
Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz
Antivir našel vir a nejde smazat
Moderátor: Moderátoři
Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]
Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.
!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Antivir našel vir a nejde smazat
Dobrý den, ahoj,
prosím o kontrolu logu...
Logfile of random's system information tool 1.10 (written by random/random)
Run by Karlos at 2016-10-22 18:32:02
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 93 GB (10%) free of 954 GB
Total RAM: 8139 MB (76% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:32:04, on 22.10.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18500)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\ProgramData\Boxtools\Toolbox.exe
C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe
C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe
C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Karlos.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [G3 mouse] "C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [rldqxyulfl] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\Run: [Boxoft Tools] "C:\ProgramData\Boxtools\Boxofttoolbox.exe" -autorun
O4 - HKCU\..\Run: [2320633bbd5b9c41d628d6d2b760a34d] "C:\Users\Karlos\AppData\Local\Temp\System32.exe" ..
O4 - HKCU\..\Run: [uqgfhuutfn] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs"
O4 - HKCU\..\Run: [ctbvysgbgs] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs"
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Startup: 2320633bbd5b9c41d628d6d2b760a34d.exe
O4 - Startup: ctbvysgbgs.vbs
O4 - Startup: KDPSIZWDgUiV.lnk = ?
O4 - Startup: NRNQBIhVHKhM.lnk = ?
O4 - Startup: rldqxyulfl.vbs
O4 - Startup: SLIN.exe
O4 - Startup: uqgfhuutfn.vbs
O4 - Startup: WaCiSORKWbCL.lnk = ?
O4 - Global Startup: TP-LINK Wireless Configuration Utility.lnk = C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotaçoes Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotaçoes Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10678 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {26244911-9441-4611-85F3-5742E035D879}
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs"
"C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe"
"C:\Users\Karlos\AppData\Local\Temp\System32.exe" ..
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs"
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs"
"C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe" -nogui
"C:\ProgramData\Boxtools\Toolbox.exe" -autorun
"C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe" "C:\Users\Karlos\JrHqBZR1HjXrPoBp\gNJEB.au3" 1
"C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe" "C:\Users\Karlos\pZ6WAIeN1keYiysV\BcHBc.au3" 1
"C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe" "C:\Users\Karlos\0jx2JCAW2rMXVnPr\KCeUL.au3" 1
0
0
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\svchost.exe -k Shewoied
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3892
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Karlos\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=53.0.2785.143 --handshake-handle=0xb0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2436.0.1298798379\1587231550" --mojo-application-channel-token=6A9934A10C8735BECF0DA212C7C066F4 --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeChannelStable/Enabled/ClientSideDetectionModel/Model0/DisallowFetchForDocWrittenScriptsInMainFrame/Control/EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_94/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,13,14,15,16,18,31,56 --gpu-vendor-id=0x1002 --gpu-device-id=0x6818 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=21.19.137.1 --gpu-driver-date=9-16-2016 --mojo-platform-channel-handle=1088 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeChannelStable/Enabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Control/*EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_94/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=41662A2F6F78F1DCE25A7B0590E7B502 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=3EAB122EDB90E7775BE6F7694DF2BE58 --mojo-application-channel-token=41662A2F6F78F1DCE25A7B0590E7B502 --channel="2436.4.1944749183\1175944676" --mojo-platform-channel-handle=4232 /prefetch:1
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Karlos\Desktop\RSITx64 (1).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13 81024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-13 69760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-16 12445288]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2015-07-08 5595848]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-09-16 8027016]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BlazeServoTool"=C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"rldqxyulfl"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs []
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2014-09-12 437248]
"Boxoft Tools"=C:\ProgramData\Boxtools\Boxofttoolbox.exe [2010-12-15 514048]
"2320633bbd5b9c41d628d6d2b760a34d"=C:\Users\Karlos\AppData\Local\Temp\System32.exe [2016-10-20 133632]
"uqgfhuutfn"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs []
"ctbvysgbgs"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-11-29 284440]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-01-27 291608]
"G3 mouse"=C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe [2012-04-24 786432]
"LifeCam"=C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
TP-LINK Wireless Configuration Utility.lnk - C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Users\Karlos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2320633bbd5b9c41d628d6d2b760a34d.exe
ctbvysgbgs.vbs
KDPSIZWDgUiV.lnk - C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe
NRNQBIhVHKhM.lnk - C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe
rldqxyulfl.vbs
SLIN.exe
uqgfhuutfn.vbs
WaCiSORKWbCL.lnk - C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-10-21 17:39:00 ----D---- C:\Users\Karlos\AppData\Roaming\VS Revo Group
2016-10-21 16:49:22 ----D---- C:\Program Files\VS Revo Group
2016-10-21 16:38:00 ----D---- C:\Program Files (x86)\Origin Games
2016-10-21 16:29:45 ----D---- C:\Users\Karlos\AppData\Roaming\Origin
2016-10-21 16:25:54 ----D---- C:\Program Files (x86)\Origin
2016-10-20 19:12:56 ----A---- C:\Users\Karlos\AppData\Roaming\QXNN.exe
2016-10-20 19:04:33 ----D---- C:\ProgramData\Avira
2016-10-20 19:04:33 ----D---- C:\ProgramData\Avg
2016-10-20 19:04:33 ----D---- C:\ProgramData\AVAST Software
2016-10-20 19:02:53 ----D---- C:\Users\Karlos\AppData\Roaming\Profiles
2016-10-20 19:02:53 ----D---- C:\Users\Karlos\AppData\Roaming\Ghuqeght
2016-10-20 19:02:52 ----D---- C:\Program Files (x86)\Phijswajerk
2016-10-20 18:18:52 ----A---- C:\Users\Karlos\AppData\Roaming\XDAW.exe
2016-10-20 14:39:35 ----D---- C:\Users\Karlos\AppData\Roaming\DriverAgentPlus
2016-10-12 16:20:59 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-10-12 16:20:59 ----A---- C:\Windows\system32\appraiser.dll
2016-10-12 16:20:59 ----A---- C:\Windows\system32\aeinv.dll
2016-10-12 16:20:59 ----A---- C:\Windows\system32\acmigration.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\invagent.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\generaltel.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\devinv.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\centel.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\aepic.dll
2016-10-12 16:20:47 ----A---- C:\Windows\system32\mshtml.dll
2016-10-12 16:20:46 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-10-12 16:20:45 ----A---- C:\Windows\system32\wmp.dll
2016-10-12 16:20:45 ----A---- C:\Windows\system32\ieframe.dll
2016-10-12 16:20:44 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-10-12 16:20:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-10-12 16:20:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-10-12 16:20:43 ----A---- C:\Windows\system32\jscript9.dll
2016-10-12 16:20:42 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-10-12 16:20:42 ----A---- C:\Windows\system32\mf.dll
2016-10-12 16:20:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-10-12 16:20:41 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2016-10-12 16:20:41 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\WsmSvc.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\wininet.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-10-12 16:20:41 ----A---- C:\Windows\system32\iertutil.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\drmv2clt.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\blackbox.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\quartz.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\urlmon.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\scavengeui.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\quartz.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\evr.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2016-10-12 16:20:39 ----A---- C:\Windows\system32\vbscript.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\qdvd.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\lsasrv.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\evr.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\DWrite.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2016-10-12 16:20:39 ----A---- C:\Windows\system32\cryptui.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\audiosrv.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\AUDIOKSE.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\AudioEng.dll
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\WsmAuto.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\win32k.sys
2016-10-12 16:20:38 ----A---- C:\Windows\system32\pcasvc.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\msfeeds.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\mfplat.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\FntCache.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\AudioSes.dll
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2016-10-12 16:20:37 ----A---- C:\Windows\system32\wmploc.DLL
2016-10-12 16:20:37 ----A---- C:\Windows\system32\mfps.dll
2016-10-12 16:20:37 ----A---- C:\Windows\system32\inetcomm.dll
2016-10-12 16:20:37 ----A---- C:\Windows\system32\EncDump.dll
2016-10-12 16:20:37 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2016-10-12 16:20:37 ----A---- C:\Windows\system32\drivers\dfsc.sys
2016-10-12 16:20:37 ----A---- C:\Windows\system32\audiodg.exe
2016-10-12 16:20:36 ----A---- C:\Windows\SYSWOW64\mfps.dll
2016-10-12 16:20:36 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-10-12 16:20:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-10-12 16:20:36 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2016-10-12 16:20:36 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2016-10-12 16:20:36 ----A---- C:\Windows\system32\msscp.dll
2016-10-12 16:20:36 ----A---- C:\Windows\system32\iedkcs32.dll
2016-10-12 16:20:36 ----A---- C:\Windows\system32\cryptsp.dll
2016-10-12 16:20:36 ----A---- C:\Windows\system32\adsmsext.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\msscp.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\adsmsext.dll
2016-10-12 16:20:35 ----A---- C:\Windows\system32\WebClnt.dll
2016-10-12 16:20:35 ----A---- C:\Windows\system32\ntdll.dll
2016-10-12 16:20:35 ----A---- C:\Windows\system32\msnetobj.dll
2016-10-12 16:20:35 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-10-12 16:20:35 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-10-12 16:20:35 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\wsmprovhost.exe
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-10-12 16:20:34 ----A---- C:\Windows\system32\wsmprovhost.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\rrinstaller.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\pcawrk.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\pcalua.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\pcadm.dll
2016-10-12 16:20:34 ----A---- C:\Windows\system32\mfpmp.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\ie4uinit.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\davclnt.dll
2016-10-12 16:20:34 ----A---- C:\Windows\system32\certcli.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\wsmplpxy.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\wsmplpxy.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\spwmp.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\rpcrt4.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\msmmsp.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\mshtmlmedia.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\jscript.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\INETRES.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\dxmasf.dll
2016-10-12 16:20:32 ----A---- C:\Windows\system32\pcaevts.dll
2016-10-12 16:20:32 ----A---- C:\Windows\system32\ieui.dll
2016-10-12 16:20:31 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2016-10-12 16:20:31 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2016-10-12 16:20:31 ----A---- C:\Windows\system32\webcheck.dll
2016-10-12 16:20:31 ----A---- C:\Windows\system32\ieapfltr.dll
2016-10-12 16:20:31 ----A---- C:\Windows\system32\dxtrans.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\msrating.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\ieui.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\occache.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\msrating.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\mshtmled.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\kerberos.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\jsproxy.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\jscript9diag.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\dxtmsft.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\occache.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\inseng.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\wdigest.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\TSpkg.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\sspicli.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\smss.exe
2016-10-12 16:20:29 ----A---- C:\Windows\system32\schannel.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\ncrypt.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\msv1_0.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\MshtmlDac.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\kernel32.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\inseng.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\ieUnatt.exe
2016-10-12 16:20:29 ----A---- C:\Windows\system32\iesetup.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\ieetwproxystub.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-10-12 16:20:29 ----A---- C:\Windows\system32\crypt32.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\advapi32.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\WsmRes.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\schannel.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\mferror.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\WsmRes.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\wow64win.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\wintrust.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\winsrv.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\srcore.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\rpchttp.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\mferror.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\lsass.exe
2016-10-12 16:20:28 ----A---- C:\Windows\system32\KernelBase.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\iernonce.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-10-12 16:20:28 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-10-12 16:20:28 ----A---- C:\Windows\system32\cryptsvc.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\cryptnet.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\cryptbase.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\wow64.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\sspisrv.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\secur32.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\drivers\appid.sys
2016-10-12 16:20:27 ----A---- C:\Windows\system32\csrsrv.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\credssp.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\conhost.exe
2016-10-12 16:20:26 ----A---- C:\Windows\SYSWOW64\secur32.dll
2016-10-12 16:20:26 ----A---- C:\Windows\SYSWOW64\credssp.dll
2016-10-12 16:20:26 ----A---- C:\Windows\system32\wow64cpu.dll
2016-10-12 16:20:26 ----A---- C:\Windows\system32\srclient.dll
2016-10-12 16:20:26 ----A---- C:\Windows\system32\auditpol.exe
2016-10-12 16:20:25 ----A---- C:\Windows\SYSWOW64\srclient.dll
2016-10-12 16:20:25 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-10-12 16:20:25 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2016-10-12 16:20:25 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-10-12 16:20:25 ----A---- C:\Windows\system32\rstrui.exe
2016-10-12 16:20:25 ----A---- C:\Windows\system32\ntvdm64.dll
2016-10-12 16:20:25 ----A---- C:\Windows\system32\appidsvc.dll
2016-10-12 16:20:25 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-10-12 16:20:25 ----A---- C:\Windows\system32\appidapi.dll
2016-10-12 16:20:23 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\user.exe
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\setup16.exe
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\instnm.exe
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2016-10-12 16:20:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-10-12 16:20:22 ----A---- C:\Windows\system32\apisetschema.dll
2016-10-12 16:20:21 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2016-10-12 16:20:21 ----A---- C:\Windows\system32\adtschema.dll
2016-10-12 16:20:20 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2016-10-12 16:20:20 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2016-10-12 16:20:20 ----A---- C:\Windows\system32\msobjs.dll
2016-10-12 16:20:20 ----A---- C:\Windows\system32\msaudite.dll
2016-10-12 16:20:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbport.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbohci.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbhub.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbehci.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbd.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2016-10-12 16:19:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-10-12 16:19:21 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-10-12 16:19:21 ----A---- C:\Windows\system32\shell32.dll
2016-10-12 16:19:21 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-10-12 16:19:21 ----A---- C:\Windows\explorer.exe
2016-10-12 16:19:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-10-12 16:19:20 ----A---- C:\Windows\SYSWOW64\authui.dll
2016-10-12 16:19:20 ----A---- C:\Windows\system32\authui.dll
2016-10-12 16:19:10 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2016-10-12 16:19:10 ----A---- C:\Windows\system32\poqexec.exe
2016-10-11 16:16:24 ----D---- C:\Users\Karlos\AppData\Roaming\Mozilla
2016-10-11 16:15:34 ----A---- C:\Users\Karlos\AppData\Roaming\Main.dat
2016-10-11 16:15:34 ----A---- C:\Users\Karlos\AppData\Roaming\agent.dat
2016-10-11 16:15:31 ----A---- C:\Users\Karlos\AppData\Roaming\Silsolex.exe
2016-10-11 16:13:44 ----A---- C:\Users\Karlos\AppData\Roaming\Installer.dat
2016-10-11 16:13:36 ----D---- C:\Users\Karlos\AppData\Roaming\Microleaves
2016-10-09 22:07:03 ----A---- C:\Users\Karlos\AppData\Roaming\Dibg.exe
2016-10-09 22:06:22 ----D---- C:\Users\Karlos\AppData\Roaming\Monitor
2016-10-09 22:06:22 ----D---- C:\ProgramData\Client
2016-10-09 21:41:09 ----HD---- C:\Program Files\Common Files\EAInstaller
2016-10-09 13:59:30 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-10-09 13:59:30 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-10-09 13:59:30 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-10-09 13:59:30 ----A---- C:\Windows\system32\vulkan-1.dll
2016-10-09 13:59:28 ----D---- C:\Program Files (x86)\VulkanRT
2016-10-09 13:38:08 ----D---- C:\_OTM
2016-09-25 16:27:13 ----A---- C:\Windows\system32\drivers\srvnet.sys
2016-09-25 16:27:13 ----A---- C:\Windows\system32\drivers\srv2.sys
2016-09-25 16:27:13 ----A---- C:\Windows\system32\drivers\srv.sys
2016-09-25 16:26:15 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2016-09-25 16:26:15 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2016-09-25 16:26:15 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2016-09-25 16:26:15 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuwebv.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wudriver.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wucltux.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuaueng.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuauclt.exe
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuapp.exe
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuapi.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\WinSetupUI.dll
2016-09-25 16:26:06 ----A---- C:\Windows\system32\wups2.dll
2016-09-25 16:26:06 ----A---- C:\Windows\system32\wups.dll
2016-09-25 16:26:06 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2016-09-25 16:26:04 ----A---- C:\Windows\SYSWOW64\wups.dll
2016-09-25 16:26:02 ----A---- C:\Windows\system32\msi.dll
2016-09-25 16:26:00 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2016-09-25 16:25:56 ----A---- C:\Windows\system32\msiexec.exe
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\msi.dll
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2016-09-25 16:25:55 ----A---- C:\Windows\system32\msimsg.dll
2016-09-25 16:25:55 ----A---- C:\Windows\system32\msihnd.dll
2016-09-25 16:25:55 ----A---- C:\Windows\system32\consent.exe
2016-09-25 16:25:55 ----A---- C:\Windows\system32\asycfilt.dll
2016-09-25 16:25:55 ----A---- C:\Windows\system32\appinfo.dll
2016-09-25 16:25:35 ----A---- C:\Windows\SYSWOW64\tzres.dll
2016-09-25 16:25:35 ----A---- C:\Windows\system32\tzres.dll
2016-09-25 16:25:32 ----A---- C:\Windows\SYSWOW64\user32.dll
2016-09-25 16:25:32 ----A---- C:\Windows\system32\user32.dll
2016-09-25 16:25:31 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2016-09-25 16:25:31 ----A---- C:\Windows\system32\oleaut32.dll
2016-09-25 16:25:31 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2016-09-25 16:25:31 ----A---- C:\Windows\system32\drivers\tcpip.sys
2016-09-25 16:25:31 ----A---- C:\Windows\system32\drivers\netio.sys
2016-09-25 16:25:31 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
======List of files/folders modified in the last 1 month======
2016-10-22 18:32:03 ----D---- C:\Program Files\trend micro
2016-10-22 18:23:46 ----D---- C:\Windows\System32
2016-10-22 18:23:46 ----D---- C:\Windows\inf
2016-10-22 18:23:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-10-22 18:20:07 ----D---- C:\Windows\system32\config
2016-10-22 18:19:13 ----D---- C:\Windows\temp
2016-10-22 18:16:48 ----D---- C:\ProgramData\Boxtools
2016-10-22 11:19:55 ----D---- C:\ProgramData\Origin
2016-10-22 00:06:18 ----SHD---- C:\System Volume Information
2016-10-21 18:08:37 ----D---- C:\Windows\Microsoft.NET
2016-10-21 18:07:46 ----RSD---- C:\Windows\assembly
2016-10-21 17:30:10 ----D---- C:\Windows\SysWOW64
2016-10-21 17:30:06 ----SHD---- C:\Windows\Installer
2016-10-21 17:30:05 ----D---- C:\Users\Karlos\AppData\Roaming\Seznam.cz
2016-10-21 17:30:04 ----D---- C:\Program Files (x86)\Steam
2016-10-21 17:23:31 ----RD---- C:\Program Files (x86)
2016-10-21 17:21:43 ----SHD---- C:\Config.Msi
2016-10-21 17:20:48 ----D---- C:\ProgramData\Codemasters
2016-10-21 17:17:26 ----D---- C:\Program Files (x86)\Ubisoft
2016-10-21 16:49:22 ----RD---- C:\Program Files
2016-10-21 16:29:42 ----D---- C:\Hry
2016-10-21 16:09:42 ----D---- C:\Windows
2016-10-20 19:04:33 ----D---- C:\ProgramData
2016-10-20 19:04:33 ----D---- C:\Program Files (x86)\Intel
2016-10-20 19:04:33 ----D---- C:\Program Files (x86)\Guitar Pro 5
2016-10-20 19:04:33 ----D---- C:\Program Files (x86)\gfx
2016-10-20 19:04:03 ----RD---- C:\Program Files (x86)\Skype
2016-10-20 19:04:03 ----HD---- C:\Program Files (x86)\Uninstall Information
2016-10-20 19:04:03 ----HD---- C:\Program Files (x86)\Temp
2016-10-20 19:04:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\WinRAR
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Sidebar
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows NT
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Media Player
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Mail
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Defender
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Webteh
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\VS Revo Group
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\VideoLAN
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\TP-LINK
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\totalcmd
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\SymSilent
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Sony Media Go Install
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Sony
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\sfx
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Seznam.cz
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\SaalDesigner
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Rockstar Games
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Realtek
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Raptr Inc
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\qst
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\OpenAL
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\MSXML 4.0
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\MSBuild
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Office
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft LifeCam
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Maxthon
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\logs
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Lavalys
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Internet Explorer
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Chcete byt milionarem PC hra
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Guitar Pro 6
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Google
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\GIGABYTE
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Gaming Mouse
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Future Pinball
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\freebird
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Free mp3 Wma Converter
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Free MP3 Sound Recorder
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Electronic Arts
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Counter-Strike 1.6
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Common Files
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\BRS
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\BlazeVideo
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\ATI Technologies
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\AMD AVT
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\AMD APP
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\AMD
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Adobe
2016-10-20 19:03:56 ----D---- C:\Windows\system32\Tasks
2016-10-20 18:45:01 ----D---- C:\Users\Karlos\AppData\Roaming\DAEMON Tools Lite
2016-10-20 18:44:57 ----D---- C:\Users\Karlos\AppData\Roaming\uTorrent
2016-10-20 18:38:24 ----D---- C:\Windows\Logs
2016-10-14 19:21:58 ----D---- C:\Windows\winsxs
2016-10-14 18:48:43 ----D---- C:\Program Files\Windows Media Player
2016-10-14 18:48:43 ----D---- C:\Program Files\Internet Explorer
2016-10-14 18:48:42 ----D---- C:\Windows\SYSWOW64\en-US
2016-10-14 18:48:42 ----D---- C:\Windows\SYSWOW64\Dism
2016-10-14 18:48:42 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-10-14 18:48:38 ----D---- C:\Windows\system32\en-US
2016-10-14 18:48:38 ----D---- C:\Windows\system32\drivers
2016-10-14 18:48:38 ----D---- C:\Windows\system32\Dism
2016-10-14 18:48:38 ----D---- C:\Windows\system32\cs-CZ
2016-10-14 18:48:31 ----D---- C:\Windows\AppPatch
2016-10-14 18:48:30 ----D---- C:\Windows\system32\Boot
2016-10-14 18:48:29 ----SD---- C:\Windows\system32\CompatTel
2016-10-14 18:48:29 ----D---- C:\Windows\system32\appraiser
2016-10-14 18:48:27 ----D---- C:\Windows\system32\drivers\cs-CZ
2016-10-14 18:48:25 ----D---- C:\Windows\cs-CZ
2016-10-14 18:48:22 ----D---- C:\Windows\system32\DriverStore
2016-10-14 18:47:20 ----D---- C:\Program Files\Microsoft Silverlight
2016-10-12 20:17:32 ----D---- C:\ProgramData\Microsoft Help
2016-10-12 16:39:33 ----D---- C:\ProgramData\Package Cache
2016-10-12 16:11:53 ----D---- C:\Windows\system32\catroot2
2016-10-12 15:56:46 ----D---- C:\Windows\LiveKernelReports
2016-10-11 18:21:26 ----D---- C:\Users\Karlos\AppData\Roaming\Turbo Booster for uTorrent
2016-10-11 17:09:59 ----D---- C:\Program Files\Enigma Software Group
2016-10-11 16:22:14 ----D---- C:\AdwCleaner
2016-10-11 16:13:44 ----D---- C:\Windows\Tasks
2016-10-09 21:41:09 ----D---- C:\Program Files\Common Files
2016-10-09 15:32:48 ----D---- C:\Windows\system32\catroot
2016-10-09 14:03:08 ----D---- C:\Program Files\AMD
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 72400]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-11-29 568600]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-01-27 16152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-27 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 53360]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 231520]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2016-09-16 26550784]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2016-09-16 518536]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2014-05-23 1930240]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2016-03-30 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-17 4734440]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-01-27 356120]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-01-27 787736]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2016-03-10 27008]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 DrvAgent64;DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2014-01-19 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-05-30 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2014-05-30 30528]
S3 IT9135BDA;IT9135 BDA Devices; C:\Windows\System32\Drivers\IT9135BDA.sys [2013-12-31 165504]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2016-10-22 192216]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2016-03-10 64896]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2011-12-02 239208]
S3 TRIDCap;AVerMedia service; C:\Windows\system32\DRIVERS\AVerTM62_x64.sys [2013-10-08 1103744]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2016-09-16 287112]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2015-07-08 1353720]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-27 76888]
R2 Shewoied;Shewoied; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-10 1136608]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-10-21 2209296]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-09-30 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-10-21 2142728]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-03-31 835664]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-12-29 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
-----------------EOF-----------------
prosím o kontrolu logu...
Logfile of random's system information tool 1.10 (written by random/random)
Run by Karlos at 2016-10-22 18:32:02
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 93 GB (10%) free of 954 GB
Total RAM: 8139 MB (76% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:32:04, on 22.10.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18500)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\ProgramData\Boxtools\Toolbox.exe
C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe
C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe
C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Karlos.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [G3 mouse] "C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [rldqxyulfl] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKCU\..\Run: [Boxoft Tools] "C:\ProgramData\Boxtools\Boxofttoolbox.exe" -autorun
O4 - HKCU\..\Run: [2320633bbd5b9c41d628d6d2b760a34d] "C:\Users\Karlos\AppData\Local\Temp\System32.exe" ..
O4 - HKCU\..\Run: [uqgfhuutfn] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs"
O4 - HKCU\..\Run: [ctbvysgbgs] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs"
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Startup: 2320633bbd5b9c41d628d6d2b760a34d.exe
O4 - Startup: ctbvysgbgs.vbs
O4 - Startup: KDPSIZWDgUiV.lnk = ?
O4 - Startup: NRNQBIhVHKhM.lnk = ?
O4 - Startup: rldqxyulfl.vbs
O4 - Startup: SLIN.exe
O4 - Startup: uqgfhuutfn.vbs
O4 - Startup: WaCiSORKWbCL.lnk = ?
O4 - Global Startup: TP-LINK Wireless Configuration Utility.lnk = C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotaçoes Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotaçoes Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10678 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
atieclxx
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {26244911-9441-4611-85F3-5742E035D879}
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"taskhost.exe"
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs"
"C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe"
"C:\Users\Karlos\AppData\Local\Temp\System32.exe" ..
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs"
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs"
"C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe" -nogui
"C:\ProgramData\Boxtools\Toolbox.exe" -autorun
"C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe" "C:\Users\Karlos\JrHqBZR1HjXrPoBp\gNJEB.au3" 1
"C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe" "C:\Users\Karlos\pZ6WAIeN1keYiysV\BcHBc.au3" 1
"C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe" "C:\Users\Karlos\0jx2JCAW2rMXVnPr\KCeUL.au3" 1
0
0
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\svchost.exe -k Shewoied
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
WLIDSvcM.exe 3892
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
C:\Windows\servicing\TrustedInstaller.exe
"C:\Windows\system32\wuauclt.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 --no-rate-limit "--database=C:\Users\Karlos\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=53.0.2785.143 --handshake-handle=0xb0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --channel="2436.0.1298798379\1587231550" --mojo-application-channel-token=6A9934A10C8735BECF0DA212C7C066F4 --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeChannelStable/Enabled/ClientSideDetectionModel/Model0/DisallowFetchForDocWrittenScriptsInMainFrame/Control/EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_94/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,13,14,15,16,18,31,56 --gpu-vendor-id=0x1002 --gpu-device-id=0x6818 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=21.19.137.1 --gpu-driver-date=9-16-2016 --mojo-platform-channel-handle=1088 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,*PreconnectMore<PreconnectMore,*TranslateUI2016Q2<TranslateUI2016Q2,UsePasswordSeparatedSigninFlow<PasswordSeparatedSigninFlow --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Disabled/ChromeChannelStable/Enabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Control/*EnableMediaRouter/Enabled/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PasswordSeparatedSigninFlow/Enabled/PasswordSmartBubble/3-Times/PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/SyncHttpContentCompression/Enabled/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_94/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=41662A2F6F78F1DCE25A7B0590E7B502 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --content-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --video-image-texture-target=3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553,3553 --mojo-channel-token=3EAB122EDB90E7775BE6F7694DF2BE58 --mojo-application-channel-token=41662A2F6F78F1DCE25A7B0590E7B502 --channel="2436.4.1944749183\1175944676" --mojo-platform-channel-handle=4232 /prefetch:1
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
C:\Windows\system32\DllHost.exe /Processid:{E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E}
"C:\Users\Karlos\Desktop\RSITx64 (1).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13 81024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-13 69760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-16 12445288]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2015-07-08 5595848]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-09-16 8027016]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BlazeServoTool"=C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"rldqxyulfl"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs []
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2014-09-12 437248]
"Boxoft Tools"=C:\ProgramData\Boxtools\Boxofttoolbox.exe [2010-12-15 514048]
"2320633bbd5b9c41d628d6d2b760a34d"=C:\Users\Karlos\AppData\Local\Temp\System32.exe [2016-10-20 133632]
"uqgfhuutfn"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs []
"ctbvysgbgs"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs []
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-11-29 284440]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-01-27 291608]
"G3 mouse"=C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe [2012-04-24 786432]
"LifeCam"=C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
TP-LINK Wireless Configuration Utility.lnk - C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Users\Karlos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2320633bbd5b9c41d628d6d2b760a34d.exe
ctbvysgbgs.vbs
KDPSIZWDgUiV.lnk - C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe
NRNQBIhVHKhM.lnk - C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe
rldqxyulfl.vbs
SLIN.exe
uqgfhuutfn.vbs
WaCiSORKWbCL.lnk - C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-10-21 17:39:00 ----D---- C:\Users\Karlos\AppData\Roaming\VS Revo Group
2016-10-21 16:49:22 ----D---- C:\Program Files\VS Revo Group
2016-10-21 16:38:00 ----D---- C:\Program Files (x86)\Origin Games
2016-10-21 16:29:45 ----D---- C:\Users\Karlos\AppData\Roaming\Origin
2016-10-21 16:25:54 ----D---- C:\Program Files (x86)\Origin
2016-10-20 19:12:56 ----A---- C:\Users\Karlos\AppData\Roaming\QXNN.exe
2016-10-20 19:04:33 ----D---- C:\ProgramData\Avira
2016-10-20 19:04:33 ----D---- C:\ProgramData\Avg
2016-10-20 19:04:33 ----D---- C:\ProgramData\AVAST Software
2016-10-20 19:02:53 ----D---- C:\Users\Karlos\AppData\Roaming\Profiles
2016-10-20 19:02:53 ----D---- C:\Users\Karlos\AppData\Roaming\Ghuqeght
2016-10-20 19:02:52 ----D---- C:\Program Files (x86)\Phijswajerk
2016-10-20 18:18:52 ----A---- C:\Users\Karlos\AppData\Roaming\XDAW.exe
2016-10-20 14:39:35 ----D---- C:\Users\Karlos\AppData\Roaming\DriverAgentPlus
2016-10-12 16:20:59 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-10-12 16:20:59 ----A---- C:\Windows\system32\appraiser.dll
2016-10-12 16:20:59 ----A---- C:\Windows\system32\aeinv.dll
2016-10-12 16:20:59 ----A---- C:\Windows\system32\acmigration.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\invagent.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\generaltel.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\devinv.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\centel.dll
2016-10-12 16:20:58 ----A---- C:\Windows\system32\aepic.dll
2016-10-12 16:20:47 ----A---- C:\Windows\system32\mshtml.dll
2016-10-12 16:20:46 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-10-12 16:20:45 ----A---- C:\Windows\system32\wmp.dll
2016-10-12 16:20:45 ----A---- C:\Windows\system32\ieframe.dll
2016-10-12 16:20:44 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-10-12 16:20:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-10-12 16:20:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-10-12 16:20:43 ----A---- C:\Windows\system32\jscript9.dll
2016-10-12 16:20:42 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-10-12 16:20:42 ----A---- C:\Windows\system32\mf.dll
2016-10-12 16:20:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-10-12 16:20:41 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2016-10-12 16:20:41 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\WsmSvc.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\wininet.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-10-12 16:20:41 ----A---- C:\Windows\system32\iertutil.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\drmv2clt.dll
2016-10-12 16:20:41 ----A---- C:\Windows\system32\blackbox.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\quartz.dll
2016-10-12 16:20:40 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\urlmon.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\scavengeui.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\quartz.dll
2016-10-12 16:20:40 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\evr.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2016-10-12 16:20:39 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2016-10-12 16:20:39 ----A---- C:\Windows\system32\vbscript.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\qdvd.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\lsasrv.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\evr.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\DWrite.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2016-10-12 16:20:39 ----A---- C:\Windows\system32\cryptui.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\audiosrv.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\AUDIOKSE.dll
2016-10-12 16:20:39 ----A---- C:\Windows\system32\AudioEng.dll
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2016-10-12 16:20:38 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\WsmAuto.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\win32k.sys
2016-10-12 16:20:38 ----A---- C:\Windows\system32\pcasvc.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\msfeeds.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\mfplat.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\FntCache.dll
2016-10-12 16:20:38 ----A---- C:\Windows\system32\AudioSes.dll
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-10-12 16:20:37 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2016-10-12 16:20:37 ----A---- C:\Windows\system32\wmploc.DLL
2016-10-12 16:20:37 ----A---- C:\Windows\system32\mfps.dll
2016-10-12 16:20:37 ----A---- C:\Windows\system32\inetcomm.dll
2016-10-12 16:20:37 ----A---- C:\Windows\system32\EncDump.dll
2016-10-12 16:20:37 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2016-10-12 16:20:37 ----A---- C:\Windows\system32\drivers\dfsc.sys
2016-10-12 16:20:37 ----A---- C:\Windows\system32\audiodg.exe
2016-10-12 16:20:36 ----A---- C:\Windows\SYSWOW64\mfps.dll
2016-10-12 16:20:36 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-10-12 16:20:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-10-12 16:20:36 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2016-10-12 16:20:36 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2016-10-12 16:20:36 ----A---- C:\Windows\system32\msscp.dll
2016-10-12 16:20:36 ----A---- C:\Windows\system32\iedkcs32.dll
2016-10-12 16:20:36 ----A---- C:\Windows\system32\cryptsp.dll
2016-10-12 16:20:36 ----A---- C:\Windows\system32\adsmsext.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\msscp.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2016-10-12 16:20:35 ----A---- C:\Windows\SYSWOW64\adsmsext.dll
2016-10-12 16:20:35 ----A---- C:\Windows\system32\WebClnt.dll
2016-10-12 16:20:35 ----A---- C:\Windows\system32\ntdll.dll
2016-10-12 16:20:35 ----A---- C:\Windows\system32\msnetobj.dll
2016-10-12 16:20:35 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-10-12 16:20:35 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-10-12 16:20:35 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\wsmprovhost.exe
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2016-10-12 16:20:34 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-10-12 16:20:34 ----A---- C:\Windows\system32\wsmprovhost.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\rrinstaller.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\pcawrk.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\pcalua.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\pcadm.dll
2016-10-12 16:20:34 ----A---- C:\Windows\system32\mfpmp.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\ie4uinit.exe
2016-10-12 16:20:34 ----A---- C:\Windows\system32\davclnt.dll
2016-10-12 16:20:34 ----A---- C:\Windows\system32\certcli.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\wsmplpxy.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2016-10-12 16:20:33 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\wsmplpxy.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\spwmp.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\rpcrt4.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\msmmsp.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\mshtmlmedia.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\jscript.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\INETRES.dll
2016-10-12 16:20:33 ----A---- C:\Windows\system32\dxmasf.dll
2016-10-12 16:20:32 ----A---- C:\Windows\system32\pcaevts.dll
2016-10-12 16:20:32 ----A---- C:\Windows\system32\ieui.dll
2016-10-12 16:20:31 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2016-10-12 16:20:31 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2016-10-12 16:20:31 ----A---- C:\Windows\system32\webcheck.dll
2016-10-12 16:20:31 ----A---- C:\Windows\system32\ieapfltr.dll
2016-10-12 16:20:31 ----A---- C:\Windows\system32\dxtrans.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\msrating.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\ieui.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-10-12 16:20:30 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\occache.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\msrating.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\mshtmled.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\kerberos.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\jsproxy.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\jscript9diag.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\dxtmsft.dll
2016-10-12 16:20:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\occache.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\inseng.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2016-10-12 16:20:29 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\wdigest.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\TSpkg.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\sspicli.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\smss.exe
2016-10-12 16:20:29 ----A---- C:\Windows\system32\schannel.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\ncrypt.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\msv1_0.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\MshtmlDac.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\kernel32.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\inseng.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\ieUnatt.exe
2016-10-12 16:20:29 ----A---- C:\Windows\system32\iesetup.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\ieetwproxystub.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-10-12 16:20:29 ----A---- C:\Windows\system32\crypt32.dll
2016-10-12 16:20:29 ----A---- C:\Windows\system32\advapi32.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\WsmRes.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\schannel.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\mferror.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2016-10-12 16:20:28 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\WsmRes.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\wow64win.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\wintrust.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\winsrv.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\srcore.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\rpchttp.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\mferror.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\lsass.exe
2016-10-12 16:20:28 ----A---- C:\Windows\system32\KernelBase.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\iernonce.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-10-12 16:20:28 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-10-12 16:20:28 ----A---- C:\Windows\system32\cryptsvc.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\cryptnet.dll
2016-10-12 16:20:28 ----A---- C:\Windows\system32\cryptbase.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2016-10-12 16:20:27 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\wow64.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\sspisrv.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\secur32.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\drivers\appid.sys
2016-10-12 16:20:27 ----A---- C:\Windows\system32\csrsrv.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\credssp.dll
2016-10-12 16:20:27 ----A---- C:\Windows\system32\conhost.exe
2016-10-12 16:20:26 ----A---- C:\Windows\SYSWOW64\secur32.dll
2016-10-12 16:20:26 ----A---- C:\Windows\SYSWOW64\credssp.dll
2016-10-12 16:20:26 ----A---- C:\Windows\system32\wow64cpu.dll
2016-10-12 16:20:26 ----A---- C:\Windows\system32\srclient.dll
2016-10-12 16:20:26 ----A---- C:\Windows\system32\auditpol.exe
2016-10-12 16:20:25 ----A---- C:\Windows\SYSWOW64\srclient.dll
2016-10-12 16:20:25 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-10-12 16:20:25 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2016-10-12 16:20:25 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-10-12 16:20:25 ----A---- C:\Windows\system32\rstrui.exe
2016-10-12 16:20:25 ----A---- C:\Windows\system32\ntvdm64.dll
2016-10-12 16:20:25 ----A---- C:\Windows\system32\appidsvc.dll
2016-10-12 16:20:25 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-10-12 16:20:25 ----A---- C:\Windows\system32\appidapi.dll
2016-10-12 16:20:23 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 16:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\user.exe
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\setup16.exe
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\instnm.exe
2016-10-12 16:20:22 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2016-10-12 16:20:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-10-12 16:20:22 ----A---- C:\Windows\system32\apisetschema.dll
2016-10-12 16:20:21 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2016-10-12 16:20:21 ----A---- C:\Windows\system32\adtschema.dll
2016-10-12 16:20:20 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2016-10-12 16:20:20 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2016-10-12 16:20:20 ----A---- C:\Windows\system32\msobjs.dll
2016-10-12 16:20:20 ----A---- C:\Windows\system32\msaudite.dll
2016-10-12 16:20:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbport.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbohci.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbhub.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbehci.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbd.sys
2016-10-12 16:19:33 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2016-10-12 16:19:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-10-12 16:19:21 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-10-12 16:19:21 ----A---- C:\Windows\system32\shell32.dll
2016-10-12 16:19:21 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-10-12 16:19:21 ----A---- C:\Windows\explorer.exe
2016-10-12 16:19:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-10-12 16:19:20 ----A---- C:\Windows\SYSWOW64\authui.dll
2016-10-12 16:19:20 ----A---- C:\Windows\system32\authui.dll
2016-10-12 16:19:10 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2016-10-12 16:19:10 ----A---- C:\Windows\system32\poqexec.exe
2016-10-11 16:16:24 ----D---- C:\Users\Karlos\AppData\Roaming\Mozilla
2016-10-11 16:15:34 ----A---- C:\Users\Karlos\AppData\Roaming\Main.dat
2016-10-11 16:15:34 ----A---- C:\Users\Karlos\AppData\Roaming\agent.dat
2016-10-11 16:15:31 ----A---- C:\Users\Karlos\AppData\Roaming\Silsolex.exe
2016-10-11 16:13:44 ----A---- C:\Users\Karlos\AppData\Roaming\Installer.dat
2016-10-11 16:13:36 ----D---- C:\Users\Karlos\AppData\Roaming\Microleaves
2016-10-09 22:07:03 ----A---- C:\Users\Karlos\AppData\Roaming\Dibg.exe
2016-10-09 22:06:22 ----D---- C:\Users\Karlos\AppData\Roaming\Monitor
2016-10-09 22:06:22 ----D---- C:\ProgramData\Client
2016-10-09 21:41:09 ----HD---- C:\Program Files\Common Files\EAInstaller
2016-10-09 13:59:30 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-10-09 13:59:30 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-10-09 13:59:30 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-10-09 13:59:30 ----A---- C:\Windows\system32\vulkan-1.dll
2016-10-09 13:59:28 ----D---- C:\Program Files (x86)\VulkanRT
2016-10-09 13:38:08 ----D---- C:\_OTM
2016-09-25 16:27:13 ----A---- C:\Windows\system32\drivers\srvnet.sys
2016-09-25 16:27:13 ----A---- C:\Windows\system32\drivers\srv2.sys
2016-09-25 16:27:13 ----A---- C:\Windows\system32\drivers\srv.sys
2016-09-25 16:26:15 ----A---- C:\Windows\SYSWOW64\wuwebv.dll
2016-09-25 16:26:15 ----A---- C:\Windows\SYSWOW64\wudriver.dll
2016-09-25 16:26:15 ----A---- C:\Windows\SYSWOW64\wuapp.exe
2016-09-25 16:26:15 ----A---- C:\Windows\SYSWOW64\wuapi.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuwebv.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wudriver.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wucltux.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuaueng.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuauclt.exe
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuapp.exe
2016-09-25 16:26:15 ----A---- C:\Windows\system32\wuapi.dll
2016-09-25 16:26:15 ----A---- C:\Windows\system32\WinSetupUI.dll
2016-09-25 16:26:06 ----A---- C:\Windows\system32\wups2.dll
2016-09-25 16:26:06 ----A---- C:\Windows\system32\wups.dll
2016-09-25 16:26:06 ----A---- C:\Windows\system32\wu.upgrade.ps.dll
2016-09-25 16:26:04 ----A---- C:\Windows\SYSWOW64\wups.dll
2016-09-25 16:26:02 ----A---- C:\Windows\system32\msi.dll
2016-09-25 16:26:00 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2016-09-25 16:25:56 ----A---- C:\Windows\system32\msiexec.exe
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\msimsg.dll
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\msihnd.dll
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\msiexec.exe
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\msi.dll
2016-09-25 16:25:55 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2016-09-25 16:25:55 ----A---- C:\Windows\system32\msimsg.dll
2016-09-25 16:25:55 ----A---- C:\Windows\system32\msihnd.dll
2016-09-25 16:25:55 ----A---- C:\Windows\system32\consent.exe
2016-09-25 16:25:55 ----A---- C:\Windows\system32\asycfilt.dll
2016-09-25 16:25:55 ----A---- C:\Windows\system32\appinfo.dll
2016-09-25 16:25:35 ----A---- C:\Windows\SYSWOW64\tzres.dll
2016-09-25 16:25:35 ----A---- C:\Windows\system32\tzres.dll
2016-09-25 16:25:32 ----A---- C:\Windows\SYSWOW64\user32.dll
2016-09-25 16:25:32 ----A---- C:\Windows\system32\user32.dll
2016-09-25 16:25:31 ----A---- C:\Windows\SYSWOW64\oleaut32.dll
2016-09-25 16:25:31 ----A---- C:\Windows\system32\oleaut32.dll
2016-09-25 16:25:31 ----A---- C:\Windows\system32\drivers\tcpipreg.sys
2016-09-25 16:25:31 ----A---- C:\Windows\system32\drivers\tcpip.sys
2016-09-25 16:25:31 ----A---- C:\Windows\system32\drivers\netio.sys
2016-09-25 16:25:31 ----A---- C:\Windows\system32\drivers\FWPKCLNT.SYS
======List of files/folders modified in the last 1 month======
2016-10-22 18:32:03 ----D---- C:\Program Files\trend micro
2016-10-22 18:23:46 ----D---- C:\Windows\System32
2016-10-22 18:23:46 ----D---- C:\Windows\inf
2016-10-22 18:23:46 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-10-22 18:20:07 ----D---- C:\Windows\system32\config
2016-10-22 18:19:13 ----D---- C:\Windows\temp
2016-10-22 18:16:48 ----D---- C:\ProgramData\Boxtools
2016-10-22 11:19:55 ----D---- C:\ProgramData\Origin
2016-10-22 00:06:18 ----SHD---- C:\System Volume Information
2016-10-21 18:08:37 ----D---- C:\Windows\Microsoft.NET
2016-10-21 18:07:46 ----RSD---- C:\Windows\assembly
2016-10-21 17:30:10 ----D---- C:\Windows\SysWOW64
2016-10-21 17:30:06 ----SHD---- C:\Windows\Installer
2016-10-21 17:30:05 ----D---- C:\Users\Karlos\AppData\Roaming\Seznam.cz
2016-10-21 17:30:04 ----D---- C:\Program Files (x86)\Steam
2016-10-21 17:23:31 ----RD---- C:\Program Files (x86)
2016-10-21 17:21:43 ----SHD---- C:\Config.Msi
2016-10-21 17:20:48 ----D---- C:\ProgramData\Codemasters
2016-10-21 17:17:26 ----D---- C:\Program Files (x86)\Ubisoft
2016-10-21 16:49:22 ----RD---- C:\Program Files
2016-10-21 16:29:42 ----D---- C:\Hry
2016-10-21 16:09:42 ----D---- C:\Windows
2016-10-20 19:04:33 ----D---- C:\ProgramData
2016-10-20 19:04:33 ----D---- C:\Program Files (x86)\Intel
2016-10-20 19:04:33 ----D---- C:\Program Files (x86)\Guitar Pro 5
2016-10-20 19:04:33 ----D---- C:\Program Files (x86)\gfx
2016-10-20 19:04:03 ----RD---- C:\Program Files (x86)\Skype
2016-10-20 19:04:03 ----HD---- C:\Program Files (x86)\Uninstall Information
2016-10-20 19:04:03 ----HD---- C:\Program Files (x86)\Temp
2016-10-20 19:04:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\WinRAR
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Sidebar
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows NT
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Media Player
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Mail
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Windows Defender
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Webteh
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\VS Revo Group
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\VideoLAN
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\TP-LINK
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\totalcmd
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\SymSilent
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Sony Media Go Install
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Sony
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\sfx
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Seznam.cz
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\SaalDesigner
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Rockstar Games
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Realtek
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Raptr Inc
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\qst
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\OpenAL
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\MSXML 4.0
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\MSBuild
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Office
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft LifeCam
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Maxthon
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\logs
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Lavalys
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Internet Explorer
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Chcete byt milionarem PC hra
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Guitar Pro 6
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Google
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\GIGABYTE
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Gaming Mouse
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Future Pinball
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\freebird
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Free mp3 Wma Converter
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Free MP3 Sound Recorder
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Electronic Arts
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Counter-Strike 1.6
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Common Files
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\BRS
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\BlazeVideo
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\ATI Technologies
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\AMD AVT
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\AMD APP
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\AMD
2016-10-20 19:04:03 ----D---- C:\Program Files (x86)\Adobe
2016-10-20 19:03:56 ----D---- C:\Windows\system32\Tasks
2016-10-20 18:45:01 ----D---- C:\Users\Karlos\AppData\Roaming\DAEMON Tools Lite
2016-10-20 18:44:57 ----D---- C:\Users\Karlos\AppData\Roaming\uTorrent
2016-10-20 18:38:24 ----D---- C:\Windows\Logs
2016-10-14 19:21:58 ----D---- C:\Windows\winsxs
2016-10-14 18:48:43 ----D---- C:\Program Files\Windows Media Player
2016-10-14 18:48:43 ----D---- C:\Program Files\Internet Explorer
2016-10-14 18:48:42 ----D---- C:\Windows\SYSWOW64\en-US
2016-10-14 18:48:42 ----D---- C:\Windows\SYSWOW64\Dism
2016-10-14 18:48:42 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-10-14 18:48:38 ----D---- C:\Windows\system32\en-US
2016-10-14 18:48:38 ----D---- C:\Windows\system32\drivers
2016-10-14 18:48:38 ----D---- C:\Windows\system32\Dism
2016-10-14 18:48:38 ----D---- C:\Windows\system32\cs-CZ
2016-10-14 18:48:31 ----D---- C:\Windows\AppPatch
2016-10-14 18:48:30 ----D---- C:\Windows\system32\Boot
2016-10-14 18:48:29 ----SD---- C:\Windows\system32\CompatTel
2016-10-14 18:48:29 ----D---- C:\Windows\system32\appraiser
2016-10-14 18:48:27 ----D---- C:\Windows\system32\drivers\cs-CZ
2016-10-14 18:48:25 ----D---- C:\Windows\cs-CZ
2016-10-14 18:48:22 ----D---- C:\Windows\system32\DriverStore
2016-10-14 18:47:20 ----D---- C:\Program Files\Microsoft Silverlight
2016-10-12 20:17:32 ----D---- C:\ProgramData\Microsoft Help
2016-10-12 16:39:33 ----D---- C:\ProgramData\Package Cache
2016-10-12 16:11:53 ----D---- C:\Windows\system32\catroot2
2016-10-12 15:56:46 ----D---- C:\Windows\LiveKernelReports
2016-10-11 18:21:26 ----D---- C:\Users\Karlos\AppData\Roaming\Turbo Booster for uTorrent
2016-10-11 17:09:59 ----D---- C:\Program Files\Enigma Software Group
2016-10-11 16:22:14 ----D---- C:\AdwCleaner
2016-10-11 16:13:44 ----D---- C:\Windows\Tasks
2016-10-09 21:41:09 ----D---- C:\Program Files\Common Files
2016-10-09 15:32:48 ----D---- C:\Windows\system32\catroot
2016-10-09 14:03:08 ----D---- C:\Program Files\AMD
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 72400]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-11-29 568600]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-01-27 16152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-27 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 53360]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 231520]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2016-09-16 26550784]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2016-09-16 518536]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2014-05-23 1930240]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2016-03-30 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-17 4734440]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-01-27 356120]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-01-27 787736]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2016-03-10 27008]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 DrvAgent64;DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2014-01-19 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-05-30 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2014-05-30 30528]
S3 IT9135BDA;IT9135 BDA Devices; C:\Windows\System32\Drivers\IT9135BDA.sys [2013-12-31 165504]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2016-10-22 192216]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2016-03-10 64896]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2011-12-02 239208]
S3 TRIDCap;AVerMedia service; C:\Windows\system32\DRIVERS\AVerTM62_x64.sys [2013-10-08 1103744]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2016-09-16 287112]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2015-07-08 1353720]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-27 76888]
R2 Shewoied;Shewoied; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2015-11-05 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2015-11-05 125112]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-10 1136608]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-10-21 2209296]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-09-30 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-10-21 2142728]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-03-31 835664]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-12-29 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2015-11-05 51376]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2015-11-05 135848]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119672
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Antivir našel vir a nejde smazat
Zdravím!
Jaký vir a kde ho našel?
Jaký vir a kde ho našel?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Antivir našel vir a nejde smazat
Operační paměť » C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe varianta infiltrace MSIL/Agent.ADE trojsky kun chyba při mazání E4CB506146F60D01EA9E6132020DEF61974A88C3
píše chybu při mazání
píše chybu při mazání
- Rudy
- Site Admin

- Příspěvky: 119672
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Antivir našel vir a nejde smazat
Zkuste ho otestovat online na www.virustotal.com . Osobně si myslím, že je to chybná detekce, NET.framework je regulérní program.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Antivir našel vir a nejde smazat
Podle programu je soubor v pořádku, ale když zapnu pc tak to vždycky vyskočí.
- Rudy
- Site Admin

- Příspěvky: 119672
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Antivir našel vir a nejde smazat
Pokud vám to hlásí antivir, dejte ho do vyjímek.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Antivir našel vir a nejde smazat
ok...a log je jinak ok?
- Rudy
- Site Admin

- Příspěvky: 119672
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Antivir našel vir a nejde smazat
Log vypadá čistý.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Antivir našel vir a nejde smazat
Když zapnu pc tak mi vyskočí chybová hláška o microsoft net framework...a padá mi GTA V, které vždy šlapalo...vše jsem aktualizoval a nepomohlo to
Logfile of random's system information tool 1.10 (written by random/random)
Run by Karlos at 2016-11-05 12:18:58
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 89 GB (9%) free of 954 GB
Total RAM: 8139 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:19:00, on 5.11.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18500)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe
C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe
C:\ProgramData\Boxtools\Toolbox.exe
C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Karlos.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [G3 mouse] "C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [rldqxyulfl] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs"
O4 - HKCU\..\Run: [Boxoft Tools] "C:\ProgramData\Boxtools\Boxofttoolbox.exe" -autorun
O4 - HKCU\..\Run: [2320633bbd5b9c41d628d6d2b760a34d] "C:\Users\Karlos\AppData\Local\Temp\System32.exe" ..
O4 - HKCU\..\Run: [uqgfhuutfn] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs"
O4 - HKCU\..\Run: [ctbvysgbgs] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Startup: 2320633bbd5b9c41d628d6d2b760a34d.exe
O4 - Startup: ctbvysgbgs.vbs
O4 - Startup: KDPSIZWDgUiV.lnk = ?
O4 - Startup: NRNQBIhVHKhM.lnk = ?
O4 - Startup: rldqxyulfl.vbs
O4 - Startup: SLIN.exe
O4 - Startup: uqgfhuutfn.vbs
O4 - Startup: WaCiSORKWbCL.lnk = ?
O4 - Global Startup: TP-LINK Wireless Configuration Utility.lnk = C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotaçoes Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotaçoes Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: InterHop - Unknown owner - C:\Program Files (x86)\InterHop\InterHop.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10684 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {07EBFB66-5643-45DA-90C1-4F7C283239E6}
C:\Windows\SysWOW64\svchost.exe -k ArcherGroupEx
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"C:\Program Files (x86)\InterHop\InterHop.exe" {2C8E8C85-942B-451C-8243-97A089265577}
"C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\svchost.exe -k Shewoied
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\SysWOW64\svchost.exe -k WinSAPSvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 2396
atieclxx
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs"
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs"
"C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe"
"C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe" -nogui
"C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe" "C:\Users\Karlos\JrHqBZR1HjXrPoBp\gNJEB.au3" 1
"C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe" "C:\Users\Karlos\pZ6WAIeN1keYiysV\BcHBc.au3" 1
"C:\ProgramData\Boxtools\Toolbox.exe" -autorun
0
"C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe" "C:\Users\Karlos\0jx2JCAW2rMXVnPr\KCeUL.au3" 1
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe"
0
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"taskhost.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "http://support.rockstargames.com/"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Karlos\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=54.0.2840.87 --handshake-handle=0x9c
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PointerEvent<PointerEvent,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/ClientSideDetectionModel/Model0/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/NonValidatingReloadOnNormalReload/Enabled2/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/StrictSecureCookies/Default/SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_94/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,14,15,16,17,19,33,59 --gpu-vendor-id=0x1002 --gpu-device-id=0x6818 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=21.19.160.512 --gpu-driver-date=11-3-2016 --mojo-application-channel-token=518C173355A4C745C0C0624E1DB7AD87 --mojo-platform-channel-handle=1112 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PointerEvent<PointerEvent,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*NonValidatingReloadOnNormalReload/Enabled2/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/*StrictSecureCookies/Default/*SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_94/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=08B3B0A73C0E95987B790464A158AA7C --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553 --mojo-application-channel-token=08B3B0A73C0E95987B790464A158AA7C --channel="1944.4.241476028\2031195510" --mojo-platform-channel-handle=4216 /prefetch:1
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Karlos\Desktop\RSITx64 (1).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
0
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13 81024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-13 69760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-16 12445288]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2015-07-08 5595848]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-11-03 8029576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BlazeServoTool"=C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"rldqxyulfl"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs []
"Boxoft Tools"=C:\ProgramData\Boxtools\Boxofttoolbox.exe [2010-12-15 514048]
"2320633bbd5b9c41d628d6d2b760a34d"=C:\Users\Karlos\AppData\Local\Temp\System32.exe [2016-10-19 133632]
"uqgfhuutfn"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs []
"ctbvysgbgs"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs []
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2014-09-12 437248]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-11-29 284440]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-01-27 291608]
"G3 mouse"=C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe [2012-04-24 786432]
"LifeCam"=C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
TP-LINK Wireless Configuration Utility.lnk - C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Users\Karlos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2320633bbd5b9c41d628d6d2b760a34d.exe
ctbvysgbgs.vbs
KDPSIZWDgUiV.lnk - C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe
NRNQBIhVHKhM.lnk - C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe
rldqxyulfl.vbs
SLIN.exe
uqgfhuutfn.vbs
WaCiSORKWbCL.lnk - C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-11-05 11:49:51 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\wksprtPS.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\wksprt.exe
2016-11-05 11:49:49 ----A---- C:\Windows\system32\TSWbPrxy.exe
2016-11-05 11:49:49 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2016-11-05 11:49:49 ----A---- C:\Windows\system32\tsgqec.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\mstsc.exe
2016-11-05 11:49:49 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2016-11-05 11:49:48 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2016-11-05 11:49:48 ----A---- C:\Windows\system32\rdvidcrl.dll
2016-11-05 11:49:48 ----A---- C:\Windows\system32\mstscax.dll
2016-11-05 11:48:10 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2016-11-05 11:48:09 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2016-11-05 11:48:09 ----A---- C:\Windows\system32\rdpudd.dll
2016-11-05 11:48:09 ----A---- C:\Windows\system32\drivers\TsUsbGD.sys
2016-11-05 11:48:09 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2016-11-05 11:48:08 ----A---- C:\Windows\system32\rdpendp_winip.dll
2016-11-05 11:48:08 ----A---- C:\Windows\system32\rdpcorets.dll
2016-11-05 11:45:21 ----A---- C:\Windows\system32\icaapi.dll
2016-11-05 11:45:20 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2016-11-05 11:44:45 ----A---- C:\Windows\SYSWOW64\nlsbres.dll
2016-11-05 11:44:45 ----A---- C:\Windows\SYSWOW64\kbdgeoqw.dll
2016-11-05 11:44:45 ----A---- C:\Windows\SYSWOW64\KBDAZEL.DLL
2016-11-05 11:44:45 ----A---- C:\Windows\SYSWOW64\KBDAZE.DLL
2016-11-05 11:44:45 ----A---- C:\Windows\system32\nlsbres.dll
2016-11-05 11:44:45 ----A---- C:\Windows\system32\kbdgeoqw.dll
2016-11-05 11:44:45 ----A---- C:\Windows\system32\KBDAZEL.DLL
2016-11-05 11:44:45 ----A---- C:\Windows\system32\KBDAZE.DLL
2016-11-05 11:44:28 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2016-11-05 11:44:28 ----A---- C:\Windows\SYSWOW64\tzres.dll
2016-11-05 11:44:28 ----A---- C:\Windows\system32\win32spl.dll
2016-11-05 11:44:28 ----A---- C:\Windows\system32\UtcResources.dll
2016-11-05 11:44:28 ----A---- C:\Windows\system32\tzres.dll
2016-11-05 11:44:24 ----A---- C:\Windows\system32\diagtrack.dll
2016-11-04 02:16:56 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2016-11-04 02:16:50 ----A---- C:\Windows\system32\atiumd6a.dll
2016-11-04 02:16:48 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2016-11-04 02:16:48 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2016-11-04 02:16:48 ----A---- C:\Windows\system32\atimpc64.dll
2016-11-04 02:16:48 ----A---- C:\Windows\system32\amdpcom64.dll
2016-11-04 02:16:42 ----A---- C:\Windows\system32\amdhcp64.dll
2016-11-04 02:16:40 ----A---- C:\Windows\SYSWOW64\amdhcp32.dll
2016-11-04 02:16:36 ----A---- C:\Windows\SYSWOW64\amdave32.dll
2016-11-04 02:16:36 ----A---- C:\Windows\system32\amdave64.dll
2016-11-04 02:16:28 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2016-11-04 02:16:28 ----A---- C:\Windows\system32\atiuxp64.dll
2016-11-04 02:16:24 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2016-11-04 02:16:22 ----A---- C:\Windows\system32\atisamu64.dll
2016-11-04 02:16:20 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2016-11-04 02:16:20 ----A---- C:\Windows\SYSWOW64\atisamu32.dll
2016-11-04 02:16:20 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2016-11-04 02:16:20 ----A---- C:\Windows\system32\atiumd64.dll
2016-11-04 02:16:18 ----A---- C:\Windows\system32\atiu9p64.dll
2016-11-04 02:16:18 ----A---- C:\Windows\system32\amfrt64.dll
2016-11-04 02:16:16 ----A---- C:\Windows\SYSWOW64\amfrt32.dll
2016-11-04 02:16:12 ----A---- C:\Windows\system32\amdvlk64.dll
2016-11-04 02:16:08 ----A---- C:\Windows\system32\GameManager64.dll
2016-11-04 02:16:06 ----A---- C:\Windows\SYSWOW64\GameManager32.dll
2016-11-04 02:16:06 ----A---- C:\Windows\SYSWOW64\amdvlk32.dll
2016-11-04 02:16:06 ----A---- C:\Windows\system32\atidxx64.dll
2016-11-04 02:16:04 ----A---- C:\Windows\system32\dgtrayicon.exe
2016-11-04 02:16:04 ----A---- C:\Windows\system32\detoured.dll
2016-11-04 02:16:02 ----A---- C:\Windows\SYSWOW64\detoured.dll
2016-11-04 02:16:02 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2016-11-04 02:16:02 ----A---- C:\Windows\system32\amduve64.dll
2016-11-04 02:16:00 ----A---- C:\Windows\SYSWOW64\amduve32.dll
2016-11-04 02:15:58 ----A---- C:\Windows\system32\aticfx64.dll
2016-11-04 02:15:56 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2016-11-04 02:15:56 ----A---- C:\Windows\system32\atitmm64.dll
2016-11-04 02:15:56 ----A---- C:\Windows\system32\atimuixx.dll
2016-11-04 02:15:56 ----A---- C:\Windows\system32\amdmmcl6.dll
2016-11-04 02:15:54 ----A---- C:\Windows\SYSWOW64\amdmmcl.dll
2016-11-04 02:15:54 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2016-11-04 02:15:52 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2016-11-04 02:15:52 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2016-11-04 02:15:52 ----A---- C:\Windows\SYSWOW64\amdmcl32.dll
2016-11-04 02:15:52 ----A---- C:\Windows\system32\atiglpxx.dll
2016-11-04 02:15:52 ----A---- C:\Windows\system32\amdmcl64.dll
2016-11-04 02:15:50 ----A---- C:\Windows\system32\atig6txx.dll
2016-11-04 02:15:50 ----A---- C:\Windows\system32\atig6pxx.dll
2016-11-04 02:15:48 ----A---- C:\Windows\system32\atiesrxx.exe
2016-11-04 02:15:46 ----A---- C:\Windows\system32\atieclxx.exe
2016-11-04 02:15:46 ----A---- C:\Windows\system32\atieah64.exe
2016-11-04 02:15:44 ----A---- C:\Windows\SYSWOW64\atieah32.exe
2016-11-04 02:15:42 ----A---- C:\Windows\system32\atidemgy.dll
2016-11-04 02:15:40 ----A---- C:\Windows\SYSWOW64\mantleaxl32.dll
2016-11-04 02:15:40 ----A---- C:\Windows\system32\mantleaxl64.dll
2016-11-04 02:15:40 ----A---- C:\Windows\system32\aticalrt64.dll
2016-11-04 02:15:38 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2016-11-04 02:15:38 ----A---- C:\Windows\system32\mantle64.dll
2016-11-04 02:15:36 ----A---- C:\Windows\SYSWOW64\mantle32.dll
2016-11-04 02:15:34 ----A---- C:\Windows\system32\ATIODE.exe
2016-11-04 02:15:34 ----A---- C:\Windows\system32\ATIODCLI.exe
2016-11-04 02:15:34 ----A---- C:\Windows\system32\aticaldd64.dll
2016-11-04 02:15:28 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2016-11-04 02:15:26 ----A---- C:\Windows\system32\aticalcl64.dll
2016-11-04 02:15:24 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2016-11-04 02:15:24 ----A---- C:\Windows\system32\atiapfxx.exe
2016-11-04 02:15:22 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2016-11-04 02:15:22 ----A---- C:\Windows\SYSWOW64\atiadlxx.dll
2016-11-04 02:15:20 ----A---- C:\Windows\system32\atiadlxx.dll
2016-11-04 02:15:18 ----A---- C:\Windows\system32\hsa-thunk64.dll
2016-11-04 02:15:16 ----A---- C:\Windows\SYSWOW64\hsa-thunk.dll
2016-11-04 02:15:14 ----A---- C:\Windows\system32\OpenCL.dll
2016-11-04 02:15:14 ----A---- C:\Windows\system32\clinfo.exe
2016-11-04 02:15:12 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-11-04 02:15:12 ----A---- C:\Windows\system32\amdmantle64.dll
2016-11-04 02:15:06 ----A---- C:\Windows\SYSWOW64\amdmantle32.dll
2016-11-04 02:15:06 ----A---- C:\Windows\system32\amdgfxinfo64.dll
2016-11-04 02:15:04 ----A---- C:\Windows\SYSWOW64\amdgfxinfo32.dll
2016-11-04 02:15:04 ----A---- C:\Windows\system32\amdocl64.dll
2016-11-04 02:15:04 ----A---- C:\Windows\system32\amdlvr64.dll
2016-11-04 02:15:02 ----A---- C:\Windows\SYSWOW64\amdlvr32.dll
2016-11-04 02:15:02 ----A---- C:\Windows\system32\drivers\amdacpksd.sys
2016-11-04 02:14:58 ----A---- C:\Windows\system32\amdocl12cl64.dll
2016-11-04 02:14:54 ----A---- C:\Windows\SYSWOW64\amdocl12cl.dll
2016-11-04 02:14:50 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2016-11-04 02:14:38 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2016-11-04 02:14:24 ----A---- C:\Windows\system32\atio6axx.dll
2016-11-04 02:13:32 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2016-11-01 13:36:51 ----D---- C:\Program Files (x86)\aienzocb
2016-11-01 13:27:43 ----D---- C:\Program Files (x86)\InterHop
2016-11-01 13:27:23 ----D---- C:\ProgramData\WinSAPSvc
2016-11-01 13:27:23 ----D---- C:\ProgramData\ChelfNotify
2016-11-01 13:27:23 ----D---- C:\Program Files (x86)\WinArcher
2016-11-01 13:27:17 ----D---- C:\Program Files (x86)\8xo22h2j
2016-10-21 19:22:38 ----A---- C:\Windows\system32\amde31a.dat
2016-10-21 19:22:10 ----A---- C:\Windows\system32\ativce03.dat
2016-10-21 18:00:40 ----A---- C:\Windows\system32\amde34a.dat
2016-10-21 18:00:10 ----A---- C:\Windows\system32\amde34b.dat
2016-10-21 16:39:00 ----D---- C:\Users\Karlos\AppData\Roaming\VS Revo Group
2016-10-21 15:49:22 ----D---- C:\Program Files\VS Revo Group
2016-10-21 15:38:00 ----D---- C:\Program Files (x86)\Origin Games
2016-10-21 15:29:45 ----D---- C:\Users\Karlos\AppData\Roaming\Origin
2016-10-21 15:25:54 ----D---- C:\Program Files (x86)\Origin
2016-10-20 18:12:56 ----A---- C:\Users\Karlos\AppData\Roaming\QXNN.exe
2016-10-20 18:04:33 ----D---- C:\ProgramData\Avira
2016-10-20 18:04:33 ----D---- C:\ProgramData\Avg
2016-10-20 18:04:33 ----D---- C:\ProgramData\AVAST Software
2016-10-20 18:02:53 ----D---- C:\Users\Karlos\AppData\Roaming\Profiles
2016-10-20 18:02:53 ----D---- C:\Users\Karlos\AppData\Roaming\Ghuqeght
2016-10-20 18:02:52 ----D---- C:\Program Files (x86)\Phijswajerk
2016-10-20 17:18:52 ----A---- C:\Users\Karlos\AppData\Roaming\XDAW.exe
2016-10-20 17:10:16 ----A---- C:\Windows\system32\ativce02.dat
2016-10-20 13:39:35 ----D---- C:\Users\Karlos\AppData\Roaming\DriverAgentPlus
2016-10-12 15:20:59 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-10-12 15:20:59 ----A---- C:\Windows\system32\appraiser.dll
2016-10-12 15:20:59 ----A---- C:\Windows\system32\aeinv.dll
2016-10-12 15:20:59 ----A---- C:\Windows\system32\acmigration.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\invagent.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\generaltel.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\devinv.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\centel.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\aepic.dll
2016-10-12 15:20:47 ----A---- C:\Windows\system32\mshtml.dll
2016-10-12 15:20:46 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-10-12 15:20:45 ----A---- C:\Windows\system32\wmp.dll
2016-10-12 15:20:45 ----A---- C:\Windows\system32\ieframe.dll
2016-10-12 15:20:44 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-10-12 15:20:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-10-12 15:20:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-10-12 15:20:43 ----A---- C:\Windows\system32\jscript9.dll
2016-10-12 15:20:42 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-10-12 15:20:42 ----A---- C:\Windows\system32\mf.dll
2016-10-12 15:20:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-10-12 15:20:41 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2016-10-12 15:20:41 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\WsmSvc.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\wininet.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-10-12 15:20:41 ----A---- C:\Windows\system32\iertutil.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\drmv2clt.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\blackbox.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\quartz.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\urlmon.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\scavengeui.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\quartz.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\evr.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2016-10-12 15:20:39 ----A---- C:\Windows\system32\vbscript.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\qdvd.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\lsasrv.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\evr.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\DWrite.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2016-10-12 15:20:39 ----A---- C:\Windows\system32\cryptui.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\audiosrv.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\AUDIOKSE.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\AudioEng.dll
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\WsmAuto.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\win32k.sys
2016-10-12 15:20:38 ----A---- C:\Windows\system32\pcasvc.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\msfeeds.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\mfplat.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\FntCache.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\AudioSes.dll
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2016-10-12 15:20:37 ----A---- C:\Windows\system32\wmploc.DLL
2016-10-12 15:20:37 ----A---- C:\Windows\system32\mfps.dll
2016-10-12 15:20:37 ----A---- C:\Windows\system32\inetcomm.dll
2016-10-12 15:20:37 ----A---- C:\Windows\system32\EncDump.dll
2016-10-12 15:20:37 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2016-10-12 15:20:37 ----A---- C:\Windows\system32\drivers\dfsc.sys
2016-10-12 15:20:37 ----A---- C:\Windows\system32\audiodg.exe
2016-10-12 15:20:36 ----A---- C:\Windows\SYSWOW64\mfps.dll
2016-10-12 15:20:36 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-10-12 15:20:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-10-12 15:20:36 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2016-10-12 15:20:36 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2016-10-12 15:20:36 ----A---- C:\Windows\system32\msscp.dll
2016-10-12 15:20:36 ----A---- C:\Windows\system32\iedkcs32.dll
2016-10-12 15:20:36 ----A---- C:\Windows\system32\cryptsp.dll
2016-10-12 15:20:36 ----A---- C:\Windows\system32\adsmsext.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\msscp.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\adsmsext.dll
2016-10-12 15:20:35 ----A---- C:\Windows\system32\WebClnt.dll
2016-10-12 15:20:35 ----A---- C:\Windows\system32\ntdll.dll
2016-10-12 15:20:35 ----A---- C:\Windows\system32\msnetobj.dll
2016-10-12 15:20:35 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-10-12 15:20:35 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-10-12 15:20:35 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\wsmprovhost.exe
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-10-12 15:20:34 ----A---- C:\Windows\system32\wsmprovhost.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\rrinstaller.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\pcawrk.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\pcalua.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\pcadm.dll
2016-10-12 15:20:34 ----A---- C:\Windows\system32\mfpmp.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\ie4uinit.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\davclnt.dll
2016-10-12 15:20:34 ----A---- C:\Windows\system32\certcli.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\wsmplpxy.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\wsmplpxy.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\spwmp.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\rpcrt4.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\msmmsp.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\mshtmlmedia.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\jscript.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\INETRES.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\dxmasf.dll
2016-10-12 15:20:32 ----A---- C:\Windows\system32\pcaevts.dll
2016-10-12 15:20:32 ----A---- C:\Windows\system32\ieui.dll
2016-10-12 15:20:31 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2016-10-12 15:20:31 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2016-10-12 15:20:31 ----A---- C:\Windows\system32\webcheck.dll
2016-10-12 15:20:31 ----A---- C:\Windows\system32\ieapfltr.dll
2016-10-12 15:20:31 ----A---- C:\Windows\system32\dxtrans.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\msrating.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\ieui.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\occache.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\msrating.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\mshtmled.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\kerberos.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\jsproxy.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\jscript9diag.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\dxtmsft.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\occache.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\inseng.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\wdigest.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\TSpkg.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\sspicli.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\smss.exe
2016-10-12 15:20:29 ----A---- C:\Windows\system32\schannel.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\ncrypt.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\msv1_0.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\MshtmlDac.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\kernel32.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\inseng.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\ieUnatt.exe
2016-10-12 15:20:29 ----A---- C:\Windows\system32\iesetup.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\ieetwproxystub.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-10-12 15:20:29 ----A---- C:\Windows\system32\crypt32.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\advapi32.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\WsmRes.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\schannel.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\mferror.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\WsmRes.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\wow64win.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\wintrust.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\winsrv.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\srcore.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\rpchttp.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\mferror.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\lsass.exe
2016-10-12 15:20:28 ----A---- C:\Windows\system32\KernelBase.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\iernonce.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-10-12 15:20:28 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-10-12 15:20:28 ----A---- C:\Windows\system32\cryptsvc.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\cryptnet.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\cryptbase.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\wow64.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\sspisrv.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\secur32.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\drivers\appid.sys
2016-10-12 15:20:27 ----A---- C:\Windows\system32\csrsrv.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\credssp.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\conhost.exe
2016-10-12 15:20:26 ----A---- C:\Windows\SYSWOW64\secur32.dll
2016-10-12 15:20:26 ----A---- C:\Windows\SYSWOW64\credssp.dll
2016-10-12 15:20:26 ----A---- C:\Windows\system32\wow64cpu.dll
2016-10-12 15:20:26 ----A---- C:\Windows\system32\srclient.dll
2016-10-12 15:20:26 ----A---- C:\Windows\system32\auditpol.exe
2016-10-12 15:20:25 ----A---- C:\Windows\SYSWOW64\srclient.dll
2016-10-12 15:20:25 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-10-12 15:20:25 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2016-10-12 15:20:25 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-10-12 15:20:25 ----A---- C:\Windows\system32\rstrui.exe
2016-10-12 15:20:25 ----A---- C:\Windows\system32\ntvdm64.dll
2016-10-12 15:20:25 ----A---- C:\Windows\system32\appidsvc.dll
2016-10-12 15:20:25 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-10-12 15:20:25 ----A---- C:\Windows\system32\appidapi.dll
2016-10-12 15:20:23 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\user.exe
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\setup16.exe
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\instnm.exe
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2016-10-12 15:20:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-10-12 15:20:22 ----A---- C:\Windows\system32\apisetschema.dll
2016-10-12 15:20:21 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2016-10-12 15:20:21 ----A---- C:\Windows\system32\adtschema.dll
2016-10-12 15:20:20 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2016-10-12 15:20:20 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2016-10-12 15:20:20 ----A---- C:\Windows\system32\msobjs.dll
2016-10-12 15:20:20 ----A---- C:\Windows\system32\msaudite.dll
2016-10-12 15:20:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbport.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbohci.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbhub.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbehci.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbd.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2016-10-12 15:19:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-10-12 15:19:21 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-10-12 15:19:21 ----A---- C:\Windows\system32\shell32.dll
2016-10-12 15:19:21 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-10-12 15:19:21 ----A---- C:\Windows\explorer.exe
2016-10-12 15:19:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-10-12 15:19:20 ----A---- C:\Windows\SYSWOW64\authui.dll
2016-10-12 15:19:20 ----A---- C:\Windows\system32\authui.dll
2016-10-12 15:19:10 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2016-10-12 15:19:10 ----A---- C:\Windows\system32\poqexec.exe
2016-10-11 15:16:24 ----D---- C:\Users\Karlos\AppData\Roaming\Mozilla
2016-10-11 15:15:34 ----A---- C:\Users\Karlos\AppData\Roaming\Main.dat
2016-10-11 15:15:34 ----A---- C:\Users\Karlos\AppData\Roaming\agent.dat
2016-10-11 15:15:31 ----A---- C:\Users\Karlos\AppData\Roaming\Silsolex.exe
2016-10-11 15:13:44 ----A---- C:\Users\Karlos\AppData\Roaming\Installer.dat
2016-10-11 15:13:36 ----D---- C:\Users\Karlos\AppData\Roaming\Microleaves
2016-10-09 21:07:03 ----A---- C:\Users\Karlos\AppData\Roaming\Dibg.exe
2016-10-09 21:06:22 ----D---- C:\Users\Karlos\AppData\Roaming\Monitor
2016-10-09 21:06:22 ----D---- C:\ProgramData\Client
2016-10-09 20:41:09 ----HD---- C:\Program Files\Common Files\EAInstaller
2016-10-09 12:59:30 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-10-09 12:59:30 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-10-09 12:59:30 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-10-09 12:59:30 ----A---- C:\Windows\system32\vulkan-1.dll
2016-10-09 12:59:28 ----D---- C:\Program Files (x86)\VulkanRT
2016-10-09 12:38:08 ----D---- C:\_OTM
======List of files/folders modified in the last 1 month======
2016-11-05 12:18:59 ----D---- C:\Program Files\trend micro
2016-11-05 12:06:25 ----D---- C:\Windows\System32
2016-11-05 12:06:25 ----D---- C:\Windows\inf
2016-11-05 12:06:25 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-11-05 12:03:20 ----D---- C:\Windows\temp
2016-11-05 12:00:38 ----D---- C:\ProgramData\Boxtools
2016-11-05 12:00:34 ----D---- C:\Windows
2016-11-05 12:00:29 ----D---- C:\Windows\winsxs
2016-11-05 11:59:38 ----D---- C:\Windows\system32\config
2016-11-05 11:58:02 ----SHD---- C:\Config.Msi
2016-11-05 11:57:04 ----D---- C:\Windows\SYSWOW64\wbem
2016-11-05 11:57:04 ----D---- C:\Windows\SYSWOW64\en-US
2016-11-05 11:57:04 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-11-05 11:57:04 ----D---- C:\Windows\SysWOW64
2016-11-05 11:57:04 ----D---- C:\Windows\system32\wbem
2016-11-05 11:57:04 ----D---- C:\Windows\system32\en-US
2016-11-05 11:57:04 ----D---- C:\Windows\system32\drivers\en-US
2016-11-05 11:57:04 ----D---- C:\Windows\system32\drivers
2016-11-05 11:57:04 ----D---- C:\Windows\system32\cs-CZ
2016-11-05 11:57:04 ----D---- C:\Windows\PolicyDefinitions
2016-11-05 11:57:03 ----RSD---- C:\Windows\Fonts
2016-11-05 11:57:02 ----D---- C:\Windows\system32\DriverStore
2016-11-05 11:56:47 ----SHD---- C:\Windows\Installer
2016-11-05 11:54:52 ----D---- C:\Windows\system32\catroot
2016-11-05 11:51:40 ----SHD---- C:\System Volume Information
2016-11-05 11:50:33 ----D---- C:\Program Files\AMD
2016-11-05 11:48:47 ----D---- C:\AMD
2016-11-05 11:42:00 ----D---- C:\Windows\system32\catroot2
2016-11-05 11:25:19 ----D---- C:\Windows\system32\MRT
2016-11-05 11:25:19 ----D---- C:\Windows\debug
2016-11-05 11:24:57 ----AC---- C:\Windows\system32\MRT.exe
2016-11-05 11:22:57 ----D---- C:\Windows\Microsoft.NET
2016-11-05 11:21:20 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2016-11-04 02:15:08 ----A---- C:\Windows\system32\coinst_16.40.dll
2016-11-01 13:36:54 ----D---- C:\Windows\system32\Tasks
2016-11-01 13:36:51 ----RD---- C:\Program Files (x86)
2016-11-01 13:27:23 ----D---- C:\ProgramData
2016-10-30 11:58:41 ----D---- C:\ProgramData\Origin
2016-10-30 11:48:51 ----D---- C:\Program Files (x86)\Steam
2016-10-26 17:29:06 ----N---- C:\Windows\system32\MpSigStub.exe
2016-10-21 17:07:46 ----RSD---- C:\Windows\assembly
2016-10-21 16:30:05 ----D---- C:\Users\Karlos\AppData\Roaming\Seznam.cz
2016-10-21 16:20:48 ----D---- C:\ProgramData\Codemasters
2016-10-21 16:17:26 ----D---- C:\Program Files (x86)\Ubisoft
2016-10-21 15:49:22 ----RD---- C:\Program Files
2016-10-21 15:29:42 ----D---- C:\Hry
2016-10-20 18:04:33 ----D---- C:\Program Files (x86)\Intel
2016-10-20 18:04:33 ----D---- C:\Program Files (x86)\Guitar Pro 5
2016-10-20 18:04:33 ----D---- C:\Program Files (x86)\gfx
2016-10-20 18:04:03 ----RD---- C:\Program Files (x86)\Skype
2016-10-20 18:04:03 ----HD---- C:\Program Files (x86)\Uninstall Information
2016-10-20 18:04:03 ----HD---- C:\Program Files (x86)\Temp
2016-10-20 18:04:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\WinRAR
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Sidebar
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows NT
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Media Player
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Mail
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Defender
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Webteh
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\VS Revo Group
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\VideoLAN
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\TP-LINK
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\totalcmd
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\SymSilent
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Sony Media Go Install
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Sony
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\sfx
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Seznam.cz
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\SaalDesigner
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Rockstar Games
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Realtek
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Raptr Inc
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\qst
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\OpenAL
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\MSXML 4.0
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\MSBuild
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Office
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft LifeCam
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Maxthon
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\logs
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Lavalys
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Internet Explorer
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Chcete byt milionarem PC hra
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Guitar Pro 6
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Google
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\GIGABYTE
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Gaming Mouse
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Future Pinball
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\freebird
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Free mp3 Wma Converter
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Free MP3 Sound Recorder
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Electronic Arts
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Counter-Strike 1.6
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Common Files
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\BRS
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\BlazeVideo
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\ATI Technologies
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\AMD AVT
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\AMD APP
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\AMD
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Adobe
2016-10-20 17:45:01 ----D---- C:\Users\Karlos\AppData\Roaming\DAEMON Tools Lite
2016-10-20 17:44:57 ----D---- C:\Users\Karlos\AppData\Roaming\uTorrent
2016-10-20 17:38:24 ----D---- C:\Windows\Logs
2016-10-18 03:39:58 ----A---- C:\Windows\system32\SET147.tmp
2016-10-14 17:48:43 ----D---- C:\Program Files\Windows Media Player
2016-10-14 17:48:43 ----D---- C:\Program Files\Internet Explorer
2016-10-14 17:48:42 ----D---- C:\Windows\SYSWOW64\Dism
2016-10-14 17:48:38 ----D---- C:\Windows\system32\Dism
2016-10-14 17:48:31 ----D---- C:\Windows\AppPatch
2016-10-14 17:48:30 ----D---- C:\Windows\system32\Boot
2016-10-14 17:48:29 ----SD---- C:\Windows\system32\CompatTel
2016-10-14 17:48:29 ----D---- C:\Windows\system32\appraiser
2016-10-14 17:48:27 ----D---- C:\Windows\system32\drivers\cs-CZ
2016-10-14 17:48:25 ----D---- C:\Windows\cs-CZ
2016-10-14 17:47:20 ----D---- C:\Program Files\Microsoft Silverlight
2016-10-12 19:17:32 ----D---- C:\ProgramData\Microsoft Help
2016-10-12 15:39:33 ----D---- C:\ProgramData\Package Cache
2016-10-12 14:56:46 ----D---- C:\Windows\LiveKernelReports
2016-10-11 17:21:26 ----D---- C:\Users\Karlos\AppData\Roaming\Turbo Booster for uTorrent
2016-10-11 16:09:59 ----D---- C:\Program Files\Enigma Software Group
2016-10-11 15:22:14 ----D---- C:\AdwCleaner
2016-10-11 15:13:44 ----D---- C:\Windows\Tasks
2016-10-09 20:41:09 ----D---- C:\Program Files\Common Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 72400]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-11-29 568600]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-01-27 16152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-27 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 53360]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 231520]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2016-11-04 26558976]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2016-11-04 520072]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2014-05-23 1930240]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2016-03-30 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-17 4734440]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-01-27 356120]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-01-27 787736]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2016-03-10 27008]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 DrvAgent64;DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2014-01-19 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-05-29 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2014-05-29 30528]
S3 IT9135BDA;IT9135 BDA Devices; C:\Windows\System32\Drivers\IT9135BDA.sys [2013-12-31 165504]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2016-10-21 192216]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2016-03-10 64896]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2011-12-02 239208]
S3 TRIDCap;AVerMedia service; C:\Windows\system32\DRIVERS\AVerTM62_x64.sys [2013-10-08 1103744]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2016-11-04 289160]
R2 Archer;Archer; C:\Windows\SysWOW64\svchost.exe [2009-07-14 20992]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-07-14 107192]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-07-14 128696]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2015-07-08 1353720]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592]
R2 InterHop;InterHop; C:\Program Files (x86)\InterHop\InterHop.exe [2016-10-31 430592]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-27 76888]
R2 Shewoied;Shewoied; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WinSAPSvc;WinSAPSvc; C:\Windows\SysWOW64\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-10 1136608]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-10-30 2209296]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-09-30 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-10-30 2142728]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-03-31 835664]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-12-29 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-14 52920]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
-----------------EOF-----------------
Logfile of random's system information tool 1.10 (written by random/random)
Run by Karlos at 2016-11-05 12:18:58
Microsoft Windows 7 Home Premium Service Pack 1
System drive C: has 89 GB (9%) free of 954 GB
Total RAM: 8139 MB (73% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:19:00, on 5.11.2016
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v11.0 (11.00.9600.18500)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe
C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe
C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe
C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe
C:\ProgramData\Boxtools\Toolbox.exe
C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Karlos.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AMD SteadyVideo BHO - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
O4 - HKLM\..\Run: [G3 mouse] "C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [rldqxyulfl] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs"
O4 - HKCU\..\Run: [Boxoft Tools] "C:\ProgramData\Boxtools\Boxofttoolbox.exe" -autorun
O4 - HKCU\..\Run: [2320633bbd5b9c41d628d6d2b760a34d] "C:\Users\Karlos\AppData\Local\Temp\System32.exe" ..
O4 - HKCU\..\Run: [uqgfhuutfn] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs"
O4 - HKCU\..\Run: [ctbvysgbgs] wscript.exe //B "C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs"
O4 - HKCU\..\Run: [Zoner Photo Studio Autoupdate] "C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE"
O4 - HKUS\S-1-5-18\..\Run: [] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [] (User 'Default user')
O4 - Startup: 2320633bbd5b9c41d628d6d2b760a34d.exe
O4 - Startup: ctbvysgbgs.vbs
O4 - Startup: KDPSIZWDgUiV.lnk = ?
O4 - Startup: NRNQBIhVHKhM.lnk = ?
O4 - Startup: rldqxyulfl.vbs
O4 - Startup: SLIN.exe
O4 - Startup: uqgfhuutfn.vbs
O4 - Startup: WaCiSORKWbCL.lnk = ?
O4 - Global Startup: TP-LINK Wireless Configuration Utility.lnk = C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
O8 - Extra context menu item: &Enviar para o OneNote - res://C:\PROGRA~2\MICROS~2\Office14\ONBttnIE.dll/105
O8 - Extra context menu item: E&xportar para o Microsoft Excel - res://C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE/3000
O9 - Extra button: Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Enviar para o OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: &Anotaçoes Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: &Anotaçoes Vinculadas do OneNote - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O18 - Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O18 - Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Úložná technologie Intel(R) Rapid (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS (ICCS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: InterHop - Unknown owner - C:\Program Files (x86)\InterHop\InterHop.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: Origin Web Helper Service - Electronic Arts - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10684 bytes
======Listing Processes======
\SystemRoot\System32\smss.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
wininit.exe
%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ServerDll=sxssrv,4 ProfileControl=Off MaxRequestThreads=16
winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\servicing\TrustedInstaller.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
taskeng.exe {07EBFB66-5643-45DA-90C1-4F7C283239E6}
C:\Windows\SysWOW64\svchost.exe -k ArcherGroupEx
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe"
"C:\Program Files (x86)\InterHop\InterHop.exe" {2C8E8C85-942B-451C-8243-97A089265577}
"C:\Program Files\Microsoft LifeCam\MSCamS64.exe"
C:\Windows\SysWOW64\PnkBstrA.exe
C:\Windows\SysWOW64\svchost.exe -k Shewoied
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\SysWOW64\svchost.exe -k WinSAPSvc
"C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE"
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe /Embedding
WLIDSvcM.exe 2396
atieclxx
"taskhost.exe"
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Windows\system32\Dwm.exe"
C:\Windows\Explorer.EXE
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\ESET\ESET Smart Security\egui.exe" /hide /waitservice
"C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe" atlogon
"C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe"
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs"
"C:\Windows\System32\wscript.exe" //B "C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs"
"C:\Program Files\Zoner\Photo Studio 17\Program32\ZPSTray.exe"
"C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe" -nogui
"C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe" "C:\Users\Karlos\JrHqBZR1HjXrPoBp\gNJEB.au3" 1
"C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe" "C:\Users\Karlos\pZ6WAIeN1keYiysV\BcHBc.au3" 1
"C:\ProgramData\Boxtools\Toolbox.exe" -autorun
0
"C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe" "C:\Users\Karlos\0jx2JCAW2rMXVnPr\KCeUL.au3" 1
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe"
"C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe"
"C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe"
0
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
"C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe"
"C:\Program Files\Windows Media Player\wmpnetwk.exe"
"taskhost.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "http://support.rockstargames.com/"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Karlos\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=54.0.2840.87 --handshake-handle=0x9c
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PointerEvent<PointerEvent,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/ClientSideDetectionModel/Model0/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/NonValidatingReloadOnNormalReload/Enabled2/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/StrictSecureCookies/Default/SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_94/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,14,15,16,17,19,33,59 --gpu-vendor-id=0x1002 --gpu-device-id=0x6818 --gpu-driver-vendor="Advanced Micro Devices, Inc." --gpu-driver-version=21.19.160.512 --gpu-driver-date=11-3-2016 --mojo-application-channel-token=518C173355A4C745C0C0624E1DB7AD87 --mojo-platform-channel-handle=1112 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,PointerEvent<PointerEvent,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ClientSideDetectionModel/Model0/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*NonValidatingReloadOnNormalReload/Enabled2/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/BiMonthlyPrompt/SSLCommonNameMismatchHandling/Control/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SignInPasswordPromo/Default/*StrictSecureCookies/Default/*SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_94/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_04/*UMA-Uniformity-Trial-5-Percent/group_13/*UMA-Uniformity-Trial-50-Percent/group_01/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=08B3B0A73C0E95987B790464A158AA7C --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553 --mojo-application-channel-token=08B3B0A73C0E95987B790464A158AA7C --channel="1944.4.241476028\2031195510" --mojo-platform-channel-handle=4216 /prefetch:1
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe6_ Global\UsGthrCtrlFltPipeMssGthrPipe6 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 524 528 536 65536 532
"C:\Users\Karlos\Desktop\RSITx64 (1).exe"
C:\Windows\system32\DllHost.exe /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
0
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2012-02-13 81024]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 532336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 690392]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C680BAE-655C-4E3D-8FC4-E6A520C3D928}]
SteadyVideoBHO Class - C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-13 69760]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18 403840]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~2\Office14\URLREDIR.DLL [2013-03-06 562904]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2012-01-16 12445288]
"egui"=C:\Program Files\ESET\ESET Smart Security\egui.exe [2015-07-08 5595848]
"StartCN"=C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe [2016-11-03 8029576]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"BlazeServoTool"=C:\Program Files (x86)\BlazeVideo\BlazeDTV 6.0\MediaDetector.exe [2009-07-07 282624]
"DAEMON Tools Lite"=C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [2013-10-28 3675352]
"rldqxyulfl"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\rldqxyulfl.vbs []
"Boxoft Tools"=C:\ProgramData\Boxtools\Boxofttoolbox.exe [2010-12-15 514048]
"2320633bbd5b9c41d628d6d2b760a34d"=C:\Users\Karlos\AppData\Local\Temp\System32.exe [2016-10-19 133632]
"uqgfhuutfn"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\uqgfhuutfn.vbs []
"ctbvysgbgs"=wscript.exe //B C:\Users\Karlos\AppData\Local\Temp\ctbvysgbgs.vbs []
"Zoner Photo Studio Autoupdate"=C:\PROGRAM FILES\ZONER\PHOTO STUDIO 17\Program32\ZPSTRAY.EXE [2014-09-12 437248]
[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2011-11-29 284440]
"USB3MON"=C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [2012-01-27 291608]
"G3 mouse"=C:\Program Files (x86)\Gaming Mouse\G3 Mouse\SMonitor.exe [2012-04-24 786432]
"LifeCam"=C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [2010-12-13 135536]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
TP-LINK Wireless Configuration Utility.lnk - C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe
C:\Users\Karlos\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2320633bbd5b9c41d628d6d2b760a34d.exe
ctbvysgbgs.vbs
KDPSIZWDgUiV.lnk - C:\Users\Karlos\JrHqBZR1HjXrPoBp\Dibg.exe
NRNQBIhVHKhM.lnk - C:\Users\Karlos\pZ6WAIeN1keYiysV\XDAW.exe
rldqxyulfl.vbs
SLIN.exe
uqgfhuutfn.vbs
WaCiSORKWbCL.lnk - C:\Users\Karlos\0jx2JCAW2rMXVnPr\QXNN.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 6671064]
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~2\Office14\GROOVEEX.DLL [2013-12-19 4171480]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"PromptOnSecureDesktop"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"msacm.msadpcm"=msadp32.acm
"midimapper"=midimap.dll
"wavemapper"=msacm32.drv
"VIDC.UYVY"=msyuv.dll
"VIDC.YUY2"=msyuv.dll
"VIDC.YVYU"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.i420"=iyuv_32.dll
"VIDC.YVU9"=tsbyuv.dll
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave4"=wdmaud.drv
"mixer4"=wdmaud.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 month======
2016-11-05 11:49:51 ----A---- C:\Windows\system32\TsUsbGDCoInstaller.dll
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\wksprtPS.dll
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\tsgqec.dll
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\mstscax.dll
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\mstsc.exe
2016-11-05 11:49:49 ----A---- C:\Windows\SYSWOW64\MsRdpWebAccess.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\wksprtPS.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\wksprt.exe
2016-11-05 11:49:49 ----A---- C:\Windows\system32\TSWbPrxy.exe
2016-11-05 11:49:49 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe
2016-11-05 11:49:49 ----A---- C:\Windows\system32\tsgqec.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\mstsc.exe
2016-11-05 11:49:49 ----A---- C:\Windows\system32\MsRdpWebAccess.dll
2016-11-05 11:49:49 ----A---- C:\Windows\system32\drivers\TsUsbFlt.sys
2016-11-05 11:49:48 ----A---- C:\Windows\SYSWOW64\rdvidcrl.dll
2016-11-05 11:49:48 ----A---- C:\Windows\system32\rdvidcrl.dll
2016-11-05 11:49:48 ----A---- C:\Windows\system32\mstscax.dll
2016-11-05 11:48:10 ----A---- C:\Windows\system32\RdpGroupPolicyExtension.dll
2016-11-05 11:48:09 ----A---- C:\Windows\SYSWOW64\rdpendp_winip.dll
2016-11-05 11:48:09 ----A---- C:\Windows\system32\rdpudd.dll
2016-11-05 11:48:09 ----A---- C:\Windows\system32\drivers\TsUsbGD.sys
2016-11-05 11:48:09 ----A---- C:\Windows\system32\drivers\rdpvideominiport.sys
2016-11-05 11:48:08 ----A---- C:\Windows\system32\rdpendp_winip.dll
2016-11-05 11:48:08 ----A---- C:\Windows\system32\rdpcorets.dll
2016-11-05 11:45:21 ----A---- C:\Windows\system32\icaapi.dll
2016-11-05 11:45:20 ----A---- C:\Windows\system32\drivers\tssecsrv.sys
2016-11-05 11:44:45 ----A---- C:\Windows\SYSWOW64\nlsbres.dll
2016-11-05 11:44:45 ----A---- C:\Windows\SYSWOW64\kbdgeoqw.dll
2016-11-05 11:44:45 ----A---- C:\Windows\SYSWOW64\KBDAZEL.DLL
2016-11-05 11:44:45 ----A---- C:\Windows\SYSWOW64\KBDAZE.DLL
2016-11-05 11:44:45 ----A---- C:\Windows\system32\nlsbres.dll
2016-11-05 11:44:45 ----A---- C:\Windows\system32\kbdgeoqw.dll
2016-11-05 11:44:45 ----A---- C:\Windows\system32\KBDAZEL.DLL
2016-11-05 11:44:45 ----A---- C:\Windows\system32\KBDAZE.DLL
2016-11-05 11:44:28 ----A---- C:\Windows\SYSWOW64\win32spl.dll
2016-11-05 11:44:28 ----A---- C:\Windows\SYSWOW64\tzres.dll
2016-11-05 11:44:28 ----A---- C:\Windows\system32\win32spl.dll
2016-11-05 11:44:28 ----A---- C:\Windows\system32\UtcResources.dll
2016-11-05 11:44:28 ----A---- C:\Windows\system32\tzres.dll
2016-11-05 11:44:24 ----A---- C:\Windows\system32\diagtrack.dll
2016-11-04 02:16:56 ----A---- C:\Windows\SYSWOW64\atiumdva.dll
2016-11-04 02:16:50 ----A---- C:\Windows\system32\atiumd6a.dll
2016-11-04 02:16:48 ----A---- C:\Windows\SYSWOW64\atimpc32.dll
2016-11-04 02:16:48 ----A---- C:\Windows\SYSWOW64\amdpcom32.dll
2016-11-04 02:16:48 ----A---- C:\Windows\system32\atimpc64.dll
2016-11-04 02:16:48 ----A---- C:\Windows\system32\amdpcom64.dll
2016-11-04 02:16:42 ----A---- C:\Windows\system32\amdhcp64.dll
2016-11-04 02:16:40 ----A---- C:\Windows\SYSWOW64\amdhcp32.dll
2016-11-04 02:16:36 ----A---- C:\Windows\SYSWOW64\amdave32.dll
2016-11-04 02:16:36 ----A---- C:\Windows\system32\amdave64.dll
2016-11-04 02:16:28 ----A---- C:\Windows\SYSWOW64\atiuxpag.dll
2016-11-04 02:16:28 ----A---- C:\Windows\system32\atiuxp64.dll
2016-11-04 02:16:24 ----A---- C:\Windows\SYSWOW64\atiumdag.dll
2016-11-04 02:16:22 ----A---- C:\Windows\system32\atisamu64.dll
2016-11-04 02:16:20 ----A---- C:\Windows\SYSWOW64\atiu9pag.dll
2016-11-04 02:16:20 ----A---- C:\Windows\SYSWOW64\atisamu32.dll
2016-11-04 02:16:20 ----A---- C:\Windows\system32\drivers\ati2erec.dll
2016-11-04 02:16:20 ----A---- C:\Windows\system32\atiumd64.dll
2016-11-04 02:16:18 ----A---- C:\Windows\system32\atiu9p64.dll
2016-11-04 02:16:18 ----A---- C:\Windows\system32\amfrt64.dll
2016-11-04 02:16:16 ----A---- C:\Windows\SYSWOW64\amfrt32.dll
2016-11-04 02:16:12 ----A---- C:\Windows\system32\amdvlk64.dll
2016-11-04 02:16:08 ----A---- C:\Windows\system32\GameManager64.dll
2016-11-04 02:16:06 ----A---- C:\Windows\SYSWOW64\GameManager32.dll
2016-11-04 02:16:06 ----A---- C:\Windows\SYSWOW64\amdvlk32.dll
2016-11-04 02:16:06 ----A---- C:\Windows\system32\atidxx64.dll
2016-11-04 02:16:04 ----A---- C:\Windows\system32\dgtrayicon.exe
2016-11-04 02:16:04 ----A---- C:\Windows\system32\detoured.dll
2016-11-04 02:16:02 ----A---- C:\Windows\SYSWOW64\detoured.dll
2016-11-04 02:16:02 ----A---- C:\Windows\SYSWOW64\atidxx32.dll
2016-11-04 02:16:02 ----A---- C:\Windows\system32\amduve64.dll
2016-11-04 02:16:00 ----A---- C:\Windows\SYSWOW64\amduve32.dll
2016-11-04 02:15:58 ----A---- C:\Windows\system32\aticfx64.dll
2016-11-04 02:15:56 ----A---- C:\Windows\SYSWOW64\aticfx32.dll
2016-11-04 02:15:56 ----A---- C:\Windows\system32\atitmm64.dll
2016-11-04 02:15:56 ----A---- C:\Windows\system32\atimuixx.dll
2016-11-04 02:15:56 ----A---- C:\Windows\system32\amdmmcl6.dll
2016-11-04 02:15:54 ----A---- C:\Windows\SYSWOW64\amdmmcl.dll
2016-11-04 02:15:54 ----A---- C:\Windows\system32\drivers\atikmpag.sys
2016-11-04 02:15:52 ----A---- C:\Windows\SYSWOW64\atiglpxx.dll
2016-11-04 02:15:52 ----A---- C:\Windows\SYSWOW64\atigktxx.dll
2016-11-04 02:15:52 ----A---- C:\Windows\SYSWOW64\amdmcl32.dll
2016-11-04 02:15:52 ----A---- C:\Windows\system32\atiglpxx.dll
2016-11-04 02:15:52 ----A---- C:\Windows\system32\amdmcl64.dll
2016-11-04 02:15:50 ----A---- C:\Windows\system32\atig6txx.dll
2016-11-04 02:15:50 ----A---- C:\Windows\system32\atig6pxx.dll
2016-11-04 02:15:48 ----A---- C:\Windows\system32\atiesrxx.exe
2016-11-04 02:15:46 ----A---- C:\Windows\system32\atieclxx.exe
2016-11-04 02:15:46 ----A---- C:\Windows\system32\atieah64.exe
2016-11-04 02:15:44 ----A---- C:\Windows\SYSWOW64\atieah32.exe
2016-11-04 02:15:42 ----A---- C:\Windows\system32\atidemgy.dll
2016-11-04 02:15:40 ----A---- C:\Windows\SYSWOW64\mantleaxl32.dll
2016-11-04 02:15:40 ----A---- C:\Windows\system32\mantleaxl64.dll
2016-11-04 02:15:40 ----A---- C:\Windows\system32\aticalrt64.dll
2016-11-04 02:15:38 ----A---- C:\Windows\SYSWOW64\aticalrt.dll
2016-11-04 02:15:38 ----A---- C:\Windows\system32\mantle64.dll
2016-11-04 02:15:36 ----A---- C:\Windows\SYSWOW64\mantle32.dll
2016-11-04 02:15:34 ----A---- C:\Windows\system32\ATIODE.exe
2016-11-04 02:15:34 ----A---- C:\Windows\system32\ATIODCLI.exe
2016-11-04 02:15:34 ----A---- C:\Windows\system32\aticaldd64.dll
2016-11-04 02:15:28 ----A---- C:\Windows\SYSWOW64\aticaldd.dll
2016-11-04 02:15:26 ----A---- C:\Windows\system32\aticalcl64.dll
2016-11-04 02:15:24 ----A---- C:\Windows\SYSWOW64\aticalcl.dll
2016-11-04 02:15:24 ----A---- C:\Windows\system32\atiapfxx.exe
2016-11-04 02:15:22 ----A---- C:\Windows\SYSWOW64\atiadlxy.dll
2016-11-04 02:15:22 ----A---- C:\Windows\SYSWOW64\atiadlxx.dll
2016-11-04 02:15:20 ----A---- C:\Windows\system32\atiadlxx.dll
2016-11-04 02:15:18 ----A---- C:\Windows\system32\hsa-thunk64.dll
2016-11-04 02:15:16 ----A---- C:\Windows\SYSWOW64\hsa-thunk.dll
2016-11-04 02:15:14 ----A---- C:\Windows\system32\OpenCL.dll
2016-11-04 02:15:14 ----A---- C:\Windows\system32\clinfo.exe
2016-11-04 02:15:12 ----A---- C:\Windows\SYSWOW64\OpenCL.dll
2016-11-04 02:15:12 ----A---- C:\Windows\system32\amdmantle64.dll
2016-11-04 02:15:06 ----A---- C:\Windows\SYSWOW64\amdmantle32.dll
2016-11-04 02:15:06 ----A---- C:\Windows\system32\amdgfxinfo64.dll
2016-11-04 02:15:04 ----A---- C:\Windows\SYSWOW64\amdgfxinfo32.dll
2016-11-04 02:15:04 ----A---- C:\Windows\system32\amdocl64.dll
2016-11-04 02:15:04 ----A---- C:\Windows\system32\amdlvr64.dll
2016-11-04 02:15:02 ----A---- C:\Windows\SYSWOW64\amdlvr32.dll
2016-11-04 02:15:02 ----A---- C:\Windows\system32\drivers\amdacpksd.sys
2016-11-04 02:14:58 ----A---- C:\Windows\system32\amdocl12cl64.dll
2016-11-04 02:14:54 ----A---- C:\Windows\SYSWOW64\amdocl12cl.dll
2016-11-04 02:14:50 ----A---- C:\Windows\SYSWOW64\amdocl.dll
2016-11-04 02:14:38 ----A---- C:\Windows\SYSWOW64\atioglxx.dll
2016-11-04 02:14:24 ----A---- C:\Windows\system32\atio6axx.dll
2016-11-04 02:13:32 ----A---- C:\Windows\system32\drivers\atikmdag.sys
2016-11-01 13:36:51 ----D---- C:\Program Files (x86)\aienzocb
2016-11-01 13:27:43 ----D---- C:\Program Files (x86)\InterHop
2016-11-01 13:27:23 ----D---- C:\ProgramData\WinSAPSvc
2016-11-01 13:27:23 ----D---- C:\ProgramData\ChelfNotify
2016-11-01 13:27:23 ----D---- C:\Program Files (x86)\WinArcher
2016-11-01 13:27:17 ----D---- C:\Program Files (x86)\8xo22h2j
2016-10-21 19:22:38 ----A---- C:\Windows\system32\amde31a.dat
2016-10-21 19:22:10 ----A---- C:\Windows\system32\ativce03.dat
2016-10-21 18:00:40 ----A---- C:\Windows\system32\amde34a.dat
2016-10-21 18:00:10 ----A---- C:\Windows\system32\amde34b.dat
2016-10-21 16:39:00 ----D---- C:\Users\Karlos\AppData\Roaming\VS Revo Group
2016-10-21 15:49:22 ----D---- C:\Program Files\VS Revo Group
2016-10-21 15:38:00 ----D---- C:\Program Files (x86)\Origin Games
2016-10-21 15:29:45 ----D---- C:\Users\Karlos\AppData\Roaming\Origin
2016-10-21 15:25:54 ----D---- C:\Program Files (x86)\Origin
2016-10-20 18:12:56 ----A---- C:\Users\Karlos\AppData\Roaming\QXNN.exe
2016-10-20 18:04:33 ----D---- C:\ProgramData\Avira
2016-10-20 18:04:33 ----D---- C:\ProgramData\Avg
2016-10-20 18:04:33 ----D---- C:\ProgramData\AVAST Software
2016-10-20 18:02:53 ----D---- C:\Users\Karlos\AppData\Roaming\Profiles
2016-10-20 18:02:53 ----D---- C:\Users\Karlos\AppData\Roaming\Ghuqeght
2016-10-20 18:02:52 ----D---- C:\Program Files (x86)\Phijswajerk
2016-10-20 17:18:52 ----A---- C:\Users\Karlos\AppData\Roaming\XDAW.exe
2016-10-20 17:10:16 ----A---- C:\Windows\system32\ativce02.dat
2016-10-20 13:39:35 ----D---- C:\Users\Karlos\AppData\Roaming\DriverAgentPlus
2016-10-12 15:20:59 ----A---- C:\Windows\system32\CompatTelRunner.exe
2016-10-12 15:20:59 ----A---- C:\Windows\system32\appraiser.dll
2016-10-12 15:20:59 ----A---- C:\Windows\system32\aeinv.dll
2016-10-12 15:20:59 ----A---- C:\Windows\system32\acmigration.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\invagent.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\generaltel.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\devinv.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\centel.dll
2016-10-12 15:20:58 ----A---- C:\Windows\system32\aepic.dll
2016-10-12 15:20:47 ----A---- C:\Windows\system32\mshtml.dll
2016-10-12 15:20:46 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-10-12 15:20:45 ----A---- C:\Windows\system32\wmp.dll
2016-10-12 15:20:45 ----A---- C:\Windows\system32\ieframe.dll
2016-10-12 15:20:44 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-10-12 15:20:43 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-10-12 15:20:43 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-10-12 15:20:43 ----A---- C:\Windows\system32\jscript9.dll
2016-10-12 15:20:42 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-10-12 15:20:42 ----A---- C:\Windows\system32\mf.dll
2016-10-12 15:20:41 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-10-12 15:20:41 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2016-10-12 15:20:41 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\WsmSvc.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\wininet.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\ntoskrnl.exe
2016-10-12 15:20:41 ----A---- C:\Windows\system32\iertutil.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\drmv2clt.dll
2016-10-12 15:20:41 ----A---- C:\Windows\system32\blackbox.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\WsmSvc.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\quartz.dll
2016-10-12 15:20:40 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\urlmon.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\scavengeui.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\quartz.dll
2016-10-12 15:20:40 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\WsmWmiPl.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\WSManMigrationPlugin.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\qdvd.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\evr.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2016-10-12 15:20:39 ----A---- C:\Windows\SYSWOW64\AUDIOKSE.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\WsmWmiPl.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
2016-10-12 15:20:39 ----A---- C:\Windows\system32\vbscript.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\qdvd.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\lsasrv.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\evr.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\DWrite.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\drivers\PEAuth.sys
2016-10-12 15:20:39 ----A---- C:\Windows\system32\cryptui.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\audiosrv.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\AUDIOKSE.dll
2016-10-12 15:20:39 ----A---- C:\Windows\system32\AudioEng.dll
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\WSManHTTPConfig.exe
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\ntkrnlpa.exe
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\cryptui.dll
2016-10-12 15:20:38 ----A---- C:\Windows\SYSWOW64\AudioEng.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\WsmAuto.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\win32k.sys
2016-10-12 15:20:38 ----A---- C:\Windows\system32\pcasvc.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\msfeeds.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\mfplat.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\FntCache.dll
2016-10-12 15:20:38 ----A---- C:\Windows\system32\AudioSes.dll
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\WsmAuto.dll
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\ntoskrnl.exe
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\DWrite.dll
2016-10-12 15:20:37 ----A---- C:\Windows\SYSWOW64\AudioSes.dll
2016-10-12 15:20:37 ----A---- C:\Windows\system32\wmploc.DLL
2016-10-12 15:20:37 ----A---- C:\Windows\system32\mfps.dll
2016-10-12 15:20:37 ----A---- C:\Windows\system32\inetcomm.dll
2016-10-12 15:20:37 ----A---- C:\Windows\system32\EncDump.dll
2016-10-12 15:20:37 ----A---- C:\Windows\system32\drivers\mountmgr.sys
2016-10-12 15:20:37 ----A---- C:\Windows\system32\drivers\dfsc.sys
2016-10-12 15:20:37 ----A---- C:\Windows\system32\audiodg.exe
2016-10-12 15:20:36 ----A---- C:\Windows\SYSWOW64\mfps.dll
2016-10-12 15:20:36 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-10-12 15:20:36 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-10-12 15:20:36 ----A---- C:\Windows\SYSWOW64\cryptsp.dll
2016-10-12 15:20:36 ----A---- C:\Windows\system32\MsSpellCheckingFacility.exe
2016-10-12 15:20:36 ----A---- C:\Windows\system32\msscp.dll
2016-10-12 15:20:36 ----A---- C:\Windows\system32\iedkcs32.dll
2016-10-12 15:20:36 ----A---- C:\Windows\system32\cryptsp.dll
2016-10-12 15:20:36 ----A---- C:\Windows\system32\adsmsext.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\WebClnt.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\ntdll.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\msscp.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\mshtmlmedia.dll
2016-10-12 15:20:35 ----A---- C:\Windows\SYSWOW64\adsmsext.dll
2016-10-12 15:20:35 ----A---- C:\Windows\system32\WebClnt.dll
2016-10-12 15:20:35 ----A---- C:\Windows\system32\ntdll.dll
2016-10-12 15:20:35 ----A---- C:\Windows\system32\msnetobj.dll
2016-10-12 15:20:35 ----A---- C:\Windows\system32\drivers\mrxdav.sys
2016-10-12 15:20:35 ----A---- C:\Windows\system32\drivers\ksecpkg.sys
2016-10-12 15:20:35 ----A---- C:\Windows\system32\drivers\ksecdd.sys
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\wsmprovhost.exe
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2016-10-12 15:20:34 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-10-12 15:20:34 ----A---- C:\Windows\system32\wsmprovhost.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\rrinstaller.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\pcawrk.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\pcalua.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\pcadm.dll
2016-10-12 15:20:34 ----A---- C:\Windows\system32\mfpmp.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\ie4uinit.exe
2016-10-12 15:20:34 ----A---- C:\Windows\system32\davclnt.dll
2016-10-12 15:20:34 ----A---- C:\Windows\system32\certcli.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\wsmplpxy.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\INETRES.dll
2016-10-12 15:20:33 ----A---- C:\Windows\SYSWOW64\davclnt.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\wsmplpxy.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\spwmp.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\rpcrt4.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\msmmsp.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\mshtmlmedia.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\jscript.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\INETRES.dll
2016-10-12 15:20:33 ----A---- C:\Windows\system32\dxmasf.dll
2016-10-12 15:20:32 ----A---- C:\Windows\system32\pcaevts.dll
2016-10-12 15:20:32 ----A---- C:\Windows\system32\ieui.dll
2016-10-12 15:20:31 ----A---- C:\Windows\SYSWOW64\rpcrt4.dll
2016-10-12 15:20:31 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2016-10-12 15:20:31 ----A---- C:\Windows\system32\webcheck.dll
2016-10-12 15:20:31 ----A---- C:\Windows\system32\ieapfltr.dll
2016-10-12 15:20:31 ----A---- C:\Windows\system32\dxtrans.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\msrating.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\ieui.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-10-12 15:20:30 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\occache.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\msrating.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\mshtmled.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\kerberos.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\jsproxy.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\jscript9diag.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\dxtmsft.dll
2016-10-12 15:20:30 ----A---- C:\Windows\system32\drivers\mrxsmb.sys
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\sspicli.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\occache.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\kerberos.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\jsproxy.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\jscript9diag.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\inseng.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\ieUnatt.exe
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\ieetwproxystub.dll
2016-10-12 15:20:29 ----A---- C:\Windows\SYSWOW64\dxtmsft.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\wdigest.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\TSpkg.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\sspicli.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\smss.exe
2016-10-12 15:20:29 ----A---- C:\Windows\system32\schannel.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\ncrypt.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\msv1_0.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\MshtmlDac.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\kernel32.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\inseng.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\ieUnatt.exe
2016-10-12 15:20:29 ----A---- C:\Windows\system32\iesetup.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\ieetwproxystub.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\drivers\mrxsmb10.sys
2016-10-12 15:20:29 ----A---- C:\Windows\system32\crypt32.dll
2016-10-12 15:20:29 ----A---- C:\Windows\system32\advapi32.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\WsmRes.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\wdigest.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\schannel.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\mferror.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\JavaScriptCollectionAgent.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\iesetup.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\iernonce.dll
2016-10-12 15:20:28 ----A---- C:\Windows\SYSWOW64\advapi32.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\WsmRes.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\wow64win.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\wintrust.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\winsrv.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\srcore.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\rpchttp.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\mferror.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\lsass.exe
2016-10-12 15:20:28 ----A---- C:\Windows\system32\KernelBase.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\iernonce.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\ieetwcollector.exe
2016-10-12 15:20:28 ----A---- C:\Windows\system32\drivers\mrxsmb20.sys
2016-10-12 15:20:28 ----A---- C:\Windows\system32\cryptsvc.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\cryptnet.dll
2016-10-12 15:20:28 ----A---- C:\Windows\system32\cryptbase.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\wintrust.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\TSpkg.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\rpchttp.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\ncrypt.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\KernelBase.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\cryptsvc.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\cryptnet.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\cryptbase.dll
2016-10-12 15:20:27 ----A---- C:\Windows\SYSWOW64\crypt32.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\wow64.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\sspisrv.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\secur32.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\drivers\appid.sys
2016-10-12 15:20:27 ----A---- C:\Windows\system32\csrsrv.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\credssp.dll
2016-10-12 15:20:27 ----A---- C:\Windows\system32\conhost.exe
2016-10-12 15:20:26 ----A---- C:\Windows\SYSWOW64\secur32.dll
2016-10-12 15:20:26 ----A---- C:\Windows\SYSWOW64\credssp.dll
2016-10-12 15:20:26 ----A---- C:\Windows\system32\wow64cpu.dll
2016-10-12 15:20:26 ----A---- C:\Windows\system32\srclient.dll
2016-10-12 15:20:26 ----A---- C:\Windows\system32\auditpol.exe
2016-10-12 15:20:25 ----A---- C:\Windows\SYSWOW64\srclient.dll
2016-10-12 15:20:25 ----A---- C:\Windows\SYSWOW64\kernel32.dll
2016-10-12 15:20:25 ----A---- C:\Windows\SYSWOW64\appidapi.dll
2016-10-12 15:20:25 ----A---- C:\Windows\system32\setbcdlocale.dll
2016-10-12 15:20:25 ----A---- C:\Windows\system32\rstrui.exe
2016-10-12 15:20:25 ----A---- C:\Windows\system32\ntvdm64.dll
2016-10-12 15:20:25 ----A---- C:\Windows\system32\appidsvc.dll
2016-10-12 15:20:25 ----A---- C:\Windows\system32\appidpolicyconverter.exe
2016-10-12 15:20:25 ----A---- C:\Windows\system32\appidapi.dll
2016-10-12 15:20:23 ----A---- C:\Windows\SYSWOW64\auditpol.exe
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-security-base-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-util-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-string-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-io-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-file-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\SYSWOW64\api-ms-win-core-console-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 15:20:22 ----AH---- C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\wow32.dll
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\user.exe
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\setup16.exe
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\ntvdm64.dll
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\instnm.exe
2016-10-12 15:20:22 ----A---- C:\Windows\SYSWOW64\apisetschema.dll
2016-10-12 15:20:22 ----A---- C:\Windows\system32\appidcertstorecheck.exe
2016-10-12 15:20:22 ----A---- C:\Windows\system32\apisetschema.dll
2016-10-12 15:20:21 ----A---- C:\Windows\SYSWOW64\adtschema.dll
2016-10-12 15:20:21 ----A---- C:\Windows\system32\adtschema.dll
2016-10-12 15:20:20 ----A---- C:\Windows\SYSWOW64\msobjs.dll
2016-10-12 15:20:20 ----A---- C:\Windows\SYSWOW64\msaudite.dll
2016-10-12 15:20:20 ----A---- C:\Windows\system32\msobjs.dll
2016-10-12 15:20:20 ----A---- C:\Windows\system32\msaudite.dll
2016-10-12 15:20:20 ----A---- C:\Windows\system32\ieetwcollectorres.dll
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbuhci.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbport.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbohci.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbhub.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbehci.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbd.sys
2016-10-12 15:19:33 ----A---- C:\Windows\system32\drivers\usbccgp.sys
2016-10-12 15:19:21 ----A---- C:\Windows\SYSWOW64\shell32.dll
2016-10-12 15:19:21 ----A---- C:\Windows\SYSWOW64\explorer.exe
2016-10-12 15:19:21 ----A---- C:\Windows\system32\shell32.dll
2016-10-12 15:19:21 ----A---- C:\Windows\system32\ExplorerFrame.dll
2016-10-12 15:19:21 ----A---- C:\Windows\explorer.exe
2016-10-12 15:19:20 ----A---- C:\Windows\SYSWOW64\ExplorerFrame.dll
2016-10-12 15:19:20 ----A---- C:\Windows\SYSWOW64\authui.dll
2016-10-12 15:19:20 ----A---- C:\Windows\system32\authui.dll
2016-10-12 15:19:10 ----A---- C:\Windows\SYSWOW64\poqexec.exe
2016-10-12 15:19:10 ----A---- C:\Windows\system32\poqexec.exe
2016-10-11 15:16:24 ----D---- C:\Users\Karlos\AppData\Roaming\Mozilla
2016-10-11 15:15:34 ----A---- C:\Users\Karlos\AppData\Roaming\Main.dat
2016-10-11 15:15:34 ----A---- C:\Users\Karlos\AppData\Roaming\agent.dat
2016-10-11 15:15:31 ----A---- C:\Users\Karlos\AppData\Roaming\Silsolex.exe
2016-10-11 15:13:44 ----A---- C:\Users\Karlos\AppData\Roaming\Installer.dat
2016-10-11 15:13:36 ----D---- C:\Users\Karlos\AppData\Roaming\Microleaves
2016-10-09 21:07:03 ----A---- C:\Users\Karlos\AppData\Roaming\Dibg.exe
2016-10-09 21:06:22 ----D---- C:\Users\Karlos\AppData\Roaming\Monitor
2016-10-09 21:06:22 ----D---- C:\ProgramData\Client
2016-10-09 20:41:09 ----HD---- C:\Program Files\Common Files\EAInstaller
2016-10-09 12:59:30 ----A---- C:\Windows\SYSWOW64\vulkaninfo.exe
2016-10-09 12:59:30 ----A---- C:\Windows\SYSWOW64\vulkan-1.dll
2016-10-09 12:59:30 ----A---- C:\Windows\system32\vulkaninfo.exe
2016-10-09 12:59:30 ----A---- C:\Windows\system32\vulkan-1.dll
2016-10-09 12:59:28 ----D---- C:\Program Files (x86)\VulkanRT
2016-10-09 12:38:08 ----D---- C:\_OTM
======List of files/folders modified in the last 1 month======
2016-11-05 12:18:59 ----D---- C:\Program Files\trend micro
2016-11-05 12:06:25 ----D---- C:\Windows\System32
2016-11-05 12:06:25 ----D---- C:\Windows\inf
2016-11-05 12:06:25 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-11-05 12:03:20 ----D---- C:\Windows\temp
2016-11-05 12:00:38 ----D---- C:\ProgramData\Boxtools
2016-11-05 12:00:34 ----D---- C:\Windows
2016-11-05 12:00:29 ----D---- C:\Windows\winsxs
2016-11-05 11:59:38 ----D---- C:\Windows\system32\config
2016-11-05 11:58:02 ----SHD---- C:\Config.Msi
2016-11-05 11:57:04 ----D---- C:\Windows\SYSWOW64\wbem
2016-11-05 11:57:04 ----D---- C:\Windows\SYSWOW64\en-US
2016-11-05 11:57:04 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-11-05 11:57:04 ----D---- C:\Windows\SysWOW64
2016-11-05 11:57:04 ----D---- C:\Windows\system32\wbem
2016-11-05 11:57:04 ----D---- C:\Windows\system32\en-US
2016-11-05 11:57:04 ----D---- C:\Windows\system32\drivers\en-US
2016-11-05 11:57:04 ----D---- C:\Windows\system32\drivers
2016-11-05 11:57:04 ----D---- C:\Windows\system32\cs-CZ
2016-11-05 11:57:04 ----D---- C:\Windows\PolicyDefinitions
2016-11-05 11:57:03 ----RSD---- C:\Windows\Fonts
2016-11-05 11:57:02 ----D---- C:\Windows\system32\DriverStore
2016-11-05 11:56:47 ----SHD---- C:\Windows\Installer
2016-11-05 11:54:52 ----D---- C:\Windows\system32\catroot
2016-11-05 11:51:40 ----SHD---- C:\System Volume Information
2016-11-05 11:50:33 ----D---- C:\Program Files\AMD
2016-11-05 11:48:47 ----D---- C:\AMD
2016-11-05 11:42:00 ----D---- C:\Windows\system32\catroot2
2016-11-05 11:25:19 ----D---- C:\Windows\system32\MRT
2016-11-05 11:25:19 ----D---- C:\Windows\debug
2016-11-05 11:24:57 ----AC---- C:\Windows\system32\MRT.exe
2016-11-05 11:22:57 ----D---- C:\Windows\Microsoft.NET
2016-11-05 11:21:20 ----A---- C:\Windows\SYSWOW64\PerfStringBackup.INI
2016-11-04 02:15:08 ----A---- C:\Windows\system32\coinst_16.40.dll
2016-11-01 13:36:54 ----D---- C:\Windows\system32\Tasks
2016-11-01 13:36:51 ----RD---- C:\Program Files (x86)
2016-11-01 13:27:23 ----D---- C:\ProgramData
2016-10-30 11:58:41 ----D---- C:\ProgramData\Origin
2016-10-30 11:48:51 ----D---- C:\Program Files (x86)\Steam
2016-10-26 17:29:06 ----N---- C:\Windows\system32\MpSigStub.exe
2016-10-21 17:07:46 ----RSD---- C:\Windows\assembly
2016-10-21 16:30:05 ----D---- C:\Users\Karlos\AppData\Roaming\Seznam.cz
2016-10-21 16:20:48 ----D---- C:\ProgramData\Codemasters
2016-10-21 16:17:26 ----D---- C:\Program Files (x86)\Ubisoft
2016-10-21 15:49:22 ----RD---- C:\Program Files
2016-10-21 15:29:42 ----D---- C:\Hry
2016-10-20 18:04:33 ----D---- C:\Program Files (x86)\Intel
2016-10-20 18:04:33 ----D---- C:\Program Files (x86)\Guitar Pro 5
2016-10-20 18:04:33 ----D---- C:\Program Files (x86)\gfx
2016-10-20 18:04:03 ----RD---- C:\Program Files (x86)\Skype
2016-10-20 18:04:03 ----HD---- C:\Program Files (x86)\Uninstall Information
2016-10-20 18:04:03 ----HD---- C:\Program Files (x86)\Temp
2016-10-20 18:04:03 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\WinRAR
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Sidebar
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows NT
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Media Player
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Mail
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Windows Defender
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Webteh
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\VS Revo Group
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\VideoLAN
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\TP-LINK
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\totalcmd
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\SymSilent
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Sony Media Go Install
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Sony
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\sfx
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Seznam.cz
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\SaalDesigner
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Rockstar Games
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Reference Assemblies
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Realtek
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Raptr Inc
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\qst
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\OpenAL
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\MSXML 4.0
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\MSBuild
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft.NET
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Synchronization Services
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Sync Framework
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Office
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft LifeCam
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Games for Windows - LIVE
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Microsoft Analysis Services
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Maxthon
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\logs
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Lavalys
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Internet Explorer
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Chcete byt milionarem PC hra
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Guitar Pro 6
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Google
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\GIGABYTE
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Gaming Mouse
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Future Pinball
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\freebird
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Free mp3 Wma Converter
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Free MP3 Sound Recorder
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Electronic Arts
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\DAEMON Tools Lite
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Counter-Strike 1.6
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Common Files
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\BRS
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\BlazeVideo
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Battlelog Web Plugins
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\ATI Technologies
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\AMD AVT
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\AMD APP
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\AMD
2016-10-20 18:04:03 ----D---- C:\Program Files (x86)\Adobe
2016-10-20 17:45:01 ----D---- C:\Users\Karlos\AppData\Roaming\DAEMON Tools Lite
2016-10-20 17:44:57 ----D---- C:\Users\Karlos\AppData\Roaming\uTorrent
2016-10-20 17:38:24 ----D---- C:\Windows\Logs
2016-10-18 03:39:58 ----A---- C:\Windows\system32\SET147.tmp
2016-10-14 17:48:43 ----D---- C:\Program Files\Windows Media Player
2016-10-14 17:48:43 ----D---- C:\Program Files\Internet Explorer
2016-10-14 17:48:42 ----D---- C:\Windows\SYSWOW64\Dism
2016-10-14 17:48:38 ----D---- C:\Windows\system32\Dism
2016-10-14 17:48:31 ----D---- C:\Windows\AppPatch
2016-10-14 17:48:30 ----D---- C:\Windows\system32\Boot
2016-10-14 17:48:29 ----SD---- C:\Windows\system32\CompatTel
2016-10-14 17:48:29 ----D---- C:\Windows\system32\appraiser
2016-10-14 17:48:27 ----D---- C:\Windows\system32\drivers\cs-CZ
2016-10-14 17:48:25 ----D---- C:\Windows\cs-CZ
2016-10-14 17:47:20 ----D---- C:\Program Files\Microsoft Silverlight
2016-10-12 19:17:32 ----D---- C:\ProgramData\Microsoft Help
2016-10-12 15:39:33 ----D---- C:\ProgramData\Package Cache
2016-10-12 14:56:46 ----D---- C:\Windows\LiveKernelReports
2016-10-11 17:21:26 ----D---- C:\Users\Karlos\AppData\Roaming\Turbo Booster for uTorrent
2016-10-11 16:09:59 ----D---- C:\Program Files\Enigma Software Group
2016-10-11 15:22:14 ----D---- C:\AdwCleaner
2016-10-11 15:13:44 ----D---- C:\Windows\Tasks
2016-10-09 20:41:09 ----D---- C:\Program Files\Common Files
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 epfwwfp;epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [2015-07-14 72400]
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys [2011-11-29 568600]
R0 iusb3hcs;Ovladač přepínání hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hcs.sys [2012-01-27 16152]
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys [2010-11-21 213888]
R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver; C:\Windows\system32\DRIVERS\dtsoftbus01.sys [2013-12-27 283064]
R1 eamonm;eamonm; C:\Windows\system32\DRIVERS\eamonm.sys [2015-07-14 255240]
R1 ehdrv;ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [2015-07-14 178520]
R1 EpfwLWF;Epfw NDIS LightWeight Filter; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2015-07-14 53360]
R1 VWiFiFlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
R2 epfw;epfw; C:\Windows\system32\DRIVERS\epfw.sys [2015-07-14 231520]
R3 amdkmdag;amdkmdag; C:\Windows\system32\DRIVERS\atikmdag.sys [2016-11-04 26558976]
R3 amdkmdap;amdkmdap; C:\Windows\system32\DRIVERS\atikmpag.sys [2016-11-04 520072]
R3 athur;Wireless Network Adapter Service; C:\Windows\system32\DRIVERS\athurx.sys [2014-05-23 1930240]
R3 AtiHDAudioService;AMD Function Driver for HD Audio Service; C:\Windows\system32\drivers\AtihdW76.sys [2016-03-30 96256]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys [2012-01-17 4734440]
R3 iusb3hub;Ovladač rozbočovače Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3hub.sys [2012-01-27 356120]
R3 iusb3xhc;Ovladač rozšiřitelného hostitelského řadiče Intel(R) USB 3.0; C:\Windows\system32\DRIVERS\iusb3xhc.sys [2012-01-27 787736]
R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2016-03-10 27008]
R3 RTL8167;Realtek 8167 NT Driver; C:\Windows\system32\DRIVERS\Rt64win7.sys [2011-09-29 646248]
R3 vwifimp;Microsoft Virtual WiFi Miniport Service; C:\Windows\system32\DRIVERS\vwifimp.sys [2009-07-14 17920]
S3 BridgeMP;@%SystemRoot%\system32\bridgeres.dll,-1; C:\Windows\system32\DRIVERS\bridge.sys [2009-07-14 95232]
S3 DrvAgent64;DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS []
S3 etdrv;etdrv; \??\C:\Windows\etdrv.sys [2014-01-19 25640]
S3 gdrv;gdrv; \??\C:\Windows\gdrv.sys [2014-05-29 25640]
S3 GVTDrv64;GVTDrv64; \??\C:\Windows\GVTDrv64.sys [2014-05-29 30528]
S3 IT9135BDA;IT9135 BDA Devices; C:\Windows\System32\Drivers\IT9135BDA.sys [2013-12-31 165504]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [2016-10-21 192216]
S3 MBAMWebAccessControl;MBAMWebAccessControl; \??\C:\Windows\system32\drivers\mwac.sys [2016-03-10 64896]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver; C:\Windows\System32\Drivers\nx6000.sys [2010-12-13 36720]
S3 nmwcdnsux64;Nokia USB Flashing Phone Parent; C:\Windows\system32\drivers\nmwcdnsux64.sys [2011-08-17 171008]
S3 pciide;pciide; C:\Windows\system32\drivers\pciide.sys [2009-07-14 12352]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver; C:\Windows\System32\drivers\rdpvideominiport.sys [2012-08-23 19456]
S3 RTHDMIAzAudService;Service for HDMI; C:\Windows\system32\drivers\RtHDMIVX.sys [2011-12-02 239208]
S3 TRIDCap;AVerMedia service; C:\Windows\system32\DRIVERS\AVerTM62_x64.sys [2013-10-08 1103744]
S3 TsUsbFlt;TsUsbFlt; C:\Windows\system32\drivers\tsusbflt.sys [2013-10-02 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device; C:\Windows\system32\drivers\TsUsbGD.sys [2012-08-23 30208]
S3 usbscan;Ovladač skeneru USB; C:\Windows\system32\DRIVERS\usbscan.sys [2013-07-03 42496]
S3 WinUsb;WinUsb; C:\Windows\system32\DRIVERS\WinUsb.sys [2010-11-21 41984]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AMD External Events Utility;AMD External Events Utility; C:\Windows\system32\atiesrxx.exe [2016-11-04 289160]
R2 Archer;Archer; C:\Windows\SysWOW64\svchost.exe [2009-07-14 20992]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2016-07-14 107192]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2016-07-14 128696]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; C:\Windows\System32\svchost.exe [2009-07-14 27136]
R2 ekrn;ESET Service; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [2015-07-08 1353720]
R2 IAStorDataMgrSvc;Úložná technologie Intel(R) Rapid; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-11-29 13592]
R2 InterHop;InterHop; C:\Program Files (x86)\InterHop\InterHop.exe [2016-10-31 430592]
R2 MSCamSvc;MSCamSvc; C:\Program Files\Microsoft LifeCam\MSCamS64.exe [2010-12-13 194416]
R2 PnkBstrA;PnkBstrA; C:\Windows\syswow64\PnkBstrA.exe [2014-07-27 76888]
R2 Shewoied;Shewoied; C:\Windows\system32\svchost.exe [2009-07-14 27136]
R2 WinSAPSvc;WinSAPSvc; C:\Windows\SysWOW64\svchost.exe [2009-07-14 20992]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-08-18 2291568]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S2 MBAMService;MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [2016-03-10 1136608]
S2 Origin Web Helper Service;Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2016-10-30 2209296]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27 144200]
S3 ICCS;Intel(R) Integrated Clock Controller Service - Intel(R) ICCS; C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe [2011-08-30 160256]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S3 IEEtwCollectorService;@%SystemRoot%\system32\ieetwcollectorres.dll,-1000; C:\Windows\system32\IEEtwCollector.exe [2016-09-30 114688]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2013-12-19 30814400]
S3 Origin Client Service;Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2016-10-30 2142728]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-03-31 835664]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe [2013-12-29 1255736]
S4 aspnet_state;Stavová služba ASP.NET; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-14 52920]
S4 NetMsmqActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8195; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
S4 NetPipeActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8197; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
S4 NetTcpActivator;@C:\Windows\Microsoft.NET\Framework64\v4.0.30319\\ServiceModelInstallRC.dll,-8199; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe [2016-07-14 136360]
-----------------EOF-----------------
- Rudy
- Site Admin

- Příspěvky: 119672
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Antivir našel vir a nejde smazat
Herní problematiku neřešíme. Jak zní ta hláška?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Re: Antivir našel vir a nejde smazat
Omluva...herní problematiku už jsem vyřešil.
Text zní takto:
V součásti aplikace došlo k neošetřené výjímce. Pokud klepnete na tlačítko Pokračovat aplikace bude tuto hcybu ignorovat a pokusí se pokračovat. Pokud klepnete na tlačítko Konec. bude aplikace okamžitě ukončena.
Toto je text z podrobností:
System.Reflection.TargetInvocationException: Cíl vyvolání způsobil výjimku. ---> System.Exception: Byla vyvolána výjimka typu System.Exception.
v ClassLibrary1.A.main()
--- Konec trasování zásobníku pro vnitřní výjimku ---
v Microsoft.VisualBasic.CompilerServices.LateBinding.InternalLateCall(Object o, Type objType, String name, Object[] args, String[] paramnames, Boolean[] CopyBack, Boolean IgnoreReturn)
v Microsoft.VisualBasic.Interaction.CallByName(Object ObjectRef, String ProcName, CallType UseCallType, Object[] Args)
v NNNNNNNN.Form1.sKGlar3XiURTGnbPqW(Object , Object , CallType , Object )
v NNNNNNNN.Form1.Invoke_F(Object Invoked, String ProcName)
v NNNNNNNN.Form1.gCxU6NmuR(Object , EventArgs )
v System.Windows.Forms.Form.OnLoad(EventArgs e)
v System.Windows.Forms.Control.CreateControl(Boolean fIgnoreVisible)
v System.Windows.Forms.Control.CreateControl()
v System.Windows.Forms.Control.WmShowWindow(Message& m)
v System.Windows.Forms.Control.WndProc(Message& m)
v System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
v System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)
Text zní takto:
V součásti aplikace došlo k neošetřené výjímce. Pokud klepnete na tlačítko Pokračovat aplikace bude tuto hcybu ignorovat a pokusí se pokračovat. Pokud klepnete na tlačítko Konec. bude aplikace okamžitě ukončena.
Toto je text z podrobností:
System.Reflection.TargetInvocationException: Cíl vyvolání způsobil výjimku. ---> System.Exception: Byla vyvolána výjimka typu System.Exception.
v ClassLibrary1.A.main()
--- Konec trasování zásobníku pro vnitřní výjimku ---
v Microsoft.VisualBasic.CompilerServices.LateBinding.InternalLateCall(Object o, Type objType, String name, Object[] args, String[] paramnames, Boolean[] CopyBack, Boolean IgnoreReturn)
v Microsoft.VisualBasic.Interaction.CallByName(Object ObjectRef, String ProcName, CallType UseCallType, Object[] Args)
v NNNNNNNN.Form1.sKGlar3XiURTGnbPqW(Object , Object , CallType , Object )
v NNNNNNNN.Form1.Invoke_F(Object Invoked, String ProcName)
v NNNNNNNN.Form1.gCxU6NmuR(Object , EventArgs )
v System.Windows.Forms.Form.OnLoad(EventArgs e)
v System.Windows.Forms.Control.CreateControl(Boolean fIgnoreVisible)
v System.Windows.Forms.Control.CreateControl()
v System.Windows.Forms.Control.WmShowWindow(Message& m)
v System.Windows.Forms.Control.WndProc(Message& m)
v System.Windows.Forms.Control.ControlNativeWindow.WndProc(Message& m)
v System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)
- Rudy
- Site Admin

- Příspěvky: 119672
- Registrován: 30 říj 2003 13:42
- Bydliště: Plzeň
- Kontaktovat uživatele:
Re: Antivir našel vir a nejde smazat
Pokuste se .NET framework opravit podle: https://support.microsoft.com/cs-cz/kb/908077 . V sedmičkách by to mělo být podobné.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:
e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.
Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.
Navštivte:

e-mail: rudy(zavináč)forum.viry.cz
Varování: Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!
Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Přispějete na provoz fóra?