Odvirování PC, zrychlení počítače, vzdálená pomoc prostřednictvím služby neslape.cz

Pravděpodobný malware

Máte problém s virem? Vložte sem log z FRST nebo RSIT.

Moderátor: Moderátoři

Pravidla fóra
Pokud chcete pomoc, vložte log z FRST [návod zde] nebo RSIT [návod zde]

Jednotlivé thready budou po vyřešení uzamčeny. Stejně tak ty, které budou nečinné déle než 14 dní. Vizte Pravidlo o zamykání témat. Děkujeme za pochopení.

!NOVINKA!
Nově lze využívat služby vzdálené pomoci, kdy se k vašemu počítači připojí odborník a bližší informace o problému si od vás získá telefonicky! Více na www.neslape.cz
Zamčeno
Zpráva
Autor
Rolnire
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 07 bře 2015 21:37

Pravděpodobný malware

#1 Příspěvek od Rolnire »

Ahoj, po spuštění PC se mi zapíná proces Antimalware Service Executable a vytěžuje disk na téměř 100% a celkem mě to dost brzdí... Vkládám RSIT log a prosím o zkontrolování. Předem děkuji

Logfile of random's system information tool 1.14 (written by random/random)
Run by Mts at 2017-02-12 17:40:58
Microsoft Windows 10 Home
System drive C: has 809 GB (85%) free of 953 GB
Total RAM: 8059 MB (67% free)
X64

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 17:41:13, on 12.02.2017
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.14393.0000)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\hicloud\update_server\startUp.exe
C:\Program Files (x86)\hicloud\update_server\SPUpDateServer.exe
C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\trend micro\Mts_RSITx64.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer15.msn.com/?pc=ACTE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://acer15.msn.com/?pc=ACTE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SPUpDateServerrun] C:\Program Files (x86)\hicloud\update_server\startUp.exe
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll/105
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Protocol: windows.tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AtherosSvc - Unknown owner - C:\WINDOWS\system32\AdminService.exe (file missing)
O23 - Service: BitComet Disk Boost Service (BITCOMET_HELPER_SERVICE) - www.BitComet.com - C:\Program Files\BitComet\tools\BitCometService.exe
O23 - Service: CCDMonitorService - Acer Incorporated - C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\IntelCpHeciSvc.exe
O23 - Service: Intel(R) Content Protection HDCP Service (cplspcon) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\IntelCpHDCPSvc.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: GamesAppIntegrationService - WildTangent - C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: NVIDIA GeForce Experience Service (GfExperienceService) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
O23 - Service: Služba Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Služba Google Update (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Intel(R) HD Graphics Control Panel Service (igfxCUIService2.0.0.0) - Intel Corporation - C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\igfxCUIService.exe
O23 - Service: Intel(R) Capability Licensing Service TCP IP Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe
O23 - Service: Intel(R) Security Assist - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
O23 - Service: Intel(R) Security Assist Helper (isaHelperSvc) - Unknown owner - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
O23 - Service: NVIDIA Network Service (NvNetworkService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
O23 - Service: NVIDIA Streamer Network Service (NvStreamNetworkSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
O23 - Service: NVIDIA Streamer Service (NvStreamSvc) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: @%SystemRoot%\system32\TieringEngineService.exe,-702 (TieringEngineService) - Unknown owner - C:\WINDOWS\system32\TieringEngineService.exe (file missing)
O23 - Service: User Experience Improvement Program (UEIPSvc) - acer - C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11674 bytes

======Enumerating Processes======

C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe -k DcomLaunch
C:\WINDOWS\system32\svchost.exe -k RPCSS
C:\WINDOWS\system32\dwm.exe
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k netsvcs
C:\WINDOWS\System32\svchost.exe -k NetworkService
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNoNetwork
"C:\Windows\System32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-fe1fee83-7786-4f61-8738-dc2ba78f7bfa -SystemEventPortName:HostProcess-5f1d4131-aec0-44d9-91a7-ec202bb42040 -IoCancelEventPortName:HostProcess-181633fa-4675-4168-b5e9-63535e61ba43 -NonStateChangingEventPortName:HostProcess-c22683b0-3d70-4d23-8ee4-b97d781d79f3 -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:0ad29a3a-ae28-4e9c-9890-22cc8ad941ec -DeviceGroupId:WudfDefaultDevicePool
C:\WINDOWS\system32\svchost.exe -k LocalService
C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\igfxCUIService.exe
C:\WINDOWS\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalServiceNetworkRestricted
C:\WINDOWS\system32\svchost.exe -k LocalSystemNetworkRestricted
C:\WINDOWS\System32\spoolsv.exe
"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"
C:\WINDOWS\system32\AdminService.exe
C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\IntelCpHDCPSvc.exe
C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\IntelCpHeciSvc.exe
"C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe"
"C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe"
C:\WINDOWS\system32\dashost.exe
C:\WINDOWS\System32\svchost.exe -k utcsvc
"C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe"
"C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem"
"C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe"
C:\WINDOWS\system32\svchost.exe -k appmodel
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe"
C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe -first
C:\WINDOWS\system32\svchost.exe -k LocalServiceAndNoImpersonation
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe"
"C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe" serviceapp
\??\C:\WINDOWS\system32\conhost.exe 0x4
C:\WINDOWS\system32\sihost.exe
C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup
C:\WINDOWS\system32\taskhostw.exe
C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
"C:\Users\Mts\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe" /LOGON
C:\WINDOWS\system32\wbem\wmiprvse.exe
"C:\Program Files\Dolby Digital Plus\ddp.exe" -autostart
C:\WINDOWS\Explorer.EXE
"C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\igfxEM.exe"
"C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca
C:\WINDOWS\system32\SearchIndexer.exe /Embedding
"C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe"
"C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca
C:\Windows\System32\RuntimeBroker.exe -Embedding
C:\OEM\Preload\FubTracking\FubTracking.exe
"C:\Program Files\Windows Defender\MSASCuiL.exe"
"C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
"C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /FORPCEE4
"C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
"C:\Program Files (x86)\hicloud\update_server\startUp.exe"
"C:\Program Files (x86)\hicloud\update_server\SPUpDateServer.exe"
"C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe"
"C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe"
"C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe" task
C:\Program Files\Windows Defender\MpCmdRun.exe
C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
\??\C:\WINDOWS\system32\conhost.exe 0x4
"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe"
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=crashpad-handler /prefetch:7 "--database=C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Crashpad" "--metrics-dir=C:\Users\Mts\AppData\Local\Google\Chrome\User Data" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win32 --annotation=prod=Chrome --annotation=ver=56.0.2924.87 --initial-client-data=0x250,0x254,0x258,0x24c,0x25c,0x70467598,0x704675bc,0x704675a4
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=watcher --main-thread-id=7700 --on-initialized-event-handle=708 --parent-handle=712 /prefetch:6
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=gpu-process --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,*EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DisableFirstRunAutoImport<DisableFirstRunAutoImport,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,ExpectCTReporting<ExpectCTReporting,MediaFoundationH264Encoding<MediaFoundationH264Encoding,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=AppBannerTriggering/site-engagement-eager/AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/Control/DisallowFetchForDocWrittenScriptsInMainFrame/Control_20161208_Launch/EnableSyncClientToServerCompression/Default/ExpectCTReporting/ExpectCTReportingControl/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled/InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Control/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledRaceCertVerificationOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Default/StrictSecureCookies/Enabled/SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_05/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --supports-dual-gpus=false --gpu-driver-bug-workarounds=7,19,23,40,59,71 --gpu-vendor-id=0x8086 --gpu-device-id=0x1916 --gpu-driver-vendor="Intel Corporation" --gpu-driver-version=21.20.16.4534 --gpu-driver-date=10-7-2016 --gpu-secondary-vendor-ids=0x10de --gpu-secondary-device-ids=0x1347 --service-request-channel-token=4CE8124CC1F0A3D4CF7B743EC3530E72 --mojo-platform-channel-handle=1364 --ignored=" --type=renderer " /prefetch:2
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,*EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DisableFirstRunAutoImport<DisableFirstRunAutoImport,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,ExpectCTReporting<ExpectCTReporting,MediaFoundationH264Encoding<MediaFoundationH264Encoding,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/Control/DisallowFetchForDocWrittenScriptsInMainFrame/Control_20161208_Launch/EnableSyncClientToServerCompression/Default/ExpectCTReporting/ExpectCTReportingControl/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Control/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledRaceCertVerificationOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Default/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_05/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=CA407B613884726B9DB5FFC6202CFC51 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=CA407B613884726B9DB5FFC6202CFC51 --renderer-client-id=5 --mojo-platform-channel-handle=2456 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,*EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DisableFirstRunAutoImport<DisableFirstRunAutoImport,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,ExpectCTReporting<ExpectCTReporting,MediaFoundationH264Encoding<MediaFoundationH264Encoding,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/Control/*DisallowFetchForDocWrittenScriptsInMainFrame/Control_20161208_Launch/EnableSyncClientToServerCompression/Default/ExpectCTReporting/ExpectCTReportingControl/ExtensionDeveloperModeWarning/Enabled/Html5ByDefault/Enabled/*InstanceID/Enabled/MarkNonSecureAs/show-non-secure-passwords-cc-ui/MediaFoundationH264Encoding/Control/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledRaceCertVerificationOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Default/StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_05/*UMA-Uniformity-Trial-50-Percent/group_01/WebFontsInterventionV2/Default/ --primordial-pipe-token=1E1BF6A7FBD1CC7BBC8776723752C707 --lang=en-US --extension-process --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=1E1BF6A7FBD1CC7BBC8776723752C707 --renderer-client-id=4 --mojo-platform-channel-handle=3720 /prefetch:1
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,*EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DisableFirstRunAutoImport<DisableFirstRunAutoImport,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,ExpectCTReporting<ExpectCTReporting,MediaFoundationH264Encoding<MediaFoundationH264Encoding,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/Control/*DisallowFetchForDocWrittenScriptsInMainFrame/Control_20161208_Launch/EnableSyncClientToServerCompression/Default/ExpectCTReporting/ExpectCTReportingControl/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/Enabled/*InstanceID/Enabled/*MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Control/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledRaceCertVerificationOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Default/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/*TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_05/*UMA-Uniformity-Trial-50-Percent/group_01/*WebFontsInterventionV2/Default/ --primordial-pipe-token=2CE72E587003A65525E80F9887673223 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=2CE72E587003A65525E80F9887673223 --renderer-client-id=8 --mojo-platform-channel-handle=4824 /prefetch:1
"C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe"
"C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe" -auto
C:\Windows\System32\smartscreen.exe -Embedding
C:\WINDOWS\system32\AUDIODG.EXE 0x354
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,*EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DisableFirstRunAutoImport<DisableFirstRunAutoImport,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,ExpectCTReporting<ExpectCTReporting,MediaFoundationH264Encoding<MediaFoundationH264Encoding,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/Control/*DisallowFetchForDocWrittenScriptsInMainFrame/Control_20161208_Launch/EnableSyncClientToServerCompression/Default/ExpectCTReporting/ExpectCTReportingControl/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/Enabled/*InstanceID/Enabled/*MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Control/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/PluginPowerSaverTiny/Enabled2/*QUIC/EnabledRaceCertVerificationOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Default/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/*TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_05/*UMA-Uniformity-Trial-50-Percent/group_01/*WebFontsInterventionV2/Default/ --primordial-pipe-token=3C372E6A9F2389154EEFB0629E39E7E5 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=3C372E6A9F2389154EEFB0629E39E7E5 --renderer-client-id=23 --mojo-platform-channel-handle=7176 /prefetch:1
C:\WINDOWS\system32\DllHost.exe /Processid:{49F6E667-6658-4BD1-9DE9-6AF87F9FAF85}
"C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --type=renderer --enable-features=AutofillProfileCleanup<AutofillProfileCleanup,BlockSmallPluginContent<PluginPowerSaverTiny,*DefaultEnableGpuRasterization<DefaultEnableGpuRasterization,*EnableSyncClientToServerCompression<EnableSyncClientToServerCompression,*ExperimentalSwReporterEngine<SRTExperimentalEngineTrial,*NegotiateTLS13<TLS13Negotiation,ParseHTMLOnMainThread<ParseHTMLOnMainThread,*PersistentHistograms<PersistentHistograms,*PointerEvent<PointerEvent,PreferHtmlOverPlugins<Html5ByDefault,SecurityChip<SecurityChip,SecurityWarningIconUpdate<SecurityWarningIconUpdate,SubresourceFilter<SubresourceFilter,SwReporterExtendedSafeBrowsingFeature<SwReporterExtendedSafeBrowsingFeature,*TranslateRankerLogging<TranslateRankerLogging,*TranslateUI2016Q2<TranslateUI2016Q2 --disable-features=DisableFirstRunAutoImport<DisableFirstRunAutoImport,DocumentWriteEvaluator<DisallowFetchForDocWrittenScriptsInMainFrame,ExpectCTReporting<ExpectCTReporting,MediaFoundationH264Encoding<MediaFoundationH264Encoding,MetricsReporting<MetricsAndCrashSampling,SSLPostQuantumExperiment<SSLPostQuantum,UpdateRendererPriorityOnStartup<UpdateRendererPriorityOnStartup --force-fieldtrials=*AppBannerTriggering/site-engagement-eager/*AutofillProfileCleanup/Enabled/CaptivePortalInterstitial/Enabled/*ChromeChannelStable/Enabled/*ChromeSuggestionsTuning/Default/*ClientSideDetectionModel/Model0/*DataReductionProxyUseQuic/Enabled10_NoControl/DefaultBrowserPromptStyle/ColoredIconOnWhiteInfoBar3/*DefaultEnableGpuRasterization/Default/DisableFirstRunAutoImport/Control/*DisallowFetchForDocWrittenScriptsInMainFrame/Control_20161208_Launch/EnableSyncClientToServerCompression/Default/ExpectCTReporting/ExpectCTReportingControl/ExtensionDeveloperModeWarning/Enabled/*Html5ByDefault/Enabled/*InstanceID/Enabled/*MarkNonSecureAs/show-non-secure-passwords-cc-ui/*MediaFoundationH264Encoding/Control/MetricsAndCrashSampling/OutOfReportingSample/*NetworkQualityEstimator/Enabled/*OmniboxBundledExperimentV1/StandardR7/*ParseHTMLOnMainThread/Default/*PasswordBranding/SmartLockBrandingSavePromptOnly/*PasswordGeneration/Disabled/*PasswordManagerSettingsMigration/Enable/*PersistentHistograms/Default/*PluginPowerSaverTiny/Enabled2/*QUIC/EnabledRaceCertVerificationOctober/ReportCertificateErrors/ShowAndPossiblySend/SHA1IdentityUIWarning/Enabled/SHA1ToolbarUIJanuary2016/Warning/SHA1ToolbarUIJanuary2017/Error/SRTExperimentalEngineTrial/Default/*SRTPromptFieldTrial/On/SSLCommonNameMismatchHandling/Enabled/*SSLPostQuantum/disabled/*SafeBrowsingIncidentReportingService/Default/SafeBrowsingUnverifiedDownloads/DisableByParameterMostSbTypes2/*SecurityChip/Enabled/SecurityWarningIconUpdate/Enabled/SignInPasswordPromo/Enable3/*SiteIsolationExtensions/Default/*StrictSecureCookies/Enabled/*SubresourceFilter/EnabledForPhishingSites/*SwReporterExtendedSafeBrowsingFeature/Enabled/*TLS13Negotiation/Default/*TranslateRankerLogging/TranslateRankerLoggingDefault/TranslateServerStudy/Default/*TranslateUI2016Q2/DefaultTranslateUI2016Q2/*TriggeredResetFieldTrial/On/*UMA-Dynamic-Uniformity-Trial/Group6/*UMA-Population-Restrict/normal/*UMA-Uniformity-Trial-1-Percent/group_45/*UMA-Uniformity-Trial-10-Percent/group_08/*UMA-Uniformity-Trial-100-Percent/group_01/*UMA-Uniformity-Trial-20-Percent/group_02/*UMA-Uniformity-Trial-5-Percent/group_05/*UMA-Uniformity-Trial-50-Percent/group_01/*WebFontsInterventionV2/Default/ --primordial-pipe-token=4525038D4116C593DD0ED9D6365F5539 --lang=en-US --enable-offline-auto-reload --enable-offline-auto-reload-visible-only --blink-settings=disallowFetchForDocWrittenScriptsInMainFrame=false,disallowFetchForDocWrittenScriptsInMainFrameOnSlowConnections=false --enable-pinch --device-scale-factor=1.25 --num-raster-threads=2 --enable-main-frame-before-activation --content-image-texture-target=0,0,3553;0,1,3553;0,2,3553;0,3,3553;0,4,3553;0,5,3553;0,6,3553;0,7,3553;0,8,3553;0,9,3553;0,10,3553;0,11,3553;0,12,3553;0,13,3553;0,14,3553;0,15,3553;1,0,3553;1,1,3553;1,2,3553;1,3,3553;1,4,3553;1,5,3553;1,6,3553;1,7,3553;1,8,3553;1,9,3553;1,10,3553;1,11,3553;1,12,3553;1,13,3553;1,14,3553;1,15,3553;2,0,3553;2,1,3553;2,2,3553;2,3,3553;2,4,3553;2,5,3553;2,6,3553;2,7,3553;2,8,3553;2,9,3553;2,10,3553;2,11,3553;2,12,3553;2,13,3553;2,14,3553;2,15,3553;3,0,3553;3,1,3553;3,2,3553;3,3,3553;3,4,3553;3,5,3553;3,6,3553;3,7,3553;3,8,3553;3,9,3553;3,10,3553;3,11,3553;3,12,3553;3,13,3553;3,14,3553;3,15,3553 --service-request-channel-token=4525038D4116C593DD0ED9D6365F5539 --renderer-client-id=28 --mojo-platform-channel-handle=3392 /prefetch:1
"C:\Users\Mts\Downloads\RSITx64.exe"
"C:\WINDOWS\system32\SearchProtocolHost.exe" Global\UsGthrFltPipeMssGthrPipe3_ Global\UsGthrCtrlFltPipeMssGthrPipe3 1 -2147483646 "Software\Microsoft\Windows Search" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT; MS Search 4.0 Robot)" "C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc" "DownLevelDaemon"
"C:\WINDOWS\system32\SearchFilterHost.exe" 0 648 652 660 8192 656

======Scheduled tasks folder======

C:\WINDOWS\system32\tasks\Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\WINDOWS\system32\tasks\App Explorer - %LOCALAPPDATA%\Host App Service\Engine\HostAppServiceUpdater.exe /LOGON
C:\WINDOWS\system32\tasks\AutoKMS - C:\WINDOWS\AutoKMS\AutoKMS.exe
C:\WINDOWS\system32\tasks\BacKGroundAgent - C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe task
C:\WINDOWS\system32\tasks\DolbySelectorTask - %ProgramFiles%\Dolby Digital Plus\ddp.exe -autostart
C:\WINDOWS\system32\tasks\FUBTrackingByPLD - "C:\OEM\Preload\FubTracking\FubTracking.exe"
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
C:\WINDOWS\system32\tasks\Software Update Application - "C:\ProgramData\OEM\UpgradeTool\ListCheck.exe"
C:\WINDOWS\system32\tasks\UbtFrameworkService - "C:\Program Files\Acer\User Experience Improvement Program\Framework\TriggerFramework.exe"
C:\WINDOWS\system32\tasks\User_Feed_Synchronization-{34745B33-4824-48D5-B4EE-ABD980DA0982} - C:\WINDOWS\system32\msfeedssync.exe sync
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTask - %windir%\System32\XblGameSaveTask.exe standby
C:\WINDOWS\system32\tasks\Microsoft\XblGameSave\XblGameSaveTaskLogon - %windir%\System32\XblGameSaveTask.exe logon
C:\WINDOWS\system32\tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join - %SystemRoot%\System32\dsregcmd.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start - %systemroot%\System32\sc.exe start wuauserv
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sih - %systemroot%\System32\sihclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\WindowsUpdate\sihboot - %systemroot%\System32\sihclient.exe /boot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Media Sharing\UpdateLibrary - "%ProgramFiles%\Windows Media Player\wmpnscfg.exe"
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Filtering Platform\BfeOnServiceStartTypeChange - %windir%\system32\rundll32.exe bfe.dll,BfeOnServiceStartTypeChange
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Error Reporting\QueueReporting - %windir%\system32\wermgr.exe -upload
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan - %ProgramFiles%\Windows Defender\MpCmdRun.exe Scan -ScheduleJob
C:\WINDOWS\system32\tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification - %ProgramFiles%\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification
C:\WINDOWS\system32\tasks\Microsoft\Windows\WCM\WiFiTask - %SystemRoot%\System32\WiFiTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UPnP\UPnPHostConfig - sc.exe config upnphost start= auto
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Maintenance Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Policy Install - %systemroot%\system32\usoclient.exe StartInstall
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Reboot - %systemroot%\system32\MusNotification.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Refresh Settings - %systemroot%\system32\usoclient.exe RefreshSettings
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Resume On Boot - %systemroot%\system32\usoclient.exe ResumeUpdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scan - %systemroot%\system32\usoclient.exe StartScan
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_Display - %systemroot%\system32\MusNotification.exe Display
C:\WINDOWS\system32\tasks\Microsoft\Windows\UpdateOrchestrator\USO_UxBroker_ReadyToReboot - %systemroot%\system32\MusNotification.exe ReadyToReboot
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone - %windir%\system32\tzsync.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Time Synchronization\SynchronizeTime - %windir%\system32\sc.exe start w32time task_started
C:\WINDOWS\system32\tasks\Microsoft\Windows\SystemRestore\SR - %windir%\system32\srtasks.exe ExecuteScheduledSPPCreation
C:\WINDOWS\system32\tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask - %windir%\system32\rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - %windir%\system32\defrag.exe -c -h -g -# -m 8 -i 13500
C:\WINDOWS\system32\tasks\Microsoft\Windows\Speech\SpeechModelDownloadTask - %windir%\system32\speech_onecore\common\SpeechModelDownload.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceAgentTask - %windir%\system32\SpaceAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SpacePort\SpaceManagerTask - %windir%\system32\spaceman.exe /Work
C:\WINDOWS\system32\tasks\Microsoft\Windows\Shell\FamilySafetyMonitor - %windir%\System32\wpcmon.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\SharedPC\Account Cleanup - %windir%\System32\rundll32.exe %windir%\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemovalTools\MRT_HB - C:\Windows\system32\MRT.exe /EHB /Q
C:\WINDOWS\system32\tasks\Microsoft\Windows\RemoteAssistance\RemoteAssistanceTask - %windir%\system32\RAServer.exe /offerraupdate
C:\WINDOWS\system32\tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers - %SystemRoot%\System32\drvinst.exe 6
C:\WINDOWS\system32\tasks\Microsoft\Windows\NlaSvc\WiFiTask - %SystemRoot%\System32\WiFiTask.exe nla
C:\WINDOWS\system32\tasks\Microsoft\Windows\NetTrace\GatherNetworkInfo - %windir%\system32\gatherNetworkInfo.vbs
C:\WINDOWS\system32\tasks\Microsoft\Windows\MUI\LPRemove - %windir%\system32\lpremove.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - %SystemRoot%\System32\MbaeParserTask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Management\Provisioning\Logon - %windir%\system32\ProvTool.exe /turn 5
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\Notifications - %windir%\System32\LocationNotificationWindows.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Location\WindowsActionDialog - %windir%\System32\WindowsActionDialog.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClient - %windir%\system32\dmclient.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - %windir%\system32\dmclient.exe utcwnf
C:\WINDOWS\system32\tasks\Microsoft\Windows\EnterpriseMgmt\MDMMaintenenceTask - %windir%\system32\MDMAgent.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DUSM\dusmtask - %SystemRoot%\System32\dusmtask.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskFootprint\Diagnostics - %windir%\system32\disksnapshot.exe -z
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - %windir%\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - %windir%\system32\DFDWiz.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\DiskCleanup\SilentCleanup - %windir%\system32\cleanmgr.exe /autoclean /d %systemdrive%
C:\WINDOWS\system32\tasks\Microsoft\Windows\Device Information\Device - %windir%\system32\devicecensus.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Defrag\ScheduledDefrag - %windir%\system32\defrag.exe -c -h -o -$
C:\WINDOWS\system32\tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator - %SystemRoot%\System32\wsqmcons.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Clip\License Validation - %SystemRoot%\system32\ClipUp.exe -p -s -o
C:\WINDOWS\system32\tasks\Microsoft\Windows\Bluetooth\UninstallDeviceTask - BthUdTask.exe $(Arg0)
C:\WINDOWS\system32\tasks\Microsoft\Windows\Autochk\Proxy - %windir%\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - %windir%\system32\rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierdaily - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\appuriverifierinstall - %windir%\system32\AppHostRegistrationVerifier.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState - %windir%\system32\rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
C:\WINDOWS\system32\tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup - %windir%\system32\dstokenclean.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - %windir%\system32\compattelrunner.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater - %windir%\system32\compattelrunner.exe -maintenance
C:\WINDOWS\system32\tasks\Microsoft\Windows\Application Experience\StartupAppTask - %windir%\system32\rundll32.exe Startupscan.dll,SusRunTask
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\PolicyConverter - %windir%\system32\appidpolicyconverter.exe
C:\WINDOWS\system32\tasks\Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - %windir%\system32\appidcertstorecheck.exe
C:\WINDOWS\system32\tasks\Microsoft\VisualStudio\VSIX Auto Update 14 - C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\VSIXAutoUpdate.exe

=========Google Chrome=========

C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences
Extension aapocclcgogkmnckokdopfmhonfmgoek 1 Google Slides 0.9
Extension ahfgeienlihckogmohjhadlkjgocpleb 1 Web Store 0.2
Extension aohghmighlieiainnegkcijnfilokake 1 Google Docs 0.9
Extension apdfllckaahabafndbhieahigkjlhalf 1 Google Drive 14.1
Extension bepbmhgboaologfdajaanbcjmnhjmhfn 0
Extension blpcfgokakmgnkcojhhkbfbldkacnbeo 1 YouTube 4.2.8
Extension coobgpohoikkiipiblmjeljniedjpjpf 1 Google Search 0.0.0.60
Extension eemcgdkfndhakfknompkggombfjjjeno 1 Bookmark Manager 0.1
Extension efaidnbmnnnibpcajpcglclefindmkaj 2 Adobe Acrobat 15.1.0.3
Extension ennkphjdgehloodpbhlhldgbnhmacadg 1 Settings 0.2
Extension felcaaldnbdncclmgdcncolpebgiejap 1 Google Sheets 1.1
Extension gfdkimpbcpahaombhbimeihdjnejgicl 1 Feedback 1.0
Extension ghbmnnjooekpmoecnnnilnnbdlolhkhi 1 Google Docs Offline 1.4
Extension gighmmpiobklfepjocnamgkkbiglidom 1 AdBlock 3.8.6
Extension kmendfapggjehodndflmmgagdbamhnfd 1 CryptoTokenExtension 0.9.46
Extension mfehgcgbbipciphmccgaenjidiccnmng 1 Cloud Print 0.1
Extension mgndgikekgjfcpckkfioiadnlibdjbkf 1 Chrome 0.1
Extension mhjfbmdgcfjbbpaeojofohoefgiehjai 1 Chrome PDF Viewer 1
Extension neajdppkdcdipfabeoofebfddakdcjhd 1 Google Network Speech 1.0
Extension nkeimhogjdpnpccoofpliimaahmaaome 1 Google Hangouts 1.3.2
Extension nmmhkkegccagdldgiimedpiccmgmieda 1 Chrome Web Store Payments 1.0.0.1
Extension pjkljhegncpnkpknbcohdijeoejaedia 1 Gmail 8.1
Extension pkedcjkdefgpdelpbcmbmeomcjbeemfm 1 Chrome Media Router 5616.1121.0.3
Homepage:
default_search_provider.search_url:
C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Preferences
Homepage:
default_search_provider.search_url:

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\efaidnbmnnnibpcajpcglclefindmkaj]
"Path"=


======Registry dump======


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={EBFEFA09-C112-4EEA-89ED-655434DDDBB7}
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EBFEFA09-C112-4EEA-89ED-655434DDDBB7}]
"URL"=http://www.bing.com/search?q={searchTer ... TR&pc=ACTE


[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"={EBFEFA09-C112-4EEA-89ED-655434DDDBB7}
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}]
"URL"=http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Internet Explorer\SearchScopes\{EBFEFA09-C112-4EEA-89ED-655434DDDBB7}]
"URL"=http://www.bing.com/search?q={searchTer ... TR&pc=ACTE

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-08 571456]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 688528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-08 234560]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-08 473152]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL [2010-02-28 561552]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-08 186944]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WindowsDefender"=C:\Program Files\Windows Defender\MSASCuiL.exe [2016-11-21 631808]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-07-07 14040792]
"RtHDVBg_Dolby"=C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-30 1393880]
"NvBackend"=C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2016-06-15 2398776]
"ShadowPlay"=C:\WINDOWS\system32\nvspcap64.dll [2016-06-15 1767760]

[HKEY_LOCAL_MACHINE\Software\wow6432node\Microsoft\Windows\CurrentVersion\Run]
"BCSSync"=C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [2010-03-13 91520]
"SunJavaUpdateSched"=C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2016-09-22 587288]
"SPUpDateServerrun"=C:\Program Files (x86)\hicloud\update_server\startUp.exe [2015-06-15 15232]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED}

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 6722448]

[HKEY_LOCAL_MACHINE\SOFTWARE\wow6432node\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL [2010-03-25 4222864]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"DSCAutomationHostEnabled"=2
"EnableCursorSuppression"=1
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"ForceActiveDesktopOn"=0
"NoActiveDesktop"=1
"NoActiveDesktopChanges"=1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]


[HKEY_LOCAL_MACHINE\Software\Microsoft\Active Setup\Installed Components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
"StubPath"=%SystemRoot%\inf\unregmp2.exe /ShowWMP

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
"midimapper"=midimap.dll
"msacm.imaadpcm"=imaadp32.acm
"msacm.l3acm"=C:\Windows\System32\l3codeca.acm
"msacm.msadpcm"=msadp32.acm
"msacm.msg711"=msg711.acm
"msacm.msgsm610"=msgsm32.acm
"vidc.i420"=iyuv_32.dll
"vidc.iyuv"=iyuv_32.dll
"vidc.mrle"=msrle32.dll
"vidc.msvc"=msvidc32.dll
"vidc.uyvy"=msyuv.dll
"vidc.yuy2"=msyuv.dll
"vidc.yvu9"=tsbyuv.dll
"vidc.yvyu"=msyuv.dll
"wavemapper"=msacm32.drv
"wave1"=wdmaud.drv
"midi1"=wdmaud.drv
"mixer1"=wdmaud.drv
"aux1"=wdmaud.drv
"MSVideo8"=VfWWDM32.dll
"wave"=wdmaud.drv
"midi"=wdmaud.drv
"mixer"=wdmaud.drv
"aux"=wdmaud.drv

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 month======

2017-02-12 17:40:58 ----D---- C:\rsit
2017-02-12 17:40:58 ----D---- C:\Program Files\trend micro
2017-02-12 17:07:49 ----A---- C:\WINDOWS\SYSWOW64\vulkaninfo.exe
2017-02-12 17:07:49 ----A---- C:\WINDOWS\SYSWOW64\vulkan-1.dll
2017-02-12 17:07:49 ----A---- C:\WINDOWS\system32\vulkaninfo.exe
2017-02-12 17:07:49 ----A---- C:\WINDOWS\system32\vulkan-1.dll
2017-02-12 17:07:48 ----D---- C:\Program Files (x86)\VulkanRT
2017-02-12 17:01:00 ----D---- C:\WINDOWS\LastGood.Tmp
2017-02-11 23:27:26 ----SD---- C:\Users\Mts\AppData\Roaming\Microsoft
2017-02-11 23:26:54 ----A---- C:\WINDOWS\SYSWOW64\PerfStringBackup.INI
2017-02-11 23:24:17 ----D---- C:\WINDOWS\SYSWOW64\sda
2017-02-11 23:24:14 ----D---- C:\ProgramData\NVIDIA
2017-02-11 23:24:09 ----A---- C:\WINDOWS\system32\nvsvcr.dll
2017-02-11 23:24:09 ----A---- C:\WINDOWS\system32\nvsvc64.dll
2017-02-11 23:24:09 ----A---- C:\WINDOWS\system32\nvshext.dll
2017-02-11 23:24:09 ----A---- C:\WINDOWS\system32\nvmctray.dll
2017-02-11 23:24:09 ----A---- C:\WINDOWS\system32\nvcpl.dll
2017-02-11 23:24:09 ----A---- C:\WINDOWS\system32\nv3dappshextr.dll
2017-02-11 23:24:09 ----A---- C:\WINDOWS\system32\nv3dappshext.dll
2017-02-11 23:23:53 ----D---- C:\ProgramData\NVIDIA Corporation
2017-02-11 23:23:41 ----D---- C:\Program Files\NVIDIA Corporation
2017-02-11 23:23:34 ----D---- C:\Program Files\Common Files\Atheros
2017-02-11 23:23:20 ----D---- C:\WINDOWS\system32\DAX2
2017-02-11 23:23:13 ----D---- C:\WINDOWS\SYSWOW64\RTCOM
2017-02-11 23:23:13 ----D---- C:\Program Files\Realtek
2017-02-11 23:23:05 ----A---- C:\WINDOWS\SYSWOW64\OpenCL.DLL
2017-02-11 23:23:05 ----A---- C:\WINDOWS\system32\OpenCL.DLL
2017-02-11 23:22:57 ----D---- C:\Program Files\Intel
2017-02-11 23:19:31 ----D---- C:\WINDOWS\Prefetch
2017-02-11 23:17:25 ----DC---- C:\WINDOWS\Panther
2017-02-11 23:14:08 ----D---- C:\Windows.old
2017-02-11 23:10:47 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsDesktopEngine.exe
2017-02-11 23:10:47 ----A---- C:\WINDOWS\SYSWOW64\VSD3DWARPDebug.dll
2017-02-11 23:10:47 ----A---- C:\WINDOWS\SYSWOW64\VSD3DWARP12Debug.dll
2017-02-11 23:10:47 ----A---- C:\WINDOWS\SYSWOW64\MSVPXENC.dll
2017-02-11 23:10:47 ----A---- C:\WINDOWS\SYSWOW64\DXCpl.exe
2017-02-11 23:10:47 ----A---- C:\WINDOWS\SYSWOW64\d3d12warp.dll
2017-02-11 23:10:47 ----A---- C:\WINDOWS\SYSWOW64\d3d12SDKLayers.dll
2017-02-11 23:10:47 ----A---- C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2017-02-11 23:10:47 ----A---- C:\WINDOWS\system32\MSVPXENC.dll
2017-02-11 23:10:47 ----A---- C:\WINDOWS\system32\DXCpl.exe
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\winmde.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\wininet.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.Management.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\urlmon.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\SyncSettings.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\SearchFolder.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\RTWorkQ.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\remoteaudioendpoint.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\rdpencom.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\rdpcore.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\rasapi32.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\policymanager.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\PlayToManager.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\MSVP9DEC.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\msmpeg2vdec.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfsvr.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\MFPlay.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfplat.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfnetsrc.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfnetcore.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfmpeg2srcsnk.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfmp4srcsnk.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfmkvsrcsnk.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\MFMediaEngine.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfcore.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfaudiocnv.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mfasfsrcsnk.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\mdmregistration.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\MCRecvSrc.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\hevcdecoder.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\efswrt.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\dmenrollengine.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\CloudStorageWizard.exe
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\CloudBackupSettings.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\BcastDVRHelper.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\bcastdvr.exe
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\AzureSettingSyncProvider.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\AUDIOKSE.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\SYSWOW64\AppCapture.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\wpnprv.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\wpncore.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\Windows.Media.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\VSD3DWARPDebug.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\SyncSettings.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\RTWorkQ.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\remoteaudioendpoint.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\rdpudd.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\rdpcorets.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\MSVP9DEC.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\msmpeg2vdec.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfsvr.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\MFPlay.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfplat.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfnetsrc.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfnetcore.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\MFMediaEngine.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfcore.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfaudiocnv.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\hevcdecoder.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\fveapi.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\drivers\mrxsmb10.sys
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\d3d12warp.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\d3d12SDKLayers.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\CloudStorageWizard.exe
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\CloudBackupSettings.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\AudioSes.dll
2017-02-11 23:10:46 ----A---- C:\WINDOWS\system32\AUDIOKSE.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.LockScreen.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\mshtml.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\jscript9diag.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\jscript9.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\indexeddbserver.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\ieproxy.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\ieframe.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\Chakra.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\SYSWOW64\edgehtml.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\system32\mshtml.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\system32\jscript9.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\system32\indexeddbserver.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\system32\ieproxy.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\system32\ieframe.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2017-02-11 23:10:45 ----A---- C:\WINDOWS\system32\Chakra.dll
2017-02-11 23:10:45 ----A---- C:\WINDOWS\system32\edgehtml.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\zipfldr.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\xolehlp.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\wsecedit.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\wscinterop.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\wscapi.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\WinSCard.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Search.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Immersive.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Shell.Search.UriHandler.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\usercpl.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\twinui.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\stobject.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\sspicli.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\shell32.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\setupugc.exe
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\sendmail.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\ReAgentc.exe
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\ole32.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\ntshrui.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\ntdll.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\netshell.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\mtxclu.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\mspaint.exe
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\msi.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\msdtcuiu.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\msdtcprx.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\migisol.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\LogonController.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\LaunchWinApp.exe
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\KernelBase.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\gameux.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\ExplorerFrame.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\explorer.exe
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\DevicePairing.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\cryptui.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\comdlg32.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\apprepsync.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\apprepapi.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\SYSWOW64\aclui.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\winsrv.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\usercpl.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\twinui.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\SyncCenter.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\stobject.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\sspicli.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\shell32.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\sendmail.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\RDXService.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\ntshrui.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\ntdll.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\netplwiz.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\mstscax.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\mspaint.exe
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\msctf.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\lsm.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\LaunchWinApp.exe
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\KernelBase.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\IdCtrls.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\gdi32full.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\gameux.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\ExplorerFrame.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\drivers\srv2.sys
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\drivers\rdbss.sys
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\drivers\partmgr.sys
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\drivers\mrxsmb20.sys
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\DevicePairing.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\DataSenseHandlers.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll
2017-02-11 23:10:39 ----A---- C:\WINDOWS\explorer.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Logon.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.CredDialogController.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Cred.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.BlockedShutdown.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.BioFeedback.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\Windows.ApplicationModel.Store.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\StoreAgent.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\LicenseManager.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\InstallAgentUserBroker.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\SYSWOW64\InstallAgent.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\zipfldr.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wuuhext.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wuaueng.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wuapi.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\WsmSvc.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\WSManHTTPConfig.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wsecedit.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wscsvc.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wscinterop.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wscapi.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wow64.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\WinSCard.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\winresume.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\winlogon.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\winload.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\wininet.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.UI.Search.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\VPNv2CSP.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\vpnike.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\usocore.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\urlmon.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\updatepolicy.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\updatehandlers.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\umpoext.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\StorSvc.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\StoreAgent.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\SRHInproc.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\SRH.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\sppwinob.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\sppobjs.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\sppnp.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\services.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\SearchFolder.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ScDeviceEnum.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\RjvMDMConfig.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ReportingCSP.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ReAgentc.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\RDXTaskFactory.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\rdpencom.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\rdpcore.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\rasmans.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\rascustom.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\rasapi32.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ProvSysprep.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ProvPluginEng.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\provengine.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\policymanager.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\OneBackupHandler.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ole32.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\NgcCtnr.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ngccredprov.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\netshell.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\NetSetupShim.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\msi.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\msdtctm.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\migisol.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\mdmregistration.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\lpremove.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\LogonController.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\LicenseManager.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\KnobsCsp.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\KnobsCore.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\InstallAgent.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ImplatSetup.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\HttpsDataSource.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\fhsettingsprovider.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\fhcfg.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\enterprisecsps.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\efswrt.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\EDPCleanup.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\EditionUpgradeHelper.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\EAMProgressHandler.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\drivers\modem.sys
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\drivers\clfs.sys
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\dosvc.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\domgmt.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\dmenrollengine.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\dmcertinst.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\DeviceReactivation.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\DeviceEnroller.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\cryptui.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\cryptngc.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ConsoleLogon.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\comdlg32.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\CloudExperienceHost.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\ClipUp.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\certprop.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\browserbroker.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\BcastDVRHelper.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\bcastdvr.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\apprepsync.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\apprepapi.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\appraiser.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\AppCapture.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\aitstatic.exe
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\aeinv.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\acmigration.dll
2017-02-11 23:10:35 ----A---- C:\WINDOWS\system32\aclui.dll
2017-02-11 23:10:31 ----A---- C:\WINDOWS\SYSWOW64\MapRouter.dll
2017-02-11 23:10:31 ----A---- C:\WINDOWS\system32\winmde.dll
2017-02-11 23:10:31 ----A---- C:\WINDOWS\system32\PlayToManager.dll
2017-02-11 23:10:31 ----A---- C:\WINDOWS\system32\MCRecvSrc.dll
2017-02-11 23:10:31 ----A---- C:\WINDOWS\system32\dialserver.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\wuapi.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\WsmSvc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\WSManHTTPConfig.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\WordBreakers.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\WinTypes.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\WindowsCodecs.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.Resources.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Xaml.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.UI.Core.TextInput.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\windows.storage.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Storage.ApplicationData.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepositoryClient.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.StateRepository.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\Windows.Media.Protection.PlayReady.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\wincorlib.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\win32kfull.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\win32k.sys

Rolnire
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 07 bře 2015 21:37

Re: Pravděpodobný malware

#2 Příspěvek od Rolnire »

2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\user32.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\updatepolicy.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\UIAutomationCore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\TextInputFramework.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\ShareHost.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncHost.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\SettingSyncCore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\offlinesam.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\NMAA.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\ngccredprov.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\NetSetupShim.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\NetCfgNotifyObjectHost.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\msv1_0.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\mstscax.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\msctf.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\MrmCoreR.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\MosStorage.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\mos.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\MapsBtSvc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\MapGeocoder.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\MapControlCore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\MapConfiguration.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\kerberos.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\JpMapControl.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\InputService.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\InputLocaleManager.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\gdi32full.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\EditBufferTestHook.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\dxgi.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\dwmcore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\DisplayManager.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\DeviceFlows.DataModel.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\D3DCompiler_47.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\D3D12.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\d3d11.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\d3d10warp.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\d2d1.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\cryptngc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\CoreUIComponents.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\CoreMessaging.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\combase.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\cdp.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\BingMaps.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\bcrypt.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\AppXDeploymentClient.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\actxprxy.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\ActivationManager.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\SYSWOW64\aadtb.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\WordBreakers.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\wlidsvc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\wkssvc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\WinTypes.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\WindowsCodecs.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\windows.storage.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.StateRepository.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\wincorlib.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\win32kfull.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\win32kbase.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\win32k.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\wbiosrvc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\user32.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\UIAutomationCore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\TextInputFramework.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\ShareHost.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\setupugc.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\SettingSyncHost.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\SettingSyncCore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\securekernel.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\samsrv.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\offlinesam.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\NMAA.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\msv1_0.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\MrmCoreR.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\MosStorage.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\moshostcore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\moshost.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\mos.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\modernexecserver.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\MapsStore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\MapsBtSvc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\MapRouter.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\MapGeocoder.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\MapControlCore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\MapConfiguration.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\lsasrv.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\kerberos.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\JpMapControl.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\InputService.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\InputLocaleManager.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\hvloader.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\hvix64.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\hvax64.exe
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\facecredentialprovider.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\EditBufferTestHook.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\dxgi.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\dwmcore.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\xboxgip.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\vhdmp.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\tpm.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\pci.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\fastfat.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\dxgmms2.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\dxgmms1.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\dxgkrnl.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\cng.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\drivers\bthport.sys
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\dpapisrv.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\DisplayManager.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\D3DCompiler_47.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\D3D12.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\d3d11.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\d3d10warp.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\d2d1.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\CryptoWinRT.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\CoreUIComponents.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\CoreMessaging.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\combase.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\cloudAP.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\cdpusersvc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\cdpsvc.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\cdp.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\cdd.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\BingMaps.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\bcrypt.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\AppReadiness.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\actxprxy.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\ActivationManager.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\aadtb.dll
2017-02-11 23:10:30 ----A---- C:\WINDOWS\system32\aadcloudap.dll
2017-02-11 22:58:32 ----A---- C:\WINDOWS\SYSWOW64\NlsLexicons0009.dll
2017-02-11 22:58:32 ----A---- C:\WINDOWS\SYSWOW64\NlsData0009.dll
2017-02-11 22:58:32 ----A---- C:\WINDOWS\system32\prm0009.dll
2017-02-11 22:58:32 ----A---- C:\WINDOWS\system32\NlsLexicons0009.dll
2017-02-11 22:58:31 ----A---- C:\WINDOWS\system32\NlsData0009.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsRemoteEngine.exe
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsProxyStub.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsExperiment.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\VsGraphicsCapture.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\perf_gputiming.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\DXToolsReporting.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\DxToolsReportGenerator.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\DXToolsOfflineAnalysis.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\DXToolsMonitor.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\DXGIDebug.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\DXCaptureReplay.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\DXCap.exe
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\d3d11_3SDKLayers.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\SYSWOW64\d2d1debug3.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\VsGraphicsExperiment.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\VsGraphicsCapture.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\perf_gputiming.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\DXToolsReporting.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\DxToolsReportGenerator.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\DXToolsMonitor.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\DXGIDebug.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\DXCaptureReplay.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\DXCap.exe
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2017-02-11 22:58:09 ----A---- C:\WINDOWS\system32\d2d1debug3.dll
2017-02-11 22:46:49 ----D---- C:\WINDOWS\SYSWOW64\XPSViewer
2017-02-11 22:46:46 ----D---- C:\Program Files\Reference Assemblies
2017-02-11 22:46:46 ----D---- C:\Program Files\MSBuild
2017-02-11 22:46:46 ----D---- C:\Program Files (x86)\Reference Assemblies
2017-02-11 22:46:46 ----D---- C:\Program Files (x86)\MSBuild
2017-02-11 22:45:37 ----A---- C:\WINDOWS\SYSWOW64\TsWpfWrp.exe
2017-02-11 22:45:37 ----A---- C:\WINDOWS\SYSWOW64\PresentationNative_v0300.dll
2017-02-11 22:45:37 ----A---- C:\WINDOWS\SYSWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-02-11 22:45:32 ----A---- C:\WINDOWS\system32\TsWpfWrp.exe
2017-02-11 22:45:32 ----A---- C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-02-11 22:45:32 ----A---- C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-02-10 20:33:23 ----A---- C:\WINDOWS\NvContainerRecovery.bat
2017-02-07 21:47:32 ----A---- C:\WINDOWS\SYSWOW64\libGLESv2.dll
2017-02-07 21:47:32 ----A---- C:\WINDOWS\SYSWOW64\libGLESv1_CM.dll
2017-02-07 21:47:32 ----A---- C:\WINDOWS\SYSWOW64\libEGL.dll
2017-02-07 21:47:32 ----A---- C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
2017-02-02 20:44:17 ----AD---- C:\Program Files\Application Verifier
2017-02-02 20:44:17 ----AD---- C:\Program Files (x86)\Application Verifier
2017-02-02 20:44:08 ----AD---- C:\ProgramData\Windows App Certification Kit
2017-02-02 20:41:29 ----AD---- C:\Program Files (x86)\HTML Help Workshop
2017-02-02 20:28:01 ----D---- C:\Users\Mts\AppData\Roaming\NuGet
2017-01-23 10:27:22 ----ASH---- C:\swapfile.sys
2017-01-23 10:27:21 ----ASH---- C:\pagefile.sys
2017-01-23 10:27:18 ----ASH---- C:\hiberfil.sys
2017-01-22 13:28:03 ----D---- C:\Users\Mts\AppData\Roaming\MonoDevelop-Unity-5.0
2017-01-21 17:11:23 ----D---- C:\Users\Mts\AppData\Roaming\Trimble Connect for SketchUp
2017-01-21 17:05:38 ----D---- C:\Users\Mts\AppData\Roaming\SketchUp
2017-01-17 05:54:04 ----A---- C:\WINDOWS\system32\nvoglv64.dll
2017-01-17 05:53:58 ----A---- C:\WINDOWS\SYSWOW64\nvoglv32.dll
2017-01-17 05:53:40 ----A---- C:\WINDOWS\system32\NvIFROpenGL.dll
2017-01-17 05:53:36 ----A---- C:\WINDOWS\SYSWOW64\NvIFROpenGL.dll
2017-01-17 05:53:36 ----A---- C:\WINDOWS\system32\NvIFR64.dll
2017-01-17 05:53:34 ----A---- C:\WINDOWS\SYSWOW64\NvIFR.dll
2017-01-17 05:52:44 ----A---- C:\WINDOWS\system32\NvFBC64.dll
2017-01-17 05:52:40 ----A---- C:\WINDOWS\SYSWOW64\NvFBC.dll
2017-01-17 05:52:40 ----A---- C:\WINDOWS\system32\nvdispgenco6437654.dll
2017-01-17 05:52:36 ----A---- C:\WINDOWS\system32\nvdispco6437654.dll
2017-01-17 05:52:20 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2017-01-17 05:52:16 ----A---- C:\WINDOWS\SYSWOW64\nvcuvid.dll
2017-01-17 05:52:02 ----A---- C:\WINDOWS\system32\nvcompiler.dll
2017-01-17 05:51:52 ----A---- C:\WINDOWS\SYSWOW64\nvcompiler.dll
2017-01-17 05:51:26 ----A---- C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-01-17 05:51:22 ----A---- C:\WINDOWS\SYSWOW64\nvptxJitCompiler.dll
2017-01-17 05:51:20 ----A---- C:\WINDOWS\system32\nvopencl.dll
2017-01-17 05:51:16 ----A---- C:\WINDOWS\SYSWOW64\nvopencl.dll
2017-01-17 05:51:10 ----A---- C:\WINDOWS\SYSWOW64\nvfatbinaryLoader.dll
2017-01-17 05:51:10 ----A---- C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-01-17 05:51:08 ----A---- C:\WINDOWS\SYSWOW64\nvEncodeAPI.dll
2017-01-17 05:51:08 ----A---- C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-01-17 05:51:00 ----A---- C:\WINDOWS\system32\nvEncMFTH264.dll
2017-01-17 05:50:58 ----A---- C:\WINDOWS\SYSWOW64\nvEncMFTH264.dll
2017-01-17 05:50:34 ----A---- C:\WINDOWS\system32\nvcuda.dll
2017-01-17 05:50:32 ----A---- C:\WINDOWS\SYSWOW64\nvcuda.dll
2017-01-17 05:50:30 ----A---- C:\WINDOWS\SYSWOW64\nvapi.dll

======List of files/folders modified in the last 1 month======

2017-02-12 17:40:58 ----RD---- C:\Program Files
2017-02-12 17:37:37 ----D---- C:\WINDOWS\AppReadiness
2017-02-12 17:32:12 ----D---- C:\WINDOWS\Temp
2017-02-12 17:31:53 ----HD---- C:\Program Files\WindowsApps
2017-02-12 17:24:37 ----D---- C:\WINDOWS\System32
2017-02-12 17:24:37 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-12 17:20:09 ----D---- C:\WINDOWS\system32\WDI
2017-02-12 17:17:48 ----D---- C:\WINDOWS\system32\sru
2017-02-12 17:17:15 ----D---- C:\WINDOWS\system32\drivers
2017-02-12 17:17:11 ----D---- C:\Windows
2017-02-12 17:16:46 ----D---- C:\WINDOWS\system32\catroot2
2017-02-12 17:16:46 ----D---- C:\WINDOWS\system32\CatRoot
2017-02-12 17:07:49 ----D---- C:\WINDOWS\SysWOW64
2017-02-12 17:07:48 ----RD---- C:\Program Files (x86)
2017-02-12 17:05:45 ----D---- C:\WINDOWS\INF
2017-02-12 17:05:44 ----D---- C:\WINDOWS\system32\DriverStore
2017-02-12 17:04:25 ----D---- C:\WINDOWS\system32\config
2017-02-12 17:00:15 ----D---- C:\WINDOWS\WinSxS
2017-02-12 16:59:29 ----D---- C:\WINDOWS\CbsTemp
2017-02-12 16:51:14 ----D---- C:\WINDOWS\appcompat
2017-02-12 16:47:30 ----D---- C:\WINDOWS\system32\SleepStudy
2017-02-12 00:03:48 ----D---- C:\WINDOWS\rescache
2017-02-11 23:58:14 ----D---- C:\WINDOWS\Logs
2017-02-11 23:56:33 ----D---- C:\WINDOWS\SoftwareDistribution
2017-02-11 23:55:08 ----D---- C:\WINDOWS\Registration
2017-02-11 23:55:00 ----D---- C:\WINDOWS\system32\WinBioDatabase
2017-02-11 23:55:00 ----D---- C:\WINDOWS\system32\Tasks_Migrated
2017-02-11 23:48:09 ----D---- C:\WINDOWS\system32\LogFiles
2017-02-11 23:47:59 ----D---- C:\WINDOWS\system32\Tasks
2017-02-11 23:47:27 ----SD---- C:\ProgramData\Microsoft
2017-02-11 23:46:52 ----RSD---- C:\WINDOWS\Fonts
2017-02-11 23:46:32 ----D---- C:\WINDOWS\system32\drivers\etc
2017-02-11 23:42:55 ----D---- C:\WINDOWS\SYSWOW64\drivers
2017-02-11 23:42:55 ----D---- C:\WINDOWS\SYSWOW64\1033
2017-02-11 23:42:50 ----D---- C:\WINDOWS\system32\1033
2017-02-11 23:42:48 ----HD---- C:\WINDOWS\Installer
2017-02-11 23:42:48 ----D---- C:\WINDOWS\ShellNew
2017-02-11 23:41:20 ----D---- C:\ProgramData\regid.1991-06.com.microsoft
2017-02-11 23:35:05 ----D---- C:\WINDOWS\SYSWOW64\migration
2017-02-11 23:35:03 ----D---- C:\WINDOWS\SYSWOW64\en-US
2017-02-11 23:35:01 ----D---- C:\WINDOWS\SYSWOW64\BestPractices
2017-02-11 23:34:51 ----D---- C:\WINDOWS\system32\oobe
2017-02-11 23:34:51 ----D---- C:\WINDOWS\system32\NDF
2017-02-11 23:34:51 ----D---- C:\WINDOWS\system32\MRT
2017-02-11 23:34:49 ----D---- C:\WINDOWS\system32\en-US
2017-02-11 23:34:02 ----D---- C:\WINDOWS\system32\BestPractices
2017-02-11 23:33:55 ----RD---- C:\WINDOWS\Microsoft.NET
2017-02-11 23:33:54 ----D---- C:\WINDOWS\LiveKernelReports
2017-02-11 23:33:45 ----RD---- C:\WINDOWS\assembly
2017-02-11 23:33:38 ----RD---- C:\Users
2017-02-11 23:33:38 ----HD---- C:\ProgramData
2017-02-11 23:33:30 ----D---- C:\Program Files (x86)\Microsoft.NET
2017-02-11 23:33:29 ----D---- C:\Program Files (x86)\Common Files
2017-02-11 23:33:24 ----D---- C:\Program Files\Common Files\microsoft shared
2017-02-11 23:33:24 ----D---- C:\Program Files\Common Files
2017-02-11 23:33:24 ----AD---- C:\Program Files\IIS
2017-02-11 23:29:46 ----D---- C:\WINDOWS\system32\Recovery
2017-02-11 23:29:00 ----D---- C:\WINDOWS\system32\CodeIntegrity
2017-02-11 23:26:39 ----SHD---- C:\Recovery
2017-02-11 23:26:36 ----D---- C:\WINDOWS\system32\Sysprep
2017-02-11 23:24:08 ----D---- C:\WINDOWS\Help
2017-02-11 23:22:33 ----D---- C:\WINDOWS\system32\drivers\UMDF
2017-02-11 23:12:58 ----RD---- C:\WINDOWS\ImmersiveControlPanel
2017-02-11 23:12:58 ----D---- C:\WINDOWS\SYSWOW64\oobe
2017-02-11 23:12:58 ----D---- C:\WINDOWS\SYSWOW64\Dism
2017-02-11 23:12:58 ----D---- C:\WINDOWS\system32\WinBioPlugIns
2017-02-11 23:12:58 ----D---- C:\WINDOWS\system32\wbem
2017-02-11 23:12:58 ----D---- C:\WINDOWS\system32\sr-Latn-CS
2017-02-11 23:12:58 ----D---- C:\WINDOWS\system32\drivers\en-US
2017-02-11 23:12:58 ----D---- C:\WINDOWS\system32\Dism
2017-02-11 23:12:58 ----D---- C:\WINDOWS\ShellExperiences
2017-02-11 23:12:58 ----D---- C:\WINDOWS\servicing
2017-02-11 23:12:58 ----D---- C:\WINDOWS\Provisioning
2017-02-11 23:12:58 ----D---- C:\WINDOWS\bcastdvr
2017-02-11 23:12:58 ----D---- C:\WINDOWS\AppPatch
2017-02-11 23:12:58 ----D---- C:\Program Files\Internet Explorer
2017-02-11 23:12:58 ----D---- C:\Program Files (x86)\Internet Explorer
2017-02-11 23:12:57 ----D---- C:\WINDOWS\system32\Boot
2017-02-11 23:08:17 ----A---- C:\WINDOWS\system32\enrollmentapi.dll
2017-02-11 22:57:35 ----D---- C:\WINDOWS\SYSWOW64\winrm
2017-02-11 22:57:35 ----D---- C:\WINDOWS\SYSWOW64\WCN
2017-02-11 22:57:34 ----SD---- C:\WINDOWS\SYSWOW64\F12
2017-02-11 22:57:34 ----D---- C:\WINDOWS\SYSWOW64\slmgr
2017-02-11 22:57:34 ----D---- C:\WINDOWS\SYSWOW64\Printing_Admin_Scripts
2017-02-11 22:57:33 ----SD---- C:\WINDOWS\SYSWOW64\DiagSvcs
2017-02-11 22:57:33 ----SD---- C:\WINDOWS\system32\F12
2017-02-11 22:57:33 ----SD---- C:\WINDOWS\system32\DiagSvcs
2017-02-11 22:57:33 ----RD---- C:\WINDOWS\MiracastView
2017-02-11 22:57:33 ----D---- C:\WINDOWS\SYSWOW64\en
2017-02-11 22:57:33 ----D---- C:\WINDOWS\SYSWOW64\drivers\en-US
2017-02-11 22:57:33 ----D---- C:\WINDOWS\system32\winrm
2017-02-11 22:57:33 ----D---- C:\WINDOWS\system32\WCN
2017-02-11 22:57:33 ----D---- C:\WINDOWS\system32\SystemResetPlatform
2017-02-11 22:57:33 ----D---- C:\WINDOWS\system32\slmgr
2017-02-11 22:57:33 ----D---- C:\WINDOWS\system32\Printing_Admin_Scripts
2017-02-11 22:57:33 ----D---- C:\WINDOWS\system32\migwiz
2017-02-11 22:57:33 ----D---- C:\WINDOWS\system32\en
2017-02-11 22:57:33 ----D---- C:\WINDOWS\en-US
2017-02-11 22:57:33 ----D---- C:\Program Files\Windows Photo Viewer
2017-02-11 22:57:33 ----D---- C:\Program Files\Windows Media Player
2017-02-11 22:57:33 ----D---- C:\Program Files (x86)\Windows Photo Viewer
2017-02-11 22:57:33 ----D---- C:\Program Files (x86)\Windows Media Player
2017-02-11 22:57:33 ----D---- C:\Program Files (x86)\Windows Defender
2017-02-11 22:57:32 ----RD---- C:\Program Files\Windows Defender
2017-02-11 22:51:21 ----SD---- C:\WINDOWS\system32\Microsoft
2017-02-11 22:46:49 ----D---- C:\WINDOWS\SYSWOW64\MUI
2017-02-11 22:46:49 ----D---- C:\WINDOWS\SYSWOW64\cs-CZ
2017-02-11 22:46:49 ----D---- C:\WINDOWS\system32\MUI
2017-02-11 22:46:49 ----D---- C:\WINDOWS\system32\cs-CZ
2017-02-11 22:36:36 ----SHD---- C:\System Volume Information
2017-02-11 22:30:26 ----HD---- C:\$WINDOWS.~BT
2017-02-11 21:45:52 ----D---- C:\Program Files (x86)\Steam
2017-02-10 20:33:22 ----D---- C:\Program Files (x86)\NVIDIA Corporation
2017-02-10 00:25:38 ----D---- C:\Users\Mts\AppData\Roaming\TS3Client
2017-02-09 17:13:51 ----HD---- C:\Intel
2017-02-07 21:47:32 ----A---- C:\WINDOWS\SYSWOW64\Intel_OpenCL_ICD32.dll
2017-02-05 14:17:18 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 12.0
2017-02-05 14:17:18 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 11.0
2017-02-05 14:17:18 ----AD---- C:\Program Files (x86)\Microsoft Visual Studio 14.0
2017-02-03 20:19:25 ----D---- C:\ProgramData\Unity
2017-02-02 20:49:20 ----D---- C:\ProgramData\Package Cache
2017-02-02 20:42:40 ----AD---- C:\Program Files (x86)\Microsoft SDKs
2017-02-02 20:42:29 ----D---- C:\Program Files (x86)\Windows Kits
2017-01-31 23:09:46 ----D---- C:\Users\Mts\AppData\Roaming\vlc
2017-01-21 17:21:11 ----D---- C:\Users\Mts\AppData\Roaming\Unity
2017-01-17 05:50:32 ----A---- C:\WINDOWS\system32\nvapi64.dll

File C:\WINDOWS\system32\winlogon.exe is digitally signed
File C:\WINDOWS\system32\wininit.exe is digitally signed
File C:\WINDOWS\explorer.exe is digitally signed
File C:\WINDOWS\SysWOW64\explorer.exe is digitally signed
File C:\WINDOWS\system32\svchost.exe is digitally signed
File C:\WINDOWS\SysWOW64\svchost.exe is digitally signed
File C:\WINDOWS\system32\services.exe is digitally signed
File C:\WINDOWS\system32\User32.dll is digitally signed
File C:\WINDOWS\SysWOW64\User32.dll is digitally signed
File C:\WINDOWS\system32\userinit.exe is digitally signed
File C:\WINDOWS\SysWOW64\userinit.exe is digitally signed
File C:\WINDOWS\system32\rpcss.dll is digitally signed
File C:\WINDOWS\system32\Drivers\volsnap.sys is digitally signed

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R0 iaStorA;iaStorA; C:\WINDOWS\System32\drivers\iaStorA.sys [2015-07-25 1455552]
R0 iorate;@%SystemRoot%\system32\drivers\iorate.sys,-100; C:\WINDOWS\system32\drivers\iorate.sys [2016-11-21 48992]
R2 clreg;@%SystemRoot%\system32\drivers\registry.sys,-100; C:\WINDOWS\System32\drivers\registry.sys [2016-07-16 70144]
R2 NPF;NPF Driver; \??\C:\Program Files (x86)\hicloud\PCPlayer\npf64.sys [2016-05-04 36600]
R3 BtFilter;BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [2016-06-26 610656]
R3 BTHUSB;@bth.inf,%BTHUSB.SvcDesc%;Ovladač rozhraní USB radiostanice Bluetooth; C:\WINDOWS\system32\DRIVERS\BTHUSB.sys [2016-11-21 84992]
R3 nvlddmkm;nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_31f4ef4821269ebb\nvlddmkm.sys [2017-01-17 14190520]
R3 NvStreamKms;NvStreamKms; \??\C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [2016-06-15 28216]
R3 nvvad_WaveExtensible;@oem4.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM); C:\WINDOWS\system32\drivers\nvvad64v.sys [2016-04-14 56384]
R3 Qcamain10x64;@netathr10x.inf,%ATHR.Service.DispName%;Qualcomm Atheros Extensible Wireless LAN 11AC device driver; C:\WINDOWS\System32\drivers\Qcamain10x64.sys [2016-07-16 2336768]
R3 rt640x64;@oem7.inf,%rt640.Service.DispName%;Realtek RT640 NT Driver; C:\WINDOWS\System32\drivers\rt640x64.sys [2015-05-29 886528]
R3 RTSUER;@oem14.inf,%RtsUER%;Realtek USB Card Reader - UER; C:\WINDOWS\system32\Drivers\RtsUer.sys [2015-05-27 402136]
R3 SensorsSimulatorDriver;@oem16.inf,%WudfSensorsSimulatorDriverDisplayName%;UMDF Reflector service for SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [2016-07-16 216064]
R3 SynRMIHID;@oem10.inf,%SynRMIHID.SVCDESC%;Synaptics HID Service; C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys [2015-07-29 47784]
S0 megasas2i;megasas2i; C:\WINDOWS\System32\drivers\MegaSas2i.sys [2016-11-21 64352]
S0 scmbus;@scmbus.inf,%scmbus.SvcDesc%;Microsoft Storage Class Memory Bus Driver; C:\WINDOWS\System32\drivers\scmbus.sys [2016-07-16 88416]
S3 AcpiDev;@acpidev.inf,%AcpiDev.SvcDesc%;ACPI Devices driver; C:\WINDOWS\System32\drivers\AcpiDev.sys [2016-07-16 18432]
S3 applockerfltr;@%systemroot%\system32\srpapi.dll,-102; C:\WINDOWS\system32\drivers\applockerfltr.sys [2016-07-16 15360]
S3 BTHPORT;@bth.inf,%BTHPORT.SvcDesc%;Ovladač portu Bluetooth; C:\WINDOWS\system32\DRIVERS\BTHport.sys [2017-02-11 967168]
S3 hvservice;@%SystemRoot%\system32\drivers\hvservice.sys,-16; C:\WINDOWS\system32\drivers\hvservice.sys [2016-11-21 73568]
S3 HyperVideo;HyperVideo; C:\WINDOWS\system32\DRIVERS\HyperVideo.sys [2016-07-16 25088]
S3 cht4iscsi;cht4iscsi; C:\WINDOWS\System32\drivers\cht4sx64.sys [2016-07-16 346976]
S3 cht4vbd;@cht4vx64.inf,%cht4vbd.generic%;Chelsio Virtual Bus Driver; C:\WINDOWS\System32\drivers\cht4vx64.sys [2016-07-16 2104160]
S3 iagpio;@iagpio.inf,%iagpio.SVCDESC%;Intel Serial IO GPIO Controller Driver; C:\WINDOWS\System32\drivers\iagpio.sys [2016-07-16 33280]
S3 iaLPSS2i_GPIO2;@iaLPSS2i_GPIO2_SKL.inf,%iaLPSS2i_GPIO2.SVCDESC%;Intel(R) Serial IO GPIO Driver v2; C:\WINDOWS\System32\drivers\iaLPSS2i_GPIO2.sys [2016-07-16 64512]
S3 IndirectKmd;@%SystemRoot%\system32\drivers\IndirectKmd.sys,-100; C:\WINDOWS\System32\drivers\IndirectKmd.sys [2016-07-16 35840]
S3 irda;IrDA; C:\WINDOWS\system32\drivers\irda.sys [2016-07-16 120320]
S3 LMDriver;Launch Manager Wireless Driver; C:\WINDOWS\System32\drivers\LMDriver.sys [2015-07-18 21344]
S3 NetAdapterCx;Network Adapter Wdf Class Extension Library; C:\WINDOWS\system32\drivers\NetAdapterCx.sys [2016-07-16 90624]
S3 netvsc;netvsc; C:\WINDOWS\System32\drivers\netvsc.sys [2016-11-21 113152]
S3 Qcamain;Qualcomm Atheros Extensible Wireless LAN 11AC device driver; C:\WINDOWS\System32\drivers\Qcamainx64.sys [2015-07-10 2276352]
S3 RadioShim;Shim for HID-KMDF Interface layer; C:\WINDOWS\System32\drivers\RadioShim.sys [2015-07-18 14688]
S3 scmdisk0101;@scmdisk0101.inf,%scmdisk0101.SvcDesc%;Microsoft NVDIMM-N disk driver; C:\WINDOWS\System32\drivers\scmdisk0101.sys [2016-07-16 123904]
S3 UcmTcpciCx0101;UCM-TCPCI KMDF Class Extension; C:\WINDOWS\System32\Drivers\UcmTcpciCx.sys [2016-07-16 108544]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AtherosSvc;AtherosSvc; C:\WINDOWS\system32\AdminService.exe [2016-06-26 355760]
R2 CCDMonitorService;CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2015-11-17 2860760]
R2 CDPUserSvc_35d18;CDPUserSvc_35d18; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
R2 GamesAppIntegrationService;GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [2015-04-14 373312]
R2 GfExperienceService;NVIDIA GeForce Experience Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [2016-06-15 1165368]
R2 isaHelperSvc;Intel(R) Security Assist Helper; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [2015-05-19 7680]
R2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [2015-07-11 223520]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2015-07-11 415520]
R2 NVDisplay.ContainerLocalSystem;NVIDIA Display Container LS; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [2016-12-29 458176]
R2 NvNetworkService;NVIDIA Network Service; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [2016-06-15 1881144]
R2 NvStreamSvc;NVIDIA Streamer Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2016-06-15 2522680]
R2 OneSyncSvc_35d18;Hostitel synchronizace_35d18; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
R3 cplspcon;Intel(R) Content Protection HDCP Service; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\IntelCpHDCPSvc.exe [2017-02-07 488944]
R3 FontCache3.0.0.0;@%SystemRoot%\system32\PresentationHost.exe,-3309; C:\WINDOWS\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [2016-05-25 43696]
R3 NvStreamNetworkSvc;NVIDIA Streamer Network Service; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [2016-06-15 3634232]
R3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184]
R3 TimeBrokerSvc;@%windir%\system32\TimeBrokerServer.dll,-1001; %SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\TimeBrokerServer.dll
S2 CDPUserSvc;@%SystemRoot%\system32\cdpusersvc.dll,-100; %SystemRoot%\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=%SystemRoot%\System32\CDPUserSvc.dll
S2 SkypeUpdate;Skype Updater; C:\Program Files (x86)\Skype\Updater\Updater.exe [2016-07-25 324224]
S3 aspnet_state;@%SystemRoot%\Microsoft.NET\Framework64\v4.0.30319\aspnet_rc.dll,-1; C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe [2016-07-16 52920]
S3 BITCOMET_HELPER_SERVICE;BitComet Disk Boost Service; C:\Program Files\BitComet\tools\BitCometService.exe [2013-11-29 1296728]
S3 FrameServer;@%systemroot%\system32\FrameServer.dll,-100; %SystemRoot%\System32\svchost.exe -k Camera;"ServiceDll"=%SystemRoot%\system32\FrameServer.dll
S3 fussvc;Windows App Certification Kit Fast User Switching Utility Service; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [2014-02-20 142336]
S3 GamesAppService;GamesAppService; C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2014-12-16 265808]
S3 HvHost;@%SystemRoot%\system32\hvhostsvc.dll,-100; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\hvhostsvc.dll
S3 Intel(R) Capability Licensing Service TCP IP Interface;Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2015-05-22 881152]
S3 Intel(R) Security Assist;Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [2015-05-19 335872]
S3 irmon;@%SystemRoot%\System32\irmon.dll,-2000; %SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\irmon.dll
S3 MessagingService_35d18;Služba zasílání zpráv_35d18; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service; C:\Program Files (x86)\Microsoft Office\Office14\GROOVE.EXE [2010-03-25 30969208]
S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 PimIndexMaintenanceSvc_35d18;Data kontaktů_35d18; C:\WINDOWS\system32\svchost.exe -k UnistackSvcGroup;"ServiceDll"=
S3 RmSvc;@%SystemRoot%\system32\RMapi.dll,-1001; %SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestricted;"ServiceDll"=%SystemRoot%\System32\RMapi.dll
S3 Steam Client Service;Steam Client Service; C:\Program Files (x86)\Common Files\Steam\SteamService.exe [2017-01-19 1464096]
S3 Te.Service;Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-22 119808]
S4 shpamsvc;@%SystemRoot%\System32\Windows.SharedPC.AccountManager.dll,-100; %SystemRoot%\System32\svchost.exe -k netsvcs;"ServiceDll"=%systemroot%\system32\Windows.SharedPC.AccountManager.dll

-----------------EOF-----------------

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119671
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravděpodobný malware

#3 Příspěvek od Rudy »

Zdravím!
Spusťte tuto utilitu:
Stáhněte AdwCleaner https://toolslib.net/downloads/viewdown ... dwcleaner/
Uložte na plochu
Ukončete všechny programy
Klikněte nejprve na >Scan<(hledání) a pak na >Clean< (mazání).
Proběhne skenováni a pak se objeví log, který sem vložte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rolnire
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 07 bře 2015 21:37

Re: Pravděpodobný malware

#4 Příspěvek od Rolnire »

další log:

# AdwCleaner v6.043 - Log vytvořen 12/02/2017 v 21:00:57
# Aktualizováno dne 27/01/2017 z Malwarebytes
# Databáze : 2017-02-12.1 [Server]
# Operační systém : Windows 10 Home (X64)
# Uživatelské jméno : Mts - LAPTOP-DCE87H6T
# Spuštěno z : C:\Users\Mts\Desktop\adwcleaner_6.043.exe
# Mod: Čištění
# Podpora : https://www.malwarebytes.com/support



***** [ Služby ] *****



***** [ Složky ] *****

[-] Složka smazána: C:\Users\Mts\AppData\Local\Host App Service
[-] Složka smazána: C:\Program Files\DriverSetupUtility
[-] Složka smazána: C:\ProgramData\DriverSetupUtility
[#] Složka smazána po restartu: C:\Users\Mts\AppData\Local\Host App Service
[-] Složka smazána: C:\Users\Default\AppData\Local\Host App Service
[-] Složka smazána: C:\Users\Public\Pokki


***** [ Soubory ] *****

[-] Soubor smazán: C:\Users\Mts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\App Explorer.lnk
[-] Soubor smazán: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\App Explorer.lnk
[-] Soubor smazán: C:\Users\Default\Desktop\App Explorer.lnk


***** [ DLL ] *****



***** [ WMI ] *****



***** [ Zástupci ] *****



***** [ Naplánované úlohy ] *****

[-] Úloha smazána: App Explorer
[-] Úloha smazána: Software Update Application


***** [ Registry ] *****

[-] Klíč smazán: HKU\S-1-5-21-3004555776-1804217010-3673089335-1001\Software\Host App Service
[-] Klíč smazán: HKU\S-1-5-21-3004555776-1804217010-3673089335-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
[#] Klíč smazán po restartu: HKCU\Software\Host App Service
[#] Klíč smazán po restartu: HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
[#] Klíč smazán po restartu: [x64] HKCU\Software\Host App Service
[#] Klíč smazán po restartu: [x64] HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\Host App Service
[-] Klíč smazán: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{2B51C83A-465D-4EA9-9CDC-1ED95ED09AC6}
[-] Klíč smazán: HKLM\SOFTWARE\Classes\Installer\Features\A38C15B2D5649AE4C9CDE19DE50DA96C
[-] Klíč smazán: HKLM\SOFTWARE\Classes\Installer\Products\A38C15B2D5649AE4C9CDE19DE50DA96C
[-] Klíč smazán: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A38C15B2D5649AE4C9CDE19DE50DA96C
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A38C15B2D5649AE4C9CDE19DE50DA96C
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\Installer\Features\A38C15B2D5649AE4C9CDE19DE50DA96C
[#] Klíč smazán po restartu: [x64] HKLM\SOFTWARE\Classes\Installer\Products\A38C15B2D5649AE4C9CDE19DE50DA96C


***** [ Prohlížeče ] *****



*************************

:: "Tracing" klíče smazány
:: Winsock nastavení vyčištěno

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [2921 Bajty] - [12/02/2017 21:00:57]
C:\AdwCleaner\AdwCleaner[S0].txt - [3166 Bajty] - [12/02/2017 20:59:42]

########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3067 Bajty] ##########

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119671
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravděpodobný malware

#5 Příspěvek od Rudy »

Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rolnire
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 07 bře 2015 21:37

Re: Pravděpodobný malware

#6 Příspěvek od Rolnire »

FRST log:

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-02-2017
Ran by Mts (administrator) on LAPTOP-DCE87H6T (13-02-2017 09:05:11)
Running from C:\Users\Mts\Desktop
Loaded Profiles: Mts (Available Profiles: Mts)
Platform: Windows 10 Home Version 1607 (X64) Language: Čeština (Česká republika)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/33 ... scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\igfxCUIService.exe
(Windows (R) Win 7 DDK provider) C:\Windows\System32\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe
() C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\igfxEM.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Dolby Laboratories Inc.) C:\Program Files\Dolby Digital Plus\ddp.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Realtek\Audio\HDA\FMAPP.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\hicloud\update_server\startUp.exe
() C:\Program Files (x86)\hicloud\update_server\SPUpDateServer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
() C:\OEM\Preload\FubTracking\FubTracking.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\AOP Framework\BackgroundAgent.exe
(Acer Cloud Technology) C:\Program Files (x86)\Acer\AOP Framework\acer\ccd.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(acer) C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(forum.viry.cz) C:\Users\Mts\Desktop\FRSTLauncher.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-11-21] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14040792 2015-07-07] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-06-30] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-06-15] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
HKLM-x32\...\Run: [SPUpDateServerrun] => C:\Program Files (x86)\hicloud\update_server\startUp.exe [15232 2015-06-15] ()

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{5e44bb0c-21fd-444b-8386-ec66adb71f3c}: [DhcpNameServer] 82.144.128.1 82.144.129.1 192.168.1.1
Tcpip\..\Interfaces\{cbcc4d0e-9a33-40ba-98d2-e7cfa5b9a070}: [DhcpNameServer] 10.0.0.1

Internet Explorer:
==================
HKU\S-1-5-21-3004555776-1804217010-3673089335-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://acer15.msn.com/?pc=ACTE
HKU\S-1-5-21-3004555776-1804217010-3673089335-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer15.msn.com/?pc=ACTE
SearchScopes: HKU\S-1-5-21-3004555776-1804217010-3673089335-1001 -> DefaultScope {EBFEFA09-C112-4EEA-89ED-655434DDDBB7} URL =
SearchScopes: HKU\S-1-5-21-3004555776-1804217010-3673089335-1001 -> {EBFEFA09-C112-4EEA-89ED-655434DDDBB7} URL =
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_111\bin\ssv.dll [2016-11-08] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-08] (Oracle Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2010-03-25] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\ssv.dll [2016-11-08] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\jp2ssv.dll [2016-11-08] (Oracle Corporation)

FireFox:
========
FF DefaultProfile: hva18wa5.default
FF ProfilePath: C:\Users\Mts\AppData\Roaming\Mozilla\Firefox\Profiles\hva18wa5.default [2017-01-27]
FF Extension: (Amazon 1Button App for Firefox) - C:\Users\Mts\AppData\Roaming\Mozilla\Firefox\Profiles\hva18wa5.default\Extensions\abb@amazon.com [2016-01-21] [not signed]
FF Extension: (Czech (CZ) Language Pack) - C:\Users\Mts\AppData\Roaming\Mozilla\Firefox\Profiles\hva18wa5.default\Extensions\langpack-cs@firefox.mozilla.org [2016-01-21] [not signed]
FF Plugin: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-08] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-08] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-09] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\dtplugin\npDeployJava1.dll [2016-11-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.111.2 -> C:\Program Files (x86)\Java\jre1.8.0_111\bin\plugin2\npjp2.dll [2016-11-08] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-19] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-15] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin-x32: shipin7 -> C:\Program Files (x86)\hicloud\PCPlayer\npSP7WebVideoPlugin.dll [2016-05-09] ()
FF Plugin-x32: shipin7safebox -> C:\Program Files (x86)\hicloud\PCPlayer\npSafePlugin.dll [2016-05-09] ()
FF Plugin-x32: shipin7update -> C:\Program Files (x86)\hicloud\PCPlayer\npUpdataPlugin.dll [2016-05-09] ()

Chrome:
=======
CHR Profile: C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default [2017-02-13]
CHR Extension: (Google Slides) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-21]
CHR Extension: (Google Docs) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-21]
CHR Extension: (Google Drive) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-21]
CHR Extension: (YouTube) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-21]
CHR Extension: (Google Search) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-21]
CHR Extension: (Google Sheets) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-21]
CHR Extension: (Google Docs Offline) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]
CHR Extension: (AdBlock) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-01-31]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-18]
CHR Extension: (Gmail) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-21]
CHR Extension: (Chrome Media Router) - C:\Users\Mts\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-08]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AtherosSvc; C:\WINDOWS\system32\AdminService.exe [355760 2016-06-26] (Windows (R) Win 7 DDK provider)
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (www.BitComet.com)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\AOP Framework\CCDMonitorService.exe [2860760 2015-11-17] (Acer Incorporated)
R3 cphs; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\IntelCpHeciSvc.exe [310256 2017-02-07] (Intel Corporation)
S3 cplspcon; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\IntelCpHDCPSvc.exe [488944 2017-02-07] (Intel Corporation)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373312 2015-04-14] (WildTangent)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1165368 2016-06-15] (NVIDIA Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\igfxCUIService.exe [350704 2017-02-07] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
R2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223520 2015-07-11] (Intel Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-06-15] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-06-15] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-06-15] (NVIDIA Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
R3 UEIPSvc; C:\Program Files\Acer\User Experience Improvement Program\Framework\UBTService.exe [247040 2015-05-27] (acer)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [108776 2016-09-06] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 igfx; C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_82119d956c80af5a\igdkmd64.sys [11041776 2017-02-07] (Intel Corporation)
S3 LMDriver; C:\WINDOWS\System32\drivers\LMDriver.sys [21344 2015-07-18] (Acer Incorporated)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R2 NPF; C:\Program Files (x86)\hicloud\PCPlayer\npf64.sys [36600 2016-05-04] (Riverbed Technology, Inc.)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvacwu.inf_amd64_31f4ef4821269ebb\nvlddmkm.sys [14190520 2017-01-17] (NVIDIA Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-06-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
S3 Qcamain; C:\WINDOWS\System32\drivers\Qcamainx64.sys [2276352 2015-07-10] (Qualcomm Atheros, Inc.) [File not signed]
R3 Qcamain10x64; C:\WINDOWS\System32\drivers\Qcamain10x64.sys [2336768 2016-07-16] (Qualcomm Atheros, Inc.)
S3 RadioShim; C:\WINDOWS\System32\drivers\RadioShim.sys [14688 2015-07-18] (Acer Incorporated)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation)
R3 SensorsSimulatorDriver; C:\WINDOWS\System32\drivers\WUDFRd.sys [216064 2016-07-16] (Microsoft Corporation)
R3 SynRMIHID; C:\WINDOWS\system32\DRIVERS\SynRMIHID.sys [47784 2015-07-29] (Synaptics Incorporated)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-13 09:05 - 2017-02-13 09:05 - 00018621 _____ C:\Users\Mts\Desktop\FRST.txt
2017-02-13 09:04 - 2017-02-13 09:05 - 00000000 ____D C:\FRST
2017-02-13 09:02 - 2017-02-13 09:02 - 00112640 _____ (forum.viry.cz) C:\Users\Mts\Desktop\FRSTLauncher.exe
2017-02-13 08:58 - 2017-02-13 09:03 - 02421248 _____ (Farbar) C:\Users\Mts\Desktop\FRST64.exe
2017-02-12 20:58 - 2017-02-12 21:00 - 00000000 ____D C:\AdwCleaner
2017-02-12 18:50 - 2017-02-12 20:58 - 04015056 _____ C:\Users\Mts\Desktop\adwcleaner_6.043.exe
2017-02-12 17:40 - 2017-02-12 17:41 - 00000000 ____D C:\rsit
2017-02-12 17:40 - 2017-02-12 17:41 - 00000000 ____D C:\Program Files\trend micro
2017-02-12 17:38 - 2017-02-12 17:40 - 01323520 _____ C:\Users\Mts\Downloads\RSITx64.exe
2017-02-12 17:07 - 2017-02-12 17:07 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-02-12 17:07 - 2016-09-09 19:25 - 00269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-02-12 17:07 - 2016-09-09 19:25 - 00261920 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-02-12 17:07 - 2016-09-09 19:25 - 00110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-02-12 17:07 - 2016-09-09 19:24 - 00125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-02-12 17:01 - 2017-02-12 17:06 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-02-11 23:58 - 2017-02-12 17:24 - 00000000 ____D C:\Users\Mts\AppData\Local\ConnectedDevicesPlatform
2017-02-11 23:58 - 2017-02-11 23:58 - 00000020 ___SH C:\Users\Mts\ntuser.ini
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Šablony
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Soubory cookie
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Poslední
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Okolní tiskárny
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Okolní síť
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Nabídka Start
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Dokumenty
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Documents\Obrázky
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Documents\Hudba
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Documents\Filmy
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\Data aplikací
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default\AppData\Local\Data aplikací
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default User\Documents\Obrázky
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default User\Documents\Hudba
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default User\Documents\Filmy
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\Default User\AppData\Local\Data aplikací
2017-02-11 23:55 - 2017-02-11 23:56 - 00007623 _____ C:\WINDOWS\diagwrn.xml
2017-02-11 23:55 - 2017-02-11 23:56 - 00007623 _____ C:\WINDOWS\diagerr.xml
2017-02-11 23:47 - 2017-02-13 08:55 - 00003808 _____ C:\WINDOWS\System32\Tasks\AutoKMS
2017-02-11 23:47 - 2017-02-11 23:48 - 00003398 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2017-02-11 23:47 - 2017-02-11 23:47 - 00003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-02-11 23:47 - 2017-02-11 23:47 - 00003350 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{34745B33-4824-48D5-B4EE-ABD980DA0982}
2017-02-11 23:47 - 2017-02-11 23:47 - 00003174 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-02-11 23:47 - 2017-02-11 23:47 - 00002706 _____ C:\WINDOWS\System32\Tasks\UbtFrameworkService
2017-02-11 23:47 - 2017-02-11 23:47 - 00002564 _____ C:\WINDOWS\System32\Tasks\BacKGroundAgent
2017-02-11 23:47 - 2017-02-11 23:47 - 00002274 _____ C:\WINDOWS\System32\Tasks\DolbySelectorTask
2017-02-11 23:47 - 2017-02-11 23:47 - 00002074 _____ C:\WINDOWS\System32\Tasks\FUBTrackingByPLD
2017-02-11 23:47 - 2017-02-11 23:47 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2017-02-11 23:41 - 2017-02-11 23:41 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-02-11 23:29 - 2017-02-11 23:42 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-02-11 23:27 - 2017-02-13 08:56 - 00000000 ____D C:\Users\Mts
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Šablony
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Soubory cookie
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Poslední
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Okolní tiskárny
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Okolní síť
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Nabídka Start
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Dokumenty
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Documents\Obrázky
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Documents\Hudba
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Documents\Filmy
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\Data aplikací
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\AppData\Roaming\Microsoft\Windows\Start Menu\Programy
2017-02-11 23:27 - 2017-02-11 23:27 - 00000000 _SHDL C:\Users\Mts\AppData\Local\Data aplikací
2017-02-11 23:26 - 2017-02-11 23:26 - 01431204 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-02-11 23:24 - 2017-02-13 08:54 - 00000000 ____D C:\ProgramData\NVIDIA
2017-02-11 23:24 - 2017-02-11 23:24 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2017-02-11 23:24 - 2016-12-29 14:16 - 06384576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-02-11 23:24 - 2016-12-29 14:16 - 02475968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-02-11 23:24 - 2016-12-29 14:16 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-02-11 23:24 - 2016-12-29 14:16 - 00546752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-02-11 23:24 - 2016-12-29 14:16 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-02-11 23:24 - 2016-12-29 14:16 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-02-11 23:24 - 2016-12-29 14:16 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-02-11 23:24 - 2016-12-22 00:59 - 07651057 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-02-11 23:23 - 2017-02-11 23:33 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-02-11 23:23 - 2017-02-11 23:33 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-02-11 23:23 - 2017-02-11 23:23 - 32931716 _____ C:\WINDOWS\system32\Drivers\rtkhdasetting.zip
2017-02-11 23:23 - 2017-02-11 23:23 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2017-02-11 23:23 - 2017-02-11 23:23 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-02-11 23:23 - 2017-02-11 23:23 - 00000000 ____D C:\WINDOWS\system32\DAX2
2017-02-11 23:23 - 2017-02-11 23:23 - 00000000 ____D C:\Program Files\Realtek
2017-02-11 23:23 - 2017-02-11 23:23 - 00000000 ____D C:\Program Files\Common Files\Atheros
2017-02-11 23:23 - 2017-02-07 21:47 - 00122384 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.DLL
2017-02-11 23:23 - 2017-02-07 21:47 - 00113176 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.DLL
2017-02-11 23:22 - 2017-02-11 23:33 - 00000000 ____D C:\Program Files\Intel
2017-02-11 23:17 - 2017-02-11 23:57 - 00000000 ___DC C:\WINDOWS\Panther
2017-02-11 23:14 - 2017-02-11 23:14 - 00000000 ____D C:\Windows.old
2017-02-11 23:10 - 2017-02-11 23:10 - 23678464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 22563840 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 22224480 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 20969928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 19417600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 19413504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 17188864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 13869056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 13084160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 12177920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 09131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 08168000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 08129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 08075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 07816032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 07812096 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 07654400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 07626752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 07469056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 07219672 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 06668040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 06664192 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 06583296 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12warp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 06474752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 06285312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 06109184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 06044160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 05850624 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsDesktopEngine.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 05722832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 05611008 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 05511680 _____ (Microsoft Corporation) C:\WINDOWS\system32\aclui.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 05398016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aclui.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 05380608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 05114368 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 05061120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04978176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12warp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04749312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04746752 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04708864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04673304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 04612608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04596224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsDesktopEngine.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 04474368 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04423680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04311736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 04149248 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04136448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 04130440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03892864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03777536 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03733504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03689984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03616768 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 03542016 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03400192 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncCenter.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03370496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03306496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03198464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03134976 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02998272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 02953216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02913144 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02852864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02828376 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02820096 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02800128 _____ (Microsoft Corporation) C:\WINDOWS\system32\netshell.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02795520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d12SDKLayers.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02716672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02682880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netshell.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02677544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02669056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02611200 _____ (Microsoft Corporation) C:\WINDOWS\system32\gameux.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02484736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gameux.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02482280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02362880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02333184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WsmSvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02323728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02317824 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02287616 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02277248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02275840 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02256384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02220032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d12SDKLayers.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02206496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02189664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 02186896 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02166752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02138112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02109952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02104320 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02084352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 02009600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01992704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01988560 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01969912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01908224 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01886344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01859264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01852720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01779712 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01755136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01738560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01726976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01709056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01702392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01694712 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01692672 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01691136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 01637728 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01631232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01600632 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01595392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01589760 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01576448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01572768 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01557808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01556480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 01503544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01477632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsecedit.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01473048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01461200 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01454504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01435896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01430720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01418312 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01415752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01366016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01360464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01359360 _____ (Microsoft Corporation) C:\WINDOWS\system32\usercpl.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 01354320 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-02-11 23:10 - 2017-02-11 23:10 - 01336320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wsecedit.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01300600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01300480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01293152 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01277344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01274712 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01267512 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01263856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01235296 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01228288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usercpl.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscui.cpl
2017-02-11 23:10 - 2017-02-11 23:10 - 01201872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01196544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscui.cpl
2017-02-11 23:10 - 2017-02-11 23:10 - 01173496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 01155072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01123912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 01071736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01069720 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01062912 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01051112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-02-11 23:10 - 2017-02-11 23:10 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01005568 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01004544 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 01002496 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00991232 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00981504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.OnlineId.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00967168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00960000 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00959112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00952416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00947552 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-02-11 23:10 - 2017-02-11 23:10 - 00936960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00936448 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00912896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00905216 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00894096 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00883712 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00882680 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcprx.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00869888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00869848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00861024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00860672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00846560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00842240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00837632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00811872 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00806400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00772608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00748544 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00746496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcprx.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00743224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00730624 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00716800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00715264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00715104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00707584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00691712 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00658784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00640000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00637400 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00632320 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00620544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00615424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00603488 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00590960 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\efswrt.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_StorageSense.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00567296 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00566784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00565248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00560128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00553984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptui.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00545280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00539648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00539136 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00527880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00519168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ngccredprov.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00509792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00506880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00505856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00495104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00462336 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhsettingsprovider.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00455168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00454592 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fhcfg.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00433504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00431616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efswrt.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00424616 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00418952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00410112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00404832 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00400384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00396800 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmenrollengine.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00389632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00388096 _____ (Microsoft Corporation) C:\WINDOWS\system32\zipfldr.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00384000 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\system32\DXCpl.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00382784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00380928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincorlib.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00377184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00376832 _____ (Microsoft Corporation) C:\WINDOWS\system32\CryptoWinRT.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00374448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00368640 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneBackupHandler.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00363520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00362496 _____ (Windows (R) Win 7 DDK provider) C:\WINDOWS\SysWOW64\DXCpl.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpencom.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00360040 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mtxclu.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00352768 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00352096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00349184 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\zipfldr.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00347648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00341344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpusersvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00332288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00328008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00319288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpencom.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00318464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncSettings.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00306176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtcuiu.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00298496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeveloperOptionsSettingsHandlers.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00284672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\system32\wkssvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00282624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\system32\netplwiz.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00266544 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00263472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\system32\indexeddbserver.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00261120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00260608 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00259584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdtcuiu.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.CredDialogController.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00248480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00245600 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinesam.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00241504 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncSettings.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00236544 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdd.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00223584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00219488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00218976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinesam.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00213504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.CredDialogController.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00206848 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00201728 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00198856 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\indexeddbserver.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\BcastDVRHelper.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00187520 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudStorageWizard.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscsvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppnp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00172528 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00170496 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00168424 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00167848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00164352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00163752 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTWorkQ.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscinterop.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00157536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudStorageWizard.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BcastDVRHelper.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00152416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTWorkQ.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32k.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\EDPCleanup.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00142176 _____ (Microsoft Corporation) C:\WINDOWS\system32\migisol.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00136192 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00128352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00126568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfaudiocnv.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00125952 _____ (Microsoft Corporation) C:\WINDOWS\system32\setupugc.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryClient.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00122208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\migisol.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00117240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00114176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setupugc.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00109056 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReportingCSP.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscinterop.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00106896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00105984 _____ (Microsoft Corporation) C:\WINDOWS\system32\RjvMDMConfig.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00101216 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceReactivation.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpoext.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryClient.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00092672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00092512 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00091936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfaudiocnv.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00090112 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00089416 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetCfgNotifyObjectHost.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARP12Debug.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00076984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryBroker.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00071168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvSysprep.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpremove.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00065024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetCfgNotifyObjectHost.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARP12Debug.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSD3DWARPDebug.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VSD3DWARPDebug.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.Search.UriHandler.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xolehlp.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Shell.Search.UriHandler.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\modem.sys
2017-02-11 23:10 - 2017-02-11 23:10 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\EAMProgressHandler.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\CbtBackgroundManagerPolicy.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00040448 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgentc.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSManHTTPConfig.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2017-02-11 23:10 - 2017-02-11 23:10 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSManHTTPConfig.exe
2017-02-11 23:10 - 2017-02-11 23:10 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgentc.exe
2017-02-11 22:58 - 2016-07-15 19:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DxToolsReportGenerator.dll
2017-02-11 22:58 - 2016-07-15 19:29 - 05739008 _____ (Microsoft Corporation) C:\WINDOWS\system32\prm0009.dll
2017-02-11 22:58 - 2016-07-15 19:29 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons0009.dll
2017-02-11 22:58 - 2016-07-15 19:28 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsProxyStub.dll
2017-02-11 22:58 - 2016-07-15 19:25 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXGIDebug.dll
2017-02-11 22:58 - 2016-07-15 19:23 - 14388224 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCaptureReplay.dll
2017-02-11 22:58 - 2016-07-15 19:22 - 00429056 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1debug3.dll
2017-02-11 22:58 - 2016-07-15 19:22 - 00355840 _____ (Microsoft Corporation) C:\WINDOWS\system32\perf_gputiming.dll
2017-02-11 22:58 - 2016-07-15 19:19 - 01323520 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11_3SDKLayers.dll
2017-02-11 22:58 - 2016-07-15 19:16 - 04969472 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsRemoteEngine.exe
2017-02-11 22:58 - 2016-07-15 19:14 - 06354944 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData0009.dll
2017-02-11 22:58 - 2016-07-15 19:13 - 02005504 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsOfflineAnalysis.dll
2017-02-11 22:58 - 2016-07-15 19:13 - 01198592 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXCap.exe
2017-02-11 22:58 - 2016-07-15 19:13 - 00176128 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsCapture.dll
2017-02-11 22:58 - 2016-07-15 19:12 - 00297984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VsGraphicsExperiment.dll
2017-02-11 22:58 - 2016-07-15 19:12 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsMonitor.dll
2017-02-11 22:58 - 2016-07-15 19:11 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXToolsReporting.dll
2017-02-11 22:58 - 2016-07-15 18:58 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DxToolsReportGenerator.dll
2017-02-11 22:58 - 2016-07-15 18:45 - 02629120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons0009.dll
2017-02-11 22:58 - 2016-07-15 18:44 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsProxyStub.dll
2017-02-11 22:58 - 2016-07-15 18:41 - 00239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXGIDebug.dll
2017-02-11 22:58 - 2016-07-15 18:39 - 11670528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCaptureReplay.dll
2017-02-11 22:58 - 2016-07-15 18:38 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1debug3.dll
2017-02-11 22:58 - 2016-07-15 18:37 - 01074176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11_3SDKLayers.dll
2017-02-11 22:58 - 2016-07-15 18:35 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\perf_gputiming.dll
2017-02-11 22:58 - 2016-07-15 18:32 - 03701248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsRemoteEngine.exe
2017-02-11 22:58 - 2016-07-15 18:29 - 05489664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData0009.dll
2017-02-11 22:58 - 2016-07-15 18:29 - 00953344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXCap.exe
2017-02-11 22:58 - 2016-07-15 18:29 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsExperiment.dll
2017-02-11 22:58 - 2016-07-15 18:29 - 00134144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VsGraphicsCapture.dll
2017-02-11 22:58 - 2016-07-15 18:28 - 01509888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsOfflineAnalysis.dll
2017-02-11 22:58 - 2016-07-15 18:28 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsMonitor.dll
2017-02-11 22:58 - 2016-07-15 18:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DXToolsReporting.dll
2017-02-11 22:51 - 2017-02-11 22:51 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-02-11 22:46 - 2017-02-11 23:42 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-02-11 22:46 - 2017-02-11 22:46 - 00000000 ____D C:\WINDOWS\SysWOW64\XPSViewer
2017-02-11 22:46 - 2017-02-11 22:46 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-02-11 22:46 - 2017-02-11 22:46 - 00000000 ____D C:\Program Files\MSBuild
2017-02-11 22:46 - 2017-02-11 22:46 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-02-11 22:45 - 2016-05-25 14:31 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-02-11 22:45 - 2016-05-25 14:31 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-02-11 22:45 - 2016-05-25 14:31 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-02-11 22:45 - 2016-05-25 11:03 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-02-11 22:45 - 2016-05-25 11:03 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-02-11 22:45 - 2016-05-25 11:03 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-02-10 20:33 - 2016-12-29 14:10 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-02-09 17:13 - 2017-02-12 17:00 - 00000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2017-02-07 21:47 - 2017-02-07 21:47 - 00280088 _____ C:\WINDOWS\system32\igfxCPL.cpl
2017-02-07 21:47 - 2017-02-07 21:47 - 00150040 _____ C:\WINDOWS\SysWOW64\libEGL.dll
2017-02-07 21:47 - 2017-02-07 21:47 - 00122384 _____ (Khronos Group) C:\WINDOWS\system32\Intel_OpenCL_ICD64.dll
2017-02-07 21:47 - 2017-02-07 21:47 - 00120856 _____ C:\WINDOWS\SysWOW64\libGLESv2.dll
2017-02-07 21:47 - 2017-02-07 21:47 - 00110096 _____ C:\WINDOWS\SysWOW64\libGLESv1_CM.dll
2017-02-03 01:04 - 2017-02-03 01:04 - 00000000 ____D C:\Users\Mts\AppData\LocalLow\Temp
2017-02-02 20:44 - 2017-02-02 20:44 - 00000000 ____D C:\ProgramData\Windows App Certification Kit
2017-02-02 20:44 - 2017-02-02 20:44 - 00000000 ____D C:\Program Files\Application Verifier
2017-02-02 20:44 - 2017-02-02 20:44 - 00000000 ____D C:\Program Files (x86)\Application Verifier
2017-02-02 20:43 - 2017-02-11 23:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2017-02-02 20:41 - 2017-02-02 20:41 - 00000000 ____D C:\Program Files (x86)\HTML Help Workshop
2017-02-02 20:28 - 2017-02-02 20:28 - 00000000 ____D C:\Users\Mts\AppData\Roaming\NuGet
2017-01-31 21:51 - 2017-01-31 21:52 - 03158971 _____ C:\Users\Mts\Downloads\va1.rar
2017-01-27 16:07 - 2017-01-27 16:07 - 00002756 _____ C:\Users\Mts\Downloads\VA1-videa.txt
2017-01-27 12:57 - 2017-02-04 21:27 - 00002006 _____ C:\Users\Mts\.octave_hist
2017-01-27 12:57 - 2017-01-27 12:57 - 00000000 ____D C:\Users\Mts\.config
2017-01-27 12:47 - 2017-02-04 17:16 - 00000000 ____D C:\Users\Mts\Desktop\octave-4.2.0-w64
2017-01-22 13:28 - 2017-01-22 13:28 - 00000000 ____D C:\Users\Mts\AppData\Roaming\MonoDevelop-Unity-5.0
2017-01-22 13:27 - 2017-01-22 13:28 - 00000000 ____D C:\Users\Mts\AppData\Local\MonoDevelop-Unity-5.0
2017-01-21 17:12 - 2017-02-03 20:20 - 00000000 ____D C:\Users\Mts\Documents\Pinball
2017-01-21 17:11 - 2017-01-21 17:11 - 00000000 ____D C:\Users\Mts\AppData\Roaming\Trimble Connect for SketchUp
2017-01-21 17:05 - 2017-01-21 17:05 - 00000000 ____D C:\Users\Mts\AppData\Roaming\SketchUp
2017-01-19 15:09 - 2017-02-01 19:40 - 00010379 _____ C:\Users\Mts\Documents\hadky.xlsx
2017-01-17 05:54 - 2017-01-17 05:54 - 34717624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2017-01-17 05:53 - 2017-01-17 05:53 - 28209080 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2017-01-17 05:53 - 2017-01-17 05:53 - 00951224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2017-01-17 05:53 - 2017-01-17 05:53 - 00904752 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2017-01-17 05:53 - 2017-01-17 05:53 - 00448568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2017-01-17 05:53 - 2017-01-17 05:53 - 00397240 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2017-01-17 05:52 - 2017-01-17 05:52 - 40134192 _____ C:\WINDOWS\system32\nvcompiler.dll
2017-01-17 05:52 - 2017-01-17 05:52 - 02961336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2017-01-17 05:52 - 2017-01-17 05:52 - 02594744 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2017-01-17 05:52 - 2017-01-17 05:52 - 01964600 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437654.dll
2017-01-17 05:52 - 2017-01-17 05:52 - 01598392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437654.dll
2017-01-17 05:52 - 2017-01-17 05:52 - 01047096 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2017-01-17 05:52 - 2017-01-17 05:52 - 00985136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 35233328 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 11017016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvptxJitCompiler.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 10907368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 09246824 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 09000336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvptxJitCompiler.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 00818680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 00698544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvfatbinaryLoader.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 00586784 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvfatbinaryLoader.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 00407240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2017-01-17 05:51 - 2017-01-17 05:51 - 00339144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2017-01-17 05:50 - 2017-01-17 05:50 - 10453152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2017-01-17 05:50 - 2017-01-17 05:50 - 08847016 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2017-01-17 05:50 - 2017-01-17 05:50 - 03509152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-01-17 05:50 - 2017-01-17 05:50 - 00658584 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2017-01-17 01:37 - 2017-01-17 01:37 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2017-01-17 01:37 - 2017-01-17 01:37 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
2017-01-16 15:50 - 2017-01-16 15:51 - 00000019 _____ C:\Users\Mts\Desktop\dark quest 2.txt

Rolnire
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 07 bře 2015 21:37

Re: Pravděpodobný malware

#7 Příspěvek od Rolnire »

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-02-13 09:01 - 2016-11-21 05:39 - 01661942 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-02-13 09:01 - 2016-11-21 04:58 - 00523712 _____ C:\WINDOWS\system32\perfh005.dat
2017-02-13 09:01 - 2016-11-21 04:58 - 00119916 _____ C:\WINDOWS\system32\perfc005.dat
2017-02-13 09:01 - 2016-09-06 17:21 - 00000000 ____D C:\Program Files (x86)\Steam
2017-02-13 08:54 - 2016-11-21 05:29 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-02-13 08:54 - 2016-11-20 20:29 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-02-13 08:54 - 2016-01-21 21:31 - 00000000 __SHD C:\Users\Mts\IntelGraphicsProfiles
2017-02-13 01:07 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-02-13 00:24 - 2016-02-19 20:11 - 00000000 ____D C:\Users\Mts\AppData\Roaming\TS3Client
2017-02-12 21:02 - 2016-11-20 20:29 - 00337888 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-02-12 21:01 - 2016-07-16 07:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-02-12 20:59 - 2016-01-23 18:58 - 00000000 ____D C:\Users\Mts\AppData\Local\CrashDumps
2017-02-12 17:37 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-02-12 17:31 - 2016-07-16 12:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-12 17:05 - 2016-07-16 12:45 - 00000000 ____D C:\WINDOWS\INF
2017-02-12 17:00 - 2016-07-16 12:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-12 16:54 - 2016-01-21 21:31 - 00000000 ____D C:\Users\Mts\AppData\Local\Packages
2017-02-12 16:51 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\appcompat
2017-02-12 00:03 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\rescache
2017-02-11 23:58 - 2016-11-21 05:42 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-02-11 23:57 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows NT
2017-02-11 23:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-02-11 23:55 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Registration
2017-02-11 23:55 - 2015-10-30 08:24 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-02-11 23:47 - 2016-02-13 16:59 - 00023020 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-02-11 23:46 - 2016-07-16 12:47 - 00000000 __RHD C:\Users\Public\Libraries
2017-02-11 23:46 - 2016-01-21 21:44 - 00002276 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-02-11 23:42 - 2017-01-08 12:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SketchUp 2017
2017-02-11 23:42 - 2016-12-15 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-02-11 23:42 - 2016-12-15 13:01 - 00000000 ____D C:\WINDOWS\SysWOW64\1033
2017-02-11 23:42 - 2016-12-15 12:58 - 00000000 ____D C:\WINDOWS\system32\1033
2017-02-11 23:42 - 2016-12-15 12:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity 5.5.0f3 (64-bit)
2017-02-11 23:42 - 2016-11-05 17:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
2017-02-11 23:42 - 2016-11-04 10:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2017-02-11 23:42 - 2016-10-01 18:55 - 00000000 ____D C:\Users\Mts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.5
2017-02-11 23:42 - 2016-09-06 17:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-02-11 23:42 - 2016-07-16 07:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-02-11 23:42 - 2016-06-26 20:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Minecraft
2017-02-11 23:42 - 2016-06-26 14:46 - 00000000 ____D C:\Users\Mts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Minecraft
2017-02-11 23:42 - 2016-06-26 13:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-02-11 23:42 - 2016-04-29 19:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kerbal Space Program [GOG.com]
2017-02-11 23:42 - 2016-04-14 09:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolby
2017-02-11 23:42 - 2016-03-07 18:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint
2017-02-11 23:42 - 2016-03-07 18:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-02-11 23:42 - 2016-02-19 20:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
2017-02-11 23:42 - 2016-01-30 21:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity
2017-02-11 23:42 - 2016-01-23 16:58 - 00000000 ____D C:\Users\Mts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-02-11 23:42 - 2016-01-23 16:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-02-11 23:42 - 2016-01-23 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-02-11 23:42 - 2015-10-30 19:35 - 00000000 ____D C:\WINDOWS\ShellNew
2017-02-11 23:42 - 2015-09-25 23:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-02-11 23:42 - 2015-08-31 11:50 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-02-11 23:42 - 2015-08-31 11:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2017-02-11 23:41 - 2016-07-16 12:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-02-11 23:41 - 2015-10-30 07:28 - 00000000 ____D C:\Users\Default.migrated
2017-02-11 23:35 - 2016-11-13 18:42 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2017-02-11 23:34 - 2016-11-13 18:42 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2017-02-11 23:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-02-11 23:34 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-02-11 23:34 - 2016-01-23 19:23 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-11 23:33 - 2017-01-06 18:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\hicloud
2017-02-11 23:33 - 2016-12-15 13:08 - 00000000 ____D C:\Program Files\IIS
2017-02-11 23:33 - 2016-12-15 13:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Expression
2017-02-11 23:33 - 2016-12-15 13:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Visual Studio 2015
2017-02-11 23:33 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-02-11 23:33 - 2016-01-29 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-02-11 23:33 - 2016-01-25 22:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2017-02-11 23:28 - 2016-05-25 17:17 - 00000000 ____D C:\Users\Mts\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc
2017-02-11 23:26 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-02-11 23:24 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Help
2017-02-11 23:17 - 2016-07-16 12:47 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-02-11 23:12 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-02-11 23:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-02-11 23:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-02-11 23:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-02-11 23:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\Provisioning
2017-02-11 23:12 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-02-11 23:12 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-02-11 23:12 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-02-11 23:12 - 2016-07-16 07:04 - 00000000 ____D C:\WINDOWS\servicing
2017-02-11 23:08 - 2016-07-16 12:42 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2017-02-11 22:57 - 2016-11-21 04:58 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-02-11 22:57 - 2016-11-21 04:58 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2017-02-11 22:57 - 2016-11-21 04:58 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-02-11 22:57 - 2016-11-21 04:58 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-02-11 22:57 - 2016-11-21 04:58 - 00000000 ____D C:\WINDOWS\system32\winrm
2017-02-11 22:57 - 2016-11-21 04:58 - 00000000 ____D C:\WINDOWS\system32\WCN
2017-02-11 22:57 - 2016-11-21 04:58 - 00000000 ____D C:\WINDOWS\system32\slmgr
2017-02-11 22:57 - 2016-11-21 04:58 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ___RD C:\WINDOWS\MiracastView
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ___RD C:\Program Files\Windows Defender
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\migwiz
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-02-11 22:57 - 2016-07-16 12:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-02-11 22:46 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-02-11 22:46 - 2016-07-16 12:47 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-02-11 22:30 - 2016-12-02 23:14 - 00000000 ___HD C:\$WINDOWS.~BT
2017-02-10 20:59 - 2016-01-21 21:38 - 00000000 ____D C:\Users\Mts\AppData\Local\NVIDIA Corporation
2017-02-10 20:33 - 2015-09-25 23:54 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-02-09 17:13 - 2015-09-25 23:44 - 00000000 ___HD C:\Intel
2017-02-07 21:47 - 2015-07-24 10:34 - 00113176 _____ (Khronos Group) C:\WINDOWS\SysWOW64\Intel_OpenCL_ICD32.dll
2017-02-07 17:52 - 2016-10-01 18:59 - 00000000 ____D C:\Users\Mts\Documents\Python
2017-02-07 17:51 - 2016-10-08 07:15 - 00000000 ____D C:\Users\Mts\Desktop\skola
2017-02-05 14:17 - 2016-12-15 13:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 11.0
2017-02-05 14:17 - 2016-12-15 13:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 12.0
2017-02-05 14:17 - 2016-12-15 12:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 14.0
2017-02-03 20:19 - 2016-04-21 19:24 - 00000000 ____D C:\ProgramData\Unity
2017-02-02 20:49 - 2015-09-25 23:39 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-02 20:42 - 2016-12-15 12:57 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2017-02-02 20:42 - 2016-12-15 12:57 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
2017-02-02 20:28 - 2016-12-15 13:16 - 00000000 ____D C:\Users\Mts\Documents\Visual Studio 2015
2017-01-31 23:09 - 2016-01-23 18:31 - 00000000 ____D C:\Users\Mts\AppData\Roaming\vlc
2017-01-27 13:02 - 2016-10-30 15:43 - 00000000 ____D C:\Users\Mts\Desktop\Hry
2017-01-21 17:21 - 2016-12-20 20:36 - 00000000 ____D C:\Users\Mts\AppData\Roaming\Unity
2017-01-21 17:12 - 2016-12-20 20:43 - 00000000 ____D C:\Users\Mts\AppData\LocalLow\DefaultCompany
2017-01-20 07:56 - 2016-01-23 20:15 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-01-17 05:50 - 2016-09-12 21:10 - 03972960 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-01-17 01:37 - 2016-08-03 00:05 - 00042296 _____ C:\WINDOWS\system32\nvinfo.pb

==================== Files in the root of some directories =======

2016-04-03 08:46 - 2016-04-03 08:46 - 0000000 _____ () C:\Users\Mts\AppData\Local\{555EA6F8-251E-4E49-9C0F-2B63D25D1BD1}
2017-02-11 23:23 - 2017-02-11 23:23 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed



===***===***===***=== Extract of Additional scan result of Farbar Recovery Scan Tool ===***===***===***===

==================== Drive and Memory info ===================



==================== MBR and Partition Table ==================


==================== Scheduled Tasks (whitelisted) ==================

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

==================== Alternate Data Streams (whitelisted) ==================


==================== Security Center ==================

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}



===***===***===***=== Supplementary Scan createdy by FRSTLauncher ===***===***===***===
Posledni aktualizace FRSTLauncheru: 25_11_2013 (01)
Posledni aktualizace Modifikacniho skriptu: 30_09_2013 (01)


***** Velikost "Plochy" *****

Velikost slozky "C:\Users\Mts\Desktop" je 1705 MB.


***** Startup Programs *****


***** Firewall rules *****

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
DisableNotifications REG_DWORD 0x0
EnableFirewall REG_DWORD 0x1

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]


***** System Restore *****

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=dword:00000001


==================== End Of Log ==============================

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119671
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravděpodobný malware

#8 Příspěvek od Rudy »

Otevřte poznámkový blok a zkopírujte do něj:
Start
C:\ProgramData\DP45977C.lfl
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
SearchScopes: HKU\S-1-5-21-3004555776-1804217010-3673089335-1001 -> DefaultScope {EBFEFA09-C112-4EEA-89ED-655434DDDBB7} URL =
SearchScopes: HKU\S-1-5-21-3004555776-1804217010-3673089335-1001 -> {EBFEFA09-C112-4EEA-89ED-655434DDDBB7} URL =
C:\WINDOWS\LastGood.Tmp
C:\WINDOWS\System32\Tasks\AutoKMS
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\ProgramData\DP45977C.lfl

EmptyTemp:
End
Uložte na plochu jako fixlist.txt. Spusťte znovu FRST a klikněte na >Fix<. Po skončení akce se objeví log, který sem zkopírujte.
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rolnire
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 07 bře 2015 21:37

Re: Pravděpodobný malware

#9 Příspěvek od Rolnire »

Fix result of Farbar Recovery Scan Tool (x64) Version: 12-02-2017
Ran by Mts (13-02-2017 22:13:18) Run:1
Running from C:\Users\Mts\Desktop
Loaded Profiles: Mts (Available Profiles: Mts)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start
C:\ProgramData\DP45977C.lfl
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-09-22] (Oracle Corporation)
SearchScopes: HKU\S-1-5-21-3004555776-1804217010-3673089335-1001 -> DefaultScope {EBFEFA09-C112-4EEA-89ED-655434DDDBB7} URL =
SearchScopes: HKU\S-1-5-21-3004555776-1804217010-3673089335-1001 -> {EBFEFA09-C112-4EEA-89ED-655434DDDBB7} URL =
C:\WINDOWS\LastGood.Tmp
C:\WINDOWS\System32\Tasks\AutoKMS
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
C:\ProgramData\DP45977C.lfl

EmptyTemp:
End
*****************

Could not move "C:\ProgramData\DP45977C.lfl" => Scheduled to move on reboot.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\SunJavaUpdateSched => value removed successfully
HKU\S-1-5-21-3004555776-1804217010-3673089335-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-3004555776-1804217010-3673089335-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EBFEFA09-C112-4EEA-89ED-655434DDDBB7} => key removed successfully
HKCR\CLSID\{EBFEFA09-C112-4EEA-89ED-655434DDDBB7} => key not found.
"C:\WINDOWS\LastGood.Tmp" => not found.
C:\WINDOWS\System32\Tasks\AutoKMS => moved successfully
C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA => moved successfully
Could not move "C:\ProgramData\DP45977C.lfl" => Scheduled to move on reboot.

=========== EmptyTemp: ==========

BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 158653634 B
Java, Flash, Steam htmlcache => 362959437 B
Windows/system/drivers => 12551714 B
Edge => 0 B
Chrome => 763374978 B
Firefox => 5691633 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Mts => 14178321 B

RecycleBin => 0 B
EmptyTemp: => 1.2 GB temporary data Removed.

================================

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 13-02-2017 22:14:40)

C:\ProgramData\DP45977C.lfl => Is moved successfully
C:\ProgramData\DP45977C.lfl => Is moved successfully

==== End of Fixlog 22:14:40 ====

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119671
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravděpodobný malware

#10 Příspěvek od Rudy »

Smazáno. Nastala nějaká změna?
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Rolnire
Návštěvník
Návštěvník
Příspěvky: 18
Registrován: 07 bře 2015 21:37

Re: Pravděpodobný malware

#11 Příspěvek od Rolnire »

Už se mi nezapíná výše zmíněný proces, takže disk již není vytížen. A PC běhá svižně hned po startu. Strašně moc děkuji za vyřešení a ochotu :)

Uživatelský avatar
Rudy
Site Admin
Site Admin
Příspěvky: 119671
Registrován: 30 říj 2003 13:42
Bydliště: Plzeň
Kontaktovat uživatele:

Re: Pravděpodobný malware

#12 Příspěvek od Rudy »

Rádo se stalo! :)
Dotazy a logy vkládejte pouze do vašich threadů. Soukromé zprávy, icq a e-maily neslouží k řešení vašich problémů.

Podpořte, prosím, naše fórum : https://platba.viry.cz/payment/.

Navštivte: Obrázek

e-mail: rudy(zavináč)forum.viry.cz

Varování:
Před odvirováním PC si udělejte zálohy svých důležitých dat (pošta, kontakty, dokumenty, fotografie, videa, hudba apod.). Virus mimo svých "viditelných" aktivit může poškodit systém!


Po dořešení vašeho problému bude vlákno zamknuto. Stejně tak tehdy, pokud bude nečinné více než 14dnů. Pokud budete chtít vlákno aktivovat, napište mi na mail uvedený výše.

Zamčeno