253872 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00252880 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00231920 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00221976 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00214840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00209536 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00203848 _____ (Harman) C:\Windows\system32\HMHVS.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00190944 _____ (Harman) C:\Windows\system32\HMEQ_Voice.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00190944 _____ (Harman) C:\Windows\system32\HMEQ.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00179600 _____ (Harman) C:\Windows\system32\HMLimiter.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00166208 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00158704 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00154368 _____ (Harman) C:\Windows\system32\HarmanAudioInterface.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00151792 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00134208 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00122328 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00118600 _____ C:\Windows\system32\AcpiServiceVnA64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00118600 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00112504 _____ (Conexant Systems, Inc.) C:\Windows\system32\Caf64api.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00110992 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00105312 _____ C:\Windows\system32\audioLibVc.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00090920 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00088352 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00088328 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00084624 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00083632 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00075544 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll
2016-07-29 14:07 - 2016-07-18 11:56 - 00005604 _____ C:\Windows\system32\cxapo.lncs
2016-07-29 14:07 - 2016-07-18 11:56 - 00000736 _____ C:\Windows\system32\cxapo.prop
2016-07-29 14:06 - 2016-08-05 09:03 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Opera Software
2016-07-29 14:06 - 2016-08-05 09:03 - 00000000 ____D C:\Users\stsam\AppData\Local\Opera Software
2016-07-29 14:06 - 2016-08-05 09:03 - 00000000 ____D C:\Program Files (x86)\Opera
2016-07-29 14:06 - 2016-07-29 14:08 - 00000000 ____D C:\Users\stsam\AppData\Roaming\DRPSu
2016-07-29 14:06 - 2016-07-29 14:07 - 00000000 ____D C:\Users\stsam\AppData\Roaming\DriverPack Notifier
2016-07-29 14:06 - 2016-07-29 14:06 - 00003526 _____ C:\Windows\System32\Tasks\DriverPack Notifier
2016-07-29 14:06 - 2016-07-29 14:06 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-07-29 14:06 - 2016-07-29 14:06 - 00000000 ____D C:\Program Files (x86)\WinRAR
2016-07-29 14:06 - 2016-07-29 14:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-07-29 14:06 - 2016-07-29 14:06 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-07-29 14:06 - 2016-07-29 14:06 - 00000000 ____D C:\Program Files (x86)\DriverPack Notifier
2016-07-29 08:25 - 2016-08-11 19:27 - 00000810 _____ C:\Users\Public\Desktop\World of Tanks.lnk
2016-07-29 08:25 - 2016-08-11 19:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World of Tanks
2016-07-29 07:43 - 2016-07-29 07:43 - 00177140 _____ C:\Windows\Minidump\072916-6984-01.dmp
2016-07-27 20:53 - 2016-07-27 20:53 - 00120180 _____ C:\Windows\Minidump\072716-6609-01.dmp
2016-07-27 20:44 - 2016-07-27 20:44 - 00007625 _____ C:\Users\stsam\AppData\Local\Resmon.ResmonCfg
2016-07-27 17:55 - 2016-07-27 17:55 - 00125508 _____ C:\Windows\Minidump\072716-6875-01.dmp
2016-07-27 17:47 - 2016-08-06 17:19 - 869743340 _____ C:\Windows\MEMORY.DMP
2016-07-27 17:47 - 2016-07-27 17:47 - 00121684 _____ C:\Windows\Minidump\072716-7578-01.dmp
2016-07-27 12:39 - 2016-07-29 14:22 - 00000000 ____D C:\Program Files (x86)\AMD
2016-07-27 12:39 - 2016-07-27 12:39 - 00004296 _____ C:\Windows\System32\Tasks\AMD Updater
2016-07-27 12:39 - 2016-07-27 12:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Radeon Settings
2016-07-27 12:39 - 2016-07-27 12:39 - 00000000 _____ C:\Windows\ativpsrm.bin
2016-07-27 12:19 - 2016-07-27 12:19 - 00001335 _____ C:\Users\stsam\Desktop\FurMark.lnk
2016-07-27 12:19 - 2016-07-27 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Geeks3D
2016-07-27 12:19 - 2016-07-27 12:19 - 00000000 ____D C:\Program Files (x86)\Geeks3D
2016-07-27 12:18 - 2016-07-27 12:18 - 00000000 ____D C:\Users\stsam\AppData\Roaming\AMD
2016-07-26 08:43 - 2016-07-26 08:43 - 00000000 ____D C:\Users\stsam\Desktop\HWiNFO64
2016-07-21 15:51 - 2016-07-21 15:51 - 00105857 _____ C:\Users\stsam\Desktop\ticket-BGHEHD.pdf
2016-07-21 15:51 - 2016-07-21 15:51 - 00105419 _____ C:\Users\stsam\Desktop\ticket-L56BD5.pdf
2016-07-15 22:20 - 2016-07-15 22:20 - 00000000 ____D C:\Font

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-13 20:16 - 2016-04-16 13:01 - 00000972 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-13 19:59 - 2016-04-16 12:18 - 01771468 _____ C:\Windows\system32\PerfStringBackup.INI
2016-08-13 19:59 - 2016-02-13 14:50 - 00750030 _____ C:\Windows\system32\perfh005.dat
2016-08-13 19:59 - 2016-02-13 14:50 - 00150654 _____ C:\Windows\system32\perfc005.dat
2016-08-13 19:59 - 2015-10-30 09:21 - 00000000 ____D C:\Windows\INF
2016-08-13 19:56 - 2016-04-17 12:13 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Skype
2016-08-13 19:56 - 2016-04-16 12:16 - 00000000 ___RD C:\Users\stsam\OneDrive
2016-08-13 19:55 - 2016-04-16 13:01 - 00000968 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-13 19:55 - 2016-02-13 15:10 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-08-13 19:54 - 2016-04-18 19:20 - 00001136 _____ C:\Users\stsam\AppData\Roaming\Microsoft\Windows\Start Menu\VideoViewer.lnk
2016-08-13 19:54 - 2015-10-30 08:28 - 00524288 ___SH C:\Windows\system32\config\BBI
2016-08-13 19:53 - 2016-04-18 22:36 - 00000000 ____D C:\Users\stsam\Desktop\avech kamera
2016-08-13 19:53 - 2016-04-18 19:19 - 00017408 _____ (Microsoft Corporation) C:\psapi.dll
2016-08-13 19:33 - 2016-06-27 18:51 - 00004190 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C2495B7A-D459-4449-A5F1-2B2CA37527E2}
2016-08-13 08:01 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\AppReadiness
2016-08-13 07:00 - 2015-10-30 09:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-08-12 15:57 - 2016-04-16 12:27 - 00000000 ____D C:\ProgramData\Package Cache
2016-08-12 15:56 - 2016-04-16 12:26 - 00000000 ____D C:\Program Files\AMD
2016-08-12 15:52 - 2016-04-16 18:26 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2016-08-12 07:10 - 2016-05-01 18:40 - 00000000 ___RD C:\Users\stsam\Documents\Scanned Documents
2016-08-12 07:02 - 2016-06-14 08:19 - 00000000 ____D C:\ProgramData\CanonIJPLM
2016-08-11 19:07 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\rescache
2016-08-11 07:22 - 2016-02-13 15:14 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-08-10 22:32 - 2016-02-13 15:01 - 00000000 ____D C:\Program Files\Windows Journal
2016-08-10 22:32 - 2015-10-30 09:24 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2016-08-10 22:32 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\system32\appraiser
2016-08-10 21:04 - 2016-04-16 12:31 - 00000000 ____D C:\Windows\system32\MRT
2016-08-10 21:04 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\system32\SecureBootUpdates
2016-08-10 21:04 - 2015-10-30 09:11 - 00000000 ____D C:\Windows\CbsTemp
2016-08-10 21:00 - 2016-04-16 12:31 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-08-10 07:50 - 2016-04-18 17:50 - 00000000 ____D C:\Users\stsam\Documents\FinePrint
2016-08-09 22:16 - 2016-04-21 21:39 - 00000000 ____D C:\Users\stsam\AppData\Local\ElevatedDiagnostics
2016-08-09 15:38 - 2016-04-16 12:15 - 00000000 ____D C:\Users\stsam
2016-08-09 11:54 - 2016-04-16 13:04 - 00002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-06 17:19 - 2016-06-29 16:12 - 00000000 ____D C:\Windows\Minidump
2016-08-05 12:46 - 2016-04-18 22:36 - 03524096 ___SH C:\Users\stsam\Desktop\Thumbs.db
2016-08-05 11:02 - 2016-04-16 12:26 - 00000000 ____D C:\AMD
2016-08-05 09:06 - 2016-07-13 10:24 - 00000000 ____D C:\Program Files (x86)\DVDFab 9
2016-08-05 07:47 - 2016-05-17 06:43 - 00000000 ____D C:\Users\stsam\AppData\Roaming\vlc
2016-08-04 14:31 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\system32\NDF
2016-08-03 10:24 - 2016-02-09 08:27 - 00263296 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00208552 _____ (ESET) C:\Windows\system32\Drivers\epfw.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00197288 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00153248 _____ (ESET) C:\Windows\system32\Drivers\ekbdflt.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00084640 _____ (ESET) C:\Windows\system32\Drivers\epfwwfp.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00061608 _____ (ESET) C:\Windows\system32\Drivers\epfwlwf.sys
2016-08-03 10:24 - 2016-02-09 08:27 - 00015488 _____ (ESET) C:\Windows\system32\Drivers\eelam.sys
2016-08-03 08:39 - 2016-05-08 06:53 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-08-01 13:04 - 2016-05-01 18:52 - 00000000 ____D C:\Users\stsam\Documents\Recepty
2016-08-01 10:23 - 2016-05-02 17:57 - 00000000 ____D C:\Users\stsam\AppData\Local\AutoPlan
2016-08-01 10:23 - 2016-05-01 18:49 - 00000000 ____D C:\Users\stsam\Documents\AutoPlan
2016-07-30 12:42 - 2015-10-30 09:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-07-30 12:41 - 2016-04-16 16:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2016-07-29 14:22 - 2016-04-16 12:27 - 00000000 ____D C:\ProgramData\AMD
2016-07-29 14:08 - 2015-10-30 09:24 - 00000000 ____D C:\Windows\System
2016-07-29 14:07 - 2016-04-16 18:27 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2016-07-29 14:07 - 2016-04-16 18:27 - 00000000 ____D C:\Windows\system32\DAX2
2016-07-29 14:06 - 2016-04-16 17:45 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-07-29 14:06 - 2016-04-16 17:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-07-29 09:11 - 2016-04-16 13:01 - 00004030 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-07-29 09:11 - 2016-04-16 13:01 - 00003798 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-07-29 08:25 - 2016-04-16 14:08 - 00000000 ____D C:\Windows\SysWOW64\directx
2016-07-29 08:25 - 2016-04-16 13:09 - 00000000 ____D C:\Games
2016-07-27 21:25 - 2016-04-16 12:33 - 00504488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2016-07-27 12:39 - 2016-04-16 12:53 - 00000000 ____D C:\Users\stsam\AppData\Local\AMD
2016-07-19 11:38 - 2016-06-19 21:10 - 00000000 ____D C:\Users\stsam\Desktop\Jana-Foto
2016-07-18 11:56 - 2016-04-16 18:26 - 05193736 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2016-07-18 11:56 - 2016-04-16 18:26 - 03283248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2016-07-18 11:56 - 2016-04-16 18:26 - 03090544 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2016-07-18 11:56 - 2016-04-16 18:26 - 00192992 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2016-07-18 11:56 - 2016-04-16 18:26 - 00023704 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2016-07-18 09:40 - 2016-05-06 06:29 - 00004562 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-07-15 09:05 - 2016-04-17 12:13 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-07-15 09:05 - 2016-04-17 12:13 - 00000000 ____D C:\ProgramData\Skype
2016-07-14 14:45 - 2016-07-13 10:32 - 00000000 ____D C:\Users\stsam\AppData\Roaming\Seznam.cz
2016-07-14 14:44 - 2016-07-13 10:33 - 00000000 ____D C:\Program Files (x86)\Seznam.cz

==================== Files in the root of some directories =======

2016-07-27 20:44 - 2016-07-27 20:44 - 0007625 _____ () C:\Users\stsam\AppData\Local\Resmon.ResmonCfg
2016-04-16 18:27 - 2016-04-16 18:27 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:
====================
C:\Users\stsam\AppData\Local\Temp\libeay32.dll
C:\Users\stsam\AppData\Local\Temp\msvcm80.dll
C:\Users\stsam\AppData\Local\Temp\msvcp80.dll
C:\Users\stsam\AppData\Local\Temp\msvcr120.dll
C:\Users\stsam\AppData\Local\Temp\msvcr80.dll
C:\Users\stsam\AppData\Local\Temp\playstv_patch.exe
C:\Users\stsam\AppData\Local\Temp\raptrpatch.exe
C:\Users\stsam\AppData\Local\Temp\raptr_stub.exe
C:\Users\stsam\AppData\Local\Temp\sqlite3.dll
C:\Users\stsam\AppData\Local\Temp\vlc-2.2.4-win32.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-08-07 20:15

==================== End of FRST.txt ============================



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================

Drive c: () (Fixed) (Total:223.08 GB) (Free:112.57 GB) NTFS
Drive w: (G71-VAT1029) (CDROM) (Total:1.22 GB) (Free:0 GB) CDFS
Drive z: (Zaloha) (Fixed) (Total:1863.01 GB) (Free:497.74 GB) NTFS

Available physical RAM: 3919.59 MB
Total physical RAM: 8136.32 MB
Percentage of memory in use: 51%

==================== MBR and Partition Table ==================

Light Image Resizer 4.7.7.0 (HKLM-x32\...\{EBE030DD-D404-4D92-85E9-8C3624820808}_is1) (Version: 4.7.7.0 - ObviousIdea)
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: F4D3C445)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=223.1 GB) - (Type=07 NTFS)
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 77A3847A)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Alternate Data Streams (whitelisted) ==================

AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]

==================== Security Center ==================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: ESET Smart Security 9.0.395.2 (Disabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personální firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\stsam\Desktop" je 1773 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000001


==================== End Of Log ==============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý PC, neustále vytěžuje Antimalware

#9 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
HKU\S-1-5-21-331433692-3961677159-1017512419-1001\...\MountPoints2: {65edbeaf-03bb-11e6-bd67-806e6f6e6963} - "W:\DVDSetup.exe"
CHR StartupUrls: Default -> "hxxp://www.google.cz/","hxxp://wiki.wargaming. ... AMX_50_120"
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
C:\ProgramData\DP45977C.lfl
C:\Users\stsam\AppData\Local\Temp
AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - 9A.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\2015 - tri.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_01.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
AlternateDataStreams: C:\Users\stsam\Documents\PR_02.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.

Z logu:
Velikost slozky "C:\Users\stsam\Desktop" je 1773 MB.
To je příliš mnoho a může to zpomalovat start systému. Vytvořte v C:\Users\stsam novou složku, do níž přesuňte všechna data z plochy (kromě zástupců). Na plochu si pak pro snazší přístup dejte zástupce té složky.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

stsam
Návštěvník
Návštěvník
Příspěvky: 43
Registrován: 14 lis 2006 15:48

Re: Pomalý PC, neustále vytěžuje Antimalware

#10 Příspěvek od stsam »

Díky, zdá se že je problém vyřešen, každopádně je výrazně svižnější, ještě jednou moc děkuju.

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119673
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pomalý PC, neustále vytěžuje Antimalware

#11 Příspěvek od Rudy »

To jsem rád a nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno