Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Svchost a Installer Worker vytěžuje disk

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
krajta5
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 03 črc 2013 16:43

Svchost a Installer Worker vytěžuje disk

#1 Příspěvek od krajta5 »

Dobrý den
Začal jsem mít problém s notebookem. Nejprve zablikala obrazovka, poté zamrzl start a ve správci úloh jsem viděl plné vytížení disku procesy svchost a Installer Worker. Notebook je skoro nový a nemyslím si že by se to týkalo aktualizací Windows tak raději píšu sem kdyby to bylo něco horšího. Občas se to stává a notebook je v tu chvíli nepoužitelný. Zamrzne. Děkuji všem za pomoc. :)

Logfile of random's system information tool 1.14 (written by random/random)
Run by Anetka at 2016-12-06 18:05:29
Microsoft Windows 8.1 Pro N
System drive C: has 405 GB (81%) free of 500 GB
Total RAM: 4016 MB (48% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 18:13:50, on 6. 12. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
C:\Program Files\trend micro\Anetka_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [Autodesk Desktop App] "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
O4 - HKLM\..\Run: [Avira System Speedup User Starter] "C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKCU\..\Run: [SSMaker2] "C:\Users\Anetka\AppData\Roaming\ScreenMaker2\SSMaker.exe"
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Anetka\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - Startup: Poslat do aplikace OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Startup: zSpeedup.lnk = C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe
O4 - Global Startup: CodeMeter Control Center.lnk = C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{83962CAD-4E16-4DE0-BDE0-6B37999F69A9}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{83962CAD-4E16-4DE0-BDE0-6B37999F69A9}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O23 - Service: Autodesk Desktop App Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Avira Phantom VPN (AviraPhantomVPN) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
O23 - Service: CodeMeter Runtime Server (CodeMeter.exe) - WIBU-SYSTEMS AG - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel Bluetooth Service (ibtsiva.exe) - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Avira System Speedup (SpeedupService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 12652 bytes

======Enumerating Processes======

C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\dwm.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 195390720912
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe"
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
"C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe"
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhostex.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
"C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe" -autorun
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\Windows\system32\CxAudMsg64.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Elantech\ETDService.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
"C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_00000694
C:\Windows\system32\SearchIndexer.exe /Embedding
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\dashost.exe
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files\Autodesk\Personal Accelerator for Revit\RevitAccelerator.exe"
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
"C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe" scan upload
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\igfxEM.exe
C:\Windows\system32\igfxHK.exe
C:\Windows\system32\igfxTray.exe
"C:\Windows\explorer.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 1 0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=54.0.2840.99 --handshake-handle=0x10c
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DisallowFetchForDocWrittenScriptsInMainFrame/Control_5/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/NonValidatingReloadOnNormalReload/Enabled2/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/StrictSecureCookies/Disabled/SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,15,16,17,20,34,51,60 --gpu-vendor-id=0x8086 --gpu-device-id=0x1616 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=20.19.15.4531 --gpu-driver-date=9-29-2016 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x1299 --mojo-application-channel-token=61C9AC9313DACB7B9E1338D03F05E1A8 --mojo-platform-channel-handle=1148 --ignored=" --type=renderer " /prefetch:2
"C:\Users\Anetka\Desktop\RSITx64.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DisallowFetchForDocWrittenScriptsInMainFrame/Control_5/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/*EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*NonValidatingReloadOnNormalReload/Enabled2/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/*StrictSecureCookies/Disabled/*SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --primordial-pipe-token=8407CEC389F904E649343DB02AE1B57C --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553 --mojo-application-channel-token=8407CEC389F904E649343DB02AE1B57C --channel="2472.8.339741915\956379934" --mojo-platform-channel-handle=3716 /prefetch:1
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\taskmgr.exe" /0
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe15_ Global\UsGthrCtrlFltPipeMssGthrPipe15 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 536 564 572 65536 568

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player PPAPI Notifier.job - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe -check pepperplugin
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe -check pepperplugin
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Avira System Speedup Tray - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe -autorun
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4117213250-101706349-321446703-1001 - %localappdata%\Microsoft\OneDrive\OneDrive.exe /autoupdate
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\OneDrive Standalone Update Task - C:\Users\Anetka\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
C:\Windows\system32\tasks\User_Feed_Synchronization-{2CA74BE9-FC3D-4F1E-9408-B22E2F955737} - C:\Windows\system32\msfeedssync.exe sync
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-4117213250-101706349-321446703-1001 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\Windows\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\Windows\System32\mcbuilder.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent /increment
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\Windows\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\Windows\system32\tasks\Microsoft\Office\Office Subscription Maintenance - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 - C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe scan upload mininterval:2880
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 - C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe scan upload
C:\Windows\system32\tasks\Lenovo\Lenovo Customer Feedback Program 64 - "%ProgramFiles(x86)%\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe"

=========Google Chrome=========

C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension flliilndjeohchalpbbcdekjklbdgfkk 0 Avira Browser Safety 2.0.0
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5416.905.0.6
Homepage:
default_search_provider.search_url:
C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk]
"Path"=


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-11-16 213192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-11-16 2099504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-11-16 154824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2016-11-23 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-11-16 1522472]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2016-11-23 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2014-08-20 3282248]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-25 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2014-04-09 1830616]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2014-11-20 919768]
"pac"=C:\Program Files\Autodesk\Personal Accelerator for Revit\RevitAccelerator.exe [2016-02-10 339464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SSMaker2"=C:\Users\Anetka\AppData\Roaming\ScreenMaker2\SSMaker.exe []
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2016-07-29 4299968]
"Akamai NetSession Interface"=C:\Users\Anetka\AppData\Local\Akamai\netsession_win.exe [2015-09-10 4691384]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-10-13 2860832]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"snp2uvc"=C:\Windows\vsnp2uvc.exe []
"Autodesk Desktop App"=C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [2016-07-01 721856]
"Avira SystrayStartTrigger"=C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2016-11-25 60120]
"Avira System Speedup User Starter"=C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [2016-11-23 25256]
"avgnt"=C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2016-10-17 916072]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
CodeMeter Control Center.lnk - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe

C:\Users\Anetka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Poslat do aplikace OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
zSpeedup.lnk - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2016-12-06 18:05:30 ----D---- C:\Program Files\trend micro
2016-12-06 18:05:29 ----D---- C:\rsit
2016-12-06 17:55:48 ----D---- C:\Windows\LastGood
2016-12-05 17:44:16 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2016-12-05 17:44:16 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2016-12-05 17:44:16 ----A---- C:\Windows\system32\XAudio2_6.dll
2016-12-05 17:44:16 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2016-12-05 17:44:15 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2016-12-05 17:44:15 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2016-12-05 17:44:15 ----A---- C:\Windows\system32\xactengine3_6.dll
2016-12-05 17:44:15 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2016-12-05 17:44:13 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2016-12-05 17:44:13 ----A---- C:\Windows\system32\XAudio2_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2016-12-05 17:44:12 ----A---- C:\Windows\system32\xactengine3_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\system32\d3dx11_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\system32\d3dcsx_42.dll
2016-12-05 17:44:10 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2016-12-05 17:44:10 ----A---- C:\Windows\system32\d3dx10_42.dll
2016-12-05 17:44:09 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2016-12-05 17:44:09 ----A---- C:\Windows\system32\D3DX9_42.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\D3DX9_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\d3dx10_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\XAudio2_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\xactengine3_4.dll
2016-12-05 17:44:06 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2016-12-05 17:44:06 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\D3DX9_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\d3dx10_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\XAudio2_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\xactengine3_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\XAudio2_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\xactengine3_2.dll
2016-12-05 17:44:00 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\system32\d3dx10_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2016-12-05 17:43:59 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2016-12-05 17:43:59 ----A---- C:\Windows\system32\D3DX9_39.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\XAudio2_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\xactengine3_1.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\d3dx10_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2016-12-05 17:43:56 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2016-12-05 17:43:56 ----A---- C:\Windows\system32\D3DX9_38.dll
2016-12-05 17:43:55 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\system32\XAudio2_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\system32\xactengine3_0.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\d3dx10_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2016-12-05 17:43:53 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2016-12-05 17:43:53 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2016-12-05 17:43:53 ----A---- C:\Windows\system32\xactengine2_10.dll
2016-12-05 17:43:53 ----A---- C:\Windows\system32\D3DX9_37.dll
2016-12-05 17:43:52 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\system32\d3dx10_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2016-12-05 17:43:51 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2016-12-05 17:43:51 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2016-12-05 17:43:51 ----A---- C:\Windows\system32\xactengine2_9.dll
2016-12-05 17:43:51 ----A---- C:\Windows\system32\d3dx9_36.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\d3dx9_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\d3dx10_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\xactengine2_8.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\d3dx10_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2016-12-05 17:43:48 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2016-12-05 17:43:48 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2016-12-05 17:43:48 ----A---- C:\Windows\system32\xinput1_3.dll
2016-12-05 17:43:48 ----A---- C:\Windows\system32\d3dx9_34.dll
2016-12-05 17:43:47 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2016-12-05 17:43:47 ----A---- C:\Windows\system32\xactengine2_7.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\d3dx9_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\d3dx10_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2016-12-05 17:43:45 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2016-12-05 17:43:45 ----A---- C:\Windows\system32\xactengine2_6.dll
2016-12-05 17:43:44 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2016-12-05 17:43:44 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2016-12-05 17:43:44 ----A---- C:\Windows\system32\xactengine2_5.dll
2016-12-05 17:43:44 ----A---- C:\Windows\system32\d3dx10.dll
2016-12-05 17:43:43 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2016-12-05 17:43:43 ----A---- C:\Windows\system32\d3dx9_32.dll
2016-12-05 17:43:42 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2016-12-05 17:43:42 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2016-12-05 17:43:42 ----A---- C:\Windows\system32\xactengine2_4.dll
2016-12-05 17:43:42 ----A---- C:\Windows\system32\x3daudio1_1.dll
2016-12-05 17:43:41 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2016-12-05 17:43:41 ----A---- C:\Windows\system32\d3dx9_31.dll
2016-12-05 17:43:40 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2016-12-05 17:43:40 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2016-12-05 17:43:40 ----A---- C:\Windows\system32\xinput1_2.dll
2016-12-05 17:43:40 ----A---- C:\Windows\system32\xactengine2_3.dll
2016-12-05 17:43:39 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2016-12-05 17:43:39 ----A---- C:\Windows\system32\xactengine2_2.dll
2016-12-05 17:43:21 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2016-12-05 17:43:21 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2016-12-05 17:43:21 ----A---- C:\Windows\system32\xactengine2_0.dll
2016-12-05 17:43:21 ----A---- C:\Windows\system32\d3dx9_29.dll
2016-12-05 17:43:20 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2016-12-05 17:43:20 ----A---- C:\Windows\system32\d3dx9_28.dll
2016-12-05 17:43:19 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2016-12-05 17:43:19 ----A---- C:\Windows\system32\d3dx9_27.dll
2016-12-05 17:43:18 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2016-12-05 17:43:18 ----A---- C:\Windows\system32\d3dx9_26.dll
2016-12-05 17:43:17 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2016-12-05 17:43:17 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2016-12-05 17:43:17 ----A---- C:\Windows\system32\d3dx9_25.dll
2016-12-05 17:43:17 ----A---- C:\Windows\system32\d3dx9_24.dll
2016-12-05 16:14:25 ----A---- C:\Windows\system32\drivers\avusbflt.sys
2016-12-05 16:13:28 ----D---- C:\Program Files (x86)\Steam
2016-12-05 16:12:38 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avipbb.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2016-12-05 16:07:25 ----SHD---- C:\Config.Msi
2016-12-05 16:06:11 ----D---- C:\Users\Anetka\AppData\Roaming\Mozilla
2016-12-05 16:05:59 ----D---- C:\Program Files (x86)\Avira
2016-12-05 16:05:57 ----D---- C:\ProgramData\Avira
2016-12-05 15:43:48 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2016-12-05 15:43:45 ----D---- C:\Program Files (x86)\VulkanRT
2016-12-05 15:42:27 ----D---- C:\Windows\LastGood.Tmp
2016-12-05 15:40:43 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-12-05 15:40:43 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-12-05 15:40:42 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-12-05 15:40:42 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-12-05 15:40:41 ----A---- C:\Windows\system32\nvopencl.dll
2016-12-05 15:40:40 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvinitx.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvIFR64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvFBC64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-12-05 15:40:38 ----A---- C:\Windows\system32\nvdispgenco6437609.dll
2016-12-05 15:40:38 ----A---- C:\Windows\system32\nvdispco6437609.dll
2016-12-05 15:40:37 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-12-05 15:40:37 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-12-05 15:40:37 ----A---- C:\Windows\system32\nvcuvid.dll
2016-12-05 15:40:37 ----A---- C:\Windows\system32\nvcuda.dll
2016-12-05 15:40:36 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-12-05 15:40:34 ----A---- C:\Windows\system32\nvcompiler.dll
2016-12-05 15:40:33 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-12-05 15:30:59 ----A---- C:\Windows\system32\NvRtmpStreamer64.dll
2016-12-05 15:30:58 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2016-12-05 15:30:58 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2016-12-05 15:30:58 ----A---- C:\Windows\system32\nvspcap64.dll
2016-12-05 15:30:58 ----A---- C:\Windows\system32\nvspbridge64.dll
2016-12-05 15:30:34 ----A---- C:\Windows\NvContainerRecovery.bat
2016-12-05 15:30:21 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2016-12-05 15:30:21 ----A---- C:\Windows\system32\nvaudcap64v.dll
2016-12-05 15:30:21 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2016-11-25 19:24:37 ----D---- C:\Users\Anetka\AppData\Roaming\NVIDIA
2016-11-25 19:24:31 ----D---- C:\Users\Anetka\AppData\Roaming\MAXON
2016-11-24 20:09:30 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2016-11-24 20:09:30 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2016-11-24 20:09:28 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2016-11-24 20:09:28 ----A---- C:\Windows\system32\wpdshext.dll
2016-11-24 20:07:48 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.dll
2016-11-24 20:07:48 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2016-11-24 20:07:44 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2016-11-24 20:07:44 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\wmploc.DLL
2016-11-24 20:07:30 ----A---- C:\Windows\system32\wmp.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\Windows.Media.Streaming.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\mfsvr.dll
2016-11-24 20:07:10 ----A---- C:\Windows\SYSWOW64\WMASF.DLL
2016-11-24 20:07:10 ----A---- C:\Windows\system32\WMASF.DLL
2016-11-24 18:46:30 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2016-11-24 18:46:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2016-11-24 18:46:30 ----A---- C:\Windows\system32\XAudio2_7.dll
2016-11-24 18:46:30 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2016-11-24 18:46:29 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2016-11-24 18:46:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2016-11-24 18:46:29 ----A---- C:\Windows\system32\xactengine3_7.dll
2016-11-24 18:46:29 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\system32\d3dx11_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\system32\d3dcsx_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\system32\D3DX9_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\system32\d3dx10_43.dll
2016-11-24 18:46:26 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2016-11-24 18:46:26 ----A---- C:\Windows\system32\xinput1_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2016-11-24 18:46:25 ----A---- C:\Windows\system32\xactengine2_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\system32\x3daudio1_0.dll
2016-11-24 18:46:18 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2016-11-24 18:46:18 ----A---- C:\Windows\system32\d3dx9_30.dll
2016-11-24 18:40:23 ----A---- C:\Windows\SYSWOW64\mfds.dll
2016-11-24 18:40:23 ----A---- C:\Windows\system32\mfds.dll
2016-11-24 17:08:05 ----D---- C:\Program Files\WIBU-SYSTEMS
2016-11-24 17:07:57 ----D---- C:\ProgramData\CodeMeter
2016-11-24 17:07:57 ----D---- C:\Program Files\CodeMeter
2016-11-24 17:07:57 ----D---- C:\Program Files (x86)\CodeMeter
2016-11-24 17:01:50 ----D---- C:\Program Files\GRAPHISOFT
2016-11-24 15:17:15 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2016-11-24 15:17:14 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2016-11-24 15:17:14 ----A---- C:\Windows\system32\WMVCORE.DLL
2016-11-24 15:17:13 ----A---- C:\Windows\system32\MSAudDecMFT.dll
2016-11-24 15:17:12 ----A---- C:\Windows\SYSWOW64\WMVCORE.DLL
2016-11-24 15:17:12 ----A---- C:\Windows\SYSWOW64\MSAudDecMFT.dll
2016-11-24 15:17:12 ----A---- C:\Windows\system32\wmpmde.dll
2016-11-24 15:17:11 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2016-11-24 15:17:11 ----A---- C:\Windows\system32\blackbox.dll
2016-11-24 15:17:09 ----A---- C:\Windows\system32\winmde.dll
2016-11-24 15:17:08 ----A---- C:\Windows\SYSWOW64\mfasfsrcsnk.dll
2016-11-24 15:17:08 ----A---- C:\Windows\system32\drmv2clt.dll
2016-11-24 15:17:07 ----A---- C:\Windows\SYSWOW64\winmde.dll
2016-11-24 15:17:07 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2016-11-24 15:17:07 ----A---- C:\Windows\system32\WMPDMC.exe
2016-11-24 15:17:07 ----A---- C:\Windows\system32\WMNetMgr.dll
2016-11-24 15:17:07 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2016-11-24 15:17:06 ----A---- C:\Windows\system32\MFMediaEngine.dll
2016-11-24 15:17:05 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2016-11-24 15:17:04 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2016-11-24 15:17:04 ----A---- C:\Windows\system32\mfsrcsnk.dll
2016-11-24 15:17:04 ----A---- C:\Windows\system32\mfplat.dll
2016-11-24 15:17:03 ----A---- C:\Windows\SYSWOW64\WMPDMC.exe
2016-11-24 15:17:03 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2016-11-24 15:17:02 ----A---- C:\Windows\SYSWOW64\WMNetMgr.dll
2016-11-24 15:17:02 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2016-11-24 15:17:02 ----A---- C:\Windows\system32\Windows.Media.dll
2016-11-24 15:17:01 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2016-11-24 15:17:01 ----A---- C:\Windows\system32\mf.dll
2016-11-24 15:17:00 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2016-11-24 15:17:00 ----A---- C:\Windows\system32\wmdrmdev.dll
2016-11-24 15:17:00 ----A---- C:\Windows\system32\WebcamUi.dll
2016-11-24 15:16:59 ----A---- C:\Windows\SYSWOW64\wmdrmdev.dll
2016-11-24 15:16:59 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-11-24 15:16:59 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2016-11-24 15:16:59 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2016-11-24 15:16:58 ----A---- C:\Windows\SYSWOW64\MSMPEG2ENC.DLL
2016-11-24 15:16:58 ----A---- C:\Windows\system32\wmdrmnet.dll
2016-11-24 15:16:57 ----A---- C:\Windows\SYSWOW64\WebcamUi.dll
2016-11-24 15:16:57 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2016-11-24 15:16:57 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\wmdrmnet.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2016-11-24 15:16:55 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\mswmdm.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\msscp.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2016-11-24 15:16:55 ----A---- C:\Windows\system32\mfreadwrite.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\CameraSettingsUIHost.exe
2016-11-24 15:16:54 ----A---- C:\Windows\SYSWOW64\mswmdm.dll
2016-11-24 15:16:54 ----A---- C:\Windows\SYSWOW64\MSAC3ENC.DLL
2016-11-24 15:16:54 ----A---- C:\Windows\system32\MDEServer.exe
2016-11-24 15:16:54 ----A---- C:\Windows\system32\DMRServer.exe
2016-11-24 15:16:53 ----A---- C:\Windows\SYSWOW64\msscp.dll
2016-11-24 15:16:53 ----A---- C:\Windows\SYSWOW64\MFCaptureEngine.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\WPDSp.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\wmpeffects.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\MFCaptureEngine.dll
2016-11-24 15:16:52 ----A---- C:\Windows\SYSWOW64\msvproc.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\WmpDui.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\MFPlay.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\dlnashext.dll
2016-11-24 15:16:50 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2016-11-24 15:16:50 ----A---- C:\Windows\system32\msvproc.dll
2016-11-24 15:16:50 ----A---- C:\Windows\system32\mftranscode.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\WPDSp.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\wmvdspa.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\mftranscode.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\mfh264enc.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\dlnashext.dll
2016-11-24 15:16:49 ----A---- C:\Windows\system32\wmvdspa.dll
2016-11-24 15:16:49 ----A---- C:\Windows\system32\mfh264enc.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\WmpDui.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\MSVideoDSP.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\wmpps.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\wmidx.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\MSVideoDSP.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\cewmdm.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\wmidx.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\PortableDeviceTypes.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\mfdvdec.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\audiodev.dll
2016-11-24 15:16:47 ----A---- C:\Windows\system32\PortableDeviceWiaCompat.dll
2016-11-24 15:16:47 ----A---- C:\Windows\system32\msnetobj.dll
2016-11-24 15:16:46 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\wmpdxm.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\mfdvdec.dll
2016-11-24 15:16:45 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2016-11-24 15:16:45 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\WPDShServiceObj.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\unregmp2.exe
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\PortableDeviceWMDRM.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\PortableDeviceWiaCompat.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\mfmjpegdec.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\mfAACEnc.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\wpd_ci.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\PortableDeviceStatus.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\PortableDeviceClassExtension.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\logagent.exe
2016-11-24 15:16:43 ----A---- C:\Windows\system32\mfAACEnc.dll
2016-11-24 15:16:43 ----A---- C:\Windows\system32\logagent.exe
2016-11-24 15:16:42 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2016-11-24 15:16:42 ----A---- C:\Windows\SYSWOW64\PortableDeviceConnectApi.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\wmpshell.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\Windows.Media.Renewal.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\mfmjpegdec.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\wmpps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.ps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\CameraSettingsUIHost.exe
2016-11-24 15:16:41 ----A---- C:\Windows\system32\Windows.Media.Streaming.ps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\system32\rrinstaller.exe
2016-11-24 15:16:41 ----A---- C:\Windows\system32\mfpmp.exe
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\WPDShextAutoplay.exe
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\wmdmps.dll
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\wmdmlog.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2016-11-24 15:16:40 ----A---- C:\Windows\system32\wmdmps.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\wmdmlog.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\unregmp2.exe
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\wmcodecdspps.dll
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\LAPRXY.DLL
2016-11-24 15:16:39 ----A---- C:\Windows\system32\wmcodecdspps.dll
2016-11-24 15:16:39 ----A---- C:\Windows\system32\spwmp.dll
2016-11-24 15:16:39 ----A---- C:\Windows\system32\LAPRXY.DLL
2016-11-24 15:16:38 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2016-11-24 15:16:38 ----A---- C:\Windows\system32\dxmasf.dll
2016-11-23 18:48:30 ----A---- C:\Windows\system32\msmpeg2adec.dll
2016-11-23 18:48:29 ----A---- C:\Windows\SYSWOW64\msmpeg2adec.dll
2016-11-23 18:48:29 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2016-11-23 18:48:29 ----A---- C:\Windows\system32\WMVDECOD.DLL
2016-11-23 18:48:29 ----A---- C:\Windows\system32\mfcore.dll
2016-11-23 18:48:28 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2016-11-23 18:48:28 ----A---- C:\Windows\system32\WMVENCOD.DLL
2016-11-23 18:48:28 ----A---- C:\Windows\system32\mfnetsrc.dll
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\WMVENCOD.DLL
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\mfnetsrc.dll
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\mfnetcore.dll
2016-11-23 18:48:27 ----A---- C:\Windows\system32\mfnetcore.dll
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\WMADMOE.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\WMADMOD.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\evr.dll
2016-11-23 18:48:26 ----A---- C:\Windows\system32\WMADMOD.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\system32\evr.dll
2016-11-23 18:48:25 ----A---- C:\Windows\SYSWOW64\WMVSDECD.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\SYSWOW64\WMSPDMOE.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\system32\WMVSDECD.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\system32\WMADMOE.DLL
2016-11-23 18:48:24 ----A---- C:\Windows\SYSWOW64\MP4SDECD.DLL
2016-11-23 18:48:23 ----A---- C:\Windows\system32\WMSPDMOE.DLL
2016-11-23 18:48:22 ----A---- C:\Windows\SYSWOW64\MFWMAAEC.DLL
2016-11-23 18:48:22 ----A---- C:\Windows\system32\WMVSENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\WMVXENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\WMVSENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\VIDRESZR.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\MPG4DECD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\COLORCNV.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\WMVXENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\MP4SDECD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\MFWMAAEC.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\RESAMPLEDMO.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\MP43DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\MP3DMOD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\mfvdsp.dll
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\mfps.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\VIDRESZR.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\RESAMPLEDMO.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MPG4DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MP43DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MP3DMOD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\mfvdsp.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\mfps.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\COLORCNV.DLL
2016-11-23 18:45:50 ----A---- C:\Windows\system32\wpdbusenum.dll
2016-11-23 17:05:53 ----D---- C:\Users\Anetka\AppData\Roaming\Graphisoft
2016-11-23 16:59:06 ----D---- C:\Program Files\Windows Portable Devices
2016-11-23 16:59:06 ----D---- C:\Program Files\Windows Multimedia Platform
2016-11-23 16:59:05 ----D---- C:\Windows\SYSWOW64\LogFiles
2016-11-23 16:59:05 ----D---- C:\Program Files\Windows Media Player
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Multimedia Platform
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Media Player
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\wmerror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\mferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\asferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\wmerror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\mferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\asferror.dll
2016-11-23 16:56:17 ----A---- C:\Windows\system32\drivers\WpdUpFltr.sys
2016-11-23 16:47:11 ----D---- C:\Users\Anetka\AppData\Roaming\Install.GS
2016-11-23 16:47:02 ----D---- C:\ProgramData\Sun
2016-11-23 16:46:59 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2016-11-23 16:46:47 ----D---- C:\ProgramData\Oracle
2016-11-23 16:46:44 ----D---- C:\Program Files (x86)\Java
2016-11-10 18:13:06 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-11-09 12:40:42 ----A---- C:\Windows\system32\mshtml.dll
2016-11-09 12:40:41 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-11-09 12:40:39 ----A---- C:\Windows\system32\ieframe.dll
2016-11-09 12:40:38 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-11-09 12:40:38 ----A---- C:\Windows\system32\jscript9.dll
2016-11-09 12:40:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-11-09 12:40:36 ----A---- C:\Windows\system32\win32k.sys
2016-11-09 12:40:36 ----A---- C:\Windows\system32\diagtrack.dll
2016-11-09 12:40:35 ----A---- C:\Windows\system32\wininet.dll
2016-11-09 12:40:35 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-11-09 12:40:34 ----A---- C:\Windows\system32\iertutil.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\urlmon.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\ole32.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\lsasrv.dll
2016-11-09 12:40:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-11-09 12:40:32 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-11-09 12:40:31 ----A---- C:\Windows\SYSWOW64\msdtcprx.dll
2016-11-09 12:40:31 ----A---- C:\Windows\system32\drivers\refs.sys
2016-11-09 12:40:30 ----AC---- C:\Windows\system32\drivers\vhdmp.sys
2016-11-09 12:40:30 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\win32spl.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\SessEnv.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\msdtcprx.dll
2016-11-09 12:40:29 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-11-09 12:40:29 ----A---- C:\Windows\system32\vmrdvcore.dll
2016-11-09 12:40:29 ----A---- C:\Windows\system32\drivers\clfs.sys
2016-11-09 12:40:28 ----A---- C:\Windows\system32\msctf.dll
2016-11-09 12:40:27 ----AC---- C:\Windows\system32\drivers\msiscsi.sys
2016-11-09 12:40:27 ----A---- C:\Windows\system32\pdh.dll
2016-11-09 12:40:27 ----A---- C:\Windows\system32\msv1_0.dll
2016-11-09 12:40:26 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2016-11-09 12:40:26 ----A---- C:\Windows\system32\atmfd.dll
2016-11-09 12:40:25 ----A---- C:\Windows\SYSWOW64\pdh.dll
2016-11-09 12:40:25 ----A---- C:\Windows\SYSWOW64\msctf.dll
2016-11-09 12:40:25 ----A---- C:\Windows\system32\drivers\bowser.sys
2016-11-09 12:40:25 ----A---- C:\Windows\system32\DafPrintProvider.dll
2016-11-09 12:40:24 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2016-11-09 12:40:24 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-11-09 12:40:24 ----A---- C:\Windows\system32\msfeeds.dll
2016-11-09 12:40:24 ----A---- C:\Windows\system32\ie4uinit.exe
2016-11-09 12:40:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2016-11-09 12:40:23 ----A---- C:\Windows\system32\iscsiexe.dll
2016-11-09 12:40:22 ----A---- C:\Windows\system32\UIAnimation.dll
2016-11-09 12:40:22 ----A---- C:\Windows\system32\localspl.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\iscsiwmi.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\inetcomm.dll
2016-11-09 12:40:20 ----A---- C:\Windows\SYSWOW64\iscsiwmi.dll
2016-11-09 12:40:20 ----A---- C:\Windows\system32\pmcsnap.dll
2016-11-09 12:40:20 ----A---- C:\Windows\system32\asycfilt.dll
2016-11-09 12:40:19 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2016-11-09 12:40:19 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2016-11-09 12:40:18 ----A---- C:\Windows\SYSWOW64\iscsidsc.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\xolehlp.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\iscsidsc.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\dab.dll
2016-11-09 12:40:15 ----A---- C:\Windows\SYSWOW64\input.dll
2016-11-09 12:40:15 ----A---- C:\Windows\system32\input.dll
2016-11-09 12:40:12 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-11-09 12:40:12 ----A---- C:\Windows\system32\iedkcs32.dll
2016-11-09 12:40:11 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-11-09 12:40:10 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-11-09 12:40:09 ----A---- C:\Windows\SYSWOW64\xolehlp.dll
2016-11-09 12:40:09 ----A---- C:\Windows\system32\webcheck.dll
2016-11-09 12:40:08 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\netlogon.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\dxtrans.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\certcli.dll
2016-11-09 12:40:07 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-11-09 12:40:06 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-11-09 12:40:05 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-11-09 12:40:05 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\mshtmled.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\jscript.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\iepeers.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\vbscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\ieapfltr.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\atmlib.dll
2016-11-09 12:40:03 ----A---- C:\Windows\SYSWOW64\atmlib.dll

======List of files/folders modified in the last 1 month======

2016-12-06 18:05:46 ----D---- C:\Windows\Prefetch
2016-12-06 18:05:36 ----D---- C:\Windows\Temp
2016-12-06 18:05:30 ----RD---- C:\Program Files
2016-12-06 18:03:12 ----D---- C:\Windows\system32\config
2016-12-06 18:00:05 ----D---- C:\Windows\system32\sru
2016-12-06 17:57:03 ----D---- C:\Windows\system32\drivers
2016-12-06 17:57:03 ----D---- C:\Windows\Inf
2016-12-06 17:57:02 ----RD---- C:\Windows\System32
2016-12-06 17:57:02 ----D---- C:\Windows\system32\DriverStore
2016-12-06 17:57:02 ----D---- C:\Windows\system32\catroot
2016-12-06 17:56:40 ----A---- C:\Windows\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-12-06 17:56:40 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-12-06 17:56:22 ----D---- C:\Windows\SysWOW64
2016-12-06 17:55:48 ----D---- C:\Windows
2016-12-06 17:54:39 ----D---- C:\Windows\WinSxS
2016-12-06 17:54:22 ----D---- C:\Windows\CbsTemp
2016-12-06 17:54:18 ----D---- C:\Windows\SYSWOW64\en-US
2016-12-06 17:54:18 ----D---- C:\Windows\system32\en-US
2016-12-06 17:52:48 ----SHD---- C:\System Volume Information
2016-12-06 15:50:10 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-12-06 15:43:31 ----D---- C:\ProgramData\NVIDIA
2016-12-06 15:43:22 ----HD---- C:\ProgramData
2016-12-05 17:43:38 ----RSD---- C:\Windows\assembly
2016-12-05 17:42:48 ----SHD---- C:\Windows\Installer
2016-12-05 16:13:31 ----D---- C:\Program Files (x86)\Common Files
2016-12-05 16:13:28 ----RD---- C:\Program Files (x86)
2016-12-05 16:10:21 ----HD---- C:\Windows\ELAMBKUP
2016-12-05 16:06:29 ----D---- C:\Windows\system32\Tasks
2016-12-05 16:06:23 ----RSD---- C:\Windows\Fonts
2016-12-05 16:05:51 ----D---- C:\ProgramData\Package Cache
2016-12-05 15:49:54 ----SD---- C:\ProgramData\Microsoft
2016-12-05 15:49:51 ----D---- C:\Windows\system32\drivers\UMDF
2016-12-05 15:44:23 ----D---- C:\ProgramData\NVIDIA Corporation
2016-12-05 15:43:12 ----D---- C:\Program Files\NVIDIA Corporation
2016-12-05 15:43:12 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-12-05 11:58:23 ----D---- C:\Windows\Microsoft.NET
2016-12-05 11:36:23 ----SD---- C:\Users\Anetka\AppData\Roaming\Microsoft
2016-11-25 22:30:06 ----D---- C:\ProgramData\RevitInterProcess
2016-11-25 21:45:17 ----D---- C:\Windows\rescache
2016-11-25 21:41:42 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-11-25 21:41:42 ----D---- C:\Windows\system32\cs-CZ
2016-11-25 19:18:19 ----D---- C:\ProgramData\Autodesk
2016-11-25 19:16:49 ----D---- C:\Users\Anetka\AppData\Roaming\Autodesk
2016-11-24 21:54:04 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvoglv64.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvapi64.dll
2016-11-24 20:39:58 ----A---- C:\Windows\system32\nvsvc64.dll
2016-11-24 20:39:58 ----A---- C:\Windows\system32\nvcpl.dll
2016-11-24 20:39:56 ----A---- C:\Windows\SYSWOW64\oemdspif.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvsvcr.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvshext.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvmctray.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-11-24 18:56:21 ----D---- C:\Program Files (x86)\Autodesk
2016-11-24 18:55:26 ----SD---- C:\Windows\Downloaded Program Files
2016-11-24 18:55:17 ----D---- C:\Program Files\Common Files\Autodesk Shared
2016-11-24 18:51:49 ----D---- C:\Program Files\Autodesk
2016-11-24 18:27:10 ----D---- C:\Autodesk
2016-11-23 18:45:04 ----D---- C:\Windows\system32\catroot2
2016-11-23 16:59:05 ----D---- C:\Windows\SYSWOW64\wbem
2016-11-23 16:59:04 ----D---- C:\Windows\system32\wbem
2016-11-23 16:59:04 ----D---- C:\Windows\system32\drivers\en-US
2016-11-23 16:59:04 ----D---- C:\Windows\PolicyDefinitions
2016-11-23 16:03:28 ----HD---- C:\Program Files\WindowsApps
2016-11-23 16:03:28 ----D---- C:\Windows\AppReadiness
2016-11-17 09:18:17 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2016-11-16 17:07:27 ----D---- C:\Program Files (x86)\Microsoft Office
2016-11-09 21:13:10 ----RD---- C:\Windows\ToastData
2016-11-09 21:13:09 ----D---- C:\Program Files\Internet Explorer
2016-11-09 21:13:09 ----D---- C:\Program Files (x86)\Internet Explorer
2016-11-09 21:13:08 ----D---- C:\Windows\SYSWOW64\migration
2016-11-09 21:13:07 ----D---- C:\Windows\system32\migration
2016-11-09 12:48:01 ----D---- C:\Windows\system32\MRT
2016-11-09 12:45:10 ----AC---- C:\Windows\system32\MRT.exe
2016-11-08 16:24:08 ----D---- C:\Windows\system32\Macromed
2016-11-08 16:24:04 ----D---- C:\Windows\SYSWOW64\Macromed

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 avusbflt;avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [2016-10-17 23640]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2016-10-17 153392]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2016-10-17 35488]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2016-10-17 151352]
R2 avnetflt;avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [2016-10-17 78208]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2015-06-09 81920]
R3 CnxtHdAudService;@oem22.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2014-11-12 1535168]
R3 dtlitescsibus;@oem31.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2016-08-05 30264]
R3 dtliteusbbus;@oem32.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\Windows\System32\drivers\dtliteusbbus.sys [2016-08-05 47672]
R3 ETD;@oem8.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2014-08-19 425736]
R3 ibtusb;@oem19.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R); C:\Windows\system32\DRIVERS\ibtusb.sys [2014-08-13 219592]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2016-10-07 7957496]
R3 intaud_WaveExtensible;@oem4.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-12-07 51704]
R3 iwdbus;@oem5.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-12-07 39920]
R3 MEIx64;@oem17.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-09-30 129312]
R3 NETwNb64;@oem12.inf,___ %NIC_Service_DispName_WINB_64%;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\Windows\system32\DRIVERS\NETwbw02.sys [2015-01-20 3494680]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2016-11-24 14057528]
R3 nvvad_WaveExtensible;@oem30.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2016-11-17 47672]
R3 RSUSBVSTOR;@oem7.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2014-03-26 331992]
R3 RTL8168;@oem20.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-05-28 873176]
R3 SNP2UVC;@oem18.inf,%SERVICE_DISPLAY_NAME%;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2015-03-11 3554328]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2016-08-13 38912]
S1 EpfwLWF;@oem30.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-11-12 61568]
S3 ACPIVPC;@oem31.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\Windows\System32\drivers\AcpiVpc.sys []
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\Windows\System32\drivers\BthEnum.sys [2015-06-09 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-06-09 1201664]
S3 IntcDAud;@oem2.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2016-05-12 481768]
S3 iscFlash;iscFlash; \??\C:\Users\Anetka\AppData\Local\Temp\7zS44CE.tmp\iscflashx64.sys [2015-06-10 60680]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-11-17 29240]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Desktop App Service; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [2016-07-01 1295376]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2016-10-17 475232]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\Antivirus\sched.exe [2016-10-17 475232]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2016-11-25 369608]
R2 AviraPhantomVPN;Avira Phantom VPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [2016-11-16 263704]
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-10-30 2946304]
R2 CodeMeter.exe;CodeMeter Runtime Server; C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2015-08-17 3526184]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2014-10-19 207576]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2013-10-15 101680]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2014-11-19 638368]
R2 ibtsiva.exe;Intel Bluetooth Service; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [2014-08-13 121288]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2016-10-07 365048]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-11-17 464440]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2016-11-24 458176]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-11-17 1165368]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2014-11-19 157088]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SpeedupService;Avira System Speedup; C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe [2016-11-23 33896]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2016-10-17 1089088]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2016-10-17 1488240]
S2 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2016-10-07 292856]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-04 154440]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-08 270016]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll"=%SystemRoot%\System32\BthHFSrv.dll
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2016-07-29 1467072]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2016-10-09 1591264]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-04 154440]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2014-11-19 268192]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-11-17 464440]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2016-10-30 209104]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-10-13 1459488]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Svchost a Installer Worker vytěžuje disk

#2 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krajta5
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 03 črc 2013 16:43

Re: Svchost a Installer Worker vytěžuje disk

#3 Příspěvek od krajta5 »

# AdwCleaner v6.040 - Logfile created 06/12/2016 at 19:19:13
# Updated on 02/12/2016 by Malwarebytes
# Database : 2016-12-05.1 [Server]
# Operating System : Windows 8.1 Pro N (X64)
# Username : Anetka - BABYANETKA
# Running from : C:\Users\Anetka\Desktop\adwcleaner_6.040.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****



***** [ Folders ] *****



***** [ Files ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****

[-] Key deleted: HKLM\SOFTWARE\HPRewriter
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\DOMStorage\piroga.space
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\DOMStorage\piroga.space
[-] Value deleted: HKU\S-1-5-21-4117213250-101706349-321446703-1001\Software\Microsoft\Windows\CurrentVersion\Run [SSMaker2]
[-] Value deleted: HKU\S-1-5-21-4117213250-101706349-321446703-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [SSMaker2]
[#] Value deleted on reboot: HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SSMaker2]
[#] Value deleted on reboot: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Run [SSMaker2]


***** [ Web browsers ] *****



*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [1442 Bytes] - [06/12/2016 19:19:13]
C:\AdwCleaner\AdwCleaner[S0].txt - [1739 Bytes] - [06/12/2016 19:18:50]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1588 Bytes] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Svchost a Installer Worker vytěžuje disk

#4 Příspěvek od Rudy »

Dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krajta5
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 03 črc 2013 16:43

Re: Svchost a Installer Worker vytěžuje disk

#5 Příspěvek od krajta5 »

Logfile of random's system information tool 1.14 (written by random/random)
Run by Anetka at 2016-12-06 20:21:16
Microsoft Windows 8.1 Pro N
System drive C: has 406 GB (81%) free of 500 GB
Total RAM: 4016 MB (58% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 20:21:24, on 6. 12. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe
C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
C:\Program Files\trend micro\Anetka_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [Autodesk Desktop App] "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
O4 - HKLM\..\Run: [Avira System Speedup User Starter] "C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\Anetka\AppData\Local\Akamai\netsession_win.exe"
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - Startup: Poslat do aplikace OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Startup: zSpeedup.lnk = C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe
O4 - Global Startup: CodeMeter Control Center.lnk = C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{83962CAD-4E16-4DE0-BDE0-6B37999F69A9}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{83962CAD-4E16-4DE0-BDE0-6B37999F69A9}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O23 - Service: Autodesk Desktop App Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Avira Phantom VPN (AviraPhantomVPN) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
O23 - Service: CodeMeter Runtime Server (CodeMeter.exe) - WIBU-SYSTEMS AG - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel Bluetooth Service (ibtsiva.exe) - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Avira System Speedup (SpeedupService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 12563 bytes

======Enumerating Processes======

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\dwm.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 675069223152
C:\Windows\System32\spoolsv.exe
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe"
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
"C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\Windows\SysWow64\IntelCpHeciSvc.exe
C:\Windows\system32\CxAudMsg64.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Elantech\ETDService.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
"C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe"
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_000006e8
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\dashost.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskhostex.exe
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
"C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe" scan upload
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Explorer.EXE
C:\Windows\system32\igfxEM.exe
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
C:\Windows\system32\igfxHK.exe
"C:\Program Files\Elantech\ETDIntelligent.exe"
C:\Windows\system32\igfxTray.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe" -autorun
C:\Windows\System32\skydrive.exe -Embedding
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files\Autodesk\Personal Accelerator for Revit\RevitAccelerator.exe"
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE" -Embedding
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 1 0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=54.0.2840.99 --handshake-handle=0x114
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DisallowFetchForDocWrittenScriptsInMainFrame/Control_5/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/NonValidatingReloadOnNormalReload/Enabled2/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/StrictSecureCookies/Disabled/SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,15,16,17,20,34,51,60 --gpu-vendor-id=0x8086 --gpu-device-id=0x1616 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=20.19.15.4531 --gpu-driver-date=9-29-2016 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x1299 --mojo-application-channel-token=345B02A571089048A6DA75AF9C327DA4 --mojo-platform-channel-handle=1108 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillCreditCardSigninPromo/Default/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DisallowFetchForDocWrittenScriptsInMainFrame/Control_5/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/*EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*NonValidatingReloadOnNormalReload/Enabled2/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/*StrictSecureCookies/Disabled/*SubresourceFilter/EnabledForPhishingSites/*TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --disable-databases --primordial-pipe-token=F41EB0FEA728BF146E8FB22F1295EE16 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553 --mojo-application-channel-token=F41EB0FEA728BF146E8FB22F1295EE16 --channel="5848.6.670200222\2103413977" --mojo-platform-channel-handle=5464 /prefetch:1
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe4_ Global\UsGthrCtrlFltPipeMssGthrPipe4 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Users\Anetka\Desktop\RSITx64.exe"
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillCreditCardSigninPromo/Default/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DisallowFetchForDocWrittenScriptsInMainFrame/Control_5/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/*EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*NonValidatingReloadOnNormalReload/Enabled2/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SafeBrowsingUpdateFrequency/Default/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/*StrictSecureCookies/Disabled/*SubresourceFilter/EnabledForPhishingSites/*TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --disable-databases --primordial-pipe-token=677BF82072B21E4E4CAECABE49C53DA9 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553 --mojo-application-channel-token=677BF82072B21E4E4CAECABE49C53DA9 --channel="5848.9.1519308278\703930422" --mojo-platform-channel-handle=6248 /prefetch:1

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player PPAPI Notifier.job - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe -check pepperplugin
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe -check pepperplugin
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Avira System Speedup Tray - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe -autorun
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4117213250-101706349-321446703-1001 - %localappdata%\Microsoft\OneDrive\OneDrive.exe /autoupdate
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\OneDrive Standalone Update Task - C:\Users\Anetka\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
C:\Windows\system32\tasks\User_Feed_Synchronization-{2CA74BE9-FC3D-4F1E-9408-B22E2F955737} - C:\Windows\system32\msfeedssync.exe sync
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-4117213250-101706349-321446703-1001 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\Windows\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\Windows\System32\mcbuilder.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent /increment
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\Windows\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\Windows\system32\tasks\Microsoft\Office\Office Subscription Maintenance - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 - C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe scan upload mininterval:2880
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 - C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe scan upload
C:\Windows\system32\tasks\Lenovo\Lenovo Customer Feedback Program 64 - "%ProgramFiles(x86)%\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe"

=========Google Chrome=========

C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension flliilndjeohchalpbbcdekjklbdgfkk 0 Avira Browser Safety 2.0.0
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5416.905.0.6
Homepage:
default_search_provider.search_url:
C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk]
"Path"=


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-11-16 213192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-11-16 2099504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-11-16 154824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2016-11-23 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-11-16 1522472]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2016-11-23 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2014-08-20 3282248]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-25 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2014-04-09 1830616]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2014-11-20 919768]
"pac"=C:\Program Files\Autodesk\Personal Accelerator for Revit\RevitAccelerator.exe [2016-02-10 339464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2016-07-29 4299968]
"Akamai NetSession Interface"=C:\Users\Anetka\AppData\Local\Akamai\netsession_win.exe [2015-09-10 4691384]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-10-13 2860832]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"snp2uvc"=C:\Windows\vsnp2uvc.exe []
"Autodesk Desktop App"=C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [2016-07-01 721856]
"Avira SystrayStartTrigger"=C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2016-11-25 60120]
"Avira System Speedup User Starter"=C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [2016-11-23 25256]
"avgnt"=C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2016-10-17 916072]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
CodeMeter Control Center.lnk - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe

C:\Users\Anetka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Poslat do aplikace OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
zSpeedup.lnk - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2016-12-06 19:17:58 ----D---- C:\AdwCleaner
2016-12-06 18:05:30 ----D---- C:\Program Files\trend micro
2016-12-06 18:05:29 ----D---- C:\rsit
2016-12-06 17:53:16 ----A---- C:\Windows\SYSWOW64\aspnet_counters.dll
2016-12-06 17:53:16 ----A---- C:\Windows\system32\aspnet_counters.dll
2016-12-05 17:44:16 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2016-12-05 17:44:16 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2016-12-05 17:44:16 ----A---- C:\Windows\system32\XAudio2_6.dll
2016-12-05 17:44:16 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2016-12-05 17:44:15 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2016-12-05 17:44:15 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2016-12-05 17:44:15 ----A---- C:\Windows\system32\xactengine3_6.dll
2016-12-05 17:44:15 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2016-12-05 17:44:13 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2016-12-05 17:44:13 ----A---- C:\Windows\system32\XAudio2_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2016-12-05 17:44:12 ----A---- C:\Windows\system32\xactengine3_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\system32\d3dx11_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\system32\d3dcsx_42.dll
2016-12-05 17:44:10 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2016-12-05 17:44:10 ----A---- C:\Windows\system32\d3dx10_42.dll
2016-12-05 17:44:09 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2016-12-05 17:44:09 ----A---- C:\Windows\system32\D3DX9_42.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\D3DX9_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\d3dx10_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\XAudio2_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\xactengine3_4.dll
2016-12-05 17:44:06 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2016-12-05 17:44:06 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\D3DX9_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\d3dx10_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\XAudio2_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\xactengine3_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\XAudio2_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\xactengine3_2.dll
2016-12-05 17:44:00 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\system32\d3dx10_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2016-12-05 17:43:59 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2016-12-05 17:43:59 ----A---- C:\Windows\system32\D3DX9_39.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\XAudio2_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\xactengine3_1.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\d3dx10_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2016-12-05 17:43:56 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2016-12-05 17:43:56 ----A---- C:\Windows\system32\D3DX9_38.dll
2016-12-05 17:43:55 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\system32\XAudio2_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\system32\xactengine3_0.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\d3dx10_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2016-12-05 17:43:53 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2016-12-05 17:43:53 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2016-12-05 17:43:53 ----A---- C:\Windows\system32\xactengine2_10.dll
2016-12-05 17:43:53 ----A---- C:\Windows\system32\D3DX9_37.dll
2016-12-05 17:43:52 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\system32\d3dx10_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2016-12-05 17:43:51 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2016-12-05 17:43:51 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2016-12-05 17:43:51 ----A---- C:\Windows\system32\xactengine2_9.dll
2016-12-05 17:43:51 ----A---- C:\Windows\system32\d3dx9_36.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\d3dx9_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\d3dx10_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\xactengine2_8.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\d3dx10_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2016-12-05 17:43:48 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2016-12-05 17:43:48 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2016-12-05 17:43:48 ----A---- C:\Windows\system32\xinput1_3.dll
2016-12-05 17:43:48 ----A---- C:\Windows\system32\d3dx9_34.dll
2016-12-05 17:43:47 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2016-12-05 17:43:47 ----A---- C:\Windows\system32\xactengine2_7.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\d3dx9_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\d3dx10_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2016-12-05 17:43:45 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2016-12-05 17:43:45 ----A---- C:\Windows\system32\xactengine2_6.dll
2016-12-05 17:43:44 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2016-12-05 17:43:44 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2016-12-05 17:43:44 ----A---- C:\Windows\system32\xactengine2_5.dll
2016-12-05 17:43:44 ----A---- C:\Windows\system32\d3dx10.dll
2016-12-05 17:43:43 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2016-12-05 17:43:43 ----A---- C:\Windows\system32\d3dx9_32.dll
2016-12-05 17:43:42 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2016-12-05 17:43:42 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2016-12-05 17:43:42 ----A---- C:\Windows\system32\xactengine2_4.dll
2016-12-05 17:43:42 ----A---- C:\Windows\system32\x3daudio1_1.dll
2016-12-05 17:43:41 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2016-12-05 17:43:41 ----A---- C:\Windows\system32\d3dx9_31.dll
2016-12-05 17:43:40 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2016-12-05 17:43:40 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2016-12-05 17:43:40 ----A---- C:\Windows\system32\xinput1_2.dll
2016-12-05 17:43:40 ----A---- C:\Windows\system32\xactengine2_3.dll
2016-12-05 17:43:39 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2016-12-05 17:43:39 ----A---- C:\Windows\system32\xactengine2_2.dll
2016-12-05 17:43:21 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2016-12-05 17:43:21 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2016-12-05 17:43:21 ----A---- C:\Windows\system32\xactengine2_0.dll
2016-12-05 17:43:21 ----A---- C:\Windows\system32\d3dx9_29.dll
2016-12-05 17:43:20 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2016-12-05 17:43:20 ----A---- C:\Windows\system32\d3dx9_28.dll
2016-12-05 17:43:19 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2016-12-05 17:43:19 ----A---- C:\Windows\system32\d3dx9_27.dll
2016-12-05 17:43:18 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2016-12-05 17:43:18 ----A---- C:\Windows\system32\d3dx9_26.dll
2016-12-05 17:43:17 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2016-12-05 17:43:17 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2016-12-05 17:43:17 ----A---- C:\Windows\system32\d3dx9_25.dll
2016-12-05 17:43:17 ----A---- C:\Windows\system32\d3dx9_24.dll
2016-12-05 16:14:25 ----A---- C:\Windows\system32\drivers\avusbflt.sys
2016-12-05 16:13:28 ----D---- C:\Program Files (x86)\Steam
2016-12-05 16:12:38 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avipbb.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2016-12-05 16:07:25 ----SHD---- C:\Config.Msi
2016-12-05 16:06:11 ----D---- C:\Users\Anetka\AppData\Roaming\Mozilla
2016-12-05 16:05:59 ----D---- C:\Program Files (x86)\Avira
2016-12-05 16:05:57 ----D---- C:\ProgramData\Avira
2016-12-05 15:43:48 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2016-12-05 15:43:45 ----D---- C:\Program Files (x86)\VulkanRT
2016-12-05 15:40:43 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-12-05 15:40:43 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-12-05 15:40:42 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-12-05 15:40:42 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-12-05 15:40:41 ----A---- C:\Windows\system32\nvopencl.dll
2016-12-05 15:40:40 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvinitx.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvIFR64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvFBC64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-12-05 15:40:38 ----A---- C:\Windows\system32\nvdispgenco6437609.dll
2016-12-05 15:40:38 ----A---- C:\Windows\system32\nvdispco6437609.dll
2016-12-05 15:40:37 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-12-05 15:40:37 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-12-05 15:40:37 ----A---- C:\Windows\system32\nvcuvid.dll
2016-12-05 15:40:37 ----A---- C:\Windows\system32\nvcuda.dll
2016-12-05 15:40:36 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-12-05 15:40:34 ----A---- C:\Windows\system32\nvcompiler.dll
2016-12-05 15:40:33 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-12-05 15:30:59 ----A---- C:\Windows\system32\NvRtmpStreamer64.dll
2016-12-05 15:30:58 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2016-12-05 15:30:58 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2016-12-05 15:30:58 ----A---- C:\Windows\system32\nvspcap64.dll
2016-12-05 15:30:58 ----A---- C:\Windows\system32\nvspbridge64.dll
2016-12-05 15:30:34 ----A---- C:\Windows\NvContainerRecovery.bat
2016-12-05 15:30:21 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2016-12-05 15:30:21 ----A---- C:\Windows\system32\nvaudcap64v.dll
2016-12-05 15:30:21 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2016-11-25 19:24:37 ----D---- C:\Users\Anetka\AppData\Roaming\NVIDIA
2016-11-25 19:24:31 ----D---- C:\Users\Anetka\AppData\Roaming\MAXON
2016-11-24 20:09:30 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2016-11-24 20:09:30 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2016-11-24 20:09:28 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2016-11-24 20:09:28 ----A---- C:\Windows\system32\wpdshext.dll
2016-11-24 20:07:48 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.dll
2016-11-24 20:07:48 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2016-11-24 20:07:44 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2016-11-24 20:07:44 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\wmploc.DLL
2016-11-24 20:07:30 ----A---- C:\Windows\system32\wmp.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\Windows.Media.Streaming.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\mfsvr.dll
2016-11-24 20:07:10 ----A---- C:\Windows\SYSWOW64\WMASF.DLL
2016-11-24 20:07:10 ----A---- C:\Windows\system32\WMASF.DLL
2016-11-24 18:46:30 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2016-11-24 18:46:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2016-11-24 18:46:30 ----A---- C:\Windows\system32\XAudio2_7.dll
2016-11-24 18:46:30 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2016-11-24 18:46:29 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2016-11-24 18:46:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2016-11-24 18:46:29 ----A---- C:\Windows\system32\xactengine3_7.dll
2016-11-24 18:46:29 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\system32\d3dx11_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\system32\d3dcsx_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\system32\D3DX9_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\system32\d3dx10_43.dll
2016-11-24 18:46:26 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2016-11-24 18:46:26 ----A---- C:\Windows\system32\xinput1_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2016-11-24 18:46:25 ----A---- C:\Windows\system32\xactengine2_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\system32\x3daudio1_0.dll
2016-11-24 18:46:18 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2016-11-24 18:46:18 ----A---- C:\Windows\system32\d3dx9_30.dll
2016-11-24 18:40:23 ----A---- C:\Windows\SYSWOW64\mfds.dll
2016-11-24 18:40:23 ----A---- C:\Windows\system32\mfds.dll
2016-11-24 17:08:05 ----D---- C:\Program Files\WIBU-SYSTEMS
2016-11-24 17:07:57 ----D---- C:\ProgramData\CodeMeter
2016-11-24 17:07:57 ----D---- C:\Program Files\CodeMeter
2016-11-24 17:07:57 ----D---- C:\Program Files (x86)\CodeMeter
2016-11-24 17:01:50 ----D---- C:\Program Files\GRAPHISOFT
2016-11-24 15:17:15 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2016-11-24 15:17:14 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2016-11-24 15:17:14 ----A---- C:\Windows\system32\WMVCORE.DLL
2016-11-24 15:17:13 ----A---- C:\Windows\system32\MSAudDecMFT.dll
2016-11-24 15:17:12 ----A---- C:\Windows\SYSWOW64\WMVCORE.DLL
2016-11-24 15:17:12 ----A---- C:\Windows\SYSWOW64\MSAudDecMFT.dll
2016-11-24 15:17:12 ----A---- C:\Windows\system32\wmpmde.dll
2016-11-24 15:17:11 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2016-11-24 15:17:11 ----A---- C:\Windows\system32\blackbox.dll
2016-11-24 15:17:09 ----A---- C:\Windows\system32\winmde.dll
2016-11-24 15:17:08 ----A---- C:\Windows\SYSWOW64\mfasfsrcsnk.dll
2016-11-24 15:17:08 ----A---- C:\Windows\system32\drmv2clt.dll
2016-11-24 15:17:07 ----A---- C:\Windows\SYSWOW64\winmde.dll
2016-11-24 15:17:07 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2016-11-24 15:17:07 ----A---- C:\Windows\system32\WMPDMC.exe
2016-11-24 15:17:07 ----A---- C:\Windows\system32\WMNetMgr.dll
2016-11-24 15:17:07 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2016-11-24 15:17:06 ----A---- C:\Windows\system32\MFMediaEngine.dll
2016-11-24 15:17:05 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2016-11-24 15:17:04 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2016-11-24 15:17:04 ----A---- C:\Windows\system32\mfsrcsnk.dll
2016-11-24 15:17:04 ----A---- C:\Windows\system32\mfplat.dll
2016-11-24 15:17:03 ----A---- C:\Windows\SYSWOW64\WMPDMC.exe
2016-11-24 15:17:03 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2016-11-24 15:17:02 ----A---- C:\Windows\SYSWOW64\WMNetMgr.dll
2016-11-24 15:17:02 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2016-11-24 15:17:02 ----A---- C:\Windows\system32\Windows.Media.dll
2016-11-24 15:17:01 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2016-11-24 15:17:01 ----A---- C:\Windows\system32\mf.dll
2016-11-24 15:17:00 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2016-11-24 15:17:00 ----A---- C:\Windows\system32\wmdrmdev.dll
2016-11-24 15:17:00 ----A---- C:\Windows\system32\WebcamUi.dll
2016-11-24 15:16:59 ----A---- C:\Windows\SYSWOW64\wmdrmdev.dll
2016-11-24 15:16:59 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-11-24 15:16:59 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2016-11-24 15:16:59 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2016-11-24 15:16:58 ----A---- C:\Windows\SYSWOW64\MSMPEG2ENC.DLL
2016-11-24 15:16:58 ----A---- C:\Windows\system32\wmdrmnet.dll
2016-11-24 15:16:57 ----A---- C:\Windows\SYSWOW64\WebcamUi.dll
2016-11-24 15:16:57 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2016-11-24 15:16:57 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\wmdrmnet.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2016-11-24 15:16:55 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\mswmdm.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\msscp.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2016-11-24 15:16:55 ----A---- C:\Windows\system32\mfreadwrite.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\CameraSettingsUIHost.exe
2016-11-24 15:16:54 ----A---- C:\Windows\SYSWOW64\mswmdm.dll
2016-11-24 15:16:54 ----A---- C:\Windows\SYSWOW64\MSAC3ENC.DLL
2016-11-24 15:16:54 ----A---- C:\Windows\system32\MDEServer.exe
2016-11-24 15:16:54 ----A---- C:\Windows\system32\DMRServer.exe
2016-11-24 15:16:53 ----A---- C:\Windows\SYSWOW64\msscp.dll
2016-11-24 15:16:53 ----A---- C:\Windows\SYSWOW64\MFCaptureEngine.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\WPDSp.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\wmpeffects.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\MFCaptureEngine.dll
2016-11-24 15:16:52 ----A---- C:\Windows\SYSWOW64\msvproc.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\WmpDui.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\MFPlay.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\dlnashext.dll
2016-11-24 15:16:50 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2016-11-24 15:16:50 ----A---- C:\Windows\system32\msvproc.dll
2016-11-24 15:16:50 ----A---- C:\Windows\system32\mftranscode.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\WPDSp.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\wmvdspa.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\mftranscode.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\mfh264enc.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\dlnashext.dll
2016-11-24 15:16:49 ----A---- C:\Windows\system32\wmvdspa.dll
2016-11-24 15:16:49 ----A---- C:\Windows\system32\mfh264enc.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\WmpDui.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\MSVideoDSP.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\wmpps.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\wmidx.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\MSVideoDSP.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\cewmdm.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\wmidx.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\PortableDeviceTypes.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\mfdvdec.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\audiodev.dll
2016-11-24 15:16:47 ----A---- C:\Windows\system32\PortableDeviceWiaCompat.dll
2016-11-24 15:16:47 ----A---- C:\Windows\system32\msnetobj.dll
2016-11-24 15:16:46 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\wmpdxm.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\mfdvdec.dll
2016-11-24 15:16:45 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2016-11-24 15:16:45 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\WPDShServiceObj.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\unregmp2.exe
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\PortableDeviceWMDRM.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\PortableDeviceWiaCompat.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\mfmjpegdec.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\mfAACEnc.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\wpd_ci.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\PortableDeviceStatus.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\PortableDeviceClassExtension.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\logagent.exe
2016-11-24 15:16:43 ----A---- C:\Windows\system32\mfAACEnc.dll
2016-11-24 15:16:43 ----A---- C:\Windows\system32\logagent.exe
2016-11-24 15:16:42 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2016-11-24 15:16:42 ----A---- C:\Windows\SYSWOW64\PortableDeviceConnectApi.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\wmpshell.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\Windows.Media.Renewal.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\mfmjpegdec.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\wmpps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.ps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\CameraSettingsUIHost.exe
2016-11-24 15:16:41 ----A---- C:\Windows\system32\Windows.Media.Streaming.ps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\system32\rrinstaller.exe
2016-11-24 15:16:41 ----A---- C:\Windows\system32\mfpmp.exe
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\WPDShextAutoplay.exe
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\wmdmps.dll
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\wmdmlog.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2016-11-24 15:16:40 ----A---- C:\Windows\system32\wmdmps.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\wmdmlog.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\unregmp2.exe
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\wmcodecdspps.dll
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\LAPRXY.DLL
2016-11-24 15:16:39 ----A---- C:\Windows\system32\wmcodecdspps.dll
2016-11-24 15:16:39 ----A---- C:\Windows\system32\spwmp.dll
2016-11-24 15:16:39 ----A---- C:\Windows\system32\LAPRXY.DLL
2016-11-24 15:16:38 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2016-11-24 15:16:38 ----A---- C:\Windows\system32\dxmasf.dll
2016-11-23 18:48:30 ----A---- C:\Windows\system32\msmpeg2adec.dll
2016-11-23 18:48:29 ----A---- C:\Windows\SYSWOW64\msmpeg2adec.dll
2016-11-23 18:48:29 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2016-11-23 18:48:29 ----A---- C:\Windows\system32\WMVDECOD.DLL
2016-11-23 18:48:29 ----A---- C:\Windows\system32\mfcore.dll
2016-11-23 18:48:28 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2016-11-23 18:48:28 ----A---- C:\Windows\system32\WMVENCOD.DLL
2016-11-23 18:48:28 ----A---- C:\Windows\system32\mfnetsrc.dll
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\WMVENCOD.DLL
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\mfnetsrc.dll
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\mfnetcore.dll
2016-11-23 18:48:27 ----A---- C:\Windows\system32\mfnetcore.dll
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\WMADMOE.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\WMADMOD.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\evr.dll
2016-11-23 18:48:26 ----A---- C:\Windows\system32\WMADMOD.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\system32\evr.dll
2016-11-23 18:48:25 ----A---- C:\Windows\SYSWOW64\WMVSDECD.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\SYSWOW64\WMSPDMOE.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\system32\WMVSDECD.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\system32\WMADMOE.DLL
2016-11-23 18:48:24 ----A---- C:\Windows\SYSWOW64\MP4SDECD.DLL
2016-11-23 18:48:23 ----A---- C:\Windows\system32\WMSPDMOE.DLL
2016-11-23 18:48:22 ----A---- C:\Windows\SYSWOW64\MFWMAAEC.DLL
2016-11-23 18:48:22 ----A---- C:\Windows\system32\WMVSENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\WMVXENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\WMVSENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\VIDRESZR.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\MPG4DECD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\COLORCNV.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\WMVXENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\MP4SDECD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\MFWMAAEC.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\RESAMPLEDMO.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\MP43DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\MP3DMOD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\mfvdsp.dll
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\mfps.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\VIDRESZR.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\RESAMPLEDMO.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MPG4DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MP43DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MP3DMOD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\mfvdsp.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\mfps.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\COLORCNV.DLL
2016-11-23 18:45:50 ----A---- C:\Windows\system32\wpdbusenum.dll
2016-11-23 17:05:53 ----D---- C:\Users\Anetka\AppData\Roaming\Graphisoft
2016-11-23 16:59:06 ----D---- C:\Program Files\Windows Portable Devices
2016-11-23 16:59:06 ----D---- C:\Program Files\Windows Multimedia Platform
2016-11-23 16:59:05 ----D---- C:\Windows\SYSWOW64\LogFiles
2016-11-23 16:59:05 ----D---- C:\Program Files\Windows Media Player
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Multimedia Platform
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Media Player
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\wmerror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\mferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\asferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\wmerror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\mferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\asferror.dll
2016-11-23 16:56:17 ----A---- C:\Windows\system32\drivers\WpdUpFltr.sys
2016-11-23 16:47:11 ----D---- C:\Users\Anetka\AppData\Roaming\Install.GS
2016-11-23 16:47:02 ----D---- C:\ProgramData\Sun
2016-11-23 16:46:59 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2016-11-23 16:46:47 ----D---- C:\ProgramData\Oracle
2016-11-23 16:46:44 ----D---- C:\Program Files (x86)\Java
2016-11-10 18:13:06 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-11-09 12:40:42 ----A---- C:\Windows\system32\mshtml.dll
2016-11-09 12:40:41 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-11-09 12:40:39 ----A---- C:\Windows\system32\ieframe.dll
2016-11-09 12:40:38 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-11-09 12:40:38 ----A---- C:\Windows\system32\jscript9.dll
2016-11-09 12:40:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-11-09 12:40:36 ----A---- C:\Windows\system32\win32k.sys
2016-11-09 12:40:36 ----A---- C:\Windows\system32\diagtrack.dll
2016-11-09 12:40:35 ----A---- C:\Windows\system32\wininet.dll
2016-11-09 12:40:35 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-11-09 12:40:34 ----A---- C:\Windows\system32\iertutil.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\urlmon.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\ole32.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\lsasrv.dll
2016-11-09 12:40:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-11-09 12:40:32 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-11-09 12:40:31 ----A---- C:\Windows\SYSWOW64\msdtcprx.dll
2016-11-09 12:40:31 ----A---- C:\Windows\system32\drivers\refs.sys
2016-11-09 12:40:30 ----AC---- C:\Windows\system32\drivers\vhdmp.sys
2016-11-09 12:40:30 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\win32spl.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\SessEnv.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\msdtcprx.dll
2016-11-09 12:40:29 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-11-09 12:40:29 ----A---- C:\Windows\system32\vmrdvcore.dll
2016-11-09 12:40:29 ----A---- C:\Windows\system32\drivers\clfs.sys
2016-11-09 12:40:28 ----A---- C:\Windows\system32\msctf.dll
2016-11-09 12:40:27 ----AC---- C:\Windows\system32\drivers\msiscsi.sys
2016-11-09 12:40:27 ----A---- C:\Windows\system32\pdh.dll
2016-11-09 12:40:27 ----A---- C:\Windows\system32\msv1_0.dll
2016-11-09 12:40:26 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2016-11-09 12:40:26 ----A---- C:\Windows\system32\atmfd.dll
2016-11-09 12:40:25 ----A---- C:\Windows\SYSWOW64\pdh.dll
2016-11-09 12:40:25 ----A---- C:\Windows\SYSWOW64\msctf.dll
2016-11-09 12:40:25 ----A---- C:\Windows\system32\drivers\bowser.sys
2016-11-09 12:40:25 ----A---- C:\Windows\system32\DafPrintProvider.dll
2016-11-09 12:40:24 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2016-11-09 12:40:24 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-11-09 12:40:24 ----A---- C:\Windows\system32\msfeeds.dll
2016-11-09 12:40:24 ----A---- C:\Windows\system32\ie4uinit.exe
2016-11-09 12:40:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2016-11-09 12:40:23 ----A---- C:\Windows\system32\iscsiexe.dll
2016-11-09 12:40:22 ----A---- C:\Windows\system32\UIAnimation.dll
2016-11-09 12:40:22 ----A---- C:\Windows\system32\localspl.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\iscsiwmi.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\inetcomm.dll
2016-11-09 12:40:20 ----A---- C:\Windows\SYSWOW64\iscsiwmi.dll
2016-11-09 12:40:20 ----A---- C:\Windows\system32\pmcsnap.dll
2016-11-09 12:40:20 ----A---- C:\Windows\system32\asycfilt.dll
2016-11-09 12:40:19 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2016-11-09 12:40:19 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2016-11-09 12:40:18 ----A---- C:\Windows\SYSWOW64\iscsidsc.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\xolehlp.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\iscsidsc.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\dab.dll
2016-11-09 12:40:15 ----A---- C:\Windows\SYSWOW64\input.dll
2016-11-09 12:40:15 ----A---- C:\Windows\system32\input.dll
2016-11-09 12:40:12 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-11-09 12:40:12 ----A---- C:\Windows\system32\iedkcs32.dll
2016-11-09 12:40:11 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-11-09 12:40:10 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-11-09 12:40:09 ----A---- C:\Windows\SYSWOW64\xolehlp.dll
2016-11-09 12:40:09 ----A---- C:\Windows\system32\webcheck.dll
2016-11-09 12:40:08 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\netlogon.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\dxtrans.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\certcli.dll
2016-11-09 12:40:07 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-11-09 12:40:06 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-11-09 12:40:05 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-11-09 12:40:05 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\mshtmled.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\jscript.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\iepeers.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\vbscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\ieapfltr.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\atmlib.dll
2016-11-09 12:40:03 ----A---- C:\Windows\SYSWOW64\atmlib.dll

======List of files/folders modified in the last 1 month======

2016-12-06 20:21:24 ----D---- C:\Windows\Prefetch
2016-12-06 20:21:05 ----D---- C:\Windows\Temp
2016-12-06 20:00:00 ----D---- C:\Windows\system32\sru
2016-12-06 19:35:34 ----D---- C:\Windows\Microsoft.NET
2016-12-06 19:35:13 ----RSD---- C:\Windows\assembly
2016-12-06 19:26:25 ----RD---- C:\Windows\System32
2016-12-06 19:26:25 ----D---- C:\Windows\Inf
2016-12-06 19:26:25 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-12-06 19:22:46 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-12-06 19:22:41 ----D---- C:\ProgramData\NVIDIA
2016-12-06 19:22:30 ----D---- C:\Windows\system32\config
2016-12-06 19:22:30 ----D---- C:\Windows
2016-12-06 19:22:20 ----D---- C:\Windows\WinSxS
2016-12-06 19:22:08 ----HD---- C:\ProgramData
2016-12-06 19:21:27 ----D---- C:\Windows\SysWOW64
2016-12-06 19:19:29 ----D---- C:\Windows\SYSWOW64\en-US
2016-12-06 19:19:29 ----D---- C:\Windows\system32\en-US
2016-12-06 18:05:30 ----RD---- C:\Program Files
2016-12-06 17:57:03 ----D---- C:\Windows\system32\drivers
2016-12-06 17:57:02 ----D---- C:\Windows\system32\DriverStore
2016-12-06 17:57:02 ----D---- C:\Windows\system32\catroot
2016-12-06 17:56:40 ----A---- C:\Windows\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-12-06 17:54:42 ----D---- C:\Windows\CbsTemp
2016-12-06 17:52:48 ----SHD---- C:\System Volume Information
2016-12-05 17:42:48 ----SHD---- C:\Windows\Installer
2016-12-05 16:13:31 ----D---- C:\Program Files (x86)\Common Files
2016-12-05 16:13:28 ----RD---- C:\Program Files (x86)
2016-12-05 16:10:21 ----HD---- C:\Windows\ELAMBKUP
2016-12-05 16:06:29 ----D---- C:\Windows\system32\Tasks
2016-12-05 16:06:23 ----RSD---- C:\Windows\Fonts
2016-12-05 16:05:51 ----D---- C:\ProgramData\Package Cache
2016-12-05 15:49:54 ----SD---- C:\ProgramData\Microsoft
2016-12-05 15:49:51 ----D---- C:\Windows\system32\drivers\UMDF
2016-12-05 15:44:23 ----D---- C:\ProgramData\NVIDIA Corporation
2016-12-05 15:43:12 ----D---- C:\Program Files\NVIDIA Corporation
2016-12-05 15:43:12 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-12-05 11:36:23 ----SD---- C:\Users\Anetka\AppData\Roaming\Microsoft
2016-11-25 22:30:06 ----D---- C:\ProgramData\RevitInterProcess
2016-11-25 21:45:17 ----D---- C:\Windows\rescache
2016-11-25 21:41:42 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-11-25 21:41:42 ----D---- C:\Windows\system32\cs-CZ
2016-11-25 19:18:19 ----D---- C:\ProgramData\Autodesk
2016-11-25 19:16:49 ----D---- C:\Users\Anetka\AppData\Roaming\Autodesk
2016-11-24 21:54:04 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvoglv64.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvapi64.dll
2016-11-24 20:39:58 ----A---- C:\Windows\system32\nvsvc64.dll
2016-11-24 20:39:58 ----A---- C:\Windows\system32\nvcpl.dll
2016-11-24 20:39:56 ----A---- C:\Windows\SYSWOW64\oemdspif.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvsvcr.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvshext.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvmctray.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-11-24 18:56:21 ----D---- C:\Program Files (x86)\Autodesk
2016-11-24 18:55:26 ----SD---- C:\Windows\Downloaded Program Files
2016-11-24 18:55:17 ----D---- C:\Program Files\Common Files\Autodesk Shared
2016-11-24 18:51:49 ----D---- C:\Program Files\Autodesk
2016-11-24 18:27:10 ----D---- C:\Autodesk
2016-11-23 18:45:04 ----D---- C:\Windows\system32\catroot2
2016-11-23 16:59:05 ----D---- C:\Windows\SYSWOW64\wbem
2016-11-23 16:59:04 ----D---- C:\Windows\system32\wbem
2016-11-23 16:59:04 ----D---- C:\Windows\system32\drivers\en-US
2016-11-23 16:59:04 ----D---- C:\Windows\PolicyDefinitions
2016-11-23 16:03:28 ----HD---- C:\Program Files\WindowsApps
2016-11-23 16:03:28 ----D---- C:\Windows\AppReadiness
2016-11-17 09:18:17 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2016-11-16 17:07:27 ----D---- C:\Program Files (x86)\Microsoft Office
2016-11-09 21:13:10 ----RD---- C:\Windows\ToastData
2016-11-09 21:13:09 ----D---- C:\Program Files\Internet Explorer
2016-11-09 21:13:09 ----D---- C:\Program Files (x86)\Internet Explorer
2016-11-09 21:13:08 ----D---- C:\Windows\SYSWOW64\migration
2016-11-09 21:13:07 ----D---- C:\Windows\system32\migration
2016-11-09 12:48:01 ----D---- C:\Windows\system32\MRT
2016-11-09 12:45:10 ----AC---- C:\Windows\system32\MRT.exe
2016-11-08 16:24:08 ----D---- C:\Windows\system32\Macromed
2016-11-08 16:24:04 ----D---- C:\Windows\SYSWOW64\Macromed

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 avusbflt;avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [2016-10-17 23640]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2016-10-17 153392]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2016-10-17 35488]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2016-10-17 151352]
R2 avnetflt;avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [2016-10-17 78208]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2015-06-09 81920]
R3 CnxtHdAudService;@oem22.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2014-11-12 1535168]
R3 dtlitescsibus;@oem31.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2016-08-05 30264]
R3 dtliteusbbus;@oem32.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\Windows\System32\drivers\dtliteusbbus.sys [2016-08-05 47672]
R3 ETD;@oem8.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2014-08-19 425736]
R3 ibtusb;@oem19.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R); C:\Windows\system32\DRIVERS\ibtusb.sys [2014-08-13 219592]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2016-10-07 7957496]
R3 iwdbus;@oem5.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-12-07 39920]
R3 MEIx64;@oem17.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-09-30 129312]
R3 NETwNb64;@oem12.inf,___ %NIC_Service_DispName_WINB_64%;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\Windows\system32\DRIVERS\NETwbw02.sys [2015-01-20 3494680]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2016-11-24 14057528]
R3 nvvad_WaveExtensible;@oem30.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2016-11-17 47672]
R3 RSUSBVSTOR;@oem7.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2014-03-26 331992]
R3 RTL8168;@oem20.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-05-28 873176]
R3 SNP2UVC;@oem18.inf,%SERVICE_DISPLAY_NAME%;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2015-03-11 3554328]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2016-08-13 38912]
S1 EpfwLWF;@oem30.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-11-12 61568]
S3 ACPIVPC;@oem31.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\Windows\System32\drivers\AcpiVpc.sys []
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\Windows\System32\drivers\BthEnum.sys [2015-06-09 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-06-09 1201664]
S3 intaud_WaveExtensible;@oem4.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-12-07 51704]
S3 IntcDAud;@oem2.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2016-05-12 481768]
S3 iscFlash;iscFlash; \??\C:\Users\Anetka\AppData\Local\Temp\7zS44CE.tmp\iscflashx64.sys [2015-06-10 60680]
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-11-17 29240]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Desktop App Service; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [2016-07-01 1295376]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2016-10-17 475232]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\Antivirus\sched.exe [2016-10-17 475232]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2016-11-25 369608]
R2 AviraPhantomVPN;Avira Phantom VPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [2016-11-16 263704]
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-10-30 2946304]
R2 CodeMeter.exe;CodeMeter Runtime Server; C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2015-08-17 3526184]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2014-10-19 207576]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2013-10-15 101680]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2014-11-19 638368]
R2 ibtsiva.exe;Intel Bluetooth Service; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [2014-08-13 121288]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2016-10-07 365048]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-11-17 464440]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2016-11-24 458176]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-11-17 1165368]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2014-11-19 157088]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SpeedupService;Avira System Speedup; C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe [2016-11-23 33896]
R3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2016-10-07 292856]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2016-10-17 1089088]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2016-10-17 1488240]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-04 154440]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-08 270016]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll"=%SystemRoot%\System32\BthHFSrv.dll
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2016-07-29 1467072]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2016-10-09 1591264]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-04 154440]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2014-11-19 268192]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-11-17 464440]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2016-10-30 209104]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-10-13 1459488]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Svchost a Installer Worker vytěžuje disk

#6 Příspěvek od Rudy »

Stáhněte OTM: http://oldtimer.geekstogo.com/OTM.exe a uložte na plochu. Spusťte a do levého okna zkopírujte:
:files
C:\Users\Anetka\AppData\Local\Akamai
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA
C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
C:\Windows\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat

:reg
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Akamai NetSession Interface"=-

:commands
[Purity]
[Emptytemp]
[Emptyflash]
a klikněte na >MoveIt!<. Po skenu restartujte PC a dejte nový log RSIT.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krajta5
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 03 črc 2013 16:43

Re: Svchost a Installer Worker vytěžuje disk

#7 Příspěvek od krajta5 »

Logfile of random's system information tool 1.14 (written by random/random)
Run by Anetka at 2016-12-07 06:40:50
Microsoft Windows 8.1 Pro N
System drive C: has 410 GB (82%) free of 500 GB
Total RAM: 4016 MB (56% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:40:51, on 7. 12. 2016
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.9600.18123)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe
C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE
C:\Program Files (x86)\Microsoft Office\Root\Office16\MsoSync.exe
C:\Program Files\trend micro\Anetka_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.cz/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll
O2 - BHO: Microsoft OneDrive for Business Browser Helper - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll
O4 - HKLM\..\Run: [snp2uvc] C:\Windows\vsnp2uvc.exe
O4 - HKLM\..\Run: [Autodesk Desktop App] "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
O4 - HKLM\..\Run: [Avira SystrayStartTrigger] "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
O4 - HKLM\..\Run: [Avira System Speedup User Starter] "C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
O4 - HKCU\..\Run: [DAEMON Tools Lite Automount] "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
O4 - HKCU\..\Run: [Steam] "C:\Program Files (x86)\Steam\steam.exe" -silent
O4 - Startup: Poslat do aplikace OneNote.lnk = C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
O4 - Startup: zSpeedup.lnk = C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe
O4 - Global Startup: CodeMeter Control Center.lnk = C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
O9 - Extra button: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra 'Tools' menuitem: Lync Click to Call - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{83962CAD-4E16-4DE0-BDE0-6B37999F69A9}: NameServer = 8.8.8.8,8.8.4.4
O17 - HKLM\System\CS1\Services\Tcpip\..\{83962CAD-4E16-4DE0-BDE0-6B37999F69A9}: NameServer = 8.8.8.8,8.8.4.4
O18 - Protocol: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O18 - Protocol: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
O23 - Service: Autodesk Desktop App Service (AdAppMgrSvc) - Autodesk Inc. - C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Avira Mail Protection (AntiVirMailService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe
O23 - Service: Avira Scheduler (AntiVirSchedulerService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\sched.exe
O23 - Service: Avira Real-Time Protection (AntiVirService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avguard.exe
O23 - Service: Avira Web Protection (AntiVirWebService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe
O23 - Service: Avira Service Host (Avira.ServiceHost) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
O23 - Service: Avira Phantom VPN (AviraPhantomVPN) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe
O23 - Service: CodeMeter Runtime Server (CodeMeter.exe) - WIBU-SYSTEMS AG - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @C:\Windows\system32\CxAudMsg64.exe,-100 (CxAudMsg) - Unknown owner - C:\Windows\system32\CxAudMsg64.exe (file missing)
O23 - Service: Disc Soft Lite Bus Service - Disc Soft Ltd - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Elan Service (ETDService) - ELAN Microelectronics Corp. - C:\Program Files\Elantech\ETDService.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel(R) Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FlexNet Licensing Service 64 - Flexera Software LLC - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel Bluetooth Service (ibtsiva.exe) - Intel Corporation - C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing)
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Unknown owner - C:\Windows\system32\igfxCUIService.exe (file missing)
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA NetworkService Container (NvContainerNetworkService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Wireless Controller Service - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel(R) Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Conexant SmartAudio service (SAService) - Conexant Systems, Inc. - C:\Windows\system32\SAsrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: Avira System Speedup (SpeedupService) - Avira Operations GmbH & Co. KG - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel(R) PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

--
End of file - 12457 bytes

======Enumerating Processes======

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\dwm.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\igfxCUIService.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe 972055964384
\??\C:\Windows\system32\conhost.exe 0x4
C:\Windows\System32\spoolsv.exe
"C:\Program Files (x86)\Avira\Antivirus\sched.exe"
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe"
"C:\Program Files (x86)\Avira\Antivirus\avguard.exe"
"C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe"
"C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe" /service
C:\Windows\system32\taskhostex.exe
C:\Windows\system32\taskeng.exe
"C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /c
C:\Windows\Explorer.EXE
C:\Windows\system32\CxAudMsg64.exe
C:\Windows\System32\svchost.exe -k utcsvc
"C:\Program Files\Elantech\ETDService.exe"
"C:\Program Files\Elantech\ETDCtrl.exe"
"C:\Program Files\Intel\WiFi\bin\EvtEng.exe"
"C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe"
"C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe" -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe"
"C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe"
C:\Windows\SysWOW64\SAsrv.exe
"C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
"C:\Program Files (x86)\Avira\Antivirus\avshadow.exe" avshadowcontrol0_000006b0
"C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe" -f "C:\ProgramData\NVIDIA\NvContainerUser%d.log" -d "C:\Program Files (x86)\NVIDIA Corporation\NvContainer\plugins\User" -r -l 3 -p 30000 -c
"C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe" -autorun
"C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe"
"C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe"
C:\Windows\system32\wbem\unsecapp.exe -Embedding
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\igfxEM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\igfxHK.exe
C:\Windows\system32\igfxTray.exe
"C:\Program Files\Elantech\ETDCtrlHelper.exe"
"C:\Program Files\Elantech\ETDIntelligent.exe"
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\dashost.exe
C:\Windows\system32\SearchIndexer.exe /Embedding
"C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\LiveComm.exe" -ServerName:Microsoft.WindowsLive.Platform.Server
C:\Windows\System32\skydrive.exe -Embedding
C:\Windows\system32\DllHost.exe /Processid:{30D49246-D217-465F-B00B-AC9DDD652EB7}
C:\Windows\System32\RuntimeBroker.exe -Embedding
"C:\Program Files\CONEXANT\ForteConfig\fmapp.exe"
"C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe"
"C:\Program Files\Autodesk\Personal Accelerator for Revit\RevitAccelerator.exe"
"C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
"C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe" /connectToHost
"C:\Windows\System32\SettingSyncHost.exe" -Embedding
"C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe" index.js
\??\C:\Windows\system32\conhost.exe 0x4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" 1 0
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel=-m --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=54.0.2840.99 --handshake-handle=0x10c
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillCreditCardSigninPromo/Default/AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/NonValidatingReloadOnNormalReload/Enabled2/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/StrictSecureCookies/Disabled/SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/WebBluetoothBlacklist/BlacklistUpdate1/WebFontsInterventionV2/Default/ --disable-direct-composition --supports-dual-gpus=false --gpu-driver-bug-workarounds=5,15,16,17,20,34,51,60 --gpu-vendor-id=0x8086 --gpu-device-id=0x1616 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=20.19.15.4531 --gpu-driver-date=9-29-2016 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x1299 --mojo-application-channel-token=29B7F38E6BC0556E1B3B7DF22E3F40A8 --mojo-platform-channel-handle=1112 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Microsoft Office\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE16\CSISYNCCLIENT.EXE" -Embedding
"C:\Program Files (x86)\Microsoft Office\Root\Office16\MsoSync.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features="*AutofillCreditCardSigninPromo<AutofillCreditCardSigninPromo,AutomaticTabDiscarding<AutomaticTabDiscarding,BlockSmallPluginContent<PluginPowerSaverTiny,MaterialDesignUserManager<MaterialDesignUserManager,NonValidatingReloadOnNormalReload<NonValidatingReloadOnNormalReload,*OverrideYouTubeFlashEmbed<Override YouTube Flash emed,*PointerEvent<PointerEvent,*PreconnectMore<PreconnectMore,SubresourceFilter<SubresourceFilter,*TranslateUI2016Q2<TranslateUI2016Q2" --disable-features=DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,MetricsReporting<MetricsAndCrashSampling,ParseHTMLOnMainThread<ParseHTMLOnMainThread,SSLPostQuantumExperiment<SSLPostQuantum,SecurityWarningIconUpdate<SecurityWarningIconUpdate,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillCreditCardSigninPromo/Default/*AutomaticTabDiscarding/Enabled_Once_10-gen2/CaptivePortalInterstitial/Enabled/*ChildAccountDetection/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DisallowFetchForDocWrittenScriptsInMainFrame/Default/EnableWin32kLockDownMimeTypes/PPAPILockdown_Enabled/*EnforceCTForProblematicRoots/disabled/ExtensionDeveloperModeWarning/Enabled/*GFE/Default/GoogleBrandedContextMenu/default/InstanceID/Enabled/MaterialDesignDownloads/Enabled/MaterialDesignUserManager/Enabled/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*NonValidatingReloadOnNormalReload/Enabled2/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/Disabled/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/PluginPowerSaverTiny/Enabled2/*PreconnectMore/Default/*QUIC/EnabledNoId/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SafeBrowsingUpdateFrequency/Default/SecurityWarningIconUpdate/Control/SignInPasswordPromo/Default/*StrictSecureCookies/Disabled/*SubresourceFilter/EnabledForPhishingSites/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group3/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_72/*UMA-Uniformity-Trial-10-Percent/group_01/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_04/*UMA-Uniformity-Trial-50-Percent/default/WebBluetoothBlacklist/BlacklistUpdate1/*WebFontsInterventionV2/Default/ --disable-databases --primordial-pipe-token=4C8ECB3CB0CC16A73B5C5C25DC0D6121 --lang=cs --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --enable-pinch --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553 --mojo-application-channel-token=4C8ECB3CB0CC16A73B5C5C25DC0D6121 --channel="6384.5.886037609\1023265344" --mojo-platform-channel-handle=2164 /prefetch:1
C:\Windows\system32\wbem\wmiprvse.exe
"C:\Windows\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe2_ Global\UsGthrCtrlFltPipeMssGthrPipe2 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\Windows\system32\SearchFilterHost.exe" 0 572 576 584 65536 580
"C:\Users\Anetka\Desktop\RSITx64.exe"

======Scheduled tasks folder======

C:\Windows\tasks\Adobe Flash Player PPAPI Notifier.job - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe -check pepperplugin
C:\Windows\tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Adobe Flash Player PPAPI Notifier - C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_23_0_0_207_pepper.exe -check pepperplugin
C:\Windows\system32\tasks\Adobe Flash Player Updater - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
C:\Windows\system32\tasks\Avira System Speedup Tray - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.UI.Systray.exe -autorun
C:\Windows\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\Windows\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\Windows\system32\tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4117213250-101706349-321446703-1001 - %localappdata%\Microsoft\OneDrive\OneDrive.exe /autoupdate
C:\Windows\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe
C:\Windows\system32\tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
C:\Windows\system32\tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe
C:\Windows\system32\tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon
C:\Windows\system32\tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe
C:\Windows\system32\tasks\OneDrive Standalone Update Task - C:\Users\Anetka\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
C:\Windows\system32\tasks\User_Feed_Synchronization-{2CA74BE9-FC3D-4F1E-9408-B22E2F955737} - C:\Windows\system32\msfeedssync.exe sync
C:\Windows\system32\tasks\WPD\SqmUpload_S-1-5-21-4117213250-101706349-321446703-1001 - %windir%\system32\rundll32.exe portabledeviceapi.dll,#1
C:\Windows\system32\tasks\Microsoft\Windows\WS\License Validation - rundll32.exe WSClient.dll,WSpTLR licensing
C:\Windows\system32\tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask - rundll32.exe WSClient.dll,RefreshBannedAppsList
C:\Windows\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join - %SystemRoot%\System32\AutoWorkplace.exe join
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network - C:\Windows\system32\sc.exe start wuauserv
C:\Windows\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\Windows\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\Windows\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -queuereporting
C:\Windows\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\Windows\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\Windows\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\Windows\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\Windows\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\Windows\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\Windows\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\Windows\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\Windows\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\Windows\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\Windows\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\Windows\system32\tasks\Microsoft\Windows\MUI\Mcbuilder - C:\Windows\System32\mcbuilder.exe
C:\Windows\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\Windows\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotifications.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\Windows\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\Windows\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\Windows\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\Windows\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Uploader - %windir%\system32\WSqmCons.exe -u
C:\Windows\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\Windows\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\Windows\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\Windows\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\AitAgent - aitagent /increment
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattel\DiagTrackRunner.exe /UploadEtlFilesOnly
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\rundll32.exe %windir%\system32\invagent.dll,RunUpdate
C:\Windows\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\Windows\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\Windows\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\Windows\system32\tasks\Microsoft\Office\Office Automatic Updates - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /update SCHEDULEDTASK displaylevel=False
C:\Windows\system32\tasks\Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService
C:\Windows\system32\tasks\Microsoft\Office\Office Subscription Maintenance - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 - C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe scan upload mininterval:2880
C:\Windows\system32\tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 - C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe scan upload
C:\Windows\system32\tasks\Lenovo\Lenovo Customer Feedback Program 64 - "%ProgramFiles(x86)%\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe"

=========Google Chrome=========

C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Prezentace Google 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Obchod Chrome 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Dokumenty Google 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Disk Google 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Tabulky Google 1.1
Extension flliilndjeohchalpbbcdekjklbdgfkk 0 Avira Browser Safety 2.0.0
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Dokumenty Google offline 1.4
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.38
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mfffpogegjflfpflabcdkioaeobkgjik 1 GaiaAuthExtension 0.0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.0
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Platby Internetového obchodu Chrome 1.0.0.0
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5416.905.0.6
Homepage:
default_search_provider.search_url:
C:\Users\Anetka\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\flliilndjeohchalpbbcdekjklbdgfkk]
"Path"=


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={0633EE93-D776-472f-A0FF-E1416B8B2E3A}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-11-16 213192]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-11-16 2099504]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}]
Lync Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2016-11-16 154824]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\ssv.dll [2016-11-23 460384]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF}]
Microsoft OneDrive for Business Browser Helper - C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2016-11-16 1522472]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_45\bin\jp2ssv.dll [2016-11-23 172640]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ETDCtrl"=C:\Program Files\Elantech\ETDCtrl.exe [2014-08-20 3282248]
"ForteConfig"=C:\Program Files\Conexant\ForteConfig\fmapp.exe [2010-10-25 49056]
"SmartAudio"=C:\Program Files\CONEXANT\SAII\SACpl.exe [2014-04-09 1830616]
"cAudioFilterAgent"=C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [2014-11-20 919768]
"pac"=C:\Program Files\Autodesk\Personal Accelerator for Revit\RevitAccelerator.exe [2016-02-10 339464]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"DAEMON Tools Lite Automount"=C:\Program Files\DAEMON Tools Lite\DTAgent.exe [2016-07-29 4299968]
"Steam"=C:\Program Files (x86)\Steam\steam.exe [2016-10-13 2860832]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"snp2uvc"=C:\Windows\vsnp2uvc.exe []
"Autodesk Desktop App"=C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [2016-07-01 721856]
"Avira SystrayStartTrigger"=C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe [2016-11-25 60120]
"Avira System Speedup User Starter"=C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe [2016-11-23 25256]
"avgnt"=C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [2016-10-17 916072]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
CodeMeter Control Center.lnk - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeterCC.exe

C:\Users\Anetka\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Poslat do aplikace OneNote.lnk - C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE
zSpeedup.lnk - C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.Core.Common.Starter.exe

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"PromptOnSecureDesktop"=0
"ConsentPromptBehaviorAdmin"=0

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
""=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe"="C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe:*:Enabled:CodeMeter Runtime Server"


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
"StubPath"="C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"VIDC.YUY2"=msyuv.dll
"vidc.i420"=iyuv_32.dll
"msacm.msgsm610"=msgsm32.acm
"msacm.msg711"=msg711.acm
"VIDC.YVYU"=msyuv.dll
"VIDC.YVU9"=tsbyuv.dll
"wavemapper"=msacm32.drv
"midimapper"=midimap.dll
"VIDC.UYVY"=msyuv.dll
"VIDC.IYUV"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.msadpcm"=msadp32.acm
"vidc.msvc"=msvidc32.dll
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv
"VIDC.LAGS"=lagarith.dll
"VIDC.X264"=x264vfw64.dll
"VIDC.XVID"=xvidvfw.dll
"msacm.ac3acm"=ac3acm.acm
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"wave2"=wdmaud.drv
"midi2"=wdmaud.drv
"mixer2"=wdmaud.drv
"wave3"=wdmaud.drv
"midi3"=wdmaud.drv
"mixer3"=wdmaud.drv
"wave4"=wdmaud.drv
"midi4"=wdmaud.drv
"mixer4"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*
.scr - open - C:\Windows\system32\notepad.exe "%1"
.scr - install -
.scr - config -

======List of files/folders created in the last 1 month======

2016-12-07 06:33:40 ----D---- C:\_OTM
2016-12-06 19:17:58 ----D---- C:\AdwCleaner
2016-12-06 18:05:30 ----D---- C:\Program Files\trend micro
2016-12-06 18:05:29 ----D---- C:\rsit
2016-12-06 17:53:16 ----A---- C:\Windows\SYSWOW64\aspnet_counters.dll
2016-12-06 17:53:16 ----A---- C:\Windows\system32\aspnet_counters.dll
2016-12-05 17:44:16 ----A---- C:\Windows\SYSWOW64\XAudio2_6.dll
2016-12-05 17:44:16 ----A---- C:\Windows\SYSWOW64\XAPOFX1_4.dll
2016-12-05 17:44:16 ----A---- C:\Windows\system32\XAudio2_6.dll
2016-12-05 17:44:16 ----A---- C:\Windows\system32\XAPOFX1_4.dll
2016-12-05 17:44:15 ----A---- C:\Windows\SYSWOW64\xactengine3_6.dll
2016-12-05 17:44:15 ----A---- C:\Windows\SYSWOW64\X3DAudio1_7.dll
2016-12-05 17:44:15 ----A---- C:\Windows\system32\xactengine3_6.dll
2016-12-05 17:44:15 ----A---- C:\Windows\system32\X3DAudio1_7.dll
2016-12-05 17:44:13 ----A---- C:\Windows\SYSWOW64\XAudio2_5.dll
2016-12-05 17:44:13 ----A---- C:\Windows\system32\XAudio2_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\SYSWOW64\xactengine3_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\SYSWOW64\D3DCompiler_42.dll
2016-12-05 17:44:12 ----A---- C:\Windows\system32\xactengine3_5.dll
2016-12-05 17:44:12 ----A---- C:\Windows\system32\D3DCompiler_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\SYSWOW64\d3dx11_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\SYSWOW64\d3dcsx_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\system32\d3dx11_42.dll
2016-12-05 17:44:11 ----A---- C:\Windows\system32\d3dcsx_42.dll
2016-12-05 17:44:10 ----A---- C:\Windows\SYSWOW64\d3dx10_42.dll
2016-12-05 17:44:10 ----A---- C:\Windows\system32\d3dx10_42.dll
2016-12-05 17:44:09 ----A---- C:\Windows\SYSWOW64\D3DX9_42.dll
2016-12-05 17:44:09 ----A---- C:\Windows\system32\D3DX9_42.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\D3DX9_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\d3dx10_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\SYSWOW64\D3DCompiler_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\D3DX9_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\d3dx10_41.dll
2016-12-05 17:44:08 ----A---- C:\Windows\system32\D3DCompiler_41.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\XAudio2_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\XAPOFX1_3.dll
2016-12-05 17:44:07 ----A---- C:\Windows\SYSWOW64\xactengine3_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\XAudio2_4.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\XAPOFX1_3.dll
2016-12-05 17:44:07 ----A---- C:\Windows\system32\xactengine3_4.dll
2016-12-05 17:44:06 ----A---- C:\Windows\SYSWOW64\X3DAudio1_6.dll
2016-12-05 17:44:06 ----A---- C:\Windows\system32\X3DAudio1_6.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\D3DX9_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\d3dx10_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\SYSWOW64\D3DCompiler_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\D3DX9_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\d3dx10_40.dll
2016-12-05 17:44:05 ----A---- C:\Windows\system32\D3DCompiler_40.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\XAudio2_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\XAPOFX1_2.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\xactengine3_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\SYSWOW64\X3DAudio1_5.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\XAudio2_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\XAPOFX1_2.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\xactengine3_3.dll
2016-12-05 17:44:03 ----A---- C:\Windows\system32\X3DAudio1_5.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\XAudio2_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\XAPOFX1_1.dll
2016-12-05 17:44:01 ----A---- C:\Windows\SYSWOW64\xactengine3_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\XAudio2_2.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\XAPOFX1_1.dll
2016-12-05 17:44:01 ----A---- C:\Windows\system32\xactengine3_2.dll
2016-12-05 17:44:00 ----A---- C:\Windows\SYSWOW64\d3dx10_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\SYSWOW64\D3DCompiler_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\system32\d3dx10_39.dll
2016-12-05 17:44:00 ----A---- C:\Windows\system32\D3DCompiler_39.dll
2016-12-05 17:43:59 ----A---- C:\Windows\SYSWOW64\D3DX9_39.dll
2016-12-05 17:43:59 ----A---- C:\Windows\system32\D3DX9_39.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\XAudio2_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\XAPOFX1_0.dll
2016-12-05 17:43:58 ----A---- C:\Windows\SYSWOW64\xactengine3_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\XAudio2_1.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\XAPOFX1_0.dll
2016-12-05 17:43:58 ----A---- C:\Windows\system32\xactengine3_1.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\X3DAudio1_4.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\d3dx10_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\SYSWOW64\D3DCompiler_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\X3DAudio1_4.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\d3dx10_38.dll
2016-12-05 17:43:57 ----A---- C:\Windows\system32\D3DCompiler_38.dll
2016-12-05 17:43:56 ----A---- C:\Windows\SYSWOW64\D3DX9_38.dll
2016-12-05 17:43:56 ----A---- C:\Windows\system32\D3DX9_38.dll
2016-12-05 17:43:55 ----A---- C:\Windows\SYSWOW64\XAudio2_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\SYSWOW64\xactengine3_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\system32\XAudio2_0.dll
2016-12-05 17:43:55 ----A---- C:\Windows\system32\xactengine3_0.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\X3DAudio1_3.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\d3dx10_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\SYSWOW64\D3DCompiler_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\X3DAudio1_3.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\d3dx10_37.dll
2016-12-05 17:43:54 ----A---- C:\Windows\system32\D3DCompiler_37.dll
2016-12-05 17:43:53 ----A---- C:\Windows\SYSWOW64\xactengine2_10.dll
2016-12-05 17:43:53 ----A---- C:\Windows\SYSWOW64\D3DX9_37.dll
2016-12-05 17:43:53 ----A---- C:\Windows\system32\xactengine2_10.dll
2016-12-05 17:43:53 ----A---- C:\Windows\system32\D3DX9_37.dll
2016-12-05 17:43:52 ----A---- C:\Windows\SYSWOW64\d3dx10_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\SYSWOW64\D3DCompiler_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\system32\d3dx10_36.dll
2016-12-05 17:43:52 ----A---- C:\Windows\system32\D3DCompiler_36.dll
2016-12-05 17:43:51 ----A---- C:\Windows\SYSWOW64\xactengine2_9.dll
2016-12-05 17:43:51 ----A---- C:\Windows\SYSWOW64\d3dx9_36.dll
2016-12-05 17:43:51 ----A---- C:\Windows\system32\xactengine2_9.dll
2016-12-05 17:43:51 ----A---- C:\Windows\system32\d3dx9_36.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\d3dx9_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\d3dx10_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\SYSWOW64\D3DCompiler_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\d3dx9_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\d3dx10_35.dll
2016-12-05 17:43:50 ----A---- C:\Windows\system32\D3DCompiler_35.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\xactengine2_8.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\X3DAudio1_2.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\d3dx10_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\SYSWOW64\D3DCompiler_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\xactengine2_8.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\X3DAudio1_2.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\d3dx10_34.dll
2016-12-05 17:43:49 ----A---- C:\Windows\system32\D3DCompiler_34.dll
2016-12-05 17:43:48 ----A---- C:\Windows\SYSWOW64\xinput1_3.dll
2016-12-05 17:43:48 ----A---- C:\Windows\SYSWOW64\d3dx9_34.dll
2016-12-05 17:43:48 ----A---- C:\Windows\system32\xinput1_3.dll
2016-12-05 17:43:48 ----A---- C:\Windows\system32\d3dx9_34.dll
2016-12-05 17:43:47 ----A---- C:\Windows\SYSWOW64\xactengine2_7.dll
2016-12-05 17:43:47 ----A---- C:\Windows\system32\xactengine2_7.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\d3dx9_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\d3dx10_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\SYSWOW64\D3DCompiler_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\d3dx9_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\d3dx10_33.dll
2016-12-05 17:43:46 ----A---- C:\Windows\system32\D3DCompiler_33.dll
2016-12-05 17:43:45 ----A---- C:\Windows\SYSWOW64\xactengine2_6.dll
2016-12-05 17:43:45 ----A---- C:\Windows\system32\xactengine2_6.dll
2016-12-05 17:43:44 ----A---- C:\Windows\SYSWOW64\xactengine2_5.dll
2016-12-05 17:43:44 ----A---- C:\Windows\SYSWOW64\d3dx10.dll
2016-12-05 17:43:44 ----A---- C:\Windows\system32\xactengine2_5.dll
2016-12-05 17:43:44 ----A---- C:\Windows\system32\d3dx10.dll
2016-12-05 17:43:43 ----A---- C:\Windows\SYSWOW64\d3dx9_32.dll
2016-12-05 17:43:43 ----A---- C:\Windows\system32\d3dx9_32.dll
2016-12-05 17:43:42 ----A---- C:\Windows\SYSWOW64\xactengine2_4.dll
2016-12-05 17:43:42 ----A---- C:\Windows\SYSWOW64\x3daudio1_1.dll
2016-12-05 17:43:42 ----A---- C:\Windows\system32\xactengine2_4.dll
2016-12-05 17:43:42 ----A---- C:\Windows\system32\x3daudio1_1.dll
2016-12-05 17:43:41 ----A---- C:\Windows\SYSWOW64\d3dx9_31.dll
2016-12-05 17:43:41 ----A---- C:\Windows\system32\d3dx9_31.dll
2016-12-05 17:43:40 ----A---- C:\Windows\SYSWOW64\xinput1_2.dll
2016-12-05 17:43:40 ----A---- C:\Windows\SYSWOW64\xactengine2_3.dll
2016-12-05 17:43:40 ----A---- C:\Windows\system32\xinput1_2.dll
2016-12-05 17:43:40 ----A---- C:\Windows\system32\xactengine2_3.dll
2016-12-05 17:43:39 ----A---- C:\Windows\SYSWOW64\xactengine2_2.dll
2016-12-05 17:43:39 ----A---- C:\Windows\system32\xactengine2_2.dll
2016-12-05 17:43:21 ----A---- C:\Windows\SYSWOW64\xactengine2_0.dll
2016-12-05 17:43:21 ----A---- C:\Windows\SYSWOW64\d3dx9_29.dll
2016-12-05 17:43:21 ----A---- C:\Windows\system32\xactengine2_0.dll
2016-12-05 17:43:21 ----A---- C:\Windows\system32\d3dx9_29.dll
2016-12-05 17:43:20 ----A---- C:\Windows\SYSWOW64\d3dx9_28.dll
2016-12-05 17:43:20 ----A---- C:\Windows\system32\d3dx9_28.dll
2016-12-05 17:43:19 ----A---- C:\Windows\SYSWOW64\d3dx9_27.dll
2016-12-05 17:43:19 ----A---- C:\Windows\system32\d3dx9_27.dll
2016-12-05 17:43:18 ----A---- C:\Windows\SYSWOW64\d3dx9_26.dll
2016-12-05 17:43:18 ----A---- C:\Windows\system32\d3dx9_26.dll
2016-12-05 17:43:17 ----A---- C:\Windows\SYSWOW64\d3dx9_25.dll
2016-12-05 17:43:17 ----A---- C:\Windows\SYSWOW64\d3dx9_24.dll
2016-12-05 17:43:17 ----A---- C:\Windows\system32\d3dx9_25.dll
2016-12-05 17:43:17 ----A---- C:\Windows\system32\d3dx9_24.dll
2016-12-05 16:14:25 ----A---- C:\Windows\system32\drivers\avusbflt.sys
2016-12-05 16:13:28 ----D---- C:\Program Files (x86)\Steam
2016-12-05 16:12:38 ----A---- C:\Windows\system32\drivers\avnetflt.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avkmgr.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avipbb.sys
2016-12-05 16:12:37 ----A---- C:\Windows\system32\drivers\avgntflt.sys
2016-12-05 16:07:25 ----SHD---- C:\Config.Msi
2016-12-05 16:06:11 ----D---- C:\Users\Anetka\AppData\Roaming\Mozilla
2016-12-05 16:05:59 ----D---- C:\Program Files (x86)\Avira
2016-12-05 16:05:57 ----D---- C:\ProgramData\Avira
2016-12-05 15:43:48 ----A---- C:\Windows\SYSWOW64\nvStreaming.exe
2016-12-05 15:43:45 ----D---- C:\Program Files (x86)\VulkanRT
2016-12-05 15:40:43 ----A---- C:\Windows\SYSWOW64\nvwgf2um.dll
2016-12-05 15:40:43 ----A---- C:\Windows\system32\nvwgf2umx.dll
2016-12-05 15:40:42 ----A---- C:\Windows\SYSWOW64\nvptxJitCompiler.dll
2016-12-05 15:40:42 ----A---- C:\Windows\system32\nvptxJitCompiler.dll
2016-12-05 15:40:41 ----A---- C:\Windows\system32\nvopencl.dll
2016-12-05 15:40:40 ----A---- C:\Windows\SYSWOW64\nvopencl.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvoglv32.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvinit.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvIFROpenGL.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvIFR.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\NvFBC.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvfatbinaryLoader.dll
2016-12-05 15:40:39 ----A---- C:\Windows\SYSWOW64\nvEncodeAPI.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvinitx.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvIFROpenGL.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvIFR64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\NvFBC64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvfatbinaryLoader.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\nvEncodeAPI64.dll
2016-12-05 15:40:39 ----A---- C:\Windows\system32\drivers\nvlddmkm.sys
2016-12-05 15:40:38 ----A---- C:\Windows\system32\nvdispgenco6437609.dll
2016-12-05 15:40:38 ----A---- C:\Windows\system32\nvdispco6437609.dll
2016-12-05 15:40:37 ----A---- C:\Windows\SYSWOW64\nvd3dum.dll
2016-12-05 15:40:37 ----A---- C:\Windows\SYSWOW64\nvcuvid.dll
2016-12-05 15:40:37 ----A---- C:\Windows\system32\nvcuvid.dll
2016-12-05 15:40:37 ----A---- C:\Windows\system32\nvcuda.dll
2016-12-05 15:40:36 ----A---- C:\Windows\SYSWOW64\nvcuda.dll
2016-12-05 15:40:34 ----A---- C:\Windows\system32\nvcompiler.dll
2016-12-05 15:40:33 ----A---- C:\Windows\SYSWOW64\nvcompiler.dll
2016-12-05 15:30:59 ----A---- C:\Windows\system32\NvRtmpStreamer64.dll
2016-12-05 15:30:58 ----A---- C:\Windows\SYSWOW64\nvspcap.dll
2016-12-05 15:30:58 ----A---- C:\Windows\SYSWOW64\nvspbridge.dll
2016-12-05 15:30:58 ----A---- C:\Windows\system32\nvspcap64.dll
2016-12-05 15:30:58 ----A---- C:\Windows\system32\nvspbridge64.dll
2016-12-05 15:30:34 ----A---- C:\Windows\NvContainerRecovery.bat
2016-12-05 15:30:21 ----A---- C:\Windows\SYSWOW64\nvaudcap32v.dll
2016-12-05 15:30:21 ----A---- C:\Windows\system32\nvaudcap64v.dll
2016-12-05 15:30:21 ----A---- C:\Windows\system32\drivers\nvvad64v.sys
2016-11-25 19:24:37 ----D---- C:\Users\Anetka\AppData\Roaming\NVIDIA
2016-11-25 19:24:31 ----D---- C:\Users\Anetka\AppData\Roaming\MAXON
2016-11-24 20:09:30 ----A---- C:\Windows\SYSWOW64\mfmp4srcsnk.dll
2016-11-24 20:09:30 ----A---- C:\Windows\system32\mfmp4srcsnk.dll
2016-11-24 20:09:28 ----A---- C:\Windows\SYSWOW64\wpdshext.dll
2016-11-24 20:09:28 ----A---- C:\Windows\system32\wpdshext.dll
2016-11-24 20:07:48 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.dll
2016-11-24 20:07:48 ----A---- C:\Windows\SYSWOW64\mfsvr.dll
2016-11-24 20:07:44 ----A---- C:\Windows\SYSWOW64\wmploc.DLL
2016-11-24 20:07:44 ----A---- C:\Windows\SYSWOW64\wmp.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\wmploc.DLL
2016-11-24 20:07:30 ----A---- C:\Windows\system32\wmp.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\Windows.Media.Streaming.dll
2016-11-24 20:07:30 ----A---- C:\Windows\system32\mfsvr.dll
2016-11-24 20:07:10 ----A---- C:\Windows\SYSWOW64\WMASF.DLL
2016-11-24 20:07:10 ----A---- C:\Windows\system32\WMASF.DLL
2016-11-24 18:46:30 ----A---- C:\Windows\SYSWOW64\XAudio2_7.dll
2016-11-24 18:46:30 ----A---- C:\Windows\SYSWOW64\XAPOFX1_5.dll
2016-11-24 18:46:30 ----A---- C:\Windows\system32\XAudio2_7.dll
2016-11-24 18:46:30 ----A---- C:\Windows\system32\XAPOFX1_5.dll
2016-11-24 18:46:29 ----A---- C:\Windows\SYSWOW64\xactengine3_7.dll
2016-11-24 18:46:29 ----A---- C:\Windows\SYSWOW64\D3DCompiler_43.dll
2016-11-24 18:46:29 ----A---- C:\Windows\system32\xactengine3_7.dll
2016-11-24 18:46:29 ----A---- C:\Windows\system32\D3DCompiler_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\SYSWOW64\d3dx11_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\SYSWOW64\d3dcsx_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\system32\d3dx11_43.dll
2016-11-24 18:46:28 ----A---- C:\Windows\system32\d3dcsx_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\SYSWOW64\D3DX9_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\SYSWOW64\d3dx10_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\system32\D3DX9_43.dll
2016-11-24 18:46:27 ----A---- C:\Windows\system32\d3dx10_43.dll
2016-11-24 18:46:26 ----A---- C:\Windows\SYSWOW64\xinput1_1.dll
2016-11-24 18:46:26 ----A---- C:\Windows\system32\xinput1_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\SYSWOW64\xactengine2_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\SYSWOW64\x3daudio1_0.dll
2016-11-24 18:46:25 ----A---- C:\Windows\system32\xactengine2_1.dll
2016-11-24 18:46:25 ----A---- C:\Windows\system32\x3daudio1_0.dll
2016-11-24 18:46:18 ----A---- C:\Windows\SYSWOW64\d3dx9_30.dll
2016-11-24 18:46:18 ----A---- C:\Windows\system32\d3dx9_30.dll
2016-11-24 18:40:23 ----A---- C:\Windows\SYSWOW64\mfds.dll
2016-11-24 18:40:23 ----A---- C:\Windows\system32\mfds.dll
2016-11-24 17:08:05 ----D---- C:\Program Files\WIBU-SYSTEMS
2016-11-24 17:07:57 ----D---- C:\ProgramData\CodeMeter
2016-11-24 17:07:57 ----D---- C:\Program Files\CodeMeter
2016-11-24 17:07:57 ----D---- C:\Program Files (x86)\CodeMeter
2016-11-24 17:01:50 ----D---- C:\Program Files\GRAPHISOFT
2016-11-24 15:17:15 ----A---- C:\Windows\system32\msmpeg2vdec.dll
2016-11-24 15:17:14 ----A---- C:\Windows\SYSWOW64\msmpeg2vdec.dll
2016-11-24 15:17:14 ----A---- C:\Windows\system32\WMVCORE.DLL
2016-11-24 15:17:13 ----A---- C:\Windows\system32\MSAudDecMFT.dll
2016-11-24 15:17:12 ----A---- C:\Windows\SYSWOW64\WMVCORE.DLL
2016-11-24 15:17:12 ----A---- C:\Windows\SYSWOW64\MSAudDecMFT.dll
2016-11-24 15:17:12 ----A---- C:\Windows\system32\wmpmde.dll
2016-11-24 15:17:11 ----A---- C:\Windows\system32\mfasfsrcsnk.dll
2016-11-24 15:17:11 ----A---- C:\Windows\system32\blackbox.dll
2016-11-24 15:17:09 ----A---- C:\Windows\system32\winmde.dll
2016-11-24 15:17:08 ----A---- C:\Windows\SYSWOW64\mfasfsrcsnk.dll
2016-11-24 15:17:08 ----A---- C:\Windows\system32\drmv2clt.dll
2016-11-24 15:17:07 ----A---- C:\Windows\SYSWOW64\winmde.dll
2016-11-24 15:17:07 ----A---- C:\Windows\SYSWOW64\blackbox.dll
2016-11-24 15:17:07 ----A---- C:\Windows\system32\WMPDMC.exe
2016-11-24 15:17:07 ----A---- C:\Windows\system32\WMNetMgr.dll
2016-11-24 15:17:07 ----A---- C:\Windows\system32\mfmpeg2srcsnk.dll
2016-11-24 15:17:06 ----A---- C:\Windows\system32\MFMediaEngine.dll
2016-11-24 15:17:05 ----A---- C:\Windows\SYSWOW64\mfsrcsnk.dll
2016-11-24 15:17:04 ----A---- C:\Windows\SYSWOW64\drmv2clt.dll
2016-11-24 15:17:04 ----A---- C:\Windows\system32\mfsrcsnk.dll
2016-11-24 15:17:04 ----A---- C:\Windows\system32\mfplat.dll
2016-11-24 15:17:03 ----A---- C:\Windows\SYSWOW64\WMPDMC.exe
2016-11-24 15:17:03 ----A---- C:\Windows\SYSWOW64\mfmpeg2srcsnk.dll
2016-11-24 15:17:02 ----A---- C:\Windows\SYSWOW64\WMNetMgr.dll
2016-11-24 15:17:02 ----A---- C:\Windows\SYSWOW64\MFMediaEngine.dll
2016-11-24 15:17:02 ----A---- C:\Windows\system32\Windows.Media.dll
2016-11-24 15:17:01 ----A---- C:\Windows\SYSWOW64\mfplat.dll
2016-11-24 15:17:01 ----A---- C:\Windows\system32\mf.dll
2016-11-24 15:17:00 ----A---- C:\Windows\SYSWOW64\Windows.Media.dll
2016-11-24 15:17:00 ----A---- C:\Windows\system32\wmdrmdev.dll
2016-11-24 15:17:00 ----A---- C:\Windows\system32\WebcamUi.dll
2016-11-24 15:16:59 ----A---- C:\Windows\SYSWOW64\wmdrmdev.dll
2016-11-24 15:16:59 ----A---- C:\Windows\SYSWOW64\mf.dll
2016-11-24 15:16:59 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2016-11-24 15:16:59 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
2016-11-24 15:16:58 ----A---- C:\Windows\SYSWOW64\MSMPEG2ENC.DLL
2016-11-24 15:16:58 ----A---- C:\Windows\system32\wmdrmnet.dll
2016-11-24 15:16:57 ----A---- C:\Windows\SYSWOW64\WebcamUi.dll
2016-11-24 15:16:57 ----A---- C:\Windows\SYSWOW64\mfreadwrite.dll
2016-11-24 15:16:57 ----A---- C:\Windows\system32\wmdrmsdk.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\wmdrmsdk.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\wmdrmnet.dll
2016-11-24 15:16:56 ----A---- C:\Windows\SYSWOW64\PortableDeviceApi.dll
2016-11-24 15:16:55 ----A---- C:\Windows\SYSWOW64\wmpeffects.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\mswmdm.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\msscp.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\MSAC3ENC.DLL
2016-11-24 15:16:55 ----A---- C:\Windows\system32\mfreadwrite.dll
2016-11-24 15:16:55 ----A---- C:\Windows\system32\CameraSettingsUIHost.exe
2016-11-24 15:16:54 ----A---- C:\Windows\SYSWOW64\mswmdm.dll
2016-11-24 15:16:54 ----A---- C:\Windows\SYSWOW64\MSAC3ENC.DLL
2016-11-24 15:16:54 ----A---- C:\Windows\system32\MDEServer.exe
2016-11-24 15:16:54 ----A---- C:\Windows\system32\DMRServer.exe
2016-11-24 15:16:53 ----A---- C:\Windows\SYSWOW64\msscp.dll
2016-11-24 15:16:53 ----A---- C:\Windows\SYSWOW64\MFCaptureEngine.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\WPDSp.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\wmpeffects.dll
2016-11-24 15:16:53 ----A---- C:\Windows\system32\MFCaptureEngine.dll
2016-11-24 15:16:52 ----A---- C:\Windows\SYSWOW64\msvproc.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\WmpDui.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\MFPlay.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\drmmgrtn.dll
2016-11-24 15:16:52 ----A---- C:\Windows\system32\dlnashext.dll
2016-11-24 15:16:50 ----A---- C:\Windows\SYSWOW64\MFPlay.dll
2016-11-24 15:16:50 ----A---- C:\Windows\system32\msvproc.dll
2016-11-24 15:16:50 ----A---- C:\Windows\system32\mftranscode.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\WPDSp.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\wmvdspa.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\mftranscode.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\mfh264enc.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\drmmgrtn.dll
2016-11-24 15:16:49 ----A---- C:\Windows\SYSWOW64\dlnashext.dll
2016-11-24 15:16:49 ----A---- C:\Windows\system32\wmvdspa.dll
2016-11-24 15:16:49 ----A---- C:\Windows\system32\mfh264enc.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\WmpDui.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\MSVideoDSP.dll
2016-11-24 15:16:48 ----A---- C:\Windows\SYSWOW64\cewmdm.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\wmpps.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\wmidx.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\MSVideoDSP.dll
2016-11-24 15:16:48 ----A---- C:\Windows\system32\cewmdm.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\wmidx.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\PortableDeviceTypes.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\mfdvdec.dll
2016-11-24 15:16:47 ----A---- C:\Windows\SYSWOW64\audiodev.dll
2016-11-24 15:16:47 ----A---- C:\Windows\system32\PortableDeviceWiaCompat.dll
2016-11-24 15:16:47 ----A---- C:\Windows\system32\msnetobj.dll
2016-11-24 15:16:46 ----A---- C:\Windows\SYSWOW64\msnetobj.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\wmpdxm.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2016-11-24 15:16:46 ----A---- C:\Windows\system32\mfdvdec.dll
2016-11-24 15:16:45 ----A---- C:\Windows\SYSWOW64\wmpdxm.dll
2016-11-24 15:16:45 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\WPDShServiceObj.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\unregmp2.exe
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\PortableDeviceWMDRM.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\PortableDeviceWiaCompat.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\mfmjpegdec.dll
2016-11-24 15:16:44 ----A---- C:\Windows\SYSWOW64\mfAACEnc.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\wpd_ci.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\PortableDeviceStatus.dll
2016-11-24 15:16:44 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\PortableDeviceStatus.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\PortableDeviceClassExtension.dll
2016-11-24 15:16:43 ----A---- C:\Windows\SYSWOW64\logagent.exe
2016-11-24 15:16:43 ----A---- C:\Windows\system32\mfAACEnc.dll
2016-11-24 15:16:43 ----A---- C:\Windows\system32\logagent.exe
2016-11-24 15:16:42 ----A---- C:\Windows\SYSWOW64\wmpshell.dll
2016-11-24 15:16:42 ----A---- C:\Windows\SYSWOW64\PortableDeviceConnectApi.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\wmpshell.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\Windows.Media.Renewal.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2016-11-24 15:16:42 ----A---- C:\Windows\system32\mfmjpegdec.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\wmpps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\Windows.Media.Streaming.ps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\rrinstaller.exe
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\mfpmp.exe
2016-11-24 15:16:41 ----A---- C:\Windows\SYSWOW64\CameraSettingsUIHost.exe
2016-11-24 15:16:41 ----A---- C:\Windows\system32\Windows.Media.Streaming.ps.dll
2016-11-24 15:16:41 ----A---- C:\Windows\system32\rrinstaller.exe
2016-11-24 15:16:41 ----A---- C:\Windows\system32\mfpmp.exe
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\WPDShextAutoplay.exe
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\wmdmps.dll
2016-11-24 15:16:40 ----A---- C:\Windows\SYSWOW64\wmdmlog.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2016-11-24 15:16:40 ----A---- C:\Windows\system32\wmdmps.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\wmdmlog.dll
2016-11-24 15:16:40 ----A---- C:\Windows\system32\unregmp2.exe
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\wmcodecdspps.dll
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\spwmp.dll
2016-11-24 15:16:39 ----A---- C:\Windows\SYSWOW64\LAPRXY.DLL
2016-11-24 15:16:39 ----A---- C:\Windows\system32\wmcodecdspps.dll
2016-11-24 15:16:39 ----A---- C:\Windows\system32\spwmp.dll
2016-11-24 15:16:39 ----A---- C:\Windows\system32\LAPRXY.DLL
2016-11-24 15:16:38 ----A---- C:\Windows\SYSWOW64\dxmasf.dll
2016-11-24 15:16:38 ----A---- C:\Windows\system32\dxmasf.dll
2016-11-23 18:48:30 ----A---- C:\Windows\system32\msmpeg2adec.dll
2016-11-23 18:48:29 ----A---- C:\Windows\SYSWOW64\msmpeg2adec.dll
2016-11-23 18:48:29 ----A---- C:\Windows\SYSWOW64\mfcore.dll
2016-11-23 18:48:29 ----A---- C:\Windows\system32\WMVDECOD.DLL
2016-11-23 18:48:29 ----A---- C:\Windows\system32\mfcore.dll
2016-11-23 18:48:28 ----A---- C:\Windows\SYSWOW64\WMVDECOD.DLL
2016-11-23 18:48:28 ----A---- C:\Windows\system32\WMVENCOD.DLL
2016-11-23 18:48:28 ----A---- C:\Windows\system32\mfnetsrc.dll
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\WMVENCOD.DLL
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\mfnetsrc.dll
2016-11-23 18:48:27 ----A---- C:\Windows\SYSWOW64\mfnetcore.dll
2016-11-23 18:48:27 ----A---- C:\Windows\system32\mfnetcore.dll
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\WMADMOE.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\WMADMOD.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\SYSWOW64\evr.dll
2016-11-23 18:48:26 ----A---- C:\Windows\system32\WMADMOD.DLL
2016-11-23 18:48:26 ----A---- C:\Windows\system32\evr.dll
2016-11-23 18:48:25 ----A---- C:\Windows\SYSWOW64\WMVSDECD.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\SYSWOW64\WMSPDMOE.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\system32\WMVSDECD.DLL
2016-11-23 18:48:25 ----A---- C:\Windows\system32\WMADMOE.DLL
2016-11-23 18:48:24 ----A---- C:\Windows\SYSWOW64\MP4SDECD.DLL
2016-11-23 18:48:23 ----A---- C:\Windows\system32\WMSPDMOE.DLL
2016-11-23 18:48:22 ----A---- C:\Windows\SYSWOW64\MFWMAAEC.DLL
2016-11-23 18:48:22 ----A---- C:\Windows\system32\WMVSENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\WMVXENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\WMVSENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\VIDRESZR.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\MPG4DECD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\SYSWOW64\COLORCNV.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\WMVXENCD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\MP4SDECD.DLL
2016-11-23 18:48:21 ----A---- C:\Windows\system32\MFWMAAEC.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\RESAMPLEDMO.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\MP43DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\MP3DMOD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\mfvdsp.dll
2016-11-23 18:48:20 ----A---- C:\Windows\SYSWOW64\mfps.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\VIDRESZR.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\RESAMPLEDMO.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MPG4DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MP43DECD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\MP3DMOD.DLL
2016-11-23 18:48:20 ----A---- C:\Windows\system32\mfvdsp.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\mfps.dll
2016-11-23 18:48:20 ----A---- C:\Windows\system32\COLORCNV.DLL
2016-11-23 18:45:50 ----A---- C:\Windows\system32\wpdbusenum.dll
2016-11-23 17:05:53 ----D---- C:\Users\Anetka\AppData\Roaming\Graphisoft
2016-11-23 16:59:06 ----D---- C:\Program Files\Windows Portable Devices
2016-11-23 16:59:06 ----D---- C:\Program Files\Windows Multimedia Platform
2016-11-23 16:59:05 ----D---- C:\Windows\SYSWOW64\LogFiles
2016-11-23 16:59:05 ----D---- C:\Program Files\Windows Media Player
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Portable Devices
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Multimedia Platform
2016-11-23 16:59:05 ----D---- C:\Program Files (x86)\Windows Media Player
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\wmerror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\mferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\SYSWOW64\asferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\wmerror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\mferror.dll
2016-11-23 16:56:36 ----A---- C:\Windows\system32\asferror.dll
2016-11-23 16:56:17 ----A---- C:\Windows\system32\drivers\WpdUpFltr.sys
2016-11-23 16:47:11 ----D---- C:\Users\Anetka\AppData\Roaming\Install.GS
2016-11-23 16:47:02 ----D---- C:\ProgramData\Sun
2016-11-23 16:46:59 ----A---- C:\Windows\SYSWOW64\WindowsAccessBridge-32.dll
2016-11-23 16:46:47 ----D---- C:\ProgramData\Oracle
2016-11-23 16:46:44 ----D---- C:\Program Files (x86)\Java
2016-11-10 18:13:06 ----A---- C:\Windows\SYSWOW64\FlashPlayerApp.exe
2016-11-09 12:40:42 ----A---- C:\Windows\system32\mshtml.dll
2016-11-09 12:40:41 ----A---- C:\Windows\SYSWOW64\mshtml.dll
2016-11-09 12:40:39 ----A---- C:\Windows\system32\ieframe.dll
2016-11-09 12:40:38 ----A---- C:\Windows\SYSWOW64\ieframe.dll
2016-11-09 12:40:38 ----A---- C:\Windows\system32\jscript9.dll
2016-11-09 12:40:37 ----A---- C:\Windows\SYSWOW64\jscript9.dll
2016-11-09 12:40:36 ----A---- C:\Windows\system32\win32k.sys
2016-11-09 12:40:36 ----A---- C:\Windows\system32\diagtrack.dll
2016-11-09 12:40:35 ----A---- C:\Windows\system32\wininet.dll
2016-11-09 12:40:35 ----A---- C:\Windows\system32\MSVidCtl.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\wininet.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\MSVidCtl.dll
2016-11-09 12:40:34 ----A---- C:\Windows\SYSWOW64\iertutil.dll
2016-11-09 12:40:34 ----A---- C:\Windows\system32\iertutil.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\urlmon.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\ole32.dll
2016-11-09 12:40:33 ----A---- C:\Windows\system32\lsasrv.dll
2016-11-09 12:40:32 ----A---- C:\Windows\SYSWOW64\urlmon.dll
2016-11-09 12:40:32 ----A---- C:\Windows\SYSWOW64\ole32.dll
2016-11-09 12:40:31 ----A---- C:\Windows\SYSWOW64\msdtcprx.dll
2016-11-09 12:40:31 ----A---- C:\Windows\system32\drivers\refs.sys
2016-11-09 12:40:30 ----AC---- C:\Windows\system32\drivers\vhdmp.sys
2016-11-09 12:40:30 ----A---- C:\Windows\SYSWOW64\SessEnv.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\win32spl.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\SessEnv.dll
2016-11-09 12:40:30 ----A---- C:\Windows\system32\msdtcprx.dll
2016-11-09 12:40:29 ----A---- C:\Windows\SYSWOW64\inetcomm.dll
2016-11-09 12:40:29 ----A---- C:\Windows\system32\vmrdvcore.dll
2016-11-09 12:40:29 ----A---- C:\Windows\system32\drivers\clfs.sys
2016-11-09 12:40:28 ----A---- C:\Windows\system32\msctf.dll
2016-11-09 12:40:27 ----AC---- C:\Windows\system32\drivers\msiscsi.sys
2016-11-09 12:40:27 ----A---- C:\Windows\system32\pdh.dll
2016-11-09 12:40:27 ----A---- C:\Windows\system32\msv1_0.dll
2016-11-09 12:40:26 ----A---- C:\Windows\SYSWOW64\atmfd.dll
2016-11-09 12:40:26 ----A---- C:\Windows\system32\atmfd.dll
2016-11-09 12:40:25 ----A---- C:\Windows\SYSWOW64\pdh.dll
2016-11-09 12:40:25 ----A---- C:\Windows\SYSWOW64\msctf.dll
2016-11-09 12:40:25 ----A---- C:\Windows\system32\drivers\bowser.sys
2016-11-09 12:40:25 ----A---- C:\Windows\system32\DafPrintProvider.dll
2016-11-09 12:40:24 ----A---- C:\Windows\SYSWOW64\UIAnimation.dll
2016-11-09 12:40:24 ----A---- C:\Windows\SYSWOW64\msv1_0.dll
2016-11-09 12:40:24 ----A---- C:\Windows\system32\msfeeds.dll
2016-11-09 12:40:24 ----A---- C:\Windows\system32\ie4uinit.exe
2016-11-09 12:40:23 ----A---- C:\Windows\SYSWOW64\DafPrintProvider.dll
2016-11-09 12:40:23 ----A---- C:\Windows\system32\iscsiexe.dll
2016-11-09 12:40:22 ----A---- C:\Windows\system32\UIAnimation.dll
2016-11-09 12:40:22 ----A---- C:\Windows\system32\localspl.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\microsoft-windows-system-events.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\iscsiwmi.dll
2016-11-09 12:40:21 ----A---- C:\Windows\system32\inetcomm.dll
2016-11-09 12:40:20 ----A---- C:\Windows\SYSWOW64\iscsiwmi.dll
2016-11-09 12:40:20 ----A---- C:\Windows\system32\pmcsnap.dll
2016-11-09 12:40:20 ----A---- C:\Windows\system32\asycfilt.dll
2016-11-09 12:40:19 ----A---- C:\Windows\SYSWOW64\olepro32.dll
2016-11-09 12:40:19 ----A---- C:\Windows\SYSWOW64\asycfilt.dll
2016-11-09 12:40:18 ----A---- C:\Windows\SYSWOW64\iscsidsc.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\xolehlp.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\iscsidsc.dll
2016-11-09 12:40:17 ----A---- C:\Windows\system32\dab.dll
2016-11-09 12:40:15 ----A---- C:\Windows\SYSWOW64\input.dll
2016-11-09 12:40:15 ----A---- C:\Windows\system32\input.dll
2016-11-09 12:40:12 ----A---- C:\Windows\SYSWOW64\webcheck.dll
2016-11-09 12:40:12 ----A---- C:\Windows\system32\iedkcs32.dll
2016-11-09 12:40:11 ----A---- C:\Windows\SYSWOW64\msfeeds.dll
2016-11-09 12:40:10 ----A---- C:\Windows\SYSWOW64\dxtrans.dll
2016-11-09 12:40:09 ----A---- C:\Windows\SYSWOW64\xolehlp.dll
2016-11-09 12:40:09 ----A---- C:\Windows\system32\webcheck.dll
2016-11-09 12:40:08 ----A---- C:\Windows\SYSWOW64\certcli.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\netlogon.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\dxtrans.dll
2016-11-09 12:40:08 ----A---- C:\Windows\system32\certcli.dll
2016-11-09 12:40:07 ----A---- C:\Windows\SYSWOW64\MshtmlDac.dll
2016-11-09 12:40:06 ----A---- C:\Windows\SYSWOW64\iedkcs32.dll
2016-11-09 12:40:05 ----A---- C:\Windows\SYSWOW64\mshtmled.dll
2016-11-09 12:40:05 ----A---- C:\Windows\SYSWOW64\iepeers.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\mshtmled.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\jscript.dll
2016-11-09 12:40:05 ----A---- C:\Windows\system32\iepeers.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\vbscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\jscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\SYSWOW64\ieapfltr.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\vbscript.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\ieapfltr.dll
2016-11-09 12:40:04 ----A---- C:\Windows\system32\atmlib.dll
2016-11-09 12:40:03 ----A---- C:\Windows\SYSWOW64\atmlib.dll

======List of files/folders modified in the last 1 month======

2016-12-07 06:40:41 ----D---- C:\Windows\Temp
2016-12-07 06:37:11 ----RD---- C:\Windows\System32
2016-12-07 06:37:11 ----A---- C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2016-12-07 06:37:01 ----HD---- C:\ProgramData
2016-12-07 06:36:52 ----D---- C:\ProgramData\NVIDIA
2016-12-07 06:33:52 ----D---- C:\Windows\system32\sru
2016-12-07 06:33:42 ----D---- C:\Windows\Tasks
2016-12-07 06:33:10 ----D---- C:\Windows\Prefetch
2016-12-07 06:31:42 ----D---- C:\Windows\system32\config
2016-12-07 06:23:20 ----D---- C:\Windows\Inf
2016-12-06 19:35:34 ----D---- C:\Windows\Microsoft.NET
2016-12-06 19:35:13 ----RSD---- C:\Windows\assembly
2016-12-06 19:26:25 ----A---- C:\Windows\system32\PerfStringBackup.INI
2016-12-06 19:22:30 ----D---- C:\Windows
2016-12-06 19:22:20 ----D---- C:\Windows\WinSxS
2016-12-06 19:21:27 ----D---- C:\Windows\SysWOW64
2016-12-06 19:19:29 ----D---- C:\Windows\SYSWOW64\en-US
2016-12-06 19:19:29 ----D---- C:\Windows\system32\en-US
2016-12-06 18:05:30 ----RD---- C:\Program Files
2016-12-06 17:57:03 ----D---- C:\Windows\system32\drivers
2016-12-06 17:57:02 ----D---- C:\Windows\system32\DriverStore
2016-12-06 17:57:02 ----D---- C:\Windows\system32\catroot
2016-12-06 17:56:40 ----A---- C:\Windows\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2016-12-06 17:54:42 ----D---- C:\Windows\CbsTemp
2016-12-06 17:52:48 ----SHD---- C:\System Volume Information
2016-12-05 17:42:48 ----SHD---- C:\Windows\Installer
2016-12-05 16:13:31 ----D---- C:\Program Files (x86)\Common Files
2016-12-05 16:13:28 ----RD---- C:\Program Files (x86)
2016-12-05 16:10:21 ----HD---- C:\Windows\ELAMBKUP
2016-12-05 16:06:29 ----D---- C:\Windows\system32\Tasks
2016-12-05 16:06:23 ----RSD---- C:\Windows\Fonts
2016-12-05 16:05:51 ----D---- C:\ProgramData\Package Cache
2016-12-05 15:49:54 ----SD---- C:\ProgramData\Microsoft
2016-12-05 15:49:51 ----D---- C:\Windows\system32\drivers\UMDF
2016-12-05 15:44:23 ----D---- C:\ProgramData\NVIDIA Corporation
2016-12-05 15:43:12 ----D---- C:\Program Files\NVIDIA Corporation
2016-12-05 15:43:12 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2016-12-05 11:36:23 ----SD---- C:\Users\Anetka\AppData\Roaming\Microsoft
2016-11-25 22:30:06 ----D---- C:\ProgramData\RevitInterProcess
2016-11-25 21:45:17 ----D---- C:\Windows\rescache
2016-11-25 21:41:42 ----D---- C:\Windows\SYSWOW64\cs-CZ
2016-11-25 21:41:42 ----D---- C:\Windows\system32\cs-CZ
2016-11-25 19:18:19 ----D---- C:\ProgramData\Autodesk
2016-11-25 19:16:49 ----D---- C:\Users\Anetka\AppData\Roaming\Autodesk
2016-11-24 21:54:04 ----A---- C:\Windows\SYSWOW64\nvapi.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvoglv64.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvd3dumx.dll
2016-11-24 21:54:04 ----A---- C:\Windows\system32\nvapi64.dll
2016-11-24 20:39:58 ----A---- C:\Windows\system32\nvsvc64.dll
2016-11-24 20:39:58 ----A---- C:\Windows\system32\nvcpl.dll
2016-11-24 20:39:56 ----A---- C:\Windows\SYSWOW64\oemdspif.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvsvcr.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvshext.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nvmctray.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nv3dappshextr.dll
2016-11-24 20:39:56 ----A---- C:\Windows\system32\nv3dappshext.dll
2016-11-24 18:56:21 ----D---- C:\Program Files (x86)\Autodesk
2016-11-24 18:55:26 ----SD---- C:\Windows\Downloaded Program Files
2016-11-24 18:55:17 ----D---- C:\Program Files\Common Files\Autodesk Shared
2016-11-24 18:51:49 ----D---- C:\Program Files\Autodesk
2016-11-24 18:27:10 ----D---- C:\Autodesk
2016-11-23 18:45:04 ----D---- C:\Windows\system32\catroot2
2016-11-23 16:59:05 ----D---- C:\Windows\SYSWOW64\wbem
2016-11-23 16:59:04 ----D---- C:\Windows\system32\wbem
2016-11-23 16:59:04 ----D---- C:\Windows\system32\drivers\en-US
2016-11-23 16:59:04 ----D---- C:\Windows\PolicyDefinitions
2016-11-23 16:03:28 ----HD---- C:\Program Files\WindowsApps
2016-11-23 16:03:28 ----D---- C:\Windows\AppReadiness
2016-11-17 09:18:17 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2016-11-16 17:07:27 ----D---- C:\Program Files (x86)\Microsoft Office
2016-11-09 21:13:10 ----RD---- C:\Windows\ToastData
2016-11-09 21:13:09 ----D---- C:\Program Files\Internet Explorer
2016-11-09 21:13:09 ----D---- C:\Program Files (x86)\Internet Explorer
2016-11-09 21:13:08 ----D---- C:\Windows\SYSWOW64\migration
2016-11-09 21:13:07 ----D---- C:\Windows\system32\migration
2016-11-09 12:48:01 ----D---- C:\Windows\system32\MRT
2016-11-09 12:45:10 ----AC---- C:\Windows\system32\MRT.exe
2016-11-08 16:24:08 ----D---- C:\Windows\system32\Macromed
2016-11-08 16:24:04 ----D---- C:\Windows\SYSWOW64\Macromed

File C:\Windows\system32\winlogon.exe is digitally signed
File C:\Windows\system32\wininit.exe is digitally signed
File C:\Windows\explorer.exe is digitally signed
File C:\Windows\SysWOW64\explorer.exe is digitally signed
File C:\Windows\system32\svchost.exe is digitally signed
File C:\Windows\SysWOW64\svchost.exe is digitally signed
File C:\Windows\system32\services.exe is digitally signed
File C:\Windows\system32\User32.dll is digitally signed
File C:\Windows\SysWOW64\User32.dll is digitally signed
File C:\Windows\system32\userinit.exe is digitally signed
File C:\Windows\SysWOW64\userinit.exe is digitally signed
File C:\Windows\system32\rpcss.dll is digitally signed
File C:\Windows\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 avusbflt;avusbflt; C:\Windows\System32\Drivers\avusbflt.sys [2016-10-17 23640]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2016-10-17 153392]
R1 avkmgr;avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [2016-10-17 35488]
R1 vwififlt;@%SystemRoot%\System32\drivers\vwififlt.sys,-259; C:\Windows\system32\DRIVERS\vwififlt.sys [2016-08-13 71680]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2016-10-17 151352]
R2 avnetflt;avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [2016-10-17 78208]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [2015-06-09 81920]
R3 CnxtHdAudService;@oem22.inf,%UAAFunctionDriverForHdAudio.SvcDesc%;Conexant UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\CHDRT64.sys [2014-11-12 1535168]
R3 dtlitescsibus;@oem31.inf,%DTLITESCSIBUS.DeviceDesc%;DAEMON Tools Lite Virtual SCSI Bus; C:\Windows\System32\drivers\dtlitescsibus.sys [2016-08-05 30264]
R3 dtliteusbbus;@oem32.inf,%DTLITEUSBBUS.DeviceDesc%;DAEMON Tools Lite Virtual USB Bus; C:\Windows\System32\drivers\dtliteusbbus.sys [2016-08-05 47672]
R3 ETD;@oem8.inf,%PS2DeviceDesc%;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys [2014-08-19 425736]
R3 ibtusb;@oem19.inf,%ibtusb.SVCDESC_IBT%;Intel(R) Wireless Bluetooth(R); C:\Windows\system32\DRIVERS\ibtusb.sys [2014-08-13 219592]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys [2016-10-07 7957496]
R3 iwdbus;@oem5.inf,%iwdbus.SVCDESC%;IWD Bus Enumerator; C:\Windows\System32\drivers\iwdbus.sys [2015-12-07 39920]
R3 MEIx64;@oem17.inf,%TEE_SvcDesc%;Intel(R) Management Engine Interface ; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [2014-09-30 129312]
R3 NETwNb64;@oem12.inf,___ %NIC_Service_DispName_WINB_64%;___ Intel(R) Wireless Adapter Driver for Windows 8.1 - 64 Bit; C:\Windows\system32\DRIVERS\NETwbw02.sys [2015-01-20 3494680]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2016-11-24 14057528]
R3 nvvad_WaveExtensible;@oem30.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\Windows\system32\drivers\nvvad64v.sys [2016-11-17 47672]
R3 RSUSBVSTOR;@oem7.inf,%RSUSBVSTOR.SvcDesc%;RtsUVStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUVStor.sys [2014-03-26 331992]
R3 RTL8168;@oem20.inf,%rtl8168.Service.DispName%;Realtek 8168 NT Driver; C:\Windows\system32\DRIVERS\Rt630x64.sys [2014-05-28 873176]
R3 SNP2UVC;@oem18.inf,%SERVICE_DISPLAY_NAME%;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2015-03-11 3554328]
R3 vwifimp;@%SystemRoot%\System32\drivers\vwifimp.sys,-261; C:\Windows\system32\DRIVERS\vwifimp.sys [2016-08-13 38912]
S1 EpfwLWF;@oem30.inf,%EpfwLWF_Desc%;ESET Personal Firewall; C:\Windows\system32\DRIVERS\EpfwLWF.sys [2016-11-12 61568]
S3 ACPIVPC;@oem31.inf,%ACPIVPC.SvcDesc%;Lenovo Virtual Power Controller Driver; C:\Windows\System32\drivers\AcpiVpc.sys []
S3 BthEnum;@bth.inf,%BthEnum.SVCDESC%;Bluetooth Enumerator Service; C:\Windows\System32\drivers\BthEnum.sys [2015-06-09 53248]
S3 BthLEEnum;@bthleenum.inf,%BthLEEnum.SVCDESC%;Bluetooth Low Energy Driver; C:\Windows\System32\drivers\BthLEEnum.sys [2013-12-04 226304]
S3 BthPan;@bthpan.inf,%BthPan.DisplayName%;Bluetooth Device (Personal Area Network); C:\Windows\System32\drivers\bthpan.sys [2015-07-10 118272]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [2015-06-09 1201664]
S3 intaud_WaveExtensible;@oem4.inf,%INTAUD_WEX.SvcDesc%;Intel WiDi Audio Device; C:\Windows\system32\drivers\intelaud.sys [2015-12-07 51704]
S3 IntcDAud;@oem2.inf,%IntcDAud.SvcDesc%;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys [2016-05-12 481768]
S3 iscFlash;iscFlash; \??\C:\Users\Anetka\AppData\Local\Temp\7zS44CE.tmp\iscflashx64.sys []
S3 NvStreamKms;NVIDIA KMS; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-11-17 29240]
S3 RFCOMM;@tdibth.inf,%RFCOMM.DisplayName%;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\System32\drivers\rfcomm.sys [2015-01-30 167424]
S3 usbvideo;@usbvideo.inf,%USBVideo.SvcDesc%;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2014-06-21 212736]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AdAppMgrSvc;Autodesk Desktop App Service; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [2016-07-01 1295376]
R2 AntiVirService;Avira Real-Time Protection; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [2016-10-17 475232]
R2 AntiVirSchedulerService;Avira Scheduler; C:\Program Files (x86)\Avira\Antivirus\sched.exe [2016-10-17 475232]
R2 Avira.ServiceHost;Avira Service Host; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [2016-11-25 369608]
R2 AviraPhantomVPN;Avira Phantom VPN; C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe [2016-11-16 263704]
R2 ClickToRunSvc;Služba Microsoft Office Klikni a spusť; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2016-10-30 2946304]
R2 CodeMeter.exe;CodeMeter Runtime Server; C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe [2015-08-17 3526184]
R2 CxAudMsg;@C:\Windows\system32\CxAudMsg64.exe,-100; C:\Windows\system32\CxAudMsg64.exe [2014-10-19 207576]
R2 DiagTrack;@%SystemRoot%\system32\UtcResources.dll,-3001; %SystemRoot%\System32\svchost.exe -k utcsvc;"ServiceDll"=%SystemRoot%\system32\diagtrack.dll
R2 ETDService;Elan Service; C:\Program Files\Elantech\ETDService.exe [2013-10-15 101680]
R2 EvtEng;Intel(R) PROSet/Wireless Event Log; C:\Program Files\Intel\WiFi\bin\EvtEng.exe [2014-11-19 638368]
R2 ibtsiva.exe;Intel Bluetooth Service; C:\Program Files (x86)\Intel\Bluetooth\utilities\ibtsiva.exe [2014-08-13 121288]
R2 igfxCUIService2.0.0.0;Intel(R) HD Graphics Control Panel Service; C:\Windows\system32\igfxCUIService.exe [2016-10-07 365048]
R2 NvContainerLocalSystem;NVIDIA LocalSystem Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-11-17 464440]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2016-11-24 458176]
R2 NVIDIA Wireless Controller Service;NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [2016-11-17 1165368]
R2 RegSrvc;Intel(R) PROSet/Wireless Registry Service; C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe [2014-11-19 157088]
R2 SAService;Conexant SmartAudio service; C:\Windows\system32\SAsrv.exe []
R2 SpeedupService;Avira System Speedup; C:\Program Files (x86)\Avira\System Speedup\Avira.SystemSpeedup.SpeedupService.exe [2016-11-23 33896]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2013-08-03 43696]
S2 AntiVirMailService;Avira Mail Protection; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [2016-10-17 1089088]
S2 AntiVirWebService;Avira Web Protection; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [2016-10-17 1488240]
S2 gupdate;Služba Google Update (gupdate); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-04 154440]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service; C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-11-08 270016]
S3 BthHFSrv;@%SystemRoot%\System32\BthHFSrv.dll,-103; %SystemRoot%\System32\svchost.exe -k LocalServiceAndNoImpersonation;"ServiceDll"=%SystemRoot%\System32\BthHFSrv.dll
S3 cphs;Intel(R) Content Protection HECI Service; C:\Windows\SysWow64\IntelCpHeciSvc.exe [2016-10-07 292856]
S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [2016-07-29 1467072]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2016-10-09 1591264]
S3 gupdatem;Služba Google Update (gupdatem); C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-04 154440]
S3 MyWiFiDHCPDNS;Wireless PAN DHCP Server; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [2014-11-19 268192]
S3 NvContainerNetworkService;NVIDIA NetworkService Container; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2016-11-17 464440]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2016-10-30 209104]
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2016-10-13 1459488]

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Svchost a Installer Worker vytěžuje disk

#8 Příspěvek od Rudy »

OK. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

krajta5
Návštěvník
Návštěvník
Příspěvky: 36
Registrován: 03 črc 2013 16:43

Re: Svchost a Installer Worker vytěžuje disk

#9 Příspěvek od krajta5 »

Zatím bez problémů.
Děkuji za pomoc. :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119529
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Svchost a Installer Worker vytěžuje disk

#10 Příspěvek od Rudy »

Nemáte zač! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno